Scale-out architecture for web-scale environments ๐
Because your containers don't wait for security scans โฑ๏ธ
https://anchore.com/platform/secure/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
Just Announced for BSides Luxembourg 2026!
๐ ๐ฆ๐๐๐จ๐ฅ๐ ๐๐๐ฉ๐๐๐ข๐ฃ๐ ๐๐ก๐ง ๐๐๐๐๐๐ฌ๐๐๐ ๐๐ฃ๐ฃ๐๐๐๐ โ ๐ ๐๐๐ ๐ง๐๐๐ก๐๐ฆ ๐ ๐ข๐ฅ๐ ๐ฆ๐๐๐จ๐ฅ๐ ๐๐ฉ๐๐ฅ๐ฌ ๐๐๐ฌ (2h Workshop) with Lisi Hocke
(@lisihocke)
Secure coding sounds overwhelming? This hands-on 2h workshop shows how: apply CIA triad, defence in depth, threat modeling, secure coding principles, security testing, and malware detection across the full dev lifecycle via interactive exercises on a real example. For anyone securing systems or reviving neglected ones. Gain core concepts, skills, and tactical advice to incrementally improve security daily.
Led by Lisi Hocke: (https://mastodon.social/@lisihocke) Security engineer & "specialized generalist," product security advocate, whole-team quality tester, community sharer.
๐
Conference Dates: 6โ8 May 2026 | 09:00โ18:00
๐ 14, Porte de France, Esch-sur-Alzette, Luxembourg
๐๏ธ Tickets: https://2026.bsides.lu/tickets/
๐
Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/
#BSidesLuxembourg #DevSecOps #SecureDevelopment #SecurityDevelopmentLifecycle
Trivy supply chain compromise:
- 75 GitHub Action tags hijacked
- Infostealer deployed in CI/CD
- Secrets exfiltrated (SSH, cloud, K8s, wallets)
- Root cause: credential compromise
Lesson: Never trust tags. Pin SHAs.
Source: https://thehackernews.com/2026/03/trivy-security-scanner-github-actions.html
Follow @technadu
#InfoSec #DevSecOps #SupplyChain
Your MCP server might be the weakest linkโhere's the data. @josh.bressers.name scanned 161 MCP images and found 9,000 vulns / 263 criticals. Read the breakdown and fixes: https://anchore.com/blog/analyzing-the-top-mcp-docker-containers/
To accompany the v1.3 release of the OWASP Automated Threat Handbook - Web Applications, project co-Leader Tin Zaw produced a video to explain what the work is about. It is technology-, vendor- and jurisdiction- agnostic. The updated handbook is free and open source - as PDF, web pages and in print.
Watch "Automated Threats - Web's Hidden Puppeteers" on YouTube: https://youtu.be/6cNwrtzPP1E
#bot #bots #oats #automatedthreats #appsec #infosec #informationsecurity #devops #devsecops #owasp @owasp
DevSecOps Services That Actually Strengthen Your Software
Looking for reliable DevSecOps services? Deuex Solutions helps you build secure software from day one by integrating security into every stage of development. Explore trusted DevSecOps services in India for safer, faster releases.
https://medium.com/@deuexsolutions/devsecops-services-that-actually-strengthen-your-software-bfffcdeca3eb
#DevSecOps #DevSecOpsServices #CyberSecurity #SoftwareDevelopment #DevSecOpsIndia #SecureCoding #CloudSecurity #ITServices #DeuexSolutions
Quarkus security is easy to start. But turning an API into a real login system is not much harder.
In this tutorial we upgrade a Quarkus Security JPA app from HTTP Basic to:
โข Form login
โข โRemember meโ sessions
โข GitHub OIDC login
โข Secure cookies
All step-by-step.
https://www.the-main-thread.com/p/quarkus-form-login-github-oidc-remember-me-jpa
GitLab 18.10 adds cheap AI code reviews, but do developers actually want them?
https://fed.brid.gy/r/https://nerds.xyz/2026/03/gitlab-agentic-ai-18-10/
Thanks #Helpnetsecurity for including #Coroot in your top 6 picks for #opensource cybersecurity tools in February!
Learn about new open tools that can improve your stack: https://www.helpnetsecurity.com/2026/02/26/hottest-cybersecurity-open-source-tools-of-the-month-february-2026/
#opensource #observability #monitoring #cybersecurity #devops #devsecops #sysadmin #AI #tech #freesoftware #nodejs #security #kubernetes #FOSS