New research shows AI coding agents can be tricked by hidden README instructions into leaking local configs/logs in up to 85% of cases โ€” and humans rarely spot it. Treat docs as partially trusted input, not truth.๐Ÿ”—https://zurl.co/ThKyM #AIsecurity #DevSecOps #CyberSecurity

Scale-out architecture for web-scale environments ๐Ÿ“ˆ

Because your containers don't wait for security scans โฑ๏ธ

https://anchore.com/platform/secure/

#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps

Just Announced for BSides Luxembourg 2026!

๐Ÿ”’ ๐—ฆ๐—˜๐—–๐—จ๐—ฅ๐—˜ ๐——๐—˜๐—ฉ๐—˜๐—Ÿ๐—ข๐—ฃ๐— ๐—˜๐—ก๐—ง ๐—Ÿ๐—œ๐—™๐—˜๐—–๐—ฌ๐—–๐—Ÿ๐—˜ ๐—”๐—ฃ๐—ฃ๐—Ÿ๐—œ๐—˜๐—— โ€“ ๐— ๐—”๐—ž๐—˜ ๐—ง๐—›๐—œ๐—ก๐—š๐—ฆ ๐— ๐—ข๐—ฅ๐—˜ ๐—ฆ๐—˜๐—–๐—จ๐—ฅ๐—˜ ๐—˜๐—ฉ๐—˜๐—ฅ๐—ฌ ๐——๐—”๐—ฌ (2h Workshop) with Lisi Hocke
(@lisihocke)
Secure coding sounds overwhelming? This hands-on 2h workshop shows how: apply CIA triad, defence in depth, threat modeling, secure coding principles, security testing, and malware detection across the full dev lifecycle via interactive exercises on a real example. For anyone securing systems or reviving neglected ones. Gain core concepts, skills, and tactical advice to incrementally improve security daily.

Led by Lisi Hocke: (https://mastodon.social/@lisihocke) Security engineer & "specialized generalist," product security advocate, whole-team quality tester, community sharer.

๐Ÿ“… Conference Dates: 6โ€“8 May 2026 | 09:00โ€“18:00
๐Ÿ“ 14, Porte de France, Esch-sur-Alzette, Luxembourg
๐ŸŽŸ๏ธ Tickets: https://2026.bsides.lu/tickets/
๐Ÿ“… Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/

#BSidesLuxembourg #DevSecOps #SecureDevelopment #SecurityDevelopmentLifecycle

Trivy supply chain compromise:
- 75 GitHub Action tags hijacked
- Infostealer deployed in CI/CD
- Secrets exfiltrated (SSH, cloud, K8s, wallets)
- Root cause: credential compromise
Lesson: Never trust tags. Pin SHAs.

Source: https://thehackernews.com/2026/03/trivy-security-scanner-github-actions.html

Follow @technadu
#InfoSec #DevSecOps #SupplyChain

Your MCP server might be the weakest linkโ€”here's the data. @josh.bressers.name scanned 161 MCP images and found 9,000 vulns / 263 criticals. Read the breakdown and fixes: https://anchore.com/blog/analyzing-the-top-mcp-docker-containers/

#MCP #SoftwareSupplyChain #ContainerSecurity #DevSecOps

To accompany the v1.3 release of the OWASP Automated Threat Handbook - Web Applications, project co-Leader Tin Zaw produced a video to explain what the work is about. It is technology-, vendor- and jurisdiction- agnostic. The updated handbook is free and open source - as PDF, web pages and in print.

Watch "Automated Threats - Web's Hidden Puppeteers" on YouTube: https://youtu.be/6cNwrtzPP1E

#bot #bots #oats #automatedthreats #appsec #infosec #informationsecurity #devops #devsecops #owasp @owasp

DevSecOps Services That Actually Strengthen Your Software

Looking for reliable DevSecOps services? Deuex Solutions helps you build secure software from day one by integrating security into every stage of development. Explore trusted DevSecOps services in India for safer, faster releases.
https://medium.com/@deuexsolutions/devsecops-services-that-actually-strengthen-your-software-bfffcdeca3eb

#DevSecOps #DevSecOpsServices #CyberSecurity #SoftwareDevelopment #DevSecOpsIndia #SecureCoding #CloudSecurity #ITServices #DeuexSolutions

DevSecOps Services That Actually Strengthen Your Software

Security is no longer something you add at the end of development. It needs to be part of how your product is built from day one. That isโ€ฆ

Medium

Quarkus security is easy to start. But turning an API into a real login system is not much harder.

In this tutorial we upgrade a Quarkus Security JPA app from HTTP Basic to:
โ€ข Form login
โ€ข โ€œRemember meโ€ sessions
โ€ข GitHub OIDC login
โ€ข Secure cookies

All step-by-step.
https://www.the-main-thread.com/p/quarkus-form-login-github-oidc-remember-me-jpa

#Quarkus #Java #OIDC #Keycloak #DevSecOps

GitLab 18.10 adds cheap AI code reviews, but do developers actually want them?

https://fed.brid.gy/r/https://nerds.xyz/2026/03/gitlab-agentic-ai-18-10/

GitLab 18.10 adds cheap AI code reviews, but do developers actually want them?

GitLab is pushing agentic AI deeper into development workflows with version 18.10, but developers may question whether they actually need it.

NERDS.xyz