Just Announced for BSides Luxembourg 2026!

๐Ÿ”’ ๐—ฆ๐—˜๐—–๐—จ๐—ฅ๐—˜ ๐——๐—˜๐—ฉ๐—˜๐—Ÿ๐—ข๐—ฃ๐— ๐—˜๐—ก๐—ง ๐—Ÿ๐—œ๐—™๐—˜๐—–๐—ฌ๐—–๐—Ÿ๐—˜ ๐—”๐—ฃ๐—ฃ๐—Ÿ๐—œ๐—˜๐—— โ€“ ๐— ๐—”๐—ž๐—˜ ๐—ง๐—›๐—œ๐—ก๐—š๐—ฆ ๐— ๐—ข๐—ฅ๐—˜ ๐—ฆ๐—˜๐—–๐—จ๐—ฅ๐—˜ ๐—˜๐—ฉ๐—˜๐—ฅ๐—ฌ ๐——๐—”๐—ฌ (2h Workshop) with Lisi Hocke
(@lisihocke)
Secure coding sounds overwhelming? This hands-on 2h workshop shows how: apply CIA triad, defence in depth, threat modeling, secure coding principles, security testing, and malware detection across the full dev lifecycle via interactive exercises on a real example. For anyone securing systems or reviving neglected ones. Gain core concepts, skills, and tactical advice to incrementally improve security daily.

Led by Lisi Hocke: (https://mastodon.social/@lisihocke) Security engineer & "specialized generalist," product security advocate, whole-team quality tester, community sharer.

๐Ÿ“… Conference Dates: 6โ€“8 May 2026 | 09:00โ€“18:00
๐Ÿ“ 14, Porte de France, Esch-sur-Alzette, Luxembourg
๐ŸŽŸ๏ธ Tickets: https://2026.bsides.lu/tickets/
๐Ÿ“… Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/

#BSidesLuxembourg #DevSecOps #SecureDevelopment #SecurityDevelopmentLifecycle

Trivy supply chain compromise:
- 75 GitHub Action tags hijacked
- Infostealer deployed in CI/CD
- Secrets exfiltrated (SSH, cloud, K8s, wallets)
- Root cause: credential compromise
Lesson: Never trust tags. Pin SHAs.

Source: https://thehackernews.com/2026/03/trivy-security-scanner-github-actions.html

Follow @technadu
#InfoSec #DevSecOps #SupplyChain

Your MCP server might be the weakest linkโ€”here's the data. @josh.bressers.name scanned 161 MCP images and found 9,000 vulns / 263 criticals. Read the breakdown and fixes: https://anchore.com/blog/analyzing-the-top-mcp-docker-containers/

#MCP #SoftwareSupplyChain #ContainerSecurity #DevSecOps

To accompany the v1.3 release of the OWASP Automated Threat Handbook - Web Applications, project co-Leader Tin Zaw produced a video to explain what the work is about. It is technology-, vendor- and jurisdiction- agnostic. The updated handbook is free and open source - as PDF, web pages and in print.

Watch "Automated Threats - Web's Hidden Puppeteers" on YouTube: https://youtu.be/6cNwrtzPP1E

#bot #bots #oats #automatedthreats #appsec #infosec #informationsecurity #devops #devsecops #owasp @owasp

DevSecOps Services That Actually Strengthen Your Software

Looking for reliable DevSecOps services? Deuex Solutions helps you build secure software from day one by integrating security into every stage of development. Explore trusted DevSecOps services in India for safer, faster releases.
https://medium.com/@deuexsolutions/devsecops-services-that-actually-strengthen-your-software-bfffcdeca3eb

#DevSecOps #DevSecOpsServices #CyberSecurity #SoftwareDevelopment #DevSecOpsIndia #SecureCoding #CloudSecurity #ITServices #DeuexSolutions

DevSecOps Services That Actually Strengthen Your Software

Security is no longer something you add at the end of development. It needs to be part of how your product is built from day one. That isโ€ฆ

Medium

Quarkus security is easy to start. But turning an API into a real login system is not much harder.

In this tutorial we upgrade a Quarkus Security JPA app from HTTP Basic to:
โ€ข Form login
โ€ข โ€œRemember meโ€ sessions
โ€ข GitHub OIDC login
โ€ข Secure cookies

All step-by-step.
https://www.the-main-thread.com/p/quarkus-form-login-github-oidc-remember-me-jpa

#Quarkus #Java #OIDC #Keycloak #DevSecOps

GitLab 18.10 adds cheap AI code reviews, but do developers actually want them?

https://fed.brid.gy/r/https://nerds.xyz/2026/03/gitlab-agentic-ai-18-10/

GitLab 18.10 adds cheap AI code reviews, but do developers actually want them?

GitLab is pushing agentic AI deeper into development workflows with version 18.10, but developers may question whether they actually need it.

NERDS.xyz

โš™๏ธ Harden Your DevSecOps Pipeline Workshop!

๐—Ÿ๐—˜๐—ฉ๐—˜๐—Ÿ ๐—จ๐—ฃ ๐—ฌ๐—ข๐—จ๐—ฅ ๐—–๐—œ/๐—–๐——: ๐—•๐—จ๐—œ๐—Ÿ๐——๐—œ๐—ก๐—š ๐—” ๐—ฆ๐—˜๐—–๐—จ๐—ฅ๐—˜ ๐—ฃ๐—œ๐—ฃ๐—˜๐—Ÿ๐—œ๐—ก๐—˜ ๐—ช๐—œ๐—ง๐—› ๐—ข๐—ฆ๐—ฆ (4h Workshop) with ๐—”๐—ก๐——๐—ข๐—ก๐—œ ๐—”๐—Ÿ๐—ข๐—ก๐—ฆ๐—ข & ๐—ฃ๐—”๐—–๐—ข ๐—ฆ๐—”๐—ก๐—–๐—›๐—˜๐—ญ
Whatโ€™s the "perfect" secure CI/CD pipeline? This hands-on 4h workshop shows you using open-source tools: integrate SAST (Semgrep), SCA, secrets detection (TruffleHog), IaC scanning, container vuln checks (Trivy), and more across the full DevSecOps lifecycle. Through live demos (break & fix), youโ€™ll see each stageโ€™s security goal, tool integration, and principles โ€“ not just copy-paste, but adaptable techniques for your own hardened pipelines.

Led by Andoni Alonso https://bsky.app/profile/andoniaf.unicrons.cloud (Prowler Open Cloud Security, unicrons.cloud founder, ex-SRE turned security/CTF pro) & Paco Sanchez https://pretalx.com/bsidesluxembourg-2026/speaker/UNNQE8/ (SRE in Developer Productivity/Platform Engineering, pragmatic tool-builder).

๐Ÿ“… Conference Dates: 6โ€“8 May 2026 | 09:00โ€“18:00
๐Ÿ“ 14, Porte de France, Esch-sur-Alzette, Luxembourg
๐ŸŽŸ๏ธ Tickets: https:// 2026.bsides.lu/tickets/
๐Ÿ“… Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/

Build secure pipelines that actually work โ€“ OSS only! ๐Ÿš€
#BsidesLuxembourg #OSS #OpenSource #SecurePipeline #CICD #DevSecOps

If you mount SSH keys into Docker for an AI coding agent, that agent can do whatever it wants with them. Push to any repo. Access any server. Frameworks that remove HITL mean nobody's watching.

Airlock v0.2.0 fixes this. Containers never hold credentials. A host-side daemon proxies CLI tools over a unix socket. Each container gets a profile with only the commands and credentials it needs. Nothing more.

https://github.com/calebfaruki/airlock/releases/tag/v0.2.0

#InfoSec #Docker #OpenSource #DevSecOps #AI #Rust