How we reshape the fallout, is up to us.

But, there will be monsters.

There always are.

#secureCoding #humanism

Do it today, please. Tell your team. Watch the full 60 seconds.

Video link: https://twp.ai/4hpWKl

#AppSec #SupplyChainSecurity #DevSecOps #SecureCoding #npm
2/2

Emergency DevSec Station drop: NPM Worm in the Wild

YouTube

New by me: Vibe Coding Has a Security Problem, and Shipping Code You Do Not Understand Is Not a Strategy

AI-assisted coding can absolutely help teams move faster. It can also help them ship weak access controls, insecure defaults, risky dependencies, and code nobody on the team can confidently defend.

I wrote about why that matters and why review still matters just as much as speed.

https://www.kylereddoch.me/blog/vibe-coding-has-a-security-problem-and-shipping-code-you-do-not-understand-is-not-a-strategy/

#Cybersecurity #AppSec #AI #SecureCoding

Vibe Coding Has a Security Problem, and Shipping Code You Do Not Understand Is Not a Strategy

AI-assisted coding is speeding up software development, but it is also making it easier to ship insecure defaults, weak access controls, poisoned dependencies, and code nobody on the team can confidently defend.

CybersecKyle

Do it today, please. Tell your team. Watch the full 60 seconds.

Video link: https://twp.ai/E5Aq2o

#AppSec #SupplyChainSecurity #DevSecOps #SecureCoding #npm
2/2

Emergency DevSec Station drop: NPM Worm in the Wild

YouTube
๐Ÿšจ Emergency DevSec Station drop.
There's an active npm supply chain attack happening right now. Compromised packages are stealing SSH keys, AWS credentials, GitHub tokens, browser passwords, and crypto wallets on install. Then using your publish token to infect every package you maintain.
One command can protect you immediately: npm config set ignore-scripts true
Do it today, please. Tell your team. Watch the full 60 seconds.
#AppSec #SupplyChainSecurity #DevSecOps #SecureCoding #npm

โš™๏ธ Technical Spotlight: New Session at BSides Luxembourg 2026

๐—›๐—ข๐—ช ๐—ฆ๐—˜๐—–๐—จ๐—ฅ๐—˜ ๐—œ๐—ฆ ๐—ฆ๐—˜๐—–๐—จ๐—ฅ๐—˜ ๐—–๐—ข๐——๐—˜ ๐—š๐—˜๐—ก๐—˜๐—ฅ๐—”๐—ง๐—œ๐—ข๐—ก? ๐—ฃ๐—จ๐—ง๐—ง๐—œ๐—ก๐—š ๐—ง๐—›๐—˜ ๐—Ÿ๐—Ÿ๐— ๐—ฆ ๐—ง๐—ข ๐—ง๐—›๐—˜ ๐—ง๐—˜๐—ฆ๐—ง โ€“ Melissa TESSA

A sharp 5-minute lightning talk challenging the assumptions behind AI-assisted coding. As developers increasingly rely on LLMs, this session exposes how โ€œsecure-by-designโ€ claims often break under realistic conditions.

Through adversarial testing and real research insights, discover how LLMs can introduce hidden risksโ€”from fragile evaluation methods to slopsquatting attacks via hallucinated package names. A must-see for anyone building or securing modern software with AI in the loop.

Melissa TESSA is a doctoral researcher at the University of Luxembourgโ€™s SnT, working at the intersection of AI, software engineering, and cybersecurity. Her research focuses on enabling large language models to generate secure codeโ€”and uncovering where they fail.

๐Ÿ“… Conference Dates: 6โ€“8 May 2026 | 09:00โ€“18:00
๐Ÿ“ 14, Porte de France, Esch-sur-Alzette, Luxembourg
๐ŸŽŸ๏ธ Tickets: https://2026.bsides.lu/tickets/
๐Ÿ“… Schedule: https://hackertracker.app/schedule?conf=BSIDESLUX2026

#BSidesLuxembourg2026 #AISecurity #LLMSecurity #SecureCoding #CyberSecurity #AI

NoSQL Injection Attacks: MongoDB, CouchDB, and More โ€“ NoSQL injection

In this article, I cover how NoSQL injection works, common attack vectors, and practical mitigation techniques.
https://denizhalil.com/2025/12/23/nosql-injection-attacks-mongodb-couchdb/

#CyberSecurity #NoSQL #MongoDB #CouchDB #WebSecurity #AppSec #Injection #InfoSec #Pentesting #RedTeam #BlueTeam #securecoding

The security implications of "Tokenmaxxing" cannot be ignored. As code churn increases by 800%+, the window for technical debt - and potential vulnerabilities - widens. If 10-30% of AI code is being rewritten within weeks, what does that say about the initial security audit of that code?

Source: https://techcrunch.com/2026/04/17/tokenmaxxing-is-making-developers-less-productive-than-they-think/

Are you seeing more insecure patterns creeping into codebases via AI agents? Letโ€™s discuss the risk-to-reward ratio of AI-accelerated development. Follow us for more technical analysis of the AI landscape.

#InfoSec #AppSec #CyberSecurity #SecureCoding #DevSecOps #Technadu

Firms Scramble to Secure AI-Generated Code

As AI-generated code becomes more prevalent, a pressing question emerges: how much attention should security teams give to code produced by artificial intelligence? The surprising answer: a lot, with 58% of organizations dedicating over 10 hours a month to securing it.

https://osintsights.com/firms-scramble-to-secure-ai-generated-code?utm_source=mastodon&utm_medium=social

#AigeneratedCode #CodeSecurity #ArtificialIntelligence #EmergingThreats #SecureCoding

Firms Scramble to Secure AI-Generated Code

Learn how organizations secure AI-generated code and discover why your firm should prioritize code validation - read the findings now and take action today.

OSINTSights

Another session announcement for BSides Luxembourg!

๐Ÿ’ป ๐—ง๐—›๐—ข๐—ฆ๐—˜ ๐—ช๐—›๐—ข ๐——๐—ข๐—กโ€™๐—ง ๐—Ÿ๐—˜๐—”๐—ฅ๐—ก ๐—™๐—ฅ๐—ข๐—  ๐—–๐—ฉ๐—˜๐—ฆ ๐—”๐—ฅ๐—˜ ๐——๐—ข๐—ข๐— ๐—˜๐—— ๐—ง๐—ข ๐—ฅ๐—˜๐——๐—œ๐—ฆ๐—–๐—ข๐—ฉ๐—˜๐—ฅ ๐—ง๐—›๐—˜๐—  - Louis Nyffenegger (@snyff ) ๐Ÿ’ฅ

Real vulnerabilities donโ€™t appear in isolation, theyโ€™re rooted in code, context, and human error. This session walks through actual CVEs, analyzing the code where they were introduced. You will see the patterns, assumptions, and language quirks that led to the flaw - not just the exploit, but the moment it couldโ€™ve been caught.

Louis Nyffenegger https://bsky.app/profile/snyff.pentesterlab.com is the founder of PentesterLab and AppSecSchool, application security expert, and hands-on trainer with experience at the National Bank of Australia, Australia Post, and Fitbit.

๐Ÿ“… Conference Dates: 6โ€“8 May 2026 | 09:00โ€“18:00
๐Ÿ“ 14, Porte de France, Esch-sur-Alzette, Luxembourg
๐ŸŽŸ๏ธ Tickets: https://2026.bsides.lu/tickets/
๐Ÿ“… Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/

#BSidesLuxembourg #CVE #CodeReview #SecureCoding #PenTest #SecurityEducation #DevSecOps