#Devsecops

2026-02-05

🚨 Did you know an SBOM is more than a simple list of components?

Our expert webinar reveals how SBOMs are the key to transforming your zero-day response from a frantic search into a precise, targeted operation.

Discover the SBOM advantage. Watch the webinar now: go.anchore.com/rapid-incident- #SBOM #Security #DevSecOps #AppSec

ActiveStateactivestate
2026-02-05

Hardened Images: 28. Unmanaged Risk: 0. The scoreboard says it all.

Don’t let a vulnerability fumble your production. Power your infrastructure with a championship-ready foundation with ActiveState’s Secure Containers.

Find your winning lineup and browse our catalog: catalog.activestate.com/?utm_s

2026-02-05

CVE-2026-25049 highlights weaknesses in sandboxing user-defined JavaScript expressions within n8n workflows.

Multiple research teams demonstrated authenticated sandbox escape leading to unrestricted RCE, credential exposure, filesystem access, cloud pivoting, and AI workflow manipulation. The issue stems from incomplete AST-based sandboxing and runtime enforcement gaps.

Fixes have been released, and mitigation guidance includes updating, rotating secrets, and restricting workflow permissions.

Source: bleepingcomputer.com/news/secu

💬 What lessons does this case offer for securing automation platforms?

➕ Follow TechNadu for accurate, vendor-neutral infosec reporting.

#Infosec #CVE #n8n #SandboxEscape #RCE #CloudSecurity #DevSecOps

Critical n8n flaws disclosed along with public exploits
2026-02-05

Sec в DevSecOps — в чем разница подходов

Привет, Хабр! Меня зовут Рома Корчагин, я занимаюсь внедрением процессов безопасной разработки в продукте

habr.com/ru/companies/chislite

#devsecops #системное_администрирование #информационная_безопасность #девопс #devops #security #штурвал

2026-02-05

Tomorrow! Get ready for our Anchore Open Source live stream at 12 PM PT. Dive into Syft, Grype, and more. Don't miss out! youtube.com/watch?v=0GtI0pEWpzI #DevSecOps

LINUXexpert.orglinuxexpert
2026-02-04

sudo isn’t “nice to have.” It’s core infrastructure.

Its long-time maintainer, Todd C. Miller, is looking for a sponsor to keep sudo maintained and secure.

👉 millert.dev/

Sponsor: github.com/sponsors/sudo-proje

If your company has a security budget, this is one of the highest-leverage OSS sponsorships you can make.

2026-02-04

Tomorrow! Get ready for our Anchore Open Source live stream at 12 PM PT. Dive into Syft, Grype, and more. Don't miss out! youtube.com/watch?v=0GtI0pEWpzI #DevSecOps

2026-02-04

The Eclipse Foundation is moving Open VSX Registry security upstream by introducing pre-publish extension verification, transitioning from reactive incident response to proactive risk reduction.

Checks are designed to flag impersonation, exposed secrets, and known malicious patterns, with suspicious submissions quarantined for review. The phased rollout aims to minimize false positives while improving ecosystem trust.

This aligns with broader trends in securing developer tooling and shared infrastructure against supply-chain abuse.

Source: thehackernews.com/2026/02/ecli

💬 How effective do you expect pre-publish controls to be in open-source ecosystems?
Follow @technadu for objective infosec reporting.

#Infosec #SupplyChainSecurity #OpenSourceSecurity #DevSecOps #VSCode #TechNadu

Eclipse Foundation Mandates Pre-Publish Security Checks for Open VSX Extensions
2026-02-04

How many critical CVEs did your team patch this week? What’s still open?
Track real-world details for recent CVEs like CVE-2026-20805 and CVE-2026-21509:
👉 cvedatabase.com #DevSecOps #RiskMgmt

CYBERDUDEBIVASHcyberdudebivash
2026-02-04

LAUNCHING TODAY: CYBERDUDEBIVASH DDoS-Killer

Stop DDoS attacks for ₹2,999 one-time (not ₹50k/month!)

Rate limiting
Auto-ban
Bot detection
2-min setup
Self-hosted

🔗 cyberdudebivash.gumroad.com/l/

2026-02-03

New by me: Digital Forensic on Compromised Containers.

Just got asked a solid question by a fellow security nerd:

“How do you do digital forensics on a compromised container… what logs do you collect and how do you snapshot it for deeper digging?”

So I wrote it up as a practical, preservation-first guide.

Digital forensics in container land is basically archaeology with a stopwatch. 🧪🕵️

kylereddoch.me/blog/digital-fo

#CyberSecurity #IncidentResponse #DigitalForensics #Kubernetes #Docker #DevSecOps #BlueTeam #CybersecKyle

2026-02-03

РБПО и сертификация — от паники к процессу

Есть момент, когда компания внезапно понимает: «мы уже не стартап на коленке, у нас продукт, клиенты, релизы, ответственность - и, кажется, пора взрослеть». Вот примерно там и появляется РБПО - разработка безопасного программного обеспечения. В выпуске CrossCheck говорят: РБПО - не «для галочки» и не «для регулятора» . Это про то, чтобы выжить в реальности, где код растёт, команды меняются, а рынок всё чаще спрашивает: «а вы вообще понимаете, из чего и как собраны ваши решения?».

habr.com/ru/companies/ctsg/art

#рбпо #безопасная_разработка #сертификация #devops #devsecops

2026-02-02

🚨 Open VSX Registry compromised to deploy GlassWorm malware

Four malicious VS Code extensions targeted macOS credentials, VPN sessions, and crypto wallets via a supply-chain attack.

technadu.com/open-vsx-registry

#InfoSec #SupplyChainSecurity #Malware #OpenVSX #DevSecOps

Open VSX Registry Deploys GlassWorm Malware via Four Malicious Extension Versions
AI Daily Postaidailypost
2026-02-02

GitLab just unveiled a roadmap where AI agents get their own social hub, promising tighter integration for software delivery, CI/CD and generative DevSecOps workflows. Could autonomous code assistants finally become a first‑class citizen in open‑source ecosystems? Read on!

🔗 aidailypost.com/news/ai-agents

Thomas Fricke (he/his)thomasfricke@23.social
2026-02-01

@tante

Wir nähern uns etwas, das wir wenigstens diskutieren können.

deutschland-stack.gov.de/gesam

Viel Pfeifen im Walde

"Wir haben angefangen den Tech-Stack mutig entlang der Ziele aus dem Koalitionsvertrag “Verantwortung für Deutschland” zu definieren"

Wenn Du sagen musst, dass Du mutig bist, hast Du Angst.

Brauchbares zu DevSecOps und zu Supply Chain.

Der KI Teil ist gefährlicher Quatsch.

#deutschlandstack #devsecops @BMDS #security

2026-02-01

False positives killing your team's productivity? 😵‍💫

Anchore Secure gives you signal, not noise 📡

anchore.com/platform/secure/

#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps

2026-01-31

Anchore SBOM Score = CVSS + EPSS + KEV status 📊

Because not all vulnerabilities are created equal ⚠️

anchore.com/platform/sbom/

#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst