Kelly Shortridge · @shortridge
4148 followers · 378 posts · Server hachyderm.io

allies and enemies, my GOTO Chicago keynote is now up for you to enjoy youtube.com/watch?v=AxqX9ovGVi

it covers my potion recipe, the five ingredients that matter for systems resilience, and how we can nurture them across the software delivery lifecycle

…and, ofc, where we can sprinkle in some chaos

hoping it inspires software engineers to extend existing practices / tools not only to sustain systems resilience but also make attackers miserable ✨

#resilience #chaosengineering #devops #appsec

Last updated 1 year ago

Bar - בר :verified_flashing: · @bararchy
104 followers · 117 posts · Server hachyderm.io

A week ago (~) I wrote about a research I did on and Injection attacks.

The research highlights is in: brightsec.com/blog/llm-prompt-

The cool thing is that now at @Brightsec we have added this as a whole new test to our platform!

This is a very cool shiny test that I am very happy to see coming from research into full feature

#llm #prompt #appsec

Last updated 1 year ago

Gonçalo Valério · @dethos
334 followers · 1387 posts · Server s.ovalerio.net
Shawn Hooper (he/him) · @shawnhooper
1424 followers · 2623 posts · Server fosstodon.org

Anyone have a good ELI5 reason for not allowing a SaaS to be embeeded in an iframe? ie... why disabling CSRF protection is a bad thing.

#infosec #appsec

Last updated 1 year ago

aegilops :github::microsoft: · @aegilops
147 followers · 576 posts · Server fosstodon.org

I’ve released more GitHub :github: Secret 🔑 Scanning 🔎 custom patterns, which you can use with Advanced Security.

Some are 🔥 (IMHO), some are for auditing only - e.g. my “common passwords” pattern, written to spot some of the most commonly leaked weak passwords - “P@55word123!” etc.

We have DataDog, Sentry, .Net configs, MS SQLServer user creation, and Bearer tokens.

aegilops.github.io/posts/new-g

#github #secretscanning #appsec #sdlc #regex

Last updated 1 year ago

aegilops :github::microsoft: · @aegilops
147 followers · 576 posts · Server fosstodon.org

I’ve released more GitHub :github: Secret 🔑 Scanning 🔎 custom patterns, which you can use if you have Advanced Security.

Some are 🔥 (if I say so myself), some are for auditing only - e.g. my “common passwords” pattern, written to spot some of the most commonly leaked weak passwords - “P@55word123!” and the like.

We’ve got DataDog, Sentry, .Net configs, MS SQLServer user creation, and Bearer tokens.

lnkd.in/eqRG_FRa

#github #secretscanning #appsec #sdlc #SecretsManagement #regex

Last updated 1 year ago

Jean-Christophe Praud · @jc
33 followers · 28 posts · Server framapiaf.org

Bordel de fuck de pompe à zob !
Encore une SQL injection dans : securityaffairs.com/148252/sec

Les SQLi sont probablement les failles les plus faciles à éviter en ! Ces gens là ne connaissent pas les Prepared Statement ?

#cybersecurity #infosec #appsec #moveit

Last updated 1 year ago

aegilops :github::microsoft: · @aegilops
147 followers · 566 posts · Server fosstodon.org

@ovid and other Perl :perl: mongers. What, if anything, do you use for code security?

I know that using taint gets you far, but SAST is mostly what I’m thinking (especially for legacy code without taint). Any tips?

Does Perl::Critic do a decent job, and is there a list of what its security policy and 3rd party plug-ins cover?

Other OS SAST I found are: github.com/htrgouvea/zarn and this grep-based one: github.com/wireghoul/graudit

Are they OK?

#sast #perl #appsec #codesecurity #perlcritic

Last updated 1 year ago

Ian Dickinson · @ijdickinson
19 followers · 122 posts · Server mastodon.org.uk

Listened to a very interesting ep. of the We Hack Purple podcast on AI in security space today. Focusing both on AI as a tool for appsec, but also the new attack vectors that AI models open up. Fascinating stuff!

wehackpurple.com/podcast/episo

#security #appsec #ai #dev

Last updated 1 year ago

Ryuno-Ki · @RyunoKi
809 followers · 15984 posts · Server layer8.space

Are you into ?
Do you know that still look for a subject to graduate on?

Assign them to implement in .

I was informed that the community will thank you.

Would be great if the community like and friends could spread the word!

#wehackpurple #appsec #elixir #erlang #ed25519 #students #mathematics

Last updated 1 year ago

Lauritz · @lauritz
76 followers · 27 posts · Server ruhr.social

Additionally, it comes with some handy features such as basic Parameter Guessing, Proxy Configuration, Throttling, Exclusion for certain strings, Non-Headless mode, ...

PSA: I only tested it on macOS Ventura for now.

(3/3)

#xss #appsec #bugbounty

Last updated 1 year ago

aegilops :github::microsoft: · @aegilops
146 followers · 560 posts · Server fosstodon.org

Microsoft :microsoft: have an open job for a Security Program Manager for Open Source.

“Help us solve open source security challenges at scale, both for the company and the world. If you live at the intersection of open source, software engineering, security, and making things happen, please take a look… [It] is US-based, but…up to 100% remote”

jobs.careers.microsoft.com/glo

#jobs #sdlc #appsec #opensource #OpenSSF #security #CodeQL

Last updated 1 year ago

Lauritz · @lauritz
75 followers · 24 posts · Server ruhr.social

So, there are formal security considerations on how to implement "OAuth 2.0 for Browser-Based Apps" using Service Workers.

But if you actually decide to go down this rabbit hole, you definitely would want to functional test your solution THOROUGHLY for ALL browsers. 🫠

(4/4)

#oauth #oidc #sso #appsec #webdevelopment

Last updated 1 year ago

Who Let The Dogs Out · @ashed
78 followers · 8297 posts · Server mastodon.ml
Gonçalo Valério · @dethos
314 followers · 1358 posts · Server s.ovalerio.net
The Hacker News · @hackernews_bot
2592 followers · 1939 posts · Server social.platypush.tech

Referenced link: thehackernews.com/2023/05/what
Discuss on discu.eu/q/https://thehackerne

Originally posted by The Hacker News / @TheHackersNews: nitter.platypush.tech/TheHacke

Don't let unexpected vulnerabilities delay your app launch! Implement Static Application Security Testing (SAST) early in development to avoid surprises, launch delays, and risky software releases.

Learn how to simplify your workflow: thehackernews.com/2023/05/what

#appsec #infosec

Last updated 1 year ago

Beth Pariseau · @BPariseau
312 followers · 133 posts · Server hachyderm.io
The Hacker News · @hackernews_bot
2569 followers · 1900 posts · Server social.platypush.tech

Referenced link: thehackernews.com/2023/06/over
Discuss on discu.eu/q/https://thehackerne

Originally posted by The Hacker News / @TheHackersNews: nitter.platypush.tech/TheHacke

Secrets management is the overlooked elephant in the room.

A recent study by @GitGuardian found that 75% of IT decision-makers reported secret leaks from applications, causing issues for companies.

Read about this here: thehackernews.com/2023/06/over

#appsec #informationsecurity

Last updated 1 year ago

Anonymous :anarchism: 🏴 · @YourAnonRiots
5667 followers · 35566 posts · Server mstdn.social

Don't let unexpected vulnerabilities delay your app launch! Implement Static Application Security Testing (SAST) early in development to avoid surprises, launch delays, and risky software releases.

Learn how to simplify your AppSec workflow: thehackernews.com/2023/05/what

#appsec

Last updated 1 year ago

The Hacker News · @hackernews_bot
2555 followers · 1882 posts · Server social.platypush.tech

Referenced link: thehackernews.com/2023/05/what
Discuss on discu.eu/q/https://thehackerne

Originally posted by The Hacker News / @TheHackersNews: nitter.platypush.tech/TheHacke

Don't let unexpected vulnerabilities delay your app launch! Implement Static Application Security Testing (SAST) early in development to avoid surprises, launch delays, and risky software releases.

Learn how to simplify your AppSec workflow: thehackernews.com/2023/05/what

#appsec

Last updated 1 year ago