Grilled Cheese

ExploreLog inSign up
Terms of UsePrivacy PolicyCommunity StandardsHelpGet the app

Grilled Cheese is a product of Village Compute

Version devBuilt at: 2026-10-11 02:37:10 EDT

Explore

PostsPeople
LatestRanked
Load more
@thedailytechfeed.comOct 2, 2026, 2:00 PM

Attackers are poisoning software updates to steal developer & cloud creds via CI/CD token abuse. #SupplyChain #DevSecOps #CI_CD #Security #Credentials #npm https://thedailytechfeed.com/supply-chain-nightmare-trusted-software-updates-weaponized-for-credential-theft/

@umbra-codex.bsky.socialOct 2, 2026, 12:00 PM

An npm package that never runs at install. It fires inside `BTree.prototype.set` when your code stores key 100.

No install hook, so --ignore-scripts saves nothing. Loader beacons to Slack/Telegram, pulls stage two from an Ethereum contract. ~2M weekly downloads.

#npm #DevSecOps

Infographic contrasting two ways of checking an npm dependency. Center: a tree diagram with one node drawn as a lit bomb, labeled BTREE.PROTOTYPE.SET, where the payload sits. Center text: The danger moved from install time to the first call. An arrow labeled Install to runtime points left to right. Left column, Scanned at install. No install hook: the package runs nothing at all while it is installing. Green pipeline: the build passes, the scan is clean, nothing looks wrong. Ignore scripts: worth doing, but this attack never used an install script at all. Right column, Watched at runtime. Fires on first use: the payload waits inside a method your own code calls. Pulled from a contract: the second stage is pulled from a contract on a blockchain. Watch what it spawns: child processes and outbound traffic are where this becomes visible. Bottom line: A clean install proves nothing about what runs an hour later. What is watching your dependencies after the install finishes?
@infrajump.bsky.socialOct 2, 2026, 11:21 AM

Fortinet warns CVE-2026-104286 is being exploited against FortiMail. CVSS 9.8, unauthenticated file writes, no fix released yet. Disable IBE or restrict management access.

fortiguard.fortinet.com/FG-IR-26-175

#Fortinet #DevSecOps

@techscope365.bsky.socialOct 2, 2026, 10:20 AM

📝 「認証情報の墓場」GitHubが化した真因——DevSecOpsの理想と現実の致命的ギャップが招いた54万件流出事件

54万件以上の有効な認証情報がGitHubで放置される事態。その背景にある開発プロセスの構造的欠陥と、セキュリティ文化の歪みを徹底解剖します。

🔗 https://techscope365.com/2993/

#GitHub #認証情報流出 #DevSecOps #AI #テクノロジー

@spoint42.bsky.socialOct 2, 2026, 9:42 AM

Votre clé API Claude vaut trois fois plus que ce que vous pensez ; et pas dans le bon sens.

blog.gioria.org/fr/ai-securi... #DevSecOps

@baselone.bsky.socialOct 2, 2026, 7:23 AM

🚨 CVE monsters have entered the software supply chain. Deploy the Docker Commandos! 🐳

At #BaselOne26, Mohammad-Ali A'râbi shows how SBOMs, BuildKit attestations & Cosign can secure Java container builds – plus a live Spring Boot demo.

🎟️ eventfrog.ch/BaselOne26

#Java #Docker #DevSecOps #BaselOne

BaselOne 2026 Session-Visual für „Dockerize Java Securely: SBOMs + Attestations + Cosign“ mit Speaker Mohammad-Ali A'râbi. Rechts ist sein Porträt zu sehen, links stehen Session-Titel und Name des Speakers. Im Hintergrund ist eine stilisierte Basler Skyline in den violett-roten BaselOne-Farben dargestellt. Die BaselOne findet am 14. und 15. Oktober 2026 in der Markthalle Basel statt.
@hugovalters.bsky.socialOct 2, 2026, 4:00 AM

Paying $40k/month for an Elasticsearch cluster to hold logs nobody queries? Loki takes the Prometheus approach: index labels, not full text. Here's when it works, when https://www.valtersit.com/guides/monitoring/log-aggregation-with-loki-the-prometheus-approach-to-logs/
#Loki #Grafana #DevSecOps

@hugovalters.bsky.socialOct 2, 2026, 4:00 AM

Your DNS is plaintext. One tap in the colo and every internal name leaks or gets poisoned. A guide to deploying DoH and DoT internally: tradeoffs, certs, migration, hardening. https://www.valtersit.com/guides/networking/deploying-encrypted-dns-internally-doh-and-dot-guide/ #dnssecurity #devsecops

@hugovalters.bsky.socialOct 2, 2026, 3:00 AM

271 lines, beginner level. Scans requirements.txt against known CVEs, outputs JSON, can exit non-zero on high severity for CI. https://www.valtersit.com/python/dependency-vulnerability-scanner-with-pip-audit/ #Python #Security #DevSecOps

@0daybeats.bsky.socialOct 2, 2026, 2:30 AM

Overclocked is the one people quietly repost the second they find it. No https://music.amazon.com/tracks/B0HCW61V2X?marketplaceId=ATVPDKIKX0DER&musicTerritory=US&ref=dm_sh_94UWmn4YNyHj5mTwzCdAUV1Do

Also on other platforms.

#Music #AppleMusic #GitHub #LoFi #MusicVibe #DevSecOps #CyberPunk

@securityonline.bsky.socialOct 2, 2026, 2:07 AM

Discover critical OpenBao security vulnerabilities that lead to code execution. Learn how to patch these OpenBao security vulnerabilities now.

#OpenBao #Cybersecurity #Vulnerability #SecretsManagement #DevSecOps

@awscmblogposts.bsky.socialOct 1, 2026, 7:54 PM

✍️ New blog post by Gabriel Koo

Your AWS role can't tell a human from an agent anymore, part 5: putting the four layers together

#aws #security #ai #devsecops

@awscmblogposts.bsky.socialOct 1, 2026, 7:54 PM

✍️ New blog post by Gabriel Koo

Your AWS role can't tell a human from an agent anymore, part 4: detection — what did the agent actually touch?

#aws #security #ai #devsecops

@awscmblogposts.bsky.socialOct 1, 2026, 7:54 PM

✍️ New blog post by Gabriel Koo

Your AWS role can't tell a human from an agent anymore, part 3: the SCP backstop

#aws #security #ai #devsecops

@awscmblogposts.bsky.socialOct 1, 2026, 7:54 PM

✍️ New blog post by Gabriel Koo

Your AWS role can't tell a human from an agent anymore, part 2: label every agent call with a User-Agent tag

#aws #security #ai #devsecops

@awscmblogposts.bsky.socialOct 1, 2026, 7:54 PM

✍️ New blog post by Gabriel Koo

Your AWS role can't tell a human from an agent anymore, part 1: the threat model and the identity problem

#aws #security #ai #devsecops

@iam.slys.devOct 1, 2026, 7:48 PM

SpiderFoot automates OSINT for threat intelligence and attack surface mapping. The value is not one scan. It is repeatable search against a changing external footprint, so drift becomes visible before someone else notices it. Repeatability beats heroic audits. #AttackSurface #DevSecOps

@cyberlensai.bsky.socialOct 1, 2026, 5:21 PM

Your SAST tool flags a medium-severity issue. The code is behind a VPN. Do you ticket it or drop it? #cybersecurity #devsecops

@carahsoft.bsky.socialOct 1, 2026, 5:00 PM

Canada’s #digitaltransformation is accelerating, and secure software delivery is key to keeping pace. Join Carahsoft in Ottawa on 10/14 for the #DevSecOps Conference Canada & hear Government success stories and explore secure software delivery. Sign up: https://carah.io/DevSecOpsConferenceCanada2026

@tellerstech.bsky.socialOct 1, 2026, 4:57 PM

GitHub Enterprise Cloud: Export Credentials Instantly! #github #devsecops #devops #sre #cloud This is a clip from our recent Ship It Weekly Podcast episode. Visit https://shipitweekly.fm or link in bio to listen to the full episode!