Grilled Cheese

ExploreLog inSign up
Terms of UsePrivacy PolicyCommunity StandardsHelpGet the app

Grilled Cheese is a product of Village Compute

Version devBuilt at: 2026-10-11 02:37:10 EDT

Explore

PostsPeople
LatestRanked
Load more
@cvedatabase.bsky.socialOct 9, 2026, 10:30 AM

Security Tip: Rotate your API keys regularly! 🛡️ Static secrets are a ticking time bomb. Automated rotation limits the window of exposure if a leak occurs. Use a secrets manager to handle the heavy lifting. Stay informed at https://cvedatabase.com #InfoSec #CyberSecurity #AppSec

@shehackspurple.bsky.socialOct 9, 2026, 2:50 AM

Question for you: What's one security control you've added (or changed) specifically because your team started using AI coding tools?

I'd love to hear what people are actually doing right now.

#AppSec #AISecurity #SecureSoftwareDevelopment
5/5

@opsmatters.comOct 9, 2026, 2:15 AM

The latest update for #SaltSecurity includes "Your #AI Transformation Needs Runtime Protection for the Whole Agentic Estate" and "When a Security Guardrail Detects the Attack and Still Can't Stop It".

#cybersecurity #APISecurity #AppSec https://opsmtrs.com/40EBWWv

@potato.softwareOct 9, 2026, 2:07 AM

The latest update for #Zenity includes "Zenity for Claude Tag: Securing the Shared Agent in Your Slack Workspace" and "Meet Dai Fujimoto: Building Zenity's Next Chapter in Japan".

#potatosecurity #lowcodesecurity #appsec https://opsmtrs.com/3GN6TxH

@opsmatters.comOct 9, 2026, 2:07 AM

The latest update for #Zenity includes "Zenity for Claude Tag: Securing the Shared Agent in Your Slack Workspace" and "Meet Dai Fujimoto: Building Zenity's Next Chapter in Japan".

#cybersecurity #lowcodesecurity #appsec https://opsmtrs.com/3GN6TxH

@opsmatters.comOct 9, 2026, 1:57 AM

The latest update for #GitGuardian includes "#AI Coding Assistants Are Unpredictable. GitGuardian AI Hooks Give You Control" and "The campaign that never stopped: tracking GhostAction from 2025 to 2026".

#cybersecurity #DevOps #infosec #appsec https://opsmtrs.com/3XY1xZb

@eyalestrin.bsky.socialOct 8, 2026, 7:35 PM

Secret protection must scale with software #appsec

@eyalestrin.bsky.socialOct 8, 2026, 7:35 PM

Never Deleted, Only Re-Pointed: Inside the 17,600-Repo FakeGit Fleet That Re-Arms Overnight #appsec

@eyalestrin.bsky.socialOct 8, 2026, 7:35 PM

TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack #appsec

@dkorunic.netOct 8, 2026, 5:32 PM

Prompt injection via cloned repo: ponytail’s SessionStart hook piped raw repo text (multi-line export { } lists, odd folder names) into the model’s hidden context. PR: identifier-only export entries + safe-path filter.
github.com/DietrichG... #security #appsec #aisecurity

@zachzang.bsky.socialOct 8, 2026, 5:00 PM

A template engine that fetches user-supplied URLs is an RFI finding

Attacker-controlled remote includes escalate to code execution, not just a bad fetch.

#CPTS #PenTesting #WebSecurity #AppSec

Full CPTS explanation, free: https://navyduck.com/cpts/web-application-penetration-testing/q203

NavyDuck infographic: A template engine that fetches user-supplied URLs is an RFI finding
@shehackspurple.bsky.socialOct 8, 2026, 4:01 PM

Season 2 of DevSec Station is about AI, agents, application security, and building systems that can survive being surprised.

🎧 Episode 1: **Your AI Worked 59 Times. What About the 60th?**

Listen or watch here: https://twp.ai/9Obuiw

#DevSecStation #AppSec #AISecurity #SecureCoding
4/4

@zaproxy.orgOct 8, 2026, 2:42 PM

Initial support for handling OAuth2.0 is now available.

Details on the ZAP Blog: www.zaproxy.org/blog/2026-10...

Lots of other add-ons have also been updated, so update ZAP now!
#appsec #zaproxy

@opensecurityconf.bsky.socialOct 8, 2026, 9:29 AM

Want some inspiration? Check out the recaps from last years: opensecurityconference.org/about/past-c...

#osco #osco26 #Security #CyberSecurity #InfoSec #AppSec #OTSecurity [lisi] 2/2

@hacks.grOct 8, 2026, 7:57 AM

Cycode leads a 2026 ranking of 10 platforms that help companies organize software security findings and route them for fixes.

The assessment gave fixin…

https://en.hacks.gr/katataxi-2026-i-cycode-proti-anamesa-se-10-platformes-gia-provlimata-asfaleias-logismikoy/

#Cycode #AppSec #SoftwareSecurity

Κατάταξη 2026: Η Cycode πρώτη ανάμεσα σε 10 πλατφόρμες για προβλήματα ασφάλειας λογισμικού
@opsmatters.comOct 8, 2026, 3:28 AM

The latest update for #GitGuardian includes "The campaign that never stopped: tracking GhostAction from 2025 to 2026" and "#SecretsManagement Best Practices: 6 Reasons Your Vault Needs Detection".

#cybersecurity #DevOps #infosec #appsec https://opsmtrs.com/3XY1xZb

@devstackdaily.bsky.socialOct 7, 2026, 6:01 PM

Tools that help developers ship more software should also take on more responsibility for securing it, since developer pace keeps outpacing manual secret…

#DevTools #AppSec #SecureByDefault #ShiftLeft
https://github.blog/ai-and-ml/github-copilot/secret-protection-must-scale-with-software/

@cyberlifecoach.bsky.socialOct 7, 2026, 5:08 PM

A website can have encryption and authentication and still leak private data.

Web Cache Deception exploits differences in how servers and caches interpret URLs.

I explain how it works and how to mitigate it:

shorturl.at/sw8Tr

#Cybersecurity #AppSec #Privacy

@owaspottawa.bsky.socialOct 7, 2026, 4:59 PM

#OWASP #Ottawa is proud to announce that Magno Logan, product security leader, will present at OWASP Ottawa Day 2026.

"Nobody's Mining Crypto Anymore: What Attackers Actually Want From Your CI"

📅 October 17
📍 UofO - STEM 117
ℹ️ tinyurl.com/87j33b82
🎟️ tinyurl.com/mr2z6z8r

#OWASPOttawa2026 #AppSec

@doyensec.bsky.socialOct 7, 2026, 4:37 PM

Congratulations to Maxence (@maxenceschmitt.bsky.social) and Yassine on successfully using their three bugs 🤯 to exploit Home Assistant Green (cc: @home-assistant.io ). Tough break that they were previously known - we'll get 'em next time!

#doyensec #appsec #security #pwn2own