Obfuscating an SDK is totally different from an app—rename the wrong thing and you break every customer's build. Here's how to protect .NET libraries…

Obfuscating an SDK is totally different from an app—rename the wrong thing and you break every customer's build. Here's how to protect .NET libraries…
PostgreSQL 42501 errors blocking your writes? A Supabase dev breaks down row-level security policy failures and the six causes to check first.
https://dev.to/toritic/supabase-42501-new-row-violates-row-level-security-3g66
De4dot makes a one-click meal of basic .NET obfuscation. Learn what actually slows attackers down — and why the real defense is keeping secrets off the client.
https://dev.to/zero_heartbeat_06a3625d7a/de4dot-and-net-deobfuscation-what-actually-stops-it-4ik4
Got a suspicious .NET DLL? Learn how to safely dissect it without running the risk—static analysis reveals what code will do before you ever execute it.
https://dev.to/zero_heartbeat_06a3625d7a/how-to-safely-analyze-a-suspicious-net-assembly-2nbf
Your AI coding assistant is leaking secrets in places your scanners can't see. Cursor, Copilot, and Claude Code all leave credentials in config files and logs—here's where and how to fix it.
https://blog.gitguardian.com/ai-coding-agents-credential-security/
Rain on Chrome. Doing nothing tonight, on purpose. Window open, https://music.amazon.com/tracks/B0H7SP3JXN?marketplaceId=ATVPDKIKX0DER&musicTerritory=US&ref=dm_sh_Y3sE0zRlvTswWyVHAeuiEWias
Also on other platforms. #AmazonMusic
#Music #Linux #DevSecOps #GitHub #CyberSecurity #CodingMusic #LoFi
Rain on Chrome. Doing nothing tonight, on purpose. Window open, https://music.amazon.com/tracks/B0H7SP3JXN?marketplaceId=ATVPDKIKX0DER&musicTerritory=US&ref=dm_sh_Y3sE0zRlvTswWyVHAeuiEWias
Also on other platforms. #AmazonMusic
#Music #Linux #DevSecOps #GitHub #PotatoSecurity #CodingMusic #LoFi
The latest update for #GitProtect includes "#AISecurity in #DevOps: Best Practices to Follow" and "Have you ever considered how much downtime costs?".
#cybersecurity #Backup #DevSecOps https://opsmtrs.com/3TszuS2
For anyone running regulated data: what would stop you leaving a hyperscaler, the compliance work or the on-call?
My on-call side runs on self-hosted @sentry.io and @prometheus.io
GitLab AI Gateway vulnerability CVE-2026-90970 (CVSS 9.9) lets Duo Agent Platform users run commands. Upgrade self-hosted gateways now.
#GitLab #AIGateway #GitLabDuo #CVE202690970 #RCE #DevSecOps #Vulnerability
Supply chain attacks aren't just about injecting malware—they're hunting for your developer credentials. New analysis shows how poisoned packages become backdoors to…
https://dev.to/gitguardian/what-a-supply-chain-attack-is-really-after-your-credentials-5gmg
Snyk vs Dependabot: both audit dependencies. Snyk's vulndb is deeper; Dependabot's workflow integration is tighter. Pick based on team size. #DevSecOps #infosec
Your unfixed vulnerabilities aren't just tech debt anymore—they're a live attack surface. Chained exploits and automated attackers make backlogs a critical risk, not a later problem.
You find an exposed .git directory on a production endpoint. Full repo is accessible. What's your immediate response? #infosec #DevSecOps
Hi! I'm Sawyer.
CISOs, who aren't founders, join later to "enterprise".
Some cling to #consumer #data, even though this increases #liability.
I work for a quiet #CEO who prioritizes security over growing the security team.
Push protection stops the secret before it exists in history
Secret scanning alerts after the fact; push protection rejects the push outright.
#GH100 #GitHub #DevSecOps #SecretScanning
Full GH-100 explanation, free: https://navyduck.com/github/gh-100/q045-what-is-githubs-push-protection-feature
Patching Doesn't Revoke Stolen Credentials #cybersecurity #devsecops #devops #sre #cloud #infosec This is a clip from our recent Ship It Weekly Podcast episode. Visit https://shipitweekly.fm or link in bio to listen to the full episode!
Testing web apps? The OWASP Top 10 is your essential guide. But pro-tip: Don't treat vuln testing as a one-off event. Integrate it *continuously* throughout your SDLC. Catch issues early, save major headaches later!
Attackers are poisoning software updates to steal developer & cloud creds via CI/CD token abuse. #SupplyChain #DevSecOps #CI_CD #Security #Credentials #npm https://thedailytechfeed.com/supply-chain-nightmare-trusted-software-updates-weaponized-for-credential-theft/
An npm package that never runs at install. It fires inside `BTree.prototype.set` when your code stores key 100.
No install hook, so --ignore-scripts saves nothing. Loader beacons to Slack/Telegram, pulls stage two from an Ethereum contract. ~2M weekly downloads.