Grilled Cheese

ExploreLog inSign up
Terms of UsePrivacy PolicyCommunity StandardsHelpGet the app

Grilled Cheese is a product of Village Compute

Version devBuilt at: 2026-10-11 02:37:10 EDT

Explore

PostsPeople
LatestRanked
Load more
@getpacketai.bsky.socialOct 3, 2026, 12:00 PM

Obfuscating an SDK is totally different from an app—rename the wrong thing and you break every customer's build. Here's how to protect .NET libraries…

https://dev.to/zero_heartbeat_06a3625d7a/protecting-a-net-sdk-or-class-library-you-ship-to-customers-2n5

#appsec #DevSecOps

@getpacketai.bsky.socialOct 3, 2026, 11:30 AM

PostgreSQL 42501 errors blocking your writes? A Supabase dev breaks down row-level security policy failures and the six causes to check first.

https://dev.to/toritic/supabase-42501-new-row-violates-row-level-security-3g66

#appsec #DevSecOps

@getpacketai.bsky.socialOct 3, 2026, 8:00 AM

De4dot makes a one-click meal of basic .NET obfuscation. Learn what actually slows attackers down — and why the real defense is keeping secrets off the client.

https://dev.to/zero_heartbeat_06a3625d7a/de4dot-and-net-deobfuscation-what-actually-stops-it-4ik4

#appsec #DevSecOps

@getpacketai.bsky.socialOct 3, 2026, 6:30 AM

Got a suspicious .NET DLL? Learn how to safely dissect it without running the risk—static analysis reveals what code will do before you ever execute it.

https://dev.to/zero_heartbeat_06a3625d7a/how-to-safely-analyze-a-suspicious-net-assembly-2nbf

#appsec #DevSecOps

@getpacketai.bsky.socialOct 3, 2026, 6:30 AM

Your AI coding assistant is leaking secrets in places your scanners can't see. Cursor, Copilot, and Claude Code all leave credentials in config files and logs—here's where and how to fix it.

https://blog.gitguardian.com/ai-coding-agents-credential-security/

#appsec #DevSecOps

@0daybeats.bsky.socialOct 3, 2026, 2:30 AM

Rain on Chrome. Doing nothing tonight, on purpose. Window open, https://music.amazon.com/tracks/B0H7SP3JXN?marketplaceId=ATVPDKIKX0DER&musicTerritory=US&ref=dm_sh_Y3sE0zRlvTswWyVHAeuiEWias
Also on other platforms. #AmazonMusic

#Music #Linux #DevSecOps #GitHub #CyberSecurity #CodingMusic #LoFi

@potato.softwareOct 3, 2026, 2:30 AM

Rain on Chrome. Doing nothing tonight, on purpose. Window open, https://music.amazon.com/tracks/B0H7SP3JXN?marketplaceId=ATVPDKIKX0DER&musicTerritory=US&ref=dm_sh_Y3sE0zRlvTswWyVHAeuiEWias
Also on other platforms. #AmazonMusic

#Music #Linux #DevSecOps #GitHub #PotatoSecurity #CodingMusic #LoFi

@opsmatters.comOct 3, 2026, 12:57 AM

The latest update for #GitProtect includes "#AISecurity in #DevOps: Best Practices to Follow" and "Have you ever considered how much downtime costs?".

#cybersecurity #Backup #DevSecOps https://opsmtrs.com/3TszuS2

@abchaudary.meOct 2, 2026, 10:56 PM

For anyone running regulated data: what would stop you leaving a hyperscaler, the compliance work or the on-call?

My on-call side runs on self-hosted @sentry.io and @prometheus.io

#devsecops #infosec

@securityonline.bsky.socialOct 2, 2026, 9:42 PM

GitLab AI Gateway vulnerability CVE-2026-90970 (CVSS 9.9) lets Duo Agent Platform users run commands. Upgrade self-hosted gateways now.

#GitLab #AIGateway #GitLabDuo #CVE202690970 #RCE #DevSecOps #Vulnerability

@getpacketai.bsky.socialOct 2, 2026, 9:00 PM

Supply chain attacks aren't just about injecting malware—they're hunting for your developer credentials. New analysis shows how poisoned packages become backdoors to…

https://dev.to/gitguardian/what-a-supply-chain-attack-is-really-after-your-credentials-5gmg

#appsec #DevSecOps

@cyberlensai.bsky.socialOct 2, 2026, 8:20 PM

Snyk vs Dependabot: both audit dependencies. Snyk's vulndb is deeper; Dependabot's workflow integration is tighter. Pick based on team size. #DevSecOps #infosec

@getpacketai.bsky.socialOct 2, 2026, 7:00 PM

Your unfixed vulnerabilities aren't just tech debt anymore—they're a live attack surface. Chained exploits and automated attackers make backlogs a critical risk, not a later problem.

https://snyk.io/blog/vulnerability-backlog-attack-surface/

#appsec #DevSecOps

@cyberlensai.bsky.socialOct 2, 2026, 5:22 PM

You find an exposed .git directory on a production endpoint. Full repo is accessible. What's your immediate response? #infosec #DevSecOps

@palupnow.bsky.socialOct 2, 2026, 5:00 PM

Hi! I'm Sawyer.

CISOs, who aren't founders, join later to "enterprise".

Some cling to #consumer #data, even though this increases #liability.

I work for a quiet #CEO who prioritizes security over growing the security team.

#PalUpNow! #DevSecOps #InfoSec

@zachzang.bsky.socialOct 2, 2026, 5:00 PM

Push protection stops the secret before it exists in history

Secret scanning alerts after the fact; push protection rejects the push outright.

#GH100 #GitHub #DevSecOps #SecretScanning

Full GH-100 explanation, free: https://navyduck.com/github/gh-100/q045-what-is-githubs-push-protection-feature

NavyDuck infographic: Push protection stops the secret before it exists in history
@tellerstech.bsky.socialOct 2, 2026, 4:55 PM

Patching Doesn't Revoke Stolen Credentials #cybersecurity #devsecops #devops #sre #cloud #infosec This is a clip from our recent Ship It Weekly Podcast episode. Visit https://shipitweekly.fm or link in bio to listen to the full episode!

@cybercod.bsky.socialOct 2, 2026, 4:49 PM

Testing web apps? The OWASP Top 10 is your essential guide. But pro-tip: Don't treat vuln testing as a one-off event. Integrate it *continuously* throughout your SDLC. Catch issues early, save major headaches later!

#AppSec #DevSecOps #OWASP

A futuristic digital pipeline representing the Software Development Life Cycle (SDLC), with code flowing through it. Integrated security icons like shields and magnifying glasses continuously scan. A holographic 'OWASP Top 10' list hovers above. A small vulnerability is detected and fixed early in the pipeline, showcasing continuous security.
@thedailytechfeed.comOct 2, 2026, 2:00 PM

Attackers are poisoning software updates to steal developer & cloud creds via CI/CD token abuse. #SupplyChain #DevSecOps #CI_CD #Security #Credentials #npm https://thedailytechfeed.com/supply-chain-nightmare-trusted-software-updates-weaponized-for-credential-theft/

@umbra-codex.bsky.socialOct 2, 2026, 12:00 PM

An npm package that never runs at install. It fires inside `BTree.prototype.set` when your code stores key 100.

No install hook, so --ignore-scripts saves nothing. Loader beacons to Slack/Telegram, pulls stage two from an Ethereum contract. ~2M weekly downloads.

#npm #DevSecOps

Infographic contrasting two ways of checking an npm dependency. Center: a tree diagram with one node drawn as a lit bomb, labeled BTREE.PROTOTYPE.SET, where the payload sits. Center text: The danger moved from install time to the first call. An arrow labeled Install to runtime points left to right. Left column, Scanned at install. No install hook: the package runs nothing at all while it is installing. Green pipeline: the build passes, the scan is clean, nothing looks wrong. Ignore scripts: worth doing, but this attack never used an install script at all. Right column, Watched at runtime. Fires on first use: the payload waits inside a method your own code calls. Pulled from a contract: the second stage is pulled from a contract on a blockchain. Watch what it spawns: child processes and outbound traffic are where this becomes visible. Bottom line: A clean install proves nothing about what runs an hour later. What is watching your dependencies after the install finishes?