Grilled Cheese

ExploreLog inSign up
Terms of UsePrivacy PolicyCommunity StandardsHelpGet the app

Grilled Cheese is a product of Village Compute

Version devBuilt at: 2026-10-10 01:38:52 EDT

Explore

PostsPeople
LatestRanked
@owaspottawa.bsky.socialOct 10, 2026, 2:02 PM

On behalf of #OWASP #Ottawa, a huge thank you to Mark Cimon for supporting OWASP’s 25th Anniversary event at OWASP Ottawa Day!

📅 October 17, 2026
📍 University of Ottawa - STEM 117
ℹ️ Information: tinyurl.com/87j33b82
🎟️ Tickets (free): tinyurl.com/mr2z6z8r

#OWASPOttawa2026 #AppSec #Cybersecurity

@eyalestrin.bsky.socialOct 10, 2026, 10:01 AM

GhostAction Returns: Malicious “Security Audit” Workflows Now Mine Credentials from Entire Git Histories #appsec

@getpacketai.bsky.socialOct 10, 2026, 7:00 AM

Parallels Desktop flaw lets unprivileged users escalate to root via appliance installs—a critical risk for developers using the virtualization platform for local testing and…

https://jfrog.com/blog/parallels-desktop-turns-appliance-install-into-root-shell/

#appsec #DevSecOps

@freegardener.bsky.socialOct 9, 2026, 10:54 PM

Silent security failures don't start where you think. New SAGE research shows most begin turns before vulnerable code is written—in plans #CyberSecurity #AIAgents #AppSec #DevSecOps

https://freegardner.com/synapse/silent-security-failures-start-before-vulnerable-code.html

@getpacketai.bsky.socialOct 9, 2026, 9:30 PM

One argument-injection bug took down OpenAI Codex at Pwn2Own—exposing how AI agents fail where traditional security tooling can't see the attack…

https://dev.to/coridev/one-argument-injection-bug-took-down-openai-codex-at-pwn2own-heres-the-detection-gap-1if1

#appsec #DevSecOps

@getpacketai.bsky.socialOct 9, 2026, 8:00 PM

Nearly 2 million malicious open source packages tracked since 2017—and Q3 2026 alone saw 149K new detections. npm still dominates, but the real threat: 74% of malware…

https://www.sonatype.com/blog/q3-2026-open-source-malware-index-when-compromise-compounds

#appsec #DevSecOps

@getpacketai.bsky.socialOct 9, 2026, 7:00 PM

15K unvetted MCP servers are a ticking supply chain bomb. Remote servers can run code that doesn't match their repos—giving your agents tool access and data…

https://dev.to/coridev/15465-public-mcp-servers-zero-vetting-what-that-means-for-your-agents-5ha0

#appsec #DevSecOps

@getpacketai.bsky.socialOct 9, 2026, 7:00 PM

AI code generation is outpacing traditional security scanning. Manicode Security's Ron Perris explains why embedding secure coding patterns into LLM context is more…

https://absolute-appsec-eps.s3.us-west-1.amazonaws.com/episodes/Absolute_AppSec_Ep_335.mp3

#appsec #DevSecOps

@securestep9.bsky.socialOct 9, 2026, 6:22 PM

#Anthropic launches FREE AI-powered vulnerability scanning service for established #opensource projects that have a critical impact on infrastructure and user security.

🔍 Periodic scans using Claude Mythos
🤖 Fully AI-generated reports
#AppSec
👇

@owaspottawa.bsky.socialOct 9, 2026, 4:38 PM

#OWASP #Ottawa is proud to announce that the dynamic duo of Logan MacLaren and Fennix will present:

"50 Shades of Red - Red Teaming & Pentesting in Practice"

📅 October 17, 2026
📍 UofO- STEM 117
ℹ️ tinyurl.com/87j33b82

🎟️ Tickets (free): tinyurl.com/mr2z6z8r

#OWASPOttawa2026 #RedTeam #AppSec

@gadgetry.bsky.socialOct 9, 2026, 3:18 PM

A compromised release of the Tensorlake npm SDK (v0.5.144) delivered an obfuscated credential-stealing worm with an active dead-man switch.

The ChainDrop supply chain attack steals cloud tokens, developer keys, and wipes hosts if GitHub access is revoked.

#infosec #cybersecurity #appsec #devsecops

@checkmarxzero.bsky.socialOct 9, 2026, 2:56 PM

🚨 6 new CVEs were published yesterday affecting different versions of fast-jwt.

Severity ranges from Medium to Critical, across different vulnerability classes including algorithm confusion and token expiration issues.

👉️ Upgrade to fast-jwt 6.3.4 to be covered against all six.

#AppSec #npm

@owasp.orgOct 9, 2026, 12:09 PM

🦎 What if your honeypot could adapt to the attacker?

CHAMELEON-REN is an adaptive web honeypot helping researchers observe, understand, and learn from real-world web attacks.

Curious how it works? 👀👇

owasp.org/news/chame...

#OWASP #AppSec #opensource

@owaspboston.bsky.socialOct 9, 2026, 12:02 PM

Our upcoming meetup is made possible by Maze!

This month Shubham Santosh Upadhyay will dive into Prompt Injection — what causes it and whether it can be detected.

RSVP to secure your spot: www.meetup.com/owaspboston/...

#owasp #boston #appsec

@bsidesberlin.bsky.socialOct 9, 2026, 11:45 AM

SPEAKER SPOTLIGHT ⚡

Catch Yunus Aydın from Trendyol at #BSidesBerlin as he presents "Your AI Just Leaked a Secret"—revealing how "vibe coding" & commit metadata expose leaked secrets across thousands of GitHub repos.

👉 Schedule & Tickets: bsides.berlin
#AISecurity #DevSecOps #AppSec

@cvedatabase.bsky.socialOct 9, 2026, 10:30 AM

Security Tip: Rotate your API keys regularly! 🛡️ Static secrets are a ticking time bomb. Automated rotation limits the window of exposure if a leak occurs. Use a secrets manager to handle the heavy lifting. Stay informed at https://cvedatabase.com #InfoSec #CyberSecurity #AppSec

@shehackspurple.bsky.socialOct 9, 2026, 2:50 AM

Question for you: What's one security control you've added (or changed) specifically because your team started using AI coding tools?

I'd love to hear what people are actually doing right now.

#AppSec #AISecurity #SecureSoftwareDevelopment
5/5

@opsmatters.comOct 9, 2026, 2:15 AM

The latest update for #SaltSecurity includes "Your #AI Transformation Needs Runtime Protection for the Whole Agentic Estate" and "When a Security Guardrail Detects the Attack and Still Can't Stop It".

#cybersecurity #APISecurity #AppSec https://opsmtrs.com/40EBWWv

@potato.softwareOct 9, 2026, 2:07 AM

The latest update for #Zenity includes "Zenity for Claude Tag: Securing the Shared Agent in Your Slack Workspace" and "Meet Dai Fujimoto: Building Zenity's Next Chapter in Japan".

#potatosecurity #lowcodesecurity #appsec https://opsmtrs.com/3GN6TxH

@opsmatters.comOct 9, 2026, 2:07 AM

The latest update for #Zenity includes "Zenity for Claude Tag: Securing the Shared Agent in Your Slack Workspace" and "Meet Dai Fujimoto: Building Zenity's Next Chapter in Japan".

#cybersecurity #lowcodesecurity #appsec https://opsmtrs.com/3GN6TxH

Load more