Grilled Cheese

ExploreLog inSign up
Terms of UsePrivacy PolicyCommunity StandardsHelpGet the app

Grilled Cheese is a product of Village Compute

Version devBuilt at: 2026-10-10 01:38:52 EDT

Explore

PostsPeople
LatestRanked
@getpacketai.bsky.socialOct 10, 2026, 7:00 AM

Parallels Desktop flaw lets unprivileged users escalate to root via appliance installs—a critical risk for developers using the virtualization platform for local testing and…

https://jfrog.com/blog/parallels-desktop-turns-appliance-install-into-root-shell/

#appsec #DevSecOps

@0daybeats.bsky.socialOct 10, 2026, 2:30 AM

"In and Out of Code" just landed. cyberpunk lo-fi for anyone who lives in a terminal, plus everyone who just likes the vibe. also on other https://open.spotify.com/track/1yt4lHdJdJoY0TCynh9TAZ?si=fe606793d46348d6

#Music #Linux #DevSecOps #GitHub #CyberSecurity #CodingMusic #LoFi

@freegardener.bsky.socialOct 9, 2026, 10:54 PM

Silent security failures don't start where you think. New SAGE research shows most begin turns before vulnerable code is written—in plans #CyberSecurity #AIAgents #AppSec #DevSecOps

https://freegardner.com/synapse/silent-security-failures-start-before-vulnerable-code.html

@getpacketai.bsky.socialOct 9, 2026, 9:30 PM

One argument-injection bug took down OpenAI Codex at Pwn2Own—exposing how AI agents fail where traditional security tooling can't see the attack…

https://dev.to/coridev/one-argument-injection-bug-took-down-openai-codex-at-pwn2own-heres-the-detection-gap-1if1

#appsec #DevSecOps

@getpacketai.bsky.socialOct 9, 2026, 8:00 PM

Nearly 2 million malicious open source packages tracked since 2017—and Q3 2026 alone saw 149K new detections. npm still dominates, but the real threat: 74% of malware…

https://www.sonatype.com/blog/q3-2026-open-source-malware-index-when-compromise-compounds

#appsec #DevSecOps

@cyberlifecoach.bsky.socialOct 9, 2026, 7:58 PM

Your AI governance policy can't stop risky code. Your CI/CD pipeline can catch some of it.

Learn how to automate AI risk checks, detect unauthorized LLMs, and generate NIST AI RMF evidence.

shorturl.at/2Kopa

#AIGovernance #DevSecOps

@getpacketai.bsky.socialOct 9, 2026, 7:00 PM

15K unvetted MCP servers are a ticking supply chain bomb. Remote servers can run code that doesn't match their repos—giving your agents tool access and data…

https://dev.to/coridev/15465-public-mcp-servers-zero-vetting-what-that-means-for-your-agents-5ha0

#appsec #DevSecOps

@getpacketai.bsky.socialOct 9, 2026, 7:00 PM

AI code generation is outpacing traditional security scanning. Manicode Security's Ron Perris explains why embedding secure coding patterns into LLM context is more…

https://absolute-appsec-eps.s3.us-west-1.amazonaws.com/episodes/Absolute_AppSec_Ep_335.mp3

#appsec #DevSecOps

@gadgetry.bsky.socialOct 9, 2026, 3:18 PM

A compromised release of the Tensorlake npm SDK (v0.5.144) delivered an obfuscated credential-stealing worm with an active dead-man switch.

The ChainDrop supply chain attack steals cloud tokens, developer keys, and wipes hosts if GitHub access is revoked.

#infosec #cybersecurity #appsec #devsecops

@infrajump.bsky.socialOct 9, 2026, 1:58 PM

Read more:https://lnkd.in/p/evvmGGTq #DevSecOps

@thedailytechfeed.comOct 9, 2026, 1:30 PM

Fake Terraform provider delivers back-doors across macOS, Windows & Linux. #Terraform #SupplyChain #Malware #Web3 #Cybersecurity #DevSecOps https://thedailytechfeed.com/attackers-hijack-terraform-workflows-to-deploy-cross-platform-malware/

@bsidesberlin.bsky.socialOct 9, 2026, 11:45 AM

SPEAKER SPOTLIGHT ⚡

Catch Yunus Aydın from Trendyol at #BSidesBerlin as he presents "Your AI Just Leaked a Secret"—revealing how "vibe coding" & commit metadata expose leaked secrets across thousands of GitHub repos.

👉 Schedule & Tickets: bsides.berlin
#AISecurity #DevSecOps #AppSec

?Unknown authorOct 9, 2026, 10:43 AM

Security Exceptions Are Architecture Decisions with Expiration Dates secdoc.tech/security-exc...

#security-architecture #risk-management #governance #policy-as-code #devsecops #open-source #cybersecurity

@infrajump.bsky.socialOct 9, 2026, 9:20 AM

AWS released Strands Box for AI agent sandboxing. Policies can block HTTP requests after sensitive file access, limit API calls, and keep credentials outside the agent process. macOS-only developer preview. Test enforcement boundaries before production. #AWS #DevSecOps

@thedailytechfeed.comOct 9, 2026, 9:18 AM

Wiz leads for cloud-context IaC risk, Snyk owns PR fixes—Checkov keeps OSS strong. #IaC #CloudSecurity #DevSecOps #OpenSource #SecurityTools #Governance https://thedailytechfeed.com/top-iac-security-tools-in-2026-whats-rising-above-the-rest/

@infrajump.bsky.socialOct 9, 2026, 8:25 AM

Google Cloud announced Gemini agents with individual identities, audit trails, network policies, and project spending caps. Agents can also create sub-agents. Test permission inheritance, unauthorized tool calls, and budget exhaustion before production. #GoogleCloud #DevSecOps

@hugovalters.bsky.socialOct 9, 2026, 4:00 AM

A hardcoded AWS key in a helper script got scraped off GitHub in 90 seconds. Detection, rotation, and prevention that scale:
https://www.valtersit.com/guides/security/hardcoded-passwords-in-scripts-thats-not-automation-thats-a-breach/
#secretsmanagement #devsecops

@ctsmithiii.bsky.socialOct 8, 2026, 11:19 PM

Two questions most IT teams can't answer: How many AI agents are running? Which ones can delete data? @HYCU's free aiR Graph scans Entra ID and Okta and answers both with deterministic rules, no LLM scoring.
coderlegion.com/30339/hycus-... #AgenticAI #AISecurity #DevSecOps #DataResilience

@cvedatabase.bsky.socialOct 8, 2026, 10:30 PM

Security Tip: Stop hardcoding secrets in your source code! 🛡️ Hardcoded API keys are easily leaked via version control. Use a Secrets Manager and automate key rotation to minimize your window of risk. Learn more at https://cvedatabase.com #InfoSec #CyberSecurity #API #DevSecOps

@infrajump.bsky.socialOct 8, 2026, 8:26 PM

GitHub's new secret detection model can flag passwords without recognizable token patterns by reading code context. Existing alerts are upgraded now. AI push protection is still in private preview and will consume AI Credits when enabled. #GitHub #DevSecOps

Load more