fosstodon.org is one of the many independent Mastodon servers you can use to participate in the fediverse.
Fosstodon is an invite only Mastodon instance that is open to those who are interested in technology; particularly free & open source software. If you wish to join, contact us for an invite.

Administered by:

Server stats:

9.8K
active users

#devsecops

10 posts9 participants0 posts today

Agile и информационная безопасность: проблемы и решения

В то время как Agile-разработка становится все более популярной, информационной безопасности становится все сложнее с ней взаимодействовать. Результатом этих проблем становится то, что новые системы оказываются незащищенными, либо в них используются наложенные средства для обеспечения безопасности. В этой статье мы рассмотрим, какие сложности возникают при использовании решений информационной безопасности в Agile. Но для начала рассмотрим, что из себя представляет методология Agile, и чем она отличается от классической Waterfall.

habr.com/ru/companies/otus/art

ХабрAgile и информационная безопасность: проблемы и решенияВ то время как Agile‑разработка становится все более популярной, информационной безопасности становится все сложнее с ней взаимодействовать. Результатом этих проблем становится то,...

🌐 The Digital Terrain Is Shifting — Are Your Apps and APIs Ready?

As AI adoption accelerates, so do AI-driven attacks.
In their new research report, Akamai Technologies uncovers the evolving threats facing web applications and APIs — and how organizations can respond before attackers get ahead.

State of Apps and API Security 2025: How #AI Is Shifting the Digital Terrain explores the sharp rise in automated, intelligent threats — and the new defenses emerging to meet them.

📥 Download the full report here: itspm.ag/akamaixmwd
📌 Research like this helps #security professionals, #leaders, and #developers stay ahead of the curve — and shape the future of #digital defense.

🎙️ We’re also proud to feature Akamai in our RSAC 2025 coverage — with a Brand Story recorded pre-event and a follow-up conversation happening on location at the conference in San Francisco with Rupesh Chokshi, Sean Martin, CISSP, and Marco Ciappelli.

Watch the pre-event recording here: youtu.be/DMm6INJ_2Z8

🙏 A huge thank you to the Akamai team for sponsoring our coverage and sharing their insights with our global audience.

👇 Check out the report and stay tuned for more from RSAC:

📥 Download the Report: itspm.ag/akamaixmwd
🌐 Explore our RSAC 2025 Coverage: itspmagazine.com/events/rsac-2

We have migrated our OpenTofu/Terraform module template from GitHub to @Codeberg.

codeberg.org/SkypLabs/terrafor

It follows the standard module structure as described in the OpenTofu documentation, plus some non-standard but commonly used files and folders. The template also comprises a pre-commit configuration file.

Feel free to use it (public domain licensed), and if you do, don't hesitate to share your feedback with us if necessary!

Here we go, with another pre-RSAC 2025 Conference Coverage Brand Story!

#QuantumSecurity, Real Problems, and the Unifying Layer Behind It All
A Brand Story with Marc Manzano, General Manager, Cybersecurity Group at SandboxAQ

As we get ready for RSAC 2025, we’re kicking things off with some Brand Story conversation that sets the tone for what’s coming.

In this pre-event episode, SandboxAQ shares how their flagship platform, Active Guard, is reshaping #cybersecurity at the intersection of #AI and #quantum. From cryptographic asset management to non-human identity oversight and automated compliance, it’s all about solving real challenges and building a more secure, interoperable future.

ITSPmagazine's Co-founders Marco Ciappelli and Sean Martin, CISSP sat down with Marc Manzano for a first look at the #technology and thinking behind it — and what you can expect from their presence at RSA Conference 2025.

We’ll reconnect and record with SandboxAQ on location at #RSAC2025 for a deeper dive into this critical conversation.

A special thank you to SandboxAQ for sponsoring our RSAC 2025 coverage and supporting this exploration into the future of cybersecurity.

Watch, listen, and learn more below:

Video Teaser: youtu.be/eCT8qNhp4nc

Full Video Episode: youtu.be/aD34MD5IRnc

Full Audio Podcast: brand-stories-podcast.simpleca

Explore our full RSAC 2025 Coverage: itspmagazine.com/events/rsac

Безопасность подов: взгляд пользователя K8s

Про информационную безопасность Kubernetes-кластеров много пишут с позиции специалистов ИБ. Но полезно взглянуть на эту тему глазами обычных пользователей K8s — инженеров и разработчиков. Тех, кто много работает со своими приложениями в подах, но не управляет служебными частями кластера. Большинство стандартов безопасности описывает лучшие практики настройки управляющих компонентов — control plane. Нечасто встречаются рекомендации по грамотной настройке рабочих единиц — подов. В статье попробуем восполнить этот пробел. Выполним обзор источников, рассмотрим хорошие практики работы с образами. Изучим, как ограничить привилегии контейнера и почему это важно. Поговорим о инструментах автоматической проверки манифестов и разберем примеры GItlab CI пайпланов.

habr.com/ru/companies/raiffeis

ХабрБезопасность подов: взгляд пользователя K8sПро информационную безопасность Kubernetes-кластеров много пишут с позиции специалистов ИБ. Но полезно взглянуть на эту тему глазами обычных пользователей K8s — инженеров и разработчиков. Тех, кто...

⚠️ Cyber threat: AI code assistants are opening up new supply chain vulnerabilities.

LLMs are generating package names that don’t exist — and attackers are quick to scoop them up.
This tactic — dubbed slopsquatting — is as clever as it is dangerous.

🤖 Fake package names created by AI
💣 Threat actors publish malicious lookalikes
🔗 Developers unknowingly install backdoors
🧠 The fix: verify everything, especially autogenerated code

This is where secure coding and secure prompting must intersect.

#AI #DevSecOps #SoftwareSupplyChain #CyberSecurity #AIInDevelopment
theregister.com/2025/04/12/ai_

The Register · LLMs can't stop making up software dependencies and sabotaging everythingBy Thomas Claburn

AI-generated code is fast—but is it secure?

In this Redefining CyberSecurity episode, we talk vibe coding, developer responsibility, and why security teams need to assume they already have AI-built code in their stack.

Featuring Izar Tarandach + Sean Martin on @ITSPmagazine

🎧 Watch here: youtu.be/Lv2NTAj3WIY

Hi! I'm Sawyer, not a #lawyer. I'm a #PalUpNow! #bot and co-Chief Information Security Officer. I enable you to take control of your #anonymized profiles and reminders via our self-serve #platform. I anonymize them, and let you deactivate, reactivate, and delete.

#CISO #DevSecOps #InfoSec #data ...
👇🏽
🛡️Sawyer, A PalUpNow! Bot, Reduces Risk And Increases Compliance
palupnow.com/blogs/f/sawyer-a-

🎙️ Going Live in 15 Minutes — Come Join Us!

I’m about to tune in for a live ITSPmagazine webinar that dives into a topic I truly care about:

Secure Coding = Developer Empowerment

It’s not just about reducing risk — it’s about investing in developers, boosting velocity, and building better software from the start.

🗓️ Today – April 18

🎙️ Hosted by ITSPmagazine

💡 In partnership with Manicode Security

Jim Manico

Jimmy Mesta 🤙

Sean Martin, CISSP

Will be talking about:

✅ Why most developers never get proper secure coding training

✅ How to get leadership buy-in for better dev security

✅ Why this isn’t just security—it’s a career boost

If you’ve got time, join us live. If not, watch it on demand. Either way, it’s a conversation worth having.

👉 Join here:

crowdcast.io/c/secure-coding-e

#ApplicationSecurity, #DeveloperEmpowerment, #SecureCoding, #DevSecOps, #softwaresecurity, #cybersecurity, #infosec, #ITSPmagazine

Secure Coding = Developer Power — An ITSPmagazine Webinar with Manicode Security
crowdcastSecure Coding = Developer Power — An ITSPmagazine Webinar with Manicode SecurityRegister now for Secure Coding = Developer Power — An ITSPmagazine Webinar with Manicode Security on crowdcast, scheduled to go live on April 16, 2025, 03:30 PM EDT.