fosstodon.org is one of the many independent Mastodon servers you can use to participate in the fediverse.
Fosstodon is an invite only Mastodon instance that is open to those who are interested in technology; particularly free & open source software. If you wish to join, contact us for an invite.

Administered by:

Server stats:

9.8K
active users

#dast

1 post1 participant0 posts today
Jakub Wołynko<p>Hi there,</p><p>If you will be able to use any tech stack for <a href="https://mastodon.social/tags/cicd" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cicd</span></a> what you will use? I’m especially interested in <a href="https://mastodon.social/tags/dast" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dast</span></a> part, for static part <a href="https://mastodon.social/tags/trivy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>trivy</span></a> and <a href="https://mastodon.social/tags/checkov" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>checkov</span></a> seems to be solid partners, but for dynamic scans I’m still searching…</p><p><a href="https://mastodon.social/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a></p>
kingthorin_rm<p>The <span class="h-card" translate="no"><a href="https://infosec.exchange/@zaproxy" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>zaproxy</span></a></span> team did some stuff in March 😎 You can get the details here:</p><p><a href="https://www.zaproxy.org/blog/2025-04-02-zap-updates-march-2025/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">zaproxy.org/blog/2025-04-02-za</span><span class="invisible">p-updates-march-2025/</span></a></p><p><a href="https://infosec.exchange/tags/DAST" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DAST</span></a> <a href="https://infosec.exchange/tags/AppSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AppSec</span></a> <a href="https://infosec.exchange/tags/WebAppSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WebAppSec</span></a> <a href="https://infosec.exchange/tags/DevSecOps" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DevSecOps</span></a></p>
kingthorin_rm<p>Giant set of <a href="https://infosec.exchange/tags/zaproxy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>zaproxy</span></a> add-on releases this morning. Including many fixes and improvements.</p><p><a href="https://infosec.exchange/tags/DAST" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DAST</span></a> <a href="https://infosec.exchange/tags/AppSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AppSec</span></a> <a href="https://infosec.exchange/tags/DevSecOps" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DevSecOps</span></a> <a href="https://infosec.exchange/tags/WebAppSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WebAppSec</span></a> <a href="https://infosec.exchange/tags/RedTeam" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RedTeam</span></a> <a href="https://infosec.exchange/tags/WebAppSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WebAppSec</span></a></p>
kingthorin_rm<p>According to my VM update this morning <span class="h-card" translate="no"><a href="https://infosec.exchange/@zaproxy" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>zaproxy</span></a></span> 2.16.0 is now available on <span class="h-card" translate="no"><a href="https://infosec.exchange/@kalilinux" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>kalilinux</span></a></span> <br><a href="https://infosec.exchange/tags/DAST" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DAST</span></a> <a href="https://infosec.exchange/tags/PenTest" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PenTest</span></a> <a href="https://infosec.exchange/tags/WebAppSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WebAppSec</span></a> <a href="https://infosec.exchange/tags/AppSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AppSec</span></a> <a href="https://infosec.exchange/tags/RedTeam" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RedTeam</span></a> <a href="https://infosec.exchange/tags/PurpleTeam" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PurpleTeam</span></a></p>
TechSplicer<p>🛡️ Security Scanner for Web Applications<br>🔒 Privacy-First Security Analysis 👩‍💻 Built by Developers, for Developers </p><p>Try it now: <a href="https://webscan.dev" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">webscan.dev</span><span class="invisible"></span></a></p><p><a href="https://mastodon.social/tags/SecurityTools" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SecurityTools</span></a> <a href="https://mastodon.social/tags/WebSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WebSec</span></a> <a href="https://mastodon.social/tags/DAST" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DAST</span></a></p>
Habr<p>Базовая настройка SAST и DAST для django в gitlab cicd: как быстро внедрить решения по безопасности</p><p>Привет, меня зовут Егор и я Tech Lead в компании ИдаПроджект :) Занимаюсь стратегией, процессами и командами в направлении backend разработки. Сегодня расскажу вам о базовой настройке SAST и DAST для django в gitlab cicd. В разработке использование SAST (Static Application Security Testing) и DAST (Dynamic Application Security Testing) в последние годы стало уже стандартом. На эту тему есть уже довольно много материала на habr, но я хочу сконцентрироваться на быстром и базовом внедрении решения по безопасности в следующий стек технологий: Infrastructure: Docker, Docker Compose, GitLab, GitLab CI/CD Backend: Python, Django с использованием Poetry Frontend: Vue.js, Nuxt.js Погнали!</p><p><a href="https://habr.com/ru/companies/idaproject/articles/868060/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">habr.com/ru/companies/idaproje</span><span class="invisible">ct/articles/868060/</span></a></p><p><a href="https://zhub.link/tags/sast" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sast</span></a> <a href="https://zhub.link/tags/dast" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dast</span></a> <a href="https://zhub.link/tags/django" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>django</span></a> <a href="https://zhub.link/tags/gitlab" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>gitlab</span></a></p>
Habr<p>Смешивать, но не взбалтывать. Как мы добавили Sec между Dev и Ops</p><p>Привет, Хабр! Меня зовут Натали Дуботолкова, я старший инженер по разработке безопасного программного обеспечения в Basis. Хочу рассказать о том, как мы задумались над интеграцией работы безопасников непосредственно в процесс разработки и к чему это привело, а также о том, какие методы и инструменты использовали в ходе интеграции и используем сейчас.</p><p><a href="https://habr.com/ru/companies/basis/articles/869648/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">habr.com/ru/companies/basis/ar</span><span class="invisible">ticles/869648/</span></a></p><p><a href="https://zhub.link/tags/devops" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>devops</span></a> <a href="https://zhub.link/tags/devsecops" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>devsecops</span></a> <a href="https://zhub.link/tags/%D0%BF%D0%BE%D0%B8%D1%81%D0%BA_%D1%83%D1%8F%D0%B7%D0%B2%D0%B8%D0%BC%D0%BE%D1%81%D1%82%D0%B5%D0%B9" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>поиск_уязвимостей</span></a> <a href="https://zhub.link/tags/%D0%B1%D0%B5%D0%B7%D0%BE%D0%BF%D0%B0%D1%81%D0%BD%D0%B0%D1%8F_%D1%80%D0%B0%D0%B7%D1%80%D0%B0%D0%B1%D0%BE%D1%82%D0%BA%D0%B0" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>безопасная_разработка</span></a> <a href="https://zhub.link/tags/%D0%B8%D0%BD%D1%81%D1%82%D1%80%D1%83%D0%BC%D0%B5%D0%BD%D1%82%D1%8B_%D1%82%D0%B5%D1%81%D1%82%D0%B8%D1%80%D0%BE%D0%B2%D0%B0%D0%BD%D0%B8%D1%8F" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>инструменты_тестирования</span></a> <a href="https://zhub.link/tags/sast" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sast</span></a> <a href="https://zhub.link/tags/dast" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dast</span></a> <a href="https://zhub.link/tags/fuzzing" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fuzzing</span></a> <a href="https://zhub.link/tags/%D0%BA%D0%BE%D0%BD%D1%82%D0%B5%D0%B9%D0%BD%D0%B5%D1%80%D1%8B" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>контейнеры</span></a></p>
kingthorin_rm<p><a href="https://infosec.exchange/tags/WebAppSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WebAppSec</span></a> <a href="https://infosec.exchange/tags/AppSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AppSec</span></a> <a href="https://infosec.exchange/tags/DAST" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DAST</span></a> <a href="https://infosec.exchange/tags/PenTest" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PenTest</span></a> <a href="https://infosec.exchange/tags/PurpleTeam" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PurpleTeam</span></a> <a href="https://infosec.exchange/tags/DevSecOps" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DevSecOps</span></a> <a href="https://infosec.exchange/tags/zaproxy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>zaproxy</span></a></p>
kingthorin_rm<p><a href="https://www.zaproxy.org/blog/2024-11-11-powering-up-dast-with-zap-and-noir/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">zaproxy.org/blog/2024-11-11-po</span><span class="invisible">wering-up-dast-with-zap-and-noir/</span></a></p><p><a href="https://infosec.exchange/tags/DAST" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DAST</span></a> <a href="https://infosec.exchange/tags/zaproxy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>zaproxy</span></a></p>
ZAP<p>We have restarted the ZAP monthly blog posts: <a href="https://www.zaproxy.org/blog/2024-11-01-zap-updates-october-2024/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">zaproxy.org/blog/2024-11-01-za</span><span class="invisible">p-updates-october-2024/</span></a><br><a href="https://infosec.exchange/tags/zaproxy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>zaproxy</span></a> <a href="https://infosec.exchange/tags/appsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>appsec</span></a> <a href="https://infosec.exchange/tags/dast" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dast</span></a></p>
kingthorin_rm<p>Get the latest on <span class="h-card" translate="no"><a href="https://infosec.exchange/@zaproxy" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>zaproxy</span></a></span>'s future from <span class="h-card" translate="no"><a href="https://infosec.exchange/@psiinon" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>psiinon</span></a></span> &amp; Ori Bendet via <span class="h-card" translate="no"><a href="https://bird.makeup/users/scmagazine" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>scmagazine</span></a></span> and Application Security Weekly podcast</p><p> <a href="https://infosec.exchange/tags/AppSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AppSec</span></a> <a href="https://infosec.exchange/tags/WebAppSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WebAppSec</span></a> <a href="https://infosec.exchange/tags/DAST" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DAST</span></a> <a href="https://infosec.exchange/tags/PenTesting" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PenTesting</span></a> <a href="https://infosec.exchange/tags/DevSecOps" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DevSecOps</span></a> <a href="https://infosec.exchange/tags/RedTeam" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RedTeam</span></a></p><p><a href="https://www.scworld.com/podcast-segment/13268-the-future-of-zed-attack-proxy-simon-bennetts-ori-bendet-asw-302" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">scworld.com/podcast-segment/13</span><span class="invisible">268-the-future-of-zed-attack-proxy-simon-bennetts-ori-bendet-asw-302</span></a></p>
Habr<p>Внедряем DevSecOps в процесс разработки. Часть 4. Этап Test-time Checks, обзор инструментов</p><p>Привет! На связи Олег Казаков из Spectr . В предыдущей части статьи я рассказал о контроле безопасности артефактов сборки в процессе проверки на безопасность. Сегодня поговорим о следующем этапе DevSecOps — Test-time Checks. Узнать больше про DevSecOps</p><p><a href="https://habr.com/ru/companies/spectr/articles/836004/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">habr.com/ru/companies/spectr/a</span><span class="invisible">rticles/836004/</span></a></p><p><a href="https://zhub.link/tags/devsecops" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>devsecops</span></a> <a href="https://zhub.link/tags/devsecops_services" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>devsecops_services</span></a> <a href="https://zhub.link/tags/dast" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dast</span></a> <a href="https://zhub.link/tags/owasp_zap" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>owasp_zap</span></a> <a href="https://zhub.link/tags/owasp" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>owasp</span></a></p>
Habr<p>Реализация сервиса сканирования на основе OWASP ZAP</p><p>Для защиты цифровых активов организаций важно оперативно выявлять и устранять уязвимости. Инструменты оценки уязвимостей автоматизируют этот процесс, позволяя эффективно находить слабые места в системах и приложениях. Привет! Меня зовут Никита, я занимаюсь информационной безопасностью в RuStore. Сегодня расскажу о том, как мы создали свой сервис сканирования уязвимостей на базе OWASP ZAP, с какими трудностями столкнулись и какие подходы применили для их решения.</p><p><a href="https://habr.com/ru/companies/vk/articles/829030/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">habr.com/ru/companies/vk/artic</span><span class="invisible">les/829030/</span></a></p><p><a href="https://zhub.link/tags/zap" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>zap</span></a> <a href="https://zhub.link/tags/dast" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dast</span></a> <a href="https://zhub.link/tags/%D1%81%D0%BA%D0%B0%D0%BD%D0%B8%D1%80%D0%BE%D0%B2%D0%B0%D0%BD%D0%B8%D0%B5_%D1%83%D1%8F%D0%B7%D0%B2%D0%B8%D0%BC%D0%BE%D1%81%D1%82%D0%B5%D0%B9" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>сканирование_уязвимостей</span></a> <a href="https://zhub.link/tags/%D0%B1%D0%B5%D0%B7%D0%BE%D0%BF%D0%B0%D1%81%D0%BD%D0%BE%D1%81%D1%82%D1%8C" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>безопасность</span></a> <a href="https://zhub.link/tags/%D0%B1%D0%B5%D0%B7%D0%BE%D0%BF%D0%B0%D1%81%D0%BD%D0%B0%D1%8F_%D1%80%D0%B0%D0%B7%D1%80%D0%B0%D0%B1%D0%BE%D1%82%D0%BA%D0%B0" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>безопасная_разработка</span></a> <a href="https://zhub.link/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://zhub.link/tags/appsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>appsec</span></a> <a href="https://zhub.link/tags/application_security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>application_security</span></a> <a href="https://zhub.link/tags/%D0%B4%D0%B8%D0%BD%D0%B0%D0%BC%D0%B8%D1%87%D0%B5%D1%81%D0%BA%D0%B8%D0%B9_%D0%B0%D0%BD%D0%B0%D0%BB%D0%B8%D0%B7" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>динамический_анализ</span></a></p>
ZAP<p>Do you use DAST from one of the many companies which build on top of ZAP but do not support us?<br>Please encourage them to support us now!<br><a href="https://www.zaproxy.org/third-party-services/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">zaproxy.org/third-party-servic</span><span class="invisible">es/</span></a><br><a href="https://infosec.exchange/tags/zaproxy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>zaproxy</span></a> <a href="https://infosec.exchange/tags/DAST" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DAST</span></a> <a href="https://infosec.exchange/tags/opensource" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>opensource</span></a></p>
kingthorin_rm<p>New <span class="h-card" translate="no"><a href="https://infosec.exchange/@zaproxy" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>zaproxy</span></a></span> community tip provided by yours truly (hit the GitHub link below).</p><p><a href="https://infosec.exchange/tags/zaproxy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>zaproxy</span></a> <a href="https://infosec.exchange/tags/DAST" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DAST</span></a> <a href="https://infosec.exchange/tags/AppSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AppSec</span></a> <a href="https://infosec.exchange/tags/WebAppSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WebAppSec</span></a></p><p><a href="https://github.com/zaproxy/community-scripts/tree/main/other/tips/selenium/edge" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/zaproxy/community-s</span><span class="invisible">cripts/tree/main/other/tips/selenium/edge</span></a></p>
ZAP<p>ZAP 2.15.0 is now available!<br>Read all about it: <a href="https://www.zaproxy.org/blog/2024-05-07-zap-2-15-0/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">zaproxy.org/blog/2024-05-07-za</span><span class="invisible">p-2-15-0/</span></a><br><a href="https://infosec.exchange/tags/zaproxy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>zaproxy</span></a> <a href="https://infosec.exchange/tags/appsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>appsec</span></a> <a href="https://infosec.exchange/tags/dast" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dast</span></a></p>
Habr<p>&lt;Cookie&gt; ctrl+c ctrl+v: автоматизируем прохождение авторизации в DAST</p><p>Привет, Хабр! С вами Анастасия Березовская, инженер по безопасности процессов разработки приложений в Swordfish Security. В этой статье мы разберемся, как пройти авторизацию в DAST-сканере с помощью прокси. Почему мы решили взяться за эту тему? Сейчас расскажем.</p><p><a href="https://habr.com/ru/companies/swordfish_security/articles/811821/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">habr.com/ru/companies/swordfis</span><span class="invisible">h_security/articles/811821/</span></a></p><p><a href="https://zhub.link/tags/%D0%B8%D0%BD%D1%84%D0%BE%D1%80%D0%BC%D0%B0%D1%86%D0%B8%D0%BE%D0%BD%D0%BD%D0%B0%D1%8F_%D0%B1%D0%B5%D0%B7%D0%BE%D0%BF%D0%B0%D1%81%D0%BD%D0%BE%D1%81%D1%82%D1%8C" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>информационная_безопасность</span></a> <a href="https://zhub.link/tags/%D0%B1%D0%B5%D0%B7%D0%BE%D0%BF%D0%B0%D1%81%D0%BD%D0%BE%D1%81%D1%82%D1%8C_%D0%B2%D0%B5%D0%B1%D0%BF%D1%80%D0%B8%D0%BB%D0%BE%D0%B6%D0%B5%D0%BD%D0%B8%D0%B9" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>безопасность_вебприложений</span></a> <a href="https://zhub.link/tags/dast" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dast</span></a> <a href="https://zhub.link/tags/%D1%81%D0%BA%D0%B0%D0%BD%D0%B5%D1%80_%D1%83%D1%8F%D0%B7%D0%B2%D0%B8%D0%BC%D0%BE%D1%81%D1%82%D0%B5%D0%B9" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>сканер_уязвимостей</span></a> <a href="https://zhub.link/tags/%D0%B0%D1%83%D1%82%D0%B5%D0%BD%D1%82%D0%B8%D1%84%D0%B8%D0%BA%D0%B0%D1%86%D0%B8%D1%8F" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>аутентификация</span></a> <a href="https://zhub.link/tags/%D1%81%D0%BA%D1%80%D0%B8%D0%BF%D1%82" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>скрипт</span></a> <a href="https://zhub.link/tags/%D0%BF%D1%80%D0%BE%D0%BA%D1%81%D0%B8%D1%80%D0%BE%D0%B2%D0%B0%D0%BD%D0%B8%D0%B5" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>проксирование</span></a></p>
Arthur Lutz (Zenika)<p>🎉 J'ai fini le "Learning Path" DevSecOps sur TryHackMe ! 🏆 Une certification de plus ! </p><p><a href="https://tryhackme.com/path/outline/devsecops" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">tryhackme.com/path/outline/dev</span><span class="invisible">secops</span></a></p><p>Super ateliers et contenus sur la supply chain, la sécurité dans la CI/CD, les outils de detection de failles, le hardening de conteneurs, docker, kubernetes, et même sur du terraform. </p><p><a href="https://pouet.chapril.org/tags/DevSecOps" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DevSecOps</span></a> <a href="https://pouet.chapril.org/tags/DevOps" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DevOps</span></a> <a href="https://pouet.chapril.org/tags/TryHackMe" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TryHackMe</span></a> <a href="https://pouet.chapril.org/tags/Gitlab" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Gitlab</span></a> <a href="https://pouet.chapril.org/tags/Jenkins" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Jenkins</span></a> <a href="https://pouet.chapril.org/tags/CICD" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CICD</span></a> <a href="https://pouet.chapril.org/tags/SAST" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SAST</span></a> <a href="https://pouet.chapril.org/tags/DAST" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DAST</span></a></p>
Habr<p>Идеальный кейс внедрения DevSecOps. Так бывает?</p><p>Привет, на связи отдел безопасной разработки СИГМЫ (ОБР). И хоть наша команда сформировалась относительно недавно, мы уже приобщились к «вечному» — а именно «противостоянию» разработки и безопасников. Если вы читаете эту статью, скорее всего такое знакомо и вам. Но иногда в этом взаимодействии формируются настоящие бриллианты. И сегодня речь пойдет как раз о таком кейсе.</p><p><a href="https://habr.com/ru/companies/sigma/articles/808999/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">habr.com/ru/companies/sigma/ar</span><span class="invisible">ticles/808999/</span></a></p><p><a href="https://zhub.link/tags/it_security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>it_security</span></a> <a href="https://zhub.link/tags/dast" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dast</span></a> <a href="https://zhub.link/tags/sast" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sast</span></a> <a href="https://zhub.link/tags/fuzzing" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fuzzing</span></a> <a href="https://zhub.link/tags/appsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>appsec</span></a> <a href="https://zhub.link/tags/%D1%83%D1%81%D1%82%D1%80%D0%B0%D0%BD%D0%B5%D0%BD%D0%B8%D0%B5_%D1%83%D1%8F%D0%B7%D0%B2%D0%B8%D0%BC%D0%BE%D1%81%D1%82%D0%B5%D0%B9" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>устранение_уязвимостей</span></a> <a href="https://zhub.link/tags/%D0%B1%D0%B5%D0%B7%D0%BE%D0%BF%D0%B0%D1%81%D0%BD%D0%B0%D1%8F_%D1%80%D0%B0%D0%B7%D1%80%D0%B0%D0%B1%D0%BE%D1%82%D0%BA%D0%B0" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>безопасная_разработка</span></a> <a href="https://zhub.link/tags/%D1%80%D0%B0%D0%B7%D1%80%D0%B0%D0%B1%D0%BE%D1%82%D0%BA%D0%B0_%D0%BF%D0%BE" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>разработка_по</span></a> <a href="https://zhub.link/tags/%D0%B8%D0%BD%D1%84%D0%BE%D1%80%D0%BC%D0%B0%D1%86%D0%B8%D0%BE%D0%BD%D0%BD%D0%B0%D1%8F_%D0%B1%D0%B5%D0%B7%D0%BE%D0%BF%D0%B0%D1%81%D0%BD%D0%BE%D1%81%D1%82%D1%8C" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>информационная_безопасность</span></a> <a href="https://zhub.link/tags/devsecops" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>devsecops</span></a></p>
Jack Poller<p>Is it reasonable to expect developers to be domain-specific experts, design experts, development experts, *and* security experts?</p><p>NightVision joins the crowded and growing field of vendors alleviating the code security burden by providing a Web and API security testing system.</p><p>Surprisingly, NightVision does not market AI as its magic sauce or as the panacea for developers lacking cybersecurity expertise.</p><p>And NightVision just raised $5.4M seed funding.</p><p><a href="https://infosec.exchange/tags/DAST" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DAST</span></a> <a href="https://infosec.exchange/tags/APIsecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>APIsecurity</span></a> <a href="https://infosec.exchange/tags/WebSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WebSecurity</span></a> <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://infosec.exchange/tags/funding" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>funding</span></a></p><p><a href="https://www.securityweek.com/nightvision-raises-5-4-million-for-application-security-testing/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">securityweek.com/nightvision-r</span><span class="invisible">aises-5-4-million-for-application-security-testing/</span></a></p>