⤷ Title: What is API discovery and how do you find shadow APIs?
════════════════════════
𐀪 Author: Apiunderattack
════════════════════════
ⴵ Time: Mon, 28 Sep 2026 17:54:26 GMT
════════════════════════
⌗ Tags: #api_security #appsec #devsecops #attack_surface_management #cybersecurity
════════════════════════
𐀪 Author: Apiunderattack
════════════════════════
ⴵ Time: Mon, 28 Sep 2026 17:54:26 GMT
════════════════════════
⌗ Tags: #api_security #appsec #devsecops #attack_surface_management #cybersecurity
Medium
What is API discovery and how do you find shadow APIs?
API discovery is the practice of finding every endpoint that answers requests in your estate, whether or not anyone documented it…
⤷ Title: An API Key and an OAuth Token Differ by One Field, and That Field Decides Who Kills the Credential
════════════════════════
𐀪 Author: Ghost Accounts
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 02:55:44 GMT
════════════════════════
⌗ Tags: #oauth #cloud_security #identity_management #devsecops #api_security
════════════════════════
𐀪 Author: Ghost Accounts
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 02:55:44 GMT
════════════════════════
⌗ Tags: #oauth #cloud_security #identity_management #devsecops #api_security
Medium
An API Key and an OAuth Token Differ by One Field, and That Field Decides Who Kills the Credential
An API key identifies the project or application behind a request. An OAuth access token identifies a principal and carries a scope and an…
⤷ Title: Octopus Server Flaw CVE-2026-101169 Allows Code Execution via Insecure Deserialization
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 09:44:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_101169 #DevSecOps #Insecure Deserialization #Octopus Deploy #Octopus Server #Octopus Server vulnerability #Remote Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 09:44:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_101169 #DevSecOps #Insecure Deserialization #Octopus Deploy #Octopus Server #Octopus Server vulnerability #Remote Code Execution
Daily CyberSecurity
Octopus Server Flaw CVE-2026-101169 Allows Code Execution via Insecure Deserialization
TL;DR Octopus Deploy has fixed a high-severity Octopus Server vulnerability, CVE-2026-101169. An authenticated user who can edit an Environment or Project can run arbitrary code in the server proc…
⤷ Title: Is the Vibe-coded application hacked ? Check with Strix.
════════════════════════
𐀪 Author: ambuj singh
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 18:10:16 GMT
════════════════════════
⌗ Tags: #devsecops #cybersecurity #penetration_testing #artificial_intelligence #open_source
════════════════════════
𐀪 Author: ambuj singh
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 18:10:16 GMT
════════════════════════
⌗ Tags: #devsecops #cybersecurity #penetration_testing #artificial_intelligence #open_source
Medium
Is the Vibe-coded application hacked ? Check with Strix.
Is the Vibe-coded application hacked? Check with Strix. An open-source team of autonomous AI pentesters that runs your code, attacks it, and proves what it finds. Introduction Most security tools …
⤷ Title: AI Coding Agents Leak 13,000 Internal Screenshots to Public GitHub Repos
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 08:21:06 +0000
════════════════════════
⌗ Tags: #Data Leak #AI Agents #Data Exposure #DevSecOps #github #Glow Labs #PixelLeak #shadow AI
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 08:21:06 +0000
════════════════════════
⌗ Tags: #Data Leak #AI Agents #Data Exposure #DevSecOps #github #Glow Labs #PixelLeak #shadow AI
Daily CyberSecurity
AI Coding Agents Leak 13,000 Internal Screenshots to Public GitHub Repos
More than 13,000 internal screenshots sat in public GitHub repositories, open to anyone. Glow Labs says AI coding agents put them there. The firm calls this AI agent screenshot leak “PixelLe…
⤷ Title: What is secure coding, and which five practices stop most CWE Top 25 bugs?
════════════════════════
𐀪 Author: Codeunderfire
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 14:13:33 GMT
════════════════════════
⌗ Tags: #application_security #web_security #devsecops #software_engineering
════════════════════════
𐀪 Author: Codeunderfire
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 14:13:33 GMT
════════════════════════
⌗ Tags: #application_security #web_security #devsecops #software_engineering
Medium
What is secure coding, and which five practices stop most CWE Top 25 bugs?
Secure coding means picking the construct that makes a weakness impossible to write, then letting scanners confirm the habit held. The 2024…
⤷ Title: Boutique, Platform or Big Consultancy? Choose the Kind of Pentest Firm Before the Brand
════════════════════════
𐀪 Author: Invadel
════════════════════════
ⴵ Time: Thu, 01 Oct 2026 11:18:35 GMT
════════════════════════
⌗ Tags: #compliance #penetration_testing #security #infosec #devsecops
════════════════════════
𐀪 Author: Invadel
════════════════════════
ⴵ Time: Thu, 01 Oct 2026 11:18:35 GMT
════════════════════════
⌗ Tags: #compliance #penetration_testing #security #infosec #devsecops
Medium
Boutique, Platform or Big Consultancy? Choose the Kind of Pentest Firm Before the Brand
For anyone shortlisting penetration testing vendors in 2026: the three shapes of firm, the names worth knowing and how to choose
⤷ Title: Your Perimeter Will Fail. The Real Question Is How Far an Attacker Gets After.
════════════════════════
𐀪 Author: Sonali Sood
════════════════════════
ⴵ Time: Thu, 01 Oct 2026 14:23:25 GMT
════════════════════════
⌗ Tags: #cybersecurity #devsecops #security #pentesting #penetration_testing
════════════════════════
𐀪 Author: Sonali Sood
════════════════════════
ⴵ Time: Thu, 01 Oct 2026 14:23:25 GMT
════════════════════════
⌗ Tags: #cybersecurity #devsecops #security #pentesting #penetration_testing
Medium
Your Perimeter Will Fail. The Real Question Is How Far an Attacker Gets After.
TL;DR: External tests and scanners check your perimeter. Neither answers the question that decides how bad a breach gets: once someone is…
⤷ Title: Think, Act, Secure: How AI Agents Are Changing DevSecOps
════════════════════════
𐀪 Author: Krunal Kawa
════════════════════════
ⴵ Time: Fri, 02 Oct 2026 17:52:33 GMT
════════════════════════
⌗ Tags: #llm #cybersecurity #devsecops #ai #application_security
════════════════════════
𐀪 Author: Krunal Kawa
════════════════════════
ⴵ Time: Fri, 02 Oct 2026 17:52:33 GMT
════════════════════════
⌗ Tags: #llm #cybersecurity #devsecops #ai #application_security
Medium
Think, Act, Secure: How AI Agents Are Changing DevSecOps
Everything you need to understand modern AI and use it to secure your pipeline.
⤷ Title: Half of You Are Googling the Wrong CASP. Here’s the One That Matters (CASP)
════════════════════════
𐀪 Author: Laura Hodgins
════════════════════════
ⴵ Time: Sun, 04 Oct 2026 09:01:02 GMT
════════════════════════
⌗ Tags: #api_security #devsecops #cybersecurity #application_security #software_development
════════════════════════
𐀪 Author: Laura Hodgins
════════════════════════
ⴵ Time: Sun, 04 Oct 2026 09:01:02 GMT
════════════════════════
⌗ Tags: #api_security #devsecops #cybersecurity #application_security #software_development
Medium
Half of You Are Googling the Wrong CASP. Here’s the One That Matters (CASP)
One changed ID can leak a million records. Here’s how API attacks really work, and how to stop them.