⤷ Title: An API Key and an OAuth Token Differ by One Field, and That Field Decides Who Kills the Credential
════════════════════════
𐀪 Author: Ghost Accounts
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 02:55:44 GMT
════════════════════════
⌗ Tags: #oauth #cloud_security #identity_management #devsecops #api_security
════════════════════════
𐀪 Author: Ghost Accounts
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 02:55:44 GMT
════════════════════════
⌗ Tags: #oauth #cloud_security #identity_management #devsecops #api_security
Medium
An API Key and an OAuth Token Differ by One Field, and That Field Decides Who Kills the Credential
An API key identifies the project or application behind a request. An OAuth access token identifies a principal and carries a scope and an…
⤷ Title: Octopus Server Flaw CVE-2026-101169 Allows Code Execution via Insecure Deserialization
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 09:44:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_101169 #DevSecOps #Insecure Deserialization #Octopus Deploy #Octopus Server #Octopus Server vulnerability #Remote Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 09:44:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_101169 #DevSecOps #Insecure Deserialization #Octopus Deploy #Octopus Server #Octopus Server vulnerability #Remote Code Execution
Daily CyberSecurity
Octopus Server Flaw CVE-2026-101169 Allows Code Execution via Insecure Deserialization
TL;DR Octopus Deploy has fixed a high-severity Octopus Server vulnerability, CVE-2026-101169. An authenticated user who can edit an Environment or Project can run arbitrary code in the server proc…
⤷ Title: Is the Vibe-coded application hacked ? Check with Strix.
════════════════════════
𐀪 Author: ambuj singh
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 18:10:16 GMT
════════════════════════
⌗ Tags: #devsecops #cybersecurity #penetration_testing #artificial_intelligence #open_source
════════════════════════
𐀪 Author: ambuj singh
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 18:10:16 GMT
════════════════════════
⌗ Tags: #devsecops #cybersecurity #penetration_testing #artificial_intelligence #open_source
Medium
Is the Vibe-coded application hacked ? Check with Strix.
Is the Vibe-coded application hacked? Check with Strix. An open-source team of autonomous AI pentesters that runs your code, attacks it, and proves what it finds. Introduction Most security tools …
⤷ Title: AI Coding Agents Leak 13,000 Internal Screenshots to Public GitHub Repos
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 08:21:06 +0000
════════════════════════
⌗ Tags: #Data Leak #AI Agents #Data Exposure #DevSecOps #github #Glow Labs #PixelLeak #shadow AI
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 08:21:06 +0000
════════════════════════
⌗ Tags: #Data Leak #AI Agents #Data Exposure #DevSecOps #github #Glow Labs #PixelLeak #shadow AI
Daily CyberSecurity
AI Coding Agents Leak 13,000 Internal Screenshots to Public GitHub Repos
More than 13,000 internal screenshots sat in public GitHub repositories, open to anyone. Glow Labs says AI coding agents put them there. The firm calls this AI agent screenshot leak “PixelLe…
⤷ Title: What is secure coding, and which five practices stop most CWE Top 25 bugs?
════════════════════════
𐀪 Author: Codeunderfire
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 14:13:33 GMT
════════════════════════
⌗ Tags: #application_security #web_security #devsecops #software_engineering
════════════════════════
𐀪 Author: Codeunderfire
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 14:13:33 GMT
════════════════════════
⌗ Tags: #application_security #web_security #devsecops #software_engineering
Medium
What is secure coding, and which five practices stop most CWE Top 25 bugs?
Secure coding means picking the construct that makes a weakness impossible to write, then letting scanners confirm the habit held. The 2024…
⤷ Title: Boutique, Platform or Big Consultancy? Choose the Kind of Pentest Firm Before the Brand
════════════════════════
𐀪 Author: Invadel
════════════════════════
ⴵ Time: Thu, 01 Oct 2026 11:18:35 GMT
════════════════════════
⌗ Tags: #compliance #penetration_testing #security #infosec #devsecops
════════════════════════
𐀪 Author: Invadel
════════════════════════
ⴵ Time: Thu, 01 Oct 2026 11:18:35 GMT
════════════════════════
⌗ Tags: #compliance #penetration_testing #security #infosec #devsecops
Medium
Boutique, Platform or Big Consultancy? Choose the Kind of Pentest Firm Before the Brand
For anyone shortlisting penetration testing vendors in 2026: the three shapes of firm, the names worth knowing and how to choose
⤷ Title: Your Perimeter Will Fail. The Real Question Is How Far an Attacker Gets After.
════════════════════════
𐀪 Author: Sonali Sood
════════════════════════
ⴵ Time: Thu, 01 Oct 2026 14:23:25 GMT
════════════════════════
⌗ Tags: #cybersecurity #devsecops #security #pentesting #penetration_testing
════════════════════════
𐀪 Author: Sonali Sood
════════════════════════
ⴵ Time: Thu, 01 Oct 2026 14:23:25 GMT
════════════════════════
⌗ Tags: #cybersecurity #devsecops #security #pentesting #penetration_testing
Medium
Your Perimeter Will Fail. The Real Question Is How Far an Attacker Gets After.
TL;DR: External tests and scanners check your perimeter. Neither answers the question that decides how bad a breach gets: once someone is…
⤷ Title: Think, Act, Secure: How AI Agents Are Changing DevSecOps
════════════════════════
𐀪 Author: Krunal Kawa
════════════════════════
ⴵ Time: Fri, 02 Oct 2026 17:52:33 GMT
════════════════════════
⌗ Tags: #llm #cybersecurity #devsecops #ai #application_security
════════════════════════
𐀪 Author: Krunal Kawa
════════════════════════
ⴵ Time: Fri, 02 Oct 2026 17:52:33 GMT
════════════════════════
⌗ Tags: #llm #cybersecurity #devsecops #ai #application_security
Medium
Think, Act, Secure: How AI Agents Are Changing DevSecOps
Everything you need to understand modern AI and use it to secure your pipeline.
⤷ Title: Half of You Are Googling the Wrong CASP. Here’s the One That Matters (CASP)
════════════════════════
𐀪 Author: Laura Hodgins
════════════════════════
ⴵ Time: Sun, 04 Oct 2026 09:01:02 GMT
════════════════════════
⌗ Tags: #api_security #devsecops #cybersecurity #application_security #software_development
════════════════════════
𐀪 Author: Laura Hodgins
════════════════════════
ⴵ Time: Sun, 04 Oct 2026 09:01:02 GMT
════════════════════════
⌗ Tags: #api_security #devsecops #cybersecurity #application_security #software_development
Medium
Half of You Are Googling the Wrong CASP. Here’s the One That Matters (CASP)
One changed ID can leak a million records. Here’s how API attacks really work, and how to stop them.
⤷ Title: I Tried to Forge SLSA Provenance. The Verifier Never Even Looked at My Forgery.
════════════════════════
𐀪 Author: cbrkrtek
════════════════════════
ⴵ Time: Sun, 04 Oct 2026 10:15:53 GMT
════════════════════════
⌗ Tags: #devsecops #application_security #supply_chain_security #cybersecurity
════════════════════════
𐀪 Author: cbrkrtek
════════════════════════
ⴵ Time: Sun, 04 Oct 2026 10:15:53 GMT
════════════════════════
⌗ Tags: #devsecops #application_security #supply_chain_security #cybersecurity
Medium
I Tried to Forge SLSA Provenance. The Verifier Never Even Looked at My Forgery.
I’ve got Cosign signing images in a couple of my pipelines. Out of curiosity, I decided to attack my own setup, and realized that signing…
⤷ Title: RootSecOps: Know What Third-Party Software Enters Your Organization
════════════════════════
𐀪 Author: Arash Shahbazi
════════════════════════
ⴵ Time: Sun, 04 Oct 2026 18:03:34 GMT
════════════════════════
⌗ Tags: #cybersecurity #application_security #docker #open_source #devsecops
════════════════════════
𐀪 Author: Arash Shahbazi
════════════════════════
ⴵ Time: Sun, 04 Oct 2026 18:03:34 GMT
════════════════════════
⌗ Tags: #cybersecurity #application_security #docker #open_source #devsecops
Medium
RootSecOps: Know What Third-Party Software Enters Your Organization
A self-hosted security workbench for reviewing Docker images, repositories, Dockerfiles, and files before deployment.
⤷ Title: Stop Patching, Start Designing: Compliance Is the Baseline, Not the Ceiling
════════════════════════
𐀪 Author: Gertrude Abagale
════════════════════════
ⴵ Time: Mon, 05 Oct 2026 00:01:02 GMT
════════════════════════
⌗ Tags: #application_security #devsecops #cybersecurity #compliance #owasp_top_10
════════════════════════
𐀪 Author: Gertrude Abagale
════════════════════════
ⴵ Time: Mon, 05 Oct 2026 00:01:02 GMT
════════════════════════
⌗ Tags: #application_security #devsecops #cybersecurity #compliance #owasp_top_10
Medium
Stop Patching, Start Designing: Compliance Is the Baseline, Not the Ceiling
Part 2 of 2: What the OWASP Top 10 means for compliance and what you can do on Monday
⤷ Title: What a Scanner Will Never Catch in Your App, and Why a Human Tester Still Does
════════════════════════
𐀪 Author: Invadel
════════════════════════
ⴵ Time: Mon, 05 Oct 2026 19:33:53 GMT
════════════════════════
⌗ Tags: #penetration_testing #regulatory_compliance #devsecops #infosec #web_security
════════════════════════
𐀪 Author: Invadel
════════════════════════
ⴵ Time: Mon, 05 Oct 2026 19:33:53 GMT
════════════════════════
⌗ Tags: #penetration_testing #regulatory_compliance #devsecops #infosec #web_security
Medium
What a Scanner Will Never Catch in Your App, and Why a Human Tester Still Does
For teams weighing automated against manual pentesting: what each one finds, what each misses, and how to combine them sensibly
⤷ Title: Vulnerability analysis that a developer can act on
════════════════════════
𐀪 Author: Sriman Soundarapandiyan
════════════════════════
ⴵ Time: Tue, 06 Oct 2026 09:56:18 GMT
════════════════════════
⌗ Tags: #information_security #application_security #cybersecurity #vulnerability_management #devsecops
════════════════════════
𐀪 Author: Sriman Soundarapandiyan
════════════════════════
ⴵ Time: Tue, 06 Oct 2026 09:56:18 GMT
════════════════════════
⌗ Tags: #information_security #application_security #cybersecurity #vulnerability_management #devsecops
Medium
Vulnerability analysis that a developer can act on
A vulnerability scanner is good at listing. It is less good at deciding which list item should move a sprint. The gap between those two…
⤷ Title: Long Running npm Malware Campaign Exposes the Growing Risk of Software Supply Chain Attacks
════════════════════════
𐀪 Author: Jas
════════════════════════
ⴵ Time: Tue, 06 Oct 2026 10:59:30 GMT
════════════════════════
⌗ Tags: #devsecops #cybersecurity #application_security #cloud_security #supply_chain_security
════════════════════════
𐀪 Author: Jas
════════════════════════
ⴵ Time: Tue, 06 Oct 2026 10:59:30 GMT
════════════════════════
⌗ Tags: #devsecops #cybersecurity #application_security #cloud_security #supply_chain_security
Medium
Long Running npm Malware Campaign Exposes the Growing Risk of Software Supply Chain Attacks
Open source software has become an essential part of modern application development.
⤷ Title: Progress Fixes Critical Command Injection Flaw CVE-2026-91140 in DataDirect AI Model Generator Agents
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 06 Oct 2026 14:12:10 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Agents #Command Injection #CVE_2026_91140 #DataDirect #DevSecOps #OpenAPI #Progress
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 06 Oct 2026 14:12:10 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Agents #Command Injection #CVE_2026_91140 #DataDirect #DevSecOps #OpenAPI #Progress
Daily CyberSecurity
Progress Fixes Critical Command Injection Flaw CVE-2026-91140 in DataDirect AI Model Generator Agents
TL;DR Progress has fixed CVE-2026-91140, a critical Progress DataDirect vulnerability in its Autonomous REST Connector AI Model Generator agents. A crafted OpenAPI or Swagger file could run comman…
⤷ Title: Can AI Autofix Actually Close a Cloud Attack Path?
════════════════════════
𐀪 Author: Cloud Under Fire
════════════════════════
ⴵ Time: Wed, 07 Oct 2026 12:44:46 GMT
════════════════════════
⌗ Tags: #ai_autofix #vulnerability_management #cloud_security #application_security #devsecops
════════════════════════
𐀪 Author: Cloud Under Fire
════════════════════════
ⴵ Time: Wed, 07 Oct 2026 12:44:46 GMT
════════════════════════
⌗ Tags: #ai_autofix #vulnerability_management #cloud_security #application_security #devsecops
Medium
Can AI Autofix Actually Close a Cloud Attack Path?
Why a patch that passes review can still leave the one hop an attacker needs wide open.
⤷ Title: Argo CD Patches Four Critical CVSS 9.9 Flaws Affecting the Repo-Server and AppProject Controls
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 07 Oct 2026 16:56:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Argo CD #CVE_2026_77459 #DevSecOps #GitOps #Jsonnet #Kubernetes #Kustomize #Remote Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 07 Oct 2026 16:56:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Argo CD #CVE_2026_77459 #DevSecOps #GitOps #Jsonnet #Kubernetes #Kustomize #Remote Code Execution
Daily CyberSecurity
Argo CD Patches Four Critical CVSS 9.9 Flaws Affecting the Repo-Server and AppProject Controls
TL;DR The Argo CD project has fixed four critical security flaws, each rated 9.9 on CVSS. Three of these Argo CD vulnerabilities let a user run commands or read files inside the argocd-repo-server…
⤷ Title: Gitea Fixes 27 Security Flaws Across 28.0.0 and 28.1.0, Including SSRF and Account Takeover Bugs
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 07 Oct 2026 14:35:06 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD security #CVE_2026_101027 #CVE_2026_103059 #CVE_2026_96404 #DevSecOps #git #Gitea #ssrf
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 07 Oct 2026 14:35:06 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD security #CVE_2026_101027 #CVE_2026_103059 #CVE_2026_96404 #DevSecOps #git #Gitea #ssrf
Daily CyberSecurity
Gitea Fixes 27 Security Flaws Across 28.0.0 and 28.1.0, Including SSRF and Account Takeover Bugs
TL;DR Gitea has shipped 27 security fixes across versions 28.0.0 and 28.1.0. This Gitea security update closes server-side request forgery (SSRF) paths, an installer bug that grants admin sessions…
⤷ Title: What Does “Secure” Actually Mean for Your Business?
════════════════════════
𐀪 Author: Parveen Kr. Arora
════════════════════════
ⴵ Time: Thu, 08 Oct 2026 05:20:32 GMT
════════════════════════
⌗ Tags: #cybersecurity #privacy #application_security #digital_transformation #devsecops
════════════════════════
𐀪 Author: Parveen Kr. Arora
════════════════════════
ⴵ Time: Thu, 08 Oct 2026 05:20:32 GMT
════════════════════════
⌗ Tags: #cybersecurity #privacy #application_security #digital_transformation #devsecops
Medium
What Does “Secure” Actually Mean for Your Business?
Why security assessments should be scoped around business risk — not generic checklists.