distroless.bsky.social
@distroless.bsky.social
Distroless. > Reducing attack surfaces in a world of supply chain noise.
DevSecOps | Cloud Native Security | AI Risk.
Shifting left until there’s nothing left to exploit.
Are LLM's the death of CTF's?

Rumours of the winners of defcon spending $50k on tokens makes me wonder if the fun has been taken out of CTFs?
digg.com/ai/8jpyrvgm

#llm #cyber #security #hacking #defcon #bsides #CTF #blackhat #claude #mythos
LLMs Dominate DEF CON CTF Finals as Token-Maxxing Overtakes Human Skill · Digg
LLMs Dominate DEF CON CTF Finals as Token-Maxxing Overtakes Human Skill - tracked by 1 author on X.
digg.com
October 1, 2026 at 4:14 PM
Trump rescinds software guidance or following NIST guidelines and production of SBOMs... This seems so counterintuitive it's crazy!

#trump #appsec #devips #devsecops #sbom #nist #owasp #hacking #cve
www.darkreading.com/application-...
Trump Administration Rescinds Biden-Era Software Guidance
Federal agencies will no longer be required to get software attestations of compliance with Secure Software Development Framework (SSDF).
www.darkreading.com
February 2, 2026 at 12:10 PM
Nginx Ingress is retiring in March. I'm moving my projects to Traefik. Make sure you take action before end of life.

dev.to/naveens16/th...

#devops #kubernetes #nginx #cluster #devsecops #hacking #k8s
The Sunsetting of Ingress NGINX: Why Kubernetes Is Moving On — And Where We Go Next
Kubernetes is officially retiring Ingress NGINX. This article breaks down why the community is making...
dev.to
January 30, 2026 at 8:52 AM
Reposted
Ubisoft Shuts Down Rainbow Six Siege After MongoDB Exploit Hits Players

Over 87,000 MongoDB instances are at risk from a critical memory leak called MongoBleed. Following the chaos at Ubisoft, see how this zero-password flaw works and how to protect your data.
#hackernews #news
Ubisoft Shuts Down Rainbow Six Siege After MongoDB Exploit Hits Players
Over 87,000 MongoDB instances are at risk from a critical memory leak called MongoBleed. Following the chaos at Ubisoft, see how this zero-password flaw works and how to protect your data.
hackread.com
December 30, 2025 at 7:01 PM
This is why you don't store your API keys in your repo

www.reddit.com/r/googleclou...
#api #iam #security #rbac #cloud #cloudbill #gcp #gitleaks #gitguardian
From the googlecloud community on Reddit
Explore this post and more from the googlecloud community
www.reddit.com
December 24, 2025 at 6:44 PM
Are MCP servers the next big gap in cyber security?

You cannot simply "scan" MCP servers for all their attack vectors with traditional app sec tools (sast, dast and sca)

I think there will be a lot more to come in this space in the coming years #ai #aisec #cybersec #sast #dast #hacking #mcp
December 20, 2025 at 3:30 PM