#devsecurity
Okay, GitHub Copilot is getting local sandboxing for its app. That's a solid move for security, keeping code suggestions more isolated from my machine. Always good to see more protections for our digital workspaces. 🛡️ #Copilot #DevSecurity
September 23, 2026 at 6:05 PM
As there is a DevOps movement, there needs to be a DevSecurity movement too. Align and embed developers and corporate security.
March 12, 2025 at 6:58 AM
March 30, 2026 at 3:23 PM
🚨🤖 Beware! The rising threat of malicious npm libraries is real. Check out our cautionary tale to protect your projects. Don't fall victim! 🔒🔍 Read more: https://innovirtuoso.com/technology/the-rising-threat-of-malicious-npm-libraries-a-cautionary-tale/ #Cybersecurity #npm #DevSecurity
Rising Threat of Malicious npm Libraries: A Cautionary Tale
The npm ecosystem is crucial for modern web development, but it faces risks from malicious libraries that impersonate trusted tools.
innovirtuoso.com
January 20, 2025 at 11:55 AM
Java developers: are you blindly trusting AI suggestions for dependencies? @spoole167.bsky.social explains why this habit can lead to security risks and technical debt in your projects.

foojay.io/today/why-ja...

#Java #AI #DevSecurity
Why Java Developers Over-Trust AI-Generated Code
AI coding tools sound confident even when they're wrong. Here's the psychology behind why Java developers accept bad suggestions — and habits that help.
foojay.io
April 10, 2026 at 8:38 AM
Developers are being targeted through fake crypto job interviews.

ReversingLabs found 192 malicious npm/PyPI packages delivering a RAT - attributed to Lazarus Group.
Clean GitHub repo.
Poisoned dependency.
Crypto wallet targeting.

#CyberSecurity #SupplyChainAttack #DevSecurity #Lazarus #Malware
February 14, 2026 at 10:12 AM
🚨 A MAJOR issue I see with vibe coders is that their Supabase app gets owned by a "SECURITY DEFINER" function.

That innocent looking function the AI added?

It's running with postgres superuser privileges 💀👇
#Supabase #PostgreSQL #WebSecurity #RLS #DatabaseSecurity #DevSecurity #VibeCoding
July 1, 2025 at 6:02 PM
⚠️ GitHub.dev-Hack: Ein manipuliertes Skript klaut dein OAuth‑Token und öffnet allen Repos die Hintertür. GitHub patched fast, jetzt Token zurücksetzen und Einstellungen prüfen! #DevSecurity – Mehr lesen.

🔗 https://news.google.com/rss/articles/CBMipAFBVV95cUxON24zcklwVUJScElid0treDZKVk1POWFnVnJz...
Angriff auf GitHub.dev stiehlt das OAuth-Token für alle Repos - heise online
news.google.com
June 7, 2026 at 4:51 AM
Tired of GitHub access tokens? Master #GitHub="/hashtag/GitHubSSHKeySetup" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#GitHubSSHKeySetup in minutes! This guide makes secure, token-free Git ops easy. #GitHub #DevSecurity #DevOps
GitHub SSH Key Setup
Welcome back, developers! If you've ever found yourself frustrated by the constant need to generate, copy, and paste access tokens for your GitHub operations, or if you're looking for a more robust and secure way to manage your repository access, you're in the right place. Today, we're going to dive deep into the essential process of GitHub SSH Key Setup…
teguhteja.id
October 9, 2025 at 1:21 PM
The @bitwarden/cli npm package v2026.4.0 was compromised on April 22, 2026, with a loader fetching Bun to run obfuscated code that stole npm tokens, GitHub keys, SSH keys, and cloud credentials. #DevSecurity #NpmBreach #USA
Bitwarden CLI npm package compromised to steal developer credentials
Bitwarden's CLI npm package was briefly compromised on April 22, 2026 when attackers published a malicious @bitwarden/cli v2026.4.0 containing a credential-stealing payload that could spread to other projects. The loader fetched the Bun runtime to execute an obfuscated bw1.js that harvested npm tokens, GitHub auth tokens, SSH keys, and cloud credentials and exfiltrated encrypted data via public GitHub repositories. #Bitwarden #TeamPCP
www.hendryadrian.com
April 23, 2026 at 9:45 PM
Hot take: unsigned Git commits are a security gap most devs ignore. 🔥

A YubiKey lets you cryptographically sign every commit — hardware proof that the code came from YOU.

✅ Prevent impersonation
✅ Protect supply chains

See how → https://lckhd.eu/V5czP5

#GitTips #DevSecurity #CyberSecurity
August 4, 2026 at 9:15 AM
Fake VS Code alerts with bogus CVE IDs are spreading malware via GitHub Discussions by impersonating maintainers and tagging users. Malware payloads are delivered after profiling victims through JavaScript scripts. #DevSecurity #GitHubAttacks #USA
Fake VS Code alerts on GitHub spread malware to developers
A large-scale campaign is targeting developers on GitHub by posting fake Visual Studio Code security alerts in repository Discussions to trick users into downloading malware. The posts impersonate maintainers, include fake CVE IDs and external Google Drive links that redirect to drnatashachinn[.]com, which runs a JavaScript reconnaissance script to profile victims before delivering a second-stage payload. #VisualStudioCode #GitHub
www.hendryadrian.com
March 27, 2026 at 8:40 PM
March 2, 2026 at 5:00 PM
February 6, 2026 at 5:00 PM
🔐 MCP server vulnerability alert: 200k servers at risk. Go serverless for safer deployment! #DevSecurity
200,000 MCP Servers Are Exposed. Here's Why Serverless Is Safer.
I've spent a lot of time thinking about where MCP servers should live. I work with remote MCP servers...
ift.tt
May 28, 2026 at 12:32 PM
Cursor & Windsurf—exciting new tools, but security first. As devs, we rush to adopt shiny things, but how much do we vet them? Open-source scrutiny? Backdoor risks? Love innovation, but let’s not trade speed for safety. Who’s audited these yet? #DevSecurity #TechTalk
news.google.com
April 11, 2025 at 9:12 AM
The "workspace trust" feature in VS Code is often deemed ineffective. Its warning is too ambiguous & easily dismissed, causing developers to inadvertently grant permission to execute malicious code. Clearer, actionable prompts are needed. #DevSecurity 2/6
January 23, 2026 at 8:00 PM
GitHub had a hole that could let attackers run ANY code on their servers 🔥 Wiz Research found it using AI. GitHub patched it in under 6 hours.

Every repo. Every pipeline. Every secret.

Nearly exposed. 😳

#GitHub #CyberSecurity #AI #DevSecurity #InfoSec
April 29, 2026 at 10:04 AM
AI agents make hundreds of API calls a day. Every one holds a credential it shouldn't.

Cordon fixes that for Hermes and OpenClaw. One command, zero code changes.

Hermes: docs.codezero.io/cli/setup#co...

 OpenClaw: docs.codezero.io/cli/setup#co...
#AIAgents #DevSecurity #Cordon
cordon setup - Cordon
Interactive setup — generates certificates, creates config, and configures integrations.
docs.codezero.io
June 29, 2026 at 5:18 PM
Good to see npm tightening up security around authentication and token management. This is important stuff for any dev relying on the ecosystem. Time to double-check those best practices! #npm #devsecurity
September 30, 2025 at 4:45 PM
GitVenom: Fake-GitHub-Repos verbreiten Malware! Kaspersky warnt vor manipulierten Open-Source-Projekten, die Daten & Krypto stehlen. Entwickler aufgepasst! 🚨 #malware #github #cyberthreat #devsecurity
February 26, 2025 at 3:20 PM
Enhance Snyk Code for security novices? 🛡️
Discover PM strategies to boost user-friendliness without compromising power.
NextSprints tackles this challenge!

#ProductManagement #DevSecurity
July 3, 2025 at 9:09 PM
Wil je meedenken? Mail API@geonovum.nl en sluit aan bij de werkgroep! #ogc #apistandards #geospatial #devsecurity
May 14, 2025 at 9:26 AM
GitVenom: Fake-GitHub-Repos verbreiten Malware! Kaspersky warnt vor manipulierten Open-Source-Projekten, die Daten & Krypto stehlen. Entwickler aufgepasst! 🚨 #Malware #GitHub #CyberThreat #DevSecurity
February 26, 2025 at 3:19 PM