Author Archive

DevSec Selection #13 – Malicious Packages Distributed, Security Automation and Prompt Airlines

DevSec Selection Logo

Intro Hi everyone! This edition covers some crucial cybersecurity topics. Check Point Research has revealed a sophisticated malware distribution network, Stargazers Ghost Network, using GitHub for phishing repositories. Additionally, a malicious Python package targeting macOS developers to steal Google Cloud Platform credentials was uncovered, emphasizing the need for vigilance in…

DevSec Selection #11 – RegreSSHion, API Rate Limiting, OWASP Quiz

DevSec Selection Logo

Intro Hi!The last few days have been full of news and articles about the RegreSSHion vulnerability, which affects hundreds of thousands of OpenSSH services. In this newsletter, you can find an article summarizing the vulnerability along with recommended remedial actions. If you’re working in Application Security field, I recommend taking the OWASP Top 10 Quiz to…

DevSec Selection #8 – SAST with AI, Git RCE, Semgrep for K8s

DevSec Selection Logo

Intro Hi!I will start this edition with the following quote: “In a 2023 GitHub survey, developers reported that their top task, second only to writing code (32%), was finding and fixing security vulnerabilities (31%).”     ~Nicole Choi (GitHub) In the newsletter you will find how Canva implemented Endpoint Vulnerability Management at scale, ideas for enhancing SAST…