DEV Community

#devsecops

Integrating security practices into the DevOps lifecycle.

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
GitLab CVE-2026-85706: When a Path Traversal Lands in the Software Delivery Chain

GitLab CVE-2026-85706: When a Path Traversal Lands in the Software Delivery Chain

Comments
4 min read
Your AWS role can't tell a human from an agent anymore, part 4: detection — what did the agent actually touch?

Your AWS role can't tell a human from an agent anymore, part 4: detection — what did the agent actually touch?

1
Comments
4 min read
Your AWS role can't tell a human from an agent anymore, part 3: the SCP backstop

Your AWS role can't tell a human from an agent anymore, part 3: the SCP backstop

1
Comments
5 min read
Your AWS role can't tell a human from an agent anymore, part 1: the threat model and the identity problem

Your AWS role can't tell a human from an agent anymore, part 1: the threat model and the identity problem

1
Comments
6 min read
What to fix first when everything is critical

What to fix first when everything is critical

Comments
6 min read
Your AWS role can't tell a human from an agent anymore, part 5: putting the four layers together

Your AWS role can't tell a human from an agent anymore, part 5: putting the four layers together

1
Comments
4 min read
What a Supply Chain Attack Is Really After: Your Credentials

What a Supply Chain Attack Is Really After: Your Credentials

Comments
5 min read
MITRE ATT&CK для Product Security: как связать pentest, threat modeling, CI/CD и реальные сценарии атак

MITRE ATT&CK для Product Security: как связать pentest, threat modeling, CI/CD и реальные сценарии атак

Comments
10 min read
OpenSSF Scorecard explained: catching risk in packages that don't have a CVE yet

OpenSSF Scorecard explained: catching risk in packages that don't have a CVE yet

Comments
3 min read
AI Autonomy: How to Find the Autonomy Your Agents Already Have

AI Autonomy: How to Find the Autonomy Your Agents Already Have

Comments
13 min read
Service Account Credential Rotation: The Blast-Radius Checklist

Service Account Credential Rotation: The Blast-Radius Checklist

Comments
9 min read
CVSS, EPSS and KEV: how to actually prioritize dependency vulnerabilities

CVSS, EPSS and KEV: how to actually prioritize dependency vulnerabilities

Comments
6 min read
A free, anonymous Snyk alternative for dependency scanning

A free, anonymous Snyk alternative for dependency scanning

Comments
2 min read
AI Created a Leaked Credentials Flood: Here's How We're Draining It

AI Created a Leaked Credentials Flood: Here's How We're Draining It

Comments
6 min read
AI Agents vs Traditional Automation: What's Actually Different for Security

AI Agents vs Traditional Automation: What's Actually Different for Security

Comments
16 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.