@SpecterDev The output is actually not that great when you really want something more than simple code, I would not worry about my job. it hardly can author a simple codeql predicate lol
modern automation becomes a target for hackers.
while #robots are not necessarily the entry-point of the attacker - they are definitely a target for once the attacker is in your network.
https://t.co/vVV1mto5Yz
#ransomware#robotics#automation#Industry40
Google launches #OSV Open Source #Vulnerabilities - a vulnerability database and triage infrastructure for open source projects aimed at helping both open source maintainers and consumers of open source:
#opensource#cve
https://t.co/dWzUVN46he
@spottedmahn Hi Mike, since PANW acquisition of Twistlock, Twistlock labs are now publishing content under Unit42’s website and the twitter handle of the labs is gone
Excellent overview of security aspects of software supply chains by @Da5h_Solo. Some Qs to ask when ensuring secure supply chains:
- can anyone access anything w/o authenticating?
- what permissions do auth’d users have?
- any sensitive info in commit/build history? #qconsf
Really excited for the discussions and the cool talks by amazing speakers on the brand new track Software Supply Chain @qconsf https://t.co/36enunvwS8 Learn abt approaches and tools for tracking provenance, securing, & maintaining observability of the entire software supply chain
This November I'm speaking at QCon San Francisco. Join me and learn about the most widespread attacks & vulnerabilities and how to protect your software supply chain. Use the code SPEAK100Daniel for $100 off. Find out more about QCon San Francisco: https://t.co/JsnBGus6g7
The ecosystem is developing at a blazing fast pace, which in turn causes various little mistakes in the products that could leave the supply chain up for grabs for a motivated adversary. More in @Da5h_Solo@PaloAltoNtwks#QConSF talk.
https://t.co/GzdypCR8l9