Releasing a Curated list of free/open-source application security tools
https://t.co/5OWq4XiGIQ
I found a lot of these tools via tldrsec newsletter, shoutout to @clintgibler for putting out amazing content every week. Feel free to recommend any tools that I am missing here
Ochrona is now a fully open source project. You can get started scanning in seconds without any signup, configuration, or limits.
https://t.co/seMOZm4UuM #OpenSource#CyberSecurity#Python
Earlier this week, yet another set of actively malicious packages were disclosed after being discovered by the @jfrog security team. These packages were downloaded a total of 30k times before being removed from Pypi.
https://t.co/LhXQxGVTrh
🚨 A debugging feature in Datasette versions <0.56.1 does not correctly escape generated HTML, leading to a reflected XSS vulnerability. Be sure to patch to version 0.56.1 or 0.57 if you’re using Datasette in your projects! #python#opensource#vulnerability
The new Ochrona VS Code Extension is live and supports auto-scanning when your dependencies change as well as support for Conda and Tox! https://t.co/zWgGeUCQrM
#python#vscode#CyberSecurity
We're looking forward to seeing you all tomorrow! Join us at 4pm ET tomorrow to learn about the “Dangers of the #Python Standard Library.” RSVP at: https://t.co/F1qQFpEYch
Unsure what dependency confusion means and how it affects you? Check out this post for a primer and tips on protecting your python apps.
https://t.co/u6TOBgtxR7 #python#cybersecurity#devsecops
Be sure to catch one of our co-founders, @drownedcoast, this Thursday at @ChicagoPython talking about #python security in the std lib https://t.co/Ax210g87LM
Just because it’s “batteries included” doesn’t mean it’s always safe. Check out these security pitfalls in the Python standard library. #python#security#devsecops https://t.co/mKxbDvo8aM
Is you use the pygments library for Python make sure you upgrade to 2.7.4 to avoid several newly disclosed ReDoS vulnerabilities. Great find by @Doyensec on CVE-2021-27291
#python#regex#vulnerability
I just updated one of my open source projects, Steg, an LSB steganography library, to use @OchronaSec for dependency security. Now I’ll be alerted if any new vulnerabilities are detected in Pillow. 🛡
https://t.co/PXM6CMRHVW
#infosec#security#python
Pillow <8.1.1 has several new CVEs associated with denial of service attacks. If you’re using pillow to process untrusted files you should update to 8.1.1 or above.
https://t.co/IjNxXik09F
1) A cyber attack can start with a single typo. Attackers can register look-alike packages to PyPI (Python’s package index), giving developers the opportunity to accidentally install them in their projects (“install reqests” instead of “install requests”). https://t.co/qs0j6Tot8e
Open Source software is something that everyone benefits from. We should all be invested in keeping the ecosystem clean and developers should always protect themselves by using SCA tools (like @OchronaSec).
https://t.co/C83mw8HYpM