I’m excited to share that my team and I just published a blog post detailing how we’ve evolved Atlassian's deployment controls over the past few years.
Check it out here: https://t.co/b3KlZt80Z5
I’d love to hear your thoughts. #Atlassian#SoftwareSecurity#DevOps
Atlassian for Startups is here to take you from MVP to IPO. 🚀
Eligible startups can now get up to 50 seats for free for 12 months! ✨
Apply today: https://t.co/jcKKb35yTZ
#AtlassianforStartups
THE WAIT IS OVER⚡️ Introducing...
🐙 Wolfi, the 1st #Linux (un)distro designed w default security measures https://t.co/ofxJRyQe0p
🎓 Chainguard Academy, the 1st interactive edu platform dedicated to software security https://t.co/AXVbscS4PG
🪄 Enforce GA https://t.co/ywSBYBbwZf
The PyPA has voted to accept two new member projects: https://t.co/iX9r0T3oeI & the corresponding GitHub action, https://t.co/RVlB80Qkpx 🎉
pip-audit audits Python environments and dependency trees for known vulnerabilities, and the action lets you easily run these audits in CI.
CVE deep dive!
Today I'll look at how scanners work rather than a CVE.
I'll focus on how they find packages, because that's the first step in looking for CVEs.
I'll show a blind spot scanners have with many popular docker images, and how you might be missing a LOT of vulns.
Today we received reports of a phishing campaign targeting PyPI users. This is the first known phishing attack against PyPI.
We’re publishing the details here to raise awareness of what is likely an ongoing threat.
Given the gravity of the times, I have decided to open source my latest security scanner that complies with some of the latest requiriements.
It's really easy to use, and you can pipe binaries, images - anything really- through it.
You can thank me later 👍🏽
I’ve begun using ‘aws sync’ to put truly vast quantities of data into other people’s misconfigured @awscloud S3 buckets, on the theory that while you might ignore a politely worded email from a security researcher, you won’t ignore a $4 million bill surprise.
Huge news in the @Atlassian IT teams world today. Two kick ass new products in the family! We launched @JiraOps - our new platform for Incident management - and acquired @OpsGenie - the leading incident alerting tool. 1/2 https://t.co/YgaYnFPady
Brought home a Dell server.
Wife: can I see the server?
Me: here’s the server.
Wife: why do you need that?
Me: For testing.
Wife: no.... I mean I thought you went #serverless?
Me: 😶
Wife: I mean... you have the t-shirts and stuff...
Me: 😶
I had no words.
Exciting announcements from #AtlassianSummit https://t.co/LVeFZY7gie : Launch of #JiraOps + an agreement to acquire @OpsGenie! See how we help IT ops teams resolve incidents faster & incur fewer incidents over time.
The secret to getting off of calls you don't want to be on is to hang up in the middle of your own sentence. Only a maniac would hang up on themselves, so you must have gotten disconnected.