The future of Sec Eng is not slowing teams down, it’s building the paved paths that let them move faster safely. As DoorDash leans into AI, we’re focused on operating in-line with Eng at the design, PR, CI/CD, and runtime layers. Take a listen https://t.co/62vTTShGST
https://t.co/aOYk0GsY8i
1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories.
Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.
4/ We continue to analyze logs, validate secret rotation, and monitor for any follow-on activity. We will take additional action as the investigation warrants.
We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.
According to the Social Security database, these are the numbers of people in each age bucket with the death field set to FALSE!
Maybe Twilight is real and there are a lot of vampires collecting Social Security 🤣🤣
People early in their careers often seek advice from me. The questions vary, but there’s a common theme: "How can I stand out in a world that’s becoming increasingly more competitive?"
My take -- the only lasting edge isn’t your skill set, network, or even your resume—it’s your psychological strength. Grit, mastering ego, unconventional thinking, delaying gratification, and focusing on the long term are your secret weapons.
🧵👇
Just wrapped the @felicis + @NextLegacy_ event at Black Hat last week! So fun to train with and learn from UFC Hall of Famer and legend @ForrestGriffin, super bowl champ @ryannece, and a handful of security founders (@tines_hq, @semgrep, @ConductorOneInc, @Resourcely, etc) / CISOs / channel partners.
After training, we had the opportunity to hear from Ryan and Forrest on mental fortitude.
A few thoughts / quotes:
- "Find something that is scary or hard for others that comes easy or is fun for you" - Forrest never got nervous before fights and credits that as a key advantage
- "If you've never put everything you have on a single bet, I feel bad for you because you aren't living…. Ante up and play the game"
- "Losses are great because they can serve as the greatest motivators" - Forrest says his greatest growth in mental fortitude came only after he put everything he had into a fight and still lost
- Forrest would remember 2 things to get in the right mindset before entering the cage:
1) "I've done the work and am not going to float the check" - training should be harder than the actual fight
2) "I'm not going to quit on myself"
cc @NancyZWang, @alexbovee, @travismcpeak, @drewdennison, @dlukeomalley, @sachafaust, @TomAlcockCRP, @ipsec, @thenava, @WayneDuso, @georgegerchow, etc.
@adityaag Fully agree here. Even with slack and email, the interpersonal nature of a live human connection is invaluable. That coupled with a quarter live 2-3 meeting/ dinner is ideal.
28 sentences that will teach you more about your health than my 4-year pharmacy degree:
1. Daily drinking kills brain matter. Stop drinking or limit to 3 times a week.