⚙ Running Renovate as a GitHub Action (and NO PAT!)
A post explaining how you can run Renovate as a GitHub Action without needing a GitHub Personal Access Token by using Octo STS.
https://www.chainguard.dev/unchained/running-renovate-as-a-github-action
#cicd
A post explaining how you can run Renovate as a GitHub Action without needing a GitHub Personal Access Token by using Octo STS.
https://www.chainguard.dev/unchained/running-renovate-as-a-github-action
#cicd
❤2👍1🔥1
An authorization bypass in Kubernetes RBAC allows for nodes/proxy GET permissions to execute commands in any Pod in the cluster.
https://grahamhelton.com/blog/nodes-proxy-rce
(Use VPN to open from Russia)
#kubernetes
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥3❤1👍1
Block's BinauthZ plugin extends their OPA-based admission controller to cryptographically verify container image signatures and attestations at Kubernetes admission time, enforcing SLSA using Sigstore/cosign with AWS KMS.
https://engineering.block.xyz/blog/kube-policies-binauthz-closing-the-supply-chain-gap-in-kubernetes
#kubernetes
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1👍1🔥1
⚙ We should all be using dependency cooldowns
Dependency cooldowns delay automatic dependency updates, providing a free and effective mitigation against most open source supply chain attacks. Tools like Dependabot and Renovate support configurable cooldown periods before adopting new dependency versions.
https://blog.yossarian.net/2025/11/21/We-should-all-be-using-dependency-cooldowns
(Use VPN to open from Russia)
#cicd
Dependency cooldowns delay automatic dependency updates, providing a free and effective mitigation against most open source supply chain attacks. Tools like Dependabot and Renovate support configurable cooldown periods before adopting new dependency versions.
https://blog.yossarian.net/2025/11/21/We-should-all-be-using-dependency-cooldowns
(Use VPN to open from Russia)
#cicd
❤2👍1🔥1
This post details a method for stealing Salesforce OAuth tokens by exploiting an XSS vulnerability and leveraging the Cloudflare Web Application Firewall (WAF).
https://castilho.sh/salesforce-oauth-ato
#saas
Please open Telegram to view this post
VIEW IN TELEGRAM
👍2❤1🔥1
Block's AI engineering approach includes: 95% of engineers using AI assistants, providing freedom to explore multiple tools, launching an AI Champions program focused on repo readiness and context engineering, implementing automated PRs, and planning team-based workshops for multi-agent workflows.
https://engineering.block.xyz/blog/ai-assisted-development-at-block
#AI
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1👍1🔥1
Mature enterprises lock down egress but often carve out broad exceptions for trusted cloud services. This post shows how reviewing deployment guides can help identify those exceptions and weaponize them with a new Mythic C2 profile called azureBlob.
https://specterops.io/blog/2026/01/30/weaponizing-whitelists-an-azure-blob-storage-mythic-c2-profile/
#azure
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1👍1🔥1
🔴 Google Looker RCE vulnerabilities: Patch now
Tenable Research discovered two novel vulnerabilities in Google Looker that could allow an attacker to completely compromise a Looker instance.
https://www.tenable.com/blog/google-looker-vulnerabilities-rce-internal-access-lookout
#gcp
Tenable Research discovered two novel vulnerabilities in Google Looker that could allow an attacker to completely compromise a Looker instance.
https://www.tenable.com/blog/google-looker-vulnerabilities-rce-internal-access-lookout
#gcp
❤2🔥2👍1
Find out more about how passkeys can be used across devices using a mechanism called Hybrid transport.
https://bughunters.google.com/blog/passkeys
#iam
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1👍1🔥1
This article introduces Slack's Anomaly Event Response (AER), an automated security system that detects suspicious activities and terminates user sessions in real-time, reducing detection-to-response gaps from hours to minutes.
https://slack.engineering/building-slacks-anomaly-event-response/
#monitor
Please open Telegram to view this post
VIEW IN TELEGRAM
❤2👍1🔥1
The fastest-growing personal AI agent ecosystem just became a new delivery channel for malware. Over the last few days, VirusTotal has detected hundreds of OpenClaw skills that are actively malicious.
https://blog.virustotal.com/2026/02/from-automation-to-infection-how.html
#AI
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
❤2👍1🔥1
A practical workflow for threat modeling agentic AI systems: use a five-zone navigation lens to trace attack paths, formalize them as attack trees, and map to OWASP's threat taxonomy and playbooks.
https://christian-schneider.net/blog/threat-modeling-agentic-ai/
#AI
Please open Telegram to view this post
VIEW IN TELEGRAM
👏3❤1👍1
This white paper examines the risks and attack vectors inherent in hybrid multi-cloud infrastructures, and analyzes various attack paths observed by Mandiant in real-world multi-cloud scenarios.
#iam
Please open Telegram to view this post
VIEW IN TELEGRAM
❤2👍1🔥1
That helpful “Summarize with AI” button? It might be secretly manipulating what your AI recommends. Microsoft security researchers have discovered a growing trend of AI memory poisoning attacks used for promotional purposes, a technique they called "AI Recommendation Poisoning".
https://www.microsoft.com/en-us/security/blog/2026/02/10/ai-recommendation-poisoning/
#AI
Please open Telegram to view this post
VIEW IN TELEGRAM
❤3🔥2👍1
🏗 Encrypting Files with Passkeys and age
A post explaining how to encrypt files with passkeys, using the WebAuthn prf extension and the TypeScript age implementation.
https://words.filippo.io/passkey-encryption
#build
A post explaining how to encrypt files with passkeys, using the WebAuthn prf extension and the TypeScript age implementation.
https://words.filippo.io/passkey-encryption
#build
❤2👍1🔥1
LLM security testing framework for detecting prompt injection, jailbreaks, and adversarial attacks. See also the companion blog post.
https://github.com/praetorian-inc/augustus
#AI
Please open Telegram to view this post
VIEW IN TELEGRAM
❤2👍1🔥1
Block Engineering discusses designing agent skills using three principles: make deterministic outputs script-based, let agents handle interpretation and conversation, and write explicit constitutional constraints. Skills codify tribal knowledge into executable documentation for AI agents across their organization.
https://engineering.block.xyz/blog/3-principles-for-designing-agent-skills
#AI
Please open Telegram to view this post
VIEW IN TELEGRAM
❤2👍1🔥1