~/devreads

#security

282 posts

Today

22 Jul

21 Jul

J Simpson 5 min read

A recent report from Salt Security published a truly alarming statistic. According to the report, 95% of API attacks come from authenticated sources. This should raise alarms for anyone who knows anything about cybersecurity, as it means API attacks are seemingly real transactions. These attacks won’t even be noticed by average cybersecurity systems, as, for ...

blogsecurityaccess controlai agentsapi logging

16 Jul

14 Jul

Janet Wagner 8 min read

One of the most difficult aspects of building systems with multiple AI agents is managing permissions. Single AI agents often accumulate permissions as they are updated with expanded capabilities, enabling them to operate beyond their original purpose. The accumulation of permissions, referred to as privilege drift or scope sprawl, leads to broader access points and ...

blogsecuritystrategyaccess controlai agents

13 Jul

Marina Elmore 6 min read

Precursor, our new continuous behavioral validation engine for bot management, offers visibility into how humans and bots actually interact across the full user journey. By turning session-level behavior into bot detection signals, it identifies advanced automation with higher precision — while reducing friction for legitimate users.

bot managementsecurityturnstilejavascriptai

9 Jul

Kristopher Sandoval 9 min read

Scope sprawl occurs when identities, applications, or tokens accumulate broader permissions than they need to perform their intended tasks. It often stems from weak internal standards, unclear documentation, or pressure on engineering teams to move quickly. For example, consider the following scenarios. A developer wires an integration, requests a broad OAuth token scope because the ...

blogsecuritystrategyaccess controlapi governance

7 Jul

Kristopher Sandoval 5 min read

The age of AI is upon us — and with it, a new age of telemetry and observability tools for MCP-driven stacks. MCP observability refers to the tools and practices used to monitor, trace, and analyze how AI agents interact with MCP servers, tools, and connected systems. The current slate of tools for MCP observability ...

blogsecuritystrategyai agentsapi logging

1 Jul

Katy Bowman 4 min read

Beginning in version 11.8.0, we will be improving the security of the Heroku CLI by storing authentication credentials in your system keychain by default. The Heroku credential manager makes use of OS-native secure storage tools with interfaces designed for sensitive data while maintaining compatibility with existing developer workflows. We began the transition to our new […] The post Securing Heroku…

engineeringclisecurity

27 Jun

25 Jun

24 Jun

23 Jun

Aditya Tripathi 12 min read

In Omdia's 2026 software supply chain security report, 73% of organizations that generate SBOMs say they enable more efficient vulnerability mitigation, yet 86% still find the generation process challenging. That gap between recognized value and operational difficulty is where most teams are stuck. For teams building and securing containerized applications, understanding what an SBOM is,...

productsconceptsdocker hardened imagessecuritysoftware supply chain security

Dennis Jackson 17 min read

This is the technical companion to our update on Distilled, “Keeping the web open and private in the bot era.” Here we take a deeper look at the problem space, the design we’re proposing, and the problems still left to solve. Bots (and privacy-preserving browsers) not welcome Browse a news site in a private window. Shop […] The post PACT:…

firefoxprivacysecurity

22 Jun

18 Jun

17 Jun

Tito Milla 11 min read

In this post, we show how Vonage network-powered solutions work with Amazon Cognito to enhance many mobile-first use cases with network-level identity verification. Vonage network-powered solutions are a composable stack of real-time mobile operator intelligence, silent authentication, and integrated fraud protection, which uses the CUSTOM_AUTH flow to complete identity verification in under 5 seconds, with zero user interaction.

amazon cognitoaws lambdacustomer solutionspartner solutionssecurity

16 Jun

Kristopher Sandoval 11 min read

In April 2026, a big story dropped in the agentic world. In nine seconds, a Claude-powered coding agent deleted the entire production database for an application called PocketOS. Despite all the existing guardrails, the agent seemingly went rogue and confirmed with its users that the actions it took were neither positive, permissible, nor requested. What ...

blogsecuritystrategyaccess controlai agents

15 Jun

Fabio Salvadori 1 min read

AI agents expose the security checks you never actually wrote​​​​‌ ‍ ​‍​‍‌‍ ‌ ​‍‌‍‍‌‌‍‌ ‌‍‍‌‌‍ ‍​‍​‍​ ‍‍​‍​‍‌ ​ ‌‍​‌‌‍ ‍‌‍‍‌‌ ‌​‌ ‍‌​‍ ‍‌‍‍‌‌‍ ​‍​‍​‍ ​​‍​‍‌‍‍​‌ ​‍‌‍‌‌‌‍‌‍​‍​‍​ ‍‍​‍​‍‌‍‍​‌ ‌​‌ ‌​‌ ​​‌ ​ ​ ‍‍​‍ ​‍ ‌‍​ ‌‍ ‌‌ ​ ​‍ ‍‌ ​ ‌ ‌​‌‍​‌‌‍​ ‌‍‍ ‌‍ ‌ ‌‍‌‍‌‌‌ ​‍‌‍‌‍‌‍ ​‌‍ ‌ ‌ ​‍ ‍‌‍​ ‌‍ ​‍ ‌‍‍‌‌‍ ‍‌ ‌​‌‍‌‌‌‍ ‍‌ ‌​​‍ ‌‍‌‌‌‍‌​‌‍‍‌‌ ‌​​‍ ‌‍ ‌‌‍ ‌‍‌​‌‍‌‌​ ‌‌ ​​‌ ​‍‌‍‌‌‌ ​ ‌‍‌‌‌‍ ‍‌ ‌​‌‍​‌‌ ‌​‌‍‍‌‌‍ ‌‍ ‍​ ‍ ‌‍‍‌‌‍‌​​ ‌​ ‌‍​ ​‍‌‍​‌‌‍​‌‌‍​‍​ ​‌​ ‌‌‌‍​‌​‍ ‌​ ​​​ ​‌​ ‌‌‌‍​‌​‍ ‌​ ‌​‌‍​‍‌‍‌‍​ ​‍​‍ ‌​ ‍​‌‍​‍​ ​ ‌‍‌‌​‍ ‌‌‍​‍​ ‍‌​ ‌​‌‍​ ‌‍​ ​ ​ ​ ‌‌​ ‌‍​ ‍‌​ ‌ ​ ‌ ​ ​​​ ‍ ‌ ‌​‌ ‍‌‌ ​​‌‍‌‌​ ‌‌‍​‍‌‍ ​‌‍ ‌‍‌ ‌‌​​‌‍ ‌ ​ ‌ ‌​​ ‍ ‌ ​​‌‍​‌‌ ‌​‌‍‍​​ ‌‌ ‌​‌‍‍‌‌ ‌​‌‍ ​‌‍‌‌​ ‌‍​‍‌‍​‌‌ ​ ‌‍‌‌‌‌‌‌‌ ​‍‌‍ ​​ ‌‌‍‍​‌ ‌​‌ ‌​‌ ​​‌ ​ ​‍‌‌​ ​ ‌​​‌​‍‌‌​ ​‍‌​‌‍​‍‌‌​ ​‍‌​‌‍‌‍​ ‌‍ ‌‌ ​ ​‍ ‍‌ ​ ‌ ‌​‌‍​‌‌‍​ ‌‍‍ ‌‍ ‌ ‌‍‌‍‌‌‌ ​‍‌‍‌‍‌‍ ​‌‍ ‌ ‌ ​‍ ‍‌‍​ ‌‍ ​‍‌‍‌‍‍‌‌‍‌​​ ‌​ ‌‍​ ​‍‌‍​‌‌‍​‌‌‍​‍​ ​‌​ ‌‌‌‍​‌​‍ ‌​ ​​​ ​‌​ ‌‌‌‍​‌​‍ ‌​ ‌​‌‍​‍‌‍‌‍​ ​‍​‍ ‌​ ‍​‌‍​‍​ ​ ‌‍‌‌​‍ ‌‌‍​‍​ ‍‌​ ‌​‌‍​ ‌‍​ ​ ​ ​ ‌‌​ ‌‍​ ‍‌​ ‌ ​ ‌ ​ ​​​‍‌‍‌ ‌​‌ ‍‌‌ ​​‌‍‌‌​ ‌‌‍​‍‌‍ ​‌‍ ‌‍‌ ‌‌​​‌‍ ‌ ​ ‌ ‌​​‍‌‍‌ ​​‌‍​‌‌ ‌​‌‍‍​​ ‌‌ ‌​‌‍‍‌‌ ‌​‌‍ ​‌‍‌‌​‍‌‍‌ ​​‌‍‌‌‌ ​‍‌ ​ ‌ ​​‌‍‌‌‌‍​ ‌ ‌​‌‍‍‌‌ ‌‍‌‍‌‌​ ‌‌ ​​‌ ‌‌‌‍​‍‌‍ ​‌‍‍‌‌ ​ ‌‍‍​‌‍‌‌‌‍‌​​‍​‍‌ ‌

Stack Overflow

How attackers took twenty thousand Instagram accounts by asking Meta's AI politely, and why that failure is about to become common.​​​​‌ ‍ ​‍​‍‌‍ ‌ ​‍‌‍‍‌‌‍‌ ‌‍‍‌‌‍ ‍​‍​‍​ ‍‍​‍​‍‌ ​ ‌‍​‌‌‍ ‍‌‍‍‌‌ ‌​‌ ‍‌​‍ ‍‌‍‍‌‌‍ ​‍​‍​‍ ​​‍​‍‌‍‍​‌ ​‍‌‍‌‌‌‍‌‍​‍​‍​ ‍‍​‍​‍‌‍‍​‌ ‌​‌ ‌​‌ ​​‌ ​ ​ ‍‍​‍ ​‍ ‌‍​ ‌‍ ‌‌ ​ ​‍ ‍‌ ​ ‌ ‌​‌‍​‌‌‍​ ‌‍‍ ‌‍ ‌ ‌‍‌‍‌‌‌ ​‍‌‍‌‍‌‍ ​‌‍…

contributedsecurityrunning-software

12 Jun

11 Jun

Dan Berezin Stelzer 4 min read

Aikido now scans Docker Hardened Images (DHI) with built-in VEX support. Vulnerabilities that Docker has verified as non-exploitable drop out of the queue automatically, so developers spend their time on findings that actually matter. This post walks through what changed, why it matters, and how users can benefit from the new integration. Why teams are...

partnershipsproductssecurity

10 Jun

9 Jun

8 Jun

Aditya Tripathi 10 min read

Understanding software supply chain security is one thing. Putting it into practice across a real pipeline, with real deadlines and real constraints, is another. Most organizations recognize that their software supply chain is a growing attack surface, but translating that awareness into concrete, repeatable practices is where the work gets difficult. But why should your...

productsconceptsdocker hardened imagessecuritysoftware supply chain security

5 Jun

Srini Sekaran 15 min read

AI agents are moving fast. According to our State of Agentic AI report, 60% of organizations already have AI agents in production, yet 40% cite security and compliance as the number-one barrier to scaling them further. And that gap between adoption and oversight is exactly where AI governance lives. As AI takes on higher-stakes decisions...

productsagentic aiconceptsdocker ai governancesecurity

4 Jun

Aditya Tripathi 7 min read

When security teams scan their container environments for the first time, they often discover hundreds of known vulnerabilities, and almost none of them trace back to application code. The overwhelming majority come from packages that shipped with the base image: shells, compilers, debug utilities, and libraries the application never calls. In a software supply chain...

productsconceptsdocker hardened imagessecuritysoftware supply chain security

3 Jun

Aditya Tripathi 15 min read

Software supply chain attacks have accelerated faster than most security teams anticipated. Sonatype's 2026 State of the Software Supply Chain report identified more than 454,000 new malicious packages published to open source repositories in 2025, bringing the cumulative total to over 1.2 million since 2019. The blast radius keeps expanding as organizations consume more open...

productsconceptssecuritysoftware supply chain security

2 Jun

Jackie Frederick 9 min read

In our State of Agentic AI report, 45% of organizations said they struggle to ensure the tools their agents use are secure and enterprise-ready. That number reflects a broader reality: AI agents are moving into production faster than the security practices around them are maturing. The challenge is not that organizations lack security awareness. It’s...

productsconceptsdocker sandboxessecurity

29 May

Phoebe Sajor 1 min read

The find out stage of AI is just supply chain and password protection​​​​‌ ‍ ​‍​‍‌‍ ‌ ​‍‌‍‍‌‌‍‌ ‌‍‍‌‌‍ ‍​‍​‍​ ‍‍​‍​‍‌ ​ ‌‍​‌‌‍ ‍‌‍‍‌‌ ‌​‌ ‍‌​‍ ‍‌‍‍‌‌‍ ​‍​‍​‍ ​​‍​‍‌‍‍​‌ ​‍‌‍‌‌‌‍‌‍​‍​‍​ ‍‍​‍​‍‌‍‍​‌ ‌​‌ ‌​‌ ​​‌ ​ ​ ‍‍​‍ ​‍ ‌‍​ ‌‍ ‌‌ ​ ​‍ ‍‌ ​ ‌ ‌​‌‍​‌‌‍​ ‌‍‍ ‌‍ ‌ ‌‍‌‍‌‌‌ ​‍‌‍‌‍‌‍ ​‌‍ ‌ ‌ ​‍ ‍‌‍​ ‌‍ ​‍ ‌‍‍‌‌‍ ‍‌ ‌​‌‍‌‌‌‍ ‍‌ ‌​​‍ ‌‍‌‌‌‍‌​‌‍‍‌‌ ‌​​‍ ‌‍ ‌‌‍ ‌‍‌​‌‍‌‌​ ‌‌ ​​‌ ​‍‌‍‌‌‌ ​ ‌‍‌‌‌‍ ‍‌ ‌​‌‍​‌‌ ‌​‌‍‍‌‌‍ ‌‍ ‍​ ‍ ‌‍‍‌‌‍‌​​ ‌‌‍‌‍‌‍​‌​ ‍‌​ ​‌‌‍‌‍​ ‌‍‌‍​‌​ ‍​​‍ ‌​ ‌​‌‍​‍‌‍‌‍​ ​​​‍ ‌​ ‌​‌‍​‌​ ‌​‌‍​‌​‍ ‌‌‍​‌‌‍​ ​ ​​​ ‌ ​‍ ‌​ ‍​‌‍‌‌​ ‌ ‌‍‌‌‌‍‌‍‌‍‌​‌‍‌‌​ ‌ ​ ​‍​ ​ ​ ‌‌‌‍‌‍​ ‍ ‌ ‌​‌ ‍‌‌ ​​‌‍‌‌​ ‌‌‍​‍‌‍ ​‌‍ ‌‍‌ ‌‌​​‌‍ ‌ ​ ‌ ‌​​ ‍ ‌ ​​‌‍​‌‌ ‌​‌‍‍​​ ‌‌ ‌​‌‍‍‌‌ ‌​‌‍ ​‌‍‌‌​ ‌‍​‍‌‍​‌‌ ​ ‌‍‌‌‌‌‌‌‌ ​‍‌‍ ​​ ‌‌‍‍​‌ ‌​‌ ‌​‌ ​​‌ ​ ​‍‌‌​ ​ ‌​​‌​‍‌‌​ ​‍‌​‌‍​‍‌‌​ ​‍‌​‌‍‌‍​ ‌‍ ‌‌ ​ ​‍ ‍‌ ​ ‌ ‌​‌‍​‌‌‍​ ‌‍‍ ‌‍ ‌ ‌‍‌‍‌‌‌ ​‍‌‍‌‍‌‍ ​‌‍ ‌ ‌ ​‍ ‍‌‍​ ‌‍ ​‍‌‍‌‍‍‌‌‍‌​​ ‌‌‍‌‍‌‍​‌​ ‍‌​ ​‌‌‍‌‍​ ‌‍‌‍​‌​ ‍​​‍ ‌​ ‌​‌‍​‍‌‍‌‍​ ​​​‍ ‌​ ‌​‌‍​‌​ ‌​‌‍​‌​‍ ‌‌‍​‌‌‍​ ​ ​​​ ‌ ​‍ ‌​ ‍​‌‍‌‌​ ‌ ‌‍‌‌‌‍‌‍‌‍‌​‌‍‌‌​ ‌ ​ ​‍​ ​ ​ ‌‌‌‍‌‍​‍‌‍‌ ‌​‌ ‍‌‌ ​​‌‍‌‌​ ‌‌‍​‍‌‍ ​‌‍ ‌‍‌ ‌‌​​‌‍ ‌ ​ ‌ ‌​​‍‌‍‌ ​​‌‍​‌‌ ‌​‌‍‍​​ ‌‌ ‌​‌‍‍‌‌ ‌​‌‍ ​‌‍‌‌​‍‌‍‌ ​​‌‍‌‌‌ ​‍‌ ​ ‌ ​​‌‍‌‌‌‍​ ‌ ‌​‌‍‍‌‌ ‌‍‌‍‌‌​ ‌‌ ​​‌ ‌‌‌‍​‍‌‍ ​‌‍‍‌‌ ​ ‌‍‍​‌‍‌‌‌‍‌​​‍​‍‌ ‌

Stack Overflow

In this two-for-one special recorded at HumanX, Ryan is joined by Dataiku’s Florian Douetteau to chat about the governance, orchestration, and data requirements for serious agentic systems and 1Password’s Nancy Wang for a conversation on making agent swarms secure.​​​​‌ ‍ ​‍​‍‌‍ ‌ ​‍‌‍‍‌‌‍‌ ‌‍‍‌‌‍ ‍​‍​‍​ ‍‍​‍​‍‌ ​ ‌‍​‌‌‍ ‍‌‍‍‌‌ ‌​‌ ‍‌​‍ ‍‌‍‍‌‌‍ ​‍​‍​‍ ​​‍​‍‌‍‍​‌ ​‍‌‍‌‌‌‍‌‍​‍​‍​ ‍‍​‍​‍‌‍‍​‌ ‌​‌ ‌​‌ ​​‌ ​…

podcastse-techse-stackoverflowaisecurity

28 May

Kristopher Sandoval 10 min read

Often, enterprises end up treating all their APIs roughly the same. They’re authenticated, maybe rate-limited, and hopefully behind a gateway, but ultimately, they’re lumped together as part of a collection of APIs. While that flatness makes sense from a product management perspective, it poses a problem for risk management. A payment processing API and a ...

blogsecurityaccess controlapi gatewayapi governance

26 May

Jennifer Kohl 16 min read

Earlier this year I mass-migrated my blog to Astro using Claude Code. 146 posts. 6,024 images. Canonical URLs, JSON-LD markup, sitemap generation, the whole stack. I'd spent hours writing a skills file to teach the agent about my blog's architecture, how deployment worked, what not to touch. And it worked. Claude Code rewrote components, fixed...

communityagentic aiai agentdocker sandboxessecurity

21 May

Jack Batzner 5 min read

Announcing a Public Preview .NET package that adds policy enforcement, startup tool scanning, fallback governance, and response sanitization to MCP servers with a single builder extension. The post Announcing Agent Governance Toolkit MCP Extensions for .NET appeared first on .NET Blog.

.netaisecurity.net 8+agent governance toolkit

Richard Lander 47 min read

The `unsafe` keyword is being redesigned to mark caller-facing contracts rather than just syntax. Safety obligations between callers and callees become visible and reviewable. The model is motivated by the rise of AI-assisted code generation and arrives as a preview in .NET 11. The post Improving C# Memory Safety appeared first on .NET Blog.

.netaic#security.net 11

Adriano Mota 6 min read

When discussing modern API security, developers frequently conflate terms like bearer token and JSON Web Token (JWT). This semantic confusion around access tokens often masks a critical architectural distinction. A bearer token specifies the transmission mechanism, while a JWT defines a specific, structured data format. But due to the extensive adoption of JWTs, there is ...

blogsecurityapi architectureapi securityapi standards

20 May

Janet Wagner 9 min read

The application and API security industries are rethinking access control for AI agents. However, the underlying foundations remain the same ones the industry has relied on for years. What’s changing is how and when those foundations are applied. Depending on the use case, a given approach may work best at runtime, with proper contextual signals, ...

blogsecuritystrategyaccess controlai agents

19 May

Phoebe Sajor 1 min read

Your fridge could be a threat to national security​​​​‌ ‍ ​‍​‍‌‍ ‌ ​‍‌‍‍‌‌‍‌ ‌‍‍‌‌‍ ‍​‍​‍​ ‍‍​‍​‍‌ ​ ‌‍​‌‌‍ ‍‌‍‍‌‌ ‌​‌ ‍‌​‍ ‍‌‍‍‌‌‍ ​‍​‍​‍ ​​‍​‍‌‍‍​‌ ​‍‌‍‌‌‌‍‌‍​‍​‍​ ‍‍​‍​‍‌‍‍​‌ ‌​‌ ‌​‌ ​​‌ ​ ​ ‍‍​‍ ​‍ ‌‍​ ‌‍ ‌‌ ​ ​‍ ‍‌ ​ ‌ ‌​‌‍​‌‌‍​ ‌‍‍ ‌‍ ‌ ‌‍‌‍‌‌‌ ​‍‌‍‌‍‌‍ ​‌‍ ‌ ‌ ​‍ ‍‌‍​ ‌‍ ​‍ ‌‍‍‌‌‍ ‍‌ ‌​‌‍‌‌‌‍ ‍‌ ‌​​‍ ‌‍‌‌‌‍‌​‌‍‍‌‌ ‌​​‍ ‌‍ ‌‌‍ ‌‍‌​‌‍‌‌​ ‌‌ ​​‌ ​‍‌‍‌‌‌ ​ ‌‍‌‌‌‍ ‍‌ ‌​‌‍​‌‌ ‌​‌‍‍‌‌‍ ‌‍ ‍​ ‍ ‌‍‍‌‌‍‌​​ ‌​ ‌‌​ ​​‌‍‌​​ ‍​​ ‌‍​ ​‍​ ‌‌​ ‍‌​‍ ‌​ ‍​​ ​‌​ ​‍​ ‌​​‍ ‌​ ‌​​ ‍‌‌‍‌‍​ ‍​​‍ ‌​ ‍​​ ‌ ​ ​ ​ ‌​​‍ ‌‌‍​‍​ ‌‌​ ​‌‌‍​‍​ ​‍‌‍‌‍‌‍‌​​ ‌‌​ ​​​ ‌​‌‍​‍‌‍​ ​ ‍ ‌ ‌​‌ ‍‌‌ ​​‌‍‌‌​ ‌‌‍​‍‌‍ ​‌‍ ‌‍‌ ‌‌​​‌‍ ‌ ​ ‌ ‌​​ ‍ ‌ ​​‌‍​‌‌ ‌​‌‍‍​​ ‌‌ ‌​‌‍‍‌‌ ‌​‌‍ ​‌‍‌‌​ ‌‍​‍‌‍​‌‌ ​ ‌‍‌‌‌‌‌‌‌ ​‍‌‍ ​​ ‌‌‍‍​‌ ‌​‌ ‌​‌ ​​‌ ​ ​‍‌‌​ ​ ‌​​‌​‍‌‌​ ​‍‌​‌‍​‍‌‌​ ​‍‌​‌‍‌‍​ ‌‍ ‌‌ ​ ​‍ ‍‌ ​ ‌ ‌​‌‍​‌‌‍​ ‌‍‍ ‌‍ ‌ ‌‍‌‍‌‌‌ ​‍‌‍‌‍‌‍ ​‌‍ ‌ ‌ ​‍ ‍‌‍​ ‌‍ ​‍‌‍‌‍‍‌‌‍‌​​ ‌​ ‌‌​ ​​‌‍‌​​ ‍​​ ‌‍​ ​‍​ ‌‌​ ‍‌​‍ ‌​ ‍​​ ​‌​ ​‍​ ‌​​‍ ‌​ ‌​​ ‍‌‌‍‌‍​ ‍​​‍ ‌​ ‍​​ ‌ ​ ​ ​ ‌​​‍ ‌‌‍​‍​ ‌‌​ ​‌‌‍​‍​ ​‍‌‍‌‍‌‍‌​​ ‌‌​ ​​​ ‌​‌‍​‍‌‍​ ​‍‌‍‌ ‌​‌ ‍‌‌ ​​‌‍‌‌​ ‌‌‍​‍‌‍ ​‌‍ ‌‍‌ ‌‌​​‌‍ ‌ ​ ‌ ‌​​‍‌‍‌ ​​‌‍​‌‌ ‌​‌‍‍​​ ‌‌ ‌​‌‍‍‌‌ ‌​‌‍ ​‌‍‌‌​‍‌‍‌ ​​‌‍‌‌‌ ​‍‌ ​ ‌ ​​‌‍‌‌‌‍​ ‌ ‌​‌‍‍‌‌ ‌‍‌‍‌‌​ ‌‌ ​​‌ ‌‌‌‍​‍‌‍ ​‌‍‍‌‌ ​ ‌‍‍​‌‍‌‌‌‍‌​​‍​‍‌ ‌

Stack Overflow

On the floor of HumanX, Ryan is joined by Adam Meyers, Senior VP of Counter Adversary Operations at Crowdstrike, for a deep dive on their latest Global Threat Report that tracks over 281 adversaries across nation states, e-crime, and hacktivist organizations.​​​​‌ ‍ ​‍​‍‌‍ ‌ ​‍‌‍‍‌‌‍‌ ‌‍‍‌‌‍ ‍​‍​‍​ ‍‍​‍​‍‌ ​ ‌‍​‌‌‍ ‍‌‍‍‌‌ ‌​‌ ‍‌​‍ ‍‌‍‍‌‌‍ ​‍​‍​‍ ​​‍​‍‌‍‍​‌ ​‍‌‍‌‌‌‍‌‍​‍​‍​ ‍‍​‍​‍‌‍‍​‌ ‌​‌ ‌​‌…

podcastse-techse-stackoverflowsecurityprivacy

18 May

Nikolche Kolev 5 min read

Package pruning in .NET 10 removes platform-provided packages from your dependency graph. With transitive auditing enabled by default, projects with these defaults have 70% fewer transitive vulnerability reports compared to projects using the previous defaults. The post NuGet Package Pruning: Cleaner Dependencies and Actionable Vulnerability Reports appeared first on .NET Blog.

.netnugetsecurityauditdotnet10

13 May

Dan Berezin Stelzer 5 min read

On April 15, NIST announced a prioritized enrichment model for the National Vulnerability Database. Most CVEs will still be published, but fewer will receive the CVSS scores, CPE mappings, and CWE classifications that container scanners and compliance programs have historically relied on. The change formalizes a drift that has been visible to anyone pulling NVD...

productscompliancesecurity

1 min read

OpenAI details its response to the TanStack “Mini Shai-Hulud” supply chain attack, outlines protections taken to secure systems and signing certificates, and explains why macOS users must update OpenAI apps by June 12, 2026. Learn what happened, what was affected, and how OpenAI is strengthening defenses against evolving software supply chain threats.

security

12 May

PeiFang Sung 6 min read

Introducing Docker AI Governance: centralized control over how agents execute, what they can reach on the network, which credentials they can use, and which MCP tools they can call, so every developer in your company can run AI agents safely, wherever they work. Your laptop is the new prod Agents are the biggest productivity unlock...

productsdocker aidocker ai governancesecurity

8 May

7 May

5 May

Firefox Security Team 2 min read

The open web is a critical platform for applications that handle highly sensitive data, from private communications to financial transactions and medical records. Traditionally, servers are trusted to deliver the appropriate code and resources for their web applications to browsers, who then provide a secure and isolated environment for their execution. In some circumstances, this […] The post Trustworthy JavaScript…

firefoxsecurity

28 Apr

Mattie Behrens 5 min read

A few years back, I created portable-color for adding color to shell scripts. Then I deprecated it in favor of a new library, dye, that fixed a number of things that bothered me about portable-color. dye eventually added its own built-in templating, which meant users could just print a string full of things like “{{red}}” […] The post How I…

development practicessecuritygithubcyber security

23 Apr

Aditya Tripathi 5 min read

Catching the KICS push: what happened, and the case for open, fast collaboration In the past few weeks we've worked through two supply chain compromises on Docker Hub with a similar shape: first Trivy, now Checkmarx KICS. In both cases, stolen publisher credentials were used to push malicious images through legitimate publishing flows. In both...

security

22 Apr

17 Apr

Matthew Green 9 min read

This is the second in a series of posts about anonymous credentials. You can find the first part here. In the previous post, we introduced the notion of anonymous credentials as a technique that allows users to authenticate to a website without sacrificing their privacy. As a quick reminder, an anonymous credential system consists of … Continue reading Anonymous credentials:…

anonymous credentialsaiartificial-intelligencecybersecuritysecurity

16 Apr

15 Apr

Bill Doerrfeld 6 min read

While some commentators in tech say that microservices architecture has seen its heyday, in reality, it’s still foundational to some massive distributed digital systems, from Netflix, to Amazon, SoundCloud, and beyond. But how exactly do you operationalize thousands of distributed microservices living in various environments? Successful microservices adoption tales often revolve around using service mesh, ...

blogplatformssecurityapi architectureapi discovery

14 Apr

13 Apr

Dominic Marks 12 min read

Excerpt In complex, long-running agentic systems, maintaining alignment and coherent reasoning between agents requires careful design. In this second article of our series, we explore these challenges and the mechanisms we built to keep teams of agents working productively over long time spans. We present a range of complementary techniques that balance the conflicting requirements…

uncategorizeddevelopmentsecuritysoftware-engineering

10 Apr

31 Mar

Bill Doerrfeld 5 min read

APIs are the modern doorway for systems to share data, but this common pathway is often unlocked. As a result, over the past two years, we’ve witnessed a string of API security incidents, including headline-worthy API exploits at 23andMe, Avelo Airlines, Authy, Optus, Trello, Volkswagen, WhatsApp, and others. 42Crunch recently released its State of API ...

blogsecurityapi best practicesapi developmentapi security

27 Mar

lukaseder 1 min read

One of jOOQ’s most popular feature is the out-of-the-box debug logging experience. jOOQ developers find this feature very useful when developing their applications. Assuming you run a jOOQ query and configure your logger to print DEBUG log output: When this query is executed, your log output might contain something like this: Executing query : select … Continue reading Managing Sensitive…

jooq-in-usedebug loggingjooqredacted columnssecurity

25 Mar

Janet Wagner 6 min read

When it comes to APIs, security has always been a serious concern. Developers who design and build APIs strive to mitigate vulnerabilities before attackers find them. Consumers want to be reassured that the APIs their applications integrate with won’t compromise data or application integrity. However, the rise of AI has led to new and evolving ...

blogsecuritystrategyaccess controlai agents

23 Mar

13 Mar

Jin Kim 3 min read

Agents have enormous potential to power secure, personal AI assistants that automate complex tasks and workflows. Realizing that potential, however, requires strong isolation, a codebase that teams can easily inspect and understand, and clear control boundaries they can trust. Today, NanoClaw, a lightweight agent framework, is integrating with Docker Sandboxes to deliver secure-by-design agent execution....

partnershipsproductssecurityagentsai agent

11 Mar

6 Mar

Emily Huang 2 min read

The web browser and certificate authority industry is shortening the maximum allowed lifetime of TLS certificates. These changes will improve security on the Web, but you may have to change certificate maintenance practices for apps you run on Heroku. The good news is that if you’re using Heroku Automated Certificate Management, no changes are required: […] The post Preparing for…

newssecurityssl

5 Mar

Miles Brown 9 min read

Most API teams I talk to are serious about the front door. They have a documented API surface, versioning rules, code review, and a continuous integration and continuous delivery (CI/CD) pipeline that runs tests and security checks before anything ships. That’s all good hygiene. But the incidents that turn into painful postmortems often start somewhere ...

blogsecurityapi discoveryapi governanceapi inventory

4 Mar

Adriano Mota 6 min read

The evolution of the modern enterprise is often marked by a transition from streamlined simplicity to architectural fragmentation. What begins as a strategic move toward distributed systems frequently devolves into gateway sprawl, a phenomenon where decentralized business units adopt distinct API tools based on localized budgets, engineering preferences, or specific technical requirements. While this flexibility ...

blogplatformssecurityai agentsapi architecture

3 Mar

Vishrut Iyengar 4 min read

Your Package Manager, Now with a Security Upgrade Last December, we made Docker Hardened Images (DHI) free because we believe secure, minimal, production-ready images should be the default. Every developer deserves strong security at no cost. It should not be complicated or locked behind a paywall. From the start, flexibility mattered just as much as...

productssecuritydockerdocker hardened imagessecurity packages

Anisha Roy 4 min read

A Story from the Frontlines of Threat Intelligence The identification of cyber threats in e-commerce is challenging because discussions on topics like gift cards and discounts, when found on underground forums, can signal fraud yet closely resemble normal customer behavior. For security teams, distinguishing a genuine threat from routine chatter is extremely difficult, making risk identification feel like searching for…

llmsecuritycybersecuritycyber-threat-intelligenceai

25 Feb

24 Feb

Tom Schuster 2 min read

Cross-site scripting (XSS) remains one of the most prevalent vulnerabilities on the web. The new standardized Sanitizer API provides a straightforward way for web developers to sanitize untrusted HTML before inserting it into the DOM. Firefox 148 is the first browser to ship this standardized security enhancing API, advancing a safer web for everyone. We […] The post Goodbye innerHTML,…

featured articlefirefoxfirefox releasessecurityweb developers

J Simpson 8 min read

When building agentic AI systems that interact with APIs and other services, securely managing JSON Web Tokens (JWTs) becomes a critical part of the architecture. Unlike traditional web applications, agentic AI can operate autonomously, invoking APIs, making decisions, and passing sensitive information without direct human supervision. These nuances create unique authorization challenges around how JWTs ...

blogdesignsecurityai agentsapi governance

17 Feb

Art Anthony 7 min read

In recent months, we’ve been writing extensively about some of the exciting possibilities offered by artificial intelligence and the agentic consumption of APIs, from new routes to monetization via AI through to more efficient workflows. But there are downsides to consider here, too. Large language models (LLMs) have a habit of disregarding the API contract, ...

blogsecuritystrategyaccess controlai agents

10 Feb

Jin Kim 6 min read

Docker Hardened Images are now free, covering Alpine, Debian, and over 1,000 images including databases, runtimes, and message buses. For security teams, this changes the economics of container vulnerability management. DHI includes security fixes from Docker’s security team, which simplifies security response. Platform teams can pull the patched base image and redeploy quickly. But free...

companyengineeringproductssecuritysolutions

5 Feb

4 Feb

Srini Sekaran 4 min read

Every time execution models change, security frameworks need to change with them. Agents force the next shift. The Unattended Laptop Problem No developer would leave their laptop unattended and unlocked. The risk is obvious. A developer laptop has root-level access to production systems, repositories, databases, credentials, and APIs. If someone sat down and started using...

engineeringproductsagentsai mlsecurity

2 Feb

Matthew Green 12 min read

It’s not every day that we see mainstream media get excited about encryption apps! For that reason, the past several days have been fascinating, since we’ve been given not one but several unusual stories about the encryption used in WhatsApp. Or more accurately, if you read the story, a pretty wild allegation that the widely-used … Continue reading WhatsApp Encryption,…

messagingaidigital-marketingnewssecurity

29 Jan

Kristopher Sandoval 6 min read

Agentic AI is an incredibly powerful frontier technology, and it’s actively changing the tech landscape day by day. One of the most significant changes is that APIs are no longer solely called by deterministic code developed and reviewed by humans. Instead, APIs are being actively and frequently called, explored, linked, and even adapted by autonomous ...

blogsecurityaccess controlai agentsapi governance

28 Jan

21 Jan

19 Jan

15 Jan

Adriano Mota 9 min read

The emergence of AI coding assistants has ushered in a new era of software creation, formalized under the concept of “vibe coding.” This concept offers tremendous productivity but also introduces significant complexities, particularly when building critical APIs. Here is a comprehensive overview of what vibe coding is and the benefits it delivers. We also cover ...

blogdesignsecurityai agentsapi development

14 Jan

8 Jan

Kristopher Sandoval 7 min read

In the software field, one of the most commonly referred to and leveraged resources is the Top Ten list from OWASP. This is for good reason — OWASP stands as a platform- and vendor-agnostic voice that can highlight application security risks in a potentially more meaningful way than the litany of whitepapers and reports issued ...

blogsecurityaccess controlapi governanceapi security

5 Jan

23 Dec 2025

Jonas Iggbom 6 min read

Authorization Exchange, or AuthZEN for short, is a new specification from the OpenID Foundation that aims to bring clarity and standardization to authorization. If OAuth 2.0 and OpenID Connect brought us standardized protocols for authentication and identity, AuthZEN aims to do something similar for fine-grained authorization. It defines a shared, interoperable way for applications to ...

blogsecurityaccess controlapi governanceapi security

22 Dec 2025

19 Dec 2025

Colin Madison 4 min read

Earlier this week, we took a major step forward for the industry. Docker Hardened Images (DHI) is now available at no cost, bringing secure-by-default development to every team, everywhere. Anyone can now start from a secure, minimal, production-ready foundation from the first pull, without a subscription. With that decision comes a responsibility: if Docker Hardened Images become...

enterpriseproductssecurity

14 Dec 2025

10 Dec 2025

Alberto Sigismondi 3 min read

We’re excited to announce a significant enhancement to how Heroku Enterprise customers connect their deployment pipelines to GitHub Enterprise Server (GHES) and GitHub Enterprise Cloud (GHEC). The new Heroku GitHub Enterprise Integration is now available in a closed pilot, offering a more secure, robust, and permanent connection between your code repositories and your Heroku apps. […] The post Heroku GitHub…

newscontinuous integrationheroku enterprisesecurity

1 Dec 2025

Dominic Marks 9 min read

Slack’s Security Engineering team is responsible for protecting Slack’s core infrastructure and services. Our security event ingestion pipeline handles billions of events per day from a diverse array of data sources. Reviewing alerts produced by our security detection system is our primary responsibility during on-call shifts. We’re going to show you how we’re using AI…

uncategorizeddevelopmentsecuritysoftware-engineering

27 Nov 2025

Kristopher Sandoval 5 min read

Authorization is having a bit of a moment in the tech world right now. Organizations like Apple are investing more heavily in policy-driven access control, signalling a shift towards policy as code. As this approach is solidified, it’s becoming clear that the next big revolution in the authorization space will be focused on a specific ...

blogsecurityaccess controlapi securityapis and data

26 Nov 2025

25 Nov 2025

John H. Ayub 2 min read

In today’s software-driven economy, securing software supply chains is no longer optional, it’s mission-critical. Yet enterprises often struggle to balance developer speed and security. According to theCUBE Research, 95% of organizations say Docker improved their ability to identify and remediate vulnerabilities, while 79% rate it highly effective at maintaining compliance with security standards. Docker embeds...

enterpriseproductssecuritysolutionsdhi

18 Nov 2025

J Simpson 9 min read

Imagine you’re running an API gateway that routes traffic to several microservices, such as authentication, payments, order management, or analytics, for example. Now imagine that everything had been running flawlessly for months, when one night a malformed request body from a mobile client triggers a 500 Internal Server Error in your monitoring system. Even the ...

blogsecurityapiapi securityapi testing

13 Nov 2025

Ajeet Singh Raina 16 min read

This is Part 5 of our MCP Horror Stories series, where we examine real-world security incidents that highlight the critical vulnerabilities threatening AI infrastructure and demonstrate how Docker’s comprehensive AI security platform provides protection against these threats. Model Context Protocol (MCP) promises seamless integration between AI agents and communication platforms like WhatsApp, enabling automated message...

productsdockermcpmcp serversecurity

12 Nov 2025

7 Nov 2025

30 Oct 2025

28 Oct 2025

Art Anthony 5 min read

It’s not an overstatement to say that the health and fitness space has been transformed in the past couple of decades. Thanks to the introduction of wearables and trackers, keeping tabs on one’s progress no longer means manually entering weights and reps into a chalky old notebook between sets. Fitness has been streamlined, incentivized, and ...

blogsecuritystrategyapi governanceapi industry

27 Oct 2025

13 Oct 2025

Bill Doerrfeld 5 min read

Real-world constraints often impact how we build digital services. This is especially true for enterprise APIs in regulated industries that transmit sensitive data across jurisdictions. Constraints around how data is managed can easily slow progress — but it doesn’t have to be that way. At Platform Summit 2025, Yinka Omole, a lead software engineer at ...

blogdesignsecurityapiapi architecture

8 Oct 2025

J Simpson 8 min read

APIs have a reputation for being the weakest link in an enterprise’s cybersecurity. This can become a self-fulfilling prophecy, as APIs’ supposed vulnerabilities make them a popular target for potential attackers and cybercriminals. This can cause all manner of security issues, as APIs can be made to divulge a wealth of sensitive information using valid ...

blogsecurityapi developerapi governanceapi security

7 Oct 2025

3 Oct 2025

J Simpson 8 min read

In January 2024, the Centers for Medicare and Medicaid Services updated The CMS Interoperability and Patient Access Act. The new revision outlines requirements and specifications for what information medical providers need to provide, as well as how it should be formatted to ensure API security and data compliance. This is towards the goal of improving ...

blogplatformssecurityapi best practicesapi governance

2 Oct 2025

1 Oct 2025

Kristopher Sandoval 8 min read

Most teams do at least some sort of injection attack testing. This testing, however, is typically focused on a small subset of particular vulnerabilities. SQL injection is a popular target, as is command injection. Some teams may even do log injection if they’ve been burned before. But when it comes to APIs — and especially ...

blogsecurityaccess controlapi securitycybersecurity

22 Sept 2025

10 Sept 2025

David Baliles 8 min read

Salesforce customers often leverage third-party or custom services to extend their orgs, and they do so with two common options: Connected Apps and External Services. Connected Apps let third-party vendors or custom code call Salesforce APIs using long-lived OAuth tokens, while External Services call vendor APIs through declarative configurations with vendor-managed hosting, scaling, and endpoint security. While both approaches deliver…

engineeringapplinksalesforcesecurity

4 Sept 2025

Nathan Lehotsky 7 min read

As cyberattacks evolve to unprecedented levels of sophistication and speed, the time gap between breach detection and response has never been more critical. Traditional security approaches often operate reactively, identifying compromises only after damage has occurred. This delay grants attackers a tactical advantage, forcing security teams to focus on damage assessment and remediation rather than…

uncategorizedincident-responsesecurity

19 Aug 2025

John Schanck 5 min read

Firefox is now the first and the only browser to deploy fast and comprehensive certificate revocation checking that does not reveal your browsing activity to anyone (not even to Mozilla). Tens of millions of TLS server certificates are issued each day to secure communications between browsers and websites. These certificates are the cornerstones of ubiquitous […] The post CRLite: Fast,…

featurefirefoxprivacysecurity

13 Aug 2025

31 Jul 2025

9 Jun 2025

5 Jun 2025

28 May 2025

Erlang Solutions Team 6 min read

Digital wallet security is essential as mobile payments grow. Understand the risks and how to keep your business and customers safe. The post The Importance of Digital Wallet Security appeared first on Erlang Solutions.

digital paymentsdigital walletelixirsecurity

27 Mar 2025

Andrew Fawcett 7 min read

Many advanced users want to use GitHub Actions with their applications on Heroku. Now there’s a straightforward way to use these great systems together, and to meet strong security and compliance requirements at the same time. A Solution for GitHub IP Range Restrictions Heroku is a powerful platform that offers robust CI/CD capabilities and secure, […] The post Using GitHub…

engineeringdeveloper toolsheroku flowsecurity

26 Mar 2025

6 Mar 2025

Gbadebo Bello 6 min read

API security is crucial, as it directly impacts your business’s success and safety. How well you secure your APIs can make or mar your product, and it is of utmost importance to spend time thinking about security. I have seen developers work in Postman without properly securing their credentials, often leaving API keys exposed in shared environments or logging sensitive…

api-securitypostmanapiauthenticationsecurity

1 Mar 2025

Matthew Green 7 min read

This is a cryptography blog and I always feel the need to apologize for any post that isn’t “straight cryptography.” I’m actually getting a little tired of apologizing for it (though if you want some hard-core cryptography content, there’s plenty here and here.) Sometimes I have to remind my colleagues that out in the real … Continue reading Dear Apple:…

applemessagingcybersecurityiphonesecurity

23 Feb 2025

Matthew Green 7 min read

Two weeks ago, the Washington Post reported that the U.K. government had issued a secret order to Apple demanding that the company include a “backdoor” into the company’s end-to-end encrypted iCloud Backup feature. From the article: The British government’s undisclosed order, issued last month, requires blanket capability to view fully encrypted material, not merely assistance … Continue reading Three questions…

applebackdoorscybersecurityencryptionsecurity

12 Feb 2025

Matthew Green 10 min read

I’m supposed to be finishing a wonky series on proof systems (here and here) and I promise I will do that this week. In the midst of this I’ve been a bit distracted by world events. Last week the Washington Post published a bombshell story announcing that the U.K. had filed “technical capability notices” demanding … Continue reading U.K. asks…

applebackdoorscybersecurityiphonesecurity

6 Feb 2025

Matthew Green 14 min read

This is the second part of a two three four-part series, which covers some recent results on “verifiable computation” and possible pitfalls that could occur there. This post won’t make much sense on its own, so I urge you to start with the first part. In the previous post we introduced a handful of concepts, … Continue reading How to…

uncategorizedblockchaincryptosecurity

27 Sept 2024

Ethan Limchayseng 3 min read

We are thrilled to announce that Heroku Automated Certificate Management (ACM) now supports wildcard domains for the Common Runtime! Heroku ACM’s support for wildcard domains streamlines your cloud management by allowing Heroku’s Certificate management to cover all your desired subdomains with only one command, reducing networking setup overhead and providing more flexibility while enhancing the […] The post Simplify Your…

newscloud infrastructureproduct featuressecurity

28 Jun 2024

Nathan Lehotsky 6 min read

At Slack, we’re committed to security that goes beyond the ordinary. We continuously strive to earn and maintain user trust by safeguarding critical components integral to every user’s experience. From passwords to session cookies, and tokens to webhooks, we prioritize protecting everything essential to how users log into the platform and remain authenticated. Through proactive…

uncategorizedsecurity

24 Jun 2024

Ryan Slama 9 min read

Slack uses cookies to track session states for users on slack.com and the Slack Desktop app. The ever-present cookie banners have made cookies mainstream, but as a quick refresher, cookies are a little piece of client-side state associated with a website that is sent up to the web server on every request. Websites use this…

uncategorizedsecurity

30 May 2024

6 May 2024

Udayaram Kammara 5 min read

Bazaarvoice has thousands of clients including brands and retailers. Bazaarvoice has billions of records of product catalog and User Generated Content(UGC)from Bazaarvoice clients. When a shopper visits a brand or retailer site/app powered by Bazaarvoice, our APIs are triggered. In 2023,Bazaarvoice UGC APIs recorded peak traffic of over 3+ billion calls per day with zero […]

conversations apisecuritysoftware architectureapi architectureapi security

3 Apr 2024

Vivek Viswanathan 1 min read

Add-on Controls for Heroku Teams At Heroku, trust and security are top priorities and we’ve been steadily adding more security controls to the platform. Recently, we launched SSO for Heroku Teams, and today, we’re excited to announce more enhancements for teams: add-on controls. Previously, this feature was only available to Heroku Enterprise customers. The Elements […] The post Add-on Controls…

newsadd-onssecurity

21 Mar 2024

Vivek Viswanathan 1 min read

Today, we’re pleased to introduce a security feature addition for Heroku pay-as-you-go customers: Single Sign-On (SSO). SSO makes it easy to centralize and manage access to all the various tools and services used by your employees. Previously, SSO was only available for Heroku Enterprise. SSO improves the employee experience in several ways. You can use […] The post SSO for…

newssecurity

9 Feb 2024

Vivek Viswanathan 1 min read

TLS and HTTPS encryption have become foundational primitives and a requirement for running any app or service on the internet. Many Heroku customers told us through our public roadmap to make Heroku Automated Certificate Management available to all dyno types, including our Eco subscription. We’re thrilled to announce that Automatic Certificate Management(ACM) and manual certificate […] The post Automatic Certificate…

newsdynosproduct featuressecurity

17 Jan 2024

John McCloskey 5 min read

We all have secrets. Sometimes, these are guilty pleasures that we try to keep hidden, like watching cheesy reality TV or indulging in strange comfort food. We often worry: “How do we keep the secret safe?” “What could happen if someone finds out the secret?” “Who is keeping a secret?” “What happens if we lose […]

securitybackstageopensource

12 Dec 2023

Archie Gunasekara 10 min read

We are heavy users of Amazon Compute Compute Cloud (EC2) at Slack — we run approximately 60,000 EC2 instances across 17 AWS regions while operating hundreds of AWS accounts. A multitude of teams own and manage our various instances. The Instance Metadata Service (IMDS) is an on-instance component that can be used to gain an…

uncategorizedawscloud-computinginfrastructuresecurity

24 Aug 2023

Bryan Sullivan 2 min read

What do you keep in your Git repos? Source code for your production applications certainly, but you probably also keep a fair amount of experimental and “hackathon” code. Maybe you keep your documentation in Git. Maybe, like the District of Columbia does, you even keep legal documents there. So which of these are the most […] The post Your Most…

engineeringmicrosoft1esautomated toolingsecurity

20 Jul 2023

Andre Soto 2 min read

Summary Subdomain reuse, also known as subdomain takeover, is a security vulnerability that occurs when an attacker claims and takes control of a target domain. Typically, this happens when an application is deprecated and an attacker directs residual traffic to a host that they control. As of 14 June 2023, we changed the format of […] The post Security Improvement:…

newscloud infrastructuredeveloper toolssecuritysecurity compliance

18 Apr 2023

Tinder 7 min read

Authored by: Rojan Rijal, Tinder Security Labs | Johnny Nipper, Sr. Director | Tanner Emek, Sr Engineering Manager Summary In 2021, GitHub released support for OpenID Connect (OIDC) for GitHub Actions (GHA), allowing developers to securely interact with their infrastructure resources in Amazon Web Services (AWS), and other major cloud service providers. The OIDC support allows GHA jobs to retrieve…

securitygithubawsoidc

21 Feb 2023

Marianne McDonough Chrisos 1 min read

Security resilience is all about reducing risk and thriving in uncertainty. The Cisco Security Outcome Report 2nd edition, showed that cybersecurity success was linked to five main security team behaviors, two of which are ‘Be proactive about technology refreshes’ and ‘Use well-integrated technologies’. Plus, as more organizations embrace hybrid work and continue to add SaaS […] The post Cisco Umbrella…

securityforrestersecure internet gatewaysse

7 Nov 2022

Tinder 7 min read

Authors: Rojan Rijal , Tinder Security Labs | Johnny Nipper, Product Security Manager | Tanner Emek, Engineering Manager Recently, Tinder Security Labs gave a talk at Recon Village @ Defcon 30 called “Scanning your way into internal systems via URLScan.” We went over examples of sensitive links indexed by URLScan that could be leveraged to gain access into corporate systems.…

securitycybersecuritypreventionengineering

11 Oct 2022

Ulzii Otgonbaatar 5 min read

Designing and engineering a messaging system that is used by 6.8 million students and half a million teachers in K-12 schools is no easy feat. While the typical threats against online systems from unauthorized and unauthenticated access to sensitive information remain, the school environment compounds privacy challenges as additional entities such as guardians, co-teachers, and […] The post Privacy and…

privacysecurity

23 Jun 2022

Yuval Yatskan 1 min read

As new ways of work – cloud collaboration, hybrid work models, and BYOD – have become the standard, it’s clear that new environments and approaches require new strategies and capabilities. The early era of cybersecurity protection was built by stacking solutions like firewalls, on-premises web proxies, sandboxing, SIEMs, and endpoint security. With more people connecting […] The post How to…

securitysasesse

14 Mar 2022

Andre Soto 1 min read

At Salesforce, we strive to balance the security of your data and apps with an efficient and enjoyable user experience. Last year, we shortened login sessions for the Heroku Dashboard to 12 hours to improve security. Starting today, users can stay logged in for up to 24 hours. Even better, if you have multi-factor authentication […] The post Improving User…

newsproduct featuressalesforcesecurity

1 Feb 2022

25 Jan 2022

JT Clay 1 min read

On December 9, 2021, the Apache Log4j vulnerability – which affects the popular Apache Foundation Log4j library – was disclosed to the public over Twitter. In the days following the event, IT and SecOps teams scrambled to patch these vulnerabilities. But log4j is a popular piece of code, which means that patching takes time. That’s […] The post Protecting Against…

securitycisco umbrellacisco umbrella investigatecloud-delivered firewalldns-layer security

19 Jan 2022

Ethan Limchayseng 9 min read

This article was originally authored by Srinath Ananthakrishnan, an engineer on the Heroku Runtime Networking Team Summary This following story outlines a recent issue we saw with migrating one of our internal systems over to a new EC2 substrate and in the process breaking one of our customer’s use cases. We also outline how we […] The post The Adventures…

engineeringawscloud infrastructurerubysecurity

11 Jan 2022

Chloe Whitaker 1 min read

Last year threw a lot at cybersecurity teams, from the emergence of several high-profile cyberattacks to the revelation of widespread vulnerabilities. As we all move into 2022, odds are your team is re-thinking your cybersecurity strategy to help make your organization more resilient and flexible. This should involve an evaluation of your cybersecurity solutions, as […] The post 3 Ways…

securitycisco umbrella

2 Nov 2021

Chloe Whitaker 1 min read

A cloud access security broker (CASB) is a cybersecurity solution that serves as an intermediary between users and the cloud services that they rely on for day-to-day activities. It allows security or IT teams to enforce policies that govern users’ access to and use of cloud services. This can prevent data loss, ensure regulatory compliance, […] The post SASE Breakdown:…

securitycasbcloud access security brokersase

12 Oct 2021

Chloe Whitaker 1 min read

Secure Access Service Edge (SASE) has become the new standard for securing connections to business-critical applications and other digital assets. An effective SASE implementation depends on performance, architecture, and support (among other factors) for hybrid and multi-cloud environments. In this post, IT Central Station members who use Cisco Umbrella and Cisco SD-WAN explain the importance […] The post The Role…

securitycasbcloud-delivered firewalldnsdns-layer security

27 Sept 2021

Michael C. Fanning 3 min read

In this post, Michael Fanning gives us a short history on standards (think Julius Caesar), how consensus on something very small can enable something very large, and how all of it relates to the design of the ‘Static Analysis Results Interchange Format’ (SARIF). The post Caesar, standards, and SAST: The road to SARIF appeared first on Engineering@Microsoft.

engineeringmicrosoft1essarifsastsecurity

21 Sept 2021

Chloe Whitaker 1 min read

Over the course of a weekend in 2020, organizations around the world pivoted from in-person workplaces to either fully remote or hybrid remote/in-person work models. For security teams, this raised a concerning question: How do you protect the perimeter when said perimeter no longer exists? This is where cloud-native security – a term we at […] The post 3 Benefits…

securitycloud securitydns security

16 Sept 2021

Bryan Sullivan 3 min read

The faster we iterate on refining secure development practices, the faster our developers can address security pain points, and the better we protect our customers. In this post, Bryan Sullivan walks through key learnings from the 1ES Security team. The post You can’t have security for DevOps until you have DevOps for security appeared first on Engineering@Microsoft.

engineeringmicrosoft1esdevopslean product developmentsecurity

14 Sept 2021

Chloe Whitaker 1 min read

Based on the kind of high-profile cyberattacks dominating news cycles, you’d be forgiven for thinking these are large enterprise or government-scale crimes. But if you operate a small business, cybersecurity may be more important than you think. Most smaller businesses lack adequate cybersecurity systems, with many small business owners unaware that solutions as simple as […] The post How DNS-layer…

securitydnsdns securitydns-layer security

7 Sept 2021

Chloe Whitaker 1 min read

Spend enough time in cybersecurity and you’re bound to have heard colleagues, analysts, and consultants suggest adding DNS-layer protection to your security stack. It’s easy to understand the appeal – using the internet’s infrastructure to block connections to malicious or unwanted domains can help protect any network from online hazards. But recently, with the conversation […] The post SASE breakdown:…

securitydns securitydns-layer securitysase

31 Aug 2021

Chloe Whitaker 1 min read

The way we think about networking and cybersecurity has changed dramatically in recent years. The rise of remote workers, coupled with the growing push of company data and infrastructure into the cloud, prompted Gartner to outline a new approach to networking and security: Secure Access Service Edge (SASE). Where an organization’s networking and security solutions […] The post What is…

securitycisco umbrella

24 Aug 2021

3 Aug 2021

Negisa Taymourian 1 min read

In our last post on SASE security, we covered two key benefits of Secure Access Service Edge architecture — the security and simplicity that come from converging multiple services in a single solution delivered from the cloud. Today, we’re talking about scaling that cybersecurity to meet the growing needs of your business. Cybersecurity at an […] The post Scaling cybersecurity…

securitycisco umbrella

27 Jul 2021

Teresa Wingfield 1 min read

What is Shadow IT? Shadow IT is the use of IT-related hardware or software by a department or individual without the knowledge of the IT or security group within an organization. It can encompass cloud services, software, and hardware. For several reasons, business and IT/security groups are more at odds than ever before over whether […] The post Secure Shadow…

security

20 Jul 2021

David Gormley 1 min read

Secure access service edge (SASE) — cloud-delivered security combining networking and security functions — is on the rise, fueled in part by the need to secure work from home in countless locations. The hybrid work model is here to stay –– and SASE solutions are critical to supporting this new normal. How do you determine which one is right for…

securitycasbcloud access security brokersasesd-wan

13 Jul 2021

Andrea Gross 1 min read

Managing cybersecurity for a small business has never been more challenging. Business-critical operations increasingly rely on cloud-based applications, while employees push for more remote and hybrid work opportunities. And if your small business is like most, odds are you lack the budget to update your security infrastructure so that it keeps pace with these changes. […] The post The Essential…

securitycasbdnsumbrella

6 Jul 2021

Bryan Sullivan 3 min read

If a security tool catches a critical vulnerability, but also reports 99 other findings that turn out to be false positives, developers are going to ignore everything that the tool reports and then miss the important issues. Bryan Sullivan talks through how you can hone your tooling to separate the signal from the noise. The post Separating the signal from…

engineeringmicrosoft1esautomated toolingsecurity

9 Jun 2021

Ulzii Otgonbaatar 4 min read

Context At Clever, we rely on nearly two thousand infrastructure secrets like DB access keys, API tokens, and session secret keys to provide our services to students and teachers. Properly securing these secrets so we don’t expose them in our various environments requires thorough engineering efforts. In fact, securing secrets is generally a hard problem […] The post How Clever…

security

8 Jun 2021

Rachel Ackerly 1 min read

Roaming users, remote offices with direct internet access, cloud and SaaS applications — today’s workplace needs have evolved beyond the capabilities of traditional perimeter-based security. As the digital perimeter expands outwards it’s important to understand the potential impact this can have on your cyber security and some of the benefits of moving to a cloud […] The post Cloud security…

securitycloud security benefits

18 May 2021

Anny Gakhokidze 9 min read

Like any web browser, Firefox loads code from untrusted and potentially hostile websites and runs it on your computer. To protect you against new types of attacks from malicious sites and to meet the security principles of Mozilla, we set out to redesign Firefox on desktop. The post Introducing Firefox’s new Site Isolation Security Architecture appeared first on Mozilla Hacks…

featured articlefirefoxsecurity

13 May 2021

Andrea Gross 1 min read

Cisco Umbrella is proud to announce the addition of our most recent global cloud data center, Spain! Our DC is located in Silicon Alley, not to be confused with Silicon Valley. We chose this location because it resides in the heart of connectivity and high-tech industry in Madrid. Improved cybersecurity services for our Spanish and […] The post Cisco Umbrella…

securitydata centerglobal cloud architectureperformancesase

20 Apr 2021

Nicholas Consolo 1 min read

A new year brings a new wave of predictions for how companies will be shaping their network security architectures in 2021. Could anyone have predicted 2020 was going to be the year that changed the way companies did business, managed networks, and secured users? Much of these changes happened in a moment’s notice and held […] The post Making ESG’s…

securitycloud adoptionesgnetwork securityremote worker

12 Apr 2021

Tushar Pradhan 2 min read

Customer Trust is our highest priority at Salesforce and Heroku. It’s more important than ever to implement stronger security measures in light of increasing security threats that could affect services and apps that are critical to businesses and communities. We’re pleased to announce that all Heroku customers can now take advantage of the security offered […] The post Enhancing Security:…

newssalesforcesecuritysecurity compliance

6 Apr 2021

Christian Holler 11 min read

We successfully deployed ThreadSanitizer in the Firefox project to eliminate data races in our remaining C/C++ components. In the process, we found several impactful bugs and can safely say that data races are often underestimated in terms of their impact on program correctness. We recommend that all multithreaded C/C++ projects adopt the ThreadSanitizer tool to enhance code quality. The post…

developer toolsfeatured articlefirefoxsecuritydata races

Andrea Gross 1 min read

Earlier this month, the National Security Agency (NSA) and Cybersecurity Infrastructure Security Agency (CISA) issued an advisory on the growing need to introduce a protective DNS (PDNS) solution to your organization’s security footprint. Because DNS is foundational to most online activity, it’s also the layer where many attacks — including malware, phishing, command and control, […] The post Protective DNS:…

security

9 Feb 2021

Tyson Smith 7 min read

Mozilla has been fuzzing Firefox and its underlying components for a while. It has proven itself to be one of the most efficient ways to identify quality and security issues. In general, we apply fuzzing on different levels: there is fuzzing the browser as a whole but a significant amount of time is also spent on fuzzing isolated code (e.g.…

featured articlefirefoxsecurityautomationfuzzing

Ken Howard 1 min read

Can we all agree the shift has happened – the workforce isn’t just working from a coffee shop on occasion? The events of 2020 accelerated a growing trend of work from anywhere, any device, any time, while expecting a seamless experience. That’s not a tall order. That’s a grande order – with a double-shot of […] The post Expanding SASE…

security

2 Feb 2021

Lorraine Bellon 1 min read

For small business owners, much has changed in the past few years – a widespread shift to remote work, a growing push for companies to use cloud apps, the general embrace of cloud data storage. In this brave new world, one thing has remained constant: For small businesses, strong cybersecurity is essential. After all, these […] The post Small Businesses…

security

19 Jan 2021

Lorraine Bellon 1 min read

These days it seems like the only constant is change, and the networking and security worlds are no exception. Industry predictions around consolidation, cloud adoption, and convergence that were previously considered aggressive now seem understated. And with the unprecedented move to remote work across industries, these massive shifts continue to accelerate. The network perimeter is […] The post How to…

security

5 Jan 2021

Andrea Gross 1 min read

Every journey starts with one step. Whether that step is the first toward climbing a mountain or launching the campaign to keep your organization safe from cyberthreats, it’s important just to take that first step forward. You might not want to hear this, but cyberthreats are becoming more advanced and attackers are using new techniques […] The post Keep these…

securitysase

15 Dec 2020

Ken Howard 1 min read

It’s no secret that the world of work has changed dramatically. The “office” is now almost anywhere except the traditional campus you own and protect. Your workers and your data have scattered to bedroom alcoves, kitchen tables, outdoor coffee shops, and the park bench. Organizations have more critical infrastructure, applications, and sensitive data stored in […] The post Secure anywhere,…

securityadvanced malware protectioncloud securitycybersecuritymalware protection

1 Dec 2020

Ken Howard 1 min read

One of the main reasons that the secure access service edge (SASE) is getting so much attention these days is that it combines several networking and security capabilities and functions normally carried in multiple, siloed point solutions into a single, fully integrated cloud-native platform. This allows organizations to overcome cost and performance issues, resulting in […] The post What goes…

securitysasesecure access service edge

24 Nov 2020

Lorraine Bellon 1 min read

Every day, the Cisco Umbrella global network processes over 250 billion recursive DNS requests. Simply processing these recursive DNS requests is a huge job, but we’re also tasked with ensuring that each of these queries is answered as quickly as possible. One of the technologies that helps us maintain our great availability and speed is […] The post Why the…

securityanycast

13 Oct 2020

Lorraine Bellon 1 min read

It’s no secret – networking and security have left the building. Even before the major shift to remote working in the first half of 2020, workplaces had already made the transition to a decentralized network architecture, where computing resources are located outside the data center and most enterprise traffic is destined for public cloud services. […] The post How to…

securitycloud access security brokercloud securitycloud-delivered firewallcybersecurity

6 Oct 2020

Lorraine Bellon 1 min read

It might be hard to believe, but it’s already October, which means the leaves are changing, the weather is getting colder, and – you guessed it – people everywhere are taking steps to improve their cybersecurity knowledge and practices to combat cyberattacks. Now in its 17th year, National Cybersecurity Awareness Month (NCSAM) started as a […] The post Cisco Umbrella…

securitycyberattackscybersecuritycyberthreatsncsam

29 Sept 2020

Lorraine Bellon 1 min read

Working outside the office is no longer a trend or an office perk — it’s our new reality. And make no mistake – cyberattacks have not slowed down while so many people have begun working remotely outside the protections of the corporate office network. Enabling off-network endpoint protection for users is no longer optional – […] The post Secure remote…

securitycisco anyconnectcisco umbrellacloud securitycyberattacks

15 Sept 2020

Sneha Shekar 1 min read

84.7% of cyberattacks involve phishing. In such a scenario, it becomes very important to understand the various ways a phishing attack could occur. Phishing URLs are commonly found on cloud providers. This article will take you through why cloud providers are being used increasingly for phishing campaigns and what pattern an attack on these sites […] The post Why cloud…

securitycloud providerscloud securitydns-layer protectionphishing

8 Sept 2020

Lorraine Bellon 1 min read

Remote work isn’t just the future – it’s here and now. With most, if not all, of your users working from home, you need to deliver the same level of protection for the sensitive, business-critical data on their laptops and mobile devices as if they were working in the office. Cybercrime hasn’t slowed down during […] The post Protect remote…

securitycasbcloud access security brokercloud securitycyberthreats

1 Sept 2020

Ken Howard 1 min read

No matter what market, industry, or regulatory challenges your organization has faced through the years, one thing is certain. Connecting and protecting your customers, employees, contractors, and partners wherever they work is always the goal, but the details are constantly evolving. That’s never been truer than in this remote, distributed, always-on world today. The very networking and security landscape itself…

securitycloud securitysasesase for dummiessd-wan

25 Aug 2020

Ken Howard 1 min read

IT, network operations, and security operations teams are being called to do more to secure the organization while also delivering information and services to an increasingly distributed and ever-expanding edge. To keep your teams and organization protected, you need a way to simplify your cybersecurity stack while evolving it to meet today’s needs and your unique challenges. Whether you’re a…

securitycloud network securitycloud securitycybersecuritydns-layer security

4 Aug 2020

Mike Conca 5 min read

Browsers are changing the default value of the SameSite attribute for cookies from None to Lax. This will greatly improve security for users. However, some web sites may depend (even unknowingly) on the old default, potentially resulting in site breakage. At Mozilla, we are slowly introducing this change. And we urge web developers to test their sites with the new…

featured articlefirefoxsecuritycookiesnetwork

1 Jul 2020

Marcos Caceres 2 min read

As part of Mozilla’s ongoing commitment to improve the privacy and security of the web platform, over the next few months, we will be making some changes to the Gamepad API. Starting with Firefox 81, the Gamepad API will be restricted to what are known as “secure contexts.” The post Securing Gamepad API appeared first on Mozilla Hacks - the…

featured articlehtmlsecurityweb apisgamepad api

30 Apr 2020

Jason Kratzer 11 min read

Fuzzing, or fuzz testing, is an automated approach for testing the safety and stability of software. For the past 3 years, the Firefox fuzzing team has been developing a new fuzzer to identify security vulnerabilities in the implementation of WebAPIs in Firefox. This fuzzer leverages the WebAPIs’ own WebIDL definitions as a fuzzing grammar. The post Fuzzing Firefox with WebIDL…

featured articlefirefoxfirefox development highlightssecurityweb apis

3 Apr 2020

Martin Thomson 5 min read

Distinguished engineer Martin Thomson explains how this problem occurred, the implications for people who might be affected, and how problems of this nature might be avoided in future. To get there, we need to dig a little into how web caching works. The post Twitter Direct Message Caching and Firefox appeared first on Mozilla Hacks - the Web developer blog.

featured articlefirefoxprivacysecurity

22 Mar 2020

Henrik Warne 6 min read

I really like Secure by Design. The key idea is that there is a big overlap between secure code and good software design. Code that is strict, clear and focused will be easier to reason about, and will have fewer … Continue reading →

learningprogrammingdesignsecurity

10 Mar 2020

Chris Mills 7 min read

The release of Firefox 74 is focused on security enhancements: Feature Policy, the Cross-Origin-Resource-Policy header, and removal of TLS 1.0/1.1 support. We’ve also got some new CSS text property features, the JS optional chaining operator, and additional 2D canvas text metric features, along with the usual wealth of DevTools enhancements and bug fixes. The post Security means more with Firefox…

developer toolsfeatured articlefirefoxfirefox development highlightssecurity

25 Feb 2020

Nathan Froyd 7 min read

Protecting the security and privacy of individuals is a central tenet of Mozilla’s mission. While we continue to make extensive use of both sandboxing and Rust in Firefox to address security challenges in the browser, each has its limitations. Today we’re adding a third approach to our arsenal. RLBox, a new sandboxing technology developed by researchers at the University of…

featured articlefirefoxrustsecuritycranelift

6 Feb 2020

Thyla van der Merwe 3 min read

The Transport Layer Security (TLS) protocol is the de facto means for establishing security on the Web. The newest version, TLS 1.3, improves efficiency and remedies the flaws and weaknesses present in earlier versions. In October 2018, we announced our plans regarding TLS 1.0 and TLS 1.1 deprecation. Now's the time for us to make this change together and move…

featured articlefirefox releasessecuritystandardstls 1.3

12 Sept 2019

Sepideh Setayeshfar 4 min read

Today we are thrilled to announce the general availability (GA) release of Heroku Enterprise Accounts. All Enterprise Teams associated with a company are nested under an Enterprise Account which delivers a higher level of visibility and accountability. With an Enterprise Account, executives and admins can ensure trust and improved agility with simple fast management of […] The post Announcing General…

newsapp architectureheroku enterpriseproduct featuressecurity

24 Jul 2019

Alex Smolen 3 min read

At Clever, we lock down code access to customer data using AWS IAM roles with session policies. In Clever’s microservice AWS architecture, each service has a unique IAM role with access to the AWS resources it needs: S3 buckets, DynamoDB tables, and so on. Our services are multi-tenant and customer data is separated via logical […] The post Using IAM…

awssecurity

15 May 2019

18 Apr 2019

2 min read

We’re excited to announce the launch of our public bug bounty program with Bugcrowd — the #1 crowdsourced security platform. This public program is open to Bugcrowd’s full crowd of top, trusted whitehat hackers, and we will award up to $1,500 per vulnerability identified on our website, API, and mobile apps.

announcementssecurity

26 Mar 2019

Wade 5 min read

There’s obviously more to security than humans, technology, and vendors with all of their implementations and expertise. At Heroku we believe that security is a byproduct of excellence in engineering. All too often, software is written solely with the happy path in mind, and security assurances of that software has its own dangerous assumptions. A […] The post Bug Bounties…

engineeringpostgressecuritysecurity incidents

21 Feb 2019

Joe Kutner 9 min read

This blog post is adapted from a talk given by Joe Kutner at Devoxx 2018 titled “10 Mistakes Hackers Want You to Make.” Building self-defending applications and services is no longer aspirational–it’s required. Applying security patches, handling passwords correctly, sanitizing inputs, and properly encoding output is now table stakes. Our attackers keep getting better, and […] The post Ten Ways…

engineeringjavasecurity

5 Dec 2018

29 Aug 2018

23 Aug 2018

Jamie Arlen 2 min read

Today we are proud to announce that Heroku has achieved several important compliance milestones that provide third party validation of our security best practices: ISO 27001 Certification: Widely recognized and internationally accepted information security standard that specifies security management best practices and comprehensive security controls following ISO 27002 best practices guidance. ISO 27017 Certification: A […] The post Announcing ISO…

newscloud infrastructureheroku shieldsecuritysecurity compliance

24 Jul 2018

Alex Smolen 3 min read

Clever Goals is a new product that tracks students’ educational software usage. It creates progress data, a new type of data for Clever. This sensitive data needs to be protected from unauthorized access, and users should feel in control over how it’s used. How does the Clever security team make sure that new products like […] The post Securing New…

privacysecurity

13 Jun 2018

Scott Truitt 1 min read

On May 10, 2018, we received notice about two critical vulnerabilities in Redis, both embargoed until this morning. Upon this notice, our Data Infrastructure team proceeded to patch all internal and customer databases in response to these vulnerabilities. As of today, all customer databases have been patched successfully. At Heroku, customer trust is our most […] The post An Update…

newsheroku key-value storeplatform updatesredissecurity

22 May 2018

Craig Ingram 5 min read

The Public Cloud Security (PCS) group at Salesforce partners very closely with Heroku engineering to review and advise on new product features across the platform, from infrastructure to applications. One of the most rewarding aspects about this partnership and working on this team for me is when we not only identify security concerns, but take […] The post Securing Dependencies…

engineeringcloud infrastructuredeveloper toolsrailssecurity

6 Apr 2018

Etienne Stalmans 6 min read

At Heroku we consistently monitor vulnerability feeds for new issues. Once a new vulnerability drops, we jump into action to triage and determine how our platform and customers may be affected. Part of this process involves evaluating possible attack scenarios not included in the original vulnerability report. We also spend time looking for “adjacent” and […] The post Ruby CVE-2017-17405:…

engineeringdeveloper toolsrubysecuritysecurity incidents

8 Mar 2018

Etienne Stalmans 10 min read

Containers, specifically Docker, are all the rage. Most DevOps setups feature Docker somewhere in the CI pipeline. This likely means that any build environment you look at, will be using a container solution such as Docker. These build environments need to take untrusted user-supplied code and execute it. It makes sense to try and securely […] The post A House…

engineeringcloud infrastructurecontinuous integrationkubernetessecurity

1 Mar 2018

Caleb Hearth 7 min read

Observatory by Mozilla helps websites by teaching developers, system administrators, and security professionals how to configure their sites safely and securely. Let's take a look at the scores Observatory gives for a fairly straightforward Static Buildpack app, https://2017.keeprubyweird.com. Test Scores Test Pass Score Explanation Content Security Policy ✗ -25 Content Security Policy (CSP) header not […] The post Using HTTP…

engineeringbuildpacksjavascriptsecurity

28 Feb 2018

Alex Smolen 1 min read

Over the past month, Clever worked with CERT to address a vulnerability in our open-source SAML2 library. Clever maintains an open source library implementing the SAML protocol in Node.js known as saml2-js. We use this library internally in our SAML service provider functionality for schools using Clever SSO and the Clever Portal. It is used […] The post saml2-js and…

nodesecurity

27 Feb 2018

Gary Spillman 8 min read

Internet security is a topic that receives more attention every day. If you’re reading this article in early 2018, issues like Meltdown, Specter and the Equifax breach are no doubt fresh in your mind. Cybersecurity is a massive concern and can seem overwhelming. Where do you start? Where do you go? What do you do […]

testingnodejssecurity

5 Jan 2018

Trey Ford 2 min read

UPDATE: Friday, January 5 19:07 PST As of 13:30 PST, AWS completed their patch deployment addressing tenant isolation threats. AWS reports they have restored the expected multi-tenancy protections similar to dedicated hardware, which leaves Heroku to address the kernel vulnerabilities in runtime host operating systems. Heroku Performance, Private, and Shield dynos feature varying degrees of […] The post Meltdown and…

newssecurity

5 Nov 2017

jgamblin 1 min read

Like most security professionals I am spending a large amount of time helping my company move securely to AWS. Certificate management in AWS is done with AWS Certificate Manager and while they do offer *free* certificates, ACM generated certs are outside your direct control. You don’t get the keys which, at least for some things, should probably be a non-starter…

careersecurity

10 Oct 2017

19 Jun 2017

29 Apr 2017

jgamblin 2 min read

Recently I started looking at the Umbrella DNS Popularity List and did a blog post about it here. The data seemed valuable and lacking at the same time so I spent my *limited* free time this week learning about R and RStudio. Protip: If you want to play along at home there is an RStudio docker container so all you…

careersecurity

3 Apr 2017

jgamblin 1 min read

I am a big fan of DigiCert for TLS Certificates and CA/WebPKI services. While they have amazing customer support and are an amazing company to work with, there are not a lot of automation scripts to interact with their API available. So over the weekend and with a lot of help from Clint Wilson I built a shell script that:…

careersecurity

21 Mar 2017

Brett Goulder 1 min read

We are happy to announce the general availability of Automated Certificate Management (ACM) for all paid Heroku dynos. With ACM, the cumbersome and costly process of provisioning and managing SSL certificates is replaced with a simple experience that is free for all paid Dynos on Heroku’s Common Runtime. Creating secure web applications has never been […] The post Announcing Free…

newsproduct featuressecurity

20 Mar 2017

Dave Cheney 3 min read

A few weeks ago I was asked by a friend, “why should I care about Go”? They knew that I was passionate about Go, but wanted to know why I thought other people should care. This article contains three salient reasons why I think Go is an important programming language. Safety As individuals, you and I may be […]

goprogrammingconcurrencyproductivitysecurity

15 Feb 2017

Owen Jacobson 6 min read

As part of our commitment to security and support, we periodically upgrade the stack image, so that we can install updated package versions, address security vulnerabilities, and add new packages to the stack. Recently we had an incident during which some applications running on the Cedar-14 stack image experienced higher than normal rates of segmentation […] The post How We…

engineeringdynossecuritysecurity incidents

19 Jan 2017

jgamblin 2 min read

I was at dinner on Tuesday with 6 security professionals and I proposed this hypothetical situation and I thought it was worth writing up and sharing. Background: Six identical safes with $1,000,000 inside are being built into the side of a public building and are being randomly assigned to everyone at the dinner. At the end of 90 days any…

careersecurity

10 Jan 2017

Alex Smolen 7 min read

The password is both a ubiquitous and brittle security mechanism. With the emergence of new security trends like post-quantum cryptography and IoT-botnet attacks, it’s easy to overlook attacks that exploit guessable, reused, or coerced passwords. But the wherewithal among users to use strong passwords and keep them safe is rare. Despite decades of practice, managing […] The post Securing Saved-password…

privacysecurity

6 Jan 2017

jgamblin 1 min read

Scanning a host with Nmap is a fairly routine act for some in security to do but you from time to time you want to either get a different view of a host or try to conceal your public IP. In this case I use this simple “trick” to run an nmap scan through TOR. To do so you need…

hackingsecurity

30 Dec 2016

jgamblin 1 min read

Yesterday US-Cert released information on GRIZZLY STEPPE the malware used in the DNC hack. The IP and hash information provided by the US-Cert was really lacking so I decided to dig through it and see if I could make more of it. The first thing I did was to run the IPs through an ipinfo2sheets spreadsheet I put together earlier…

hackingsecurity

29 Dec 2016

jgamblin 1 min read

In November I saw this youtube video on turning a USB Air Purifier into a $75 USB Killer: My soldering skills are basically nonexistent so while I had some time off around the holidays I decided this would be a decent project to help improve them. So in early December I ordered 3 of these from Amazon: USB ionic Oxygen…

hackingsecurity

22 Dec 2016

jgamblin 1 min read

I had a coach whose favorite quote was “Pain is the best teacher.” and that was the first thing that popped into my head this morning when I realized that I had left an $80 a month Digital Ocean Droplet running for an extra 3 weeks after I got done using it. To be honest $60 isn’t *that* painful but…

careerhackingsecurity

20 Dec 2016

jgamblin 1 min read

What will 2017 hold for the security industry? I sat down and looked into my crystal ball and came up with these 8 security predictions for 2017. A Fortune 500 Will Use “DDOS as a Service” To Attack A Competitor. A bored VP of Marketing with a paypal account, a six pack and a nephew who can get him on…

careerhackingsecurity

5 Dec 2016

lukaseder 1 min read

As long as we allow ourselves to write string-based dynamic SQL embedded in other programming languages like Java, we will have a certain risk of being vulnerable to SQL injection. That’s a fact. Don’t believe it? Check out this website exposing all vulnerabilities on Stack Overflow for PHP questions: https://laurent22.github.io/so-injections In a previous blog post, … Continue reading Prevent SQL…

javasqljooqsecuritysql injection

4 Dec 2016

jgamblin 1 min read

I have been playing with my stack of pizero a bunch lately and tonight I decided to put together a piZero OTG Ethernet gadget that runs Kali (Really KaToolin), XRDP and Mate in a computer on a stick configuration. This way I have a full (as I want it to be) Kali installation with me as long as I have…

careerhackingsecurity

30 Nov 2016

jgamblin 1 min read

I have been playing with my stack of piZero’s recently and started to read about the kernel OTG gadgets and was intrigued by the OTG_HID gadget. So after doing some reading I found that someone had ported the USB Rubber Ducky platform to the piZero and called it rspiducky. Building it is fairly straight forward but if you if you…

careerhackingsecurity

28 Nov 2016

jgamblin 1 min read

I have been reading a lot about Beacon Frames on my vacation this week (stop laughing) and I came across a tool in Kali called MDK3 that will allow you to send fake beacon frames. I couldnt pass up a chance to test this so I pulled out my trusty TL-WN722N and made a list of the 5,0000 most common…

hackingsecurity

26 Nov 2016

jgamblin 1 min read

Thanks to PoisonTap I have finally had a reason to pull my PiZero out of the ever growing “Stuff to Hack” pile and start working on it. I have a couple of neat ideas that are coming down the pipeline but this weekend I built a VPN sidecar using a USB OTG Gadget. I wanted to be able to use…

careerhackingsecurity

13 Nov 2016

jgamblin 1 min read

In the last two years Burp Suite Proxy has become my go to web application security scanner. As with everything recently if I can automate it, I do. So this weekend I built a simple script to scan a website with Burp, create a PDF report and post it to Slack: Here is how I set it up: Create a…

careersecurity

9 Nov 2016

jgamblin 1 min read

I have recently been automating a lot of my technical security tasks and building slack bots around them and it was w3af‘s turn. W3af is an amazing open source web application security scanner that my friend Andres Riancho writes and maintains. The goal of this project was to build scheduled and automated scans of my web properties with pdf reporting…

careersecurity

5 Nov 2016

jgamblin 1 min read

As I have talked about before “You can’t defend what you dont know exists” so today while sitting around and trying to recover from walking pneumonia I wrote slackmap to continually nmap a network and post the differences to slack: Configuration is amazingly easy. I run a copy of this on a $5 a month Digitalocean Droplet for an external…

careersecurity

30 Sept 2016

Dave Cheney 4 min read

The recent total war bombardment of Brian Krebs’ site, and the subsequent allegation that the traffic emanated from compromised home routers, cameras, baby monitors, doorbells, thermostats, and whatnot, got me thinking. Prolexic said the 665 Gbps attack that hit my site tonight is almost twice the size of the largest attack they've seen previously. — […]

small ideasinternet of shitiotsecurity

22 Sept 2016

Brett Goulder 2 min read

Encrypted communication is now the norm for applications on the Internet. At Heroku, part of our mission is to spread encryption by making it easy for developers to setup and use SSL on every application. Today we take a big step forward in that mission by making Heroku SSL generally available, allowing you to easily […] The post SSL Is…

newsproduct featuressecurity

25 Aug 2016

jgamblin 1 min read

One of the first things I like to do when I start looking at a PCAP during an investigation is run it through snort to see if it finds anything suspicious. You can easily do this at the command line with snort -dv -r test.pcap but the output is not great. I have been using a tool called websnort for…

careerhackingsecurity

17 Aug 2016

jgamblin 1 min read

My friends at DigitalOcean were nice enough to give me a generous amount of credit on their cloud platform to do some security research with so I decided to do the most reckless thing I could think of and run a full ssh honeypot on the internet. The build out is pretty simple, it is the SSHoneypot Docker Container I…

hackingsecurity

25 Jul 2016

jgamblin 2 min read

I took some time tonight and read through the Security Summer Camp (BSidesLV, Blackhat and Defcon) schedules and picked the talks from this year that I think will be the best and that I do not want to miss. I ended up with these 16 talks I am going to make a special point to see next week: BSidesLV Managing…

careerhackingsecurity

15 Jul 2016

jgamblin 2 min read

We are two weeks away from Security Summer Camp (which is BSidesLV, Blackhat and Defcon)! So it is time for everyone to write their annual blog posts about what you must do before you head out. I want to be one of the cool kids so here is my list of 6 things to do before you pack: Delete All…

hackingsecurity

13 Jul 2016

jgamblin 1 min read

While doing security research it is not uncommon for me to build and destroy between 20 and 25 cloud servers a week on Digital Ocean. While there are great guides like: My First 10 Minutes On a Server – Primer for Securing Ubuntu My First 5 Minutes On A Server; Or, Essential Security for Linux Servers I do not have…

hackingsecurity

10 Jul 2016

jgamblin 1 min read

There has been a lot of talk about why you should use a VPN on public networks and why it shouldn’t be a commercial one. I am a huge fan of the Streisand privacy stack because it includes and L2TP/IPsec VPN, OpenConnect, OpenSSH, OpenVPN, Shadowsocks, sslh, Stunnel, and a Tor bridge all in one amazing package. The problem with Streisand…

careerhackingsecurity

9 Jul 2016

jgamblin 1 min read

I worked with a consultant using the lair framework two years ago and since then I have been a huge fan of the project to manage pentest information. Tom Steele has done an amazing job with the project but it has been a pain to install but thanks to Ryan Hanson and Docker you can now setup a lair instance…

careersecurity

18 May 2016

Brett Goulder 4 min read

Editor's Note: SSL Is Now Included on All Paid Dynos as of September 22, 2016 At Heroku, we want to make it easy for everyone to be able to learn and explore our service, and the related ecosystem of technologies, for free – be it student, professional developer, hobbyist or just curious individual. We view […] The post Announcing Heroku…

newsdynosproduct featuressecurity

12 May 2016

Alex Smolen 9 min read

Clever Badges makes it easy for K-2 students to log into applications. As with any new feature, we wanted to understand and address any potential security risks before we launched Clever Badges to our users. If we built Clever Badges without thinking deeply about security, it would have been easy to introduce a vulnerability and […] The post Clever Badges…

privacysecurity

27 Dec 2015

Henrik Warne 6 min read

I recently finished reading Ghost in the Wires by Kevin Mitnick. It is the story of Mitnick’s hacking career, from the start in his teens, through becoming the FBI’s most wanted hacker, to spending years in jail before finally being … Continue reading →

learningworkhackingsecuritysocial engineering

17 Dec 2015

Ike DeLorenzo 2 min read

We’re pleased to announce the beta of SSO for Heroku. With this beta, Heroku now supports the current and most widely supported SSO standard known as SAML 2.0, and has partnered with leading identity providers (IdPs) for easy set-up. Customers can use their existing identity provider like Salesforce Identity, Okta, PingOne, Microsoft Active Directory, and […] The post SSO for…

newsheroku enterprisesecurity

20 Oct 2015

10 Sept 2015

Balan Subramanian 4 min read

Apps are at the heart of modern businesses, and are important assets that need a secure platform geared for compliance and security. We launched Heroku Enterprise earlier this year with this in mind and today we are excited to announce the beta of Heroku Identity Federation for Heroku Enterprise customers. This feature unifies the login […] The post Integrated security…

newsheroku enterprisesalesforcesecuritysecurity compliance

9 Jul 2015

Balan Subramanian 4 min read

In February, we announced Heroku Enterprise, with collaboration and management capabilities for building and running your app portfolio in a governable and secure way on Heroku. We also introduced fine-grained access controls with app privileges as a beta feature. Today, we are pleased to announce general availability of this feature: Heroku Enterprise accounts are now […] The post Managing apps…

newscloud infrastructuredeveloper toolssecuritysecurity compliance

26 May 2015

Luciano Mammino 2 min read

Keybase.io is a new service that combines asymmetric cryptography with a social network. It allows users to easily share public keys and authenticate messages by linking keys to profiles on Twitter, GitHub, Reddit, etc. The service provides encrypted messaging and bitcoin wallet pairing to make adopting cryptography seamless.

securitycryptography

29 Sept 2014

wpengine 2 min read

CVE-2014-6271 and CVE-2014-7169, also known as “Shellshock”, are high impact vulnerabilities affecting the Born Again Shell (BASH). The vulnerability allows an attacker to trick Bash into running arbitrary commands which could result in unauthorized disclosure of information, unauthorized modification and disruption of service. Because this is such a big threat, and because at Clever we take security […] The post…

security

15 Sept 2014

David Gouldin 1 min read

Celery is by far the most popular library in Python for distributing asynchronous work using a task queue. If you’re building a Python web app, chances are you already use it to send email, perform API integrations, etc. Many people choose Redis as their message broker of choice because it’s dead simple to set up: […] The post How to…

engineeringdeveloper toolspythonsecurity

30 Jul 2014

kevin 1 min read

You should sign up for a VPN service! Yes you, the casual Internet browser. Here is why. Any time you connect from your laptop/phone to a wireless network (SFO Wifi, Starbucks, etc), anyone else on that network can read all of your traffic over HTTP, to sites like Wikipedia, Netflix, YouTube, WebMD and more. This […]

security

11 Apr 2014

30 Mar 2014

Luciano Mammino 2 min read

Learn how to reset a lost MySQL root password by restarting the server with disabled security checks. This allows resetting the password directly in the database. Useful when locked out but reduces security temporarily.

securitymysqlserver

14 Feb 2014

30 Aug 2012

Schakko 1 min read

Today I had to move the WSUS internal database to one of our backend database servers. Microsoft has a good instruction how to do this, nevertheless I ran into a problem. Microsoft SQL Server 2008 did not allow me to add the machine account of our WSUS frontend server (let […] The post WSUS: Moving from Windows Internal Database to…

databaseswindowsbasedmicrosoftsecurity

4 Jul 2010

Schakko 1 min read

Hin und wieder kann es vorkommen, dass der pop3proxy der Sophos UTM (ehemals Astaro) die eingehenden E-Mails “verschluckt”. Grund dafür ist der Spamassassin, der im Hintergrund läuft und bei bestimmten E-Mails eine extrem hohe Prozessorlast verursacht. Das Verhalten habe ich jetzt einige Male bei E-Mails beobachtet, die über die Bugtraq-Mailingliste […] The post How-To: Mail-Queue in Sophos UTM pop3proxy flushen/löschen…

networkingsecurityastaroblockdelete