Identity and Access Management
Hackers Target Popular arrayref Rust Crate in Supply-Chain Attack
Security researchers are sorting through a complex, stealthy, and fast-moving supply-chain attack aimed at pushing information-stealing malware by compromising the account of the maintainer of multiple Rust crates and introducing four more ...
Critical Flaw in isolated-vm Can Lead to Sandbox Escape, RCE Threat
Developers for years have been using vm2, an open-source Node.js library, to run untrusted JavaScript inside a secure and isolated sandbox environment. It uses Node.js’s built-in modules and JavaScript Proxies and lets ...
Attackers Can Exploit a Claude Code RCE Flaw to Take Command of System
A dangerous vulnerability found in Anthropic’s popular Claude Code developer model could have allowed bad actors to grab control of a victim’s system by luring them into clicking on a crafted malicious ...
Massive VS Code Secrets Leak Puts Focus on Extensions, AI: Wiz
Researchers with cybersecurity firm Wiz earlier this year discovered, almost by chance, a significant supply chain risk and massive secrets leak in the Visual Studio Code and OpenVSX marketplaces that they said ...
Five Great DevOps Job Opportunities
Looking for a great new DevOps job? Check out these available opportunities at Cognizant, IBM, Workday and more! ...
Venafi Adds Ability to Prevent Unauthorized Code From Running
Venafi added an ability to prevent unauthorized code from running in IT environments that make use of its machine identity management platform ...
Sonar Adds Secrets Detection to Code Analysis Portfolio
Sonar has added a secrets detection capability to its portfolio of tools for analyzing code and DevOps workflows ...
RBAC For Your CI/CD Pipeline: Why and How
By implementing RBAC in your CI/CD pipeline, you can help ensure secure and efficient operations ...
Navigating Passkeys: Challenges, Pitfalls and Considerations for Developers
While passkeys can dramatically improve the security and UX of authenticating users to applications, there’s a lot that still rests on the shoulders of developers ...
Who Should Have Access to Production?
In a perfect world, no one would have access to production, as that’s the safest way to make sure there won’t be any issues ...
Policy-Based Governance: Modernizing Authorization for the Enterprise
Change of control and management of access in the privileged environment requires a new approach to the solutions we use for privileged access governance ...
Pulumi Previews Tool to Integrate Secrets and Infrastructure Management
Pulumi previewed a tool that enables DevOps teams to unify environments, secrets and configuration (ESC) management ...

