Shift-Left in Software Security: Making Peace Between Developers and Security
When security sends a 300-finding report the day before release, nobody wins. Here's how to put security checks into the developer's flow without the noise.
Guides, analysis and field notes on cyber security, software and technology.
When security sends a 300-finding report the day before release, nobody wins. Here's how to put security checks into the developer's flow without the noise.
Containers speed you up, but left on defaults they speed attackers up too. We cover hardening across four layers, from image to runtime, and compare the open source tools for each.
Most cloud breaches come not from sophisticated attacks but from an open storage bucket or an over-privileged key. We walk through the most common mistakes and their lasting fixes.