Cloud & App Security (DevSecOps)

Shift‑left, IaC scanning, secrets, SBOMs, and container/k8s hardening.

  • 4 Tracked terms
  • Last 30 days Feed window

What this topic collects on

An article joins this feed when it matches these terms. Each one is also a search of its own.

Latest in Cloud & App Security (DevSecOps)

DEV Community
dev.to > kserude > unsecured-low-code-apps-expose-sensitive-data-implementing-security-oversight-to-mitigate-risks-4cej

Unsecured Low-Code Apps Expose Sensitive Data: Implementing Security Oversight to Mitigate Risks

1+ week, 5+ day ago   (249+ words) Many LCNC platforms rely on cloud infrastructure (AWS, GCP, Azure) for hosting. CSPM tools monitor these environments for misconfigurations and unauthorized resources, such as unapproved storage buckets, serverless functions, or API gateways created by LCNC platforms. Unsanctioned applications frequently communicate…...

OX Security
ox.security > blog > research-clickfix-phishing-npm-packages

ClickFix Phishing Pages Discovered in 24 npm Packages

2+ week, 4+ day ago   (462+ words) OX Security identified and is tracking a fake Cloudflare Captcha campaign that can potentially distribute ClickFix malware through npm, and found 24 distinct malicious packages sharing the exact same malicious code. The OX Research team is tracking a fake Cloudflare campaign…...

Medium
medium.com > @jh.baek.sd > cursor-origin-has-7-traps-and-one-of-them-is-permanent-5b9bcb8b34a8

Cursor Origin Has 7 Traps, And One of Them Is Permanent 😬

3+ week, 4+ day ago   (28+ words) Cursor Origin is live in beta. One setup step is permanent, mirrors block the CI apps, and privacy follows the namespace owner. Here is what to check first....