Cloud & App Security (DevSecOps)

Shift‑left, IaC scanning, secrets, SBOMs, and container/k8s hardening.

  • 4 Tracked terms
  • Last 30 days Feed window

What this topic collects on

An article joins this feed when it matches these terms. Each one is also a search of its own.

Latest in Cloud & App Security (DevSecOps)


dev.to > judsonrhodes1569 > manage-internal-dns-hostnames-from-infrastructure-code-in-4-deploy-steps-43fd

Manage Internal DNS Hostnames from Infrastructure Code in 4 Deploy Steps

2+ day, 19+ hour ago   (1004+ words) TL;DR: Keep stable internal DNS records in the infrastructure repository, upsert them during deployment, then read them back and fail the deployment on any difference. That makes a marketplace hostname cutover reviewable and gives rollback a concrete input: the…...


dev.to > kserude > unsecured-low-code-apps-expose-sensitive-data-implementing-security-oversight-to-mitigate-risks-4cej

Unsecured Low-Code Apps Expose Sensitive Data: Implementing Security Oversight to Mitigate Risks

2+ week, 6+ day ago   (249+ words) Many LCNC platforms rely on cloud infrastructure (AWS, GCP, Azure) for hosting. CSPM tools monitor these environments for misconfigurations and unauthorized resources, such as unapproved storage buckets, serverless functions, or API gateways created by LCNC platforms. Unsanctioned applications frequently communicate…...


ox.security > blog > research-clickfix-phishing-npm-packages

ClickFix Phishing Pages Discovered in 24 npm Packages

3+ week, 5+ day ago   (462+ words) OX Security identified and is tracking a fake Cloudflare Captcha campaign that can potentially distribute ClickFix malware through npm, and found 24 distinct malicious packages sharing the exact same malicious code. The OX Research team is tracking a fake Cloudflare campaign…...