postmodern, to opensource
@postmodern@ruby.social avatar

PSA: HEADS UP EVERYONE! Another project noticed they were being targeted with similar social engineering tactics as the xz-utils backdoor attack. Be on the lookout for random people demanding that you add someone new as a maintainer for vague but urgent "reasons". Google their emails, check their GitHub/GitLab histories, see if they are on Mastodon/Reddit/"X"/LinkedIn. If they do not have an internet footprint, they are probably a plant.
https://openssf.org/blog/2024/04/15/open-source-security-openssf-and-openjs-foundations-issue-alert-for-social-engineering-takeovers-of-open-source-projects/

AJCxZ0, to infosec

Today I finished listening to the entire back catalogue of @joshbressers ' excellent "Hacker History" podcast - https://hackerhistory.com/ in which Josh skillfully dismisses his guests' attempts to disclaim their hacker status and tell their consistently fascinating stories.
Naturally it's especially interesting to me how often I share similar experiences with these guests, which goes some way to explain my rise to InfoSec Legend™. Either that or we're just old.

This podcast is quite different from his "Open Source Security" podcast - https://opensourcesecurity.io/ - with @kurtseifried in which they play a cantankerous couple of grizzled professionals with opinions on Information Security and (mostly) related topics which occasionally align.

Both are strongly recommended.

osi, to opensource
@osi@opensource.org avatar

supply chain security is critical, but it can be complex. This panel will help you understand the key concepts, best practices + how to apply them to your organization.
https://2023.allthingsopen.org/sessions/panel-open-source-compliance-security

osi, to opensource
@osi@opensource.org avatar

We’re excited to bring a panel to @AllThingsOpen on supply chain compliance + security. Join us for perspectives from @CISAgov, @github + @StackLokHQ https://2023.allthingsopen.org/sessions/panel-open-source-compliance-security

  • All
  • Subscribed
  • Moderated
  • Favorites
  • provamag3
  • InstantRegret
  • mdbf
  • ethstaker
  • magazineikmin
  • GTA5RPClips
  • rosin
  • thenastyranch
  • Youngstown
  • osvaldo12
  • slotface
  • khanakhh
  • kavyap
  • DreamBathrooms
  • JUstTest
  • Durango
  • everett
  • cisconetworking
  • Leos
  • normalnudes
  • cubers
  • modclub
  • ngwrru68w68
  • tacticalgear
  • megavids
  • anitta
  • tester
  • lostlight
  • All magazines