ppfosec
  • Home
  • About
  • LinkedIn
  • Jokes
Sign in Subscribe

DevOps

A collection of 4 posts
How to convince developers to fix their security vulnerabilities?
GRC

How to convince developers to fix their security vulnerabilities?

Presenting developers with vulnerabilities is one of the most common -and frustrating- tasks of any security analyst. Here's a list of the most common excuses developers come up with to avoid fixing vulnerabilities and how I react to them.
22 Nov 2023 6 min read
10 Harsh Truths About Cloud Security
DevSecOps

10 Harsh Truths About Cloud Security

As a specialist in cloud security due diligence and third-party security risk management, I present the hardest aspects of the discipline. Questionnaires and scanners have created a culture of "checkmarkism" that lead to fast results but low value advice.
30 Aug 2023 8 min read
How do Supply-Chain Attacks Work? Examples from Software Development
ELI5

How do Supply-Chain Attacks Work? Examples from Software Development

Did you know software is made up of hundreds of tiny pieces of software called libraries? Attackers sure do. Nowadays, they prey on developers' cognitive loads to infiltrate our most trusted applications. Let's unpack the new phenomenon of supply chain attacks.
07 Jun 2023 6 min read
The Supply Chain Security Crisis: Tools vs Talent
DevOps

The Supply Chain Security Crisis: Tools vs Talent

Remember Log4Shell? Not actual shipping containers - I'm talking about that infamous vulnerability that exposed the fragility of our software ecosystem. Log4Shell, a critical vulnerability discovered in December 2021 in the ubiquitous Log4j Java library, allowed attackers to execute arbitrary code by injecting malicious strings into log entries.
06 Jul 2022 3 min read
Page 1 of 1
ppfosec © 2025
  • Sign up
Powered by Ghost