mastodon.world is one of the many independent Mastodon servers you can use to participate in the fediverse.
Generic Mastodon server for anyone to use.

Server stats:

9K
active users

#softwaresecurity

2 posts2 participants0 posts today

⚠️ The EU 🇪🇺 to launch its own vulnerability database because the US is dropping the ball 🇺🇸 😢 — and the timing couldn’t be more telling 🛡️

In response to growing digital sovereignty concerns, NIS2 compliance, and calls for vendor accountability, the EU is building a public vulnerability catalog. The goal?
📂 Track and disclose security bugs across government, industry, and open source
🔍 Complement—not compete with—the CVE Program
📊 Increase trust, transparency, and resilience within the bloc

But let’s be honest:
🤝 Multiple public vuln databases means we must align identifiers, disclosure standards, and data feeds—or risk fragmentation
💡 Transparency is great, but what about verification, consistency, and maintenance?
📉 And if vendors or agencies self-report, how do we ensure accuracy or prevent omission?

Done right, this could increase pressure on lagging suppliers and elevate accountability. But if we don’t connect the dots globally, we may just multiply confusion.

What do you think: smart evolution or coordination nightmare?

#CyberSecurity #VulnerabilityManagement #EU #CVE #NIS2 #SoftwareSecurity #Governance #security #privacy #cloud #infosec
theregister.com/2025/05/13/eu_

The Register · As US vuln-tracking falters, EU enters with its own security bug databaseBy Jessica Lyons

🚀 A decade of OSSRA reveals how open source has transformed software development! From 35% to 70% open source code in apps, vulnerabilities have surged too-154 per app on average in 2025. Managing security & licenses is now mission-critical. Dive into the data & future challenges here: techradar.com/pro/ten-years-of 🔐💻 #OpenSource #Cybersecurity #OSSRA #DevSecOps #SoftwareSecurity #TechTrends #newz

TechRadar · Ten years of OSSRA: what a decade of data tells us about the state of open source securityA decade of OSSRA reveals growing open source risks

🎙️ Going Live in 15 Minutes — Come Join Us!

I’m about to tune in for a live ITSPmagazine webinar that dives into a topic I truly care about:

Secure Coding = Developer Empowerment

It’s not just about reducing risk — it’s about investing in developers, boosting velocity, and building better software from the start.

🗓️ Today – April 18

🎙️ Hosted by ITSPmagazine

💡 In partnership with Manicode Security

Jim Manico

Jimmy Mesta 🤙

Sean Martin, CISSP

Will be talking about:

✅ Why most developers never get proper secure coding training

✅ How to get leadership buy-in for better dev security

✅ Why this isn’t just security—it’s a career boost

If you’ve got time, join us live. If not, watch it on demand. Either way, it’s a conversation worth having.

👉 Join here:

crowdcast.io/c/secure-coding-e

#ApplicationSecurity, #DeveloperEmpowerment, #SecureCoding, #DevSecOps, #softwaresecurity, #cybersecurity, #infosec, #ITSPmagazine

Secure Coding = Developer Power — An ITSPmagazine Webinar with Manicode Security
crowdcastSecure Coding = Developer Power — An ITSPmagazine Webinar with Manicode SecurityRegister now for Secure Coding = Developer Power — An ITSPmagazine Webinar with Manicode Security on crowdcast, scheduled to go live on April 16, 2025, 03:30 PM EDT.

A nice hands on approach to #SoftwareSecurity, in the best GTD manner. Celine Pypaert from Johnson Matthey giving an interesting talk here in #QConLondon about how teams can get started with securing their development processes.

#Security is difficult, complex, impossible to enforce and it requires awareness and participation of a lot of stakeholders in an organization or a team. So just start small and scale up as you go!

Yes, it is true! 😏 🎙️💻 It’s Webinar Time! Secure coding isn’t just about writing safer software—it’s a career game-changer.

But most companies don’t invest in secure coding training, leaving developers without the skills they need to protect their apps.

Join us live on April 16, 2025, for an ITSPmagazine Webinar where we’ll explore how to change that.

💡 Secure Coding = Developer Power: How To Convince Your Boss To Invest In You

With:
🎙️ Jim Manico, Manicode Security
🎙️ Jimmy Mesta 🤙, RAD Security
🎙️ Moderated by yours truly — Sean Martin, CISSP

👉 Register here: crowdcast.io/c/secure-coding-e

Why You Should Attend
Secure coding isn’t just about preventing security failures—it’s a career accelerator. Developers who understand security are more valuable to their companies, build better products, and stand out in the job market. This session will equip you with the knowledge and tools to make the case for secure coding training at your company, giving you an edge as both a developer and an advocate for better software security.

We’ll cover:
🔐 Live code reviews & secure fixes
🔧 Automation tips for secure defaults
📚 What effective training really looks like

If you care about building secure software and stronger engineering teams, don’t miss this one.

👉 Register here: crowdcast.io/c/secure-coding-e

Secure Coding = Developer Power — An ITSPmagazine Webinar with Manicode Security
crowdcastSecure Coding = Developer Power — An ITSPmagazine Webinar with Manicode SecurityRegister now for Secure Coding = Developer Power — An ITSPmagazine Webinar with Manicode Security on crowdcast, scheduled to go live on April 16, 2025, 03:30 PM EDT.

Yes, it is true! 😏
🎙️💻 It's Webinar Time!

... and we’re back with another ITSPmagazine Thought Leadership Webinar — because impactful conversations and meaningful perspective exchanges are what we’re all about.

🚀 After the success of our debut session “AI In Healthcare: Who Benefits, Who Pays, And Who’s At Risk?” (missed it? Watch it on demand 👉 crowdcast.io/c/ai-in-healthcar) —we’re diving back in with a brand-new conversation focused on the heart of what drives our work: cybersecurity, technology, and society.

💡 Secure Coding = Developer Power: How To Convince Your Boss To Invest In You An ITSPmagazine Webinar With Manicode Security 🗓️ April 16, 2025

We’re honored to welcome two brilliant minds joining Sean Martin, CISSP — yes, of course, he’s pretty sharp too 😬 — for this one:

🎙️💥 Jim Manico, Founder and Secure Coding Educator at Manicode Security
🎙️💥 Jimmy Mesta 🤙, Course Instructor for Manicode and CTO at RAD Security

Why does #securecoding still feel like an afterthought? This session tackles that question head-on—covering why most companies don’t invest in secure coding training, how developers can advocate for themselves, and how this skillset can seriously boost your career. We’ll even get into some live code reviews and automation demos you won’t want to miss.

🔐💥 Secure Coding = Developer Power: How To Convince Your Boss To Invest In You
🗓️💥 LIVE: April 16, 2025
📍💥 REGISTER HERE: crowdcast.io/c/secure-coding-e

Be sure to share this with your fellow #developers, coworkers, and anyone who cares about building safer software and smarter teams. This is your chance to invest in yourself—and help your company do the same.

LET'S go, we can do this!!! 🤘😬✨

#webinar, #securecoding, #developerlife, #cybersecurity, #infosec, #softwaresecurity, #devsecops, #itspmagazine #infosecurity #tech #technology #software #programmers

There is a malicious #phishing #fake website impersonating #homebrew for MacOS - sometimes this fake website is even featured as sponsored ad when searching for „homebrew“ on #Google!

!!! Please take care to not fall for it !!!

When you visit the fake website, you are guided to copy a WRONG curl command that supposedly retrieves and installs Homebrew. While the legitimate one is hosted on GitHub, this one pulls it from the attacker’s malicious infrastructure.
After the payload is loaded, a fake prompt for the admin password is repeatedly displayed. That is literally all it takes to lose all your passwords in Apple’s keychain, all your browser cookies, and other valuable data!
 
! Never run commands you are not sure about, and always double-check the sources of what you're using!
#security #itsecurity #softwaresecurity #software #cybersecurity #macos #apple #phishingattack
 

It’s always a great pleasure to spend time with Jim Manico and learn from his expertise! 🧐✨📚

Turning #Developers into #Security Champions: The Business Case for Secure Development | A Manicode Security Brand Story with Jim Manico

In this insightful episode, hosted by @seanmartin and @Marcociappelli on @ITSPmagazine, Jim shares how enabling developers to embrace secure coding practices can elevate them into true security champions.

He explains why secure development isn’t just about writing safer code—it’s a transformative approach that strengthens #business resilience, protects critical data, and fosters a company-wide culture of security-first thinking.

📺 Watch the full episode here:
youtu.be/OJXD_cS1JJM?si=KGwqwm

🎧Listen and subscribe here:
brand-stories-podcast.simpleca

Follow this link to listen, watch, or read the episode—whichever works best for you.

📚 itspmagazine.com/their-stories

youtu.be- YouTubeEnjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.

𝗦𝗶𝗰𝗵𝗲𝗿 𝗲𝗻𝘁𝘄𝗶𝗰𝗸𝗲𝗹𝗻 𝘀𝘁𝗮𝘁𝘁 𝘀𝗽ä𝘁𝗲𝗿 𝗽𝗮𝘁𝗰𝗵𝗲𝗻!
HiSolutions Know-how to go | 02.04.2025 | Bonn | Kostenfrei

Software ist oft die erste Angriffsstelle für Cyberkriminelle – doch viele Sicherheitsmaßnahmen greifen erst spät. Wie gelingt es, Risiken frühzeitig zu minimieren?

Themen des Wissensfrühstücks:
👉 Security-by-Design in jeder Entwicklungsphase
👉 Praktische Einblicke in sichere Softwarearchitektur & Testing
👉Austausch mit Experten & Best Practices für Ihre Projekte

Jetzt anmelden & Security von Anfang an mitdenken ▶️ hisolutions.com/knowhow