Blog
A practical GitHub security checklist for teams: branch protection, rulesets, secret scanning, push protection, Dependabot, CodeQL, GitHub Actions hardening, least-privilege access, OIDC, and SECURITY.md.
Guide
Practical AI-assisted GitHub security skills for code scanning, secret scanning, pull request review, dependency triage, and secure coding workflows.
Blog
PR reviews are no longer enough for modern GitHub security. Code, AI-generated changes, dependencies, secrets, CI logs, and runtime signals are growing too fast. The next shift-left model is continuous security monitoring across the full software path.
Blog
The Miasma worm reportedly led GitHub to disable 73 repositories across four Microsoft organizations. The campaign shows how compromised maintainer identity, CI trust, repository configuration, and AI coding agents can become one self-replicating supply chain.
Guide
Reusable security-team workflows for Antigravity CLI, GitHub Copilot CLI, Claude Code, and OpenAI Codex, including secure code review, dependency triage, CI/CD audit, sandboxed remediation, and agent governance.
Guide
A security-focused comparison of Claude Code, OpenAI Codex, GitHub Copilot CLI, Antigravity CLI, and Cursor for secure code review, vulnerability remediation, AppSec workflows, and enterprise guardrails.
Role Hub
AppSec-focused AI security guidance for secure coding assistants, AI code review, GitHub security, dependency triage, and CI/CD guardrails.
Checklist
Downloadable Markdown checklist for secure rollout of Codex, Claude Code, GitHub Copilot, Cursor, Antigravity CLI, and similar assistants.
Checklist
Downloadable Markdown checklist for secure coding assistants, AI code review, GitHub security, dependency triage, CI/CD guardrails, and supply chain risk.
Comparison
Compare Claude Code, OpenAI Codex, GitHub Copilot, Antigravity CLI, and Cursor for secure code review, AppSec remediation, dependency triage, and security workflows.
Tool
Free cybersecurity tools and HackWednesday resources for AI readiness, vulnerability triage, password security, GitHub security, and incident response.
Hub
Practical AI security skills for Splunk, Wiz, Palo Alto Networks, CrowdStrike, Microsoft Sentinel, Okta, GitHub, Trivy, and LiteLLM.
Topic
Software supply chain security coverage for packages, CI/CD, GitHub, scanners, SBOMs, and dependency attacks.
Blog
Vercel confirmed unauthorized access to certain internal systems while hackers claimed to be selling stolen data. Security teams should avoid panic, but immediately review activity logs, rotate exposed environment variables, harden sensitive variables, and check GitHub, npm, and deployment tokens.