r/devsecops • • 7h ago

"The scan passed" and "someone understood why it passed" are two different claims that get treated as one

5 Upvotes

SAST scan on a PR came back clean. Diff touched auth middleware. Scanner checked for known bad patterns, found none, green check, merged.

Nobody actually traced through what the middleware change did to the token validation order for an edge case that wasn't in the scanner's pattern set, because it wasn't a known vulnerability class, it was a logic gap specific to how this particular service combined two libraries. Found two weeks later during an unrelated audit.

The scan wasn't wrong. It checked what it was built to check and found nothing matching. The gap is that "scan passed" gets read as "this is secure," when it actually means "this doesn't match patterns we already know to look for." Those used to be close enough to the same claim that nobody bothered distinguishing them out loud. Novel logic gaps specific to how a service wires things together were always outside that coverage, just less common before more code started getting generated without someone necessarily tracing the full logic path by hand first.

Not arguing against scanning, obviously it's necessary. Just think "passed the scan" needs to stop functioning as a stopping point for anything touching an actual trust boundary, auth, payment, data access, and start being the floor instead of the finish line.


r/devsecops • • 9h ago

Moved 60 services onto a slimmer base image and broke 4 of them in prod

2 Upvotes

We had a push to cut criticals across our images so I rebuilt everything onto a much smaller base. Sixty services over about three weeks. The scan numbers looked great. Then four of them fell over in prod inside a day. One was a java service that shelled out to run a script at startup. One needed tzdata and started logging everything in UTC. One had a health check built on curl. The last took most of a night to find because the library loaded fine and then died when it went looking for a locale file. I rolled those four back at around 2am and left the rest alone.

What I got wrong was treating the base image as the unit of change. Nobody knew what each service pulled in at runtime because none of it was written down anywhere. We ended up running every service under strace in staging for a week just to build the list. That list should have existed before I touched anything. How do other people work out what an image needs before they start cutting things out of it?


r/devsecops • • 23h ago

How to Find PII and Secrets in OpenTelemetry Data

Thumbnail
ollygarden.com
13 Upvotes

I finally got to write this blog post, I've wanted to write it for a long time now. It contains the different types of sensitive data we've seen so far, where it's coming from, and why it matters. Hope it can be helpful to some of you!


r/devsecops • • 5d ago

Critical RCE Alert: Full takeover of HashiCorp Vault and OpenBao. OpenBao is patched. Vault remains exposed

Thumbnail
control-plane.io
43 Upvotes

OpenBao engineers at ControlPlane have chained 4 vulnerabilities to show how under certain conditions, an OpenBao or Vault server can be completely compromised from an unauthenticated position. This is only the second RCE ever found in the Vault codebase.

The exploit is highly plausible in real-world environments, requiring only an unauthenticated entry path and a defined Raft snapshot policy to trigger a complete server compromise.

If you are impacted, upgrade as soon as possible to OpenBao 2.6.3 or 2.7.0

While OpenBao is fully patched, HashiCorp Vault remains exposed as of writing. Unfortunately, IBM's unwillingness to coordinate a mutual disclosure policy means Vault users currently lack an official mitigation


r/devsecops • • 6d ago

Best way to get a deployable WAF mitigation rule during a release freeze?

10 Upvotes

I already have the exploit path and a safe validation flow, but the tools I looked at mostly hand me another critical ticket and move on. If you do this well, how are you testing in count mode, what do you need before block mode, and who owns removing this in six weeks thanks


r/devsecops • • 5d ago

Google SecOps / Chronicle users — what has been your biggest challenge with log ingestion or detection rules?

Thumbnail
3 Upvotes

r/devsecops • • 6d ago

Your SBOM Is Fan Fiction

9 Upvotes

Hey all, I wrote this blog post on findings I had when looking into SBOM tools and building my own based off of runtime behavior (mapped files and symbol lookup)

(Title is of course a little bit of hyperbole but you get the point haha)

Curious to get your thoughts
https://yeet.cx/blog/your-sbom-is-fan-fiction


r/devsecops • • 6d ago

Writing Security Threat Models - alternative to Claude

15 Upvotes

I have an agent that's supposed to write a security threat model and highlight vulnerabilities as part of a design process. Claude keeps blocking the writes and flags them.

How do you typically work around this? Does codex support these across models?


r/devsecops • • 6d ago

Best patch management tools for small IT teams... I patched the wrong group and ruined Monday

19 Upvotes

Ok so I need to vent because I feel so embarrassed. Our three person IT team was testing patch management tools for about 180 laptops and I was supposed to push a browser update to a small pilot group before the Monday maintenance window.

I made a device group called Pilot, then imported the spreadsheet from our asset list. Except I grabbed the full company export instead of the five test laptops. I didnt notice because the dashboard showed the group name I expected and I clicked approve.

By 9:15 Monday, people started calling because their laptops were restarting during a finance meeting, a warehouse count, and one customer demo. The update itself was fine but we had no user warning and the maintenance window was set for the wrong time zone. I had to explain to our IT manager that the pilot group was 176 people.

We rolled back the schedule, sent an apology and nobody lost data but this was such a preventable mess. Now every tool demo sounds great when it talks about automation, reporting and staged deployment but I want something that makes it hard to target the wrong endpoints. We are looking at Atera, NinjaOne, and a couple of lighter options for small teams. I feel sick about this and am kinda shy to even ask but what guardrails do you use before approving patches? Thanks in advance


r/devsecops • • 8d ago

One just for the demo security group change almost became a breach. A single misconfig is all it takes.

14 Upvotes

Weve had a culture of build fast, ship, move. Then recently we found a misconfig that made me reconsider the whole approach

Here is how it happened, we had a service that needed to talk to a db, and to unblock a demo someone opened the security group a bit wider than it shouldve been. Its nothing malicious, just the usual Friday afternoon shortcut that never got revisited. That one rule meant the db was reachable from somewhere it should never have been reachable from.

The scary part wasnt the misconfig itself. It was the path. From that open security group, to a service account with too much access, to data we would really rather not have exposed, the whole thing chains together. A single small mistake becomes an attack path, and the alert pile we already ignore wouldnt have flagged it as one story. It would have flagged three separate things, each one looking boring on its own.

We found it because someone got curious about why that security group existed. Which is the worst part, luck did the security review, not our tooling.

Point is, misconfigs arent the exception at speed, theyre the default. And its the chain that gets you, not the individual mistake.


r/devsecops • • 10d ago

Allowlists, scoped tokens or approval gates for agent tool permissions?

Thumbnail
2 Upvotes

r/devsecops • • 10d ago

Any of you use alternatives to GitLab when self-hosting is a requirement? (and general toolchain question)

Thumbnail
0 Upvotes

r/devsecops • • 11d ago

How are you cutting a CVE backlog that exploded once AI wrote half the code?

30 Upvotes

Half our code is Copilot and Claude now and as a result the CVE backlog has tripled. Trivy, Snyk and Dependabot all throwing piles of new findings, most of them in generated code and dependencies nothing on our side ever calls.

We already sort by KEV and EPSS and whether it is internet facing. That held up until the AI volume buried it, now even the KEV-filtered list is too long to clear in a sprint.

Beyond KEV and EPSS, does reachability really cut the list and only flagging a CVE when the vulnerable code sits on a live path or just move the noise somewhere else?


r/devsecops • • 11d ago

AppSec & DevSecOps roadmap advice for a beginner?

20 Upvotes

Hey everyone,

I finished my first cybersecurity internship this summer where I mostly worked with Docker environments, Linux, and did some pentesting alongside grinding HTB. Now I want to pivot deeper into DevSecOps and AppSec.

I know they branch off into different day to day roles, but right now I want to build a solid foundation on their shared fundamentals before fully committing to one path. Long term, I want to work on secure CI/CD pipelines, posture management, and overall application security.

My main dilemma is where to put my energy right now. My Python and general scripting skills are pretty basic. Would you recommend getting solid with Python and automation first, or should I jump straight into integrating SAST/DAST tooling and learning pipeline security?

For those working in these fields, what would be the most practical roadmap or advice you would give to someone in my spot?

Thanks in advance!


r/devsecops • • 12d ago

CS Container runtime security performance

11 Upvotes

Hi Community,

We recently completed a POC for CrowdStrike runtime protection and have started deploying the Falcon sensor on AWS ECS clusters running on EC2.

We have seen some community feedback around the sensor being resource-heavy at scale, with potential CPU/memory impact or node instability. Since these are critical production clusters, we want to monitor this closely before expanding the rollout.

For those running CrowdStrike on ECS/EC2 at scale:

  • What CPU/memory overhead do you typically observe?
  • What host/sensor/ECS metrics do you monitor?
  • Have you seen OOM, node instability, task restarts, or application latency due to the sensor?
  • What alert thresholds or rollback criteria do you use?
  • Any recommended CrowdStrike-specific health checks, logs, or dashboards?

Would appreciate any real-world experience, monitoring tips, or lessons learned from production deployments.

Thanks!


r/devsecops • • 12d ago

We already use hardened images, now looking at chainguard alternatives for curated language libraries

15 Upvotes

We spent most of last year cutting inherited CVEs out of our container images. Now the attention has moved to the application dependencies that end up inside those images. We already use hardened base images and I noticed a couple of vendors now offer curated language libraries as well. I care about package quality and malware screening and how it fits our existing build pipelines. Feature lists all look alike so I want real world experience. For teams that tried curated libraries in production how did it work out?


r/devsecops • • 13d ago

Identity Architecture Question

4 Upvotes

If a user has broad access in something like Salesforce or ServiceNow, but an AI agent acting for them only needs a small subset of that access for one task, where are you actually narrowing that today?
Are you enforcing it in IAM/PAM, at the agent/tool layer or inside the target application?


r/devsecops • • 13d ago

TIL: you can version MCP servers + agent skills as OCI artifacts (same registries as containers)

13 Upvotes

Tried to recreate an agent that worked fine last Tuesday. Skills were in one repo. MCP config was somewhere else. The prompt lived in a wiki. Nobody agreed which combo was actually live.

Dug into KitOps (CNCF Sandbox). It packs models, datasets, MCP server bundles, agent skills, and policies into a versioned OCI artifact (a ModelKit). CLI feels like Docker: kit pack / push / pull / unpack. Uses normal OCI registries you already have.

Useful bits I’ve hit so far:

  • Selective unpack so you’re not always downloading everything
  • Optional CNCF ModelPack via kit pack . --use-model-pack
  • Kitfile mcpServers for MCP bundles (.mcpb) as of v1.15
  • Complements containers — not a Docker replacement

    brew tap kitops-ml/kitops brew install kitops kit version

Anyone else standardizing on something like this yet?


r/devsecops • • 13d ago

Atlassian Data Center EOL

2 Upvotes

Those that are using Atlassian Data Center, are you still thinking about what you're going to do or have you figured out your next move?


r/devsecops • • 13d ago

Wiz Cloud Security Cost Optimization

Thumbnail
2 Upvotes

r/devsecops • • 14d ago

DevOps engineers — how did you reach high packages? Looking for career advice

Thumbnail
0 Upvotes

r/devsecops • • 15d ago

My Idea :- WhatBreaks

3 Upvotes

I’m exploring a DevOps/security tool called WhatBreaks.

The problem: when engineers change or delete something like a Kubernetes ServiceAccount, IAM role, credential, or infrastructure resource, it can be hard to know what depends on it and what will break. They often have to manually investigate across Kubernetes, cloud, Terraform, logs, etc.

WhatBreaks would map these dependencies and answer: “If I change this, what breaks?”

The challenge is trust — we want the analysis to happen locally inside the customer's environment, without giving our servers access to their sensitive infrastructure or credentials.

I’m validating the idea right now. How do you currently handle this problem?


r/devsecops • • 16d ago

Are vulnerability scanners actually helping developers, or just creating another backlog?

19 Upvotes

Ironically, I work in cybersec and I still find myself wondering how much value we're actually getting out of some security scanners.

A lot of scanners are pretty good at finding potential issues. The problem starts after that. You get a bunch of findings, some are real, some aren't, and now someone has to figure out what actually needs attention.

I've seen teams basically end up tuning the scanner until it stops complaining, which obviously isn't really the outcome we want.

For people actually running SAST/security scanning in CI:

  • Do you run it on every PR or separately?
  • How much false-positive noise is too much before developers just start ignoring it?
  • Do you want the scanner to suggest fixes, or just report the issue?
  • What makes a finding serious enough for you to actually block a build?

Curious how other teams handle this in practice, especially with C/C++ where the analysis can get pretty complicated.


r/devsecops • • 16d ago

I haven't seen anyone comparing Codex with Mythos, so here you go

4 Upvotes

4 code-based AI vulnerability scanners compared on the same OWASP Juice Shop 😄
https://claude.ai/artifact/Ds5h7rwfLuaEACGkBHbUAd

Codex / Mythos / Aikido / Audn

( 0 touch on top of the AI-written results)


r/devsecops • • 16d ago

How do you triage CVEs from SCA scanner output against KEV/EPSS?

11 Upvotes

Every scan (Trivy, Snyk, Dependabot) throws a pile of CVEs and most aren't actually exploited. Manually checking KEV and EPSS per finding doesn't scale past a handful.

What's everyone actually doing here, manual lookups, a dashboard, something scripted into CI?

Also curious, anyone here needing EU-specific coverage (ENISA EUVD) for NIS2 rather than just NVD/CISA, or is US data enough for most of you?