<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #DevSecOps</title><description>Cybersecurity articles tagged #DevSecOps on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Cordyceps: Defending Against Malicious Pull Requests in CI/CD</title><link>https://runtimerebel.com/blog/cordyceps-defending-against-malicious-pull-requests-in-ci-cd</link><guid isPermaLink="true">https://runtimerebel.com/blog/cordyceps-defending-against-malicious-pull-requests-in-ci-cd</guid><description>The Cordyceps campaign highlights critical CI/CD vulnerabilities in GitHub Actions, targeting high-profile projects like Apache Doris and Cloudflare Workers SDK.</description><pubDate>Wed, 24 Jun 2026 09:23:01 GMT</pubDate><category>GitHub Actions</category><category>CI CD Security</category><category>Supply Chain Attack</category><category>DevSecOps</category><category>Cordyceps</category></item><item><title>Novo Nordisk Breach: Securing Secrets in GitHub Development Pipelines</title><link>https://runtimerebel.com/blog/novo-nordisk-breach-securing-secrets-in-github-development-pipelines</link><guid isPermaLink="true">https://runtimerebel.com/blog/novo-nordisk-breach-securing-secrets-in-github-development-pipelines</guid><description>Analysis of the Novo Nordisk GitHub token leak and why secrets management must transition from static tools to identity-based security frameworks.</description><pubDate>Fri, 19 Jun 2026 09:48:31 GMT</pubDate><category>GitHub</category><category>Secrets Management</category><category>Novo Nordisk</category><category>DevSecOps</category><category>CI CD Security</category></item><item><title>GitHub Supply Chain Disruption: Microsoft Repos Abused to Host Malware</title><link>https://runtimerebel.com/blog/github-supply-chain-disruption-microsoft-repos-abused-to-host-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-supply-chain-disruption-microsoft-repos-abused-to-host-malware</guid><description>GitHub recently disabled 73 official Microsoft repositories after they were targeted in a massive campaign pushing password-stealing malware to developers.</description><pubDate>Tue, 09 Jun 2026 17:00:46 GMT</pubDate><category>GitHub</category><category>Microsoft</category><category>Supply Chain Attack</category><category>Infostealer</category><category>DevSecOps</category></item><item><title>Boost Security Expands SDLC Defense via Strategic Acquisitions</title><link>https://runtimerebel.com/blog/boost-security-expands-sdlc-defense-via-strategic-acquisitions</link><guid isPermaLink="true">https://runtimerebel.com/blog/boost-security-expands-sdlc-defense-via-strategic-acquisitions</guid><description>Boost Security secures $4 million and acquires SecureIQx and Korbit.ai to streamline automated governance and security within the development lifecycle.</description><pubDate>Thu, 07 May 2026 16:42:57 GMT</pubDate><category>Boost Security</category><category>SDLC</category><category>DevSecOps</category><category>Supply Chain Security</category><category>Automated Governance</category></item><item><title>SAP NPM Supply Chain Attack: Analyzing the Mini Shai-Hulud Campaign</title><link>https://runtimerebel.com/blog/sap-npm-supply-chain-attack-analyzing-the-mini-shai-hulud-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/sap-npm-supply-chain-attack-analyzing-the-mini-shai-hulud-campaign</guid><description>Security researchers identified a malicious supply chain attack targeting SAP via NPM packages using the Bun runtime to evade traditional EDR detection.</description><pubDate>Thu, 30 Apr 2026 16:38:51 GMT</pubDate><category>SAP</category><category>NPM Security</category><category>Mini Shai Hulud</category><category>Dependency Confusion</category><category>Bun Runtime</category><category>DevSecOps</category></item><item><title>Checkmarx GitHub Repository Data Leaked Following Supply Chain Attack</title><link>https://runtimerebel.com/blog/checkmarx-github-repository-data-leaked-following-supply-chain-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/checkmarx-github-repository-data-leaked-following-supply-chain-attack</guid><description>Checkmarx confirms internal GitHub repository data was published on the dark web following a March 2026 supply chain incident. Learn the impact and TTPs.</description><pubDate>Mon, 27 Apr 2026 16:37:34 GMT</pubDate><category>Checkmarx</category><category>GitHub</category><category>Supply Chain Attack</category><category>Data Leak</category><category>DevSecOps</category></item><item><title>Anthropic Claude Code Source Code Leaked via NPM Registry</title><link>https://runtimerebel.com/blog/anthropic-claude-code-source-code-leaked-via-npm-registry</link><guid isPermaLink="true">https://runtimerebel.com/blog/anthropic-claude-code-source-code-leaked-via-npm-registry</guid><description>Anthropic accidentally exposed proprietary source code for its Claude Code CLI tool on the public npm registry. Analyze the technical impact and risks.</description><pubDate>Wed, 01 Apr 2026 00:43:28 GMT</pubDate><category>Anthropic</category><category>Claude Code</category><category>NPM</category><category>Source Code Leak</category><category>DevSecOps</category></item><item><title>GitGuardian 2026 Report: Analyzing the 34% Surge in Secrets Sprawl</title><link>https://runtimerebel.com/blog/gitguardian-2026-report-analyzing-the-34-surge-in-secrets-sprawl</link><guid isPermaLink="true">https://runtimerebel.com/blog/gitguardian-2026-report-analyzing-the-34-surge-in-secrets-sprawl</guid><description>GitGuardian&apos;s 2026 report reveals 29 million leaked secrets on GitHub in 2025. Learn how AI and hardcoded credentials impact enterprise security posture.</description><pubDate>Mon, 30 Mar 2026 12:26:38 GMT</pubDate><category>GitGuardian</category><category>Secrets Sprawl</category><category>GitHub</category><category>DevSecOps</category><category>Hard Coded Credentials</category></item><item><title>Betterleaks: A New Open-Source Tool for Detecting Secrets in Git</title><link>https://runtimerebel.com/blog/betterleaks-a-new-open-source-tool-for-detecting-secrets-in-git</link><guid isPermaLink="true">https://runtimerebel.com/blog/betterleaks-a-new-open-source-tool-for-detecting-secrets-in-git</guid><description>Betterleaks is a new open-source secrets scanner designed to identify hardcoded credentials and sensitive data across directories and Git repositories.</description><pubDate>Sun, 15 Mar 2026 16:11:15 GMT</pubDate><category>Betterleaks</category><category>Gitleaks</category><category>Secrets Scanning</category><category>DevSecOps</category><category>Credential Leakage</category></item><item><title>Secure-by-Design: Mitigating Enterprise Risk &amp; Human Error</title><link>https://runtimerebel.com/blog/secure-by-design-mitigating-enterprise-risk-human-error</link><guid isPermaLink="true">https://runtimerebel.com/blog/secure-by-design-mitigating-enterprise-risk-human-error</guid><description>Leverage secure-by-design principles from software development to address non-technical enterprise risks, including governance gaps and human error, enhancing…</description><pubDate>Thu, 05 Mar 2026 20:17:03 GMT</pubDate><category>Secure By Design</category><category>Enterprise Risk Management</category><category>Human Error</category><category>Cybersecurity Governance</category><category>DevSecOps</category><category>Risk Mitigation</category></item><item><title>AI-Driven Development and the Crisis of Firewall Rule Backlogs</title><link>https://runtimerebel.com/blog/ai-driven-development-and-the-crisis-of-firewall-rule-backlogs</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-driven-development-and-the-crisis-of-firewall-rule-backlogs</guid><description>Examine how AI-accelerated coding creates network security bottlenecks and why manual firewall management fails in modern DevSecOps environments.</description><pubDate>Tue, 03 Mar 2026 04:38:38 GMT</pubDate><category>Ai Driven Development</category><category>Firewall Management</category><category>Network Security</category><category>DevSecOps</category><category>Automation</category></item><item><title>Claude Code Security Analysis: Assessing AI CLI Assistant Risks</title><link>https://runtimerebel.com/blog/claude-code-security-analysis-assessing-ai-cli-assistant-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/claude-code-security-analysis-assessing-ai-cli-assistant-risks</guid><description>Technical analysis of Anthropic&apos;s Claude Code CLI tool, evaluating its impact on application security and potential for introducing code vulnerabilities.</description><pubDate>Fri, 27 Feb 2026 16:17:21 GMT</pubDate><category>Anthropic</category><category>Claude Code</category><category>AI Security</category><category>DevSecOps</category><category>Secure Coding</category></item><item><title>Anthropic Claude Code Security: Automated Static Analysis and Remediation Preview</title><link>https://runtimerebel.com/blog/anthropic-claude-code-security-automated-static-analysis-and-remediation-preview</link><guid isPermaLink="true">https://runtimerebel.com/blog/anthropic-claude-code-security-automated-static-analysis-and-remediation-preview</guid><description>Anthropic has introduced Claude Code Security, a research-preview tool designed to perform static analysis for vulnerability detection and automated patch generation…</description><pubDate>Mon, 23 Feb 2026 04:06:17 GMT</pubDate><category>AI</category><category>SDLC</category><category>SAST</category><category>Vulnerability Management</category><category>DevSecOps</category></item></channel></rss>