Varun Sharma

92 posts

Varun Sharma banner
Varun Sharma

Varun Sharma

@varunsh_coder

CEO & Founder, StepSecurity @step_security, ex-MSFT

Seattle, Washington Katılım Nisan 2022
56 Takip Edilen48 Takipçiler
Varun Sharma retweetledi
StepSecurity
StepSecurity@step_security·
🚨 A Mini Shai-Hulud has appeared. Your npm install just handed your credentials to an attacker. We detected a new supply chain campaign targeting SAP developer packages. It downloads Bun (not Node) to run an 11 MB obfuscated payload. Victim repos are being created on GitHub as we speak. Full breakdown: stepsecurity.io/blog/a-mini-sh…
English
0
19
24
1.4K
Varun Sharma retweetledi
StepSecurity
StepSecurity@step_security·
🚨 Last week, North Korean state actors hijacked axios on npm. 300M+ weekly downloads. Turned into a remote access trojan. We just published the behind-the-scenes story of how we detected it, fought the threat actor in real time, and helped the community respond.
English
3
11
38
4.5K
Varun Sharma retweetledi
StepSecurity
StepSecurity@step_security·
Live Analysis of Backdoored XZ Utils Build Process with StepSecurity Harden-Runner 📅Date & Time: May 22nd 2024, 9:30 am Pacific Time ➡️Register here: linkedin.com/events/7184238…
English
1
1
1
227
Varun Sharma retweetledi
OpenSSF
OpenSSF@openssf·
We're thrilled to announce @step_security joining OpenSSF! 👏 StepSecurity offers a platform that secures CI/CD infrastructure and pipelines against security attacks, trusted by over 2700 open source projects that use GitHub Actions. 💻
OpenSSF tweet media
English
0
5
12
686
Varun Sharma retweetledi
StepSecurity
StepSecurity@step_security·
🎉We are thrilled to announce that StepSecurity has secured $3 million in seed #funding to protect CI/CD pipelines for open-source communities and enterprises! stepsecurity.io/blog/stepsecur…
English
0
3
9
296
Varun Sharma retweetledi
StepSecurity
StepSecurity@step_security·
🚀The @openssf (Open Source Security Foundation) recently announced StepSecurity as one of its newest members alongside leading technology, aerospace, and security firms!
English
1
2
3
168
Varun Sharma retweetledi
Adnan Khan
Adnan Khan@adnanthekhan·
Read how I used a custom scanner to discover a GitHub Actions vulnerability hiding in plain sight for 3 years in a Google OSS repository and earned a $7,500 💰 #bugbounty! adnanthekhan.com/2024/04/15/an-…
English
1
31
79
6.1K
Varun Sharma retweetledi
StepSecurity
StepSecurity@step_security·
Yesterday security researchers detailed how a CI/CD supply chain vulnerability could have compromised the Bazel project. Check out this case study on how the Bazel Project defended against this CI/CD Supply Chain Vulnerability with StepSecurity. stepsecurity.io/case-studies/b…
StepSecurity tweet media
English
0
2
5
461
Abhishek Arya
Abhishek Arya@infernosec·
This supply chain attack on @PyTorch shows an insecure use of custom/self-hosted github runners and insecure default config ("Require approval for first-time contributors"; anyone can submit a typo fix) gone wrong together. @GitHubSecurity - have you considered changing default to "Require approval for all outside collaborators" for custom runner usecases? - johnstawinski.com/2024/01/11/pla…
English
3
8
25
3.8K
Mark Wolfe 🐺
Mark Wolfe 🐺@wolfeidau·
Been looking for a way to update pinned github actions I am using in my workflows as per hardening recommendations #using-third-party-actions" target="_blank" rel="nofollow noopener">docs.github.com/en/actions/sec… Sick of dependbot updates, just want "upgrade a pipeline". Building on existing libs, I wrote. github.com/wolfeidau/gith… #github #security
English
3
0
3
319
Varun Sharma retweetledi
StepSecurity
StepSecurity@step_security·
🎉Thrilled to see @Intel’s dffml project leveraging StepSecurity to automate #GitHubActions Security best practices. The automated pull request modified 25 source code files and was merged by the Intel developer without any changes! #CICD #CyberSecurity
StepSecurity tweet mediaStepSecurity tweet mediaStepSecurity tweet mediaStepSecurity tweet media
English
1
2
3
325
Varun Sharma retweetledi
StepSecurity
StepSecurity@step_security·
🚀 Kickstarting 2024 on a high with another big name using the StepSecurity #GitHub Actions Security Automation platform! @GetPermify is a Google Zanzibar based open-source authorization service for creating and managing granular permissions in your applications and services.
StepSecurity tweet mediaStepSecurity tweet mediaStepSecurity tweet mediaStepSecurity tweet media
English
1
2
3
127
Varun Sharma retweetledi
StepSecurity
StepSecurity@step_security·
Do you find it difficult to implement and track all the GitHub Actions security best practices? If yes, you need to check out the latest StepSecurity blog post that has a checklist of all the best practices you should be adhering to. stepsecurity.io/blog/github-ac…
English
1
2
4
244
Varun Sharma retweetledi
StepSecurity
StepSecurity@step_security·
📢 Press release of our GitHub Actions Security Platform! While many of you are already familiar with its prowess — given its adoption by over 1,200 open-source projects and numerous enterprises — today, we formally put it in the spotlight. prnewswire.com/news-releases/…
English
0
3
10
2K
Varun Sharma retweetledi
StepSecurity
StepSecurity@step_security·
🔐Excited to announce 'GitHub Actions Goat' - an educational project that simulates security attacks and vulnerabilities in a CI/CD environment and shows how to defend against such attacks. All you need to follow the tutorials is your GitHub Account! stepsecurity.io/blog/github-ac…
English
0
2
4
397