× Want to read this newsletter every week?! × 👋  Join FAUN
 
DevSecOps Weekly Newsletter, Zeno. Curated DevSecOps news, tutorials, tools and more!
🌐 View in your browser   |  ✍️ Publish on FAUN   |  🦄 Become a sponsor
 
Last week's must-read news and stories from the DevSecOps community
Zeno
 
 
👨‍💻👩‍💻 Humans Behind Code
 
faun.dev faun.dev
 
Jeronimo Irazabal, immudb Co-Founder, the Vision & the Fascination of Immutable Data
 
 
This week in Humans Behind Code, we're happy to have Jeronimo Irazabal!

Jeronimo Irazabal is the Chief Architect & Co-Founder of immudb , and Open Source Immutable Database.

Read the interview to discover more about the Human and the Code!
 
 
👉Are you the developer/founder of an Open Source project? Apply here and get featured on Humans Behind Code.
 
🔗 Stories, Tutorials & Articles
 
techmindfactory.com techmindfactory.com
 
Improve the security of Azure environment and DevOps platforms
 
 
This article presents how to monitor the security posture of Azure cloud environments and DevOps platforms
 
 
cloud.google.com cloud.google.com
 
Automating security operations and managing it as code
 
 
According to a prediction from Google Cloud experts, by 2025, 90% of security operations workflows will be automated and managed as code. The prediction is based on the current challenges faced by organizations in managing security risk across modern technology environments, including a lack of funding, resourcing, skills, and applicable solutions, as well as an increase in data volume, alert fatigue, financial costs, and complexity.

To address these challenges, organizations are turning to automation and managed services, and shifting to security engineering over operations in order to manage risk at scale.

Google has developed the Autonomic Security Operations (ASO) framework as a holistic approach to modernizing people, processes, and technologies, with the goal of enabling organizations to adopt a cloud-scale engineering approach to threat management.
 
 
auth0.com auth0.com
 
Shhhh... Kubernetes Secrets Are Not Really Secret!
 
 
Learn how to setup secure secrets on Kubernetes using Sealed Secrets, External Secrets Operator, and Secrets Store CSI driver.
 
 
cloud.google.com cloud.google.com
 
Auditing GKE Clusters across the entire organization
 
 
GKE Policy Automation is a tool for automating the checking of GKE clusters across an organization.

It comes with a library of policies based on best practices and recommendations from Google, and can be run manually or continuously for automated verification. It uses the Kubernetes Engine API to gather data from the clusters, and checks it against the set of policies. Results can be output in the console or saved to Cloud Storage or Pub/Sub.

It can also integrate with Google's Security Command Center to allow for easier analysis and remediation of non-compliant clusters.
 
 
www.csoonline.com www.csoonline.com
 
Researchers show techniques for malware persistence on F5 and Citrix load balancers
 
 
Tests show that deploying malware in a persistent manner on load balancer firmware is within reach of less sophisticated attackers.
 
 
 
📺 Quick Hits
 
 
GitHub brings free secret scanning to all public repos.
 
 
Qualys launched new security and compliance features for Oracle Cloud Infrastructure (OCI). The organization’s security platform was further integrated into OCI through the Vulnerability Scanning Service (VSS).
 
 
Malicious packages that download ransomware binaries written in Golang were found in PyPI and NPM.
 
 
⭐ Supporters
 
faun.dev faun.dev
 
Join Humans Behind Code
 
 
👉 If you're a Developer or a maintainer of a widely adopted Open Source project and you think it's worth talking about it and your experiences in building it, join Humans Behind Code and get interviewed and published on faun.dev!
 
 
👉 Spread the word and help developers find you by promoting your projects on FAUN. Get in touch for more information.
 
🛍️ Swag, Deals, And Offers
 
 
Kubernetes Mug - One container ain't enough
 
 
"My Code, My Rules" Mousepad
 

❤️ Get a 20% exclusive discount on all our swag (with free shipping) when you use the code "THANKSFAUN".

 
📚 Book picks
 
www.amazon.com www.amazon.com
 
Multi-Cloud Architecture and Governance
 
 
Leverage Azure, AWS, GCP, and VMware vSphere to build effective multi-cloud solutions.

What you will learn:
  • Get to grips with the core functions of multiple cloud platforms
  • Deploy, automate, and secure different cloud solutions
  • Design network strategy and get to grips with identity and access management for multi-cloud
  • Design a landing zone spanning multiple cloud platforms
  • Use automation, monitoring, and management tools for multi-cloud
  • Understand multi-cloud management with the principles of BaseOps, FinOps, SecOps, and DevOps
  • Define multi-cloud security policies and use cloud security tools
  • Test, integrate, deploy, and release using multi-cloud CI/CD pipelines

 
 
 
⚙️ Tools, Apps & Software
 
github.com github.com
 
p0dalirius/Coercer
 
 
A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.
 
 
github.com github.com
 
yuvalpress/version-notifier
 
 
Version Notifier is a modern solution for the "being notified" aspect of each Techy's day-to-day work. By using it, you'll be notified for any new global repository release you choose, directly to your Slack / Telegram channel.
 
 
github.com github.com
 
evilpete/flipper_toolbox
 
 
Random scripts for generating Flipper data files.
 
 
github.com github.com
 
bytedance/Elkeid
 
 
Elkeid is an open source solution that can meet the security requirements of various workloads such as hosts, containers and K8s, and serverless. It is derived from ByteDance's internal best practices.
 
 

👉 Spread the word and help developers find and follow your Open Source project by promoting it on FAUN. Get in touch for more information.

 
🤔 Did you know?
 
 
The first high-level programming language was Plankalkül, created by Konrad Zuse between 1942 and 1945.
 
 
😂 Meme of the week
 
 
 
 
❤️ Thanks for reading
 
 
👉 Never miss an issue
Join FAUN Developer Community and subscribe to our newsletter here.

👋 Keep in touch and follow us on social media:
- 💼LinkedIn
- 📝Medium
- 🐦Twitter
- 👥Facebook
- 📰Reddit
- 📸Instagram

👌 Was this newsletter helpful?
We'd really appreciate it if you could share it with your friends! You can also donate to help us keep this newsletter going.

ℹ️ Have a question or feedback?
Feel free to reach out to us at community@faun.dev. We'd love to hear from you!

🤩 Want to sponsor our newsletter?
Reach out to us at sponsors@faun.dev and we'll get back to you as soon as possible.