The web is changing, and we must adapt our threat model and our mitigations across the board to prepare for future attacks.
2. The security scanner that cried wolf
Keep your eyes focused on the results of your container scanners and use additional tools besides trivy to scan for vulnerabilities in your workloads.
While we don’t recommend that you dig into the depths of crypto, a software engineer should understand how crypto works at a high-level.
Use static analysis tools against all the things, shell scripts included!
DevOps is here to stay – let’s embrace DevOps + security is standard operating procedure.