Log inSign up
Log inSign up
ActiveState
14.7K posts
ActiveState profile banner
@ActiveState

ActiveState

@ActiveState
ActiveState enables DevOps, InfoSec, and Development teams to improve their security posture while simultaneously increasing productivity and innovation.
Vancouver, BC
activestate.com
Joined November 2008
1,620 Following
3,998 Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·US TIDA·Ads Info·© 2026 X Corp.
  • @ActiveState
    ActiveState
    @ActiveState
    Sep 26
    If a CVE lands on your team today, can you answer “are we exposed” in minutes, not days? A governed source with a contractual SLA (5 business days for critical, clock starting at upstream fix availability) turns that into a scheduled event instead of a fire drill. Worth
  • @ActiveState
    ActiveState
    @ActiveState
    Sep 25
    A flaw just landed on CISA’s Known Exploited Vulnerabilities catalog. The remediation clock started the day it was listed, not the day your team got around to checking. Could you answer “are we exposed” right now, in minutes? Most teams can’t. That’s not a scanning problem.
    CISA Just Turned Ingestion Governance Into a Federal Deadline
    From medium.com
  • @ActiveState
    ActiveState
    @ActiveState
    Sep 25
    319 of 639 packages carried it in May. 111 days dormant. Then it resurfaced in four new packages, straight past npm's own malware scanner. Same week: CVE remediation across 21 major vendors got slower, not faster. Link below for the full article
    1
  • @ActiveState
    ActiveState
    @ActiveState
    Sep 22
    Famous last words right before production goes down on a Friday at 5PM 🙃
    00:00
  • @ActiveState
    ActiveState
    @ActiveState
    Sep 22
    Anthropic, Google, and OpenAI's coding-agent tooling has critical flaws sitting in the permission and sandboxing code wrapped around it, not in the models themselves. Jonny Rivera on why the wrapper is the attack surface, not the agent:
    The Anthropic, Google, and OpenAI Coding-Agent Flaws Were in the Permission Layer
    From medium.com
    1