The Stack
"“These deployments rarely got the hardening a production web app would. They run with default authentication settings and sit on public IPs because someone needed to demo a flow to a stakeholder..."
"To be clear about our approach to legal matters, we have no intention to pursue action against individuals conducting or publishing their security research."
Also reveals an acquisition as it targets sensitiev workloads ahead of FedRAMP High certification
"Talk to us about how you protect your downside from potentially enabling value abstraction out of Salesforce?"
Cloudflare’s CSO: “The principle is to make exploitation harder for an attacker even when a bug exists”
"When you're trying to identify whether a payment chain connects back to a suspicious origin, relational databases choke"