# AppSec Newsletter 0029

### Links

* \[artigo\] [Three key learnings for AppSec teams from the XZ backdoor](https://semgrep.dev/blog/2024/three-key-learnings-for-appsec-teams-from-the-xz-backdoor)
    
* \[wiki\] [../../../../hacking\_methodology](https://0xxyc.gitbook.io/hacking_methodology)
    
* \[artigo\] [Passkeys – under the hood](https://research.kudelskisecurity.com/2024/03/14/passkeys-under-the-hood/)
    
* \[tutorial\] [Kubernetes Threat Detection with Kubescape, Prometheus, and Grafana](https://araji.medium.com/proactive-kubernetes-security-unlocking-threat-detection-with-kubescape-prometheus-and-grafana-ad69593998fd)
    
* 🎖️ \[repo\] [A basic guideline on implementing auth for the web](https://github.com/pilcrowOnPaper/copenhagen)
    
* \[curso\] [Securing Projects with OpenSSF Scorecard Course](https://openssf.org/training/securing-projects-with-openssf-scorecard-course/?utm_content=287036701&utm_medium=social&utm_source=linkedin&hss_channel=lcp-76521837)
    
* \[artigo\] [Securing Flutter Applications](https://8ksec.io/securing-flutter-applications/)
    

### Vagas

* [Contabilizei :: Analista de Segurança da Informação Sênior (Segurança de Produto)](https://www.linkedin.com/jobs/view/3875034877/)
    
* [Neon :: Senior DevSecOps](https://www.linkedin.com/jobs/view/3875929226/?alternateChannel=search&refId=HKEZbauYvkJlsnkzt4U7zA%3D%3D&trackingId=xdA4qPDddY1owjKL6BWMCg%3D%3D&trk=d_flagship3_search_srp_jobs)
    

### **Siga o Guia de AppSec nas redes!**

* Youtube: [**youtube.com/@GuiadeAppSec**](http://youtube.com/@GuiadeAppSec)
    
* Twitter / X: [**twitter.com/guiadeappsec**](http://twitter.com/guiadeappsec)
    
* Site: [**guiadeappsec.com.br**](http://guiadeappsec.com.br/)
