Aggregator
安全动态回顾|国家计算机病毒应急处理中心监测发现13款违规移动应用 起亚经销商平台被发现存在严重漏洞
往期回顾:
Recall 2.0: Microsoft дает второй шанс ИИ-помощнику, в которого никто не верил
三分之二的美国科技行业从业者有兴趣加入工会
Анализ прошивки дрона DJI Mavic 3: часть 1
FreeBuf早报 | WordPress与托管商WP Engine决裂;伊朗黑客被指控影响选举
欣望江山千里秀,欢颂祖国万年春 | 庆祖国75周年华诞
Could APIs be the undoing of AI?
Application programming interfaces (APIs) are essential to how generative AI (GenAI) functions with agents (e.g., calling upon them for data). But the combination of API and LLM issues coupled with rapid rollouts is likely to see numerous organizations having to combat security failings. While GenAI is susceptible to the usual security issues associated with APIs such as authentication, authorization and data exposure, there are also AI-specific concerns which have been well-documented by the OWASP Project … More →
The post Could APIs be the undoing of AI? appeared first on Help Net Security.
SCCMSecrets: Open-source SCCM policies exploitation tool
SCCMSecrets is an open-source tool that exploits SCCM policies, offering more than just NAA credential extraction. SCCM policies are a key target for attackers in Active Directory environments, as they can expose sensitive technical information, including account credentials. Attackers may retrieve these credentials by impersonating a registered device with authenticated access or, in some cases, even from an unauthenticated position by exploiting misconfigurations in policy distribution. SCCMSecrets provides a thorough approach to identifying and exploiting … More →
The post SCCMSecrets: Open-source SCCM policies exploitation tool appeared first on Help Net Security.
SCTF 2024|W&M打破屏障,竞逐夺冠!
SCTF 2024|W&M打破屏障,竞逐夺冠!
SCTF 2024|W&M打破屏障,竞逐夺冠!
Open source maintainers: Key to software health and security
Open source has become the foundation of modern application development, with up to 98% of applications incorporating open-source components and open-source code accounting for 70% or more of the typical application. In this Help Net Security video, Donald Fischer, CEO at Tidelift, discusses the 2024 State of the Open Source Maintainer report, which provides insights into the work and mindset of open source maintainers. The study showed that paid maintainers are 55% more likely than … More →
The post Open source maintainers: Key to software health and security appeared first on Help Net Security.
BuckeyeCTF 2024
Date: Sept. 27, 2024, 8 p.m. — 29 Sept. 2024, 20:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://pwnoh.io/
Rating weight: 50.91
Event organizers: Buckeye Bureau of BOF
SCTF 2024
Date: Sept. 28, 2024, 1 a.m. — 30 Sept. 2024, 01:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://adworld.xctf.org.cn/contest/assess?hash=4124a446-65a9-11ef-a39a-000c297261bb
Rating weight: 37.00
Event organizers: Syclover
JVN: 複数のセイコーエプソン製品のWeb Configにおける初期パスワードに関する脆弱性
会议预告 | 第一届网络空间安全学术会议通知(第一轮)
Telegram转向,将配合执法部门的合理要求
国庆值守安排 | 为祖国庆生,与安全同行
Businesses turn to private AI for enhanced security and data management
In this Help Net Security interview, Joe Baguley, CTO EMEA at Broadcom, shares insights on private AI and its significance in data security. He explains how it helps organizations maintain control over sensitive information while addressing the complexities of compliance and data privacy. Baguley also discusses the sectors leading the way in private AI adoption and the risks that come with it. What are the key technological components that make AI “private”? Which industries or … More →
The post Businesses turn to private AI for enhanced security and data management appeared first on Help Net Security.