Aggregator
某省移动网络安全技能竞赛决赛 个人赛第一名wp
Data Pipeline Challenges of Privacy-Preserving Federated Learning
ASD’s ACSC, CISA, and US and International Partners Release Guidance on Choosing Secure and Verifiable Technologies
Today, CISA—in partnership with the Australian Signals Directorate Australian Cyber Security Centre (ASD ACSC), and other international partners—released updates to a Secure by Design Alert, Choosing Secure and Verifiable Technologies. Partners that provided recommendations in this alert include:
- The Canadian Centre for Cyber Security (CCCS).
- United Kingdom’s National Cyber Security Centre (NCSC-UK).
- New Zealand’s National Cyber Security Centre (NCSC-NZ).
- Republic of Korea’s National Intelligence Service (NIS) and NIS’ National Cyber Security Centre (NCSC).
Cyber threats to user privacy and data are growing, requiring customers to evaluate their processes for acquiring products and services from technology manufacturers. Proactive integration of security mitigations into the procurement process can assist in managing risks present within the technology supply chain and reduce costs for organizations. This guidance aids procuring organizations and manufacturers of digital products and services in choosing and developing technology that is secure by design. This is an update to previously released guidance (Secure by Design Choosing Secure and Verifiable Technologies).
CISA and partners encourage all organizations to read the guidance to assist with making secure and informed choices when procuring digital products and services. Software manufacturers are also encouraged to incorporate the secure by design principles and practices found in the guidance. To learn more about secure by design principles and practices, visit CISA’s Secure by Design webpage.
Cisco Releases Security Updates for NX-OS Software
Cisco released security updates to address a vulnerability in Cisco NX-OS software. A cyber threat actor could exploit this vulnerability to take control of an affected system.
CISA encourages users and administrators to review the following advisory and apply the necessary updates:
CISA Releases Two Industrial Control Systems Advisories
CISA released two Industrial Control Systems (ICS) advisories on December 5, 2024. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.
- ICSA-24-340-01 AutomationDirect C-More EA9 Programming Software
- ICSA-24-340-02 Planet Technology Planet WGS-804HPT
CISA encourages users and administrators to review newly released ICS advisories for technical details and mitigations.
3 NIST Researchers Receive Presidential Rank Awards
网络钓鱼电子邮件越来越多地使用 SVG 附件来逃避检测
全球酒业巨头宣告破产,百年伏特加遭勒索攻击重创
真•软件管家!微软商店现在可以更新通过外部安装的软件 即非商店软件也能更新
CVE-2015-5134 | Adobe Flash Player 11.2.202.491/18.0.0.209 use after free (APSB15-19 / EDB-37852)
Russian Hackers Exploit Rival Attackers' Infrastructure for Espionage
CVE-2006-4516 | FreeBSD 6.0 ptrace PT_LWPINFO denial of service (EDB-2524 / XFDB-29476)
Any good ways to learn coding
SurePath AI Discover classifies AI use by intent and detects sensitive data violations
SurePath AI launched SurePath AI Discover, a new offering that provides visibility into a company’s employee use of public AI services. By classifying AI use by intent and identifying sensitive data violations, companies can better understand the volume, use case, and risk of AI use across their organization. “Our launch of the GenAI discovery program creates a first-in-industry solution for our launch partners,” said Jim Melton, VP of Alliance at SurePath AI. “We are excited … More →
The post SurePath AI Discover classifies AI use by intent and detects sensitive data violations appeared first on Help Net Security.