cigitalgem, to random
@cigitalgem@sigmoid.social avatar

Microsoft security engineering fucks up again. I seem to recall this happening thirty years ago https://www.theregister.com/2024/06/06/microsoft_research_recall/

cigitalgem, to infosec
@cigitalgem@sigmoid.social avatar
cigitalgem, to infosec
@cigitalgem@sigmoid.social avatar
cigitalgem, to random
@cigitalgem@sigmoid.social avatar
cigitalgem, to infosec
@cigitalgem@sigmoid.social avatar
cigitalgem, to ML
@cigitalgem@sigmoid.social avatar

Re-up in preparation for Monday's talk in Bergen, Norway.

Have a listen to the episode of the Google Cloud Security Podcast, featuring me.

EP150 Taming the AI Beast: Threat Modeling for Modern AI Systems with Gary McGraw

https://berryvilleiml.com/2024/01/25/google-cloud-security-podcast-features-biml/

seniorfrosk, to random Norwegian

Always a pleasure to watch @cigitalgem in action - #swsec with a sprinkling of #MLsec

cigitalgem, to infosec
@cigitalgem@sigmoid.social avatar

Thanks Stockholm. The breakfast seminar on #swsec was good. Next up is OSLO tomorrow morning (THURSDAY). If you are in Norway, please come join me!

I will also briefly cover machine learning security #MLsec

#appsec #infosec #software #LLM

https://www.lyyti.fi/reg/CDR-NO-18-04-2024

cigitalgem,
@cigitalgem@sigmoid.social avatar

Did I say tomorrow morning? I meant today. See you soon at the #swsec seminar.

cigitalgem, to infosec
@cigitalgem@sigmoid.social avatar

Software Security Seminar in Stockholm TOMORROW 17.4

Please join me for an early morning breakfast seminar on (with some thrown in for good measure). Build security in.

Register here https://www.lyyti.fi/reg/CDR-SV-17-04-2024

Thank you in advance for passing this on to dev types you know in Sweden. Please boost for reach.

cigitalgem, to infosec
@cigitalgem@sigmoid.social avatar

The mid-April breakfast seminar I am giving in Stockholm still has plenty of space. If you happen to know anyone who would benefit from attending, please let them know!

Calling all Swedes interested in software security. (Thanks for passing this on.)

STOCKHOLM 17.4 https://www.lyyti.fi/reg/CDR-SV-17-04-2024

#swsec #appsec #infosec

cigitalgem, to infosec
@cigitalgem@sigmoid.social avatar

I am giving two #swsec breakfast seminars back to back mid-April. If you are in Sweden, Norway or Finland, please consider coming. Pass it on to those who may be interested.

#appsec #infosec #MLsec

STOCKHOLM 17.4 https://www.lyyti.fi/reg/CDR-SV-17-04-2024

OSLO 18.4 https://www.lyyti.fi/reg/CDR-NO-18-04-2024

cigitalgem, to ML
@cigitalgem@sigmoid.social avatar

Have a look at the Usenix login; interview featuring myself and the BIML LLM work. #MLsec #ML #AI #LLM

https://berryvilleiml.com/2024/03/15/rik-farrow-interviews-mcgraw-for-login/

cigitalgem,
@cigitalgem@sigmoid.social avatar

@seniorfrosk @cigitalgem it was called Reliable Software Technologies (rstcorp.com). We changed the name to cigital in 2001. 15 years later, we sold it to synopsys. It remains the main engine in the synopsys #swsec software integrity group which they are currently trying to sell.

seniorfrosk,

@cigitalgem Interesting, I did not realize Synopsis was getting out of #swsec

cigitalgem, to security
@cigitalgem@sigmoid.social avatar

I will try to beat @0xmchow to the punch since it's my 58th birthday!

#swsec #appsec #security

Secure your ML algorithms too while you're at it.

#MLsec #ML #AI #LLM

cigitalgem, to ML
@cigitalgem@sigmoid.social avatar
Weld, to random

Many of us in AppSec have been saying this for a while. Your developers are part of the cybersecurity workforce and must be trained that way in college.

"It is long overdue for academia to reconsider their role in producing a software developer workforce that enables increasingly damaging cyberattacks."

It's great to hear CISA using their influence to push for change here. https://www.cisa.gov/news-events/news/we-must-consider-software-developers-key-part-cybersecurity-workforce

cigitalgem,
@cigitalgem@sigmoid.social avatar

@phf @Weld Absolutely agree. I trained execs at Qualcomm in the Boardroom as well as all in-house lawyers on #swsec personally (way back when past the statute of limitations). Made a huge difference. (tagging @againsthimself)

cigitalgem, to ML
@cigitalgem@sigmoid.social avatar

Have a listen to the #MLsec episode of the Google Cloud Security Podcast, featuring me.

EP150 Taming the AI Beast: Threat Modeling for Modern AI Systems with Gary McGraw

#swsec #appsec #ML #AI

https://berryvilleiml.com/2024/01/25/google-cloud-security-podcast-features-biml/

cigitalgem, to random
@cigitalgem@sigmoid.social avatar
cigitalgem, (edited ) to random
@cigitalgem@sigmoid.social avatar

Lets do a TOP TEN LLM Risks list

9: Model Trustworthiness

Get the full paper here https://berryvilleiml.com/results/

cigitalgem, (edited ) to random
@cigitalgem@sigmoid.social avatar

Lets do a TOP TEN LLM Risks list

10: Encoding Integrity

https://berryvilleiml.com/results/BIML-LLM24.pdf

seniorfrosk, to random

IEEE SWEBOK finally has a chapter on Software Security - too bad @cigitalgem has abandoned us https://waseda.app.box.com/v/ieee-cs-swebok/file/1414917107168

cigitalgem,
@cigitalgem@sigmoid.social avatar

@seniorfrosk oh I just retired, that's all. In my view the most important work in is being done by Irius Risk (threat modeling automation) and Legit Security (sw supply chain management).

cigitalgem, to ML
@cigitalgem@sigmoid.social avatar

The MATCH webinar was recorded and is now available via video
#swsec #appsec #threatmodeling
#MLsec #ML #AI

Proud to have participated with Irius Risk and Calypso AI

https://youtu.be/RI0pNGH9bgA?feature=shared

cigitalgem, to random
@cigitalgem@sigmoid.social avatar

I am reminded of the very early days of where all we did was talk about attacks. Penetrate and patch won’t work here in my view. We therefore need to focus on design by security versus red teaming.

See --> https://apnews.com/article/ai-cybersecurity-malware-microsoft-google-openai-redteaming-1f4c8d874195c9ffcc2cdffa71e4f44b

cigitalgem, to ML
@cigitalgem@sigmoid.social avatar

The webinar will begin in 5 minutes:
Machine learning
Artificial intelligence
Threat modeling
Compliance
How the heck these link together

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • mdbf
  • ngwrru68w68
  • cubers
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • DreamBathrooms
  • megavids
  • tacticalgear
  • osvaldo12
  • normalnudes
  • tester
  • cisconetworking
  • everett
  • GTA5RPClips
  • ethstaker
  • anitta
  • Leos
  • provamag3
  • modclub
  • lostlight
  • All magazines