Aggregator
2024开放原子开源生态大会安全与密码产业实践分论坛成功举办
“噪音风暴”伪造大量互联网流量
安全动态回顾|国家计算机病毒应急处理中心监测发现13款违规移动应用 起亚经销商平台被发现存在严重漏洞
往期回顾:
Recall 2.0: Microsoft дает второй шанс ИИ-помощнику, в которого никто не верил
三分之二的美国科技行业从业者有兴趣加入工会
Анализ прошивки дрона DJI Mavic 3: часть 1
FreeBuf早报 | WordPress与托管商WP Engine决裂;伊朗黑客被指控影响选举
欣望江山千里秀,欢颂祖国万年春 | 庆祖国75周年华诞
Could APIs be the undoing of AI?
Application programming interfaces (APIs) are essential to how generative AI (GenAI) functions with agents (e.g., calling upon them for data). But the combination of API and LLM issues coupled with rapid rollouts is likely to see numerous organizations having to combat security failings. While GenAI is susceptible to the usual security issues associated with APIs such as authentication, authorization and data exposure, there are also AI-specific concerns which have been well-documented by the OWASP Project … More →
The post Could APIs be the undoing of AI? appeared first on Help Net Security.
SCCMSecrets: Open-source SCCM policies exploitation tool
SCCMSecrets is an open-source tool that exploits SCCM policies, offering more than just NAA credential extraction. SCCM policies are a key target for attackers in Active Directory environments, as they can expose sensitive technical information, including account credentials. Attackers may retrieve these credentials by impersonating a registered device with authenticated access or, in some cases, even from an unauthenticated position by exploiting misconfigurations in policy distribution. SCCMSecrets provides a thorough approach to identifying and exploiting … More →
The post SCCMSecrets: Open-source SCCM policies exploitation tool appeared first on Help Net Security.
SCTF 2024|W&M打破屏障,竞逐夺冠!
SCTF 2024|W&M打破屏障,竞逐夺冠!
SCTF 2024|W&M打破屏障,竞逐夺冠!
Open source maintainers: Key to software health and security
Open source has become the foundation of modern application development, with up to 98% of applications incorporating open-source components and open-source code accounting for 70% or more of the typical application. In this Help Net Security video, Donald Fischer, CEO at Tidelift, discusses the 2024 State of the Open Source Maintainer report, which provides insights into the work and mindset of open source maintainers. The study showed that paid maintainers are 55% more likely than … More →
The post Open source maintainers: Key to software health and security appeared first on Help Net Security.
BuckeyeCTF 2024
Date: Sept. 27, 2024, 8 p.m. — 29 Sept. 2024, 20:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://pwnoh.io/
Rating weight: 50.91
Event organizers: Buckeye Bureau of BOF
SCTF 2024
Date: Sept. 28, 2024, 1 a.m. — 30 Sept. 2024, 01:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://adworld.xctf.org.cn/contest/assess?hash=4124a446-65a9-11ef-a39a-000c297261bb
Rating weight: 37.00
Event organizers: Syclover