#ChatGPT is wrong more than half the time—makes many conceptual errors, but sounds confident, authoritative.
— @Richi 🤓 Jennings (@RiCHi) August 15, 2023
So, hard to spot the errors, say researchers. In this week’s #SSBlogwatch we can’t say we’re totally surprised. For @ReversingLabs: https://t.co/egp3AdqNmJ #AI #DevOps
Tuesday, 15 August 2023
AI coding helpers get FAILing grade - ReversingLabs
Tuesday, 25 July 2023
No net for some, no root for devs — Google pilot walls off staff internet, access for ‘safety’ - ReversingLabs
Googlers will be protected from themselves. In what’s described as a pilot program, they’ll lose internet access at work and/or root privs.
— @Richi 🤓 Jennings (@RiCHi) July 25, 2023
The idea is to stop break-ins. In this week’s #SSBlogwatch we try not to imagine the horror. For @ReversingLabs: https://t.co/jiSig18Bn9
Tuesday, 11 July 2023
EU-US data transfers back in hotseat: Security of user data adds to privacy concerns - ReversingLabs
#EU says new agreement with US means it’s OK to transfer data westwards again. Third time’s a charm?
— @Richi 🤓 Jennings (@RiCHi) July 12, 2023
This time it’ll stick, right? In this week’s #SSBlogwatch we fear it won’t — not if @MaxSchrems has his way.
For @ReversingLabs: https://t.co/6yomrHHqZ4 #GDPR
Wednesday, 5 July 2023
Here’s MITRE’s top-25 CWE list — with your old vulnerability category favorites - ReversingLabs
:@MITREcorp’s top three are exactly the same as last year. Combined, just those three account for about half the problems.#CWE #1, #4, #7 and #17 are #MemorySafety bugs. In this week’s #SSBlogwatch we point the finger at C/C++. For @ReversingLabs: https://t.co/AaeUWf2C6R
— @Richi 🤓 Jennings (@RiCHi) July 5, 2023
Tuesday, 27 June 2023
Hackers breached UPS data for SMS phish spree - ReversingLabs
Bug allowed bad actor to manipulate URLs:
— @Richi 🤓 Jennings (@RiCHi) July 4, 2023
ðŸ’Dev should avoid consecutive object references and add entropy.
ðŸ’Ops should detect attacks and shut ’em down or tarpit them.
In this week’s #SSBlogwatch we ask what Brown can do for us? For @ReversingLabs: https://t.co/6vbRBvEbWK
Wednesday, 21 June 2023
Passkeys standard: Time to add it to your dev plans? - ReversingLabs
#Passkeys looks almost ready for prime time. Apple and Google are supporting it — and being interoperable.
— @Richi 🤓 Jennings (@RiCHi) June 21, 2023
Isn’t it time your dev team did, too? In this week’s #SSBlogwatch we get below the surface blather. For @ReversingLabs: https://t.co/9wb7qBJZNF
Tuesday, 6 June 2023
PyPI hackers code sneaky new tactic. Researchers caught 'em red handed - ReversingLabs
:@PyPI attackers used compiled code to evade detection. Possibly first attack to take advantage of .PYC files.@ReversingLabs’ reverse engineering team led by Karlo Zanki (pictured) spotted the tactic. In this week’s #SSBlogwatch we round up reax right: https://t.co/N2oLtWkGCn
— @Richi 🤓 Jennings (@RiCHi) June 6, 2023
Wednesday, 31 May 2023
‘Extinction risk’: Could AI wipe out humans via software backdoors? - ReversingLabs
Industry warns of doom unless #AI tamed. Today’s #GenerativeAI models are writing semi-decent code—shouldn’t we worry we’re prepping ground for Skynet?
— @Richi 🤓 Jennings (@RiCHi) May 31, 2023
In this week’s #SSBlogwatch we need your clothes, your boots and your motorcycle. For @ReversingLabs: https://t.co/A0B3AP8Et7
Tuesday, 23 May 2023
PyPI paused as automated attack overwhelms admins - ReversingLabs
:@PyPI under attack from bots at weekend. Bad actors submitting malicious packages with names similar to established deps.
— @Richi 🤓 Jennings (@RiCHi) May 23, 2023
Yet another scary illustration of fragile #SoftwareSupplyChains. In this week’s #SSBlogwatch we look deeper.
For @ReversingLabs: https://t.co/ahUzInOJjM
Wednesday, 17 May 2023
MSI UEFI key breach: How safe are YOUR secrets?
Last month’s @MSItweets data theft causing panic: Extremely sensitive signing #keys have been found among the leaked data.
— @Richi 🤓 Jennings (@RiCHi) May 17, 2023
If nothing else, there are important lessons to learn. In this week’s #SSBlogwatch we lock up our secrets.
For @ReversingLabs: https://t.co/QIJL1wXoun
Tuesday, 9 May 2023
Red teamers take on AI at DEF CON 31 - ReversingLabs
At @DEFCON 31, #infosec researchers can compete to find vulns in the new generation of #LLM #generativeAI.
— @Richi 🤓 Jennings (@RiCHi) May 9, 2023
From bias, to hallucination and jailbreaks, expect much egg on face. In this week’s #SSBlogwatch we prime for prompt action. For @ReversingLabs: https://t.co/bhxGToJADr
Wednesday, 3 May 2023
SolarWinds hack: Did DoJ know 6 months earlier? - ReversingLabs
What did @TheJusticeDept know about the @SolarWinds fiasco? How early did it find out? And who did it tell?
— @Richi 🤓 Jennings (@RiCHi) May 3, 2023
It’s complicated. But Hanlon’s razor probably applies. In this week’s #SSBlogwatch we look at the story from all sides. For @ReversingLabs: https://t.co/cunYTPlzYO
Wednesday, 26 April 2023
#RSAC is bustling — AI + security is huge: #StrongerTogether? - ReversingLabs
At #RSAC, you can’t move for #AI chatter. How will it help with #SoftwareSupplyChain #security? And will it help bad actors?@MosconeCenter is full of people again. In this week’s #SSBlogwatch we believe the hype. For @ReversingLabs’ @SecuredSoftware: https://t.co/2SaXAzF1II
— @Richi 🤓 Jennings (@RiCHi) April 26, 2023
Tuesday, 18 April 2023
EU cyber laws ‘will’ make FOSS devs liable - ReversingLabs
The Python Software Foundation is very, very unhappy with the draft Cyber Resilience Act (CRA) and Product Liability Act (PLA).
European lawmakers want all software makers to be liable for security holes. Even non-profit or hobbyist developers could be sued for negligence.
The EU’s draft Cyber Resilience Act (CRA) and Product Liability Act (PLA) would “create a chilling effect” and do “irreparable harm,” according to the organization behind Python and PyPI. When replicated across other parts of the software supply chain ecosystem, we risk the whole house of cards crashing down — as devs race to limit their liability.
The goal might be laudable, but some aspects need a major rethink. In this week’s Secure Software Blogwatch, we fear unintended consequences.
Read more: EU cyber laws ‘will’ make FOSS devs liable
Tuesday, 11 April 2023
Has public USB ‘juice jacking’ made it into the wild? - ReversingLabs
🫣@FBIDenver last week warned folks not to plug into public #USB charging stations.
— @Richi 🤓 Jennings (@RiCHi) April 11, 2023
As more and more laptops can charge via USB PD, traveling #DevOps staff (with credentials etc.) need to be aware.
In this week’s #SSBlogwatch, we remember DEF CON 19: https://t.co/i3mhj08HV3
Wednesday, 5 April 2023
With Twitter code in the wild, DevSecOps doubts surface - ReversingLabs
First, @Twitter’s source code was leaked. Then it open-sourced its #ranking algorithm.
— @Richi 🤓 Jennings (@RiCHi) April 6, 2023
In this week’s #SSBlogwatch we ponder the unintended consequences of “transparency.”
For @ReversingLabs’ @SecuredSoftware: https://t.co/SOnU3SFz3V
Wednesday, 29 March 2023
Do you trust AI to find app sec holes while you sleep? - ReversingLabs
Microsoft has turned OpenAI’s LLM onto cybersecurity. “Security Copilot” is its name for conversational, ChatGPT security analysis and monitoring.
Or, at least, so says #Microsoft.
— @Richi 🤓 Jennings (@RiCHi) March 30, 2023
In this week’s #SSBlogwatch we wonder whether to believe the hype.
For @ReversingLabs’ @SecuredSoftware: https://t.co/TMl9H2xe08 #AI #ML #GPT #GPT4 #ChatGPT #ChatGPT4
Wednesday, 15 March 2023
GitHub enforces 2FA — it’s about time (given the state of supply chain security) - ReversingLabs
This week’s #SSBlogwatch for @ReversingLabs’ @SecuredSoftware: https://t.co/hJnLLAR8Zf #2FA #MFA #SoftwareSupplyChain
— @Richi 🤓 Jennings (@RiCHi) March 15, 2023
Tuesday, 7 March 2023
White House cyber strategy: A love/hate story - ReversingLabs
3/ Naturally, it’s dividing opinions.
— @Richi 🤓 Jennings (@RiCHi) March 7, 2023
As usual, in this week’s #SSBlogwatch we’re not going to tell you what to think.
For @ReversingLabs’ @SecuredSoftware: https://t.co/n6ZhKsK2YS
Wednesday, 1 March 2023
LastPass revelations: BIG lessons for DevSecOps teams - ReversingLabs
And waddya know? The PC was infected with a #keylogger.
— @Richi 🤓 Jennings (@RiCHi) March 1, 2023
In this week’s #SSBlogwatch we facepalm, furiously.
For @ReversingLabs’ @SecuredSoftware: https://t.co/ySjfUL4sey #LastPass
