cigitalgem, to infosec
@cigitalgem@sigmoid.social avatar
cigitalgem, to random
@cigitalgem@sigmoid.social avatar
cigitalgem, to infosec
@cigitalgem@sigmoid.social avatar
cigitalgem, to ML
@cigitalgem@sigmoid.social avatar

Re-up in preparation for Monday's talk in Bergen, Norway.

Have a listen to the episode of the Google Cloud Security Podcast, featuring me.

EP150 Taming the AI Beast: Threat Modeling for Modern AI Systems with Gary McGraw

https://berryvilleiml.com/2024/01/25/google-cloud-security-podcast-features-biml/

seniorfrosk, to random Norwegian
@seniorfrosk@snabelen.no avatar

Always a pleasure to watch @cigitalgem in action - with a sprinkling of

cigitalgem, to infosec
@cigitalgem@sigmoid.social avatar

Thanks Stockholm. The breakfast seminar on was good. Next up is OSLO tomorrow morning (THURSDAY). If you are in Norway, please come join me!

I will also briefly cover machine learning security

https://www.lyyti.fi/reg/CDR-NO-18-04-2024

cigitalgem,
@cigitalgem@sigmoid.social avatar

Did I say tomorrow morning? I meant today. See you soon at the seminar.

cigitalgem, to infosec
@cigitalgem@sigmoid.social avatar

Software Security Seminar in Stockholm TOMORROW 17.4

Please join me for an early morning breakfast seminar on (with some thrown in for good measure). Build security in.

Register here https://www.lyyti.fi/reg/CDR-SV-17-04-2024

Thank you in advance for passing this on to dev types you know in Sweden. Please boost for reach.

cigitalgem, to infosec
@cigitalgem@sigmoid.social avatar

The mid-April breakfast seminar I am giving in Stockholm still has plenty of space. If you happen to know anyone who would benefit from attending, please let them know!

Calling all Swedes interested in software security. (Thanks for passing this on.)

STOCKHOLM 17.4 https://www.lyyti.fi/reg/CDR-SV-17-04-2024

cigitalgem, to infosec
@cigitalgem@sigmoid.social avatar

I am giving two breakfast seminars back to back mid-April. If you are in Sweden, Norway or Finland, please consider coming. Pass it on to those who may be interested.

STOCKHOLM 17.4 https://www.lyyti.fi/reg/CDR-SV-17-04-2024

OSLO 18.4 https://www.lyyti.fi/reg/CDR-NO-18-04-2024

cigitalgem, to ML
@cigitalgem@sigmoid.social avatar

Have a look at the Usenix login; interview featuring myself and the BIML LLM work.

https://berryvilleiml.com/2024/03/15/rik-farrow-interviews-mcgraw-for-login/

cigitalgem,
@cigitalgem@sigmoid.social avatar

@seniorfrosk @cigitalgem it was called Reliable Software Technologies (rstcorp.com). We changed the name to cigital in 2001. 15 years later, we sold it to synopsys. It remains the main engine in the synopsys software integrity group which they are currently trying to sell.

seniorfrosk,
@seniorfrosk@snabelen.no avatar

@cigitalgem Interesting, I did not realize Synopsis was getting out of

cigitalgem, to security
@cigitalgem@sigmoid.social avatar

I will try to beat @0xmchow to the punch since it's my 58th birthday!

Secure your ML algorithms too while you're at it.

cigitalgem, to ML
@cigitalgem@sigmoid.social avatar
Weld, to random

Many of us in AppSec have been saying this for a while. Your developers are part of the cybersecurity workforce and must be trained that way in college.

"It is long overdue for academia to reconsider their role in producing a software developer workforce that enables increasingly damaging cyberattacks."

It's great to hear CISA using their influence to push for change here. https://www.cisa.gov/news-events/news/we-must-consider-software-developers-key-part-cybersecurity-workforce

cigitalgem,
@cigitalgem@sigmoid.social avatar

@phf @Weld Absolutely agree. I trained execs at Qualcomm in the Boardroom as well as all in-house lawyers on personally (way back when past the statute of limitations). Made a huge difference. (tagging @againsthimself)

cigitalgem, to ML
@cigitalgem@sigmoid.social avatar

Have a listen to the episode of the Google Cloud Security Podcast, featuring me.

EP150 Taming the AI Beast: Threat Modeling for Modern AI Systems with Gary McGraw

https://berryvilleiml.com/2024/01/25/google-cloud-security-podcast-features-biml/

cigitalgem, to random
@cigitalgem@sigmoid.social avatar
cigitalgem, (edited ) to random
@cigitalgem@sigmoid.social avatar

Lets do a TOP TEN LLM Risks list

9: Model Trustworthiness

Get the full paper here https://berryvilleiml.com/results/

cigitalgem, (edited ) to random
@cigitalgem@sigmoid.social avatar

Lets do a TOP TEN LLM Risks list

10: Encoding Integrity

https://berryvilleiml.com/results/BIML-LLM24.pdf

seniorfrosk, to random
@seniorfrosk@snabelen.no avatar

IEEE SWEBOK finally has a chapter on Software Security - too bad @cigitalgem has abandoned us https://waseda.app.box.com/v/ieee-cs-swebok/file/1414917107168

cigitalgem,
@cigitalgem@sigmoid.social avatar

@seniorfrosk oh I just retired, that's all. In my view the most important work in is being done by Irius Risk (threat modeling automation) and Legit Security (sw supply chain management).

cigitalgem, to ML
@cigitalgem@sigmoid.social avatar

The MATCH webinar was recorded and is now available via video

Proud to have participated with Irius Risk and Calypso AI

https://youtu.be/RI0pNGH9bgA?feature=shared

cigitalgem, to random
@cigitalgem@sigmoid.social avatar

I am reminded of the very early days of where all we did was talk about attacks. Penetrate and patch won’t work here in my view. We therefore need to focus on design by security versus red teaming.

See --> https://apnews.com/article/ai-cybersecurity-malware-microsoft-google-openai-redteaming-1f4c8d874195c9ffcc2cdffa71e4f44b

cigitalgem, to ML
@cigitalgem@sigmoid.social avatar

The webinar will begin in 5 minutes:
Machine learning
Artificial intelligence
Threat modeling
Compliance
How the heck these link together

noplasticshower, to ML
@noplasticshower@zirk.us avatar

I plan to "live toot" this morning's webinar beginning at 11am NY time (4pm London time) with my @cigitalgem identity. Feel free to follow along using the hashtag .

cigitalgem, to ai
@cigitalgem@sigmoid.social avatar

, , , , and regulation. WTF??

Webinar at 11am EST (in 90 minutes). I will participate.

Register --> https://www.iriusrisk.com/iriusrisk-match-webinar-2023

  • All
  • Subscribed
  • Moderated
  • Favorites
  • anitta
  • mdbf
  • magazineikmin
  • InstantRegret
  • hgfsjryuu7
  • Durango
  • Youngstown
  • slotface
  • everett
  • thenastyranch
  • rosin
  • kavyap
  • khanakhh
  • PowerRangers
  • Leos
  • DreamBathrooms
  • vwfavf
  • ethstaker
  • tacticalgear
  • cubers
  • ngwrru68w68
  • modclub
  • cisconetworking
  • osvaldo12
  • GTA5RPClips
  • normalnudes
  • tester
  • provamag3
  • All magazines