home.social

#swsec — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #swsec, aggregated by home.social.

fetched live
  1. Is Microsoft super amazing good at #swsec these days? Why no...they are not. This is a very obvious front door attack through parameter manipulation. Absolutely ridiculous. #MKsec security engineering is directly corrupting #swsec #appsec #security because #ML treaded as an insider not good.

    arstechnica.com/security/2026/

  2. @gcve @aristot73 @trailofbits @jamesberthoty @jackhcable We are not really focused on #swsec as much as #MLsec at BIML. Thank you for the suggestion, though.

  3. This is hilarious. Counterfactual #MLsec versus #swsec failure reads like a blueprint of what will happen.

    nesbitt.io/2026/06/26/incident

  4. Good coverage in the NY Times of the mythos/fable situation, including wise advice from @k8em0

    Security tools cut both ways. Fix the broken software.
    #swsec #MLsec #AI #ML

    nytimes.com/2026/06/17/technol

  5. The Silver Bullet Security Podcast is released on the first of every month. Since rebooting this year, we have published 4 episodes:

    berryvilleiml.com/podcast/

    Previous 153 episodes

    garymcgraw.com/technology/silv

    Current episode

    berryvilleiml.com/2026/06/01/s

    Please have a listen and pass it on.

    #MLsec #swsec #appsec #infosec #security

  6. The Silver Bullet Security Podcast is released on the first of every month. Since rebooting this year, we have published 4 episodes:

    berryvilleiml.com/podcast/

    Previous 153 episodes

    garymcgraw.com/technology/silv

    Current episode

    berryvilleiml.com/2026/06/01/s

    Please have a listen and pass it on.

    #MLsec #swsec #appsec #infosec #security

  7. @RichBartlett it was a bummer but not at all surprising to see real #swsec degenerate to box checking #appsec a decade ago

  8. @sparta amazing how when you spend money (tokens) on #swsec you do a better job of it. Who would have thought?

  9. @paco tokens = money. We are finally spending real money on #swsec

  10. @coreysnipes thank you.

    I have been at this for a while ...both as a security guy who helped get #swsec and #appsec going 28 years ago and as a student of Doug Hofstader's with a Ph.D. in #cogsci. BIML has been spearheading independent #MLsec since 2019.

  11. More on mythos. #swsec #appsec #MLsec #ML #AI

    "What changed with Mythos Preview is that a model can now take those low-severity bugs (which would traditionally sit invisible in a backlog) and chain them into a single, more severe exploit."

    blog.cloudflare.com/cyber-fron

  12. The one good thing about the mythos nonsense is at least broken software is finally being fixed. If that's what it takes, so be it. #swsec #appsec #MLsec

    theguardian.com/technology/202

  13. Registration requirement for access to our new paper "No Security Meter for AI" has been removed due to urgency of content and to promote frictionless distribution

    berryvilleiml.com/results/no-s

    Please consider registering, which enables you to receive email notifications from BIML.

    #MLsec #ML #AI #infosec #swsec #appsec

  14. Have you read BIML's new report No Security Meter for AI?
    #MLsec #ML #AI #swsec #appsec

    berryvilleiml.com/results/no-s

    We removed the reg wall this morning.

  15. How can you measure security in #ML systems? Maybe similarly to the way we measure security in software systems. #swsec #appsec

    BIML wrote about this in a new report released today: berryvilleiml.com/results/

    Get your copy now, released for free under a creative commons license.

    Applied #MLsec

  16. How can you measure security in #ML systems? Maybe similarly to the way we measure security in software systems. #swsec #appsec

    BIML wrote about this in a new report released today: berryvilleiml.com/results/

    Get your copy now, released for free under a creative commons license.

    Applied #MLsec

  17. @koehntopp @tychotithonus this is literally changing in real time. I used to believe that too. And as you know. I know a smidge about #swsec
    You two may both enjoy reading this new thing released this morning
    No Security Meter for AI
    berryvilleiml.com/results/no-s

    Email me if the reg wall bothers you too much

  18. @tychotithonus in the best of all possible worlds, all this #AI stuff will accelerate #swsec and #appsec so we can finally do what we know we should have done since 2001

  19. So how is it going in the #swsec and #appsec tools and services space in the age of #mythos?

    "Mythos is like a nuke going off in the middle of our industry. Most of our biggest clients who have used it figure they will get rid of all their pipeline tools and replace with mythos. Toss the findings to copilot (or their own agentic engines) and have them fix the bugs. And completely get rid of Pentesting. Synk renewals are at 30%, BlackDuck at 60%."