No video

Hidden Risks In Open-Source Code And AI Models - Tal Folkman

  Рет қаралды 202

OWASP London

OWASP London

Күн бұрын

"Hidden Risks In Open-Source Code And AI Models" - Tal Folkman
Through our efforts in tracking and combatting attackers in open source software supply chains, my team has gained valuable insights and lessons. In this presentation, we aim to provide attendees with a new perspective and tools for evaluating the trustworthiness of open source packages and AI models before using them in their own projects. This talk is for anyone who uses open source in their daily work. The goal is to raise awareness about the risks of software supply chain attackers hiding in open source code, and to demonstrate how easy it is for attackers to launch attacks. Attendees will learn about tools for detecting when they are being tricked and how to stay alert to potential threats.
SPEAKER BIO:
Tal Folkman is a security research team lead and accomplished expert in cybersecurity with over 8 years of experience in the field. Tal possesses exceptional skills in detecting and analyzing malicious code present in open-source software supply chains. In 2021, Tal joined Dustico, a software supply chain security startup that was later acquired by Checkmarx. Prior to this, she served for 5 years as both member and leader of IDF's Cybersecurity Red Team. Currently, Tal and her team are dedicated to identifying and combating software supply chain attackers, thereby ensuring the safety and security of the ecosystem.
----
This talk was presented at the ‪@OWASPLondon‬ Meetup on April 18th, 2024 kindly hosted by ‪@thoughtmachine903‬ and sponsored by ‪@CheckmarxOfficial‬
--
Do you want to attend OWASP London meetups in person? Follow OWASPLondon on LinkedIN/Meetup/EventBrite/Facebook/Twitter.
Please SUBSCRIBE to this channel so you get notified when new videos are published
#OWASP #OWASPLondon #SBOM #AppSec

Пікірлер
这三姐弟太会藏了!#小丑#天使#路飞#家庭#搞笑
00:24
家庭搞笑日记
Рет қаралды 40 МЛН
Kids' Guide to Fire Safety: Essential Lessons #shorts
00:34
Fabiosa Animated
Рет қаралды 16 МЛН
The Joker kisses Harley Quinn underwater!#Harley Quinn #joker
00:49
Harley Quinn with the Joker
Рет қаралды 6 МЛН
Build Trust - Build Secure: Using Open Source Security Tools
1:04:26
The moment we stopped understanding AI [AlexNet]
17:38
Welch Labs
Рет қаралды 955 М.
DevSecOps Worst Practices - Tanya Janca
54:23
OWASP London
Рет қаралды 787
A Data-Led Approach To Cybersecurity - Disha Mukherjee
32:13
OWASP London
Рет қаралды 108
ModSecurity 22 Years Later: Success and Failure - Ivan Ristić
21:23
HACKED!  How a Buffer Overflow Exploit works, plus Code Red!
25:50
Dave's Garage
Рет қаралды 194 М.
这三姐弟太会藏了!#小丑#天使#路飞#家庭#搞笑
00:24
家庭搞笑日记
Рет қаралды 40 МЛН