Hidden Risks In Open-Source Code And AI Models - Tal Folkman

  Рет қаралды 202

OWASP London

OWASP London

Күн бұрын

"Hidden Risks In Open-Source Code And AI Models" - Tal Folkman
Through our efforts in tracking and combatting attackers in open source software supply chains, my team has gained valuable insights and lessons. In this presentation, we aim to provide attendees with a new perspective and tools for evaluating the trustworthiness of open source packages and AI models before using them in their own projects. This talk is for anyone who uses open source in their daily work. The goal is to raise awareness about the risks of software supply chain attackers hiding in open source code, and to demonstrate how easy it is for attackers to launch attacks. Attendees will learn about tools for detecting when they are being tricked and how to stay alert to potential threats.
SPEAKER BIO:
Tal Folkman is a security research team lead and accomplished expert in cybersecurity with over 8 years of experience in the field. Tal possesses exceptional skills in detecting and analyzing malicious code present in open-source software supply chains. In 2021, Tal joined Dustico, a software supply chain security startup that was later acquired by Checkmarx. Prior to this, she served for 5 years as both member and leader of IDF's Cybersecurity Red Team. Currently, Tal and her team are dedicated to identifying and combating software supply chain attackers, thereby ensuring the safety and security of the ecosystem.
----
This talk was presented at the ‪@OWASPLondon‬ Meetup on April 18th, 2024 kindly hosted by ‪@thoughtmachine903‬ and sponsored by ‪@CheckmarxOfficial‬
--
Do you want to attend OWASP London meetups in person? Follow OWASPLondon on LinkedIN/Meetup/EventBrite/Facebook/Twitter.
Please SUBSCRIBE to this channel so you get notified when new videos are published
#OWASP #OWASPLondon #SBOM #AppSec

Пікірлер
are we seriously STILL talking about this?
10:00
Low Level Learning
Рет қаралды 13 М.
Please Help Barry Choose His Real Son
00:23
Garri Creative
Рет қаралды 22 МЛН
КТО ЛЮБИТ ГРИБЫ?? #shorts
00:24
Паша Осадчий
Рет қаралды 2,7 МЛН
Schoolboy Runaway в реальной жизни🤣@onLI_gAmeS
00:31
МишАня
Рет қаралды 3,7 МЛН
Is Gravity RANDOM Not Quantum?
20:19
PBS Space Time
Рет қаралды 377 М.
A Data-Led Approach To Cybersecurity - Disha Mukherjee
32:13
OWASP London
Рет қаралды 108
DevSecOps Worst Practices - Tanya Janca
54:23
OWASP London
Рет қаралды 787
Why The Sun is Bigger Than You Think
10:30
StarTalk
Рет қаралды 380 М.
Как настроить камеру хоп-ап
1:00
TimToker
Рет қаралды 3,2 МЛН
Сделал из зарядного устройства нечто!
0:48