Published inNerd For TechControl systems exposure puts critical infrastructure at riskIndustrial control systems run most of the nation’s critical infrastructure. Too many of them are vulnerable to hackers.4d ago4d ago
Published inNerd For TechBoth good and bad guys showing that LLMs aren’t ready for prime timeLarge language models—the brains behind artificial intelligence—keep getting better, but still need lots of improvement,Dec 9Dec 9
Published inNerd For TechThese software packages contain “presents” you don’t want to openMalicious hackers, instead of waiting for software developers to make mistakes, are trying to trick them into downloading mistakes.Dec 2Dec 2
Published inNerd For TechAre there too many “top software vulnerabilities” lists? Or are they the wrong lists?Are there too many lists of top software vulnerabilities? Maybe. Or maybe the lists should be about how to build more secure code.Nov 25Nov 25
Report: Building trust into software takes a team of testsA new report documents the benefits of multiple software security testing toolsNov 12Nov 12
Will AI be good for democracy? That depends on the humans in chargeArtificial intelligence is invading every element of our lives, including our system of government. That will likely be both good and bad.Nov 4Nov 4
Published inNerd For TechZero-day software defects are leading to many very bad daysZero-day software vulnerabilities are among the most dangerous, because there is no patch for them. And they are increasing.Oct 28Oct 28
Published inNerd For TechResearcher finds government cybersecurity is still porousDespite catastrophic breaches of government, cybersecurity hasn’t improved as much as it could, or shouldOct 21Oct 21
Published inNerd For TechCybersecurity awareness should be aimed at software creators as well as usersThe need for better cybersecurity is universal. So an awareness month should apply to those who make software, as well as use it.Oct 15Oct 15
Published inNerd For TechReport: Build trust (and speed) in your software with DevSecOpsA new report by Black Duck documents the need for improvement in DevSecOps, along with recommendations on how to improve.Oct 8Oct 8