If you’re in the Albuquerque area this Friday and/or Saturday, we hope you’re planning on going to BSides ABQ – it promises to be a fun-filled weekend of learning. The team there has pulled together an interesting set of talks covering a wide variety of topics such as Infosec Ontology, Social Engineering, Red Team Persistence, Log Manipulation, Cellular Networks, OSINT, Quantifying Risk, IoT / OT Security and a lot more.
Our very own Ivan Novikov will be presenting his work on building a more fact-based API Security top-10 threat list based on 25 years of data. He’ll be talking on Saturday (09/09) at 11:00 MST.
His research explores an AI-driven approach to API security. It’s based on a comprehensive dataset of public CVEs (bulletins, bug bounty reports, and vendor-specific security bulletins) published over the past 25 years. By applying cutting-edge AI models such as ChatGPT 3.5 and ChatGPT 4, this research seeks to uncover new insights and refine the understanding of API security best practices.
A key output is a comprehensive, real-world API Security Top-10 Risks list, built on a comprehensive AI-powered analysis which uncovered inadequacies in OWASP API Security Top-10 coverage, suggesting the need for enhancements in API security mapping and risk prioritization.
Our new API Security Top-10 Risks list, based on current API security knowledge and analyzed using the strongest publicly available AI as of Q2-2023, outperforms the OWASP API Security Top-10 list. This superiority is verified both statistically and by the ChatGPT AI model.
You don’t want to miss it!
* Also on Saturday: Happy Hour and Dinner Party starting at 17:30. RSVP required.
Location
The University of New Mexico
Bldg. 60 (Student Union | SUB)
Albuquerque, NM 87131
Registration
Register via Eventbrite here
For More Information
Contact: info@bsidesabq.org
TL;DR- AI deployment has outpaced AI governance. Most enterprises running AI on AWS cannot answer…
Editor's note: This article was originally published by Craig Riddell on LinkedIn. It has been…
The Model Context Protocol (MCP) is a de facto standard for providing structured access to…
As API and AI adoption grows across the Middle East, so do the expectations around…
Most organizations treating AI security as a model problem are defending the wrong layer. Security…
Your legal team just handed you a 400-page document and said "figure out compliance." The…