unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
Five Questions to Answer Before Buying an AI Security Product
In the young security-for-AI market, what a product protects and how it ships can differ from what...
2026-8-3 00:0:0 | 阅读: 9 |
收藏
|
Lenny Zeltser - zeltser.com
security
protects
buying
asset
roadmap
A Field Guide to the AI Security Market
The market for products that secure AI is crowded and hard to read, with overlapping categories and...
2026-7-30 00:0:0 | 阅读: 15 |
收藏
|
Lenny Zeltser - zeltser.com
catalog
security
crowded
agents
asset
Cyber Company Profiles: Consistent AI Analysis of Security Vendors
Judging a security vendor from its own materials tells you little about how it compares to the rest...
2026-7-28 00:0:0 | 阅读: 3 |
收藏
|
Lenny Zeltser - zeltser.com
scores
security
answers
analysis
What 239 Products Reveal About the Shape of AI Security
The security-for-AI market is young and lopsided. Incumbents quickly extended their products into t...
2026-7-26 00:0:0 | 阅读: 15 |
收藏
|
Lenny Zeltser - zeltser.com
security
catalog
asset
claims
startups
Benchmark Your AI Security Decisions: A Five-Minute Survey
Answer ten questions about how your organization secures AI, and you get a peer benchmark in return...
2026-7-20 00:0:0 | 阅读: 7 |
收藏
|
Lenny Zeltser - zeltser.com
security
sounil
secures
ten
leaders
A Report Template for Malware Analysis
A malware report is only as useful as readers' ability to find in it what they need. This customiza...
2026-6-18 00:0:0 | 阅读: 23 |
收藏
|
Lenny Zeltser - zeltser.com
analysis
artifacts
download
behaviors
mcp
Templates for Cybersecurity Executive Briefings
In an effective executive brief, you lead with the bottom line and what a finding means for your or...
2026-6-14 00:0:0 | 阅读: 30 |
收藏
|
Lenny Zeltser - zeltser.com
brief
briefs
security
makers
Handling High-Profile Vulnerabilities
When a high-profile vulnerability surfaces, executives and customers want to know whether it affect...
2026-6-9 00:0:0 | 阅读: 23 |
收藏
|
Lenny Zeltser - zeltser.com
exposure
celebrity
brief
branding
Securing API Keys on Your Workstation
Every dev tool you grant API access to, AI assistants included, can read the keys within its reach....
2026-6-9 00:0:0 | 阅读: 29 |
收藏
|
Lenny Zeltser - zeltser.com
ssh
keychain
scrub
exposure
transcripts
Security of Third-Party Keyboard Apps on Mobile Devices
Keyboard apps offer better predictions, voice transcription, and AI-powered writing, all requiring...
2026-6-2 00:0:0 | 阅读: 39 |
收藏
|
Lenny Zeltser - zeltser.com
keyboards
developer
developers
network
security
A Report Template for Security Assessments
The technical severity of an assessment finding tells only part of the story. A customizable report...
2026-5-31 00:0:0 | 阅读: 32 |
收藏
|
Lenny Zeltser - zeltser.com
mcp
adjusted
engagement
security
The Past, Present, and Future of the Web's Trust Model
Observability, short-lived credentials, and active enforcement hold the web's trust model together....
2026-5-28 00:0:0 | 阅读: 26 |
收藏
|
Lenny Zeltser - zeltser.com
cas
lived
sigstore
failures
chrome
A Report Template for Cyber Threat Intelligence
Cyber threat intelligence analysts produce defensible reports by weighing the same signals at tacti...
2026-5-19 00:0:0 | 阅读: 20 |
收藏
|
Lenny Zeltser - zeltser.com
attribution
analysis
cti
hypotheses
signals
Six Signals for Threat Attribution
Intelligence analysts weigh six signals together to build defensible attribution to a threat actor....
2026-5-19 00:0:0 | 阅读: 34 |
收藏
|
Lenny Zeltser - zeltser.com
attribution
signals
victim
defensible
artifacts
Plant Decoy Personas to Detect Impersonation Attacks
Decoy personas extend honeytoken thinking to user accounts and public profiles. The technique gives...
2026-5-14 00:0:0 | 阅读: 23 |
收藏
|
Lenny Zeltser - zeltser.com
decoy
personas
persona
bait
honeytoken
Making Sense of Security for AI: The AI Defense Matrix
The AI Defense Matrix maps eight AI asset classes to NIST CSF functions, giving security leaders on...
2026-5-11 00:0:0 | 阅读: 25 |
收藏
|
Lenny Zeltser - zeltser.com
security
asset
mcp
gaps
Build a Decoy MCP Server to Catch AI Agent Attackers
Your AI agent's MCP config can be a target for an attacker who reaches your machine. A decoy MCP se...
2026-5-3 00:0:0 | 阅读: 34 |
收藏
|
Lenny Zeltser - zeltser.com
mcp
attacker
honeypot
webhook
payload
Plant Honeytokens to Detect Intrusions
Plant decoy credentials, configs, and URLs to surface an attack the rest of your stack might miss....
2026-4-30 00:0:0 | 阅读: 32 |
收藏
|
Lenny Zeltser - zeltser.com
honeytoken
attacker
plant
fires
The Personal AI Stack: A Power User's Guide
好的,我现在需要帮用户总结一篇文章的内容,控制在100个字以内,而且不需要用“文章内容总结”或者“这篇文章”这样的开头。直接写文章的描述即可。 首先,我得仔细阅读用户提供的文章内容。这篇文章主要介绍了一个名为Personal AI Stack的七层模型,用于优化AI工具Claude Code。每一层都有不同的功能和例子,比如Layer 1是Harness,使用Claude Code、Ghostty、Maestro等工具;Layer 2是Scaffolding,涉及PAI和Skills;Layer 3是Personalization,用于自定义设置;Layer 4是Hardening,安全增强;Layer 5是Tech Stack,技术栈;Layer 6是Connectors,连接器;Layer 7是Work,项目。 接下来,我需要将这些信息浓缩到100字以内。重点在于说明这是一个七层模型,帮助优化AI工具Claude Code,并且每层都有特定的功能和示例。同时要提到这个模型可以调整以适应个人偏好。 可能会遇到的问题是如何在有限的字数内涵盖所有关键点而不遗漏重要信息。因此需要选择最核心的内容:七层模型、优化Claude Code、各层功能、可调整性。 最后,确保语言简洁明了,直接描述文章内容。 </think> 文章介绍了一个七层模型(Personal AI Stack),用于优化AI工具Claude Code的功能。通过自定义设置、安全增强、技术栈整合和项目管理等层层配置,使AI更贴合个人需求和工作流程。...
2026-4-28 00:0:0 | 阅读: 33 |
收藏
|
Lenny Zeltser - zeltser.com
claude
pai
mcp
skill
anthropic
Trust Boundary of SaaS Will Include Customers' AI Agents
好的,我现在需要帮用户总结这篇文章的内容,控制在100字以内。首先,我得仔细阅读文章,理解其主要观点。 文章讨论了SaaS供应商在面对客户AI代理时的信任边界问题。过去银行经历了四次安全措施扩展到客户设备的浪潮,现在第五次浪潮围绕AI代理展开。每次浪潮都是由责任、监管、客户保护需求和损失经济学驱动的。 接下来,我需要提取关键点:信任边界、AI代理作为新端点、安全措施扩展的历史、驱动因素以及未来的措施建议。 然后,我需要用简洁的语言把这些点整合起来,确保在100字以内。避免使用“文章总结”之类的开头,直接描述内容。 最后,检查字数是否符合要求,并确保信息准确传达。 </think> SaaS供应商需评估是否将客户AI代理纳入信任边界。银行过去四次因责任压力扩展安全措施至客户设备,第五波围绕AI代理展开。AI代理作为新交互端点缺乏强防御,SaaS产品面临攻击面风险。历史表明责任和监管将推动新安全措施,建议供应商考虑身份验证、行为分析和高风险操作的人工确认。...
2026-4-24 00:0:0 | 阅读: 53 |
收藏
|
Lenny Zeltser - zeltser.com
banks
agents
liability
defenses
wave
Previous
1
2
3
4
5
6
7
8
Next