27 Matching Annotations
  1. Last 7 days
    1. The industry average time to detect a supply chain breach is 267 days. SolarWinds went undetected for 14 months. XZ Utils took two years to surface. Socket, an a16z portfolio company, detected the malicious dependency in the Axios attack within 6 minutes of its publication.

      检测时间的巨大差异(267天与6分钟)展示了安全检测领域的革命性变化。传统方法依赖已知漏洞数据库,而新型行为分析系统能够在攻击发生时立即检测到异常行为,这种能力差异决定了安全事件的严重程度。

  2. Apr 2026
    1. A deliberately planted backdoor doesn’t have a CVE.

      戳中了传统安全工具的阿喀琉斯之踵。基于已知漏洞(CVE)的防御逻辑在应对蓄意植入且会自毁的新型后门时形同虚设。这启示我们,静态的特征匹配已无法应对动态的攻击手段,必须转向对代码运行时行为的动态分析,从“它是什么”转向“它做了什么”。

  3. Aug 2022
  4. Apr 2022
  5. Dec 2021
  6. Nov 2021
  7. Mar 2021
  8. Feb 2021
  9. Nov 2020
  10. Sep 2020
  11. Aug 2020
  12. Jun 2020
  13. Apr 2020