7 Matching Annotations
  1. Last 7 days
  2. Sep 2026
    1. ederal leaders risk falling victim to a modern cyber version of the McNamara Fallacy. Named for Defense Secretary Robert McNamara’s reliance on quantifiable metrics during the Vietnam War, it describes managing by what is easiest to count (e.g., patches applied, tickets closed and average CVSS scores) while overlooking operational reality.

      What is "operational reality"? I think for businesses, it is staying in the "green," so checking the boxes for programs and policies. Whereas, in the scope of the "defender's dilemma," the defenders users these programs and policies to their advantage.

  3. Jun 2026
    1. Vulnerability reports, on their own, do not protect anyone. The value comes from validating the issue, understanding its impact, developing and testing a patch, coordinating disclosure, and helping teams deploy the fix.

      大多数人认为发现并报告漏洞本身就提供了安全价值,但作者明确表示,单纯的漏洞报告并不能保护任何人。这一观点挑战了安全行业普遍重视漏洞数量而非修复质量的共识,强调了从发现到修复的完整流程才是真正有价值的部分。

  4. Apr 2026
    1. select known-vulnerable dependency versions 50% more often than humans.

      这一统计洞察颠覆了“AI写代码更安全”的迷思。AI代理在优化代码功能性时,往往以牺牲安全性为代价,倾向于选择存在已知漏洞的旧版本依赖。这反映出当前AI模型在训练时对安全维度的忽视,也警示我们在AI辅助开发流程中必须强制引入自动化的安全卡点。

  5. Jul 2020
  6. May 2020