Connect with us

Technology

Zenity Launches GenAI Attacks Matrix to Guide Security Efforts for GenAI Systems, Copilots and Agents

Published

on

TEL AVIV-YAFO, Israel, Oct. 3, 2024 /PRNewswire/ — Zenity, the leader in securing enterprise copilots and low-code development, has announced a new security framework, the GenAI Attacks Matrix. The open-source project, inspired by MITRE ATLAS and spearheaded by Zenity with help from many of the world’s leading security researchers, is focused on attacks that target the users of various GenAI systems, examining how AI systems interact with and on behalf of their users, and vice versa.

While many well-known security frameworks have historically taken an endpoint-driven approach, with the introduction of enterprise copilots and GenAI systems, security teams need a purpose-built framework to help them defend against the ensuing new wave of risks. This project’s scope includes any system that uses GenAI, allows for GenAI to make decisions, and interfaces with or is operated by users (or on their behalf, in the case of agentic AI) and is built towards helping security practitioners understand and contextualize their risk. This explicitly includes licensable AI systems such as ChatGPT Enterprise, GitHub Copilot or Microsoft 365 Copilot, extensions and agents anyone can build with low-code/no-code tools, and custom AI applications built for specific use cases.

Zenity co-founder and CTO Michael Bargury, said, “What we’re hoping to do here is bring the leading AI security researchers together in order to take a focused approach to GenAI systems. Our aim is to collectively document discovered attack techniques in order to clarify the threats to help enterprises devise corresponding mitigation and risk management strategies. AI changes every day, and it is critical that we share information about potential attacks as soon as they are discovered, before they are observed in the wild. I am proud to announce this project and look forward to collaborating with the security community.”

Bargury, who also founded the OWASP Low-Code/No-Code Top 10, realized that as the gold rush to place AI in the hands of all business users surges on, it is clear that security for AI is still a great unknown. By letting GenAI act on behalf of business users, enterprises have unwillingly opened up new attack pathways for adversaries to target powerful systems that inherently contain access to loads of corporate and sensitive data and are curious by nature. Attackers are exploiting these systems with promptware, which is content with hidden malicious instructions that gets picked up and acted on by AI apps.

This project aspires to lay the foundation for security teams that need to adopt a defense-in-depth approach focused on malicious behavior rather than malicious static content. The primary goal of this project is to document and share knowledge of those behaviors and to look beyond prompt injection at the entire lifecycle of a promptware attack. For more information about joining and contributing to this project, check out the GitHub repository or learn more on our website.

About Zenity

Zenity, the world’s first application security platform for Enterprise Copilots and Low-Code development, protects organizations from security threats, helps meet compliance, and enables business continuity. Established in 2021, many of the world’s leading organizations trust Zenity to help configure security guardrails, generate prioritized lists of vulnerabilities, and accurately pinpoint and remediate vulnerabilities by continuously scanning business-led development platforms and providing centralized visibility, risk assessment, and governance. Visit us at https://www.zenity.io for more.

View original content to download multimedia:https://www.prnewswire.com/news-releases/zenity-launches-genai-attacks-matrix-to-guide-security-efforts-for-genai-systems-copilots-and-agents-302266276.html

SOURCE Zenity

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Technology

BlueOptima Report Confirms EPAM’s Excellence in Software Development Productivity

Published

on

By

BlueOptima’s report reveals that more than 76.5% of EPAM’s lead developers exceed global productivity and quality standards

NEWTOWN, Pa., Oct. 3, 2024 /PRNewswire/ — As organizations increasingly rely on outsourcing to accelerate their digital transformation efforts, understanding software development productivity and quality is crucial for optimizing software development lifecycles and making informed outsourcing decisions. EPAM Systems, Inc. (NYSE: EPAM), a leading digital transformation services and product engineering company, today announced that EPAM’s developers have outperformed the global developer quality and productivity benchmarks set by BlueOptima, an independent organization specializing in evaluating and measuring software development practices against industry standards and global leaders.

“We’re delighted that our global development teams have surpassed the independent quality and productivity benchmarks set by BlueOptima,” said Balazs Fejes, President of Global Business and Chief Revenue Officer, EPAM. “In today’s cost-conscious environment, this achievement reflects our commitment to delivering exceptional and differentiating value across our global teams, proving that investing in EPAM’s high-caliber developer talent yields results that truly resonate in a competitive enterprise IT outsourcing marketplace.”

In BlueOptima’s Q2 2024 Global Benchmark Report, more than 76.5% of EPAM’s lead developers surveyed outperformed the global average, indicating the superior quality and efficiency of EPAM’s engineering talent across industries and geographical regions. The benchmarking report provides objective, data-driven insights that can inform strategic decision making, improve service delivery and ultimately contribute to the success of outsourcing relationships.

“Our evaluation of EPAM’s lead developers against our extensive global dataset of more than 700,000 developers highlights their exceptional quality and productivity, including when metrics are adjusted for value,” said Jason Rolles, CEO and Managing Director, BlueOptima. “By leveraging our Developer Analytics platform, organizations can make informed decisions and optimize their software development processes. This ensures they partner with the most effective and efficient teams, ultimately leading to better outcomes for all stakeholders in the outsourcing ecosystem.”

For enterprise IT outsourcing customers, BlueOptima’s Global Benchmark Report serves as a critical standard for global software development productivity and quality. By leveraging a dataset of more than 700,000 developers across 30 countries and using metrics like Coding Effort and source code maintainability, BlueOptima’s report offers enterprise outsourcing customers key insights into global software development productivity and quality, helping them benchmark developer efficiency and optimize their outsourced projects.

To learn more about EPAM’s engineering excellence in software development, visit: www.epam.com/services/engineering

About EPAM Systems
Since 1993, EPAM Systems, Inc. (NYSE: EPAM) has used its software engineering expertise to become a leading global provider of digital engineering, cloud and AI-enabled transformation services, and a leading business and experience consulting partner for global enterprises and ambitious startups. We address our clients’ transformation challenges by focusing EPAM Continuum’s integrated strategy, experience and technology consulting with our 30+ years of engineering execution to speed our clients’ time to market and drive greater value from their innovations and digital investments.

We make GenAI real with our AI LLM orchestration, testing and engineering solutions, EPAM DIAL, EPAM EliteA™ and EPAM AI/RUN™, respectively.

We deliver globally but engage locally with our expert teams of consultants, architects, designers and engineers, making the future real for our clients, our partners, and our people around the world. We believe the right solutions are the ones that improve people’s lives and fuel competitive advantage for our clients across diverse industries. Our thinking comes to life in the experiences, products and platforms we design and bring to market.

Added to the S&P 500 and the Forbes Global 2000 in 2021 and recognized by Glassdoor and Newsweek as a Top 100 Best Workplace, our multidisciplinary teams serve customers across six continents. We are proud to be among the top 15 companies in Information Technology Services in the Fortune 1000 and to be recognized as a leader in the IDC MarketScapes for Worldwide Experience Build Services, Worldwide Experience Design Services and Worldwide Software Engineering Services as well as a leader in the 2024 Gartner® Magic Quadrant™ for Custom Software Development Services, Worldwide.*

Learn more at www.epam.com and follow us on LinkedIn.

* Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

 

View original content to download multimedia:https://www.prnewswire.com/news-releases/blueoptima-report-confirms-epams-excellence-in-software-development-productivity-302266639.html

SOURCE EPAM Systems, Inc.

Continue Reading

Technology

energyRe and Google Sign 12-Year Power Purchase Agreement for 435-MWdc Solar Project

Published

on

By

HOUSTON, Oct. 3, 2024 /PRNewswire/ — energyRe today announced that Google has signed a 12-year power purchase agreement to purchase renewable energy from a 435-megawatt (MWdc) solar project to be developed, owned, and operated by energyRe. energyRe will supply electricity and Renewable Energy Credits (RECs) generated from the solar project to Google to power the equivalent of more than 56,000 homes.

The project will support Google’s 2030 goal to run on 24/7 carbon-free energy on every grid where the company operates. The deal was facilitated through LEAP™ (LevelTen Energy’s Accelerated Process), which was co-developed by Google and LevelTen Energy to make clean energy buying and selling more efficient.

“As we continue to progress towards our goal to operate every Google campus on clean electricity every hour of every day by 2030, we are always looking for opportunities to accelerate the delivery of new clean power to the grid,” said Amanda Peterson Corio, Google Global Head of Data Center Energy. “Using our scalable procurement approach, we’ve been able to collaborate quickly with energyRe to deliver new clean energy to the SPP grid system and support our 24/7 progress in the region.”         

“energyRe is proud to deliver reliable clean power to support Google’s ambitious sustainability and decarbonization goals,” said Miguel Prado, Chief Executive Officer of energyRe. “Google is a global leader in renewable energy and continues to set a high bar across the technology industry. energyRe’s track record of delivering clean energy solutions for our customers makes us a trusted partner for companies working to reduce their carbon footprints.”

Nationally, energyRe’s onshore utility-scale portfolio includes 1,520 MWdc of contracted solar assets and 398 megawatt-hours (MWh) of contracted battery storage assets.

About energyRe
energyRe is a leading independent energy company focused on solving complex sustainability challenges and providing clean energy solutions in utility-scale transmission, onshore wind and solar, offshore wind, energy storage and distributed generation. Guided by the principles of innovation and partnership and backed by expertise and experience, energyRe is committed to creating a reliable, renewable energy future for all. energyRe has offices in New York, Houston, Indianapolis, and Charleston. For more information about energyRe, visit www.energyre.com

View original content to download multimedia:https://www.prnewswire.com/news-releases/energyre-and-google-sign-12-year-power-purchase-agreement-for-435-mwdc-solar-project-302266902.html

SOURCE energyRe

Continue Reading

Technology

CREST Awards ControlCase Penetration Testing Accreditation

Published

on

By

ControlCase, the global leader in technology-enabled certification, cybersecurity, and continuous compliance services has achieved CREST accreditation for Penetration Testing.

FAIRFAX, Va., Oct. 3, 2024 /PRNewswire-PRWeb/ — ControlCase, the global leader in technology-enabled certification, cybersecurity, and continuous compliance services, is delighted to announce that we have achieved CREST accreditation for Penetration Testing. CREST is an international not-for-profit membership body that represents the global cybersecurity industry.

“CREST is delighted to welcome ControlCase as an accredited member company for its penetration testing services.” – Rowland Johnson, CREST President

ControlCase is committed to collaborating with both customers and partners to deliver a supportive end-to-end compliance experience with simplified processes that provide both efficiency and accuracy while saving time and expenses. Clients and partners utilize our Compliance Hub™ and One Audit technology and our amazing team to advance their businesses and to keep their environment and their data private and secure. At ControlCase we recognize the significant risks that a security breach entails and are fully committed to providing world-class security in all our offerings. The attainment of CREST Penetration Testing accreditation underscores ControlCase’s consistent fulfillment of rigorous regulations ensuring the security and safeguarding of sensitive data.

“ControlCase is fully committed to representing the global cybersecurity industry and collectively raising the standards of cyber service providers and professionals. Our CREST Penetration Testing accreditation demonstrates our unwavering commitment to safety, emphasizing our steadfast focus on ensuring the security and satisfaction of our valued clients.” – Mike Jenner, CEO of ControlCase

“CREST is delighted to welcome ControlCase as an accredited member company for its penetration testing services. ControlCase has successfully been through our demanding assessment process that examines test methodologies, legal and regulatory requirements, data protection standards, logging and auditing, internal and external communications with stakeholders, as well as how test data security is maintained. Accrediting ControlCase’s penetration testing services means that CREST is formally recognizing that the company consistently delivers the highest professional security services standards to its customers.”- Rowland Johnson, CREST President

“When you combine our CREST-certified penetration testing with our world-class Compliance Hub™ and One Audit technologies, ControlCase’s capability to deliver both protection and compliance is something all companies should be considering. We make company environments safer, and we do it with less pain, all while saving both time and money. At this time of year, when every company is working to meet their end-of-year and beginning-of-year pen testing deadlines, it is important to get the process started before it is too late to finish. We are here to help.” – Josh Hoffman, CRO of ControlCase

ABOUT CONTROLCASE

ControlCase is a global provider of certification, cybersecurity, and continuous compliance services. ControlCase is committed to empowering organizations to develop and deploy strategic information security and compliance programs that are simplified, cost effective, and comprehensive in both on-premises and cloud environments.

ControlCase specializes in delivering cybersecurity services and IT compliance audits, such as CMMC, ISO, SOC, HIPAA, HITRUST, FedRAMP, and PCI DSS, supported by state-of-the-art technology and amazing people. ControlCase offers a full selection of cybersecurity services and scans to assist clients in attaining IT security certifications, developing readiness strategies, completing assessments, and working through remediation.

For more information, please contact Amy Poblete at apoblete@controlcase.com or visit the company website at www.controlcase.com. You can also connect with ControlCase on social media through LinkedIn at www.linkedin.com/company/controlcase, YouTube at www.youtube.com/controlcasemedia, and Instagram at www.instagram.com/controlcasehq.

ABOUT CREST

Since 2006, CREST has been leading the global cybersecurity community to raise standards. CREST represents the industry and ensures the quality of cybersecurity service providers and professionals. With over 370 accredited member companies operating in dozens of countries, CREST certifies thousands of professionals worldwide through industry-leading examinations. Additionally, CREST collaborates with governments, regulators, academia, training partners, professional bodies, and other stakeholders worldwide.

Additional information about the company can be found on the CREST website at www.crest-approved.org, LinkedIn at www.linkedin.com/company/crest-approved/, X at x.com/CRESTadvocate, and YouTube at www.youtube.com/crestadvocate.

Media Contact

Amy Poblete, ControlCase, LLC, 1 7034836383, apoblete@controlcase.com, https://www.controlcase.com/ 

LinkedIn

View original content to download multimedia:https://www.prweb.com/releases/crest-awards-controlcase-penetration-testing-accreditation-302266543.html

SOURCE ControlCase, LLC

Continue Reading

Trending