Photo de couverture de Start With WCPGW
Start With WCPGW

Start With WCPGW

Fabrication de semi-conducteurs

Paris, Ile-de-France 3 518 abonnés

You may have heard it during an audit: "What Could Possibly Go Wrong?" Start with the question for early assessment

À propos

Our mission: Enable semiconductor and EDA companies understand and solve hardware security issues efficiently Our values: Integrity, Customer focus, Trustworthiness and Passion Our work: Through discovery, knowledge sharing and creative thinking, we achieve effective engineering methodologies. We provide - Consulting services in security, helping to accelerate semiconductor and EDA companies to bring security testing from post-silicon to pre-silicon. - Education to understand quickly security concepts and how to apply them in semiconductor. - Threat analysis in hardware/software, - Identification of incremental changes in design/verification methodologies - Technical reviews for EDA companies, semi-conductor design and verification teams, and end-user (automotive, industrial and consumer companies). Is your security solution finding resistance in the market and needs friction-less adoption ? Is your team trying to move into security mindset in designing or verifying their systems/IPs ? Are you trying to leverage your existing technology and move it into the security market ? Contact us if we can be of assistance

Site web
http://www.startwithwcpgw.com/
Secteur
Fabrication de semi-conducteurs
Taille de l’entreprise
2-10 employés
Siège social
Paris, Ile-de-France
Type
Société civile/Société commerciale/Autres types de sociétés

Lieux

Employés chez Start With WCPGW

Nouvelles

  • This incident reinforces an important reality: the security of an AI system extends far beyond the model itself. As AI agents become more autonomous, every connected service, API, sandbox, and integration becomes part of the attack surface. A single exposed endpoint or overly permissive configuration can become the path from an isolated experiment to real-world impact. This isn't a new security principle. It's the same lesson the industry has learned from cloud computing, containers, and software supply chains: attackers rarely break the strongest control. They look for the weakest connection between trusted systems. The difference is that AI agents can identify, chain, and exploit those weaknesses at a speed and scale that traditional threat models were never designed to handle. That raises the bar for secure architecture, not just model safety. Going forward, AI evaluation environments should be treated as security-critical infrastructure. Strong isolation, least privilege, continuous monitoring, verified dependencies, and rapid containment should be foundational controls, not optional safeguards applied after deployment. The future of AI security won't be defined by how capable the models become. It will be defined by whether the environments around them are designed to remain resilient when those models behave in unexpected ways. 💡https://lnkd.in/e9k8BRvw

  • AI coding assistants have changed how software is written, but they've also introduced a new supply chain risk. Hallucinated package names aren't just accuracy issues anymore. They can become attack paths when malicious actors register those packages before developers realize they don't exist. This is a reminder that AI-generated code should be treated like code from any untrusted source. Verify dependencies, validate package authenticity, and use approved repositories before anything reaches production. As AI accelerates development, the discipline of verifying what it generates becomes even more important. Speed should never replace trust. 💡https://lnkd.in/giQkxcCw

    • Aucune description alternative pour cette image
  • The hardware is impressive, but that's only the beginning. As robots become more autonomous and connected, the conversation needs to move beyond performance to trust. Organizations won't adopt these systems because they're fast or can navigate difficult terrain. They'll adopt them when they can trust them to operate safely, recover from failures, receive secure software updates, protect operational data, and remain resilient against cyber threats. We've seen this pattern with cloud computing, IoT, and now AI. Capability drives interest, but trust drives adoption. The next generation of robotics won't be defined only by better mobility. It will be defined by how well we secure the software, the supply chain, the communications, and the decisions these machines make in the real world. The future belongs not to the smartest robots, but to the ones people can confidently trust. https://lnkd.in/gqzyvHFv

  • This research is a reminder that security is often about trade-offs. Features designed to protect users can sometimes create new risks when combined in unexpected ways. Good security means looking beyond individual features and understanding how the whole system behaves. 💡 Denis Laskov

    Hack Apple’s Find My network to locate and steal lost items: Security internals and new bugs 📱🧭🧳🔎😈 Security researchers Zhenyu Ren, Yanbo Zhang, Boya Liu, and Mo Li published their research on Apple’s Find My network, how it works, and the ways it leaks data about your lost items that may - and likely will - help others locate your stuff and steal it. These are the facts: 1️⃣ Find My must make lost devices discoverable. 2️⃣ Anti-stalking protections must help strangers detect hidden trackers. Combined, 1 and 2 help thieves locate and steal lost property. How it works: 🏷️ For AirTags and AirPods, a non-owner can trigger the device’s anti-stalking sound. A phone microphone then helps determine the direction of the sound. ⌚ For silent devices such as iPhones and Apple Watches, the system the authors developed uses Bluetooth signal strength and the attacker’s phone-motion sensors to estimate whether they are moving closer. If you’re into the Apple ecosystem or RF cybersecurity, this will be a super fun read for you. Enjoy, and share it with people who use AirTags! :) More details: Snatcher: Apple Find My Network Exposes Your Lost Devices To Strangers [PDF]: https://lnkd.in/gEpwwr9z #cybersecurity #Apple #FindMy #Bluetooth #BLE #hacking #research #privacy #surveillance #tracking #AirTag #AirPods #iPhone #theft #AppleWatch #infosec #tech

    • Aucune description alternative pour cette image
  • Zero-day vulnerabilities always get attention, but this story highlights a bigger challenge. Many organizations still rely on open-source components that quietly become part of critical applications. Over time, some of these projects stop receiving active maintenance, yet they continue running in production because "they still work." That's where risk starts to grow. Security isn't just about patching software when an update is available. Sometimes there isn't a patch. The harder question is whether you know where that component exists, how critical it is, and what your options are if support ends. This is why software inventories and dependency management have become just as important as vulnerability scanning. You can't protect what you don't know you're running. Open source remains one of the strongest drivers of innovation, but it also comes with shared responsibility. Before adopting a library, organizations should ask not only, "Does it solve today's problem?" but also, "Who will maintain it two or five years from now?" The next major security incident may not come from the code you wrote. It may come from the code you forgot was there. https://lnkd.in/g3qh9j3E #CyberSecurity #ApplicationSecurity #OpenSource #DevSecOps #SoftwareSupplyChain #RiskManagement

    • Aucune description alternative pour cette image
  • This isn't just about a 20-year-old vulnerability still being around. It's a reminder that some of the most critical systems are also the ones organizations pay the least attention to. Baseboard Management Controllers (BMCs) sit below the operating system. They're designed to help administrators recover and manage servers, but if exposed to the internet, they can become one of the easiest paths into an entire data center. What stands out isn't the age of the flaw. It's that thousands of systems were still accessible with weak or predictable credentials. That tells us the problem isn't only outdated technology. It's configuration, visibility, and basic security hygiene. Too often, security teams focus on what they can easily see, servers, endpoints, cloud workloads, and applications. The infrastructure that manages those systems can quietly become the weakest link if it's not included in regular security reviews. As organizations continue investing in AI infrastructure and GPU clusters, protecting the management plane becomes even more important. If an attacker gains control there, they don't need to attack every server individually, they've reached the control room. The biggest risks aren't always the newest vulnerabilities. Sometimes they're the trusted systems we've stopped paying attention to. https://lnkd.in/g7qHeGZ5 from Dark Reading by Jai Vijayan #CyberSecurity #DataCenter #InfrastructureSecurity #HardwareSecurity #CyberResilience #RiskManagement

    • Aucune description alternative pour cette image
  • The number of vulnerabilities fixed is attention-grabbing, but that's not the biggest takeaway. The real lesson is that even one of the world's most mature technology ecosystems continues to uncover weaknesses that need to be addressed. Security isn't a finished product. It's an ongoing process of finding, fixing, and improving. Some of these flaws could have allowed apps to gain higher privileges, escape security boundaries, or access sensitive information. While many of these attacks require specific conditions, they reinforce an important principle: every unpatched device extends your exposure. For individuals, installing updates is one of the simplest ways to reduce risk. For organizations, patching is only one part of the equation. Knowing which devices are behind on updates, verifying that patches were successfully applied, and having a plan for high-risk vulnerabilities are just as important. The strongest security programs don't wait for attackers to prove a vulnerability matters. They reduce the opportunity before it can be exploited. Good security isn't about reacting faster after an attack. It's about consistently removing opportunities before they're found. https://lnkd.in/gkmgBNC3 #CyberSecurity #Apple #SecurityUpdates #VulnerabilityManagement

    • Aucune description alternative pour cette image
  • This isn't just another antitrust case. It's a signal that technology companies are entering an era where business decisions will increasingly be evaluated through the lens of trust, fairness, and accountability. For years, security and compliance were often viewed as technical or legal requirements. Today, they're becoming business differentiators. The same is happening with competition and platform governance. As digital platforms grow, every design choice matters, how recommendations are made, how third parties are treated, and how users are given choices. Those decisions can shape markets just as much as innovation itself. For organizations building AI, cloud services, or digital platforms, the lesson is clear: governance should be part of the design process, not a response to regulatory action. The companies that earn lasting trust won't be those that simply meet regulations after the fact. They'll be the ones that build transparency, fairness, and accountability into their products from the beginning. In the long run, trust is more difficult to earn than market share, and far easier to lose. 💡https://lnkd.in/gwgMGKC2 #Technology #AIGovernance #DigitalTrust #CyberSecurity #Compliance #PlatformGovernance #RiskManagement

    • Aucune description alternative pour cette image
  • Whether this bill becomes law or not, it reflects a bigger shift in how governments are thinking about AI. As AI systems become more capable and more deeply integrated into business operations, the conversation is moving beyond innovation. It's becoming about governance, accountability, and operational resilience. A "kill switch" may sound like a simple safety feature, but it also raises important questions. Who decides when it's used? Under what conditions? And how do organizations maintain critical operations if an AI service is suddenly restricted or taken offline? These aren't just regulatory questions. They're business continuity and security questions. Organizations adopting AI should plan for the same scenarios they already prepare for with cloud providers and other critical services: outages, security incidents, and service disruptions. That means understanding dependencies, avoiding single points of failure, and having contingency plans when AI becomes part of critical workflows. The future of AI won't be defined by capability alone. It will also be defined by how resilient our systems remain when AI is unavailable, restricted, or behaves unexpectedly. https://lnkd.in/gX4qc2QC #AISecurity #AIGovernance #CyberSecurity #RiskManagement #BusinessContinuity #EnterpriseAI #Resilience

    • Aucune description alternative pour cette image

Pages similaires

Parcourir les offres d’emploi