Workflow
安全运营
icon
Search documents
环球问策|微步在线薛锋:数字化时代网络安全≠软件防御,安全运营应回归本质
Huan Qiu Wang· 2025-08-27 04:25
Group 1 - The current cybersecurity landscape has significantly changed compared to ten years ago, with most enterprises having completed digital transformation and requiring a reassessment of cybersecurity importance [1][3] - Many companies still hold outdated views, believing that purchasing cybersecurity software guarantees safety, while real threats like phishing attacks demonstrate the inadequacy of this approach [3][4] - Companies face eight major challenges in security operations, including phishing attacks, vulnerability management, and credential misuse, necessitating a return to the essence of security operations and improvement of foundational capabilities [3][4] Group 2 - The cybersecurity industry is experiencing internal competition driven by low pricing strategies, as many digitalized enterprises fail to recognize the evolving nature of cybersecurity [4] - This low-price competition leads to a negative cycle where customers face unresolved cybersecurity issues after initial engagement, highlighting the need for proactive measures [4] - The company aims to differentiate itself by helping enterprises prevent cybersecurity incidents before they occur, advocating for a positive industry development rather than reactive measures post-incident [4]
API攻击激增,安全智能体何以安全?丨ToB产业观察
Tai Mei Ti A P P· 2025-07-17 11:36
Group 1: AI and Cybersecurity Risks - AI has introduced greater risks to enterprise cybersecurity, with 57% of privacy and data security issues and 55% of AI-driven cyberattacks being attributed to generative AI cloud security concerns, yet only 7% of IT decision-makers believe there are no related security risks [2] - The complexity of attack methods has increased, with attackers leveraging a larger internet exposure as an entry point, utilizing AI capabilities for social engineering phishing attacks and supply chain attacks, leading to full-chain attacks [3] - Gartner predicts that by 2025, the adoption of generative AI will increase the need for cybersecurity resources in enterprises, resulting in a more than 15% rise in application and data security spending [3] Group 2: API Security Concerns - In the past year, China spent the highest cost on resolving API security incidents, amounting to $778,000 (approximately 5.68 million RMB), with a total of 108 billion API attacks recorded in the Asia-Pacific region from January 2023 to June 2024, accounting for 15% of all web attacks [4] - Over 60% of web attack traffic is focused on API interfaces, with attack volume increasing by 23% year-on-year, driven by the new threat exposure brought by the large-scale implementation of generative AI technology [4] - Common API vulnerabilities include misconfigurations, network firewalls not intercepting, and authorization flaws, with API misconfiguration being the most prevalent at 22.3% [5] Group 3: Web Security Trends - Web vulnerability exploitation attacks are expected to increase by 68% in 2024, with a significant rise in attacks targeting AI application vulnerabilities [6] - The concept of using AI to combat AI is gaining traction, with security service providers launching corresponding large model services to enhance threat detection and response capabilities [7][8] - The evolution of web security defense has shifted from static rule-based defenses to dynamic game-theoretic defenses, with AI becoming the central component of security systems [9] Group 4: Systematic Defense Strategies - Enterprises are moving towards a systematic defense approach, integrating various security tools into a cohesive defense mechanism, breaking down data silos and policy fragmentation [11] - For API security, companies need to establish a comprehensive API security strategy, including continuous discovery of vulnerabilities, threat management systems, and proactive testing [12] - The demand for security operations is driving the development of security service providers, focusing on asset, vulnerability, threat, intelligence, and security policy operations [13]
北京市公安局举办“平安有我”安全宣讲走进出租车、网约车和汽车租赁行业主题活动
Yang Shi Wang· 2025-05-29 12:42
Core Viewpoint - The "Safe with Me" safety promotion event aims to enhance safety awareness and operational safety in the taxi, ride-hailing, and car rental industries in Beijing [4]. Group 1: Event Overview - The event was organized by the Beijing Public Security Bureau in collaboration with the Beijing Transportation Commission and other relevant units [1]. - Key stakeholders, including leaders from the Beijing Public Security Bureau, the Transportation Commission, and representatives from the taxi and car rental industries, participated in the event [1]. Group 2: Safety Promotion Activities - A safety promotional video titled "What Capital Taxi Drivers Should Know" was played during the event [3]. - The event featured speeches from leaders of the Beijing Public Security Bureau, who introduced the "Safe with Me" safety promotion theme [3]. - A police team from various departments provided lectures on safety management, traffic safety, and prevention of various risks, including drug abuse and terrorism [3]. Group 3: Industry Impact - The main goal of the event is to convey safety operation concepts within the taxi, ride-hailing, and car rental industries, thereby improving safety prevention levels [4]. - The Beijing Public Security Bureau plans to continue the "Safe with Me" safety promotion activities to enhance public safety awareness and encourage community participation in safety measures [4].