JusticeTech System
الذهاب إلى القناة على Telegram
Learn to learn before you teach
إظهار المزيدلم يتم تحديد البلدالفئة غير محددة
227
المشتركون
لا توجد بيانات24 ساعات
-17 أيام
+130 أيام
أرشيف المشاركات
Now everyone knows exactly which student is being discussed.
CVE works somewhat like that.
Instead of saying "That Log4j vulnerability"
security researchers can refer to its standardized identifier:
CVE-2021-44228
Everyone can use that identifier to refer to the same vulnerability.
Imagine that millions of students attend different schools.
If someone says "The student named John", there could be thousands of Johns, so the school might give every student a unique student ID.
For example:
Student ID: 2026-004821
1. CVE
What is CVE?
It stands for common Vulnerabilities and Exposures
It is basically a standard naming system for publicly known cybersecurity vulnerabilities.
Two major things we are going to focus on
Two important things you need to understand are:
CVE >> gives a vulnerability an identification number.
CVSS >> gives that vulnerability a severity score.
Let me quickly address this
There's difference between a house and a home.
House is a physical tangible structure
Home is a place where you feel sense of belonging it does not necessarily needs to be your family. A home is more of emotional, psychological and social concept
You will be shocked that many adults don't know this
Lol
Now you know
Think about your house
Imagine the house has astrong front door, a strong windows but one window doesn't lock.
That unlocked window is a weakness because someone could potentially use that weakness to get into the house.
The same idea applies to computers.
So a vulnerability is a weakness or mistake in a computer system that could potentially be exploited.
Let's imagine you are the security guard of a huge school.
Your job is to find weaknesses in the school before someone uses them to cause problems.
In cybersecurity, computers, websites, apps, servers, and networks can also have weaknesses. These weaknesses are called vulnerabilities.
I will glance through some part of cybersecurity while teaching this so prepare your mind
+1
‼️🚨 BREAKING: Security researchers have uncovered all of those who fell victim to the LiteLLM supply chain attack by obtaining its archive: 153GB holding 433,909 files from 2,488 organisations.
According to Hudson Rock and CloudSEK, victims include Nvidia, AWS, Samsung, Boeing, Intel and more.
This is one of the biggest hits by TeamPCP yet.
The archive contains 118,829 CI/CD runner dumps attributed to corporate domains, with signing secrets and AI provider API keys sitting in plaintext.
If you ran LiteLLM 1.82.7 or 1.82.8, assume every secret in that environment is burned.
Link to article: https://infostealers.com/article/largest-ai-supply-chain-breach-of-2026-litellm-hack-impacts-thousands-of-global-enterprises-claim-your-ethical-disclosure/
Link to full list of victims: https://exposure.cloudsek.com/ai-supply-chain-incident
