Databricks' CSO - Previously: Citrix's CISO, Semmle's CSO, Google's Head of Product Security, MSFT, entrepreneur. Real Madrid supporter. All opinions my own.
1/3 Lately, I have been talking to so many CISOs and their security teams. There is a clear trend. While Data security is generally well understood, AI security is not. Security teams are catching up on MLops, model training, training datasets, model serving, ...
2/3 @databricks has gone through this already and we have a very good understanding of the field. Happy to help!
Are you curious about Data AI security? What about model generation and serving security best practices? What about security use cases for Generation AI and LLMs?
3/3 @databricks is hosting the Data AI Summit Jun/26-29 and our security team will be there to engage with you.
Virtual and on site registration here: databricks.com/dataaisummit/
Excited to launch the first two #LLM MOOC courses with @edXOnline. Learn about prompt engineering, vector embeddings, retrieval, chains, and MLOps. Learn how to create your own LLM from scratch on a data lakehouse!
databricks.com/blog/enroll-o…
I can’t tell which I’m more excited about, Dolly 2.0 or the fact that we’re giving away the 15k instruction tuning records, created by thousands of Databricks employees in the last two weeks, we used to train it.
Free and licensed for commercial use! 🐑
github.com/databrickslabs/do…
Free Dolly! Introducing the first *commercially viable*, open source, instruction-following LLM. Dolly 2.0 is available for commercial applications without having to pay for API access or sharing data with 3rd parties. bit.ly/43oXmsy
I hacked into a @Bing CMS that allowed me to alter search results and take over millions of @Office365 accounts.
How did I do it? Well, it all started with a simple click in @Azure… 👀
This is the story of #BingBang 🧵⬇️
I hacked into a @Bing CMS that allowed me to alter search results and take over millions of @Office365 accounts.
How did I do it? Well, it all started with a simple click in @Azure… 👀
This is the story of #BingBang 🧵⬇️
There is a long history of people not caring about breaches and the stock price recovers (and even outperforms) within X months. Customers just don’t care about security usually. I wonder if things will be different for Lastpass this time…
PREDICTION: There's a mass extinction event coming for early & mid-stage companies. Late '23 & '24 will make the '08 financial crisis look quaint for startups. Below I explain when, why & how it will start & offer *detailed advice to founders* on surviving the looming die-off. /1
Matt Mochary has been CEO coach to @naval, the founders of OpenAI, Notion, Rippling, Robinhood, Coinbase, Reddit, Plaid, Flexport, Opendoor, partners at Sequoia, YC, Benchmark, and many others.
He also open-sourced his entire curriculum, templates and all. Here's a link 👇
Super excited to be here in NYC for the @databricks CDO Forum. Sold out!
I can't wait to deliver my talk around "Securing the Data in your Lakehouse" and network with the fantastic audience.
It has been a pretty amazing week. Nothing big just a small set of tiny nuggets here and there. Thanks to everyone who contributed. Looking fwd to the next couple of weeks and Databrick's security leadership offsite and planning how to conquer the world.
Listen to Nico, he is right here. Vuln management should be outcome driven... reduce risk by mitigating discovered vulns within the minimum time possible. Not having accurate data, wastes time in the short term and impacts the long run by diminishing trust in the effort.
This is -big-.
Building a healthy vuln management program is about building trust relationship with engineer. Every false positive, every non actionable alert diminish that trust.
Which is why accurate dependency alerts are critical!
Great work semgrep team!