Priča o jednom bankarskom softveru, „nevidljivom“ bagu i lozinkama koje su (bukvalno) skraćene na pola. 🚨 Propust je odavno ispravljen, pa je vreme za lekciju.
(Napomena: Neću pominjati ni firme ni banke koje su ovome "kumovale". Ovo je lekcija kako NE treba raditi.)
Scenario: Menjate lozinku na e-bankingu preko veba. Sistem traži: najmanje 8 karaktera (tada su mislili da je to dovoljno), velika/mala slova, cifre, specijalni znaci. Standardno. Unesete novu lozinku i dobijete poruku: 👉 „Vaša lozinka je uspešno promenjena.“
Odjavite se, probate da se prijavite – pogrešna lozinka. Probate ponovo, pažljivo, preko Notepad-a i copy/paste opcije – opet greška. Treći pokušaj – nalog je uspešno blokiran.
Nakon mučnih razgovora sa korisničkom podrškom i njihovog uveravanja da je „greška sigurno do mene“, seo sam da istražim šta se desilo.
🛠️ Tehnički rezime: Šta je uradio softver?
Ovo je školski primer loše arhitekture, agresivne sanitizacije inputa (Input Sanitization) i potpunog odsustva validacije:
❌ „Tiho“ brisanje karaktera (Silent Failure): U lošem pokušaju da se aplikacija zaštiti od injekcionih napada, developer je upotrebio filter koji je specijalne znakove ($!%#&) jednostavno brisao iz stringa prilikom upisa. Tako je lozinka "tiho" skraćena tj. promenjena, bez ikakve poruke korisniku.
❇️ Kako sam saznao? Pogledao sam kod na front-endu. Kada sam konačno pokušao da se prijavim unoseći lozinku bez tih specijalnih znakova – prošao sam odmah.
❌ Kolaps entropije: Ako ste pratili tadašnja pravila i u lozinku od 8 karaktera stavili 5 specijalnih znakova, vaša stvarna lozinka u bazi imala je svega 3 karaktera. Raj za brute-force napade u roku od nekoliko milisekundi. Iluzija bezbednosti u svom najgorem obliku.
❌ Dodatni bonus: Maksimalna dužina lozinke u sistemu bila je „zakucana“ na samo 16 karaktera.
💡 Lekcija za kraj:
Matematika i entropija su jasne – što je lozinka duža, to bolje. Dužina uvek pobeđuje veštačku kompleksnost karaktera, što danas nalažu i moderne NIST smernice. Džaba sve preporuke ako softver iza kulisa tajno sakati vašu bezbednost.
Da li ste se sretali sa sličnim „kreativnim“ rešenjima u sistemima gde bezbednost mora biti na prvom mestu? 👇
Zato razvijamo https://t.co/KmT3gAuAHX Software Security Solutions – jer bezbednost softvera ne sme da se oslanja na slepe pretpostavke i „tihe“ filtere, već na proaktivnu i pametnu proveru koda.
Naša napredna AI rešenja dubinski analiziraju kod i automatski ispravljaju ovakve skrivene logičke i arhitektonske ranjivosti pre nego što uopšte stignu do produkcije. Umesto pukog skeniranja, fokusiramo se na autonomnu remedijaciju – jer ovakvi bagovi ne treba samo da budu detektovani, već trajno i pravilno popravljeni u samom kodu.
Zapratite @Glog_AI!
#banka #softver #ebanking #lozinke #software #security
The Evolution from Tool to Strategic Asset.
In the world of deep tech, there is a distinct moment when a platform transcends being a 'utility' and becomes a strategic asset.
https://t.co/KmT3gAuAHX has officially crossed that threshold. By merging advanced AI with deep architectural security, we have moved beyond the traditional reactive model. Our platform now secures high-stakes environments where downtime is unacceptable and manual intervention is a fatal bottleneck.
What excites me most isn't just the portfolio of patents, books, and scientific papers, or the decades of R&D and industrial experience behind it, it’s the institutional credibility earned in the field. When your technology is trusted by global leaders in science, energy, telco, critical infrastructure, defence, and finance to secure their core assets, you know you’ve built something truly unique.
The performance metrics speak for themselves: we are now seeing an 80% reduction in manual remediation effort across complex enterprise environments.
We are now looking at the next phase of our evolution. For a technology this 'sticky' and essential, the goal is no longer just incremental growth, but maximum strategic alignment within the broader infrastructure of the digital age.
#DeepTech #Security50 #AIGovernance #ScaleUp #StrategicGrowth #SoftwareSecurity #SovereignAI
The New Arms Race is Algorithmic.
In an era where cyber threats are evolving at the speed of AI, legacy defense systems are no longer enough. To stay ahead, you don't just need a firewall, you need an intelligence that thinks faster than the attack.
Join the Glogosphere: Partner with the Future of Autonomous Security
The era of reactive cybersecurity is over. At https://t.co/KmT3gAuAHX, we are building the Glogosphere, an ecosystem of elite partners dedicated to delivering Security 5.0: predictive, autonomous, and resilient digital environments.
Who We Partner with?
We empower organizations that are ready to move beyond traditional scanners and alerts, including:
✅ MSSPs & MSPs: Enhance your managed services with autonomous remediation and predictive intelligence.
✅ Consultants & Advisors: Offer your clients a roadmap to digital sovereignty and AI-driven efficiency.
✅ VARs & System Integrators: Add a high-margin, “partner-first” solution to your portfolio that solves the talent gap through automation.
Why Partner with https://t.co/KmT3gAuAHX?
1️⃣ Predictive Resilience: Empower your clients to neutralize threats before they manifest, using our advanced AI engines.
2️⃣ Outcome-Based Growth: Generate consistent, recurring revenue through an incentive program designed to reward your expertise and scale.
3️⃣ Sovereignty First: Offer flexible deployment options, including on-premises and private cloud, ensuring your clients maintain total data control.
Let’s Build the Future Together
Ready to scale your business and secure the future? Join us in redefining what’s possible in cybersecurity.
Contact us at [email protected] to explore our partner-first incentive program and start your journey into the Glogosphere.
#Glogosphere #Security50 #AutonomousSecurity #MSSP #PredictiveResilience #CybersecurityAI #DigitalSovereignty #ChannelPartners #ManagedServices #CyberAutomation #AIOperations #PartnerFirst
Big milestones for https://t.co/p8lyGMPGeZ! 🏆
1️⃣ Named a Top 10 AI Innovator in the Serbia AI Landscape 2026 by the Global Investors Forum.
2️⃣ Recommended by the Geneva Manual, validating our methodology for international governance standards.
The future of AI is here.
Big news! 🛡️ https://t.co/KmT3gAuAHX has been named among the top 10 AI Innovators Shaping Serbia's Intelligent Future by the Global Investors Forum
By moving the needle from detection to prediction, we’re making autonomous, self-healing security a reality. Proud to represent Serbian innovation on the global stage.
Onward. 🚀
#AI #TechSerbia #CyberDefense #Software #AISerbia #CyberSecurity #PredictiveIntelligence #Innovation
In a recent independent technical paper, https://t.co/OP36XaoV5P’s methodology was noted for its 'fundamental shift toward a predictive model,' moving beyond traditional reactive security frameworks.
#predictive#resilience#cybersecurity#AI#threat#context@Glog_AI
Is your team drowning in security alerts instead of shipping code?
Introduce speed and precision to your security pipeline with https://t.co/KmT3gAuAHX. We’ve tackled the biggest challenges in application security to bring you a platform that works with your developers, not against them.
https://t.co/KmT3gAuAHX Key Platform Advantages:
🤖 AI Auto-Fix: Get contextual remediation guidance that suggests actual code fixes, not just generic advice.
🔇 Drastic Noise Reduction: Sophisticated triaging eliminates false positives so you focus on real threats.
🛡️ Security by Design: Full integration with Threat Modeling and DevSecOps workflows.
🔒 Intellectual Property Protection: Your source code never leaves your secure environment.
🚀 Automated DevSecOps: Achieve security at the Speed of Development.
Built by scientific and industrial professionals with decades of experience solving real-world software security challenges.
Ready to modernize your approach? Follow https://t.co/KmT3gAuAHX and DM us for a demo
#DevSecOps #CyberSecurity #AI #SoftwareEngineering #AppSec #GlogAI
Note: Image created by Google Gemini AI.
2025 Reflection: From building the engine to winning the race. 🏎️
As 2025 comes to a close, I’ve been taking a moment to look back at the trajectory of https://t.co/KmT3gAuAHX.
It has been a year of quiet but massive validation. We’ve successfully deployed our predictive AI across the most demanding sectors imaginable, from global technology leaders and premier scientific and research institutions to major telecom operators and international banking groups.
We have proven that our automated remediation doesn't just work in a sandbox; it secures the infrastructure that powers the modern world. We have answered the biggest question in AI security: "Is it enterprise-ready?" The answer is a definitive Yes.
We have built a Formula 1 engine. Now, as we look toward 2026, the focus shifts to the track we race on.
We are approaching a key strategic inflection point. The market demand for our tech is outpacing what any specialized team can service alone. To truly capture the opportunity in front of us and to scale the impact of our AI, we realize our next phase of growth requires a different kind of scale.
For 2026, we are actively exploring the right strategic alignments that can act as a catalyst to take this technology global instantly, rather than incrementally.
If you are thinking about how "Agentic AI" and predictive security fit into your platform's DNA next year, let’s have a chat. We are ready for the next chapter. 🚀
#AI #Cybersecurity #StrategicGrowth #Innovation #GlogAI #2026Vision
Visuals for this post were created using Google's Gemini AI.
https://t.co/KmT3gAv8xv obuke za računarsku i softversku bezbednost i primenu veštačke inteligencije. Više detalja na linku sa slike. Trenutna lista:
· Software & Application Security
· Artificial Intelligence for Cybersecurity and Software Security
· Acceptable Use of AI
· Shadow AI - The Hidden Risk in Modern Organizations
· AI Hallucinations - Myths, Risks, and Realities Unveiled
· Data Leakage - Risks of Sharing Sensitive Information with Public AI Models
· Creating Company AI Use Policy
Visit: https://t.co/t8acxD078A
#AI #cybersecurity #software #security
Image generated by Google #Gemini
At https://t.co/KmT3gAuAHX, we prioritize Software Security. Our AI-powered platform ensures seamless code protection by automatically detecting and resolving vulnerabilities throughout the development phase. With our solution, your team can accelerate product innovation while upholding robust security standards.
Effortlessly secure your code with our AI-powered platform that automatically identifies and fixes vulnerabilities during the development process. Empower your team to build innovative products faster, without compromising on security.
#SoftwareSecurity #AI #Innovation
Subscribe to https://t.co/KmT3gAuAHX Security Predictions - Cybersecurity Intelligence!
Leverage the power of foresight with our advanced AI that analyzes threat intelligence to anticipate emerging attack patterns and potential targets. Take preemptive action to neutralize threats before they materialize, ensuring your defenses are always a step ahead.
#threat #intelligence #security #predictions #AI
Is security slowing down your development pipeline? Developers should be building features, not getting bogged down by endless vulnerability reports.
What if you could make your software more secure, seamlessly?
That's exactly what https://t.co/KmT3gAuAHX does. Our solution identifies and helps remediate security vulnerabilities directly within your software code.
✅ Empower your development teams to focus on innovation.
✅ Move towards the ultimate goal: precise context specific remediation advice or even automated security vulnerability remediation.
✅ Make true agility in software security a reality.
Stop choosing between speed and security. Achieve both.
DM me for a demo or visit our website to learn more!
We are also looking for [exclusive] distribution partners for our leading suite of AI-based cybersecurity solutions.
@Glog_AI #DevSecOps #ApplicationSecurity #AppSec #SecureCoding #SoftwareDevelopment #Developer #Cybersecurity #AI
My key cybersecurity messages that I have shared with audiences during recent speaking engagements and panels:
● Prediction is the new standard; reaction is obsolete.
● Automation is not an option, but an imperative.
● Security must be an integral part of everything, not an add-on. It must be built-in from the start.
● Intelligence (context) is more important than data.
● AI is a partner, not a replacement for humans.
● Cybersecurity is a multi-layered and continuous process.
We, at https://t.co/KmT3gAuAHX, develop products, solutions and services that implement exactly these principles.
@Glog_AI #future #cybersecurity #sofwaresecurity #principles #prediction #automation #built_in #intelligence #context #AI #partnership #multi_layered #continuous_process