Carnegie Mellon University Software Engineering Institute

Carnegie Mellon University Software Engineering Institute The SEI is a federally funded research and development center (FFRDC).

The Department of War is increasingly using digital twins and digital engineering to support training, testing, cybersec...
09/10/2026

The Department of War is increasingly using digital twins and digital engineering to support training, testing, cybersecurity, mission rehearsal, and AI-enabled analysis. But how much of the real system needs to be reproduced for an effective simulation?

In the Nov. 4 webcast "How Real Is Real Enough? A Decade of Lessons from GHOSTS," the SEI's Dustin Updyke and Matthew Butkovic draw on a decade of developing and deploying General Human-Oriented Synthetic Teammates and Systems (GHOSTS) to examine how engineers can determine the level of realism needed and decide what must be modeled--including networks, users, organizations, adversaries, and autonomous agents--and what can safely be left out - https://events.zoomgov.com/ev/AsFKaBZclrg-380IvZ2LTzLR9DOOS7AOpHVnT-tLQ8yOBpevI35I~Ai79iWPleSo0EBvoK-RNkswskc5q2KXxm6ShqQlkIe6NQ9dR0l336pVzQA

A New CERT Vulnerability Note: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vuln...
09/09/2026

A New CERT Vulnerability Note: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability - https://kb.cert.org/vuls/id/943094

The SEI has opened registration for Mission Ready Research 2026: Innovation in Action. This free, in-person event on Nov...
09/08/2026

The SEI has opened registration for Mission Ready Research 2026: Innovation in Action. This free, in-person event on November 18 and 19 in Pittsburgh will showcase the SEI’s latest achievements and research advancements in artificial intelligence, cybersecurity, and software engineering.

Participants can engage directly with the SEI engineers and researchers transitioning innovation to drive demonstrable results, meet with SEI staff to discuss solutions to today’s challenges, and establish a mission partnership with the SEI. Demonstrations will provide hands-on experience with the latest software solutions - https://www.sei.cmu.edu/news/mission-ready-research-event-to-demonstrate-innovation-in-action/?utm_source=social&utm_medium=fb&utm_campaign=news_fb

The appeal of applying AI to MBSE is apparent. Our latest post explores how to integrate AI without weakening engineerin...
09/03/2026

The appeal of applying AI to MBSE is apparent. Our latest post explores how to integrate AI without weakening engineering rigor -

The appeal of applying AI to MBSE is apparent. This post explores how to integrate AI without weakening engineering rigor.

Check out the latest Tactical Guide in the Software Acquisition Go Bag, "The Key to SWP Success: The User Agreement" - h...
09/02/2026

Check out the latest Tactical Guide in the Software Acquisition Go Bag, "The Key to SWP Success: The User Agreement" -https://www.sei.cmu.edu/documents/6567/The_Key_to_SWP_Success_The_User_Agreement.pdf

Collaboration among the Program Management Office, the Product Team, and users is paramount to the success of software acquisition. The user agreement is the cornerstone of that collaboration and a key document for programs on the Software Acquisition Pathway. Even those not on the SWP, but who are using Agile development methods, should consider developing and adopting a user agreement to get commitment from users to participate throughout the software development lifecycle.

As open‑source ecosystems grow ever more central to modern software development, the traditional view of Coordinated Vul...
08/28/2026

As open‑source ecosystems grow ever more central to modern software development, the traditional view of Coordinated Vulnerability Disclosure (CVD) as a “nice‑to‑have” becomes dangerously inadequate.

In a recent talk at the 38th Annual FIRST Conference, “From CVD to Secure Releases: Automating Security from Source to Releases,” the SEI's Vijay Sarvepalli and Christopher Cullen argue that CVD must evolve: not just to notify, but to actively secure software supply chains, builds, releases, and audit tools. By integrating CVD into developer workflows on platforms such as GitHub, GitLab, and public registries like npm and PyPI, we can shift security “left,” enforce continuous policy checks, and ensure that disclosure actually leads to safer software in production -

Vijay Sarvepalli (Software Engineering Institute, US), Christopher ...

Address

4500 5th Avenue
Pittsburgh, PA
15213

Alerts

Be the first to know and let us send you an email when Carnegie Mellon University Software Engineering Institute posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share