To answer the need for a better, more efficient way for teams to work together, Slack is releasing new AI enhancements set to improve team collaboration and data integration.
These enhancements follow a recent report from Salesforce which highlighted that Slack AI integrations saved50,000 hours of work in just one quarter. With the innovations announced today, customers can centralize everything they need to get work done more efficiently.
Key innovations include:
- Agentforce in Slack: With a new user interface (UI) for agents, teams can now talk to their data, surface insights, and take action on tasks in Slack with Salesforce’s Agentforce Agents.
- Third-party AI agents: AI agents and assistants from partners like Adobe, Anthropic, Cohere, Perplexity, and more can be deployed in the same trusted, secure environment in Slack.
- Salesforce channels: A new type of channel that connects Salesforce CRM records to channel-based conversations in Slack gives teams a comprehensive space to collaborate on every account and opportunity, increasing alignment to move work forward. Coming soon, Salesforce channels will be embedded in the Salesforce user interface.
New enhancements in Slack also include purpose-built AI functionality across search and automation as well as new solutions-based templates to unlock productivity for every use case and line of business.
- New Slack AI features: Enhanced capabilities like huddle notes, simplified automation, and improved search allow teams to work smarter, faster, and with greater focus.
- Slack templates: Collections of ready-to-use templated channels, canvases, lists, and automated workflows make work in any department and for any task faster and more productive.
- AI Workflow Builder: Generates workflows with simple conversational prompts so users can easily automate their tasks.
Availability:
- Third-party agents are available now in the Slack Marketplace, with more coming soon.
- Agentforce (formerly Einstein Copilot) in Slack will be available in beta in October 2024.
- Slack AI is available now as a paid add-on for all paid Slack plans.
- Salesforce channels are available to Slack Sales Elevate customers now and will be included in Salesforce Starter Suite in the coming months.
- Slack templates will be available in October 2024.
Explore more:
- Read more about Slack product innovations at Dreamforce
Horizon3.ai Publishes Details On An Ivanti Cloud Services Appliance Vulnerability
Posted in Commentary with tags horizon3.ai on September 16, 2024 by itnerdHorizon3.ai Chief Attack Engineer Zach Hanley has just published “CVE-2024-8190: Investigating CISA KEV Ivanti Cloud Service Appliance Command Injection Vulnerability”
Ivanti’s advisory reads: Ivanti has released a security update for Ivanti CSA 4.6 which addresses a high severity vulnerability. Successful exploitation could lead to unauthorized access to the device running the CSA. Dual-homed CSA configurations with ETH-0 as an internal network, as recommended by Ivanti, are at a significantly reduced risk of exploitation.
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.
Zach said: “The description definitely sounds like it may have the opportunity for accidental exposure given the details around misconfigurations of the external versus internal interfaces.”
His investigation details how, putting together the pieces, Zach and team achieved a command injection exploit, and looks at Ivanti’s configuration guidance for insight into how some of their clients were being exploited in the wild. Zach’s post also includes indicators of compromise.
Links:
CVE-2024-8190: Investigating CISA KEV Ivanti Cloud Service Appliance Command Injection Vulnerability: https://www.horizon3.ai/attack-research/cisa-kev-cve-2024-8190-ivanti-csa-command-injection/
Security Advisory Ivanti Cloud Service Appliance (CSA) (CVE-2024-8190): https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Service-Appliance-CSA-CVE-2024-8190?language=en_US
CISA KEV – Ivanti Cloud Services Appliance OS Command Injection Vulnerability: https://www.cisa.gov/news-events/alerts/2024/09/13/cisa-adds-one-known-exploited-vulnerability-catalog
Leave a comment »