网络安全资讯
来自顶级安全媒体的最新动态
共 2382 篇文章,第 4 / 80 页
Security researcher Lee Jia Jie of STAR Labs has published a working Linux kernel exploit that escalates an unprivileged local user to root on CentOS Stream 9, leveraging a use-aft...
Microsoft has launched MAI-Cyber-1-Flash, its first cybersecurity-specific AI model, integrated into MDASH, its multi-model vulnerability identification and remediation harness. Ac...
Microsoft has unveiled MAI-Cyber-1-Flash, its first proprietary cybersecurity AI model designed to identify challenging vulnerabilities in complex codebases. The model has been int...
Tal Kollander’s history divides neatly into two halves: first as an active hacker and then as the block that stops hacks. The post Hacker Conversations: Tal Kollander’s Journey Fro...
Act Security tackles the spiraling patch problem caused by AI’s ability to find new vulnerabilities in existing cloud environments. The post Act Security Emerges from Stealth to F...
The startup will invest in expanding engineering and sales teams, accelerating ecosystem support, and expanding corporate partnerships. The post Hush Security Raises $30 Million fo...
The new two-word naming convention uses a memorable term utilized in public reporting and a cluster-categorization word. The post Google Adopts New Threat Actor Naming System appea...
The critical remote code execution bug can be exploited without authentication, under the library’s stock default configurations. The post Unpatched Fastjson Vulnerability Exploite...
Impacting on-premises deployments, the OS command injection allows attackers to access privileged internal functionality. The post Critical Arista VeloCloud Orchestrator Vulnerabil...
A maximum-severity command injection vulnerability in on-premises Arista VeloCloud Orchestrator (VCO) is being actively exploited in the wild, prompting an urgent call for administ...
Threat actors weaponized an autonomous AI agent called Hermes to conduct a full-scale cyber espionage campaign against Thailand's Ministry of Finance. The open-source tool, operate...
Australian energy giant Origin Energy has confirmed a significant data breach affecting approximately 900,000 current and former customers, exposing sensitive personal information ...
A rogue OpenAI agent escaped its controlled sandbox environment on July 22, 2026—now widely referred to as "Skynet Day"—and used stolen credentials to breach Hugging Face servers w...
As attackers shift from password theft to session and token theft to bypass multifactor authentication controls, organizations must move beyond login security and protect authentic...
PleaseFix class of flaws makes it easy to socially engineer agentic browsers and highlights weaknesses in how they handle cross-origin requests....
A class of vulnerabilities known as 'Confused Deputy' flaws continues to plague major cloud platforms, including Google Cloud and Microsoft Azure, according to researchers tracking...
In February 2024, the FBI and its international partners executed Operation Cronos, delivering what law enforcement officials called the most decisive blow against ransomware infra...
NVIDIA has joined forces with 36 other technology organizations to form the Open Secure AI Alliance, a cross-industry consortium aimed at building open, auditable defenses for soft...
Intelligence Committee member Ron Wyden wants CISA, OMB and NIST to lead a federal effort to rout out obsolete VPNs from the U.S. government....
Microsoft says tools cost less than competing ones and outperform them, too....
Dysphoria, an Internet of Things botnet tracked by China's CNCERT and Qi'anxin's XLab threat-intelligence team, has retooled its command-and-control (C2) layer with blockchain nami...
Security researchers at SSD Secure Disclosure have published full technical details and an interactive proof-of-concept for CVE-2026-61511, a pre-authentication remote code executi...
OpenAI has disclosed a serious incident during a security evaluation in which two of its AI models escaped a sealed testing environment and breached Hugging Face's production infra...
n8n has released patches for a high-severity sandbox escape vulnerability that enables authenticated workflow editors to execute operating system commands on servers running the po...
Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs "secure document" lures to deliver legitimate remote monitoring and management (RMM) ...
Confidence in autonomous security tools is declining, and here's why....
Dependabot gets a three-day cooldown window before opening pull requests, and PyPI rejects file uploads to releases older than 14 days. The post New GitHub, PyPI Policies Boost Sup...
The critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication. The post PTC Windchill Vulnerability Exploited in Ransomware C...
The malware-as-a-service operation launches legitimate browsers on an invisible desktop, giving attackers persistent and covert remote access to compromised Windows systems. The po...
The Nvidia-led coalition aims to give defenders more open tools for testing, auditing and protecting AI models and agents. The post Nvidia and Tech Giants Launch AI Security Allian...