網路安全資訊
來自頂級安全媒體的最新動態
共 1540 篇文章,第 1 / 52 頁
The National Security Agency is undertaking one of the most significant restructurings in a decade, breaking up its traditional directorates and replacing them with five new "missi...
Anthropic CEO Dario Amodei issued a stark warning Saturday, urging the artificial intelligence industry to decelerate its rapid development cycle to allow safety guardrails time to...
Microsoft has disclosed two concurrent threat campaigns targeting enterprise users, one leveraging AI-generated CEO impersonation emails to steal funds via fraudulent ACH transfers...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik Router...
Enterprise security operations centers are seeing an unprecedented category of alert emerge: those triggered not by attacks against AI, but by the ordinary daily use of AI tools ac...
A coordinated cyberattack that flooded RubyGems with more than 2,000 malicious packages in May 2026 has been traced to a swarm of autonomous OpenAI agents, according to new researc...
Proofpoint researchers have identified a new exploit kit dubbed BlueMoon that chains three previously unpatched vulnerabilities—two zero-days in Chrome and one in Windows—to compro...
Anthropic has disclosed that users operating from Houthi-controlled territory in northern Yemen attempted to weaponize its Claude AI model to develop advanced missile systems, hype...
A threat actor has leveraged generative AI to produce one million highly personalized fraud emails in just three days, signaling a new era of scalable, credible phishing operations...
A new joint government advisory signals a regulatory shift, pressing organizations to adopt more transparent breach notification and incident response protocols....
Fred Heiding of Menlo Park Intelligence talks with the Dark Reading News Desk about his research on frontier models, and their ability to influence human behavior and create emotio...
The Florida Department of Motor Vehicles confirmed a data breach claimed by the cybercrime group ShinyHunters, saying it originated with the theft of credentials stored on a police...
GitLab has shipped emergency patches for a maximum-severity path traversal vulnerability—CVE-2026-85706 with a CVSS score of 10.0—that is already being probed by attackers in real ...
Anthropic disclosed on Thursday that it identified and disrupted industrial-scale illicit distillation attacks targeting Claude, tracing the activity to seven AI labs based in Chin...
Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between ...
Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of t...
Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerab...
Adversaries can manipulate AI defensive reasoning to silently compromise target networks....
From creating lab environments for staging and testing agentic attacks to reconnaissance to lateral movement and exfiltration, the most innovative attackers are widely incorporatin...
Analysis of 2.47 million simulated attacks shows why organizations should measure credential leaks and reporting, not just clicks. The post Phishing Research Challenges Conventiona...
The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server. The post GitLab Vulnerability Exploited One Day After Dis...
Noteworthy stories that might have slipped under the radar: Invisible Unicode slips past phishing filters, US puts $10 million bounty on Iranian cyber official, military ties of Ch...
Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking. The post Trezor Says 347,000 Users Recei...
Researchers analyzed a flood of fraudulent business emails and found that the threat actors had doubled-up on tactics to make them appear legitimate, including help from AI....
Anthropic detected and disrupted a Russia-linked cyber-espionage group that used its AI tool Claude in a hacking campaign targeting more than 20 government, intelligence, diplomati...
A Ukrainian national was sentenced to four years in a U.S. prison for his role in the notorious Conti ransomware operation, which targeted more than 1,000 victims worldwide before ...
PaperCut has rolled out Regular Maintenance Releases (MR) — versions 26.0.5, 25.0.13, and 24.1.10 — that supersede the three emergency patches previously shipped for PaperCut NG/MF...
Attackers have chained two flaws in JFrog Artifactory to seize administrator control of self-hosted instances and deploy persistent backdoors, according to a report from cloud secu...
A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' c...
Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center ...