網路安全資訊
來自頂級安全媒體的最新動態
共 2382 篇文章,第 3 / 80 頁
OpenAI has confirmed that the autonomous AI agent which escaped its sealed evaluation environment and penetrated Hugging Face's production infrastructure on July 16, 2026, also exp...
Security researchers at Rapid7 have published full technical details and a working proof-of-concept (PoC) exploit for CVE-2026-16232, a critical authentication bypass vulnerability...
Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch con...
Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent researcher NetAskari traced...
A total of five vulnerabilities have been patched in VMware ESXi, vCenter, Workstation, and Fusion. The post Critical VM Escape Vulnerability Patched in VMware ESXi appeared first ...
The guidance details steps organizations can take to isolate vital OT and supporting systems, and operate in isolation for an extended period. The post US, Australia Release OT Iso...
Hugging Face has published an anatomy of the attack and OpenAI has shared additional information from its investigation. The post OpenAI’s Rogue AI Ventured Beyond Hugging Fa...
The IP intelligence company will use the fresh investment to accelerate and scale its operations. The post Spur Raises $200 Million for IP Intelligence Platform appeared first on S...
The OpenAI models targeted services beyond Hugging Face as they attempted to solve the tasks they were given. The post JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack appeare...
State and federal agencies respond after intrusions disrupt automated controls at municipal water and wastewater utilities. The post Dozens of Minnesota Water Utilities Targeted in...
Ernst & Young previously confirmed that personal and financial information was stolen from a third-party management platform. The post ShinyHunters Claims Ernst & Young H...
Two beta versions of npm packages in the @joyfill namespace—@joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4—have been compromised to deliver a rem...
Anthropic's Claude Mythos Preview has achieved a significant cryptanalytic breakthrough, deriving an end-to-end key-recovery attack against the HAWK-256 post-quantum signature sche...
Security researcher Aleksandr Krasnov has spotlighted a growing blind spot in cloud environments: dormant non-human identities (NHIs) that retain trust paths long after they should...
Thousands of internet-exposed Baseboard Management Controllers (BMCs) and similar remote hardware management interfaces are vulnerable to offline password-cracking attacks, and thr...
OpenAI's latest AI agent sandbox escape has sent ripples through the security community, reinforcing a message practitioners have preached for decades: foundational security hygien...
Researchers propose focusing on identification of certain cognitive elements in LLMs that indicate when AI systems may take an unwanted action....
A party-line vote in the Senate installed Jay Clayton as director of national intelligence, a job that has drawn increasing scrutiny during Donald Trump's second term as president....
Cybersecurity researchers at Israeli firm Lava have identified more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing the Intelligent Platform Manage...
JFrog has confirmed that OpenAI models exploited a zero-day vulnerability in self-hosted Artifactory during a sealed ExploitGym cyber-capability evaluation, before escalating the a...
Security researchers at Nozomi Networks Labs have uncovered a new Mirai-derived botnet dubbed Tengu that targets Linux-based IoT devices with an unusually resilient persistence ...
OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default. The critical is...
The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of...
Microsoft patched a high-severity vulnerability earlier this month that allows a threat actor to escalate privileges and compromise an AD environment....
The cybersecurity pioneer discusses the evolution of the CISO role, AI's impact on careers, and why operational resilience is the profession's next frontier....
Oasis Security recently raised $120 million in Series B funding for its agentic access management platform. The post Cyera Acquiring Oasis Security in $1 Billion Deal appeared firs...
Apple announced that dozens of vulnerabilities have been patched in each of its operating systems. The post Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe appeared fir...
The company will use the fresh investment to grow its customer success and AI R&D teams. The post OT Security Startup Frenos Raises $1.52 Million appeared first on SecurityWee...
An employee's email account had been compromised, allowing unauthorized access to "certain data," Bank of Baroda reported....
JetBrains has disclosed a critical security vulnerability in its on-premises TeamCity CI/CD platform that allows unauthenticated attackers to execute arbitrary operating system com...