網路安全資訊
來自頂級安全媒體的最新動態
共 2391 篇文章,第 9 / 80 頁
A Russian-speaking actor, "Trim," dismantled publicly available frontier models and integrated them with offensive security tools....
By a party-line vote, the Senate Intelligence Committee sent the nomination of Jay Clayton to lead ODNI to the Senate floor....
Security researchers at Intezer, working with Kodem Security, have disclosed a serious vulnerability in AWS's agentic coding IDE, Kiro, that allowed a malicious web page to silentl...
Google DeepMind has launched Gemini 3.5 Flash Cyber, a specialized AI model built atop Gemini 3.5 Flash, engineered to autonomously discover, validate, and patch software vulnerabi...
Microsoft has confirmed that a third SharePoint Server vulnerability patched in its July 2026 Patch Tuesday cycle is now under active exploitation in the wild. Tracked as CVE-20...
Threat actors affiliated with the Qilin (also known as Agenda) ransomware-as-a-service (RaaS) operation have been weaponizing a now-patched high-severity flaw in Palo Alto Networks...
Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component. ...
An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more s...
Every patch is a confession. The moment a vendor ships a security fix, the diff between the old code and the new code tells anyone watching exactly what was broken and where. Turn...
A cloud tenant using nothing but ordinary GPU access can push a data center's power draw up and down fast enough to threaten the grid it runs on, with no exploit and no break-in. ...
AI-generated code introduces 15 vulnerabilities on average per codebase, but the actual risk depends on framework pairing more than the model used....
The Agencia Española de Protección de Datos (AEPD) announced the fine on Friday, saying in its decision that more than 2,600 Spaniards were impacted by a breach affecting 6.9 milli...
The speed of 5G and 4G networks across much of Taiwan will be temporarily reduced to 1 percent of capacity as the island holds annual civilian and military exercises....
The website was hacked on Saturday, when its homepage was replaced with a message displaying a cryptocurrency wallet address and threatening to publish unspecified information abou...
Attackers are actively exploiting two critical vulnerabilities in WordPress—tracked as CVE-2026-63030 and CVE-2026-60137 and collectively codenamed "wp2shell"—to achieve unauthenti...
Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, an AI-agent-driven operator first documented earlier this month. The same threat actor ...
Threat actors are weaponizing a severe sandbox escape vulnerability in the ServiceNow AI Platform, enabling unauthenticated attackers to execute arbitrary code on vulnerable instan...
HollowGraph, a newly documented malware toolkit, is leveraging a compromised Microsoft 365 account's calendar as a two-way dead-drop for command-and-control (C&C) communication, ac...
Gaetje’s story shows that you don’t need to be a ‘deep bit-crawler’ to become a Chief Information Security Officer. The post CISO Conversations: Andreas Gaetje – From Economics to ...
Hackers exfiltrated personal, financial, and health information from the company’s Oracle EBS instance in August 2025. The post Estée Lauder Discloses Impact From Oracle EBS Zero-D...
A security researcher discovered a broken access control vulnerability in Meta’s support infrastructure. The post Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Suppo...
Using social engineering, hackers compromised employee accounts with access to personal and health information. The post Clover Health Investments Discloses Data Breach appeared fi...
The ServiceNow AI platform vulnerability tracked as CVE-2026-6875 can be exploited for remote code execution. The post Exploitation of ServiceNow Vulnerability Seen Days After Disc...
The latest Zimbra refresh resolves command injection, XSS, restriction bypass, and SSRF security defects. The post Zimbra Update Patches Critical Vulnerabilities appeared first on ...
Marc Maiffret reflects on Code Red's legacy and the security lessons helping organizations navigate AI risk today....
Threat actors are actively chaining two newly disclosed vulnerabilities in the WP2Shell management plugin to achieve unauthenticated remote code execution on WordPress sites at sca...
Ivanti is betting that frontier large language models can take the drudgery out of one of cybersecurity's most persistent challenges: patching known vulnerabilities at scale. Chief...
Cybersecurity researchers at Island have uncovered a sprawling malware distribution operation dubbed FakeGit that has flooded GitHub with nearly 7,600 malicious repositories, more ...
Job pressures have increased as companies run headlong into AI adoption, causing 26% of top security executives to consider leaving their position....
"The TFF Trap" uses fileless techniques and loaders with low detection rates to deploy various RATs and stealers, including Agent Tesla, Remcos, XWorm, and Best Private Logger....