微信内可能无法直接打开本站。请点右上角 ··· → 在浏览器打开,或复制链接后用系统浏览器访问。
XMT
信流 · 上滑连读 · 来源可核
Using a VM to Contain an AI Agent
It won’t work: My suspicion was that GPT 5.6-Cyber would succeed, but the frequency and manner of its success removed all doubt.…
- We have to reassess sandboxing quality for capable AI agents, and in g…
- An off-the-shelf VM is not enough to contain a modern, cyber-capable A…
- There is simply too much attack surface.
RSS 官方收录 · 可信分层展示
FBI investigates breach of 153 million driving license records at IDscan.net
Drivers in North America received a nasty shock this week when it was revealed that digital scans of 153 million drivers’ licenses were for sale on the dark web.…
- Among the victims were US Defense Secretary Pete Hegseth – and investi…
- The driving license details were offered for sale by a user of the Rus…
- In addition to the 153 million driving licenses, the user also offered…
RSS 官方收录 · 可信分层展示
Bidding war for defunct Spirit Airlines’ employee data will not die
The destiny of Spirit Airline’s data is still undecided, months after the company sought bankruptcy protection.…
- AI data company Micro1 has now offered $12.
- 5 million to acquire a trove of the company’s emails, Teams chats, ope…
- 5 million SharePoint items, and more than 30 million recorded customer…
RSS 官方收录 · 可信分层展示
Security Vulnerability in a Voting System
It’s a vulnerability that allows someone to recover the order of ballots cast, newly exploited with AI tools.…
- Nearly four years since the original vulnerability was disclosed, I wa…
- Notably, I never touched a voting machine, exploited a network, examin…
- After pointing a coding agent to the original vulnerability paper, I s…
RSS 官方收录 · 可信分层展示
AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks
We cannot forget that AI coding agents are not yet trustworthy: Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies.…
- Of the 8,265 llms.
- txt and llms-full.
- txt files they found (many sites hosted both an llms.
RSS 官方收录 · 可信分层展示
OpenAI launches GPT-6 Astra, its first model to cross a critical cybersecurity threshold
OpenAI launched GPT-6 Astra on Thursday, disclosing that the new flagship model has crossed the “Critical” threshold for cybersecurity risk under its Preparedness Framework, a classification the company said triggers additional deployment restrictions.…
- “GPT‑6 Astra is rolling out today to a limited set of organizations an…
- Enterprise administrators must manually enable Astra for their workspa…
- Developers can access Astra in the API as gpt-6-astra or through Amazo…
RSS 官方收录 · 可信分层展示
The democratization of cyber warfare — and what it means for CISOs
For most of modern history, sophisticated and costly warfare had a high barrier to entry.…
- In order to maintain a significant tactical advantage, you needed mone…
- In the physical realm, you needed trained and capable warfighters alon…
- In cyber, you needed operators who understood networks, vulnerabilitie…
RSS 官方收录 · 可信分层展示
OpenAI targets small utilities with $1 billion cyber defense initiative
In a keynote speech during a summit at OpenAI’s headquarters attended by 300 enterprise security leaders and CISOs from Fortune 1000 companies, OpenAI President Greg Brockman announced Daybreak for Frontline Defenders, a new global initiative to help frontline defenders use frontier cyber AI to protect essential services in the United States and around the world.…
- The initiative entails a $1 billion global commitment to expand subsid…
- Daybreak is a defensive model that involves frontier models; the Codex…
- In announcing the initiative, Brockman said he asked an off-the-shelf …
RSS 官方收录 · 可信分层展示
What We Missed: Did ShinyHunters 'Breach' ReliaQuest?
In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the latest antics of ShinyHunters to new research about the prevalence (or lack thereof) of AI-generated malware.
RSS 官方收录 · 可信分层展示
Decade-old PostgreSQL flaw turns backup account into a backdoor
A critical vulnerability in PostgreSQL had remained hidden for more than a decade, potentially turning a routine backup account into a path to full database and server compromise.…
- The issue, dubbed PostGREShell by Cyera Research, exists in the databa…
- “The flaw lets a low-privilege “backup” account load and execute arbit…
- “That foothold escalates to full PostgreSQL superuser with persistent …
RSS 官方收录 · 可信分层展示
Counterfeit installers turn routine software downloads into enterprise breaches
Microsoft has warned that attackers are breaching enterprise systems via counterfeit download sites impersonating software including Microsoft Edge, Kaspersky and Razer, delivering trojanized installers for persistent access.…
- “Once executed, the malicious installers deploy malware that establish…
- The campaign, tracked by Microsoft Defender Experts, has impacted orga…
- The attackers are using a network of spoofed websites mimicking legiti…
RSS 官方收录 · 可信分层展示
AI agents help compress ransomware intrusion to under 10 hours, raising stakes for CISOs
A ransomware attacker used AI agents to move through an enterprise network in less than 10 hours, according to Palo Alto Networks researchers, who estimated that similar work could have taken human operators about two weeks.…
- The incident involved more than 50 techniques mapped to the MITRE ATT&…
- The techniques themselves were largely familiar.
- The notable difference, according to Unit 42, was the use of AI agents…
RSS 官方收录 · 可信分层展示
Stop playing with the CISO role. Fix cybersecurity leadership
We have spent years telling chief information security officers (CISOs) that they need to become better aligned with the business.…
- They need to understand strategy.
- They need to speak the language of the board.
- They need to build relationships with business leaders.
RSS 官方收录 · 可信分层展示
Zero trust has a big AI agent problem ahead
Despite singing the praises of zero trust for many years, many CISOs have struggled to implement the framework in full.…
- And now comes what could be the final nail: agentic AI.
- Can zero trust coexist with autonomous agents in typical enterprise en…
- Technically, yes.
RSS 官方收录 · 可信分层展示
SonicWall reports two major security holes under active exploit
SonicWall on Monday reported two major security holes in its Secure Mobile Access 1000 series appliances, both of which it said are being actively exploited, and published patches for each.…
- Consultants called the holes, one of which permits remote attacks that…
- In its security alert, SonicWall described the first hole, tracked as …
- A remote unauthenticated attacker could potentially exploit this vulne…
RSS 官方收录 · 可信分层展示