Skip to main content

XMT

短闻

信流 · 上滑连读 · 来源可核

今日 稍后 搜索 RSS
1 / 24
Aggregate CSO Online 网络安全 45″

SonicWall reports two major security holes under active exploit

SonicWall on Monday reported two major security holes in its Secure Mobile Access 1000 series appliances, both of which it said are being actively exploited, and published patches for each.…

  • Consultants called the holes, one of which permits remote attacks that…
  • In its security alert, SonicWall described the first hole, tracked as …
  • A remote unauthenticated attacker could potentially exploit this vulne…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 12″

AI’s Vulnerability Surge May Be More Manageable Than First Feared

New research suggests the coming Vulnpocalypse may not be so overwhelming for enterprise security teams — if they have the right strategies.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 11″

SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE

The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 13″

AI Gives Cybercriminals a Dangerous Time Advantage

Former cybercriminal Brett Johnson provides a look inside the mind of a threat actor and discusses where AI provides the most value for attackers.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Schneier on Security 网络安全 45″

AI Agents Are Now Emailing Me with Their Security Concerns

I received the two emails below earlier in the month.They’re vaguely coherent.…

  • I suppose I shouldn’t be surprised that the corpus that AIs are traini…
  • After all, I observe that behavior in many humans as well.
  • (Hi, humans.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 14″

Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users

The "Spring Ring" operation aims to compromise users of the collaboration suite to remotely access their sessions, spread malware, and even take over infrastructure.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Anthropic introduces zero-retention AI safety monitoring for enterprises

Anthropic is introducing a new framework aimed at helping enterprises monitor AI misuse without ceding control over sensitive data, as organizations struggle to balance security visibility with strict compliance requirements.…

  • The company announced a new solution called Enterprise Frontier Safegu…
  • Under the approach, activity data used for monitoring will be stored i…
  • The feature will be rolled out in phases later this fall and will be o…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Exploited JFrog Artifactory bug puts software supply chain on alert

A critical authentication bypass in JFrog Artifactory is now being exploited in the wild, with attackers observed generating administrator tokens and probing the software supply-chain platform’s sensitive data.…

  • The flaw, tracked as CVE-2026-82329, was disclosed by JFrog on August …
  • By September 1, watchTowr said its Attacker Eye honeypot was already s…
  • The activity included attackers minting administrator tokens and enume…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Schneier on Security 网络安全 45″

Wireless Routers as Motion Detectors

Comcast has added motion detection as a feature to its wireless routers: The feature sends push notifications to users when motion is detected near a connected device, such as a TV or printer.…

  • It has different settings for when people are home, asleep, or away.
  • The Xfinity app also lets users see live motion activity and a feed of…
  • Comcast acknowledges that the system has some limitations.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

When the patch tsunami meets the maintenance window

In April 2026, the balance between finding software flaws and fixing them broke.…

  • Frontier AI models released by Anthropic and OpenAI can now autonomous…
  • According to the same paper, at least 40 of the largest software and h…
  • Hathaway’s conclusion is blunt: four decades of “field it fast and fix…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

How China industrialized the infrastructure behind state hacking

Last week, the US Justice Department and FBI announced court-authorized seizures of domains hard-coded into two complementary hacking platforms known as “QScan” and “QTRouter,” used by Chinese state-sponsored hackers to target US critical infrastructure and other sensitive networks.…

  • A People’s Republic of China (PRC) state-sponsored group known as “QTF…
  • Among the targets of QTFY are the National Aeronautics and Space Admin…
  • The law enforcement agencies said QTFY offers computer hacking service…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Anthropic makes changes to stop AI agents running amok again

Learning from the OpenAI-Hugging Face fiasco, as well as from recent revelations about its own model, Anthropic is revamping its security and alignment practices.…

  • The company has established controls that flag when a model attempts t…
  • ” Anthropic conceded that three recent security incidents involving Cl…
  • ” Recent events “stressed that the urgency of improving our cybersecur…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 13″

Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency

Threat actors exploited commodity in ownCloud to gain initial access, resulting in stolen reactor databases, personnel records, and credential stores.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

What happens when AI models take aim at ICS exploits

LLMs have shown great improvement in vulnerability research and exploit development capabilities over the past six months.…

  • But it’s one thing to find vulnerabilities in well documented open-sou…
  • That’s why researchers from industrial IoT security firm Forescout set…
  • Using AI assistance to port a known exploit from one model of programm…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Krebs on Security 网络安全 45″

FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada.…

  • Based on interviews with individuals whose licenses are available for …
  • KrebsOnSecurity also has learned that the New Orleans field office of …
  • A record available at this identity theft service that includes the dr…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 14″

Critical Langflow Flaw Exploited as Attacks on AI Platform Rise

The attacks targeting CVE-2026-0768 are the latest threat against the low-code AI development platform, which is receiving more attention from adversaries this year.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 14″

Stronger Security Drives Ransomware Groups to Recruit From Within

Some security researchers have observed an uptick in insider-assisted ransomware attacks, but malicious insiders pose other threats that cost companies millions.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 13″

Attackers Pounce on Critical Artifactory Flaw Following Disclosure

CVE-2026-82329 is an authentication bypass flaw in JFrog's repository manager that enables bad actors to gain admin-level access on affected systems.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 13″

AI Model Evaluator METR Hit by Credential Theft, Probing

In one attack, threat actors stole an API key that ultimately led to the consumption of $600,000 in public AI model credits for the security nonprofit.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

CrowdStrike launches cyber frontier AI models, agentic security system

CrowdStrike today announced SafeMind, a cybersecurity-specific AI model-harness system that CEO George Kurtz described as the “first complete agentic system for cybersecurity” at the company’s Fal.…

  • Con conference in Las Vegas.
  • At the heart of SafeMind are two purpose-built cybersecurity models, t…
  • Both models have been trained on CrowdStrike’s Falcon sensor telemetry…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Schneier on Security 网络安全 45″

What’s the Scam?

To subscribe to my monthly email newsletter, you have to enter your information on the webpage, and then reply to an automatically generated email.…

  • This is, of course, to prevent people from subscribing addresses other…
  • Starting last weekend, I have been receiving a lot of individual respo…
  • Always one line: Thank you for the positive impact your emails have ha…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Schneier on Security 网络安全 45″

Leaked Russian Cyber-Operations Training Materials

This is interesting: The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications, cryptography, and information security.…

  • […] The reporting also linked a 2024 Department No.
  • 4 graduate, Aleksei Kondrashov, to Military Unit 74455, widely known a…
  • That unit has been associated with destructive cyber activity against …

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 13″

ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain

The campaign uses EtherHiding to dynamically update its command-and-control server, abusing the blockchain as an attacker-controlled address book.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 13″

The Guardrails Debate: Security Researcher Changes His Mind

While guardrails are critical, as evidenced by recent high-profile incidents, defenders need help staying ahead of attackers who do not play by the rules.

RSS 官方收录 · 可信分层展示

详情 原文 分享图