Skip to main content

XMT

短闻

信流 · 上滑连读 · 来源可核

今日 稍后 搜索 RSS
1 / 24
Aggregate CSO Online 网络安全 45″

OpenAI targets small utilities with $1 billion cyber defense initiative

In a keynote speech during a summit at OpenAI’s headquarters attended by 300 enterprise security leaders and CISOs from Fortune 1000 companies, OpenAI President Greg Brockman announced Daybreak for Frontline Defenders, a new global initiative to help frontline defenders use frontier cyber AI to protect essential services in the United States and around the world.…

  • The initiative entails a $1 billion global commitment to expand subsid…
  • Daybreak is a defensive model that involves frontier models; the Codex…
  • In announcing the initiative, Brockman said he asked an off-the-shelf …

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 14″

Large Enterprises Targeted in Fake Merger & Acquisition Scams

Threat actors behind the "Phantom Deal" campaign are studying companies in extreme detail, aiming to dupe midlevel employees into initiating large financial transfers.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 19″

What We Missed: Did ShinyHunters 'Breach' ReliaQuest?

In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the latest antics of ShinyHunters to new research about the prevalence (or lack thereof) of AI-generated malware.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 12″

'Breeze Comet' Tears Into Brazilian & Global Financial Systems

Brazil's most sophisticated threat group is making light work of the country's financial systems, putting money directly into its own pocket.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 13″

AI 'Machine Speed' Cuts 2-Week Attack Down to 10 Hours

The incident demonstrates how frontier AI agents can dramatically compress an attack timeline and coordinate a large-scale breach, according to researchers.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Decade-old PostgreSQL flaw turns backup account into a backdoor

A critical vulnerability in PostgreSQL had remained hidden for more than a decade, potentially turning a routine backup account into a path to full database and server compromise.…

  • The issue, dubbed PostGREShell by Cyera Research, exists in the databa…
  • “The flaw lets a low-privilege “backup” account load and execute arbit…
  • “That foothold escalates to full PostgreSQL superuser with persistent …

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Counterfeit installers turn routine software downloads into enterprise breaches

Microsoft has warned that attackers are breaching enterprise systems via counterfeit download sites impersonating software including Microsoft Edge, Kaspersky and Razer, delivering trojanized installers for persistent access.…

  • “Once executed, the malicious installers deploy malware that establish…
  • The campaign, tracked by Microsoft Defender Experts, has impacted orga…
  • The attackers are using a network of spoofed websites mimicking legiti…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Schneier on Security 网络安全 6″

Researching Employment Scams

Researchers built a fake company to study fake employee scams.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

AI agents help compress ransomware intrusion to under 10 hours, raising stakes for CISOs

A ransomware attacker used AI agents to move through an enterprise network in less than 10 hours, according to Palo Alto Networks researchers, who estimated that similar work could have taken human operators about two weeks.…

  • The incident involved more than 50 techniques mapped to the MITRE ATT&…
  • The techniques themselves were largely familiar.
  • The notable difference, according to Unit 42, was the use of AI agents…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Stop playing with the CISO role. Fix cybersecurity leadership

We have spent years telling chief information security officers (CISOs) that they need to become better aligned with the business.…

  • They need to understand strategy.
  • They need to speak the language of the board.
  • They need to build relationships with business leaders.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Zero trust has a big AI agent problem ahead

Despite singing the praises of zero trust for many years, many CISOs have struggled to implement the framework in full.…

  • And now comes what could be the final nail: agentic AI.
  • Can zero trust coexist with autonomous agents in typical enterprise en…
  • Technically, yes.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

SonicWall reports two major security holes under active exploit

SonicWall on Monday reported two major security holes in its Secure Mobile Access 1000 series appliances, both of which it said are being actively exploited, and published patches for each.…

  • Consultants called the holes, one of which permits remote attacks that…
  • In its security alert, SonicWall described the first hole, tracked as …
  • A remote unauthenticated attacker could potentially exploit this vulne…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 12″

AI’s Vulnerability Surge May Be More Manageable Than First Feared

New research suggests the coming Vulnpocalypse may not be so overwhelming for enterprise security teams — if they have the right strategies.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 11″

SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE

The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 13″

AI Gives Cybercriminals a Dangerous Time Advantage

Former cybercriminal Brett Johnson provides a look inside the mind of a threat actor and discusses where AI provides the most value for attackers.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Schneier on Security 网络安全 45″

AI Agents Are Now Emailing Me with Their Security Concerns

I received the two emails below earlier in the month.They’re vaguely coherent.…

  • I suppose I shouldn’t be surprised that the corpus that AIs are traini…
  • After all, I observe that behavior in many humans as well.
  • (Hi, humans.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 14″

Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users

The "Spring Ring" operation aims to compromise users of the collaboration suite to remotely access their sessions, spread malware, and even take over infrastructure.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Anthropic introduces zero-retention AI safety monitoring for enterprises

Anthropic is introducing a new framework aimed at helping enterprises monitor AI misuse without ceding control over sensitive data, as organizations struggle to balance security visibility with strict compliance requirements.…

  • The company announced a new solution called Enterprise Frontier Safegu…
  • Under the approach, activity data used for monitoring will be stored i…
  • The feature will be rolled out in phases later this fall and will be o…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Exploited JFrog Artifactory bug puts software supply chain on alert

A critical authentication bypass in JFrog Artifactory is now being exploited in the wild, with attackers observed generating administrator tokens and probing the software supply-chain platform’s sensitive data.…

  • The flaw, tracked as CVE-2026-82329, was disclosed by JFrog on August …
  • By September 1, watchTowr said its Attacker Eye honeypot was already s…
  • The activity included attackers minting administrator tokens and enume…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Schneier on Security 网络安全 45″

Wireless Routers as Motion Detectors

Comcast has added motion detection as a feature to its wireless routers: The feature sends push notifications to users when motion is detected near a connected device, such as a TV or printer.…

  • It has different settings for when people are home, asleep, or away.
  • The Xfinity app also lets users see live motion activity and a feed of…
  • Comcast acknowledges that the system has some limitations.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

When the patch tsunami meets the maintenance window

In April 2026, the balance between finding software flaws and fixing them broke.…

  • Frontier AI models released by Anthropic and OpenAI can now autonomous…
  • According to the same paper, at least 40 of the largest software and h…
  • Hathaway’s conclusion is blunt: four decades of “field it fast and fix…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

How China industrialized the infrastructure behind state hacking

Last week, the US Justice Department and FBI announced court-authorized seizures of domains hard-coded into two complementary hacking platforms known as “QScan” and “QTRouter,” used by Chinese state-sponsored hackers to target US critical infrastructure and other sensitive networks.…

  • A People’s Republic of China (PRC) state-sponsored group known as “QTF…
  • Among the targets of QTFY are the National Aeronautics and Space Admin…
  • The law enforcement agencies said QTFY offers computer hacking service…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Anthropic makes changes to stop AI agents running amok again

Learning from the OpenAI-Hugging Face fiasco, as well as from recent revelations about its own model, Anthropic is revamping its security and alignment practices.…

  • The company has established controls that flag when a model attempts t…
  • ” Anthropic conceded that three recent security incidents involving Cl…
  • ” Recent events “stressed that the urgency of improving our cybersecur…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 13″

Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency

Threat actors exploited commodity in ownCloud to gain initial access, resulting in stolen reactor databases, personnel records, and credential stores.

RSS 官方收录 · 可信分层展示

详情 原文 分享图