Skip to main content

XMT

短闻

信流 · 上滑连读 · 来源可核

今日 稍后 搜索 RSS

当前信源:CSO Online · 清除信源筛选

1 / 24
Aggregate CSO Online 网络安全 45″

FBI investigates breach of 153 million driving license records at IDscan.net

Drivers in North America received a nasty shock this week when it was revealed that digital scans of 153 million drivers’ licenses were for sale on the dark web.…

  • Among the victims were US Defense Secretary Pete Hegseth – and investi…
  • The driving license details were offered for sale by a user of the Rus…
  • In addition to the 153 million driving licenses, the user also offered…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Bidding war for defunct Spirit Airlines’ employee data will not die

The destiny of Spirit Airline’s data is still undecided, months after the company sought bankruptcy protection.…

  • AI data company Micro1 has now offered $12.
  • 5 million to acquire a trove of the company’s emails, Teams chats, ope…
  • 5 million SharePoint items, and more than 30 million recorded customer…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

OpenAI launches GPT-6 Astra, its first model to cross a critical cybersecurity threshold

OpenAI launched GPT-6 Astra on Thursday, disclosing that the new flagship model has crossed the “Critical” threshold for cybersecurity risk under its Preparedness Framework, a classification the company said triggers additional deployment restrictions.…

  • “GPT‑6 Astra is rolling out today to a limited set of organizations an…
  • Enterprise administrators must manually enable Astra for their workspa…
  • Developers can access Astra in the API as gpt-6-astra or through Amazo…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

The democratization of cyber warfare — and what it means for CISOs

For most of modern history, sophisticated and costly warfare had a high barrier to entry.…

  • In order to maintain a significant tactical advantage, you needed mone…
  • In the physical realm, you needed trained and capable warfighters alon…
  • In cyber, you needed operators who understood networks, vulnerabilitie…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

OpenAI targets small utilities with $1 billion cyber defense initiative

In a keynote speech during a summit at OpenAI’s headquarters attended by 300 enterprise security leaders and CISOs from Fortune 1000 companies, OpenAI President Greg Brockman announced Daybreak for Frontline Defenders, a new global initiative to help frontline defenders use frontier cyber AI to protect essential services in the United States and around the world.…

  • The initiative entails a $1 billion global commitment to expand subsid…
  • Daybreak is a defensive model that involves frontier models; the Codex…
  • In announcing the initiative, Brockman said he asked an off-the-shelf …

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Decade-old PostgreSQL flaw turns backup account into a backdoor

A critical vulnerability in PostgreSQL had remained hidden for more than a decade, potentially turning a routine backup account into a path to full database and server compromise.…

  • The issue, dubbed PostGREShell by Cyera Research, exists in the databa…
  • “The flaw lets a low-privilege “backup” account load and execute arbit…
  • “That foothold escalates to full PostgreSQL superuser with persistent …

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Counterfeit installers turn routine software downloads into enterprise breaches

Microsoft has warned that attackers are breaching enterprise systems via counterfeit download sites impersonating software including Microsoft Edge, Kaspersky and Razer, delivering trojanized installers for persistent access.…

  • “Once executed, the malicious installers deploy malware that establish…
  • The campaign, tracked by Microsoft Defender Experts, has impacted orga…
  • The attackers are using a network of spoofed websites mimicking legiti…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

AI agents help compress ransomware intrusion to under 10 hours, raising stakes for CISOs

A ransomware attacker used AI agents to move through an enterprise network in less than 10 hours, according to Palo Alto Networks researchers, who estimated that similar work could have taken human operators about two weeks.…

  • The incident involved more than 50 techniques mapped to the MITRE ATT&…
  • The techniques themselves were largely familiar.
  • The notable difference, according to Unit 42, was the use of AI agents…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Stop playing with the CISO role. Fix cybersecurity leadership

We have spent years telling chief information security officers (CISOs) that they need to become better aligned with the business.…

  • They need to understand strategy.
  • They need to speak the language of the board.
  • They need to build relationships with business leaders.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Zero trust has a big AI agent problem ahead

Despite singing the praises of zero trust for many years, many CISOs have struggled to implement the framework in full.…

  • And now comes what could be the final nail: agentic AI.
  • Can zero trust coexist with autonomous agents in typical enterprise en…
  • Technically, yes.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

SonicWall reports two major security holes under active exploit

SonicWall on Monday reported two major security holes in its Secure Mobile Access 1000 series appliances, both of which it said are being actively exploited, and published patches for each.…

  • Consultants called the holes, one of which permits remote attacks that…
  • In its security alert, SonicWall described the first hole, tracked as …
  • A remote unauthenticated attacker could potentially exploit this vulne…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Anthropic introduces zero-retention AI safety monitoring for enterprises

Anthropic is introducing a new framework aimed at helping enterprises monitor AI misuse without ceding control over sensitive data, as organizations struggle to balance security visibility with strict compliance requirements.…

  • The company announced a new solution called Enterprise Frontier Safegu…
  • Under the approach, activity data used for monitoring will be stored i…
  • The feature will be rolled out in phases later this fall and will be o…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Exploited JFrog Artifactory bug puts software supply chain on alert

A critical authentication bypass in JFrog Artifactory is now being exploited in the wild, with attackers observed generating administrator tokens and probing the software supply-chain platform’s sensitive data.…

  • The flaw, tracked as CVE-2026-82329, was disclosed by JFrog on August …
  • By September 1, watchTowr said its Attacker Eye honeypot was already s…
  • The activity included attackers minting administrator tokens and enume…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

When the patch tsunami meets the maintenance window

In April 2026, the balance between finding software flaws and fixing them broke.…

  • Frontier AI models released by Anthropic and OpenAI can now autonomous…
  • According to the same paper, at least 40 of the largest software and h…
  • Hathaway’s conclusion is blunt: four decades of “field it fast and fix…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

How China industrialized the infrastructure behind state hacking

Last week, the US Justice Department and FBI announced court-authorized seizures of domains hard-coded into two complementary hacking platforms known as “QScan” and “QTRouter,” used by Chinese state-sponsored hackers to target US critical infrastructure and other sensitive networks.…

  • A People’s Republic of China (PRC) state-sponsored group known as “QTF…
  • Among the targets of QTFY are the National Aeronautics and Space Admin…
  • The law enforcement agencies said QTFY offers computer hacking service…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Anthropic makes changes to stop AI agents running amok again

Learning from the OpenAI-Hugging Face fiasco, as well as from recent revelations about its own model, Anthropic is revamping its security and alignment practices.…

  • The company has established controls that flag when a model attempts t…
  • ” Anthropic conceded that three recent security incidents involving Cl…
  • ” Recent events “stressed that the urgency of improving our cybersecur…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

What happens when AI models take aim at ICS exploits

LLMs have shown great improvement in vulnerability research and exploit development capabilities over the past six months.…

  • But it’s one thing to find vulnerabilities in well documented open-sou…
  • That’s why researchers from industrial IoT security firm Forescout set…
  • Using AI assistance to port a known exploit from one model of programm…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

CrowdStrike launches cyber frontier AI models, agentic security system

CrowdStrike today announced SafeMind, a cybersecurity-specific AI model-harness system that CEO George Kurtz described as the “first complete agentic system for cybersecurity” at the company’s Fal.…

  • Con conference in Las Vegas.
  • At the heart of SafeMind are two purpose-built cybersecurity models, t…
  • Both models have been trained on CrowdStrike’s Falcon sensor telemetry…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

OpenClaw rolls out system-wide overhaul, updates security controls across agent platform

OpenClaw has released what it describes as the largest update in its history, introducing a system-wide overhaul spanning runtime behavior, plugins, and security controls, as enterprises increasingly evaluate how such agent-based systems operate across connected environments.…

  • “This update touches every part of OpenClaw, including installation, m…
  • The project said that the scope of the release expanded during develop…
  • “We started by simplifying installation and rebuilding the browser app…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Fake Cloudflare CAPTCHA tricks victims into opening a tunnel for attackers

Attackers are using fake CAPTCHA prompts to trick victims into running malicious PowerShell commands as part of a multi-stage intrusion campaign that can establish persistence, conduct network reconnaissance and potentially give operators a path to deeper access within an organization.…

  • Microsoft Threat Intelligence said a campaign it calls TerminalFix, a …
  • Victims are tricked into copying and running a malicious PowerShell co…
  • “While traditional ClickFix campaigns direct victims to the Windows Ru…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

China-linked hackers turn Cisco routers into covert attack infrastructure

A China-linked cyber espionage group has expanded beyond VMware environments to target network and authentication infrastructure that enterprises rely on to manage access and administer critical systems, according to new findings from incident response firm Sygnia.…

  • The threat actor, tracked by Sygnia as Fire Ant, targeted Cisco IOS XR…
  • The attackers also compromised TACACS authentication infrastructure an…
  • The findings build on Sygnia research published last year that documen…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Microsoft nudges enterprise security closer to its passwordless future. But ‘123456’ will survive.

Today marks the beginning of the end of an era for enterprise Microsoft authentication.As of Sept.…

  • 1, passkeys are now the default authentication method for Entra ID, Mi…
  • 1, 2027, Microsoft-provided SMS and voice authentication will be a thi…
  • The move is seen as one aimed at pushing enterprises toward passwordle…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Windows bug incorrectly tells users that Microsoft Defender Antivirus is turned off

Microsoft on Friday reported that a glitch is causing Windows to tell users that Microsoft Defender Antivirus is turned off when it is in fact fully functional, a bug that the vendor says it is working to fix.…

  • Consultants say that this advisory raises a major concern in that it w…
  • The Microsoft release health dashboard update on the issue reported: “…
  • These notifications can appear when Windows starts and intermittently …

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

OpenAI-led coalition warns AI will compress cyberattack timelines, expose enterprise weaknesses

A coalition led by OpenAI is warning that AI will sharply accelerate the speed and scale of cyberattacks, leaving enterprises with a narrowing window to fix long-standing security weaknesses before they are exploited.…

  • “In the coming months, AI-enabled cyber attacks will become far more w…
  • “We have a limited window to strengthen cyber defenses.
  • ” OpenAI CEO Sam Altman reinforced the urgency in a post on X, calling…

RSS 官方收录 · 可信分层展示

详情 原文 分享图