Aggregator
【报告】美国专门负责中国方向工作与对华研究机构的开源情报深度调研
CVE-2026-64530 | Linux Kernel up to 7.1.4 cls_api net/sched/cls_api.c tcf_qevent_handle use after free (EUVD-2026-49051 / Nessus ID 330017)
连续四年!威努特工业防火墙蝉联中国市场份额第一
【AI复盘】AI Coding Agent攻击手法:bash
Claude Opus 5 sharpens coding and cybersecurity work on AWS
Claude Opus 5 went live on Amazon Bedrock and Claude Platform on AWS. Anthropic says the model improves on Claude Opus 4.8’s cyber capabilities, coding through cybersecurity. Anyone with an AWS account in a supported region can call it. On higher-risk requests, Opus 5 hands the job back to Opus 4.8, the older model. The user sees a notice when that happens. API customers can configure the fallback. The guardrail that catches the riskiest requests … More →
The post Claude Opus 5 sharpens coding and cybersecurity work on AWS appeared first on Help Net Security.
D^3CTF 2026
Date: July 25, 2026, noon — 26 July 2026, 12:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://d3c.tf/
Rating weight: 69.22
Event organizers: D^3CTF Organizers
When AI Breaks Its Own Cage: The OpenAI Model That Hacked Hugging Face
AI agents are no longer passive tools waiting for simple prompts. A recent incident involving an OpenAI frontier model and […]
The post When AI Breaks Its Own Cage: The OpenAI Model That Hacked Hugging Face appeared first on HawkEye.
Физики создали «электронный маяк», который направляет электрический ток с помощью света
APT28, UNC3886, FIN11 — запутались? Google тоже. И решила переделать всю систему названий для группировок с нуля
CVE-2026-57990 | Microsoft Edge information disclosure (EUVD-2026-49059)
CVE-2026-57989 | Microsoft Edge up to 150.0.4078.80 improper authorization (EUVD-2026-49058)
CVE-2026-17501 | ggml-org llama.cpp e15efe0 JSON-Schema-to-GBNF Conversion json-schema-to-grammar.cpp transform allocation of resources (Issue 25283 / EUVD-2026-49061)
CVE-2026-17500 | ggml-org llama.cpp d006858/e15efe0 json-schema-to-grammar.cpp _visit_pattern null pointer dereference (Issue 25284 / EUVD-2026-49060)
Submit #798504: ggml-org llama.cpp (confirmed on commit e15efe0 / tag b8635+1) Uncontrolled Recursion [Accepted]
Submit #798503: ggml-org llama.cpp confirmed on commit d006858 / 2025-04-03 and commit e15efe0 / tag b8635+1) Reachable Assertion [Accepted]
CVE-2026-57978 | Microsoft Edge up to 150.0.4078.80 improper authorization (EUVD-2026-49057)
Венера буквально разрывает себя изнутри: гигантские трещины оказались слишком свежими для «мёртвой» планеты
Claude AI Shared Chats Reportedly Exposed in Google Search Results
Anthropic’s Claude share links appeared in public search results, raising fresh privacy concerns for users who shared sensitive conversations. A Reddit post this weekend revealed that hundreds of Claude AI shared chats were publicly discoverable through Google. Users searching queries such as site:claude.ai/share could access conversations containing legal advice, engineering work, and personal discussions without […]
The post Claude AI Shared Chats Reportedly Exposed in Google Search Results appeared first on Cyber Security News.
Weekly Cyber Security Newsletter Bulletin – Certighost Exploit, Checkpoint 0-day, HTTP/2 Flaw, Notepad++ Plugin Abuse +20 Stories
Threat actors continued to combine classic exploitation techniques with AI-accelerated tooling this week, from a 15-year-old NGINX bug and an actively exploited Check Point authentication flaw to autonomous AI agents chaining zero-days against Hugging Face. Below is a roundup of 18 major stories covering ransomware, AI security, kernel vulnerabilities, cloud/SaaS abuse, and critical infrastructure flaws. […]
The post Weekly Cyber Security Newsletter Bulletin – Certighost Exploit, Checkpoint 0-day, HTTP/2 Flaw, Notepad++ Plugin Abuse +20 Stories appeared first on Cyber Security News.