Aggregator
有和有效的距离|从 FATF 最新报告看风险控制
Anonymous Researcher Dumps 204 0-Day Exploit Files Before Vendors Can Patch Them
An anonymous GitHub user has quietly assembled one of the most disruptive exploit collections of the year, dropping 204 zero‑day proof‑of‑concept files for dozens of open‑source projects before vendors had a chance to patch them. The archive, hosted under the name “exploitarium” by a researcher using the handle “bikini,” turned coordinated disclosure on its head […]
The post Anonymous Researcher Dumps 204 0-Day Exploit Files Before Vendors Can Patch Them appeared first on Cyber Security News.
一图读懂|GA/T 1390.8—2025 《信息安全技术 网络安全等级保护基本要求 第8部分:IPv6网络安全扩展要求》
Показал один раз — робот запомнил: в Claude Cowork появилась функция обучения по записи экрана
苹果应用商店涌入大量 AI 辅助开发的应用
Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Agents and Steal Data
A newly disclosed flaw in Microsoft’s official Azure DevOps MCP server shows how an invisible comment in a pull request can silently hijack a developer’s AI coding assistant and turn it into a data-exfiltration tool. Security researchers at Manifold Security found that the bug lets an attacker with access to just one project steer a […]
The post Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Agents and Steal Data appeared first on Cyber Security News.
诚邀渠道合作伙伴共启新征程
火绒小问答--「个人版」近期top问题解答
供应链威胁持续发酵:Shai-Hulud出新变种绕过npm防护窃密
OpenAI AI models exploited zero-days to reach Hugging Face in benchmark test
440 уязвимостей за 48 часов: в Linux случился рекордный всплеск CVE
Spain Fines 23andMe €2.4 Million Over Security Failures Behind 6.9 Million-User Breach
Spain’s data protection authority has fined the genetic testing company 23andMe €2.4 million due to security failures linked to a data breach in 2023. This incident exposed highly sensitive information such as genetic, health, ethnicity, and family-related data belonging to over 2,600 individuals in Spain. The penalty follows a significant credential-stuffing attack that compromised data […]
The post Spain Fines 23andMe €2.4 Million Over Security Failures Behind 6.9 Million-User Breach appeared first on Cyber Security News.
为何月球正面和背面接收到太阳风不同
Google’s Gemini 3.5 Flash Cyber becomes a vulnerability hunter
Google’s Gemini 3.5 Flash Cyber model finds, validates, and patches vulnerabilities before they can be exploited while helping mitigate broader misuse. It is part of a limited-access pilot program that will soon be available to governments and trusted partners through CodeMender, Google DeepMind’s AI coding agent, with broader access planned over time. “CodeMender is our managed code security agent, and starting today, we’re bringing its code scanning and remediation capabilities directly to you in preview. … More →
The post Google’s Gemini 3.5 Flash Cyber becomes a vulnerability hunter appeared first on Help Net Security.
从IT到OT:美国国民警卫队“网络盾牌”演习聚焦电力行业关基防护
AI失控后入侵知名企业:系OpenAI内测模型 自主逃离隔离环境
Hackers Abuse Compromised Outlook Accounts to Steal MFA-Protected Microsoft 365 Sessions
Attackers are quietly turning trusted Microsoft Outlook mailboxes into launchpads for stealing multi factor authenticated Microsoft 365 sessions, even when users think they are protected. Adversary in the middle phishing has evolved into a reliable tool for hijacking live cloud sessions that organizations depend on for daily work. The activity surfaced in May 2026, when […]
The post Hackers Abuse Compromised Outlook Accounts to Steal MFA-Protected Microsoft 365 Sessions appeared first on Cyber Security News.