Aggregator
【安全圈】苹果崩了!App Store等多项服务故障
Marathon Petroleum’s CISO on OT security automation, supply chain risk
In this interview with Help Net Security, Mary Rose Martinez, CISO at Marathon Petroleum, talks about what happens to security when automation reaches deep into refineries, pipelines, and terminals. She explains why the old idea of air-gapped operational technology has faded, how the Purdue model helps her team apply controls without stopping production, and where supply chain risk sits when vendors and their vendors hold the keys. She also covers cross-skilling the workforce and working … More →
The post Marathon Petroleum’s CISO on OT security automation, supply chain risk appeared first on Help Net Security.
LockBit5 and Qilin Lead Ransomware Attacks Against Italian Organizations
华为据报道在建造内存芯片工厂
Nono: Open-source sandbox for AI agents
An AI coding agent opens a terminal, reads a config file, and finds a live cloud key sitting in plaintext. It runs with the permissions of the person who launched it. Every file that person can read, the agent reads. Every credential in the environment, the agent can use. That reach is where the damage starts. A prompt injection, a mistyped command, or a hallucinated path points that access at the company’s own credentials and … More →
The post Nono: Open-source sandbox for AI agents appeared first on Help Net Security.
CVE-2025-43210 | Apple macOS MediaToolbox Framework memory corruption (EUVD-2025-209193)
CVE-2024-44219 | Apple macOS up to 15.0 permission
CVE-2024-44250 | Apple macOS up to 15.0 App permission
CVE-2025-43210 | Apple iOS/iPadOS Media File out-of-bounds (EUVD-2025-209193)
CVE-2025-43210 | Apple tvOS Media File out-of-bounds (EUVD-2025-209193)
CVE-2025-43210 | Apple visionOS Media File out-of-bounds (EUVD-2025-209193)
CVE-2025-43210 | Apple watchOS Media File out-of-bounds
CVE-2024-44286 | Apple macOS up to 15.0 Keyboard Event state issue
CVE-2024-44303 | Apple macOS up to 15.0 App access control
CVE-2024-40858 | Apple macOS up to 15.0 App permission
CVE-2025-43236 | Apple macOS up to 13.7.6/14.7.6/15.5 type confusion
Китайские ученые создали одежду из кордицепса. Главное теперь не стать зомби прямо на презентации
What the identity attack surface looks like when trust becomes the target
In this Help Net Security video, Joel Moses, VP, Strategic Engineering at F5, explains how attackers use identity instead of breaking through it. He walks through MFA fatigue, session token theft, and consent given to malicious applications, using the 2022 Uber breach as an example. He also covers how cloud and on-premises trust relationships give attackers a path between environments. Moses suggests number matching, FIDO2 keys, periodic reviews of third party application access, and watching … More →
The post What the identity attack surface looks like when trust becomes the target appeared first on Help Net Security.