Aggregator
腾讯办公网智能体安全治理实践
该文档由腾讯云安全出品,聚焦办公网AI Agent的安全治理实践。随着AI Agent从"内容生成"演进为"代为行动",安全风险已从单点漏洞转变为"行动链失控"——通过Prompt注入、工具调用、权限继承、数据触达和审计断点,导致权限被放大、数据被外带、责任难追溯。
文档提出办公网智能体安全治理"五问"框架:围绕"身份可识别、环境可信任、工具有边界、数据受保护、行为可追溯"构建行动链治理体系。基于腾讯iOA产品,建立"事前预防—事中管控—事后溯源"三层闭环:事前通过AI资产盘点、Skill安全准入、运行时防护与沙箱隔离实现"看得见";事中依托EDR全链路审计、Skill自动处置、零信任联动与DLP外发拦截实现"防得住";事后通过统一资产台账与事件溯源取证实现"可追溯"。
文档还给出了30天落地路线,从试点人群和高风险工具入手,分阶段完成资产盘点、边界控制和审计运营。核心主张是:安全治理不是限制AI,而是让AI Agent在企业中走向可信、可控、可运营,实现放心规模化使用。
AI Powered编程与智能体安全管控实践
该文档由萤石网络出品,聚焦AI驱动编程与智能体安全管控实践。文档指出,代理式开发模式正重塑软件生命周期,将传统数周至数月的开发周期压缩至数小时至数天,实现从"人工编写"到"人类引导、智能体执行"的范式转变。然而效率提升伴随显著风险:AI生成代码漏洞率高达40%-62%,API密钥硬编码率达28%,且存在智能体失控、提示词注入等安全隐患。
文档提出"用AI管理AI"的治理思路,构建覆盖需求评审、代码审查、安全测试、情报监控的AI-SDLC全链路防护体系,并借鉴员工管理逻辑,通过统一入口/出口、工具白名单、技能安全检查、密钥托管、行为可观测与幻觉抑制等机制,实现智能体的集中管控与全程审计。
面向未来,文档认为风险正从内容合规向行为失控转移,建议构建端点身份权限管控、网络隔离沙箱、AI多层护栏与策略校验、三位一体协同决策及安全态势反馈的闭环体系,推动安全防护从被动应对向主动适应演进,为企业在智能体时代的安全实践提供了系统性的方法论与落地路径。
工业AI智能体安全治理方法与实践
该文档由安恒信息出品,聚焦工业AI智能体的安全治理方法与实践。随着工业大模型市场规模快速增长,智能体安全已从"说了什么"的内容合规,演进为"做了什么"的行为安全,面临身份不清、凭据分散、权限过大、过程黑盒、影子AI蔓延等现实困境。尤其在OT/IT融合的工业场景中,对确定性、可审计性和紧急制动提出了更高要求。
文档提出覆盖智能体全生命周期的安全治理框架,涵盖评估、准备、部署、使用、停用五个阶段,强调最小权限、环境隔离、日志审计与停用清理。核心构建"非人身份(NHI)""零信任动态授权""AI资产台账(ASBOM)"三大支柱,实现智能体"可识别、可授权、可审计、可控制"。在运行时防护方面,建立输入检测、工具调用前权限校验、调用后结果审查、最终输出合规扫描的四阶段闭环,并针对MCP服务、技能供应链、高危操作等关键风险点提供专项防护。
文档还分享了大型央企集团与医疗行业的实践案例,展示了如何通过统一安全中枢治理影子AI、实现业务场景精准防护,以及医疗大模型在诱导攻击拦截与合规溯源方面的落地成效,为企业构建智能体安全治理体系提供了可复用的方法论与实施路径。
美团正式发布 CatPaw:全场景 AI Agent,从个人提效到企业智能化
Одно СМС от военкомата обнулило родительский сейф на 75 миллионов рублей
Is Your SSO Protected Against Modern Credential Attacks?
Solve Multi-CDN Entitlement Drift with Edge Functions Without Losing Viewers
维基基金会决定不自愿认可员工工会
От центра Земли до момента рождения Вселенной: куда бы отправились астрономы, если бы можно было лететь со скоростью света?
JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
From Payments to Portfolios: How Financial Super Apps Rewrite Economics of Global Investing
BlackCloak extends deepfake protection to the executive’s trusted circle
Deepfakes have made one of our oldest assumptions unreliable: that you can trust a familiar face or voice. While the industry focuses mainly on building “in-line detection tools” that try to spot the fake, BlackCloak, the leader in Digital Executive Protection (DEP), built Impersonation Protection to focus on validating the authenticity of communications. Circle of trust functionality is the most significant expansion of that capability to date — giving executives and high-profile individuals a new … More →
The post BlackCloak extends deepfake protection to the executive’s trusted circle appeared first on Help Net Security.
Bugcrowd introduces Savant Pathseeker for agentic penetration testing with exploit validation
Bugcrowd unveils Savant Pathseeker, the first solution in its Agentic Offensive Testing line. Savant Pathseeker gives security teams the speed and scale to test every external web application and API continuously, not just the assets that make it onto the pentest schedule, while providing the evidence to prove that the findings are genuinely exploitable. Security teams are attempting both deep and broad coverage, and getting the worst of each. Crown-jewel assets sit exposed for months … More →
The post Bugcrowd introduces Savant Pathseeker for agentic penetration testing with exploit validation appeared first on Help Net Security.
【转】Mythos向左,AiPy往右|继Mythos之后,他们又发现100多个漏洞
Prescient Security adds attack surface management to Cait, broadens AI-assisted pentesting
Prescient Security has announced a series of capability expansions to Cait (Cacilian AI), its continuous AI-assisted penetration testing service. The updates which will roll out through summer 2026 add attack surface management (ASM), new asset testing types and expanded environment support, extending Cait’s reach well beyond its initial web application focus. The announcements follow Cait’s general availability launch earlier this year, which introduced an autonomous, context-aware pentester that explores applications before attacking them and delivers … More →
The post Prescient Security adds attack surface management to Cait, broadens AI-assisted pentesting appeared first on Help Net Security.
Cyberhaven launches Flow to secure data across human and AI workflows
Cyberhaven has introduced Cyberhaven Flow, an AI-native data security platform built to protect data across human and AI workflows. Flow connects lineage, identity, and behavior to protect data as it is created, copied, fragmented, and shared, marking a shift in how protection adapts to the changing context of work in the AI era. Flow secures data across every human and agentic workflow, wherever people and AI agents work: on endpoints, in browsers, and in the … More →
The post Cyberhaven launches Flow to secure data across human and AI workflows appeared first on Help Net Security.
Fake Claude Code Installer Delivers MacSync macOS Infostealer Through Google Ads
A highly convincing malvertising campaign is targeting macOS users searching for “how to install Claude Code on Mac,” delivering the MacSync infostealer through a trusted-looking workflow that abuses legitimate infrastructure rather than exploiting software vulnerabilities. The attack highlights a growing shift toward trust-based compromise, where attackers weaponize authentic platforms such as Google Ads and claude.ai […]
The post Fake Claude Code Installer Delivers MacSync macOS Infostealer Through Google Ads appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.