微信内可能无法直接打开本站。请点右上角 ··· → 在浏览器打开,或复制链接后用系统浏览器访问。
XMT
信流 · 上滑连读 · 来源可核
The AI harness is the new attack surface
Ask a security researcher what makes an AI agent dangerous, and the instinct is to talk about the model — what it will and won’t refuse, how easily it can be jailbroken, whether its weights can be trusted.…
- That instinct is increasingly out of date.
- A growing body of security research — exploit demonstrations, independ…
- That code, increasingly called the harness, wraps the model, gives it …
RSS 官方收录 · 可信分层展示
4 gaps slowing AI in enterprise SOCs
Artificial intelligence (AI) has quickly become a strategic priority for enterprise security teams.…
- Yet despite growing investment in AI-driven security software, many en…
- The issue isn’t whether AI belongs in the SOC.
- The challenge is that many organizations are approaching AI adoption i…
RSS 官方收录 · 可信分层展示
Fake CCleaner downloads turn Chrome into a credential-stealing surveillance tool
A convincing fake version of the widely used CCleaner utility is being used to deliver a multi-stage Windows malware that ultimately abuses Google Chrome for credential theft and surveillance.…
- Researchers from Malwarebytes found the campaign distributing a malici…
- Attackers created a lookalike CCleaner download site and used it to di…
- exe,” researcher Sav Wheeler said in a blog post.
RSS 官方收录 · 可信分层展示
Microsoft wants you to rethink your approach to cyber defense
Cyber defenders need to shake off traditional best practices and switch from reactive patching to building inherently resilient systems in the face of AI-accelerated vulnerability discovery, according to a senior security manager at Microsoft.…
- David Weston, group manager in the Windows team at Microsoft, told del…
- Weston’s keynote — entitled “The End of Rare: Defending When Offense I…
- That’s no longer the case, he said.
RSS 官方收录 · 可信分层展示
Researcher bypasses Microsoft Defender security patch, seizing control
Just weeks after Microsoft patched a critical hole in Microsoft Defender, a cybersecurity researcher has posted an apparent bypass that provides system-level control to attackers once they gain any level of access.…
- The researcher, who goes by the name Nightmare Eclipse, has been engag…
- Nightmare Eclipse has not provided the further details we requested, h…
- But the proof of concept (PoC) security bypass, ShieldBreak, described…
RSS 官方收录 · 可信分层展示
Friday Squid Blogging: Searching for the Colossal Squid
Fascinating video about searching for life undersea.…
- The video basically makes the point that our bright white searchlights…
- That, plus bait to attract sea creatures, is teaching us a lot about w…
- Lots of footage of giant squid, and speculation about the colossal squ…
RSS 官方收录 · 可信分层展示
It took $58 to break Microsoft’s SCCM, but a patch made it harder
Researchers at XM Cyber found that a standard domain user with no Microsoft SCCM privileges can chain multiple flaws to reach remote code execution, although the attack does require network access to the SCCM environment.…
- Enterprises use Microsoft System Center Configuration Manager (SCCM) t…
- XM Cyber’s attack can move from an ordinary domain account to code exe…
- “After the Site Server is compromised, all of its managed clients are …
RSS 官方收录 · 可信分层展示
Trump administration opens door to private-sector cyber offensives
The Trump administration is opening the door for vetted US companies to conduct cyber operations against foreign cybercriminal organizations under federal supervision, giving the private sector a more direct role in disrupting cyber-enabled crime.…
- A presidential memorandum issued on August 12 directs the National Coo…
- The memorandum says, “any resulting operational action will be exclusi…
- ” Companies admitted to the program will have to contract with either …
RSS 官方收录 · 可信分层展示
AI agents wage near-autonomous cyberattack on Asian government networks
Autonomous AI agents built on open-source frameworks breached Taiwanese government systems, compromised credentials, and probed a nuclear safety agency in a multi-day cyberattack that researchers say signals a new phase in AI-enabled operations.…
- The campaign unfolded over four days in early July, during which multi…
- “In roughly four days, the agentic attacker produced 1,395 files, 85 c…
- “It spells out one thing loudly – the cost of running a competent atta…
RSS 官方收录 · 可信分层展示