Skip to main content

XMT

短闻

信源:CSO Online · 短平快可信阅读。

抖音式连刷节奏 · 视频号式正能量克制 · 第三种:可信信流——短平快,可核验。

今日 稍后 搜索 RSS

当前信源:CSO Online · 清除信源筛选

Aggregate CSO Online 网络安全 45″

ServiceNow patches three maximum severity flaws that could put enterprise data at risk

Code injection and SQL injection attacks have been around for decades, and they are still tried-and-true ways for attackers to compromise systems.…

  • ServiceNow’s latest trio of maximum severity flaws shows that even AI-…
  • Although its cloud-based instances have already been updated, ServiceN…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

GPUThor hardware attack can root Nvidia GPU systems

Hardware security researchers from University of Toronto have developed a new memory bit flipping technique that significantly improves on previously known attacks against GPU memory.…

  • The new method can defeat the error-correcting codes (ECC) defense use…
  • Dubbed GPUThor, the technique falls in a category of attacks known as …

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

The first 24 hours of an AI agent security incident

Most of what I read on AI agent security follows the same shape: a taxonomy of risks, a list of governance principles and a call to “adopt responsible AI practices.…

  • ” That’s useful for a board deck.
  • It’s nearly useless at 2 a.

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Beyond compliance: Designing systems that earn customer trust

Over the years, I have learned that customer trust is not built by compliance alone.It comes from how systems actually handle data every day.…

  • In practice, I think five areas matter most Making customer intent con…
  • For CISOs and other security leaders, these ideas can also help turn b…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

CTEM can give your security team a contextual edge

Traditional vulnerability management is accelerating toward a reset, with many security organizations considering continuous threat exposure management (CTEM) to better align their operations with the pace of change — and attacks — today.…

  • Whereas traditional vulnerability management relies on periodic assess…
  • “CTEM brings something different to the table in three key areas,” hig…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

AI can be made to read an email much differently than you do

Security researchers are claiming it is possible for users to see one email in their inbox while their AI assistant reads another.…

  • Forcepoint X-Labs has demonstrated how a few lines of invisible HTML c…
  • In a controlled environment, the researchers did this using HTML styli…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Critical infrastructure’s long, undefended tail exposed by UK energy attack

A cyberattack that forced a small British electricity generator offline for four days caused no power outage, threatened no part of the national grid, and may not even have been carried out by the Iran-linked hackers initially blamed.…

  • But the incident illustrates a consequential weakness in Western criti…
  • Thousands of small generators, water systems, and other industrial sit…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

NemoClaw’s AI can be poisoned through a browser tab

A vulnerability affecting Nvidia’s NemoClaw could let an attacker gain control of the local Ollama model server through a single malicious website visit on the victim’s machine.…

  • According to a Cyera research, the flaw could give attackers unauthent…
  • The attacker doesn’t directly connect to the victim’s Ollama server fr…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Microsoft warns patch window is collapsing, urges shift to network-level containment

Microsoft is warning that the window for patching vulnerabilities is rapidly shrinking, as attackers move from disclosure to exploitation faster than enterprises can safely deploy fixes, and is urging organizations to adopt network-level controls to limit exposure during that gap.…

  • In a blog post, Igor Sakhnov, corporate vice president and general man…
  • “When a vulnerability was disclosed, organizations had time to underst…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Who is accountable when your AI agent goes rogue?

AI agents can go to great lengths to complete the tasks their operators assign, and as a series of recent incidents showed, this can include exploiting third-party systems, manipulating people, and distributing malicious code.…

  • But AI agents are not people who can be fired, sued, or criminally pro…
  • The clearest example occurred during an OpenAI cybersecurity evaluatio…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Nucleus wants to get ahead of scanners on new vulnerabilities

There usually is a crucial time lapse from when a vulnerability is newly disclosed to when security scanners are finally updated to scan for it.…

  • Nucleus Security says it wants to close that gap.
  • The cybersecurity outfit focused on unified exposure management is exp…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

AI helps Chinese-speaking hackers speed up attacks on exposed servers

A Chinese-speaking cybercrime group is using AI-driven tools to help compromise internet-facing Windows and Linux web servers, according to Cisco Talos, Cisco’s threat intelligence research unit.…

  • Talos said the activity points to increasingly automated offensive ope…
  • Talos, which tracks the group as UAT-10147, found evidence that AI-gen…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

New attack lets hackers plant hidden instructions in AI memory with a single prompt

A newly demonstrated attack technique allows hackers to plant hidden instructions inside an AI agent’s memory with a single prompt, enabling them to influence how the system responds to future queries.…

  • The technique, called InjecMEM, is described in a research paper as a …
  • ” “The attacker specifies a target topic and target output, aiming to …

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

How Equifax is using AI to elevate its cybersecurity

For nearly a decade, Equifax has been dealing with the aftermath of one of the worst cybersecurity breaches in US history, racking up $1.…

  • 4 billion on cleanup costs.
  • Among the mistakes that led to the breach were a mismanaged patching p…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Windows Defender’s own driver can leave systems defenseless

A Microsoft-signed Windows Defender remediation driver can be repurposed into a kernel-level “operation engine” capable of deleting files, modifying the registry and neutralizing security controls, according to new research from Check Point Research (CPR).…

  • The technique does not exploit a vulnerability or rely on the traditio…
  • Instead, it abuses functionality intentionally built into Defender’s B…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

7 ways AI can be used to enhance security operations

AI has an almost unlimited number of applications, yet none may be more important than its ability to strengthen enterprise security.…

  • AI marks a new era of business transformation in which AI autonomy and…
  • “The development of agentic AI — systems that can learn, make informed…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

OpenAI adds an AI safety layer to detect misuse without retaining enterprise data

OpenAI is adding a new safety capability that allows enterprises to detect misuse of its AI systems across multiple interactions without retaining prompts or responses, enabling risk monitoring while preserving its Zero Data Retention (ZDR) commitments.…

  • “OpenAI does not retain…prompts or model responses after a request is …
  • The new system, called Private Safety Processing, is “designed to iden…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

AI threats are everywhere. A risk-first CISO decides what to prioritize

The good news?AI gives cyber defenders some of the best discovery tooling they’ve ever had.…

  • The bad news?
  • It gives attackers the same capability.

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Backdoored Rust packages hit crates.io, exposing developers to malware at build time

Malicious versions of three Rust packages, including the widely used arrayref, were published to the crates.…

  • io registry on August 20, carrying a backdoor that executed automatica…
  • Security researchers at Wiz said the attack also shares infrastructure…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Ransomware takes aim at enterprise resilience

Ransomware remains one of the most disruptive cyber threats organizations face.…

  • Companies have strengthened their cyber defenses over the years, but a…
  • From the rise of AI-enabled attacks and extortion-only campaigns to gr…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Critical flaw patched in popular JavaScript sandbox used in AI projects

A critical sandbox escape vulnerability was discovered and patched in isolated-vm, a library for running JavaScript code inside an isolated process.…

  • If exploited, the vulnerability could allow attackers to hijack the ho…
  • Isolated-vm is downloaded more than 1 million times per week and is al…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Citrix issues critical security updates for its NetScaler devices

Citrix is urging its NetScaler ADC and NetScaler Gateway customers to quickly patch two critical security holes, one involving a memory overflow vulnerability leading to unpredictable behavior or denial of service, and the other allowing authentication bypass.…

  • Citrix said in an advisory that supported versions of customer-managed…
  • Citrix-managed cloud services and Citrix-managed Adaptive Authenticati…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Kriminal breaks out of Grok, Claude guardrails at $12.99

Security researchers are warning of a criminal AI service built on Grok and Claude, among other models, that promises uncensored access to powerful AI capabilities for as little as $12.…

  • ThreatDown researchers say “Kriminal” is largely a storefront wrapped …
  • The service is publicly accessible on the clearnet, indexed by Google …

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Airlock Digital Completes Independent IRAP Assessment at the PROTECTED Level

Airlock Digital, a global provider of application control and allowlisting solutions, today announced that it has completed an independent Information Security Registered Assessors Program (IRAP) assessment at the PROTECTED classification level.…

  • The assessment was conducted by an Australian Signals Directorate (ASD…
  • It provides Australian organisations with additional independent evide…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

OpenAI ‘temporarily slows’ scaling efforts, also promises zero data retention for select frontier model customers

OpenAI this week announced multiple moves designed to counter negative perceptions of its security and privacy, saying it had slowed its pace of scaling, implemented a two-week pause in reinforcement learning, and will be offering zero data retention for “eligible API customers.…

  • ” In its first announcement, issued Tuesday, OpenAI said it “temporari…
  • Those efforts occurred while OpenAI hardened and red-teamed its resear…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Snowflake flaw slips past AI checks, gets exploited by another AI

An autonomous AI security agent developed by cloud security firm Wiz identified and exploited a critical vulnerability in Snowflake’s GitHub Actions pipeline, while GitHub Copilot had previously reviewed the code change without flagging the flaw.…

  • The vulnerable code was part of a pull request (PR) that GitHub Copilo…
  • “Copilot was a co-author that checked the merged PR and code change, a…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Most organizations aren’t ready for a Hugging Face-level event

The National Security Agency (NSA) and Central Security Service recently published an advisory statement on behalf of the Five Eyes Cyber Security Agencies, warning that AI technologies are making it easier than ever for would-be malicious actors to infiltrate and compromise sensitive networks.…

  • “AI is not a future consideration — it is already here,” the statement…
  • “It lowers barriers for malicious actors and increases the speed and c…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

CISOs are struggling to threat-model AI. Can 15-minute sessions help?

A few weeks ago, on a busy day, threat-modeling expert Adam Shostack opened an email from a client.…

  • Someone at that organization had vibe-coded an app and put it to work …
  • Now, the client wanted to know what risks the tool posed.

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Microsoft finally patches critical one-click Copilot vulnerability, more than eight months after learning of it

More than eight months after confirming a critical security vulnerability within the personal version of its AI assistant, Copilot, Microsoft on Tuesday issued a patch to close the hole, which relies on an LLM’s inability to distinguish the data in a query from an instruction.…

  • The CoSnitch hole was discovered by Varonis, and marked the third Copi…
  • All three share the same exploit pattern: one click on a legitimate-lo…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Critical GitLab flaw allows attackers to delete and modify public repos

GitLab has fixed a critical vulnerability that could allow unauthenticated attackers to perform unauthorized modifications inside code repositories or to completely delete them with a single HTTP request.…

  • The patched releases also address a second high-risk cross-site reques…
  • The critical vulnerability, tracked as CVE-2026-19478, is described as…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图