Skip to main content

XMT

短闻

信源:CSO Online · 短平快可信阅读。

财经 · 科技 · 国内 · 国际——短平快可读,来源可核验。

搜索 稍后

当前信源:CSO Online · 清除信源筛选

Aggregate AI 摘要 CSO Online 网络安全 OpenAI 45″

Sam Altman calls GPT-6 Astra rollout ‘messy’ as enterprise users wait for access

GPT-6 Astra rollout delayed for most users; only Daybreak program participants…

  • Altman apologized for 'messy' GPT-6 Astra launch affecting…
  • Only Daybreak cybersecurity program organizations accessed…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate AI 摘要 CSO Online 网络安全 45″

Back-to-back N-able bugs send admins on a patching spree

N-able曝高危零日漏洞CVE-2026-86218,已遭野外利用,需紧急升级Hotfix 4

  • CVE-2026-86218为未经认证远程代码执行漏洞,已确认野外利用
  • 9月5日披露的两个漏洞(CVE-2026-86206/07)与新漏洞无关,但存在绕过访问控制的利用链

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate AI 摘要 CSO Online 网络安全 45″

What do CISOs need to rest easy about future AI risks?

41%的CISO对未来2年AI安全风险持乐观态度,关键在组织赋权而非技术成熟度

  • 41% CISO乐观、38%悲观,差距源于组织支持而非当前安全能力
  • CISO信心强弱取决于领导理解、AI治理权属、预算控制等6项组织因素

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate AI 摘要 CSO Online 网络安全 45″

FBI investigates breach of 153 million driving license records at IDscan.net

FBI调查IDscan.net泄露15300万驾照记录事件

  • 15300万驾照记录及超1000万其他证件信息遭泄露
  • 泄露源头为身份验证服务商IDscan.net,客户含赫兹、Target等

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate AI 摘要 CSO Online 网络安全 45″

Bidding war for defunct Spirit Airlines’ employee data will not die

Micro1出价1250万美元竞购Spirit航空6亿条员工数据,此前Google已以1000万美元拍得

  • Micro1最新报价1250万美元竞购Spirit员工邮件、聊天等数据
  • 数据含6亿条记录、3000万客服录音等,含敏感历史信息

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate AI 摘要 CSO Online 网络安全 45″

OpenAI launches GPT-6 Astra, its first model to cross a critical cybersecurity threshold

OpenAI发布GPT-6 Astra,首个达‘Critical’网络安全风险阈值的模型

  • Astra在ExploitBench测试中漏洞利用成功率100%,较GPT-5.6 Sol提升21.5个百分点
  • 企业需手动启用Astra,API定价为10美元/百万输入token、50美元/百万输出token

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate AI 摘要 CSO Online 网络安全 45″

The democratization of cyber warfare — and what it means for CISOs

网络战正加速平民化,低成本商用技术让个体可实施高威胁攻击

  • 乌克兰战场显示商用无人机已能突破克里姆林宫等传统高防护目标
  • 火器、十字弓等历史先例表明战争平民化是长期趋势

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate AI 摘要 CSO Online 网络安全 45″

OpenAI targets small utilities with $1 billion cyber defense initiative

OpenAI推10亿美元网络安全计划,重点保护小型水电公司等关键基础设施

  • Daybreak计划投入10亿美元,提供AI防御模型、培训与技术支持
  • 覆盖水电气等小型公用事业及地方政府、银行等关键基础设施

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate AI 摘要 CSO Online 网络安全 45″

Decade-old PostgreSQL flaw turns backup account into a backdoor

十年未被发现的PostgreSQL漏洞CVE-2026-6471,低权限备份账号可远程执行代码

  • 漏洞存在于逻辑复制插件加载机制,绕过安全检查check_restricted_library_name()
  • 影响PostgreSQL 9.4至18.6等所有旧版,已通过8月13日补丁修复

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate AI 摘要 CSO Online 网络安全 45″

Counterfeit installers turn routine software downloads into enterprise breaches

微软警告:假冒软件下载站投递木马安装包,已波及医疗、制造等多行业企业

  • 攻击者伪造Edge、卡巴斯基等官网下载页,分发带持久化后门的安装包
  • 恶意安装包每次下载哈希值不同但文件名相同,绕过基于文件的检测

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate AI 摘要 CSO Online 网络安全 45″

AI agents help compress ransomware intrusion to under 10 hours, raising stakes for CISOs

AI agents compressed ransomware intrusion to under 10 hours vs. 2 weeks for hu…

  • 攻击者用AI代理执行50+ MITRE ATT&CK技术,全程<10小时
  • AI代理自动侦察微服务、搜源码库密钥、劫持代码应用窃取云密钥

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Stop playing with the CISO role. Fix cybersecurity leadership

We have spent years telling chief information security officers (CISOs) that they need to become better aligned with the business.…

  • They need to understand strategy.
  • They need to speak the language of the board.

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Zero trust has a big AI agent problem ahead

Despite singing the praises of zero trust for many years, many CISOs have struggled to implement the framework in full.…

  • And now comes what could be the final nail: agentic AI.
  • Can zero trust coexist with autonomous agents in typical enterprise en…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

SonicWall reports two major security holes under active exploit

SonicWall on Monday reported two major security holes in its Secure Mobile Access 1000 series appliances, both of which it said are being actively exploited, and published patches for each.…

  • Consultants called the holes, one of which permits remote attacks that…
  • In its security alert, SonicWall described the first hole, tracked as …

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Anthropic introduces zero-retention AI safety monitoring for enterprises

Anthropic is introducing a new framework aimed at helping enterprises monitor AI misuse without ceding control over sensitive data, as organizations struggle to balance security visibility with strict compliance requirements.…

  • The company announced a new solution called Enterprise Frontier Safegu…
  • Under the approach, activity data used for monitoring will be stored i…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Exploited JFrog Artifactory bug puts software supply chain on alert

A critical authentication bypass in JFrog Artifactory is now being exploited in the wild, with attackers observed generating administrator tokens and probing the software supply-chain platform’s sensitive data.…

  • The flaw, tracked as CVE-2026-82329, was disclosed by JFrog on August …
  • By September 1, watchTowr said its Attacker Eye honeypot was already s…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

When the patch tsunami meets the maintenance window

In April 2026, the balance between finding software flaws and fixing them broke.…

  • Frontier AI models released by Anthropic and OpenAI can now autonomous…
  • According to the same paper, at least 40 of the largest software and h…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

How China industrialized the infrastructure behind state hacking

Last week, the US Justice Department and FBI announced court-authorized seizures of domains hard-coded into two complementary hacking platforms known as “QScan” and “QTRouter,” used by Chinese state-sponsored hackers to target US critical infrastructure and other sensitive networks.…

  • A People’s Republic of China (PRC) state-sponsored group known as “QTF…
  • Among the targets of QTFY are the National Aeronautics and Space Admin…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Anthropic makes changes to stop AI agents running amok again

Learning from the OpenAI-Hugging Face fiasco, as well as from recent revelations about its own model, Anthropic is revamping its security and alignment practices.…

  • The company has established controls that flag when a model attempts t…
  • ” Anthropic conceded that three recent security incidents involving Cl…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

What happens when AI models take aim at ICS exploits

LLMs have shown great improvement in vulnerability research and exploit development capabilities over the past six months.…

  • But it’s one thing to find vulnerabilities in well documented open-sou…
  • That’s why researchers from industrial IoT security firm Forescout set…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

CrowdStrike launches cyber frontier AI models, agentic security system

CrowdStrike today announced SafeMind, a cybersecurity-specific AI model-harness system that CEO George Kurtz described as the “first complete agentic system for cybersecurity” at the company’s Fal.…

  • Con conference in Las Vegas.
  • At the heart of SafeMind are two purpose-built cybersecurity models, t…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

OpenClaw rolls out system-wide overhaul, updates security controls across agent platform

OpenClaw has released what it describes as the largest update in its history, introducing a system-wide overhaul spanning runtime behavior, plugins, and security controls, as enterprises increasingly evaluate how such agent-based systems operate across connected environments.…

  • “This update touches every part of OpenClaw, including installation, m…
  • The project said that the scope of the release expanded during develop…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Fake Cloudflare CAPTCHA tricks victims into opening a tunnel for attackers

Attackers are using fake CAPTCHA prompts to trick victims into running malicious PowerShell commands as part of a multi-stage intrusion campaign that can establish persistence, conduct network reconnaissance and potentially give operators a path to deeper access within an organization.…

  • Microsoft Threat Intelligence said a campaign it calls TerminalFix, a …
  • Victims are tricked into copying and running a malicious PowerShell co…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

China-linked hackers turn Cisco routers into covert attack infrastructure

A China-linked cyber espionage group has expanded beyond VMware environments to target network and authentication infrastructure that enterprises rely on to manage access and administer critical systems, according to new findings from incident response firm Sygnia.…

  • The threat actor, tracked by Sygnia as Fire Ant, targeted Cisco IOS XR…
  • The attackers also compromised TACACS authentication infrastructure an…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Microsoft nudges enterprise security closer to its passwordless future. But ‘123456’ will survive.

Today marks the beginning of the end of an era for enterprise Microsoft authentication.As of Sept.…

  • 1, passkeys are now the default authentication method for Entra ID, Mi…
  • 1, 2027, Microsoft-provided SMS and voice authentication will be a thi…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate AI 摘要 CSO Online 网络安全 45″

Windows bug incorrectly tells users that Microsoft Defender Antivirus is turned off

Windows bug falsely warns Defender is off despite being active, affecting all …

  • Windows displays false 'Defender turned off' notifications…
  • Bug impacts all Windows client/server versions with latest…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate AI 摘要 CSO Online 网络安全 45″

OpenAI-led coalition warns AI will compress cyberattack timelines, expose enterprise weaknesses

OpenAI等100+科技公司警告:AI将大幅压缩网络攻击时间窗口

  • AI加速发现和利用企业长期存在的安全弱点
  • 超100家科技与网络安全公司联合签署公开信

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate AI 摘要 CSO Online 网络安全 45″

Trusted Chrome, Edge extensions weaponized in supply chain campaign

19个Chrome/Edge扩展遭劫持,7万用户受影响,可窃取密码、加密货币及社交账号

  • 攻击者收购5个合法扩展并植入恶意更新,另创建14个初期无害的扩展
  • 恶意更新自动推送给现有用户,无需重新安装即可执行窃密代码

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Is your cloud security strategy ready for AI’s looming threat?

Cloud architectures designed to withstand human attackers are facing a new threat: AI agents that rewrite the rules on the pace and scope of attacks.…

  • The recent OpenAI incident involving Hugging Face offers an early exam…
  • Many organizations report being uncertain about their ability to secur…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

ServiceNow patches three maximum severity flaws that could put enterprise data at risk

Code injection and SQL injection attacks have been around for decades, and they are still tried-and-true ways for attackers to compromise systems.…

  • ServiceNow’s latest trio of maximum severity flaws shows that even AI-…
  • Although its cloud-based instances have already been updated, ServiceN…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图