微信内可能无法直接打开本站。请点右上角 ··· → 在浏览器打开,或复制链接后用系统浏览器访问。
XMT
信流 · 上滑连读 · 来源可核
GitHub already has an EDR. You just have to listen to it
Many of the recent supply-chain attacks could have been caught earlier if defenders looked closely at the telemetry GitHub already provides, researchers said.…
- At their Black Hat USA 2026 presentation, researchers Yossi Weizman of…
- You’re just not listening.
- ” The duo described an EDR-style detection approach built from GitHub’…
RSS 官方收录 · 可信分层展示
Zoom zero-click RCE flaws allow attackers to compromise meeting participants
Zoom has fixed four vulnerabilities across its applications, including two that could allow attackers who join a meeting to execute malicious code on the systems of all other meeting participants with no interaction required from them.…
- Three of the vulnerabilities affect all Zoom client applications for a…
- 6, while the fourth impacts Zoom Workplace VDI Client for Windows and …
- Products such as Zoom Rooms and Zoom Meeting SDK before versions 7.
RSS 官方收录 · 可信分层展示
Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability
A currently exploited zero-day elevation of privilege vulnerability that needs to be patched in a Windows driver for WinSock is the highlight of the 398 fixes issued today in Microsoft’s August Patch Tuesday releases.…
- The hole is in Windows’ Ancillary Function Driver for WinSock (CVE-202…
- Past vulnerabilities in this component have let an authorized attacker…
- “Exploitation has already been detected,” noted Jack Bicer, director o…
RSS 官方收录 · 可信分层展示
17 old software bugs that took way too long to squash
In 2021, a vulnerability was revealed in a system that lay at the foundation of modern computing.…
- An attacker could force the system to execute arbitrary code.
- Shockingly, the vulnerable code was almost 54 years old — and there wa…
- Fortunately, that’s because the system in question was Marvin Minsky’s…
RSS 官方收录 · 可信分层展示
Metabase SQLi exploit grants attackers total access
Business intelligence (BI) platform provider Metabase has disclosed a zero-day SQL Injection vulnerability, warning that customers’ sensitive credentials, tokens, API keys, and other data may have been exposed.…
- The Metabase vulnerability revealed on August 6, designated CVE-2026-7…
- It is present in versions 1.
- “You don’t see a perfect 10/10 on CVSS often, but when you do, be worr…
RSS 官方收录 · 可信分层展示
The AI harness is the new attack surface
Ask a security researcher what makes an AI agent dangerous, and the instinct is to talk about the model — what it will and won’t refuse, how easily it can be jailbroken, whether its weights can be trusted.…
- That instinct is increasingly out of date.
- A growing body of security research — exploit demonstrations, independ…
- That code, increasingly called the harness, wraps the model, gives it …
RSS 官方收录 · 可信分层展示
4 gaps slowing AI in enterprise SOCs
Artificial intelligence (AI) has quickly become a strategic priority for enterprise security teams.…
- Yet despite growing investment in AI-driven security software, many en…
- The issue isn’t whether AI belongs in the SOC.
- The challenge is that many organizations are approaching AI adoption i…
RSS 官方收录 · 可信分层展示
Fake CCleaner downloads turn Chrome into a credential-stealing surveillance tool
A convincing fake version of the widely used CCleaner utility is being used to deliver a multi-stage Windows malware that ultimately abuses Google Chrome for credential theft and surveillance.…
- Researchers from Malwarebytes found the campaign distributing a malici…
- Attackers created a lookalike CCleaner download site and used it to di…
- exe,” researcher Sav Wheeler said in a blog post.
RSS 官方收录 · 可信分层展示
Researcher bypasses Microsoft Defender security patch, seizing control
Just weeks after Microsoft patched a critical hole in Microsoft Defender, a cybersecurity researcher has posted an apparent bypass that provides system-level control to attackers once they gain any level of access.…
- The researcher, who goes by the name Nightmare Eclipse, has been engag…
- Nightmare Eclipse has not provided the further details we requested, h…
- But the proof of concept (PoC) security bypass, ShieldBreak, described…
RSS 官方收录 · 可信分层展示