Skip to main content

XMT

短闻

信源:CSO Online · 短平快可信阅读。

抖音式连刷节奏 · 视频号式正能量克制 · 第三种:可信信流——短平快,可核验。

今日 稍后 搜索 RSS

当前信源:CSO Online · 清除信源筛选

Aggregate CSO Online 网络安全 45″

GitHub already has an EDR. You just have to listen to it

Many of the recent supply-chain attacks could have been caught earlier if defenders looked closely at the telemetry GitHub already provides, researchers said.…

  • At their Black Hat USA 2026 presentation, researchers Yossi Weizman of…
  • You’re just not listening.

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Zoom zero-click RCE flaws allow attackers to compromise meeting participants

Zoom has fixed four vulnerabilities across its applications, including two that could allow attackers who join a meeting to execute malicious code on the systems of all other meeting participants with no interaction required from them.…

  • Three of the vulnerabilities affect all Zoom client applications for a…
  • 6, while the fourth impacts Zoom Workplace VDI Client for Windows and …

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability

A currently exploited zero-day elevation of privilege vulnerability that needs to be patched in a Windows driver for WinSock is the highlight of the 398 fixes issued today in Microsoft’s August Patch Tuesday releases.…

  • The hole is in Windows’ Ancillary Function Driver for WinSock (CVE-202…
  • Past vulnerabilities in this component have let an authorized attacker…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Metabase SQLi exploit grants attackers total access

Business intelligence (BI) platform provider Metabase has disclosed a zero-day SQL Injection vulnerability, warning that customers’ sensitive credentials, tokens, API keys, and other data may have been exposed.…

  • The Metabase vulnerability revealed on August 6, designated CVE-2026-7…
  • It is present in versions 1.

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

17 old software bugs that took way too long to squash

In 2021, a vulnerability was revealed in a system that lay at the foundation of modern computing.…

  • An attacker could force the system to execute arbitrary code.
  • Shockingly, the vulnerable code was almost 54 years old — and there wa…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

The AI harness is the new attack surface

Ask a security researcher what makes an AI agent dangerous, and the instinct is to talk about the model — what it will and won’t refuse, how easily it can be jailbroken, whether its weights can be trusted.…

  • That instinct is increasingly out of date.
  • A growing body of security research — exploit demonstrations, independ…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

4 gaps slowing AI in enterprise SOCs

Artificial intelligence (AI) has quickly become a strategic priority for enterprise security teams.…

  • Yet despite growing investment in AI-driven security software, many en…
  • The issue isn’t whether AI belongs in the SOC.

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Fake CCleaner downloads turn Chrome into a credential-stealing surveillance tool

A convincing fake version of the widely used CCleaner utility is being used to deliver a multi-stage Windows malware that ultimately abuses Google Chrome for credential theft and surveillance.…

  • Researchers from Malwarebytes found the campaign distributing a malici…
  • Attackers created a lookalike CCleaner download site and used it to di…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Microsoft wants you to rethink your approach to cyber defense

Cyber defenders need to shake off traditional best practices and switch from reactive patching to building inherently resilient systems in the face of AI-accelerated vulnerability discovery, according to a senior security manager at Microsoft.…

  • David Weston, group manager in the Windows team at Microsoft, told del…
  • Weston’s keynote — entitled “The End of Rare: Defending When Offense I…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Researcher bypasses Microsoft Defender security patch, seizing control

Just weeks after Microsoft patched a critical hole in Microsoft Defender, a cybersecurity researcher has posted an apparent bypass that provides system-level control to attackers once they gain any level of access.…

  • The researcher, who goes by the name Nightmare Eclipse, has been engag…
  • Nightmare Eclipse has not provided the further details we requested, h…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

It took $58 to break Microsoft’s SCCM, but a patch made it harder

Researchers at XM Cyber found that a standard domain user with no Microsoft SCCM privileges can chain multiple flaws to reach remote code execution, although the attack does require network access to the SCCM environment.…

  • Enterprises use Microsoft System Center Configuration Manager (SCCM) t…
  • XM Cyber’s attack can move from an ordinary domain account to code exe…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Trump administration opens door to private-sector cyber offensives

The Trump administration is opening the door for vetted US companies to conduct cyber operations against foreign cybercriminal organizations under federal supervision, giving the private sector a more direct role in disrupting cyber-enabled crime.…

  • A presidential memorandum issued on August 12 directs the National Coo…
  • The memorandum says, “any resulting operational action will be exclusi…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

AI agents wage near-autonomous cyberattack on Asian government networks

Autonomous AI agents built on open-source frameworks breached Taiwanese government systems, compromised credentials, and probed a nuclear safety agency in a multi-day cyberattack that researchers say signals a new phase in AI-enabled operations.…

  • The campaign unfolded over four days in early July, during which multi…
  • “In roughly four days, the agentic attacker produced 1,395 files, 85 c…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Attackers target zero-day vulnerability in geospatial data platform GeoServer

Security researchers have seen evidence that attackers are attempting to exploit a currently unpatched SQL injection vulnerability in GeoServer, an open-source web server for managing and publishing geospatial data.…

  • The software is widely used by organizations in many industries, inclu…
  • A bug bounty hunter shared the vulnerability Wednesday on X as a zero …

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

5 key takeaways from Black Hat USA 2026

AI’s potential as a security tool and the danger of autonomous AI agents as a new attack surface were key themes of the presentations and product announcements at Black Hat and DEFCON in Las Vegas last week.…

  • Here are some key takeaways from this year’s hacker summer camp that C…
  • Reactive patching alone is no longer sufficient Microsoft’s David West…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

How CSOs can turn cybersecurity into a business growth strategy

For years, cybersecurity leaders have worked to convince organizations that security deserves a seat at the executive table.…

  • Today, that conversation is changing.
  • The challenge is no longer proving that cybersecurity matters; it is d…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

The cybersecurity backlog is not a security problem

Cybersecurity teams should be responsible for risk oversight, rather than for executing every corrective action.…

  • Assigning security teams the tasks of finding, prioritizing, assigning…
  • Instead, it results in an organizational repository for unresolved iss…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Akira ransomware reboots into Windows Safe Mode to knock EDR offline

Akira ransomware affiliates were seen using a new technique to evade endpoint detection and response (EDR), where they rebooted a compromised Windows system into Safe Mode with Networking enabled.…

  • According to Huntress, the technique successfully took both its agent …
  • This, the researchers said, gave the attacker a window to operate with…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Oracle’s new database security tool is free — for six months

Oracle has released a security tool intended to provide organizations with a centralized view of security risk across their database environments.…

  • Oracle Database Security Central will be available free of charge unti…
  • It arrives at a critical time for Oracle customers, with attackers tar…

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Salesforce, ServiceNow data targeted in ‘City-Forum’ attacks

Records held in Salesforce and ServiceNow systems are under attack leaving user data exposed, according to researchers at Reco.…

  • The attack appears similar to those perpetrated by the extortion group…
  • ShinyHunters has been particularly active this year, attacking dating …

RSS 官方收录 · 可信分层展示

信流 详情 原文 分享图