Skip to main content

XMT

短闻

信流 · 上滑连读 · 来源可核

今日 稍后 搜索 RSS

当前信源:CSO Online · 清除信源筛选

1 / 10
Aggregate CSO Online 网络安全 45″

It took $58 to break Microsoft’s SCCM, but a patch made it harder

Researchers at XM Cyber found that a standard domain user with no Microsoft SCCM privileges can chain multiple flaws to reach remote code execution, although the attack does require network access to the SCCM environment.…

  • Enterprises use Microsoft System Center Configuration Manager (SCCM) t…
  • XM Cyber’s attack can move from an ordinary domain account to code exe…
  • “After the Site Server is compromised, all of its managed clients are …

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Trump administration opens door to private-sector cyber offensives

The Trump administration is opening the door for vetted US companies to conduct cyber operations against foreign cybercriminal organizations under federal supervision, giving the private sector a more direct role in disrupting cyber-enabled crime.…

  • A presidential memorandum issued on August 12 directs the National Coo…
  • The memorandum says, “any resulting operational action will be exclusi…
  • ” Companies admitted to the program will have to contract with either …

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

AI agents wage near-autonomous cyberattack on Asian government networks

Autonomous AI agents built on open-source frameworks breached Taiwanese government systems, compromised credentials, and probed a nuclear safety agency in a multi-day cyberattack that researchers say signals a new phase in AI-enabled operations.…

  • The campaign unfolded over four days in early July, during which multi…
  • “In roughly four days, the agentic attacker produced 1,395 files, 85 c…
  • “It spells out one thing loudly – the cost of running a competent atta…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Attackers target zero-day vulnerability in geospatial data platform GeoServer

Security researchers have seen evidence that attackers are attempting to exploit a currently unpatched SQL injection vulnerability in GeoServer, an open-source web server for managing and publishing geospatial data.…

  • The software is widely used by organizations in many industries, inclu…
  • A bug bounty hunter shared the vulnerability Wednesday on X as a zero …
  • According to his post, the jsonArrayContains function contains a vulne…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

5 key takeaways from Black Hat USA 2026

AI’s potential as a security tool and the danger of autonomous AI agents as a new attack surface were key themes of the presentations and product announcements at Black Hat and DEFCON in Las Vegas last week.…

  • Here are some key takeaways from this year’s hacker summer camp that C…
  • Reactive patching alone is no longer sufficient Microsoft’s David West…
  • Rather than attempting to respond faster than attackers, he said, the …

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

How CSOs can turn cybersecurity into a business growth strategy

For years, cybersecurity leaders have worked to convince organizations that security deserves a seat at the executive table.…

  • Today, that conversation is changing.
  • The challenge is no longer proving that cybersecurity matters; it is d…
  • As organizations accelerate digital transformation, CSOs have an oppor…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Akira ransomware reboots into Windows Safe Mode to knock EDR offline

Akira ransomware affiliates were seen using a new technique to evade endpoint detection and response (EDR), where they rebooted a compromised Windows system into Safe Mode with Networking enabled.…

  • According to Huntress, the technique successfully took both its agent …
  • This, the researchers said, gave the attacker a window to operate with…
  • The incident investigated by Huntress began on August 4 with a credent…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

The cybersecurity backlog is not a security problem

Cybersecurity teams should be responsible for risk oversight, rather than for executing every corrective action.…

  • Assigning security teams the tasks of finding, prioritizing, assigning…
  • Instead, it results in an organizational repository for unresolved iss…
  • A more effective model distinguishes roles clearly: security functions…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Oracle’s new database security tool is free — for six months

Oracle has released a security tool intended to provide organizations with a centralized view of security risk across their database environments.…

  • Oracle Database Security Central will be available free of charge unti…
  • It arrives at a critical time for Oracle customers, with attackers tar…
  • Oracle is also concerned about the threat posted by the launch of bug-…

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate CSO Online 网络安全 45″

Salesforce, ServiceNow data targeted in ‘City-Forum’ attacks

Records held in Salesforce and ServiceNow systems are under attack leaving user data exposed, according to researchers at Reco.…

  • The attack appears similar to those perpetrated by the extortion group…
  • ShinyHunters has been particularly active this year, attacking dating …
  • Reco has named the latest campaign of attacks “City-Forum,” after a do…

RSS 官方收录 · 可信分层展示

详情 原文 分享图