Skip to main content

XMT

短闻

信流 · 上滑连读 · 来源可核

今日 稍后 搜索 RSS

当前信源:Dark Reading · 清除信源筛选

1 / 24
Aggregate Dark Reading 网络安全 12″

CSS: The Hidden Threat Lurking in Your Inbox

CSS was once just about design. Now researchers warn it's powerful enough to exfiltrate data from webmail — and some vendors aren't prepared.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 13″

AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking

Attackers can take control of agents through malicious instructions hidden in content supplied to AI browsers, and there's no simple fix for the threat.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 12″

No Perfect Fix for AI Browser Prompt Injection Flaws

AI browsers from top vendors remain vulnerable to prompt injection attacks despite multiple security guardrails, according to new research.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 17″

AI Sends Global Crime Syndicates Into Fraud Nirvana

Organized crime is convincingly scamming at scale, making billions thanks to AI-enabled voice cloning, deepfake real-time video overlays, LLM-driven persona management, and automated translation.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 15″

From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture

Two former chief security officers of the Democratic National Committee explain that a strong security-first mindset requires executive support — and a dose of absurdity.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 14″

Researcher Claims Control of ChatGPT Secure Sandbox

A researcher demonstrated a proof-of-concept attack chain that provided C2-style influence over ChatGPT's isolated sandbox during a session at Black Hat USA 2026.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 12″

Déjà Vu? Meta's AI Escapes Testing Lab in Hacking Joyride

In the span of three weeks, OpenAI, Anthropic, and Meta have all disclosed AI agent sandbox escape events affecting real organizations.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 13″

The Coordination Gap: How Attackers Are Outpacing Law Enforcement

The fight against cybercrime continues because threat actors have adapted their strategies to avoid deterrents, but law enforcement still operates in silos.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 16″

Sherlock Holmes Was the 'OG' Social Engineer

The crime solver wore disguises, spied on targets, and built intelligence networks long before modern-day tactics emerged. He has lessons for today's ethical- and unethical hackers.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 12″

AI-Generated Patches Fail Half the Time

A study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are open to bypass.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 13″

Outdated Cybercrime Laws Put Security Researchers at Risk

A public policy expert mapped global cybercrime laws to develop a five-point framework for protecting ethical hackers and good-faith security research.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 11″

Coruna, DarkSword iOS Exploits Proliferate Globally

Sophisticated iPhone exploit chains previously limited to nation-states are spreading far and wide to organized cybercrime groups.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 10″

The Patch Gap: Why Defenders Need to Think in Chains, Not Checklists

It's time to turn from CVSS-backed patching to choke-point patching focused on breaking chains to critical assets.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 14″

Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius

The maximum-severity vulnerability, which still has no CVE, allows malicious, remote administrator access to the business-analytics platform and its downstream users.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 10″

Multistate Water System Attacks Widen, Iran Suspected

Attacks targeting water systems just keep flowing across a dozen states, against ill-secured, Internet-exposed PLCs.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 10″

'GhostJacking' Exposes Identity Governance Gaps in AI Agents

New research shows how attackers can use security alerts and blocked events to manipulate and hijack AI agents.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 14″

Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

The ransomware-as-a-service operation is finding success against critical infrastructure targets with leaked Conti code and old flaws in firewalls and VPN appliances.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 13″

Walmart Leaders Transform Security Operations Without Going Bananas

The big-box giant has scaled its defenses by encouraging trust and innovation. Good communications, transparency, and team spirit are key factors.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 14″

Microsoft's Patch Tuesday Deluge Continues With August Updates

The most concerning bug in the batch is CVE-2026-62878 (CVSS: 9.8), a remote code execution (RCE) vulnerability in Windows DNS Server that requires no user interaction.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 14″

Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition

Attackers continue to target critical infrastructure and government-linked organizations in the country, mirroring the increased activity across Latin America.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 10″

Walmart Takes a 'Trusted Agent' Approach to Purple Teaming

Walmart colocates red and blue teams to build trust and improve security through collaborative purple teaming exercises

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 12″

Long-running Data Theft Campaign Targeting Salesforce, ServiceNow

The "City-Forum" campaign has been active since at least March 2025 and has targeted organizations across multiple sectors with custom tooling.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 16″

Belgium's eID Authentication Opens Citizen Accounts to RCE

The trust framework underlying Belgium's electronic ID system was fully compromised by severe vulnerabilities in a key browser extension, showcasing bigger problems with extensions in general.

RSS 官方收录 · 可信分层展示

详情 原文 分享图
Aggregate Dark Reading 网络安全 11″

'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft

Researchers discovered hackers-for-hire performing cyber espionage and financially motivated heists from the same Web panel.

RSS 官方收录 · 可信分层展示

详情 原文 分享图