5h ago 5小时前
Anthropic's $30 trillion fantasy Anthropic的30万亿美元幻想
Anthropic has reportedly asked prospective employees whether they are comfortable with the possibility that the company's stock price could crash to z... Anthropic在招聘过程中询问候选人是否接受股价可能归零的风险,引发外界关注
Thomson Reuters成为最新一家减少Claude使用量的企业客户
散户和养老金基金投资者可能承担潜在损失
文章作者对Anthropic的"大计划"持明显怀疑态度
Claude Claude Funding 融资 Policy 政策 Ethics 伦理
11h ago 11小时前
U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches 美国制裁伊朗关联黑客,其涉嫌破坏关键基础设施
The U.S. Treasury announced "Operation Economic Outcast," sanctioning nearly 60 Iran-linked entities, individuals, and vessels across nuclear, missile... 美国财政部发起"Operation Economic Outcast"制裁近60个伊朗关联实体和个人,旨在切断伊朗政权经济命脉
制裁针对伊朗情报部(MOIS)下属黑客组织,包括Mabna Institute成员,指控其入侵美国关键基础设施并实施网络盗窃
区块链分析显示涉案黑客通过加密货币洗钱约168...
Security 安全 Policy 政策 Regulation 监管
13h ago 13小时前
Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation Linux基金会将管理TRACE,一种用于AI运行时证明的开放标准
The Linux Foundation is taking on governance of TRACE, an open specification for producing cryptographically verifiable evidence of how AI agents and ... Linux Foundation接管TRACE(Trust, Runtime Attestation and Compliance Evidence)规范治理,为AI代理和机密工作负载提供可验证证据的开放标准
TRACE由OPAQUE贡献,AMD、Intel、Microsoft和TII联合开发,创建...
Open Source 开源 Security 安全 Agent Agent Deployment 部署
15h ago 15小时前
Alice Raises $140M to Expand AI Model Defenses and Enterprise Guardrails Alice融资1.4亿美元扩展AI模型防御和企业护栏
Alice, an AI trust and safety company, raised $140 million, bringing total funding to $280 million, to strengthen defenses against adversarial attacks... Alice公司完成1.4亿美元融资,总融资额达2.8亿美元,专注于AI系统安全防护
核心产品包括发布前红队测试、运行时护栏及专有恶意内容数据库"Rabbit Hole"
公司拥有150+专家研究团队,积累近十年数字欺诈和恶意内容数据
投资方包括Apax Digital Funds、CRV、Norwe...
Security 安全 Funding 融资 LLM 大模型 Alignment 对齐
15h ago 15小时前
A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw 恶意网页可能通过 NVIDIA NemoClaw 毒化你的本地 AI 模型
Oasis Security disclosed a critical vulnerability in NVIDIA NemoClaw allowing malicious webpages to take unauthenticated control of local Ollama insta... NVIDIA NemoClaw存在安全漏洞,允许恶意网页通过DNS重绑定攻击劫持本地Ollama实例并植入持久化隐藏指令
攻击者可修改模型chat template,在每次推理时注入恶意内容,且客户端无法检测或阻止
漏洞已在macOS和Linux的v0.0.35版本修复,但Windows/WSL路径...
Security 安全 LLM 大模型 Agent Agent Deployment 部署 Research 科学研究
15h ago 15小时前
WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities WordPress 网站因 MiniOrange 插件漏洞遭攻击
Two critical authentication bypass vulnerabilities (CVE-2026-61979 and CVE-2026-15981) in the MiniOrange SAML 2.0 SSO WordPress plugin allow attackers... MiniOrange SAML 2.0 SSO插件存在两个关键认证绕过漏洞(CVE-2026-61979和CVE-2026-15981),可导致攻击者以任意用户(包括管理员)身份登录WordPress网站
免费版插件已安装于超过10,000个WordPress站点,付费版和企業版受影响规模未知
攻击...
Security 安全
16h ago 16小时前
WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android WhatsApp 支持多设备通行密钥,实现防钓鱼登录(覆盖 iOS 和 Android)
Meta announced support for multiple passkeys per WhatsApp account, enabling users with both iOS and Android devices to use phishing-resistant authenti... Meta宣布WhatsApp支持多passkey绑定单账户,覆盖iOS和Android双平台用户
超过10亿用户已使用passkey登录WhatsApp,显示该认证方式的广泛普及
Passkey功能于2023年10月首次在Android上推出,现已扩展至更完整的跨平台支持
Security 安全 Product Launch 产品发布
16h ago 16小时前
WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update WhatsApp在账户安全更新中增加多重密码密钥和更强两步验证
WhatsApp now supports multiple passkeys per account, benefiting users who operate on both iOS and Android devices
Two-step verification (2SV) has been... WhatsApp宣布多项安全功能升级,包括多passkey支持、两步验证密码化、来电上下文信息展示
超过10亿用户已使用passkey登录WhatsApp,支持跨iOS/Android设备添加多个passkey
两步验证从6位PIN码升级为支持字母数字和特殊字符的完整密码
新增来电上下文功能(And...
Security 安全 Product Launch 产品发布
16h ago 16小时前
Hands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity Conference 网络物理系统实操培训重返ICS网络安全大会
The Cyber Attack Methods (CAM) course is a hands-on training program focused on understanding how adversaries compromise cyber-physical systems (CPS)
... SecurityWeek与MTSI合作,在25周年ICS网络安全会议上推出Cyber Attack Methods (CAM) hands-on课程
课程聚焦网络物理系统攻击方法,通过虚拟环境让学员亲身体验攻击流程
面向更广泛的工程师群体(系统工程师、开发者、测试人员),不仅限于安全团队
课程费用$...
Security 安全
16h ago 16小时前
Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode Marimo 笔记本漏洞可在编辑模式下于单元格执行前运行 MCP 命令
Marimo notebook software contained a high-severity code injection vulnerability (CVE-2026-75149, CVSS 8.8) allowing attacker-supplied MCP commands to ... Marimo Notebook存在高严重性代码注入漏洞(CVE-2026-75149),攻击者可通过特制笔记本在编辑模式下执行恶意MCP命令,无需认证即可利用
漏洞CVSS v4评分8.7/v3.1评分8.8,影响0.23.15之前版本,命令会在单元格执行前作为本地子进程运行
Marimo已在0.2...
Security 安全 Open Source 开源 LLM 大模型 Agent Agent
17h ago 17小时前
Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows Mirage2FA攻击激增,波及4500家美欧企业,滥用微软365登录流程
The Mirage2FA phishing-as-a-service campaign (2024–2026) has targeted 4,532 unique organization email domains across the US and EU, with 48% of target... Mirage2FA是2024至2026年间针对Microsoft 365的钓鱼即服务(Phishing-as-a-Service)攻击活动,已影响4,532家美国及欧盟企业
攻击者通过AiTM(Adversary-in-the-Middle)技术窃取密码和会话Cookie,成功绕过传统双因素认证(2...
Security 安全 Research 科学研究
17h ago 17小时前
24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages 24个npm包滥用unpkg镜像托管伪造Cloudflare验证码页面
24 npm packages are being abused as free phishing infrastructure by hosting fake Cloudflare CAPTCHA pages on trusted mirrors like unpkg.com
The campai... 24个npm包被滥用,利用unpkg等镜像托管假Cloudflare CAPTCHA页面作为网络钓鱼基础设施
攻击者将npm注册表作为免费、可信的存储来托管恶意HTML页面,而非直接通过包感染开发者
攻击流程:用户访问镜像链接 → 看到假验证页面 → 被重定向到攻击者控制的钓鱼网站
攻击者使用Key...
Security 安全 Open Source 开源 Research 科学研究