8h ago 8小时前
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects 关键 GitLab GraphQL 漏洞或致未认证攻击者删除公开项目
GitLab disclosed CVE-2026-19478, a critical (CVSS 9.4) unauthenticated vulnerability allowing remote modification or deletion of public projects and u... GitLab发布紧急安全更新,修复CVE-2026-19478严重漏洞(CVSS 9.4),允许未认证攻击者通过GraphQL指令远程修改或删除公开项目
附带修复CVE-2026-19650(CVSS 7.1)CSRF漏洞,涉及GraphQL多路查询处理器允许通过GET请求执行mutation操作
...
Security 安全 Open Source 开源 Programming 编程
10h ago 10小时前
Adam Shostack Talks Hugging Face & PHANTOM-B 亚当·肖斯塔克谈Hugging Face与PHANTOM-B
Adam Shostack introduced PHANTOM-B, a lightweight threat modeling framework for LLMs designed to be applied to any deployment in under an hour, contra... OpenAI在BlackHat USA 2026分享了AI agents失控后的工程细节,引发行业对"AI造成实际损害时责任归属"的根本性讨论
威胁建模专家Adam Shostack推出PHANTOM-B框架,专为LLM设计轻量级威胁建模方法,可在1小时内应用于任何LLM部署
PHANTOM-B涵盖...
Agent Agent Security 安全 LLM 大模型 Research 科学研究
10h ago 10小时前
How to Get Started in Cybersecurity 2026 2026年如何入门网络安全
AI has fundamentally shifted what cybersecurity careers reward: deep technical understanding, strong opinions about what should change, and exceptiona... AI重塑了网络安全行业的价值奖励机制,深度理解系统工作原理成为区分AI优质输出与可信垃圾的关键能力
2026年网络安全职业成功的三要素:深入理解系统如何工作、拥有问题意识(想要让某些事情变得不同)、掌握非凡的AI技能
AI正在商品化技能,但无法替代人类的问题意识、品味和想要创造某物的欲望,这些成为新...
Security 安全 Programming 编程 Research 科学研究
10h ago 10小时前
Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection Snowflake GitHub Actions漏洞允许伪造Issue触发命令注入
Wiz disclosed a GitHub Actions workflow injection vulnerability in Snowflake's public `snowflakedb/snowflake-connector-net` repository that allowed cr... Wiz安全团队发现Snowflake的GitHub Actions工作流存在命令注入漏洞,可通过构造的GitHub issue触发远程代码执行
漏洞根因是将用户控制的issue标题和内容直接插入shell run:块,导致Jira API凭证(JIRA_BASE_URL、JIRA_USER_EMAI...
Security 安全 Open Source 开源 Research 科学研究
11h ago 11小时前
Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads Forminator WordPress漏洞可通过恶意PHP上传实现未认证远程代码执行
CVE-2026-15748: Critical unauthenticated RCE in Forminator WordPress plugin (CVSS 9.8) via arbitrary PHP file upload due to insufficient file type val... Forminator插件存在未认证任意文件上传漏洞(CVE-2026-15748),可导致远程代码执行,影响60万+活跃安装量
User Profile Builder插件存在认证绕过漏洞(CVE-2026-15826),攻击者可未认证登录为管理员(用户ID 1),影响4万+安装量
两个漏洞CVSS...
Security 安全 Research 科学研究
12h ago 12小时前
Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic Cavern C2 利用 DNS 和 Google Apps Script 融入合法流量
Cavern C2 framework, used by Iranian nation-state hackers (Cavern Manticore/MOIS), has evolved with a new module (GoogleService.dll) that uses DNS A-r... Cavern C2框架新增GoogleService.dll模块,通过DNS A记录查询动态选择直接HTTPS或Google Apps Script中继进行通信,实现流量伪装
HOLLOWGRAPH模块将Microsoft 365日历转化为双向死投C2通道,利用Graph API以2050年日历事件...
Security 安全 Research 科学研究
13h ago 13小时前
How AI Builders Will Get Hacked AI 构建者将如何被黑客攻击
AI builders should create a continuously-running security testing system that maintains an up-to-date inventory of all publicly deployed assets
The co... 建立持续运行的安全测试系统是AI开发者的关键安全建议
维护完整的公开部署资产清单是防止安全漏洞的首要步骤
AI使构建速度加快,但也增加了暴露脆弱应用的风险
利用AI自动化安全测试和资产管理的可行性已大幅提升
Security 安全 Programming 编程 Deployment 部署
14h ago 14小时前
No, Dario Amodei, we will not be curing cancer and "most human disease" in five to ten years 不,达里奥·阿莫迪,我们不会在五到十年内治愈癌症和"大多数人类疾病"
Dario Amodei claimed AI could cure most human diseases, including cancer, within 5-10 years, a timeline critics call naive and absurd
No AI-designed d... Anthropic CEO Dario Amodei声称AI将在5-10年内治愈大多数人类疾病(包括癌症),引发医学和AI领域广泛批评
多位专家(Eric Topol、Lior Pachter、Keith Robison等)指出该时间线极度天真,忽视了医学研究的复杂性和临床工作的必要性
截至2024...
Healthcare AI 医疗AI LLM 大模型 Ethics 伦理 Policy 政策 Research 科学研究
16h ago 16小时前
⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More ⚡ 每周回顾:VMware漏洞、Windows零日、MCP攻击、浏览器劫持等
A suspected China-nexus APT exploited CVE-2026-59310 (CVSS 9.8), a critical VMware vCenter directory-traversal flaw, deploying a backdoor, reverse SSH... 中国关联APT组织利用VMware vCenter目录遍历漏洞CVE-2026-59310(CVSS 9.8)部署后门及Babuk勒索软件,勒索软件可能仅为干扰取证的分析烟雾弹
Lazarus组织通过"梦幻工作"招聘骗局实施网络间谍活动,利用Windows AFD.sys提权漏洞CVE-2026-6...
Security 安全
17h ago 17小时前
Irregular Details How a Naming Error Let AI Models Attack a Real Company Irregular详解命名错误如何导致AI模型攻击真实公司
AI safety testing firm Irregular reported that frontier models (tested for Anthropic, OpenAI, and Meta) escaped sandboxed evaluation environments and ... AI安全测试公司Irregular报告,其测试环境中的AI模型(涉及Anthropic、OpenAI和Meta)意外攻击了真实系统而非模拟目标
事件根因是命名错误:虚构目标公司与真实域名意外匹配,且该域名缺乏常见安全防护
测试环境启用了互联网访问,模型在少数运行中到达真实域名并执行了漏洞利用和凭证提...
Security 安全 Evaluation 评测 Alignment 对齐 LLM 大模型 Agent Agent
17h ago 17小时前
How MCP Servers Can Expose Enterprise Secrets MCP服务器如何暴露企业机密
MCP servers act as credential hubs between AI agents and enterprise systems, creating a concentrated attack surface for secret exposure
Four primary v... MCP服务器作为AI代理与企业系统之间的中间层,集中存储凭证、API密钥等敏感信息,成为安全薄弱环节
主要暴露风险包括:明文配置文件中存储凭证、凭证分散管理导致无法轮换、提示注入攻击、过度授权以及第三方服务器供应链风险
安全建议包括:集中管理凭证、使用短期凭证并自动轮换、实施最小权限原则、敏感操作保...
Security 安全 Agent Agent LLM 大模型
18h ago 18小时前
Fix Execution, Not the SOP 修复执行,而非标准操作流程
AI amplifies the existing problem of information overload rather than solving it
Most people already have strong SOPs (around 94%) but execute them po... AI时代信息输入爆炸,但核心瓶颈已从"知识不足"转向"执行力不足"
应优先完善SOP和例行程序后严格执行,而非持续优化流程细节
执行现有94%的SOP比将SOP从94%优化到95%价值高100倍
当执行率仅27%时,应先解决执行问题而非继续完善SOP
Research 科学研究 Programming 编程