Aggregator
网络安全信息与动态周报2025年第33期(8月11日-8月17日)
【漏洞通告】Commvault 未授权远程代码执行漏洞(CVE-2025-57790)
Protect Your Phone: Guard Against SIM Swap Scams and Fraud
Rrise of SIM swap fraud, its implications, and how to protect yourself. Stay informed and secure your accounts today!
The post Protect Your Phone: Guard Against SIM Swap Scams and Fraud appeared first on Security Boulevard.
一图读懂 | 国家标准GB/T 31722—2025《网络安全技术 信息安全风险管理指导》
关于举办“AI安全攻防与测试”培训班的通知
专家解读 | 构建数据标注新生态 推进高质量数据集建设
专题·原创 | 可信数据空间建设路径的探索与思考
新态势·新实战 | CSOP 2025 网络安全运营实战大会在京开幕
Hijacking Windsurf: How Prompt Injection Leaks Developer Secrets
This is the first post in a series exploring security vulnerabilities in Windsurf. If you are unfamiliar with Windsurf, it is a fork of VS Code and the coding agent is called Windsurf Cascade.
The attack vectors we will explore today allow an adversary during an indirect prompt injection to exfiltrate data from the developer’s machine.
These vulnerabilities are a great example of Simon Willison’s lethal trifecta pattern.
Overall, the security vulnerability reporting experience with Windsurf has not been great. All findings were responsibly disclosed on May 30, 2025, and receipt was acknowledged a few days later. However, all further inquiries regarding bug status or fixes remain unanswered. The recent business disruptions and departure of CEO and core team members certainly put Windsurf in the news.