Aggregator
CVE-2026-9991 | Google Chrome up to 148.0.7778.179 on Windows Media cross-domain policy (ID 513173)
CVE-2026-9986 | Google Chrome up to 148.0.7778.179 OptimizationGuide clickjacking (ID 513028)
CVE-2026-9989 | Google Chrome up to 148.0.7778.179 Media cross-domain policy (ID 513054)
CVE-2026-9985 | Google Chrome up to 148.0.7778.179 on ChromeOS Media information disclosure (ID 513019)
CVE-2026-9983 | Google Chrome up to 148.0.7778.179 Skia type confusion (ID 513001)
CVE-2026-9982 | Google Chrome up to 148.0.7778.179 ANGLE sandbox (ID 513001)
CVE-2026-9981 | Google Chrome up to 148.0.7778.179 Skia information disclosure (ID 512995)
CVE-2026-9980 | Google Chrome up to 148.0.7778.179 Printing improper isolation or compartmentalization (ID 511776)
Anthropic launches Claude Opus 4.8, prepares Mythos-class models for all customers
Anthropic has released Claude Opus 4.8 and outlined plans for broader access to its Mythos-class models, which the company expects to make available to all customers in the coming weeks. Claude Opus 4.8 (Source: Anthropic) Claude Opus 4.8 is available to all users, with pricing unchanged from Opus 4.7. Anthropic highlighted improvements in model honesty, noting that Opus 4.8 is more likely to acknowledge when it lacks sufficient information and less likely to make unsupported … More →
The post Anthropic launches Claude Opus 4.8, prepares Mythos-class models for all customers appeared first on Help Net Security.
Netskope extends data localization capabilities with NewEdge updates
Netskope has enhanced its NewEdge Network infrastructure, expanding data sovereignty capabilities to more regions than any other SASE cloud provider. The NewEdge Network architecture provides national data localization features that address requirements for network transport, data processing, and metadata governance in major regions worldwide, while enabling Netskope to extend this coverage to additional countries. The solution will also offer third-party validation to help customers meet compliance and data localization requirements. A comprehensive approach to data … More →
The post Netskope extends data localization capabilities with NewEdge updates appeared first on Help Net Security.
AI靶场安全实战系列:从成员推断到隐私泄露——数据与知识安全深度剖析
应用年订阅用户取消之后 95% 不会再回头
Claroty targets cyber-physical system risks with AI-powered security agent
Claroty has launched Claroty Claire, a CPS-native AI security agent designed to help organizations defend mission-critical infrastructure. Claire is powered by a CPS language model trained on more than a decade of industry expertise and CPS-related data. The launch expands organizations’ capabilities for supporting the safety, uptime, and availability of cyber-physical systems. Defending a rapidly expanding attack surface from supercharged threats The rate at which AI is expanding the CPS attack surface requires proactive steps … More →
The post Claroty targets cyber-physical system risks with AI-powered security agent appeared first on Help Net Security.
Humanix expands detection to identify live violations of security procedures
Humanix has announced a capability to identify live violations of organization-defined procedures governing IT support workflows. Designed to prevent unauthorized access, these procedures typically require help desk and service desk agents to follow identity verification steps before fulfilling sensitive requests, such as credential resets. Attackers have learned that pressuring agents to bypass these safeguards is among the fastest paths to a breach. “People staffing help desks and service desks are placed in an impossible position. … More →
The post Humanix expands detection to identify live violations of security procedures appeared first on Help Net Security.
Шестизначный PIN — и весь Google-аккаунт у злоумышленников. Рассказываем, как работает новая атака VaultJacking
从一次AppLocker思考,再看如今终端安全的发展方向
每周高级威胁情报解读(2026.05.22~05.28)
Algorithmic Infiltration: Microsoft Unmasks Generative AI Poisoning in Cryptojacking Campaign
Exploitation of High-Performance Hardware Boundaries Microsoft recently discovered an advanced cryptojacking campaign. Specifically, this malware masquerades as popular hardware monitoring utilities and PC overclocking software. Consequently, the threat actors do not focus on mass...
The post Algorithmic Infiltration: Microsoft Unmasks Generative AI Poisoning in Cryptojacking Campaign appeared first on Information Security News.
Malicious RVTools Installer Abuses Sectigo Certificate to Bypass SmartScreen Warnings
A trusted tool for VMware administrators has been weaponized. Attackers built a fake version of RVTools, a widely used utility for managing virtual infrastructure, and disguised it with a real digital certificate to slip past Windows security warnings without raising a flag. RVTools is a staple in enterprise environments. IT administrators rely on it daily […]
The post Malicious RVTools Installer Abuses Sectigo Certificate to Bypass SmartScreen Warnings appeared first on Cyber Security News.