Aggregator
Default Azure Automation Setting Enables Cross-Tenant Identity Takeover
菲尔兹奖得主邓煜谈人工智能:已能帮助数学证明,但不能替代独立思考
有准可循 互联互通 | 《大模型安全网关产品安全指南》国标项目启动会顺利召开
全国工商联领导一行莅临绿盟科技调研指导,共商安全产业发展新路径
微软向LG施压要求停止推送弹窗广告
Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
Russian hackers exploit unpatched Zimbra servers to steal emails
Russian state-backed hacker group Laundry Bear has been breaking into government and commercial networks for at least a year by exploiting a vulnerability in the Zimbra Collaboration Suite (ZCS) webmail platform. Laundry Bear (also known as Void Blizzard, CL-STA-1114, and TA488) has been running the campaign since July 2025, according to a joint advisory from the NSA, FBI, CISA, and cybersecurity agencies from the Netherlands, UK, Australia, Canada, and a dozen other countries. “Laundry Bear’s … More →
The post Russian hackers exploit unpatched Zimbra servers to steal emails appeared first on Help Net Security.
Google 账号支持自拍人脸登录
Google 账号支持自拍人脸登录
Your Best Analyst Shouldn’t Be a Person. It Should Be a Capability Everyone Can Summon.
Your Best Analyst Shouldn’t Be a Person. It Should Be a Capability Everyone Can Summon.
近期觀影 - 無間道三部曲、醉好的時光、阿波羅 13 號
Hotel Wi-Fi Routers Compromised to Steal Corporate Login Credentials From Visitors
Apache Syncope Release Patches for Multiple RCE and SQL Injection Vulnerabilities
Apache has issued critical security updates for its Syncope identity and access management (IAM) platform to address multiple vulnerabilities, including remote code execution (RCE), SQL injection, privilege escalation, server-side request forgery (SSRF), and information disclosure. These flaws affect various versions of Syncope, and administrators are strongly urged to upgrade promptly to the latest secure releases. […]
The post Apache Syncope Release Patches for Multiple RCE and SQL Injection Vulnerabilities appeared first on Cyber Security News.
JetBrains Fixes Critical IntelliJ IDEA Code Execution Flaw and Four TeamCity Vulnerabilities
JetBrains has released security updates to address a critical code execution vulnerability in IntelliJ IDEA, alongside four high-severity vulnerabilities in TeamCity. Development teams and CI administrators are urged to apply these patches immediately to prevent potential remote attacks. JetBrains published a security advisory that details multiple issues across its IDE and server products, including IntelliJ […]
The post JetBrains Fixes Critical IntelliJ IDEA Code Execution Flaw and Four TeamCity Vulnerabilities appeared first on Cyber Security News.
SectopRAT Gives Attackers Remote Access to Passwords, Credit Cards, Cookies and Corporate Files
SectopRAT is at the center of a highly targeted malvertising campaign abusing Anthropic’s Claude platform to deliver a stealthy, HVNC‑enabled RAT that gives attackers deep, persistent access to victims’ passwords, credit cards, cookies and corporate files. The artifact masqueraded as a genuine Claude Desktop installer but redirected victims to claude.ai.download-app[.]us and then to downloading-api.it[.]com/html/claude/win, where […]
The post SectopRAT Gives Attackers Remote Access to Passwords, Credit Cards, Cookies and Corporate Files appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
FakeAgent Campaign Uses Malicious Bing Ads and Claude.ai Artifacts to Infect Corporate Users
A dangerous new malware campaign is tricking corporate workers who simply want a desktop version of a popular AI assistant. Between July 21 and July 22, 2026, at least 29 organizations saw unusual software installs and hidden persistence on their systems after staff searched for the Claude desktop app. The attack begins with paid ads […]
The post FakeAgent Campaign Uses Malicious Bing Ads and Claude.ai Artifacts to Infect Corporate Users appeared first on Cyber Security News.