Aggregator
JVN: リコーおよびコニカミノルタジャパン製プリンタドライバーにおける権限昇格の脆弱性
会计师事务所毕马威使用AI撰写AI使用报告 里面有多种AI产生的幻觉内容
Weekly Update 508
Light switches. How on earth is it so hard to find decent light switches?! It sounds ridiculous until you actually spend enough time looking for ones that meet two simple criteria:
- Aren't stateful (switch is up or down, has to be push-button)
- Looks good
Now, I'
玩具题满分,真实项目瘫痪?AI辅助开发能力“真”评测
Proving what a military AI model will do is the real problem
Defense contractors build AI systems that task drones automatically and propose kill-chains to support soldiers. Several of these contractors have partnered with frontier AI companies to put advanced models into military tools. Anduril works with OpenAI, Palantir works with Microsoft, and Lockheed Martin works with Meta. The systems coming out of these partnerships carry a security problem that sits outside the methods of arms control diplomacy: confirming what an AI model will do. Verification built … More →
The post Proving what a military AI model will do is the real problem appeared first on Help Net Security.
Как взломать поставщика Coca-Cola? Достаточно украсть один токен доступа в GitHub
お知らせ:インシデント報告Webフォームメンテナンス(2026年6月26日)のお知らせ
对话夏勇峰:做了 6 年,我亲手按下 AI 眼镜的暂停键
对话夏勇峰:做了 6 年,我亲手按下 AI 眼镜的暂停键
Senior engineers are spending their week cleaning up AI-generated code
At most U.S. technology companies, machines now write the bulk of the code that ships each week. The engineer’s job has shifted toward reviewing what the AI produces, and that review gives the code high marks. Leaders rate AI-generated code as higher quality than the code their own people write, praising its clean structure, consistent style, and low count of obvious bugs at submission time. The same code behaves worse once it runs. Production incidents … More →
The post Senior engineers are spending their week cleaning up AI-generated code appeared first on Help Net Security.
从RSAC2026看安全运营技术发展趋势(1):Agentic AI重塑安全
数世咨询:《新质·数字安全专精百强(2026)》正式发布
Handala’s FBI Drone Hack Claim Doubted by Experts
An Iran-linked hacking group called Handala has claimed it gained access to data from the FBI’s FPV drones, and the group is now threatening participants in the upcoming World Cup. According to a report...
The post Handala’s FBI Drone Hack Claim Doubted by Experts appeared first on Information Security News.
GreatXML BitLocker Bypass: Windows Defender & WinRE Exploit
Full-disk encryption safeguards data only until the recovery environment emerges as a catastrophic weak link. Recently, the infamous cybersecurity researcher, Nightmare Eclipse, unveiled a novel Windows vulnerability. They dubbed this flaw GreatXML. Specifically, this...
The post GreatXML BitLocker Bypass: Windows Defender & WinRE Exploit appeared first on Information Security News.
没显卡没资源?复旦 NLP 直接把免费 GPU 塞进 AI,科研全自动时代来了!
Oracle PeopleSoft Zero-Day Exploit: ShinyHunters Attack
The Hidden Threat Within Utility Modules Colossal corporate networks frequently suffer breaches through obscure utility modules. Indeed, these quiet systems harbor valuable employee, student, and client archives for decades. Recently, the notorious ShinyHunters syndicate...
The post Oracle PeopleSoft Zero-Day Exploit: ShinyHunters Attack appeared first on Information Security News.
Chrome’s Manifest V3 Shift Threatens Ad Blockers
The internet has long been a place where advertising and malicious code travel hand in hand. Soon, however, Chrome users may face a difficult tradeoff. They will need to choose between extension security and...
The post Chrome’s Manifest V3 Shift Threatens Ad Blockers appeared first on Information Security News.