Aggregator
CISA Adds 3 D-Link Router Flaws to KEV Catalog After Active Exploitation Reports
CISA Adds 3 D-Link Vulnerabilities to KEV Catalog Amid Active Exploitation Evidence
JetBrains推出基于AI的无代码平台Kineto 帮助用户轻松构建网站和应用程序
The Semiconductor Industry and Regulatory Compliance
CISOs say they’re prepared, their data says otherwise
Most security teams believe they can act quickly when a threat emerges. But many don’t trust the very data they rely on to do so, and that’s holding them back. A new Axonius report, based on a survey of 500 U.S.-based IT and security leaders, shows a disconnect between perceived readiness and actual performance in vulnerability and exposure management. While 90% of respondents said their organization is prepared to act when a threat is found, … More →
The post CISOs say they’re prepared, their data says otherwise appeared first on Help Net Security.
I built a client-only webtools site – P2P file & screen sharing, fingerprint tester, PDF tools, and more (no backend at all)
闪迪基于UltraQLC技术推出256TB超大容量固态硬盘 主要面向数据中心和AI领域
百度基于大模型安全运营的质效提升实践
百度作为一家业务复杂的大型互联网企业,同时又是关键基础设施,随着网络安全威胁的日益加剧,传统的安全运营手段在效率和效果上都面临巨大挑战。本次分享将介绍百度如何基于大模型构建深度安全推理智能体框架,实现运营效率和效果的双重提升,并展示包括告警自动研判和漏洞事件分析在内的实践经验,希望能给听众带来一些大模型安全领域应用最佳实践的启示。
演讲提纲
- 背景和挑战
大模型开始逐步应用于安全运营场景 百度安全运营面临的双效(效率+效果)提升需求 2. 架构设计
设计目标:基于深度安全推理智能体框架,实现双效提升 设计考虑:人机协同的工作流设计(运营流程梳理、质量标准定义、人机交互模式)、模型能力边界与拓展(模型结果可信度和可解释性、知识和工具依赖)、实施成本 整体架构(自底向上): 底座模型的知识补充 RAG、CoT、Function calling 流程编排 智能体 Review 机制 3. 实践案例
告警自动/辅助研判 + 事件处置 漏洞事件自动分析 + 处置 4. 未来展望
大模型原生的安全运营中心 实践痛点
明确目标,围绕安全运营场景的风险偏好,制定更贴合实际的落地目标,避免直接盲目追求大而全的零职守无人干预 以数据驱动能力迭代,缺少可用数据时应当从实际场景中提升标准化和自动化水平,引入业务的数据活水,避免直接使用脱离业务的合成数据 演讲亮点
从架构设计层面剖析安全运营场景双效提升应遵循的必要准则,提供构建深度安全推理智能体框架的完整视角 细粒度展现告警研判、漏洞分析处置等实际场景的双效提升最佳实践 听众收益
了解互联网大厂的安全运营需求痛点与大模型实践经验 了解规模化且对效果要求较高的安全运营场景下,大模型智能体设计考虑与整体架构
CVE-2025-7036 | CleverReach WP Plugin up to 1.5.20 on WordPress Title sql injection
CVE-2025-6256 | Flex Guten Plugin up to 1.2.5 on WordPress thumbnailHoverEffect cross site scripting
CVE-2025-6259 | esri-map-view Plugin up to 1.2.3 on WordPress Shortcode cross site scripting
CVE-2025-6690 | WP Tournament Registration Plugin up to 1.3.0 on WordPress Field cross site scripting
CVE-2025-6986 | FileBird Plugin up to 6.4.8 on WordPress Search sql injection
CVE-2025-7502 | WPBakery Page Builder Plugin up to 8.5 on WordPress cross site scripting
CVE-2013-10068 | Foxit Reader 5.4.4.1128 npFoxitReaderPlugin.dll memory corruption (EUVD-2013-7278 / EDB-23944)
【文末有奖互动】补天城市沙龙杭州站亮点抢先看!
Why 90% of cyber leaders are feeling the heat
90% of cyber leaders find managing cyber risks harder today than five years ago, mainly due to the explosion of AI and expanding attack surfaces, according to BitSight. These threats are also fueling high rates of burnout, with 47% of cybersecurity and cyber risk professionals reporting exhaustion. Another key factor in the burnout crisis is the lack of threat visibility. Those who work at organizations with the tools to regularly map threats across their environments … More →
The post Why 90% of cyber leaders are feeling the heat appeared first on Help Net Security.
Hacks on 3 Specialty Medical Providers Affect Nearly 800,000
Recent hacks on a provider of sleep disorder diagnostic gear and services, a network of medical imaging facilities and a multi-disciplinary cancer care center have affected nearly 800,000 patients. The breaches are among the latest rash of cybercriminal attacks plaguing the healthcare sector.
Dutch Prosecutors Recover From Suspected Russian Hack
The Dutch Public Prosecution Service on Monday began phased restoration of its networks after a cyberattack last month forced the agency to take down its services offline. The agency confirmed that hackers exploited a vulnerability in a Citrix device.