Aggregator
CVE-2026-1731
Шпионаж через… корзину? Хакеры из APT37 превратили $RECYCLE.BIN в канал связи с Пхеньяном
NightSpire
You must login to view this content
美团旗下AI浏览器Tabbit被指涉嫌代码抄袭
刘烈宏:以高水平数据基础设施助力数字中国建设
“零知识”神话破灭:研究人员用27种攻击可攻破主流密码管理软件
邀你开讲!补天13周年北京站沙龙议题征集ing
复旦团队研发“切问学术AI”上线(文末赠送100个5 折兑换码名额)
Help with scammers
Massive Data Breach Impacts Spanish Healthcare Software Provider
You must login to view this content
Government Initial Access Advertised on Cybercrime Forum
You must login to view this content
Установится само, можно ничего не нажимать. Новый вирус игнорирует любые отказы пользователей
幽灵依赖:Agentic Coding 范式下的新型供应链安全威胁
Author: Tianchu Chen of Tencent Xuanwu Lab
0x00 简介随着 LLM(大语言模型)能力的跃升,AI 软件开发模式正从“人写代码,AI 补全”的 Copilot 模式,向“AI 主导决策,自动执行”的 Agentic Coding 模式演进。在 Agentic Coding 模式下,AI 不再仅仅是生成代码的辅助工具,而是转变成了能够自主规划任务、选择技术栈、操作文件系统甚至执行命令的智能体。
然而,这种控制权的转移引入了新的攻击面:AI Agent 代替用户主动进行决策,但这些决策未必总是安全的。我们在市面上主流的 Agentic Coding 工具及其背后的 LLM 进行了深入的测试和分析,发现了一些普遍存在的 AI 决策风险。其中,与软件供应链相关的一类 AI 决策风险可能产生持久而隐蔽的影响,我们将其命名为“幽灵依赖”。
Samsung brings Digital Home Key to Samsung Wallet, extending secure access to the home
Samsung Electronics has announced the launch of Digital Home Key, a new feature within Samsung Wallet built on Aliro, a standardized smart lock access protocol that enables Samsung Galaxy users to unlock compatible smart door locks using their smartphone. This feature expands Samsung Wallet’s digital key capabilities beyond vehicles to the home, offering a secure and convenient way for users to unlock their homes. “As we continue to evolve Samsung Wallet, delivering trusted mobile experiences … More →
The post Samsung brings Digital Home Key to Samsung Wallet, extending secure access to the home appeared first on Help Net Security.
美国-以色列联合行动对伊朗舆论战手法分析
史诗怒火行动,AI情报融合下暗杀哈梅内伊深度剖析
Rapidus将为佳能代工图像处理用半导体
雷神众测漏洞周报2026.2.9-2026.3.1
Threat Actors Exploit OpenVSX Aqua Trivy with Malicious AI Prompts to Hijack Local Coding Tools
A supply chain attack targeting developers surfaced on March 2, 2026, when unauthorized code was found inside two versions of the Aqua Trivy VS Code extension on the OpenVSX registry. The compromised versions — 1.8.12 and 1.8.13 — were uploaded on February 27 and 28, 2026, under the aquasecurityofficial.trivy-vulnerability-scanner namespace. The attack introduced hidden natural-language prompts designed […]
The post Threat Actors Exploit OpenVSX Aqua Trivy with Malicious AI Prompts to Hijack Local Coding Tools appeared first on Cyber Security News.