Aggregator
内存成本占到了手机成本的五成以上
Onspring CISO on where automated GRC systems fall short
In this interview with Help Net Security, Nichole Windholz, CISO at Onspring, talks about the limits of automated GRC systems and continuous control monitoring. She explains why color-coded dashboards can hide nuance, how teams can check the data feeding their tools, and which risks resist measurement, such as insider behavior and vendor concentration. Continuous control monitoring tools tend to produce a green-yellow-red mosaic that flattens nuance. When a CISO walks into a board meeting with … More →
The post Onspring CISO on where automated GRC systems fall short appeared first on Help Net Security.
Дискриминация, чертежи оружия и поддельные фото. За что бывший инженер подал в суд на компанию Илона Маска
Open-source CI/CD abuse detector guards against stolen credential attacks
CI/CD Abuse Detector is an open-source project that uses a large language model to flag suspicious changes to continuous integration and continuous deployment pipelines, workflows, and automation configurations. The repository contains drop-in templates for GitHub Actions, GitLab CI, and Azure DevOps. The project targets a common attack chain in software supply chain compromises. Stolen developer credentials are used to push modifications to workflow files, which then harvest secrets stored in the CI environment. The detector … More →
The post Open-source CI/CD abuse detector guards against stolen credential attacks appeared first on Help Net Security.
Linux 7.1 释出
The Complete Guide to Authentication Ecosystems: From Kerberos & LDAP to OAuth2 & OIDC
有消息称Claude Fable 5有望在本周恢复访问 A社派遣专员与美国政府商讨
Искали хентай — скачали троян. Argamal RAT даёт хакерам полный доступ к системам любителей «японской клубнички»
一张散步照片,暗流涌动半个地球
A hardware neural network backdoor that hides in plain sight
Deep learning systems on phones, cars, and other edge devices increasingly run on custom silicon. Specialized chips such as FPGAs and ASICs give these systems the speed and low power consumption that edge applications need. Many of these chips come from third-party design houses and foundries, which adds steps to the supply chain where an outside party can alter a device. Researchers at the University of Tennessee and the University of Florida built an attack … More →
The post A hardware neural network backdoor that hides in plain sight appeared first on Help Net Security.
Anti-Slop CTF 2026
Date: June 13, 2026, 1 a.m. — 15 June 2026, 01:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://ctf.antislopp.i.ng/
Rating weight: 0
Event organizers: hackme
CyberSci Nationals 2025-2026
Date: June 13, 2026, 1 p.m. — 14 June 2026, 23:00 UTC [add to calendar]
Format: Jeopardy
On-site
Location: Ottawa, Canada
Offical URL: https://cybersecuritychallenge.ca/
Rating weight: 0.00
Event organizers: CyberSciOrganizers
Operation Heist CTF 2026
Date: June 13, 2026, 2 p.m. — 14 June 2026, 14:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://registration.hackkap.com/
Rating weight: 0
Event organizers: HACK KAP
SCTF 2026
Date: June 14, 2026, 1 a.m. — 15 June 2026, 01:00 UTC [add to calendar]
Format: Jeopardy
On-line
Location: On-line
Offical URL: https://sctf2026.xctf.org.cn/
Rating weight: 0
Event organizers: Syclover
会计师事务所毕马威使用AI撰写AI使用报告 里面有多种AI产生的幻觉内容
Weekly Update 508
Light switches. How on earth is it so hard to find decent light switches?! It sounds ridiculous until you actually spend enough time looking for ones that meet two simple criteria:
- Aren't stateful (switch is up or down, has to be push-button)
- Looks good
Now, I'
玩具题满分,真实项目瘫痪?AI辅助开发能力“真”评测
Proving what a military AI model will do is the real problem
Defense contractors build AI systems that task drones automatically and propose kill-chains to support soldiers. Several of these contractors have partnered with frontier AI companies to put advanced models into military tools. Anduril works with OpenAI, Palantir works with Microsoft, and Lockheed Martin works with Meta. The systems coming out of these partnerships carry a security problem that sits outside the methods of arms control diplomacy: confirming what an AI model will do. Verification built … More →
The post Proving what a military AI model will do is the real problem appeared first on Help Net Security.