Aggregator
黑客在Laravel 生态系统中隐藏恶意PHP包,发动供应链攻击
OpenAI joins the race in AI-assisted code security
OpenAI introduced Codex Security, an AI agent that reviews codebases to find, verify, and help fix software vulnerabilities. The launch comes a few weeks after rival Anthropic unveiled its Claude Code Security tool. Codex Security (Source: OpenAI) The feature is available in research preview via Codex Web for ChatGPT Pro, Enterprise, Business, and Edu customers, with free access for the next month. Previously known as Aardvark, Codex Security launched last year in a private beta … More →
The post OpenAI joins the race in AI-assisted code security appeared first on Help Net Security.
从网络防御到网络征伐:特朗普政府发布新版美国网络战略
AI医生可被任意劫持:篡改患者处方剂量、给出错误医疗建议
CVE-2023-43000
CVE-2025-43530
Хакеры, убытки и 10 килограммов курицы в секунду. Крупнейший экспортер мяса из Румынии оказался на грани банкротства
上周关注度较高的产品安全漏洞(20260302-20260308)
CNVD漏洞周报2026年第9期
AI 驱动安全升级|慢雾(SlowMist) 将举办链上合规新品发布会
AI “养龙虾” 走红,官方提示:警惕安全风险
Critical ExifTool Flaw Lets Malicious Images Trigger Code Execution on macOS
A newly discovered vulnerability is challenging the long-held belief that macOS systems are inherently immune to malware. Security researchers from Kaspersky’s Global Research and Analysis Team (GReAT) have identified a critical flaw that allows threat actors to execute malicious code on Macs simply by processing a tampered image file. ExifTool, a widespread open-source utility for […]
The post Critical ExifTool Flaw Lets Malicious Images Trigger Code Execution on macOS appeared first on Cyber Security News.
Отпечаток трафика и риск блокировок. Viber пытался обмануть фильтры, но обманул только пользователей
Hikvision Multiple Products Vulnerability Allows Malicious Users to Escalate Privileges
A severe vulnerability affecting multiple Hikvision products was added to the Known Exploited Vulnerabilities (KEV) catalog on March 5, 2026. Tracked globally under CVE-2017-7921, this security flaw poses a significant risk to organizations that rely on these popular surveillance systems. The flaw enables malicious users to bypass standard security checks, escalate their privileges, and gain […]
The post Hikvision Multiple Products Vulnerability Allows Malicious Users to Escalate Privileges appeared first on Cyber Security News.
FBI 通过 Proton Mail 识别抗议者身份
Microsoft Warns Fake AI Browser Extensions Compromised Chat Histories Across 20,000+ Enterprise Tenants
A wave of counterfeit AI-powered browser extensions has silently breached over 20,000 enterprise environments, compromising the chat histories of employees who routinely used AI tools for work. These malicious Chromium-based extensions disguised themselves as legitimate AI assistant tools and accumulated close to 900,000 installs before the threat was surfaced. What made these extensions particularly alarming […]
The post Microsoft Warns Fake AI Browser Extensions Compromised Chat Histories Across 20,000+ Enterprise Tenants appeared first on Cyber Security News.
Android 小程序APP 抓包,从一直报错443到抓包畅通无阻
Заходи кто хочешь, бери что видишь. В коде популярного видеодвижка выявили критическую ошибку
CISA Warns of macOS and iOS Vulnerabilities Exploited in Attacks
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert regarding multiple Apple vulnerabilities currently facing active exploitation. On March 5, 2026, CISA added three security flaws affecting macOS, iOS, iPadOS, and other Apple products to its Known Exploited Vulnerabilities (KEV) catalog. This addition warns network defenders that threat actors are actively leveraging […]
The post CISA Warns of macOS and iOS Vulnerabilities Exploited in Attacks appeared first on Cyber Security News.