Posts of last few hours
Please support the site operations by clicking ads.
https://cyber.gc.ca/en/alerts-advisories/forcepoint-security-advisory-av26-960
https://cyber.gc.ca/en/alerts-advisories/dell-security-advisory-av26-959
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
https://govuln.com/news/url/x8dB
https://cyber.gc.ca/en/alerts-advisories/mikrotik-security-advisory-av26-958
These are the top threats you should know about this week.
https://www.f5.com/labs/articles/weekly-threat-bulletin-september-23rd-2026
https://cyber.gc.ca/en/alerts-advisories/nvidia-security-advisory-av26-957
https://cyber.gc.ca/en/alerts-advisories/github-security-advisory-av26-956
https://cyber.gc.ca/en/alerts-advisories/google-chrome-security-advisory-av26-955
https://cyber.gc.ca/en/alerts-advisories/ubiquiti-security-advisory-av26-954
https://cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-953
Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication.
The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at
https://thehackernews.com/2026/09/mikrotrick-chain-let-attackers-take.html
企业需要的已经不只是一个能写文档、做 PPT 的通用助手,而是一个能够理解组织数据、进入业务流程,同时受到身份、权限和审计约束的 Agent。
https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653114033&idx=2&sn=c9b31f0a70466292034a399be91e8f3a
用了 AI、消耗了 Token,不一定就是 AI 原生组织,但不用肯定没有机会。
https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653114033&idx=1&sn=2d1d206aa8f34540147a77a459563e5c
对 4740 万英国机动车年检(MOT test)数据的分析发现,当汽车行驶里程达到 9-12 万英里时,电动汽车的年检不合格率为汽油车同类车型的 75%(16.5% 对 22.1%)。行驶里程超过 12 万英里后,电动汽车的不合格率为 16%,而汽油车为 23.5%。研究发现,较低行驶里程两种动力类型的汽车之间的不合格率差异相对较小。研究还发现,电动汽车的一大问题是其轮胎磨损问题两倍于燃油车。英国机动车年检没有检查电池的健康状况,因此电动汽车电池健康情况未知。研究人员表示他们的研究驳斥了高里程电动汽车应该报废的观念。
https://www.solidot.org/story?sid=85467
https://cyber.gc.ca/en/alerts-advisories/wordpress-security-advisory-av26-952
Anthropic 声称其模型 Claude Mythos 在发现软件漏洞上胜过大多数安全专家。随后发生了 OpenAI–Hugging Face 安全事件,此后 Anthropic(自豪)和 Meta(不情愿)也披露了各自模型的类似事件。紧接着 Anthropic 宣称其模型取得了数学领域的突破;OpenAI 也声称自己取得了数学突破。Anthropic 工程师 Jacob Coxon 在宣布离职时引发了广泛关注,他声称该公司与 OpenAI 正“冲向自我进化的超级智能,并拿我们的生命在赌博”。媒体大肆报道了这些事件,且沿用了相关公司赋予其软件的拟人化叙事——即把软件描绘成不仅功能强大,而且已初具通用人工智能(AGI)雏形的产物。但深入研究的专家则给出了不同的答案,虽然这些发现并不能吸引眼球。网络安全专家指出,涉及模型的安全事件更多是 OpenAI 的疏忽大意,未能采取基本的安全措施,而不是“模型失控”或“AI 智能体创造文明”。OpenAI 模型在解决数学难题上的突破其原创性也相当可疑。数学家公开对 AI 企业利用其专业领域进行炒作提出了警告。AI 公司通过炒作模型失控也将自己置身事外,将责任归咎于大模型而不是公司本身,逃避应承担的责任。以 OpenAI 为例,当该公司开发的恶意软件被用于入侵另一家公司时,媒体、名人和议员谈论是“失控模型”而不是 OpenAI 的责任,仿佛大模型真的会自动发动攻击,公众的注意力被转移到虚构的“超级智能”的恐惧之上。我们不要被 AI 公司的炒作所愚弄。
https://www.solidot.org/story?sid=85466
https://cyber.gc.ca/en/alerts-advisories/hpe-security-advisory-av26-951
英国竞争监管机构 CMA 想要让 Android 和 Chrome 用户对 AI 助手和搜索引擎有更大的选择权和控制权。CMA 公布了一份提案,要求 Google 在用户首次设置 Android 手机或打开 Chrome 浏览器时,向其展示多种搜索引擎供选择,并且每年提示用户选择一个默认搜索引擎;符合技术与安全标准的 AI 助手也必须获准出现在选择屏上上。该提案目前进入公众咨询阶段,截止日期为 10 月 9 日,CMA 预计将在今年底前做出最终决定。
https://www.solidot.org/story?sid=85465
https://cyber.gc.ca/en/alerts-advisories/solarwinds-security-advisory-av26-950
A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22.
The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup work from start to finish, and the public version of the malware does not work as it is.
https://thehackernews.com/2026/09/windows-malware-is-built-to-let-up-to.html
Latest Blog Posts
- 1 month ago
- 3 months ago
- 3 months ago
- 3 months ago
- 3 months ago
- 7 months 3 weeks ago
- 1 year 1 month ago
- 1 year 1 month ago
- 1 year 2 months ago
- 1 year 6 months ago