Posts of last few hours
Please support the site operations by clicking ads.
Google 因地理位置数据处理被爱尔兰数据保护委员会(DPC)罚款 4.03 亿欧元。DPC 对 Google 的调查持续了六年,涉及 Google 在 2018 年 5 月 25 日至 2020 年 2 月 4 日间 Web & App Activity、Location History 和 Location Accuracy 三项功能的位置数据处理。DPC 的报告认为 Google 的位置数据处理违反了 2018 年生效的数据保护法律 GDPR,可能导致用户未意识到自己的位置信息正被用于投放定向广告或推断其兴趣偏好,丧失对自己个人数据的控制权。Google 发表声明,表示它从 2019 年起就调整了位置数据管理。引入了位置数据自动删除功能。
https://www.solidot.org/story?sid=85447
After the exit of around 1,000 CISA workers, legislation from three top House Democrats orders a force structure assessment like that more common to military branches.
The post Dems seek top-to-bottom assessment of CISA workforce appeared first on CyberScoop.
https://cyberscoop.com/house-democrats-cisa-force-structure-assessment-act/
A forum actor posting as RedStone is offering what they claim is the full database of the Fédération Française de Spéléologie (FFS), France's national caving federation.
https://darkwebinformer.com/federation-francaise-de-speleologie-dataset-claim-covers-93-493-members/
Ireland's Data Protection Commission (DPC) has fined Google €403 million ($463M) for multiple GDPR violations related to processing users' location data. [...]
https://www.bleepingcomputer.com/news/security/google-fined-403-million-over-location-data-privacy-violations/
Belgium’s national table tennis federation is investigating a cyberattack after a hacker claimed to have stolen data on tens of thousands of members.
https://therecord.media/belgium-table-tennis-cyberattack
https://cyber.gc.ca/en/alerts-advisories/exim-security-advisory-av26-944
The AI giant disclosed six examples of concerning model activity and published a new framework for investigating and disclosing such incidents.
https://www.darkreading.com/cyber-risk/rogue-behavior-openai-more-model-misalignment-incidents
Microsoft has fixed a known issue that causes copy-and-paste failures for Excel users after installing the September 2026 security updates. [...]
https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-broken-excel-copy-and-paste-for-all-office-users/
https://cyber.gc.ca/en/alerts-advisories/ibm-security-advisory-av26-943
深度集成 Gemini、运行 Android 的笔记本电脑 Googlebooks 将于 10 月 4 日上市。Google 硬件合作伙伴中除了宏碁推出一款起售价 899 美元的型号外,其余厂商的产品都超过 1000 美元。Googlebook 不同于 Chromebook 面向低端市场,它面向的是中端笔记本电脑市场。Googlebooks 的 Continue On 功能允许用户在手机或 Googlebook 之间无缝切换,但需要应用开发者支持;Cast My Apps 可以直接在 Googlebook 上使用 Android 手机已安装应用;Play Store 是 Googlebook 获取应用的主要渠道,侧载受到了限制,只能安装运行已通过 Google 验证身份的开发者的应用;通过深度集成 Gemini Intelligence,用户仅仅移动光标就能激活被称为“Magic Pointer”的 AI 功能,AI 会分析屏幕上的内容,根据上下文提供建议,能从多个应用中提取数据。比如将光标指向电邮中的日期即可创建日历预约。
https://www.solidot.org/story?sid=85446
A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week.
The trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming back, exposed systems, weak checks, fake fixes, and attack paths that look almost too easy. Even the research side is getting messy, with more findings, more automation, and not
https://thehackernews.com/2026/09/weekly-recap-cisco-0-day-ai-agent-rce.html
Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts.
The backdoor "automatically harvests and exfiltrates business documents, watches the filesystem for new files in real time, steals Wi-Fi passwords and clipboard contents, takes screenshots, and accepts arbitrary
https://thehackernews.com/2026/09/taskstomp-powershell-backdoor-steals.html
The FBI's CJIS Security Policy v6.1 strengthens requirements around encryption and vulnerability scanning while continuing the shift toward more continuous security assessment. Specops explains what changed and how agencies can address password, MFA, and identity requirements as they prepare for upcoming audits. [...]
https://www.bleepingcomputer.com/news/security/fbis-cjis-v61-what-security-teams-need-to-know/
The university, commonly known as LMU Munich, said Saturday that an attacker accessed enrollment data stored on one of its IT systems.
https://therecord.media/cyberattack-hits-university-of-munich-potentially-exposing-data
The ShinyHunters extortion group hijacked the dark web leak site of the prolific Cl0p ransomware gang, according to material posted on the site over the weekend.
https://therecord.media/shinyhunters-clop-cyberattack-website
https://mp.weixin.qq.com/s?__biz=MzI0NjU2NDMwNQ==&mid=2247509282&idx=2&sn=83d8f4f7b68a0b108b8c64a7c0e5a285
https://mp.weixin.qq.com/s?__biz=MzI0NjU2NDMwNQ==&mid=2247509282&idx=1&sn=21b2504a5e3f213c955e4c9e374867b6
Saturn 的一项研究显示,ChatGPT、Claude、Copilot、Grok 和 Gemini 等主流 AI 模型在回答财务相关问题时,平均有 57% 会给出错误答案。研究使用了逾百个财务相关问题,分别测试了 ChatGPT、Gemini、Claude 和 Copilot 提供的免费及付费 AI 模型。每个问题最多重复提问五次,向 18 种 AI 模型共提出了逾 10,000 个问题。研究发现,AI 模型的回答中包含计算错误、遗漏即将实施的税收政策变更,或是凭空捏造规则(即幻觉)。在最严重的情况下,依赖 AI 对税务问题的回答可能导致严重的经济损失。研究发现,付费模型的回答比免费模型更准确,较新的模型表现优于较旧的模型。表现最好的是推理模式的 Claude Opus 5,但仍然有 39% 的答案存在错误。
https://www.solidot.org/story?sid=85445
Blackpoint uncovers ChainScript, a Node.js RAT that queries a Polygon smart contract to find and rotate its command server. Blackpoint’s Adversary Pursuit Group was chasing a ClickFix campaign spreading an unknown RAT namend ChainScript. The malicious code is a previously undocumented Node.js remote access trojan that hides its command server on a public blockchain. The […]
https://securityaffairs.com/199471/malware/chainscript-the-rat-that-hides-its-command-server-inside-a-blockchain-contract.html
Latest Blog Posts
- 4 weeks 2 days ago
- 3 months ago
- 3 months ago
- 3 months ago
- 3 months ago
- 7 months 3 weeks ago
- 1 year 1 month ago
- 1 year 1 month ago
- 1 year 2 months ago
- 1 year 6 months ago