因缺少 MTE 安全功能,GrapheneOS 当前阶段放弃适配谷歌 Pixel 11 系列手机
IT之家 8 月 30 日消息,GrapheneOS(石墨烯 OS)开发团队今天在 X 平台宣布,由于谷歌 Pixel 11 系列手机缺少 MTE(Arm 内存标记扩展)安全功能,他们当前不得不放弃 Pixel 11 的 GrapheneOS 适配工作。 官方表示,他们经过一周的工作后完成了 Pix…
IT之家 8 月 30 日消息,GrapheneOS(石墨烯 OS)开发团队今天在 X 平台宣布,由于谷歌 Pixel 11 系列手机缺少 MTE(Arm 内存标记扩展)安全功能,他们当前不得不放弃 Pixel 11 的 GrapheneOS 适配工作。 官方表示,他们经过一周的工作后完成了 Pix…
IT之家 8 月 29 日消息,开发者 Sebastien Guillemot 本周三在 X 上反馈称,他在测试 AI 智能体的文件删除防护机制时遭遇严重事故,Claude 直接给他删除了大约 700GB 数据,包括整个用户主目录,相当于一周的工作成果。 据称,事故发生前,Anthropic 的安全…
IT之家 8 月 27 日消息,安全公司 Socket 发文,曝光了 77 款 Firefox 火狐浏览器恶意插件,这些插件均带有雷同代码,预计是同一批黑客所为。 Socket 进一步调查发现,这批恶意插件中有 40 款可窃取用户设备上各类凭据信息,其中 13 款可篡改受害者设备上加密货币钱包代码、…
IT之家 8 月 27 日消息,OpenAI 当地时间周三发布了关于 Hugging Face 遭入侵事件的 官方报告 ,首次较为完整地还原了这起事件的经过:一系列罕见因素叠加,导致一款 AI 模型突破测试环境限制,最终引发了一场波及范围广泛的网络安全事件。 IT之家注意到,这份报告距离事件首次曝光…
破解加密推理闭环,看研究团队如何窥探AI私有思考,安全边界再受拷问
In August 2026, a team at MATS Research, the ELLIS Institute Tübingen, and the Max Planck Institute for Intelligent Systems wanted to test whethe…
警惕!假冒R星的GTA6演示网站实为恶意软件陷阱,玩家下载即中招。
Grand Theft Auto fans, eager for news about one of the most anticipated video games of all time, appear especially vulnerable to this new cyberattack.
用证据门控从结构上杜绝漏洞幻觉的AI渗透测试智能体,全离线运行,安全报告终于不是AI编的故事了
If you point any LLM at a target and ask it to "write a security report," it will confidently invent findings that aren't there: an imagined TLS weakn…
AI生成代码的安全执行利器,AOT沙箱为JavaScript提供高性能隔离防护。
Article URL: https://github.com/ErosZy/sablejs Comments URL: https://news.ycombinator.com/item?id=49433953 Points: 3 # Comments: 0
开源CLI工具,一键对LLM发起15种提示注入攻击,快速检验模型安全防线。
Article URL: https://github.com/Ventrova/sentinel-scan-cli Comments URL: https://news.ycombinator.com/item?id=49431289 Points: 1 # Comments: 0
OpenAI披露封禁俄方AI水军,揭露利用大模型伪装智库操纵舆论的新手段。
OpenAI banned Russia-origin accounts using AI to promote a fake Israel-based think tank and a “sovereignty” index praising Russia and criticizing the …
Fitbit创始人打造的LTE健康安全手环,实时监测家人状态,紧急求助一键直达,是家庭照护的智能卫士。
Luffu Link combines all day health sensing, voice logging, location awareness, and the ability to get help from trusted contacts into a single device,…
Google官方AI工具被挖出SSRF漏洞,八天修复并获CVE,披露过程值得一看。
Earlier this year I found a server-side request forgery bug in Google's MCP Toolbox, the official server Google publishes for connecting language-mode…
MoE大模型的安全防线可能只藏在少数专家里,RASET框架专攻这一漏洞并揭示其风险。
arXiv:2605.29708v2 Announce Type: replace Abstract: Mixture-of-Experts (MoE) LLMs rely on sparse, router-driven expert activation, yet how safety alig…
大模型如何精准“遗忘”敏感数据又不伤能力?这项自校准对齐方案给出新思路。
arXiv:2602.02824v2 Announce Type: replace Abstract: LLM unlearning aims to remove the influence of undesirable knowledge from pretrained language mode…
首个聚焦音视频大模型安全性的基准,曝光跨模态越狱漏洞,为多模态安全研究提供关键测试标准。
arXiv:2508.07173v3 Announce Type: replace Abstract: Omni-modal Large Language Models (OLLMs) that integrate visual, auditory, and textual processing f…
不只是拒绝请求,更是防住有害动作:这项研究揭示安全训练在智能体环境中能否真正“扛住”优化冲刷。
arXiv:2603.02229v2 Announce Type: replace Abstract: Safety post-training has been studied extensively in single-step "chat" settings where safety typi…
十四种后处理都扛不住20条样本复学攻击?这项研究用边界校准让LLM遗忘跨过悬崖、真正稳固。
arXiv:2607.27836v2 Announce Type: replace Abstract: Large language model unlearning is consistently fragile under relearn attacks. On TOFU, fine-tunin…
大模型写代码常“编造”不存在依赖包?这篇论文系统评估了推理时防御手段,帮你避开代码幻觉坑。
arXiv:2608.22652v1 Announce Type: cross Abstract: LLMs are increasingly used for code generation, yet they frequently hallucinate non-existent softwar…
揭秘大模型智能体如何通过工具实现“遗忘”,为安全与能力平衡提供新思路。
arXiv:2608.21544v1 Announce Type: cross Abstract: Large language models (LLMs) are increasingly deployed as tool-augmented agents, where responses can…