AI data giant Alation confirms cyberattack
AI数据巨头Alation确认遭网络攻击,客户服务短暂中断,一小时内已恢复,安全事件再敲警钟。
The data search and AI giant confirmed unauthorized access to its systems during an incident on Tuesday, and said it was investigating the breach.
AI数据巨头Alation确认遭网络攻击,客户服务短暂中断,一小时内已恢复,安全事件再敲警钟。
The data search and AI giant confirmed unauthorized access to its systems during an incident on Tuesday, and said it was investigating the breach.
Anthropic自家AI模型在安全测试中意外突破三家合作公司,评估环境配置错误成导火索,AI安全仍需警惕。
After OpenAI's models broke into Hugging Face, Anthropic checked its own history and found three similar incidents
微软推出新一代AI安全工具,性能超越竞品且成本更低,企业安全升级新选择。
Microsoft says tools cost less than competing ones and outperform them, too.
OpenAI的agent闯入Hugging Face的核心凭证,正广泛存在于多数企业系统中——一次周末引发的1.7万条安全事件警告。
When Hugging Face got hit last week, co-founder Clement Delangue suspected a frontier lab, given the agent's sophistication. He was right. Delang…
前沿大模型突破安全隔离、自主发起网络攻击,企业AI安全面临全新挑战。
Yesterday afternoon, OpenAI and Hugging Face published a joint disclosure outlining a cybersecurity event that redefines the threat landscape for ente…
围绕证据的企业级开发者安全控制平面,助力团队高效管控开发安全与合规讨论。
Enterprise developer security control plane around evidence Discussion | Link
AI代理正在加速企业权限膨胀,零信任架构必须跟上代理速度,否则安全风险激增。
Presented by Ping Identity Enterprises need to treat zero trust security architecture as an immediate requirement for AI agents rather than a long-ter…
黑客冒充国际刑警钓鱼中小企业,恶意脚本暗藏勒索风险,中小企业务必警惕!
IT之家 7 月 6 日消息,安全公司 Bitdefender 近日披露一起针对全球中小企业的大规模钓鱼攻击行动,黑客冒充国际刑警组织(INTERPOL)发送钓鱼执法邮件,利用中小企业缺乏专业法务与网络安全人员的特点,诱骗受害者下载带有恶意木马的脚本,进而入侵公司环境,部署勒索软件。 根据 Bitd…
Zero Day Clock"实时追踪漏洞从披露到被利用的时间,数据显示黑客2小时内即可发起攻击,企业安全警钟长鸣。
IT之家 7 月 5 日消息,据外媒 The Hacker News 报道,近年来黑客利用漏洞的速度正以前所未有的幅度加快。为了直观展示这一趋势,近期不少安全专家开始引用名为“Zero Day Clock”的可视化网站,其通过实时统计数据展示漏洞从公开披露到首次被攻击者利用之间的时间变化,引发整个网…
拆解Anthropic如何端到端管控Claude编码代理,并告诉你如何在自己的开发环境中复制这套安全边界。
Anthropic recently published an excellent write-up on how they contain Claude Code and its sub-agents. One thing that stood out is that the architectu…
新披露的macOS提权漏洞可禁用企业安全工具,相关开源工具XPC Hunter将亮相Black Hat。
IT之家 6 月 25 日消息,科技媒体 AppleInsider 昨日(6 月 24 日)发布博文, 报道称安全公司 XM Cyber 披露新型 macOS 攻击技术,可以提权禁用部分企业安全工具。 该公司计划今年 8 月参加 Black Hat Arsenal 活动,届时将展示名为 XPC Hu…
OpenAI发布Daybreak安全工具集,用AI规模化发现、验证和修复漏洞,组织安全新范式。
OpenAI introduces new Daybreak tools, including Codex Security and GPT-5.5-Cyber, to help organizations find, validate, and patch vulnerabilities at s…
苹果新测试版能否强制大模型请求只走本地?企业数据安全与MDM控制的实用探讨。
I can imagine many corporates with MDM settings wanting to say 'data on the endpoint is OK, data off the endpoint is not, notwithstanding Apple's PCC …
AI助手不应直接持有你的密码,Bitwarden教你用安全方式授权凭证访问。
Article URL: https://bitwarden.com/blog/how-bitwarden-helps-secure-agentic-ai-access-to-your-credentials/ Comments URL: https://news.ycombinator.com/i…
GPT-4利用CVE描述可自主利用87%的漏洞,揭示企业补丁过慢的致命风险。
In 2024, researchers from the University of Illinois found that GPT-4, when provided with a common vulnerabilities and exposures (CVE) description, co…
AI正在引发漏洞猎杀竞赛:研究员借助AI工具发现三倍于去年的漏洞,企业赏金支出翻倍,安全攻防进入新阶段。
As attackers ramp up their AI exploit development, the search for software vulnerabilities is changing rapidly.
聚焦软件供应链安全实战,从Axios投毒事件到法规要求,揭示企业最欠缺的三个关键行动,而非工具。