Show HN: Echidra – open-source deception platform for attacker behavior
开源多协议蜜罐平台,诱捕SSH、HTTP、FTP攻击并自动分类行为,安全研究利器。
Article URL: https://github.com/Qyleron/EchidraOSS Comments URL: https://news.ycombinator.com/item?id=49349397 Points: 2 # Comments: 0
开源多协议蜜罐平台,诱捕SSH、HTTP、FTP攻击并自动分类行为,安全研究利器。
Article URL: https://github.com/Qyleron/EchidraOSS Comments URL: https://news.ycombinator.com/item?id=49349397 Points: 2 # Comments: 0
小心!AI 开源网关 LiteLLM 被投毒,40 分钟窃取英伟达等 2500 家企业 195TB 凭据,供应链安全警钟长鸣。
IT之家 8 月 13 日消息,科技媒体 Ars Technica 今天(8 月 13 日)发布博文,报道称今年 3 月爆发的 API 网关 LiteLLM 投毒事件中, 在约 40 分钟的攻击窗口内波及全球约 2500 家企业,导致约 195TB 的密码数据泄露。 IT之家曾于今年 3 月报道, …
开源工具Aileaks可扫描代码仓库,揪出泄露的LLM推理轨迹与敏感秘密。
Article URL: https://github.com/sarthakuwar/aileaks Comments URL: https://news.ycombinator.com/item?id=49271711 Points: 3 # Comments: 1
无需注册,秒级扫描任何公开GitHub仓库的安全漏洞,适用于遗留代码、外包项目或求职者作业审查。
TL;DR You can now paste any public GitHub repo URL and get a security grade back in seconds, no signup. It runs static analysis, secret detection, and…
私密聊天利器!端到端加密保障隐私,开源可审,有效对抗Chat Control消息扫描。
Article URL: https://www.heise.de/en/news/Chat-Control-1-0-EU-Council-forces-messenger-scans-via-fast-track-11353659.html Comments URL: https://news.y…
AI Agent两大明星框架被曝441处递归执行漏洞,安全风险不容忽视。
I just opened 3 security issues on two of the most popular AI agent frameworks on GitHub (combined 110K+ stars). The Issues microsoft/autogen#7917 : D…
Linux 基金会联手科技巨头推出 Akrites 项目,专门防御由 AI 引发的开源软件漏洞攻击,开源安全迎来新防线。
IT之家 6 月 26 日消息,据科技媒体 Phoronix 昨天报道,Linux 基金会现已与亚马逊、Anthropic、OpenAI、英伟达和红帽等多家企业达成合作,共同推出 Akrites 项目。 IT之家从原报道获悉, Akrites 旨在保护开源软件 , 防范基于 AI 与大语言模型的漏洞…
OpenAI联手安全公司启动新计划,用AI技术帮开源项目找补漏洞,警惕Log4j式危机重演
OpenAI is attempting to tackle the security issues of the open source software community.
OpenAI推出开源漏洞修复计划,用AI+专家审查助力维护者快速修复安全问题。
OpenAI introduces Patch the Planet, a Daybreak initiative helping open-source maintainers find, validate, and fix vulnerabilities with AI and expert r…
揭露攻击者如何利用AI幻觉诱骗开发者安装恶意npm包,防不胜防。
You should read this before you install any #npm package. Because the author mentioned the taking advantage of the #AI #hallucinations but forgot that…
全面评估开源安全防护模型的性能与局限,为AI安全部署提供关键参照。
arXiv:2605.28830v1 Announce Type: cross Abstract: As Large Language Models (LLMs) are increasingly deployed in safety-critical applications, robust co…
AI抓虫效率惊人,Anthropic一个月发现超1万个高危漏洞,误报率甚至优于人工。
IT之家 5 月 23 日消息,Anthropic 昨日(5 月 22 日)发布公告,披露称 Project Glasswing 项目上线 1 个月后,携手约 50 家合作伙伴, 已在关键软件中挖掘出超过 1 万个高危(High)和关键(Critical)级别漏洞。 根据 Project Glass…
黑客通过VSCode扩展投毒开源代码,GitHub遭供应链攻击,规模史无前例。
GitHub is just the latest victim of TeamPCP, a gang that has carried out a spree of software supply chain attacks.
揭露黑客大规模污染开源代码,通过VSCode扩展攻击GitHub,供应链安全告急。
GitHub is just the latest victim of TeamPCP, a gang that has carried out a spree of software supply chain attacks that has impacted hundreds of organi…
可视化开源CVE趋势,揭示软件供应链安全恶化现状,简洁有力
I was curious what it would look like if I plotted the intensity and volume of software supply chain CVEs over time, given what seemed like a flood of…
数十个流行开源软件包遭供应链攻击,黑客持续投毒,开发者需警惕依赖风险
The attacks are part of a wider campaign known as Mini Shai-Hulud, which has already compromised several open source projects and, in turn, developers…
用Git的–author标志轻松拦截AI机器人,保护开源项目免遭垃圾评论污染。
Article URL: https://archestra.ai/blog/only-responsible-ai Comments URL: https://news.ycombinator.com/item?id=48181125 Points: 106 # Comments: 35