SECURITY NEWS
安全资讯
汇集先知社区、Seebug Paper、腾讯玄武实验室、The Hacker News、Krebs on Security 等国内外安全社区的最新文章,追踪漏洞情报与攻防研究。
今天10月7日 · 周三5 条
Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes(在新标签页打开)
Cybersecurity researchers have disclosed details of a "human-operated phishing platform" that impersonates advertising products for artificial intelligence (AI) chatbots like Google Gemini, Anthropic Claude, OpenAI ChatG…
Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan(在新标签页打开)
Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection. Threat actors ar…
Google's PageBreak AI Agent Finds 500 Flaws in Its Web Apps(在新标签页打开)
The situation illustrates a trend toward using AI and deterministic validation to identify flaws and exploitability, and provide a risk assessment.
IANS' Kakolowski: How AI Is Reshaping CISO Budgets & Security Teams(在新标签页打开)
In this video interview, Nick Kakolowski, senior director for CISO research at IANS, talks AI: budgets, ROI, and changes inside security teams.
'BigDiskBuster' Leaves Microsoft Defender Running While Blocking Updates(在新标签页打开)
Not quite an EDR-killer, but the proof-of-concept cyber technique creates a silent virus detection gap while service runs normally, no exploit required.
昨天10月6日 · 周二8 条
LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings(在新标签页打开)
A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There is no warning first, of the kind either program shows before…
Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies(在新标签页打开)
The Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful efforts to compromise Etherpad, a public note-taking tool, an…
Possible Vulnerability in Apple’s Automatic Reboot(在新标签页打开)
404Media is reporting (alternate link) that a cyber-weapons arms manufacturer is exploiting a vulnerability in iOS to bypass its automatic reboot security feature. This is the feature that automatically puts an iPhone in…
Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers(在新标签页打开)
In 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools and data. The protocol delivered. Thousands of developers built servers, and enterpri…
Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports(在新标签页打开)
Google has stopped accepting product vulnerability reports through its bug bounty program for its open-source software. The change, in effect since October 1, means researchers can no longer submit security flaws in the…
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products(在新标签页打开)
A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory. The attacker must alr…
FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach(在新标签页打开)
The U.S. Federal Bureau of Investigation (FBI) has removed an Accenture contractor for their alleged role in a ShinyHunters-breach that led to the theft of personal details of thousands of bureau employees. That's accord…
ClingSTUN Turns Vulnerable IoT Devices Into Proxy Nodes(在新标签页打开)
The Linux backdoor exploits 24 known flaws to compromise IoT devices and uses legitimate public STUN servers to obscure communications.
10月5日周一3 条
Chinese Hackers Impersonate US Officials for AI Cyber Espionage(在新标签页打开)
An emerging threat group known as TA419 established seemingly legitimate professional relationships with AI policy experts working for US think tanks, universities, and legal organizations.
Need for Speed: AI-Driven Attacks Are Changing Security Strategies(在新标签页打开)
AI-powered attacks are fast, relentless, and automated. How security teams can keep up is top of mind, according to the latest Dark Reading reader poll.
Another Historic Cipher Falls to AI(在新标签页打开)
This one is from 1809, written by Napoleon's nephew.
10月4日周日1 条
Weekly Update 524: Live From Copenhagen(在新标签页打开)
I'm in Denmark! Well, just, I'm now at Copenhagen airport ready to begin the long trek home, with the final event at GOTO now done and going just perfectly. This week, there are two ShinyHunters arrests in the news: Pepi…
10月3日周六3 条
Friday Squid Blogging: EU is Trying to Fight Unregulated Squid Fishing(在新标签页打开)
The EU is recommending import controls to combat unregulated squid fishing in the Southwest Atlantic. I'm not optimistic. As usual, you can also use this squid post to talk about the security stories in the news that I h…
RemoteThreat Bets Security Teams Need to Test What Happens After Defenses Fail(在新标签页打开)
The offensive cyber operations startup looks to evolve red teaming beyond traditional methods to simulate attackers' increasingly advanced capabilities.
Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response(在新标签页打开)
One company told customers to power down its data-protection platform during a nine-hour window, while the other remained mum on reported attacks prior to releasing a patch for its product.
10月2日周五2 条
Unidentified Flock Cameras in Florida(在新标签页打开)
St. Lucie County in Florida discovered (alt link) a dozen Flock cameras whose ownership it can't identify, and that the county government had not permitted. I am reminded of the decade-old story of StingRay cell phone su…
How American Political Campaigns Are Using AI—and What They’re Spending on the Tools(在新标签页打开)
This essay was written with Nathan E. Sanders, and originally appeared in The Guardian. New campaign finance disclosure data shines a light on which US political campaigns are using AI tools and how much they are spendin…
10月1日周四1 条
Connected Cars Are a Surveillance Platform(在新标签页打开)
Researchers at Northeastern University, in collaboration with Consumer Reports, evaluated how much modern cars spy in their drivers: The new Northeastern study shows, for the first time, data flowing among the vehicles…
9月30日周三1 条
I Want Better Reporting on AI Genie Behavior(在新标签页打开)
AI systems are regularly completing tasks in ways that their prompters don't want or intend. Some of them are disturbing, and some of them are dangerous. This is something I've been calling "genie behavior," because I th…
9月29日周二2 条
Using Device Linking to Eavesdrop on WhatsApp and Signal(在新标签页打开)
Modern messaging apps allow users to link their phone accounts to their computer desktop. Eavesdroppers are taking advantage of this capability: Apps such as WhatsApp Web and Signal Desktop allow people to use their acco…
从 ZCode Trust Folder Bypass 0day 漏洞看 Coding Agent 的 Trust Folder 安全问题(在新标签页打开)
算是一个 ZCode 都 0day,通过打开恶意的目录触发
9月28日周一5 条
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation(在新标签页打开)
Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the sus…
Weekly Update 523: Live From a Norwegian Fjord(在新标签页打开)
How's that view?! With NDC Oslo now done, it's a little bit of sightseeing before heading to Denmark for GOTO in Copenhagen for Scott's and my "Cyber-broken" talk. In the meantime, this week is mostly about the ShinyHunt…
迟到 9 + length 字节的检查:CVE-2026-88975,http4s Ember HTTP/2 帧校验为何形同虚设(在新标签页打开)
CVE-2026-88975(CVSS 3.1 7.5,CWE-400)是 http4s Ember HTTP/2 实现的未认证资源消耗漏洞:读循环在缓冲完整 9 + length 字节之前不做任何帧大小校验,对端可以在 9 字节帧头里声明一个接近 24 位上限的单帧长度,并持续发送接近 16 MiB、但仍不足额的负载,使当前未完成帧的累积缓冲 acc 驻留约 16 MiB——约为 16 KiB
编码斜杠击穿 Go 路由器:ServeMux 双视图解析与路径穿越(在新标签页打开)
Go 1.22 起 net/http.ServeMux 的路由匹配改用编码视图(EscapedPath)逐段比较,%2F 不再是段分隔符;匹配命中后通配捕获值按解码视图交付,.. 回退语义恢复。授权中间件按解码路径前缀放行,处理器拼接磁盘路径时越出前缀——同一请求在两份视图里各被信任一次。
多签、冷钱包为何仍被击穿?Bybit 与 Bitget 事件的分析(在新标签页打开)
多签、冷钱包
9月26日周六3 条
glibc 2.43 堆利用实战:tcache_key + safe-linking 双重防线下的 UAF 到 Getshell(在新标签页打开)
随机 tcache_key 拦截 double-free,safe-linking 隐藏链表指针,malloc/free hook 被连根移除。
ciscn决赛内核(在新标签页打开)
很基础的利用
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions(在新标签页打开)
A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in feder…
9月25日周五1 条
LLM 安全风险的三个入口:提示词注入、供应链、数据与模型投毒(在新标签页打开)
关于 LLM 风险入口的小总结
9月24日周四2 条
多源 LLM 智能体输入中分段级投毒的检测与定位(在新标签页打开)
作者:Xue Tan, Changhui Wang, Sanrui Yang, Hao Luan, Zhuyang Yu, Jin Wei, Ping Chen, Xiaoyan Sun†, Jun Dai 原文链接:https://arxiv.org/html/2609.14723v1 摘要 现代大语言模型(LLM)智能体越来越多地通过聚合外部数据分段来构造提示词(prompt),这些分段包括检...
Web Fuzz的艺术(在新标签页打开)
web fuzz的意义,以及我为什么要开发fastfuzz的初衷。
9月23日周三1 条
Weekly Update 522: Live From Oslo with Scott Helme(在新标签页打开)
Heads up: the first 7 mins is a bit quiet until we worked out the external mic was misbehaving - sorry! But get through that and have a listen to Scott's experiences with how Report URI is identifying malware-infected ma…
9月21日周一1 条
面向安全漏洞的自动化程序修复智能体的对抗性测试(在新标签页打开)
作者:Fares Trad, Simin Chen, Hung Viet Pham, Gias Uddin, Baishakhi Ray 原文链接:https://arxiv.org/pdf/2609.15963v1 摘要 基于大语言模型(LLM)的软件智能体被设计用于自动化程序修复(Automated Program Repair, APR)任务,这使得在不久的将来,APR 智能体有望在无需太多...
9月20日周日1 条
大模型中转站研究与测评报告(2026)(在新标签页打开)
作者:知道创宇积极防御实验室 前言 随着大语言模型在编码、Agent(智能体)等场景中的深入应用,开发者对多模型、低成本、开箱即用的模型 API 需求持续增长,大模型中转站逐渐成为连接开发者与模型服务的重要基础设施。中转站对外提供与主流模型 API 兼容的统一接口,将不同模型厂商的服务进行聚合,调用者通常只需修改模型名称即可完成切换。 与直接调用模型厂商官方 API 不同,开发者在使用中转站时,实...
9月17日周四2 条
当世界说谎:面向下游控制的潜在世界模型后门攻击(在新标签页打开)
作者:Roberto Riaño, Gorka Abad, Stjepan Picek, Aitor Urbieta 原文链接:https://arxiv.org/pdf/2609.15781 摘要 预训练世界模型——一种学习得到的模拟器,它将观测编码为潜在状态并预测该状态在动作作用下如何演化——正开始像如今的预训练编码器和语言模型那样,被作为现成的动力学骨干网络复用于控制任务。我们表明,这种复用...
Data Broker Radaris Loses Domains in Privacy Fight(在新标签页打开)
The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recent…
9月15日周二1 条
融合谱特征与激活聚类用于医疗影像模型后门检测:方法、实现与评估(在新标签页打开)
作者:Suresh Tamang 原文链接:https://arxiv.org/pdf/2609.14290v1 摘要 机器学习模型正越来越多地部署于医疗影像流程中,用于辅助诊断,而针对这些模型的训练期攻击已成为一个被明确点名的行业级关切:医疗行业指南将模型投毒与对抗攻击列为需要专门防御措施的威胁,而联邦政策则指示将扩展的人工智能漏洞检测工具提供给农村医院等关键基础设施运营方。谱特征分析(spec...
9月12日周六1 条
Weekly Update 521: Breach Perception v. Reality(在新标签页打开)
I think what really resonates with me this week is being able to completely turn the tables on perceptions around things like AI being the big bad hacking tool the news would have you believe. There's the stat I talk abo…
9月9日周三2 条
POLYFLOW:一种用于静态跨语言信息流分析的神经符号框架(在新标签页打开)
作者:Haoran Yang、Zhixuan Zhong、Jiawei Guo、Haipeng Cai 原文链接:https://arxiv.org/pdf/2608.29808v1 摘要 现代软件系统通常由多种相互交互的编程语言构建而成。这种构建方式导致了额外的、往往隐蔽的漏洞,这些漏洞深藏于因语言交互而产生的复杂信息流之中。现有的静态分析器受到不同语言异构语义的阻碍,而动态方法则受限于(可用和...
Microsoft Plugs Nearly 1,000 Security Holes(在新标签页打开)
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping…
9月7日周一1 条
Weekly Update 520: The Unscripted Edition(在新标签页打开)
I've started playing around with YouTube's "create video thumbnail", which hopefully will give me back a bit of time in my day (it used to be a manual job in Photoshop) and be a bit more interesting. And on that note, th…
9月4日周五1 条
UiAs:基于多模态无线信号的用户无关3D人脸反欺骗(在新标签页打开)
作者:Zhiwei Chen,Lebin Lyu,Yimo Zhang,Dingyu Zhong等 原文链接:https://arxiv.org/pdf/2608.29084v1 摘要 人脸认证已广泛应用于安全敏感的应用中,而日益逼真的3D欺骗攻击正构成越来越大的威胁。高保真3D面具可以再现人脸外观和几何结构,但无法复制活体组织的固有物理响应,而无线信号可以主动探测这些响应。然而,由无线信号捕获的...
9月2日周三3 条
SIR:面向计算机使用智能体的自我改进型红队测试(在新标签页打开)
作者:Chen Xiong, Zhiyuan He, Pin-Yu Chen, Stjepan Picek, Tsung-Yi Ho 原文链接:https://arxiv.org/html/2608.30207v1 摘要 计算机使用智能体(Computer Use Agents, CUA)是一类视觉语言模型,它们感知屏幕,并通过鼠标、键盘和终端在真实操作系统上执行操作,如今正被日益广泛地部署用来自...
FBI Probes Service Selling 153M+ Drivers Licenses(在新标签页打开)
A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose l…
Weekly Update 519: Breaches & Data Integrity(在新标签页打开)
It does feel like I've bitten off too much and am now chewing like crazy this week. The 3D printing talk with Elle in Oslo, the "normal" NDC infosec talk, the cyber-broken talk with Scott in Copenhagen and then those rat…
8月27日周四1 条
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia(在新标签页打开)
Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In…
8月26日周三1 条
A Cautionary Tale About Data Breach Claims, Verification and Carhartt(在新标签页打开)
You're not going to believe this, but turns out you can't always take criminals at their word. Actually, I'll walk that back a bit as it may not even be the cybercrime guys who got this wrong, but it all starts here: 🚨Cy…
8月24日周一1 条
Weekly Update 518: IoT Doorlock Nirvana with UniFi(在新标签页打开)
I genuinely think I've nailed the IoT door lock situation! Well, Ubiquiti has, but I think I've worked out how to put it all into a residential house and have it make sense. There are a few basic tenets:Main power (never…
8月14日周五1 条
Who’s Tracking You? Use This New Service to Find Out(在新标签页打开)
It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily pa…
8月12日周三1 条
Microsoft Plugs Nearly 400 Security Holes(在新标签页打开)
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others tha…
7月17日周五1 条
Xuanwu Atuin AI 在 CyberGym 上的表现:GLM-5.2 更新结果(在新标签页打开)
我们此前报道过,由 GLM-5.1 驱动的腾讯玄武 Atuin AI 在 CyberGym 上取得了 84.0% 的 pass@1,见文章链接。 现在我们使用 GLM‑5.2 重新评估了 Atuin AI。在相同的评估方法下,Atuin AI 达到了 84.8% 的 pass@1(1,278 / 1,507 个任务)。
2月28日周六1 条
幽灵依赖:Agentic Coding 范式下的新型供应链安全威胁(在新标签页打开)
Author: Tianchu Chen of Tencent Xuanwu Lab 0x00 简介随着 LLM(大语言模型)能力的跃升,AI 软件开发模式正从“人写代码,AI 补全”的 Copilot 模式,向“AI 主导决策,自动执行”的 Agentic Coding 模式演进。在 Agentic Coding 模式下,AI 不再仅仅是生成代码的辅助工具,而是转变成了能够自主规划任务、选择技术栈、操作文件系统甚至执行命令的智能体…
2月2日周一1 条
AI网络爬虫安全白皮书(在新标签页打开)
Author: Guancheng Li and Zheng Wang of Tencent Xuanwu Lab 本文是腾讯玄武实验室发布的《AI网络爬虫安全白皮书》。我们系统分析了 AI 时代服务端浏览器 / 爬虫在真实业务中的典型使用方式,以及由此带来的新的攻击面与风险。 在这篇白皮书中,我们结合多款实际产品的安全测试案例,梳理了完整的攻击链路,并提出以“静态攻击面收敛 + 动态行为隔离”为核心的纵深防御框架,同时给出了开源防护方…
1月6日周二1 条
ComfyUI-Manager 远程代码执行风险通告(在新标签页打开)
近期腾讯玄武实验室发现可视化 AI 工作流工具 ComfyUI 的官方扩展组件 ComfyUI-Manager 中存在一个高危漏洞(CVE-2025-67303)。利用该漏洞可在无需任何账号的情况下远程入侵安装 ComfyUI 的系统。玄武实验室在发现漏洞后向 ComfyUI 官方进行了报告,目前该漏洞已被修复。