Aggregator
Rigged Game: How North Korea’s ScarCruft Group Infiltrated a Gaming Platform to Deploy BirdCall Spyware
The seemingly innocuous download of a mobile game could culminate in a smartphone being compromised by sophisticated spyware.
The post Rigged Game: How North Korea’s ScarCruft Group Infiltrated a Gaming Platform to Deploy BirdCall Spyware appeared first on Penetration Testing Tools.
Quasar Linux (QLNX) Emerges to Subvert the Global Software Supply Chain
The novel Linux implant, Quasar Linux, poses a formidable threat not merely to individual workstations but to the
The post Quasar Linux (QLNX) Emerges to Subvert the Global Software Supply Chain appeared first on Penetration Testing Tools.
The Invisible 4GB Update: Why Google Chrome is Secretly Loading Gemini Nano onto Your Hard Drive
A contentious debate has emerged surrounding Google Chrome following reports of the surreptitious deployment of a substantial AI
The post The Invisible 4GB Update: Why Google Chrome is Secretly Loading Gemini Nano onto Your Hard Drive appeared first on Penetration Testing Tools.
Submit #777668: FlowiseAI Flowise <= 3.0.12 Server-Side Request Forgery (CWE-918) [Accepted]
The Administrator’s Shadow: How Hackers Turned a Popular GitHub Utility into an Invisible C2 Backdoor
Adversaries no longer find it requisite to engineer sophisticated malware from its inception. Frequently, the appropriation of a
The post The Administrator’s Shadow: How Hackers Turned a Popular GitHub Utility into an Invisible C2 Backdoor appeared first on Penetration Testing Tools.
Submit #777662: FlowiseAI Flowise <= 3.0.12 Server-Side Request Forgery (CWE-918) [Accepted]
Submit #777661: FlowiseAI Flowise <= 3.0.12 Server-Side Request Forgery (CWE-918) [Accepted]
Submit #777660: FlowiseAI Flowise <= 3.0.12 OS Command Injection (CWE-78) [Duplicate]
Submit #777659: FlowiseAI Flowise <= 3.0.12 Exposure of Sensitive Information (CWE-200) [Accepted]
Submit #777658: FlowiseAI Flowise <= 3.0.12 Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) [Accepted]
Submit #777657: FlowiseAI Flowise <= 3.0.12 Authorization Bypass Through User-Controlled Key (CWE-639) [Accepted]
Submit #777656: FlowiseAI Flowise <= 3.0.12 Exposure of Sensitive Information (CWE-200) [Accepted]
ФБР тоже читает чаты. Как переписка в мессенджере стоила хакеру восьми лет свободы
日产汽车将在欧洲裁减九百名办公室员工
MCP:从诞生到行业标准,从繁荣到安全危机
Emergency Patch: Critical RCE Vulnerability in Apache HTTP Server 2.4.67 Threatens Millions of Systems
A critical vulnerability has been identified within the ubiquitous Apache web server, potentially facilitating the complete compromise of
The post Emergency Patch: Critical RCE Vulnerability in Apache HTTP Server 2.4.67 Threatens Millions of Systems appeared first on Penetration Testing Tools.
Careful adoption of agentic AI services
本文档由澳大利亚、美国、加拿大、新西兰及英国等多国国家级网络安全机构联合发布,旨在为政府、关键基础设施及行业企业提供智能体AI(Agentic AI)安全采用的权威指南。智能体AI基于大语言模型,具备自主推理、规划与执行能力,但其高度的自主性与复杂的系统架构显著扩大了攻击面,引入了权限滥用、目标错位、行为不可预测、结构耦合及问责困难等新型安全风险。
指南系统梳理了智能体AI在设计、开发、部署与运营全生命周期中的安全挑战,并提出分层防御最佳实践。核心建议包括:严格遵循最小权限与零信任原则,强化细粒度身份管理;实施纵深防御与环境隔离;完善输入验证、第三方组件审查与持续监控机制;在高风险流程中强制保留“人在回路”监督;并通过威胁建模、红队演练与动态评估提升系统韧性。文档强调,组织应将AI安全深度融入现有网络安全框架,仅将其用于低风险任务,采取渐进式部署策略,优先保障系统的可观测性、可逆性与风险可控性,在安全可控的前提下推进技术落地。