Aggregator
North Korea's Lazarus Targets macOS Users via ClickFix
Users advised to drop passwords and make room for passkeys
In a decisive move that could reshape how users log in online, the National Cyber Security Centre (NCSC) is urging consumers to abandon passwords in favour of passkeys, positioning them as the future of authentication. “Passkeys should become consumers’ first choice for logging into digital services,” NCSC said. Overhauling decades of security guidance, the agency will no longer recommend passwords where passkeys are available, citing their weaker resistance to current cyber threats. Since most breaches … More →
The post Users advised to drop passwords and make room for passkeys appeared first on Help Net Security.
Прочитали GitHub - написали вирус. Первая эксплуатация SSRF в инструменте для запуска моделей
MiniMax 登上戛纳,AI 与艺术的全球和解开始了?
Void Dokkaebi Hackers Use Fake Job Interviews to Spread Malware via Code Repositories
A North Korea-linked hacking group known as Void Dokkaebi, also tracked as Famous Chollima, is running a campaign that tricks software developers into installing malware through fake job interviews. The group lures developers into cloning infected code repositories as part of a fabricated coding test, then turns their machines and projects into malware-spreading tools. The […]
The post Void Dokkaebi Hackers Use Fake Job Interviews to Spread Malware via Code Repositories appeared first on Cyber Security News.
网络安全信息与动态周报2026年第16期(4月13日-4月19日)
【漏洞通告】Apache ActiveMQ 远程代码执行漏洞(CVE-2026-40466)
【漏洞通告】FortiSandbox目录遍历漏洞(CVE-2026-39813)
【恶意文件通告】Xinference供应链投毒
Indirect prompt injection is taking hold in the wild
The open web is slowly but surely filling up with “traps” designed for LLM-powered AI agents. The technique, known as indirect prompt injection (IPI), involves hiding (more or less) covert instructions inside ordinary web pages, waiting for an AI agent to read them and carry out the author’s commands. The IPI attack kill chain (Source: Forcepoint) “Ignore previous instructions” In back-to-back reports published this week, Google and Forcepoint researchers laid out real-world evidence of these … More →
The post Indirect prompt injection is taking hold in the wild appeared first on Help Net Security.
INC
You must login to view this content
Ransom House
You must login to view this content