Aggregator
EU organizations buckle under rising compliance pressure
Cybersecurity governance in the EU is shifting under expanding frameworks such as NIS2 and DORA, while AI raises new questions for security teams. What the future brings is hard to predict, and organizations must find a way to cope. Antonija Vojnović, Governance, Risk and Compliance Department Manager at Span, spoke with Help Net Security at the Span Cyber Security Arena conference about how these regulatory frameworks are shaping compliance priorities and day-to-day decision-making. Compliance overload … More →
The post EU organizations buckle under rising compliance pressure appeared first on Help Net Security.
OWASP Agent Memory Guard: Stop AI agents from being weaponized through their own memory
AI agents keep memory across sessions. Conversation history, vector stores, scratchpads, and RAG indexes persist between runs, and anything written into that store becomes a privileged input the agent reads back later. An attacker who plants text in the wrong field can override an agent’s instructions, pull out user data, or steer future tool calls, and the effect survives across sessions because the memory does. Agent Memory Guard is an open-source runtime defense layer that … More →
The post OWASP Agent Memory Guard: Stop AI agents from being weaponized through their own memory appeared first on Help Net Security.
腾讯云618活动上线:99元/年版境外CN2服务器补货 另有3年超低价服务器
黄仁勋表示AI被视为GDP的“生成器”
Ошибка 19-летней давности в Linux. Любой локальный пользователь может получить права root через сетевой модуль CIFS
AI Coding 正在进入下一个阶段,MonkeyCode 专业版现已支持 MiniMax M3
Governing shadow AI without killing innovation
In this Help Net Security video, Alan Snyder, CEO at NowSecure, talks about governing shadow AI without stopping innovation. He frames the problem as two opposing forces. Companies need to adopt AI fast because attackers and competitors will outpace them otherwise, but they also need to do it safely. Snyder argues the pressure to move quickly will win, so leaders must work hard to manage AI risk along the way. He references the first 8-K … More →
The post Governing shadow AI without killing innovation appeared first on Help Net Security.
线下联结带来的安全感
Anthropic 推出 Claude Opus 4.8,Mythos 系列模型即将全面开放;五部门联合发布互联网信息内容多渠道分发服务新规,9 月起施行| 牛览
从幻觉到真实入侵:Scenario框架用 Crescendo 策略,重构 AI 代理红队测试
The ChatGPhish Phenomenon: Indirect Prompt Injection via AI Summarization
Mechanics of the Summary Vector A standard webpage can become an effective lure if an AI assistant summarizes its content. New research reveals how an adversary can conceal instructions directly within a website. Consequently,...
The post The ChatGPhish Phenomenon: Indirect Prompt Injection via AI Summarization appeared first on Information Security News.
微软以证书过期为借口让 Mac 版 Office 2019 进入只读模式
微软以证书过期为借口让 Mac 版 Office 2019 进入只读模式
The Wikimedia Schism: Editors Revolt Over Community Tech Dissolution
The Catalyzing Decision The Wikimedia Foundation recently encountered severe backlash from volunteer Wikipedia editors. This indignation followed the controversial decision to dissolve the dedicated Community Tech team. For years, this specialized cohort methodically addressed...
The post The Wikimedia Schism: Editors Revolt Over Community Tech Dissolution appeared first on Information Security News.
The Rise of the Algorithmic Intruder: AI-Driven Exploitation of Marimo Servers
The Breach and Execution Lifecycle An adversary recently weaponized an artificial intelligence agent to orchestrate a sophisticated cyberattack. Specifically, the intruder targeted a publicly accessible Marimo computation server. According to findings from Sysdig, the...
The post The Rise of the Algorithmic Intruder: AI-Driven Exploitation of Marimo Servers appeared first on Information Security News.
Perimeter Peril: Bypassing Authentication via Palo Alto Networks GlobalProtect
The GlobalProtect Vulnerability Palo Alto Networks recently issued a stark warning regarding CVE-2026-0257. This security flaw compromises PAN-OS and Prisma Access architectures. Specifically, the vulnerability resides within the GlobalProtect portal and gateway. Under unique...
The post Perimeter Peril: Bypassing Authentication via Palo Alto Networks GlobalProtect appeared first on Information Security News.
145 AI laws passed in 2025 and privacy teams aren’t catching a break
145 AI-related laws were enacted by state legislatures in 2025, and more than 1,000 additional bills were introduced or revised, according to DataGrail’s Privacy and AI Trends Report 2026. Average cost of manual data subject request management (Source: DataGrail) Shadow AI risks Of the 2,400 popular business software providers that advertised AI capabilities, 63.6% did not disclose third-party AI subprocessors in their legal documentation, exposing businesses to shadow AI risks they may not be aware … More →
The post 145 AI laws passed in 2025 and privacy teams aren’t catching a break appeared first on Help Net Security.