Aggregator
【安全圈】朝鲜黑客滥用 VS Code 自动运行任务部署 StoatWaffle 恶意软件
【安全圈】马自达通报安全事件:员工和合作伙伴数据遭泄露
Top 3 takeaways for security leaders
RSAC 2026 | Agent安全与AI SOC引领变革
利用codeQL自动化寻找反序列化链—myfaces反序列化
GitHub-hosted malware campaign uses split payload to evade detection
A large-scale malware delivery campaign has been targeting developers, gamers, and general users through fake tools hosted on GitHub, Netskope researchers have warned. These “lures” are highly polished and appear legitimate, occasionally mimicking real projects, thus making them difficult to distinguish from safe software. A dual-component trojan is delivered Netskope threat researchers first discovered a trojanized GitHub repository ostensibly offering a Docker image of the OpenClaw AI assistant. The repo was very convincing. “The README … More →
The post GitHub-hosted malware campaign uses split payload to evade detection appeared first on Help Net Security.
SecurityScorecard automates third-party risk management with TITAN AI
SecurityScorecard has introduced TITAN AI to automate third-party risk management, replacing manual processes with continuous, AI-driven intelligence. TITAN AI is built on top of SecurityScorecard’s Ratings and TPRM platform with AI-driven technology and enhanced threat intelligence, delivering a powerful solution built for the demands of today’s risk landscape. With TITAN AI, organizations will be able to automate the majority of the work traditionally required to manage vendor risk. TPRM, security, and risk teams will reclaim … More →
The post SecurityScorecard automates third-party risk management with TITAN AI appeared first on Help Net Security.
【重磅推荐】2026 年度 NVIDIA 创业企业展示现已启动招募!
【北京站】 4 月 23 日 北京站将深度解析 GTC2026 精彩内容和发布,聚焦物理AI、AI智能体、大语言模型应用等领域,探索 AI 的下一个篇章。参与形式包括:路演、展示、大企业和技术对接等。
【成都站】 5 月 15 日 成都站为 AI 应用和出海专场,NVIDIA 专家及行业嘉宾将带来 AI 出海、物理 AI、AI 智能体、AI 落地应用等精彩内容分享。
【上海站】 5 月 21 日 上海站将聚焦 AI 智能体、物理AI、大语言模型应用等领域,探索 AI 的应用场景。参与形式包括:路演、展示、大企业和技术对接等。
【澳门站】 5 月 26-30 日 澳门站为境外专场,结合澳门BEYOND 国际科技创新博览会,聚焦AI智能体、物理AI、企业出海等前沿技术领域和方向,涵盖#GTC26 技术精华解读、项目路演、圆桌讨论、投融资与需求对接等环节。报名企业将有机会获得免费BEYONDEXPO 展位。
诚邀您莅临现场,共同交流与探讨!报名可扫描下方二维码:
Lumu enhances Defender to detect compromise across network, cloud, endpoint, and identity
Lumu has upgraded its Lumu Defender NDR solution, extending Continuous Compromise Assessment beyond the network to include endpoints, cloud environments, and user behavior for unified visibility. The past year marks a strategic shift in attack methods, with threat actors pivoting from high-profile malware to increasingly sophisticated, stealth-based tactics. The increase of AI-driven security attacks, attackers using legitimate tools instead of malware, and attackers quietly using cloud applications for exfiltration, creates more opportunities for criminals to … More →
The post Lumu enhances Defender to detect compromise across network, cloud, endpoint, and identity appeared first on Help Net Security.
TeamPCP Hacks Checkmarx GitHub Actions Using Stolen CI Credentials
网络安全AI智能体在金融业落地挑战与实践探索
Tuskira replaces centralized detection model with real-time, distributed approach
Tuskira has released its Federated Detection Engine, a new capability within its Agentic SecOps platform that enables real-time threat detection across cloud, identity, endpoint, network, SaaS, infrastructure, and legacy SIEM environments, without relying on centralized logging. Detection engineering still depends on centralized log architectures and manual rule authoring. That model is expensive to scale, slow to adapt, and increasingly misaligned with how modern attacks move across distributed environments. Tuskira takes a different approach by bringing … More →
The post Tuskira replaces centralized detection model with real-time, distributed approach appeared first on Help Net Security.
Russian Initial Access Broker Handed 81-Month Sentence
Firefox 149 释出
Ваш сервер заговорил по-турецки и шлет эмодзи – первые признаки того, что все данные уже украли
AI 促使源码进化还是导致它灭绝?
Canada-Based Organization Health Shared Services Accelerates SOC Investigations with ANY.RUN
ANY.RUN spoke with the Interim CISO and Director of Cyber Operations at Health Shared Services, who provided insights into how their team addressed alert fatigue, improved MTTD and MTTR, and strengthened their investigation workflow with ANY.RUN. In this new addition to our success story series, we explore how the healthcare organization’s SOC team improved detection, triage, and response efficiency while maintaining the existing operational processes. Organization Overview Health Shared Services is a healthcare support organization based in Alberta, Canada. Its SOC team consists of 16 […]
The post Canada-Based Organization Health Shared Services Accelerates SOC Investigations with ANY.RUN appeared first on ANY.RUN's Cybersecurity Blog.