The engineering team at software company Figma recently documented how they built AI agents to help their security team investigate alerts, search past incidents, check company systems, and even...
After a 10-week hiatus since the last batch of Spring ecosystem releases, there was a flurry of activity during the week of August 17th, 2026, highlighting first milestone releases of: Spring...
Anthropic将Claude Mythos 5模型集成至Claude Security企业工具,用于扫描代码漏洞并生成补丁,同时与网络安全公司合作,推出3500万美元基金支持开源软件修复。该模型此前仅限内部使用,现通过受控输出方式向企业开放,降低恶意使用风险,但开发者需注意开源代码的漏洞共享问题。
Security researchers at Wiz recently examined S3-compatible object storage services across six popular neoclouds, revealing significant security gaps compared to Amazon S3. While S3 has become the...
Cloudflare is introducing WriteGuard, now in private beta, to provide fine-grained security controls for MCP (Model Context Protocol) servers. It aims to make AI agents safer by controlling their...
Anthropic conducted an audit of 141006 evaluation runs after OpenAI's sandbox escape disclosure. The review identified three incidents where Claude models accessed the internet due to...
CSRF(跨站请求伪造)利用浏览器自动携带Cookie的特性,诱骗已登录用户向目标网站发送伪造请求。攻击者无需窃取Cookie,只需诱导用户访问恶意网站,浏览器便会自动附带用户的会话凭证。防御措施包括CSRF令牌、SameSite Cookie、Origin/Referer校验等。Spring Security通过CsrfFilter实现防护,开发者应确保GET请求只读,并采用多层防御策略。
Dropbox has integrated Model Context Protocol (MCP) with its internal knowledge platform, Dash, to surface security design context during AI assisted code reviews. The system retrieves threat...
Mate Security获3500万美元A轮融资,主张安全运营需AI原生架构而非仅给SIEM加LLM。其核心是安全上下文图,持续更新组织资产、用户和业务流程,帮助AI代理更准确判断警报。公司称客户含财富500强,收入自2025年Q3增长超500%,资金将用于扩展团队和产品。
JFrog Security Research revealed "PixelSmash," a vulnerability in the FFmpeg media framework, allowing for Remote Code Execution and Denial of Service attacks. Present for sixteen years, it...
The bottleneck in a mature SOC is rarely analyst triage; rather, it is the detection-engineering team's ability to keep the rule base aligned with a threat landscape that evolves faster than rules...
Google Cloud has published a new blueprint setting out how organisations should secure artificial intelligence workloads running on Google Kubernetes Engine, arguing that the shift from prototype...
GitLab has released version 19.2 of its DevSecOps platform, adding agentic automation aimed at the security and review work that has piled up as AI coding tools generate more code than developers...
Amazon Web Services has recently introduced AWS Continuum, a new integrated security platform to automate the discovery, enforcement, and remediation of security issues across codebases,...
AWS构建者中心上线一周年,功能不断扩展,包括沙盒环境和网络扫描功能。Security Hub新增网络扫描,支持AWS和Azure资源监控。Amazon SageMaker与Hugging Face集成,简化模型部署。EKS和ECS管理费用下调,Aurora DSQL CDC功能正式发布。AWS还推出Loom和Claude应用程序网关,增强安全性和管理能力。
InfoQ has opened enrollment for a five-week AI Security & Privacy Engineering cohort for senior engineers and architects in regulated industries, focused on applying security, privacy, threat...
In this episode, Alex Zenla (CTO/Co-founder, Edera) challenges the "laissez-faire" attitude toward modern infrastructure. She promotes "spite-driven development", building software to solve...
This virtual panel brings together AI security experts to examine the evolution of AI-driven threats, from prompt injection and data poisoning to agent abuse and AI-powered social engineering. The...
The Argo CD project released a v3.5 release candidate in June 2026. This version adds mutual TLS enforcement for internal components. It also includes Git commit signature verification for supply...
AWS Security Agent 在 re:Invent 2025 上推出新功能,包括按需渗透测试、代码审核和威胁建模,支持多种代码存储库,提供安全分析和风险识别,帮助开发者保障应用安全。新集成的 Kiro 能力包和 Claude Code 插件可直接在 IDE 中运行,简化安全审查和修复流程。
完成下面两步后,将自动完成登录并继续当前操作。