小红花·文摘
  • 首页
  • 广场
  • 排行榜🏆
  • 直播
  • FAQ
Dify.AI

An XML injection (improper output neutralization) vulnerability in the Qt XMLQDom comment, CDATA section, and processing-instruction serialization of the Qt Framework (QtXml module) has been...

Security advisory: CVE-2026-15037 - XML injection vulnerability in QDom comment, CDATA and processing-instruction serialization

Qt Blog
Qt Blog · 2026-07-23T12:27:55Z

The bottleneck in a mature SOC is rarely analyst triage; rather, it is the detection-engineering team's ability to keep the rule base aligned with a threat landscape that evolves faster than rules...

Article: Multi-Agent AI for Production Security Operations: An A2A and MCP Architecture in a 5G Core

InfoQ
InfoQ · 2026-07-23T09:00:00Z

Google Cloud has published a new blueprint setting out how organisations should secure artificial intelligence workloads running on Google Kubernetes Engine, arguing that the shift from prototype...

GKE Security Blueprint Joins Growing List of Cloud AI Frameworks

InfoQ
InfoQ · 2026-07-22T08:00:00Z
Google launches a cheaper alternative to large AI security models like Mythos

Google is launching Gemini 3.6 Flash alongside a new security model dedicated to quickly finding and patching security vulnerabilities. In a blog post on Tuesday, Google describes Gemini 3.5 Flash...

Google launches a cheaper alternative to large AI security models like Mythos

The Verge
The Verge · 2026-07-21T15:00:00Z

An out-of-bounds read (buffer over-read) vulnerability in the QTextCodec::codecForName() function of the Qt 5 Core Compatibility APIs (the Qt5Compat module) has been discovered and has been...

Security advisory: Out-of-bounds read vulnerability in QTextCodec::codecForName() in Qt

Qt Blog
Qt Blog · 2026-07-21T12:31:54Z

GitLab has released version 19.2 of its DevSecOps platform, adding agentic automation aimed at the security and review work that has piled up as AI coding tools generate more code than developers...

GitLab 19.2 Puts AI Agents to Work on the Security Backlog

InfoQ
InfoQ · 2026-07-21T08:00:00Z
OpenAI and Hugging Face partner to address security incident during model evaluation

OpenAI and Hugging Face share early findings from a security incident during AI model evaluation, highlighting advanced cyber capabilities and lessons for defenders.

OpenAI and Hugging Face partner to address security incident during model evaluation

OpenAI
OpenAI · 2026-07-21T07:00:00Z
Monday, July 27, 2026 Security Releases

Monday, July 27, 2026 Security Releases

Node.js Blog
Node.js Blog · 2026-07-21T03:00:00Z
July 2026 Security Release

The July 2026 security release for Next.js is now available

July 2026 Security Release

Next.js Blog
Next.js Blog · 2026-07-20T12:00:00Z
AI didn’t replace our security team — it multiplied it.

For years, the assumption in security has been straightforward: mature detection and response programs require a Security Operations Center (SOC). The post AI didn’t replace our security team — it...

AI didn’t replace our security team — it multiplied it.

The New Stack
The New Stack · 2026-07-18T16:00:00Z

Amazon Web Services has recently introduced AWS Continuum, a new integrated security platform to automate the discovery, enforcement, and remediation of security issues across codebases,...

AWS Continuum to Enable Agentic Code Security for Enterprises

InfoQ
InfoQ · 2026-07-16T19:00:00Z
AWS 一周综述:AWS 构建者中心上线一周年、Security Hub 网络扫描功能、适用于 AWS 的 Loom 等(2026 年 7 月 13 日)

AWS构建者中心上线一周年,功能不断扩展,包括沙盒环境和网络扫描功能。Security Hub新增网络扫描,支持AWS和Azure资源监控。Amazon SageMaker与Hugging Face集成,简化模型部署。EKS和ECS管理费用下调,Aurora DSQL CDC功能正式发布。AWS还推出Loom和Claude应用程序网关,增强安全性和管理能力。

AWS 一周综述:AWS 构建者中心上线一周年、Security Hub 网络扫描功能、适用于 AWS 的 Loom 等(2026 年 7 月 13 日)

亚马逊AWS官方博客
亚马逊AWS官方博客 · 2026-07-13T10:07:14Z

Anthropic’s Claude Mythos has put mainframe security teams on notice. As a frontier AI model capable of autonomously identifying and chaining vulnerabilities at machine speed, Mythos represents a...

Don’t Let “Inherent Mainframe Security” Make You Complacent About Mythos

BMC Software | Blogs
BMC Software | Blogs · 2026-07-10T11:06:52Z

InfoQ has opened enrollment for a five-week AI Security & Privacy Engineering cohort for senior engineers and architects in regulated industries, focused on applying security, privacy, threat...

InfoQ Opens AI Security & Privacy Engineering Cohort for Regulated Industries

InfoQ
InfoQ · 2026-07-06T12:00:00Z

In this episode, Alex Zenla (CTO/Co-founder, Edera) challenges the "laissez-faire" attitude toward modern infrastructure. She promotes "spite-driven development", building software to solve...

Podcast: Spite-Driven Engineering: A New Blueprint for Cloud Security in the AI Native Era

InfoQ
InfoQ · 2026-07-06T11:00:00Z

This virtual panel brings together AI security experts to examine the evolution of AI-driven threats, from prompt injection and data poisoning to agent abuse and AI-powered social engineering. The...

Article: Virtual panel: Security in the Machine Age: Expert Insights on AI Threat Evolution

InfoQ
InfoQ · 2026-06-29T11:00:00Z

The Argo CD project released a v3.5 release candidate in June 2026. This version adds mutual TLS enforcement for internal components. It also includes Git commit signature verification for supply...

Argo CD 3.5 Tightens Supply Chain Security with Internal mTLS and Source Integrity

InfoQ
InfoQ · 2026-06-26T12:00:00Z
AWS Security Agent 增加威胁建模、Kiro 能力包、Claude Code 插件及更多功能

AWS Security Agent 在 re:Invent 2025 上推出新功能,包括按需渗透测试、代码审核和威胁建模,支持多种代码存储库,提供安全分析和风险识别,帮助开发者保障应用安全。新集成的 Kiro 能力包和 Claude Code 插件可直接在 IDE 中运行,简化安全审查和修复流程。

AWS Security Agent 增加威胁建模、Kiro 能力包、Claude Code 插件及更多功能

亚马逊AWS官方博客
亚马逊AWS官方博客 · 2026-06-26T07:28:10Z
如何通过与UnderDefense合作迁移到Elastic Security,帮助一家数字安全软件公司将安全事件减少85%

一家数字安全软件公司与UnderDefense合作,将其安全系统从传统的QRadar迁移到Elastic Security,成功减少了85%的安全事件,响应时间缩短了61%。迁移过程中进行了全面的日志审计和定制检测规则的建立,提升了安全监控的效率和合规性,使安全团队能够主动进行威胁狩猎。

如何通过与UnderDefense合作迁移到Elastic Security,帮助一家数字安全软件公司将安全事件减少85%

Elastic Blog - Elasticsearch, Kibana, and ELK Stack
Elastic Blog - Elasticsearch, Kibana, and ELK Stack · 2026-06-24T00:00:00Z

In a new Windows Developer Blog post titled "Windows platform security for AI agents", Microsoft positions Windows as the trustworthy operating system for autonomous agents and introduces the...

Windows Platform Security and the Race to Secure AI Agents

InfoQ
InfoQ · 2026-06-19T08:00:00Z
  • <<
  • <
  • 1 (current)
  • 2
  • 3
  • >
  • >>
👤 个人中心
在公众号发送验证码完成验证
登录验证
在本设备完成一次验证即可继续使用

完成下面两步后,将自动完成登录并继续当前操作。

1 关注公众号
小红花技术领袖公众号二维码
小红花技术领袖
如果当前 App 无法识别二维码,请在微信搜索并关注该公众号
2 发送验证码
在公众号对话中发送下面 4 位验证码
小红花技术领袖俱乐部
小红花·文摘:汇聚分发优质内容
小红花技术领袖俱乐部
Copyright © 2021-
粤ICP备2022094092号-1
公众号 小红花技术领袖俱乐部公众号二维码
视频号 小红花技术领袖俱乐部视频号二维码