Anthropic conducted an audit of 141006 evaluation runs after OpenAI's sandbox escape disclosure. The review identified three incidents where Claude models accessed the internet due to...
CSRF(跨站请求伪造)利用浏览器自动携带Cookie的特性,诱骗已登录用户向目标网站发送伪造请求。攻击者无需窃取Cookie,只需诱导用户访问恶意网站,浏览器便会自动附带用户的会话凭证。防御措施包括CSRF令牌、SameSite Cookie、Origin/Referer校验等。Spring Security通过CsrfFilter实现防护,开发者应确保GET请求只读,并采用多层防御策略。
Dropbox has integrated Model Context Protocol (MCP) with its internal knowledge platform, Dash, to surface security design context during AI assisted code reviews. The system retrieves threat...
Mate Security获3500万美元A轮融资,主张安全运营需AI原生架构而非仅给SIEM加LLM。其核心是安全上下文图,持续更新组织资产、用户和业务流程,帮助AI代理更准确判断警报。公司称客户含财富500强,收入自2025年Q3增长超500%,资金将用于扩展团队和产品。
JFrog Security Research revealed "PixelSmash," a vulnerability in the FFmpeg media framework, allowing for Remote Code Execution and Denial of Service attacks. Present for sixteen years, it...
The bottleneck in a mature SOC is rarely analyst triage; rather, it is the detection-engineering team's ability to keep the rule base aligned with a threat landscape that evolves faster than rules...
Google Cloud has published a new blueprint setting out how organisations should secure artificial intelligence workloads running on Google Kubernetes Engine, arguing that the shift from prototype...
GitLab has released version 19.2 of its DevSecOps platform, adding agentic automation aimed at the security and review work that has piled up as AI coding tools generate more code than developers...
Amazon Web Services has recently introduced AWS Continuum, a new integrated security platform to automate the discovery, enforcement, and remediation of security issues across codebases,...
AWS构建者中心上线一周年,功能不断扩展,包括沙盒环境和网络扫描功能。Security Hub新增网络扫描,支持AWS和Azure资源监控。Amazon SageMaker与Hugging Face集成,简化模型部署。EKS和ECS管理费用下调,Aurora DSQL CDC功能正式发布。AWS还推出Loom和Claude应用程序网关,增强安全性和管理能力。
InfoQ has opened enrollment for a five-week AI Security & Privacy Engineering cohort for senior engineers and architects in regulated industries, focused on applying security, privacy, threat...
In this episode, Alex Zenla (CTO/Co-founder, Edera) challenges the "laissez-faire" attitude toward modern infrastructure. She promotes "spite-driven development", building software to solve...
This virtual panel brings together AI security experts to examine the evolution of AI-driven threats, from prompt injection and data poisoning to agent abuse and AI-powered social engineering. The...
The Argo CD project released a v3.5 release candidate in June 2026. This version adds mutual TLS enforcement for internal components. It also includes Git commit signature verification for supply...
AWS Security Agent 在 re:Invent 2025 上推出新功能,包括按需渗透测试、代码审核和威胁建模,支持多种代码存储库,提供安全分析和风险识别,帮助开发者保障应用安全。新集成的 Kiro 能力包和 Claude Code 插件可直接在 IDE 中运行,简化安全审查和修复流程。
一家数字安全软件公司与UnderDefense合作,将其安全系统从传统的QRadar迁移到Elastic Security,成功减少了85%的安全事件,响应时间缩短了61%。迁移过程中进行了全面的日志审计和定制检测规则的建立,提升了安全监控的效率和合规性,使安全团队能够主动进行威胁狩猎。
GitLab 19.0 extends agentic AI beyond code generation into securing credentials, reviewing and merging changes, and scanning dependencies, adding a public beta Secrets Manager, a full merge...
In a new Windows Developer Blog post titled "Windows platform security for AI agents", Microsoft positions Windows as the trustworthy operating system for autonomous agents and introduces the...
Cybersecurity firm Chainguard has announced the launch of Athena, an industry coalition to use artificial intelligence to find and fix vulnerabilities in widely-used open-source software before...
There was a flurry of activity in the Spring ecosystem during the week of June 8th, 2026, highlighting point releases of: Spring Boot, Spring Security, Spring Session, Spring Integration, Spring...
完成下面两步后,将自动完成登录并继续当前操作。