新聞上週爆發的Klue供應鏈攻擊事故,已有超過10家公司證實受到影響,導致他們存放在Salesforce平臺的資料出現未經授權存取的現象,其中大部分是資安公司。如今有SaaS服務公司也受害。根據資安新聞網站SecurityWeek報導,本週產品體驗平臺公司Pendo與雲端通訊服務廠商8×8皆傳出受害,Pendo於6月22日發布部落格文章表示,他們於6月14日接獲通報,未經授權的攻擊者入侵Pendo…
業界新聞
新聞JavaScript與TypeScript執行環境Deno發布2.9版,新增實驗性的deno desktop工具,讓開發者可將JavaScript與TypeScript網頁專案封裝成桌面應用程式。該功能讓Deno從伺服器端與命令列執行環境,擴大到桌面程式開發,開發者可用既有網頁技術建立Windows、macOS與Linux應用。deno desktop可指定一支指令碼作為進入點,也可用於既有網…
新聞微軟本周低調透過官方部落格公告,針對個人用Windows 10 PC提供的延伸安全更新(Extended Security Update,ESU)將再免費展延一年到2027年10月。微軟指出Windows 10 ESU的涵蓋時期將可擴展到2027年10月12日,這次展延可提供客戶更多時間轉移到新的Windows 11 PC,同時持續獲得關鍵的安全更新。微軟在2025年10月14日終止Windo…
新聞上週Salesforce揭露Klue供應鏈攻擊,並宣布切斷Klue Battlecards應用程式與用戶的Salesforce系統連結因應。然而就在有許多受害公司證實他們的Salesforce因此出現未經授權存取的情形之際,有另一家公司指出,他們的用戶也可能遭到這波供應鏈事故波及。6月19日AI營收情資平臺Gong表示,同時使用Klue進行整合的用戶,有可能受到這起事故波及。對此,Gong已撤…
Chinese cybersecurity vendor Qihoo 360 claims it’s built an AI bug-finder that’s better than Anthropic’s Mythos model. CEO Zhou Hongyi revealed the model in a speech at the 14th Beijing Cybersecurity …
新聞蘋果周四(6/25)調漲了旗下從HomePod、iPad、MacBook到iMac的價格,漲幅從15%到25%不等,臺灣蘋果線上商店的價格也已同步調漲,13吋MacBook Air的新售價為42,900元新臺幣,上周還只有35,900元新臺幣,一口氣漲了7,000元。此波蘋果硬體產品調漲並未波及iPhone。微軟亦於同一天宣布自8月1日起於全球調漲Xbox遊戲主機售價。其實蘋果執行長庫克(Ti…
Spain To Require Carriers To Keep Mobile Networks Live During Power Outages https://hardware.slashdot.org/story/26/06/25/2056248/spain-to-require-carriers-to-keep-mobile-networks-live-during-power-out…
新聞可觀測性平臺業者Grafana Labs於5月16日確認,該公司GitHub儲存庫遭未授權存取,攻擊者下載程式碼並提出勒索要求。後續調查指出,事件源自TanStack NPM供應鏈攻擊中的Mini Shai-Hulud活動。Grafana Labs於5月27日完成內部調查,6月23日進一步發布事後檢討報告,說明事件限於GitHub環境,客戶正式環境與Grafana Cloud平臺並未受影響。G…
新聞6月25日美國網路安全與基礎設施安全局(CISA)表示,他們已掌握CVE-2026-12569、CVE-2026-20230兩個漏洞遭到利用的情形,並要求聯邦機構於28日前完成修補。其中存在於PTC產品生命週期管理(Product Lifecycle Management,PLM)系統Windchill、FlexPLM的重大漏洞CVE-2026-12569,相當值得留意,因為PTC已在一週前警…
新聞市場研究與顧問公司Gartner於6月24日發布預測報告指出,隨著企業擴大採用大型語言模型(LLM)驅動的AI程式開發代理(AI coding agents),相關工具的token消耗量也會持續增加。若供應商的收費模式持續從席次授權制轉為依用量計算,到了2028年,企業的AI程式開發成本將超過開發者平均薪資。根據Computer Weekly引述Gartner Peer Insights研究的…
新聞本月初思科修補重大等級的伺服器請求偽造(SSRF)漏洞CVE-2026-20230,此漏洞存在於整合通訊管理平臺Unified Communications Manager(Unified CM)與Unified Communications Manager Session Management Edition(Unified CM SME),攻擊者可透過特製的HTTP請求利用,將檔案寫入底層…
新聞6月22日威脅情報公司Defused Cyber警告,他們偵測到有人首度利用伺服器請求偽造(SSRF)漏洞CVE-2026-20230的跡象,此弱點存在於思科整合通訊管理平臺Unified Communications Manager(Unified CM)與Unified Communications Manager Session Management Edition(Unified CM…
Coreboot 26.06 Brings Support For Intel Nova Lake, AMD Strix Halo & 31 New Boards Coreboot 26.06 is out today as the latest quarterly feature release for this software project providing open-source sy…
Ubuntu 26.10 Snapshot 2 Released For Monthly Testing Daily ISOs of Ubuntu 26.10 "Stonking Stingray" continue to be published, but for those preferring something a bit more regulated, out today is Ubun…
Security firm Huntress allegedly has a turncoat insider leaking info to a ransomware operation, according to an ex-employee who took his grievances to social media after claiming the security shop tri…
A sealed scroll from the Roman town of Herculaneum, which was destroyed by Mount Vesuvius' eruption nearly 2,000 years ago, has finally given up its secrets, thanks to a combination of machine learnin…
A new self-destructing backdoor called Mistic used in intrusions since April appears to be linked to a criminal gang that compromises corporate networks and then sells that access to ransomware groups…
AI-POCALYPSE Several leading US AI companies joined with former US government officials on Thursday to form a bipartisan coalition focused on helping to prepare workers for the AI tsunami, even as man…
Feds deny Polestar authorization to sell cars in US from model year 2027 Unlike with Volvo, there will be no authorization for Polestar to sell its cars here. https://arstechnica.com/cars/2026/06/feds…
Google Finance finally gets a mobile app as AI-powered overhaul leaves beta It took 20 years, but the Finance app arrives just in time to be packed full of AI. https://arstechnica.com/google/2026/06/g…