新聞之前傳出AI公司Mistral AI的PyPI套件遭到入侵,駭客發布含有惡意程式碼的2.4.6版,此為蠕蟲Mini Shai-Hulud供應鏈攻擊的一部分,Mistral AI也發布資安公告,證實NPM與PyPI套件先後遭到入侵,指出該公司是TanStack供應鏈攻擊事故而受到波及,如今傳出駭客已開始兜售竊得的資料。根據資安新聞網站Bleeping Computer的報導,駭客團體TeamPC…
業界新聞
新聞資安業者Proofpoint發現近日出現新的攻擊基礎架構,可讓駭客更容易發動裝置碼釣魚(device code phishing)攻擊,進而竊取Microsoft 365或其他雲端帳號的存取權杖(Access Tokens)。裝置碼釣魚目的在誘騙使用者授權惡意應用程式存取企業郵件帳號。其原理是濫用OAuth 2.0裝置授權;攻擊者先發送電子郵件、檔案或QR code給受害者,利用社交工程誘使受…
Samsung found itself facing down controversy in South Korea last week, when the weather app pre-installed on many of its devices incorrectly labelled an island territory named Dokdo as part of North K…
新聞上週OpenAI宣布預覽一項個人金融新功能,讓ChatGPT連結其金融帳戶,協助快速了解個人全面的財務狀況。OpenAI表示,現在每個月全球有超過2億人使用ChatGPT執行預算、詢問投資、比較不同路徑、或為未來目標進行規劃。而底層的GPT-5.5也為ChatGPT賦予更強的推理能力來回答複雜的個人金融問題。最新服務透過金融科技(FinTech)公司Plaid實現ChatGPT和用戶個人金融機…
新聞美國資安與雲端運算業者Akamai Technologies週四(5/14)宣布,已簽署最終協議,將以約2.05億美元收購以色列瀏覽器安全新創LayerX Security,交易預計於今年第三季完成。Akamai表示,此舉將強化其零信任(Zero Trust)與AI使用控制(AI Usage Control)產品線,以因應企業員工大量使用生成式AI、SaaS AI服務與AI代理人所帶來的新資安…
新聞5月12日Mozilla基金會發布Firefox 150.0.3更新,總共修補5個高風險漏洞CVE-2026-8388、CVE-2026-8389、CVE-2026-8390、CVE-2026-8391、CVE-2026-8401。值得留意的是,雖然Mozilla評估這些漏洞都是高風險等級,但根據美國國家漏洞資料庫(NVD)登記的資料,美國網路安全暨基礎設施安全局(CISA)認為最危險的漏洞是…
America's Library of Congress Officially Inducts... the Soundtrack for the Videogame 'Doom' https://games.slashdot.org/story/26/05/18/0130213/americas-library-of-congress-officially-inducts-the-soundt…
Linux kernel boss Linus Torvalds has declared the project’s security mailing list has become “almost entirely unmanageable” due to multiple researchers using AI to find bugs and then filling the list …
Former Google CEO Eric Schmidt Booed During Graduation Speech About AI https://slashdot.org/story/26/05/17/2343248/former-google-ceo-eric-schmidt-booed-during-graduation-speech-about-ai?utm_source=rss…
新聞企業應用軟體業者SAP宣布擴充商業資料雲SAP Business Data Cloud(SAP BDC)與資料庫服務SAP HANA Cloud,更新重點放在多雲資料整合、資料治理,以及代理式AI應用開發。在資料整合方面,SAP在SAP BDC加入資料雲端平臺Snowflake解決方案的整合,讓客戶可直接透過SAP使用Snowflake的資料與AI能力,並依不同資料與AI工作負載選擇合適的運算…
KETTLE Hopefully you haven't had reason to notice yet, but there's a rising problem with AI services on Google Cloud, AWS, and other platforms sticking their customers with bills in the tens of thousa…
Small Town Fights Over Flock's AI-Enhanced Network of License Plate-Reading Cameras https://yro.slashdot.org/story/26/05/17/2236232/small-town-fights-over-flocks-ai-enhanced-network-of-license-plate-r…
Microsoft is retiring Teams’ Together Mode https://www.theverge.com/tech/932215/microsoft-teams-together-mode
Linux 7.1-rc4 Released With Many Fixes, New Documentation For Security/AI Topics It was another busy week in the Linux 7.1 kernel space that has culminated with the release of Linux 7.1-rc4... https:/…
Microsoft Exchange Server Vulnerability Actively Exploited, in a Bad Week for Microsoft https://it.slashdot.org/story/26/05/17/2053257/microsoft-exchange-server-vulnerability-actively-exploited-in-a-b…
'We Still Can't See Dark Matter. But What If We Can Hear It?' https://science.slashdot.org/story/26/05/17/198215/we-still-cant-see-dark-matter-but-what-if-we-can-hear-it?utm_source=rss1.0mainlinkanon
University of Arizona students boo Eric Schmidt’s AI cheerleading during commencement https://www.theverge.com/ai-artificial-intelligence/932203/university-of-arizona-students-boo-eric-schmidt-ai-comm…
Revamped Siri will reportedly offer auto-deleting chats https://www.theverge.com/tech/932207/siri-apple-intelligence-auto-deleting-chats
新聞開放原始碼IT系統監控與分析平臺業者Grafana Labs最近發生資料外洩事故,起因在於攻擊者非法取得GitHub的存取權杖,以此登入GitHub下載其程式碼庫,並向其勒索。週日(5月17日)Grafana Labs在社群平臺X和LinkedIn發文,坦承近期發現有個未經授權的團體獲得該公司GitHub環境的存取權杖,使攻擊者得以下載該公司的程式碼庫,根據內部調查指出,這起事故期間並無客戶資…
Us Math/Reading Scores Continue 13-Year Decline. Researchers Blame Reduced Testing and Social Media https://news.slashdot.org/story/26/05/17/1729245/us-mathreading-scores-continue-13-year-decline-rese…