NHS England has admitted that a data protection document inaccurately stated who could access patient information, failing to disclose that Palantir staff could view identifiable data held within part…
業界新聞
Elon Musk finally launches X Money. What could possibly go wrong? Expect bumps with X Money rollout as major US financial markets are excluded. https://arstechnica.com/tech-policy/2026/07/elon-musk-fi…
Valve Sponsors Work Bringing Open-Source RADV Driver To Windows Valve has been sponsoring Collabora engineers with early phase, exploratory work for trying to bring the open-source Radeon Vulkan "RADV…
Vibe Coded X11 YSERVER Gets Steam Working, Full-Screen Games With Cinnamon A new software creation that debuted this summer was YSERVER as a modern X11 server written in Rust largely by AI via Claude …
新聞資安公司卡巴斯基近日指出,外號為UNC1549、Smoke Sandstorm、Nimbus Manticore、Mirage Kitten的伊朗駭客組織,近期使用後門程式NightLedger,並搭配以WebSocket為基礎的隧道程式ArcBridge和BridgeHead,針對中東及非洲航太、航空、國防及電信產業從事網路間諜活動,並確認有埃及、約旦、坦尚尼亞的中小企業及政府環境,以及巴基…
新聞線性傳動元件與工業機器人廠商上銀科技(2049)7月28日晚間於股市公開觀測站發布重大訊息,義大利子公司資訊系統遭到攻擊,資訊部門於第一時間偵測異常後,立即啟動資安應變程序。 目前上銀正對相關系統進行全面性資安掃描與檢測,並在確認資訊安全無虞的情況下,利用備份資料復原系統運作。根據上銀的初步評估,本起事故對公司營運無重大影響。
FreeBSD's Kernel Still Has A Bit Of GPL Code While Its Base User-Space Is GPL-Free A few weeks ago there was excitement in the FreeBSD camp with FreeBSD 16 set to retire the last of its GPL code from …
GCC To Decline Any Significant Contributions Made Via AI/LLMs - Except For Test Cases The GCC Steering Committee announced today that they have accepted the recommended policy of the GCC AI Policy Wor…
Your brain apparently spends the night remixing reality rather than simply replaying it, according to researchers armed with AI and more than 3,700 accounts of dreams and waking life. Researchers at I…
新聞7月中旬AI模型開發與託管平臺Hugging Face透露遭到自主AI代理攻擊,導致雲端與叢集憑證遭竊,事隔數日,OpenAI承認是旗下正在進行資安能力評估的模型所引起,本週Hugging Face公布整起事故發生的過程,同一天有一家資安廠商透露,OpenAI模型為了逃脫測試環境,利用了他們產品的零時差漏洞來達到目的。 7月27日JFrog發布部落格文章指出,受測模型於從OpenAI內部建置的…
新聞本日新聞焦點 ● 微軟進一步說明AD CS Certighost權限提升漏洞修補詳情 ● Hugging Face公布AI代理人入侵始末 ● Java JSON函式庫Fastjson重大RCE漏洞已遭實際利用 ● 奧義智慧揭露代理式AI的關鍵風險 ● 印度第二大公營行庫Bank of Baroda遭駭 資安新聞總覽 微軟對AD CS Certighost權限提升漏洞修補提出進一步說明,建議企業…
新聞資安業者Lava掃描發現,網際網路上有36,872個伺服器IPMI管理介面直接對外開放,其中24,650個會在使用者登入前,回傳由密碼產生的驗證資料。攻擊者可利用已知漏洞CVE-2013-4786,將資料帶回自己的電腦猜測密碼,而弱密碼及格式固定的出廠密碼,在GPU協助下可能遭到破解。 IPMI是用於遠端管理實體伺服器的協定,通常由主機板上的基板管理控制器(BMC)提供。管理人員可透過BMC開…
Your Brain Can Rewire Itself To Allow True Multitasking https://science.slashdot.org/story/26/07/29/0455211/your-brain-can-rewire-itself-to-allow-true-multitasking?utm_source=rss1.0mainlinkanon
Airbus yesterday flew the latest variant of its A350 widebody jet from Australia to France, non-stop, on a route that saw it remain aloft for over 24 hours. The variant is called the A350-1000ULR, whi…
OPINION A week after becoming the UK's seventh Prime Minister in ten years, Andy Burnham has made some good headlines, but, among the promises to cap bus fares and end rough sleeping, something was mi…
New Orleans Cops Published Policy Document Allowing Weaponized Drones https://news.slashdot.org/story/26/07/20/2259204/new-orleans-cops-published-policy-document-allowing-weaponized-drones?utm_source=…
Longtime Web-Weirdness Site Fark Faces Ad Pinch https://news.slashdot.org/story/26/07/20/2239204/longtime-web-weirdness-site-fark-faces-ad-pinch?utm_source=rss1.0mainlinkanon
新聞Anthropic周二(7/28)公布研究,表示Claude Mythos Preview找到後量子數位簽章演算法HAWK的數學弱點,能大幅降低破解所需運算量;Claude也改進針對簡化版AES加密演算法的攻擊方法,使速度較先前最佳方法提升200至800倍。不過,兩項成果目前皆未影響正式運作的系統。 HAWK為美國國家標準暨技術研究院(NIST)後量子數位簽章標準化計畫的第三輪候選演算法之一,…
新聞討論區軟體vBulletin修補重大遠端程式碼執行漏洞CVE-2026-61511。攻擊者不需要帳號,便可能透過公開的網頁功能送入特製資料,在伺服器執行任意PHP程式碼。漏洞影響vBulletin 5.0.0至5.7.5,以及6.0.0至6.2.1,vBulletin 6.2.2已修補這項漏洞。資安研究員Egidio Romano也已在個人網站Karma(In)Security公開概念驗證程式…
新聞去年底安碁資訊(ACSI)首度揭露自行發展的生成式AI模型CyberSage,以及代理型AI平臺安答系統(Anda),並介紹其大幅領先GPT-4o-mini的高精準度與成本效率。 今年3月該公司在新發布的114年度年報,也特別介紹這套AI系統的發展近況,例如,安答設置在安碁資訊營運的雲端資安監控服務Cloud SOC之上,導入多個AI代理組成的系統架構,並以AI SecOps Agent為核心…