Wayfire Wayland Compositor Closing In On v1.0 Release The Wayfire modular and extensible Wayland compositor formally used by default on Raspberry Pi SBCs is nearing its v1.0 release. Wayfire 0.11 was …
Wayfire Wayland Compositor Closing In On v1.0 Release The Wayfire modular and extensible Wayland compositor formally used by default on Raspberry Pi SBCs is nearing its v1.0 release. Wayfire 0.11 was …
FreeBSD Developing New NTSYNC Driver For Accelerating Windows NT Sync Primitives The FreeBSD project published today their Q2-2026 status report that highlights all of their interesting open-source de…
OPINION Sick of relying on proprietary programs and American software giants and hyperclouds? Join the digital sovereignty revolution. It really is the smart thing to do. Honestly, with Donald Trump c…
NVIDIA & Others Form The Open Secure AI Alliance NVIDIA and more than two dozen other companies have started the Open Secure AI Alliance for helping to keep open-source AI models secure. The other fou…
新聞本日新聞焦點 ● 中國駭客透過AI代理於泰國財政部從事網路間諜活動 ● 勒索軟體Clop滲透Windchill與FlexPLM並向用戶寄勒索信 ● 勒索軟體Chaos打造將C2藏在瀏覽器的木馬程式msaRAT ● Google緊急修補4個Chrome 150高風險漏洞 ● 數發部公布網路詐騙查詢網執行成果 資安新聞總覽 AI代理Hermes執行自主攻擊,中國駭客以此在泰國財政部從事網路間諜活動…
新聞Python套件索引服務PyPI開始拒絕向發布超過14天的套件版本新增檔案,避免專案發布憑證或自動化流程遭入侵後,攻擊者向長期穩定的舊版本加入惡意程式。PyPI表示,目前尚未發現這種攻擊方式遭實際利用,但在此之前並無技術限制阻止這種做法。 一個Python套件版本通常包含多個檔案,除了原始程式碼,也可能提供適用於不同作業系統、處理器架構或Python版本的預先建置套件。過去維護者發布版本後,仍…
OPINION The best way to bust out of jail is not to get locked up in the first place. There are options once you're inside, legal and illegal, and all are complicated, time-consuming, and probably won'…
What frightens a seasoned IT professional? A screen streaked with unidentified fluid? An error message that only hints at what has gone wrong behind the scenes? Roller coasters are not scary. Nausea-i…
新聞AI程式開發代理人Devin的開發商Cognition上周四(7/23)宣布,已收購簡訊AI助理Poke的開發商The Interaction Company of California,計畫把Poke主動聯絡使用者、持續追蹤任務及較像朋友的對話方式導入Devin。雙方並未公布交易金額,但TechCrunch報導,這筆交易對The Interaction Company的估值超過1億美元。 今…
Google has created a new taxonomy to describe cybercrime outfits, seemingly abandoning a Microsoft-led effort to create consistent names. The Big G announced its new schema on Saturday in a post that …
新聞微軟Active Directory憑證服務(AD CS)存在名為Certighost的權限提升漏洞,在研究人員測試的特定配置下,持有一般網域帳號的攻擊者可誘使憑證授權單位簽發帶有網域控制站身分資訊的憑證,藉此冒充網域控制站,取得網域內的帳號機密。該漏洞編號為CVE-2026-54121,微軟已於7月14日發布更新修補。 AD CS是微軟用於企業網域的數位憑證服務,可替使用者及電腦簽發身分憑證…
新聞一般而言,駭客為了隱匿C2通訊,最常見的其中一種作法,就是濫用合法的雲端服務來建立通訊,以這些服務的合法流量來掩蓋非法活動。現在有駭客團體採用全新的手法來達到目的,引起研究人員的注意。 思科威脅情報團隊Talos揭露遠端存取木馬(RAT)msaRAT,此惡意程式以Rust打造而成,採用執行環境Tokio實作C2通訊,攻擊者可透過瀏覽器遠端執行任意程式碼(RCE)。Talos強調,雖然駭客在ms…
WHO, ME? Mistakes happen, and when readers of The Register make them, we like to share those tales of woe in a Monday column we call "Who, Me?" It's our guide on how not to get ahead in the modern wor…
新聞微軟上周五(7/24)發布《開放權重與美國AI領導地位》聯合公開信,呼籲美國決策者支持開放權重AI模型,避免過早限制可供下載的模型。目前連署者包括Meta、微軟、Nvidia、OpenAI、Google、IBM、AMD、GitHub、Hugging Face及Linux基金會等業者與組織。 開放權重模型是指開發商允許外界下載訓練完成的AI模型,在自己的設備上執行或調整,但不一定公開訓練資料及完…
新聞Anthropic上周五(7/24)推出Claude Opus 5,主打程式設計、知識工作及電腦操作等日常任務,效能接近前沿模型Claude Fable 5,但使用成本僅約一半。Opus 5即日起成為Claude Max方案的預設模型,也是Claude Pro方案提供的最強模型。 Anthropic目前依效能、成本及用途,將Claude模型分為Mythos、Fable、Opus、Sonnet及…
新聞三年前烏克蘭電腦緊急應變團隊(CERT-UA)揭露俄羅斯駭客UAC-0099的攻擊行動,後續資安公司Deep Instinct公布進一步的調查結果,指出駭客的主要目標是境外公司的烏克蘭員工,透過多種管道在受害電腦植入惡意程式LonePage,其中一種是WinRAR已知漏洞CVE-2023-38831。如今CERT-UA指出,這些駭客手法出現了顯著變化。 7月21日CERT-UA表示,他們近日發…
新聞去年聲稱從許多企業組織的Oracle E-Business Suite(EBS)竊得大批資料的勒索軟體駭客Clop(FIN11、Lace Tempest、Graceful Spider),近期發動新一波攻擊,並向許多企業組織寄送勒索信的情形。 資料外洩情資平臺eCrime.ch與威脅情報公司Defused Cyber聯手,於勒索軟體威脅情報共享社群Ransom-ISAC發布警告,他們從7月20…
新聞WordPress開發團隊宣布,React 19不會納入WordPress 7.1,該版本將繼續使用React 18.3。團隊先前曾在Gutenberg外掛中短暫啟用React 19,但測試發現,新舊React版本之間的互動,以及部分外掛使用React的方式,會引發未預期的相容問題,因此撤回這項變更,並需要較長的測試期,持續改善及調整相容層。 React是許多WordPress區塊、編輯器擴充…
The 13th flight of SpaceX’s Starship made it off the launchpad on Friday and ticked off just about everything on the company’s to-do list. After delays and engine replacements, Elon Musk’s colosso-lau…
新聞威脅情報公司Group-IB揭露中國駭客組織JadeProx的攻擊活動,這些駭客曾入侵越南醫院的醫療影像系統、馬來西亞外交部、香港教育機構,並在拉丁美洲從事網釣,範圍包含宏都拉斯國會與委內瑞拉市政稅務系統。上述活動的最終目標,都是在受害組織植入惡意程式載入工具TriBack Loader,以便傳遞後續的攻擊工具,包括C2框架AdaptixC2與後門程式Beagle。其中,委內瑞拉的釣魚網站模擬…