Filter

×
Active Filters Clear All
Keyword: 漏洞 ×
86 Total Reports
2/5 Page
Fortinet Other 2026-07-17

FortiBleed Credential Leak Exposes 75K FortiGate Firewalls, Management Plane Security Gaps

The FortiBleed campaign leaked configs from ~75,000 internet-facing FortiGate firewalls, with admin credentials hashed using weak SHA-256 (pre-PBKDF2) easily cracked offline. This highlights risks of exposed management interfaces and inadequate password policies.

CrowdStrike Other 2026-07-16

CrowdStrike Buys XM Cyber IP: Attack Path Management to Power Predictive Security on Falcon

CrowdStrike acquires all IP assets of XM Cyber (45+ patents and source code) while leaving XM Cyber as an independent licensee. This integrates attack path management into the Falcon platform, shifting from reactive EDR to predictive security, and strengthens partnership with European retail giant Schwarz Digits for market expansion.

Other Other 2026-07-15

CrowdStrike Integrates Claude Compliance API, Bringing AI Agent Monitoring into SOC

CrowdStrike integrates Anthropic's Claude Compliance API into its Falcon platform, enabling unified monitoring of Claude AI activities alongside endpoint, identity, and cloud telemetry. This formalizes AI agent security as a standard SOC function, reflecting the industry-wide shift of security budgets towards specialized vendors.

Fortinet Other 2026-07-14

FortiBleed Exposes 70k+ Devices: Attack Surface Shifts from Zero-Day to Credential Hygiene

In July 2026, the FortiBleed credential theft campaign targeted 73,000+ Fortinet devices using a custom sniffer tool. Attackers exploited default/weak passwords, not zero-days, and are linked to INC and Lynx ransomware groups. Global banks, energy firms, and critical infrastructure operators are impacted, exposing a systemic failure in basic security hygiene.

Other Other 2026-07-14

MemGhost Attack: Persistent False Memory Injection in AI Agents via Email

Researchers unveil MemGhost, a stealth memory injection attack that plants persistent false memories into AI agents via a single email without user notification. It exploits the persistent memory feature, highlighting critical security gaps and driving demand for memory auditing.

Other Other 2026-07-14

SANS Identifies Distributed Scanning of MCP Servers and AI Assistant Configs

SANS Internet Storm Center reports systematic scanning of MCP servers, AI assistant configs, and local LLM endpoints. 49 IPs targeted MCP handshakes, exploiting CVEs in MCP SDKs, signaling AI infrastructure as a new attack vector.

Fortinet Other 2026-07-12

FortiGate Firewalls Breached: 430K Devices Targeted with VPN Credential Sniffing

Attackers compromised approximately 430,000 FortiGate firewalls worldwide, deploying custom sniffers to intercept VPN credentials. The operation is linked to INC Ransom and Lynx ransomware groups, highlighting a new attack surface on edge devices that bypasses traditional EDR/SIEM.

Other Other 2026-07-12

OpenClaw Vulnerabilities Reveal Host Execution Environment as New Attack Surface for AI Assistants

Three critical vulnerabilities (CVSS 8.8/8.4) in OpenClaw's personal AI assistant enable command injection and path traversal, leading to host RCE. This confirms the host execution environment as a new attack surface for AI assistants, blending traditional exploits with AI agent risks.

Palo Alto Networks Other 2026-07-12

Palo Alto Networks PAN-OS Vulnerabilities: Buffer Overflow and Active Exploitation

Palo Alto Networks disclosed 13 PAN-OS vulnerabilities, with the most critical being CVE-2026-0288 (CVSS 9.2), a buffer overflow in User-ID TSA allowing unauthenticated RCE. CVE-2026-0257, an authentication bypass in GlobalProtect, is actively exploited in the wild.

Anthropic Other 2026-07-09

GhostApproval Vuln Exposes Systemic AI Coding Tool Flaw: Symlink Bypass in Human Review

Wiz Research discloses GhostApproval vulnerability affecting six major AI coding tools (Claude Code, Codex, Cursor, Amazon Q, Antigravity). Attackers use symlinks to bypass human review, achieving persistent remote access. The flaw reveals fundamental UI-level security gaps in Human-in-the-Loop mechanisms as agent permissions expand, requiring a redesign of confirmation workflows.

OpenAI Other 2026-07-06

OpenAI Launches GPT-5.6 Series, Regulatory Compliance Becomes Prerequisite for Frontier Models

OpenAI releases GPT-5.6 series with Sol achieving 96.7% SOTA on Terminal-Bench 2.1 via Ultra mode with sub-agent parallelism. Terra matches GPT-5.5 at half price, Luna for low-cost high-concurrency. Initial access limited to 20 trusted partners, subject to US government safety review.

Google Cloud Other 2026-07-06

Google Cloud Launches Blackwell GPU Confidential VM & Open-Source Prompt Encryption SDK, Redefining AI Security

Google Cloud upgrades its confidential computing portfolio with Blackwell GPU-based confidential VMs (Confidential G4 VMs preview), open-source Prompt Encryption SDK, and enhanced Confidential Space featuring Intel Trust Authority and Hopper GPU support, addressing TEE vulnerability CVE-2026-33697 to bolster AI inference and cross-organization training security.

Intel Other 2026-07-04

Critical Relay Attack Found in Attestation TLS Protocol: Both Intel TDX and AMD SEV-SNP Affected

A critical architecture flaw in the attestation TLS protocol, enabling relay attacks, has been discovered affecting both Intel TDX and AMD SEV-SNP platforms. With a CVSS score of 7.5, it surpasses recent high-profile confidential computing vulnerabilities. No official patch is currently available.

Palo Alto Networks Other 2026-07-02

Active Exploitation of CVE-2026-0257: GlobalProtect VPN Authentication Bypass Threatens Enterprise Networks

Palo Alto Networks confirms active exploitation of CVE-2026-0257 in GlobalProtect VPN. Attackers exploit shared certificates between HTTPS and authentication override to forge cookies, impersonating admins. CISA added to KEV. Urgent upgrade or dedicated cookie encryption certificate recommended.

Anthropic Other 2026-07-02

Anthropic Launches Sonnet 5: 40% Cost for Near-Opus Performance, Reshaping AI Inference Economics

Anthropic launches Claude Sonnet 5, a mid-range flagship model priced at 40% of Opus 4.8. It scores 63.2% on SWE-bench Pro, approaching Opus's 69.2%, and surpasses Opus on GDPval-AA v2. With native 1M token context and 48B average activated parameters, Sonnet 5 targets high-volume API revenue growth.

Research Other 2026-06-30

libssh2 CVE-2026-55200: Pre-auth RCE via Malicious Server, Attack Surface Shifts to Clients

A critical heap out-of-bounds write vulnerability (CVE-2026-55200, CVSS 9.2) in libssh2 allows a malicious SSH server to achieve pre-auth RCE on connecting clients. The flaw affects curl, Git, PHP, and many other projects statically linking the library, expanding the attack surface from servers to virtually any client application, including CI/CD, backup, and embedded systems.

Check Point Other 2026-06-23

Check Point Bets on GPT-5.5 Privileged Access: Security Control Shifts from Firewalls to LLM APIs

Check Point joins OpenAI's Cybersecurity Trusted Access Program, gaining privileged access to GPT-5.5 for threat analysis and incident response. This signals a shift in security competition from proprietary firewalls to reliable LLM API access, though the access tier is fully controlled by OpenAI.

Cisco Other 2026-06-21

Cisco Cloud Control: Control Plane Shifts from Silos to Unified AI Agent Orchestration

At Cisco Live 2026, Cisco launched Cloud Control, a unified platform for human and AI agent collaboration across network, security, compute, and observability. Key features include AI Canvas workspace, Cloud Control Studio agent builder (50+ integrations), and Live Protect runtime protection. This signals a major control plane consolidation from domain tools to a single intelligent orchestration layer.

OpenAI Other 2026-06-17

OpenAI buys Ona: Control point shifts to persistent AI agent runtime

OpenAI acquires cloud infrastructure startup Ona to integrate its persistent execution environment into Codex, enabling AI agents to run independently for hours or days in enterprise-owned clouds. This addresses security, governance, and audit requirements, signaling OpenAI's shift from model provider to full-stack AI platform.

AMD Other 2026-06-16

AMD Critical RCE Vulnerability Disclosed After 124 Days, Sparks AI Infrastructure Security Crisis

Security researcher mr.bruh publicly disclosed a critical remote code execution (RCE) vulnerability in AMD processors after 124 days without a fix, with AMD refusing a $10,000 bounty. The flaw affects AI servers running AMD EPYC and Instinct, likened to a Log4j moment for AI infrastructure, forcing enterprises to reassess chip-level security response and supply chain risk.