AI生产力工具引入的攻击面 – 从亚马逊VS Code扩展攻击事件说起
2025年7月的亚马逊VS Code扩展被黑客攻击事件,是AI安全风险的一个典型案例,它揭示了AI生产力工具集成过程中的深层次安全隐患。本研究将以此事件为切入点,探讨AI大模型相关的新型安全事件,分析其攻击面和技术手段,并评估其潜在影响。
Since mid-July, this vulnerability has been actively exploited in the wild by multiple threat actors, including groups believed to be affiliated with nation-state interests. To date, more than 85 SharePoint servers worldwide have reportedly been compromised, emphasizing the urgent need for organizations to implement available mitigations and apply emergency security patches without delay. Technical Details…
The post New SharePoint Zero-Day Allows Unauthenticated Remote Code Execution appeared first on Sentrium Security.
The post New SharePoint Zero-Day Allows Unauthenticated Remote Code Execution appeared first on Security Boulevard.