Posts of last 24 hours
Currently trending CVE - Hype Score: 4 - Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
https://cvemon.intruder.io/cves/CVE-2025-32711
模型能力越来越强,美国开始决定谁能先用最强AI。
https://mp.weixin.qq.com/s?__biz=MzU4NzUxOTI0OQ==&mid=2247499548&idx=1&sn=d41e0a1f77045089c74812add369fb51
AWS DevOps Agent helps administrators inspect logs, review firewall rules and network paths, identify configuration changes that caused AWS Network Firewall to block traffic, and restore connectivity. The service is an AI-powered operations assistant for DevOps and SRE teams that investigates and troubleshoots application and infrastructure issues. It connects to monitoring tools, logs, code repositories, and deployment pipelines, analyses incidents, pinpoints likely root causes, and recommends fixes or preventive improvements. It works across AWS, multicloud, … More →
The post AWS gives DevOps teams an AI investigator for firewall incidents appeared first on Help Net Security.
https://www.helpnetsecurity.com/2026/07/27/aws-devops-agent-network-firewall-troubleshooting/
抹香鲸是以竖立的方式在海面下睡眠的,它如何在睡眠中保持平衡?根据发表在《实验生物学杂志》上的一项研究,研究团队在挪威海域为野生抹香鲸安装了吸盘式记录仪。这种装置能够记录声音和三维运动数据。研究人员不仅捕捉到清晰的气泡释放声,还结合鲸体运动、组织密度、水中阻力以及体内气体体积等信息建立模拟模型,分析抹香鲸休息时的浮力变化。结果显示,抹香鲸在休息过程中释放气泡,可有效降低自身正浮力,使其能够持续停留在海面下方而不会缓慢上浮。这种调节极为重要,因为抹香鲸头部富含鲸脑油,天然具有较强的浮力。同时,作为闭气潜水动物,抹香鲸若在休息过程中缓慢上浮,肺内气体会随着环境压力降低而不断膨胀,进一步增加浮力。释放气泡则有助于抵消这一效应,使其保持接近中等的浮力。研究团队表示,抹香鲸能够在疑似睡眠状态下完成如此精细的浮力调节,展现出极高的生理控制能力。
https://www.solidot.org/story?sid=84932
上周关注度较高的产品安全漏洞(20260720-20260726)
https://mp.weixin.qq.com/s?__biz=MzU3ODM2NTg2Mg==&mid=2247497136&idx=2&sn=982dd172fe8bf161e4ce77ac7d323754
国家信息安全漏洞共享平台(以下简称CNVD)本周共收集、整理信息安全漏洞578个,其中高危漏洞335个、中危漏洞184个、低危漏洞59个。
https://mp.weixin.qq.com/s?__biz=MzU3ODM2NTg2Mg==&mid=2247497136&idx=1&sn=6afa6bbee11b2b7fa66ca5a4b21a0df7
Submit #862537 / VDB-383396
https://vuldb.com/submit/862537
Юристы, врачи и финансисты сдали свои аккаунты, просто заселившись в номер.
https://www.securitylab.ru/news/575330.php
Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the Middle East.
The intrusions have resulted in the deployment of previously unreported malware families dubbed TELESHIM, MIXEDKEY, and BINDCLOAK, according to Zscaler ThreatLabz. The cybersecurity firm said it detected the campaign earlier this month.
https://thehackernews.com/2026/07/teleshim-abuses-telegram-for-c2-in.html
Submit #862536 / VDB-383395
https://vuldb.com/submit/862536