分类: AI 资讯

npm 对可绕过 2FA 的细粒度访问令牌实施限制

npm 对可绕过 2FA 的细粒度访问令牌实施限制

npm 宣布限制可绕过双因素认证(2FA)的细粒度访问令牌,这类令牌将无法再执行创建令牌、修改包权限、管理组织等敏感操作。此前,一旦此类令牌泄露,攻击者可直接控制账户并植入恶意代码,这是 npm 生态最危险的攻击路径之一。

瓦解诈骗犯罪行动

瓦解诈骗犯罪行动

OpenAI 在 2026 年 8 月 4 日披露,其封禁了一组位于柬埔寨的 ChatGPT 账号网络,这些账号被用于投资、恋爱、赌博和冒充执法人员的诈骗活动。这不仅是安全团队的又一次“清剿”,也把大模型遭恶意利用的形态从“单点滥用”推向“有组织的黑产运营”。

Lioness season 3 is Taylor Sheridan’s most scathing, brutal, and AI-wary outing yet — but the new Paramount+ series is still making sure that the Yellowstone creator is the action hero of the hour

Lioness season 3 is Taylor Sheridan's most scathing, brutal, and AI-wary outing yet — but the new Paramount+ series is still making sure that the Yellowstone creator is the action hero of the hour

Paramount+ 剧集《Lioness》第三季罕见地将剧情核心对准 AI 与无人机战争,借角色之口直接表达“AI 是比民主终结更大的威胁”。这标志着好莱坞主流影视创作者开始在战争叙事中认真讨论 AI 的战场角色与潜在风险。

AI骗子比人类更会建立信任。

AI骗子比人类更会建立信任。

一项由四所大学联合完成的研究发现,在“杀猪盘”式诈骗的信任建立阶段,AI 聊天机器人的表现已超过人类诈骗者——近半数测试对象在 AI 引导下执行了对方要求的操作,而人类诈骗组的成功率不到五分之一。这意味着大模型驱动的诈骗自动化可能比预期更快成为现实。

‘C-suite executives need to upskill themselves to really understand the threats’: AI is becoming a tool for attackers and defenders, but true resilience requires a constantly changing strategy, says former GCHQ intelligence expert

'C-suite executives need to upskill themselves to really understand the threats': AI is becoming a tool for attackers and defenders, but true resilience requires a constantly changing strategy, says former GCHQ intelligence expert

AI正在同时增强网络攻击与防御两端的能力——攻击者用AI将攻击效率提升到国家级水平,而防御方也开始用AI做动态响应。前GCHQ专家Julian Richards指出,真正的韧性不是一次性的安全方案,而是持续变化、多样化、动态调整的防守策略。