🔧 AI Nachrichten How to evaluate LLMs before production(25.08.2026 um 23:35 Uhr)
⚠️ Malware / Trojaner / VirenStill: From Akira to Ink Wash, Building a Generative Garden in WebGPU(09.09.2026 um 16:11 Uhr)
🔧 AI Nachrichten LLMs im Browser – Teil 1: Eine neue KI-Runtime(09.09.2026 um 09:10 Uhr)
🔧 AI Nachrichten OpenAI’s GPT-6 Astra now available in Microsoft applications(08.09.2026 um 18:30 Uhr)
🔧 AI Nachrichten Build vs Buy: When to Outsource Machine Learning Development(10.09.2026 um 18:40 Uhr)
🔧 AI Nachrichten How to evaluate LLMs before production(25.08.2026 um 23:35 Uhr)
⚠️ Malware / Trojaner / VirenStill: From Akira to Ink Wash, Building a Generative Garden in WebGPU(09.09.2026 um 16:11 Uhr)
🔧 AI Nachrichten LLMs im Browser – Teil 1: Eine neue KI-Runtime(09.09.2026 um 09:10 Uhr)
🔧 AI Nachrichten OpenAI’s GPT-6 Astra now available in Microsoft applications(08.09.2026 um 18:30 Uhr)
🔧 AI Nachrichten Build vs Buy: When to Outsource Machine Learning Development(10.09.2026 um 18:40 Uhr)

🕵️ Sicherheitslücken 🕛 vor 4 Std. 2 Min Lesezeit SECURITY-FEED
0

Security Weekly - A CRA Resource: 9/11 at 25, OfferLoader, Gemini CLI, Liquid, 10% Doom, Josh Marpet, and More - SWN #615

↗ Quelle (YouTube · Security Weekly - A CRA Resource)
🗣️ Stimme:
📺
YouTube · Security Weekly - A CRA Resource
25 YouTube-Aufrufe
Twenty-five years since 9/11, and we open by marking it properly — the people who didn't come home, and the survivors and responders still carrying it, physically and mentally, a quarter of a century on.

Then we get to work.

Shift-left didn't fail. The starting line moved. AI coding agents now read the issue, write the code, pick the dependencies and open the pull request — so the earliest trust boundary isn't your first commit any more, it's the moment an agent gets context and authority. Most of us haven't moved our controls with it.

Unit 42 pull the lid off a pay-per-install operation running out of eleven gaming YouTube channels, with over ten thousand loader samples underneath it. Every layer built to look too boring to escalate. When your analyst closes that alert as adware, they may have just closed three separate compromises.

Google's threat tracker: a credential-harvesting campaign built and run in under six hours, with Markdown files as attacker playbooks. And malware carrying prompt-injection text designed to make your LLM scanner refuse to look at it — because a refusal that reads as "clean" is a free pass.

A CVSS 10 in Gemini CLI that never touched the model. No prompt, no injection, no tool call. The attacker just turned up before the sandbox did.

The first ever Take It Down Act sentencing — handled carefully, with what you actually do if someone tells you something, and a proper shout-out to Dale, the Cyber Safety Guy, whose work every parent with a teenager online should have bookmarked.

Two hundred and sixty-three million dollars walks out of a Bitcoin sidechain and then walks back in. Nobody stole the keys. They just convinced the system to sign a lie.

Anthropic's 154-page threat report. And an alignment lead who puts extinction odds above ten percent.

All that, plus Josh Marpet's take, on Security Weekly News #615.

Visit https://www.securityweekly.com/swn for all the latest episodes!

Show Notes: https://securityweekly.com/swn-615
Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf youtube.com.
↗ Original-Artikel auf youtube.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
2 Quellen
Microsoft admits Windows 11’s biggest September update is breaking multiple features, days after it warned users not to delay updates
1 Quelle
The Gemini desktop app is now available for Windows
1 Quelle
Windows 11 just dropped the tool ransomware abused, Microsoft says don’t restore WMIC