Ch12 安全与治理¶
Agent 权限越大,安全责任越重:凭据、审计、合规
本章收录 130 篇实体,按深度递增排列。
本章导航¶
| Level | 含义 | 篇数 |
|---|---|---|
| ⭐ 入门 | 零基础可读 | 10 |
| ⭐⭐ 工程师 | 需编程基础 | 118 |
| ⭐⭐⭐⭐ 科学家 | 需研究背景 | 1 |
| ⭐⭐⭐⭐⭐ 大师 | 前沿/哲学 | 1 |
导读¶
AI Agent 正在获得越来越多的权限——执行代码、访问数据库、发送邮件、操作文件系统。
权限越大,攻击面越大。本章覆盖 Agent 安全的完整谱系:凭据管理(1Password 的机器身份方案)、Prompt 注入防御、供应链攻击(TanStack npm 事件)、恶意软件分析(GlassWASM WebAssembly 恶意代码)、逆向工程(Themida 脱壳)。
你还会看到 100 万+ AI 服务暴露在公网的扫描报告,以及 Google 与国际特赦组织联手打击商业间谍软件的行动。
安全不是"做完再考虑"的事——它应该内嵌在 Agent 架构的第一天。
本章内容¶
- 001. CISA urges critical infrastructure firms to 'fortify' before it's too late | Cybersecurity Dive
- 002. Token 撤销触发设备擦除的安全漏洞
- 003. A Framework for AI Threat Readiness
- 004. From SSH to REST: A Security-Driven Modernization of Slack's EMR Data Pipelines
- 005. Mozilla warns UK: Breaking VPNs will not magically fix Britain's age-check mess
- 006. Offensive Security Blog
- 007. Sandworm Hackers Shift From IT Breaches to Critical OT Targets
- 008. 5 Things to Know about the CLARITY Act
- 009. fedora hummingbird brings the container security model to a linux host os
- 010. 推出-amazon-bedrock-managed-knowledge-base助力企业人工智能应用程序更快速更准确
- 011. Mythos finds a curl vulnerability
- 012. 飞来汇借助 AWS Security Agent 构建跨境支付应用的智能安全防线
- 013. Canvas Hackers ShinyHunters Say Their Official Domain Was Suspended
- 014. Hermes Agent v0.14.0 核心架构与快速上手
- 015. Bleeding Llama:Ollama 未授权内存泄漏漏洞
- 016. SHub Reaper: macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain
- 017. LLMReaper - DOM Based AI Conversation Exfiltration via Browser Extensions
- 018. Resecurity | CVE-2026-20182: Unauthenticated Cisco SD-WAN Control-Plane Compromise via vHub Authentication Bypass
- 019. Towards Native Post-Quantum Private ETH - Privacy - Ethereum Research
- 020. Static Devirtualization of Themida
- 021. Static Devirtualization 2024
- 022. What My Privacy and Security Stack Actually Looks Like
- 023. Alliance for Critical Infrastructure (ACI): US Critical Infrastructure Cybersecurity Coalition
- 024. How an image could compromise your
- 025. Static Devirtualization of Themida
- 026. Inference Theft as AI Endpoint Attack Surface — Vercel Token Theft Defense 2026
- 027. Apple corecrypto formal verification blueprint — post-quantum ML-KEM/ML-DSA in iMessage
- 028. OpenClaw 安全和功能增强实践
- 029. xz-utils Backdoor 2 Years On — Maintainer Trust Hijack Pattern Beyond CVE Scanners
- 030. Disgruntled researcher releases two more Microsoft zero-days
- 031. Mythos 对企业安全架构影响的思考
- 032. Where OpenClaw Security Is Heading — OpenClaw Blog
- 033. Disgruntled researcher releases two more Microsoft zero-days
- 034. Canvas Breach Disrupts Schools & Colleges Nationwide
- 035. Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access
- 036. 别让你的 Amazon Bedrock 模型为他人打工——API 调用安全防护指南
- 037. 首篇VLA安全综述出炉:机器人听懂指令,安全评测也要升级
- 038. Postmortem: TanStack npm supply-chain compromise | TanStack Blog
- 039. Canvas Hackers ShinyHunters Say Their Official Domain Was Suspended
- 040. 100万+AI服务暴露在公网——HackerNews扫描报告
- 041. Optimize blueprint extraction accuracy in Amazon Bedrock Data Automation
- 042. Disgruntled researcher releases two more Microsoft zero-days
- 043. How Amazon Bedrock catches AI-generated phishing
- 044. GitLab CI/CD Kill Chain Audit — Black Hills InfoSec 2026 大规模审计研究
- 045. Cyberscammers are bypassing banks' security with illicit tools sold on Telegram
- 046. INTERPOL Operation Ramz MENA Cybercrime Networks
- 047. AI in Cybersecurity Training Resources | SANS Institute
- 048. Canvas LMS 攻击者 ShinyHunters 官方域名被暂停:转向暗网的运营安全转向
- 049. U of T AI Worm:CleverHans Lab 展示可自适应的 AI 蠕虫威胁
- 050. Securing AI Agents and Machine Identities
- 051. A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens
- 052. ICO fines South Staffordshire £963K over 2022 breach
- 053. NGINX Rift: Achieving NGINX Remote Code Execution via an 18-Year-Old Vulnerability | depthfirst
- 054. ICO 对 South Staffordshire 处以 96.3 万英镑罚款:2022 年 Cl0p 勒索软件攻击暴露的安全失败
- 055. Fake Job Interview Apps Drop JobStealer Malware on Windows and macOS
- 056. bagel — Fleet 级 Secret Scanning 守护开发工作站
- 057. ICO fines Cl0p victim South Staffs Water over data breach
- 058. A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens
- 059. Pwn2Own Berlin 2026, Day Three: DEVCORE Crowned Master of Pwn, $1.298 Million Total
- 060. Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming
- 061. Autonomous Vulnerability Hunting with MCP
- 062. Sandworm Hackers Shift From IT Breaches to Critical OT Targets
- 063. GlassWASM: WebAssembly Malware Found in Trojanized Open VSX Extensions
- 064. Static Devirtualization of Themida
- 065. NIST SP 800-213r1 — IoT Product Cybersecurity Guidelines
- 066. CVE-2026-20182: Unauthenticated Cisco SD-WAN Control Plane Compromise via vHub Authentication Bypass
- 067. Stealing Passwords via HTML Injection Under a Strict CSP
- 068. TeamPCP Claims Sale of Mistral AI Repositories Amid Mini Shai-Hulud Attack
- 069. Meta U-turns on encryption push for Instagram as DMs go plaintext
- 070. OpenAI launches Daybreak to combat cyber threats
- 071. AI Voice Cloning: The Technology Behind It, Who's Building It, and Where It's Headed
- 072. Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt
- 073. Temporarily disabling new user registrations
- 074. Google and Amnesty International teamed up to make Android spyware detectable
- 075. RFC 9958: Post-Quantum Cryptography for Engineers
- 076. Thinkst Package Proxy: Supply Chain Safety Checks
- 077. Disgruntled researcher releases two more Microsoft zero-days
- 078. Funnel Builder 漏洞正被利用于 WooCommerce 支付 skimming
- 079. The down fall of bug bounties
- 080. Mozilla warns UK: Breaking VPNs will not magically fix Britain's age-check mess
- 081. JetBrains Marketplace Ecosystem Security Update: Malicious AI Plugins
- 082. LLMReaper: 浏览器扩展的对话窃取攻击
- 083. AI Detection and Response Aidr a Zero Impact Operating Model
- 084. Exploiting vulnerabilities in Johnson & Johnson web apps
- 085. Romanian Man Faces Up to 30 Years in US Prison Over Vishing Scams
- 086. Milvus 3.0 聚合下推:3 层隔离、2 条路径、4 倍安全因子
- 087. GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos
- 088. Hackers accessed BWH Hotels reservation system for months
- 089. Getting a CVE Without Shipping Slop
- 090. The IT and security field guide to AI adoption | Tines
- 091. Unlocking the Cloudflare app ecosystem with OAuth for all
- 092. Mythos for Offensive Security: XBOW's Evaluation
- 093. Fedora Hummingbird brings the container security model to a Linux host OS
- 094. ShinyHunters hack 7-Eleven: franchisee data and Salesforce records exposed
- 095. GitHub Secret Scanning: AI/ML 驱动的大规模误报降低
- 096. 飞连 AI 办公安全体系 1+3+N 架构
- 097. Meet Bluekit: The AI-Powered All-in-One Phishing Kit
- 098. Building is just the beginning: Introducing Discoverability | Lovable
- 099. Scammers Send Physical Phishing Letters to Steal Ledger Wallet Seed Phrases
- 100. Cyberscammers are bypassing banks' security with illicit tools sold on Telegram
- 101. How Unified EDR and ITDR Stop Attacks Before They Spread
- 102. Guide to Security Operations at Machine Speed
- 103. Discord 全平台端到端加密
- 104. Nikesh Arora 20VC 访谈:Token 定价、FDE、SaaS→AI 转型与记忆护城河
- 105. Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming
- 106. Forward launches Predict to verify network changes before they reach production - SiliconANGLE
- 107. Static Devirtualization of Themida
- 108. CyberSecQwen-4B
- 109. Mystery Microsoft bug leaker keeps the zero-days coming
- 110. GitHub Breached — Employee Device Hack Led to Exfiltration
- 111. AI phishing attacks are on the rise — Are you prepared? | Bitwarden
- 112. cPanel, WHM Release Fixes for Three New Vulnerabilities — Patch Now
- 113. Semgrep Intercom Php Security
- 114. peerd: 浏览器原生的 AI Agent Harness
- 115. A DOD contractor’s API flaw exposed military course data and service member records
- 116. OpenSandbox:阿里开源的云端 Agent 安全沙箱(凭据 Vault + egress sidecar)
- 117. Anthropic's bug-hunting Mythos was greatest marketing stunt ever, says cURL creator
- 118. Incendium Fuzzing Ms Rpc
- 119. How Semgrep Cut Taint Analysis Time by 75%
- 120. On Post-Quantum Security Adoption
- 121. Jane Street — 形式化方法与编程的未来
- 122. Semgrep Intercom Php Supply Chain
- 123. 中国用户安全高性能访问海外 Bedrock
- 124. Drupal to Release Urgent Core Security Updates on May 20, Sites Told to Prepare
- 125. Cyberscammers are bypassing banks’ security with illicit tools sold on Telegram
- 126. DeepSecBench:评估 AI 模型在网络安全漏洞发现中的性能
- 127. Agent 审计:从海量噪音中捞出真风险
- 128. A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens
- 129. U of T researchers demonstrate AI worm: self-spreading malware using open-weight models
- 130. Japan’s PM orders cybersecurity review to defend against Anthropic Mythos