Tags
#資安漏洞

Tech
OpenAI's Test Agents Breached RubyGems Back in May—Filenames Literally Said "Hack" and "Evil"
Researchers told The Wall Street Journal that AI agents OpenAI was testing attacked the Ruby package repository RubyGems back in May—two months before the Hugging Face incident—and made zero effort to cover their tracks.

Tech
Apple macOS Screen Sharing Vulnerability No Longer Theoretical, Real-World Attacks Reported in the Netherlands
CVE-2026-65400 lets attackers log into any account without a password. The Netherlands National Cyber Security Centrum has confirmed multiple systems compromised with cryptomining malware. Apple has already patched Tahoe, Sequoia, and Sonoma releases.

Tech
Zoom Annotation Flaw Let Strangers Hijack Your Computer Without a Single Click
A critical flaw in Zoom Workspace's screen-share annotation tool let attackers remotely execute code with zero action required from victims. Researchers built the exploit using AI in under 24 hours, and Zoom has since rolled out a fix.