Anthropic's AI found 10,000 flaw candidates. Only 97 are patched. A single model can now spot critical software flaws faster than every developer on earth can fix them. https://t.co/MPj4s9rfQK
Google 把内部工程师的代码审查(Code Review)规范公开啦
这几乎是目前业界最顶级的标准
很多程序员只会写代码,但不知道怎么审代码,可以看看 Google 是怎么做的
1.双向指南:不仅教审查者怎么挑毛病,还教作者怎么写出容易通过的代码
2.术语科普:解释了 Google 内部常用的 LGTM(看起来不错)和 CL(变更列表)到底意味着什么
3.实战价值:这套规范不是理论,而是 Google 每一位工程师都在用的实际操作准则
如果你想提升团队的代码质量,或者想知道顶级大厂的开发门槛,这份文档必读!
https://t.co/OdaozRkMYn
How easy is CVE-2026-23918 to trigger?
🔸 One TCP connection.
🔸 Two frames.
🔸 HEADERS + immediate RST_STREAM (non-zero error code).
That’s it → double-free in mod_http2, worker crashes.
Researchers built a working RCE PoC using Apache’s fixed scoreboard + mmap allocator (default on Debian & official Docker).
If you’re on 2.4.66 with mod_http2 + threaded MPM: patch to 2.4.67 now. (prefork MPM is safe)
🚨 QLNX, a previously undocumented #Linux RAT, is targeting developers and DevOps systems to steal npm, PyPI, AWS, Kubernetes, Docker, and CI/CD credentials.
The malware uses fileless execution, PAM backdoors, eBPF rootkits, and 58 remote commands to maintain covert access and hijack software supply chains.
Learn more about QLNX here: https://t.co/dZLOWzXdGi
We uncovered a new Brazilian banking trojan campaign: TCLBANKER.
What makes TCLBANKER notable isn’t just the malware itself, but how it spreads.
The campaign uses compromised WhatsApp and Outlook accounts to propagate through trusted user relationships, deploys targeted banking overlays, and incorporates anti-analysis techniques designed to evade detection.
For defenders, it’s another example of malware increasingly blending into legitimate user behavior and everyday communication channels, making detection harder and trust easier to exploit.
Our latest research breaks down the infection chain, propagation methods, evasion tactics, and detection opportunities observed across the campaign.
Read the full analysis: https://t.co/9z47oaEWdD
The attack on the Trellix source code repository disclosed last week has been claimed by the RansomHouse threat group, which leaked a small set of images as proof of the intrusion.
https://t.co/uDQuMJXewY
📢⚠️ Researchers have uncovered #ClaudeBleed, a flaw in Anthropic’s Claude for Chrome extension that could let hackers hijack the AI assistant, steal Google Drive files, and access Gmail data.
Read more: https://t.co/P3VPRxK1GQ
#CyberSecurity#AI#ClaudeAI#Chrome#Anthropic
🛑 REMINDER: Today, May 8, 2026 — #Instagram officially disabled end-to-end encryption for Direct Messages.
• Meta can now read all your chats.
• Download everything NOW or lose it.
• Switch to WhatsApp for encryption.
Details: https://t.co/qHKNzvEdTm
Señores @ANLA_Col ¿Donde puedo obtener el listado actualizado de Certificados de Emisiones por Prueba Dinámica para consulta de las autoridades competentes? El listado disponible en su sitio web se encuentra desactualizado desde Mayo 2024: https://t.co/eZupsgH9vy
Google Threat Intelligence Group is tracking an active supply chain attack 🔎
North Korea-nexus actor UNC1069 compromised the "axios" NPM package (v1.14.1 & 0.30.4), deploying the WAVESHAPER.V2 backdoor across Windows, macOS, and Linux.
Learn more: https://t.co/pII35aPpRA
⚡ WARNING - Axios npm (83M weekly downloads) was compromised, turning installs into a malware delivery path.
Versions 1.14.1 and 0.30.4 pulled a fake dependency that dropped a cross-platform RAT, then erased evidence. Published using stolen maintainer credentials.
🔗 What happened and how the attack worked → https://t.co/6BquPCKtID