Threats

OpenAI pledges $1B to provide resources, training for frontline cyber defenders
OpenAI announced on Thursday that it will commit $1 billion to provide subsidized access and training for frontline cyber defenders, helping small IT security teams use cutting-edge AI to protect critical infrastructure. The project, named Daybreak for Frontline Defenders, will first run a six-month pilot in partnership with MS-ISAC and will cover areas such as healthcare and open-source maintainers.

Government, industry partner to shut down long-running Sality botnet
US law enforcement agencies and cybersecurity company CrowdStrike took joint action on Monday to dismantle the Russian Sality botnet, which had been operating for 23 years. The botnet had been in continuous operation since 2003, involving criminal activities such as spam, credential theft, DDoS attacks, and cryptocurrency hijacking. During this operation, US authorities seized related domains, CrowdStrike assisted in disconnecting infected devices from the network, and investigators from Bulgaria, Hungary, and Romania also carried out simultaneous crackdowns in their respective jurisdictions.

Frontier AI tipping the scales toward cyber adversaries
At a media briefing in New York, Palo Alto Networks disclosed that after participating in Anthropic's Project Glasswing and OpenAI's Daybreak project, it found that frontier AI can compress a year's worth of vulnerability discovery work into months, and a single attacker with AI can possess nation-state-level attack capabilities. The 3-to-5-month attack window the company previously warned about is becoming a reality, with recent observations of attackers exploiting 50 vulnerabilities to complete a full attack chain within 10 hours.

数据激增为何反而模糊了企业的风险视野
现代安全团队掌握的数据量远超十年前,但许多企业反而更难回答“当前暴露在哪里”这一关键问题。碎片化的安全架构、各自为政的工具与评分体系,以及第三方供应商的介入,共同造成了风险盲区。SpearTip 安全运营中心负责人 DJ Hoeksema 结合案例指出,资产清单缺失、单点修复遗漏横向移动、供应商风险难以自测等问题普遍存在。他建议企业从明确自身威胁画像入手,整合数据与统一风险评分,以清晰视野支撑战略决策。