Workflow
网络安全
icon
Search documents
周鸿祎“评价一切”:DeepSeek、Manus、华为、英伟达、智能眼镜……
Xin Lang Ke Ji· 2025-07-23 09:09
Group 1: Development of Large Models and Intelligent Agents - Current large models are limited and primarily function as chatbots, lacking true productivity capabilities [3] - Intelligent agents complement large models by executing complex tasks autonomously, enhancing enterprise applications [3] - Future intelligent agents should specialize in different industries rather than being generalized, akin to virtual consultants [3][4] Group 2: Business Model Challenges - The advertising model for AI, as seen with Manus, is not sustainable due to high operational costs and user demands [5] - Direct user charging may become necessary as AI task completion requires significantly more resources than traditional chat interactions [5] Group 3: Domestic Chip Procurement - The company is shifting towards domestic chip procurement, particularly from Huawei, despite acknowledging the performance gap with NVIDIA [6] - Emphasis is placed on the necessity of using domestic chips to drive improvement and innovation [6] Group 4: DeepSeek and Open Source Value - DeepSeek's recent traffic decline is attributed to its focus on AGI rather than app performance, with its true value lying in third-party applications [6] - The open-source nature of DeepSeek is seen as a strategic advantage against monopolistic practices [6][7] Group 5: Cybersecurity Risks - The deployment of large models introduces significant security risks, including hallucinations, lowered attack barriers, and advanced threats from hackers [8][9] - The company is developing solutions to counter these risks, including intelligent agents for real-time defense and monitoring [9] Group 6: AI Hardware Development - Upcoming AI hardware includes an AI recording pen and smart glasses, with the latter requiring a display to enhance functionality [10] - The company critiques the practicality of AI glasses without display features, emphasizing the need for diverse functionalities [10] Group 7: Commercialization of Intelligent Agents - There is a strong domestic market potential for intelligent agents, particularly for small and medium enterprises [10] - The company aims to lower costs and enable personalized intelligent agent creation for individual users [10]
微软服务器软件遭到大规模“网络间谍活动”,外交部回应
news flash· 2025-07-23 07:46
Core Viewpoint - The Chinese government emphasizes the importance of international cooperation in addressing cybersecurity challenges, while rejecting allegations of hacking activities against China [1] Group 1 - The Chinese Foreign Ministry spokesperson, Guo Jia Kun, stated that they are unaware of the specific situation regarding Microsoft's server software being targeted by large-scale cyber espionage [1] - The spokesperson reiterated that cybersecurity is a common challenge faced by all countries and should be addressed through dialogue and cooperation [1] - China consistently opposes and legally combats hacking activities, while also opposing the use of cybersecurity issues to smear the country [1]
周鸿祎:大模型降低了使用门槛,也降低了被攻击门槛
Xin Lang Ke Ji· 2025-07-23 03:26
Core Insights - The 2025 China Internet Conference highlighted significant risks associated with large models in practical applications, as discussed by Zhou Hongyi, founder of 360 Group [1][2]. Group 1: Risks Identified - The first major risk is that large models can produce errors or "hallucinations," leading to potentially dangerous outcomes when integrated into industrial production and government operations [1][2]. - The second risk involves the lowered barrier for individuals to attack AI systems, as even those without programming knowledge can manipulate large models to execute harmful commands, such as "injection attacks" [2]. - The third risk pertains to advanced threats at a national level, where hackers can embed their skills into large models, allowing them to control multiple AI agents simultaneously, thus transforming the landscape of cybersecurity [2][3]. Group 2: Proposed Solutions - In response to these risks, 360 Group is developing intelligent security agents to provide real-time detection and defense against attacks, effectively using algorithms to counteract other algorithms [3]. - Additionally, 360 has created a "Large Model Guardian," a specialized system designed to monitor the commands given to large models and assess the validity of their outputs, aiming to minimize the occurrence of errors [3].
直面掌门人|盛邦安全董事长权小文:不愿做外企大厂“螺丝钉”的网络工程师正在守护中国卫星互联网
2025年6月,我国成功将卫星互联网低轨04组卫星送入预定轨道。自2024年12月16日成功发射卫星互联 网低轨01组卫星以来,我国已完成四次低轨卫星发射任务,展现了我国在卫星互联网领域的快速进步。 这也让盛邦安全董事长权小文更加坚定了他多年前的选择,并对公司未来发展充满信心。 从"打短工"到行业标杆: 十五年前,面对老东家的不看好以及网络安全行业日益激烈的竞争,不甘心成为外企"螺丝钉"的权小文 毅然决定创业。面对完全市场化的残酷竞争,创业团队靠着"吹过的牛必须自己兑现"的信念,通过给大 厂"打零工"的方式,慢慢在业内找到一席之地,逐渐站稳了脚跟。 当谈及这段成功的创业历程时,权小文谦逊地表示,其中不乏"运气"的因素。他直言,正是因为工程师 的"迟钝"基因,公司与接连涌现的热门风口擦身而过,当行业回归理性时,迎来了真正属于公司的机 会。从漏洞扫描起步,盛邦安全的业务现已覆盖场景化安全、网络空间地图和卫星互联网安全,成为我 国网络信息安全行业的重要参与者。 工程师的长期主义突围战 "我们内部常讲'坚持长期主义',要敢于耐下心坐'冷板凳',唯有这样才能将机会做深做透,好多机会都 是熬出来的。"复盘创业历程,权小文 ...
事关服务器,微软又曝出严重安全漏洞
Guan Cha Zhe Wang· 2025-07-22 01:27
Core Insights - A significant security vulnerability in Microsoft's SharePoint server software has led to global cyberattacks targeting U.S. government agencies, universities, energy companies, and an Asian telecom company [1][2] - The attacks are classified as "zero-day attacks," exploiting previously unknown vulnerabilities, allowing attackers to impersonate trusted entities and potentially manipulate financial markets [1] - Microsoft has released a security patch for one version of the software but acknowledges that two other versions remain vulnerable and are still under development for patches [2] Group 1: Attack Details - Thousands of SharePoint servers are at risk, with evidence of attempts to exploit the vulnerability before the patch was released [2] - At least two U.S. federal agencies have reported server breaches, with one state government official noting that attackers compromised a public government document repository [3] - The Cybersecurity and Infrastructure Security Agency (CISA) received reports of the vulnerability and immediately contacted Microsoft for coordination [3] Group 2: Expert Opinions - Cybersecurity experts have labeled the vulnerability as severe, indicating that all users hosting SharePoint servers are at risk [2] - Concerns have been raised that even after applying patches, hackers may retain access due to previously obtained keys [2] - The White House's Cyber Safety Review Board has previously criticized Microsoft's security culture following past incidents, indicating ongoing concerns about the company's cybersecurity practices [3]
新加坡遭中国黑客网络攻击?中方:反对无端抹黑
Huan Qiu Shi Bao· 2025-07-21 22:54
Group 1 - Singapore is facing a "serious" cyber attack targeting critical infrastructure, attributed to a complex entity known as UNC3886 [1] - The attack is characterized as an "advanced persistent threat," aiming at high-value strategic targets, which could lead to espionage and significant disruption to Singapore's national security [1] - This is the first time Singapore has publicly named a hacker organization responsible for attacks, although the government did not directly link UNC3886 to any specific country [1] Group 2 - The Chinese Embassy in Singapore expressed strong discontent regarding media claims linking UNC3886 to China, emphasizing that China opposes any unfounded accusations [2] - The Embassy highlighted that China has also been a victim of cyber attacks, citing over 270,000 attacks on the Asian Winter Games information system and more than 1,300 instances of "advanced persistent threat" attacks in 2024 [2]
逾万家企业面临风险,微软服务器软件遭遇全球性网络攻击
Hua Er Jie Jian Wen· 2025-07-21 16:16
SharePoint是微软面向企业提供的文档管理和协作平台,广泛用于文件共享、项目管理、企业内部信息 门户等关键业务系统。全球成千上万家企业、机构、政府部门都在使用SharePoint。一旦被攻破,黑客 就可能进入整个组织的"神经中枢"——文档系统、用户权限、后台接口等全部暴露。 消息公布后,微软股价在周一美股盘初跌近0.9%,随后震荡转涨。 微软发布紧急补丁,但漏洞仍未彻底封堵 微软核心产品SharePoint文档系统遭大规模黑客攻击,安全研究人员警告全球可能出现大规模数据泄 露。 微软公司近日警告称,黑客正主动攻击其文档管理软件SharePoint的用户。据美国网络安全与基础设施 安全局(CISA)上周日警告,黑客正大规模利用SharePoint的安全漏洞对企业和政府机构展开攻击,可 能造成全球范围的大规模入侵。 攻击规模正在扩大,全球多个行业受波及 微软方面表示,当前黑客攻击的重点是那些自行在本地网络中部署SharePoint服务器的客户,而不是使 用微软托管服务的用户,这可能在一定程度上限制了影响范围。 根据美国网络安全公司Censys研究员Silas Cutler的估计,全球约有超过1万家企业部署了 ...
民航华东局组织对江西辖区开展网络安全联合检查
Core Viewpoint - The article discusses a joint cybersecurity inspection conducted by the Civil Aviation Administration in Jiangxi, aimed at enhancing network security capabilities and mitigating risks in the aviation sector [1][2][3] Group 1: Cybersecurity Inspection - A joint inspection team was formed to conduct a comprehensive cybersecurity check at Nanchang Changbei Airport and Jiangxi Airlines from July 14 to 16 [1] - The inspection involved reviewing compliance with cybersecurity laws and regulations, including on-site checks, system testing, and record verification [1][2] Group 2: Specific Requirements for Cybersecurity - Companies are required to enhance their political awareness and implement cybersecurity responsibilities, focusing on risk prevention and emergency response [2] - There is an emphasis on strengthening compliance construction by regularly updating information asset inventories and revising company regulations to align with the latest standards [2] - The need for robust emergency plans and drills was highlighted to improve the response capabilities of emergency teams in extreme situations [2] - Companies must also focus on data security and the management of passenger personal information throughout its lifecycle [2] Group 3: Future Actions and Collaboration - The inspection serves as both a "system check" for enterprises and a "precise empowerment" for regulatory teams, utilizing a collaborative approach to enhance regulatory effectiveness [3] - The Jiangxi Regulatory Bureau will continue to oversee cybersecurity efforts in the region, ensuring a stable and secure operational environment for the aviation sector [3]
隐藏在暗处的“技术后门”或成失泄密导火索 如何防范?安全提示来帮忙↓
Yang Shi Wang· 2025-07-21 06:54
Group 1 - The article emphasizes the significance of cybersecurity, highlighting that it affects personal privacy, corporate secrets, and national security [1] - It explains the concept of "technical backdoors," which allow unauthorized access to systems and sensitive information if not properly managed [1][3] - The article warns that foreign-produced chips, smart devices, or software may contain intentionally embedded backdoors that can be exploited for remote control or data theft [3] Group 2 - The national security agency suggests that sensitive positions should adopt domestically controlled chips and operating systems to mitigate risks from foreign hardware and software backdoors [5] - It recommends enhancing technical protective measures, such as patch strategies, regular operating system updates, and monitoring for unusual traffic to reduce potential security risks from technical backdoors [5] - Citizens and organizations are encouraged to cooperate with national security agencies in reporting suspicious activities related to cyber espionage [5]
微软(MSFT.US)漏洞引爆全球安全危机!超一万家企业服务器面临风险
智通财经网· 2025-07-21 04:04
Group 1 - Microsoft is facing a significant cybersecurity threat as its server software is under attack by unknown hackers, potentially leading to widespread security vulnerabilities globally [1] - The company has released a new security patch for SharePoint servers to mitigate active attacks on on-premises servers and is deploying additional fixes [1] - The U.S. Cybersecurity and Infrastructure Security Agency has confirmed the existence of the vulnerability, which allows hackers to access file systems, internal configurations, and execute code over the network [1] Group 2 - Over 10,000 companies globally using SharePoint servers are estimated to be at risk, with the highest number of affected enterprises located in the U.S., followed by the Netherlands, the UK, and Canada [1] - Cybersecurity experts warn that these vulnerabilities pose a serious threat, with indications that hackers are already exploiting them [1] - This incident is part of a series of recent cyberattacks on Microsoft, with previous warnings about Asian hackers targeting remote management tools and cloud applications [2]