Workflow
网络安全
icon
Search documents
360安全专家谈快手遭大面积入侵:暴露出极端安全攻击风控防御体系的漏洞。
Xin Lang Cai Jing· 2025-12-23 02:45
Core Viewpoint - Kuaishou experienced a severe attack from black and gray market hackers, leading to a significant security breach within a short time frame of 60 to 90 minutes, exposing vulnerabilities in its risk control system [1][3]. Group 1: Attack Details - Hackers infiltrated Kuaishou's system using approximately 17,000 zombie accounts to create live streaming rooms that broadcasted illegal content, including pornography, violence, and terrorism, with some streams attracting nearly 100,000 viewers [1][2]. - The attack is believed to be organized and premeditated, exploiting vulnerabilities in the live streaming interface to bypass Kuaishou's real-name authentication and content review processes [3]. Group 2: Industry Implications - The incident highlights a growing trend in internet black and gray market attacks, characterized by increased concealment, enhanced intelligence, and deeper industrialization, particularly with the rise of artificial intelligence [3][4]. - As AI technology evolves, the nature of cyber attacks is shifting from traditional human confrontations to automated battles between intelligent agents, posing a broader challenge to the digital society [4]. Group 3: Security Recommendations - In response to the new security challenges posed by the widespread use of AI in black and gray market activities, organizations need to transition from passive defense to a systematic and intelligent security capability [2][3]. - 360 Digital Security Group has developed a security defense solution tailored for the intelligent era, leveraging its expertise in both security and AI [2].
快手遭黑产攻击瘫痪,“自动化攻击” 时代网络安全怎么做?
Tai Mei Ti A P P· 2025-12-23 02:35
12月22日22时许,国内知名短视频平台快手遭遇黑灰产猛烈攻击。在短短60到90分钟内,黑客组织通过 技术手段侵入快手系统,导致整个平台安全体系陷入瘫痪。攻击者利用约1.7万个僵尸账号开设直播 间,大量播放包含色情、暴力、恐怖等违规内容,有的直播间单场观看量甚至逼近10万人。 值得注意的是,这些直播中还隐藏着病毒链接。许多用户点入后,微信账号即被盗取,不法分子随即向 账号好友发送借款请求,实施诈骗。目前快手平台已紧急关闭和下架绝大多数直播内容,但事件造成的 用户隐私泄露和财产损失已难以挽回。平台方提醒用户保持警惕,切勿轻信异常链接,防止上当受骗。 从22时左右异常初现,到大量违规内容刷屏直播间,再到平台紧急启动最高级别应急响应,这场持续近 两小时的网络攻防战,不仅短暂打乱了平台的正常运营节奏,更将短视频行业的安全防御困境再次推向 公众视野。 事件还原 不同于传统网络攻击的"瞬间瘫痪",此次针对快手的攻击呈现出"精准突袭、梯次推进"的特征,从用户 感知异常到平台完成核心防御,形成了清晰的时间线脉络。结合快手官方通报、用户反馈及行业监测数 据,此次事件的关键节点可精准梳理为四个阶段。 第一阶段为预警潜伏期(大概在 ...
三六零获评年度卓越人工智能应用企业,周鸿祎荣膺年度卓越领袖?
Ge Long Hui· 2025-12-23 02:32
Core Viewpoint - The company, 360, has been recognized as the "Outstanding AI Application Enterprise of the Year" and its CEO Zhou Hongyi as the "Outstanding Leader of the Year" at the annual "Golden Award" selection by Gelonghui, indicating a successful transition from a traditional internet security company to an AI application platform [1] Group 1: AI Strategy and Growth - The company has established a dual strategy of "AI + Security," integrating AI technology deeply into its security business while enhancing the credibility of AI products through its security capabilities [3][4] - The global AI investment is surging, with IDC projecting a total investment of $315.8 billion in AI IT by 2024, and the Chinese market expected to grow at a compound annual growth rate (CAGR) of 35.2% over five years [3] - The company’s AI applications are focused on practical implementations rather than competing directly with major players on model size, emphasizing a more grounded approach to AI development [5] Group 2: AI Product Development - The company has developed its own large model, "360 Zhinao," which ranks among the top domestic models in comprehensive capabilities, particularly excelling in mathematical reasoning [6] - The "Nano AI Search Super Intelligent Agent" is a flagship product that leverages multi-platform information and model collaboration to execute complex tasks, positioning the company favorably in the AI search market [8] - The company’s internet value-added services generated revenue of 1.379 billion yuan in 2024, with a significant year-on-year growth of 253.25% in value-added services [9] Group 3: Security Business and Digital Transformation - The company has a strong foundation in security, having covered 1.5 billion terminals globally, and is expanding its offerings to include AI-driven security solutions for government and enterprise clients [10] - The introduction of the "360 Security Intelligent Agent" has been recognized in multiple core areas of security operations and compliance, showcasing the company's commitment to enhancing its digital security capabilities [10][11] - The company has secured contracts worth over 300 million yuan for AI and digital security projects, highlighting its strong B-end implementation capabilities [12] Group 4: Financial Performance and Future Outlook - The company reported a revenue of 2.241 billion yuan in Q3 2025, reflecting a year-on-year growth of 16.88%, indicating a significant improvement in financial performance [13] - The company is expected to achieve revenues of 8.637 billion yuan, 9.695 billion yuan, and 10.918 billion yuan from 2025 to 2027, with corresponding growth rates of 8.7%, 12.2%, and 12.6% [13] - The company maintains a high R&D expense ratio of nearly 40%, significantly above the industry average, which is expected to solidify its technological advantages [13]
突发!快手深夜变“快播”,10 个直播七八个涉黄,网友称举报都没用。官方称遭攻击已报警!
程序员的那些事· 2025-12-23 02:24
"快手疯了吗?同事告诉我的,我不信,结果[傻眼],这也太辣眼睛了" 一、深夜惊魂:刷直播刷出 "不雅盲盒" 12 月 22 日晚 23 点左右,不少快手用户被眼前的画面吓了一跳。 原本刷着搞笑、生活类直播的屏幕上,突然冒出大量陌生直播间,点进去全是露骨表演和淫秽影片。 有网友表示,他连续刷到 10 多场这类直播,其中一个在线人数达 10 万,播了 20 多分钟才被关闭。 华商报大风新闻记者看到,有的涉黄直播间主播裸露敏感部位跳舞,评论中还有人称"过了今晚就没机会了", 直播间观看人数超 8 万人,不断有网友刷礼物,评论多是起哄让女主播脱衣服的。 还有直播间男主播播放淫秽视频,拿着月饼说自己是带货直播,"不这样就被封了,就彻底看不成了。" 还有女 主播在直播中裸露并搔首弄姿说:"下播了再加,下播了再弄。" 更让用户崩溃的是举报失灵:点击举报按钮要么提示 "人数过多",要么提交后毫无反应,有网友吐槽 "像闯进 了无人管的灰色地带"。 直到 23 日 0 时 30 分,快手干脆关闭了整个直播频道,页面显示 "没有找到内容",短视频、提现功能也出现 短暂波动,凌晨 0 时 45 分才恢复正常。 二、技术拆解:黑灰产的 ...
快手开盘股价直线下跌,黑灰产攻击后冲上苹果免费榜第二
Di Yi Cai Jing· 2025-12-23 02:03
快手此前建立了由安全委员会决策层、安全委员会办公室、关联部门三个层级组成的安全组织保障架构。 12月23日,港股开盘,快手(1024.HK)股价直线下跌。截至发稿,股价62.9港元,跌5.7%。另外,网络安全指数(884133.W)上涨,截至发稿,该指数已 涨0.66%。 消息面上,22日22时左右,快手平台多个直播间出现违规内容。据快手官方向第一财经确认:平台遭到黑灰产攻击,目前已紧急处理修复中,平台坚决抵制 违规内容,相应情况已上报给相关部门,并向公安机关报警。截至发稿,快手已冲至苹果AppStore免费APP下载榜第二。 据记者了解,22日22:00至23:30,快手平台上的违规直播情况达高峰;23日00:15左右,快手强制关闭直播功能,部分账号被封禁。 奇安信安全专家汪列军表示,此次攻击之所以能造成大规模破坏,核心原因在于黑灰产已全面迈入"自动化攻击" 时代,而平台仍依赖传统人工防御模式。 黑客借助自动化工具批量注册、操控僵尸号,实现违规内容的秒级发布与扩散,这种规模化攻击完全超出人工审核的应对极限。传统人工审核存在天然滞后 性,面对每秒数十条的违规内容洪流,往往陷入"封禁不及新增" 的被动局面,即便 ...
A股高开,交建股份、祥源文旅大幅低开
Di Yi Cai Jing Zi Xun· 2025-12-23 01:55
本文字数:565,阅读时长大约1分钟 2025.12.23 作者 |一财阿驴 09:29海南板块延续强势,海汽集团、海南瑞泽3连板,海峡股份涨停,康芝药业、海南机场、海南海 药、神农种业等多股高开。 09:27广期所铂、钯期货主力合约均打开涨停板。 09:25 A股开盘丨三大指数集体高开 沪指高开0.04%,深成指高开0.05%,创业板指高开0.14%。 | 代码 | 名称 | 两日图 | 现价 | 涨跌 | 涨跌幅 | | --- | --- | --- | --- | --- | --- | | 000001 | 上证指数 | Hunt | 3919.1 | | 0,04% | | 399001 | 深证成指 | Mr. | 13338.93 | 6.20 | 0.05% | | 399006 | 创业板指 | 5 | 3196.31 | 4.32 | 0.14% | 盘面上,海南自贸区概念股持续发酵,乳业、光伏、黄金、网络安全题材活跃。核聚变、算力硬件等概 念股调整。 个股方面,交建股份、祥源文旅分别低开5.9%、3.78%。消息面上,12月22日晚,两家公司同步公告, 实际控制人俞发祥因涉嫌犯罪被采取 ...
三六零获评年度卓越人工智能应用企业,周鸿祎荣膺年度卓越领袖
Ge Long Hui A P P· 2025-12-23 01:50
Core Viewpoint - The company has been recognized for its achievements in AI applications, marking a significant transformation from a traditional software vendor to an AI application platform, which provides a basis for re-evaluation in the market [1] Group 1: AI Strategy and Growth - The company has established a dual strategy of "AI + Security," integrating AI technology deeply into its security business while enhancing the credibility of AI products through its security capabilities [3][4] - The company’s approach to AI is application-oriented, focusing on practical implementations rather than competing directly with major players on model size or general capabilities [5] - The company’s self-developed large model, "360智脑," has been continuously iterated, achieving top-tier performance in domestic evaluations, particularly in mathematical reasoning [6][8] Group 2: Product Development and Market Position - The "Nano AI Search Super Intelligent Agent" is a flagship product that leverages multi-platform information to complete complex tasks, positioning the company advantageously in the competitive AI search market [9] - The company’s internet value-added services generated revenue of 1.379 billion yuan in 2024, with a significant year-on-year growth of 253.25% in other value-added services, indicating a shift in revenue structure towards AI applications [10] Group 3: Security Capabilities and Digital Transformation - The company has a strong foundation in security, having covered 1.5 billion terminals globally, and is now enhancing its digital security capabilities through the "360 Security Intelligent Agent" [11][12] - The company has secured contracts exceeding 300 million yuan for AI and digital security projects, demonstrating its strong B-end implementation capabilities [13] Group 4: Financial Performance and Future Outlook - In Q3 2025, the company reported revenues of 2.241 billion yuan, a year-on-year increase of 16.88%, and a net profit of 160 million yuan, marking a significant turnaround [15] - The company is expected to see continued revenue growth, with projections of 8.7% to 12.6% annual growth from 2025 to 2027, driven primarily by its AI business [15][16]
快手平台突遭黑灰产攻击 奇安信安全专家汪列军:规模化攻击超出人工审核的应对极限
Xin Lang Ke Ji· 2025-12-23 01:21
Group 1 - Kuaishou experienced a severe attack from hacker organizations, leading to a complete breakdown of its security system within 60 to 90 minutes [1] - Attackers utilized approximately 17,000 zombie accounts to create live streaming rooms, broadcasting a large volume of illegal content, with some streams nearing 100,000 viewers [1] - The core reason for the extensive damage was identified as the transition of black and gray industries into an "automated attack" era, while Kuaishou relied on traditional manual defense methods [1] Group 2 - Experts emphasized that network security upgrades should not only focus on external attack defenses but also address risks from internal vulnerabilities [2] - Incidents of data leaks, internal account theft, and unauthorized operations have become frequent, with some attacks leveraging internal personnel and permission vulnerabilities [2] - Companies are advised to adopt a "defense against both internal and external threats" approach, integrating internal defenses into the overall security system, particularly focusing on "insider threat" prevention and permission management [2]
快手回应:色情直播遭到黑灰产攻击(T0级网安事故)
Xin Lang Cai Jing· 2025-12-23 01:17
Group 1 - The core incident involves a surge of pornographic content on Kuaishou's live streaming platform, with some streams attracting over 100,000 viewers [1][32] - The timeline of the event shows that reports of abnormal live streams began at 18:00 on December 22, peaking between 22:00 and 23:30, before Kuaishou enforced a shutdown at around 00:15 on December 23 [2][32] - The platform's response included a claim of being attacked by organized black and gray market entities, with immediate actions taken to address the situation [15][44] Group 2 - The official explanation categorizes the incident as an organized attack, suggesting a significant scale that could bypass content moderation systems [24][54] - External analysts have raised concerns about Kuaishou's long-standing content governance issues, linking the incident to previous failures in managing inappropriate content [26][56] - There is speculation that the attack may have exploited existing vulnerabilities in Kuaishou's real-time content review and emergency response systems [28][58] Group 3 - The incident has sparked rumors about potential financial theft through malicious links associated with Kuaishou, which have been identified as false [4][48] - The event has highlighted the ongoing challenges in balancing user growth with regulatory compliance, leading to potential oversight in content moderation [27][57] - Kuaishou has previously reported its governance achievements, including the closure of over 1,500 violating live streams daily and penalties against more than 37,000 incentivized streamers this year [28][58]
色情内容刷屏!快手深夜回应:遭到灰黑产攻击 已报警
Xin Lang Ke Ji· 2025-12-22 22:55
今天凌晨,快手官方紧急回应称,当晚22时左右,平台遭到黑灰产攻击,目前已紧急处理修复中,平台 坚决抵制违规内容,相应情况已上报给相关部门,并向公安机关报警。 直播间突然出现大量色情内容 据大量用户反馈,昨晚10点,不少正在浏览快手直播的用户发现异常:原本正常的直播间,在点击推荐 直播页面后均出现不同程度的色情内容,部分直播间观看量直飙5万+。 昨晚11点半,快手方面开始大规模查删此类视频。直播频道被强制关闭并显示"服务器繁忙,请稍后重 试"。 昨晚,快手突发严重网络安全事件——大量露骨色情内容短时间内侵入多个直播间,引发用户大量围 观,部分直播间人数飙至5万+,该事件时长超过1小时。 十余位高管先后离职卸任,多人为技术岗 实际上,如今的快手正经历着一场管理层更迭和战略重塑。 据媒体不完全统计,自2023年10月宿华卸任快手董事长,由程一笑接任以来,快手已有超过十位副总裁 级别以上的高管离职或卸任,且多人为技术岗高管。 其中包括:原数据平台负责人董西成、磁力引擎副总裁袁帅、安全合规线负责人余海波、国际电商算法 负责人王犇、多模态负责人王仲远等。今年上半年,快手高级副总裁、研发线负责人于冰也已转任公司 技术顾问。 ...