by Tech Voice | Aug 26, 2026 | Connectivity, Cybersecurity
你最薄弱的一环,可能在别人的网络里 2023年,一个几乎只有IT才听说过的软件,成了史上最大规模数据泄露之一的入口。这个叫 MOVEit 的工具,本是企业用来安全传输文件的。攻击者只找到了它的一个漏洞,就通过这一个供应商,波及了至少2,773家机构,泄露了超过9,500万人的个人数据。而这些受害者中的绝大多数,自己根本没装过 MOVEit,他们只是,和装了它的人做了生意。(Swif)...
by Tech Voice | Aug 25, 2026 | Connectivity, Cybersecurity
Your Weakest Link Is Someone Else’s Network In 2023, a single piece of software almost no one outside IT had heard of became the doorway to one of the largest data breaches in history. The tool, MOVEit, was used by companies to transfer files securely. Attackers...
by Tech Voice | Aug 12, 2026 | Cybersecurity
当眼见不再为实:深度伪造诈骗,正盯上你的每一笔汇款 2024年初,跨国工程巨头 Arup 香港办公室的一名财务员工,接入了一场看似寻常的视频会议。屏幕上,公司的首席财务官在场,还有几位他认得的同事。对方要求他处理一笔紧急而机密的付款。他照做了,先后完成十五笔转账,合计约2亿港元(约2560万美元)。直到事后与总部核对,他才明白真相:那场会议里,没有一个人是真的。每一张脸、每一个声音,都是用公司公开发布的影像与音频合成出来的AI深度伪造。(CNN)...
by Tech Voice | Aug 11, 2026 | Cybersecurity
When Seeing Is No Longer Believing: Deepfake Fraud and Your Money In early 2024, a finance employee at the Hong Kong office of the global engineering firm Arup joined a routine video call. The chief financial officer was on screen, along with several colleagues he...
by Tech Voice | Jul 31, 2026 | Cybersecurity
无人操控的键盘:第一起完全由 AI 自动执行的勒索攻击 2026 年 6 月下旬,一个正在运行的生产数据库被入侵、被加密,随后被彻底摧毁。这起攻击真正的不同之处,不在于手法,而在于是谁,或者说是什么,动的手。有史以来第一次,键盘前没有任何人。整场攻击,由一个人工智能代理独立完成。 7 月 1 日,Sysdig 威胁研究团队公布了对代号 JADEPUFFER 攻击者的调查结果:这是首个有据可查的代理式勒索软件(agentic ransomware)案例,整场勒索行动由一个大语言模型从头到尾自主驱动。这个 AI...
by Tech Voice | Jul 30, 2026 | Cybersecurity
No Human at the Keyboard: The First AI-Run Ransomware Attack In late June 2026, a live production database was broken into, encrypted, and destroyed. What made this attack different was not the technique. It was who, or rather what, carried it out. For the first time...