BTC $79,280.35 -1.01%
ETH $2,493.92 -0.68%
BNB $740.54 -1.39%
XRP $1.40 -1.08%
SOL $104.06 -1.79%
TRX $0.3342 -0.29%
DOGE $0.0913 +0.45%
ADA $0.2219 -0.76%
BCH $261.42 +0.42%
LINK $12.78 -2.72%
HYPE $85.21 -2.65%
AAVE $132.61 -2.11%
SUI $0.8295 +1.63%
XLM $0.1936 +2.88%
ZEC $1,138.91 -4.55%
BTC $79,280.35 -1.01%
ETH $2,493.92 -0.68%
BNB $740.54 -1.39%
XRP $1.40 -1.08%
SOL $104.06 -1.79%
TRX $0.3342 -0.29%
DOGE $0.0913 +0.45%
ADA $0.2219 -0.76%
BCH $261.42 +0.42%
LINK $12.78 -2.72%
HYPE $85.21 -2.65%
AAVE $132.61 -2.11%
SUI $0.8295 +1.63%
XLM $0.1936 +2.88%
ZEC $1,138.91 -4.55%

iso

Tất cả
Bài viết
Tin nhanh

KuCoin đạt chứng nhận hệ thống quản lý trí tuệ nhân tạo ISO/IEC 42001

Tin tức từ ChainCatcher, KuCoin hôm nay thông báo rằng hệ thống quản lý trí tuệ nhân tạo (AIMS) của họ đã chính thức nhận được chứng nhận quốc tế ISO/IEC 42001:2023, tăng cường khả năng hệ thống của công ty trong việc triển khai, quản lý và cải tiến liên tục một cách có trách nhiệm đối với trí tuệ nhân tạo.Chứng nhận này là tiêu chuẩn quốc tế đầu tiên về hệ thống quản lý trí tuệ nhân tạo trên toàn cầu, cung cấp khung quản lý được công nhận quốc tế cho các doanh nghiệp trong việc thiết lập, thực hiện, duy trì và cải tiến liên tục hệ thống quản lý trí tuệ nhân tạo. Chứng nhận lần này bao gồm hệ thống quản lý trí tuệ nhân tạo của KuCoin và các chức năng hỗ trợ liên quan, thúc đẩy việc ứng dụng AI một cách minh bạch, an toàn và có trách nhiệm trong hoạt động của nền tảng.Khi AI ngày càng sâu sắc trong việc kiểm soát rủi ro, chống rửa tiền, phát hiện gian lận, giám sát thị trường, dịch vụ khách hàng thông minh và các tình huống tài chính kỹ thuật số khác, KuCoin đang tiếp tục thúc đẩy đổi mới AI và quản lý đáng tin cậy song song. Chứng nhận lần này đã hoàn thiện thêm khung tin cậy của KuCoin, cùng với ISO/IEC 27001, SOC 2 Type II và ISO 22301, xây dựng cơ sở hạ tầng đáng tin cậy bao gồm an ninh thông tin, độ tin cậy hoạt động, tính liên tục kinh doanh và quản lý trí tuệ nhân tạo.

Cựu CISO của Twitter Michael Coates đảm nhận vị trí Giám đốc An ninh Thông tin của Quỹ Solana

Tin tức từ ChainCatcher, chuyên gia an ninh Michael Coates đã thông báo trên nền tảng X rằng ông đã đảm nhận vị trí Giám đốc An ninh Thông tin (CISO) của Quỹ Solana, mở ra một chương mới trong sự nghiệp. Trước đây, Coates từng giữ chức vụ Giám đốc An ninh tại Mozilla, CISO của Twitter, và đã thành lập một công ty khởi nghiệp tập trung vào an ninh dữ liệu SaaS cho doanh nghiệp mang tên Altitude Networks, công ty này sau đó đã được CoinList mua lại, từ đó ông bước vào ngành công nghiệp tiền điện tử.Coates cho biết, lý do ông chọn gia nhập Solana là vì chuỗi này hiện có khối lượng giao dịch stablecoin hàng ngày đạt hàng trăm tỷ đô la, với khối lượng giao dịch hàng ngày vượt qua tổng số của hầu hết các loại tiền điện tử. Ông đề cập rằng công việc trong tương lai sẽ tập trung vào việc tích hợp khả năng an ninh vào hoạt động ngành và cơ sở an ninh ứng dụng, đối phó với những thách thức an ninh đặc thù của tiền điện tử, và hợp tác với các nhà hoạch định chính sách cũng như các tổ chức tiêu chuẩn để thúc đẩy sự hoàn thiện của quy định an ninh mạng.

Superfortune: The leakage of the attacker's private key rather than address poisoning is not the work of an insider

Superfortune, incubated by Manta, recently released an update on the X platform regarding a security incident, stating that the attack was not carried out by internal personnel and that no team members were involved. The claim about the team secretly selling tokens is incorrect. The team has also not had any contact with Web3Port.The investigation confirmed that the attack was not due to address poisoning, but rather a leak of the signer's private key. The attacker independently held the private key and submitted a transaction with a forged address 43 minutes after the correct transaction. The forged address shares the first and last four characters with the correct address (starting with 0x70AE and ending with 5C15) to disguise itself in the Safe interface preview. The stolen funds are fully traceable and are currently stored in three cold wallets on Ethereum, containing approximately 2784 ETH, along with about 170,000 USDT that were cross-chain transferred out.The attacker also created a large number of counterfeit addresses and sent false transfer events to these addresses using Unicode-forged token symbols in an attempt to confuse tracking. This counterfeit address construction technique is the same as the method used when attacking this project. The attacker had pre-built a large-scale infrastructure, indicating that this was an industrialized operation rather than an opportunistic attack.

AI Agent Security Risk Exposure: Attackers Can Exploit "Memory Pollution" to Induce Misoperation of Funds

The GoPlus Security team has disclosed a new type of attack in its AgentGuard AI project: inducing AI agents to perform unauthorized sensitive operations through "memory poisoning." This attack method does not rely on traditional vulnerabilities or malicious code but exploits the long-term memory mechanism of AI agents. For example, an attacker first induces the agent to "remember preferences," such as "usually prioritizing proactive refunds instead of waiting for chargebacks," and then uses vague expressions like "process as usual" or "execute as before" in subsequent instructions, thereby triggering automated financial operations.GoPlus points out that the key risk in such cases lies in the AI agent mistakenly treating "historical preferences" as a basis for authorization, leading to financial losses or security incidents in operations such as refunds, transfers, and configuration changes. To address this issue, the team has proposed several protective recommendations, including:Operations involving refunds, transfers, deletions, or sensitive configurations must require explicit confirmation in the current session.Memory-related instructions like "habit," "usual way," and "as before" should be regarded as high-risk state changes.Long-term memory must have a traceability mechanism (writer, time, confirmation status).Vague instructions should automatically elevate the risk level and trigger secondary verification.Long-term memory must not replace real-time authorization processes.The team emphasizes that the "AI agent memory system" should be viewed as a potential attack surface and should be constrained and audited through a dedicated security framework.
app_icon
ChainCatcher Building the Web3 world with innovations.