內 容
|
1. 【防詐快訊】打擊假帳號!Meta 推出免費臉書「真人驗證」徽章
- 摘要:為了防範假帳號詐騙與AI假內容,Meta 推出免費的 Facebook 真人驗證服務,使用者只要透過自拍影片即可申請驗證徽章。
- 建議行動:建議教職員可申請臉書真人驗證;在臉書進行交易、交友或參與重要社團討論前,可先確認互動對象是否已完成真人驗證,以降低遭詐騙風險。
- 參考連結: Meta 推出臉書真人驗證 (iThome)
2. 【軟體安全】當心冒牌 Notepad++!駭客利用假外掛散布惡意程式
- 摘要:烏克蘭資安機構警告,近期有駭客以提供知名的純文字編輯工具 Notepad++ 及其擴充外掛為誘餌,實則暗藏惡意程式,企圖入侵電腦竊取資料。
- 建議行動:校內同仁若需下載或更新 Notepad++ 等各類免費辦公軟體,請務必前往「官方網站」下載,切勿點擊來路不明的論壇或信件連結。
- 參考連結: 冒牌 Notepad++ 外掛危機 (iThome)
3. 【AI 威脅】AI 代理爆「沙箱逃逸」漏洞!Claude Cowork 恐遭駭客利用
- 摘要:資安研究員發現,AI 代理工具 Claude Cowork 存在嚴重漏洞,駭客可利用該漏洞突破系統隔離區(沙箱),進而讀取甚至寫入底層主機的敏感檔案與憑證。
- 建議行動:在使用各類 AI 工具或代理程式處理公務時,請避免上傳或匯入未經授權的機密公文、學生個資或重要系統密碼。
- 參考連結: Claude Cowork 沙箱逃逸漏洞 (iThome)
4. 【系統更新】Google 緊急發布更新!修補 4 個 Chrome 高風險漏洞
- 摘要:Google 於 7 月下旬緊急發布 Chrome 瀏覽器更新,一次修補了 4 個高風險的零時差漏洞。若未更新,駭客可能透過特製網頁發動攻擊。
- 建議行動:請同仁盡速開啟 Chrome 瀏覽器右上角的「設定」>「關於 Chrome」,系統將會自動檢查並安裝最新版本,完成後請重新啟動瀏覽器。
- 參考連結: Chrome 150 版緊急更新 (iThome)
5. 【帳號安全】AI 音樂平臺 Suno 遭駭,逾 5500 萬筆信箱資料外洩
- 摘要:知名 AI 音樂生成平臺 Suno 驚傳資料外洩事件,包含超過 5,530 萬個使用者的電子郵件地址與部分付款資料已遭駭客竊取,恐被用於後續的釣魚信件攻擊。
- 建議行動:若您曾註冊 Suno 平臺,請留意近期是否收到可疑的釣魚信件。建議教職員在註冊外部非公務 AI 服務時,盡量避免使用學校公務信箱與常用密碼。
- 參考連結: Suno 音樂平臺資料外洩 (iThome)
1. [Anti-Fraud Alert] Fight Fake Accounts! Meta Launches Free "Facebook Verified" Badge
- Summary: To combat fake account scams and AI-generated misinformation, Meta is rolling out a free Facebook Verified service. Users can apply for the verification badge simply by submitting a selfie video.
- Action: We recommend staff apply for Facebook verification. Before engaging in transactions, making friends, or participating in important group discussions, check if the other party is verified to reduce the risk of scams.
- Reference: Meta Launches Facebook Verified (iThome)
2. [Software Security] Beware of Fake Notepad++! Hackers Distribute Malware via Malicious Plugins
- Summary: Ukrainian cybersecurity agencies warn that hackers are using the popular text editor Notepad++ and its plugins as bait. These downloads actually contain malware designed to infiltrate computers and steal data.
- Action: If you need to download or update free productivity software like Notepad++, always use the "official website." Never click on download links from unknown forums or suspicious emails.
- Reference: Fake Notepad++ Plugin Threat (iThome)
3. [AI Threat] "Sandbox Escape" Vulnerability in AI Agents! Claude Cowork at Risk of Exploitation
- Summary: Security researchers have discovered a critical vulnerability in the AI agent tool Claude Cowork. Hackers can exploit this flaw to bypass system isolation (the sandbox) and read or even write sensitive files and credentials on the underlying host machine.
- Action: When using AI tools or agents for work, avoid uploading or importing unauthorized confidential documents, student personal data, or important system passwords.
- Reference: Claude Cowork Sandbox Escape (iThome)
4. [System Update] Urgent Google Update! 4 High-Risk Vulnerabilities Patched in Chrome
- Summary: In late July, Google released an urgent update for the Chrome browser, patching four high-risk zero-day vulnerabilities. If left unpatched, hackers could launch attacks via specially crafted webpages.
- Action: Please open your Chrome browser, go to the top-right menu > "Settings" > "About Chrome." The system will automatically check for and install the latest version. Restart your browser to complete the update.
- Reference: Urgent Chrome Version 150 Update (iThome)
5. [Account Security] AI Music Platform Suno Hacked: Over 55 Million Emails Leaked
- Summary: Suno, a popular AI music generation platform, suffered a major data breach. The email addresses and partial payment information of over 55.3 million users were stolen by hackers, potentially leading to subsequent phishing attacks.
- Action: If you have registered on the Suno platform, be on the lookout for suspicious phishing emails. When signing up for external, non-work AI services, avoid using your university email address and commonly used passwords.
- Reference: Suno Platform Data Breach (iThome)
|
|