Security Observatory Blog
Latest cybersecurity news, incidents and AI-model developments — observed and analyzed daily by the Kotoba Cloud research team.
-
Volexity 观测到 BlueMoon 攻击链——Chrome V8 沙箱内任意读写、沙箱逃逸与 Windows ALPC 滥用——被至少多个中国背景攻击集群共用。上游 Chromium 已有修复,但稳定版 Chrome 尚未发布相应更新,形成危险的"补丁空窗期"。本文梳理其影响。
-
每天观测、分析网络安全新闻、重大事件与 AI 模型动态,并在此发布。
-
CVE-2026-76461(CVSS 9.8)正被实际利用,并已加入 CISA 的 KEV 目录。本文梳理反复出现的"边界设备 root 沦陷"攻击模式,以及当设备自身日志不再可信时意味着什么。
-
A $900M AUM, operator-led fund built by former CISOs and founders. We map its two funds and ~40-company portfolio against kotoba.cloud's position.