إلى الخلف
استخبارات الخصم
جدول المحتوى
لم يتم العثور على أية عناصر.

ملخص تنفيذي

في مارس 2026، قامت مجموعة التهديد TeamPCP بتنفيذ ما يُعتقد أنه أكبر هجوم على سلسلة توريد يستهدف البنية التحتية للذكاء الاصطناعي من خلال اختراق LiteLLM. تمكنت وحدة استخبارات التهديدات في CloudSEK من الوصول إلى معلومات الضحايا، وهي تكشف الآن عن تفاصيل جميع الجهات المتضررة. 

نشارك هذه المعلومات علنًا لتمكين كل مؤسسة متضررة من اتخاذ إجراءات استباقية. لا يزال التهديد قائمًا؛ حيث حذر مكتب التحقيقات الفيدرالي (FBI) في تقريره الصادر في يوليو 2026 (FLASH-20260702-01) من أن الجهات الفاعلة التابعة من المرجح أن تستغل بيانات الاعتماد التي تم جمعها لفترة طويلة بعد الاختراق الأولي، مما يعني أن المزيد من هجمات سلسلة التوريد تظل احتمالًا واردًا. الوعي المبكر هو أقوى وسيلة دفاع؛ فمعرفتك بأنك كنت من المتضررين تتيح لك تغيير بيانات الاعتماد، وإغلاق ثغرات التعرض، وتعزيز أمنك قبل وقوع الحملة التالية.

تتزايد الهجمات على البنية التحتية للذكاء الاصطناعي، وهذا بالضبط ما صُممت منصة CloudSEK AIvigil، منصتنا لمراقبة سطح هجوم الذكاء الاصطناعي، لمنعه. تعمل AIvigil باستمرار على اكتشاف ومراقبة وتأمين البنية التحتية للذكاء الاصطناعي المعرضة للخطر، وخوادم MCP، وبيانات اعتماد الذكاء الاصطناعي المسربة، وقواعد بيانات المتجهات، وسير عمل الوكلاء، والذكاء الاصطناعي الظلي. نحن نجمع بين قوة استخبارات التهديدات السيبرانية والتعرض للذكاء الاصطناعي لاكتشاف ومنع الهجمات السيبرانية على البنية التحتية للذكاء الاصطناعي.

‍
تتراوح الجهات المتضررة من شركات الذكاء الاصطناعي الكبرى ومزودي النماذج إلى بائعي الأمن السيبراني، ومنصات البرمجيات كخدمة (SaaS)، والمؤسسات حول العالم. 

تحقق مما إذا كانت مؤسستك معرضة للخطر في اختراق سلسلة توريد الذكاء الاصطناعي هذا: https://exposure.cloudsek.com/ai-supply-chain-incident

2,500+
companies in CloudSEK's reconstructed exposure dataset
434,000
CI/CD pipelines potentially exposed
40 min
approximate period the affected PyPI packages were live

‍‍

بيانات تعرض الضحايا

مؤسسات مختارة ذات موثوقية عالية في مجموعة بيانات التعرض

السجلات أدناه هي أهم المطابقات على مستوى المؤسسات المقدمة لهذا التقرير. تشير الموثوقية العالية إلى قوة مطابقة التعرض، وليس دليلاً على نجاح الاختراق أو استغلاله من قبل المهاجم.

يتم عرض "الأسرار" (Secrets) و"التشغيلات" (Runs) كأعداد إجمالية من مجموعة البيانات المقدمة. تظهر النطاقات فقط حيثما تم توفيرها. لا يتم تضمين أي قيم سرية، أو بيانات اعتماد، أو مسارات داخلية، أو معلومات شخصية.

القائمة الكاملة متاحة هنا -

Organization / domain Secrets Runs Confidence
Amazon Web Services (AWS) amazon.com 19 12 High
Samsung Electronics samsung.com 10 19 High
Salesforce, Inc. — 2 4 High
Cisco Systems, Inc. cisco.com 327 1,900 High
F. Hoffmann-La Roche AG roche.com 4 16 High
ServiceNow servicenow.com 44 162 High
Siemens AG siemens.com 21 138 High
Airbus U.S. Space & Defense airbus.com 0 64 High
John Deere deere.com 185 203 High

‍

مختارات من المنظمات عالية الموثوقية - متابعة

Organization / domain Secrets Runs Confidence
Robert Bosch GmbH — 1 1 High
London Stock Exchange Group (LSEG) lseg.com 48 241 High
Thomson Reuters thomsonreuters.com 0 36 High
FedEx fedex.com 164 147 High
Munich Re munichre.com 110 62 High
MediaTek Inc. mediatek.com 126 119 High
Volkswagen AG volkswagenag.com 0 2,242 High
Deloitte deloitte.com 462 503 High
The Kroger Co. kroger.com 95 35 High
Siemens Energy siemens-energy.com 0 36 High
Thales Group thalesgroup.com 146 266 High
X Corp (Twitter) twitter.com 3,459 1,153 High
Zscaler, Inc. zscaler.com 65 304 High
Epic Games epicgames.com 62 31 High

‍

مختارات من المنظمات عالية الموثوقية، متابعة

Organization / domain Secrets Runs Confidence
Orange S.A. orange.com 180 5,642 High
HP Inc. hp.com 1 18 High
Philips philips.com 5 6 High
Fortum Oyj fortum.com 823 455 High
Vodafone Group Plc vodafone.com 83 51 High
Carl Zeiss AG zeiss.com 119 178 High
Deutsche Bahn AG , 25 35 High
NGINX, Inc. nginx.com 267 269 High
Liebherr liebherr.com 98 20 High
Krungthai Bank Public Company Limited krungthai.com 614 604 High
Roku, Inc. roku.com 61 51 High

‍

Interpretation requirement

A high-confidence organization match should trigger private validation, notification, credential review, and log investigation. Public wording should remain “potentially exposed” unless malicious execution, exfiltration, unauthorized access, or downstream use has been independently verified.

‍

بيانات في خطر

ما يهم الضحايا

  • كان الشيء المسروق عبارة عن  قد تتيح مفاتيح السحابة، ورموز المستودعات، ومفاتيح SSH، وأسرار Kubernetes، وبيانات اعتماد نشر الحزم، ومتغيرات البيئة، ومفاتيح مزودي الذكاء الاصطناعي للمهاجمين تجاوز حدود الحزمة المتضررة بكثير.
  • الإزالة لا تنهي الحادثة. يمكن أن تختفي الحزمة في دقائق بينما تظل بيانات الاعتماد المنسوخة قابلة للاستخدام لأسابيع أو أشهر ما لم يتم تغييرها والتحقيق في الأنشطة اللاحقة.
  • خطوط الأنابيب المؤتمتة تضخم أثر الاختراق الوجيز. تقوم أنظمة CI/CD بتثبيت التبعيات بسرعة فائقة وغالباً ما تعمل بصلاحيات واسعة، مما يجعل نافذة النشر القصيرة ذات أهمية تشغيلية كبيرة.
  • أصبحت البنية التحتية للذكاء الاصطناعي هدفاً استراتيجياً. تتمركز البوابات، والوكلاء، ومخازن المتجهات، ونقاط نهاية النماذج، وخوادم MCP بين البيانات الحساسة والأنظمة القادرة على اتخاذ إجراءات.
  • سياق الجهة الفاعلة ثانوي. تنسب التقارير العامة الحملة إلى TeamPCP؛ ويقتصر هذا التقرير في مناقشة الجهة الفاعلة على ما يحتاجه المدافعون لتحديد الهوية والاستجابة.

Important interpretation

The 2,500+ company and 434,000 pipeline figures describe reconstructed exposure. They should not be read as proof that every listed organization was successfully compromised or that every credential was stolen.

حجم التعرض للمخاطر

ما الذي تمت سرقته

على كل مُشغّل CI مخترق، قام برنامج السرقة الخاص بـ TeamPCP (الذي تتبعه Google باسم SANDCLOCK) برفع صلاحياته إلى مستوى الجذر (root) واستولى على:

  • مفاتيح SSH
  • بيانات اعتماد AWS وGCP وAzure
  • رموز Kubernetes المميزة (tokens)
  • ملفات .env وأسرار CI/CD — بما في ذلك القيم التي تحاول GitHub Actions إخفاءها، والتي تم استخراجها مباشرة من /proc/<pid>/mem
  • بالنسبة لبناء نماذج الذكاء الاصطناعي تحديداً: مفاتيح واجهة برمجة تطبيقات LLM وإعدادات البوابة — وهي بيانات الاعتماد الخاصة بكامل حزمة الذكاء الاصطناعي للمؤسسة

تمت قراءة مفاتيح السحابة مباشرة من خدمة بيانات تعريف المثيل (IMDS) ورموز Kubernetes من مسارات حساب الخدمة المثبتة، دون الحاجة إلى أي ثغرة، فقط باستخدام الوصول الذي كان يتمتع به كل مُشغّل بالفعل. تم بعد ذلك تشفير البيانات المجمعة باستخدام AES-256 تحت مفتاح RSA-4096 مُضمن برمجياً، بحيث تظل حركة البيانات المعترضة غير قابلة للقراءة دون المفتاح الخاص للمهاجم.

تم تشفير المسروقات وإرسالها إلى نطاق يحاكي اسماً معروفاً (typosquatted). وفي حال فشل عملية التسريب، كان البرنامج الضار ينشئ مستودعاً عاماً داخل حساب GitHub الخاص بالضحية ويقوم برفع البيانات المسروقة هناك كأصل إصدار (release asset)، مما يعني أن بعض المؤسسات كانت تُسرّب أسرارها الخاصة إلى العلن دون علمها.

‍

انكشاف الضحايا

الانكشاف: المؤسسات، وخطوط الأنابيب، والأنظمة التابعة

كيف يمكن أن يتحول الانكشاف إلى تأثير تجاري

1. Affected artifact — A compromised package or dependency enters a build or developer environment.

2. Secret access — The process reads credentials, tokens, keys, configuration, and runtime data available to that host.

3. Privilege expansion — Stolen access reaches repositories, registries, clusters, cloud accounts, SaaS tenants, or AI providers.

4. Downstream loss — Attackers can steal code and data, publish poisoned packages, persist, disrupt services, or extort the victim.

‍

ما يجب أن يتضمنه الإفصاح على مستوى الضحية

Field Why it matters
Organization and affected domain/project Resolves the exposure to the correct security owner and avoids ambiguous naming.
Observed pipeline or dependency evidence Separates direct evidence from inference and supports reproducible validation.
Credential classes potentially accessible Determines which keys, tokens, service accounts, and sessions must be rotated.
Exposure window and last-known activity Defines the log-search period and the minimum investigation scope.
Notification and remediation status Turns disclosure into measurable risk reduction rather than a static list.

‍

ما الذي كان معرضاً للخطر داخل البيئات المكشوفة

تكمن خطورة الاختراق في ما يمكن للعملية المتأثرة قراءته، وليس فقط في اسم الحزمة.

تعمل LiteLLM عادةً بالقرب من مزودي النماذج، وخدمات التطبيقات، وأنظمة النشر. وفي بيئات التطوير وخطوط التكامل والنشر المستمر (CI/CD)، قد يحتوي المضيف نفسه على بيانات اعتماد للتحكم في المصدر، والبنية التحتية السحابية، والسجلات، والحاويات، وخدمات الإنتاج. الفئات أدناه هي فئات التعرض المحتملة عند وجودها على نظام متأثر.

Exposure class Examples Potential consequence
Cloud credentials AWS, GCP, Azure keys and metadata-service tokens Account takeover, data access, compute abuse, persistence
Source-control access GitHub/GitLab tokens, SSH keys, deploy keys Repository theft, malicious commits, secret discovery
Package publishing npm, PyPI, container registry and artifact tokens Downstream supply chain compromise
Kubernetes and CI/CD Cluster tokens, runner secrets, service accounts Workload takeover, lateral movement, service disruption
AI provider access Model API keys and gateway credentials Prompt/data exposure, model abuse, cost fraud
Application secrets .env files, database URLs, SaaS keys, webhook tokens Data theft, impersonation, operational compromise
Code and artifacts Private repositories, builds, images, model assets IP theft, backdoors, release tampering

‍

Why credential rotation must be broad

Rotating only the LiteLLM or model-provider key is insufficient. Any credential readable by the affected process, present in process memory, injected into the job, stored on disk, or retrievable through an instance metadata service should be treated as potentially exposed until validated.

‍

مسار الهجوم

من حزمة موثوقة إلى الوصول للمؤسسة

يوضح حادث شهر مارس كيف يمكن لمكون الذكاء الاصطناعي أن يصبح نقطة دخول إلى نطاق البرمجيات والبنية التحتية السحابية الأوسع.

1. Upstream compromise: The release process's trusted security scanner (Trivy) was taken over. A leaked automation token , rotated but not fully revoked , left an approximately 20-day window in which the attacker force-pushed malicious code over the scanner's published version tags, so downstream builds pulling those tags received poisoned code that still looked legitimate.

2. Poisoned LiteLLM release: Versions 1.82.7 and 1.82.8 are published to PyPI during a short exposure window.

3. Automatic execution: A malicious .pth file runs when Python starts,no explicit LiteLLM import is required. Because a .pth file executes at interpreter startup rather than on import, the payload ran wherever the package was merely installed , sidestepping the --ignore-scripts protection teams rely on to keep installs safe.

4. Secret collection: Credentials and environment data available to the process can be harvested.

5. Downstream access: Repositories, cloud accounts, clusters, registries, SaaS, and AI services become reachable.

6. Persistence and reuse: Stolen access can be sold, reused, or weaponized after the malicious package is removed.

‍

How the poison reached LiteLLM

LiteLLM was never attacked directly. Its CI pipeline installed the Trivy scanner unpinned from the system package manager (apt), so the compromised scanner flowed into the build automatically, and that build produced and published the malicious 1.82.7 and 1.82.8 releases to PyPI. Trivy, then the build system, then the LiteLLM release: one un-revoked token, three tools deep. That chain is what turns a single credential leak into ecosystem-wide exposure.

A 40-minute package window can create a months-long incident

Automated build systems compress time. Once a malicious artifact reaches a registry, scheduled jobs, dependency resolvers, ephemeral runners, developer laptops, and cached layers can copy it rapidly. The forensic and credential-rotation window therefore extends beyond package removal.

‍

مخاطر البنية التحتية للذكاء الاصطناعي

لماذا ستستهدف الموجة التالية من سلاسل التوريد البنية التحتية للذكاء الاصطناعي

تقييم CloudSEK: أصبحت أنظمة الذكاء الاصطناعي نقاط ربط عالية القيمة بين البيانات، والهوية، والحوسبة، والإجراءات المستقلة.

In the industrial age, rail junctions became strategic targets because many supply routes met at one point. AI gateways, agent runtimes, MCP servers, and vector stores are becoming the junctions of digital operations.

موقع ذو صلاحيات مميزة. غالباً ما تحتفظ بوابات الذكاء الاصطناعي وبيئات تشغيل الوكلاء ببيانات اعتماد للنماذج، وقواعد البيانات، والإضافات، والخدمات السحابية، والأدوات الداخلية.

رسم بياني واسع للتبعيات. تجمع حزم الذكاء الاصطناعي الحديثة بين الحزم مفتوحة المصدر، والنماذج المستضافة، ومجموعات تطوير البرمجيات (SDKs)، والملحقات، والموصلات، وقواعد بيانات المتجهات، والجهات الخارجية.

التنفيذ المستقل. يمكن لسير عمل الوكلاء القراءة والكتابة واستدعاء الأدوات وتشغيل العمليات التجارية، مما يزيد من نطاق تأثير الوصول المسروق.

الاعتماد السريع وغير الرسمي. تقوم الفرق بنشر خدمات الذكاء الاصطناعي بشكل أسرع من تحديث سجلات الأمان المركزية، مما يترك أصولاً غير معروفة وبيانات اعتماد غير مُدارة.

بيانات عالية القيمة. تتركز المعلومات الحساسة في المطالبات (Prompts)، ومخازن الاسترجاع، وبيانات التدريب، ومخرجات النماذج، وأنظمة الأعمال المتصلة.

فجوات الرؤية التقليدية. ترى أدوات سطح الهجوم التقليدية نقاط النهاية والمنافذ، لكنها غالبًا ما تغفل عن سياق النماذج، والوكلاء، وخدمات MCP، والمطالبات، وسير عمل الذكاء الاصطناعي.

The lesson of LiteLLM

The incident was not only a software supply chain breach that happened to involve an AI product. It demonstrated that compromising an AI control point can expose the identities and systems around it. Future attacks are likely to target the AI layer precisely because it is connected to everything else.

‍

استجابة الضحية

إجراءات فورية للمؤسسات المحتمل تعرضها للاختراق

يجب أن تفترض الاستجابة تعرض بيانات الاعتماد للخطر أولاً، ثم استخدام الأدلة لتقليص نطاق التأثير.

0–24 hours 24–72 hours Ongoing controls
Identify use of LiteLLM 1.82.7/1.82.8 and affected build windows. Isolate affected runners, hosts, images, and caches. Rotate every credential accessible to the affected process, including cloud, repository, registry, Kubernetes, SaaS, database, and AI keys. Rebuild affected environments from known-clean sources. Hunt for unexpected repositories such as tpcp-docs/docs-tpcp, suspicious egress, unauthorized tokens, and new service accounts. Review cloud, source-control, package registry, and cluster audit logs. Pin dependencies and GitHub Actions to verified hashes. Shorten credential lifetime and scope; prefer workload identity over static keys. Monitor CI/CD runtime behavior and third-party AI dependencies continuously. Inventory AI assets and owners.

أسئلة التحقيق لتحديد التأثير الفعلي على الضحية

  • هل تم تنزيل الأداة المتأثرة، أو تخزينها مؤقتًا، أو تنفيذها، أم تمت الإشارة إليها فقط؟
  • ما هي الأسرار التي كانت موجودة في متغيرات البيئة، أو ذاكرة العمليات، أو الملفات، أو خدمات البيانات الوصفية، أو سياقات الوظائف المحقونة؟
  • هل أظهر أي رمز (token) استخدامًا من عنوان IP، أو جهاز، أو موقع جغرافي، أو مشغل، أو وكيل مستخدم غير معتاد بعد فترة التعرض؟
  • هل كان من الممكن أن تؤدي بيانات اعتماد النشر المسروقة إلى اختراق سلسلة التوريد من الجيل الثاني؟
  • هل اتصلت بوابة الذكاء الاصطناعي المتأثرة بمطالبات حساسة، أو مخازن متجهات، أو وكلاء، أو أدوات داخلية، أو بيانات عملاء؟
Do not wait for proof before rotating high-value secrets

A lack of obvious malicious activity is not evidence that a credential was not copied. For credentials with production reach, the cost of rotation is usually lower than the cost of delayed containment.

‍

CLOUDSEK AIVIGIL

من الاستجابة للحوادث إلى الإدارة المستمرة لمخاطر الذكاء الاصطناعي

صُممت منصة CloudSEK AIVigil لاكتشاف ومراقبة سطح هجوم الذكاء الاصطناعي وهجمات سلسلة التوريد قبل أن تتحول البنية التحتية المكشوفة إلى مسار للهجوم.

تعمل AIVigil على اكتشاف ومراقبة وتأمين بنية الذكاء الاصطناعي التحتية المكشوفة، وخوادم MCP، وبيانات اعتماد الذكاء الاصطناعي المسربة، وقواعد بيانات المتجهات، وسير عمل الوكلاء، والذكاء الاصطناعي الظلي بشكل مستمر. وهي تجمع بين معلومات التهديدات السيبرانية من CloudSEK ومراقبة مخاطر الذكاء الاصطناعي، مما يتيح لفرق الأمن ربط الإشارات الخارجية بأصول الذكاء الاصطناعي، وبيانات الاعتماد، والتبعيات، وأنظمة الأعمال المعرضة للخطر.

Security blind spot How AIVigil addresses it
Unknown AI assets Continuous outside-in discovery and AI Bill of Materials (AI-BOM)
Exposed AI services Monitoring of model endpoints, gateways, vector databases, GPU infrastructure, and cloud AI misconfigurations
Leaked AI credentials Threat intelligence correlation across credential leaks, repositories, malware logs, and external sources
MCP and agentic risk Assessment of MCP servers, tool access, agent permissions, and workflow exposure
Shadow AI Discovery of unmanaged AI applications and services operating outside approved inventory
Prioritization gap Risk scoring based on authentication, reachability, agent agency, blast radius, and live threat signals

الحلقة المستمرة

1. Discover: Find AI assets and shadow AI.

2. Scan: Assess exposures and attack paths.

3. Triage: Correlate with live threat intelligence.

4. Report: Drive ownership and remediation.

‍

The objective

Move from learning about an AI infrastructure breach after credentials are stolen to continuously knowing which AI assets exist, what they expose, and which attack paths require action now.

‍

المنهجية والنطاق

المنهجية، ومستوى الثقة، والتفسير المسؤول

يُميز الإفصاح القوي بين التعرض المرصود، والاختراق المحتمل، والنشاط الضار المؤكد.

مدخلات أبحاث CloudSEK

  • حصل فريق استخبارات التهديدات في CloudSEK على بيانات التعرض من خلال مصادره الاستخباراتية، بما في ذلك السجلات المتعلقة بالمؤسسات، وخطوط أنابيب CI/CD، وتسريبات بيانات الاعتماد/الرموز المميزة المرتبطة بسلسلة توريد مارس 2026 التي تضمنت إصدارات مخترقة من Trivy وCheckmarx KICS وLiteLLM.
  • أصول الذكاء الاصطناعي والسحابة المعرضة للخطر التي تصل إليها بيانات الاعتماد تلك، ونقاط نهاية النماذج، والبوابات، وقواعد بيانات المتجهات، وبنية وحدة معالجة الرسومات (GPU)، والحسابات السحابية، وسير عمل MCP/الوكلاء.
  • ناقلات الأدوات الثلاثة التي تم استغلالها وتسببت في هذا التعرض: Trivy وCheckmarx KICS وLiteLLM.
  • التحذيرات العامة التي تؤكد الحملة والأدوات المتأثرة: FBI FLASH، وAqua Security، وCheckmarx، وLiteLLM/BerriAI، وUnit 42، وSophos.

تصنيفات الثقة الموصى بها لمجموعة بيانات الضحايا.

Label Meaning Recommended wording
Exposed Evidence links the organization or pipeline to an affected artifact or exposure path. Potentially exposed; validation required.
Probable compromise Execution or credential-access evidence exists, but attacker use is not confirmed. Likely affected; containment and investigation required.
Confirmed compromise Malicious execution, exfiltration, unauthorized access, or downstream use is verified. Confirmed victim; incident response active.

الإسناد في فقرة واحدة

تُرجع التقارير العامة الحملة الأوسع إلى مجموعة TeamPCP ذات الدوافع المالية. وقد قامت الجهة الفاعلة باختراق أدوات الأمان والمطورين الموثوقة واستخدمت برمجيات خبيثة لسرقة بيانات الاعتماد للوصول إلى البيئات السحابية وبيئات CI/CD. إن هوية المجموعة، ونزاعاتها الداخلية، وانتماءاتها للمنتديات، وتاريخ قيادتها ليست ضرورية لفهم تعرض الضحايا، وقد تم استبعادها عمداً من السرد الرئيسي.

‍

المصادر والخلاصة

CloudSEK AIVigil - مراقبة سطح هجوم الذكاء الاصطناعي

تتزايد الهجمات على البنية التحتية للذكاء الاصطناعي، وهذا بالضبط ما صُممت منصة CloudSEK AIvigil، المتخصصة في مراقبة سطح هجوم الذكاء الاصطناعي، لمنعه. تعمل AIvigil باستمرار على اكتشاف ومراقبة وتأمين البنية التحتية المعرضة للخطر للذكاء الاصطناعي، وخوادم MCP، وبيانات اعتماد الذكاء الاصطناعي المسربة، وقواعد بيانات المتجهات، وسير عمل الوكلاء، والذكاء الاصطناعي الخفي. نحن نجمع بين قوة استخبارات التهديدات السيبرانية والتعرض للذكاء الاصطناعي للكشف عن الهجمات السيبرانية على البنية التحتية للذكاء الاصطناعي ومنعها.

المراجع الأساسية

1. LiteLLM، تحديث أمني: حادثة سلسلة توريد مشتبه بها (24 مارس 2026)

2. مكتب التحقيقات الفيدرالي (FBI)، مجموعة الجرائم السيبرانية TeamPCP، FLASH-20260702-01 (2 يوليو 2026)

3. Unit 42، هجوم سلسلة التوريد متعدد المراحل الذي شنته TeamPCP على البنية التحتية الأمنية (31 مارس 2026)

4. Sophos، تعاون بين Vect وTeamPCP في حملات برامج الفدية (2 يوليو 2026)

5. CloudSEK، تقديم AIVigil: مراقبة سطح هجوم الذكاء الاصطناعي

6. CloudSEK، ما هي مراقبة سطح هجوم الذكاء الاصطناعي؟

مدونات ذات صلة