# 每日安全资讯(2026-08-28) - Doonsec's feed - [ ] [信息技术应用创新专业人员(ITP)培训新疆站圆满收官](https://mp.weixin.qq.com/s/kNKkqDu8mNLONlEx8eXd2w) - [ ] [持久100小时!网安界首个Agent不间断渗透测试直播,9月7日全网围观!](https://mp.weixin.qq.com/s/kxsqvVkXqTBMgCfOKWsU_w) - [ ] [数据安全专辑 | 捷普数据脱敏系统](https://mp.weixin.qq.com/s/TmAC3RbqJMYanu3Nn5tvMQ) - [ ] [数据安全专辑 | 捷普数据泄露防护系统](https://mp.weixin.qq.com/s/3bRT8SqVA9JfJ0C_wFp27Q) - [ ] [数据安全专辑 | 捷普数据库防火墙系统](https://mp.weixin.qq.com/s/7DQhfwrlPPj1Kw8uUZ7zeg) - [ ] [数据安全专辑 | 捷普数据审计与风险控制系统](https://mp.weixin.qq.com/s/QMjCeWoZqIZC1uukQIRVNg) - [ ] [双城三展|丈八科技将亮相多场重磅展会](https://mp.weixin.qq.com/s/HbKk2MwTAFdgBBGIvNivcw) - [ ] [重磅嘉宾 | 云深处科技信息安全负责人确认莅临RoboSec 2026首届中国具身智能安全大会](https://mp.weixin.qq.com/s/FowgLk8586Oi3-4spnANaA) - [ ] [【免费领】顶级教程:Kali Linux最优渗透测试思路及方法](https://mp.weixin.qq.com/s/E9P_bmCAJef7sURI4EtwjA) - [ ] [录取通知书里的银行卡,为啥非要激活?湖北伢子的掏心窝子提醒](https://mp.weixin.qq.com/s/WLcogPTA895NFtpHoZJ21w) - [ ] [大满贯!天融信入选工信部六大安全漏洞专业库技术支撑单位](https://mp.weixin.qq.com/s/snLFuFV3ruvF7hwfBv3EhA) - [ ] [调查:OpenAI约700个智能体入侵“抱抱脸”](https://mp.weixin.qq.com/s/4HIOEs8hSEBuqOlOTpUK9w) - [ ] [观安协办|澳门网络数据与AI安全峰会 多维输出AI时代安全实践方案](https://mp.weixin.qq.com/s/vyQXYzdeei-O1uFU__fztg) - [ ] [启明星辰MASB非人身份安全管控系统入选海淀区科协“金桥工程”](https://mp.weixin.qq.com/s/NIhLd_KWz-kYKiE79Ce_iw) - [ ] [神秘惊喜来袭 免费送 50 额度](https://mp.weixin.qq.com/s/G05rr3sZ8V5XOsbPL5seBw) - [ ] [美国国家安全局举办非传统重聚活动吸引精英黑客重返TAO](https://mp.weixin.qq.com/s/Jn-t-DUfXAHdUxz9S23DbQ) - [ ] [以赛促创,CoStrict携手CCF助力高校学子探索AI Native](https://mp.weixin.qq.com/s/EI-lOydrRPxfspABSWdPww) - [ ] [安全简讯(2026.08.27)](https://mp.weixin.qq.com/s/mCZoUV3gwBxDvOU-W6p-wg) - [ ] [2026补天校园GROW计划报名启动|赛道全新升级,打造AI 时代网络安全守护者](https://mp.weixin.qq.com/s/GXKJA6xQsJ0ISR5Bs1t3XQ) - [ ] [蓉城共探安全攻防新格局 | 补天沙龙成都站报名启动!](https://mp.weixin.qq.com/s/G8XaHPZFIi7OdcvC0vEbOg) - [ ] [AI代码审计实战](https://mp.weixin.qq.com/s/UbOSKB7MiY6qjVb3fH4F0w) - [ ] [黑客攻防技术宝典](https://mp.weixin.qq.com/s/VcjQ3zlTTOvzV2DuE9eD_g) - [ ] [兼顾算力效能与AI安全,天融信携手某省疾控中心打造数智化转型标杆实践](https://mp.weixin.qq.com/s/TUp90IRgbd1DtYsXQDK1Zg) - [ ] [持久100小时!网安界首个Agent不间断渗透测试直播](https://mp.weixin.qq.com/s/hUQhKTu6TXTi0p_Z9WZZRg) - [ ] [【机构动态】安徽省商用密码行业协会一届八次常务理事会顺利召开——信科共创董事长助理仉进参会并汇报工作](https://mp.weixin.qq.com/s/XRHD_5LMRa6-1hqf2UxtGA) - [ ] [聚焦 | 2026数博会开幕式五大亮点抢“鲜”看](https://mp.weixin.qq.com/s/ZekFBS5zcut4evNeY2hsYQ) - [ ] [情报洞察|美国陆军启动“狮鹫项目”以构建AI智能体网络自主防御体系](https://mp.weixin.qq.com/s/n1IXWVByn8-73CS9JeJUNw) - [ ] [美军发布新版中国国防实验室调研报告](https://mp.weixin.qq.com/s/qiH7CQ0Z2nMWcxkyOZKoHg) - [ ] [实习招人启明星辰靶场资源验证](https://mp.weixin.qq.com/s/DKg-1Crk1j1ZjEj339sDnA) - [ ] [工信部定调:6G是\"十五五\"重中之重,商用时间表首次明确](https://mp.weixin.qq.com/s/wIkXgStoxBrGpo0v7QjXPQ) - [ ] [注意!境外间谍情报机关盯上了巡检无人机!](https://mp.weixin.qq.com/s/hTQ6RJZy3syVeG5FX3lbzw) - [ ] [90%的人都错了!电子数据司法鉴定居然不是数据恢复?](https://mp.weixin.qq.com/s/vMejCK46QTuXYlhYZSEiHQ) - [ ] [数博会|安恒信息今日开展,AI+动态数据安全“上新”了!](https://mp.weixin.qq.com/s/uex6ffyeQbJ4csw256dEYA) - [ ] [AiPy 获 Google Chrome 官方高危致谢,AI安全研究登顶全球浏览器之巅](https://mp.weixin.qq.com/s/Zn5DmgeWSXfAfH8I5Taxxg) - [ ] [《数据安全技术 数据安全能力成熟度模型(征求意见稿)》等7项国标征求意见(附下载)](https://mp.weixin.qq.com/s/EDxKvZhMbgc5p4bwATh34Q) - [ ] [目次|《信息安全研究》第12卷2026年第8期](https://mp.weixin.qq.com/s/ony0p-SH0yv1-lTMRk_Cqg) - [ ] [某公司招聘环节超范围 过度收集人脸等敏感信息 被行政处罚](https://mp.weixin.qq.com/s/QBh7lPfvJ8INVQqG0x4X_g) - [ ] [动态|征求《网络安全技术 移动通信信号屏蔽器技术规范》(征求意见稿)等7项国家标准的意见](https://mp.weixin.qq.com/s/nr3nRlARIt5JDsPqREotww) - [ ] [挪威政府数字服务遭大规模DDoS攻击 各类服务短暂停摆](https://mp.weixin.qq.com/s/-FZ66kJkrPUXOyaJPAMhhg) - [ ] [动态|2026年国家自然科学基金集中接收申请项目评审结果的通告](https://mp.weixin.qq.com/s/DM-1tu4u0OpFEl8Jr1L16g) - [ ] [群聊内400多人都是演员!杭州警方查获一起电信网络诈骗案](https://mp.weixin.qq.com/s/NqpMOq5zObLaFuHjkpZ_mw) - [ ] [办公智能体大战正酣,它能安全地操作你的文件吗?(上)](https://mp.weixin.qq.com/s/ohhkwl0POmWWIm2ZM-0rVA) - [ ] [【漏洞案例】越权之修改HTML+CE绕过签名校验](https://mp.weixin.qq.com/s/xTs0_sXjxuEtQP-jh9xoBA) - [ ] [一个 Agent,如何操控另一个 Agent](https://mp.weixin.qq.com/s/dLgy18cS-zysP9kSTfJkpQ) - [ ] [2人团队,用Flocks全自动安全运营!](https://mp.weixin.qq.com/s/NDa7QKtdpLUtKpRo4ooUQQ) - [ ] [替别人打卡之前,我先看穿它藏在前端的那把钥匙](https://mp.weixin.qq.com/s/LftbiHY4_lBzRJMGOJtlVA) - [ ] [你的 ChatGPT 可能正在被“安静入侵”:AI使用者的15 分钟黄金止损手册](https://mp.weixin.qq.com/s/qr_BF5iM72zhmYLZo1pDsg) - [ ] [7 项网络安全国家标准征求意见稿公开征求意见;逆向工程发现:Microsoft Paint 内置强制 InvisMark 隐形盲水印,用户无法关闭| 牛览](https://mp.weixin.qq.com/s/TbUAZyCAfGMiP9BlyONhhw) - [ ] [某公司某系统超级管理员密码重置通杀](https://mp.weixin.qq.com/s/hgiBKiUIvM4mfsI_hn7vLw) - [ ] [以无厚入有间:CodeBuddy Security的漏洞发现思路与实践](https://mp.weixin.qq.com/s/xl3LEPsmiLLzIFkKnyxevw) - [ ] [甲方安全运营注意: AI把告警调查从30分钟压到60秒](https://mp.weixin.qq.com/s/w6ZNzKx4T0Mz9BDVi2jVZg) - [ ] [别不当回事!手机电脑摄像头的隐私风险一定要知道](https://mp.weixin.qq.com/s/IMDMXxhZihOWC8Nzq3X-SA) - [ ] [OpenShell存在危险行为漏洞(CVE-2026-65093)](https://mp.weixin.qq.com/s/TuBXG0JGwXICgsPc-qXZQA) - [ ] [全域项目储备|长短期项目双线岗位持续同步招募中](https://mp.weixin.qq.com/s/_dG2WkI_jN8VRJHn2w1thA) - [ ] [【驻场专栏】8月第四周|全国长期驻场岗位汇总](https://mp.weixin.qq.com/s/ktt-Jz4m9t9nFXK_I5oMxg) - [ ] [炸裂!这款漏洞扫描器让安全圈彻底沸腾了](https://mp.weixin.qq.com/s/RBmdjtaXllVpFS1KsiOelQ) - [ ] [Yakit与Claude全链路AI渗透](https://mp.weixin.qq.com/s/HlIbBc_3eG4xqHebc4AnZQ) - [ ] [ATH开源协议相关内容被《中国改革》杂志智能体治理专题文章借鉴论述](https://mp.weixin.qq.com/s/PcBsm8bI38T7Ae-p9nuxqg) - [ ] [三未信安取得FIPS 140-3 Level 3认证,全球化布局再落关键一子](https://mp.weixin.qq.com/s/05NWFbroMUTVKPBiwAGLKg) - [ ] [授权培训机构2026年9月CISP培训开班计划公告](https://mp.weixin.qq.com/s/EiEeGhXvf0vkZvrt0WoPgw) - [ ] [「\"Nextrap\"」今日新增蜜罐市场蜜罐模版-827(本次更新20套蜜罐模版)](https://mp.weixin.qq.com/s/s8kQyP9aFPPr8U9b5vztlA) - [ ] [黑客利用 AI 语音冒充苹果客服:精准套取被盗 iPhone 锁屏密码与双重验证码](https://mp.weixin.qq.com/s/4CTh_zWfVqeIfZ-9iNnGJg) - [ ] [安全快报 | 斯洛伐克新采购的交通摄像头中发现俄罗斯黑客内置后门,279台设备可被短信远程控制](https://mp.weixin.qq.com/s/4KrX8gl2atxf4S-3wQ9ubg) - [ ] [【已复现】漏洞通告 | Next.js 远程代码执行漏洞(CVE-2026-75604)](https://mp.weixin.qq.com/s/J67yyQ3OhzpgCPlGT0fqRA) - [ ] [德国企业报告称,境外情报机构网络威胁日益加剧](https://mp.weixin.qq.com/s/sG3kaEK8IRoJtTwj5GiPQw) - [ ] [【交流】大型进口设备无屏蔽条件下工控链路合规检测方案](https://mp.weixin.qq.com/s/nAXT_-cMZH1WQQWTcqBw-w) - [ ] [红队渗透工具 -- bface-agent](https://mp.weixin.qq.com/s/UD8iv_LmAQnGxTeFThV6dw) - [ ] [浙江省数据集团揭牌成立,与安恒信息签约共建安全TOKEN工厂](https://mp.weixin.qq.com/s/lJ8JVKsfUtqzJvBmdNehvw) - [ ] [安服?阿福!](https://mp.weixin.qq.com/s/5Hm6up7I3zO7CNIxCJHb_A) - [ ] [基于Gopher协议残存攻击面的SSRF内网协议链式探测](https://mp.weixin.qq.com/s/O1vSjOz3EjS3-0fx95HifA) - [ ] [汽车钥匙:汽车取证中容易忽视的“隐秘角落”](https://mp.weixin.qq.com/s/5yCJZxeF1BST_6hx6WO0Vw) - [ ] [重磅!Anthropic内部AI Native经验公开了!](https://mp.weixin.qq.com/s/BpwSsSjjNoy2T-5dlkBuhA) - [ ] [工具 | Vipere](https://mp.weixin.qq.com/s/oRk3w4xV_EQR5Tg7kFFvKw) - [ ] [极端气象环境下外军无人机作战适应性与全天候运用能力研究](https://mp.weixin.qq.com/s/bGSwcWLjpPD0xD8qzfB5hQ) - [ ] [认知战与权力逻辑:解读俄罗斯战略信息作战中的进攻现实主义(二)](https://mp.weixin.qq.com/s/9N_HTM-WKlHP0REmsx4xCQ) - [ ] [北约ACT《认知战》概念探索(一):当战争从身体转向心智](https://mp.weixin.qq.com/s/LYWGSPwcdMQw17hXbJJS3w) - [ ] [GAT 2380—2026《信息安全技术 网络安全等级保护数据安全基本要求》(报批稿)](https://mp.weixin.qq.com/s/d_Bp0xLgkc-L688_j5RYAw) - [ ] [行业资讯:网络安全项目中标情况汇总(8月26日)](https://mp.weixin.qq.com/s/9tZMDdYxZn146McuErG0TA) - [ ] [工具推荐 | SQL注入检测效率翻倍,一键配置自动化检测](https://mp.weixin.qq.com/s/ccbJdlj-25HhGylyMxoiUg) - Private Feed for M09Ic - [ ] [anthropics released v2.1.248 at anthropics/claude-code](https://github.com/anthropics/claude-code/releases/tag/v2.1.248) - [ ] [strands-agents released python/v1.54.0 at strands-agents/harness-sdk](https://github.com/strands-agents/harness-sdk/releases/tag/python/v1.54.0) - [ ] [mgeeky starred pollen-robotics/microduck](https://github.com/pollen-robotics/microduck) - [ ] [timwhitez starred timwhitez/aegis-agent](https://github.com/timwhitez/aegis-agent) - [ ] [Ascotbe starred freestylefly/awesome-gpt-image-2](https://github.com/freestylefly/awesome-gpt-image-2) - [ ] [wh0amitz starred LAME-Projects/stratum-c2](https://github.com/LAME-Projects/stratum-c2) - [ ] [esrrhs contributed to esrrhs/fakecc](https://github.com/esrrhs/fakecc/pull/41) - [ ] [gh0stkey starred raullenchai/Rapid-MLX](https://github.com/raullenchai/Rapid-MLX) - [ ] [joaoviictorti starred tailscale/tailcat](https://github.com/tailscale/tailcat) - [ ] [Rvn0xsy starred exelban/stats](https://github.com/exelban/stats) - [ ] [airbus-seclab released v4.8.4 at airbus-seclab/soxy](https://github.com/airbus-seclab/soxy/releases/tag/v4.8.4) - Recent Commits to cve:main - [ ] [Update Thu Aug 27 11:56:08 UTC 2026](https://github.com/trickest/cve/commit/ea673a226031bc550c60f1e0bf6d46d3e190eff9) - SecWiki News - [ ] [SecWiki News 2026-08-27 Review](http://www.sec-wiki.com/?2026-08-27) - Microsoft Security Blog - [ ] [What’s new in Microsoft Security: August 2026](https://www.microsoft.com/en-us/security/blog/2026/08/27/whats-new-in-microsoft-security-august-2026/) - Tenable Blog - [ ] [How to build an exposure management program the business trusts: Lessons from Tenable’s CSO](https://www.tenable.com/blog/how-to-build-an-exposure-management-program-the-business-trusts-lessons-from-tenables-cso) - 安全客-有思想的安全新媒体 - [ ] [Redis补丁被绕过了:最新RCE的PoC已全网公开,你的缓存服务器还在裸奔吗](https://www.anquanke.com/post/id/316025) - [ ] [科技云报到:Agent不省钱反而亏钱?你需要这位“魔术师”](https://www.anquanke.com/post/id/316019) - GuidePoint Security - [ ] [Hunting Abuse: Detecting Privilege Escalation Through the ADCS Database](https://www.guidepointsecurity.com/blog/detecting-privilege-escalaction-through-adcs/) - Malwarebytes - [ ] [Flock wants privacy to meet surveillance halfway](https://www.malwarebytes.com/blog/privacy/2026/08/flock-wants-privacy-to-meet-surveillance-halfway) - [ ] [Fake listings can turn trusted platforms into scam springboards](https://www.malwarebytes.com/blog/scams/2026/08/fake-listings-can-turn-trusted-platforms-into-scam-springboards) - [ ] [Fake Apple Pay charge brings the classic tech support scam to your phone](https://www.malwarebytes.com/blog/scams/2026/08/fake-apple-pay-charge-brings-the-classic-tech-support-scam-to-your-phone) - [ ] [New Instagram and Facebook rules set a default two-hour limit for teens](https://www.malwarebytes.com/blog/news/2026/08/new-instagram-and-facebook-rules-will-set-a-default-two-hour-daily-limit-for-teens) - Kitploit - [ ] [AIDebug](https://kitploit.com/en/tools/github/anpa1200/aidebug) - [ ] [llm-agent-testbed](https://kitploit.com/en/tools/github/pie-script/llm-agent-testbed) - [ ] [OWN-Defender](https://kitploit.com/en/tools/github/nirvanaon/own-defender) - [ ] [ysonet](https://kitploit.com/en/tools/github/irsdl/ysonet) - [ ] [stratum-c2](https://kitploit.com/en/tools/github/lame-projects/stratum-c2) - [ ] [log4j2-rce](https://kitploit.com/en/tools/github/hypnguyen1209/log4j2-rce) - [ ] [OWASP-Hunting](https://kitploit.com/en/tools/github/owasp/owasp-hunting) - [ ] [OWASP-Top-10-AI-Infrastructure-Security-Risks](https://kitploit.com/en/tools/github/owasp/owasp-top-10-ai-infrastructure-security-risks) - [ ] [nl-kat-coordination](https://kitploit.com/en/tools/github/ssc-ict-innovatie/nl-kat-coordination) - [ ] [WSGoat](https://kitploit.com/en/tools/github/makarov05bm/wsgoat) - [ ] [CVE-2014-085](https://kitploit.com/en/tools/github/ehaoxiongdiycw/cve-2014-085) - [ ] [FuzzingBrain-Bench](https://kitploit.com/en/tools/github/fuzzingbrain/fuzzingbrain-bench) - [ ] [agentZ](https://kitploit.com/en/tools/github/accuknox/agentz) - [ ] [binviz](https://kitploit.com/en/tools/github/karankantaria/binviz) - [ ] [imMapper](https://kitploit.com/en/tools/github/ioallocate/immapper) - [ ] [ditto](https://kitploit.com/en/tools/github/airbus-cert/ditto) - [ ] [WinFlesher](https://kitploit.com/en/tools/github/mindsflee/winflesher) - [ ] [specterops-k8s-red-teamers-libvirt-patch](https://kitploit.com/en/tools/github/gregdurys/specterops-k8s-red-teamers-libvirt-patch) - [ ] [nvidia-gpu-security-poc](https://kitploit.com/en/tools/github/abhinavagarwal07/nvidia-gpu-security-poc) - [ ] [pentx-vapt-skill](https://kitploit.com/en/tools/github/yashas-13/pentx-vapt-skill) - [ ] [Findomain v11.0.0-beta.1](https://kitploit.com/en/posts/github-findomain-findomain-1100-beta1) - [ ] [aegis-latent-core](https://kitploit.com/en/tools/github/juanlunaia/aegis-latent-core) - [ ] [RDP-Guard](https://kitploit.com/en/tools/gitlab/siberanka/rdp-guard) - [ ] [hayduk](https://kitploit.com/en/tools/github/jolovicdev/hayduk) - [ ] [Sentora](https://kitploit.com/en/tools/github/d3vhex/sentora) - HackerNews - [ ] [Avada WordPress 主题严重漏洞可实现零点击 RCE](http://0.0.0.0:8080/post/64607) - [ ] [Boston Scientific 称网络攻击导致全球运营中断](http://0.0.0.0:8080/post/64606) - [ ] [新型 GPUThor 攻击突破 NVIDIA ECC 保护实现 root 权限获取](http://0.0.0.0:8080/post/64605) - [ ] [CISA 红队攻陷两家关键基础设施组织,一家毫无察觉](http://0.0.0.0:8080/post/64604) - [ ] [Nimbus Manticore 扩展工具集:新增类 TWOSTROKE 后门与 SSH 隧道工具](http://0.0.0.0:8080/post/64603) - [ ] [NovaCookies 活动滥用真实 Docusign 通知窃取 Microsoft 365 会话](http://0.0.0.0:8080/post/64602) - 奇客Solidot–传递最新科技情报 - [ ] [一名微软工程师一个月的 AI 支出高达 2.8 万美元](https://www.solidot.org/story?sid=85216) - [ ] [Meta将支付 170 亿美元和解儿童隐私保护诉讼,将限制青少年在特定时间访问社媒](https://www.solidot.org/story?sid=85215) - [ ] [NASA 准备本周日发射罗曼太空望远镜](https://www.solidot.org/story?sid=85214) - [ ] [亚马逊 AI 训练设施员工谈内部工作](https://www.solidot.org/story?sid=85213) - [ ] [亚马逊 Mechanical Turk 将于 9 月 30 日关闭](https://www.solidot.org/story?sid=85212) - [ ] [LibreOffice 26.8 释出](https://www.solidot.org/story?sid=85211) - [ ] [Apple Maps 加入广告](https://www.solidot.org/story?sid=85210) - [ ] [中尼边境泥石流灾害逾 1300 人失踪](https://www.solidot.org/story?sid=85209) - [ ] [亚马逊收购开源数据库 DuckDB 开发团队](https://www.solidot.org/story?sid=85208) - [ ] [新 Twitter.now 上线](https://www.solidot.org/story?sid=85207) - [ ] [英伟达同意以 129 亿美元收购 Hugging Face](https://www.solidot.org/story?sid=85206) - Panda's Blog - [ ] [Java安全20年:从BlackHat20年议题看Java安全发展趋势](https://www.cnpanda.net/sec/java-security-blackhat-2002-2026.html) - 腾讯玄武实验室 - [ ] [每日安全动态推送(26/8/27)](https://mp.weixin.qq.com/s?__biz=MzA5NDYyNDI0MA==&mid=2651960534&idx=1&sn=8a01a89a934021f179cc88cf5f29b27b) - Shostack & Friends Blog - [ ] [Boundaries, Not Trust Boundaries (Threat Model Thursday)](https://shostack.org/blog/boundaries-threat-model-thursday/) - 威努特安全网络 - [ ] [大模型和算力的选型与调优](https://mp.weixin.qq.com/s?__biz=MzAwNTgyODU3NQ==&mid=2651143689&idx=1&sn=31d94ec6565ada63882975f0334caaac) - 微步在线研究响应中心 - [ ] [不是"核弹"。Log4j issue 4255 的FAQ](https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&mid=2247508851&idx=1&sn=6d4abc77773fd4c209c7f88dcf8dbe6e) - 安全内参 - [ ] [知名医疗器械上市公司遭网络攻击:全球运营中断 预计数周才能恢复](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516487&idx=1&sn=5e38d92ebe9baa097e570f52c7b5f5d2) - [ ] [美国国家安全局举办非传统重聚活动吸引精英黑客重返TAO](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516487&idx=2&sn=ee540fe85ef729105ee850e1e68a51ad) - 黑鸟 - [ ] [浏览网页劫持本地 AI 智能体](https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451188310&idx=1&sn=d037430d718c37b91701a75cb3f5ca86) - 代码卫士 - [ ] [OpenSSL 多个漏洞可导致服务器远程崩溃、堆内存损坏](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247526978&idx=1&sn=0b79f23829d11d3ffdf826da6b5075d2) - [ ] [SonicWall NetExtender 多个漏洞可用于以root身份写入任意文件](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247526978&idx=2&sn=43af008fe7c471a0e023d7056f53e66d) - 安全客 - [ ] [Redis补丁被绕过了:最新RCE的PoC已全网公开,你的缓存服务器还在裸奔吗](https://mp.weixin.qq.com/s?__biz=MzA5ODA0NDE2MA==&mid=2649790421&idx=1&sn=04d34797f18ebbbcc719392803a5cade) - 吾爱破解论坛 - [ ] [吾爱破解论坛网络诊断修复工具 v3.2 新增验证码异常修复](https://mp.weixin.qq.com/s?__biz=MjM5Mjc3MDM2Mw==&mid=2651144702&idx=1&sn=6bb514af5aac64ef49fbd1b72c0b66d4) - 微步在线 - [ ] [2人团队,用Flocks全自动安全运营!](https://mp.weixin.qq.com/s?__biz=MzI5NjA0NjI5MQ==&mid=2650187785&idx=1&sn=6e3cded727785abec4375e15d23bab5d) - 奇安信 CERT - [ ] [Log4j2 Issue #4255 深度解析:技术真相与风险评估](https://mp.weixin.qq.com/s?__biz=MzU5NDgxODU1MQ==&mid=2247507249&idx=1&sn=abb209214149c740debd33859fd3e96d) - 安全学术圈 - [ ] [行业会议|第八届“纵横”网络空间安全创新论坛详细议题](https://mp.weixin.qq.com/s?__biz=MzU5MTM5MTQ2MA==&mid=2247495854&idx=1&sn=eca06ff0e907a75962e7399d2d0b1923) - 中国信息安全 - [ ] [前沿 | 汽车数据出境的安全风险演进及治理谱系建构](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265962&idx=1&sn=d7f8f8beb98093c52330822001c8e332) - [ ] [专家解读|做强做优做大网信企业 以高质量发展扛起高水平科技自立自强时代使命](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265962&idx=2&sn=d005d169fed301572d4fc7ace8271e53) - [ ] [专家观点 | 落实四大全球倡议 推进人工智能全球治理](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265962&idx=3&sn=59a6b1fba9dca970b293aa85f2b1656d) - [ ] [观点 | 推动大型个人信息处理者提升保护能力](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265962&idx=4&sn=48b8bc5b476ec0daa6083fb3ca7a244b) - [ ] [评论 | 开放共赢是人工智能发展的必由之路](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265962&idx=5&sn=601b9348f4cec47e34982f1a2a5c07d5) - 极客公园 - [ ] [编辑部来了 AI 实习生|千问入职 20 天,我给它写了一份实习小结](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653112790&idx=1&sn=d0ad1e4770af28b086658469fe0f3e3d) - [ ] [一年卖出 3 万台后,极壳即将发布下一代外骨骼](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653112782&idx=1&sn=cb0fe63a5ca2a8d04711cb7cf37bd645) - [ ] [Ox Alpha「牛来」 身份揭晓;黄仁勋:AI 已迈过商业化拐点;世界人形机器人运动会闭幕:天工 Ultra 百米跑出 8 秒 64|极客早知道](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653112732&idx=1&sn=0f42387fba8026a9603a21b24b1a4c96) - 看雪学苑 - [ ] [永夜鏖战落幕!2026 KCTF 圆满收官,榜单公布](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458618994&idx=1&sn=32bb5fe3d643c6f97f2982cc991ebb58) - [ ] [D3CTF 2026 d3llvm.apk 反调试定位与加密 SO的Dump](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458618994&idx=2&sn=f6d8e52efe0c96ba3684bce3529c3d30) - [ ] [Log4j2 新漏洞绕过安全白名单,部分部署可远程代码执行](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458618994&idx=3&sn=0488a148cf4827e04a6ac7248fb80eea) - 奇安信威胁情报中心 - [ ] [npm 供应链双重威胁:AI 远控植入 + ClickFix 钓鱼存储](https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247520041&idx=1&sn=d6c2f6dff18ee2a3a81507b59e9f60b6) - 安全圈 - [ ] [【安全圈】GPUThor击穿N卡ECC防线:普通算力夺宿主Root](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078465&idx=1&sn=6803572c0747bad6b3bca99e1d770ca7) - [ ] [【安全圈】CISA通报网关与数据库6大漏洞遭在野利用](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078465&idx=2&sn=40dc01c9d631dc45a8ac7ea0406d1a8f) - [ ] [【安全圈】FBI捣毁黑客隐蔽跳板军火库斩断潜伏链路](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078465&idx=3&sn=649134b790a408e1586536a05fdbc592) - 青藤云安全 - [ ] [AI攻防备战报告:攻击可以买,防守只能自建](https://mp.weixin.qq.com/s?__biz=MzAwNDE4Mzc1NA==&mid=2650851725&idx=1&sn=95c3457371369392343676c165b459ec) - 数世咨询 - [ ] [微软 Defender 自带的驱动程序可能被恶意利用,在启动时删除安全软件](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247543807&idx=1&sn=253c60961a081a59c2f6da0ad03daa09) - [ ] [三十年网安跃迁:从产业迭代看国产ASIC的使命与担当](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247543807&idx=2&sn=de5a3240e3e5edbd0981ff0746d08eef) - 补天平台 - [ ] [蓉城共探安全攻防新格局 | 补天沙龙成都站报名启动!](https://mp.weixin.qq.com/s?__biz=MzI2NzY5MDI3NQ==&mid=2247510996&idx=1&sn=61b1f91efb8343278462371807c3f5f7) - 复旦白泽战队 - [ ] [办公智能体大战正酣,它能安全地操作你的文件吗?(上)](https://mp.weixin.qq.com/s?__biz=MzU4NzUxOTI0OQ==&mid=2247499683&idx=1&sn=713e61025310a75ef0357d8c31a7115e) - 安全牛 - [ ] [你的 ChatGPT 可能正在被“安静入侵”:AI使用者的15 分钟黄金止损手册](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142477&idx=1&sn=c1c013bdc1feaba8a2df1e2eb95fbded) - [ ] [7 项网络安全国家标准征求意见稿公开征求意见;逆向工程发现:Microsoft Paint 内置强制 InvisMark 隐形盲水印,用户无法关闭| 牛览](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142477&idx=2&sn=269a11fe2db5a3c9264f1799db190113) - 火绒安全 - [ ] [开学季这些"套路"要当心 火绒护航开学新征程](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247536866&idx=1&sn=9fcd945343a550f6a4fb8e253fc71bb2) - [ ] [诚邀渠道合作伙伴共启新征程](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247536866&idx=2&sn=b210c17b21e3ebe4e502adc149223803) - 云鼎实验室 - [ ] [以无厚入有间:CodeBuddy Security的漏洞发现思路与实践](https://mp.weixin.qq.com/s?__biz=MzU3ODAyMjg4OQ==&mid=2247497935&idx=1&sn=4a79fa45de221104b0195b8d0bcd0234) - 安全分析与研究 - [ ] [EDR架构与检测机制](https://mp.weixin.qq.com/s?__biz=MzA4ODEyODA3MQ==&mid=2247497067&idx=1&sn=d23a5ec63b908dd0db297e9b68b3209a) - 字节跳动技术团队 - [ ] [ADrive 跨产品协作实践:文件通了,Agent 就通了](https://mp.weixin.qq.com/s?__biz=MzI1MzYzMjE0MQ==&mid=2247521712&idx=1&sn=584ee46d8b9021b56004a8a7e318e2d0) - 君哥的体历 - [ ] [情报洞察|美国陆军启动“狮鹫项目”以构建AI智能体网络自主防御体系](https://mp.weixin.qq.com/s?__biz=MzI2MjQ1NTA4MA==&mid=2247492547&idx=1&sn=31a7f62db860ec7acd09eaefaeb5233e) - 情报分析师 - [ ] [尼泊尔"8·26"山洪的地理情报复盘——卫星图前后对比曝光之后,我们到底看见了什么?](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650569279&idx=1&sn=120c8db43dfbc924b928d67703188a45) - [ ] [新西兰情报局发布《安全威胁环境》报告,外国国家及其代理人针对知识产权、创新技术与侨民社区的活动对我在太平洋及海外利益的关联风险](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650569279&idx=2&sn=9e84d0decfbc3d8391872da18c514a70) - 丁爸 情报分析师的工具箱 - [ ] [【开源报告】美国国家安全局恢复 “特定入侵行动办公室”](https://mp.weixin.qq.com/s?__biz=MzI2MTE0NTE3Mw==&mid=2651157205&idx=1&sn=4db45c88b7b3053048b2a897ef76ebdc) - [ ] [【开源报告】美国特别入侵行动办公室人员梳理调研报告](https://mp.weixin.qq.com/s?__biz=MzI2MTE0NTE3Mw==&mid=2651157205&idx=2&sn=17c103d14b9d55e955f4b7ad636f9c2a) - 表图 - [ ] [从奖励黑客到超级对齐:AI 为何会完成任务,却背离人类意图](https://mp.weixin.qq.com/s?__biz=MzUzOTI4NDQ3NA==&mid=2247485161&idx=1&sn=1c3e5f54f27433991d8930d6c97b8b97) - ChaMd5安全团队 - [ ] [某国产PLC固件安全分析研究](https://mp.weixin.qq.com/s?__biz=MzIzMTc1MjExOQ==&mid=2247514453&idx=1&sn=620c8da5e32a1fc8c142be0092a5e0a6) - Qualys Security Blog - [ ] [PCI DSS 4.0.1: Application Requirements You’re Being Assessed On in 2026](https://blog.qualys.com/category/qualys-insights) - D3Lab - [ ] [Phishing a danno del Registro delle Imprese](https://www.d3lab.net/phishing-a-danno-del-registro-delle-imprese/) - 国家互联网应急中心CNCERT - [ ] [中国—东盟网络安全应急响应能力建设研讨会在北京举办](https://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw==&mid=2247502071&idx=1&sn=40c30dbc916c2ee8c1873c9af86e69b5) - 美团技术团队 - [ ] [GeoRA: 为RLVR设计的LoRA——ACL 2026杰出论文解析](https://mp.weixin.qq.com/s?__biz=MjM5NjQ5MTI5OA==&mid=2651783211&idx=1&sn=ebc6f935700052ebc5ab702911ce8449) - [ ] [校招|美团无人机2027届北斗计划热招中](https://mp.weixin.qq.com/s?__biz=MjM5NjQ5MTI5OA==&mid=2651783211&idx=2&sn=68dc28cbb4d361a2d3fffc92ff03dcf3) - [ ] [55 万元大奖等你挑战!2026 美团低空经济与具身智能挑战赛报名倒计时](https://mp.weixin.qq.com/s?__biz=MjM5NjQ5MTI5OA==&mid=2651783211&idx=3&sn=61a0e88c38f88d9b529882611b696d3f) - 威胁猎人Threat Hunter - [ ] [恶意手机号产业链调研:海外手机号成为黑产批量注册和换号验证的重要资源](https://mp.weixin.qq.com/s?__biz=MzI3NDY3NDUxNg==&mid=2247505131&idx=1&sn=ba2c8fbd9ca0ce910e36385a61500f46) - LastKnight.com Feed - [ ] [META HA VINTO: la multa è solo il prezzo](https://mgpf.it/2026/08/27/meta-ha-vinto.html) - Schneier on Security - [ ] [LLM-Based Social Engineering Scams](https://www.schneier.com/blog/archives/2026/08/llm-based-social-engineering-scams.html) - SANS Internet Storm Center, InfoCON: green - [ ] [A polymorphic phishing page (that occasionally breaks itself), (Thu, Aug 27th)](https://isc.sans.edu/diary/rss/33290) - [ ] [ISC Stormcast For Thursday, August 27th, 2026 https://isc.sans.edu/podcastdetail/10070, (Thu, Aug 27th)](https://isc.sans.edu/diary/rss/33286) - RedTeam - [ ] [用 AI 搞 Google VRP 赚了50万美金](https://mp.weixin.qq.com/s?__biz=Mzg5NjAxNjc5OQ==&mid=2247484692&idx=1&sn=da658538620fddc879c274ba5f08c6bb) - Yak Project - [ ] [牛来,速归!Memfit接入:GLM-5.3;Qwen3.8-Flash](https://mp.weixin.qq.com/s?__biz=Mzk0MTM4NzIxMQ==&mid=2247530123&idx=1&sn=479bf6c20dba87a9a83ac70af777ffc3) - Future of Tech and Security: Strategy & Innovation with Raffy - [ ] [Strategy Is Not the Value-Creation Plan](https://raffy.ch/blog/2026/08/27/strategy-is-not-the-value-creation-plan/) - Securelist - [ ] [Threat landscape for industrial automation systems. Q2 2026](https://securelist.com/industrial-threat-report-q2-2026/121159/) - The Hacker News - [ ] [OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face](https://thehackernews.com/2026/08/openai-says-reward-hacking-drove-ai.html) - [ ] [Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE](https://thehackernews.com/2026/08/nextjs-patches-critical-avif-and.html) - [ ] [ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories](https://thehackernews.com/2026/08/threatsday-296k-iot-botnet-100-water.html) - [ ] [Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers](https://thehackernews.com/2026/08/amazon-kiro-prompt-injection-can.html) - [ ] [Learn How to Build Security Operations Ready for AI-Powered Attacks](https://thehackernews.com/2026/08/learn-how-to-build-security-operations.html) - [ ] [Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks](https://thehackernews.com/2026/08/alleged-teampcp-hackers-charged-in.html) - [ ] [What the Data Says About AI in Security Operations in 2026](https://thehackernews.com/2026/08/what-data-says-about-ai-in-security.html) - [ ] [Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools](https://thehackernews.com/2026/08/spark-rat-targets-cambodia-abuses.html) - [ ] [GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address](https://thehackernews.com/2026/08/gocaracal-malware-uses-ethereum-smart.html) - [ ] [New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access](https://thehackernews.com/2026/08/gputhor-rowhammer-defeats-ecc-on-nvidia.html) - [ ] [CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs](https://thehackernews.com/2026/08/cisa-adds-six-exploited-flaws-to-kev.html) - KitPloit - PenTest Tools! - [ ] [AIDebug](https://kitploit.com/en/tools/github/anpa1200/aidebug) - [ ] [llm-agent-testbed](https://kitploit.com/en/tools/github/pie-script/llm-agent-testbed) - [ ] [OWN-Defender](https://kitploit.com/en/tools/github/nirvanaon/own-defender) - [ ] [ysonet](https://kitploit.com/en/tools/github/irsdl/ysonet) - [ ] [stratum-c2](https://kitploit.com/en/tools/github/lame-projects/stratum-c2) - [ ] [log4j2-rce](https://kitploit.com/en/tools/github/hypnguyen1209/log4j2-rce) - [ ] [OWASP-Hunting](https://kitploit.com/en/tools/github/owasp/owasp-hunting) - [ ] [OWASP-Top-10-AI-Infrastructure-Security-Risks](https://kitploit.com/en/tools/github/owasp/owasp-top-10-ai-infrastructure-security-risks) - [ ] [nl-kat-coordination](https://kitploit.com/en/tools/github/ssc-ict-innovatie/nl-kat-coordination) - [ ] [WSGoat](https://kitploit.com/en/tools/github/makarov05bm/wsgoat) - [ ] [CVE-2014-085](https://kitploit.com/en/tools/github/ehaoxiongdiycw/cve-2014-085) - [ ] [FuzzingBrain-Bench](https://kitploit.com/en/tools/github/fuzzingbrain/fuzzingbrain-bench) - [ ] [agentZ](https://kitploit.com/en/tools/github/accuknox/agentz) - [ ] [binviz](https://kitploit.com/en/tools/github/karankantaria/binviz) - [ ] [imMapper](https://kitploit.com/en/tools/github/ioallocate/immapper) - [ ] [ditto](https://kitploit.com/en/tools/github/airbus-cert/ditto) - [ ] [WinFlesher](https://kitploit.com/en/tools/github/mindsflee/winflesher) - [ ] [specterops-k8s-red-teamers-libvirt-patch](https://kitploit.com/en/tools/github/gregdurys/specterops-k8s-red-teamers-libvirt-patch) - [ ] [nvidia-gpu-security-poc](https://kitploit.com/en/tools/github/abhinavagarwal07/nvidia-gpu-security-poc) - [ ] [pentx-vapt-skill](https://kitploit.com/en/tools/github/yashas-13/pentx-vapt-skill) - [ ] [Findomain v11.0.0-beta.1](https://kitploit.com/en/posts/github-findomain-findomain-1100-beta1) - [ ] [aegis-latent-core](https://kitploit.com/en/tools/github/juanlunaia/aegis-latent-core) - [ ] [RDP-Guard](https://kitploit.com/en/tools/gitlab/siberanka/rdp-guard) - [ ] [hayduk](https://kitploit.com/en/tools/github/jolovicdev/hayduk) - [ ] [Sentora](https://kitploit.com/en/tools/github/d3vhex/sentora) - [ ] [keyhog v0.5.86](https://kitploit.com/en/posts/github-santhreal-keyhog-v0586) - Instapaper: Unread - [ ] [Black Hat Asia 2026 | Exploiting DFIR Agents Through Adversarial Manipulation](https://www.youtube.com/watch?v=sK8omfWUMaM) - [ ] [Android Intrusion Logs](https://www.iverify.com/blog/android-intrusion-logging-forensics-analysis) - Security Affairs - [ ] [Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback](https://securityaffairs.com/197948/apt/dark-caracal-deploys-new-go-malware-with-ethereum-based-c2-fallback.html) - [ ] [Australian Police Charge Two Over TeamPCP Credential Theft](https://securityaffairs.com/197929/security/two-arrests-one-supply-chain-attack-and-a-lot-of-stolen-credentials.html) - [ ] [Meta to Pay Up to $18B Over Teen Social Media Use](https://securityaffairs.com/197914/laws-and-regulations/meta-to-pay-up-to-18b-over-teen-social-media-use.html) - [ ] [CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do](https://securityaffairs.com/197891/ics-scada/cisa-warns-water-utilities-find-your-exposed-plcs-before-attackers-do.html) - [ ] [OpenAI banned Russian ChatGPT accounts backing covert influence operation](https://securityaffairs.com/197878/intelligence/openai-banned-russian-chatgpt-accounts-backing-covert-influence-operation.html) - Tor Project blog - [ ] [New Alpha Release: Tor Browser 16.0a10](https://blog.torproject.org/new-alpha-release-tor-browser-160a10/) - Krebs on Security - [ ] [Two Alleged ‘TeamPCP’ Hackers Arrested in Australia](https://krebsonsecurity.com/2026/08/two-alleged-teampcp-hackers-arrested-in-australia/) - www.theregister.com - Articles - [ ] [CRPx0 hacking service for dummies claims victim count more than quintupled](https://www.theregister.com/cyber-crime/2026/08/27/crpx0-hacking-service-for-dummies-claims-victim-count-more-than-quintupled/5293097) - [ ] [AI girlfriend review site's secrets were exposed to the world for three weeks](https://www.theregister.com/security/2026/08/27/ai-girlfriend-review-sites-secrets-were-exposed-to-the-world-for-three-weeks/5293064) - [ ] [Omarchy distro gains serious backing](https://www.theregister.com/os-platforms/2026/08/27/omarchy-distro-gains-serious-backing/5293026) - [ ] [ATF responds to 'major' cybersecurity incident after ransomware gang's claims](https://www.theregister.com/security/2026/08/27/atf-responds-to-major-cybersecurity-incident-after-ransomware-gangs-claims/5292990) - [ ] [Schrödinger's backup: not actually recovered until you try to restore IT](https://www.theregister.com/security/2026/08/27/sponsored-schroedingers-backup-not-actually-recovered-until-you-try-to-restore-it/5286772) - [ ] [Cybercrooks jet off with Manchester Airports Group customer data](https://www.theregister.com/security/2026/08/27/cybercrooks-jet-off-with-manchester-airports-group-customer-data/5292943) - [ ] [Nuisance-call blocker fined £190k for being a nuisance caller](https://www.theregister.com/security/2026/08/27/nuisance-call-blocker-fined-190k-for-being-a-nuisance-caller/5292888) - [ ] [FBI seizes hacking tools it says China used to attack NASA, DOE, US Senate and other critical networks](https://www.theregister.com/security/2026/08/27/fbi-seizes-hacking-tools-it-says-china-used-to-attack-nasa-doe-us-senate-and-other-critical-networks/5292742) - Security Weekly Podcast Network (Audio) - [ ] [Hacking All The Devices, with AI? - Rob Allen - PSW #941](http://sites.libsyn.com/18678/hacking-all-the-devices-with-ai-rob-allen-psw-941)
每日安全资讯(2026-08-28)