# 每日安全资讯(2026-08-29) - SecWiki News - [ ] [SecWiki News 2026-08-28 Review](http://www.sec-wiki.com/?2026-08-28) - Paper - 知道创宇404实验室 - [ ] [通过基于搜索的优化从工业网络流量中恢复过程变量](https://paper.seebug.org/3514) - Doonsec's feed - [ ] [视频 | 数智人才齐汇聚 青春挺膺护网安!第三届“长城杯”网数智安全大赛(作品赛)决赛在哈尔滨圆满举办](https://mp.weixin.qq.com/s/sXNvBSg3wh1dkk81Hu45rA) - [ ] [安恒信息入选全国数标委数据基础设施三项国标验证试点单位](https://mp.weixin.qq.com/s/bAk3RWet3EYLbAQ59dDuag) - [ ] [Redstone 使用指南(二)丨渗透测试模块](https://mp.weixin.qq.com/s/9aK9ki7fgmwcz0Gq20RJxg) - [ ] [评论 | 莫让人工智能“偷声”击穿社会信任](https://mp.weixin.qq.com/s/UQdr3chY67y2aDsLV3fKmQ) - [ ] [深化产教融合|郑州经贸学院大数据与人工智能学院走进天融信教育](https://mp.weixin.qq.com/s/JxTP7CekiTwd5gEvCEO86w) - [ ] [如何打造一款以实战环境为目标的漏洞研究专](https://mp.weixin.qq.com/s/LAm_4LEIRWMFJn2pR1dzrQ) - [ ] [《国际金融报》再度采访CertiK,聚焦AI“越界”风险与安全治理](https://mp.weixin.qq.com/s/XilZ0K35h_AAMvdru7FJiQ) - [ ] [盛邦安全半年报:四大“新”突破,赋能蓄势成长新局](https://mp.weixin.qq.com/s/QGQDlYjvBMgOBJxONnbE1w) - [ ] [覆盖车联网、信创、AI等领域,360入选工信部六大漏洞专业库技术支撑单位](https://mp.weixin.qq.com/s/mYyTkLv21_d1XfFe7jqmTg) - [ ] [AI威胁推高网络安全支出,多家网安企业业绩再超预期](https://mp.weixin.qq.com/s/j5R7FTQTF-AmrL7OIPh4TA) - [ ] [企业文档安全最佳实践(五):业务系统集成——三种方式让加密文件在业务系统中照常应用](https://mp.weixin.qq.com/s/5cNa7ubYWG-lM-sGjqfv-g) - [ ] [学校荣获成都世运会先进集体和先进个人表彰](https://mp.weixin.qq.com/s/6mRtancOWKqr4uLVh1W54w) - [ ] [9月19日,天融信邀您共赴CCSC2026「网络空间安全科技女性发展论坛」](https://mp.weixin.qq.com/s/HopF5Lfa1abFwA4Rq_C8fA) - [ ] [看好咱的“家伙事儿”,别让数据“溜出去”](https://mp.weixin.qq.com/s/ufzhAoKQZ-L5iMWjl2NXEA) - [ ] [武汉算力公共服务平台3.0上线,《促进网信企业高质量发展行动计划》印发(8.21-8.28)](https://mp.weixin.qq.com/s/eMxkVboVBf028FiB0w7Qag) - [ ] [砸几万块考网安证书,面试却被当成“花瓶”?一文讲透CISP与OSCP的本质差异与职业规划](https://mp.weixin.qq.com/s/tPO1C5DU1KlWUmc5iAHgbQ) - [ ] [中国—东盟网络安全应急响应能力建设研讨会在北京举办,多国代表走进天融信实地参观](https://mp.weixin.qq.com/s/PNaY-QV6rJgAglq6VecBJw) - [ ] [公安机关持续严厉打击编造传播涉台风等涉灾网络谣言,公布4起典型案例](https://mp.weixin.qq.com/s/stkkxRlW0o79lFrjk-eGZw) - [ ] [勇夺第一名 | 中国网安/三十所在2026年成都市电子信息工会“五小”创新成果评选中获优异成绩](https://mp.weixin.qq.com/s/SmpIWs-_9mtZr4dliB30PA) - [ ] [常规操作下,安全漏洞无所遁形](https://mp.weixin.qq.com/s/EF3kM-xigIdm7F_VxcQ75Q) - [ ] [【免费领】全网最全的CTF入门到实战学习宝典(超1800页)](https://mp.weixin.qq.com/s/SJUQvDkNRZwVisM_ZQeb4Q) - [ ] [网络安全动态 - 2026.8.28](https://mp.weixin.qq.com/s/MEHHogdaVvdfY8e8cS6I3g) - [ ] [甲方敢问,专家敢答 | 关于聚铭铭溯全流量分析系统V2.0的10个硬核答案](https://mp.weixin.qq.com/s/3ifGk9cBtKSJoY-Jh7j3kA) - [ ] [筑牢关基安全屏障,工程中心作为参编单位受邀参加关键信息基础设施安全保护系列团体标准发布大会](https://mp.weixin.qq.com/s/0px_encqa8ht5QiAN5m9Tg) - [ ] [麦肯锡:AI 用得越来越多,钱却没赚到](https://mp.weixin.qq.com/s/ItLPoGDGGK9HMeMUjXjsww) - [ ] [关于加强知识产权数据资源开发利用的意见](https://mp.weixin.qq.com/s/C_dmBPmp0FawrijQc_epOQ) - [ ] [安全威胁情报周报(2026/08/22-2026/08/28)](https://mp.weixin.qq.com/s/WHaugebfQMbP0dTiOHZiHg) - [ ] [安全简讯(2026.08.28)](https://mp.weixin.qq.com/s/CFbaFytdNXvxQGprcvP9aQ) - [ ] [【漏洞通告】Nacos 管理接口权限绕过漏洞](https://mp.weixin.qq.com/s/yZ-wtOU99e5tqpSTNUNjig) - [ ] [未来健康主题产业对接活动在蓉成功举办 政产学研资共绘健康产业新蓝图](https://mp.weixin.qq.com/s/0QJvbguI5CTPP7yWWX-1jg) - [ ] [AI安全典型案例 | 观安观鉴——大模型可信治理平台](https://mp.weixin.qq.com/s/4ave1IJsjbUrUg-_GckTcA) - [ ] [千亿资管巨头被社工攻破泄密:再强大的安全设备,也防不住人被骗](https://mp.weixin.qq.com/s/J58sBJIeZoy7cOsioGy_fg) - [ ] [红队专挑半夜上强度,长亭 AIMDR 这波顶住了](https://mp.weixin.qq.com/s/-o-n2LquzxyTmkzw9x_fXA) - [ ] [兰德公司评估美国人工智能能源供应链的脆弱环节](https://mp.weixin.qq.com/s/0OlAWVXw3U2wSKx-aEYPDg) - [ ] [能信安:安全漏洞通报](https://mp.weixin.qq.com/s/fsunndt3L9ANweVxQp1-1Q) - [ ] [2026数博会直击|天融信专访:安全护航词元价值释放](https://mp.weixin.qq.com/s/8a5yKCZzM-4A2mhv14cfHg) - [ ] [倒计时!一文掌握《公安机关网络空间安全监督检查办法》核心要点,10月1日生效](https://mp.weixin.qq.com/s/UEBuokB2RZeMlmO6mWLryw) - [ ] [警惕境外间谍情报机关盯上网联无人机!国家安全部提醒](https://mp.weixin.qq.com/s/q6ZUIjhFUuFhcrjWsOgnRA) - [ ] [限时众测:赛力斯SRC 2026车端靶场众测项目火热开启](https://mp.weixin.qq.com/s/XCFzPrNNEWxFUwIBeFLUKA) - [ ] [国家安全部:境外间谍瞄准网联无人机巡检平台,多类安全漏洞亟待补齐;OpenAI等百余家机构,呼吁联合抵御失控AI带来的网络威胁| 牛览](https://mp.weixin.qq.com/s/Is8X1mg1NfQAdLSDoiJvQA) - [ ] [AI的世界里只有Claude模型和其他模型](https://mp.weixin.qq.com/s/UxlSZhrfmAkxPGOyUVZzKg) - [ ] [从告警积压到持续调查,AI Agent正在重写SOC工作流](https://mp.weixin.qq.com/s/MOUSekPpkWt_7lmIK4tjmw) - [ ] [全球速卖通利用WebAudio API偷采指纹,蓝牙音频切换遭干扰](https://mp.weixin.qq.com/s/_PDw0o3Zqnc8HM3NM9d3pw) - [ ] [测评公告(2026年第11号)](https://mp.weixin.qq.com/s/OANyseMhusSI0CFt-1O5CQ) - [ ] [实力认证|华云安双向入选工信部 NVDB 两大漏洞专业库技术支撑单位](https://mp.weixin.qq.com/s/-THC_W6Ddc9sWb601Ze4Fw) - [ ] [分享的图片、视频、链接](https://mp.weixin.qq.com/s/g1LtsfxACqMClyozNYzvkA) - [ ] [最后一代应用安全工程师的自白](https://mp.weixin.qq.com/s/GzjDSFx4_uR7n2fO4jrFHw) - [ ] [AI MDR震撼发布|你的超级数字员工AI SenSo已就位!](https://mp.weixin.qq.com/s/toSl4DpVsjtLyTBFHgASyg) - [ ] [数智赋能 安全守护,新华三出席2026教育数据安全专题研修班](https://mp.weixin.qq.com/s/LSMo3KiAE7dko_IXrQMUJg) - [ ] [Apache Log4j2 新问题曝光:不是所有 RCE 都普遍,但窄场景也不能忽略](https://mp.weixin.qq.com/s/S7hxvbIOjCC0Owy6GjNTsg) - [ ] [AI 驱动的自主渗透测试平台](https://mp.weixin.qq.com/s/hkzOs_8bWIv-aIdVZRGnGQ) - [ ] [【安全/科技】互联网情报资讯08.28](https://mp.weixin.qq.com/s/jsWzfnXQiibtg6x9UPFlDg) - [ ] [一个页面,看清应用从需求到上线的安全治理状态](https://mp.weixin.qq.com/s/6B-V4zg17ISJT3TNe_u10Q) - [ ] [显存直降 80%!Unsloth 发力,消费级显卡就](https://mp.weixin.qq.com/s/NI378g3HK1opedj2_cHauw) - [ ] [张量无限Tensor系列3D相机成功完成多款光伏组件铺装机器人的交付](https://mp.weixin.qq.com/s/F3fb8C2WHBtAIW9wjQOX6g) - [ ] [一图看懂|山石网科2026年半年度报告](https://mp.weixin.qq.com/s/fkDYM8-gDwnHggXeEuZwHw) - [ ] [Agent一来,贵圈人人都是“安全专家”了?](https://mp.weixin.qq.com/s/13NlMfuexzdRauU51khU3w) - [ ] [实测一周:iOS 26.6.1和iOS 27 Beta7到底该选谁?我把坑都踩明白了](https://mp.weixin.qq.com/s/yb1akxo0vtdCebLLUFVx7g) - [ ] [2026补天校园GROW计划报名启动|赛道全新升级,打造AI 时代网络安全守护者](https://mp.weixin.qq.com/s/gxO_cx1nTTOnanAuw88tkQ) - [ ] [蓉城共探安全攻防新格局 | 补天沙龙成都站报名启动!](https://mp.weixin.qq.com/s/86nNRre_QZthmvVqfnxJsw) - [ ] [仅328元,拿下 3TOPS 算力工业 AI 视觉开发板,兼容树莓派 40Pin 脚,打造边缘计算网关产品](https://mp.weixin.qq.com/s/SlMxGURqeVHN9VYdO1n4ig) - [ ] [浏览网页劫持本地 AI 智能体](https://mp.weixin.qq.com/s/6EImMB_pEhT_zq3wLmK-bw) - [ ] [APP自动化测试挖洞工具](https://mp.weixin.qq.com/s/xHPvXrpFYL8Sv9d4CjXkQA) - [ ] [现金装进茶叶罐寄快递?南充一女子1.3万\"跨境电商\"垫资骗局被拦截追回](https://mp.weixin.qq.com/s/LfHa_vtL2Cxzq1QNt_6MJA) - [ ] [夫妻拖行李箱取280万被警方拦截,竟投诉\"发财大计被破坏\"](https://mp.weixin.qq.com/s/dE_a_Qj6VXUFQtamTMy4fQ) - [ ] [骗子为何诱导你取现金、买黄金线下交易?5类预警情形+骗局揭秘](https://mp.weixin.qq.com/s/HmQiOiX-LmuZ9eW64Bx1Tg) - obaby 𝐢𝐧⃝ void - [ ] [纸嫁衣](https://zhongxiaojie.cn/2026/08/1783/) - 安全客-有思想的安全新媒体 - [ ] [波士顿科学被打停了:全球医疗巨头网络中断,订单发不出去,股价应声下跌](https://www.anquanke.com/post/id/316032) - [ ] [智能体安全能力图谱发布:企业可落地的建设路径](https://www.anquanke.com/post/id/316028) - Private Feed for M09Ic - [ ] [timwhitez contributed to timwhitez/dsh-self-evolving](https://github.com/timwhitez/dsh-self-evolving/pull/246) - [ ] [anthropics released v2.1.251 at anthropics/claude-code](https://github.com/anthropics/claude-code/releases/tag/v2.1.251) - [ ] [Teach2Breach starred explodingcamera/tinywasm](https://github.com/explodingcamera/tinywasm) - [ ] [mgeeky starred kyutai-labs/moshi](https://github.com/kyutai-labs/moshi) - [ ] [timwhitez starred ApodexAI/FrontierAgent](https://github.com/ApodexAI/FrontierAgent) - [ ] [Rvn0xsy starred OpenHands/OpenHands](https://github.com/OpenHands/OpenHands) - [ ] [mgeeky starred pollen-robotics/microduck_rl](https://github.com/pollen-robotics/microduck_rl) - [ ] [WAY29 starred Hsiung-Shao/PobTools-zh](https://github.com/Hsiung-Shao/PobTools-zh) - [ ] [0xbug starred img2threejs/img2threejs](https://github.com/img2threejs/img2threejs) - [ ] [gh0stkey starred Cy-S3c/BurpMCP-Ultra](https://github.com/Cy-S3c/BurpMCP-Ultra) - [ ] [bolucat released 202608280407 at bolucat/Archive](https://github.com/bolucat/Archive/releases/tag/202608280407) - [ ] [agentscope-ai released v2.0.7.post1 at agentscope-ai/agentscope](https://github.com/agentscope-ai/agentscope/releases/tag/v2.0.7.post1) - [ ] [Rvn0xsy starred Tencent/BrowserSkill](https://github.com/Tencent/BrowserSkill) - [ ] [Mel0day starred anthropics/claude-plugins-community](https://github.com/anthropics/claude-plugins-community) - [ ] [anthropics released v2.1.250 at anthropics/claude-code](https://github.com/anthropics/claude-code/releases/tag/v2.1.250) - [ ] [pydantic released v2.35.3 at pydantic/pydantic-ai](https://github.com/pydantic/pydantic-ai/releases/tag/v2.35.3) - Recent Commits to cve:main - [ ] [Update Fri Aug 28 11:57:06 UTC 2026](https://github.com/trickest/cve/commit/fecc92e205d4edc167e2a790c088c911b20fd7fb) - Tenable Blog - [ ] [Why a cryptographic inventory is key for addressing the quantum computing threat](https://www.tenable.com/blog/why-a-cryptographic-inventory-is-key-for-addressing-the-quantum-computing-threat) - Darknet – Hacking Tools, Hacker News & Cyber Security - [ ] [AI IR Overlay – Incident Response Specification for AI Agents](https://www.darknet.org.uk/2026/08/ai-ir-overlay-incident-response-specification-for-ai-agents/) - 小刀志 - [ ] [从 PE 到 PKCS#7:深入理解 Windows PE 数字签名机制](https://xiaodaozhi.com/security/482.html) - pwning.systems - [ ] [I accidentally turned LLM memory into program analysis](https://pwning.systems/posts/llm-memory-program-analysis/) - Kitploit - [ ] [malvinci](https://kitploit.com/en/tools/github/gsoffmarket/malvinci) - [ ] [conductai](https://kitploit.com/en/tools/github/sseshachala/conductai) - [ ] [Atlas](https://kitploit.com/en/tools/github/portbuster1337/atlas) - [ ] [sliver v1.7.6](https://kitploit.com/en/posts/github-bishopfox-sliver-v176) - [ ] [pmd pmd_releases/7.27.0](https://kitploit.com/en/posts/github-pmd-pmd-pmd_releases7270) - [ ] [aiiroverlay](https://kitploit.com/en/tools/github/jacobideji/aiiroverlay) - [ ] [pyrite](https://kitploit.com/en/tools/gitlab/renich/pyrite) - [ ] [ruby-advisory-db](https://kitploit.com/en/tools/github/rubysec/ruby-advisory-db) - [ ] [vegadns — Updated!](https://kitploit.com/en/posts/gitlab-wattocyber-vegadns-98175e161febf6e04d7c4b61b68bc9608c60f9fa9e5abdb057fa68608fda59b3) - [ ] [Red-Team-Infrastructure-Wiki](https://kitploit.com/en/tools/github/bluscreenofjeff/red-team-infrastructure-wiki) - [ ] [flyphish](https://kitploit.com/en/tools/github/virtualsamuraii/flyphish) - [ ] [w12scan-client](https://kitploit.com/en/tools/github/w-digital-scanner/w12scan-client) - [ ] [crapsecrets](https://kitploit.com/en/tools/github/irsdl/crapsecrets) - [ ] [Mhyprot2DrvControl](https://kitploit.com/en/tools/github/kagurazakasanae/mhyprot2drvcontrol) - [ ] [evil-mhyprot-cli](https://kitploit.com/en/tools/github/kkent030315/evil-mhyprot-cli) - [ ] [poc-redis](https://kitploit.com/en/tools/github/rop4sh/poc-redis) - [ ] [gatekeeper v3.23.1](https://kitploit.com/en/posts/github-open-policy-agent-gatekeeper-v3231) - [ ] [hydrafw](https://kitploit.com/en/tools/github/hydrabus/hydrafw) - [ ] [cved](https://kitploit.com/en/tools/github/git-rep-src/cved) - [ ] [maltrail v3.2](https://kitploit.com/en/posts/github-stamparm-maltrail-32) - [ ] [flatpak v1.18.2](https://kitploit.com/en/posts/github-flatpak-flatpak-1182) - [ ] [upx v5.2.1](https://kitploit.com/en/posts/github-upx-upx-v521) - [ ] [thingsboard v4.3.1.4](https://kitploit.com/en/posts/github-thingsboard-thingsboard-v4314) - [ ] [grype v0.118.0](https://kitploit.com/en/posts/github-anchore-grype-v01180) - [ ] [Spring-Cloud-Function-SpEL](https://kitploit.com/en/tools/github/pizz33/spring-cloud-function-spel) - [ ] [electroniz3r](https://kitploit.com/en/tools/github/r3ggi/electroniz3r) - [ ] [msdt-follina](https://kitploit.com/en/tools/github/johnhammond/msdt-follina) - [ ] [Learning-to-Detect](https://kitploit.com/en/tools/github/shuangliangx/learning-to-detect) - [ ] [qlcoder](https://kitploit.com/en/tools/github/neuralprogram/qlcoder) - [ ] [DNSRPC-BOF](https://kitploit.com/en/tools/github/paradoxis/dnsrpc-bof) - SentinelOne - [ ] [The Good, the Bad and the Ugly in Cybersecurity – Week 35](https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-35-8/) - Malwarebytes - [ ] [Protect your WhatsApp account with new passkey and 2FA upgrades](https://www.malwarebytes.com/blog/mobile/2026/08/protect-your-whatsapp-account-with-new-passkey-and-2fa-upgrades) - [ ] [The AI agent swarm that attacked Hugging Face is a warning for the future](https://www.malwarebytes.com/blog/ai/2026/08/the-ai-agent-swarm-that-attacked-hugging-face-is-a-warning-for-the-future) - Intigriti - [ ] [Intigriti Bug Bytes #239 - August 2026 🚀](https://www.intigriti.com/researchers/blog/bug-bytes/intigriti-bug-bytes-239-august-2026) - 奇客Solidot–传递最新科技情报 - [ ] [澳大利亚有望在未来十年消灭宫颈癌](https://www.solidot.org/story?sid=85226) - [ ] [一次性纸杯会释放大量微塑料](https://www.solidot.org/story?sid=85225) - [ ] [无人机拍下了引发中尼边境致命泥石流的冰川崩塌](https://www.solidot.org/story?sid=85224) - [ ] [美国将意大利安全托管服务商列入恐怖分子名单](https://www.solidot.org/story?sid=85223) - [ ] [德国 Sovereign Tech 基金资助 Flatpak 逾 50 万欧元](https://www.solidot.org/story?sid=85222) - [ ] [IBM 推出双指令集处理器](https://www.solidot.org/story?sid=85221) - [ ] [法国法庭认定辐射与空乘罹患乳腺癌相关](https://www.solidot.org/story?sid=85220) - [ ] [Haiku R1/beta6 释出](https://www.solidot.org/story?sid=85219) - [ ] [Google 要求 Android 应用开发商降低内存占用](https://www.solidot.org/story?sid=85218) - [ ] [气候变暖放大东太平洋的厄尔尼诺变率](https://www.solidot.org/story?sid=85217) - HackerNews - [ ] [澳大利亚警方指控两人涉 TeamPCP 凭据窃取案](http://0.0.0.0:8080/post/64613) - [ ] [Dark Caracal 部署新型 Go 恶意软件,配备基于以太坊的 C2 备用机制](http://0.0.0.0:8080/post/64612) - [ ] [PaperCut 警告 NG 和 MF 漏洞正被用于零日攻击](http://0.0.0.0:8080/post/64611) - [ ] [曼彻斯特机场集团称黑客窃取了旅客数据](http://0.0.0.0:8080/post/64610) - [ ] [OpenAI 称奖励黑客驱动 AI 智能体利用零日漏洞入侵 Hugging Face](http://0.0.0.0:8080/post/64609) - [ ] [Next.js 修复严重 AVIF 与 Windows 漏洞,可导致未认证 RCE](http://0.0.0.0:8080/post/64608) - 杨龙 - [ ] [gotenberg html转dpf](https://www.yanglong.pro/gotenberg-html%e8%bd%acdpf/) - 360 Netlab Blog - Network Security Research Lab at 360 - [ ] [AI安全专题周报(20260828)](https://blog.netlab.360.com/aian-quan-zhuan-ti-zhou-bao-4/) - 黑海洋Wiki | AI机器人硬件开发 | 网络安全攻防实战 | 区块链技术文档教程 - 免费资源平台 - [ ] [谷歌在AI模式下进一步将搜索结果隐藏得更深](https://blog.upx8.com/%E8%B0%B7%E6%AD%8C%E5%9C%A8AI%E6%A8%A1%E5%BC%8F%E4%B8%8B%E8%BF%9B%E4%B8%80%E6%AD%A5%E5%B0%86%E6%90%9C%E7%B4%A2%E7%BB%93%E6%9E%9C%E9%9A%90%E8%97%8F%E5%BE%97%E6%9B%B4%E6%B7%B1) - [ ] [台湾拟斥资逾70亿美元扶持无人机制造商以抗衡中国](https://blog.upx8.com/%E5%8F%B0%E6%B9%BE%E6%8B%9F%E6%96%A5%E8%B5%84%E9%80%BE70%E4%BA%BF%E7%BE%8E%E5%85%83%E6%89%B6%E6%8C%81%E6%97%A0%E4%BA%BA%E6%9C%BA%E5%88%B6%E9%80%A0%E5%95%86%E4%BB%A5%E6%8A%97%E8%A1%A1%E4%B8%AD%E5%9B%BD) - [ ] [长鑫科技营收激增,得益于存储芯片短缺](https://blog.upx8.com/%E9%95%BF%E9%91%AB%E7%A7%91%E6%8A%80%E8%90%A5%E6%94%B6%E6%BF%80%E5%A2%9E-%E5%BE%97%E7%9B%8A%E4%BA%8E%E5%AD%98%E5%82%A8%E8%8A%AF%E7%89%87%E7%9F%AD%E7%BC%BA) - [ ] [英伟达成立政治行动委员会 扩大政策影响力](https://blog.upx8.com/%E8%8B%B1%E4%BC%9F%E8%BE%BE%E6%88%90%E7%AB%8B%E6%94%BF%E6%B2%BB%E8%A1%8C%E5%8A%A8%E5%A7%94%E5%91%98%E4%BC%9A-%E6%89%A9%E5%A4%A7%E6%94%BF%E7%AD%96%E5%BD%B1%E5%93%8D%E5%8A%9B) - [ ] [腾讯混元Hy4 preview发布,稳居开源模型第一梯队](https://blog.upx8.com/%E8%85%BE%E8%AE%AF%E6%B7%B7%E5%85%83Hy4-preview%E5%8F%91%E5%B8%83-%E7%A8%B3%E5%B1%85%E5%BC%80%E6%BA%90%E6%A8%A1%E5%9E%8B%E7%AC%AC%E4%B8%80%E6%A2%AF%E9%98%9F) - 微步在线研究响应中心 - [ ] [尽快修复! Nacos权限绕过漏洞](https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&mid=2247508857&idx=1&sn=efd36a593443f2b95f3c81a6c1d75a30) - 黑鸟 - [ ] [不再只伪装IT岗:朝鲜远程工作者渗透销售医疗机构等岗位](https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451188319&idx=1&sn=5732d230422338a8c985c89ec3fe749f) - 威努特安全网络 - [ ] [威努特工控主机卫士:构筑工控主机“白环境”最后防线](https://mp.weixin.qq.com/s?__biz=MzAwNTgyODU3NQ==&mid=2651143721&idx=1&sn=8cad469adde014339e0435e8f7446eea) - 安全客 - [ ] [波士顿科学被打停了:全球医疗巨头网络中断,订单发不出去,股价应声下跌](https://mp.weixin.qq.com/s?__biz=MzA5ODA0NDE2MA==&mid=2649790426&idx=1&sn=8fa722e861713c615da988d32648c781) - 安全内参 - [ ] [AI威胁推高网络安全支出,多家网安企业业绩再超预期](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516493&idx=1&sn=050c891f13c92fc5a9b75d36964afc4d) - [ ] [CNCERT“银狐”木马专项:恶意域名及恶意IP(一)](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516493&idx=2&sn=d4d3db186a37e9048d24f3030c226af7) - 代码卫士 - [ ] [PaperCut提醒注意已遭利用的 NG 和 MF 0day漏洞](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247526988&idx=1&sn=c14d3de892f45e836a8d2e5bea7aa045) - [ ] [TeamViewer 多个漏洞可导致RCE攻击](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247526988&idx=2&sn=d9963aa394ca4b8b36a63f40fabffe3a) - 安全学术圈 - [ ] [2025年度浙江省科学技术奖受理名单(网络空间安全领域)](https://mp.weixin.qq.com/s?__biz=MzU5MTM5MTQ2MA==&mid=2247495855&idx=1&sn=42edeac819258f49283bb34418bc71d8) - 长亭安全应急响应中心 - [ ] [【已复现】Nacos 管理接口权限绕过漏洞](https://mp.weixin.qq.com/s?__biz=MzIwMDk1MjMyMg==&mid=2247493348&idx=1&sn=ae0eb736ac5b93b210441f45ad157735) - 信安之路 - [ ] [最后一代应用安全工程师的自白](https://mp.weixin.qq.com/s?__biz=MzI5MDQ2NjExOQ==&mid=2247500646&idx=1&sn=305dc392de2bc0d64c5c84fa6f4a32fe) - 中国信息安全 - [ ] [前沿 | 把握总体国家安全观工具性内涵 为筑牢国家安全屏障提供有力支撑](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265998&idx=1&sn=a6132749999a7b29ddb2ce718b41972f) - [ ] [专家解读|牢牢把握优质网信企业培育服务主线 促进网信企业高质量发展](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265998&idx=2&sn=c4c0e895244616e34be1674243810125) - [ ] [外交部:坚决反对美方再次借网络安全问题向中国泼脏水](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265998&idx=3&sn=c7eafad591d7b6ecb71b699a3e200d13) - [ ] [关注 | 一批“银狐”木马相关恶意域名及恶意IP公布](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265998&idx=4&sn=65b9bc006b20ef4f71c9d27fb2df3550) - [ ] [评论 | 莫让人工智能“偷声”击穿社会信任](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265998&idx=5&sn=84ce5884c71e97f1f3513dcaaef59f34) - 信息安全国家工程研究中心 - [ ] [筑牢关基安全屏障,工程中心作为参编单位受邀参加关键信息基础设施安全保护系列团体标准发布大会](https://mp.weixin.qq.com/s?__biz=MzU5OTQ0NzY3Ng==&mid=2247504825&idx=1&sn=01239a3b75fda3cd636fe7cbefadf4a2) - 安全研究GoSSIP - [ ] [G.O.S.S.I.P 阅读推荐 2026-08-28 CVE 仙人(工智能)](https://mp.weixin.qq.com/s?__biz=Mzg5ODUxMzg0Ng==&mid=2247502060&idx=1&sn=b935ef9db0f02dca5caecda2cef581fb) - 安全圈 - [ ] [【安全圈】APT28新型木马突袭欧洲外交机构潜伏窃密](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078481&idx=1&sn=1d3f9e3f0a8de85baf4dcaba0e734fef) - [ ] [【安全圈】PaperCut曝0day漏洞遭在野攻击全版本沦陷](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078481&idx=2&sn=e8c569ddfa369b2fef92fa2bbaa2419f) - [ ] [【安全圈】OpenAI曝智能体失控利用0day打穿平台](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078481&idx=3&sn=f8beee27dca643a51feff49f5c4e8f8c) - 数世咨询 - [ ] [车主注意:Android 恶意软件攻击汽车中控主机](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247543815&idx=1&sn=98725665cef56613f36fbfbdba68a6fa) - 长亭科技 - [ ] [红队专挑半夜上强度,长亭 AIMDR 这波顶住了](https://mp.weixin.qq.com/s?__biz=MzIwNDA2NDk5OQ==&mid=2651390640&idx=1&sn=7d50eef9b1e1d517b4cf27f0617c1834) - M01N Team - [ ] [每周蓝军技术推送(2026.8.22-8.28)](https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&mid=2247495459&idx=1&sn=b80d70caec631c14dc47c343fd91840f) - 绿盟科技研究通讯 - [ ] [AI与云安全事件案例分析周报|2026.08.24 - 2026.08.28](https://mp.weixin.qq.com/s?__biz=MzIyODYzNTU2OA==&mid=2247500244&idx=1&sn=a44b628931360a58d55a9461443cd48b) - 看雪学苑 - [ ] [当高频观测不再经过异常路径:Shadow Cave 与常驻式插桩架构](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458619028&idx=1&sn=5a500adeee5194bc8b270c6819973a89) - [ ] [Claude Code自动模式曝出重大漏洞,可被提示注入劫持执行恶意代码](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458619028&idx=2&sn=87a487c4c11fadf2466724ed460efd12) - [ ] [我该如何驾驭AI,让自己不可替代?](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458619028&idx=3&sn=1fc10e26cbf3fd31d3030b89401ea23e) - 安全牛 - [ ] [自动化渗透测试正在转向实战化验证体系升级](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142493&idx=1&sn=374e5c5abe85f6f8f73b438abe289a3a) - [ ] [国家安全部:境外间谍瞄准网联无人机巡检平台,多类安全漏洞亟待补齐;OpenAI等百余家机构,呼吁联合抵御失控AI带来的网络威胁| 牛览](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142493&idx=2&sn=436e19f50e871d6a249e1056ed2f7c00) - 奇安信威胁情报中心 - [ ] [每周高级威胁情报解读(2026.08.21~08.27)](https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247520096&idx=1&sn=e2b5d62ad122417b76ffd4b416fddc54) - 奇安信 CERT - [ ] [【已复现】Nacos 权限绕过漏洞(QVD-2026-59388)安全风险通告](https://mp.weixin.qq.com/s?__biz=MzU5NDgxODU1MQ==&mid=2247507264&idx=1&sn=3658b007d3d1b06af4409856271cfc8b) - ChaMd5安全团队 - [ ] [复现与修复指南:Linux内核本地提权漏洞OVSwrap(CVE-2026-64531)](https://mp.weixin.qq.com/s?__biz=MzIzMTc1MjExOQ==&mid=2247514454&idx=1&sn=e4f7d8f8545d414742d06d79a0b87c87) - 火绒安全 - [ ] [火绒小问答——「企业版」违规外联](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247536886&idx=1&sn=57500360799bc62db9935c2fa8665cc1) - [ ] [【火绒安全周报】国安机关提醒:警惕巡检无人机被渗透攻击/曝GTA6黑客已赚约33万元](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247536886&idx=2&sn=102285f36bf251c6163d99627102d1df) - [ ] [诚邀渠道合作伙伴共启新征程](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247536886&idx=3&sn=6c5d8e6d8196f2179ef8f02f668a3597) - 安全分析与研究 - [ ] [用户态异步执行注入-APC与Fiber](https://mp.weixin.qq.com/s?__biz=MzA4ODEyODA3MQ==&mid=2247497076&idx=1&sn=39c0b07c33f133059e11fbf78fb380b3) - 字节跳动安全中心 - [ ] [行业首发|智能体安全能力图谱发布:企业可落地的建设路径](https://mp.weixin.qq.com/s?__biz=MzUzMzcyMDYzMw==&mid=2247496326&idx=1&sn=e5d84b2ae3ebf12bea49172b73f98f20) - 极客公园 - [ ] [特努斯时代首秀,苹果发布会定档 9 月 10 日;116 家公司联名信:重视 AI 时代网络安全;英伟达预计三季度营收破千亿美元 | 极客早知道](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653112801&idx=1&sn=37c0e2779180778cf630c751e4055b92) - 枇杷熟了 - [ ] [Nacos 最新权限绕过漏洞——分析与复现报告](https://mp.weixin.qq.com/s?__biz=MzU0MzkzOTYzOQ==&mid=2247490117&idx=1&sn=de179eca788884721f1dbbf2f060fccd) - Beacon Tower Lab - [ ] [【0828】重保演习每周情报汇总](https://mp.weixin.qq.com/s?__biz=MzkyNzcxNTczNA==&mid=2247488363&idx=1&sn=2d3fc091fd193a9bb8389d18ce5deda0) - 表图 - [ ] [-8.0%!网络安全行业收入连续12个季度下滑](https://mp.weixin.qq.com/s?__biz=MzUzOTI4NDQ3NA==&mid=2247485173&idx=1&sn=fa1e7e39b4db7b9696a80c1f46e1d0a4) - 360数字安全 - [ ] [覆盖车联网、信创、AI等领域,360入选工信部六大漏洞专业库技术支撑单位](https://mp.weixin.qq.com/s?__biz=MzA4MTg0MDQ4Nw==&mid=2247586805&idx=1&sn=100520e51a2f849ecbc36a5f435f18a4) - 墨菲安全 - [ ] [一个页面,看清应用从需求到上线的安全治理状态](https://mp.weixin.qq.com/s?__biz=MzkwOTM0MjI5NQ==&mid=2247488659&idx=1&sn=fba289d275aecde95330e39decc63afa) - 慢雾科技 - [ ] [威胁情报|Qwen 仿冒仓库背后的 StealC 窃密链](https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&mid=2247505804&idx=1&sn=cb42a146320de54510a0711fed546ecd) - 国家互联网应急中心CNCERT - [ ] [“银狐”木马专项——恶意域名及恶意IP(一)](https://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw==&mid=2247502072&idx=1&sn=731d22ff72b725cc6b491b0fbd6d7503) - Yak Project - [ ] [YTray: 浏览器隔离与分身测试新神器](https://mp.weixin.qq.com/s?__biz=Mzk0MTM4NzIxMQ==&mid=2247530142&idx=1&sn=748ccd8d4e8f1b5a193a4b93b1fb2f3a) - 安全419 - [ ] [AI赋能安全运营的七种方式](https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&mid=2247554650&idx=1&sn=bf194180fd6c742205a3d791c560b0df) - 放之 - [ ] [AI Agent时代的SDLC:安全工程如何落地](https://mp.weixin.qq.com/s?__biz=Mzg3ODAzNjg5OA==&mid=2247485567&idx=1&sn=d172785b1ffe5c7ffbd9bf5631e46361) - Arturo Di Corinto - [ ] [Guerra profonda: come l’IA e le “bombe furbe” manipolano la nostra realtà. Arturo Di Corinto a Materia](https://dicorinto.it/tipologia/presentazioni/guerra-profonda-come-lia-e-le-bombe-furbe-manipolano-la-nostra-realta-arturo-di-corinto-a-materia/) - SANS Internet Storm Center, InfoCON: green - [ ] [Some Malicious PE Stats, (Thu, Aug 27th)](https://isc.sans.edu/diary/rss/33292) - [ ] [ISC Stormcast For Friday, August 28th, 2026 https://isc.sans.edu/podcastdetail/10072, (Fri, Aug 28th)](https://isc.sans.edu/diary/rss/33294) - 白泽安全实验室 - [ ] [美国网络安全公司通过高仿真系统环境,成功诱捕APT攻击过程](https://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&mid=2247492978&idx=1&sn=38f528c0d4570f237a18ddcc6a4fc5f2) - Javvad Malik - [ ] [Breach of Confidence — 28 August 2026](https://javvadmalik.com/2026/08/28/breach-of-confidence-28-august-2026/) - Over Security - [ ] [McKesson discloses breach after ShinyHunters claims patient data theft](https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft/) - [ ] [ClickFix via Cloudflare Zaraz and the BW Panel](https://www.derp.ca/research/zaraz-clickfix-bw-panel/) - [ ] [Dindoor - The Technical Analysis of an Iranian Backdoor](https://binarydefense.com/resources/blog/dindoor-the-technical-analysis-of-an-iranian-backdoor) - [ ] [Encrypted Prompts Defeat Grok and Gemini Guardrails; Chat Histories Stolen](https://thecyberexpress.com/encrypted-prompts-defeat-grok-gemini-guardrail/) - [ ] [US Treasury Launches Major Campaign to Disrupt Iran’s Global Networks](https://thecyberexpress.com/operation-economic-outcast-targets-iran/) - [ ] [New Zealand Moves to Ban Social Media for Under-16s](https://thecyberexpress.com/new-zealand-social-media-ban-for-under-16s/) - [ ] [Ledger Fixes Ethereum App Flaw as Disclosure Timeline Is Disputed](https://thecyberexpress.com/ledger-ethereum-app-clear-signing-flaw/) - [ ] [Britain Gains Access to Ukraine’s ‘Goldmine’ of Battlefield AI Data](https://thecyberexpress.com/uk-ukraine-ai-partnership/) - [ ] [Global Crackdown on West African Crime Networks Leads to 58 Arrests](https://thecyberexpress.com/west-african-organized-crime-groups-crackdown/) - [ ] [Cyble and DRONA Launch New Push to Close India’s Cybersecurity Gap](https://thecyberexpress.com/ai-powered-cyber-defense-cyble-drona/) - [ ] [Boston Scientific Cyberattack Disrupts Order Processing, Shipping Worldwide](https://thecyberexpress.com/boston-scientific-cyberattack-disruption/) - [ ] [Can We Trust AI Agents With Security Decisions? Adarsh Kant Sinha Explains](https://thecyberexpress.com/ai-agents-ai-security-risks-adarsh-sinha/) - [ ] [The Cyber Express Weekly Roundup: Exploited Entra ID Flaw, AI Agent Risks, and Global Cybercrime Crackdown](https://thecyberexpress.com/weekly-roundup-microsoft-entra-id-ai-risks/) - [ ] [A Single Canadian Tax Lure Spread into a 46-Country, US-First RMM Campaign](https://any.run/cybersecurity-blog/us-campaign-malware-analysis/) - [ ] [US Finance Under Phishing Pressure: What the SOC Data Reveals?](https://any.run/cybersecurity-blog/phishing-us-finance/) - [ ] [A Note on Pentesting Passkeys](https://blog.compass-security.com/2026/08/a-note-on-pentesting-passkeys/) - [ ] [Senator asks US government watchdog to review how feds use hacking tools](https://techcrunch.com/2026/08/21/senator-asks-us-federal-watchdog-to-review-how-feds-use-hacking-tools/) - [ ] [Alabama launches investigation into OpenAI’s hack of Hugging Face](https://techcrunch.com/2026/08/24/alabama-launches-investigation-into-openais-hack-of-hugging-face/) - [ ] [Here’s all the times AI has gone rogue and hacked other companies](https://techcrunch.com/2026/08/27/heres-all-the-times-ai-has-gone-rogue-and-hacked-other-companies/) - [ ] [Il 94% del lavoro di un MDR (che funziona) è quello che non vedi](https://www.certego.net/blog/il-lavoro-di-un-mdr-che-funziona-quello-che-non-vedi/) - [ ] [Fake NYPD Officers on Video Calls: How Scammers Build a Convincing Trap](https://www.suspectfile.com/fake-nypd-officers-on-video-calls-how-scammers-build-a-convincing-trap/) - [ ] [Storm Claims Attack on American Contractors Insurance Group (ACIG) and Publishes Stolen Data](https://www.suspectfile.com/storm-claims-attack-on-american-contractors-insurance-group-acig-and-publishes-stolen-data/) - [ ] [1.4 TB of Data and Thousands of Patients: PEAR Claims Attack on South Plains Rural Health Services (SPRHS)](https://www.suspectfile.com/1-4-tb-of-data-and-thousands-of-patients-pear-claims-attack-on-south-plains-rural-health-services-sprhs/) - [ ] [UK Cybercrime Journal: ACRO Breach Report](https://blog.bushidotoken.net/2026/08/uk-cybercrime-journal-acro-breach-report.html) - [ ] [Golf Canada - 568,972 breached accounts](https://haveibeenpwned.com/Breach/GolfCanada) - [ ] [NIUS - 6,090 breached accounts](https://haveibeenpwned.com/Breach/NIUS) - [ ] [Carhartt - 12,933,413 breached accounts](https://haveibeenpwned.com/Breach/Carhartt) - [ ] [What Is a Website Attack Surface? A Beginner’s Guide to Reducing Risk](https://blog.sucuri.net/2026/08/what-is-a-website-attack-surface-a-beginners-guide-to-reducing-risk.html) - [ ] [Third-Party Script Security: How Tags, Pixels, and Embeds Can Put Websites at Risk](https://blog.sucuri.net/2026/08/third-party-script-security-how-tags-pixels-and-embeds-can-put-websites-at-risk.html) - [ ] [The Evolution of Hacktivism in Hybrid Warfare: Modern Tactics and Real-World Impact](https://flashpoint.io/blog/evolution-hacktivism-hybrid-warfare-modern-tactics-real-world-impact/) - [ ] [MFA is in Retrograde, Phishing Kit Analysis](https://catchingphish.com/posts/f/mfa-is-in-retrograde-phishing-kit-analysis) - [ ] [ClickExfil: My iteration on ClickFix and FileFix](https://catchingphish.com/posts/f/clickexfil-my-iteration-on-clickfix-and-filefix) - [ ] [The safety penalty: Reclaiming operational sovereignty in the age of AI](https://blog.talosintelligence.com/the-safety-penalty-reclaiming-operational-sovereignty-in-the-age-of-ai/) - [ ] [Choose your fighter: Balancing competing requirements to select models for your AI SOC](https://blog.talosintelligence.com/choose-your-fighter-balancing-competing-requirements-to-select-models-for-your-ai-soc/) - [ ] [JavaScript obfuscation: From party trick to phishing kit](https://blog.talosintelligence.com/javascript-obfuscation-from-party-trick-to-phishing-kit/) - [ ] [“Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend](https://blog.talosintelligence.com/sorry-i-cant-help-with-that-how-your-guardrails-might-become-the-attackers-best-friend/) - [ ] [Condivisione sicura delle credenziali e monitoraggio data leak: gestire le password in azienda a 3,59 €](https://www.cybersecurity360.it/cultura-cyber/sicurezza-password-manager-aziendale/) - [ ] [OpenAI – Hugging Face: perché cambia la portata dell’incidente](https://www.cybersecurity360.it/nuove-minacce/openai-hugging-face-perche-cambia-la-portata-dellincidente/) - [ ] [Diritto all’oblio e rimozione automatica dai broker: eliminare email e numeri dalla rete a 5,99 €](https://www.cybersecurity360.it/cultura-cyber/cancellare-dati-personali-dai-siti-con-lo-sconto/) - [ ] [Dalla crittografia zero-knowledge agli alias per l’email: il tool per proteggere gli account online a 2,49 €](https://www.cybersecurity360.it/cultura-cyber/password-manager-alias-email-passkey-sconto/) - [ ] [Controller e processor: le parole del GDPR rivelano le funzioni](https://www.cybersecurity360.it/legal/privacy-dati-personali/controller-e-processor-le-parole-del-gdpr-rivelano-le-funzioni/) - [ ] [L’illusione della terapia digitale: i rischi dell’AI applicata alla salute mentale](https://www.cybersecurity360.it/cultura-cyber/lillusione-della-terapia-digitale-i-rischi-dellai-applicata-alla-salute-mentale/) - [ ] [Cyber attacco alla piattaforma Spaggiari: allarme per i minori, la questione è la trasparenza](https://www.cybersecurity360.it/news/cyber-attacco-a-classeviva-allarme-per-studenti-e-famiglie-come-mitigare-i-rischi/) - [ ] [TeamSystem, dati contabili esfiltrati: perché il rischio non si ferma all’Iban](https://www.cybersecurity360.it/nuove-minacce/teamsystem-dati-contabili-esfiltrati-perche-il-rischio-non-si-ferma-alliban/) - [ ] [Interferenze GNSS: come l’Europa (e l’Italia) proteggono trasporti e infrastrutture critiche](https://www.cybersecurity360.it/nuove-minacce/interferenze-gnss-come-leuropa-e-litalia-proteggono-trasporti-e-infrastrutture-critiche/) - [ ] [Security, non securAIty: l’evoluzione degli strumenti di difesa](https://www.cybersecurity360.it/cultura-cyber/security-non-securaity-levoluzione-degli-strumenti-di-difesa/) - [ ] [ClickFix + winget + Deno](https://roccosicilia.com/2026/08/27/clickfix-winget-deno/) - [ ] [Quando serve davvero la process injection?](https://roccosicilia.com/2026/08/28/quando-serve-davvero-la-process-injection/) - [ ] [PSD3, PSR and the Rise of Privacy-Preserving Behavioural Analytics](https://www.threatfabric.com/blogs/psd3-psr-and-the-rise-of-privacy-preserving-behavioural-analytics) - [ ] [Balonx Sistema: El Rostro Detrás del PhaaS que Impacta la Banca Mexicana](https://www.group-ib.com/blog/balonx-sistema-mexico-phaas-es/) - TorrentFreak - [ ] [Belgian Orders Demand Pirate Site Operators’ Bank Details, Crypto Wallets and Server Logs](https://torrentfreak.com/belgian-orders-demand-pirate-site-operators-bank-details-crypto-wallets-and-server-logs/) - Security Affairs - [ ] [Love Electric Breach: 877,000 Driver Records Offered for $600](https://securityaffairs.com/198033/data-breach/love-electric-breach-877000-driver-records-offered-for-600.html) - [ ] [Trump Targets Foreign Technology in New U.S. Power Grid Security Order](https://securityaffairs.com/198025/security/trump-targets-foreign-technology-in-new-u-s-power-grid-security-order.html) - [ ] [U.S. CISA adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog](https://securityaffairs.com/198014/hacking/u-s-cisa-adds-owncloud-linux-kernel-and-jfrog-artifactory-flaws-to-its-known-exploited-vulnerabilities-catalog.html) - [ ] [Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations](https://securityaffairs.com/197996/apt/russian-apt-bluedelta-uses-hookedge-to-target-defense-and-diplomatic-organizations.html) - [ ] [PaperCut Zero-Day Under Active Attack: Emergency Patch Released](https://securityaffairs.com/197980/uncategorized/papercut-zero-day-under-active-attack-emergency-patch-released.html) - [ ] [U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog](https://securityaffairs.com/197975/hacking/u-s-cisa-adds-red-hat-linux-kernel-ajax-net-professional-microsoft-sql-server-and-citrix-netscaler-flaws-to-its-known-exploited-vulnerabilities-catalog.html) - [ ] [Cyberattack on UK Airport Operator MAG Exposes Data of 8.7 Million Customers Across Three Airports](https://securityaffairs.com/197966/data-breach/cyberattack-on-uk-airport-operator-mag-exposes-data-of-8-7-million-customers-across-three-airports.html) - Deeplinks - [ ] [EFF and Allies on Brazil's Elections: Privacy Protections are Crucial to Electoral Integrity](https://www.eff.org/deeplinks/2026/08/eff-and-allies-brazils-elections-privacy-protections-are-crucial-electoral) - www.theregister.com - Articles - [ ] [Researcher shows how Claude Code can be tricked simply by asking it to summarize a website](https://www.theregister.com/research/2026/08/28/researcher-shows-how-claude-code-can-be-tricked-simply-by-asking-it-to-summarize-a-website/5293372) - [ ] [US government snitch-finder pleads guilty to leaking state secrets to foreign spies](https://www.theregister.com/security/2026/08/28/us-government-snitch-finder-pleads-guilty-to-leaking-state-secrets-to-foreign-spies/5293248) - [ ] [CISA: Most exploited vulnerabilities should have been eradicated decades ago](https://www.theregister.com/security/2026/08/28/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago/5293194) - [ ] [Industry that built the problem offers to sell you the solution](https://www.theregister.com/security/2026/08/28/industry-that-built-the-problem-offers-to-sell-you-the-solution/5293207) - [ ] [Print management outfit PaperCut is under 0-day attack, and it’s drawing customers’ blood](https://www.theregister.com/security/2026/08/28/print-management-outfit-papercut-is-under-0-day-attack-and-its-drawing-customers-blood/5293168) - [ ] [Australian cops cuff alleged TeamPCP masterminds](https://www.theregister.com/security/2026/08/28/australian-cops-cuff-alleged-teampcp-masterminds/5293157) - The Hacker News - [ ] [Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network](https://thehackernews.com/2026/08/berlin-refuses-to-pay-hackers-who-stole.html) - [ ] [Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable](https://thehackernews.com/2026/08/cosmos-evm-flaw-exploited-after-cosmos.html) - [ ] [Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication](https://thehackernews.com/2026/08/attackers-chain-two-papercut-flaws-to.html) - [ ] [Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers](https://thehackernews.com/2026/08/android-17-adds-os-wide-ech-to-hide.html) - [ ] [ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body](https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets.html) - [ ] [19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code](https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html) - [ ] [Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth](https://thehackernews.com/2026/08/two-unitree-g1-edu-humanoid-robot-flaws.html) - [ ] [Key Reasons Why Identity Fabric Matters in 2026](https://thehackernews.com/2026/08/key-reasons-why-identity-fabric-matters.html) - [ ] [Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL](https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html) - [ ] [China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access](https://thehackernews.com/2026/08/china-made-zbt-routers-ship-with-two.html) - [ ] [Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server](https://thehackernews.com/2026/08/critical-cpanel-flaw-could-let-one.html) - [ ] [PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions](https://thehackernews.com/2026/08/papercut-zero-day-exploited-in-attacks.html) - [ ] [APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations](https://thehackernews.com/2026/08/apt28-linked-hookedge-backdoor-targets.html) - GRAHAM CLULEY - [ ] [Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more](https://www.bitdefender.com/en-us/blog/hotforsecurity/shai-hulud-hackers-charged-teampcps) - KitPloit - PenTest Tools! - [ ] [malvinci](https://kitploit.com/en/tools/github/gsoffmarket/malvinci) - [ ] [conductai](https://kitploit.com/en/tools/github/sseshachala/conductai) - [ ] [Atlas](https://kitploit.com/en/tools/github/portbuster1337/atlas) - [ ] [sliver v1.7.6](https://kitploit.com/en/posts/github-bishopfox-sliver-v176) - [ ] [pmd pmd_releases/7.27.0](https://kitploit.com/en/posts/github-pmd-pmd-pmd_releases7270) - [ ] [aiiroverlay](https://kitploit.com/en/tools/github/jacobideji/aiiroverlay) - [ ] [pyrite](https://kitploit.com/en/tools/gitlab/renich/pyrite) - [ ] [ruby-advisory-db](https://kitploit.com/en/tools/github/rubysec/ruby-advisory-db) - [ ] [vegadns — Updated!](https://kitploit.com/en/posts/gitlab-wattocyber-vegadns-98175e161febf6e04d7c4b61b68bc9608c60f9fa9e5abdb057fa68608fda59b3) - [ ] [Red-Team-Infrastructure-Wiki](https://kitploit.com/en/tools/github/bluscreenofjeff/red-team-infrastructure-wiki) - [ ] [flyphish](https://kitploit.com/en/tools/github/virtualsamuraii/flyphish) - [ ] [w12scan-client](https://kitploit.com/en/tools/github/w-digital-scanner/w12scan-client) - [ ] [crapsecrets](https://kitploit.com/en/tools/github/irsdl/crapsecrets) - [ ] [Mhyprot2DrvControl](https://kitploit.com/en/tools/github/kagurazakasanae/mhyprot2drvcontrol) - [ ] [evil-mhyprot-cli](https://kitploit.com/en/tools/github/kkent030315/evil-mhyprot-cli) - [ ] [poc-redis](https://kitploit.com/en/tools/github/rop4sh/poc-redis) - [ ] [gatekeeper v3.23.1](https://kitploit.com/en/posts/github-open-policy-agent-gatekeeper-v3231) - [ ] [hydrafw](https://kitploit.com/en/tools/github/hydrabus/hydrafw) - [ ] [cved](https://kitploit.com/en/tools/github/git-rep-src/cved) - [ ] [maltrail v3.2](https://kitploit.com/en/posts/github-stamparm-maltrail-32) - [ ] [flatpak v1.18.2](https://kitploit.com/en/posts/github-flatpak-flatpak-1182) - [ ] [upx v5.2.1](https://kitploit.com/en/posts/github-upx-upx-v521) - [ ] [thingsboard v4.3.1.4](https://kitploit.com/en/posts/github-thingsboard-thingsboard-v4314) - [ ] [grype v0.118.0](https://kitploit.com/en/posts/github-anchore-grype-v01180) - [ ] [Spring-Cloud-Function-SpEL](https://kitploit.com/en/tools/github/pizz33/spring-cloud-function-spel) - [ ] [electroniz3r](https://kitploit.com/en/tools/github/r3ggi/electroniz3r) - [ ] [msdt-follina](https://kitploit.com/en/tools/github/johnhammond/msdt-follina) - [ ] [Learning-to-Detect](https://kitploit.com/en/tools/github/shuangliangx/learning-to-detect) - [ ] [qlcoder](https://kitploit.com/en/tools/github/neuralprogram/qlcoder) - [ ] [DNSRPC-BOF](https://kitploit.com/en/tools/github/paradoxis/dnsrpc-bof) - Schneier on Security - [ ] [Friday Squid Blogging: Truckload of Squid Spills in Rhode Island](https://www.schneier.com/blog/archives/2026/08/friday-squid-blogging-truckload-of-squid-spills-in-rhode-island.html) - [ ] [AI Doesn’t Mean the End of Mathematics—at Least Not Yet](https://www.schneier.com/blog/archives/2026/08/ai-doesnt-mean-the-end-of-mathematics-at-least-not-yet.html) - Security Weekly Podcast Network (Audio) - [ ] [Mythos Writes the Exploit. Atlas Writes the Response. - Harman Kaur - SWN #611](http://sites.libsyn.com/18678/mythos-writes-the-exploit-atlas-writes-the-response-harman-kaur-swn-611)
每日安全资讯(2026-08-29)