# 每日安全资讯(2026-09-02) - SecWiki News - [ ] [SecWiki News 2026-09-01 Review](http://www.sec-wiki.com/?2026-09-01) - Doonsec's feed - [ ] [四重硬约束压顶,具身智能企业合规焦虑或许才刚开始](https://mp.weixin.qq.com/s/p7m9JtOur0HIcNkYQ_zQvA) - [ ] [沙龙报名|Data Agent:数据生产与智能决策新范式](https://mp.weixin.qq.com/s/eLM_PvHuiodMTM6n31WnkA) - [ ] [报名开启!第九届全国职工职业技能大赛海南选拔赛等你来战](https://mp.weixin.qq.com/s/ncREpIAS4jICSiNamBVmtw) - [ ] [关于举办人工智能安全工程师培训班的通知](https://mp.weixin.qq.com/s/lS8b_u19YmweCu9N641SrQ) - [ ] [地方动态xa0|xa02026年“数据要素×”大赛安徽分赛决赛成功举办](https://mp.weixin.qq.com/s/Gj4ciJpwu0kiufmTnBk7zw) - [ ] [地方动态 | 2026年“数据要素×”大赛湖南分赛决赛路演正式开赛](https://mp.weixin.qq.com/s/WggvlON6NwRvgr7mhfs6Xw) - [ ] [中央网信办:当前人工智能领域主要面临5方面安全风险挑战](https://mp.weixin.qq.com/s/1A87UWt3CkMn1iop_Qpvgg) - [ ] [跨境安全合作交流|乾冠与马来西亚沙巴州代表洽谈 AI智能驱动安全](https://mp.weixin.qq.com/s/X1InT-vvwNeWSYtSJScwtA) - [ ] [【2026hvv】JeecgBoot 【0day】,文档细琐~【附验证exp】,速修~!](https://mp.weixin.qq.com/s/LCFrnxpW2_5c2l6ucedcvg) - [ ] [解锁渗透测试中的隐藏技能](https://mp.weixin.qq.com/s/Hw9VHjy-n_UktVsKjNG_Pg) - [ ] [【免费领】渗透测试必备工具:Nmap实战技术全解教程](https://mp.weixin.qq.com/s/R2A0c0LSnEo_IgxxPYi6cg) - [ ] [全球安全动态日报|20260831|早](https://mp.weixin.qq.com/s/z2lOJU6fnfdpQqo65Mgj3w) - [ ] [为什么企业更愿意为建设买单,而运营却始终是短板?](https://mp.weixin.qq.com/s/qC71k_W7RX5uWCpXolHFBw) - [ ] [网络安全动态 - 2026.9.1](https://mp.weixin.qq.com/s/Kk0YeVZ9UPQBTO7X08iArw) - [ ] [【项目推荐】DVLAA 本地 AI LLM & Agent 安全靶场](https://mp.weixin.qq.com/s/fxSf0_GQJRZHdSB4ZJ3NvA) - [ ] [【活动预告】ISC2北京分会线下技术分享会丨富士胶片商业创新智慧办公解决方案研讨会](https://mp.weixin.qq.com/s/a6AwiqKLPRLpPN6nPUPG4Q) - [ ] [安全简讯(2026.09.01)](https://mp.weixin.qq.com/s/-hVTw1NhOlfqa2BcBg0ikA) - [ ] [“银狐”木马专项——CCTGA公布恶意域名及恶意IP(二)](https://mp.weixin.qq.com/s/UA0urJ2RdOkPqAkfRjp48A) - [ ] [药明康德网络安全事件敲警钟 :网络安全成产业“必修课”](https://mp.weixin.qq.com/s/ldsoeD0Qe-gGntj3RAA_Mw) - [ ] [晋级名单|“观安杯”第二届网络安全大学生主持新人赛晋级复赛名单](https://mp.weixin.qq.com/s/wIkBbeLb9ma6XMpv-H_5Jg) - [ ] [稳居未上市安全公司首位!长亭科技再登中国网络安全产业百强](https://mp.weixin.qq.com/s/DYhxFedzSZckO8MRKcYUtA) - [ ] [从“能用可用”,走向“善管善用”!恒安嘉新袋鼠智能体DataAgent强势破局!](https://mp.weixin.qq.com/s/ZDhLsoYq9iIZGqYt0OEgsg) - [ ] [通知](https://mp.weixin.qq.com/s/u6wu1AO-8MHCMC9cM2JuHQ) - [ ] [加密失效:人工智能和量子技术如何为数据安全划定新界限](https://mp.weixin.qq.com/s/5LaXd4kuH7uwe62XWZyJ8A) - [ ] [活动报名!2026警安法务科技展重磅活动提前锁定](https://mp.weixin.qq.com/s/407vKR0o8VnX54r3UO8J_Q) - [ ] [密评驱动的医疗机构商用密码建设与改造](https://mp.weixin.qq.com/s/a2iMmug9qDMZsS0mtnQveA) - [ ] [这个培训班,很前卫](https://mp.weixin.qq.com/s/OW0vmA152EVIcp6hhhet3g) - [ ] [网警护航开学季:《反谣儿歌》请牢记](https://mp.weixin.qq.com/s/fxMiXprca3J_Bno8JblhaA) - [ ] [快讯丨2026年国家网络安全宣传周将于9月14日至20日在全国范围举行](https://mp.weixin.qq.com/s/k5R1M6e0_BMZCRXl5fx10A) - [ ] [iOS 27 beta8 上手体验:没新功能,但老机型终于不烫了?](https://mp.weixin.qq.com/s/lD-3rcBP0vr0Z0oHcjuz2g) - [ ] [公安部通报42款违规App,医疗健康领域成个人信息保护重点核查对象](https://mp.weixin.qq.com/s/2RjhiOOjqTsJ654sQWPKlQ) - [ ] [王欣深度拆解网络安全AI奇点时刻,五大核心技术构筑新一代防御体系](https://mp.weixin.qq.com/s/NgEDAcaBkmjUSIZgXG9FpQ) - [ ] [一个 BOLA 漏洞](https://mp.weixin.qq.com/s/ECvtZO1iY2Xj7zDLilHsoA) - [ ] [某物业公司泊车小程序未按规定备案存在安全风险 被处罚](https://mp.weixin.qq.com/s/JdingBnj1rrsf6_m2zdtog) - [ ] [韩国个人信息保护委员会:GS Retail因信息泄露被罚128.36亿韩元](https://mp.weixin.qq.com/s/GknQdGkVi2GembVmRM4tsA) - [ ] [净网警示|提供无人机破解服务触犯刑律,编造灾情谣言难逃法律追责](https://mp.weixin.qq.com/s/TOVgOeKarKQAU-pD5kGnPg) - [ ] [“艳遇”敲诈43人获刑!德州警方披露细](https://mp.weixin.qq.com/s/mALIR66qvR9Yl7YCEFfOSg) - [ ] [One-Fox零基础培训计划(二期本月11日截止报名),带你从配置环境到实战攻防-文末附公开课](https://mp.weixin.qq.com/s/oEVpLpoSHI0izmzIS9TRug) - [ ] [第四届网络空间安全(天津)论坛嘉宾寄语](https://mp.weixin.qq.com/s/q94qOKmTZGzyXJ0jJgvi5Q) - [ ] [全球公共安全合作论坛(连云港)2026年大会媒体通气会在京召开](https://mp.weixin.qq.com/s/WDtxR_KVrMDqJ7xzTFjVNA) - [ ] [深耕加密流量安全创新 | 观成瞰云获官方 “三新” 资质认可](https://mp.weixin.qq.com/s/QmUa0ANVupfcrAYaYxAsJg) - [ ] [电力系统中哪些地方需要使用密码技术?](https://mp.weixin.qq.com/s/lJFhCzgE36sQK50hJ7qF5A) - [ ] [QuickFox:出海互联网软件企业的开源治理实践](https://mp.weixin.qq.com/s/VnmF6Cu6bGkCRyzUcPN9AA) - [ ] [Sign in with Apple 0day 复盘:十万美元赏金背后的认证绕过](https://mp.weixin.qq.com/s/hI_J8xEsFGdzZskpVlA-Ww) - [ ] [以智能体源代码审计领跑对抗性 AI](https://mp.weixin.qq.com/s/eX2_XXXU65TN4d5PLONAHA) - [ ] [迎接开学季流量洪峰,华青融天正式发布 “智流观校” 产品,守护高校师生数字化业务体验](https://mp.weixin.qq.com/s/ZY9H5nShyG-xbvHpmwRMBQ) - [ ] [安全能力池一点通xa0|xa0第4期](https://mp.weixin.qq.com/s/FKDoal9UQuAwrivSPMM8WA) - [ ] [深信服运维安全管理系统 change_net 命令执行漏洞](https://mp.weixin.qq.com/s/F7kHn038WxtvPKS683ajmA) - [ ] [公安部计算机信息系统安全产品质量监督检验中心检测发现42款违法违规收集使用个人信息的移动应用](https://mp.weixin.qq.com/s/H5B8TEKAcvoh1v4nqPf1_A) - [ ] [建议收藏!国家部委发布的15份“低空经济”文件解读](https://mp.weixin.qq.com/s/R_cv97mC2lwgfzOFh6TlTA) - [ ] [什么是低空基础设施?<国家发展改革委给出明确分类>](https://mp.weixin.qq.com/s/dPTW-pASQCDHmZTarKgP1Q) - [ ] [9月安全预警|开学季诈骗爆发+高危漏洞频发,企业轻量化自查加固方案](https://mp.weixin.qq.com/s/kHX9N2PXWNhZy55qkALnnw) - [ ] [多重福利活动|人人皆有专属激励,组队上号开挖!](https://mp.weixin.qq.com/s/LS47PPRIUFsbsf51VS8ZUg) - [ ] [确认裁员22000人,赔偿N+4!](https://mp.weixin.qq.com/s/ghC0IQbLjxu4lougMKbxnA) - [ ] [【境外间谍无孔不入】别以为自己只是普通人,就不会被盯上](https://mp.weixin.qq.com/s/vGhxtG17Ly-MioyfgQzSgg) - [ ] [工具分享 | 一款全功能 Web 漏洞扫描工具](https://mp.weixin.qq.com/s/dMcvIyMpjhuvUTm1l_7vaA) - [ ] [03Unitree G1 人形机器人蓝牙漏洞:会动的设备一旦失守,风险比电脑更直观](https://mp.weixin.qq.com/s/87_Ntg3kKDb0Z6qUGCPRHA) - [ ] [美中情局局长秘密赴俄并与俄情报部门接触,需警惕美俄情报沟通机制回暖对中俄战略协作及乌克兰局势的潜在影响](https://mp.weixin.qq.com/s/R8qU4Gi4lJOM58GUtDMGyA) - [ ] [金融稳定委员会警告AI驱动网络风险加剧,全球金融体系安全面临新挑战](https://mp.weixin.qq.com/s/lscHiVxtAsw6IQEzN4gYNA) - [ ] [手机号归一化缺失导致的批量刷积分](https://mp.weixin.qq.com/s/p9oNSe5ht5gPM6Yim9OFBA) - [ ] [检查项翻倍、程序更严、技术更强 176号令10月1日施行,一线执法怎么做?](https://mp.weixin.qq.com/s/tahdFoWEpschpnboGtyU3w) - [ ] [破解AI落地“最后一公里”:鼎夏智能发布FDE企业转型免费诊断](https://mp.weixin.qq.com/s/VroylKqaOQe17YlbYrAAuw) - [ ] [威胁扩张:朝鲜伪装求职者已渗透医疗、销售营销等非 IT 行业](https://mp.weixin.qq.com/s/UySW6GwRIea8GHWSJxMGUg) - [ ] [首届盘古石计算机取证纯图WP](https://mp.weixin.qq.com/s/KL_zzhb6hvNmVvjbi9tPrw) - [ ] [滥用Entra ID备份密钥攻陷Azure VM](https://mp.weixin.qq.com/s/z4kQPYyvR6_6TtIDt47NKA) - [ ] [【情报】支付宝8.2亿数据泄露?给同事说一声,别自己吓自己](https://mp.weixin.qq.com/s/Kfv2J7EFqVmGIb5jkN1N6A) - [ ] [第十九届全国大学生信息安全竞赛(创新实践能力赛)决赛圆满收官,永信至诚连续十一年提供赛事运营保障服务](https://mp.weixin.qq.com/s/5Vr3OXIrGmi-FOlz5tNvKA) - [ ] [漏洞预警 | 亿赛通电子文档安全管理系统SQL注入漏洞](https://mp.weixin.qq.com/s/f4xMViM1KN0zxh--s5k4iQ) - [ ] [工具 | CyberSecurity-Skills](https://mp.weixin.qq.com/s/bzjpZYmDrnM93fseqVTA8g) - Paper - 知道创宇404实验室 - [ ] [Drishti:面向 5G 核心网的AI主导、人工导向的漏洞审计](https://paper.seebug.org/3515) - 安全客-有思想的安全新媒体 - [ ] [Aiker World社区 AI 联创基地落地海南东方:从赛场到产业,共建 AI 新生态](https://www.anquanke.com/post/id/316048) - Recent Commits to cve:main - [ ] [Update Tue Sep 1 12:04:02 UTC 2026](https://github.com/trickest/cve/commit/bfcf023d9a4ddb50bf427bb99c53ab6e6bd5f5fb) - Sucuri Blog - [ ] [Vulnerability & Patch Roundup — August 2026](https://blog.sucuri.net/2026/08/vulnerability-patch-roundup-august-2026.html) - ongoing by Tim Bray - [ ] [Un-Racing Issues](https://www.tbray.org/ongoing/When/202x/2026/09/01/Un-Racing) - Microsoft Security Blog - [ ] [Counterfeit installers to system compromise: Tracking a deceptive software download campaign](https://www.microsoft.com/en-us/security/blog/2026/09/01/counterfeit-installers-system-compromise-tracking-deceptive-software-download-campaign/) - [ ] [Cybersecurity IR Workshop: The workshop you shouldn’t miss](https://www.microsoft.com/en-us/security/blog/2026/09/01/cybersecurity-ir-workshop-you-shouldnt-miss/) - 小刀志 - [ ] [从 PE 到 PKCS#7:深入理解 Windows PE 数字签名机制](https://xiaodaozhi.com/security/482.html) - Didier Stevens - [ ] [Overview of Content Published in August](https://blog.didierstevens.com/2026/09/01/overview-of-content-published-in-august-11/) - GuidePoint Security - [ ] [EtherHiding Exposed: What Security Leaders Need to Know](https://www.guidepointsecurity.com/blog/etherhiding_exposed_what_security_leaders_need_to_know/) - Private Feed for M09Ic - [ ] [anthropics released v2.1.258 at anthropics/claude-code](https://github.com/anthropics/claude-code/releases/tag/v2.1.258) - [ ] [bolucat released 202609012253 at bolucat/Archive](https://github.com/bolucat/Archive/releases/tag/202609012253) - [ ] [usestrix released v1.6.0 at usestrix/strix](https://github.com/usestrix/strix/releases/tag/v1.6.0) - [ ] [anthropics released v2.1.257 at anthropics/claude-code](https://github.com/anthropics/claude-code/releases/tag/v2.1.257) - [ ] [esrrhs contributed to esrrhs/fakelua](https://github.com/esrrhs/fakelua/pull/393) - [ ] [timwhitez contributed to timwhitez/agent-sdk-golang](https://github.com/timwhitez/agent-sdk-golang/pull/90) - [ ] [Mr-xn starred huilang-me/CF-Server-Monitor](https://github.com/huilang-me/CF-Server-Monitor) - [ ] [esrrhs contributed to esrrhs/fakecc](https://github.com/esrrhs/fakecc/pull/49) - [ ] [Mel0day starred juanfont/headscale](https://github.com/juanfont/headscale) - [ ] [uknowsec starred 0xuezhang985/985gmgn-helper](https://github.com/0xuezhang985/985gmgn-helper) - [ ] [gh0stkey starred Gaoshu705/QzoneArchive](https://github.com/Gaoshu705/QzoneArchive) - [ ] [rabbitmask starred oritera/Cairn](https://github.com/oritera/Cairn) - Horizon3 - [ ] [CVE-2026-9586 | Sangoma Switchvox Unauthenticated SQL Injection Remote Code Execution Vulnerability](https://horizon3.ai/attack-research/vulnerabilities/cve-2026-9586/) - [ ] [CVE-2026-81578 + CVE-2026-82078 | PaperCut NG/MF Authentication Bypass and Unsafe Dynamic Class Loading Vulnerabilities](https://horizon3.ai/attack-research/vulnerabilities/cve-2026-81578-cve-2026-82078/) - [ ] [Off the Hook: Discovering and Observing Active Exploitation of Sangoma Switchvox CVE-2026-9586](https://horizon3.ai/attack-research/disclosures/cve-2026-9586-sangoma-switchvox-rce/) - Kitploit - [ ] [snuffleupagus v0.14.0](https://kitploit.com/en/posts/github-jvoisin-snuffleupagus-v0140) - [ ] [yolobox v0.19.4](https://kitploit.com/en/posts/github-finbarr-yolobox-v0194) - [ ] [mitaka v2.10.1](https://kitploit.com/en/posts/github-ninoseki-mitaka-v2101) - [ ] [DLLHijackHunter v2.4.0](https://kitploit.com/en/posts/github-ghostvectoracademy-dllhijackhunter-v240) - [ ] [super clearfog-v1.2.6](https://kitploit.com/en/posts/github-spr-networks-super-clearfog-v126) - [ ] [webanalyze v0.4.5](https://kitploit.com/en/posts/github-rverton-webanalyze-v045) - [ ] [bunkerweb v1.6.15-rc1](https://kitploit.com/en/posts/github-bunkerity-bunkerweb-v1615-rc1) - [ ] [MemShellParty v2.10.0](https://kitploit.com/en/posts/github-reajason-memshellparty-v2100) - [ ] [pipelock v3.5.0](https://kitploit.com/en/posts/github-luckypipewrench-pipelock-v350) - [ ] [vet v1.19.0](https://kitploit.com/en/posts/github-safedep-vet-v1190) - [ ] [LangAlpha v2026.09.01](https://kitploit.com/en/posts/github-ginlix-ai-langalpha-v20260901) - [ ] [python-tuf v7.0.1](https://kitploit.com/en/posts/github-theupdateframework-python-tuf-v701) - [ ] [TrustTunnel v1.1.0](https://kitploit.com/en/posts/github-trusttunnel-trusttunnel-v110) - [ ] [allstar v4.6](https://kitploit.com/en/posts/github-ossf-allstar-v46) - [ ] [wazuh v5.0.0-beta5](https://kitploit.com/en/posts/github-wazuh-wazuh-v500-beta5) - [ ] [intercept v2.33.0](https://kitploit.com/en/posts/github-smittix-intercept-v2330) - [ ] [wtf v0.5.8](https://kitploit.com/en/posts/github-0vercl0k-wtf-v058) - [ ] [beelzebub v3.9.1](https://kitploit.com/en/posts/github-beelzebub-labs-beelzebub-v391) - [ ] [BloodHound v9.7.0-rc1](https://kitploit.com/en/posts/github-specterops-bloodhound-v970-rc1) - [ ] [seer snap-latest](https://kitploit.com/en/posts/github-epasveer-seer-snap-latest) - [ ] [dalfox v3.2.2](https://kitploit.com/en/posts/github-hahwul-dalfox-v322) - [ ] [ja4 v1.0.1](https://kitploit.com/en/posts/github-foxio-llc-ja4-v101) - [ ] [testkube v2.13.1](https://kitploit.com/en/posts/github-kubeshop-testkube-2131) - [ ] [wBlock v3.0.0](https://kitploit.com/en/posts/github-0xcub3-wblock-300) - [ ] [vm2 v3.11.8](https://kitploit.com/en/posts/github-patriksimek-vm2-v3118) - [ ] [wappalyzergo v0.2.96](https://kitploit.com/en/posts/github-projectdiscovery-wappalyzergo-v0296) - [ ] [PF_RING v9.4.0](https://kitploit.com/en/posts/github-ntop-pf_ring-940) - [ ] [pingap v0.13.10](https://kitploit.com/en/posts/github-vicanso-pingap-v01310) - [ ] [KubeArmor v1.7.5-rc2](https://kitploit.com/en/posts/github-kubearmor-kubearmor-v175-rc2) - [ ] [zizmor v1.30.0](https://kitploit.com/en/posts/github-zizmorcore-zizmor-v1300) - [ ] [gping gping-v1.21.0](https://kitploit.com/en/posts/github-orf-gping-gping-v1210) - [ ] [chipsec v2.0.8](https://kitploit.com/en/posts/github-chipsec-chipsec-208) - [ ] [nDPI v6.0](https://kitploit.com/en/posts/github-ntop-ndpi-60) - [ ] [librepods nightly-53679cc](https://kitploit.com/en/posts/github-librepods-org-librepods-nightly-53679cc) - [ ] [cloudflared v2026.8.3](https://kitploit.com/en/posts/github-cloudflare-cloudflared-202683) - [ ] [Sandboxie v1.18.3](https://kitploit.com/en/posts/github-sandboxie-plus-sandboxie-v1183) - [ ] [frigate v0.18.0-rc1](https://kitploit.com/en/posts/github-blakeblackshear-frigate-v0180-rc1) - [ ] [ps5-uart — Updated!](https://kitploit.com/en/posts/github-symbrkrs-ps5-uart-6bc743493331ac089680e50b54c391a7b3d078d32749833c26270497ae0735e1) - [ ] [fingerprint-pro-internals — Updated!](https://kitploit.com/en/posts/github-proofofbots-fingerprint-pro-internals-74483b09060e477a91793ded91dbd68d5d5709468078a636a47f7465bed72913) - [ ] [awesome-ai-security — Updated!](https://kitploit.com/en/posts/github-gmh5225-awesome-ai-security-b300d9d87b8f9e8ae7c8a840597e9c3555b56d954e6819ad4f6329226a239eee) - Intigriti - [ ] [Reconnaissance unleashed: Meet CrowdRecon](https://www.intigriti.com/blog/news/reconnaissance-unleashed-meet-crowdrecon) - Malwarebytes - [ ] [Fake GTA 6 leaked copy drains your crypto wallet](https://www.malwarebytes.com/blog/scams/2026/09/fake-gta-6-leaked-copy-drains-your-crypto-wallet) - [ ] [TerminalFix looks like ClickFix, but delivers a very different payload](https://www.malwarebytes.com/blog/news/2026/09/terminalfix-looks-like-clickfix-but-delivers-a-very-different-payload) - [ ] [Infostealers are hijacking Claude accounts at users’ expense](https://www.malwarebytes.com/blog/news/2026/09/infostealers-are-hijacking-claude-accounts-at-users-expense) - VMRay - [ ] [Pivoting in MISP: From Individual Indicators to Broader Threat Context](https://www.vmray.com/pivoting-in-misp-from-individual-indicators-to-broader-threat-context/) - Exploit-DB.com RSS Feed - [ ] [[webapps] Wolf CMS 0.8.3.1 - RCE v](https://www.exploit-db.com/exploits/52672) - [ ] [[webapps] Payload CMS 3.72.0 - Blind SQL Injection](https://www.exploit-db.com/exploits/52671) - [ ] [[webapps] Bludit CMS - Stored XSS](https://www.exploit-db.com/exploits/52670) - [ ] [[webapps] Grav CMS 2.0.7 - RCE](https://www.exploit-db.com/exploits/52669) - [ ] [[webapps] miniOrange 5.4.3 - Unauthenticated Auth Bypass](https://www.exploit-db.com/exploits/52668) - [ ] [[webapps] EasyAppointments 1.5.1 - Blind SQL Injection](https://www.exploit-db.com/exploits/52667) - 奇客Solidot–传递最新科技情报 - [ ] [小规模民调显示七成韩国民众支持限制青少年使用社交网络](https://www.solidot.org/story?sid=85257) - [ ] [Softaculous 遭遇长达 33 小时的 BGP 路由劫持](https://www.solidot.org/story?sid=85256) - [ ] [科学家定位调控冬眠的关键脑回路](https://www.solidot.org/story?sid=85255) - [ ] [ChatGPT 和 Reddit 被要求遵守欧盟的 DSA](https://www.solidot.org/story?sid=85254) - [ ] [太阳风暴导致美国 GPS 信号偏差逾 10 米](https://www.solidot.org/story?sid=85253) - [ ] [智神星一号成功完成首次演示飞行](https://www.solidot.org/story?sid=85252) - [ ] [中国光伏装机容量首次超过煤电](https://www.solidot.org/story?sid=85251) - [ ] [Paint.NET 实验性支持 Wine/Linux](https://www.solidot.org/story?sid=85250) - [ ] [带电雨滴会腐蚀汽车](https://www.solidot.org/story?sid=85249) - [ ] [拒绝改名的 MapQuest 成为美国 App Store 下载量最高的地图导航应用](https://www.solidot.org/story?sid=85248) - [ ] [Google 从其扩展商店移除了包括 uBlock Origin 在内的所有 Manifest V2 扩展](https://www.solidot.org/story?sid=85247) - 威努特安全网络 - [ ] [一文读懂IEC 63452《轨道交通 网络安全》](https://mp.weixin.qq.com/s?__biz=MzAwNTgyODU3NQ==&mid=2651143740&idx=1&sn=e4c380e6c1ee588fca5a0e1465bfa8a7) - rtl-sdr.com - [ ] [SDR++ IAK: A Modified Version of SDR++ Available on the Google Play Store](https://www.rtl-sdr.com/sdr-iak-a-modified-version-of-sdr-available-on-the-google-play-store/) - [ ] [An HTML Browser Page that Uses Display Pixel Clock EMI Leakage to Transmit VHF Morse Code](https://www.rtl-sdr.com/an-html-browser-page-that-uses-display-pixel-clock-emi-leakage-to-transmit-vhf-morse-code/) - Reverse Engineering - [ ] [/r/ReverseEngineering's Triannual Hiring Thread](https://www.reddit.com/r/ReverseEngineering/comments/1w44a8f/rreverseengineerings_triannual_hiring_thread/) - [ ] [Reverse-engineered Granny.dll (v1.2b) from 2000s for Sacred Gold RPG game.](https://www.reddit.com/r/ReverseEngineering/comments/1w4ehub/reverseengineered_grannydll_v12b_from_2000s_for/) - [ ] [NotHackable CTF: Jeopardy Style, Sept 4](https://www.reddit.com/r/ReverseEngineering/comments/1w4b78d/nothackable_ctf_jeopardy_style_sept_4/) - [ ] [Lumma Stealer – dllhost.exe Hollowing, C2 Domains & Payload Extraction](https://www.reddit.com/r/ReverseEngineering/comments/1w4f0qx/lumma_stealer_dllhostexe_hollowing_c2_domains/) - [ ] [Don’t Let Abliteration Abliterate Your Bug Hunting: Discovering Verdict Bias in Uncensored Models](https://www.reddit.com/r/ReverseEngineering/comments/1w42aby/dont_let_abliteration_abliterate_your_bug_hunting/) - [ ] [Klarion.sh - A reverse engineering platform for Windows (Mac and Linux releasing soon)](https://www.reddit.com/r/ReverseEngineering/comments/1w49vkr/klarionsh_a_reverse_engineering_platform_for/) - [ ] [Windows internals walkthrough: PE files and manual module mapping. Parsing IMAGE_DOS_HEADER / IMAGE_NT_HEADERS64, walking sections to locate .text, comparing disk vs memory layouts, and page alignment via VirtualProtect. Verifying with Cheat Engine. Looking for honest feedback! (might be boring)](https://www.reddit.com/r/ReverseEngineering/comments/1w481pp/windows_internals_walkthrough_pe_files_and_manual/) - 雷神众测 - [ ] [雷神众测漏洞周报2026.8.24-2026.8.30](https://mp.weixin.qq.com/s?__biz=MzI0NzEwOTM0MA==&mid=2652503934&idx=1&sn=653f59d8f877022699727252afdfbfae) - 青衣十三楼飞花堂 - [ ] [小小四现在不爱上学](https://mp.weixin.qq.com/s?__biz=MzUzMjQyMDE3Ng==&mid=2247489910&idx=1&sn=efda842dd06ccf3e8f9de6a57d9eba8d) - 代码卫士 - [ ] [Composer 漏洞可导致恶意依赖暴露 SSH 密钥和敏感文件](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247527008&idx=1&sn=0950887e9ff27c87182a5f98f8812f82) - [ ] [npm 热门包遭凭据窃取供应链蠕虫攻击](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247527008&idx=2&sn=15704bd374bcb0fdcff2dd82f78ea6e7) - 安全内参 - [ ] [零售龙头因泄露百万用户信息被罚超6000万元](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516508&idx=1&sn=94a2a3d2e1968901bd55042ace90cbc7) - [ ] [英国最大机场集团发生数据泄露,近900万客户数据失窃](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516508&idx=2&sn=f3a6a279f951f559c6f41ad1af2d451b) - 黑鸟 - [ ] [关于美军基地小卖部们的冰柜集体罢工事件](https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451188387&idx=1&sn=16d55fb849ce98bfd74f3a8ee1dce4f7) - Shostack & Friends Blog - [ ] [Register now for our training at OWASP](https://shostack.org/blog/registration-for-OWASP-SF-training-is-open/) - 看雪学苑 - [ ] [人机共智·重构攻防|弦盾科技,助力第十届安全开发者峰会(SDC2026)](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458619249&idx=1&sn=e7895bbe3704517944ab241685a92534) - [ ] [PH 钱包 App 注册协议分析与还原](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458619249&idx=2&sn=551475d99a5204f2ea807b999cb90337) - [ ] [恶意网站主题暗藏攻击链!黑客借Composer投毒窃取iPhone加密货币助记词](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458619249&idx=3&sn=84142bbb9dd6116443f2122283847580) - 安全研究GoSSIP - [ ] [G.O.S.S.I.P 阅读推荐 2026-09-01 隐私文档的十五年](https://mp.weixin.qq.com/s?__biz=Mzg5ODUxMzg0Ng==&mid=2247502073&idx=1&sn=5f4a860951f73342434e2602973b68ae) - 信息安全国家工程研究中心 - [ ] [药明康德网络安全事件敲警钟 :网络安全成产业“必修课”](https://mp.weixin.qq.com/s?__biz=MzU5OTQ0NzY3Ng==&mid=2247504840&idx=1&sn=ae12098c8c3e423a82bfe7fe32bbc11b) - 安全圈 - [ ] [【安全圈】Langflow与Rails曝高危漏洞黑客疯狂刺探凭证](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078572&idx=1&sn=1dd76fbf109a9faa6973891c20bda588) - [ ] [【安全圈】黑客盗取METR密钥狂刷60万美元算力](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078572&idx=2&sn=df1213cdf961ac58c0e053bc19a95ffb) - [ ] [【安全圈】PaperCut零日漏洞遭链式利用黑客洗劫企业数据](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078572&idx=3&sn=e1fed16292b0ab76de4cafc0b4f66723) - M01N Team - [ ] [AI安全案例分析 | NVIDIA NemoClaw聊天模板投毒漏洞](https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&mid=2247495479&idx=1&sn=00279f79fa4af36b6e32049ff54ec96d) - 中国信息安全 - [ ] [聚焦 | 2026年国家网络安全宣传周将于9月14日至20日在全国范围举行](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664266095&idx=1&sn=b3ffa8b56a536d5c985deb72eecd0838) - [ ] [CNNVD | 关于WebPros cPanel安全漏洞的通报](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664266095&idx=2&sn=631cd148481cee29f91e4c06098809a8) - [ ] [发布 | 国家互联网信息办公室、农业农村部联合发布《中国数字乡村发展报告(2019—2025年)》](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664266095&idx=3&sn=9a05b28afc21b3fd6b57f3075c782cb4) - [ ] [关注 | 新一批“银狐”木马相关恶意域名及恶意IP公布](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664266095&idx=4&sn=b92d3bcbe9f75001f4890ad37a0c9880) - [ ] [注意 | 这42款APP违法违规收集使用个人信息](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664266095&idx=5&sn=52b1233274c42618f4899f07c4ef8d41) - [ ] [评论 | 个人信息不容黑产染指](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664266095&idx=6&sn=341b343d200b5bb0d45d9e8fe9e12d68) - 数世咨询 - [ ] [加密失效:人工智能和量子技术如何为数据安全划定新界限](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247543834&idx=1&sn=b29db373e3842ea987c7df185772b6d9) - 奇安信威胁情报中心 - [ ] [黑客服务器裸奔泄露内幕:Aurora 勒索团伙用 Cursor AI 做攻击规划,完整还原从入侵到洗钱全链路](https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247520161&idx=1&sn=61ee15f915debc760d7d4ddbd6fb19ad) - 青藤云安全 - [ ] [AI攻防备战报告(金融篇):不碰一行代码,转走2亿港元](https://mp.weixin.qq.com/s?__biz=MzAwNDE4Mzc1NA==&mid=2650851740&idx=1&sn=de59a36e4afcae310d9476afc6778355) - 安全牛 - [ ] [比数据泄露更可怕的是:当你开始调查Shadow AI时,关键证据早就没了](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142535&idx=1&sn=ba58eebc4b8790ac12a9415042f7bbec) - [ ] [CNVD发布2026年第34期漏洞周报;OpenAI官方确认ChatGPT发生故障,ChatGPT Work及Plus服务受影响| 牛览](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142535&idx=2&sn=d6dc4b3777fa583939bc0c271b9a195f) - 安全分析与研究 - [ ] [自动化红队框架设计与工程实现](https://mp.weixin.qq.com/s?__biz=MzA4ODEyODA3MQ==&mid=2247497091&idx=1&sn=daf747910a08bbe2e492d6fc68046343) - 补天平台 - [ ] [一文读懂“GROW计划“三大挖洞赛道!](https://mp.weixin.qq.com/s?__biz=MzI2NzY5MDI3NQ==&mid=2247511008&idx=1&sn=ba8f43821ac66ac3b63a1f61fff0a215) - [ ] [2026补天校园GROW计划报名启动|赛道全新升级,打造AI 时代网络安全守护者](https://mp.weixin.qq.com/s?__biz=MzI2NzY5MDI3NQ==&mid=2247511008&idx=2&sn=a1f71dc8da06083299f576dd15528290) - 京东安全应急响应中心 - [ ] [反爬专项众测开启|最高 5 万元奖励,四大方向征集](https://mp.weixin.qq.com/s?__biz=MjM5OTk2MTMxOQ==&mid=2727851242&idx=1&sn=63959ce45394aba0b6e2528174a756a0) - 极客公园 - [ ] [梅卡曼德上市,具身智能又跑出一家百亿公司](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653113027&idx=1&sn=49b793aabeb35c8510acc9b32516b72d) - [ ] [硬件加强版「WorkBuddy」,拿下数亿融资,瞄向你的终极上下文](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653113014&idx=1&sn=17ece999ee94255575d1777ce0e56a0d) - [ ] [库克告别苹果 CEO;罗永浩官宣年底科技大会;华为、小米、荣耀手机今日集体调价|极客早知道](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653112996&idx=1&sn=efd90d8a1150573a3079ff811f922d86) - 阿里安全响应中心 - [ ] [十年坚守,报名开启|16家SRC邀您加入双11安全保卫战](https://mp.weixin.qq.com/s?__biz=MzIxMjEwNTc4NA==&mid=2652999052&idx=1&sn=4cb6ec76672b824e62a5010e3811c75e) - 字节跳动安全中心 - [ ] [多重福利活动|人人皆有专属激励,组队上号开挖!](https://mp.weixin.qq.com/s?__biz=MzUzMzcyMDYzMw==&mid=2247496343&idx=1&sn=0130718115e2f6714fb47946a14dbc33) - 火绒安全 - [ ] [银狐借AI信任链钓鱼 搜索结果暗藏下载陷阱](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247536988&idx=1&sn=ec7f000e629139b96b1f3caa956f5958) - [ ] [诚邀渠道合作伙伴共启新征程](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247536988&idx=2&sn=9e5dd4af7cd40eca9bfa37fd1f5c4d38) - 情报分析师 - [ ] [英国一次测试发现AI为了完成任务,开始伪造身份欺骗人类](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650569382&idx=1&sn=42fc0b14d61fbb36aaf55fba6e982d8f) - [ ] [美中情局局长秘密赴俄并与俄情报部门接触,需警惕美俄情报沟通机制回暖对中俄战略协作及乌克兰局势的潜在影响](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650569382&idx=2&sn=77dbadb1080c3ea69956d8f2991e9ab3) - 字节跳动技术团队 - [ ] [VLDB 2026|字节数据库 5 篇论文入选,附现场分享安排](https://mp.weixin.qq.com/s?__biz=MzI1MzYzMjE0MQ==&mid=2247521958&idx=1&sn=c7c173ceb0fbf6827a6cf448e4380d0f) - 表图 - [ ] [OpenAI - Hugging Face 事件最终技术报告:当上千个 Agent 开始互相授权,谁还能让它们停下?](https://mp.weixin.qq.com/s?__biz=MzUzOTI4NDQ3NA==&mid=2247485185&idx=1&sn=0a952f0343c959bc6785c2330ec25025) - 慢雾科技 - [ ] [“灰犀牛”与“黑天鹅”:慢雾创始人余弦谈加密世界安全风险与防护](https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&mid=2247505923&idx=1&sn=af78a7bff9bc55c19a3f20a0363060ab) - T00ls安全 - [ ] [CC1 链深度拆解:反序列化利用链是如何一步步执行的](https://mp.weixin.qq.com/s?__biz=Mzg3NzYzODU5NQ==&mid=2247485807&idx=1&sn=2d410e3a8ac951bed51391f057858fb8) - 墨菲安全 - [ ] [QuickFox:出海互联网软件企业的开源治理实践](https://mp.weixin.qq.com/s?__biz=MzkwOTM0MjI5NQ==&mid=2247488670&idx=1&sn=392208dbc4258868ce94f472ee3c3035) - ICT Security Magazine - [ ] [Prova digitale e anti-forensics: cosa cambia con l’AI generativa](https://www.ictsecuritymagazine.com/articoli/prova-digitale/) - 国家互联网应急中心CNCERT - [ ] [CNVD漏洞周报2026年第34期](https://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw==&mid=2247502074&idx=1&sn=d1cf330acfd03f6240f28a912939572c) - Over Security - [ ] [FBI Probes Service Selling 153M+ Drivers Licenses](https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/) - [ ] [Hackers abuse Faronics Deploy admin tool to install ScreenConnect](https://www.bleepingcomputer.com/news/security/hackers-abuse-faronics-deploy-admin-tool-to-install-screenconnect/) - [ ] [China's 'Fire Ant' campaign used compromised Cisco routers as platform for more attacks](https://therecord.media/router-hacks-fire-ant-group-china) - [ ] [Aesto Health says data breach affects over 9.5 million patients](https://www.bleepingcomputer.com/news/security/aesto-health-says-data-breach-affects-over-95-million-patients/) - [ ] [Critical Langflow flaw exploited to steal OpenAI and AWS keys](https://www.bleepingcomputer.com/news/security/critical-langflow-flaw-exploited-to-steal-openai-and-aws-keys/) - [ ] [Healthcare facilities operator Nutex says patient, employee data stolen in August incident](https://therecord.media/nutex-health-data-breach) - [ ] [Claude supera i confini dei test: Anthropic rallenta e ripensa la sicurezza dell’AI](https://www.cybersecurity360.it/news/claude-supera-i-confini-dei-test-anthropic-rallenta-e-ripensa-la-sicurezza-dellai/) - [ ] [Clonazione account WhatsApp su iPhone: abbiamo replicato l'exploit e segnalato a Meta](https://www.forenser.it/clonazione-account-whatsapp-iphone/) - [ ] [Hackers push malicious Virtualizor update in BGP hijacking attack](https://www.bleepingcomputer.com/news/security/hackers-push-malicious-virtualizor-update-in-bgp-hijacking-attack/) - [ ] [Cybercrime at Machine Speed: Key Takeaways from Flashpoint’s 2026 Midyear Threat Intelligence Briefing](https://flashpoint.io/blog/cybercrime-machine-speed-key-takeaways-flashpoints-2026-midyear-threat-intelligence/) - [ ] [Novocure data breach affects more than 1,400 cancer patients](https://www.bleepingcomputer.com/news/security/novocure-data-breach-affects-more-than-1-400-cancer-patients/) - [ ] [Why Even the Best Edge Security Still Misses High-Risk Sessions](https://www.bleepingcomputer.com/news/security/why-even-the-best-edge-security-still-misses-high-risk-sessions/) - [ ] [China-Linked Fire Ant Turned Cisco Routers, TACACS Servers Into Espionage Platforms](https://thecyberexpress.com/cisco-routers-tacacs-servers-espionage/) - [ ] [Il tuo nuovo sviluppatore lavora per Pyongyang: i rischi dell’onboarding remoto](https://www.cybersecurity360.it/nuove-minacce/il-tuo-nuovo-sviluppatore-lavora-per-pyongyang-i-rischi-dellonboarding-remoto/) - [ ] [Iranian cyber spies target aviation, fintech developers with new malware](https://therecord.media/iranian-cyber-spies-target-aviation-fintech-new-malware) - [ ] [Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks](https://www.bleepingcomputer.com/news/security/nearly-22-000-microsoft-exchange-servers-vulnerable-to-hijack-attacks/) - [ ] [Cyber risk from frontier AI poses ‘most immediate concern’ to global financial system, watchdog warns](https://therecord.media/cyber-risk-from-frontier-ai-most-immediate-concern-to-global-finance) - [ ] [RWA e tokenizzazione on-chain nel 2026: T-Bills, azioni tokenizzate e i provider da conoscere](https://hackerstribe.com/2026/rwa-e-tokenizzazione-on-chain-nel-2026-t-bills-azioni-tokenizzate-e-i-provider-da-conoscere/) - [ ] [I migliori wallet per criptovalute nel 2026: guida tecnica completa](https://hackerstribe.com/2026/i-migliori-wallet-per-criptovalute-nel-2026-guida-tecnica-completa/) - [ ] [Gli Stack perfetti per siti web e landing page nel 2026](https://hackerstribe.com/2026/gli-stack-perfetti-per-siti-web-e-landing-page-nel-2026/) - [ ] [Mac Mini M5 Pro: perché l'architettura a memoria unificata cambia le regole del training locale di LLM](https://hackerstribe.com/2026/mac-mini-m5-pro-perche-larchitettura-a-memoria-unificata-cambia-le-regole-del-training-locale-di-llm/) - [ ] [Meta paga 17 miliardi e vince: la sicurezza dei minori online e il paradosso dell’age assurance](https://www.cybersecurity360.it/news/meta-paga-17-miliardi-e-vince-la-sicurezza-dei-minori-online-e-il-paradosso-dellage-assurance/) - [ ] [Five Venezuelans plead guilty to ATM jackpotting attacks in US](https://www.bleepingcomputer.com/news/security/five-venezuelans-plead-guilty-to-atm-jackpotting-attacks-in-us/) - [ ] [Colleferro, Bulgaria e Lipsia: cosa c’è davvero dietro gli attacchi con droni, sabotaggi e disinformazione](https://www.cybersecurity360.it/nuove-minacce/colleferro-bulgaria-e-lipsia-cosa-ce-davvero-dietro-gli-attacchi-con-droni-sabotaggi-e-disinformazione/) - [ ] [Recently patched PaperCut zero-days used in data theft attacks](https://www.bleepingcomputer.com/news/security/recently-patched-papercut-zero-days-used-in-data-theft-attacks/) - [ ] [Terzo settore e GDPR: il “pulsante di aiuto” sui siti Web non è una semplice pagina di contatto](https://www.cybersecurity360.it/legal/privacy-dati-personali/data-protection-terzo-settore-pulsante-aiuto-siti-trattamento-alto-rischio/) - [ ] [Ionos e il commercio elettronico per le PMI: come l’integrazione di IA e sicurezza Cloud trasforma la creazione dei negozi online](https://www.cybersecurity360.it/cultura-cyber/ionos-ecommerce-plus-sicurezza-cloud-intelligenza-artificiale/) - [ ] [Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set](https://securelist.com/mirage-kitten-new-backdoors-noderabbit-pollcat/121244/) - [ ] [Major Cyber Attacks in August 2026: US and EU Businesses Hit by Session Hijacking, Remote Access, and Insider Risk](https://any.run/cybersecurity-blog/major-cyber-attacks-august-2026/) - [ ] [Questel - 1,226,209 breached accounts](https://haveibeenpwned.com/Breach/Questel) - [ ] [Vulnerability & Patch Roundup — August 2026](https://blog.sucuri.net/2026/08/vulnerability-patch-roundup-august-2026.html) - SANS Internet Storm Center, InfoCON: green - [ ] [Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)](https://isc.sans.edu/diary/rss/33300) - [ ] [ISC Stormcast For Tuesday, September 1st, 2026 https://isc.sans.edu/podcastdetail/10076, (Tue, Sep 1st)](https://isc.sans.edu/diary/rss/33302) - IT Service Management News - [ ] [Diritto alla riparazione](http://blog.cesaregallotti.it/2026/09/diritto-alla-riparazione.html) - Future of Tech and Security: Strategy & Innovation with Raffy - [ ] [AI Changes What Security Has To Remember](https://raffy.ch/blog/2026/09/01/ai-changes-what-security-has-to-remember/) - TrustedSec - [ ] [waf-fu, or Some Log Replay Nonsense](https://trustedsec.com/blog/waf-fu-or-some-log-replay-nonsense) - Have I Been Pwned latest breaches - [ ] [Questel - 1,226,209 breached accounts](https://haveibeenpwned.com/Breach/Questel) - Dark Space Blogspot - [ ] [Le Più Note Storie Di Ingegneria Sociale](http://darkwhite666.blogspot.com/2026/09/le-piu-note-storie-di-ingegneria-sociale.html) - Schneier on Security - [ ] [What’s the Scam?](https://www.schneier.com/blog/archives/2026/09/whats-the-scam.html) - [ ] [Leaked Russian Cyber-Operations Training Materials](https://www.schneier.com/blog/archives/2026/09/leaked-russian-cyber-operations-training-materials.html) - [ ] [Rewiring Democracy Series on The Renovator](https://www.schneier.com/blog/archives/2026/09/rewiring-democracy-series-on-the-renovator.html) - LockBoxx - [ ] [Behavior, Identity, and Controls for Coding Agents (Introducing Dream Serpent)](http://blog.lockboxx.org/2026/09/behavior-identity-and-controls-for.html) - Troy Hunt's Blog - [ ] [Weekly Update 519: Breaches & Data Integrity](https://www.troyhunt.com/weekly-update-519/) - www.theregister.com - Articles - [ ] [Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes](https://www.theregister.com/cyber-crime/2026/09/02/cops-crowdstrike-disrupt-sality-botnet-by-poisoning-the-network-and-diverting-into-sinkholes/5293795) - [ ] [Another Artifactory CVE under attack by AI agents or humans](https://www.theregister.com/security/2026/09/01/another-artifactory-cve-under-attack-by-ai-agents-or-humans/5293769) - [ ] [Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks](https://www.theregister.com/security/2026/09/01/attacker-stole-a-metr-api-key-used-600k-worth-of-credits-and-no-one-noticed-for-weeks/5293730) - [ ] [Firefox helps iPhone users bypass ads on web sites while making money showing its own ads](https://www.theregister.com/security/2026/09/01/firefox-helps-iphone-users-bypass-ads-on-web-sites-while-making-money-showing-its-own-ads/5293747) - [ ] [Anthropic pledges to try harder to keep models under control, asks partners to chip in](https://www.theregister.com/ai-and-ml/2026/09/01/anthropic-pledges-to-try-harder-to-keep-models-under-control-asks-partners-to-chip-in/5293733) - [ ] [33-hour BGP hijack of Softaculous traffic prompts security scramble](https://www.theregister.com/security/2026/09/01/33-hour-bgp-hijack-of-softaculous-traffic-prompts-security-scramble/5293608) - KitPloit - PenTest Tools! - [ ] [snuffleupagus v0.14.0](https://kitploit.com/en/posts/github-jvoisin-snuffleupagus-v0140) - [ ] [yolobox v0.19.4](https://kitploit.com/en/posts/github-finbarr-yolobox-v0194) - [ ] [mitaka v2.10.1](https://kitploit.com/en/posts/github-ninoseki-mitaka-v2101) - [ ] [DLLHijackHunter v2.4.0](https://kitploit.com/en/posts/github-ghostvectoracademy-dllhijackhunter-v240) - [ ] [super clearfog-v1.2.6](https://kitploit.com/en/posts/github-spr-networks-super-clearfog-v126) - [ ] [webanalyze v0.4.5](https://kitploit.com/en/posts/github-rverton-webanalyze-v045) - [ ] [bunkerweb v1.6.15-rc1](https://kitploit.com/en/posts/github-bunkerity-bunkerweb-v1615-rc1) - [ ] [MemShellParty v2.10.0](https://kitploit.com/en/posts/github-reajason-memshellparty-v2100) - [ ] [pipelock v3.5.0](https://kitploit.com/en/posts/github-luckypipewrench-pipelock-v350) - [ ] [vet v1.19.0](https://kitploit.com/en/posts/github-safedep-vet-v1190) - [ ] [LangAlpha v2026.09.01](https://kitploit.com/en/posts/github-ginlix-ai-langalpha-v20260901) - [ ] [python-tuf v7.0.1](https://kitploit.com/en/posts/github-theupdateframework-python-tuf-v701) - [ ] [TrustTunnel v1.1.0](https://kitploit.com/en/posts/github-trusttunnel-trusttunnel-v110) - [ ] [allstar v4.6](https://kitploit.com/en/posts/github-ossf-allstar-v46) - [ ] [wazuh v5.0.0-beta5](https://kitploit.com/en/posts/github-wazuh-wazuh-v500-beta5) - [ ] [intercept v2.33.0](https://kitploit.com/en/posts/github-smittix-intercept-v2330) - [ ] [wtf v0.5.8](https://kitploit.com/en/posts/github-0vercl0k-wtf-v058) - [ ] [beelzebub v3.9.1](https://kitploit.com/en/posts/github-beelzebub-labs-beelzebub-v391) - [ ] [BloodHound v9.7.0-rc1](https://kitploit.com/en/posts/github-specterops-bloodhound-v970-rc1) - [ ] [seer snap-latest](https://kitploit.com/en/posts/github-epasveer-seer-snap-latest) - [ ] [dalfox v3.2.2](https://kitploit.com/en/posts/github-hahwul-dalfox-v322) - [ ] [ja4 v1.0.1](https://kitploit.com/en/posts/github-foxio-llc-ja4-v101) - [ ] [testkube v2.13.1](https://kitploit.com/en/posts/github-kubeshop-testkube-2131) - [ ] [wBlock v3.0.0](https://kitploit.com/en/posts/github-0xcub3-wblock-300) - [ ] [vm2 v3.11.8](https://kitploit.com/en/posts/github-patriksimek-vm2-v3118) - [ ] [wappalyzergo v0.2.96](https://kitploit.com/en/posts/github-projectdiscovery-wappalyzergo-v0296) - [ ] [PF_RING v9.4.0](https://kitploit.com/en/posts/github-ntop-pf_ring-940) - [ ] [pingap v0.13.10](https://kitploit.com/en/posts/github-vicanso-pingap-v01310) - [ ] [KubeArmor v1.7.5-rc2](https://kitploit.com/en/posts/github-kubearmor-kubearmor-v175-rc2) - [ ] [zizmor v1.30.0](https://kitploit.com/en/posts/github-zizmorcore-zizmor-v1300) - [ ] [gping gping-v1.21.0](https://kitploit.com/en/posts/github-orf-gping-gping-v1210) - [ ] [chipsec v2.0.8](https://kitploit.com/en/posts/github-chipsec-chipsec-208) - [ ] [nDPI v6.0](https://kitploit.com/en/posts/github-ntop-ndpi-60) - [ ] [librepods nightly-53679cc](https://kitploit.com/en/posts/github-librepods-org-librepods-nightly-53679cc) - [ ] [cloudflared v2026.8.3](https://kitploit.com/en/posts/github-cloudflare-cloudflared-202683) - [ ] [Sandboxie v1.18.3](https://kitploit.com/en/posts/github-sandboxie-plus-sandboxie-v1183) - [ ] [frigate v0.18.0-rc1](https://kitploit.com/en/posts/github-blakeblackshear-frigate-v0180-rc1) - [ ] [ps5-uart — Updated!](https://kitploit.com/en/posts/github-symbrkrs-ps5-uart-6bc743493331ac089680e50b54c391a7b3d078d32749833c26270497ae0735e1) - [ ] [fingerprint-pro-internals — Updated!](https://kitploit.com/en/posts/github-proofofbots-fingerprint-pro-internals-74483b09060e477a91793ded91dbd68d5d5709468078a636a47f7465bed72913) - [ ] [awesome-ai-security — Updated!](https://kitploit.com/en/posts/github-gmh5225-awesome-ai-security-b300d9d87b8f9e8ae7c8a840597e9c3555b56d954e6819ad4f6329226a239eee) - Krebs on Security - [ ] [FBI Probes Service Selling 153M+ Drivers Licenses](https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/) - Instapaper: Unread - [ ] [Webmail polizia vendita forum viminale](https://pasqualepillitteri.it/news/13612/webmail-polizia-vendita-forum-viminale) - [ ] [Webmail della polizia in vendita sul forum cosa c’è di vero](https://www.matricedigitale.it/2026/08/31/webmail-polizia-viminale-forum-kodex-accesso/) - [ ] [The Most Difficult Problem in Forensic Validation How Do You Validate a Method When the True Answer Is Unknown](https://www.buddingforensicexpert.in/2026/09/forensic-validation-unknown-truth.html) - [ ] [Strengthening the tools behind consensual forensics investigations Mobile Verification Toolkit & Android Quick Forensic Secure Design Assessment](https://securitylab.amnesty.org/latest/2026/08/strengthening-the-tools-behind-consensual-forensics-secure-design-assessment/) - The Hacker News - [ ] [Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure](https://thehackernews.com/2026/09/attackers-exploit-critical-jfrog.html) - [ ] [Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems](https://thehackernews.com/2026/09/breeze-comet-executes-hundreds-of.html) - [ ] [13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds](https://thehackernews.com/2026/09/13-malicious-packagist-packages-target.html) - [ ] [Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests](https://thehackernews.com/2026/09/iranian-hackers-pose-as-recruiters-to.html) - [ ] [Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones](https://thehackernews.com/2026/09/threat-actors-dont-want-better-attacks.html) - [ ] [Attackers Steal METR API Key and Consume AI Credits Worth About $600,000](https://thehackernews.com/2026/09/attackers-steal-metr-api-key-and.html) - [ ] [Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis](https://thehackernews.com/2026/09/russia-aligned-uac-0099-plants-nuclear.html) - [ ] [Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity](https://thehackernews.com/2026/09/attackers-exploit-critical-langflow-and.html) - Securelist - [ ] [Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set](https://securelist.com/mirage-kitten-new-backdoors-noderabbit-pollcat/121244/) - Deep Web - [ ] [Que tan vulnerable son los cajeros automaticos en colombia, es su parte de sotfware ?](https://www.reddit.com/r/deepweb/comments/1w3x43r/que_tan_vulnerable_son_los_cajeros_automaticos_en/) - TorrentFreak - [ ] [“A Cute Little LibGen Babysitter”: Music Publishers Sue Anthropic Founders Over Torrenting Spree](https://torrentfreak.com/a-cute-little-libgen-babysitter-music-publishers-sue-anthropic-founders-over-torrenting-spree/) - Security Affairs - [ ] [Attackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million Records](https://securityaffairs.com/198250/data-breach/attackers-access-aesto-health-aws-infrastructure-exposing-9-5-million-records.html) - [ ] [Chaotic Eclipse Releases GenDigital Avast Antivirus ZeroDay PrettyPrague](https://securityaffairs.com/198243/hacking/chaotic-eclipse-releases-gendigital-avast-antivirus-zeroday-prettyprague.html) - [ ] [Five Venezuelan Nationals Plead Guilty in Kansas ATM Jackpotting Attempt](https://securityaffairs.com/198233/cyber-crime/five-venezuelan-nationals-plead-guilty-in-kansas-atm-jackpotting-attempt.html) - [ ] [North Korea-linked IT Workers Are Getting Hired Inside Western Companies](https://securityaffairs.com/198227/apt/north-korea-linked-it-workers-are-getting-hired-inside-western-companies.html) - [ ] [Chaotic Eclipse Releases Kaspersky Zero-Day HardBreacher](https://securityaffairs.com/198214/hacking/chaotic-eclipse-releases-kaspersky-zero-day-hardbreacher.html) - [ ] [U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog](https://securityaffairs.com/198200/security/u-s-cisa-adds-papercut-ng-mf-flaws-to-its-known-exploited-vulnerabilities-catalog.html) - Tor Project blog - [ ] [New Release: Tor Browser 15.0.21](https://blog.torproject.org/new-release-tor-browser-15021/) - Deeplinks - [ ] [Meta's $17 Billion Settlement is a Bad Deal for Teens and All Social Media Users](https://www.eff.org/deeplinks/2026/09/metas-17-billion-settlement-bad-deal-teens-and-all-social-media-users)
每日安全资讯(2026-09-02)