# 每日安全资讯(2026-09-04) - SecWiki News - [ ] [SecWiki News 2026-09-03 Review](http://www.sec-wiki.com/?2026-09-03) - Private Feed for M09Ic - [ ] [timwhitez made this repository public](https://github.com/timwhitez/neocloud-sec) - [ ] [anthropics released v2.1.260 at anthropics/claude-code](https://github.com/anthropics/claude-code/releases/tag/v2.1.260) - [ ] [Mr-xn starred systembad403/Coruna6](https://github.com/systembad403/Coruna6) - [ ] [bolucat released 202609032250 at bolucat/Archive](https://github.com/bolucat/Archive/releases/tag/202609032250) - [ ] [liamg contributed to liamg/grabber](https://github.com/liamg/grabber/pull/52) - [ ] [Rvn0xsy starred Tampermonkey/tampermonkey-mcp](https://github.com/Tampermonkey/tampermonkey-mcp) - [ ] [Ridter starred DietrichGebert/ponytail](https://github.com/DietrichGebert/ponytail) - [ ] [mgeeky starred SpecterOps/skills](https://github.com/SpecterOps/skills) - [ ] [Mr-xn starred ADScanPro/Claude-AD](https://github.com/ADScanPro/Claude-AD) - [ ] [esrrhs starred boostorg/mysql](https://github.com/boostorg/mysql) - [ ] [timwhitez starred ADScanPro/Claude-AD](https://github.com/ADScanPro/Claude-AD) - [ ] [mgeeky starred dtmsecurity/badpie](https://github.com/dtmsecurity/badpie) - [ ] [pydantic released v2.38.0 at pydantic/pydantic-ai](https://github.com/pydantic/pydantic-ai/releases/tag/v2.38.0) - [ ] [timwhitez starred SemiAnalysisAI/ClusterMAX](https://github.com/SemiAnalysisAI/ClusterMAX) - [ ] [gh0stkey starred zvec-ai/zvec-grep](https://github.com/zvec-ai/zvec-grep) - 安全客-有思想的安全新媒体 - [ ] [漏洞开始工业化生产:AI让黑客的经验可以复制粘贴了](https://www.anquanke.com/post/id/316072) - Recent Commits to cve:main - [ ] [Update Thu Sep 3 12:15:12 UTC 2026](https://github.com/trickest/cve/commit/8ca4b817d19578a08ae45e704d541b7860e61b9f) - ElcomSoft blog - [ ] [Elcomsoft Quick Triage 2.2: Timeline, file system snapshot, and a plugin engine](https://blog.elcomsoft.com/2026/09/elcomsoft-quick-triage-2-2-timeline-file-system-snapshot-and-a-plugin-engine/) - Microsoft Security Blog - [ ] [ASCII smuggling crosses over from AI prompt injection to phishing evasion](https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/) - Kitploit - [ ] [javascript-obfuscator](https://kitploit.com/en/tools/github/javascript-obfuscator/javascript-obfuscator) - [ ] [View8](https://kitploit.com/en/tools/github/suleram/view8) - [ ] [Windows-Kernel-Exploitation](https://kitploit.com/en/tools/github/vp777/windows-kernel-exploitation) - [ ] [root-s24-e1s](https://kitploit.com/en/tools/github/everyoneexe/root-s24-e1s) - [ ] [pocindex](https://kitploit.com/en/tools/github/0xmarcio/pocindex) - [ ] [lure v0.7.1](https://kitploit.com/en/posts/github-0xusmanismail-lure-v071) - [ ] [Rocket.Chat v8.8.0](https://kitploit.com/en/posts/github-rocketchat-rocketchat-880) - [ ] [burpFakeIP](https://kitploit.com/en/tools/github/thekingofduck/burpfakeip) - [ ] [honeypot-auditor](https://kitploit.com/en/tools/github/mziqudhd92/honeypot-auditor) - [ ] [Specter-FlipperZero v2.8](https://kitploit.com/en/posts/github-at0m-b0mb-specter-flipperzero-v28) - [ ] [pphack v0.1.5](https://kitploit.com/en/posts/github-edoardottt-pphack-v015) - [ ] [globalping-probe v0.52.0](https://kitploit.com/en/posts/github-jsdelivr-globalping-probe-v0520) - [ ] [Nightingale v1.1.47](https://kitploit.com/en/posts/github-rajanagori-nightingale-v1147) - [ ] [multi-juicer v10.3.1](https://kitploit.com/en/posts/github-juice-shop-multi-juicer-v1031) - [ ] [AuroraStore](https://kitploit.com/en/tools/gitlab/auroraoss/aurorastore) - [ ] [Lumma-Stealer-dllhost-Hollowing-C2-Domains-Payload-Extraction-Analysis](https://kitploit.com/en/tools/github/kaandemir993/lumma-stealer-dllhost-hollowing-c2-domains-payload-extraction-analysis) - [ ] [nono v0.75.0](https://kitploit.com/en/posts/github-nolabs-ai-nono-v0750) - [ ] [Final-project-SQL-injection-pipeline](https://kitploit.com/en/tools/github/mlily2024/final-project-sql-injection-pipeline) - [ ] [LR-WebPKI](https://kitploit.com/en/tools/github/nserser/lr-webpki) - [ ] [T-MAP](https://kitploit.com/en/tools/github/pwnhyo/t-map) - [ ] [CatSniffer-Firmware](https://kitploit.com/en/tools/github/electroniccats/catsniffer-firmware) - [ ] [GreenSection](https://kitploit.com/en/tools/github/msnightmare/greensection) - [ ] [EmailXpose — Updated!](https://kitploit.com/en/posts/gitlab-roxanne_ardary-emailxpose-38091ee723cd10c821088f35742a73dc13a45e528f55595f358d9856a9d683fd) - [ ] [envsec v1.0.0-rc.2](https://kitploit.com/en/posts/github-davidnussio-envsec-v100-rc2) - [ ] [sshconfig-lint v0.5.0](https://kitploit.com/en/posts/github-noah4ever-sshconfig-lint-v050) - [ ] [Dependency Scanning v2.1.1](https://kitploit.com/en/posts/gitlab-components-dependency-scanning-211) - [ ] [Root-My-Device v0.0.7](https://kitploit.com/en/posts/github-witaqua-tools-root-my-device-v007) - [ ] [wrongsecrets-binaries v0.3.0](https://kitploit.com/en/posts/github-owasp-wrongsecrets-binaries-v030) - [ ] [safer-dependencies v0.6.1](https://kitploit.com/en/posts/github-robert-auger-safer-dependencies-v061) - [ ] [muad-dib v2.12.0](https://kitploit.com/en/posts/github-dnszlsk-muad-dib-v2120) - [ ] [laravel-threat-detection v1.7.2](https://kitploit.com/en/posts/github-jay123anta-laravel-threat-detection-v172) - GuidePoint Security - [ ] [Recent Update to FAQ Regarding SAQ Eligibility Criteria Could Affect Your PCI DSS Compliance](https://www.guidepointsecurity.com/blog/pci-dss-saq-elibigility-criteria/) - Horizon3 - [ ] [How Virginia Tech Connected Pentesting to Its Engineering Workflow](https://horizon3.ai/customer-story/virginia-tech-automated-external-pentesting/) - Malwarebytes - [ ] [StreamRat Android malware spreads through Meta and TikTok ads](https://www.malwarebytes.com/blog/news/2026/09/streamrat-android-malware-spreads-through-meta-and-tiktok-ads) - [ ] [Your phone or computer may soon ask how old you are](https://www.malwarebytes.com/blog/privacy/2026/09/your-phone-or-computer-may-soon-ask-how-old-you-are) - Binary Ninja - [ ] [Binary Ninja 6.0 (Krypton)](https://binary.ninja/2026/09/03/binary-ninja-6.0-krypton.html) - MalwareTech - [ ] [Machine Speed is a lie: stop trying to fight AI with AI](https://malwaretech.com/2026/09/machine-speed-is-a-lie-stop-trying-to-fight-ai-with-ai.html) - Exploit-DB.com RSS Feed - [ ] [[webapps] FreePBX 17.0.2 - Remote Code Execution (RCE)](https://www.exploit-db.com/exploits/52681) - [ ] [[webapps] Metabase 0.61.0 - Authenticated Remote Code Execution](https://www.exploit-db.com/exploits/52680) - rtl-sdr.com - [ ] [FreeDV RADE: An Open-Source Digital Voice Mode for HF that Beats SSB at Low SNR](https://www.rtl-sdr.com/freedv-rade-an-open-source-digital-voice-mode-for-hf-that-beats-ssb-at-low-snr/) - 黑鸟 - [ ] [当ELF文件被压缩至57字节](https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451188411&idx=1&sn=0802ffd8d6d6ef9b7776eb5a43e8a4dd) - 全频带阻塞干扰 - [ ] [重磅 | 24~48GHz 高频检测是伪命题?](https://mp.weixin.qq.com/s?__biz=MzIzMzE2OTQyNA==&mid=2648959519&idx=1&sn=62e628dd786e887eda26444da9aa589c) - 威努特安全网络 - [ ] [打造从网络到终端的影子AI立体识别体系](https://mp.weixin.qq.com/s?__biz=MzAwNTgyODU3NQ==&mid=2651143777&idx=1&sn=be39833c515a7b3a4791e1a13d0baeae) - 安全内参 - [ ] [国家级身份认证平台疑似数据泄露:涉1.5 亿余条公民证照 暗网可实时查询](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516535&idx=1&sn=bec163c257d8069d2d35090bfc01d25e) - [ ] [美国国防部即将推出的新版网络战略将聚焦三大优先事项](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516535&idx=2&sn=7589d03a1948f77053792595a61315c6) - 奇客Solidot–传递最新科技情报 - [ ] [衰老的大脑会混淆扭曲记忆](https://www.solidot.org/story?sid=85282) - [ ] [纽约市禁止八年级以下公立学校学生使用生成式 AI](https://www.solidot.org/story?sid=85281) - [ ] [微软和索尼表示他们无法律义务将美国关税退款退给消费者](https://www.solidot.org/story?sid=85280) - [ ] [Audacity 4.0 释出](https://www.solidot.org/story?sid=85279) - [ ] [尼泊尔认为主要碳排放国家应补偿它因气候变化遭受的损失](https://www.solidot.org/story?sid=85278) - [ ] [LibreOffice 26.8 发布一周下载量突破 100 万次](https://www.solidot.org/story?sid=85277) - [ ] [科学家可能观测到暗物质粒子](https://www.solidot.org/story?sid=85276) - [ ] [土星南极发现十边形气体结构](https://www.solidot.org/story?sid=85275) - [ ] [Nexus Mods 收购 SteamDB](https://www.solidot.org/story?sid=85274) - [ ] [NASA 选择 Blue Origin 作为火星通信网络供应商](https://www.solidot.org/story?sid=85273) - [ ] [人体不同组织的结构衰老呈现三种模式](https://www.solidot.org/story?sid=85272) - [ ] [CERN 从 RHEL/CentOS 迁移到 Debian](https://www.solidot.org/story?sid=85270) - [ ] [Uber 裁员 3300 人](https://www.solidot.org/story?sid=85269) - 代码卫士 - [ ] [JFrog Artifactory 严重漏洞被用于获取管理员访问权限](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247527023&idx=1&sn=6354e796f83527707ce66da427e69c03) - [ ] [近2.2万台微软 Exchange 服务器易受劫持攻击](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247527023&idx=2&sn=80bb88dde336ad0a9976a52d48f42d11) - 安全客 - [ ] [漏洞开始工业化生产:AI让黑客的经验可以复制粘贴了](https://mp.weixin.qq.com/s?__biz=MzA5ODA0NDE2MA==&mid=2649790446&idx=1&sn=f16ce91e0e805bc0813f6115275de86c) - 360漏洞云 - [ ] [中秋福利 | 漏洞换月饼,2026冲榜+纳新+回归,三重狂欢!](https://mp.weixin.qq.com/s?__biz=Mzg5MTc5Mzk2OA==&mid=2247505201&idx=1&sn=50bf11fe9fe3e2f5b0dc3980e6dd50e7) - 中国信息安全 - [ ] [独家报告 | 前沿AI企业"控制标准"首评深度评述——基于Guidelight《Control Assessment》原文与译文](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664266259&idx=1&sn=3b6317ee050c2282ffa39d316af2a3c6) - [ ] [关注 | 市场监管总局就《网络交易小程序平台合规指引(征求意见稿)》公开征求意见(附全文)](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664266259&idx=2&sn=2b05031f8c2a5d536f00a26f6807dd6a) - [ ] [前沿 | 认识和把握主权人工智能建设](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664266259&idx=3&sn=f1c3b4d42ca25915070c0140c547fecc) - [ ] [观点 | 智能时代,如何与算法共处](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664266259&idx=4&sn=794c1062a194b86a90ee318f2935cd52) - [ ] [观点 | “虚拟相机”技术滥用的法律风险及其治理](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664266259&idx=5&sn=65f7ac415e9b5bf182606d55a414b62b) - 信息安全国家工程研究中心 - [ ] [中央网信办:当前人工智能领域主要面临5方面安全风险挑战](https://mp.weixin.qq.com/s?__biz=MzU5OTQ0NzY3Ng==&mid=2247504850&idx=1&sn=c340e2214caedebd15fdca20a35fe922) - 看雪学苑 - [ ] [9月9日,邀您共赴2026外滩大会“智能体安全”之约](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458619367&idx=1&sn=e06fc369717dfd7c24a47a64fdaade25) - [ ] [Superpowers 这类“教 AI 怎么写代码”的插件,过时了吗?](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458619367&idx=2&sn=be887af1c6dd7a7a082d563bb6cba42a) - [ ] [CVSS 9.8高危|Cisco Nexus 9000曝未认证RCE漏洞,可直接获取设备Root权限](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458619367&idx=3&sn=2a5c3530ba0befbb2deb97b3e6b9df12) - 安全圈 - [ ] [【安全圈】淘宝崩了](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078625&idx=1&sn=9dc8d00b36df15e243d9e2e1f3dea21b) - 微步在线 - [ ] [三个机制,让超大型集团敏捷迎战“银狐”](https://mp.weixin.qq.com/s?__biz=MzI5NjA0NjI5MQ==&mid=2650187814&idx=1&sn=436eca00ace2ffa63b54dd498eff59e4) - 默安科技 - [ ] [从海量告警到精准修复:默安智能体助力大型金融机构打通开发安全工具链](https://mp.weixin.qq.com/s?__biz=MzIzODQxMjM2NQ==&mid=2247502022&idx=1&sn=27ba4353366bc98eecfe755a8f4108db) - 腾讯科恩实验室 - [ ] [BinaryAI-Bench:面向实战业务的二进制安全分析任务评测集](https://mp.weixin.qq.com/s?__biz=MzU1MjgwNzc4Ng==&mid=2247513253&idx=1&sn=0f0b7419dda27ae69e5059f600dc0a1c) - 青藤云安全 - [ ] [AI攻防备战报告(能源篇):AI学会了拉闸](https://mp.weixin.qq.com/s?__biz=MzAwNDE4Mzc1NA==&mid=2650851790&idx=1&sn=54cbf0b4c24c7a92c1193ae2887fcd8d) - 腾讯安全威胁情报中心 - [ ] [BinaryAI-Bench:面向实战业务的二进制安全分析任务评测集](https://mp.weixin.qq.com/s?__biz=MzI5ODk3OTM1Ng==&mid=2247512067&idx=1&sn=22dc6a7127c33c05619f384d6af0cfad) - 安全分析与研究 - [ ] [AI增强的威胁检测系统架构](https://mp.weixin.qq.com/s?__biz=MzA4ODEyODA3MQ==&mid=2247497099&idx=1&sn=0dd07d474f76b7a6705d9c137b20fca3) - 奇安信威胁情报中心 - [ ] [一场“面试笔试”背后的入侵:Mirage Kitten 转向 Node.js/JavaScript 恶意软件](https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247520202&idx=1&sn=8006a96f5fd860011b5a2bf253037f58) - 极客公园 - [ ] [成立不到一年连融三轮,这个睡眠 AI 产品「火」了](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653113105&idx=1&sn=10394fa42d6aa07877395900ace069a3) - [ ] [马斯克:火箭再炸一次,SpaceX 就没了;小米「阔折叠」全球首秀;豆包工作支持多 Agent 和屏幕操作 | 极客早知道](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653113100&idx=1&sn=82a76842dba8b1e596afb1c7ccbc975d) - 字节跳动安全中心 - [ ] [字节跳动安全与风控 2027 校招来袭! 一起守护亿级用户网络安全](https://mp.weixin.qq.com/s?__biz=MzUzMzcyMDYzMw==&mid=2247496365&idx=1&sn=12db8793f612169a106c8bb3317185a7) - 安全牛 - [ ] [《AI驱动的SDLC及软件供应链安全技术应用指南》重磅发布](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142579&idx=1&sn=356c208bfd659d0a561ff37d2295aac0) - [ ] [AI训练数据版权之争升级:美国政府提交20页文件支持OpenAI;OpenLeash 为 AI Agent 增设人工审核机制,拦截高风险自主操作| 牛览](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142579&idx=2&sn=55b7e8ee118e3d75733e735d24dd6268) - 火绒安全 - [ ] [隐蔽驻留 无痕执行│OverLord远控木马技术分析](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247537053&idx=1&sn=5ba2ce2a68722fa74ebd9953a4c19404) - [ ] [诚邀渠道合作伙伴共启新征程](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247537053&idx=2&sn=d9bab81e82da3189e5ad96b81fdaef8e) - 情报分析师 - [ ] [一张"普通"自拍,能出卖你多少?](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650569454&idx=1&sn=a003f3c8b43763ce892387b02e767a03) - [ ] [印度宣称挫败“巴基斯坦支持的武装袭击”并逮捕200余人,需警惕南亚恐怖网络及跨境渗透活动对我西部边境安全、中巴经济走廊建设和](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650569454&idx=2&sn=00eb3059491519730285facf77fc76ed) - 嘶吼专业版 - [ ] [9月9日,邀您共赴2026外滩大会“智能体安全”之约](https://mp.weixin.qq.com/s?__biz=MzI0MDY1MDU4MQ==&mid=2247587814&idx=1&sn=07f9feb069464a18c93837605e2b22e0) - TrustedSec - [ ] [LLMHaxor Update](https://trustedsec.com/blog/llmhaxor-update) - 360数字安全 - [ ] [第四届“天网杯”网络安全大赛圆满落幕,360以实战筑牢人才之基](https://mp.weixin.qq.com/s?__biz=MzA4MTg0MDQ4Nw==&mid=2247586825&idx=1&sn=f2cf2fd1373c31be178dc4c08e140817) - 墨菲安全 - [ ] [连续三年入选|墨菲安全上榜数说安全“2026中国网安新势力30强”](https://mp.weixin.qq.com/s?__biz=MzkwOTM0MjI5NQ==&mid=2247488683&idx=1&sn=f5c5c63bc9705e05fa1622a210393d47) - 美团技术团队 - [ ] [美团智播——数字人直播技术创新与实践](https://mp.weixin.qq.com/s?__biz=MjM5NjQ5MTI5OA==&mid=2651783277&idx=1&sn=69b406db34fc05f4a17b0310dcf3a7f5) - [ ] [报名 | 清华大学-美团学术论坛:物理世界中的AI及大模型](https://mp.weixin.qq.com/s?__biz=MjM5NjQ5MTI5OA==&mid=2651783277&idx=2&sn=8095c2d91985ee6b04bb7a6f06c88f5e) - 白日放歌须纵9 - [ ] [数智化转型下的业务安全原生体系](https://mp.weixin.qq.com/s?__biz=MzIzNjAyODE0NQ==&mid=2247483957&idx=1&sn=3670d5fb974a1ac18e89f7b06227d43a) - Over Security - [ ] [French hospital fined €500,000 after breach exposes data of 727,000](https://www.bleepingcomputer.com/news/security/french-hospital-fined-500-000-after-breach-exposes-data-of-727-000/) - [ ] [Coder's registry infrastructure compromised to push malicious modules](https://www.bleepingcomputer.com/news/security/coders-registry-infrastructure-compromised-to-push-malicious-modules/) - [ ] [Large group of Serbian opposition, activist figures targeted with spyware](https://therecord.media/serbia-spyware-pegasus-europe) - [ ] [HPE patches critical ArubaOS-CX remote code execution flaw](https://www.bleepingcomputer.com/news/security/hpe-patches-critical-arubaos-cx-remote-code-execution-flaw/) - [ ] [The story behind the intelligence](https://blog.talosintelligence.com/the-story-behind-the-intelligence/) - [ ] [Microsoft: KB5120998 mouse reset bug affects only non-English PCs](https://www.bleepingcomputer.com/news/microsoft/microsoft-kb5120998-mouse-reset-bug-affects-only-non-english-pcs/) - [ ] [Bugpocalypse: perché l’apocalisse AI è in ritardo](https://www.cybersecurity360.it/cultura-cyber/bugpocalypse-perche-lapocalisse-ai-e-in-ritardo/) - [ ] [Anthropic confirms Claude is down, multiple models affected](https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-confirms-claude-is-down-multiple-models-affected/) - [ ] [OpenAI confirms ChatGPT is down ahead of 'Astra' model launch](https://www.bleepingcomputer.com/news/artificial-intelligence/openai-confirms-chatgpt-is-down-ahead-of-astra-model-launch/) - [ ] [Critical Elementor Pro flaw exploited to take over WordPress sites](https://www.bleepingcomputer.com/news/security/critical-elementor-pro-flaw-exploited-to-take-over-wordpress-sites/) - [ ] [Your Employee’s Password Appeared in an Infostealer Log. Now What?](https://www.bleepingcomputer.com/news/security/your-employees-password-appeared-in-an-infostealer-log-now-what/) - [ ] [Email aziendali, metadati e controlli difensivi: l’utilizzabilità della prova digitale](https://www.cybersecurity360.it/legal/privacy-dati-personali/email-aziendali-metadati-e-controlli-difensivi-lutilizzabilita-della-prova-digitale/) - [ ] [Falso rimborso TARI sfruttato nelle nuove campagne di phishing ai danni di PagoPA](https://cert-agid.gov.it/news/falso-rimborso-tari-sfruttato-nelle-nuove-campagne-di-phishing-ai-danni-di-pagopa/) - [ ] [ClickFix evolve con TerminalFix: il falso CAPTCHA diventa una porta verso la rete aziendale](https://www.cybersecurity360.it/news/clickfix-evolve-con-terminalfix-il-falso-captcha-diventa-una-porta-verso-la-rete-aziendale/) - [ ] [Microsoft says KB5120998 Windows update resets desktop settings](https://www.bleepingcomputer.com/news/microsoft/microsoft-says-kb5120998-windows-update-resets-desktop-settings/) - [ ] [Analisi Tecnica del Kit MaoMao PhaaS: Tattiche AiTM ed Evasione Avanzata](https://blog.lobsec.com/2026/09/analisi-tecnica-maomao-phaas/) - [ ] [US and Canadian court data exposed in Thomson Reuters breach](https://therecord.media/thomson-reuters-cyberattack-data) - [ ] [Plex warns users to patch security vulnerabilities immediately](https://www.bleepingcomputer.com/news/security/plex-warns-users-to-patch-security-vulnerabilities-immediately/) - [ ] [Zero Trust 2.0 e Identity-First Security: l’identità diventa il nuovo perimetro](https://www.cybersecurity360.it/soluzioni-aziendali/zero-trust-2-0-e-identity-first-security-lidentita-diventa-il-nuovo-perimetro/) - [ ] [CVE-2026-84115 in Cleo Harmony: JWT Refresh Token Handler Flaw Exposes Remote Attack Risk](https://thecyberexpress.com/cve-2026-84115-cleo-harmony-jwt-refresh-token/) - [ ] [Release Notes: Faster TI Investigations, Fresh Threat Research, and 650+ Threat Coverage Updates](https://any.run/cybersecurity-blog/release-notes-august-2026/) - [ ] [Microsoft Teams, Outlook fail to launch on ARM-based Windows PCs](https://www.bleepingcomputer.com/news/microsoft/microsoft-teams-outlook-fail-to-launch-on-arm-based-windows-pcs/) - [ ] [Zero-day e attacchi autonomi: perché OpenAI frena il rilascio di Astra](https://www.cybersecurity360.it/news/zero-day-e-attacchi-autonomi-perche-openai-frena-il-rilascio-di-astra/) - [ ] [CRA Reporting – What you need to know](https://blog.compass-security.com/2026/09/cra-reporting-what-you-need-to-know/) - [ ] [Supply Chain Attacks in 2026: Why Threat Intelligence Is the Only Early Warning System That Works](https://cyble.com/blog/supply-chain-attacks-in-2026-vendor-risk/) - [ ] [Cheatsheet: Threat Attribution in Threat Intelligence - root@fareed:~#](https://fareedfauzi.github.io/cheatsheets/threat-attribution/) - [ ] [62,920 Files in Orova’s Crosshairs: Alleged Theft from DL Holdings Hits Finance, Bitcoin and Mongolia](https://www.suspectfile.com/62920-files-in-orovas-crosshairs-alleged-theft-from-dl-holdings-hits-finance-bitcoin-and-mongolia/) - [ ] [SonicWall Warns of Two Actively Exploited SMA1000 Zero-Days, One Rated Maximum Severity](https://thecyberexpress.com/sonicwall-warns-of-two-zero-days-in-sma1000/) - [ ] [Click to Pray, Click to Leak: The Pope's Official App Exposes 700,000+ User Emails](https://bobdahacker.com/blog/click-to-pray) - [ ] [Norton e la difesa contro le minacce basate su IA: come la suite Norton 360 integra il rilevamento dei deepfake e la protezione anti-truffa](https://www.cybersecurity360.it/cultura-cyber/norton-360-protezione-ia-deepfake-dark-web-monitoring/) - [ ] [Crittografia XChaCha20: le architetture zero-knowledge mettono in sicurezza le credenziali delle PMI](https://www.cybersecurity360.it/cultura-cyber/nordpass-business-gestione-password-aziendali-xchacha20/) - [ ] [The Outsider Phishing Kit: A Resilient Threat in the Face of Law Enforcement Action](https://www.group-ib.com/blog/chenlun-outsider-phaas-kit/) - [ ] [CISA, FBI Urge Clearer Communication During Major Outages](https://thecyberexpress.com/cisa-fbi-issue-outage-communications-guidance/) - [ ] [DOJ Investigates Cyberattack Targeting Hundreds of Thousands of X Users](https://thecyberexpress.com/cyberattack-on-x-users-doj-investigation/) - Tails - News - [ ] [Tails 7.12](https://tails.net/news/version_7.12/) - Yak Project - [ ] [指针审计:一组新的 SyntaxFlow Native Call](https://mp.weixin.qq.com/s?__biz=Mzk0MTM4NzIxMQ==&mid=2247530172&idx=1&sn=ac7ea0a574f18837ef5b1044933053f9) - SANS Internet Storm Center, InfoCON: green - [ ] [Honeypot-Omaha and batch.py [Guest Diary], (Wed, Sep 2nd)](https://isc.sans.edu/diary/rss/33306) - [ ] [ISC Stormcast For Thursday, September 3rd, 2026 https://isc.sans.edu/podcastdetail/10080, (Thu, Sep 3rd)](https://isc.sans.edu/diary/rss/33308) - Schneier on Security - [ ] [Researching Employment Scams](https://www.schneier.com/blog/archives/2026/09/researching-employment-scams.html) - 360威胁情报中心 - [ ] [APT-C-56(透明部落)近期攻击活动分析](https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247508875&idx=1&sn=39ad939372621e4f7bc675dda5b0d7b3) - 丁爸 情报分析师的工具箱 - [ ] [【开源报告】认知战相关全球资源网站调研报告](https://mp.weixin.qq.com/s?__biz=MzI2MTE0NTE3Mw==&mid=2651157275&idx=1&sn=6d251d19a37db1646a8276c613d7ac8e) - [ ] [【通知】第六届开源情报技术大会与第四届全国大学生开源情报数据采集与分析挑战赛](https://mp.weixin.qq.com/s?__biz=MzI2MTE0NTE3Mw==&mid=2651157275&idx=2&sn=546a26ce13e38d0c93ea488c50d9bf2b) - Instapaper: Unread - [ ] [WhatsApp Lets You View Photos Without Unlocking Smartphone](https://www.mobile-hacker.com/2026/09/02/whatsapp-lets-you-view-photos-without-unlocking-smartphone/) - [ ] [BrowserState.db last_viewed_time](https://dfir.pubpub.org/pub/9sso3o3m) - [ ] [Metadata Is Not Truth Why Digital Timestamps Can Mislead Forensic Investigations](https://www.buddingforensicexpert.in/2026/09/metadata-is-not-truth.html) - NetSPI - [ ] [Modern Adventures in Azure Privilege Escalation](https://www.netspi.com/blog/technical-blog/cloud-pentesting/modern-adventures-in-azure-privilege-escalation/) - [ ] [A New Era for Offensive Security](https://www.netspi.com/blog/executive-blog/netspi-updates/a-new-era-for-offensive-security/) - KitPloit - PenTest Tools! - [ ] [javascript-obfuscator](https://kitploit.com/en/tools/github/javascript-obfuscator/javascript-obfuscator) - [ ] [View8](https://kitploit.com/en/tools/github/suleram/view8) - [ ] [Windows-Kernel-Exploitation](https://kitploit.com/en/tools/github/vp777/windows-kernel-exploitation) - [ ] [root-s24-e1s](https://kitploit.com/en/tools/github/everyoneexe/root-s24-e1s) - [ ] [pocindex](https://kitploit.com/en/tools/github/0xmarcio/pocindex) - [ ] [lure v0.7.1](https://kitploit.com/en/posts/github-0xusmanismail-lure-v071) - [ ] [Rocket.Chat v8.8.0](https://kitploit.com/en/posts/github-rocketchat-rocketchat-880) - [ ] [burpFakeIP](https://kitploit.com/en/tools/github/thekingofduck/burpfakeip) - [ ] [honeypot-auditor](https://kitploit.com/en/tools/github/mziqudhd92/honeypot-auditor) - [ ] [Specter-FlipperZero v2.8](https://kitploit.com/en/posts/github-at0m-b0mb-specter-flipperzero-v28) - [ ] [pphack v0.1.5](https://kitploit.com/en/posts/github-edoardottt-pphack-v015) - [ ] [globalping-probe v0.52.0](https://kitploit.com/en/posts/github-jsdelivr-globalping-probe-v0520) - [ ] [Nightingale v1.1.47](https://kitploit.com/en/posts/github-rajanagori-nightingale-v1147) - [ ] [multi-juicer v10.3.1](https://kitploit.com/en/posts/github-juice-shop-multi-juicer-v1031) - [ ] [AuroraStore](https://kitploit.com/en/tools/gitlab/auroraoss/aurorastore) - [ ] [Lumma-Stealer-dllhost-Hollowing-C2-Domains-Payload-Extraction-Analysis](https://kitploit.com/en/tools/github/kaandemir993/lumma-stealer-dllhost-hollowing-c2-domains-payload-extraction-analysis) - [ ] [nono v0.75.0](https://kitploit.com/en/posts/github-nolabs-ai-nono-v0750) - [ ] [Final-project-SQL-injection-pipeline](https://kitploit.com/en/tools/github/mlily2024/final-project-sql-injection-pipeline) - [ ] [LR-WebPKI](https://kitploit.com/en/tools/github/nserser/lr-webpki) - [ ] [T-MAP](https://kitploit.com/en/tools/github/pwnhyo/t-map) - [ ] [CatSniffer-Firmware](https://kitploit.com/en/tools/github/electroniccats/catsniffer-firmware) - [ ] [GreenSection](https://kitploit.com/en/tools/github/msnightmare/greensection) - [ ] [EmailXpose — Updated!](https://kitploit.com/en/posts/gitlab-roxanne_ardary-emailxpose-38091ee723cd10c821088f35742a73dc13a45e528f55595f358d9856a9d683fd) - [ ] [envsec v1.0.0-rc.2](https://kitploit.com/en/posts/github-davidnussio-envsec-v100-rc2) - [ ] [sshconfig-lint v0.5.0](https://kitploit.com/en/posts/github-noah4ever-sshconfig-lint-v050) - [ ] [Dependency Scanning v2.1.1](https://kitploit.com/en/posts/gitlab-components-dependency-scanning-211) - [ ] [Root-My-Device v0.0.7](https://kitploit.com/en/posts/github-witaqua-tools-root-my-device-v007) - [ ] [wrongsecrets-binaries v0.3.0](https://kitploit.com/en/posts/github-owasp-wrongsecrets-binaries-v030) - [ ] [safer-dependencies v0.6.1](https://kitploit.com/en/posts/github-robert-auger-safer-dependencies-v061) - [ ] [muad-dib v2.12.0](https://kitploit.com/en/posts/github-dnszlsk-muad-dib-v2120) - [ ] [laravel-threat-detection v1.7.2](https://kitploit.com/en/posts/github-jay123anta-laravel-threat-detection-v172) - Tor Project blog - [ ] [New Release: Tails 7.12](https://blog.torproject.org/new-release-tails-7_12/) - Security Affairs - [ ] [Pegasus and NoviSpy Used Against Serbian Protesters](https://securityaffairs.com/198377/intelligence/pegasus-and-novispy-used-against-serbian-protesters.html) - [ ] [Cisco Fixed Critical RCE in Nexus 9000 Series Switches](https://securityaffairs.com/198366/security/cisco-fixed-critical-rce-in-nexus-9000-series-switches.html) - [ ] [412,000 The Town 2025 Ticket Buyers’ Data Hits the Dark Web](https://securityaffairs.com/198354/data-breach/412000-the-town-2025-ticket-buyers-data-hits-the-dark-web.html) - [ ] [Chaotic Eclipse Releases Crowdstrike Falcon ZeroDay FalconFlank](https://securityaffairs.com/198342/hacking/chaotic-eclipse-releases-crowdstrike-falcon-zeroday-falconflank.html) - [ ] [2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators](https://securityaffairs.com/198332/intelligence/2000-leaked-documents-reveal-how-russia-turns-engineering-students-into-gru-cyber-operators.html) - www.theregister.com - Articles - [ ] [OpenAI commits $1B in AI credits to frontline cyber defenders](https://www.theregister.com/security/2026/09/04/openai-commits-1b-in-ai-credits-to-frontline-cyber-defenders/5294382) - [ ] [Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC](https://www.theregister.com/security/2026/09/03/prolific-microsoft-0-day-hunter-drops-crowdstrike-falcon-exploit-poc/5294318) - [ ] [Drowning in CVEs and thirsty for answers? Try CTEM](https://www.theregister.com/security/2026/09/03/sponsored-drowning-in-cves-and-thirsty-for-answers-try-ctem/5293906) - [ ] [Cybercrooks trawl Fishbrain to net password hashes](https://www.theregister.com/cyber-crime/2026/09/03/cybercrooks-trawl-fishbrain-to-net-password-hashes/5294158) - [ ] [UK's Online Safety Act has made 'absolutely no difference,' kids say](https://www.theregister.com/security/2026/09/03/uks-online-safety-act-has-made-absolutely-no-difference-kids-say/5293893) - [ ] [Terminated employee cost company hundreds of thousands of dollars because nobody revoked access](https://www.theregister.com/security/2026/09/03/terminated-employee-cost-company-hundreds-of-thousands-of-dollars-because-nobody-revoked-access/5292763) - [ ] [To keep the AI hacking genie bottled up, try one-way networks](https://www.theregister.com/ai-and-ml/2026/09/03/to-keep-the-ai-hacking-genie-bottled-up-try-one-way-networks/5294121) - The Hacker News - [ ] [ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories](https://thehackernews.com/2026/09/threatsday-ceo-phishing-kits-5k-dropbox.html) - [ ] [Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root](https://thehackernews.com/2026/09/critical-cisco-nexus-9000-flaw-lets.html) - [ ] [BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory](https://thehackernews.com/2026/09/brazetsu-malware-turns-compromised.html) - [ ] [Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data](https://thehackernews.com/2026/09/thomson-reuters-court-software-breach.html) - [ ] [US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries](https://thehackernews.com/2026/09/us-becomes-top-target-in-rmm-phishing.html) - [ ] [Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks](https://thehackernews.com/2026/09/attackers-turn-trusted-nodejs-runtime.html) - [ ] [Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means](https://thehackernews.com/2026/09/shai-huluds-reach-just-grew-to-469.html) - [ ] [Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone](https://thehackernews.com/2026/09/pegasus-zero-click-spyware-exploit.html) - [ ] [Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon](https://thehackernews.com/2026/09/researcher-releases-falconflank-poc.html) - [ ] [CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners](https://thehackernews.com/2026/09/cisa-adds-seven-exploited-flaws-as.html) - Deeplinks - [ ] [Court Rules Against Citizen Journalists in DMCA Takedown Case—EFF Will Appeal](https://www.eff.org/deeplinks/2026/09/court-rules-against-citizen-journalists-dmca-takedown-case-eff-will-appeal) - Security Weekly Podcast Network (Audio) - [ ] [Linux Threat Hunting - PSW #942](http://sites.libsyn.com/18678/linux-threat-hunting-psw-942)
每日安全资讯(2026-09-04)