# 每日安全资讯(2026-09-10) - SecWiki News - [ ] [SecWiki News 2026-09-09 Review](http://www.sec-wiki.com/?2026-09-09) - Private Feed for M09Ic - [ ] [bolucat released 202609092247 at bolucat/Archive](https://github.com/bolucat/Archive/releases/tag/202609092247) - [ ] [strands-agents released python/v1.55.1 at strands-agents/harness-sdk](https://github.com/strands-agents/harness-sdk/releases/tag/python/v1.55.1) - [ ] [anthropics released v2.1.267 at anthropics/claude-code](https://github.com/anthropics/claude-code/releases/tag/v2.1.267) - [ ] [timwhitez contributed to timwhitez/timwhitez](https://github.com/timwhitez/timwhitez/pull/1) - [ ] [esrrhs starred codeplea/genann](https://github.com/codeplea/genann) - [ ] [itm4n released 2026.09.09-1 at itm4n/PrivescCheck](https://github.com/itm4n/PrivescCheck/releases/tag/2026.09.09-1) - [ ] [chainreactors released v1.0.0-rc3 at chainreactors/cyber-harness](https://github.com/chainreactors/cyber-harness/releases/tag/v1.0.0-rc3) - [ ] [esrrhs contributed to esrrhs/fakecc](https://github.com/esrrhs/fakecc/pull/69) - [ ] [niudaii starred exelban/stats](https://github.com/exelban/stats) - [ ] [safedv starred outflanknl/ntlmrain](https://github.com/outflanknl/ntlmrain) - [ ] [mgeeky starred bytewreck/DumpGuard](https://github.com/bytewreck/DumpGuard) - [ ] [WAY29 starred shner-elmo/TradingView-Screener](https://github.com/shner-elmo/TradingView-Screener) - [ ] [4ra1n starred jar-analyzer/jsd](https://github.com/jar-analyzer/jsd) - [ ] [timwhitez contributed to timwhitez/neocloud-sec](https://github.com/timwhitez/neocloud-sec/pull/11) - [ ] [pydantic released v2.42.0 at pydantic/pydantic-ai](https://github.com/pydantic/pydantic-ai/releases/tag/v2.42.0) - Doonsec's feed - [ ] [内卷时代,客户为什么把系统安全交给了慧等保?](https://mp.weixin.qq.com/s/Agk-SfuHBO9q-d1Ld3yxFQ) - [ ] [面向即时通讯工具的输入伪装与检测绕过:银狐类生态中 Hook 组件的技术迭代](https://mp.weixin.qq.com/s/2uOSVkHA2prvIGaUaSdRrg) - [ ] [【漏洞通告】微软9月多个安全漏洞](https://mp.weixin.qq.com/s/p-HXXlx6SY2XkVH3R5hLqA) - [ ] [同样被黑进域控,为什么有的企业毫无察觉,有的却能快速反应?](https://mp.weixin.qq.com/s/JqYkw7Ceo2fXuRSPFmHtXg) - [ ] [国家安全部警示:军事禁区不可越界;欧盟《网络弹性法案》漏洞披露相关义务将于2026年9月11日正式生效 | 牛览](https://mp.weixin.qq.com/s/upYdPZxCA9Kd4cZ-Lu1UqA) - [ ] [下周一正式开始|16家SRC邀您加入双11安全保卫战](https://mp.weixin.qq.com/s/tAPpwkZbaikjLsf4mMffeQ) - [ ] [微信零点击蠕虫病毒通过来电入侵iPhone和安卓手机账户](https://mp.weixin.qq.com/s/42R20xVngjT-O-Jx_G6Now) - [ ] [【展会邀请】共赴2026年国家网络安全宣传周,思而听期待与您相见](https://mp.weixin.qq.com/s/io3kfZ31zfw4yZ9-4VURvg) - [ ] [【驻场专栏】9月第二周|全国长期驻场岗位汇总](https://mp.weixin.qq.com/s/dF6PyWryWFNzo1pJnyk0Hg) - [ ] [亮点抢先看|中孚信息邀您共赴2026国家网络安全宣传周!](https://mp.weixin.qq.com/s/nQaxjSBOwkADm0QJeUQBXQ) - [ ] [中国信通院可信AI供应链工作一览](https://mp.weixin.qq.com/s/pgL2g-PIdnH_NOyew-MsAg) - [ ] [中储棉花信息中心社会招聘网络安全工程师](https://mp.weixin.qq.com/s/WOyw957DM0YPuYpivPgGnA) - [ ] [千人大帮会|100T资源终身独享|CISP/PTE考证底价|18年网安大佬带队](https://mp.weixin.qq.com/s/Kz7H25C_hup3WsRlXvpCQw) - [ ] [山东广电信通网络运营有限公司面向社会公开招聘](https://mp.weixin.qq.com/s/K3CgxjGnqjZMzq9ksq01rw) - [ ] [SAP 提醒注意满分 “OVERPASS” 内核漏洞](https://mp.weixin.qq.com/s/XMloH8KZLXuf0gD56mVapg) - [ ] [美国两党议员推动《停止失控AI法案》:智能体安全走向身份、行为与责任管理](https://mp.weixin.qq.com/s/PuwO8EFdJ0s5_iakVVcGEA) - [ ] [服务器被入侵 6阶段处置表 + 3条合规红线](https://mp.weixin.qq.com/s/PUlKx6q_nk7TKKYY27f8ug) - [ ] [ChatGPT或Claude官方套餐IOS渠道直充服务](https://mp.weixin.qq.com/s/f9uRJH7S0oZ7o6cpLPkTfQ) - [ ] [基于大模型的网络安全渗透测试系统 -- AegisAI(神盾)](https://mp.weixin.qq.com/s/wMHJt71d1VuQ91lk4DdGtg) - [ ] [WeWorm:首个通过iOS和Android微信通话传播的零点击蠕虫病毒](https://mp.weixin.qq.com/s/DnF5RKpwiP6QM16VXN7N2Q) - [ ] [漏洞通告|DELL Cloud Disaster Recovery操作系统命令注入漏洞(CVE-2026-71171)](https://mp.weixin.qq.com/s/oEuv8YWvwNmf2JozL5SiXw) - Tenable Blog - [ ] [Introducing the CyberAgents Exchange AI Inspector: Rigorous review for community-built AI](https://www.tenable.com/blog/ai-agent-security-openai-tenable-cyberagents-exchange-inspector) - 先知安全技术社区 - [ ] [从 APP 异常请求发现外围服务器文件上传漏洞:我是如何30分钟发现高危的](https://xz.aliyun.com/news/92800) - Paper - 知道创宇404实验室 - [ ] [POLYFLOW:一种用于静态跨语言信息流分析的神经符号框架](https://paper.seebug.org/3518) - Microsoft Security Blog - [ ] [Threat matrix: Mapping threats across cloud web applications](https://www.microsoft.com/en-us/security/blog/2026/09/09/threat-matrix-mapping-threats-across-cloud-web-applications/) - [ ] [Passkey-themed social engineering leads to identity and cloud compromise](https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/) - Recent Commits to cve:main - [ ] [Update Wed Sep 9 12:12:28 UTC 2026](https://github.com/trickest/cve/commit/d41ac80dcbe410807deb0ba50854bfff6ae6beaf) - Horizon3 - [ ] [Patch Tuesday to Pentest Wednesday: How an Equipment Rental Company Is Turning Continuous Testing Into Continuous Exposure Management](https://horizon3.ai/intelligence/blogs/pentest-wednesday-continuous-exposure-management/) - GuidePoint Security - [ ] [CRA Reporting Goes Live September 11: What Manufacturers Must Have in Place When the Clock Starts](https://www.guidepointsecurity.com/blog/eu-cra-reporting-requirements/) - Kitploit - [ ] [Empire v7.0.2](https://kitploit.com/en/posts/github-bc-security-empire-v702) - [ ] [BlueBox](https://kitploit.com/en/tools/github/svdwi/bluebox) - [ ] [unimap v0.8.0](https://kitploit.com/en/posts/github-edu4rdshl-unimap-080) - [ ] [iLEAPP v2026.3.3](https://kitploit.com/en/posts/github-abrignoni-ileapp-v202633) - [ ] [securityonion v3.3.0-20260908](https://kitploit.com/en/posts/github-security-onion-solutions-securityonion-330-20260908) - [ ] [patchright v1.63.0](https://kitploit.com/en/posts/github-kaliiiiiiiiii-vinyzu-patchright-v1630) - [ ] [irflow-timeline v1.0.13](https://kitploit.com/en/posts/github-r3nzsec-irflow-timeline-v1013) - [ ] [detection-rules dev-v2.2.0](https://kitploit.com/en/posts/github-elastic-detection-rules-dev-v220) - [ ] [worldmonitor v2.10.0](https://kitploit.com/en/posts/github-koala73-worldmonitor-v2100) - [ ] [firmware-analysis-toolkit v2.0.0-alpha.1](https://kitploit.com/en/posts/github-attify-firmware-analysis-toolkit-v200-alpha1) - [ ] [mobileAudit v3.2.0](https://kitploit.com/en/posts/github-mpast-mobileaudit-320) - [ ] [Starkiller v4.0.3](https://kitploit.com/en/posts/github-bc-security-starkiller-v403) - [ ] [SSHintel](https://kitploit.com/en/tools/github/sonitbahl/sshintel) - [ ] [droidground v1.0.15](https://kitploit.com/en/posts/github-secforce-droidground-v1015) - [ ] [GitMiner3](https://kitploit.com/en/tools/github/unkl4b/gitminer3) - [ ] [aethel_core](https://kitploit.com/en/tools/github/lokinpendawa/aethel_core) - [ ] [halo-record v0.2.42](https://kitploit.com/en/posts/github-bkuan001-halo-record-v0242) - [ ] [adPEAS v2.5.0](https://kitploit.com/en/posts/github-61106960-adpeas-v250) - [ ] [Umbra v1.1.0](https://kitploit.com/en/posts/github-openconstruct-umbra-110) - [ ] [CyberStrikeAI v1.7.18](https://kitploit.com/en/posts/github-ed1s0nz-cyberstrikeai-v1718) - [ ] [afrog v3.5.7](https://kitploit.com/en/posts/github-zan8in-afrog-v357) - [ ] [nerva v1.69.6](https://kitploit.com/en/posts/github-praetorian-inc-nerva-v1696) - [ ] [renode v1.17.0](https://kitploit.com/en/posts/github-renode-renode-v1170) - [ ] [KasperMeow](https://kitploit.com/en/tools/github/mein-0/kaspermeow) - [ ] [ctf-tracker](https://kitploit.com/en/tools/github/xxdndxx/ctf-tracker) - [ ] [tlsx v1.4.0](https://kitploit.com/en/posts/github-projectdiscovery-tlsx-v140) - [ ] [cli v1.1307.1](https://kitploit.com/en/posts/github-snyk-cli-v113071) - [ ] [firezone headless-client-1.5.12](https://kitploit.com/en/posts/github-firezone-firezone-headless-client-1512) - The Trail of Bits Blog - [ ] [A “proof” of Fermat’s Last Theorem that fits the margin](https://blog.trailofbits.com/2026/09/09/a-proof-of-fermats-last-theorem-that-fits-the-margin/) - Malwarebytes - [ ] [More than 100,000 fake stores are out to steal your card details](https://www.malwarebytes.com/blog/scams/2026/09/more-than-100000-fake-stores-are-out-to-steal-your-card-details) - [ ] [Microsoft fixes record 964 flaws, including 2 exploited zero-days](https://www.malwarebytes.com/blog/news/2026/09/microsoft-fixes-record-964-flaws-including-2-exploited-zero-days) - [ ] [The push to stop algorithms controlling social media feeds has begun](https://www.malwarebytes.com/blog/news/2026/09/the-push-to-stop-algorithms-controlling-social-media-feeds-has-begun) - Reverse Engineering - [ ] [Reverse engineered NFS Most Wanted, Underground 2 and Carbon (also MAD) servers.](https://www.reddit.com/r/ReverseEngineering/comments/1wbyoq0/reverse_engineered_nfs_most_wanted_underground_2/) - [ ] [Piracy CDN renamed .ts video segments to .woff2 to abuse extension-based CDN caching, a byte-level analysis](https://www.reddit.com/r/ReverseEngineering/comments/1wbqfll/piracy_cdn_renamed_ts_video_segments_to_woff2_to/) - [ ] [Reverse engineering the 2008 LogiCola, a logic drill program](https://www.reddit.com/r/ReverseEngineering/comments/1wbzlrt/reverse_engineering_the_2008_logicola_a_logic/) - [ ] [Update: Attack Shark X6 Linux driver — from DPI-only to button remap, lighting, and emergency reset (Go + Wails)](https://www.reddit.com/r/ReverseEngineering/comments/1wbqh36/update_attack_shark_x6_linux_driver_from_dpionly/) - Dancho Danchev's Blog - Mind Streams of Information Security Knowledge - [ ] [ExploitShield - Embedded malware detection for your legitimate domain - Wordpress Plugin](https://ddanchev.blogspot.com/2026/09/exploitshield-embedded-malware.html) - 奇客Solidot–传递最新科技情报 - [ ] [屏幕使用时长导致学生阅读得分大幅下降](https://www.solidot.org/story?sid=85333) - [ ] [Google 将“降级”欧洲搜索服务](https://www.solidot.org/story?sid=85332) - [ ] [《星际迷航》上映 60 周年](https://www.solidot.org/story?sid=85331) - [ ] [NVIDIA 创业企业展示半程活动10月苏州举行,30家科创企业路演+投资人对接](https://www.solidot.org/story?sid=85330) - [ ] [美国政府指控中国公司系统性蒸馏美国 AI 模型](https://www.solidot.org/story?sid=85329) - [ ] [Fermi Explorer Mission 项目考虑 2029 年向半人马座α星发射探测器](https://www.solidot.org/story?sid=85328) - [ ] [Valve 要求澳大利亚玩家用信用卡验证年龄以访问 R18+ 游戏](https://www.solidot.org/story?sid=85327) - [ ] [《南方公园》改名为《南方美国》](https://www.solidot.org/story?sid=85326) - [ ] [孕期记忆力下降背后的生物学机制](https://www.solidot.org/story?sid=85325) - HackerNews - [ ] [与越南相关的大型 APIS 数据库暴露护照和航班数据](http://0.0.0.0:8080/post/64661) - [ ] [ShinyHunters 黑客声称入侵佛罗里达州 "DAVID" DMV 数据库](http://0.0.0.0:8080/post/64660) - [ ] [DoppelCart 欺诈网络利用 119,000 个假商店窃取信用卡](http://0.0.0.0:8080/post/64659) - [ ] [ChatGPT 漏洞:植入的提示可将受害者的 Gmail 数据发送到另一个账户](http://0.0.0.0:8080/post/64658) - [ ] [Slim Spider 从巴西金融机构窃取加密货币托管机密](http://0.0.0.0:8080/post/64657) - [ ] [黑客归还通过 Elements 漏洞获取的 3,400 枚比特币,仍持有价值 4,700 万美元的 BTC](http://0.0.0.0:8080/post/64656) - 雷神众测 - [ ] [雷神众测漏洞周报2026.8.31-2026.9.6](https://mp.weixin.qq.com/s?__biz=MzI0NzEwOTM0MA==&mid=2652503943&idx=1&sn=3bfc0e21784c37e22ee2890c0b12147c) - 威努特安全网络 - [ ] [IDC认证!威努特实力入选中国安全运营智能体主要厂商](https://mp.weixin.qq.com/s?__biz=MzAwNTgyODU3NQ==&mid=2651143902&idx=1&sn=c79c29c13c8b6be499a34cc36e78b641) - Shostack & Friends Blog - [ ] [Appsec roundup - July + August 2026](https://shostack.org/blog/appsec-roundup-july-aug-2026/) - [ ] [Save on Threat Modeling 2nd Edition](https://shostack.org/blog/barnes-and-noble-preorder-sale/) - 代码卫士 - [ ] [微软9月补丁星期二值得关注的漏洞](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247527069&idx=1&sn=69bc83e52667b561185aa958c9a2bce3) - [ ] [SAP 提醒注意满分 “OVERPASS” 内核漏洞](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247527069&idx=2&sn=38d5fe63d1405b5a8feb85fe1103a558) - 黑鸟 - [ ] [美国预测情报目标小组悄然分析民众金融数据,无嫌疑亦可拦停搜查](https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451188538&idx=1&sn=4c47afe1595d269f6349f934e34934c2) - 懒人在思考 - [ ] [走过路过欢迎了解我们[爱心]](https://mp.weixin.qq.com/s?__biz=MzA3NTEzMTUwNA==&mid=2651082054&idx=1&sn=15124292dd985f5332b4c4dc06cfbe9e) - vivo千镜 - [ ] [【vivo 助力】 XCon2026:从3.7万静态信号到可执行PoC,共探AI时代的漏洞研究新范式](https://mp.weixin.qq.com/s?__biz=MzI0Njg4NzE3MQ==&mid=2247492398&idx=1&sn=82df99975a267abf1245b0b18121f834) - 安全内参 - [ ] [超2.2亿条航班乘客数据公网暴露,涉及大量中国用户](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516557&idx=1&sn=61a21f370d443d760f3cd9fe07eb8287) - [ ] [聚焦人工智能驱动的网络对抗演练:美国网络司令部举行第十三届“网络旗帜”演习](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516557&idx=2&sn=813a87d7481cdbac290c9eca6f679f80) - 奇安信 CERT - [ ] [微软9月补丁日多个产品安全漏洞风险通告:2个在野利用、28个紧急漏洞](https://mp.weixin.qq.com/s?__biz=MzU5NDgxODU1MQ==&mid=2247507507&idx=1&sn=be74c21bfe84fa67670136c6d3db05ca) - 安全分析与研究 - [ ] [Agent安全工程实现](https://mp.weixin.qq.com/s?__biz=MzA4ODEyODA3MQ==&mid=2247497123&idx=1&sn=23068a4cce3941229963545eacb9aa4b) - 看雪学苑 - [ ] [App 抽取壳的内存脱壳与请求签名逆向](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458619713&idx=1&sn=ec61b7e3afb64384c71693657e53d117) - [ ] [零点击入侵!新型微信蠕虫可盗号扩散,无需接打电话(已被修复)](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458619713&idx=2&sn=7a7240ec6af36256a20a5cee3b1c99a4) - [ ] [基于CVD的云手机定制与风控分析](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458619713&idx=3&sn=f5721c9f5bbd0fcc1531debb1326f6c0) - 数世咨询 - [ ] [微软 9 月补丁日:974 个漏洞创历史新高,但真正值得 CISO 失眠的只有一件事](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247543862&idx=1&sn=6f4941138dc45bca40c5117828a2f20a) - 天御攻防实验室 - [ ] [中央情报局黑客协助美军抓获委内瑞拉领导人](https://mp.weixin.qq.com/s?__biz=MzU0MzgyMzM2Nw==&mid=2247487164&idx=1&sn=e9efea765ab408f682acec849f1aa903) - 中国信息安全 - [ ] [中国工程院院士吴世忠:大模型系统安全的观察与思考](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664266423&idx=1&sn=8bbaa4a82aeee0ddb4aa86fb994c4471) - [ ] [专家解读 | 薄兆一:加速数字化绿色化协同转型发展 迈向融合创新与深度协同新阶段](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664266423&idx=2&sn=1724caa9e0f96110b7f064cd1456f623) - [ ] [关注 | 美方指控DeepSeek、月之暗面等中企,外交部驳斥!](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664266423&idx=3&sn=6b7f0e479bd777ff42938a77e0465e57) - [ ] [2026外滩大会探营:当AI开始干活,一种新经济正在形成](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664266423&idx=4&sn=ee7bec03e99d4126e0f1e6e77407ea07) - [ ] [法治 | 精准打击涉网络黑恶犯罪](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664266423&idx=5&sn=922c9a1dfc4ab48c2e0876278f8cb980) - [ ] [评论 | 强化合规意识守护用户信息安全](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664266423&idx=6&sn=7c6120eeaa1ee74f1ea7e8c7b4a73029) - 微步在线 - [ ] [AI时代,到底需要什么样的SOC?](https://mp.weixin.qq.com/s?__biz=MzI5NjA0NjI5MQ==&mid=2650187974&idx=1&sn=3950736f3ed49ae156c54728a9d91286) - 安全圈 - [ ] [【安全圈】微信曝零点击高危漏洞:响铃无需接听即遭账号接管](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078793&idx=1&sn=f80af8438a745cdfbd5130695d5253ef) - [ ] [【安全圈】微软9月修复974个漏洞:2个在野0day且含蠕虫风险](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078793&idx=2&sn=be3e3ee2eb33f6ed04d9beeb4b8c7858) - [ ] [【安全圈】英特尔发布24.70.0驱动:修补无线内核提权与断连Bug](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078793&idx=3&sn=9d1f9578fc5a4c382d6ff5a6e7d9209f) - 唯品会安全应急响应中心 - [ ] [关于 VSRC 例行维护的通知](https://mp.weixin.qq.com/s?__biz=MzI5ODE0ODA5MQ==&mid=2652281770&idx=1&sn=f681152374004258d33b37ab2f288be0) - 腾讯安全威胁情报中心 - [ ] [面向即时通讯工具的输入伪装与检测绕过:银狐类生态中 Hook 组件的技术迭代](https://mp.weixin.qq.com/s?__biz=MzI5ODk3OTM1Ng==&mid=2247512101&idx=1&sn=e20fd6231e7a625687b853e30b0220a0) - 字节跳动安全中心 - [ ] [ByteSRC发布《测试红线10条》及违规白帽处罚公告](https://mp.weixin.qq.com/s?__biz=MzUzMzcyMDYzMw==&mid=2247496377&idx=1&sn=657d9a329e2dd6cdb7eadfd615067497) - 百度安全应急响应中心 - [ ] [秋光揽月,礼伴团圆|BSRC中秋限定礼盒如约而至](https://mp.weixin.qq.com/s?__biz=MzA4ODc0MTIwMw==&mid=2652545140&idx=1&sn=cbd77613cb1712001fd3cfe6d94efd28) - 极客公园 - [ ] [助听器躺赚三十年暴利,被 AI 打破了](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653113357&idx=1&sn=11ed1eae88415169f7a9d26b1e320886) - [ ] [Token 之后,谁来组织 AI 计算?Arm 寻找下一代计算的答案](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653113357&idx=2&sn=13802eb9cfbc95edc7cfe459cbeb0c73) - [ ] [折叠屏 iPhone 初期产量受限,每日仅数百部;环比增长 379%,腾讯 HY4 登顶全球大模型调用榜;特斯拉时隔 19 个月再降价|极客早知道](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653113328&idx=1&sn=ac749acd11d37d2c322be912845dc053) - 奇安信威胁情报中心 - [ ] [沙箱里的“共享剪贴板”:ChatGPT跨账号数据泄露通道深度复盘](https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247520299&idx=1&sn=47acee104fc76c8de22432d50f9fc567) - 复旦白泽战队 - [ ] [白泽迎新 | 2026级新生图鉴已送达,请查收!](https://mp.weixin.qq.com/s?__biz=MzU4NzUxOTI0OQ==&mid=2247499747&idx=1&sn=36864c98a2d78386a491b8bc06368f93) - 深信服千里目安全技术中心 - [ ] [微软补丁日安全通告|9月份](https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&mid=2247526112&idx=1&sn=53055e40919a1533ab081899b8887bcf) - [ ] [网络安全信息与动态周报2026年第36期(8月31日-9月6日)](https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&mid=2247526112&idx=2&sn=d44047aca9465f0b02fcbed34228d507) - 云鼎实验室 - [ ] [SharePoint 双漏洞再曝风险!8 月必修漏洞清单请查收](https://mp.weixin.qq.com/s?__biz=MzU3ODAyMjg4OQ==&mid=2247497944&idx=1&sn=4671de1456bd8fde91a4a84e7e08fee0) - 火绒安全 - [ ] [火绒个人版6.0功能升级|网络防护、程序管控、应用加固多项能力优化](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247537284&idx=1&sn=f438c224d2991c96f95d9598ae9b02f5) - [ ] [2026-09微软漏洞通告](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247537284&idx=2&sn=b6bd57ec48fb5fd9011970b07a6faaea) - [ ] [火绒小问答--「个人版」近期top问题解答](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247537284&idx=3&sn=3050c92a77feef1f19c812bf5e8d0e4e) - [ ] [诚邀渠道合作伙伴共启新征程](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247537284&idx=4&sn=f7480ad7f450da26f6fd7d7a418b6999) - 字节跳动技术团队 - [ ] [TLS 全链路可观测体系:破解 LLM 应用黑盒,实现会话透明复盘](https://mp.weixin.qq.com/s?__biz=MzI1MzYzMjE0MQ==&mid=2247522374&idx=1&sn=33c26eab48cc34d99c8e25423a715489) - [ ] [火山引擎 AI MediaKit X 懂车帝,探索汽车内容智能创作新方式](https://mp.weixin.qq.com/s?__biz=MzI1MzYzMjE0MQ==&mid=2247522374&idx=2&sn=eb309174c350b07a904cdc890f771b43) - 情报分析师 - [ ] [社交媒体炫富照背后如何拼出一个隐形商业帝国](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650569566&idx=1&sn=1a8c68951917c5b80e23f590af9d7c64) - [ ] [鲍曼莫斯科国立技术大学第四系泄密事件暴露俄军网络作战人才培养链路,其与俄军总参谋部情报总局相关单位联系值得关注](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650569566&idx=2&sn=9e4880415d68119fcf2387ec35894469) - 阿里安全响应中心 - [ ] [下周一正式开始|16家SRC邀您加入双11安全保卫战](https://mp.weixin.qq.com/s?__biz=MzIxMjEwNTc4NA==&mid=2652999114&idx=1&sn=0a59099207bb3c7241a1a15dc2ff699a) - 国家互联网应急中心CNCERT - [ ] [网络安全信息与动态周报2026年第36期(8月31日-9月6日)](https://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw==&mid=2247502143&idx=1&sn=4360ee04b339d5546f3981bad338886f) - Qualys Security Blog - [ ] [The Models That Found 10,000 Zero-Days Broke Into Three Companies Using Weak Passwords](https://blog.qualys.com/category/qualys-insights) - 安全419 - [ ] [安全419|一周国际网安资讯:零日漏洞密集利用 AI攻击进入10小时时代](https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&mid=2247554904&idx=1&sn=1417c8b531309ef544b60fbc46d7302f) - ICT Security Magazine - [ ] [Il caso di Autistici/Inventati: la sovranità digitale alla prova della politica internazionale](https://www.ictsecuritymagazine.com/notizie/sovranita-digitale-autistici-inventati/) - 丁爸 情报分析师的工具箱 - [ ] [【开源报告】AI驱动的电诈-全球与东南亚现状、能力演进与未来趋势研判](https://mp.weixin.qq.com/s?__biz=MzI2MTE0NTE3Mw==&mid=2651157428&idx=1&sn=11b69d0fe2d6421b22e2063c78328dbf) - [ ] [【下周开会】聚焦AI实战破局!FCTS 2026 议题正式发布,报名进入最后倒计时](https://mp.weixin.qq.com/s?__biz=MzI2MTE0NTE3Mw==&mid=2651157428&idx=2&sn=038c10d8a8fb116e836ea9810e458dc5) - LockBoxx - [ ] [Book Review: "The Scaling Era"](http://blog.lockboxx.org/2026/09/book-review-scaling-era.html) - SANS Internet Storm Center, InfoCON: green - [ ] [Scans for Proxmox Servers, (Wed, Sep 9th)](https://isc.sans.edu/diary/rss/33324) - [ ] [ISC Stormcast For Wednesday, September 9th, 2026 https://isc.sans.edu/podcastdetail/10086, (Wed, Sep 9th)](https://isc.sans.edu/diary/rss/33322) - Schneier on Security - [ ] [Driver’s License Data for Sale](https://www.schneier.com/blog/archives/2026/09/drivers-license-data-for-sale.html) - [ ] [Claude Fable Solves a Historical Cipher](https://www.schneier.com/blog/archives/2026/09/claude-fable-solves-a-historical-cipher.html) - Over Security - [ ] [CISA head says agency must change quickly to prevent the 'worst that could happen'](https://therecord.media/cisa-hiring-nick-andersen-warning) - [ ] [AdaptHealth confirms 4.1 million people exposed in July cyberattack](https://www.bleepingcomputer.com/news/security/adapthealth-confirms-41-million-people-exposed-in-july-cyberattack/) - [ ] [Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks](https://www.bleepingcomputer.com/news/security/cisco-confirms-cve-2026-20079-secure-fmc-flaw-exploited-in-attacks/) - [ ] [Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking](https://www.bleepingcomputer.com/news/security/skullcandy-dime-3-earbuds-expose-users-to-bluetooth-hijacking/) - [ ] [US disrupts Xinbi Guarantee marketplace fueling the cyber scam economy](https://therecord.media/us-disrupts-xinbi-guarantee-marketplace-cybercrime) - [ ] [Grindr settles privacy lawsuit tied to disclosure of users’ HIV statuses for $35 million](https://therecord.media/grindr-settles-privacy-lawsuit-hiv-status-35-million) - [ ] [Electronic health record company says customer data stolen in breach](https://therecord.media/electronic-health-record-company-says-customer-data-stolen-in-breach) - [ ] [Multiple Chinese hacking groups seen using identical Chrome zero-day exploit](https://therecord.media/china-hackers-chrome-browser-zero-day-multiple-groups) - [ ] [US says Chinese firms extracted billions of tokens from frontier AI models](https://www.bleepingcomputer.com/news/security/us-says-chinese-firms-extracted-billions-of-tokens-from-frontier-ai-models/) - [ ] [Active exploitation of Cisco Secure Firewall Management Center vulnerabilities](https://blog.talosintelligence.com/fmc-ongoing-exploitation/) - [ ] [Sistemi legacy e obsolescenza dei PLC: strategie di protezione e mitigazione dei rischi in fabbrica](https://www.cybersecurity360.it/soluzioni-aziendali/sistemi-legacy-e-obsolescenza-dei-plc-strategie-di-protezione-e-mitigazione-dei-rischi-in-fabbrica/) - [ ] [FBI puts its cyber strategy on paper](https://therecord.media/fbi-releases-first-public-cybersecurity-strategy) - [ ] [Veradigm warns of patient data breach after ransomware gang claims attack](https://www.bleepingcomputer.com/news/security/veradigm-discloses-patient-data-breach-after-gentlemen-gang-claims-attack/) - [ ] [The Flashpoint Threat Intelligence Brief: Middle East](https://flashpoint.io/blog/the-flashpoint-threat-intelligence-brief-middle-east/) - [ ] [MFA's Weakest Link: Account Recovery Is the New Attack Path](https://www.bleepingcomputer.com/news/security/mfas-weakest-link-account-recovery-is-the-new-attack-path/) - [ ] [AI, vishing e spionaggio industriale: gli attacchi sono più credibili, veloci e più vicini alla vittima](https://www.cybersecurity360.it/news/ai-vishing-e-spionaggio-industriale-gli-attacchi-sono-piu-credibili-veloci-e-piu-vicini-alla-vittima/) - [ ] [Patch Tuesday settembre 2026: due zero-day già sfruttate e venti bug wormable](https://www.cybersecurity360.it/news/patch-tuesday-settembre-2026-due-zero-day-gia-sfruttate-e-venti-bug-wormable/) - [ ] [Piano ispettivo del Garante privacy: una bussola per tutti, ma servono trasparenza e certezza dei tempi](https://www.cybersecurity360.it/legal/privacy-dati-personali/piano-ispettivo-del-garante-privacy-una-bussola-per-tutti-ma-servono-trasparenza-e-certezza-dei-tempi/) - [ ] [Ukraine prosecutor general steps down amid scam call center bribery probe](https://therecord.media/ukraine-prosecutor-general-scam-center) - [ ] [AI e spionaggio: dov’è il confine e cosa apporta il digitale all’elemento umano](https://www.cybersecurity360.it/cybersecurity-nazionale/ai-e-spionaggio-dove-il-confine-e-cosa-apporta-il-digitale-allelemento-umano/) - [ ] [Avast Premium Security sconta del 60% il piano per 10 dispositivi: protezione completa contro ransomware e deepfake](https://www.cybersecurity360.it/cultura-cyber/avast-premium-security-sconto-60-percento-10-dispositivi/) - [ ] [Proton Drive lancia l’offerta da 1 euro: 200 GB di cloud crittografato per proteggere i dati personali](https://www.cybersecurity360.it/cultura-cyber/proton-drive-offerta-1-euro-cloud-crittografato-protezione-ia/) - [ ] [Over 36,000 exposed Plex servers vulnerable to recent flaws](https://www.bleepingcomputer.com/news/security/over-36-000-plex-servers-unpatched-against-recently-disclosed-flaws/) - [ ] [Il fragile patto di fiducia della cybersecurity](https://www.guerredirete.it/il-fragile-patto-di-fiducia-della-cybersecurity/) - [ ] [Fusion Fireside #20: Collaboration Against Fraud with Dianne Doodnath](https://www.threatfabric.com/blogs/fusion-fireside-20-collaboration-against-fraud-with-dianne-doodnath) - [ ] [ChatGPT Sandbox Flaw Let a Planted Prompt Ship Victim’s Gmail Data to Another Account](https://thecyberexpress.com/chatgpt-sandbox-flaw-leads-to-gmail-leak/) - [ ] [Man gets 15 years for extorting women with AI-generated porn videos](https://www.bleepingcomputer.com/news/security/man-gets-15-years-in-prison-for-cyberstalking-and-sextortion/) - [ ] [15 Minutes Saved Per Alert: How a Lean German Manufacturer Protects 10,000 Endpoints with ANY.RUN](https://any.run/cybersecurity-blog/german-manufacturer-success-story/) - [ ] [L’AI non sfugge all’uomo, si fa più capace. Cosa ci insegna il caso OpenAI-Hugging Face](https://www.cybersecurity360.it/outlook/lai-non-sfugge-alluomo-si-fa-piu-capace-cosa-ci-insegna-il-caso-openai-hugging-face/) - [ ] [New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access](https://www.bleepingcomputer.com/news/security/new-microsoft-defender-shieldcrash-zero-day-grants-system-access/) - [ ] [Vwork: Weaponized Open-source Software as an Addon for Gigabud](https://www.group-ib.com/blog/vwork-app-cloning-gigabud-goldfactory/) - [ ] [Microsoft Patch Tuesday Hits Record 974 CVEs, Two Exploited](https://thecyberexpress.com/patch-tuesday-september-2026/) - [ ] [Google warns of new Chrome zero-day bug exploited in attacks](https://www.bleepingcomputer.com/news/security/google-patches-seventh-chrome-zero-day-exploited-in-attacks-this-year/) - [ ] [Microsoft adds age-awareness APIs that can tell if users are children, teens, or adults](https://www.bleepingcomputer.com/news/microsoft/microsoft-adds-age-awareness-apis-that-can-tell-if-users-are-children-teens-or-adults/) - The Hacker News - [ ] [U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto](https://thehackernews.com/2026/09/us-disrupts-xinbi-guarantee-scam.html) - [ ] [Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week](https://thehackernews.com/2026/09/four-spy-groups-used-same-chrome-and.html) - [ ] [Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA](https://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.html) - [ ] [Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE](https://thehackernews.com/2026/09/webinar-learn-how-to-answer-are-we.html) - [ ] [DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval](https://thehackernews.com/2026/09/deepseek-harness-flaw-let-ai-agents.html) - [ ] [Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets](https://thehackernews.com/2026/09/alby-hub-critical-flaw-could-let.html) - [ ] [U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok](https://thehackernews.com/2026/09/us-agencies-accuse-china-ai-firms-of.html) - [ ] [Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox](https://thehackernews.com/2026/09/chrome-v8-zero-day-exploited-in-wild.html) - [ ] [New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root](https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account.html) - [ ] [F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans](https://thehackernews.com/2026/09/f5-big-ip-apm-malware-injects-php-web.html) - [ ] [Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed](https://thehackernews.com/2026/09/researcher-drops-new-microsoft-defender.html) - [ ] [SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution](https://thehackernews.com/2026/09/sap-patches-cvss-100-kernel-flaw.html) - [ ] [Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days](https://thehackernews.com/2026/09/microsoft-patches-record-974-flaws.html) - [ ] [N-able N-central Pre-Auth RCE Flaw Exploited in the Wild](https://thehackernews.com/2026/09/n-able-n-central-pre-auth-rce-flaw.html) - Deeplinks - [ ] [Cops Play Hide and Seek About Using Spy Tech to Avoid Scrutiny and Bad PR](https://www.eff.org/deeplinks/2026/09/cops-play-hide-and-seek-about-using-spy-tech-avoid-scrutiny-and-bad-pr) - [ ] [Digital Sovereignty: What It Is, What It Could Be](https://www.eff.org/deeplinks/2026/09/digital-sovereignty-what-it-what-it-could-be) - [ ] [2026 EFF Award Winners: Access Now, 7amleh – The Arab Center for the Advancement of Social Media, DeFlock, and New Media Rights](https://www.eff.org/deeplinks/2026/09/2026-eff-award-winners-access-now-7amleh-arab-center-advancement-social-media) - Tor Project blog - [ ] [New Release: Tor Browser 15.0.22](https://blog.torproject.org/new-release-tor-browser-15022/) - [ ] [Tor VPN Beta: What we've learned building our own VPN for Android from scratch](https://blog.torproject.org/tor-vpn-beta/) - www.theregister.com - Articles - [ ] [Anthropic reveals fourth likely crime committed by its AI](https://www.theregister.com/ai-and-ml/2026/09/10/anthropic-reveals-fourth-likely-crime-committed-by-its-ai/5295412) - [ ] [Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits](https://www.theregister.com/research/2026/09/09/novel-blue-moon-kit-targeting-chrome-and-windows-reflects-new-reality-of-ai-driven-exploits/5295399) - [ ] [Serial Microsoft 0-day hunter drops yet another Defender exploit](https://www.theregister.com/security/2026/09/09/serial-microsoft-0-day-hunter-drops-yet-another-defender-exploit/5295335) - [ ] [WeChat worm could pwn a friend before they even answered the call](https://www.theregister.com/security/2026/09/09/wechat-worm-could-pwn-a-friend-before-they-even-answered-the-call/5295234) - [ ] [Microsoft breaks Patch Tuesday record with 974-CVE deluge](https://www.theregister.com/security/2026/09/09/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge/5295160) - TorrentFreak - [ ] [Private Torrent Tracker Lawsuit Takes Bizarre Turn: ‘I’m a Different Matthew Schneider’ (Updated)](https://torrentfreak.com/private-torrent-tracker-lawsuit-takes-bizarre-turn-im-a-different-matthew-schneider/) - Security Affairs - [ ] [US Agencies Warn Chinese AI Firms Are Extracting Advanced AI Models](https://securityaffairs.com/198770/security/us-agencies-warn-chinese-ai-firms-are-extracting-advanced-ai-models.html) - [ ] [Google fixes the seventh actively exploited Chrome zero-day of 2026](https://securityaffairs.com/198757/security/google-fixes-the-seventh-actively-exploited-chrome-zero-day-of-2026.html) - [ ] [PoisonedRefresh: A Fileless Linux Rootkit That Injects PHP Web Shells Into F5 BIG-IP APM Server Memory](https://securityaffairs.com/198746/malware/poisonedrefresh-a-fileless-linux-rootkit-that-injects-php-web-shells-into-f5-big-ip-apm-server-memory.html) - [ ] [Chaotic Eclipse Released ShieldCrash, A PoC For Microsoft Defender Zero-Day](https://securityaffairs.com/198726/security/chaotic-eclipse-released-shieldcrash-a-poc-for-microsoft-defender-zero-day.html) - [ ] [Microsoft’s Biggest Patch Tuesday: 974 CVEs, 2 Zero-Days and 20 Wormable Bugs](https://securityaffairs.com/198705/security/microsofts-biggest-patch-tuesday-974-cves-2-zero-days-and-20-wormable-bugs.html) - Deep Web - [ ] [How do I find out if my data is leaked on the dark web? Any non scam resources?](https://www.reddit.com/r/deepweb/comments/1wb8tyc/how_do_i_find_out_if_my_data_is_leaked_on_the/) - KitPloit - PenTest Tools! - [ ] [Empire v7.0.2](https://kitploit.com/en/posts/github-bc-security-empire-v702) - [ ] [BlueBox](https://kitploit.com/en/tools/github/svdwi/bluebox) - [ ] [unimap v0.8.0](https://kitploit.com/en/posts/github-edu4rdshl-unimap-080) - [ ] [iLEAPP v2026.3.3](https://kitploit.com/en/posts/github-abrignoni-ileapp-v202633) - [ ] [securityonion v3.3.0-20260908](https://kitploit.com/en/posts/github-security-onion-solutions-securityonion-330-20260908) - [ ] [patchright v1.63.0](https://kitploit.com/en/posts/github-kaliiiiiiiiii-vinyzu-patchright-v1630) - [ ] [irflow-timeline v1.0.13](https://kitploit.com/en/posts/github-r3nzsec-irflow-timeline-v1013) - [ ] [detection-rules dev-v2.2.0](https://kitploit.com/en/posts/github-elastic-detection-rules-dev-v220) - [ ] [worldmonitor v2.10.0](https://kitploit.com/en/posts/github-koala73-worldmonitor-v2100) - [ ] [firmware-analysis-toolkit v2.0.0-alpha.1](https://kitploit.com/en/posts/github-attify-firmware-analysis-toolkit-v200-alpha1) - [ ] [mobileAudit v3.2.0](https://kitploit.com/en/posts/github-mpast-mobileaudit-320) - [ ] [Starkiller v4.0.3](https://kitploit.com/en/posts/github-bc-security-starkiller-v403) - [ ] [SSHintel](https://kitploit.com/en/tools/github/sonitbahl/sshintel) - [ ] [droidground v1.0.15](https://kitploit.com/en/posts/github-secforce-droidground-v1015) - [ ] [GitMiner3](https://kitploit.com/en/tools/github/unkl4b/gitminer3) - [ ] [aethel_core](https://kitploit.com/en/tools/github/lokinpendawa/aethel_core) - [ ] [halo-record v0.2.42](https://kitploit.com/en/posts/github-bkuan001-halo-record-v0242) - [ ] [adPEAS v2.5.0](https://kitploit.com/en/posts/github-61106960-adpeas-v250) - [ ] [Umbra v1.1.0](https://kitploit.com/en/posts/github-openconstruct-umbra-110) - [ ] [CyberStrikeAI v1.7.18](https://kitploit.com/en/posts/github-ed1s0nz-cyberstrikeai-v1718) - [ ] [afrog v3.5.7](https://kitploit.com/en/posts/github-zan8in-afrog-v357) - [ ] [nerva v1.69.6](https://kitploit.com/en/posts/github-praetorian-inc-nerva-v1696) - [ ] [renode v1.17.0](https://kitploit.com/en/posts/github-renode-renode-v1170) - [ ] [KasperMeow](https://kitploit.com/en/tools/github/mein-0/kaspermeow) - [ ] [ctf-tracker](https://kitploit.com/en/tools/github/xxdndxx/ctf-tracker) - [ ] [tlsx v1.4.0](https://kitploit.com/en/posts/github-projectdiscovery-tlsx-v140) - [ ] [cli v1.1307.1](https://kitploit.com/en/posts/github-snyk-cli-v113071) - [ ] [firezone headless-client-1.5.12](https://kitploit.com/en/posts/github-firezone-firezone-headless-client-1512) - GRAHAM CLULEY - [ ] [Smashing Security podcast #484: How websites are tracking you with silence](https://grahamcluley.com/smashing-security-podcast-484/) - [ ] [CRPx0 ransomware: what you need to know](https://www.fortra.com/blog/crpx0-ransomware-what-you-need-know) - Security Weekly Podcast Network (Audio) - [ ] [Security Money: The Index Explodes, as the History of AI Teaches Us About Investments - John Willis - BSW #464](http://sites.libsyn.com/18678/security-money-the-index-explodes-as-the-history-of-ai-teaches-us-about-investments-john-willis-bsw-464)
每日安全资讯(2026-09-10)