# 每日安全资讯(2026-09-11) - SecWiki News - [ ] [SecWiki News 2026-09-10 Review](http://www.sec-wiki.com/?2026-09-10) - Doonsec's feed - [ ] [AI供应链安全工程](https://mp.weixin.qq.com/s/6qJlcARd3Y_-yrBaUn9MxQ) - [ ] [大华智慧园区综合管理平台queryById接口存在敏感信息泄露 xa0附POC](https://mp.weixin.qq.com/s/Nsip3mfrydYirZEZ5kFs2g) - [ ] [管防火墙的系统,被三个团伙排队打穿:Cisco FMC CVE-2026-20079 全链拆解](https://mp.weixin.qq.com/s/uX9rXrbtnCmwdr_hFeRA6g) - [ ] [实测白帽的一站式AI渗透测试平台](https://mp.weixin.qq.com/s/D7tJf-dZcIGs0d4acEKK4w) - [ ] [敬逝去的少年芳华-给第四十二个教师节](https://mp.weixin.qq.com/s/v-fw-X7UIn20Xb-HFgCXmA) - [ ] [难怪计算机同学都说大学上课是最没用的...(家长还不清醒过来吗)](https://mp.weixin.qq.com/s/wfrH769Y4Q9VGDT_jeOxxg) - [ ] [一份 AI 写的二进制摆上逆向台,分析师可能什么都看不出来](https://mp.weixin.qq.com/s/gnrMPM3W_SufVsCGkI6_pw) - [ ] [获客从来不是人干的事](https://mp.weixin.qq.com/s/edhA5C2r6ZWtKnSmXV6QhA) - [ ] [创信资讯丨聚焦医疗数据合规,创信华通连续四年参加卫生健康网络安全专业技术人员继续教育培训活动](https://mp.weixin.qq.com/s/PJvSOvV8xj4GcXcJ8O3X2A) - [ ] [每日一学:若依(Ruoyi)框架,你必须知道的四个通用漏洞](https://mp.weixin.qq.com/s/azoyt805nHgrJXyV0qKY7g) - [ ] [映作Ai创作新平台来袭](https://mp.weixin.qq.com/s/6Cb0VueHI0KAjqw5DuiUow) - [ ] [改了一个目录参数,我上传的图片替换了别人网站首页:2026年OSS直传签名越权实录](https://mp.weixin.qq.com/s/pKKhOeunwErfQnTWdz23VA) - [ ] [智改数转 AI兴工 2026全球工业互联网大会在沈阳开幕](https://mp.weixin.qq.com/s/rejN9ENuXz1zq_ilisJeUQ) - [ ] [【AI安全】EAL-Bench发现:Agent会把记错的权限当成真实授权](https://mp.weixin.qq.com/s/Yn3G_YuAp7hulnA26k_ZSw) - [ ] [工联安全大讲堂第四十期即将开讲](https://mp.weixin.qq.com/s/dSFeyBHxLJz8OMH_CFT3rA) - [ ] [惊!“0交互”被入侵现实案例:语音没接微信就被接管&打印机还没工作就被控制](https://mp.weixin.qq.com/s/_AUDe9ijGEDYJjo4zOWgOQ) - [ ] [Anthropic 正在建造一套预测性监控系统](https://mp.weixin.qq.com/s/_TKJgwj5cBMAgxE6f2drOg) - [ ] [威胁情报 | 威胁行为者声称攻破某制造企业阿里云托管环境,核心业务数据被挂网兜售](https://mp.weixin.qq.com/s/TStMXfyZB3LTbDPEU5HAMg) - [ ] [AI 助手还在问你是否信任项目,程序怎么已经跑起来了?](https://mp.weixin.qq.com/s/YlDuWzXaOQS410utaJyJ-w) - [ ] [第1章,网络安全快速入门(网络安全新手到高手)](https://mp.weixin.qq.com/s/imwkAVJ89uC0DVgAvKOHTQ) - [ ] [【黑产链分析】域名过期一年后,武汉某职业院校公众号成了色情站的免费流量入口](https://mp.weixin.qq.com/s/Nc_pdNB-a3pa-Nfxa6OFUg) - [ ] [2026网安周 | 深信服邀您看直播、答竞赛,提升AI安全意识,赢取丰厚好礼!](https://mp.weixin.qq.com/s/8DSsT8Zx4fO5MDasiPcOcQ) - [ ] [斗象AISCC上线“Agent安全评测”;新增Tool call检测](https://mp.weixin.qq.com/s/0Q-COASd_g6G3OYO-qrKGQ) - [ ] [首批+最高等级,斗象AI安全计算云平台通过中国信通院大模型安全围栏能力评测](https://mp.weixin.qq.com/s/dNb3iEcVkGmyjsbKRD3X7Q) - [ ] [美国情报机构承认美国对中国公司进行间谍活动](https://mp.weixin.qq.com/s/s1Ypbr81c5xa0YofFL42Yw) - [ ] [美国联邦调查局首次公开网络战略,要让黑客的攻击生意更难维持](https://mp.weixin.qq.com/s/uq631oCsGJ1RloeRlGgL5w) - [ ] [感恩教师节 | 师者如光,微以致远](https://mp.weixin.qq.com/s/t-jWkU1cOjFSslIDtIAkPw) - [ ] [《网络空间安全科学学报》祝老师们节日快乐!](https://mp.weixin.qq.com/s/n2wrwVYlwd42zHtXVxct3A) - [ ] [测试那些没人愿意测试的接口,总能发现点什么](https://mp.weixin.qq.com/s/WpQ6zc5yoZq9DEqsWvjAqQ) - [ ] [载誉赋能|江苏骏安安全检测入选江苏省网络安全服务资源池三大类目,筑牢数字安全防线](https://mp.weixin.qq.com/s/uwjUECG-DV8xt9nfRHRHGA) - [ ] [面向智能体网络的去中心化身份体系综述|网信办数据与技术保障中心](https://mp.weixin.qq.com/s/KolGK3iwg9Ei9_hfctYv2Q) - [ ] [【漏洞通告】Apache-Impala存在代码注入漏洞(CVE-2026-65181)](https://mp.weixin.qq.com/s/nvgl_PFA6qhgfpkjePCIkQ) - [ ] [【漏洞通告】FireBox存在权限提升漏洞(CVE-2026-76801)](https://mp.weixin.qq.com/s/mHtAoHdXTuLERDLZYTHjEA) - [ ] [【漏洞通告】Next-Cart迁移插件认证绕过漏洞(CVE-2026-76009)](https://mp.weixin.qq.com/s/10jOf3NSJEmJVg40kvcKEg) - [ ] [【漏洞通告】cjose JWE全零密钥漏洞(CVE-2026-53939)](https://mp.weixin.qq.com/s/Z3Z1R7hV47S_hZYnKmZkoQ) - [ ] [分享的图片、视频、链接](https://mp.weixin.qq.com/s/i34VQDsZXhQD4D_6cgWKsA) - [ ] [【安全更新】微软9月安全更新多个产品高危漏洞通告](https://mp.weixin.qq.com/s/yYFG4CjwEZWAgnKLogUxVw) - [ ] [参编邀请 | 全国首部“AI生成内容合规”标准,欢迎加入编制组!](https://mp.weixin.qq.com/s/wfK5sb1EJNNMDGBYU9iguQ) - [ ] [卫星什么时候能拍?不用等厂商反馈,一句话查询卫星过境情况](https://mp.weixin.qq.com/s/c4xemnUztyNJMeEKybdTsw) - [ ] [iPhone 8 Plus越狱终极指南:A11芯片全版本方案与避坑指南](https://mp.weixin.qq.com/s/l9BUo0JBdGZZlEDiB2p1tA) - [ ] [三款新iPhone 终于发布了,但真的值得买吗?](https://mp.weixin.qq.com/s/lNHN4IUBqYVzM7rdVn1YgA) - [ ] [慧等保-保障业务安全合规前行](https://mp.weixin.qq.com/s/DnI_e9-yJ5x50x62ujDl3Q) - [ ] [倒计时已开始:9月11日起,卖到欧盟的每一款产品都背着\"24小时报告\"义务,安全负责人这周必须做完的几件事](https://mp.weixin.qq.com/s/Wghz7XM_C2y_y-U2rf8z0A) - [ ] [谷歌欧洲搜索大规模整改:监管合规带来平台生态与信息访问格局变化;FBI 发布首份公开网络安全战略,扩大网络攻击“主动干扰”行动| 牛览](https://mp.weixin.qq.com/s/4upqYOwG68WEq47-J9Ow-w) - [ ] [净网专项行动 | 编造“往鲜花饼里吐痰”谣言者已被依法行拘](https://mp.weixin.qq.com/s/UMhShyqvTqytJUVg2RMWaA) - [ ] [[更新]主打一个听劝,znaide1.0.3源码+Releases已push](https://mp.weixin.qq.com/s/2NohgE89GC43IXecYxF14A) - [ ] [一条命令 让别人访问你本地项目](https://mp.weixin.qq.com/s/3PyXAsiCgKCM-jutY0phwg) - [ ] [某省护网一次特殊的SQL注入-论当盲注不能堆叠注入而且布尔不生效如何跑数据](https://mp.weixin.qq.com/s/ciTilSNPR4usSYHn1_oTZQ) - [ ] [9月社区投稿活动 | 漏洞挖掘/AI渗透/面试经验/简历编写](https://mp.weixin.qq.com/s/y8H8XC-Ioujeglphw3oNJQ) - [ ] [当AI Agent开始自主渗透,你的安全防线还扛得住吗?](https://mp.weixin.qq.com/s/ygZhEDOQQZ-f7P97DlWzrA) - [ ] [iPhone Duo来了,腾讯 Kuikly 助 App 从容适配](https://mp.weixin.qq.com/s/pp6GO54L2wVjrcoPe5uiCQ) - [ ] [疑似HW攻击队白加白样本分析:伪装DOCX诱饵背后的CS后门](https://mp.weixin.qq.com/s/-TC7C52sMRY-GC0OvOD0eQ) - [ ] [无人战争迈向电力时代:中国的产业优势与美国的战略焦虑](https://mp.weixin.qq.com/s/JKGr9PaXj4WvuQ5y_-CoEA) - [ ] [中国易评估:基于《易经》哲学的道法术器势评估理论体系重构](https://mp.weixin.qq.com/s/GA2z1u0qwJ63QcmClz0HuA) - [ ] [知远防务论坛 |“日本防空反导作战”桌面推演邀请](https://mp.weixin.qq.com/s/Xz9sl-1Y73obeSiVTNmwCQ) - [ ] [“台湾地区关键能源基础设施韧性”研讨会议程](https://mp.weixin.qq.com/s/7u3Bu36sjTI1dbx_5u_egQ) - [ ] [LoopX:长时Agent管控利器](https://mp.weixin.qq.com/s/FbP9ZHv_spgVCJ7J_hlNHw) - [ ] [重磅APT预警!黎巴嫩Dark Caracal(黑山猫)卷土重来:GoCaracal木马登场,以太坊智能合约充当“不死C2备份”](https://mp.weixin.qq.com/s/VSYBmGkoGsyW_sCU4sMJIA) - [ ] [教师节 | 师者如光 至高至远](https://mp.weixin.qq.com/s/kyeQXX-JInXk42vKGrVppg) - [ ] [大数据技术专家是如何练成的:大数据助手 Agent Team 实践](https://mp.weixin.qq.com/s/f9RyPFGWpXRUtH6kFdZvUA) - [ ] [9月8日 威胁情报IOC分享](https://mp.weixin.qq.com/s/eMSN1oKEJUczQOzNn11jOQ) - [ ] [诚邀渠道合作伙伴共启新征程](https://mp.weixin.qq.com/s/0g1Ob85xJj5slWdi1hKXzw) - [ ] [钓鱼邮件应急响应 邮件头5分钟判真假](https://mp.weixin.qq.com/s/WVkPV2PZ3r9UIyMjdVVfmg) - [ ] [甲方运维的等保自查清单 先跑这7个高危项,再迎评](https://mp.weixin.qq.com/s/UmSb6MJ1d6CnV4SFaTvBFg) - [ ] [第75篇 AI全栈 · 静态分析工具Joern原理分析及0Day漏洞挖掘_](https://mp.weixin.qq.com/s/N6QOcUIrJ-skWzL4G_XZVg) - [ ] [三尺讲台育桃李,安全路上共相伴!](https://mp.weixin.qq.com/s/VY7OL5haGb_b54H3ozir1Q) - [ ] [深信服aStor统一存储全面升级,打造最适合AI时代的数据底座](https://mp.weixin.qq.com/s/aocuPHf3ZU6VR46fcQKRUQ) - [ ] [紧急安全预警|ArangoDB曝两枚严重漏洞,未认证攻击者可通过漏洞链实现Root级RCE](https://mp.weixin.qq.com/s/R4xjjcw1JpbAfMgnLWPmXg) - [ ] [开源项目偷key 活不起就去死?](https://mp.weixin.qq.com/s/-yAKYDA_G9ubgjNPWOSF4Q) - [ ] [普通用户注册即可投毒!某高校虚拟仿真平台爆出存储 XSS 漏洞](https://mp.weixin.qq.com/s/pksvtje37mzLwReiLHbwzw) - [ ] [教师节|《网络与信息安全学报》编辑部恭祝您节日快乐!](https://mp.weixin.qq.com/s/YlwvJ_mSoUx5LnoHwEAYPA) - Tenable Blog - [ ] [The agentic harness for Tenable Hexa AI: How Tenable prevents AI agents from going off the rails](https://www.tenable.com/blog/how-agentic-harness-works-tenable-hexa-ai) - 先知安全技术社区 - [ ] [《针对初学者的虚拟机逃逸实践:一次完整的挂载逃逸排错过程》](https://xz.aliyun.com/news/92810) - [ ] [Web Cache Deception:URL 规范化错位下的变体验证](https://xz.aliyun.com/news/92808) - [ ] [LangFlow任意 npm/PyPI 包代码执行漏洞](https://xz.aliyun.com/news/92807) - [ ] [谁在偷偷调用大模型?内网 LLM API 流量的识别、检测与绕过实测](https://xz.aliyun.com/news/92806) - [ ] [从一个辅助 API 看资源边界:CVE-2026-71486(vLLM)](https://xz.aliyun.com/news/92805) - Microsoft Security Blog - [ ] [Protecting organizations from AI-assisted executive impersonation and invoice fraud](https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/) - [ ] [Detect and disrupt AI-themed attacks with Microsoft Defender](https://www.microsoft.com/en-us/security/blog/2026/09/10/detect-and-disrupt-ai-themed-attacks-with-microsoft-defender/) - 安全客-有思想的安全新媒体 - [ ] [22万条最私密的照片和病历,就从一个API接口流了出去](https://www.anquanke.com/post/id/316093) - Recent Commits to cve:main - [ ] [Update Thu Sep 10 12:13:23 UTC 2026](https://github.com/trickest/cve/commit/776f16dcfaed66e2d7ff15a3279fdf209c26c921) - Zdziarski - [ ] [AI Can’t Kill Us All Without Humans To Help](https://www.zdziarski.com/blog/?p=13970) - Private Feed for M09Ic - [ ] [bolucat released 202609102242 at bolucat/Archive](https://github.com/bolucat/Archive/releases/tag/202609102242) - [ ] [anthropics released v2.1.268 at anthropics/claude-code](https://github.com/anthropics/claude-code/releases/tag/v2.1.268) - [ ] [timwhitez contributed to timwhitez/agent-sdk-golang](https://github.com/timwhitez/agent-sdk-golang/pull/138) - [ ] [esrrhs contributed to esrrhs/fakelua](https://github.com/esrrhs/fakelua/pull/402) - [ ] [esrrhs starred codeplea/tinyexpr](https://github.com/codeplea/tinyexpr) - [ ] [esrrhs contributed to esrrhs/fakecc](https://github.com/esrrhs/fakecc/pull/73) - [ ] [ZeddYu starred MG1937/ASC](https://github.com/MG1937/ASC) - [ ] [liamg contributed to infracost/go-proto](https://github.com/infracost/go-proto/pull/97) - [ ] [rabbitmask starred MG1937/ASC](https://github.com/MG1937/ASC) - [ ] [gh0stkey starred MG1937/ASC](https://github.com/MG1937/ASC) - [ ] [safedv starred bytewreck/DumpGuard](https://github.com/bytewreck/DumpGuard) - [ ] [timwhitez starred petergyang/no-ai-slop](https://github.com/petergyang/no-ai-slop) - [ ] [esrrhs starred CppCXY/EmmyLuaCodeStyle](https://github.com/CppCXY/EmmyLuaCodeStyle) - Kitploit - [ ] [tmux v3.8-rc](https://kitploit.com/en/posts/github-tmux-tmux-38-rc) - [ ] [auth v2.197.0](https://kitploit.com/en/posts/github-supabase-auth-v21970) - [ ] [ecapture v2.6.0](https://kitploit.com/en/posts/github-gojue-ecapture-v260) - [ ] [cve-lite-cli v1.34.0](https://kitploit.com/en/posts/github-owasp-cve-lite-cli-v1340) - [ ] [scilla v1.3.4](https://kitploit.com/en/posts/github-edoardottt-scilla-v134) - [ ] [brutus v1.15.0](https://kitploit.com/en/posts/github-praetorian-inc-brutus-v1150) - [ ] [pomerium v0.33.3](https://kitploit.com/en/posts/github-pomerium-pomerium-v0333) - [ ] [serverless sf-core@4.42.0](https://kitploit.com/en/posts/github-serverless-serverless-sf-core4420) - [ ] [garak v0.17.0](https://kitploit.com/en/posts/github-nvidia-garak-v0170) - [ ] [falco v0.45.0-rc1](https://kitploit.com/en/posts/github-falcosecurity-falco-0450-rc1) - [ ] [openssl openssl-4.1.0-alpha1](https://kitploit.com/en/posts/github-openssl-openssl-openssl-410-alpha1) - [ ] [how_to_become_a_malware_analyst](https://kitploit.com/en/tools/github/pinksawtooth/how_to_become_a_malware_analyst) - [ ] [TATS](https://kitploit.com/en/tools/github/icemoonhsv/tats) - [ ] [inspector v2.6.0](https://kitploit.com/en/posts/github-modelcontextprotocol-inspector-260) - [ ] [geiger](https://kitploit.com/en/tools/github/atomburstofficial/geiger) - [ ] [Packet-Sniffer v6.0.0](https://kitploit.com/en/posts/github-eonraider-packet-sniffer-v600) - [ ] [pd-agent v0.2.1](https://kitploit.com/en/posts/github-projectdiscovery-pd-agent-v021) - [ ] [hermes-decomp v0.2.3](https://kitploit.com/en/posts/github-symbioticsec-hermes-decomp-v023) - [ ] [oss-oopssec-store v2.20.0](https://kitploit.com/en/posts/github-koadt-oss-oopssec-store-v2200) - [ ] [uac v3.4.0](https://kitploit.com/en/posts/github-tclahr-uac-v340) - [ ] [jadx-magic-strings v1.0.3-dev](https://kitploit.com/en/posts/github-0rshemesh-jadx-magic-strings-v103-dev) - [ ] [kyverno v1.19.1-rc.1](https://kitploit.com/en/posts/github-kyverno-kyverno-v1191-rc1) - [ ] [server v1.0.1](https://kitploit.com/en/posts/github-hashtopolis-server-v101) - [ ] [aws-security-assessment-solution v3.0.0](https://kitploit.com/en/posts/github-awslabs-aws-security-assessment-solution-v300) - [ ] [PCAPdroid v2.0.1](https://kitploit.com/en/posts/github-emanuele-f-pcapdroid-v201) - [ ] [threatest v1.5.0](https://kitploit.com/en/posts/github-datadog-threatest-v150) - [ ] [sherlock v0.16.2](https://kitploit.com/en/posts/github-sherlock-project-sherlock-v0162) - [ ] [ESP32Marauder v1.16.0](https://kitploit.com/en/posts/github-justcallmekoko-esp32marauder-v1160) - [ ] [redcell](https://kitploit.com/en/tools/github/martian56/redcell) - [ ] [openshield](https://kitploit.com/en/tools/github/owasp/openshield) - [ ] [pii-shield v2.2.3](https://kitploit.com/en/posts/github-pii-shield-pii-shield-v223) - Toooold - [ ] [The Phishing Email Was Actually From Google, but Should I Trust It?](https://toooold.com/2026/09/10/fake_google_call.html) - GuidePoint Security - [ ] [Agentic AI Security: Key Findings from New IDC Research on the Identity Control Plane](https://www.guidepointsecurity.com/blog/agentic-ai-security-idc-research-findings/) - Malware-Traffic-Analysis.net - Blog Entries - [ ] [2026-09-08: XWorm infection](https://www.malware-traffic-analysis.net/2026/09/08/index.html) - [ ] [2026-09-10: Atomic macOS (AMOS) Stealer infection](https://www.malware-traffic-analysis.net/2026/09/10/index.html) - rtl-sdr.com - [ ] [GNU Radio World: Browser-Based GNU Radio Flowgraphs](https://www.rtl-sdr.com/gnu-radio-world-browser-based-gnu-radio-flowgraphs/) - [ ] [GridDown Secure Messenger: Using an SX1262 LoRa Radio as a Drone Scanner and Secure Messenger](https://www.rtl-sdr.com/griddown-secure-messenger-using-an-sx1262-lora-radio-as-a-drone-scanner-and-secure-messenger/) - [ ] [IC-SDR: A New Multimode SDR Software for Windows Written in Go](https://www.rtl-sdr.com/ic-sdr-a-new-multimode-sdr-software-for-windows-written-in-go/) - Malwarebytes - [ ] [BlueMoon exploit kit turns Chrome and Windows flaws into attacks](https://www.malwarebytes.com/blog/bugs/2026/09/bluemoon-exploit-kit-turns-chrome-and-windows-flaws-into-attacks) - [ ] [Will AI kill us all within the next decade?](https://www.malwarebytes.com/blog/ai/2026/09/will-ai-kill-us-all-within-the-next-decade) - [ ] [Update Chrome now to protect against an actively exploited vulnerability](https://www.malwarebytes.com/blog/bugs/2026/09/update-chrome-now-to-protect-against-an-actively-exploited-vulnerability) - [ ] [Copyright scammers get Instagram accounts suspended and demand payment](https://www.malwarebytes.com/blog/scams/2026/09/copyright-scammers-get-instagram-accounts-suspended-and-demand-payment) - HackerNews - [ ] [Veradigm 在勒索团伙声称发动攻击后警告患者数据泄露](http://0.0.0.0:8080/post/64667) - [ ] [信息窃取器日志暴露可重放的 AI 令牌,可绕过 MFA](http://0.0.0.0:8080/post/64666) - [ ] [Trezor 警告用户注意电子邮件服务商遭入侵及网络钓鱼攻击](http://0.0.0.0:8080/post/64665) - [ ] [Cisco 确认 Secure FMC 漏洞 CVE-2026-20079 已被在野利用](http://0.0.0.0:8080/post/64664) - [ ] [AdaptHealth 确认 7 月网络攻击导致 410 万人数据暴露](http://0.0.0.0:8080/post/64663) - [ ] [Skullcandy Dime 3 耳机使用户面临蓝牙劫持风险](http://0.0.0.0:8080/post/64662) - text/plain - [ ] [Simple Browser Security Improvements](https://textslashplain.com/2026/09/10/simple-browser-security-improvements/) - 奇客Solidot–传递最新科技情报 - [ ] [LG 强烈否认其监视电视用户](https://www.solidot.org/story?sid=85341) - [ ] [育碧准备在 Steam 上取消安装 Ubisoft Connect 客户端的要求](https://www.solidot.org/story?sid=85340) - [ ] [OpenAI 声称解决了 Navier-Stokes 问题,但引发了利用未发布成果的争议](https://www.solidot.org/story?sid=85339) - [ ] [微软九月例行更新修复近千个 Bug](https://www.solidot.org/story?sid=85338) - [ ] [Google 向司机推荐更长的行驶路线以缓解拥堵](https://www.solidot.org/story?sid=85337) - [ ] [2026 年拉斯克奖宣布](https://www.solidot.org/story?sid=85336) - [ ] [苹果推出折叠屏手机 iPhone Duo](https://www.solidot.org/story?sid=85335) - [ ] [小岛秀夫与索尼终止合作,改为与微软合作](https://www.solidot.org/story?sid=85334) - vivo千镜 - [ ] [【vivo 助力】扬帆安全沙龙·2026·上海站:聚焦海外AI标识监管,共筑可信AI出海新未来](https://mp.weixin.qq.com/s?__biz=MzI0Njg4NzE3MQ==&mid=2247492407&idx=1&sn=a1fb8e4e9bf39dfa9ba1aeaace223ee8) - 威努特安全网络 - [ ] [当水厂越来越“智慧”,如何守住城市供水安全底线?](https://mp.weixin.qq.com/s?__biz=MzAwNTgyODU3NQ==&mid=2651143959&idx=1&sn=7c733953f7628aebfd56910dbe33004c) - 黑鸟 - [ ] [震网Stuxnet蠕虫病毒重构源码公开](https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451188559&idx=1&sn=8c947d1088a5dd699cd60d0fbefc5d6b) - 安全客 - [ ] [22万条最私密的照片和病历,就从一个API接口流了出去](https://mp.weixin.qq.com/s?__biz=MzA5ODA0NDE2MA==&mid=2649790466&idx=1&sn=8d1be72b1af7a1c1228aa0340836e66c) - 雷神众测 - [ ] [雷神众测 AI / AI Agent 辅助安全测试功能上线啦!](https://mp.weixin.qq.com/s?__biz=MzI0NzEwOTM0MA==&mid=2652503963&idx=1&sn=151e59defb2e6085c164411c2eec7759) - 我的安全视界观 - [ ] [我的读书笔记:输出大于输入,就这么点事](https://mp.weixin.qq.com/s?__biz=MzI3Njk2OTIzOQ==&mid=2247488032&idx=1&sn=d5d1214a7964008afd166594435752a0) - 安全内参 - [ ] [泄露用户敏感数据,企业投入数千万元赔偿和安全升级](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516565&idx=1&sn=2917868fa57710340f3cbe917df4e583) - [ ] [韩国医美平台用户敏感数据泄露,近5000名中国人受影响](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516565&idx=2&sn=471213df695db64969e0cfdd7f7bb4e7) - 代码卫士 - [ ] [PAN-OS 缓冲溢出漏洞可导致以root 身份执行任意代码](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247527085&idx=1&sn=c3cc7ceb0784271a331d96ddf2c12ced) - [ ] [cPanel 新漏洞可导致单个托管账户接管整个服务器,影响所有版本](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247527085&idx=2&sn=401518b5ad719760f10f3a256a2c352a) - 暗影安全 - [ ] [微信移动端接管账号漏洞,一场无公开exp和时间的赛跑,在护网期间,究竟能翻出多大的浪花](https://mp.weixin.qq.com/s?__biz=MzI2MzA3OTgxOA==&mid=2657165803&idx=1&sn=84a39b8c3a1713fdde9ccd9ebd3c93a8) - 安全学术圈 - [ ] [安全学术圈 | 投稿须知](https://mp.weixin.qq.com/s?__biz=MzU5MTM5MTQ2MA==&mid=2247495898&idx=1&sn=9419ba5f2f67dc7409a8c1429766fc33) - 安全分析与研究 - [ ] [AI供应链安全工程](https://mp.weixin.qq.com/s?__biz=MzA4ODEyODA3MQ==&mid=2247497127&idx=1&sn=b446db6d7e32caba5ef38a79ae4d6f8e) - Shostack & Friends Blog - [ ] [Diagram Style (Threat Model Thursday)](https://shostack.org/blog/diagram-style-threat-model-thursday/) - 看雪学苑 - [ ] [VT调试器原理揭秘--DebugPort转移与重建调试体系](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458619748&idx=1&sn=3da8fd74ca09ea5d3b1a7e5df02207ca) - [ ] [9月11日13:30 | 人工智能赋能网络安全创新推进会(现场多轮抽奖)](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458619748&idx=2&sn=6efd160280fa4ca392eb9540a3ba96c7) - [ ] [Anthropic披露第四起AI模型入侵真实系统事件!Claude Opus 4.6闯祸](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458619748&idx=3&sn=14ecc6169822b3abd74bb3d645bcc424) - 信息安全国家工程研究中心 - [ ] [教师节 | 致敬引路人](https://mp.weixin.qq.com/s?__biz=MzU5OTQ0NzY3Ng==&mid=2247504915&idx=1&sn=b562f1d17ce78b2a07aaab4d9483d8e7) - 吾爱破解论坛 - [ ] [老师,您才是全论坛最该加精的,被岁月置顶,被一届届学生收藏,加精理由:受用终身](https://mp.weixin.qq.com/s?__biz=MjM5Mjc3MDM2Mw==&mid=2651144711&idx=1&sn=a19acf13ce94874d2bbde2f218a373dc) - 安全圈 - [ ] [【安全圈】豆包又崩了!!!](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078814&idx=1&sn=4bb4de8f89d37090d16af701bb3151a7) - [ ] [【安全圈】JumpServer曝高危越权漏洞:普通用户发请求可窃管理员AK](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078814&idx=2&sn=377865fd1deaae1b0ff7ae47552a4242) - [ ] [【安全圈】Anthropic曝第4起AI越界入侵:Claude逃逸沙盒向PyPI传毒](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078814&idx=3&sn=8d6cac1a983f4a3a96104bc92128c640) - 中国信息安全 - [ ] [网聚智汇 | 健全网络安全治理体系,推动构建网络空间命运共同体](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664266524&idx=1&sn=b58b9d54c942de39678269df01d99d17) - [ ] [商务部新闻发言人:美方以打击蒸馏为名,行产业垄断之实](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664266524&idx=2&sn=e989eb19c3651c51b4cfca6e7b6eaf06) - [ ] [关注 | 国际打击电信网络诈骗联盟正式成立](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664266524&idx=3&sn=8ffb5a31ae29619eb119d96e995bca61) - [ ] [发布 | 北京市人民政府印发《北京市“十五五”时期数字经济发展规划》(附全文)](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664266524&idx=4&sn=30ce0b088c7d250747dfab5d4114c047) - [ ] [聚焦 | 共创AI新经济,2026 Inclusion·外滩大会在沪开幕](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664266524&idx=5&sn=49592e01cb7ec1bfe31bc854a7cfbc77) - [ ] [行业 | 两项智能体安全团体标准启动,共筑智能体规模化应用安全基线](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664266524&idx=6&sn=cbe30310092c7c080e663577685564d8) - [ ] [关注 | 8月全国网络举报1797.2万件](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664266524&idx=7&sn=0bad5a214d91d5c5e8f0552c1dac60ce) - DataCon大数据安全分析竞赛 - [ ] [粉笔书日月,讲台育芳华](https://mp.weixin.qq.com/s?__biz=MzU5Njg1NzMyNw==&mid=2247489669&idx=1&sn=78818c7bbc373c8dc146d78eeec83f9c) - 安全牛 - [ ] [倒计时已开始:9月11日起,卖到欧盟的每一款产品都背着"24小时报告"义务,安全负责人这周必须做完的几件事](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142671&idx=1&sn=afa0d790a4a0df29797885810805b9f4) - [ ] [谷歌欧洲搜索大规模整改:监管合规带来平台生态与信息访问格局变化;FBI 发布首份公开网络安全战略,扩大网络攻击“主动干扰”行动| 牛览](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142671&idx=2&sn=18e558c456d1ac97f626c00d08363bce) - 奇安信威胁情报中心 - [ ] [26秒攻陷11家机构:一场由数百个AI智能体编排的PaperCut全球攻击行动](https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247520315&idx=1&sn=a3fdb128f4f336bd12525bb09f93e54a) - 微步在线 - [ ] [180分钟到8分钟,Flocks实现自动化漏洞排查](https://mp.weixin.qq.com/s?__biz=MzI5NjA0NjI5MQ==&mid=2650188010&idx=1&sn=38693f4ea44ef183d677b831aa06436f) - 网络空间安全科学学报 - [ ] [《网络空间安全科学学报》祝老师们节日快乐!](https://mp.weixin.qq.com/s?__biz=MzI0NjU2NDMwNQ==&mid=2247508508&idx=1&sn=062fdfc24ed8ecf614919499c3f108f2) - 慢雾科技 - [ ] [美国 OFAC、DOJ 联手打击新币担保,超 5200 万美元加密资产遭限制](https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&mid=2247506017&idx=1&sn=ceb559a5052a5aa0a97b7a4212689cc3) - 奇安信 CERT - [ ] [【在野利用】Google Chrome V8 越界写入漏洞(CVE-2026-87491)安全风险通告](https://mp.weixin.qq.com/s?__biz=MzU5NDgxODU1MQ==&mid=2247507534&idx=1&sn=1afaf71f958bac541e8fa7a000f514b9) - 极客公园 - [ ] [微信,悄悄迈出 AI 社交的第一步](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653113419&idx=1&sn=0e2052b064355158114f67b33ad7ceff) - [ ] [对话极壳创始人孙宽:年出货 3 万台后,外骨骼「全班第一」的成长和焦虑](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653113413&idx=1&sn=7e70fa7daec174494af90db0a749a2cc) - 火绒安全 - [ ] [教师节 | 师者如光 至高至远](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247537302&idx=1&sn=021e042f23a86544bc111e131004a065) - [ ] [诚邀渠道合作伙伴共启新征程](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247537302&idx=2&sn=a7628364aab98947e91b3730869280ee) - 谛听ditecting - [ ] [谛听 工控安全月报 | 8月](https://mp.weixin.qq.com/s?__biz=MzU3MzQyOTU0Nw==&mid=2247503396&idx=1&sn=95aa4bbbb3329778ee14f786fe85bba3) - 情报分析师 - [ ] [如何调查越南军方网络部门ECQ集团与以色列专家合作](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650569582&idx=1&sn=f5db786eb5c32ab62e6c18221e76d74a) - [ ] [美国以防范网络安全“后门”为由宣布国家紧急状态并限制采购外国产电力系统设备,相关供应链安全审查及涉我设备排除风险需关注](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650569582&idx=2&sn=a563730463f78b2c63c748a9400ca698) - 国家互联网应急中心CNCERT - [ ] [CNCERT在2026年国家网络安全宣传周活动全预告](https://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw==&mid=2247502155&idx=1&sn=aaeba4da312718b6f2c9fcba837247f0) - OnionSec - [ ] [我的杏仁核,好像真的有一点修复了](https://mp.weixin.qq.com/s?__biz=MzUyMTUwMzI3Ng==&mid=2247485986&idx=1&sn=9734975664468c00e0ce87f49e11708b) - 绿盟科技CERT - [ ] [【安全更新】微软9月安全更新多个产品高危漏洞通告](https://mp.weixin.qq.com/s?__biz=Mzk0MjE3ODkxNg==&mid=2247493642&idx=1&sn=8c4d96b64dbfc41b8d4da5187cac3093) - 墨菲安全 - [ ] [CRA报告义务9月11日起适用:出海企业能在24小时内说清漏洞影响吗?](https://mp.weixin.qq.com/s?__biz=MzkwOTM0MjI5NQ==&mid=2247488702&idx=1&sn=07a3e203780bfdb05bd0b247a74776b8) - 美团技术团队 - [ ] [《Agent 评测白皮书》系列01:Agent 评测全览](https://mp.weixin.qq.com/s?__biz=MjM5NjQ5MTI5OA==&mid=2651783390&idx=1&sn=0cddf09e2bb8edf61ba5e712ca63ddfd) - [ ] [报名 | 清华大学-美团学术论坛:物理世界中的AI及大模型](https://mp.weixin.qq.com/s?__biz=MjM5NjQ5MTI5OA==&mid=2651783390&idx=2&sn=721393f0c6f2e4d45507866de02c89f8) - Qualys Security Blog - [ ] [What Is ISPM? How It Differs from IAM, PAM, IGA, and IDaaS](https://blog.qualys.com/category/product-tech) - 青藤智库 - [ ] [5000字分享:Mythos/GPT-5对企业安全架构影响思考](https://mp.weixin.qq.com/s?__biz=MzUyOTkwNTQ5Mg==&mid=2247489493&idx=1&sn=11114327ee44dc01fdbfae7f1094825b) - TrustedSec - [ ] [So… You Found AWS Access Keys (Part 1)](https://trustedsec.com/blog/so-you-found-aws-access-keys-part-1) - Over Security - [ ] [New Android malware encrypts files, steals data, and harasses victims](https://www.bleepingcomputer.com/news/security/new-android-malware-encrypts-files-steals-data-and-harasses-victims/) - [ ] [Treasury urges banks to file cyber scam reports, noting nearly $13 billion in losses since 2023](https://therecord.media/treasury-urges-banks-report-cyber-scams) - [ ] [September Windows Server updates break Remote Desktop Services](https://www.bleepingcomputer.com/news/microsoft/september-windows-server-updates-break-remote-desktop-services/) - [ ] [MetaEncryptor Claims Attack on EllisDon: “409 GB of Data Stolen, We Are Still Accessing the Systems”](https://www.suspectfile.com/metaencryptor-claims-attack-on-ellisdon-409-gb-of-data-stolen-we-are-still-accessing-the-systems/) - [ ] [Microsoft Excel KB5002914 update breaks copy and paste for some users](https://www.bleepingcomputer.com/news/microsoft/microsoft-excel-kb5002914-update-breaks-copy-and-paste-for-some-users/) - [ ] [Surfshark VPN says hackers breached internal testing, proxy servers](https://www.bleepingcomputer.com/news/security/surfshark-vpn-says-hackers-breached-internal-testing-proxy-servers/) - [ ] [IDScan confirms breach after hackers offer 153 million driver’s license scans for sale](https://therecord.media/idscan-data-breach-notice-drivers-licenses) - [ ] [Multiple crypto companies warn customers of phishing emails after alleged provider breach](https://therecord.media/trezor-bitbox-cointracking-phishing-crypto-holders) - [ ] [AI Agents Compromised 440 PaperCut Servers, Researchers Say](https://thecyberexpress.com/ai-agents-compromised-440-papercut-servers/) - [ ] [Cyber Command turns to veteran of intelligence agencies for top AI role](https://therecord.media/cyber-command-ai-leader-ronzelle-green) - [ ] [We've got one word for it, and it's usually the wrong one](https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/) - [ ] [AI-powered attack exploited PaperCut flaws to hack 395 organizations](https://www.bleepingcomputer.com/news/security/ai-powered-attack-exploited-papercut-flaws-to-hack-395-organizations/) - [ ] [BforeAI Partners with Food and Ag-ISAC to Advance Predictive Attack Intelligence](https://bfore.ai/news/bforeai-partners-with-food-and-ag-isac-to-advance-predictive-attack-intelligence/) - [ ] [Incidenti AI e alignment: la lezione di Anthropic per la cyber sicurezza](https://www.cybersecurity360.it/news/incidenti-ai-e-alignment-la-lezione-di-anthropic-per-la-cyber-sicurezza/) - [ ] [Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers](https://www.bleepingcomputer.com/news/security/cisco-fmc-flaws-exploited-by-ransomware-gang-state-sponsored-hackers/) - [ ] [Agenti AI fuori dal perimetro: il caso OpenAI riapre il confine tra misalignment e incidente cyber](https://www.cybersecurity360.it/nuove-minacce/agenti-ai-fuori-dal-perimetro-il-caso-openai-riapre-il-confine-tra-misalignment-e-incidente-cyber/) - [ ] [IDScan confirms breach tied to 153 million stolen driver’s licenses](https://www.bleepingcomputer.com/news/security/idscan-confirms-breach-tied-to-153-million-stolen-drivers-licenses/) - [ ] [The Top 4 Threats We Found by Investigating Every Alert for a Quarter](https://www.bleepingcomputer.com/news/security/the-top-4-threats-we-found-by-investigating-every-alert-for-a-quarter/) - [ ] [New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws](https://www.bleepingcomputer.com/news/security/new-bluemoon-kit-exploited-windows-and-chrome-zero-day-flaws/) - [ ] [Russian e-commerce giant Wildberries says DDoS attack delayed payments to sellers](https://therecord.media/russian-e-commerce-giant-wildberries-says-payments-disrupted) - [ ] [Interfacce HMI e continuità di processo: mitigare i rischi sui terminali di linea](https://www.cybersecurity360.it/soluzioni-aziendali/interfacce-hmi-e-continuita-di-processo-mitigare-i-rischi-sui-terminali-di-linea/) - [ ] [UK appoints new commander of National Cyber Force](https://therecord.media/uk-appoints-new-commander-of-national-cyber-force) - [ ] [Cyble Introduces Major Upgrade to its Executive Monitoring Module](https://cyble.com/blog/cyble-major-upgrades-to-executive-monitoring-module/) - [ ] [From Infostealer Log to Marketplace Listing: A Technical Walkthrough of the Credential Theft Pipeline](https://cyble.com/blog/infostealer-malware-credential-theft-pipeline/) - [ ] [Microsoft says September updates fix mouse settings reset issues](https://www.bleepingcomputer.com/news/microsoft/microsoft-resolves-mouse-settings-reset-bug-windows-11-update/) - [ ] [EU’s 24-Hr Vulnerability Reporting Rules Take Effect Friday, a Year Before the Rest of the Cyber Resilience Act](https://thecyberexpress.com/eu-cyber-resilience-act-24-hr-reporting/) - [ ] [it-sa Expo&Congress 2026: a Norimberga la cyber security europea guarda alle nuove sfide](https://www.cybersecurity360.it/cultura-cyber/it-sa-expocongress-2026-a-norimberga-la-cyber-security-europea-guarda-alle-nuove-sfide/) - [ ] [Cyberoo: “L’MDR non basta. Ecco come cambia la cyber security”](https://www.cybersecurity360.it/soluzioni-aziendali/cyberoo-lmdr-non-basta-ecco-come-cambia-la-cyber-security/) - [ ] [ANY.RUN Secures Leader Status in G2’s Malware Analysis Rankings](https://any.run/cybersecurity-blog/g2-leader-fall-2026/) - [ ] [Inside an Indonesian phishing kit factory](https://carlesi.vg/2026/09/10/inside-an-indonesian-phishing-kit/) - [ ] [CISA: WatchGuard RCE flaw now exploited in ransomware attacks](https://www.bleepingcomputer.com/news/security/cisa-watchguard-rce-flaw-now-exploited-in-ransomware-attacks/) - [ ] [Surfshark: pacchetto VPN e Antivirus da 2,49 €/mese, come cambia la protezione degli endpoint illimitati](https://www.cybersecurity360.it/cultura-cyber/surfshark-vpn-antivirus-249-euro-protezione-endpoint-illimitati/) - [ ] [Cyber Resilience Act: cosa cambia dall’11 settembre](https://www.cybersecurity360.it/legal/cyber-resilience-act-cosa-cambia-dall11-settembre/) - [ ] [La classificazione nell’AI ACT: i 4 livelli di rischio](https://www.cybersecurity360.it/legal/la-classificazione-nellai-act-i-4-livelli-di-rischio/) - [ ] [Preinstalled but Not Safe. OnePlus OEM App Session Takeover Vulnerability](https://blog.doyensec.com/2026/09/10/oneplus-session-takeover.html) - [ ] [Microsoft fixes bug that wiped Windows desktop settings](https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-bug-that-wiped-windows-desktop-settings/) - [ ] [OT Security 4.0, il modello A2A Smart City per proteggere le infrastrutture critiche nell’era della convergenza IT/OT](https://www.cybersecurity360.it/soluzioni-aziendali/ot-security-4-0-il-modello-a2a-smart-city-per-proteggere-le-infrastrutture-critiche-nellera-della-convergenza-it-ot/) - [ ] [Trezor warns users of email provider breach, phishing attacks](https://www.bleepingcomputer.com/news/security/trezor-warns-users-of-email-provider-breach-phishing-attacks/) - [ ] [McKesson - 6,404,340 breached accounts](https://haveibeenpwned.com/Breach/McKesson) - Have I Been Pwned latest breaches - [ ] [McKesson - 6,404,340 breached accounts](https://haveibeenpwned.com/Breach/McKesson) - 360威胁情报中心 - [ ] [APT-C-55(Kimsuky)组织利用伪装安装包植入远控木马的攻击链分析](https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247508878&idx=1&sn=d67dbc1305acff320756e665c0c923de) - ICT Security Magazine - [ ] [Tecniche anti-forensics assistite dall’AI: da deepfake e data poisoning ai rischi per l’attribuzione della prova](https://www.ictsecuritymagazine.com/articoli/tecniche-anti-forensics/) - Schneier on Security - [ ] [AIs Compress Exploit Timeline](https://www.schneier.com/blog/archives/2026/09/ais-compress-exploit-timeline.html) - 悬镜安全 - [ ] [无缝平替BlackDuck|悬镜安全代码安全+智能体安全产品中国市场应用率双双第一!](https://mp.weixin.qq.com/s?__biz=MzA3NzE2ODk1Mg==&mid=2647800665&idx=1&sn=97567accee629b5b8ee5552ae068eef9) - SANS Internet Storm Center, InfoCON: green - [ ] [Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th)](https://isc.sans.edu/diary/rss/33326) - [ ] [ISC Stormcast For Thursday, September 10th, 2026 https://isc.sans.edu/podcastdetail/10088, (Thu, Sep 10th)](https://isc.sans.edu/diary/rss/33328) - 丁爸 情报分析师的工具箱 - [ ] [情报搜集的历史脉络:从传统人力情报到现代开源情报](https://mp.weixin.qq.com/s?__biz=MzI2MTE0NTE3Mw==&mid=2651157437&idx=1&sn=0b677c700e338bbda1e23c2dceaecb44) - [ ] [【报名倒计时】第四届全国大学生开源情报数据采集与分析挑战赛](https://mp.weixin.qq.com/s?__biz=MzI2MTE0NTE3Mw==&mid=2651157437&idx=2&sn=71197eaa1d2eb86a2f7ca37520d5228f) - Instapaper: Unread - [ ] [eSIMs The 2026 Answer to the Burner Phone](https://nerdvittles.com/esims-the-2026-answer-to-the-burner-phone/) - [ ] [Before Direct NAND Acquisition Diagnosing an Undetectable Monolithic SD Card](https://paraben.com/before-direct-nand-acquisition-diagnosing-an-undetectable-monolithic-sd-card/) - [ ] [The Sound Of Silence – What Institutional Silence On DFI Well-Being Actually Tells Us](https://www.forensicfocus.com/articles/the-sound-of-silence-what-institutional-silence-on-dfi-well-being-actually-tells-us/) - [ ] [Cyber Resilience Act cosa cambia dall’11 settembre](https://www.cybersecurity360.it/legal/cyber-resilience-act-cosa-cambia-dall11-settembre/) - [ ] [AutisticiInventati, l’editto Usa che si fa beffe della sovranità europea](https://www.agendadigitale.eu/cultura-digitale/autistici-inventati-leditto-usa-che-si-fa-beffe-della-sovranita-europea/) - [ ] [Il PDF di Schrödinger stesso hash, due contenuti diversi](https://www.forenser.it/schrodinger-pdf-apple-jpx-renderer/) - [ ] [The Bayesian Revolution in Forensic Science How Should Evidence Change What We Believe](https://www.buddingforensicexpert.in/2026/09/the-bayesian-revolution-in-forensic.html) - [ ] [Two conference talks (slides)](https://dfir.ru/2026/09/09/two-conference-talks-slides/) - [ ] [Il fragile patto di fiducia della cybersecurity](https://www.guerredirete.it/il-fragile-patto-di-fiducia-della-cybersecurity/) - [ ] [Il Garante ha “spento” il riconoscimento facciale dello Stadio Olimpico. Ma una legge potrebbe riattivarlo](https://irpimedia.irpi.eu/riconoscimento-facciale-stadio-olimpico-roma/) - GRAHAM CLULEY - [ ] [‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars](https://www.bitdefender.com/en-us/blog/hotforsecurity/anne-hathaway-245-million-crypto-theft-nightclubs-watches-luxury-cars) - Deeplinks - [ ] [We All Deserve a Better Internet, Not A Smaller One](https://www.eff.org/press/releases/we-all-deserve-better-internet-not-smaller-one) - Daniel Miessler - [ ] [The Boring Way to Get to AI Taking Over Everything](https://danielmiessler.com/blog/slow-path-to-ai-takeover?utm_source=rss&utm_medium=feed&utm_campaign=website) - TorrentFreak - [ ] [Pirate IPTV Operators Face $32.7 Million Judgment and Self-Expanding Blocking Injunction](https://torrentfreak.com/pirate-iptv-operators-face-32-7-million-judgment-and-self-expanding-blocking-injunction/) - The Hacker News - [ ] [ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories](https://thehackernews.com/2026/09/threatsday-200-android-flaws-browser.html) - [ ] [Google Play Early Access Abused to Push Thousands of Deceptive Android Apps](https://thehackernews.com/2026/09/google-play-early-access-abused-to-push.html) - [ ] [Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE](https://thehackernews.com/2026/09/check-point-discloses-two-98-rated-vpn.html) - [ ] [PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances](https://thehackernews.com/2026/09/papercut-attacker-uses-hundreds-of-ai.html) - [ ] [Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks](https://thehackernews.com/2026/09/gigabud-creates-android-work-profiles.html) - [ ] [CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline](https://thehackernews.com/2026/09/cisa-flags-exploited-cisco-citrix.html) - [ ] [Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key](https://thehackernews.com/2026/09/nearly-1-in-10-exposed-litellm-gateways.html) - [ ] [Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6](https://thehackernews.com/2026/09/anthropic-ai-models-breached-real.html) - www.theregister.com - Articles - [ ] [Latest Anthropic horror story chills with tales of kamikaze drone swarms and bioweapons research](https://www.theregister.com/ai-and-ml/2026/09/10/latest-anthropic-horror-story-chills-with-tales-of-kamikaze-drone-swarms-and-bioweapons-research/5295702) - [ ] [Watch out: Apple timepiece can grab snippets of conversation without both speakers' consent](https://www.theregister.com/security/2026/09/10/watch-out-apple-timepiece-can-grab-snippets-of-conversation-without-both-speakers-consent/5295666) - [ ] [Hundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script](https://www.theregister.com/security/2026/09/10/hundreds-of-ai-agents-helped-papercut-attacker-hit-395-orgs-and-some-went-off-script/5295650) - [ ] [ShinyHunters expose 6.4M in attack on medical supplier McKesson](https://www.theregister.com/security/2026/09/10/shinyhunters-expose-64m-in-attack-on-medical-supplier-mckesson/5295550) - [ ] [Dental contractor set up secret account with access to 4,000 patient records then left the company](https://www.theregister.com/security/2026/09/10/dental-contractor-set-up-secret-account-with-access-to-4000-patient-records-then-left-the-company/5295361) - Security Affairs - [ ] [U.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog](https://securityaffairs.com/198850/security/u-s-cisa-adds-cisco-google-chromium-v8-fortinet-and-citrix-netscaler-flaws-to-its-known-exploited-vulnerabilities-catalog.html) - [ ] [More Capable AI, Not Enough Guardrails](https://securityaffairs.com/198833/ai/more-capable-ai-not-enough-guardrails.html) - [ ] [A New Claude ‘s Sandbox Failure Shows How AI Can Rationalize Real-World Harm](https://securityaffairs.com/198814/hacking/a-new-claude-s-sandbox-failure-shows-how-ai-can-rationalize-real-world-harm.html) - [ ] [U.S. CISA adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog](https://securityaffairs.com/198802/hacking/u-s-cisa-adds-microsoft-windows-n-able-n-central-and-adobe-flaws-to-its-known-exploited-vulnerabilities-catalog.html) - [ ] [Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days](https://securityaffairs.com/198783/apt/four-nation-state-actors-used-the-same-chrome-zero-day-exploit-kit-within-12-days.html) - KitPloit - PenTest Tools! - [ ] [tmux v3.8-rc](https://kitploit.com/en/posts/github-tmux-tmux-38-rc) - [ ] [auth v2.197.0](https://kitploit.com/en/posts/github-supabase-auth-v21970) - [ ] [ecapture v2.6.0](https://kitploit.com/en/posts/github-gojue-ecapture-v260) - [ ] [cve-lite-cli v1.34.0](https://kitploit.com/en/posts/github-owasp-cve-lite-cli-v1340) - [ ] [scilla v1.3.4](https://kitploit.com/en/posts/github-edoardottt-scilla-v134) - [ ] [brutus v1.15.0](https://kitploit.com/en/posts/github-praetorian-inc-brutus-v1150) - [ ] [pomerium v0.33.3](https://kitploit.com/en/posts/github-pomerium-pomerium-v0333) - [ ] [serverless sf-core@4.42.0](https://kitploit.com/en/posts/github-serverless-serverless-sf-core4420) - [ ] [garak v0.17.0](https://kitploit.com/en/posts/github-nvidia-garak-v0170) - [ ] [falco v0.45.0-rc1](https://kitploit.com/en/posts/github-falcosecurity-falco-0450-rc1) - [ ] [openssl openssl-4.1.0-alpha1](https://kitploit.com/en/posts/github-openssl-openssl-openssl-410-alpha1) - [ ] [how_to_become_a_malware_analyst](https://kitploit.com/en/tools/github/pinksawtooth/how_to_become_a_malware_analyst) - [ ] [TATS](https://kitploit.com/en/tools/github/icemoonhsv/tats) - [ ] [inspector v2.6.0](https://kitploit.com/en/posts/github-modelcontextprotocol-inspector-260) - [ ] [geiger](https://kitploit.com/en/tools/github/atomburstofficial/geiger) - [ ] [Packet-Sniffer v6.0.0](https://kitploit.com/en/posts/github-eonraider-packet-sniffer-v600) - [ ] [pd-agent v0.2.1](https://kitploit.com/en/posts/github-projectdiscovery-pd-agent-v021) - [ ] [hermes-decomp v0.2.3](https://kitploit.com/en/posts/github-symbioticsec-hermes-decomp-v023) - [ ] [oss-oopssec-store v2.20.0](https://kitploit.com/en/posts/github-koadt-oss-oopssec-store-v2200) - [ ] [uac v3.4.0](https://kitploit.com/en/posts/github-tclahr-uac-v340) - [ ] [jadx-magic-strings v1.0.3-dev](https://kitploit.com/en/posts/github-0rshemesh-jadx-magic-strings-v103-dev) - [ ] [kyverno v1.19.1-rc.1](https://kitploit.com/en/posts/github-kyverno-kyverno-v1191-rc1) - [ ] [server v1.0.1](https://kitploit.com/en/posts/github-hashtopolis-server-v101) - [ ] [aws-security-assessment-solution v3.0.0](https://kitploit.com/en/posts/github-awslabs-aws-security-assessment-solution-v300) - [ ] [PCAPdroid v2.0.1](https://kitploit.com/en/posts/github-emanuele-f-pcapdroid-v201) - [ ] [threatest v1.5.0](https://kitploit.com/en/posts/github-datadog-threatest-v150) - [ ] [sherlock v0.16.2](https://kitploit.com/en/posts/github-sherlock-project-sherlock-v0162) - [ ] [ESP32Marauder v1.16.0](https://kitploit.com/en/posts/github-justcallmekoko-esp32marauder-v1160) - [ ] [redcell](https://kitploit.com/en/tools/github/martian56/redcell) - [ ] [openshield](https://kitploit.com/en/tools/github/owasp/openshield) - [ ] [pii-shield v2.2.3](https://kitploit.com/en/posts/github-pii-shield-pii-shield-v223) - Security Weekly Podcast Network (Audio) - [ ] [It's More Secure When It's Disabled - PSW #943](http://sites.libsyn.com/18678/its-more-secure-when-its-disabled-psw-943)
每日安全资讯(2026-09-11)