# 每日安全资讯(2026-09-16) - SecWiki News - [ ] [SecWiki News 2026-09-15 Review](http://www.sec-wiki.com/?2026-09-15) - Private Feed for M09Ic - [ ] [bolucat released 202609152306 at bolucat/Archive](https://github.com/bolucat/Archive/releases/tag/202609152306) - [ ] [anthropics released v2.1.273 at anthropics/claude-code](https://github.com/anthropics/claude-code/releases/tag/v2.1.273) - [ ] [kpcyrd contributed to DNSCrypt/doh-server](https://github.com/DNSCrypt/doh-server/pull/121) - [ ] [strands-agents released typescript/v1.18.0 at strands-agents/harness-sdk](https://github.com/strands-agents/harness-sdk/releases/tag/typescript/v1.18.0) - [ ] [Ridter starred LongWayHomie/PolyEngine](https://github.com/LongWayHomie/PolyEngine) - [ ] [mgeeky starred ustayready/tradecraft](https://github.com/ustayready/tradecraft) - [ ] [Mr-xn starred Yean-Sec/StrikeAgent_Coder-Flash](https://github.com/Yean-Sec/StrikeAgent_Coder-Flash) - [ ] [panjf2000 starred YaoFANGUK/video-subtitle-extractor](https://github.com/YaoFANGUK/video-subtitle-extractor) - [ ] [Chuyu-Team released v1.2.3-Beta.2 at Chuyu-Team/YY-Thunks](https://github.com/Chuyu-Team/YY-Thunks/releases/tag/v1.2.3-Beta.2) - [ ] [kpcyrd contributed to kpcyrd/hussh](https://github.com/kpcyrd/hussh/pull/2) - [ ] [esrrhs contributed to esrrhs/fakecc](https://github.com/esrrhs/fakecc/pull/79) - [ ] [timwhitez starred chainreactors/ioa](https://github.com/chainreactors/ioa) - [ ] [kpcyrd contributed to kpcyrd/signal-tlsd](https://github.com/kpcyrd/signal-tlsd/pull/11) - [ ] [kpcyrd starred Antiz96/arch-update](https://github.com/Antiz96/arch-update) - [ ] [kpcyrd contributed to kpcyrd/repro-env](https://github.com/kpcyrd/repro-env/pull/62) - [ ] [anthropics released v2.1.272 at anthropics/claude-code](https://github.com/anthropics/claude-code/releases/tag/v2.1.272) - Paper - 知道创宇404实验室 - [ ] [融合谱特征与激活聚类用于医疗影像模型后门检测:方法、实现与评估](https://paper.seebug.org/3519) - Der Flounder - [ ] [Enrolling macOS Golden Gate 27.0.0 virtual machines with MDM servers does not work correctly](https://derflounder.wordpress.com/2026/09/15/enrolling-macos-golden-gate-27-0-0-virtual-machines-with-mdm-servers-does-not-work-correctly/) - [ ] [Intel apps and macOS Golden Gate](https://derflounder.wordpress.com/2026/09/15/intel-apps-and-macos-golden-gate/) - 先知安全技术社区 - [ ] [Groovy 沙箱绕过技术分析-以Apache Syncope为例的多版本RCE绕过](https://xz.aliyun.com/news/92835) - [ ] [CVE-2024-51504 漏洞分析](https://xz.aliyun.com/news/92832) - [ ] [vm2 沙箱逃逸全解析:从跨 Realm 边界到异常与 Promise 链的攻防演进](https://xz.aliyun.com/news/92831) - Doonsec's feed - [ ] [字节:半年进账8050亿,但利润却下滑了,只有1340亿](https://mp.weixin.qq.com/s/Wes1a8JFveUuNJnWyxkzcg) - [ ] [我们正在积极对红队/逆向的内容构思和编写之中!](https://mp.weixin.qq.com/s/-TRI5lftG36n1ykkPXB0Pg) - [ ] [朝鲜IT远程工作战术升级:跨境招募绕过风控](https://mp.weixin.qq.com/s/5YEFNrw9lpkL_L2yI74sxg) - [ ] [宇树暴跌!从4400亿到1900亿,制度漏洞还是估值泡沫?](https://mp.weixin.qq.com/s/qPdkwy1Y9a_M3ZQ9cICt4A) - [ ] [“网络安全为人民,网络安全靠人民——智能时代,网安护航” |2026年国家网络安全宣传周](https://mp.weixin.qq.com/s/_DXgm3GbSZhgHJ9agXBKBg) - [ ] [【战法skill】欲盖弥彰:把笔录、流水、位置放在一起比,矛盾点自己跳出来](https://mp.weixin.qq.com/s/dKCkI2_Cil_hLFyS5tfnlQ) - [ ] [1632份问卷,MIT最新报告发布:AI对学生的学习与认知冲击](https://mp.weixin.qq.com/s/q7M1HXTGlbSZmQMZhOyrjg) - [ ] [RapidDNS](https://mp.weixin.qq.com/s/CIGQyxkK_RAt1PEnzI33Bg) - [ ] [AI SOC 上线后,真正难的是验收、授权和接管](https://mp.weixin.qq.com/s/XR6ZF2xM7efguZDRqLUTEg) - [ ] [网安圈炸了!天融信被全军永久禁入采购,到底发生了什么?](https://mp.weixin.qq.com/s/-o6yyvvO9q6TBZtMP4Hzeg) - [ ] [慧等保 · 只做一件事:把等保测评做专业、做扎实、做成一次通过](https://mp.weixin.qq.com/s/PnHrjblTvjU6AVTrbLXUdA) - [ ] [2026网安周 | 多图预警!一文看遍网安周网络安全技术应用体验区](https://mp.weixin.qq.com/s/NXhwYsY2dLn09UddI3mV0w) - [ ] [行业 | 从Anthropic报告看政企AI落地的数据安全挑战,五一嘉峪以「原生安全」构建数据「反萃取」防线](https://mp.weixin.qq.com/s/OeRsgu7GcqzTJq9ZjXyG2w) - [ ] [筑牢能源行业网络安全屏障 护航企业数字化高质量发展——中国石油天然气集团有限公司扎实开展2026年网络安全宣传周主题教育实践活动](https://mp.weixin.qq.com/s/7wHpKc3VcJ0pKM75O3JX9w) - [ ] [关注 | 国家网信办发布近期网络安全、数据安全、个人信息保护等领域执法典型案例](https://mp.weixin.qq.com/s/XdaU9WYm0A2z5ml6Sqt9Og) - [ ] [发布 | 网安标委发布《人工智能应用安全指引 总则》等4项网络安全标准实践指南(附下载)](https://mp.weixin.qq.com/s/CIGh10lf23-rt--PcarVqw) - [ ] [发布 | 网安标委发布《网络安全标准实践指南——半导体存储介质块擦除技术指引》等3项网络安全标准实践指南(附下载)](https://mp.weixin.qq.com/s/T9s5r4DMmZJYY1sCPj7LGw) - [ ] [发布 | 网安标委发布《网络安全标准实践指南——座舱数据处理安全要求》(附全文)](https://mp.weixin.qq.com/s/cokSjs3drv1q96ec9g69sw) - [ ] [已复现 | 搜狗输入法“1点击”远程代码执行漏洞(视频)](https://mp.weixin.qq.com/s/Sf9ns4WBGhxVNjOpQ1IqBg) - [ ] [行业资讯|Paid Ranking &网络安全项目中标情况汇总(9月15日)](https://mp.weixin.qq.com/s/5J1QUyE0PZAUz9XpTeHeyg) - [ ] [专治「读完就忘」的 PDF 阅读神器!把笔记和复习都安排明白了](https://mp.weixin.qq.com/s/FoX1LbZGa8ImXDX0yAoYrw) - [ ] [AI已成网络犯罪“核动力”?Anthropic警告黑客组织滥用AI进度惊人](https://mp.weixin.qq.com/s/1Ab9FSweRv8z_OB19ymlTw) - [ ] [欧盟《数据法》迎来关键节点:新上市连接产品必须“默认支持用户访问数据”](https://mp.weixin.qq.com/s/NtBLchTE59_Z8WEsFNNHcQ) - [ ] [神州希望测评智能质量审核系统上线](https://mp.weixin.qq.com/s/ZOy_DwQQhkkKzhkwOBW5Ig) - [ ] [【长亭AI安全·网安周进行时】速存!20张AI安全海报免费领](https://mp.weixin.qq.com/s/Mq8-6Ndg8k5Tp-xNa_72yw) - [ ] [【长亭AI安全·网安周进行时】AI 含量拉满!一文带你看完今年网安周展区](https://mp.weixin.qq.com/s/_ICvGJ0ZIpepT5li80Qe_Q) - [ ] [科普:精准定位](https://mp.weixin.qq.com/s/7hl1G8sHfA3E6oDxYBBKcg) - [ ] [美国贸易代表办公室就2027年国家贸易预测报告中重大对外贸易壁垒进行意见征询](https://mp.weixin.qq.com/s/Mvxk1YbpQWk8tccyb1gSEg) - [ ] [生物域成为新战线:美陆军生物防御战略解读](https://mp.weixin.qq.com/s/2D73cY-seySYYAo7DSr7Sw) - [ ] [天融信发布《智能体全域安全防护框架》](https://mp.weixin.qq.com/s/1bcmcx_n5oElhL89N1BZtA) - [ ] [你永远挖不到高价洞的真相:扫描器救不了新人](https://mp.weixin.qq.com/s/zBkR0fZ5rhEqlNb5SUwYEw) - [ ] [国家网络安全宣传周|造谣传谣,也停一下](https://mp.weixin.qq.com/s/KISROqnbbHsbnyYTOqu7jQ) - [ ] [采购文件暗藏杀机——PureRAT木马针对电商定向窃密](https://mp.weixin.qq.com/s/tseg9C7Sx4QVZceCl8RXlA) - [ ] [诚邀渠道合作伙伴共启新征程](https://mp.weixin.qq.com/s/VOktSOe34qBjTiSCp25F3Q) - [ ] [活动预告丨“从网安超级模型到网安超级智能”技术报告会明日开启](https://mp.weixin.qq.com/s/VAhVnYoIF8pPCs1a1_Gr8w) - [ ] [《AI 时代,白帽进阶:补天沙龙成都站议题精华抢先看!》](https://mp.weixin.qq.com/s/gu7Pl1OW7jIeqmn4htz59Q) - [ ] [从“信息检索”到“专业交付”:库库 AI 正在重做金融投资与科研教育的工作流](https://mp.weixin.qq.com/s/2A5ZR0e0-x-WhPLqBIjNjQ) - [ ] [终于有人挖出了网络安全这108页保姆秘籍,带详细教程!](https://mp.weixin.qq.com/s/y1lAhRNaWg9OPscvjSvc1g) - [ ] [URL解析差异的WCD利用:缓存键原语、PII泄露与缓存投毒](https://mp.weixin.qq.com/s/hut24M29UZ5QrrmggF_F4w) - [ ] [2026年网络空间安全学术会议注册早鸟票延期通知](https://mp.weixin.qq.com/s/s0Gy3TJ8R93Efaq24ifKkA) - [ ] [vivo 通过ISO漏洞管理体系认证,漏洞治理全面接轨国际标准](https://mp.weixin.qq.com/s/CkhLyM5FtUgtUAmc0_sJ0Q) - [ ] [藏不住了!安全圈的“神盾局”档案首次公开](https://mp.weixin.qq.com/s/kLsH8p662oo-XvXqNydiyg) - [ ] [国家网络安全宣传周丨中国电信以全栈安全能力护航智能时代](https://mp.weixin.qq.com/s/B4NQFFKUJeOfiI1TihKhwQ) - [ ] [第80篇 AI全栈 · 62个与弱密码相关的协议](https://mp.weixin.qq.com/s/aRpr4PDKvhYcpHDPhRouCg) - [ ] [中标|陕西延长石油集团横山魏墙煤业](https://mp.weixin.qq.com/s/vciOGoCXVLxZZL52AT-vUA) - [ ] [“176号令”落地倒计时:日志合规这道关怎么过?](https://mp.weixin.qq.com/s/gva1R5h7qxpL_liytOw9hQ) - [ ] [2025-2026年 百度反诈治理报告](https://mp.weixin.qq.com/s/AWIQ6LQo5mtbzCpA9SkdRg) - [ ] [美国国家安全局“五大任务中心”重组的战略逻辑、制度风险与全球影响](https://mp.weixin.qq.com/s/CpPXy4cA5nNWbRRXvABptA) - [ ] [备战高端冲突:美陆军战斗航空旅推进结构性重组](https://mp.weixin.qq.com/s/deruLEx9ZKPU41Xz-T25cQ) - [ ] [“认知竞争+台能源设施”学术沙龙活动简报](https://mp.weixin.qq.com/s/8uCo_jyeIIvBQKaPWjRfAw) - [ ] [知远防务论坛 |“日本防空反导作战”桌面推演邀请](https://mp.weixin.qq.com/s/lPptxt6dURoMCH2Hr3l4Iw) - [ ] [【推荐】知远蓝军战术态势数据系统系列产品](https://mp.weixin.qq.com/s/MUhpYCMG1pod8H15gXQwpA) - [ ] [剑指“银狐”!瑞星亮相2026网安周](https://mp.weixin.qq.com/s/syBHtRiRigSSqrKu-XeIwQ) - [ ] [AI攻防:壕!](https://mp.weixin.qq.com/s/lZ9F6jGIQi2ft11qx9pzKw) - [ ] [(入门)最近工具的使用体验](https://mp.weixin.qq.com/s/Pj6Ldpel7GviUwhGRD275g) - [ ] [网安入门必学:基础不牢,漏洞白学](https://mp.weixin.qq.com/s/hQphKssKvTZ0q3G2mrny8A) - [ ] [【2026hvv】搜狗一键RCE漏洞之三个\"各自不算致命\"的缺陷如何变成 Critical,文章详谈~【附验证exp】](https://mp.weixin.qq.com/s/2TyIwuivZQ6wJ7Mm-E3RYw) - [ ] [Linux内核网络 专栏更新完成](https://mp.weixin.qq.com/s/HtWagqUCKBF8pW785INBYQ) - [ ] [牟林:中国为何不踩坑?巴基斯坦的尴尬足够引以为戒](https://mp.weixin.qq.com/s/f5B_ObkFyN9IFfxymUX88g) - [ ] [秦安:太猛了,胡塞大捷!](https://mp.weixin.qq.com/s/9UAmyTCD1YzpZpKntK4JDg) - [ ] [习近平给福建省“漳州110”全体队员回信](https://mp.weixin.qq.com/s/PgOlw9bh5D7jk066cpujvQ) - [ ] [无人机在天上飞,后台却被境外IP登录:巡检平台四类盲区](https://mp.weixin.qq.com/s/KSAIehxKn1233l50ydTaCA) - [ ] [服务器成了勒索主战场:8月国内勒索反馈中 Weaxor 占65.74%](https://mp.weixin.qq.com/s/6WPas5RKYaCcoo1iESYXLA) - [ ] [普通用户能拿到管理员密钥:JumpServer 过滤漏洞已公开 PoC](https://mp.weixin.qq.com/s/S0Soo6bIHFOxiMFRHNHM8g) - [ ] [国家网络安全宣传周|网络谣言的自我毁灭之路](https://mp.weixin.qq.com/s/7upVjToT8sGwPnqWWY_A8w) - [ ] [Anthropic主动踩刹车,AI落地团队该醒醒了:模型聪明≠敢让它碰核心系统](https://mp.weixin.qq.com/s/7oG32SOKZN0EJHqtSDPTiQ) - [ ] [网安标委发布《人工智能安全治理框架3.0》,风险分类与技术应对措施同步更新;CNVD发布2026年第36期漏洞周报| 牛览](https://mp.weixin.qq.com/s/AEHea_NgsPtQh6yL7dkjLA) - [ ] [如果重新选择一次,你还会进网络安全吗?](https://mp.weixin.qq.com/s/zCCaxprnBfR5_DJybLbAqw) - [ ] [行业信息化属性探讨:政府、军工](https://mp.weixin.qq.com/s/s4ArlKZCuBjrWUq5jvosnQ) - [ ] [关于发布完成个人信息收集使用优化改进App清单的公告(2026年第3批)](https://mp.weixin.qq.com/s/whmi5eeVmeaJ67XwQMm7Qw) - [ ] [AI编程安全:业务逻辑漏洞,至今过不了的坎](https://mp.weixin.qq.com/s/KfQKypZlvpd_mvP94k05Qw) - [ ] [CNVD漏洞周报2026年第36期](https://mp.weixin.qq.com/s/x-1QzlFO8ffKL5DpOJTvPg) - [ ] [WooCommerce批发潜客捕获插件漏洞遭在野利用](https://mp.weixin.qq.com/s/HZXA47-_Gt9AdU8A8eCYrQ) - [ ] [1.5 万美元—从 CSPT 开始,最终实现账户完全接管,随后通过原型链绕过双因素认证](https://mp.weixin.qq.com/s/cC9I-qsUhK7FJ1DCMrqMdQ) - [ ] [iOS27正式版推送!国行全部可用新功能整理,有些惊喜有些遗憾](https://mp.weixin.qq.com/s/W9Goflh8eA9RG2CYxsSIFg) - [ ] [2026年国家网络安全宣传周 | 网警发布网络安全宣传周主题海报](https://mp.weixin.qq.com/s/gdm0b4ZUpLPj8cHRvTV10Q) - [ ] [美国头部AI企业呼吁放缓前沿AI发展,特朗普政府以对华竞争为由拒绝大幅收紧](https://mp.weixin.qq.com/s/IsB6AvigQLBvNbQo14BZwA) - [ ] [10大模式+17个插件!这款DSH红队大模型工具凭什么刷屏安全圈?](https://mp.weixin.qq.com/s/1N_B-ADWNYc-XvHjgxee4g) - [ ] [DeepSeek-DSH红队模式 - 覆盖渗透测试、红队评估、代码审计、免杀对抗等](https://mp.weixin.qq.com/s/cW8FI4ZHZLdiIIYAPB9j7w) - [ ] [不许胡说](https://mp.weixin.qq.com/s/BzoCzU3zoc8qRT5kZlcc6Q) - [ ] [1v1论文指导!985/211专业对口导师手把手指导至录用!SCI/SSCI/EI/中文核心/毕业论文](https://mp.weixin.qq.com/s/j-ZPswNLSu4kIB2wVAMoCQ) - [ ] [2026年国家网络安全宣传周人才招聘会+宣传素材](https://mp.weixin.qq.com/s/wGIWJ-XXd9ZCGJpYGoFm3A) - [ ] [千人大帮会|网盘资源终身领取|CISP/PTE考证底价|18年网安大佬带队](https://mp.weixin.qq.com/s/Tl3sZprHp2oyGrcwtvJuMg) - [ ] [崂山国家实验室聘信息安全技术岗](https://mp.weixin.qq.com/s/abqMDo2s59RKMK2sa3xIKQ) - [ ] [华橙网络2027届校园招聘](https://mp.weixin.qq.com/s/EqFf_HviReU4XQAlpAdGDQ) - [ ] [银狐投毒云调度进化:被识破的假官网改发微信安装包,黑名单机制上线](https://mp.weixin.qq.com/s/nQZGBZJ_r3j6UUcSE5NUDA) - [ ] [安恒参编|全国网安周开幕式重磅发布《人工智能安全治理框架》3.0 版](https://mp.weixin.qq.com/s/WuqyJqC_W3iVqEU1D6q1VQ) - [ ] [高危预警|CVE-2026-51990 搜狗输入法RCE漏洞!可植入灰兔后门,已被APT野利用](https://mp.weixin.qq.com/s/TAfELBir0dA7gtKG5Znbcg) - [ ] [暗网“钥匙经济”:初始访问经纪人IAB如何把企业网络访问权限卖成商品](https://mp.weixin.qq.com/s/MizRp9lmyZhvDEHKqyDbMw) - [ ] [暗网拍卖师\"backdoor\":3天卖掉3家欧美网店,你家后台密码改了吗?](https://mp.weixin.qq.com/s/WEi41tagZ3V1SQ_4nfOw5w) - [ ] [逆向新手的第一课:某端游从 CE 搜索->断点->血量基址](https://mp.weixin.qq.com/s/80L2T7CO1TV38ltQccD_7A) - [ ] [Web安全测试的终极利器:Burp Suite核心模块与插件开发实战](https://mp.weixin.qq.com/s/JRUQKGd5VGe1s_2Jxy55Sw) - [ ] [一图解读《公安机关网络空间安全监督检查办法》](https://mp.weixin.qq.com/s/HxPmwk9GLSRvY0dvxmh7MA) - [ ] [云天 · 安全通告(2026年9月15日)](https://mp.weixin.qq.com/s/qDZZaDcnLDhtH1U7xDU9tg) - [ ] [ALiYun云渗透指南二](https://mp.weixin.qq.com/s/UPypd9ggkFtumcH1oTyMoA) - [ ] [2026年网络安全宣传周 | 不点可疑链接,不开未知附件](https://mp.weixin.qq.com/s/QfGn2wYGXW2Ca6enDdnGCA) - [ ] [做网络工程必须知道的知识:单模与多模光缆到底怎么选](https://mp.weixin.qq.com/s/JmHZQp_CagWkv4c_dUDwhA) - [ ] [关于网线的4个常见误区,很多人都搞错了](https://mp.weixin.qq.com/s/Yev8u62m_3uQwAfuZ1AcFg) - [ ] [新华社:学生信息竟成黑市商品,必须一剿到底!](https://mp.weixin.qq.com/s/JCS4Z3AVYXF6njHxXuT3oA) - [ ] [央视新闻:网传“外卖员向餐食吐口水”系摆拍!警方披露案件细节](https://mp.weixin.qq.com/s/SfxRuGLvRDWJDHdjz9a4GA) - [ ] [搜狗输入法曝一键 RCE 漏洞(CVE-2026-51990),已被在野利用投放后门](https://mp.weixin.qq.com/s/rC8uFUAeDcYnhXA2a7SClg) - [ ] [股票到底是啥?你买的那个数字是什么](https://mp.weixin.qq.com/s/Lb2AG1Vd3ziQ6ND0dAE5rA) - [ ] [iOS 27 发布当日即遭破解:AirLift 配对越狱 PoC 深度技术分析](https://mp.weixin.qq.com/s/rGODvKFJ_ID2-pTL2rgauw) - [ ] [GitLab CVE-2026-85706路径遍历漏洞:无认证任意文件读取](https://mp.weixin.qq.com/s/2vBN21nh0KK6tF7tpx8z8w) - [ ] [45 美元把 ESP32-P4 变成开源 IP-KVM 远程控制卡](https://mp.weixin.qq.com/s/wMXWhYqmW1MOsNqLkfm8xQ) - [ ] [EvidenceForge 工具介绍:生成高可信度的合成网络安全日志](https://mp.weixin.qq.com/s/-qTGflTdf97mmdydLmp4MA) - [ ] [【热点安全风险】9月15日 | ConnectWise ScreenConnect 提权漏洞遭在野利用,攻击者可接管企业终端运维通道(CVE-2026-84869)](https://mp.weixin.qq.com/s/aTapxCJ62HhbipP0qrcmmQ) - [ ] [dddd-Next 自动化资产测绘 + 漏洞扫描工具,覆盖指纹识别、弱口令、nuclei POC、Shiro 专项检测和 HTML 报告](https://mp.weixin.qq.com/s/ZUINewc4p6R1U2h9mGMRcg) - [ ] [ARTEX:自动化渗透测试-多版本更新](https://mp.weixin.qq.com/s/lGiyiP_cTNSlm7ZqKNAALw) - [ ] [密钥将死?芯片\"物理指纹\"重写无人机与数据中心安全规则](https://mp.weixin.qq.com/s/evw1j99HSTEal3UKJ2Meyg) - [ ] [德国警方如何“克隆”你的Signal、Telegram和WhatsApp](https://mp.weixin.qq.com/s/-urdXPsLLmTbVYdEDyy7xA) - [ ] [前间谍头子坐镇东京:日澳情报\"准联盟\"进入实操阶段](https://mp.weixin.qq.com/s/qFKMXhKD93tTwHLYxsJwrw) - [ ] [本地文档搜索神器qmd](https://mp.weixin.qq.com/s/_izBiumsviv5t6Bgl3O6Ug) - [ ] [《人工智能安全治理框架3.0》发布](https://mp.weixin.qq.com/s/GK7y86y-jni4D4cNjzIzqQ) - [ ] [DNSSEC NSEC 遍历(Zone Walking)](https://mp.weixin.qq.com/s/2tK1hPA75mmyUhnGr2G3pQ) - [ ] [Avast 防病毒软件零日漏洞利用概念验证允许攻击者导出 SAM 数据库并获得 SYSTEM Shell](https://mp.weixin.qq.com/s/gmVrqqnkAXo4cL4U9eQcIw) - [ ] [双节重磅福利|AI安全认证报一送一!花1份学费,解锁2项AI安全硬核能力](https://mp.weixin.qq.com/s/8VDGTEsGeJezNSl2ybyFqA) - [ ] [美国国家安全局(NSA)十年之组织重构 | 中国被单独列出为五个中心中唯一的国家](https://mp.weixin.qq.com/s/zCLgfqGThRvO-fMoRfKZKw) - [ ] [甲方还是乙方:安全人五年后的岔路口](https://mp.weixin.qq.com/s/UxNzk01EPunyS9Y2JhF3Qg) - [ ] [为啥有些网站Chrome记不住密码](https://mp.weixin.qq.com/s/7ryN_8H_lSucd2y23SuDRg) - [ ] [菏泽警方破获特大直播带货诈骗案,虚构企业老总人设骗500余万元,抓获11人](https://mp.weixin.qq.com/s/8dE_pFln9m_jG30Q48oxhw) - [ ] [西宁南川警方破获刷单返利诈骗案,跨省抓获嫌疑人,涉案35万元](https://mp.weixin.qq.com/s/r5IArZqnT-2eT8vDC1LIiw) - [ ] [泾川公安破获证券股票诈骗案,抓获6人挽损18万元](https://mp.weixin.qq.com/s/CwiXeHqWDuDeeFX0Na43_g) - [ ] [秦安:日本“狗粮”增加10倍,“特高科”领衔情报战,在华间谍到底有多少?](https://mp.weixin.qq.com/s/yV0CrofmDQUoK8urYa0JTQ) - [ ] [秦安:非常震撼!中国空军这四种机型,首次在国外航展公开亮相。](https://mp.weixin.qq.com/s/974UPXF7CZkBH45yJ9-txQ) - [ ] [秦安:突破性发现,我国在西太平洋海底锁定高温热液区,矿产资源价值超乎你的想象!](https://mp.weixin.qq.com/s/_pv1AzD6FD7bfqqLque_LQ) - [ ] [又发现一个超香的开源监控神器!Pika个人服务器必备](https://mp.weixin.qq.com/s/Ph6GO2y6H1a3mJWpYeapow) - [ ] [紧急安全提醒:PVE 8 全系列已被攻破,请立即升级至 PVE 9](https://mp.weixin.qq.com/s/M8XsQWpBxq0S-D0_OViDkw) - [ ] [Prometheus配半天只为看机器还活着?这个5MB工具刚够用](https://mp.weixin.qq.com/s/uWDPVoL9YPyvUs_l2u90Ig) - [ ] [安全工具丨一个轻量 C2 框架覆盖「生成载荷 → 会话管理 → 任务执行」的完整链路。红队演练、渗透测试开箱即用。](https://mp.weixin.qq.com/s/bNJoqHvPYkVwB4hCba8bUA) - [ ] [反无人机新锐手段与装备运用系列报告(25.8万字干货)](https://mp.weixin.qq.com/s/7t-YeVQRObOOj5qOIn8nCg) - [ ] [反制美日台潜航器:作战概念、装备体系构成与演习试验运用研判(7.2万字干货)](https://mp.weixin.qq.com/s/R4TR3mnZkZlPoN0kA--eLg) - [ ] [乌克兰军用无人机武器调查报告(3.6万字干货)](https://mp.weixin.qq.com/s/1zAJW9_vyGhTaj6plgTq2g) - [ ] [【理论专著】强敌印太地区利益与战略布局解析——美国利益排序、体系构建与战略约束研究](https://mp.weixin.qq.com/s/jpnOjKjZLDfM5JI9DbNe0Q) - [ ] [【研究报告】俄乌冲突中无人机视像摄取与认知塑造闭环研究](https://mp.weixin.qq.com/s/j_qBSaT6jHype19_Zf43Lg) - [ ] [【分析报告】美军新型作战力量战备生成机制与实战化特征分析](https://mp.weixin.qq.com/s/bPioLztO4n9AhSr9zxIzzQ) - [ ] [【分析报告】美军网络预备役部队建设模式及战略启示](https://mp.weixin.qq.com/s/6xmCCGtNRFUK_aG9XlPU7Q) - [ ] [【蓝军译粹】《俄乌战争的初始阶段:顿巴斯(2014–2015年)(2.5万字干货)》【现代战争研究系列第7册】](https://mp.weixin.qq.com/s/H8Q3i94jAtuYF3C-_XTf_w) - [ ] [使用ASC + 自建 MCP 做APK漏洞面定位流水线](https://mp.weixin.qq.com/s/rGr1WhpTcPK2WoFngUcVHw) - [ ] [从两张中国残缺版图看国内某OSINT大V的“精神倒错”与认知缺陷](https://mp.weixin.qq.com/s/nRhZTQ9HHbNELpZg6sFAiw) - Tenable Blog - [ ] [Oracle September 2026 Critical Security Patch Update addresses 672 CVEs](https://www.tenable.com/blog/oracle-september-2026-critical-security-patch-update-addresses-672-cves) - [ ] [Australia is replacing the Essential Eight with a new cyber framework. Here’s how exposure management can help you get ahead of it.](https://www.tenable.com/blog/australia-essential-eight-replacement-compliance-exposure-management) - Recent Commits to cve:main - [ ] [Update Tue Sep 15 12:11:31 UTC 2026](https://github.com/trickest/cve/commit/f4a9fe77dab6bbcb968031a8159589af57be8024) - obaby 𝐢𝐧⃝ void - [ ] [成也UNI,败也UNI](https://zhongxiaojie.cn/2026/09/1914/) - Horizon3 - [ ] [Security Data Isn’t the Problem. Security Context Is.](https://horizon3.ai/intelligence/blogs/security-data-context-crowdstrike/) - [ ] [Horizon3 Announces Integration with CrowdStrike Falcon® Next-Gen SIEM](https://horizon3.ai/news/press-release/crowdstrike-falcon-next-gen-siem-integration/) - Kitploit — Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal! - [ ] [macnoise v1.0.0](https://kitploit.com/en/posts/github-0xv1n-macnoise-v100) - [ ] [django-DefectDojo v3.3.100](https://kitploit.com/en/posts/github-defectdojo-django-defectdojo-33100) - [ ] [reasongate v0.4.0](https://kitploit.com/en/posts/github-cgrtml-reasongate-v040) - [ ] [ziti v2.0.5](https://kitploit.com/en/posts/github-openziti-ziti-v205) - [ ] [sippts v4.2.1](https://kitploit.com/en/posts/github-pepelux-sippts-v421) - [ ] [zeek v9.0.0](https://kitploit.com/en/posts/github-zeek-zeek-v900) - [ ] [nuclei-burp-plugin v1.1.4](https://kitploit.com/en/posts/github-projectdiscovery-nuclei-burp-plugin-v114) - [ ] [IDAssist v2.4.0](https://kitploit.com/en/posts/github-symgraph-idassist-240) - [ ] [FACT_core v4.4.1](https://kitploit.com/en/posts/github-fkie-cad-fact_core-v441) - [ ] [BloodHound v9.7.1-rc1](https://kitploit.com/en/posts/github-specterops-bloodhound-v971-rc1) - [ ] [lava v3.3.1](https://kitploit.com/en/posts/github-panda-re-lava-v331) - [ ] [gowitness v3.2.0](https://kitploit.com/en/posts/github-sensepost-gowitness-320) - [ ] [stop-bots](https://kitploit.com/en/tools/github/ivankovic/stop-bots) - [ ] [tamarin-prover](https://kitploit.com/en/tools/github/tamarin-prover/tamarin-prover) - [ ] [OpenHunterAI](https://kitploit.com/en/tools/github/lumoslab-innovation/openhunterai) - [ ] [xalgorix](https://kitploit.com/en/tools/github/xalgorix/xalgorix) - [ ] [PEASS-ng v20260914-6273eb76](https://kitploit.com/en/posts/github-peass-ng-peass-ng-20260914-6273eb76) - [ ] [prismor v1.51.0](https://kitploit.com/en/posts/github-prismorsec-prismor-v1510) - [ ] [missing-cve-nuclei-templates v2026-09-14](https://kitploit.com/en/posts/github-edoardottt-missing-cve-nuclei-templates-2026-09-14) - [ ] [s3dns v0.2.30](https://kitploit.com/en/posts/github-olizimmermann-s3dns-v0230) - [ ] [MESH v0.2.0-beta](https://kitploit.com/en/posts/github-barghest-ngo-mesh-v020-beta) - [ ] [runeward](https://kitploit.com/en/tools/github/runewardd/runeward) - [ ] [dependency-track v4.14.4](https://kitploit.com/en/posts/github-dependencytrack-dependency-track-4144) - [ ] [Kage-DFIR-toolkit](https://kitploit.com/en/tools/github/karim852/kage-dfir-toolkit) - [ ] [KUMO-Domain-Recon-Tool](https://kitploit.com/en/tools/github/karim852/kumo-domain-recon-tool) - [ ] [hosts v3.16.114](https://kitploit.com/en/posts/github-stevenblack-hosts-316114) - [ ] [giskard-oss giskard-checks/v1.0.4](https://kitploit.com/en/posts/github-giskard-ai-giskard-oss-giskard-checksv104) - [ ] [WhoCord v1.2.1](https://kitploit.com/en/posts/github-siv-nick-whocord-v121) - [ ] [brook v20270101](https://kitploit.com/en/posts/github-txthinking-brook-v20270101) - [ ] [osv-scanner v2.6.0](https://kitploit.com/en/posts/github-google-osv-scanner-v260) - [ ] [warpgate v0.29.0-beta.1](https://kitploit.com/en/posts/github-warp-tech-warpgate-v0290-beta1) - [ ] [cowrie v3.0.14](https://kitploit.com/en/posts/github-cowrie-cowrie-v3014) - GuidePoint Security - [ ] [The Next Evolution of Identity: Extending IAM Across People, Machines, and AI](https://www.guidepointsecurity.com/blog/evolution-of-identity-extending-iam/) - Malwarebytes - [ ] [How to opt out of AI chatbot training](https://www.malwarebytes.com/blog/how-to/2026/09/how-to-opt-out-of-ai-chatbot-training) - [ ] [HBO Max’s verified Reddit account hijacked to spread malware](https://www.malwarebytes.com/blog/news/2026/09/hbo-maxs-verified-reddit-account-hijacked-to-spread-malware) - [ ] [Meta AI builds detailed profiles of children from years of family posts](https://www.malwarebytes.com/blog/family-and-parenting/2026/09/meta-ai-builds-detailed-profiles-of-children-from-years-of-family-posts) - [ ] [Search results are sending people to fake Bitrefill checkouts](https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts) - The Trail of Bits Blog - [ ] [1Password's AI patching benchmark is misleading](https://blog.trailofbits.com/2026/09/15/1passwords-ai-patching-benchmark-is-misleading/) - rtl-sdr.com - [ ] [SDR–: A Software-Defined Radio Application with Visual Signal Path](https://www.rtl-sdr.com/sdr-a-software-defined-radio-application-with-visual-signal-path/) - [ ] [AVARE ADS-B Receiver for Android Updated](https://www.rtl-sdr.com/avare-ads-b-receiver-for-android-updated/) - [ ] [FoxSDR: A From-Scratch Software-Defined Radio Receiver for Windows](https://www.rtl-sdr.com/foxsdr-a-from-scratch-software-defined-radio-receiver-for-windows/) - Shostack & Friends Blog - [ ] [Threat Modeling Intensive with Complete AI: From a Developer's POV](https://shostack.org/blog/threat-modeling-from-a-software-pov/) - 奇客Solidot–传递最新科技情报 - [ ] [夜晚睡眠光照太亮可能会损伤心脏](https://www.solidot.org/story?sid=85388) - [ ] [出于兴趣阅读有助于促进终身的身心健康](https://www.solidot.org/story?sid=85387) - [ ] [英国殖民之前的澳大利亚原居民人口约 222 万](https://www.solidot.org/story?sid=85386) - [ ] [F-Droid 上的应用有多少是在 AI 帮助下编写的?](https://www.solidot.org/story?sid=85385) - [ ] [廉价太阳能改变世界能源格局](https://www.solidot.org/story?sid=85384) - [ ] [一款在浏览器里运行、部署在自己服务器上的 SQL 客户端](https://www.solidot.org/story?sid=85383) - [ ] [美国军方首次证实在太空部署了武器](https://www.solidot.org/story?sid=85382) - [ ] [科学家演示水下太阳能电池](https://www.solidot.org/story?sid=85381) - [ ] [Steam Frame 起售价 1059 美元](https://www.solidot.org/story?sid=85380) - [ ] [NVIDIA中国开发者日定档10月苏州,现场设认证考试与黑客松决赛](https://www.solidot.org/story?sid=85379) - [ ] [Windows 11 的 9 月例行安全更新再次引发了大量故障](https://www.solidot.org/story?sid=85378) - [ ] [XCancel 服务再次下线](https://www.solidot.org/story?sid=85377) - HackerNews - [ ] [黑客针对暴露的 Vite 开发服务器窃取 AWS、Azure 机密信息](http://0.0.0.0:8080/post/64685) - [ ] [安装量达 3 万的 Twitch 扩展泄露用户 OAuth 令牌](http://0.0.0.0:8080/post/64684) - [ ] [日本数字厅称 VPN 漏洞泄露 24.6 万条人员记录](http://0.0.0.0:8080/post/64683) - [ ] [Telegram Desktop 缺陷允许隐藏 JavaScript 从 HTML 导出文件中窃取消息](http://0.0.0.0:8080/post/64682) - [ ] [新型 DDRop 攻击攻破 Intel TDX 和 AMD SEV-SNP 机密计算](http://0.0.0.0:8080/post/64681) - [ ] [3BB 攻击者利用 MeshCentral 后门获取 root 权限,目标是用户凭据](http://0.0.0.0:8080/post/64680) - 黑海洋Wiki | AI机器人硬件开发 | 网络安全攻防实战 | 区块链技术文档教程 - 免费资源平台 - [ ] [又一位研究员发布离职警告 谷歌前员工:AI可能害死所有人](https://blog.upx8.com/%E5%8F%88%E4%B8%80%E4%BD%8D%E7%A0%94%E7%A9%B6%E5%91%98%E5%8F%91%E5%B8%83%E7%A6%BB%E8%81%8C%E8%AD%A6%E5%91%8A-%E8%B0%B7%E6%AD%8C%E5%89%8D%E5%91%98%E5%B7%A5-AI%E5%8F%AF%E8%83%BD%E5%AE%B3%E6%AD%BB%E6%89%80%E6%9C%89%E4%BA%BA) - [ ] [美军首次证实已在轨道上部署武器](https://blog.upx8.com/%E7%BE%8E%E5%86%9B%E9%A6%96%E6%AC%A1%E8%AF%81%E5%AE%9E%E5%B7%B2%E5%9C%A8%E8%BD%A8%E9%81%93%E4%B8%8A%E9%83%A8%E7%BD%B2%E6%AD%A6%E5%99%A8) - [ ] [白宫科技顾问抨击美AI巨头:你们自己得保证产品安全 别老想着靠政府](https://blog.upx8.com/%E7%99%BD%E5%AE%AB%E7%A7%91%E6%8A%80%E9%A1%BE%E9%97%AE%E6%8A%A8%E5%87%BB%E7%BE%8EAI%E5%B7%A8%E5%A4%B4-%E4%BD%A0%E4%BB%AC%E8%87%AA%E5%B7%B1%E5%BE%97%E4%BF%9D%E8%AF%81%E4%BA%A7%E5%93%81%E5%AE%89%E5%85%A8-%E5%88%AB%E8%80%81%E6%83%B3%E7%9D%80%E9%9D%A0%E6%94%BF%E5%BA%9C) - [ ] [中国应届毕业生求职难:就业市场饱和叠加人工智能冲击](https://blog.upx8.com/%E4%B8%AD%E5%9B%BD%E5%BA%94%E5%B1%8A%E6%AF%95%E4%B8%9A%E7%94%9F%E6%B1%82%E8%81%8C%E9%9A%BE-%E5%B0%B1%E4%B8%9A%E5%B8%82%E5%9C%BA%E9%A5%B1%E5%92%8C%E5%8F%A0%E5%8A%A0%E4%BA%BA%E5%B7%A5%E6%99%BA%E8%83%BD%E5%86%B2%E5%87%BB) - [ ] [美司法部称百万伊朗石油收益通过币安洗钱](https://blog.upx8.com/%E7%BE%8E%E5%8F%B8%E6%B3%95%E9%83%A8%E7%A7%B0%E7%99%BE%E4%B8%87%E4%BC%8A%E6%9C%97%E7%9F%B3%E6%B2%B9%E6%94%B6%E7%9B%8A%E9%80%9A%E8%BF%87%E5%B8%81%E5%AE%89%E6%B4%97%E9%92%B1) - [ ] [Steam Frame头显正式发布 1059美元起](https://blog.upx8.com/Steam-Frame%E5%A4%B4%E6%98%BE%E6%AD%A3%E5%BC%8F%E5%8F%91%E5%B8%83-1059%E7%BE%8E%E5%85%83%E8%B5%B7) - [ ] [亚马逊Prime Video推新闻短片叫板TikTok](https://blog.upx8.com/%E4%BA%9A%E9%A9%AC%E9%80%8APrime-Video%E6%8E%A8%E6%96%B0%E9%97%BB%E7%9F%AD%E7%89%87%E5%8F%AB%E6%9D%BFTikTok) - [ ] [甲骨文据称已启动新一轮裁员 部分团队被裁比例达到两位数](https://blog.upx8.com/%E7%94%B2%E9%AA%A8%E6%96%87%E6%8D%AE%E7%A7%B0%E5%B7%B2%E5%90%AF%E5%8A%A8%E6%96%B0%E4%B8%80%E8%BD%AE%E8%A3%81%E5%91%98-%E9%83%A8%E5%88%86%E5%9B%A2%E9%98%9F%E8%A2%AB%E8%A3%81%E6%AF%94%E4%BE%8B%E8%BE%BE%E5%88%B0%E4%B8%A4%E4%BD%8D%E6%95%B0) - [ ] [美参议院酝酿AI监管立法:要求AI公司证明已采取安全措施防止伤害](https://blog.upx8.com/%E7%BE%8E%E5%8F%82%E8%AE%AE%E9%99%A2%E9%85%9D%E9%85%BFAI%E7%9B%91%E7%AE%A1%E7%AB%8B%E6%B3%95-%E8%A6%81%E6%B1%82AI%E5%85%AC%E5%8F%B8%E8%AF%81%E6%98%8E%E5%B7%B2%E9%87%87%E5%8F%96%E5%AE%89%E5%85%A8%E6%8E%AA%E6%96%BD%E9%98%B2%E6%AD%A2%E4%BC%A4%E5%AE%B3) - [ ] [Anthropic进军金融顾问市场 推出新工具](https://blog.upx8.com/Anthropic%E8%BF%9B%E5%86%9B%E9%87%91%E8%9E%8D%E9%A1%BE%E9%97%AE%E5%B8%82%E5%9C%BA-%E6%8E%A8%E5%87%BA%E6%96%B0%E5%B7%A5%E5%85%B7) - 威努特安全网络 - [ ] [集团分支越多,安全风险越大?威努特给出一体化方案](https://mp.weixin.qq.com/s?__biz=MzAwNTgyODU3NQ==&mid=2651144091&idx=1&sn=ef35fe3b0b28fc4a77eb35a6c99a027e) - 黑鸟 - [ ] [朝鲜IT远程工作战术升级:跨境招募绕过风控](https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451188777&idx=1&sn=9fce50553941fc03c79980c7fa3ab062) - 网安志异 - [ ] [数学家的数学,还是数学的数学?](https://mp.weixin.qq.com/s?__biz=MzAxNzYyNzMyNg==&mid=2664232853&idx=1&sn=7ea5ea2ff05dbd44abb84b7951fdb310) - [ ] [数学是什么?](https://mp.weixin.qq.com/s?__biz=MzAxNzYyNzMyNg==&mid=2664232853&idx=2&sn=ba711ebfe4f4e1d800860105ac6c281f) - 安全分析与研究 - [ ] [FDE工程实战05-客户交付与模式沉淀](https://mp.weixin.qq.com/s?__biz=MzA4ODEyODA3MQ==&mid=2247497154&idx=1&sn=c9f422632d62bf38174fa2b088a9dbe3) - vivo千镜 - [ ] [vivo 通过ISO漏洞管理体系认证,漏洞治理全面接轨国际标准](https://mp.weixin.qq.com/s?__biz=MzI0Njg4NzE3MQ==&mid=2247492424&idx=1&sn=ddf6fff159e06459eeb6f3daf07d5d3d) - 看雪学苑 - [ ] [SDC2026·安全训练营报名开启!直击固件、AI 攻防、Android 逆向](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458620413&idx=1&sn=428e84150cf637b0e9b8d8ebf058b50f) - [ ] [安卓ACE反作弊拉黑设备机制技术解析](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458620413&idx=2&sn=8845e3d839e35c55394911375ee298b5) - [ ] [高危漏洞潜伏2年!Telegram导出文件暗藏窃密后门,旧文档至今危险](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458620413&idx=3&sn=48a06d747ea585125c655237ecec878c) - 安全客 - [ ] [AI已经开始自动打你了:Anthropic捅破窗户纸,黑客用Claude实现"检测即重生"](https://mp.weixin.qq.com/s?__biz=MzA5ODA0NDE2MA==&mid=2649790476&idx=1&sn=259ec76a2dc788f984e054bb78b54e1f) - 奇安信威胁情报中心 - [ ] [Cyclops Blink 卷土重来:沉寂四年后再升级,Sandworm 模块化植入体现身 Cisco 防火墙管理中心](https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247520420&idx=1&sn=fa97b272ba8e38d318ef6721a59c5b10) - 奇安信 CERT - [ ] [【已复现】搜狗输入法 Windows 版远程代码执行漏洞(CVE-2026-51990)安全风险通告](https://mp.weixin.qq.com/s?__biz=MzU5NDgxODU1MQ==&mid=2247507611&idx=1&sn=e76659ca3884261ca6e4af22710cb167) - 安全圈 - [ ] [【安全圈】DeepSeek又崩了!!!](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078938&idx=1&sn=c5c5b2a63e54a1113a078fcee36f047a) - 补天平台 - [ ] [《AI 时代,白帽进阶:补天沙龙成都站议题精华抢先看!》](https://mp.weixin.qq.com/s?__biz=MzI2NzY5MDI3NQ==&mid=2247511045&idx=1&sn=9ef0ff8a0241ce57b4a196a8fbcecff7) - 微步在线 - [ ] [微步收购主流AI渗透工具CyberStrikeAI](https://mp.weixin.qq.com/s?__biz=MzI5NjA0NjI5MQ==&mid=2650188078&idx=1&sn=d57338f080a0c7d41b16094080ab906e) - 极客公园 - [ ] [在飞书的上下文底座上,豆包开工了](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653113628&idx=1&sn=dfdf0f7a300cb13179445a543c369ced) - [ ] [对话小宇宙 kyth:播客的护城河是真实,AI 无法取代的是人的立场](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653113576&idx=1&sn=eb6fa0af13ee2ed5bc1057ce88b202c8) - [ ] [iOS 27、MacOS 27 正式发布;豆包手机助手消费者版亮相;李想:「大车」趋势一定会结束 | 极客早知道](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653113565&idx=1&sn=a8850001e818966b020623026d7cbef1) - 安全牛 - [ ] [Anthropic主动踩刹车,AI落地团队该醒醒了:模型聪明≠敢让它碰核心系统](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142730&idx=1&sn=5a5ac466370969789abc0eb2c54946c8) - [ ] [网安标委发布《人工智能安全治理框架3.0》,风险分类与技术应对措施同步更新;CNVD发布2026年第36期漏洞周报| 牛览](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142730&idx=2&sn=1b5184c30967d3d8dc83d1996adfe06b) - 青藤云安全 - [ ] [深度报告 | NIST CSF 2.0,给 AI 一把安全标尺](https://mp.weixin.qq.com/s?__biz=MzAwNDE4Mzc1NA==&mid=2650851857&idx=1&sn=c440d38a99344ead7ca2afa307eff8d3) - 数世咨询 - [ ] [Debian 13.7 修复 92 项安全公告涉及问题,更新 106 个软件包](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247543905&idx=1&sn=074bf9ce52a52f1aa52fa2cf51d0bccc) - [ ] [直播预热:ASIC芯片的硬核极致打磨之路](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247543905&idx=2&sn=cf9b292b35fc2a72b1272f920049f4ac) - 安全内参 - [ ] [AI已成网络犯罪“核动力”?Anthropic警告黑客组织滥用AI进度惊人](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516598&idx=1&sn=7065f075905a219b4ed6ef61a4335a5b) - [ ] [欧盟《数据法》迎来关键节点:新上市连接产品必须“默认支持用户访问数据”](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516598&idx=2&sn=fbb62480d771378a662b4b4f2579ad42) - CNVD漏洞平台 - [ ] [2025年度CNVD优秀单位(个人)名单](https://mp.weixin.qq.com/s?__biz=MzU3ODM2NTg2Mg==&mid=2247497365&idx=1&sn=157360bcf4c8fc6439fadc347b915683) - 安全419 - [ ] [AI 向善 安全有道|2026 CCS 启幕 多维共探智能时代网安新范式](https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&mid=2247555004&idx=1&sn=df8849c9cbe3ed3659747a82a34c3518) - 网络空间安全科学学报 - [ ] [2026年网络空间安全学术会议注册早鸟票延期通知](https://mp.weixin.qq.com/s?__biz=MzI0NjU2NDMwNQ==&mid=2247508693&idx=1&sn=00cc38b00ff11dd37ac384f361e99ea1) - 360数字安全 - [ ] [CCS 2026成都网络安全技术交流活动启幕,360破解智能体规模应用必答题!](https://mp.weixin.qq.com/s?__biz=MzA4MTg0MDQ4Nw==&mid=2247586896&idx=1&sn=1e5665a04adb8216f42d05a53591b305) - [ ] [香港政府及业界代表团到访360数字安全集团参观交流](https://mp.weixin.qq.com/s?__biz=MzA4MTg0MDQ4Nw==&mid=2247586896&idx=2&sn=ef5959e02a2cdaac6faaeeb073fa918a) - 字节跳动技术团队 - [ ] [飞连,让豆包工作更安全办公](https://mp.weixin.qq.com/s?__biz=MzI1MzYzMjE0MQ==&mid=2247522397&idx=1&sn=c787c3b15a18e9d64fcf1280f127b958) - Qualys Security Blog - [ ] [Before You Patch. Why Patch Reliability Matters for Confident Deployment](https://blog.qualys.com/category/product-tech) - [ ] [Automate Asset Isolation: Your Last Resort to Meet Remediation Deadlines](https://blog.qualys.com/category/product-tech) - ICT Security Magazine - [ ] [Richieste dell’autorità contraffatte: il caso Revolut e la verifica delle istanze](https://www.ictsecuritymagazine.com/notizie/richieste-dati-contraffatte-autorita-caso-revolut/) - [ ] [DDRop, un interposer da 159 dollari rimette in discussione le garanzie del confidential computing](https://www.ictsecuritymagazine.com/notizie/ddrop-confidential-computing-intel/) - JUMPSEC - [ ] [An emerging Silver Fox-like cluster: PAPERMILL](https://www.jumpsec.com/guides/an-emerging-silver-fox-like-cluster-papermill/) - 国家互联网应急中心CNCERT - [ ] [CNVD漏洞周报2026年第36期](https://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw==&mid=2247502165&idx=1&sn=f76897a4faed11bffee8aada736cb34b) - 火绒安全 - [ ] [采购文件暗藏杀机——PureRAT木马针对电商定向窃密](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247537496&idx=1&sn=8d47c16e350caf59e3306701ea2a21c8) - [ ] [诚邀渠道合作伙伴共启新征程](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247537496&idx=2&sn=fb35a0a25037c93f6159f0129c4df3fe) - Over Security - [ ] [Threat Hunting and Defending #2: concepts, framework, Threat Model (p3)](https://roccosicilia.com/2026/09/13/threat-hunting-and-defending-2-concepts-framework-threat-model-p3/) - [ ] [CenterPoint Energy confirms customer data stolen in cyberattack](https://www.bleepingcomputer.com/news/security/centerpoint-energy-confirms-customer-data-stolen-in-cyberattack/) - [ ] [Sensoristica IIoT e monitoraggio energetico: strategie per un’integrazione sicura nelle reti industriali](https://www.cybersecurity360.it/soluzioni-aziendali/sensoristica-iiot-e-monitoraggio-energetico-strategie-per-unintegrazione-sicura-nelle-reti-industriali/) - [ ] [Iranian cyber spies used fake MRI scan results to hack ‘enemy of regime’](https://therecord.media/iran-cyber-spies-use-fake-mri-scans-as-lure) - [ ] [Accessi remoti dei fornitori: governance e tracciabilità nei siti produttivi distribuiti](https://www.cybersecurity360.it/soluzioni-aziendali/accessi-remoti-dei-fornitori-governance-e-tracciabilita-nei-siti-produttivi-distribuiti/) - [ ] [Zelensky appoints former police chief to lead Ukraine’s cyber coordination center](https://therecord.media/ukraine-cyber-coordination-center-ihor-klymenko) - [ ] [BambooToken malware controls Windows and Linux systems via MQTT](https://www.bleepingcomputer.com/news/security/bambootoken-malware-controls-windows-and-linux-systems-via-mqtt/) - [ ] [Simulazioni di phishing: non misuriamo chi sbaglia, ma quanto regge il sistema](https://www.cybersecurity360.it/soluzioni-aziendali/simulazioni-di-phishing-non-misuriamo-chi-sbaglia-ma-quanto-regge-il-sistema/) - [ ] [Sanzione privacy a BBVA: quando il CRM vanifica il diritto di opposizione](https://www.cybersecurity360.it/news/sanzione-privacy-a-bbva-quando-il-crm-vanifica-il-diritto-di-opposizione/) - [ ] [Hackers target WordPress sites via third-party WooCommerce plugin](https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-via-third-party-woocommerce-plugin/) - [ ] [Electric and gas utility CenterPoint Energy warns of data breach after dark web post](https://therecord.media/centerpoint-energy-data-breach) - [ ] [What Zero-Day Response Should Be in the Post-Mythos Era](https://www.bleepingcomputer.com/news/security/what-zero-day-response-should-be-in-the-post-mythos-era/) - [ ] [China spy chief points at US AI models in cyber threat warning](https://therecord.media/china-spy-chief-warns-of-us-ai-models) - [ ] [Manhattan DA takes down 12 AI deepfake porn sites](https://therecord.media/manhattan-da-takes-down-12-ai-deepfake-porn-sites) - [ ] [Cyber security, l’Europa investe 96 milioni: AI, resilienza e NIS2 tra le priorità](https://www.cybersecurity360.it/cybersecurity-nazionale/cyber-security-leuropa-investe-96-milioni-ai-resilienza-e-nis2-tra-le-priorita/) - [ ] [CISA: Critical VMware RCE flaw now exploited by ransomware gangs](https://www.bleepingcomputer.com/news/security/cisa-critical-vmware-vcenter-rce-flaw-now-exploited-by-ransomware-gangs/) - [ ] [Revolut Data Breach: Inside the Extortion Site](https://www.kelacyber.com/blog/revolut-data-breach/) - [ ] [I Migliori Progetti Open-Source Che Abbiamo Starrato a Settembre 2026](https://hackerstribe.com/2026/i-migliori-progetti-open-source-che-abbiamo-starrato-a-settembre-2026/) - [ ] [The Best Open-Source Projects We Starred in August 2026](https://hackerstribe.com/2026/the-best-open-source-projects-we-starred-in-august-2026/) - [ ] [Revolut: violati dati alto profilo, la pista porta al Viminale](https://www.cybersecurity360.it/nuove-minacce/revolut-violati-dati-alto-profilo-la-pista-porta-al-viminale/) - [ ] [Suspected Black Axe gang leaders face cybercrime charges in the US](https://www.bleepingcomputer.com/news/security/black-axe-gang-members-extradited-to-us-face-cybercrime-charges/) - [ ] [6 Months on Alert: Get H1 2026 Cyber Risk Report for SOCs and MSSPs](https://any.run/cybersecurity-blog/h1-2026-cyber-risk-report/) - [ ] [Proton VPN in offerta al 70%: trasparenza open source e audit no-log](https://www.cybersecurity360.it/cultura-cyber/proton-vpn-sconto-70-sicurezza-open-source/) - [ ] [Microsoft confirms KB5002914 Excel update breaks copy and paste](https://www.bleepingcomputer.com/news/microsoft/microsoft-september-kb5002914-security-update-breaks-excel-copy-and-paste/) - [ ] [4 in 5 Singapore Business Websites Have WordPress Vulnerabilities](https://thecyberexpress.com/wordpress-vulnerabilities-singapore-study/) - [ ] [Il “pulsante di aiuto” sui siti del Terzo settore: come progettarlo in linea con il GDPR](https://www.cybersecurity360.it/legal/privacy-dati-personali/il-pulsante-di-aiuto-sui-siti-del-terzo-settore-come-progettarlo-in-linea-con-il-gdpr/) - [ ] [Cisco patches Secure Email Gateway zero-day exploited in attacks](https://www.bleepingcomputer.com/news/security/new-cisco-secure-email-zero-day-exploited-to-execute-commands-as-root/) - [ ] [International Meteor Organization Hit by Cyberattack, Weeks of Disruption Expected](https://thecyberexpress.com/international-meteor-organization-cyberattack/) - [ ] [Nintendo Switch Flaw Lets Nearby Attackers Run Code, Steal Data](https://thecyberexpress.com/nintendo-switch-vulnerability/) - [ ] [UK Small Firms Bear Brunt of Rising Cyberattacks, Hiscox Finds](https://thecyberexpress.com/uk-cyberattack-rate-hits-38-among-small-firms/) - SANS Internet Storm Center, InfoCON: green - [ ] [MacOS 27 - First Boot, (Tue, Sep 15th)](https://isc.sans.edu/diary/rss/33340) - [ ] [ISC Stormcast For Tuesday, September 15th, 2026 https://isc.sans.edu/podcastdetail/10094, (Tue, Sep 15th)](https://isc.sans.edu/diary/rss/33338) - Tor Project blog - [ ] [New Release: Tor Browser 15.0.23](https://blog.torproject.org/new-release-tor-browser-15023/) - The Hacker News - [ ] [KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens](https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html) - [ ] [Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists](https://thehackernews.com/2026/09/iranian-hackers-use-telegram-controlled.html) - [ ] [BambooToken Malware Uses MQTT to Control Windows and Linux Systems](https://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.html) - [ ] [Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds](https://thehackernews.com/2026/09/human-attacker-exploits-marimo-rce.html) - [ ] [Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point](https://thehackernews.com/2026/09/attack-chains-not-just-attack-surfaces.html) - [ ] [Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers](https://thehackernews.com/2026/09/mass-scanning-campaign-exploits-vite.html) - [ ] [LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server](https://thehackernews.com/2026/09/litespeed-enterprise-flaw-could-let-one.html) - [ ] [Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution](https://thehackernews.com/2026/09/cisco-secure-email-gateway-flaw.html) - [ ] [China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE](https://thehackernews.com/2026/09/china-linked-hackers-exploit-chrome.html) - www.theregister.com - Articles - [ ] [The vulnpocalypse rains iBugs down on Apple with record-setting number of patches](https://www.theregister.com/security/2026/09/15/the-vulnpocalypse-rains-ibugs-down-on-apple-with-record-setting-number-of-patches/5296679) - [ ] [Low-quality casino sites conceal highly dangerous threat actors](https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652) - [ ] [Iranian spies hit Windows machines with Chosen Brick data-stealing malware](https://www.theregister.com/security/2026/09/15/iranian-spies-hit-windows-machines-with-chosen-brick-data-stealing-malware/5296646) - [ ] [Cisco email security boxes can be rooted by... an email](https://www.theregister.com/security/2026/09/15/cisco-email-security-boxes-can-be-rooted-by-an-email/5296604) - [ ] [Who's governing your AI? A trust framework for enterprise agents and models](https://www.theregister.com/security/2026/09/15/sponsored-whos-governing-your-ai-a-trust-framework-for-enterprise-agents-and-models/5294237) - [ ] [Swiss court sentences 52-year-old Ukrainian ransomware dev to nearly 13 years in the cooler](https://www.theregister.com/security/2026/09/15/swiss-court-sentences-52-year-old-ukrainian-ransomware-dev-to-nearly-13-years-in-the-cooler/5296482) - [ ] [The latest AI doomsayer is China’s intelligence boss](https://www.theregister.com/ai-and-ml/2026/09/15/the-latest-ai-doomsayer-is-chinas-intelligence-boss/5296451) - TorrentFreak - [ ] [Rep. Issa Files Competing U.S. Pirate Site Blocking Bill](https://torrentfreak.com/rep-issa-files-competing-u-s-pirate-site-blocking-bill/) - [ ] [Accused Impostor in Private Tracker Lawsuit Driven by Revenge, Defense Says](https://torrentfreak.com/accused-impostor-in-private-tracker-lawsuit-driven-by-revenge-defense-says/) - KitPloit - PenTest Tools! - [ ] [macnoise v1.0.0](https://kitploit.com/en/posts/github-0xv1n-macnoise-v100) - [ ] [django-DefectDojo v3.3.100](https://kitploit.com/en/posts/github-defectdojo-django-defectdojo-33100) - [ ] [reasongate v0.4.0](https://kitploit.com/en/posts/github-cgrtml-reasongate-v040) - [ ] [ziti v2.0.5](https://kitploit.com/en/posts/github-openziti-ziti-v205) - [ ] [sippts v4.2.1](https://kitploit.com/en/posts/github-pepelux-sippts-v421) - [ ] [zeek v9.0.0](https://kitploit.com/en/posts/github-zeek-zeek-v900) - [ ] [nuclei-burp-plugin v1.1.4](https://kitploit.com/en/posts/github-projectdiscovery-nuclei-burp-plugin-v114) - [ ] [IDAssist v2.4.0](https://kitploit.com/en/posts/github-symgraph-idassist-240) - [ ] [FACT_core v4.4.1](https://kitploit.com/en/posts/github-fkie-cad-fact_core-v441) - [ ] [BloodHound v9.7.1-rc1](https://kitploit.com/en/posts/github-specterops-bloodhound-v971-rc1) - [ ] [lava v3.3.1](https://kitploit.com/en/posts/github-panda-re-lava-v331) - [ ] [gowitness v3.2.0](https://kitploit.com/en/posts/github-sensepost-gowitness-320) - [ ] [stop-bots](https://kitploit.com/en/tools/github/ivankovic/stop-bots) - [ ] [tamarin-prover](https://kitploit.com/en/tools/github/tamarin-prover/tamarin-prover) - [ ] [OpenHunterAI](https://kitploit.com/en/tools/github/lumoslab-innovation/openhunterai) - [ ] [xalgorix](https://kitploit.com/en/tools/github/xalgorix/xalgorix) - [ ] [PEASS-ng v20260914-6273eb76](https://kitploit.com/en/posts/github-peass-ng-peass-ng-20260914-6273eb76) - [ ] [prismor v1.51.0](https://kitploit.com/en/posts/github-prismorsec-prismor-v1510) - [ ] [missing-cve-nuclei-templates v2026-09-14](https://kitploit.com/en/posts/github-edoardottt-missing-cve-nuclei-templates-2026-09-14) - [ ] [s3dns v0.2.30](https://kitploit.com/en/posts/github-olizimmermann-s3dns-v0230) - [ ] [MESH v0.2.0-beta](https://kitploit.com/en/posts/github-barghest-ngo-mesh-v020-beta) - [ ] [runeward](https://kitploit.com/en/tools/github/runewardd/runeward) - [ ] [dependency-track v4.14.4](https://kitploit.com/en/posts/github-dependencytrack-dependency-track-4144) - [ ] [Kage-DFIR-toolkit](https://kitploit.com/en/tools/github/karim852/kage-dfir-toolkit) - [ ] [KUMO-Domain-Recon-Tool](https://kitploit.com/en/tools/github/karim852/kumo-domain-recon-tool) - [ ] [hosts v3.16.114](https://kitploit.com/en/posts/github-stevenblack-hosts-316114) - [ ] [giskard-oss giskard-checks/v1.0.4](https://kitploit.com/en/posts/github-giskard-ai-giskard-oss-giskard-checksv104) - [ ] [WhoCord v1.2.1](https://kitploit.com/en/posts/github-siv-nick-whocord-v121) - [ ] [brook v20270101](https://kitploit.com/en/posts/github-txthinking-brook-v20270101) - [ ] [osv-scanner v2.6.0](https://kitploit.com/en/posts/github-google-osv-scanner-v260) - [ ] [warpgate v0.29.0-beta.1](https://kitploit.com/en/posts/github-warp-tech-warpgate-v0290-beta1) - [ ] [cowrie v3.0.14](https://kitploit.com/en/posts/github-cowrie-cowrie-v3014) - Deeplinks - [ ] [California: Tell the Governor to Stand Up for Net Neutrality, Affordability, and Public Safety](https://www.eff.org/deeplinks/2026/09/california-tell-governor-stand-net-neutrality-affordability-and-public-safety) - Schneier on Security - [ ] [25 Years of Mass Surveillance Is Enough](https://www.schneier.com/blog/archives/2026/09/25-years-of-mass-surveillance-is-enough.html) - [ ] [On the NSA’s Supercomputer from the 1960s](https://www.schneier.com/blog/archives/2026/09/on-the-nsas-supercomputer-from-the-1960s.html) - Security Affairs - [ ] [U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog](https://securityaffairs.com/199156/security/u-s-cisa-adds-cisco-secure-email-gateway-flaw-to-its-known-exploited-vulnerabilities-catalog.html) - [ ] [Cisco Warns of Ongoing Exploitation of Critical Email Gateway Zero-Day](https://securityaffairs.com/199137/hacking/cisco-warns-of-ongoing-exploitation-of-critical-email-gateway-zero-day.html) - [ ] [Shared Hosting at Risk: LiteSpeed Enterprise Bug Can Grant Root from a Single Tenant](https://securityaffairs.com/199127/security/shared-hosting-at-risk-litespeed-enterprise-bug-can-grant-root-from-a-single-tenant.html) - [ ] [One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire](https://securityaffairs.com/199104/apt/one-exploit-chain-two-espionage-campaigns-chrome-and-windows-under-fire.html) - [ ] [Telegram Desktop Flaw Could Turn Old Chat Exports Into Data Theft Traps](https://securityaffairs.com/199076/security/telegram-desktop-flaw-could-turn-old-chat-exports-into-data-theft-traps.html) - [ ] [Non-Zero-Day VPN Flaw Left Japan ‘s Government Shared Network Platform Exposed: 246,000 Records at Risk](https://securityaffairs.com/199090/security/non-zero-day-vpn-flaw-left-japan-government-shared-network-platform-exposed-246000-records-at-risk.html) - Security Weekly Podcast Network (Audio) - [ ] [RoboGators, HBOMAX, Microsoft, DAS, Horsebot 3000, Aaran Leyland does AI, and More - SWN #616](http://sites.libsyn.com/18678/robogators-hbomax-microsoft-das-horsebot-3000-aaran-leyland-does-ai-and-more-swn-616) - [ ] [The AI Threat Multiplier: Securing Mobile Apps in the Automated Era - Ryan Lloyd, Jason Cortlund - ASW #400](http://sites.libsyn.com/18678/the-ai-threat-multiplier-securing-mobile-apps-in-the-automated-era-ryan-lloyd-jason-cortlund-asw-400)
每日安全资讯(2026-09-16)