# 每日安全资讯(2026-09-17) - SecWiki News - [ ] [SecWiki News 2026-09-16 Review](http://www.sec-wiki.com/?2026-09-16) - 先知安全技术社区 - [ ] [政务 RAG 白盒审计:4 类真实缺陷的发现、复现与零回归修复](https://xz.aliyun.com/news/92848) - [ ] [x32游戏逆向-列表类数据定位:从背包、仓库到周围 NPC](https://xz.aliyun.com/news/92844) - [ ] [游戏逆向之手搓封包工具思路](https://xz.aliyun.com/news/92842) - [ ] [一条 exec 如何穿过沙箱:DeepSeek Harness QVD-2026-52646 漏洞与安全模型分析](https://xz.aliyun.com/news/92841) - Recent Commits to cve:main - [ ] [Update Wed Sep 16 12:19:54 UTC 2026](https://github.com/trickest/cve/commit/0925f1fd50b79b2898d38d32ef9530eb63dbda50) - 安全客-有思想的安全新媒体 - [ ] [Cisco邮件网关9.8分漏洞被在野利用:一封邮件直接拿root,没有任何绕过的余地](https://www.anquanke.com/post/id/316111) - Doonsec's feed - [ ] [孙宇晨又发小作文了:《我为什么要设立孙宇晨奖》](https://mp.weixin.qq.com/s/2ZZiCrrb1W4SWNVfZ_yMzQ) - [ ] [德国军工巨头把作战系统核心接口开源了](https://mp.weixin.qq.com/s/DBL-ZiPdsb3_-vTgtLTKog) - [ ] [刷到一条长鑫存储的薪资爆料,着实有点被惊到了。网传是上海的技术岗,税前基本工资每月57000元,年终奖按4个月基本工资来核算。](https://mp.weixin.qq.com/s/72CSqjbtv29-LeVEnWJjBw) - [ ] [7100亿!43岁张一鸣,首次坐上亚洲首富](https://mp.weixin.qq.com/s/df31Ajkg3GDe4XGygkKZJA) - [ ] [DeepSeek工程师《我不得不把才华埋葬在昨天》刷屏与回应](https://mp.weixin.qq.com/s/4eFsESmHqzGZ9acYOjnF1g) - [ ] [圈子限时优惠活动(公众号关注福利)](https://mp.weixin.qq.com/s/fcuiFQbzWFIB8u5AIXFO-Q) - [ ] [GPT-6 Astra「白嫖入口」马上蹬!!!](https://mp.weixin.qq.com/s/Uoh2y-dNly4TQPAwcu9eJw) - [ ] [国家网络安全宣传周|富滇银行先手布局国家网络身份认证公共服务](https://mp.weixin.qq.com/s/UUUY_mO9JquS_1AIIrSJTQ) - [ ] [还在等什么?黑盒漏洞挖掘agent等你来收货](https://mp.weixin.qq.com/s/Mkn-yWDWJmZ8x8q_MVUQUA) - [ ] [2026年国家网络安全宣传周汽车数据安全论坛在济南举办](https://mp.weixin.qq.com/s/en91jjbz2b2YTnkY9VuJkQ) - [ ] [全球安全动态日报|20260916|早](https://mp.weixin.qq.com/s/KHx7IdSGYSw0Q4idmzvlig) - [ ] [CCS2026 | AI向善 安全有道 2026CCS正式启动,多维共探智能时代网安新范式](https://mp.weixin.qq.com/s/FFskw-6dzcpOslz5lXt4eg) - [ ] [聚焦 | 全国网络安全标准化技术委员会2026年第二次“标准周”活动在济南举办](https://mp.weixin.qq.com/s/95KIXA7Fa0H4PuQaHWG0fw) - [ ] [发布 | 最高法发布人民法院网络法治典型案例](https://mp.weixin.qq.com/s/i4Kwv3y2weIzkUb1KKpAwA) - [ ] [专家解读 | 沈彬华:以统一数据产权登记体系 推动全国一体化数据市场建设](https://mp.weixin.qq.com/s/jxISzAVE9nDu5CiVEp4oLQ) - [ ] [评论 | 以监督检查筑牢网络空间安全屏障](https://mp.weixin.qq.com/s/2H6VRMsITNZ5DIiCzkP73g) - [ ] [提示词写得再严,为什么仍挡不住所有提示注入?](https://mp.weixin.qq.com/s/xrb3yIz32PaYw1jimvP_Kg) - [ ] [EDR检测体系与静态分析](https://mp.weixin.qq.com/s/rRlzksN00IfnaNJ5zQ5M_w) - [ ] [国家网络安全宣传周|云南高校首家!使用网号网证筑牢校园数字安全防线](https://mp.weixin.qq.com/s/Wnb5VVfdr8bUmiKipLujjA) - [ ] [习近平总书记给福建省“漳州110”全体队员的回信引发热烈反响](https://mp.weixin.qq.com/s/P0zYXLkkH1rtFER1WJHCvw) - [ ] [今年的网络安全有点不一样了?3个月从零到渗透的完整路线](https://mp.weixin.qq.com/s/TqadQyFinFTy7d59Qhx9mw) - [ ] [AI 已成为网络安全新增预算的首要驱动力](https://mp.weixin.qq.com/s/Oe6OJtcsT-qZgEEyiNcpfA) - [ ] [企业数据安全:影子 AI,正在\"偷\"走你的数据?](https://mp.weixin.qq.com/s/Y1taGuxAeis3Pkx4FZTLCA) - [ ] [众测 30 分钟挖到鸿蒙App高危上传漏洞 | 从 APP 一条异常图片请求,发现被忽略的外围攻击面](https://mp.weixin.qq.com/s/g7C_-SkNwavzz5K3kODpsg) - [ ] [挖了半年SRC颗粒无收](https://mp.weixin.qq.com/s/RlBdK4VWw48DlC6khWc00Q) - [ ] [网安标委2026第二次“标准周” | 华为发表《面向人工智能的网络安全技术与产品标准化研究》课题报告](https://mp.weixin.qq.com/s/rKr0bC91QsYkkS84QKds9Q) - [ ] [华为全联接大会2026丨逛展免费领!《漫谈SD-WAN》实体书,手慢无!](https://mp.weixin.qq.com/s/Q4fg05JsEgra2JOD8NSUAw) - [ ] [重磅|对抗AI换脸,网易智企拿下信通院\"卓越级\"首证!](https://mp.weixin.qq.com/s/hgnjEe2G-9MozFOtFYRvOg) - [ ] [民航局、国家数据局联合印发《民航数据治理体系建设实施方案》](https://mp.weixin.qq.com/s/Ebmnrpw6xl1eHVlbHPLoUg) - [ ] [一图读懂|《民航数据治理体系建设实施方案》](https://mp.weixin.qq.com/s/OgKsMg56fnqImqAtZQ1xaA) - [ ] [连续5年!威胁猎人再获vivo“最佳安全技术合作伙伴”](https://mp.weixin.qq.com/s/b1Yjy1X0YKNlBubB9q0XwA) - [ ] [已复现 | Langflow post-auth RCE](https://mp.weixin.qq.com/s/A0h3oCFG6EB8TEomt5Pxbw) - [ ] [又是一年网络安全周:回头看中国网络安全这些年的重要节点](https://mp.weixin.qq.com/s/V_EYzJ2pYj-XZXpmZj6GKw) - [ ] [2026 网安周|奇安信在国家级AI赋能网络安全应用测试中获双第一](https://mp.weixin.qq.com/s/j9TtcmsWIdC_sRJ887kosQ) - [ ] [cPanel:LiteSpeed Web Server 企业版严重漏洞可导致提权](https://mp.weixin.qq.com/s/Hg5KbPZeA24zDtKcHWI9Pg) - [ ] [奇安信即将亮相中东地区最具影响力的网络安全盛会——GISECxa0Global 2026](https://mp.weixin.qq.com/s/7HuwDyWROxv9UZTygdfVIA) - [ ] [观安观鉴沙箱管理平台|打造安全分析专属隔离执行底座](https://mp.weixin.qq.com/s/jNT41ISBV-gO1mSOVNX88w) - [ ] [聚铭网络入选2026年度连云港市网络和数据安全应急支撑服务机构并获授牌](https://mp.weixin.qq.com/s/JtsYqlGpEgP3z1D9_K6Kog) - [ ] [网络安全动态 - 2026.9.16](https://mp.weixin.qq.com/s/D6CaRnEq1AbXGKkUZnatOw) - [ ] [安全419|一周国际网安资讯:微软974个补丁创纪录 FMC零日引爆勒索攻击](https://mp.weixin.qq.com/s/8LPyHbySExj9kcnTu1VLrQ) - [ ] [邀请函丨2026上海网络安全产业创新推进会](https://mp.weixin.qq.com/s/o4PW4N_5QYnelADvE8t91w) - [ ] [技术护航,实战育人:骐跃信息承办2026年银川市“网信杯”网络安全技能大赛纪实](https://mp.weixin.qq.com/s/RIhutn69OEjc7VKqtmWVEA) - [ ] [答题赢平板,通关领AI安全证书——深信服数智安全大赛,全民可参与!](https://mp.weixin.qq.com/s/Zu1mqO_hoDi9Eg4O1xxR5g) - [ ] [病毒库也有“保质期” ,国家安全机关发布提示](https://mp.weixin.qq.com/s/oPLeQxlL-4BYzujLKjcEdg) - [ ] [《暗网监测2025年度报告》正式发布](https://mp.weixin.qq.com/s/Tp58JMfM7nbga8MigG_3kA) - [ ] [《人工智能应用安全指引 总则》等4项网络安全标准实践指南发布](https://mp.weixin.qq.com/s/JiNbHWIpLY8tUp2o3GrB5A) - [ ] [中文互联网基础语料4.0等三类高质量数据集正式发布](https://mp.weixin.qq.com/s/2iA8qGDkj9pd4B4S65UM9g) - [ ] [国家网信办发布近期网络安全、数据安全、个人信息保护等领域执法典型案例](https://mp.weixin.qq.com/s/zLIF1hNq1eQALWObki4t_Q) - [ ] [中孚信息在2026网安周发布AI安全产品矩阵,“1+2+3”智能安全新体系同步亮相](https://mp.weixin.qq.com/s/da-e-_iQCalYGQHJLWsdaQ) - [ ] [喜报|中孚信息入围2026山东民营企业创新100强!](https://mp.weixin.qq.com/s/G8TpL-rSMT7RgappiIDxEQ) - [ ] [2026网安周 | 启明星辰以硬核实力斩获多项权威荣誉!](https://mp.weixin.qq.com/s/64QlOKmQlYdFqie603PE_g) - [ ] [【活动预告】ISC2北京分会线上技术分享会丨FDE工程师的自我修养](https://mp.weixin.qq.com/s/r2mdGVYFFxeKFD_V2uCy0Q) - [ ] [ThinkPHP框架:2.x-8.x全版本必须知道的10个通用漏洞(附实战getshell案例)](https://mp.weixin.qq.com/s/dhG4uwa_zWI_Ng_7wmt-ZQ) - [ ] [搜狗输入法 Windows 版远程代码执行漏洞(CVE-2026-51990)](https://mp.weixin.qq.com/s/di-2_6CBcmYkiEy_lFw8dA) - [ ] [AI手机安全实测:当“帮我操作手机”也可能被利用](https://mp.weixin.qq.com/s/qhqPiyWvqYQmGQ0aAgalYw) - [ ] [Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability(CVE-2026-85893)](https://mp.weixin.qq.com/s/dmvcbKBWuy1bldoNOLSDaA) - [ ] [AI逆向SKILL技能路由包,一键搞定脱壳分析、渗透测试与CTF竞赛全场景、适配Frida/IDA/Ghidra](https://mp.weixin.qq.com/s/2t8x6rsi8RFACbWjADSvIg) - [ ] [国家网络安全宣传周|别上当](https://mp.weixin.qq.com/s/1tiChqukLCTca9G-RT2P-g) - [ ] [考证别等双11,双节已经提前放“价”了](https://mp.weixin.qq.com/s/9NkbwWA73sHfBAdEUkxUkA) - [ ] [常见Web安全技术总结!474页Web安全从入门到精通(附PDF)](https://mp.weixin.qq.com/s/FIV_oyZDB47XCCcWAZPq_g) - [ ] [华顺信安荣获CNVD“2025年度漏洞应急工作突出贡献单位”](https://mp.weixin.qq.com/s/HfmWdQkKsppP8Y_4akp8Ww) - [ ] [惊!微信电话一响,账号可能就没了?AI两天造出零点击蠕虫,iOS安卓全中招!](https://mp.weixin.qq.com/s/p8UEQ9IQE7CBN4UUGiuH4Q) - [ ] [梆梆安全参编《移动互联网应用安全统计分析报告(2026)》,助力构建协同共治生态](https://mp.weixin.qq.com/s/vJWkw9h_vgfkn0btWeBCGw) - [ ] [安全简讯(2026.09.16)](https://mp.weixin.qq.com/s/jAyxGfGkgRXR6YSeeMvWtg) - [ ] [【漏洞通告】Oracle WebLogic Server未授权远程接管漏洞(CVE-2026-70756)](https://mp.weixin.qq.com/s/UAywPSxyEDaHD9XkWZ93QQ) - [ ] [实战练兵!第九届“精武杯”电子数据取证比武,等你来挑战!](https://mp.weixin.qq.com/s/FarHPkFu1F1Tjv4kTBWmtg) - [ ] [斗象 × MiniMax发糖了,这对CP向安全研究员撒千万Token](https://mp.weixin.qq.com/s/tLRjSO2w6NM1m6nTjB_cQg) - [ ] [TCP的意义是什么?](https://mp.weixin.qq.com/s/Dhexn-fPbUaiKSbDFNFtTQ) - [ ] [火绒企业版2.0功能升级|跨平台漏洞检测上线 查杀支持断点续杀](https://mp.weixin.qq.com/s/7NUR-THvCuqWIiNtFBt6yA) - [ ] [爱企查 + 8 个引擎联合查询:企业资产底裤级收集方案](https://mp.weixin.qq.com/s/pRsQR9vc4my-r1rvLa918Q) - [ ] [火绒小问答--「个人版」近期top问题解答](https://mp.weixin.qq.com/s/Bh160YhZEuWWkUX3hEZwSQ) - [ ] [诚邀渠道合作伙伴共启新征程](https://mp.weixin.qq.com/s/6w9_ygphNuheJhCt0qqQBA) - [ ] [美国贸易代表办公室联合多部门推进全球强迫劳动进口禁令](https://mp.weixin.qq.com/s/8MQe1uKy5KKSOFn-Vah8eg) - [ ] [全球人工智能系统网络安全研究态势与关键空白](https://mp.weixin.qq.com/s/_ztycdsZ42oM1BNQUUVOyQ) - [ ] [浏览器的\"信任\"被伪造:KREMLIN 攻破 Chrome 完整性校验,1500+ 巴西网银主机沦陷](https://mp.weixin.qq.com/s/tBCeWn20eyNRRvHgN5ipHA) - [ ] [以攻促防 智御未来 | 四叶草安全2027校园招聘](https://mp.weixin.qq.com/s/4MA9E7cSyoO15z3uLRlfXg) - [ ] [网安人有自己的作业帮,这波真的赢麻了!](https://mp.weixin.qq.com/s/R3QqHYLaACs9WlfXvLj0lQ) - [ ] [国家网络安全宣传周|从前有一匹小马......](https://mp.weixin.qq.com/s/PaWoWl8BCQTOJrDRJf-a5A) - [ ] [雷神众测漏洞周报2026.9.7-2026.9.13](https://mp.weixin.qq.com/s/PzQm7pYMyOaTKL6Fzh9vnQ) - [ ] [一句话“骗”过AI 警惕“提示词注入”攻击风险!](https://mp.weixin.qq.com/s/EWiRTZBt-u7KWNr00Ge9tw) - [ ] [TOM集团:正就数据安全事件对业务及营运影响展开全面评估](https://mp.weixin.qq.com/s/Ckartga5IrsjwTiLK6neSA) - [ ] [Android逆向密码学基础:HEX/Base64/MD5识别与MessageDigest通杀Hook](https://mp.weixin.qq.com/s/C0YObLaoWTFZjXZRkCZ4kA) - [ ] [湖北省网络和数据安全协会党支部召开树立和践行正确政绩观学习教育总结会](https://mp.weixin.qq.com/s/nujSn1uk2ZApoba46S53gw) - [ ] [发扬党内民主xa0规范推选担使命|省网数协会党支部圆满完成上级党工委党代表候选人推荐及参会代表选举工作](https://mp.weixin.qq.com/s/ZXUfCepx7qOimEp65_lQWQ) - [ ] [2026年国家网络安全宣传周网络安全技术高峰论坛在济南举行](https://mp.weixin.qq.com/s/xAAiVLnIDQNs3LXXtgdNSw) - [ ] [《人工智能安全治理框架3.0》发布](https://mp.weixin.qq.com/s/kTmYvNNUdZa5_erZudOEdw) - [ ] [Fortinet FortiWeb 8.0–8.0.1 未授权 RCE 利用链地下售卖事件](https://mp.weixin.qq.com/s/Dys5lUgDo39zIv4wEOaOSQ) - Private Feed for M09Ic - [ ] [bolucat released 202609162308 at bolucat/Archive](https://github.com/bolucat/Archive/releases/tag/202609162308) - [ ] [zema1 starred larashero3-dotcom/lieflat-less-ai-tone](https://github.com/larashero3-dotcom/lieflat-less-ai-tone) - [ ] [gh0stkey starred ibelick/mesurer](https://github.com/ibelick/mesurer) - [ ] [Chuyu-Team released v1.2.3-Beta.3 at Chuyu-Team/YY-Thunks](https://github.com/Chuyu-Team/YY-Thunks/releases/tag/v1.2.3-Beta.3) - [ ] [Rvn0xsy starred joelbqz/writer-computer](https://github.com/joelbqz/writer-computer) - [ ] [Rvn0xsy forked Rvn0xsy/writer-computer from joelbqz/writer-computer](https://github.com/Rvn0xsy/writer-computer) - [ ] [ZeddYu contributed to ccfddl/ccf-deadlines](https://github.com/ccfddl/ccf-deadlines/pull/1670) - Kitploit — Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal! - [ ] [privacybadger v2026.9.15](https://kitploit.com/en/posts/github-efforg-privacybadger-release-2026915) - [ ] [douglas-042-HQ](https://kitploit.com/en/tools/github/douglas-042/douglas-042-hq) - [ ] [easywall v2.20.1](https://kitploit.com/en/posts/github-jp1337-easywall-v2201) - [ ] [polaris v10.2.3](https://kitploit.com/en/posts/github-fairwindsops-polaris-v1023) - [ ] [codejail v4.1.1](https://kitploit.com/en/posts/github-openedx-codejail-v411) - [ ] [SindriKit v2.0.0](https://kitploit.com/en/posts/github-youssefnoob003-sindrikit-v200) - [ ] [wazuh v4.10.5](https://kitploit.com/en/posts/github-wazuh-wazuh-v4105) - [ ] [dalfox v3.2.3](https://kitploit.com/en/posts/github-hahwul-dalfox-v323) - [ ] [sonar v0.9.1](https://kitploit.com/en/posts/github-raskrebs-sonar-v091) - [ ] [augustus v0.14.30](https://kitploit.com/en/posts/github-praetorian-inc-augustus-v01430) - [ ] [Responsible-Alliance-Protocol](https://kitploit.com/en/tools/github/philippeabraxas-jpg/responsible-alliance-protocol) - [ ] [whitelist-bypass](https://kitploit.com/en/tools/github/kulikov0/whitelist-bypass) - [ ] [ResetSpy](https://kitploit.com/en/tools/github/mlcsec/resetspy) - [ ] [limeyard](https://kitploit.com/en/tools/github/clickswave/limeyard) - [ ] [Aresius](https://kitploit.com/en/tools/github/0xmarik/aresius) - [ ] [XXStrike](https://kitploit.com/en/tools/github/anonmoty/xxstrike) - [ ] [ActGuard](https://kitploit.com/en/tools/github/binzhwang/actguard) - [ ] [Silverseal](https://kitploit.com/en/tools/github/idov31/silverseal) - [ ] [ThreatIntel-Aggregator](https://kitploit.com/en/tools/github/ethan-andrews/threatintel-aggregator) - [ ] [bombini](https://kitploit.com/en/tools/github/bombinisecurity/bombini) - [ ] [msteams](https://kitploit.com/en/tools/github/whispergate/msteams) - [ ] [pki-toolbox](https://kitploit.com/en/tools/github/youkyi/pki-toolbox) - [ ] [Claude-Red](https://kitploit.com/en/tools/github/snailsploit/claude-red) - [ ] [OpenShell](https://kitploit.com/en/tools/github/nvidia/openshell) - [ ] [Data-Shield_IPv4_Blocklist](https://kitploit.com/en/tools/github/duggytuxy/data-shield_ipv4_blocklist) - [ ] [bithoven v0.1.0](https://kitploit.com/en/posts/github-chrischo-h-bithoven-v010) - [ ] [speakeasy v2.0.0b8](https://kitploit.com/en/posts/github-mandiant-speakeasy-v200b8) - [ ] [vpod v0.8.4](https://kitploit.com/en/posts/github-capsulerun-vpod-v084) - [ ] [kata-containers v4.2.0](https://kitploit.com/en/posts/github-kata-containers-kata-containers-420) - [ ] [FLAWED](https://kitploit.com/en/tools/github/off-by-1-labs/flawed) - [ ] [noble-curves](https://kitploit.com/en/tools/github/paulmillr/noble-curves) - [ ] [cloudquery cli-v6.42.3](https://kitploit.com/en/posts/github-cloudquery-cloudquery-cli-v6423) - [ ] [suricata suricata-8.0.7](https://kitploit.com/en/posts/github-oisf-suricata-suricata-807) - [ ] [Osintgram v2.0](https://kitploit.com/en/posts/github-datalux-osintgram-20) - [ ] [envocabulary v1.0.5](https://kitploit.com/en/posts/github-sreckoskocilic-envocabulary-v105) - [ ] [testkube v2.13.2](https://kitploit.com/en/posts/github-kubeshop-testkube-2132) - [ ] [numa v0.23.1](https://kitploit.com/en/posts/github-razvandimescu-numa-v0231) - [ ] [Ghostwriter v7.3.0-rc1](https://kitploit.com/en/posts/github-ghostmanager-ghostwriter-v730-rc1) - Horizon3 - [ ] [CTEM Technology Evaluation Scorecard](https://horizon3.ai/downloads/factsheets/ctem-technology-evaluation-scorecard/) - [ ] [CISO’s CTEM Evaluation Checklist](https://horizon3.ai/downloads/factsheets/ciso-ctem-evaluation-checklist/) - [ ] [CVE-2026-86218 | N-able N-central Pre-Authentication Remote Code Execution Vulnerability](https://horizon3.ai/attack-research/vulnerabilities/cve-2026-86218/) - Malwarebytes - [ ] [Google Pixel owners urged to patch actively exploited modem flaw](https://www.malwarebytes.com/blog/mobile/2026/09/google-pixel-owners-urged-to-patch-actively-exploited-modem-flaw) - [ ] [AI helps scammers build convincing antivirus renewal pages](https://www.malwarebytes.com/blog/threat-intel/2026/09/ai-helps-scammers-build-convincing-antivirus-renewal-pages) - Reverse Engineering - [ ] [A IDA CLI tool: agent first & stateless & batch processing.](https://www.reddit.com/r/ReverseEngineering/comments/1whknv4/a_ida_cli_tool_agent_first_stateless_batch/) - [ ] [Help Needed: Missing global perspective/rotation matrix data when converting UMK3 iOS .meshset files to .obj](https://www.reddit.com/r/ReverseEngineering/comments/1whqcps/help_needed_missing_global_perspectiverotation/) - [ ] [Widescreen + Online Multiplayer Coop for my Rust WASM Zelda 2 decompilation. Github and playable link coming soon.](https://www.reddit.com/r/ReverseEngineering/comments/1whosli/widescreen_online_multiplayer_coop_for_my_rust/) - Securelist - [ ] [NightEagle targets Russian companies](https://securelist.com/tr/nighteagle-apt-ghostcontainer-and-tunneling/121323/) - rtl-sdr.com - [ ] [Automating Indoor RF Heatmapping with a PlutoSDR, Raspberry Pi 5 and LiDAR SLAM](https://www.rtl-sdr.com/automating-indoor-rf-heatmapping-with-a-plutosdr-raspberry-pi-5-and-lidar-slam/) - [ ] [InjectEave: Eavesdropping on Headphones by Injecting a Carrier and Listening to the Modulated Retransmission](https://www.rtl-sdr.com/injecteave-eavesdropping-on-headphones-by-injecting-a-carrier-and-listening-to-the-modulated-retransmission/) - [ ] [Bluewatch: Detecting new Bluetooth Devices in your Neighbourhood via a Raspberry Pi](https://www.rtl-sdr.com/bluewatch-detecting-new-bluetooth-devices-in-your-neighbourhood-via-a-raspberry-pi/) - [ ] [Frugal Radio: A Six SDR Setup with KrakenSDR and SDRplay for ADSB, ACARS, VDL2, P25](https://www.rtl-sdr.com/frugal-radio-a-six-sdr-setup-with-krakensdr-and-sdrplay-for-adsb-acars-vdl2-p25/) - HackerNews - [ ] [CenterPoint Energy 确认客户数据在网络攻击中被窃取](http://0.0.0.0:8080/post/64691) - [ ] [恶意 Admin Menu Editor Pro 插件在 1,500 个 WordPress 网站上植入后门](http://0.0.0.0:8080/post/64690) - [ ] [Acronis 警告其 cPanel 备份插件存在已被积极利用的漏洞](http://0.0.0.0:8080/post/64689) - [ ] [人类攻击者利用 Marimo RCE 漏洞,八秒内攻入 SSH 堡垒机](http://0.0.0.0:8080/post/64688) - [ ] [伊朗黑客利用 Telegram 控制的恶意软件监视异见人士和记者](http://0.0.0.0:8080/post/64687) - [ ] [KREMLIN 银行木马劫持 Chrome 和 Edge 窃取凭据与会话令牌](http://0.0.0.0:8080/post/64686) - 微步在线研究响应中心 - [ ] [已复现 | Langflow post-auth RCE](https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&mid=2247508945&idx=1&sn=ede35abd23d0c1aa811bc57d2ae2e9a6) - 黑鸟 - [ ] [德国军工巨头把作战系统核心接口开源了](https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451188796&idx=1&sn=67b6bb44fe41499dac36901738ea6ae3) - 奇客Solidot–传递最新科技情报 - [ ] [付费给大学生睡足七小时提高了他们的学习成绩](https://www.solidot.org/story?sid=85400) - [ ] [PS2 Fat 使用的安全芯片在时隔 26 年被破解](https://www.solidot.org/story?sid=85399) - [ ] [Denuvo 起诉黑客违反 DMCA 反规避条款](https://www.solidot.org/story?sid=85398) - [ ] [AWS 称无法恢复中东部分可用区资源和数据的访问](https://www.solidot.org/story?sid=85397) - [ ] [FAST 发现极短周期、最轻双中子星系统](https://www.solidot.org/story?sid=85396) - [ ] [Mistral 与 Mozilla 合作推出 Firefox Smart Window](https://www.solidot.org/story?sid=85395) - [ ] [Mozilla 报告称中国开放权重模型与美国前沿模型仅相差 4.4 个月](https://www.solidot.org/story?sid=85394) - [ ] [SDL3 移植到 HarmonyOS / OpenHarmony](https://www.solidot.org/story?sid=85393) - [ ] [时光机器遭遇大规模机器流量](https://www.solidot.org/story?sid=85392) - [ ] [Fedora 45 Beta 释出](https://www.solidot.org/story?sid=85391) - [ ] [Firefox 156 释出](https://www.solidot.org/story?sid=85390) - [ ] [日本百岁老人人数首次超过 10 万人](https://www.solidot.org/story?sid=85389) - 安全客 - [ ] [Cisco邮件网关9.8分漏洞被在野利用:一封邮件直接拿root,没有任何绕过的余地](https://mp.weixin.qq.com/s?__biz=MzA5ODA0NDE2MA==&mid=2649790481&idx=1&sn=31afea38178e241350d0fe91e6424485) - 代码卫士 - [ ] [2026 网安周|奇安信在国家级AI赋能网络安全应用测试中获双第一](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247527155&idx=1&sn=1d956ddc17a2c0d9d2d05ea22ec4dec9) - [ ] [cPanel:LiteSpeed Web Server 企业版严重漏洞可导致提权](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247527155&idx=2&sn=731309593b43d749b4d952223f7fc491) - [ ] [奇安信即将亮相中东地区最具影响力的网络安全盛会——GISEC Global 2026](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247527155&idx=3&sn=8a7d721716cca7e236fda45b4656e3bf) - 雷神众测 - [ ] [雷神众测漏洞周报2026.9.7-2026.9.13](https://mp.weixin.qq.com/s?__biz=MzI0NzEwOTM0MA==&mid=2652503972&idx=1&sn=0a80c34da9499b4cb8cf5fc4d8463f59) - 看雪学苑 - [ ] [Windows内核免杀学习:不调 API 找 ntdll 基址](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458620444&idx=1&sn=bd763b6986b4c05a62ddf89ef70e891b) - [ ] [工具投毒入侵!泰国顶级宽带运营商3BB遭攻破,黑客获取最高权限窃取用户凭证](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458620444&idx=2&sn=65a6a3528518c6437749359a55b70d24) - [ ] [更新3节 | 冰与火的战歌:Windows内核攻防实战](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458620444&idx=3&sn=19cf0f2494218412bb1b4aec299267ef) - 威努特安全网络 - [ ] [告警太多,研判太慢:如何快速锁定真正的风险?](https://mp.weixin.qq.com/s?__biz=MzAwNTgyODU3NQ==&mid=2651144135&idx=1&sn=e504f3ec7b4523b42e9ba675d8ba81df) - 安全分析与研究 - [ ] [EDR检测体系与静态分析](https://mp.weixin.qq.com/s?__biz=MzA4ODEyODA3MQ==&mid=2247497158&idx=1&sn=d9c3ac51dc821660c1f7ecb8b11e3124) - 安全研究GoSSIP - [ ] [G.O.S.S.I.P 阅读推荐 2026-09-16 卧龙凤雏](https://mp.weixin.qq.com/s?__biz=Mzg5ODUxMzg0Ng==&mid=2247502223&idx=1&sn=72dea2cf103221a9910e120cf26e865c) - 安全内参 - [ ] [大模型网络攻击能力该如何管控?首份AI行为“思想钢印”公布](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516605&idx=1&sn=b33f3871eb15de46fd586c5aa1cbc31c) - [ ] [CNCERT公布2026年人工智能技术赋能网络安全应用测试结果](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516605&idx=2&sn=bddc155ef486eb08c2e1488902d59a17) - 奇安信威胁情报中心 - [ ] [浏览器的"信任"被伪造:KREMLIN 攻破 Chrome 完整性校验,1500+ 巴西网银主机沦陷](https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247520463&idx=1&sn=15fc3f9babb8f6b469ebd32ec58827ca) - 青衣十三楼飞花堂 - [ ] [三角形角度挑战](https://mp.weixin.qq.com/s?__biz=MzUzMjQyMDE3Ng==&mid=2247489940&idx=1&sn=ab5612d17a94b1793034158a83a10a82) - 长亭科技 - [ ] [【长亭AI安全·网安周进行时】9奖齐发!漏洞治理见真章,AI成果树标杆](https://mp.weixin.qq.com/s?__biz=MzIwNDA2NDk5OQ==&mid=2651390745&idx=1&sn=02b45b9edf89fc3991d74fd99820cb83) - 安全圈 - [ ] [【安全圈】WooCommerce 批发插件曝 9.8 高危漏洞:未授权上传即成 PHP Web Shell](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078970&idx=1&sn=79e2e22a1ea642c180b12f34e2d63115) - [ ] [【安全圈】WSO2 API Manager 爆 JWT 签名绕过漏洞:伪造管理员 Token 直接拿下控制台](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078970&idx=2&sn=1a1c65218e30a1fe49375dd00d68006d) - [ ] [【安全圈】Vite 开发服务器被大规模扫描:云凭据和 AWS / Azure 配置被直接拿走](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078970&idx=3&sn=831e1e6cc470864b0321fca813a9d6e7) - 软件安全与逆向分析 - [ ] [安卓Pixel设备最新免解锁Root方案](https://mp.weixin.qq.com/s?__biz=MzU3MTY5MzQxMA==&mid=2247485467&idx=1&sn=9d5fd685054053ef5bba72c1c6c8b816) - M01N Team - [ ] [AI安全案例分析|可信AI平台成为恶意软件分发新通道](https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&mid=2247495534&idx=1&sn=83820ce11c0e30688e643efba0a58b8d) - [ ] [2026网安周 | 绿盟科技位居国家级AI安全应用测试结果前列](https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&mid=2247495534&idx=2&sn=d484f6098bf73e7fd4bfeb5a36f9d4a7) - 极客公园 - [ ] [马斯克再暗示合并特斯拉和 SpaceX;传 iPhone 18 Pro 系列卖爆;大疆 Pocket 4P「珠光白」3799 开售|极客早知道](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653113706&idx=1&sn=acb9b3e79b156d392b91f6397be3a7df) - [ ] [豆包手机正式开卖:这次,App 可以对 AI「说不」](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653113693&idx=1&sn=7393952e689d036b7abcdb27ffb2a5a1) - [ ] [京东押注物理 AI,冲在前面的是一群 95 后](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653113681&idx=1&sn=c8202657d800cbb9bbe928dd4c0b7a67) - [ ] [OriginOS 7 深度体验:新一代个人化智能到底是什么样?](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653113671&idx=1&sn=3d4162df09917ae515bb9a3dd20865aa) - 复旦白泽战队 - [ ] [AI手机安全实测:当“帮我操作手机”也可能被利用](https://mp.weixin.qq.com/s?__biz=MzU4NzUxOTI0OQ==&mid=2247499912&idx=1&sn=0b1f565d081212e2ccb242642847e55e) - 火绒安全 - [ ] [火绒企业版2.0功能升级|跨平台漏洞检测上线 查杀支持断点续杀](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247537497&idx=1&sn=91fb6e1fb4627ad1f361e29c02c5afad) - [ ] [火绒小问答--「个人版」近期top问题解答](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247537497&idx=2&sn=eb449ffb68d51fa38e1df77bae588d5c) - [ ] [诚邀渠道合作伙伴共启新征程](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247537497&idx=3&sn=1e760905b2dcf4e6870698f1d2834ec1) - 情报分析师 - [ ] [【开源调查】美国国家安全局开始招募心理学家,NSA为什么开始给自己“看心理医生”?](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650569677&idx=1&sn=39e35ce0d4089f0e7a1eae781dd650c4) - [ ] [【深度研判】荷兰及多国拟扩大情报权并以我为“显见对手”,欧洲对我反间谍制度化风险](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650569677&idx=2&sn=f45b1ad142777b236509c21103ee87b6) - 百度安全应急响应中心 - [ ] [百度安全应急响应中心对相关违规事件的处置公告](https://mp.weixin.qq.com/s?__biz=MzA4ODc0MTIwMw==&mid=2652545168&idx=1&sn=c34bff6c85a2416039fba0eba4bc79a2) - 信息安全国家工程研究中心 - [ ] [国家网信办发布近期网络安全、数据安全、个人信息保护等领域执法典型案例](https://mp.weixin.qq.com/s?__biz=MzU5OTQ0NzY3Ng==&mid=2247505100&idx=1&sn=faff744fc67763029ba2d1125b959f2e) - 字节跳动技术团队 - [ ] [从“做过”到“会做”:用 OpenViking 经验记忆构建 Agent 的进化闭环](https://mp.weixin.qq.com/s?__biz=MzI1MzYzMjE0MQ==&mid=2247522604&idx=1&sn=6ea201d826647e12047227cd3d386ba4) - [ ] [Agent 写稿突然“断片”?OpenViking 治好了我的内容创作焦虑](https://mp.weixin.qq.com/s?__biz=MzI1MzYzMjE0MQ==&mid=2247522604&idx=2&sn=38a6922a7fb8711c9851a44e15582b31) - 安全牛 - [ ] [从“工具人”到“授衔者”:Astra模型揭示的AI安全范式革命,正在重新定义网安工程师的边界](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142731&idx=1&sn=dca3c1d103e76117a0302810e454bc0c) - [ ] [【调研启动】AI驱动网络安全:安全大模型及安全Agent生态研究与应用实践](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142731&idx=2&sn=004a8f3f5a377845d32847f03fb5b42f) - 国家互联网应急中心CNCERT - [ ] [第23届中国网络安全年会暨国家网络安全宣传周网络安全协同防御论坛在济南召开](https://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw==&mid=2247502172&idx=1&sn=0be5cb636b6a68c6e32684f746cb496e) - 天御攻防实验室 - [ ] [NSA以巨额薪酬吸引早期成员重返黑客部门TAO](https://mp.weixin.qq.com/s?__biz=MzU0MzgyMzM2Nw==&mid=2247487172&idx=1&sn=9c1616d4ff9eeb9bf23da491a234dd23) - 微步在线 - [ ] [AI中转站,做起了数据买卖生意?](https://mp.weixin.qq.com/s?__biz=MzI5NjA0NjI5MQ==&mid=2650188143&idx=1&sn=55c1740cac6b7d819993cd9e87a66ad2) - Qualys Security Blog - [ ] [Oracle Critical Security Patch Update, September 2026 Review](https://blog.qualys.com/category/vulnerabilities-threat-research) - 安全419 - [ ] [安全419|一周国际网安资讯:微软974个补丁创纪录 FMC零日引爆勒索攻击](https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&mid=2247555048&idx=1&sn=d7853d7121d2c675010d99530370aca6) - OnionSec - [ ] [无意间看到一份招聘信息](https://mp.weixin.qq.com/s?__biz=MzUyMTUwMzI3Ng==&mid=2247486008&idx=1&sn=b3338cbe36010419b796e44f23e64308) - ICT Security Magazine - [ ] [SBOM e supply chain: il CRA lo renderà obbligatorio, ma lo scambio tra fornitori e clienti resta raro](https://www.ictsecuritymagazine.com/articoli/sbom-fornitori-cra/) - [ ] [Incidenti ICT gravi: il primo anno di segnalazioni DORA in Italia](https://www.ictsecuritymagazine.com/articoli/incidenti-ict-gravi-dora-banca-italia-2025/) - [ ] [it-sa Expo&Congress 2026: ottieni il tuo biglietto gratuito](https://www.ictsecuritymagazine.com/notizie/it-sa-expo-congress-2026-biglietto-gratuito/) - 360数字安全 - [ ] [16部门指导AI安全测试揭榜 360大模型卫士获国家级测试第一](https://mp.weixin.qq.com/s?__biz=MzA4MTg0MDQ4Nw==&mid=2247586921&idx=1&sn=005a92c25dc52042af61b57e9dd0b473) - [ ] [360深度参与昆明网安周,以实景攻防演练护航智能时代网络安全](https://mp.weixin.qq.com/s?__biz=MzA4MTg0MDQ4Nw==&mid=2247586921&idx=2&sn=9b290cc4612c51b04060a39dc1ff212e) - Virus Bulletin's blog - [ ] [2026 Péter Szőr Award shortlisted nominees](https://www.virusbulletin.com/blog/2026/09/2026-peter-szor-award-shortlisted-nominees/) - IT Service Management News - [ ] [D. Lgs. 160 del 2026 - Uso dell'IA per le forze di Polizia e sanzioni per tutti](http://blog.cesaregallotti.it/2026/09/d-lgs-160-del-2026-uso-dellia-per-le.html) - CYBER ARMS – Computer Security - [ ] [New Book – Foundations of AI Security: A Practical Guide for Cybersecurity Professionals and Students](https://cyberarms.wordpress.com/2026/09/16/new-book-foundations-of-ai-security-a-practical-guide-for-cybersecurity-professionals-and-students/) - SEI Blog - [ ] [AI-Augmented AADL in Visual Studio Code](https://www.sei.cmu.edu/blog/ai-augmented-aadl-in-visual-studio-code/?utm_source=blog&utm_medium=rss&utm_campaign=my_site_updates) - Tor Project blog - [ ] [New Release: Tails 7.13](https://blog.torproject.org/new-release-tails-7_13/) - bellingcat - [ ] [“A Recurring Pattern”: Civilians Paying the Price in Mali’s Drone Campaign](https://www.bellingcat.com/news/2026/09/16/drone-strike-civilians-killed-aes-sahel-mali-russia-africa-corps-guilt-by-location-jeune-afrique/) - Schneier on Security - [ ] [Fake CAPTCHA Scams](https://www.schneier.com/blog/archives/2026/09/fake-captcha-scams.html) - Javvad Malik - [ ] [I want a better watch](https://javvadmalik.com/2026/09/16/i-want-a-better-watch/) - www.theregister.com - Articles - [ ] [AI agents can modify themselves without humans telling them to do so](https://www.theregister.com/security/2026/09/16/ai-agents-can-modify-themselves-without-humans-telling-them-to-do-so/5296991) - [ ] [CISA decides weekly vulnerability bulletin isn't necessary anymore](https://www.theregister.com/security/2026/09/16/cisa-decides-weekly-vulnerability-bulletin-isnt-necessary-anymore/5296968) - [ ] [Google Pixel phones pwned in zero-click attacks](https://www.theregister.com/security/2026/09/16/google-pixel-phones-pwned-in-zero-click-attacks/5296936) - [ ] [Spain gets its first taste of AI-aided cyber attack](https://www.theregister.com/cyber-crime/2026/09/16/spain-gets-its-first-taste-of-ai-aided-cyber-attack/5296844) - [ ] [Ministry of Justice apologizes after court staff accessed Southport victims' files](https://www.theregister.com/security/2026/09/16/ministry-of-justice-apologizes-after-court-staff-accessed-southport-victims-files/5296808) - [ ] [Mythos has made 2026 patching hell. It might make 2027 a breeze](https://www.theregister.com/security/2026/09/16/mythos-has-made-2026-patching-hell-it-might-make-2027-a-breeze/5296747) - Instapaper: Unread - [ ] [Riconoscimento facciale con AI per la Polizia, in Gazzetta Ufficiale il decreto legislativo 1602026. Entrerà in vigore dal 30 settembre](https://www.cybersecitalia.it/riconoscimento-facciale-con-ai-per-la-polizia-in-gazzetta-ufficiale-il-decreto-legislativo-160-2026-in-vigore-dal-30-settembre/69566/) - [ ] [Caso Revolut, il giallo dei dati istituzionali italiani sottratti dai criminali](https://www.cybersecurity360.it/news/caso-revolut-il-giallo-dei-dati-istituzionali-italiani-sottratti-dai-criminali/) - [ ] [ACN, online il vademecum NIS per il supporto agli adempimenti](https://www.cybersecitalia.it/acn-online-il-vademecum-nis-per-il-supporto-agli-adempimenti/69430/) - [ ] [Sanzioni Usa, lo scudo europeo alla prova del caso AutisticiInventati](https://www.agendadigitale.eu/cultura-digitale/sanzioni-usa-lo-scudo-europeo-alla-prova-del-caso-autistici-inventati/) - [ ] [Podcast RSI – Zitto, l’orologio ti ascolta](https://attivissimo.me/podcast-rsi-zitto-lorologio-ti-ascolta/) - [ ] [Ransomware senza cifratura perché il backup non basta più](https://www.agendadigitale.eu/sicurezza/ransomware-senza-cifratura-perche-il-backup-non-basta-piu/) - [ ] [Drone forensics a guide for investigators](https://www.magnetforensics.com/blog/drone-forensics-a-guide-for-investigators/) - [ ] [New hardware device can RAM into encrypted memory, expose your data](https://www.theregister.com/security/2026/09/14/new-hardware-device-can-ram-into-encrypted-memory-expose-your-data/5296377) - [ ] [Revolut violati dati di alto profilo, la pista porta al Viminale](https://www.cybersecurity360.it/nuove-minacce/revolut-violati-dati-alto-profilo-la-pista-porta-al-viminale/) - Blackhat Library: Hacking techniques and research - [ ] [is there any site which.](https://www.reddit.com/r/blackhat/comments/1wi1ftd/is_there_any_site_which/) - The Hacker News - [ ] [Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution](https://thehackernews.com/2026/09/attackers-exploit-issabel-framework.html) - [ ] [Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers](https://thehackernews.com/2026/09/three-threat-groups-target-russian.html) - [ ] [One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude](https://thehackernews.com/2026/09/one-extension-could-hijack-ai.html) - [ ] [Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories](https://thehackernews.com/2026/09/attacker-hijacks-ai-coding-assistant.html) - [ ] [Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix](https://thehackernews.com/2026/09/parallels-desktop-flaw-lets-non-admin.html) - [ ] [N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security](https://thehackernews.com/2026/09/n0va-phishkit-targets-us-and-eu.html) - [ ] [Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation](https://thehackernews.com/2026/09/google-patches-pixel-modem-flaw-amid.html) - [ ] [Threat Intelligence Alone Won't Close the Exploitation Gap](https://thehackernews.com/2026/09/threat-intelligence-alone-wont-close.html) - [ ] [Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks](https://thehackernews.com/2026/09/acronis-cpanel-backup-plugin.html) - [ ] [Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells](https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html) - [ ] [Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens](https://thehackernews.com/2026/09/active-exploitation-attempts-target.html) - KitPloit - PenTest Tools! - [ ] [privacybadger v2026.9.15](https://kitploit.com/en/posts/github-efforg-privacybadger-release-2026915) - [ ] [douglas-042-HQ](https://kitploit.com/en/tools/github/douglas-042/douglas-042-hq) - [ ] [easywall v2.20.1](https://kitploit.com/en/posts/github-jp1337-easywall-v2201) - [ ] [polaris v10.2.3](https://kitploit.com/en/posts/github-fairwindsops-polaris-v1023) - [ ] [codejail v4.1.1](https://kitploit.com/en/posts/github-openedx-codejail-v411) - [ ] [SindriKit v2.0.0](https://kitploit.com/en/posts/github-youssefnoob003-sindrikit-v200) - [ ] [wazuh v4.10.5](https://kitploit.com/en/posts/github-wazuh-wazuh-v4105) - [ ] [dalfox v3.2.3](https://kitploit.com/en/posts/github-hahwul-dalfox-v323) - [ ] [sonar v0.9.1](https://kitploit.com/en/posts/github-raskrebs-sonar-v091) - [ ] [augustus v0.14.30](https://kitploit.com/en/posts/github-praetorian-inc-augustus-v01430) - [ ] [Responsible-Alliance-Protocol](https://kitploit.com/en/tools/github/philippeabraxas-jpg/responsible-alliance-protocol) - [ ] [whitelist-bypass](https://kitploit.com/en/tools/github/kulikov0/whitelist-bypass) - [ ] [ResetSpy](https://kitploit.com/en/tools/github/mlcsec/resetspy) - [ ] [limeyard](https://kitploit.com/en/tools/github/clickswave/limeyard) - [ ] [Aresius](https://kitploit.com/en/tools/github/0xmarik/aresius) - [ ] [XXStrike](https://kitploit.com/en/tools/github/anonmoty/xxstrike) - [ ] [ActGuard](https://kitploit.com/en/tools/github/binzhwang/actguard) - [ ] [Silverseal](https://kitploit.com/en/tools/github/idov31/silverseal) - [ ] [ThreatIntel-Aggregator](https://kitploit.com/en/tools/github/ethan-andrews/threatintel-aggregator) - [ ] [bombini](https://kitploit.com/en/tools/github/bombinisecurity/bombini) - [ ] [msteams](https://kitploit.com/en/tools/github/whispergate/msteams) - [ ] [pki-toolbox](https://kitploit.com/en/tools/github/youkyi/pki-toolbox) - [ ] [Claude-Red](https://kitploit.com/en/tools/github/snailsploit/claude-red) - [ ] [OpenShell](https://kitploit.com/en/tools/github/nvidia/openshell) - [ ] [Data-Shield_IPv4_Blocklist](https://kitploit.com/en/tools/github/duggytuxy/data-shield_ipv4_blocklist) - [ ] [bithoven v0.1.0](https://kitploit.com/en/posts/github-chrischo-h-bithoven-v010) - [ ] [speakeasy v2.0.0b8](https://kitploit.com/en/posts/github-mandiant-speakeasy-v200b8) - [ ] [vpod v0.8.4](https://kitploit.com/en/posts/github-capsulerun-vpod-v084) - [ ] [kata-containers v4.2.0](https://kitploit.com/en/posts/github-kata-containers-kata-containers-420) - [ ] [FLAWED](https://kitploit.com/en/tools/github/off-by-1-labs/flawed) - [ ] [noble-curves](https://kitploit.com/en/tools/github/paulmillr/noble-curves) - [ ] [cloudquery cli-v6.42.3](https://kitploit.com/en/posts/github-cloudquery-cloudquery-cli-v6423) - [ ] [suricata suricata-8.0.7](https://kitploit.com/en/posts/github-oisf-suricata-suricata-807) - [ ] [Osintgram v2.0](https://kitploit.com/en/posts/github-datalux-osintgram-20) - [ ] [envocabulary v1.0.5](https://kitploit.com/en/posts/github-sreckoskocilic-envocabulary-v105) - [ ] [testkube v2.13.2](https://kitploit.com/en/posts/github-kubeshop-testkube-2132) - [ ] [numa v0.23.1](https://kitploit.com/en/posts/github-razvandimescu-numa-v0231) - [ ] [Ghostwriter v7.3.0-rc1](https://kitploit.com/en/posts/github-ghostmanager-ghostwriter-v730-rc1) - [ ] [installer v14.0.0-rc.7](https://kitploit.com/en/posts/github-mondoohq-installer-v1400-rc7) - [ ] [SynGhost](https://kitploit.com/en/tools/github/zhou-cybersecurity-ai/synghost) - [ ] [INTACT](https://kitploit.com/en/tools/github/siyuanli00/intact) - [ ] [Rubrics-as-an-Attack-Surface](https://kitploit.com/en/tools/github/zdcslab/rubrics-as-an-attack-surface) - TorrentFreak - [ ] [Denuvo Sues Game Cracker ‘voices38’ for Bypassing its Anti-Tamper DRM](https://torrentfreak.com/denuvo-sues-game-cracker-voices38-for-bypassing-its-anti-tamper-drm/) - Security Affairs - [ ] [BambooToken: The Malware That Speaks MQTT to Stay Under the Radar](https://securityaffairs.com/199205/malware/bambootoken-the-malware-that-speaks-mqtt-to-stay-under-the-radar.html) - [ ] [Google Patches Pixel Modem Zero-Day Exploited in Targeted Attacks](https://securityaffairs.com/199193/hacking/google-patches-pixel-modem-zero-day-exploited-in-targeted-attacks.html) - [ ] [Revolut Data Leak May Trace Back to Compromised Italian Government Accounts](https://securityaffairs.com/199180/data-breach/revolut-data-leak-may-trace-back-to-compromised-italian-government-accounts.html) - [ ] [Texas Utility CenterPoint Energy Confirms Data Breach After Hacker Claims 7.49M Records Stolen](https://securityaffairs.com/199170/data-breach/texas-utility-centerpoint-energy-confirms-data-breach-after-hacker-claims-7-49m-records-stolen.html) - Krebs on Security - [ ] [Data Broker Radaris Loses Domains in Privacy Fight](https://krebsonsecurity.com/2026/09/data-broker-radaris-loses-domains-in-privacy-fight/) - SANS Internet Storm Center, InfoCON: green - [ ] [Scans Targeting Hospitality Applications, (Wed, Sep 16th)](https://isc.sans.edu/diary/rss/33344) - [ ] [ISC Stormcast For Wednesday, September 16th, 2026 https://isc.sans.edu/podcastdetail/10096, (Wed, Sep 16th)](https://isc.sans.edu/diary/rss/33342) - Security Weekly Podcast Network (Audio) - [ ] [Followership, CyberSecurity Leadership, and Judgement as a Defining Skill - Kenyada Meadows - BSW #465](http://sites.libsyn.com/18678/followership-cybersecurity-leadership-and-judgement-as-a-defining-skill-kenyada-meadows-bsw-465) - Over Security - [ ] [Key lawmaker suggests action on AI safety legislation will wait until 2027](https://therecord.media/frontier-act-ai-bill-house-brett-guthrie) - [ ] [Windows 11 KB5124008 update breaks domain trust for some users](https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5124008-update-breaks-domain-trust-for-some-users/) - [ ] [Iranian hackers use CHOSEN BRICK Windows malware to spy on targets](https://www.bleepingcomputer.com/news/security/iranian-hackers-use-chosen-brick-windows-malware-to-spy-on-targets/) - [ ] [Living Inside the Shell: zsh Modules on macOS](https://dfir.ch/posts/zsh_modules/) - [ ] [Coast Guard, FBI boarded tanker after attack by ‘foreign cyber actors’](https://therecord.media/oil-tanker-cyberattack-coast-guard-fbi) - [ ] [Malware bypasses browser checks to force install Chrome, Edge extensions](https://www.bleepingcomputer.com/news/security/malware-bypasses-browser-checks-to-force-install-chrome-edge-extensions/) - [ ] [House passes bill to equip local law enforcement with scam-fighting tools](https://therecord.media/house-passes-bill-to-equip-local-law-enforcement-scams) - [ ] [Data Broker Radaris Loses Domains in Privacy Fight](https://krebsonsecurity.com/2026/09/data-broker-radaris-loses-domains-in-privacy-fight/) - [ ] [Spain's data agency gets first report of AI-powered data breach](https://www.bleepingcomputer.com/news/security/spains-data-agency-gets-first-report-of-ai-powered-data-breach/) - [ ] [Managed Detection & Response: perché la vera sfida oggi è personalizzare la detection](https://www.cybersecurity360.it/soluzioni-aziendali/managed-detection-response-perche-la-vera-sfida-oggi-e-personalizzare-la-detection/) - [ ] [Spain reports first alleged AI-powered data theft attack](https://www.bleepingcomputer.com/news/security/spain-reports-first-alleged-ai-powered-data-theft-attack/) - [ ] [International Meteor Organization says cyberattack dealt ‘critical blow’ to website](https://therecord.media/international-meteor-organization-cyberattack) - [ ] [Supply chain cyber risk: come AI e automazione stanno cambiando il Vendor Risk Management](https://www.cybersecurity360.it/soluzioni-aziendali/supply-chain-cyber-risk-come-ai-e-automazione-stanno-cambiando-il-vendor-risk-management/) - [ ] [Three Ukrainians to face charges for alleged hack of 610,000 Roblox accounts](https://therecord.media/ukraine-roblox-hacker-arrested) - [ ] [I costi del downtime industriale da attacco cyber: come quantificare l’impatto economico dei blocchi di produzione](https://www.cybersecurity360.it/soluzioni-aziendali/i-costi-del-downtime-industriale-da-attacco-cyber-come-quantificare-limpatto-economico-dei-blocchi-di-produzione/) - [ ] [The true cost of a ransomware attack, with and without BCDR](https://www.bleepingcomputer.com/news/security/the-true-cost-of-a-ransomware-attack-with-and-without-bcdr/) - [ ] [Flock camera use by internal affairs unit puts DC police at odds with officers’ union](https://therecord.media/dc-police-union-opposes-flock-camera-use-probing-officers) - [ ] [EU chief wants joint response to cyberattacks, sabotage](https://therecord.media/eu-chief-wants-joint-response-to-cyberattacks) - [ ] [From Alert Triage to Threat Hunting: The New SOC Analyst Priority](https://binarydefense.com/resources/blog/from-alert-triage-to-threat-hunting-the-new-soc-analyst-priority) - [ ] [Ukraine moves to crack down on scam call centers after corruption scandal](https://therecord.media/ukraine-call-center-scam-crackdown) - [ ] [CenterPoint Energy Tells SEC Customer Data Was Stolen After 7.5Mn Records Advertised Online](https://thecyberexpress.com/centerpoint-energy-data-breach-sec-disclosure/) - [ ] [Falso “Bonus Vacanze” dell’Agenzia delle Entrate ruba dati personali](https://cert-agid.gov.it/news/falso-bonus-vacanze-dellagenzia-delle-entrate-ruba-dati-personali/) - [ ] [Webinar: What happens in the first hours of a Google Workspace breach](https://www.bleepingcomputer.com/news/security/webinar-what-happens-in-the-first-hours-of-a-google-workspace-breach/) - [ ] [Microsoft says Copilot buttons still missing in classic Outlook](https://www.bleepingcomputer.com/news/microsoft/microsoft-shares-workaround-for-missing-outlook-copilot-buttons/) - [ ] [Critical ScreenConnect flaw now actively exploited in attacks](https://www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploiting-critical-screenconnect-flaw/) - [ ] [Caso Revolut, il giallo dei dati istituzionali italiani sottratti dai criminali](https://www.cybersecurity360.it/news/caso-revolut-il-giallo-dei-dati-istituzionali-italiani-sottratti-dai-criminali/) - [ ] [NightEagle targets Russian companies](https://securelist.com/tr/nighteagle-apt-ghostcontainer-and-tunneling/121323/) - [ ] [Securing the unpatchable in an age of AI-driven vulnerabilities](https://blog.talosintelligence.com/securing-the-unpatchable-in-an-age-of-ai-driven-vulnerabilities/) - [ ] [10 Best Brand Protection Solutions (Ranked and Compared)](https://thecyberexpress.com/10-best-brand-protection-solutions/) - [ ] [VPN illimitata e sicura per 12 mesi: è il momento di attivare Total VPN per proteggere traffico, banda e privacy](https://www.cybersecurity360.it/cultura-cyber/total-vpn-illimitata-sicura-12-mesi-cifratura-privacy/) - [ ] [The MRI Scan That Wasn’t: Inside Iran’s ‘Chosen Brick’ Malware Campaign Against Its Critics Abroad](https://thecyberexpress.com/inside-irans-chosen-brick-malware-campaign/) - [ ] [Zelensky Appoints Ihor Klymenko to Lead Ukraine’s Cybersecurity Center](https://thecyberexpress.com/ukraine-cybersecurity-gets-new-leader-klymenko/) - [ ] [Manhattan D.A. Seizes 12 Deepfake Porn Websites Targeting 1,200 People](https://thecyberexpress.com/ai-generated-deepfake-websites-seized/) - [ ] [Apple Patches 273 Vulnerabilities as iOS 26.7 Rolls Out](https://thecyberexpress.com/apple-security-update-ios-26-7-vulnerabilities/) - [ ] [Pakistan Finalizes 90-Day Cybersecurity Action Plan, Federal CERT to Lead Rollout](https://thecyberexpress.com/pakistan-cybersecurity-action-plan/) - [ ] [ANY.RUN & SentinelOne: One Workspace, Instant Context for Rapid Response](https://any.run/cybersecurity-blog/sentinelone-integration/) - [ ] [EXCLUSIVE: Storm introduces automated ransomware negotiations: AI enters the process, but humans remain behind the scenes](https://www.suspectfile.com/exclusive-storm-introduces-automated-ransomware-negotiations-ai-enters-the-process-but-humans-remain-behind-the-scenes/) - [ ] [Anthropic e i 4 incidenti cyber: l’enfasi sulla capacità di fermarsi](https://www.cybersecurity360.it/nuove-minacce/anthropic-e-i-4-incidenti-cyber-lenfasi-sulla-capacita-di-fermarsi/) - [ ] [Come il gruppo Aurora ha usato un agente AI per violare sette aziende](https://www.cybersecurity360.it/outlook/come-il-gruppo-aurora-ha-usato-un-agente-ai-per-violare-sette-aziende/) - [ ] [Data breach alla velocità dell’AI: il GDPR regge, ma la difesa deve accelerare](https://www.cybersecurity360.it/nuove-minacce/data-breach-alla-velocita-dellai-il-gdpr-regge-ma-la-difesa-deve-accelerare/) - [ ] [One Router, Three Vulnerabilities: Security Research on the TOTOLINK A720R](https://www.hacktivesecurity.com/blog/2026/09/16/one-router-three-vulnerabilities-security-research-on-the-totolink-a720r/) - [ ] [The Adversary We Are Fighting Is Now a Full-Force Industry: Inside cybercrime’s new economy](https://www.group-ib.com/blog/adversary-full-force-industry/) - [ ] [Norway announces investigations into telecom Telenor’s work with Myanmar junta](https://therecord.media/norway-investigations-telenor-telecom-myanmar-regime) - [ ] [Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites](https://www.bleepingcomputer.com/news/security/malcious-admin-menu-editor-pro-plugin-backdoors-1-500-wordpress-sites/) - [ ] [Acronis warns of actively exploited flaw in its cPanel backup plugin](https://www.bleepingcomputer.com/news/security/acronis-warns-of-actively-exploited-flaw-in-its-cpanel-backup-plugin/) - [ ] [Google fixes actively exploited Android zero-day on Pixel devices](https://www.bleepingcomputer.com/news/security/google-fixes-actively-exploited-android-zero-day-on-pixel-devices/) - [ ] [Windows Server 2022 reaches end of mainstream support next month](https://www.bleepingcomputer.com/news/microsoft/windows-server-2022-reaches-end-of-mainstream-support-next-month/) - GRAHAM CLULEY - [ ] [Smashing Security podcast #485: These researchers got drunk to hack an LG TV](https://grahamcluley.com/smashing-security-podcast-485/) - Deeplinks - [ ] [Victory! Appeals Court Rejects Expansive New Copyright Claim](https://www.eff.org/deeplinks/2026/09/victory-appeals-court-rejects-expansive-new-copyright-claim) - [ ] [Victory: Court, Using a New Test, Rules Embedding Links is Legal](https://www.eff.org/deeplinks/2026/09/victory-court-using-new-test-rules-embedding-links-legal) - [ ] [EFF Welcomes Alexander Macgillivray to its Board of Directors](https://www.eff.org/deeplinks/2026/09/eff-welcomes-alexander-macgillivray-its-board-directors) - [ ] [👮 Flock Searches for the LOLs | EFFector 38.16](https://www.eff.org/deeplinks/2026/09/flock-searches-lols-effector-3816) - [ ] [How the Meta Settlement Silences Youth Activism](https://www.eff.org/deeplinks/2026/09/meta-settlement-yet-another-example-online-youth-organizing-under-threat)
每日安全资讯(2026-09-17)