# 每日安全资讯(2026-09-20) - SecWiki News - [ ] [SecWiki News 2026-09-19 Review](http://www.sec-wiki.com/?2026-09-19) - Doonsec's feed - [ ] [渗透工具包( PEEP)将 Chrome 和 Edge 浏览器变成入侵后执行高危命令的后门](https://mp.weixin.qq.com/s/-NIB_ogIamwt-z1nBUpFSA) - [ ] [当全网以为现在是2006年](https://mp.weixin.qq.com/s/uLWmq0OrrBD5qxKObRYMHw) - [ ] [一文读懂FDE工程师的七大核心能力](https://mp.weixin.qq.com/s/1DSDb05h0rv7XyoyupJxYA) - [ ] [分享的图片、视频、链接](https://mp.weixin.qq.com/s/ljLqsLrJHIbpTuQuWux8gg) - [ ] [开源PentAGI的 AI 驱动自动化渗透测试平台调研测评](https://mp.weixin.qq.com/s/6XhP5mmhYsuc5NxfXaRgXw) - [ ] [Claude 打穿 OpenAI细节:一张 HEIC 图,撬开私有代码库](https://mp.weixin.qq.com/s/76CCR5J4dbpGB1Xv6ja9JA) - [ ] [美国炸伊朗小学、123名儿童遇难:旧情报+AI信任过载,两枚战斧炸出的战争罪](https://mp.weixin.qq.com/s/CxkpA6D6KaV-3l6-rkC5OA) - [ ] [一个Word文档,就能“远程控制”你的Microsoft Copilot](https://mp.weixin.qq.com/s/XphmqrEVLAjEksSZVPK6Ag) - [ ] [27岁,不整虚的!](https://mp.weixin.qq.com/s/vwQfeiQ3qakAs5AnKdEk9g) - [ ] [EDR攻击技术-进程与遥测欺骗](https://mp.weixin.qq.com/s/BOfqCKKKKycHWMfGmg1lxw) - [ ] [华为全联接大会2026|华为星河AI网络安全解决方案为企业在AI时代构筑一体化智能安全防护体系](https://mp.weixin.qq.com/s/E3cxDSsC3vMqIP70cgXJqg) - [ ] [网安回忆录xa0-xa0一白板上那行\"待确认\",答案不只在网络日志里](https://mp.weixin.qq.com/s/CofrUOZIssWBh2vebVisbQ) - [ ] [攻防技战术动态一周更新 - 20260914](https://mp.weixin.qq.com/s/D8W0R8AKl3j3fYZ7KrMzvA) - [ ] [iOS 26.7 升不升?15、16、17 三个系列,三个不同答案](https://mp.weixin.qq.com/s/aXhtryXRU9NFFJxn7sj3DA) - 安全客-有思想的安全新媒体 - [ ] [3000 美元、3 个人、72 小时:AI 把 OpenAI 的论坛打穿了](https://www.anquanke.com/post/id/316124) - [ ] [一个月 68 个 CVE、91.8% 没有 OAuth:你的 AI 工具层正在裸奔](https://www.anquanke.com/post/id/316121) - Recent Commits to cve:main - [ ] [Update Sat Sep 19 12:26:43 UTC 2026](https://github.com/trickest/cve/commit/d2c1721a31be4adbef7d8969ab2cb94a05da24fb) - Sploitus.com Exploits RSS Feed - [ ] [hash-identifier exploit](https://sploitus.com/exploit?id=KITPLOIT:1455874543546034505&utm_source=rss&utm_medium=rss) - [ ] [CyberStrikeAI exploit](https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-ED1S0NZ-CYBERSTRIKEAI&utm_source=rss&utm_medium=rss) - [ ] [BruteShark exploit](https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-ODEDSHIMON-BRUTESHARK&utm_source=rss&utm_medium=rss) - [ ] [trivy exploit](https://sploitus.com/exploit?id=KITPLOIT:7323577050718865961&utm_source=rss&utm_medium=rss) - [ ] [CVE-Lib exploit](https://sploitus.com/exploit?id=1C797369-C048-5DA4-8C1B-2A7D2F947D3B&utm_source=rss&utm_medium=rss) - [ ] [tcpdump exploit](https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-THE-TCPDUMP-GROUP-TCPDUMP&utm_source=rss&utm_medium=rss) - [ ] [malicious-pdf exploit](https://sploitus.com/exploit?id=KITPLOIT:8063277894541294784&utm_source=rss&utm_medium=rss) - [ ] [awesome-osint-arsenal exploit](https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-RAWFILEJSON-AWESOME-OSINT-ARSENAL&utm_source=rss&utm_medium=rss) - [ ] [redamon exploit](https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-SAMUGIT83-REDAMON&utm_source=rss&utm_medium=rss) - Private Feed for M09Ic - [ ] [bolucat released 202609192223 at bolucat/Archive](https://github.com/bolucat/Archive/releases/tag/202609192223) - [ ] [chainreactors released v1.0.0-rc4 at chainreactors/cyber-harness](https://github.com/chainreactors/cyber-harness/releases/tag/v1.0.0-rc4) - [ ] [esrrhs contributed to esrrhs/pingtunnel](https://github.com/esrrhs/pingtunnel/pull/100) - [ ] [esrrhs contributed to esrrhs/spp](https://github.com/esrrhs/spp/pull/44) - [ ] [Mr-xn forked Mr-xn/dsh2shell from ChaoMixian/dsh2shell](https://github.com/Mr-xn/dsh2shell) - [ ] [kpcyrd contributed to kpcyrd/repro-threshold](https://github.com/kpcyrd/repro-threshold/pull/9) - [ ] [timwhitez starred QiantangCredit/heimdall-pentest](https://github.com/QiantangCredit/heimdall-pentest) - [ ] [Mel0day forked Mel0day/wx-cli-again from jackwener/wx-cli-again](https://github.com/Mel0day/wx-cli-again) - [ ] [Mel0day starred jackwener/wx-cli-again](https://github.com/jackwener/wx-cli-again) - [ ] [CHYbeta starred tamaratran/fast-jev-compaction](https://github.com/tamaratran/fast-jev-compaction) - [ ] [mgeeky starred purehate/herdr-plugin-picker](https://github.com/purehate/herdr-plugin-picker) - [ ] [pydantic released v2.46.0 at pydantic/pydantic-ai](https://github.com/pydantic/pydantic-ai/releases/tag/v2.46.0) - [ ] [Mel0day starred Mel0day/retro2003](https://github.com/Mel0day/retro2003) - [ ] [anthropics released v2.1.278 at anthropics/claude-code](https://github.com/anthropics/claude-code/releases/tag/v2.1.278) - [ ] [Mr-xn starred xtaci/smux](https://github.com/xtaci/smux) - [ ] [Ridter starred xtaci/smux](https://github.com/xtaci/smux) - [ ] [esrrhs contributed to esrrhs/fakecc](https://github.com/esrrhs/fakecc/pull/85) - [ ] [esrrhs contributed to esrrhs/fakelua](https://github.com/esrrhs/fakelua/pull/18) - Kitploit — Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal! - [ ] [rustinel v1.8.0-rc.1](https://kitploit.com/en/posts/github-karib0u-rustinel-v180-rc1) - [ ] [urx v0.11.0](https://kitploit.com/en/posts/github-hahwul-urx-0110) - [ ] [lightkeeper v1.4.1](https://kitploit.com/en/posts/github-worksbutnottested-lightkeeper-141) - [ ] [firefox-devtools-mcp v0.10.3](https://kitploit.com/en/posts/github-mozilla-firefox-devtools-mcp-v0103) - [ ] [xalgorix v4.6.78](https://kitploit.com/en/posts/github-xalgord-xalgorix-v4678) - [ ] [rspamd v4.2.0](https://kitploit.com/en/posts/github-rspamd-rspamd-420) - [ ] [Reversecore_MCP v3.0.4](https://kitploit.com/en/posts/github-sjkim1127-reversecore_mcp-v304) - [ ] [vigolium v0.4.8](https://kitploit.com/en/posts/github-vigolium-vigolium-v048) - [ ] [yakit v1.4.8-0919](https://kitploit.com/en/posts/github-yaklang-yakit-v148-0919) - [ ] [red-teaming-auto-mode](https://kitploit.com/en/tools/github/safety-research/red-teaming-auto-mode) - [ ] [ciso-assistant-community](https://kitploit.com/en/tools/github/intuitem/ciso-assistant-community) - [ ] [agent-scan v0.6.4-snapshot-6e2d290-1638](https://kitploit.com/en/posts/github-snyk-agent-scan-v064-snapshot-6e2d290-1638) - [ ] [maigret v0.6.6](https://kitploit.com/en/posts/github-soxoj-maigret-v066) - [ ] [wolfCOSE v2.0.0](https://kitploit.com/en/posts/github-wolfssl-wolfcose-v200) - [ ] [OpenAM v16.1.3](https://kitploit.com/en/posts/github-openidentityplatform-openam-1613) - [ ] [bunkerweb v1.6.15-rc3](https://kitploit.com/en/posts/github-bunkerity-bunkerweb-v1615-rc3) - [ ] [volatility3 v2.28.2](https://kitploit.com/en/posts/github-volatilityfoundation-volatility3-v2282) - [ ] [checkov v3.3.19](https://kitploit.com/en/posts/github-bridgecrewio-checkov-3319) - [ ] [proxmark3 v4.23346](https://kitploit.com/en/posts/github-rfidresearchgroup-proxmark3-v423346) - [ ] [frida-ssl-bypass](https://kitploit.com/en/tools/github/danieldev23/frida-ssl-bypass) - [ ] [Veridiff](https://kitploit.com/en/tools/github/veridiff/veridiff) - [ ] [js-x-ray @nodesecure/js-x-ray@16.1.0](https://kitploit.com/en/posts/github-nodesecure-js-x-ray-nodesecurejs-x-ray1610) - [ ] [evmbench-certora-agent-harness](https://kitploit.com/en/tools/github/gmh5225/evmbench-certora-agent-harness) - [ ] [sslscan v2.2.3](https://kitploit.com/en/posts/github-rbsec-sslscan-223) - [ ] [faraday v5.24.2](https://kitploit.com/en/posts/github-infobyte-faraday-v5242) - Reverse Engineering - [ ] [CVE-2026-77179: Docker's hypervisor for Mac compromised (Docker Desktop, Docker Sandboxes)](https://www.reddit.com/r/ReverseEngineering/comments/1wkehjs/cve202677179_dockers_hypervisor_for_mac/) - [ ] [New weekly CTF challenge is now live. Ranking is based on solve order.](https://www.reddit.com/r/ReverseEngineering/comments/1wko5uy/new_weekly_ctf_challenge_is_now_live_ranking_is/) - 奇客Solidot–传递最新科技情报 - [ ] [大脑由两个不同的器官构成](https://www.solidot.org/story?sid=85426) - [ ] [Android 17 QPR1 引入了 Pixel 暂时独占的新 API](https://www.solidot.org/story?sid=85425) - [ ] [海豚 Bubbles 被发现会强迫饱腹鱼吐出食物然后自己将其吞下](https://www.solidot.org/story?sid=85424) - 安全客 - [ ] [国家信息安全漏洞共享平台认证!360揽获三项漏洞治理核心殊荣](https://mp.weixin.qq.com/s?__biz=MzA5ODA0NDE2MA==&mid=2649790491&idx=1&sn=4dcf28d6df4c4eeff6eebcf39bc3dcc4) - 黑鸟 - [ ] [当全网以为现在是2006年](https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451188860&idx=1&sn=0be1615627475a59dca7d45ba5a12b1b) - 我的安全视界观 - [ ] [AI在企业级漏洞预警中的应用](https://mp.weixin.qq.com/s?__biz=MzI3Njk2OTIzOQ==&mid=2247488068&idx=1&sn=46340601f344788aa253f02e77e47a18) - 安全分析与研究 - [ ] [EDR攻击技术-进程与遥测欺骗](https://mp.weixin.qq.com/s?__biz=MzA4ODEyODA3MQ==&mid=2247497178&idx=1&sn=bc85ee18b9552d272157a8c07ffcda05) - XCTF联赛 - [ ] [第九届“强网”拟态防御国际精英挑战赛设计安全大赛报名启动!](https://mp.weixin.qq.com/s?__biz=MjM5NDU3MjExNw==&mid=2247516653&idx=1&sn=7bf26328ba975767dbb76f4ac9cd076f) - 看雪学苑 - [ ] [OLLVM学姐攻略手册](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458620747&idx=1&sn=b6cdcf56b1664c94f4a37df1fd185ee5) - [ ] [基于CVD的云手机定制与风控分析](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458620747&idx=2&sn=662385a51d32288a3332eec39beed28e) - ChaMd5安全团队 - [ ] [喜报 | ChaMd5荣获第六届“长城杯”网络安全大赛决赛“二等奖”](https://mp.weixin.qq.com/s?__biz=MzIzMTc1MjExOQ==&mid=2247514481&idx=1&sn=917acf1c02a024abc702081424c199d8) - 极客公园 - [ ] [不可逆的人类衰老,快被 AI 破解了](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653113803&idx=1&sn=b9376438580cf7a9f202bed98f3fa1d7) - [ ] [折叠屏iPhone维修费传8000元,苹果称尚未定价;腾讯Chatterfly输入法内测;微软高管称AI训练是「史上最大规模劳动盗窃」|极客早知道](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653113820&idx=1&sn=f0fbec42cd39f0844f985dd4b04222e8) - OnionSec - [ ] [从春天走到秋天](https://mp.weixin.qq.com/s?__biz=MzUyMTUwMzI3Ng==&mid=2247486017&idx=1&sn=b60b274839e45d2d2a15333714ff742e) - T00ls安全 - [ ] [十八而志,与子同袍 - tormail](https://mp.weixin.qq.com/s?__biz=Mzg3NzYzODU5NQ==&mid=2247485845&idx=1&sn=e0bbe6f8e76a33ecc679cd22aa3f598d) - IT Service Management News - [ ] [ISO 9001:2026](http://blog.cesaregallotti.it/2026/09/iso-90012026.html) - bellingcat - [ ] [Christy Kinahan’s UAE Residence Visa Cancelled](https://www.bellingcat.com/news/2026/09/19/christy-kinahans-uae-residence-visa-cancelled/) - Over Security - [ ] [Viral AI actress' hotline face-scans every caller, watches their mood](https://www.bleepingcomputer.com/news/security/viral-ai-actress-hotline-face-scans-every-caller-watches-their-mood/) - [ ] [BragJack attacks hijack AI browser agents through malicious extensions](https://www.bleepingcomputer.com/news/security/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions/) - [ ] [North Korean WaterPlum hackers infected 30,000 devices worldwide](https://www.bleepingcomputer.com/news/security/north-korean-waterplum-hackers-infected-30-000-devices-worldwide/) - [ ] [ShinyHunters hacks Clop leak site, threatens to extort ransomware gang](https://www.bleepingcomputer.com/news/security/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang/) - [ ] [Calling viral AI actress Tilly Norwood? Agree to a face scan first](https://www.bleepingcomputer.com/news/security/calling-viral-ai-actress-tilly-norwood-agree-to-a-face-scan-first/) - SANS Internet Storm Center, InfoCON: green - [ ] [HTTP QUERY Method: The Grey Zone Between GET And POST., (Fri, Sep 18th)](https://isc.sans.edu/diary/rss/33352) - 技术猫屋 - [ ] [现代 Web 框架共享原生图片处理链的攻击面拆解](https://mp.weixin.qq.com/s?__biz=Mzg4MzYxODA4Mw==&mid=2247484194&idx=1&sn=0385d879aac31fc35ae40227258d5c1c) - www.theregister.com - Articles - [ ] [Agentic security is the billion-dollar challenge for some clever startup to solve](https://www.theregister.com/security/2026/09/19/agentic-security-is-the-billion-dollar-challenge-for-some-clever-startup-to-solve/5297546) - Daniel Miessler - [ ] [My Early Thoughts on Jev](https://danielmiessler.com/blog/early-thoughts-on-jev?utm_source=rss&utm_medium=feed&utm_campaign=website) - KitPloit - PenTest Tools! - [ ] [rustinel v1.8.0-rc.1](https://kitploit.com/en/posts/github-karib0u-rustinel-v180-rc1) - [ ] [urx v0.11.0](https://kitploit.com/en/posts/github-hahwul-urx-0110) - [ ] [lightkeeper v1.4.1](https://kitploit.com/en/posts/github-worksbutnottested-lightkeeper-141) - [ ] [firefox-devtools-mcp v0.10.3](https://kitploit.com/en/posts/github-mozilla-firefox-devtools-mcp-v0103) - [ ] [xalgorix v4.6.78](https://kitploit.com/en/posts/github-xalgord-xalgorix-v4678) - [ ] [rspamd v4.2.0](https://kitploit.com/en/posts/github-rspamd-rspamd-420) - [ ] [Reversecore_MCP v3.0.4](https://kitploit.com/en/posts/github-sjkim1127-reversecore_mcp-v304) - [ ] [vigolium v0.4.8](https://kitploit.com/en/posts/github-vigolium-vigolium-v048) - [ ] [yakit v1.4.8-0919](https://kitploit.com/en/posts/github-yaklang-yakit-v148-0919) - [ ] [red-teaming-auto-mode](https://kitploit.com/en/tools/github/safety-research/red-teaming-auto-mode) - [ ] [ciso-assistant-community](https://kitploit.com/en/tools/github/intuitem/ciso-assistant-community) - [ ] [agent-scan v0.6.4-snapshot-6e2d290-1638](https://kitploit.com/en/posts/github-snyk-agent-scan-v064-snapshot-6e2d290-1638) - [ ] [maigret v0.6.6](https://kitploit.com/en/posts/github-soxoj-maigret-v066) - [ ] [wolfCOSE v2.0.0](https://kitploit.com/en/posts/github-wolfssl-wolfcose-v200) - [ ] [OpenAM v16.1.3](https://kitploit.com/en/posts/github-openidentityplatform-openam-1613) - [ ] [bunkerweb v1.6.15-rc3](https://kitploit.com/en/posts/github-bunkerity-bunkerweb-v1615-rc3) - [ ] [volatility3 v2.28.2](https://kitploit.com/en/posts/github-volatilityfoundation-volatility3-v2282) - [ ] [checkov v3.3.19](https://kitploit.com/en/posts/github-bridgecrewio-checkov-3319) - [ ] [proxmark3 v4.23346](https://kitploit.com/en/posts/github-rfidresearchgroup-proxmark3-v423346) - [ ] [frida-ssl-bypass](https://kitploit.com/en/tools/github/danieldev23/frida-ssl-bypass) - [ ] [Veridiff](https://kitploit.com/en/tools/github/veridiff/veridiff) - [ ] [js-x-ray @nodesecure/js-x-ray@16.1.0](https://kitploit.com/en/posts/github-nodesecure-js-x-ray-nodesecurejs-x-ray1610) - [ ] [evmbench-certora-agent-harness](https://kitploit.com/en/tools/github/gmh5225/evmbench-certora-agent-harness) - [ ] [sslscan v2.2.3](https://kitploit.com/en/posts/github-rbsec-sslscan-223) - [ ] [faraday v5.24.2](https://kitploit.com/en/posts/github-infobyte-faraday-v5242) - TorrentFreak - [ ] [South African Minister Tells Film Summit It Has a Double Standard on Piracy](https://torrentfreak.com/south-african-minister-tells-film-summit-it-has-a-double-standard-on-piracy/) - Security Affairs - [ ] [Google Gemini also Broke Out of Its Test Environment](https://securityaffairs.com/199392/ai/google-gemini-also-broke-out-of-its-test-environment.html) - [ ] [AI Helps Hackers Hijack OpenAI Staff Accounts Through a Forum](https://securityaffairs.com/199378/ai/ai-helps-hackers-hijack-openai-staff-accounts-through-a-forum.html) - The Hacker News - [ ] [Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws](https://thehackernews.com/2026/09/claude-opus-5-helped-researchers-take.html) - [ ] [Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar](https://thehackernews.com/2026/09/can-you-prove-new-cve-is-exploitable.html) - [ ] [Identity Visibility in 2026: The Foundation of Identity Security](https://thehackernews.com/2026/09/identity-visibility-in-2026-foundation.html) - [ ] [SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE](https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html) - [ ] [Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild](https://thehackernews.com/2026/09/critical-pre-auth-rce-in-orkes.html) - [ ] [Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up](https://thehackernews.com/2026/09/google-gemini-broke-into-real-company.html) - [ ] [CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories](https://thehackernews.com/2026/09/crowdsec-says-tanstack-npm-attack-led.html) - [ ] [CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild](https://thehackernews.com/2026/09/cisa-flags-three-linux-kernel.html) - Blackhat Library: Hacking techniques and research - [ ] [Back when you could just freely login to hundreds of active servers a day](https://www.reddit.com/r/blackhat/comments/1wkw4o5/back_when_you_could_just_freely_login_to_hundreds/)
每日安全资讯(2026-09-20)