# 每日安全资讯(2026-08-22) - Private Feed for M09Ic - [ ] [mgeeky starred j178/prek](https://github.com/j178/prek) - [ ] [gh0stkey starred curlconverter/curlconverter](https://github.com/curlconverter/curlconverter) - [ ] [kpcyrd contributed to kpcyrd/rebuilderd](https://github.com/kpcyrd/rebuilderd/pull/260) - [ ] [anthropics released v2.1.239 at anthropics/claude-code](https://github.com/anthropics/claude-code/releases/tag/v2.1.239) - [ ] [mgeeky starred openclaw/mcporter](https://github.com/openclaw/mcporter) - [ ] [bolucat released 202608212044 at bolucat/Archive](https://github.com/bolucat/Archive/releases/tag/202608212044) - [ ] [gh0stkey starred hardbeat920/monocode](https://github.com/hardbeat920/monocode) - [ ] [liamg contributed to liamg/grabber](https://github.com/liamg/grabber/pull/48) - [ ] [strands-agents released python/v1.53.0 at strands-agents/harness-sdk](https://github.com/strands-agents/harness-sdk/releases/tag/python/v1.53.0) - [ ] [mgeeky starred mrexodia/toilet-pi](https://github.com/mrexodia/toilet-pi) - [ ] [Mr-xn starred opensandbox-group/OpenSandbox](https://github.com/opensandbox-group/OpenSandbox) - [ ] [shmilylty starred 0xShe/PHP-Code-Audit-Skill](https://github.com/0xShe/PHP-Code-Audit-Skill) - [ ] [OpenAEV-Platform released 3.260821.0 at OpenAEV-Platform/openaev](https://github.com/OpenAEV-Platform/openaev/releases/tag/3.260821.0) - [ ] [niudaii starred t8y2/dbx](https://github.com/t8y2/dbx) - [ ] [esrrhs contributed to esrrhs/fakecc](https://github.com/esrrhs/fakecc/pull/27) - [ ] [veo starred MDX-Tom/gpt-5.6-instruct](https://github.com/MDX-Tom/gpt-5.6-instruct) - [ ] [INotGreen starred jihe520/MathModelAgent](https://github.com/jihe520/MathModelAgent) - [ ] [huoji120 starred jianghoucheng/AlphaEdit](https://github.com/jianghoucheng/AlphaEdit) - [ ] [pydantic released v2.33.0 at pydantic/pydantic-ai](https://github.com/pydantic/pydantic-ai/releases/tag/v2.33.0) - [ ] [esrrhs starred cordiverse/cordis](https://github.com/cordiverse/cordis) - [ ] [mgeeky starred koalaman/shellcheck](https://github.com/koalaman/shellcheck) - [ ] [panjf2000 starred deepseek-ai/deepseek-harness](https://github.com/deepseek-ai/deepseek-harness) - SecWiki News - [ ] [SecWiki News 2026-08-21 Review](http://www.sec-wiki.com/?2026-08-21) - CXSECURITY Database RSS Feed - CXSecurity.com - [ ] [Laravel Socialite < 5.29.0 - Facebook OIDC Nonce Replay Authentication Bypass](https://cxsecurity.com/issue/WLB-2026080013) - [ ] [WordPress Plugin WPZOOM Portfolio 1.4.21 Reflected Cross-Site Scripting (XSS)](https://cxsecurity.com/issue/WLB-2026080012) - [ ] [WooCommerce 1.5.0 Unauthenticated Arbitrary File Upload](https://cxsecurity.com/issue/WLB-2026080011) - [ ] [PCMan 2.0.7 Buffer Overflow](https://cxsecurity.com/issue/WLB-2026080010) - Doonsec's feed - [ ] [DSH渗透测试插件dsh-pentest全新升级!适配DeepSeek Harness,可视化探索链路,一键搭建轻量化AI渗透测试环境。](https://mp.weixin.qq.com/s/TB7czIXIe-FnWFIDxuuGbA) - Recent Commits to cve:main - [ ] [Update Fri Aug 21 12:30:26 UTC 2026](https://github.com/trickest/cve/commit/452b995d13047bf6493509009d048af049598e13) - Sploitus.com Exploits RSS Feed - [ ] [SOC-Lab-Vulnerability-Assessment exploit](https://sploitus.com/exploit?id=458CF757-B0D4-5D27-9E5F-5C580E9B0B64&utm_source=rss&utm_medium=rss) - [ ] [OSCP-Exploits](https://sploitus.com/exploit?id=B17F5F4E-FAAD-5D43-863A-769ED873F3AB&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Improper Authentication in Apple Macos](https://sploitus.com/exploit?id=1E99C40C-4AFC-56D3-AA4D-08A333199E02&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Improper Access Control in Widgetfactorylimited Jce](https://sploitus.com/exploit?id=BB3A85A9-468E-5902-9898-74122FCE6534&utm_source=rss&utm_medium=rss) - [ ] [dsh2shell exploit](https://sploitus.com/exploit?id=778FE329-C74E-5319-BD17-07ED1918598D&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-58455](https://sploitus.com/exploit?id=95C7431E-4F72-576F-BC08-274AD2697E6D&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-76564](https://sploitus.com/exploit?id=B44477A4-3D6C-5E09-AA00-D0C0AE67D2FE&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-76565](https://sploitus.com/exploit?id=877CAA6E-74E6-576F-AA23-134CBADD46AF&utm_source=rss&utm_medium=rss) - [ ] [live-copilot-poc exploit](https://sploitus.com/exploit?id=9975179A-6D96-51D2-8868-964637C544EB&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Heap-based Buffer Overflow in Google Chrome](https://sploitus.com/exploit?id=7F343D08-06CA-5E53-A922-E56B77B0C592&utm_source=rss&utm_medium=rss) - [ ] [Exploit for OS Command Injection in Devcode Openstamanager](https://sploitus.com/exploit?id=39DE119C-3F7A-5EB6-915A-EDBD561DB43A&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-64638](https://sploitus.com/exploit?id=71F7EA57-BC87-578C-B747-9E165851B9B4&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-19598](https://sploitus.com/exploit?id=881796AE-5A53-58CA-A576-442889ADF147&utm_source=rss&utm_medium=rss) - [ ] [VulnScan exploit](https://sploitus.com/exploit?id=B88075DB-94CD-5943-B9B5-A49339631325&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-41567](https://sploitus.com/exploit?id=8D3466F1-84C1-5B91-9BB5-ACEC8212C746&utm_source=rss&utm_medium=rss) - [ ] [mcp-recon exploit](https://sploitus.com/exploit?id=6B73DB8A-924E-537B-B849-E7039FD530AE&utm_source=rss&utm_medium=rss) - [ ] [prismsec exploit](https://sploitus.com/exploit?id=A8BA3225-0EF8-50FA-9C4A-22D3BE52D2FB&utm_source=rss&utm_medium=rss) - [ ] [PoC-Exploit](https://sploitus.com/exploit?id=3B966B55-C44B-594F-A22B-E78277419152&utm_source=rss&utm_medium=rss) - [ ] [cveye exploit](https://sploitus.com/exploit?id=33F0E442-853F-5822-8EFC-64D4284CBB14&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-39113](https://sploitus.com/exploit?id=A820751A-E413-589A-97E0-4BAD8D4D0CB3&utm_source=rss&utm_medium=rss) - [ ] [binary-exploitation-mitigation-bypass-lab](https://sploitus.com/exploit?id=35947CA0-5E17-5E69-983B-A11A4F4F0B82&utm_source=rss&utm_medium=rss) - [ ] [Offstep-Exploit](https://sploitus.com/exploit?id=ABDF584C-1E77-535C-82F0-8504335EC8B7&utm_source=rss&utm_medium=rss) - [ ] [Chrome_Issue992914 exploit](https://sploitus.com/exploit?id=3E770CA1-3FD1-5CD8-90A6-AA20D9AD021C&utm_source=rss&utm_medium=rss) - [ ] [V2E_artifacts exploit](https://sploitus.com/exploit?id=79D8AB3B-D7A9-53DE-B14D-2762D712DE00&utm_source=rss&utm_medium=rss) - [ ] [Exploit for SQL Injection in Sequelizejs Sequelize](https://sploitus.com/exploit?id=3C366C70-5F3B-5ECB-876E-F3F1B2B87C3A&utm_source=rss&utm_medium=rss) - [ ] [Exploit for SQL Injection in Mikro-Orm Mikroorm](https://sploitus.com/exploit?id=38BC0585-FDF3-5F58-879A-F1C19560E220&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-0603](https://sploitus.com/exploit?id=6C73067A-0EFF-5401-91BC-98C2674FB633&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Expression Language Injection in Mathjs](https://sploitus.com/exploit?id=6D3C328C-7452-53BB-9635-27F2B38233DC&utm_source=rss&utm_medium=rss) - 安全客-有思想的安全新媒体 - [ ] [保镖成了内鬼:微软Defender再曝零日漏洞,普通账户一键提权SYSTEM,补丁还没用](https://www.anquanke.com/post/id/316003) - Verne in GitHub - [ ] [把 Android 手机当成 USB 无线网卡:以及那些被低估的安卓妙用](https://blog.einverne.info/post/2026/08/android-phone-as-usb-network-adapter-and-more.html) - 小刀志 - [ ] [从 PE 到 PKCS#7:深入理解 Windows PE 数字签名机制](https://xiaodaozhi.com/security/482.html) - Kitploit - [ ] [awesome-web3-security](https://kitploit.com/en/tools/github/gmh5225/awesome-web3-security) - [ ] [intentshield v1.3.0](https://kitploit.com/en/posts/github-mattijsmoens-intentshield-v130) - [ ] [binsync v5.15.4](https://kitploit.com/en/posts/github-binsync-binsync-v5154) - [ ] [build.prop build-20260821](https://kitploit.com/en/posts/github-pixel-props-buildprop-build-20260821) - [ ] [mcpsnoop v0.19.0](https://kitploit.com/en/posts/github-kerlenton-mcpsnoop-v0190) - [ ] [OnionHop v3.8.1](https://kitploit.com/en/posts/github-center2055-onionhop-v381) - [ ] [HaE HaEFile-1.0.3](https://kitploit.com/en/posts/github-overspace-labs-hae-haefile-103) - [ ] [Krawl v2.3.0](https://kitploit.com/en/posts/github-blessedrebus-krawl-v230) - [ ] [prowler v5.39.1](https://kitploit.com/en/posts/github-prowler-cloud-prowler-5391) - [ ] [yakit v1.4.8-0821](https://kitploit.com/en/posts/github-yaklang-yakit-v148-0821) - [ ] [emp3r0r v4.11.0](https://kitploit.com/en/posts/github-jm33-m0-emp3r0r-v4110) - [ ] [edk2 edk2-stable202608](https://kitploit.com/en/posts/github-tianocore-edk2-edk2-stable202608) - [ ] [retire.js v5.5.0](https://kitploit.com/en/posts/github-retirejs-retirejs-550) - [ ] [claude-bug-bounty v6.0.0](https://kitploit.com/en/posts/github-shuvonsec-claude-bug-bounty-v600) - [ ] [awesome-llvm-security](https://kitploit.com/en/tools/github/gmh5225/awesome-llvm-security) - [ ] [awesome-game-security](https://kitploit.com/en/tools/github/gmh5225/awesome-game-security) - [ ] [camoufox v152.0.4-beta.29](https://kitploit.com/en/posts/github-daijro-camoufox-v15204-beta29) - [ ] [prismsec](https://kitploit.com/en/tools/github/azmisyahrul/prismsec) - [ ] [agentic-dm-gateway](https://kitploit.com/en/tools/gitlab/wattocyber/agentic-dm-gateway) - [ ] [Sandb0x-Xtract0r](https://kitploit.com/en/tools/github/darnellwashingtonjr94-art/sandb0x-xtract0r) - [ ] [detection-defense-library](https://kitploit.com/en/tools/gitlab/wattocyber/detection-defense-library) - [ ] [custom-oscp-tooling](https://kitploit.com/en/tools/gitlab/wattocyber/custom-oscp-tooling) - [ ] [mcp-stdio-shellguard v0.1.2](https://kitploit.com/en/posts/github-studiomeyer-io-mcp-stdio-shellguard-v012) - [ ] [oscp-notes-2026](https://kitploit.com/en/tools/gitlab/wattocyber/oscp-notes-2026) - [ ] [cantina](https://kitploit.com/en/tools/gitlab/wattocyber/cantina) - [ ] [Sitadel v1.5.1](https://kitploit.com/en/posts/github-shenril-sitadel-v151) - [ ] [pbtk v1.1.3](https://kitploit.com/en/posts/github-marin-m-pbtk-113) - [ ] [iDescriptor v0.6.2](https://kitploit.com/en/posts/github-idescriptor-idescriptor-v062) - [ ] [badkeys v0.0.20](https://kitploit.com/en/posts/github-badkeys-badkeys-v0020) - [ ] [mora-hwbp](https://kitploit.com/en/tools/github/dovughs/mora-hwbp) - [ ] [lure v0.5.1](https://kitploit.com/en/posts/github-0xusmanismail-lure-v051) - [ ] [deadair v0.6.0](https://kitploit.com/en/posts/github-big-comfy-deadair-v060) - [ ] [node9-proxy v1.67.3](https://kitploit.com/en/posts/github-node9-ai-node9-proxy-v1673) - [ ] [bramble v1.18.0-chromium](https://kitploit.com/en/posts/github-flythenimbus-bramble-1180-chromium) - [ ] [tailscale v1.102.3](https://kitploit.com/en/posts/github-tailscale-tailscale-v11023) - [ ] [rustnet v1.6.0](https://kitploit.com/en/posts/github-domcyrus-rustnet-v160) - [ ] [Signal-iOS v8.25.0.1809](https://kitploit.com/en/posts/github-signalapp-signal-ios-82501809) - [ ] [renovate-operator v6.0.1](https://kitploit.com/en/posts/github-mogenius-renovate-operator-601) - [ ] [pipelock v3.4.0](https://kitploit.com/en/posts/github-luckypipewrench-pipelock-v340) - [ ] [monitor v0.39.0](https://kitploit.com/en/posts/github-betterdb-inc-monitor-v0390) - [ ] [asterisk v23.5.0-rc2](https://kitploit.com/en/posts/github-asterisk-asterisk-2350-rc2) - [ ] [UltraViolet v1.0.11](https://kitploit.com/en/posts/github-yakushstanislav-ultraviolet-v1011) - [ ] [mboxshell v0.7.1](https://kitploit.com/en/posts/github-dcarrero-mboxshell-v071) - [ ] [wlctl v0.1.10](https://kitploit.com/en/posts/github-aashish-thapa-wlctl-v0110) - Horizon3 - [ ] [How a Manufacturer Turned Password Risk Into Measurable Security Action](https://horizon3.ai/customer-story/how-a-manufacturer-turned-password-risk-into-measurable-security-action/) - Reverse Engineering - [ ] [I reverse engineered Hikvision's push notifications on GrapheneOS, released a patcher tool, and submitted a fix PR](https://www.reddit.com/r/ReverseEngineering/comments/1vuo4kf/i_reverse_engineered_hikvisions_push/) - [ ] [Reverse-engineered a gaming mouse’s HID protocol to bring it to Linux (beta out, some pieces still unsolved)](https://www.reddit.com/r/ReverseEngineering/comments/1vuqobr/reverseengineered_a_gaming_mouses_hid_protocol_to/) - [ ] [I reverse engineered the Plants vs. Zombies' RNG](https://www.reddit.com/r/ReverseEngineering/comments/1vuk1ij/i_reverse_engineered_the_plants_vs_zombies_rng/) - [ ] [BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive](https://www.reddit.com/r/ReverseEngineering/comments/1vuid10/btr_reforged_weaponizing_defenders_remediation/) - [ ] [Advanced Static malware analyzer that reveals 8 injection techniques, critical API calls, hidden strings, exports PE sections (.text, .rdata) as .bin, supports PE/ELF/Mach-O/scripts, and integrates 60+ AV engines via VirusTotal - Open Source](https://www.reddit.com/r/ReverseEngineering/comments/1vucgfy/advanced_static_malware_analyzer_that_reveals_8/) - [ ] [Need help with this crackme](https://www.reddit.com/r/ReverseEngineering/comments/1vu7fsl/need_help_with_this_crackme/) - Malware-Traffic-Analysis.net - Blog Entries - [ ] [2026-08-21: SmartApeSG ClickFix campaign leads to two RATs](https://www.malware-traffic-analysis.net/2026/08/21/index.html) - ADD / XOR / ROL - [ ] [Three important steps in my maturation process](http://addxorrol.blogspot.com/2026/08/three-important-steps-in-my-maturation.html) - Malwarebytes - [ ] [Zombie Card: An expired Visa credit card can be used for purchases](https://www.malwarebytes.com/blog/news/2026/08/zombie-card-an-expired-visa-credit-card-can-be-used-for-purchases) - [ ] [Medical records, SSNs, and bank details exposed in CareCloud data breach](https://www.malwarebytes.com/blog/news/2026/08/medical-records-ssns-and-bank-details-exposed-in-carecloud-data-breach) - Securelist - [ ] [The invisible passenger in your car](https://securelist.com/android-head-unit-malware/121106/) - SentinelOne - [ ] [The Good, the Bad and the Ugly in Cybersecurity – Week 34](https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-34-8/) - Dancho Danchev's Blog - Mind Streams of Information Security Knowledge - [ ] [Who Is REvil's Ransomware Developer Anatoly Sergeevitsch Kravchuk?](https://ddanchev.blogspot.com/2026/08/who-is-revils-ransomware-developer.html) - 奇客Solidot–传递最新科技情报 - [ ] [中国准备发射嫦娥七号,前往月球南极寻找水冰](https://www.solidot.org/story?sid=85160) - [ ] [微软隐藏 OneDrive Photos,但该应用并未删除](https://www.solidot.org/story?sid=85159) - [ ] [微软调查部分用户在安装 Windows 11 八月安全更新后遭遇游戏崩溃的报告](https://www.solidot.org/story?sid=85158) - [ ] [混合型 T 细胞在超级百岁老人血液中显著增加](https://www.solidot.org/story?sid=85157) - [ ] [达斯·维达赞美 Flock 车牌跟踪系统](https://www.solidot.org/story?sid=85156) - [ ] [Bilibili 进军国际市场](https://www.solidot.org/story?sid=85155) - [ ] [天文学家发现银河系已知最快的恒星](https://www.solidot.org/story?sid=85154) - [ ] [Thunderbird 跟随 Firefox 采用双周发布模式](https://www.solidot.org/story?sid=85153) - [ ] [太阳能扩张政策与鸟类多样性下降相关](https://www.solidot.org/story?sid=85152) - HackerNews - [ ] [Zimbra 高危远程代码执行漏洞现已遭到实际利用](http://0.0.0.0:8080/post/64583) - [ ] [新型 Android 恶意软件 Manic:可借助周边受感染设备窃取外传数据](http://0.0.0.0:8080/post/64582) - [ ] [Citrix 敦促管理员尽快修补 NetScaler 新漏洞](http://0.0.0.0:8080/post/64581) - [ ] [Elementor Pro 高危漏洞可导致 WordPress 网站远程代码执行](http://0.0.0.0:8080/post/64580) - [ ] [疑似俄罗斯黑客滥用谷歌合法认证流程开展间谍钓鱼活动](http://0.0.0.0:8080/post/64579) - 360 Netlab Blog - Network Security Research Lab at 360 - [ ] [AI安全专题周报](https://blog.netlab.360.com/aian-quan-zhuan-ti-zhou-bao-3/) - 黑鸟 - [ ] [花几欧元买下一个过期域名,意外记录了数十万条打向军事基地的电话](https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451188175&idx=1&sn=5957e5c6803cf3a7a1610b62b37d0f87) - 锦行科技 - [ ] [产教融合聚力,共研网安育人新模式--网安专业一流课程建设研讨会顺利举办](https://mp.weixin.qq.com/s?__biz=MzIxNTQxMjQyNg==&mid=2247494993&idx=1&sn=50b6e5ece81e89e24efd0819244addcf) - 信息时代的犯罪侦查 - [ ] [有偿征集大数据应用思路](https://mp.weixin.qq.com/s?__biz=MzAxNTA4NDAwOQ==&mid=2650737062&idx=1&sn=afd10681c6cfa7679f4319047509fd61) - 微步在线研究响应中心 - [ ] [2.45亿次下载的Rust包arrayref被投毒](https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&mid=2247508844&idx=1&sn=dfecf255881fedd5771d3d22cadd083a) - 威努特安全网络 - [ ] [威努特超融合一体机亮相华为湖南生态大会](https://mp.weixin.qq.com/s?__biz=MzAwNTgyODU3NQ==&mid=2651143613&idx=1&sn=a6b3ee597254d77e280765ee52c7a453) - 暗影安全 - [ ] [没有 0day,也能瘫痪一座电厂](https://mp.weixin.qq.com/s?__biz=MzI2MzA3OTgxOA==&mid=2657165799&idx=1&sn=946395dfdb6f9b9c1eefb1a9a532671f) - 安全内参 - [ ] [首个政府预警!AI驱动攻击已对水务、能源等行业构成真实威胁](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516468&idx=1&sn=9965d010744a2b88eee0297016cac828) - [ ] [特朗普网络攻击新政策遭遇俄罗斯“灰色地带”困境](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516468&idx=2&sn=1710423afc9e0ece818035895eee6c4a) - 安全客 - [ ] [保镖成了内鬼:微软Defender再曝零日漏洞,普通账户一键提权SYSTEM,补丁还没用](https://mp.weixin.qq.com/s?__biz=MzA5ODA0NDE2MA==&mid=2649790398&idx=1&sn=09a5b3324cc9783656c9f5b7a4cf0e8c) - 代码卫士 - [ ] [Zimbra SNMP 未认证 RCE 漏洞已遭利用](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247526941&idx=1&sn=11e4c40814e3f01c72e6879ff92a5b4c) - [ ] [Rust 三个热门crate遭投毒,被用于供应链攻击](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247526941&idx=2&sn=788a548f95d9b2c816994f379dbef5d5) - 绿盟科技研究通讯 - [ ] [AI与云安全事件案例分析周报|2026.08.17 - 2026.08.21](https://mp.weixin.qq.com/s?__biz=MzIyODYzNTU2OA==&mid=2247500228&idx=1&sn=5a4c60d70f5f377f8eb3ce4961b91b8b) - 安全研究GoSSIP - [ ] [G.O.S.S.I.P 阅读推荐 2026-08-21 空中危机](https://mp.weixin.qq.com/s?__biz=Mzg5ODUxMzg0Ng==&mid=2247502010&idx=1&sn=d71ec2b60f7f896f180fbaf36a090dec) - 数世咨询 - [ ] [人工智能加剧网络攻击 思科防火墙订单增长超30%](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247543725&idx=1&sn=17c960413426c0e034c90882d1576c75) - [ ] [8月28日北京见:XCon2026,9场AI安全硬核实战,等你落座,门票开抢!](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247543725&idx=2&sn=fbd1aaf49c3f6a88985db07428ceea3f) - [ ] [新规今日施行 |《网络数据安全风险评估办法》学习理解划重点](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247543725&idx=3&sn=361bb2493a49f87a5cb2a1a58a5cfc8c) - 中国信息安全 - [ ] [论坛·原创 | 人工智能军事应用的安全风险和治理路径](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265776&idx=1&sn=7d477640d563911df31501f5798c6366) - [ ] [前沿 | 以丰富国际公共产品供给引领人工智能全球治理](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265776&idx=2&sn=aaa9488dede2cf2ebf14b55fab1c77f8) - [ ] [观点 | AI认知环境成话语权博弈关键点](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265776&idx=3&sn=161a47a0ed204484cccf4716db621f7a) - [ ] [法治 | “网络水军”违法犯罪的新情况新动向、治理难点及对策建议](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265776&idx=4&sn=2e4069f08f7719f63518b4f3afe6c62e) - [ ] [评论 | 厚植法治素养 守护清朗空间](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265776&idx=5&sn=edbe78bf6dcb5408c6a31d01d1a2a051) - 奇安信 CERT - [ ] [安全热点周报:黑客利用 macOS 屏幕共享漏洞部署门罗币挖矿程序](https://mp.weixin.qq.com/s?__biz=MzU5NDgxODU1MQ==&mid=2247507178&idx=1&sn=11d97e33c51432a1d87745724fb2c4e8) - M01N Team - [ ] [每周蓝军技术推送(2026.8.15-8.21)](https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&mid=2247495419&idx=1&sn=35ee667ce921a5c4ca8e8cb628169d7b) - 长亭科技 - [ ] [限时开放下载|一份可落地的 AI 安全实战指南!附企业实施全路径](https://mp.weixin.qq.com/s?__biz=MzIwNDA2NDk5OQ==&mid=2651390618&idx=1&sn=f29b0d8e7027f7ad443093aff4f8f991) - 安全圈 - [ ] [【安全圈】微软Entra_ID曝满分漏洞:无需凭据远程代码执行](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078384&idx=1&sn=a9a371c2b58a0b4e29ce4be72c93ae9f) - [ ] [【安全圈】Rust生态遭供应链投毒:编译即触发执行恶意后门](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078384&idx=2&sn=584bb5bc43fa1c97b2c06330516c2e27) - [ ] [【安全圈】GitLab曝严重代码注入:公开项目面临任意篡改](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078384&idx=3&sn=7ff2787dd6ecc28cbc0d963d8d2b7940) - 唯品会安全应急响应中心 - [ ] [关于 VSRC 例行维护的通知](https://mp.weixin.qq.com/s?__biz=MzI5ODE0ODA5MQ==&mid=2652281765&idx=1&sn=c961e1014f7385ebd8683615102ab0b5) - 奇安信威胁情报中心 - [ ] [2.45亿次下载的Rust基石crate被投毒:一次编译,就是一次沦陷](https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247519957&idx=1&sn=b666c8c8fef193b22443d9861d95d60c) - [ ] [每周高级威胁情报解读(2026.08.14~08.20)](https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247519957&idx=2&sn=aafeada85716143c834687ec457e4034) - 腾讯安全威胁情报中心 - [ ] [AI 蠕虫已现形:AI 基建成为攻击者的循环攻击温床](https://mp.weixin.qq.com/s?__biz=MzI5ODk3OTM1Ng==&mid=2247512062&idx=1&sn=4b18cf041e6f0fa7f68cdc87f745adc3) - 复旦白泽战队 - [ ] [首尔盛夏:ICML'26 行记](https://mp.weixin.qq.com/s?__biz=MzU4NzUxOTI0OQ==&mid=2247499636&idx=1&sn=39b9507dd33bf4f80f58ce917316f984) - 安全牛 - [ ] [你采购的不是软件,而是一个会"进化"的供应链风险:AI供应商选型实操指南](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142415&idx=1&sn=45526c5a275bc733ada708275701bd9a) - [ ] [Microsoft Defender更新引发扫描崩溃,快速和完整扫描大面积失效;全国网安标委就座舱数据处理安全要求公开征求意见| 牛览](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142415&idx=2&sn=d0cae1fe5a9341e4c56a956489484e93) - 火绒安全 - [ ] [安全预警:360签名漏洞驱动被恶意利用 可致终端安全防护失效](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247536697&idx=1&sn=3a18cfe3988300974634b7172c086e5f) - [ ] [火绒小问答——「企业版」信任文件](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247536697&idx=2&sn=7a0e1321f9ad3869c9fb310c7fba1fe5) - [ ] [【火绒安全周报】西安某公司遭勒索攻击/宝可梦确认数据泄露](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247536697&idx=3&sn=67877d1affbcccd3492b1ae83bbd1cc0) - [ ] [诚邀渠道合作伙伴共启新征程](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247536697&idx=4&sn=2007b572653de80a2dc265582ab44b71) - 极客公园 - [ ] [形界智能:沿用两段式架构,是市场对 AI 实时视频的最大误判](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653112471&idx=1&sn=0281317712e3f2dd0b03470be31aef59) - [ ] [AI 音乐走到「该怎么做」,中国大模型为啥选最难的路?](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653112471&idx=2&sn=87eace7a36a3cda67f657c00377b117e) - [ ] [从单点突破到全数 SOTA,阿里打响「模型团战」第一枪](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653112452&idx=1&sn=9db8790e3a9e6265ae282f25a49b4944) - [ ] [逛完 WRC,我们发现机器人行业最该回答的 5 个问题](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653112437&idx=1&sn=dbcbf186c2fef7dab461f2cf8d2a76b4) - 字节跳动技术团队 - [ ] [豆包大模型测评招募丨寻找行业资深AI实践者](https://mp.weixin.qq.com/s?__biz=MzI1MzYzMjE0MQ==&mid=2247521383&idx=1&sn=abb9e4f892fdc334e752ca8c3c4483d1) - 奇安信病毒响应中心 - [ ] [每周勒索威胁摘要](https://mp.weixin.qq.com/s?__biz=MzI5Mzg5MDM3NQ==&mid=2247498635&idx=1&sn=afccb4538ed5f7ebf7334613d9a1f12e) - 安全分析与研究 - [ ] [第16篇-勒索组织情报画像库](https://mp.weixin.qq.com/s?__biz=MzA4ODEyODA3MQ==&mid=2247497039&idx=1&sn=ad5348f15be6c8a291d2dc868369144e) - 看雪学苑 - [ ] [2026 KCTF | 第七题《戌时·暗能潜流》设计思路及解析](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458618874&idx=1&sn=354a1884e7d6d70cc0abb8ee54c88e8a) - [ ] [8月28日北京见:XCon2026,9场AI安全硬核实战,等你落座,门票开抢!](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458618874&idx=2&sn=63f8c0533f1b004781182a9746d59f9a) - [ ] [脱离苹果硬件!Linux系统可合规接入苹果定位服务](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458618874&idx=3&sn=351eb3b86465620afa621aae4a861c71) - 慢雾科技 - [ ] [8 月 28 日香港见|从稳定币到 AI Agent,慢雾将亮相香港多场行业活动](https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&mid=2247505751&idx=1&sn=4cb1442cc5927e47964438d6b2728b79) - Beacon Tower Lab - [ ] [【0821】重保演习每周情报汇总](https://mp.weixin.qq.com/s?__biz=MzkyNzcxNTczNA==&mid=2247488359&idx=1&sn=01249c3c0d9d86a08ed68eb9938850cc) - 威胁猎人Threat Hunter - [ ] [机器越来越像人,平台还能识别出来吗?我们用8台设备做了一次实验](https://mp.weixin.qq.com/s?__biz=MzI3NDY3NDUxNg==&mid=2247505049&idx=1&sn=834389a1dbd86356daa6852cf548a66c) - Over Security - [ ] [Hackers abuse FTP server banners to deliver new Windows malware](https://www.bleepingcomputer.com/news/security/hackers-abuse-ftp-server-banners-to-deliver-new-windows-malware/) - [ ] [Phishing ai danni del Ministero della Salute sfrutta un falso “rimborso ticket sanitario”](https://cert-agid.gov.it/news/phishing-ai-danni-del-ministero-della-salute-sfrutta-un-falso-rimborso-ticket-sanitario/) - [ ] [SickKids data breach exposes employee and job applicant info](https://www.bleepingcomputer.com/news/security/sickkids-data-breach-exposes-employee-and-job-applicant-info/) - [ ] [Endpoint Blind Spots: The 5 Places Ransomware Hides Before It Detonates](https://cyble.com/blog/ransomware-attack-vectors-endpoint-blind-spots/) - [ ] [Automazione e gestione del rischio nel SOC moderno](https://www.cybersecurity360.it/cultura-cyber/automazione-e-gestione-del-rischio-nel-soc-moderno/) - [ ] [Sicurezza dei siti web: quali garanzie cercare in un piano hosting](https://www.cybersecurity360.it/cultura-cyber/cloud-hosting-sicurezza-data-center-dati-personali/) - [ ] [The invisible passenger in your car](https://securelist.com/android-head-unit-malware/121106/) - [ ] [Il “will” del GDPR: la volontà che trasforma il dovere in accountability](https://www.cybersecurity360.it/legal/privacy-dati-personali/il-will-del-gdpr-la-volonta-che-trasforma-il-dovere-in-accountability/) - 丁爸 情报分析师的工具箱 - [ ] [【开源报告】美国“金穹”(Golden Dome)导弹防御系统深度分析](https://mp.weixin.qq.com/s?__biz=MzI2MTE0NTE3Mw==&mid=2651157024&idx=1&sn=75b368a6c59391969d39fbb7c95295b1) - [ ] [【通知】第六届开源情报技术大会拟于2026年11月贵阳召开](https://mp.weixin.qq.com/s?__biz=MzI2MTE0NTE3Mw==&mid=2651157024&idx=2&sn=b3192dcc968c8f6de1c62b9da7c1b5c8) - 白泽安全实验室 - [ ] [疑似Lazarus组织成员遭反向钓鱼设局,渗透全流程被完整捕获](https://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&mid=2247492974&idx=1&sn=425c3cc0d05bd09d98db2570f89243d0) - Yak Project - [ ] [让 AI Agent 跑得更快:Memfit 速度优化](https://mp.weixin.qq.com/s?__biz=Mzk0MTM4NzIxMQ==&mid=2247530078&idx=1&sn=108a53239a83a19674e5996694208a52) - 安全419 - [ ] [软件供应链安全的十字路口:当AI“自己干了”,本土厂商如何破局?](https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&mid=2247554548&idx=1&sn=a47c2d217ca48bab2774f185acc3d033) - [ ] [8月28日北京见:XCon2026,9场AI安全硬核实战,等你落座,门票开抢!](https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&mid=2247554548&idx=2&sn=334e294a142d7dd3b1b24b2498df0065) - Schneier on Security - [ ] [Friday Squid Blogging: Neon Flying Squid](https://www.schneier.com/blog/archives/2026/08/friday-squid-blogging-neon-flying-squid.html) - [ ] [AI Is Learning to Write Genetic Code](https://www.schneier.com/blog/archives/2026/08/ai-is-learning-to-write-genetic-code.html) - [ ] [More Incidents of AIs Going Rogue in Cybersecurity Challenges](https://www.schneier.com/blog/archives/2026/08/more-incidents-of-ais-going-rogue-in-cybersecurity-challenges.html) - LockBoxx - [ ] [Building Tools for the Games I Love](http://blog.lockboxx.org/2026/08/building-tools-for-games-i-love.html) - SEI Blog - [ ] [Visualizing Infrastructure Security at Software Project Inception](https://www.sei.cmu.edu/blog/visualizing-infrastructure-security-at-software-project-inception/?utm_source=blog&utm_medium=rss&utm_campaign=my_site_updates) - NETRESEC Network Security Blog - [ ] [CNCMachineRMS C2 Protocol](https://www.netresec.com/?page=Blog&month=2026-08&post=CNCMachineRMS-C2-Protocol) - SANS Internet Storm Center, InfoCON: green - [ ] [Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!, (Fri, Aug 21st)](https://isc.sans.edu/diary/rss/33272) - [ ] [ISC Stormcast For Friday, August 21st, 2026 https://isc.sans.edu/podcastdetail/10062, (Fri, Aug 21st)](https://isc.sans.edu/diary/rss/33270) - [ ] [Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays, (Fri, Aug 21st)](https://isc.sans.edu/diary/rss/33268) - LastKnight.com Feed - [ ] [Bacco, Tabacco e Social: come Internet sta per cambiare](https://mgpf.it/2026/08/21/bacco-tabacco-e-social.html) - NetSPI - [ ] [Introducing EchoBench: A Human Calibrated Benchmark for Autonomous Pentesting](https://www.netspi.com/blog/technical-blog/ai-ml-pentesting/introducing-echobench-a-human-calibrated-benchmark-for-autonomous-pentesting/) - [ ] [Verifying the Verifier – Assessing Identity Verification Services](https://www.netspi.com/blog/executive-blog/social-engineering/verifying-the-verifier-assessing-identity-verification-services/) - The Hacker News - [ ] [14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2](https://thehackernews.com/2026/08/14-trojanized-npm-packages-drop-redc2.html) - [ ] [Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot](https://thehackernews.com/2026/08/microsoft-defenders-own-driver-can-be.html) - [ ] [Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet](https://thehackernews.com/2026/08/android-car-malware-spreads-through.html) - [ ] [Wazuh and AI For Enhanced SOC Workflows](https://thehackernews.com/2026/08/wazuh-and-ai-for-enhanced-soc-workflows.html) - [ ] [Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0](https://thehackernews.com/2026/08/cisco-patches-nine-crosswork-and-secure.html) - [ ] [GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure](https://thehackernews.com/2026/08/gitlab-cve-2026-19478-comes-under.html) - [ ] [Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution](https://thehackernews.com/2026/08/microsoft-entra-id-flaw-cvss-100.html) - Security Affairs - [ ] [Your Shredded Visa Card May Still Work at the Checkout](https://securityaffairs.com/197663/hacking/your-shredded-visa-card-may-still-work-at-the-checkout.html) - [ ] [Six Maximum-Severity Flaws Found in Cisco Products](https://securityaffairs.com/197640/security/six-maximum-severity-flaws-found-in-cisco-products.html) - [ ] [Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics](https://securityaffairs.com/197630/apt/fake-conferences-oauth-and-whatsapp-inside-russias-new-espionage-tactics.html) - [ ] [GitLab Warns of Active Exploitation of Critical GraphQL Flaw](https://securityaffairs.com/197622/uncategorized/gitlab-warns-of-active-exploitation-of-critical-graphql-flaw.html) - [ ] [Poland’s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite Flaw](https://securityaffairs.com/197610/security/polands-cert-warns-of-active-exploitation-of-critical-zimbra-collaboration-suite-flaw.html) - [ ] [U.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog](https://securityaffairs.com/197602/security/u-s-cisa-adds-trueconf-server-flaws-to-its-known-exploited-vulnerabilities-catalog.html) - [ ] [Cl0p Targets 40+ Organizations Through PTC Windchill Flaw](https://securityaffairs.com/197587/cyber-crime/cl0p-targets-40-organizations-through-ptc-windchill-flaw.html) - Deep Web - [ ] [What Happened to r/darknet_questions?](https://www.reddit.com/r/deepweb/comments/1vuwc3n/what_happened_to_rdarknet_questions/) - [ ] [Good place to find .onion links](https://www.reddit.com/r/deepweb/comments/1vu0pe9/good_place_to_find_onion_links/) - KitPloit - PenTest Tools! - [ ] [awesome-web3-security](https://kitploit.com/en/tools/github/gmh5225/awesome-web3-security) - [ ] [intentshield v1.3.0](https://kitploit.com/en/posts/github-mattijsmoens-intentshield-v130) - [ ] [binsync v5.15.4](https://kitploit.com/en/posts/github-binsync-binsync-v5154) - [ ] [build.prop build-20260821](https://kitploit.com/en/posts/github-pixel-props-buildprop-build-20260821) - [ ] [mcpsnoop v0.19.0](https://kitploit.com/en/posts/github-kerlenton-mcpsnoop-v0190) - [ ] [OnionHop v3.8.1](https://kitploit.com/en/posts/github-center2055-onionhop-v381) - [ ] [HaE HaEFile-1.0.3](https://kitploit.com/en/posts/github-overspace-labs-hae-haefile-103) - [ ] [Krawl v2.3.0](https://kitploit.com/en/posts/github-blessedrebus-krawl-v230) - [ ] [prowler v5.39.1](https://kitploit.com/en/posts/github-prowler-cloud-prowler-5391) - [ ] [yakit v1.4.8-0821](https://kitploit.com/en/posts/github-yaklang-yakit-v148-0821) - [ ] [emp3r0r v4.11.0](https://kitploit.com/en/posts/github-jm33-m0-emp3r0r-v4110) - [ ] [edk2 edk2-stable202608](https://kitploit.com/en/posts/github-tianocore-edk2-edk2-stable202608) - [ ] [retire.js v5.5.0](https://kitploit.com/en/posts/github-retirejs-retirejs-550) - [ ] [claude-bug-bounty v6.0.0](https://kitploit.com/en/posts/github-shuvonsec-claude-bug-bounty-v600) - [ ] [awesome-llvm-security](https://kitploit.com/en/tools/github/gmh5225/awesome-llvm-security) - [ ] [awesome-game-security](https://kitploit.com/en/tools/github/gmh5225/awesome-game-security) - [ ] [camoufox v152.0.4-beta.29](https://kitploit.com/en/posts/github-daijro-camoufox-v15204-beta29) - [ ] [prismsec](https://kitploit.com/en/tools/github/azmisyahrul/prismsec) - [ ] [agentic-dm-gateway](https://kitploit.com/en/tools/gitlab/wattocyber/agentic-dm-gateway) - [ ] [Sandb0x-Xtract0r](https://kitploit.com/en/tools/github/darnellwashingtonjr94-art/sandb0x-xtract0r) - [ ] [detection-defense-library](https://kitploit.com/en/tools/gitlab/wattocyber/detection-defense-library) - [ ] [custom-oscp-tooling](https://kitploit.com/en/tools/gitlab/wattocyber/custom-oscp-tooling) - [ ] [mcp-stdio-shellguard v0.1.2](https://kitploit.com/en/posts/github-studiomeyer-io-mcp-stdio-shellguard-v012) - [ ] [oscp-notes-2026](https://kitploit.com/en/tools/gitlab/wattocyber/oscp-notes-2026) - [ ] [cantina](https://kitploit.com/en/tools/gitlab/wattocyber/cantina) - [ ] [Sitadel v1.5.1](https://kitploit.com/en/posts/github-shenril-sitadel-v151) - [ ] [pbtk v1.1.3](https://kitploit.com/en/posts/github-marin-m-pbtk-113) - [ ] [iDescriptor v0.6.2](https://kitploit.com/en/posts/github-idescriptor-idescriptor-v062) - [ ] [badkeys v0.0.20](https://kitploit.com/en/posts/github-badkeys-badkeys-v0020) - [ ] [mora-hwbp](https://kitploit.com/en/tools/github/dovughs/mora-hwbp) - [ ] [lure v0.5.1](https://kitploit.com/en/posts/github-0xusmanismail-lure-v051) - [ ] [deadair v0.6.0](https://kitploit.com/en/posts/github-big-comfy-deadair-v060) - [ ] [node9-proxy v1.67.3](https://kitploit.com/en/posts/github-node9-ai-node9-proxy-v1673) - [ ] [bramble v1.18.0-chromium](https://kitploit.com/en/posts/github-flythenimbus-bramble-1180-chromium) - [ ] [tailscale v1.102.3](https://kitploit.com/en/posts/github-tailscale-tailscale-v11023) - [ ] [rustnet v1.6.0](https://kitploit.com/en/posts/github-domcyrus-rustnet-v160) - [ ] [Signal-iOS v8.25.0.1809](https://kitploit.com/en/posts/github-signalapp-signal-ios-82501809) - [ ] [renovate-operator v6.0.1](https://kitploit.com/en/posts/github-mogenius-renovate-operator-601) - [ ] [pipelock v3.4.0](https://kitploit.com/en/posts/github-luckypipewrench-pipelock-v340) - [ ] [monitor v0.39.0](https://kitploit.com/en/posts/github-betterdb-inc-monitor-v0390) - [ ] [asterisk v23.5.0-rc2](https://kitploit.com/en/posts/github-asterisk-asterisk-2350-rc2) - [ ] [UltraViolet v1.0.11](https://kitploit.com/en/posts/github-yakushstanislav-ultraviolet-v1011) - [ ] [mboxshell v0.7.1](https://kitploit.com/en/posts/github-dcarrero-mboxshell-v071) - [ ] [wlctl v0.1.10](https://kitploit.com/en/posts/github-aashish-thapa-wlctl-v0110) - TorrentFreak - [ ] [Nintendo Wipes Out 400+ Switch Emulator Repos in Single-Day GitHub Sweep](https://torrentfreak.com/nintendo-wipes-out-400-switch-emulator-repos-in-single-day-github-sweep/) - Deeplinks - [ ] [EFF and Civil Society Groups Call on Nottinghamshire Police to Halt Live Face Recognition](https://www.eff.org/deeplinks/2026/08/eff-and-civil-society-groups-call-nottinghamshire-police-halt-live-face) - www.theregister.com - Articles - [ ] [AWS Security makes an inscrutable choice](https://www.theregister.com/security/2026/08/22/aws-security-makes-an-inscrutable-choice-corey-quinn/5291446) - [ ] [Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it](https://www.theregister.com/patches/2026/08/21/homeland-security-cybercops-say-patch-trueconf-russias-zoom-if-youre-using-it/5291156) - [ ] [Hackers poison popular Rust crates to steal developers' credentials](https://www.theregister.com/security/2026/08/21/hackers-poison-popular-rust-crates-to-steal-developers-credentials/5291075) - [ ] [Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5.](https://www.theregister.com/security/2026/08/21/cisco-bug-severity-warning-reads-like-olympic-gymnastics-scores-10-10-99-96-and-75/5290838) - [ ] [Russian snoops add OAuth abuse to targeted phishing campaigns](https://www.theregister.com/security/2026/08/21/russian-snoops-add-oauth-abuse-to-targeted-phishing-campaigns/5290706) - Blackhat Library: Hacking techniques and research - [ ] [I finally released Operon 1.0, a Rust-native agent harness built from scratch](https://www.reddit.com/r/blackhat/comments/1vuew4n/i_finally_released_operon_10_a_rustnative_agent/)
每日安全资讯(2026-08-22)