# 每日安全资讯(2026-09-23) - Private Feed for M09Ic - [ ] [strands-agents released harness-cli/v0.1.1 at strands-agents/harness-sdk](https://github.com/strands-agents/harness-sdk/releases/tag/harness-cli/v0.1.1) - [ ] [bolucat released 202609222307 at bolucat/Archive](https://github.com/bolucat/Archive/releases/tag/202609222307) - [ ] [mgeeky starred tensorflow/playground](https://github.com/tensorflow/playground) - [ ] [spf13 starred wassermanproductions/blockout](https://github.com/wassermanproductions/blockout) - [ ] [strands-agents released python/v1.57.0 at strands-agents/harness-sdk](https://github.com/strands-agents/harness-sdk/releases/tag/python/v1.57.0) - [ ] [anthropics released v2.1.280 at anthropics/claude-code](https://github.com/anthropics/claude-code/releases/tag/v2.1.280) - [ ] [spf13 forked spf13/kit from kenn-io/kit](https://github.com/spf13/kit) - [ ] [esrrhs starred Netease-Games-AI-Lab-Guangzhou/realikun](https://github.com/Netease-Games-AI-Lab-Guangzhou/realikun) - [ ] [chainreactors released v1.0.0-rc5 at chainreactors/cyber-harness](https://github.com/chainreactors/cyber-harness/releases/tag/v1.0.0-rc5) - [ ] [WAY29 starred open-telemetry/opentelemetry-go-compile-instrumentation](https://github.com/open-telemetry/opentelemetry-go-compile-instrumentation) - [ ] [niudaii starred abue-ammar/tinycast](https://github.com/abue-ammar/tinycast) - [ ] [timwhitez starred MiniMax-AI/minimax-code](https://github.com/MiniMax-AI/minimax-code) - [ ] [mgeeky starred boydhacks/ntlmscout](https://github.com/boydhacks/ntlmscout) - [ ] [niudaii starred getpaseo/paseo](https://github.com/getpaseo/paseo) - [ ] [pydantic released v2.47.0 at pydantic/pydantic-ai](https://github.com/pydantic/pydantic-ai/releases/tag/v2.47.0) - SecWiki News - [ ] [SecWiki News 2026-09-22 Review](http://www.sec-wiki.com/?2026-09-22) - Doonsec's feed - [ ] [字节半年营收8000亿,快追上阿里腾讯总和了,但我更怕另一件事](https://mp.weixin.qq.com/s/-ti1asn3l5IONgmdzfyDYA) - [ ] [当黑客交给AI Agent干活:拿下每个目标仅需 25 美元](https://mp.weixin.qq.com/s/2SsCQxu_AHPZaJpewR9yGg) - [ ] [我用AI辅助挖了三个月SRC,聊聊哪些环节真能省时间](https://mp.weixin.qq.com/s/Kcy0XQAapl_BHta_8pVoDQ) - [ ] [10月17日专题会议:系统安全与基础设施防御学术会议](https://mp.weixin.qq.com/s/O575jkM5koqg1LgOGn_V6w) - [ ] [共鉴网安学术力量|2026年度《网络空间安全科学学报》优秀论文投票正式开启](https://mp.weixin.qq.com/s/E3pnKgSkfL6TZ5LJWeIFPg) - [ ] [王小洪在全国公安机关视频会议上强调 深入学习贯彻习近平总书记重要回信精神 坚决扛牢守百姓幸福护家国平安重任](https://mp.weixin.qq.com/s/hFyNlk2guoeIFNAmbfrsuw) - [ ] [长鑫存储上海技术岗,月薪税前5.7W,年终奖4个月,算下来税前年薪91W+,加上补贴奖金妥妥破百万。](https://mp.weixin.qq.com/s/PaZrp0f_Ryayvz3sKTRo-A) - [ ] [【已复现】CVE-2026-65660 Microsoft SharePoint 远程代码执行漏洞](https://mp.weixin.qq.com/s/meQDGztz6IsCdcI6MCOM9w) - [ ] [院士领航、产研协同:首届中国网络空间安全大会在合肥举办](https://mp.weixin.qq.com/s/ypn38CgbWUDAO2o_clO-uw) - [ ] [关注 | “两高”联合发布依法惩治网络食品安全犯罪典型案例](https://mp.weixin.qq.com/s/4MGvhtZXJ0VPlA0tc23RKQ) - [ ] [守护智能时代网络安全——2026年国家网络安全宣传周综述](https://mp.weixin.qq.com/s/dQqZanJgEnXFPOpoIOp6dA) - [ ] [通报 | CNCERT通报2026年人工智能大模型安全众测活动典型漏洞风险](https://mp.weixin.qq.com/s/xx8BoK_TevJefmWZFD4nrw) - [ ] [遇见、速聊、kim……这31款App涉诈情况突出!](https://mp.weixin.qq.com/s/ePVjZ4Icd-Yx1PqJGflQJQ) - [ ] [关注 | 北京交通APP、猎聘、新浪财经……这82款App违法违规收集使用个人信息被通报!](https://mp.weixin.qq.com/s/gAfGl9z74I5YSDKqqYOjJw) - [ ] [点击“关闭”,反而触发更多弹窗?关个APP广告咋这么难](https://mp.weixin.qq.com/s/bC1YhSwfPs85P_toLsQN3w) - [ ] [Qiko3.0 全行业征集首测用户!](https://mp.weixin.qq.com/s/KGOHFhqnhEWlNXefcyuE2Q) - [ ] [一大波AI+新品发布,速来!](https://mp.weixin.qq.com/s/UiEzdI7UPtc3r2QaMbe4pQ) - [ ] [分享的图片、视频、链接](https://mp.weixin.qq.com/s/XdK1PHzNWrGOoWQYYnSZwg) - [ ] [喜迎中秋,欢度国庆AiScan-N 集成200+ 安全能力的工作台!零基础也能上手从聊天到脱壳|CTF网络安全大赛|搭配本地大模型可无需访问互联网](https://mp.weixin.qq.com/s/JcQEi6H-G8r_0dT_Ue2bVw) - Hacking Articles - [ ] [Impacket for Pentester: tstool](https://www.hackingarticles.in/impacket-for-pentester-tstool/) - obaby 𝐢𝐧⃝ void - [ ] [闺蜜圈 [v 5.2.16]](https://zhongxiaojie.cn/2026/09/1959/) - Recent Commits to cve:main - [ ] [Update Tue Sep 22 12:28:04 UTC 2026](https://github.com/trickest/cve/commit/7ddd33341bf3f8b0f5beb1f2ab5b05d240669794) - ElcomSoft blog - [ ] [IoT Forensics on the Rise: Extracting More Apple Watch, Apple TV 4K Devices](https://blog.elcomsoft.com/2026/09/iot-forensics-on-the-rise-extracting-more-apple-watch-apple-tv-and-homepod-models/) - Microsoft Security Blog - [ ] [Unmasking EvilTokens: Getting to the root of device code phishing](https://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing/) - Horizon3 - [ ] [NodeZero Federal](https://horizon3.ai/downloads/factsheets/nodezero-federal/) - Kitploit — Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal! - [ ] [LOLRMM](https://kitploit.com/en/tools/github/magicsword-io/lolrmm) - [ ] [antidbg](https://kitploit.com/en/tools/github/notrequiem/antidbg) - [ ] [EntraTrace](https://kitploit.com/en/tools/github/bert-janp/entratrace) - [ ] [osiris](https://kitploit.com/en/tools/github/simplifaisoul/osiris) - [ ] [java-html-sanitizer v20260921.1](https://kitploit.com/en/posts/github-owasp-java-html-sanitizer-release-202609211) - [ ] [paperweight v0.7.0](https://kitploit.com/en/posts/github-wslyvh-paperweight-v070) - [ ] [PrivescCheck v2026.09.21-1](https://kitploit.com/en/posts/github-itm4n-privesccheck-20260921-1) - [ ] [libsrtp v2.8.1](https://kitploit.com/en/posts/github-cisco-libsrtp-v281) - [ ] [mailcow-dockerized v2026-09](https://kitploit.com/en/posts/github-mailcow-mailcow-dockerized-2026-09) - [ ] [emba v2.0.4-summer_edition](https://kitploit.com/en/posts/github-e-m-b-a-emba-v204-summer_edition) - [ ] [mvt v2026.9.21](https://kitploit.com/en/posts/github-mvt-project-mvt-v2026921) - [ ] [MSRKit](https://kitploit.com/en/tools/github/rurixis/msrkit) - [ ] [PureRAT-msbuild.exe--C2-Extraction--Net-Evasion-Analysis](https://kitploit.com/en/tools/github/kaandemir993/purerat-msbuild.exe--c2-extraction--net-evasion-analysis) - [ ] [pentest-harness](https://kitploit.com/en/tools/github/s1n6h/pentest-harness) - [ ] [shannon v3.3.0](https://kitploit.com/en/posts/github-keygraphhq-shannon-v330) - [ ] [dbeaver v26.2.1](https://kitploit.com/en/posts/github-dbeaver-dbeaver-2621) - [ ] [Argus](https://kitploit.com/en/tools/github/divinelabio/argus) - [ ] [Podroid v1.2.9](https://kitploit.com/en/posts/github-extv-podroid-v129) - [ ] [zitadel v4.18.0](https://kitploit.com/en/posts/github-zitadel-zitadel-v4180) - [ ] [secretive v4.0.0](https://kitploit.com/en/posts/github-maxgoedjen-secretive-v400) - [ ] [AADOutsider-py](https://kitploit.com/en/tools/github/synacktiv/aadoutsider-py) - [ ] [OneDrive-UDC2](https://kitploit.com/en/tools/github/nmht3t/onedrive-udc2) - [ ] [ai-ctf](https://kitploit.com/en/tools/github/mubix/ai-ctf) - [ ] [radioguard](https://kitploit.com/en/tools/github/pushkarreddyy/radioguard) - [ ] [BigDiskBuster](https://kitploit.com/en/tools/github/msnightmare/bigdiskbuster) - [ ] [njsscan v1.0.1](https://kitploit.com/en/posts/github-ajinabraham-njsscan-101) - [ ] [kviklet v0.9.0](https://kitploit.com/en/posts/github-kviklet-kviklet-090) - [ ] [ship-safe v10.1.0](https://kitploit.com/en/posts/github-asamassekou10-ship-safe-v1010) - [ ] [Mobile-Security-Framework-MobSF v4.5.3](https://kitploit.com/en/posts/github-mobsf-mobile-security-framework-mobsf-v453) - [ ] [opensoho v0.15.2](https://kitploit.com/en/posts/github-rubenbe-opensoho-v0152) - [ ] [kube-monkey v0.7.0](https://kitploit.com/en/posts/github-asobti-kube-monkey-v070) - [ ] [aquaman v0.15.0](https://kitploit.com/en/posts/github-tech4242-aquaman-v0150) - Lenny Zeltser - [ ] [My Favorite Findings From the AI Security Decisions Report](https://zeltser.com/ai-security-decisions-report) - Reverse Engineering - [ ] [I reverse-engineered Intel's NPU stack and got custom C kernels running on its programmable SHAVE cores](https://www.reddit.com/r/ReverseEngineering/comments/1wn4ps7/i_reverseengineered_intels_npu_stack_and_got/) - [ ] [MacOS offensive security, detection engineering, and solo Apple research](https://www.reddit.com/r/ReverseEngineering/comments/1wmyoic/macos_offensive_security_detection_engineering/) - Malwarebytes - [ ] [Some cheap smart glasses are a security disaster](https://www.malwarebytes.com/blog/news/2026/09/some-cheap-smart-glasses-are-a-security-disaster) - [ ] [Meta’s Muse AI assistant has a zero-day that can turn it into a Mac backdoor](https://www.malwarebytes.com/blog/bugs/2026/09/metas-muse-ai-assistant-has-a-zero-day-that-can-turn-it-into-a-mac-backdoor) - [ ] [Researchers used Claude to hack OpenAI](https://www.malwarebytes.com/blog/news/2026/09/researchers-used-claude-to-hack-openai) - 奇客Solidot–传递最新科技情报 - [ ] [新 Halo 游戏将由动视开发](https://www.solidot.org/story?sid=85456) - [ ] [美国酒精消费自疫情以来首次下降](https://www.solidot.org/story?sid=85455) - [ ] [天文学家发现已知最年轻行星](https://www.solidot.org/story?sid=85454) - [ ] [为躲避亿万富翁税 Larry Page 等人迁出加州](https://www.solidot.org/story?sid=85453) - [ ] [NASA 火星样本采集送回任务终止](https://www.solidot.org/story?sid=85452) - [ ] [6 岁女孩打破女子三阶魔方还原世界纪录](https://www.solidot.org/story?sid=85451) - [ ] [阿里巴巴下一代模型参数将扩大到 5-10 万亿规模](https://www.solidot.org/story?sid=85450) - [ ] [AMD 加入万亿美元市值俱乐部](https://www.solidot.org/story?sid=85448) - Panda's Blog - [ ] [杂谈:聊聊 Jev 与 Laya 的非生成式决策机制](https://www.cnpanda.net/talksafe/jev-laya-non-generative-decision-models.html) - HackerNews - [ ] [WordPress Comment2Shell 漏洞可通过管理员会话将匿名评论 XSS 变成 RCE](http://0.0.0.0:8080/post/64719) - [ ] [Zyxel 和 Veeam 漏洞正被积极利用,可获得命令执行和 SYSTEM 权限](http://0.0.0.0:8080/post/64718) - [ ] [一个隐藏的 Meta Muse 设置可能让攻击者将 AI 助手变成后门](http://0.0.0.0:8080/post/64717) - [ ] [假冒 LastPass Authenticator 安装程序滥用微软签名的驱动程序终止杀毒软件和 EDR](http://0.0.0.0:8080/post/64716) - [ ] [SideCopy 利用 ReverseRAT 鱼叉式网络钓鱼将攻击目标扩大至印度学术界](http://0.0.0.0:8080/post/64715) - [ ] [BigCommerce 提醒商家防范与 Ribon 应用相关的数据泄露](http://0.0.0.0:8080/post/64714) - 腾讯玄武实验室 - [ ] [每日安全动态推送(26/9/22)](https://mp.weixin.qq.com/s?__biz=MzA5NDYyNDI0MA==&mid=2651960557&idx=1&sn=820f5ff1f35478e92147d7ad3d37b1fc) - 微步在线研究响应中心 - [ ] [假期挖洞不卡壳,X漏洞计划焕新升级!](https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&mid=2247508955&idx=1&sn=85e13ada762b0cde86a116b54fe28bfc) - 威努特安全网络 - [ ] [10月1日正式实施《公安机关网络空间安全监督检查办法》](https://mp.weixin.qq.com/s?__biz=MzAwNTgyODU3NQ==&mid=2651144327&idx=1&sn=f1b4504b854c59eb5324e02015662bf5) - 雷神众测 - [ ] [雷神众测漏洞周报2026.9.14-2026.9.20](https://mp.weixin.qq.com/s?__biz=MzI0NzEwOTM0MA==&mid=2652503979&idx=1&sn=5e831912dbc1d69d919d0d4c7d4395e8) - Shostack & Friends Blog - [ ] [Heading to San Francisco and ready to party for OWASP's 25th](https://shostack.org/blog/our-plans-for-owasp-and-threatmodcon-26/) - 黑鸟 - [ ] [当黑客交给AI Agent干活:拿下每个目标仅需 25 美元](https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451188907&idx=1&sn=d90e75941cc99220cfa6be0771332a42) - 安全内参 - [ ] [违法收集处理个人信息,巨头被罚超30亿元](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516644&idx=1&sn=af578a0e1d63d0e0de53789e7bb4c052) - [ ] [CNCERT:2026年人工智能大模型安全众测活动典型漏洞风险通报](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516644&idx=2&sn=58544de569ce44f51e329b684154f526) - 安全分析与研究 - [ ] [安全对齐的数学基础与对齐税](https://mp.weixin.qq.com/s?__biz=MzA4ODEyODA3MQ==&mid=2247497190&idx=1&sn=a379473a27dc2958575a3f0013563efd) - 代码卫士 - [ ] [CISA:三个Linux 内核漏洞已遭活跃利用](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247527207&idx=1&sn=ee496b1b2360baa934d52866a4de28eb) - [ ] [安全测试域名混淆,Gemini 入侵真实公司系统](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247527207&idx=2&sn=8e9c8dd90a684130b7fbe2646f3d2c9b) - 奇安信 CERT - [ ] [【已复现】Microsoft SharePoint 远程代码执行漏洞(CVE-2026-65660)安全风险通告](https://mp.weixin.qq.com/s?__biz=MzU5NDgxODU1MQ==&mid=2247507667&idx=1&sn=526042840c14d10444d80a7ed0cef7c0) - 中国信息安全 - [ ] [数智拓远 善治久安 | 第十六届网络安全漏洞分析与风险评估大会在重庆举办](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664267243&idx=1&sn=e2e31583a47c79077b7d9f3e9672b099) - 微步在线 - [ ] [AI做安全运营,怎样才让人放心?](https://mp.weixin.qq.com/s?__biz=MzI5NjA0NjI5MQ==&mid=2650188269&idx=1&sn=db3c80393b836b4989ae1f3ba72597c6) - 数世咨询 - [ ] [报告发布 |《全球数据泄露态势月度报告》(2026年8月)| 附下载地址](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247544039&idx=1&sn=c3ba49bfe47809db1668069ba706b281) - [ ] [破解5G政务专网建设痛点|“政务专网安全体系构建线上专题分享会”圆满举办](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247544039&idx=2&sn=b2f586b5b02882b53b15c2880d30e935) - [ ] [直播预约:2026 西湖论剑大会](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247544039&idx=3&sn=0502b403c35fe29c8dedbbc4b3610c50) - 长亭科技 - [ ] [长亭科技获评两项首批国家级人工智能安全资质!](https://mp.weixin.qq.com/s?__biz=MzIwNDA2NDk5OQ==&mid=2651390767&idx=1&sn=f45cf53582fbde8a592c2799b5fb80a2) - 白帽100安全攻防实验室 - [ ] [别了,人工驱动的世界。](https://mp.weixin.qq.com/s?__biz=MzIxMDYyNTk3Nw==&mid=2247515494&idx=1&sn=c9a0bb51366c74f6cf52365eb6cfd33f) - 默安科技 - [ ] [默安代码审计智能体捕获 SAST 盲区逻辑漏洞](https://mp.weixin.qq.com/s?__biz=MzIzODQxMjM2NQ==&mid=2247502083&idx=1&sn=d63fd34772d4bad4ac5ff9ba02799cfa) - [ ] [默安代码审计智能体:发现SAST看不见的逻辑漏洞](https://mp.weixin.qq.com/s?__biz=MzIzODQxMjM2NQ==&mid=2247502085&idx=1&sn=7f5b9f2df29a44e8fa0ef53e1be3e490) - 看雪学苑 - [ ] [浅析 Google Play 自动保护(PairIP):代码虚拟化、TEE 密钥与运行时反篡改](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458620834&idx=1&sn=bb5885497395f2a93a892c5f0d3be2e3) - [ ] [已在野利用|合勤GS1900交换机高危漏洞入库KEV,内网无认证即可接管设备](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458620834&idx=2&sn=d6038a0523f2c18db151c69bf4a4cef3) - [ ] [小班教学,火热报名中!SDC2026·安全训练营:8小时提升实战技能](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458620834&idx=3&sn=d3f4f114af53ad5b013b932d2e219a16) - 安全圈 - [ ] [【安全圈】WordPress爆Comment2Shell高危漏洞:匿名评论经由管理员会话直达RCE](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652079072&idx=1&sn=81b11d4454e85cae46eca7eabb0908e4) - [ ] [【安全圈】Zyxel与Veeam高危漏洞遭野外在途利用:防火墙注入与备份控制权沦陷](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652079072&idx=2&sn=3a8b43e5688e04e6f5da417020190d85) - [ ] [【安全圈】伪造LastPass安装包携微软签名驱动:BYOVD攻击静默绞杀EDR与安全软件](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652079072&idx=3&sn=07f203d11303bd4b45a73ce76e19af0f) - 安全客 - [ ] [给AI出考卷的人,把考场门开到了马路上:Gemini入侵三家真实企业始末](https://mp.weixin.qq.com/s?__biz=MzA5ODA0NDE2MA==&mid=2649790512&idx=1&sn=e6ac2601b5edddf0a29263d1011b03b0) - 安全牛 - [ ] [别再把 API Key 塞进 Agent:企业 AI 密钥管理的正确打开方式](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142835&idx=1&sn=b772e3e7a9aaba34ab2a917b6b13ba1a) - [ ] [Amazon封禁Meta AI Agent Muse,AI购物代理的数据安全争议升级;CNVD周报:Apache与Google产品漏洞集中爆发,电信行业风险突出| 牛览](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142835&idx=2&sn=da824288caded987f3cf2bfcda9098ee) - 极客公园 - [ ] [从单卡到千卡互联,平头哥真武 V900 背后的 AI 算力变局](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653113988&idx=1&sn=18bc16d0dec8e51d78d66eebf7ab28cc) - [ ] [拆解下阿里的 AI 经济学,与它的下注](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653113986&idx=1&sn=bbecbba705777781805c71f340f32dab) - [ ] [黄仁勋:AI 时代,企业应该尽可能多付薪酬;宇树科技发布 Dex5-S 灵巧手;OpenAI 新模型 24 天解决 100+ 世界级数学难题 | 极客早知道](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653113959&idx=1&sn=13db4f7bc0be2f4aa064c4b35b5dcecf) - 火绒安全 - [ ] [月满中秋 乐享团圆 | 火绒守护相伴](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247537874&idx=1&sn=3c60039df49c527121ec8f3d38f46b8c) - [ ] [诚邀渠道合作伙伴共启新征程](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247537874&idx=2&sn=9aad07dbe6ff4dc666e2db279f96939b) - 复旦白泽战队 - [ ] [告别“开卷考试”,用“闭卷测试“检验AI真实攻击能力](https://mp.weixin.qq.com/s?__biz=MzU4NzUxOTI0OQ==&mid=2247499966&idx=1&sn=3aadc26e544a81eab6e4d7075e9bad1a) - 奇安信威胁情报中心 - [ ] [npm 供应链攻防进入"运行时时代":200 万周下载的恶意包如何绕开 npm v12 防线](https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247520685&idx=1&sn=49425e3c022de8f0bd17158478041f28) - 慢雾科技 - [ ] [解读|日、美、澳、德联合报告:朝鲜黑客组织"WaterPlum"的求职钓鱼与笔记本农场](https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&mid=2247506163&idx=1&sn=7159a2d0e06a66adb034e1b76ae8098c) - 美团安全应急响应中心 - [ ] [美团SRC关于违规测试行为的警示与规范重申](https://mp.weixin.qq.com/s?__biz=MzI5MDc4MTM3Mg==&mid=2247494933&idx=1&sn=06d1851a01f87ff15cd9cd464031c733) - 云鼎实验室 - [ ] [腾讯安全首批“安全 KOL”全球招募中:以连接·影响·共振·共创,引领安全社区未来](https://mp.weixin.qq.com/s?__biz=MzU3ODAyMjg4OQ==&mid=2247497970&idx=1&sn=57d49d23adff4c7e06e66f54371cfccd) - 字节跳动技术团队 - [ ] [Agent 已经进入工作流,文件还要靠人传来传去?](https://mp.weixin.qq.com/s?__biz=MzI1MzYzMjE0MQ==&mid=2247522794&idx=1&sn=f78bb16a0448933da06fcc4d353de927) - [ ] [一图看懂 ADrive 跨产品协作实践:文件通了,Agent 就通了](https://mp.weixin.qq.com/s?__biz=MzI1MzYzMjE0MQ==&mid=2247522794&idx=2&sn=50a39d3e2016757e656d911c1b6fffff) - 吴鲁加 - [ ] [五个小时能干什么](https://mp.weixin.qq.com/s?__biz=Mzg5NDY4ODM1MA==&mid=2247486248&idx=1&sn=766e0a844637cd198243c33c48ca7b35) - 字节跳动安全中心 - [ ] [特别奖励发布!ByteSRC邀你参加双11安全保卫战!](https://mp.weixin.qq.com/s?__biz=MzUzMzcyMDYzMw==&mid=2247496386&idx=1&sn=588106c459bf13d8002fbb12746929b4) - OnionSec - [ ] [难过又难忘](https://mp.weixin.qq.com/s?__biz=MzUyMTUwMzI3Ng==&mid=2247486029&idx=1&sn=7bed429a6d4620c0ef135183a346d3a2) - 情报分析师 - [ ] [埃及总统与美国中央情报局局长就加沙、苏丹和伊朗问题会谈详情](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650569764&idx=1&sn=55bb4db49f156997101c5b2d4d68cfa7) - [ ] [美国国家安全局设立五大任务中心并启动十余年来最大规模重组,对我信号情报搜集与人工智能对抗体系加速成型](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650569764&idx=2&sn=65b39c20380b37500b235d87199b40ac) - T00ls安全 - [ ] [十八载同行-潜心习安全 - cxaqhq 第四弹](https://mp.weixin.qq.com/s?__biz=Mzg3NzYzODU5NQ==&mid=2247485867&idx=1&sn=a47e8e0e973d5afbfcb2662bd7e2e8c8) - 美团技术团队 - [ ] [MTFM:美团统一推荐基座大模型在外卖多业务场景的落地实践 | 送中秋礼盒](https://mp.weixin.qq.com/s?__biz=MjM5NjQ5MTI5OA==&mid=2651783470&idx=1&sn=da5e4ae285f534a2687fce77543806b0) - [ ] [清华大学-美团学术论坛举办,两项高校支持计划同步发布](https://mp.weixin.qq.com/s?__biz=MjM5NjQ5MTI5OA==&mid=2651783470&idx=2&sn=071ad0eeeb070cd3759487d3333455b5) - Over Security - [ ] [Rogue external MFA providers can steal passwords during logins](https://www.bleepingcomputer.com/news/security/rogue-external-mfa-providers-can-steal-passwords-during-logins/) - [ ] [Sweden fines Miljödata $183,000 over breach affecting 2.2 million](https://www.bleepingcomputer.com/news/security/sweden-fines-milj-data-183-000-over-breach-affecting-22-million/) - [ ] [Chinese hackers exploit multiple technologies to steal govt data](https://www.bleepingcomputer.com/news/security/chinese-hackers-exploit-multiple-technologies-to-steal-govt-data/) - [ ] [Process Parameter Poisoning: Inside a Novel EDR Evasion Technique](https://flashpoint.io/blog/process-parameter-poisoning-edr-evasion-technique/) - [ ] [Canadian regulator opens probe of IDScan for allegedly violating data privacy laws](https://therecord.media/canadian-regulator-opens-probe-of-idscan-following-data-breach) - [ ] [ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach](https://www.bleepingcomputer.com/news/security/shinyhunters-claims-fbi-hack-data-theft-in-peoplesoft-zero-day-breach/) - [ ] [New ClosedQuorum Windows malware uses AI for attack decisions](https://www.bleepingcomputer.com/news/security/new-closedquorum-windows-malware-uses-ai-for-attack-decisions/) - [ ] [Reducing shadow IT visibility gaps with Wazuh](https://www.bleepingcomputer.com/news/security/reducing-shadow-it-visibility-gaps-with-wazuh/) - [ ] [Check Point warns of Management Server zero-day exploited in attacks](https://www.bleepingcomputer.com/news/security/check-point-patches-management-server-zero-day-exploited-in-attacks/) - [ ] [Two arrested in UK after Microsoft takedown of ‘Eviltokens’ AI-chatbot for cybercriminals](https://therecord.media/two-arrested-in-uk-after-microsoft-takedown-eviltokens) - [ ] [Cyber Asset Management: perché la resilienza inizia dalla conoscenza degli asset](https://www.cybersecurity360.it/soluzioni-aziendali/cyber-asset-management-perche-la-resilienza-inizia-dalla-conoscenza-degli-asset/) - [ ] [Automazione nella cyber security: quando non fidarsi della macchina diventa un rischio](https://www.cybersecurity360.it/soluzioni-aziendali/automazione-nella-cyber-security-quando-non-fidarsi-della-macchina-diventa-un-rischio/) - [ ] [EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts](https://www.bleepingcomputer.com/news/security/eviltokens-phaas-disrupted-after-compromising-12-000-microsoft-accounts/) - [ ] [Supervisione indipendente e sicurezza dei sistemi di AI: cosa cambia con l’ordine esecutivo della California](https://www.cybersecurity360.it/legal/supervisione-indipendente-e-sicurezza-dei-sistemi-di-ai-cosa-cambia-con-lordine-esecutivo-della-california/) - [ ] [PAYLOAD, il ransomware che trasforma Active Directory in strumento d’attacco](https://www.cybersecurity360.it/nuove-minacce/ransomware/payload-il-ransomware-che-trasforma-active-directory-in-strumento-dattacco/) - [ ] [AI is set to help cyber attackers much more than defenders, says UK official](https://therecord.media/ai-set-to-help-attackers-more-than-defenders) - [ ] [D-Link warns of max severity zero-day bug in DIR-822A routers](https://www.bleepingcomputer.com/news/security/d-link-warns-of-max-severity-zero-day-bug-in-dir-822a-routers/) - [ ] [Webinar tomorrow: Inside real-world Google Workspace breaches](https://www.bleepingcomputer.com/news/security/webinar-tomorrow-inside-real-world-google-workspace-breaches/) - [ ] [Russia's internet shutdowns disrupt warnings about incoming drone attacks](https://therecord.media/russia-internet-shutdowns-disrupt-warnings-about-drone-attacks) - [ ] [CSuite Targets US and EU Organizations with Device-Code Phishing and Remote Access](https://any.run/cybersecurity-blog/csuite-attack-analysis/) - [ ] [Incogni Unlimited cancella i dati personali dal web](https://www.cybersecurity360.it/cultura-cyber/incogni-unlimited-cancella-dati-personali-dal-web/) - [ ] [New Windows Defender zero-day blocks Microsoft antivirus updates](https://www.bleepingcomputer.com/news/security/new-windows-defender-zero-day-blocks-microsoft-antivirus-updates/) - [ ] [Introducing CAIRN: Frontier tracking for AI-integrated malware](https://blog.talosintelligence.com/introducing-cairn-frontier-tracking-for-ai-integrated-malware/) - [ ] [The Closed Quorum: Inside the first reported autonomous AI C2 implant](https://blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/) - [ ] [LimeLeads - 17,838,396 breached accounts](https://haveibeenpwned.com/Breach/LimeLeads) - [ ] [Rapporto CRIF 2026: il cybercrime non ruba più solo credenziali, costruisce identità digitali](https://www.cybersecurity360.it/news/rapporto-crif-2026-il-cybercrime-non-ruba-piu-solo-credenziali-costruisce-identita-digitali/) - [ ] [CISA orders feds to patch Zyxel flaw exploited for data theft](https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-zyxel-flaw-by-thursday/) - [ ] [Google Faces €403 Million GDPR Fine Over Location Tracking](https://thecyberexpress.com/google-location-data-fines-google-e403-million/) - [ ] [Belgian Sports Federations Hit by Cyberattacks, Data Under Investigation](https://thecyberexpress.com/belgium-sports-federations-cyberattack/) - [ ] [EU Cybersecurity Response Hampered by Critical Information Gaps](https://thecyberexpress.com/eu-cybersecurity-incidents-expose-gaps/) - [ ] [India’s DoT Warns Citizens Over SIM Fraud and IMEI Tampering](https://thecyberexpress.com/fraudulent-sim-cards-could-lead-to-fine/) - [ ] [August 2026 Cyber Attacks Statistics](https://www.hackmageddon.com/2026/09/22/august-2026-cyber-attacks-statistics/) - [ ] [August 2026 Cyber Attacks Statistics Infographic](https://www.hackmageddon.com/2026/09/22/august-2026-cyber-attacks-statistics-infographic/) - [ ] [Piano ispettivo del Garante privacy: dalle nuove tecnologie ai data breach, le priorità per le imprese](https://www.cybersecurity360.it/news/piano-ispettivo-del-garante-privacy-dalle-nuove-tecnologie-ai-data-breach-le-priorita-per-le-imprese/) - [ ] [An Italian Phishing Campaign Delivering an iOS Exploit Chain](https://www.d3lab.net/an-italian-phishing-campaign-delivering-an-ios-exploit-chain/) - [ ] [Soggetti vulnerabili e GDPR: i limiti di anonimato e riservatezza nei servizi di ascolto](https://www.cybersecurity360.it/legal/privacy-dati-personali/soggetti-vulnerabili-e-gdpr-i-limiti-di-anonimato-e-riservatezza-nei-servizi-di-ascolto/) - D3Lab - [ ] [An Italian Phishing Campaign Delivering an iOS Exploit Chain](https://www.d3lab.net/an-italian-phishing-campaign-delivering-an-ios-exploit-chain/) - ICT Security Magazine - [ ] [Registrazione NIS2 2027: scadenze e obblighi da preparare](https://www.ictsecuritymagazine.com/cyber-security/registrazione-nis-2027-finestra-adempimenti-2/) - [ ] [Spazio europeo dei dati sanitari: le regole di sicurezza di MyHealth@EU arrivano molto prima dell’obbligo di scambio](https://www.ictsecuritymagazine.com/articoli/spazio-europeo-dei-dati-sanitari-myhealth-eu/) - Daniel Miessler - [ ] [Attacker vs. Defender AI Advantage](https://danielmiessler.com/blog/attacker-defender-ai-advantage?utm_source=rss&utm_medium=feed&utm_campaign=website) - [ ] [How to Think About the Difference Between Choice and Score in Jev](https://danielmiessler.com/blog/jev-choice-vs-score?utm_source=rss&utm_medium=feed&utm_campaign=website) - The Hacker News - [ ] [Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks](https://thehackernews.com/2026/09/check-point-warns-of-management-server.html) - [ ] [WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers](https://thehackernews.com/2026/09/wordpress-issues-patch-for-critical.html) - [ ] [Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials](https://thehackernews.com/2026/09/malicious-npm-package-poses-as-twilio.html) - [ ] [Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises](https://thehackernews.com/2026/09/microsoft-takes-down-eviltokens-device.html) - [ ] [Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials](https://thehackernews.com/2026/09/critical-bifrost-ai-gateway-flaw-lets.html) - [ ] [Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates](https://thehackernews.com/2026/09/researcher-drops-bigdiskbuster-zero-day.html) - [ ] [AI Agents Are Rewriting the Rules of Lateral Movement](https://thehackernews.com/2026/09/ai-agents-are-rewriting-rules-of.html) - [ ] [New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups](https://thehackernews.com/2026/09/new-cvss-100-velocloud-orchestrator.html) - [ ] [DORA Year Two: Can Your SOC Actually See the Attack?](https://thehackernews.com/2026/09/dora-year-two-can-your-soc-actually-see.html) - [ ] [New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory](https://thehackernews.com/2026/09/new-linux-kernel-flaw-gives-arm64-kvm.html) - [ ] [SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE](https://thehackernews.com/2026/09/sharepoint-flaw-initially-listed-as.html) - [ ] [Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal](https://thehackernews.com/2026/09/malicious-npm-package-indexed-btree-hid.html) - [ ] [SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing](https://thehackernews.com/2026/09/sidecopy-broadens-india-targeting-to.html) - [ ] [One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor](https://thehackernews.com/2026/09/one-hidden-meta-muse-setting-could-let.html) - [ ] [WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session](https://thehackernews.com/2026/09/wordpress-comment2shell-flaw-can-turn.html) - [ ] [Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access](https://thehackernews.com/2026/09/zyxel-and-veeam-flaws-under-active.html) - Instapaper: Unread - [ ] [AutisticiInventati is gone, and it proved who really controls the internet](https://andreafortuna.org/2026/09/17/autistici-inventati-digital-sovereignty/) - [ ] [Cybersicurezza, startup italiana sfrutta l’AI per trovare le frodi tributarie. Ma un reato si può predire](https://www.cybersecitalia.it/cybersicurezza-startup-italiana-sfrutta-lai-per-trovare-le-frodi-tributarie-ma-un-reato-si-puo-predire/69713/) - [ ] [IoT Forensics on the Rise Extracting More Apple Watch, Apple TV 4K Devices](https://blog.elcomsoft.com/2026/09/iot-forensics-on-the-rise-extracting-more-apple-watch-apple-tv-and-homepod-models/) - [ ] [DORA, la filiera sotto esame cosa deve verificare il CdA](https://www.agendadigitale.eu/sicurezza/dora-la-filiera-sotto-esame-cosa-deve-verificare-il-cda/) - [ ] [Rapporto CRIF 2026 il cybercrime non ruba più solo credenziali, costruisce identità digitali](https://www.cybersecurity360.it/news/rapporto-crif-2026-il-cybercrime-non-ruba-piu-solo-credenziali-costruisce-identita-digitali/) - [ ] [Cybersecurity in sanità quando un attacco mette a rischio le cure](https://www.agendadigitale.eu/sicurezza/cybersecurity-in-sanita-quando-un-attacco-mette-a-rischio-le-cure/) - [ ] [The Hacker Myth Why Real Cyber Operations Rarely Look Like Movies](https://www.pillolhacking.net/the-hacker-myth-why-real-cyber-operations-rarely-look-like-movies/) - SANS Internet Storm Center, InfoCON: green - [ ] [The Truth about GET and HTTP Standards, (Tue, Sep 22nd)](https://isc.sans.edu/diary/rss/33358) - [ ] [LausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)](https://isc.sans.edu/diary/rss/33348) - [ ] [ISC Stormcast For Tuesday, September 22nd, 2026 https://isc.sans.edu/podcastdetail/10104, (Tue, Sep 22nd)](https://isc.sans.edu/diary/rss/33356) - Schneier on Security - [ ] [GPT-6 Astra Breaks an Old Enigma Message](https://www.schneier.com/blog/archives/2026/09/gpt-6-astra-breaks-an-old-enigma-message.html) - Have I Been Pwned latest breaches - [ ] [LimeLeads - 17,838,396 breached accounts](https://haveibeenpwned.com/Breach/LimeLeads) - KitPloit - PenTest Tools! - [ ] [LOLRMM](https://kitploit.com/en/tools/github/magicsword-io/lolrmm) - [ ] [antidbg](https://kitploit.com/en/tools/github/notrequiem/antidbg) - [ ] [EntraTrace](https://kitploit.com/en/tools/github/bert-janp/entratrace) - [ ] [osiris](https://kitploit.com/en/tools/github/simplifaisoul/osiris) - [ ] [java-html-sanitizer v20260921.1](https://kitploit.com/en/posts/github-owasp-java-html-sanitizer-release-202609211) - [ ] [paperweight v0.7.0](https://kitploit.com/en/posts/github-wslyvh-paperweight-v070) - [ ] [PrivescCheck v2026.09.21-1](https://kitploit.com/en/posts/github-itm4n-privesccheck-20260921-1) - [ ] [libsrtp v2.8.1](https://kitploit.com/en/posts/github-cisco-libsrtp-v281) - [ ] [mailcow-dockerized v2026-09](https://kitploit.com/en/posts/github-mailcow-mailcow-dockerized-2026-09) - [ ] [emba v2.0.4-summer_edition](https://kitploit.com/en/posts/github-e-m-b-a-emba-v204-summer_edition) - [ ] [mvt v2026.9.21](https://kitploit.com/en/posts/github-mvt-project-mvt-v2026921) - [ ] [MSRKit](https://kitploit.com/en/tools/github/rurixis/msrkit) - [ ] [PureRAT-msbuild.exe--C2-Extraction--Net-Evasion-Analysis](https://kitploit.com/en/tools/github/kaandemir993/purerat-msbuild.exe--c2-extraction--net-evasion-analysis) - [ ] [pentest-harness](https://kitploit.com/en/tools/github/s1n6h/pentest-harness) - [ ] [shannon v3.3.0](https://kitploit.com/en/posts/github-keygraphhq-shannon-v330) - [ ] [dbeaver v26.2.1](https://kitploit.com/en/posts/github-dbeaver-dbeaver-2621) - [ ] [Argus](https://kitploit.com/en/tools/github/divinelabio/argus) - [ ] [Podroid v1.2.9](https://kitploit.com/en/posts/github-extv-podroid-v129) - [ ] [zitadel v4.18.0](https://kitploit.com/en/posts/github-zitadel-zitadel-v4180) - [ ] [secretive v4.0.0](https://kitploit.com/en/posts/github-maxgoedjen-secretive-v400) - [ ] [AADOutsider-py](https://kitploit.com/en/tools/github/synacktiv/aadoutsider-py) - [ ] [OneDrive-UDC2](https://kitploit.com/en/tools/github/nmht3t/onedrive-udc2) - [ ] [ai-ctf](https://kitploit.com/en/tools/github/mubix/ai-ctf) - [ ] [radioguard](https://kitploit.com/en/tools/github/pushkarreddyy/radioguard) - [ ] [BigDiskBuster](https://kitploit.com/en/tools/github/msnightmare/bigdiskbuster) - [ ] [njsscan v1.0.1](https://kitploit.com/en/posts/github-ajinabraham-njsscan-101) - [ ] [kviklet v0.9.0](https://kitploit.com/en/posts/github-kviklet-kviklet-090) - [ ] [ship-safe v10.1.0](https://kitploit.com/en/posts/github-asamassekou10-ship-safe-v1010) - [ ] [Mobile-Security-Framework-MobSF v4.5.3](https://kitploit.com/en/posts/github-mobsf-mobile-security-framework-mobsf-v453) - [ ] [opensoho v0.15.2](https://kitploit.com/en/posts/github-rubenbe-opensoho-v0152) - [ ] [kube-monkey v0.7.0](https://kitploit.com/en/posts/github-asobti-kube-monkey-v070) - [ ] [aquaman v0.15.0](https://kitploit.com/en/posts/github-tech4242-aquaman-v0150) - Blackhat Library: Hacking techniques and research - [ ] [Masterhacker](https://www.reddit.com/r/blackhat/comments/1wner1p/masterhacker/) - [ ] [How do coordinated comment-bot rings manipulate short-form video algorithms to force "Top Comments"? (Technical Breakdown)](https://www.reddit.com/r/blackhat/comments/1wn4o1j/how_do_coordinated_commentbot_rings_manipulate/) - [ ] [A New Tool Found Malware That’s Guided by an AI Hive Mind—No Humans in Sight](https://www.reddit.com/r/blackhat/comments/1wn7rix/a_new_tool_found_malware_thats_guided_by_an_ai/) - www.theregister.com - Articles - [ ] [Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions](https://www.theregister.com/security/2026/09/22/windows-closedquorum-malware-uses-ai-models-to-autonomously-select-post-compromise-actions/5298435) - [ ] [ShinyHunters claims FBI hack: 'This is NOT financially motivated'](https://www.theregister.com/security/2026/09/22/shinyhunters-claims-fbi-hack-this-is-not-financially-motivated/5298385) - [ ] [NightmareEclipse's latest zero-day leaves Microsoft Defender stuck in the past](https://www.theregister.com/security/2026/09/22/nightmareeclipses-latest-zero-day-leaves-microsoft-defender-stuck-in-the-past/5298320) - [ ] [Z.ai says sorry for slurping up your code, open sources ZCode](https://www.theregister.com/security/2026/09/22/zai-says-sorry-for-slurping-up-your-code-open-sources-zcode/5298300) - [ ] [UK cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites](https://www.theregister.com/security/2026/09/22/uk-cops-arrest-2-eviltokens-suspects-microsoft-seizes-50-phishing-kit-websites/5298317) - [ ] [Who signed off on that AI agent? Nobody? Thought so.](https://www.theregister.com/security/2026/09/22/sponsored/5297693) - TorrentFreak - [ ] [Pirate IPTV App LiveNetTV Shut Down After Turkish Police Raid, Operators Settle With ACE](https://torrentfreak.com/pirate-iptv-app-livenettv-shut-down-after-turkish-police-raid-operators-settle-with-ace/) - Full Disclosure - [ ] [Code Security Review tool](https://seclists.org/fulldisclosure/2026/Sep/49) - [ ] [HP Advance / Output Central: unauthenticated SYSTEM RCE and two additional vulnerabilities (CVE-2026-89082/89083/89084)](https://seclists.org/fulldisclosure/2026/Sep/66) - [ ] [CFP No cON Name 2k26 - Palma, Mallorca - Spain](https://seclists.org/fulldisclosure/2026/Sep/48) - [ ] [CVE-2026-17613: Penpot cross-team file takeover via import-binfile (unpatched in 2.17.2)](https://seclists.org/fulldisclosure/2026/Sep/47) - [ ] [CVE-2026-44756: Pre-Auth RCE in SAP EPP Processing (ICM, Web Dispatcher, disp+work)](https://seclists.org/fulldisclosure/2026/Sep/65) - [ ] [[0day-rubbish] TigerGraph Community Edition 4.2.4 Default credentials plus GSQL TO_CSV arbitrary file write to SSH code execution (9.8)](https://seclists.org/fulldisclosure/2026/Sep/64) - [ ] [[0day-rubbish] Teltonika RutOS 00.07.06.21 Authenticated ipsec.lua logread command injection with reflected output (8.8)](https://seclists.org/fulldisclosure/2026/Sep/63) - [ ] [APPLE-SA-09-14-2026-10 Xcode 27](https://seclists.org/fulldisclosure/2026/Sep/62) - [ ] [APPLE-SA-09-14-2026-9 Safari 27](https://seclists.org/fulldisclosure/2026/Sep/61) - [ ] [APPLE-SA-09-14-2026-8 visionOS 27](https://seclists.org/fulldisclosure/2026/Sep/60) - [ ] [APPLE-SA-09-14-2026-7 watchOS 27](https://seclists.org/fulldisclosure/2026/Sep/59) - [ ] [APPLE-SA-09-14-2026-6 tvOS 27](https://seclists.org/fulldisclosure/2026/Sep/58) - [ ] [APPLE-SA-09-14-2026-5 macOS Sequoia 15.8](https://seclists.org/fulldisclosure/2026/Sep/57) - [ ] [APPLE-SA-09-14-2026-4 macOS Tahoe 26.7](https://seclists.org/fulldisclosure/2026/Sep/56) - [ ] [APPLE-SA-09-14-2026-3 macOS Golden Gate 27](https://seclists.org/fulldisclosure/2026/Sep/55) - Tor Project blog - [ ] [New Alpha Release: Tor Browser 16.0a12](https://blog.torproject.org/new-alpha-release-tor-browser-160a12/) - Security Affairs - [ ] [Check Point Fixes a New Actively Exploited Critical Security Flaw](https://securityaffairs.com/199549/security/check-point-fixes-a-new-actively-exploited-critical-security-flaw.html) - [ ] [Chaotic Eclipse Released BigDiskBuster, A PoC For Windows Defender Update DoS Zero-Day](https://securityaffairs.com/199538/hacking/chaotic-eclipse-released-bigdiskbuster-a-poc-for-windows-defender-update-dos-zero-day.html) - [ ] [Public PoC Exposes Critical Veeam Agent Privilege Escalation](https://securityaffairs.com/199532/security/public-poc-exposes-critical-veeam-agent-privilege-escalation.html) - [ ] [U.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalog](https://securityaffairs.com/199518/hacking/u-s-cisa-adds-zyxel-flaw-to-its-known-exploited-vulnerabilities-catalog.html) - [ ] [Contagious Interview: 30,000 devices infected by a fake job interview](https://securityaffairs.com/199506/uncategorized/contagious-interview-30000-devices-infected-by-a-fake-job-interview.html) - NetSPI - [ ] [CVE-2026-78902: XSS to RCE in pfSense with one DNS request](https://www.netspi.com/blog/technical-blog/web-application-pentesting/cve-2026-78902-xss-to-rce-in-pfsense-with-one-dns-request/) - Security Weekly Podcast Network (Audio) - [ ] [Understanding Prompt Injection In Order to Contain It - Julie Brunias - ASW #401](http://sites.libsyn.com/18678/understanding-prompt-injection-in-order-to-contain-it-julie-brunias-asw-401)
每日安全资讯(2026-09-23)