# 每日安全资讯(2026-09-25) - Microsoft Security Blog - [ ] [Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments](https://www.microsoft.com/en-us/security/blog/2026/09/24/beyond-ransomware-tracking-storm-2570-consistent-tradecraft-across-deployments/) - [ ] [What’s new in Microsoft Security: September 2026](https://www.microsoft.com/en-us/security/blog/2026/09/24/whats-new-in-microsoft-security-september-2026/) - Private Feed for M09Ic - [ ] [bolucat released 202609242322 at bolucat/Archive](https://github.com/bolucat/Archive/releases/tag/202609242322) - [ ] [strands-agents released harness-cli/v0.1.3 at strands-agents/harness-sdk](https://github.com/strands-agents/harness-sdk/releases/tag/harness-cli/v0.1.3) - [ ] [anthropics released v2.1.282 at anthropics/claude-code](https://github.com/anthropics/claude-code/releases/tag/v2.1.282) - [ ] [esrrhs contributed to esrrhs/spp](https://github.com/esrrhs/spp/pull/48) - [ ] [strands-agents released mcp/v0.3.0 at strands-agents/harness-sdk](https://github.com/strands-agents/harness-sdk/releases/tag/mcp/v0.3.0) - [ ] [huoji120 starred lordx64/phantom-kv](https://github.com/lordx64/phantom-kv) - [ ] [Mr-xn starred yu1745/wetype-ime-linux](https://github.com/yu1745/wetype-ime-linux) - [ ] [pydantic released v1.0.0-beta.3 at pydantic/monty](https://github.com/pydantic/monty/releases/tag/v1.0.0-beta.3) - [ ] [huoji120 forked huoji120/cyberkimi-benchmarks from lordx64/cyberkimi-benchmarks](https://github.com/huoji120/cyberkimi-benchmarks) - [ ] [huoji120 starred lordx64/cyberkimi-benchmarks](https://github.com/lordx64/cyberkimi-benchmarks) - [ ] [timwhitez starred NandhaKishorM/laya](https://github.com/NandhaKishorM/laya) - [ ] [safedv starred ricardojoserf/CrystalPotato](https://github.com/ricardojoserf/CrystalPotato) - [ ] [gh0stkey starred nex-agi/Nex-N2.5](https://github.com/nex-agi/Nex-N2.5) - [ ] [whwlsfb starred yaklang/javajive](https://github.com/yaklang/javajive) - [ ] [future-architect released v0.41.0-rc.1 at future-architect/vuls](https://github.com/future-architect/vuls/releases/tag/v0.41.0-rc.1) - [ ] [pydantic released v2.49.0 at pydantic/pydantic-ai](https://github.com/pydantic/pydantic-ai/releases/tag/v2.49.0) - [ ] [timwhitez starred tihanyin/REx-skill](https://github.com/tihanyin/REx-skill) - [ ] [Mel0day starred riba2534/claude-opus-5-5-demo](https://github.com/riba2534/claude-opus-5-5-demo) - 安全客-有思想的安全新媒体 - [ ] [26秒攻陷11家机构:AI智能体第一次像蜂群一样打过来](https://www.anquanke.com/post/id/316181) - ElcomSoft blog - [ ] [Low-Level Extraction the Apple TV 4K 2nd Generation](https://blog.elcomsoft.com/2026/09/low-level-extraction-the-apple-tv-4k-2nd-generation/) - Doonsec's feed - [ ] [【AI安全】LoRango把触发器拆成两份LoRA:单独审计为何看不见后门](https://mp.weixin.qq.com/s/szMEifJEuPOrvk8aRwbyHg) - [ ] [【客户端安全】代理绕过127监听CDP+Websocket协议未授权RCE漏洞](https://mp.weixin.qq.com/s/fQpansPQgG_9YKMVknKaiQ) - [ ] [别再把LLM当扫描器用了:CyberStrike把Claude订阅变成了一个会自己思考的红队操作员](https://mp.weixin.qq.com/s/E_Qf1MouykW8_ngM-88gDw) - [ ] [朝鲜黑客组织(Kimsuky)利用 OpenCode人工智能代理大规模生产 LNK 攻击中的钓鱼诱饵](https://mp.weixin.qq.com/s/4n-0c7paIIJkgOMa_lLOIA) - [ ] [【AI安全】恶意仓库指定审查员:Claude Code为何在绿灯测试中执行载荷](https://mp.weixin.qq.com/s/UfahWPAjO8NJqR2FFEdguA) - [ ] [三年了,我从一罐假蜂蜜里醒了过来](https://mp.weixin.qq.com/s/m_a72VUgrNnId22R2xWQ2w) - arighi's blog - [ ] [Porting Linux's fair/EEVDF Scheduler to BPF](http://arighi.blogspot.com/2026/09/porting-linuxs-faireevdf-scheduler-to.html) - SecWiki News - [ ] [SecWiki News 2026-09-24 Review](http://www.sec-wiki.com/?2026-09-24) - Blog on STAR Labs - [ ] [Dirty Cert: Cisco Smart Software Manager's Silently Patched RCE](https://starlabs.sg/blog/2026/09-dirty-cert-cisco-smart-software-managers-silently-patched-rce/) - [ ] [How I Found a $113,337 AF_ALG Linux Local Privilege Escalation Before Copy Fail](https://starlabs.sg/blog/2026/09-how-i-found-a-113337-af_alg-linux-local-privilege-escalation-before-copy-fail/) - Der Flounder - [ ] [App Settings declarative management may block unsigned apps on macOS Golden Gate](https://derflounder.wordpress.com/2026/09/24/app-settings-declarative-management-may-block-unsigned-apps-on-macos-golden-gate/) - Paper - 知道创宇404实验室 - [ ] [多源 LLM 智能体输入中分段级投毒的检测与定位](https://paper.seebug.org/3523) - Recent Commits to cve:main - [ ] [Update Thu Sep 24 12:46:49 UTC 2026](https://github.com/trickest/cve/commit/655b5e8b3e802011ccb22592adff749bc13e69cc) - Kitploit — Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal! - [ ] [mauidll](https://kitploit.com/en/tools/github/bishopfox/mauidll) - [ ] [Ajar](https://kitploit.com/en/tools/github/resharma/ajar) - [ ] [deleting-the-trace](https://kitploit.com/en/tools/github/usama1002/deleting-the-trace) - [ ] [dpapi-toolkit](https://kitploit.com/en/tools/github/crypt0p3g/dpapi-toolkit) - [ ] [not-a-mused](https://kitploit.com/en/tools/github/pwardle/not-a-mused) - [ ] [TBP-NETWORK](https://kitploit.com/en/tools/github/philippeabraxas-jpg/tbp-network) - [ ] [REx-skill](https://kitploit.com/en/tools/github/tihanyin/rex-skill) - [ ] [Dji_ble_vuln](https://kitploit.com/en/tools/github/feedbeef/dji_ble_vuln) - [ ] [security-portfolio](https://kitploit.com/en/tools/github/mitsu-bis/security-portfolio) - Securelist - [ ] [MacSync under the microscope: new delivery methods and a new payload](https://securelist.com/macsync-new-version/121383/) - Malwarebytes - [ ] [OpenAI agent breached Australian government site, took months to report it](https://www.malwarebytes.com/blog/ai/2026/09/openai-agent-breached-medicare-statistics-portal-then-took-months-to-report-it) - [ ] [New Browser Guard features add protection before and after you click](https://www.malwarebytes.com/blog/product/2026/09/new-browser-guard-features-add-protection-before-and-after-you-click) - [ ] [Update Chrome: 108 security fixes for desktop, new release for Android](https://www.malwarebytes.com/blog/bugs/2026/09/update-chrome-108-security-fixes-for-desktop-new-release-for-android) - [ ] [Google’s location data privacy failures draw a €403 million fine](https://www.malwarebytes.com/blog/news/2026/09/googles-location-data-privacy-failures-draw-a-e403-million-fine) - GuidePoint Security - [ ] [Securing GenAI in the Real World: Assessing a Structured GenAI Implementation with Amazon Bedrock](https://www.guidepointsecurity.com/blog/securing-gen-ai/) - Reverse Engineering - [ ] [How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers](https://www.reddit.com/r/ReverseEngineering/comments/1wp462h/how_cloudflare_addressed_a_crosstenant_data/) - [ ] [Design Token Extractor - Chrome Web Store](https://www.reddit.com/r/ReverseEngineering/comments/1wox817/design_token_extractor_chrome_web_store/) - [ ] [Part 2: DWM Visual-layer anti-capture — CVisual::HasProtectedContent (Win11 research notes)](https://www.reddit.com/r/ReverseEngineering/comments/1wopzgc/part_2_dwm_visuallayer_anticapture/) - HAHWUL - [ ] [Statusline for Claude Code, agy, Codex, Grok](https://www.hahwul.com/notes/agent-cli/statusline/) - Lenny Zeltser - [ ] [AI-Assisted Malware Analysis Tips](https://zeltser.com/ai-assisted-malware-analysis-tips) - text/plain - [ ] [“The” IP Address](https://textslashplain.com/2026/09/24/the-ip-address/) - HackerNews - [ ] [OpenAI 智能体绕过澳大利亚 Medicare 门户的访问控制,访问了非公开文件](http://0.0.0.0:8080/post/64731) - [ ] [攻击者利用恶意 Terraform Providers 通过 HashiCorp 注册表投递 Go 恶意软件](http://0.0.0.0:8080/post/64730) - [ ] [一个泄露的 GitLab Issue 电子邮件地址让任何人都能以你的身份推送代码并运行 CI 任务](http://0.0.0.0:8080/post/64729) - [ ] [MikroTrick 攻击链让攻击者无需密码或 SSH 密钥即可接管 MikroTik 路由器](http://0.0.0.0:8080/post/64728) - [ ] [开发文档中的占位域名现在被用于发动 ClickFix 攻击](http://0.0.0.0:8080/post/64727) - [ ] [新型 RemControl Android 银行木马瞄准欧洲和加拿大用户](http://0.0.0.0:8080/post/64726) - 奇客Solidot–传递最新科技情报 - [ ] [蝙蝠起源于欧洲](https://www.solidot.org/story?sid=85473) - [ ] [部分三星智能冰箱在升级固件之后停止工作](https://www.solidot.org/story?sid=85472) - [ ] [微软放弃封禁 Microslop](https://www.solidot.org/story?sid=85471) - [ ] [阿根廷生育率十年内下降五成](https://www.solidot.org/story?sid=85470) - [ ] [arXiv 项目获得 1720 万美元的捐赠承诺](https://www.solidot.org/story?sid=85469) - [ ] [2025 年全台每 46 名新生儿就有 1 个是台积电宝宝](https://www.solidot.org/story?sid=85468) - 腾讯玄武实验室 - [ ] [每日安全动态推送(26/9/24)](https://mp.weixin.qq.com/s?__biz=MzA5NDYyNDI0MA==&mid=2651960560&idx=1&sn=856d2100189b10178a08e9bba2f280a9) - 黑鸟 - [ ] [取证软件巨头暗掩俄资身份,美国多部门集体踩雷](https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451188938&idx=1&sn=b25fb2a3ee71bce29cbb22a605db970d) - 威努特安全网络 - [ ] [工业数据“出海”:从本地到跨境,如何保障全程安全?](https://mp.weixin.qq.com/s?__biz=MzAwNTgyODU3NQ==&mid=2651144357&idx=1&sn=258ab2f56dddc1734e7851fc27770fbd) - 代码卫士 - [ ] [ManageEngine 严重漏洞可导致攻击者通过 Windows 登录获屏幕得系统权限](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247527227&idx=1&sn=9cb59c56483b05b9d69397491a54323c) - [ ] [GitLab 邮件地址可用于供应链攻击](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247527227&idx=2&sn=ebe8eb1c6273dd854494ce61cdcf3e57) - 微步在线研究响应中心 - [ ] [已复现 | VMware vCenter pre-auth RCE](https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&mid=2247508960&idx=1&sn=7769927037c8c71dff3bd7802cce35ff) - 安全分析与研究 - [ ] [差分隐私的信息论基础与最优机制](https://mp.weixin.qq.com/s?__biz=MzA4ODEyODA3MQ==&mid=2247497198&idx=1&sn=de28d86dd85c7e6389b0d33f35edb7d1) - Shostack & Friends Blog - [ ] [Diagrams versus Models (Threat Model Thursday)](https://shostack.org/blog/diagrams-versus-models/) - 安全内参 - [ ] [智能体非法入侵政府网站,OpenAI遭一国家总理严厉训诫](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516656&idx=1&sn=f10fa4ab3cdf77d0d6f02c3a87ccf4be) - [ ] [当黑客交给AI Agent干活:拿下每个目标仅需25美元](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516656&idx=2&sn=d2be84cc68d7a6312e6153581d1fef8a) - 中国信息安全 - [ ] [第十六届网络安全漏洞分析与风险评估大会 | “智·基 数智赋能下关键信息基础设施安全治理实践”分论坛成功举办](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664267324&idx=1&sn=f9b142e00efbdfe27684769e90dd9ccd) - [ ] [第十六届网络安全漏洞分析与风险评估大会 | 人工智能漏洞研究与治理分论坛成功举办](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664267324&idx=2&sn=afb32ff37beb0f00184ed0669de5ae3e) - [ ] [第十六届VARA大会信息安全企业家论坛在重庆举办 首批人工智能安全资质正式发布](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664267324&idx=3&sn=d77e9d58976cbaff20dfb559a1f68667) - 安全研究GoSSIP - [ ] [G.O.S.S.I.P 阅读推荐 2026-09-24 Baseband 安全小结](https://mp.weixin.qq.com/s?__biz=Mzg5ODUxMzg0Ng==&mid=2247502257&idx=1&sn=e6594a5f1aaaa088178256bd44ca64ab) - 数世咨询 - [ ] [225 个 Anthropic 相关 CVE,真正被利用的只有 1 个](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247544051&idx=1&sn=ec36427487a4953f007849d392a3609a) - [ ] [设备一碰就"瘫"?一场夜间扫描揭开芯片制造的隐形风险](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247544051&idx=2&sn=922e47beac5464ae6663c7559eb6c594) - 奇安信 CERT - [ ] [安全热点周报:Check Point 警告称其管理服务器零日漏洞正被用于定向攻击](https://mp.weixin.qq.com/s?__biz=MzU5NDgxODU1MQ==&mid=2247507676&idx=1&sn=5413b9d5c8b63749207148b9f0c93bb0) - 安全学术圈 - [ ] [10月17日专题会议:网络威胁机理及数据集构建学术会议](https://mp.weixin.qq.com/s?__biz=MzU5MTM5MTQ2MA==&mid=2247495968&idx=1&sn=a8275f153b987bfe3a02c90eb7301706) - [ ] [10月17日专题会议:新技术应用安全前沿学术会议](https://mp.weixin.qq.com/s?__biz=MzU5MTM5MTQ2MA==&mid=2247495968&idx=2&sn=bdbdb0bf7d3c5e2649dbf1c4b7133ae1) - [ ] [10月17日专题会议:系统安全与基础设施防御学术会议](https://mp.weixin.qq.com/s?__biz=MzU5MTM5MTQ2MA==&mid=2247495968&idx=3&sn=ab2c922dc72fb5e3e4d2af49ffd70664) - [ ] [10月17日专题会议:新型网络体系与行为智能分析学术会议](https://mp.weixin.qq.com/s?__biz=MzU5MTM5MTQ2MA==&mid=2247495968&idx=4&sn=8d5e53f86b84030360eb4dcbc0b7fa9c) - [ ] [10月17日专题会议:人工智能安全前沿学术会议](https://mp.weixin.qq.com/s?__biz=MzU5MTM5MTQ2MA==&mid=2247495968&idx=5&sn=4d504aee48dbe2a5d5b3bd20e0f7e86c) - [ ] [10月17日专题会议:数据安全防护与治理前沿学术会议](https://mp.weixin.qq.com/s?__biz=MzU5MTM5MTQ2MA==&mid=2247495968&idx=6&sn=a956d9228d8e04ad9764160aa5fa7205) - 安全牛 - [ ] [当"运维故障"成为攻击伪装:波兰热电厂事件深度解读](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142839&idx=1&sn=f643296c204f81ce26f49ba2b3ef30b2) - [ ] [为可信智能时代筑基:2026 CSA大中华区大会暨AI+安全大会聚焦基础设施安全与产业实践](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142839&idx=2&sn=23ebebf313d4d0e55184f92b670e47be) - NOVASEC - [ ] [间接性暂停更新](https://mp.weixin.qq.com/s?__biz=MzUzODU3ODA0MA==&mid=2247490937&idx=1&sn=0e93d9cb35bccb69d0d9d9977c4ed207) - 京东安全应急响应中心 - [ ] [京东安全应急响应中心关于白帽子违规测试的处置公告](https://mp.weixin.qq.com/s?__biz=MjM5OTk2MTMxOQ==&mid=2727851365&idx=1&sn=225aefe18a3566889038b5685665b2e2) - 看雪学苑 - [ ] [议题公布!SDC2026 议程上线,解锁人机时代攻防新篇](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458621752&idx=1&sn=a441196ba1fecde164b052739091d462) - 奇安信威胁情报中心 - [ ] [AI 记忆框架遭供应链投毒:MemTensor 双仓库沦陷,新型 Go 蠕虫 sckit 窃凭证、能自我复制](https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247520712&idx=1&sn=8b736ff41e91f4f975ab73e1d19505fb) - 极客公园 - [ ] [中国智能汽车的后台,越来越像阿里云的主场](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653114115&idx=1&sn=4d57e7af98a2edd9d183bf3104b27bc8) - [ ] [从超级个体到超级组织,究竟还有多远?](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653114087&idx=1&sn=5aceda5f6261095392d3cf0f7d58f294) - [ ] [Agent 时代来了,3D 生成大模型接下来比什么?](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653114072&idx=1&sn=a8961f7e34e728abb8a925b80b0c6978) - 字节跳动安全中心 - [ ] [TWIST 入选 ACM CCS 2026:面向云上大模型服务的隐私保护新方案](https://mp.weixin.qq.com/s?__biz=MzUzMzcyMDYzMw==&mid=2247496388&idx=1&sn=0091694c8514d609e619f61895bc492a) - OPPO安全中心 - [ ] [OSRC中秋国庆放假通知](https://mp.weixin.qq.com/s?__biz=MzUyNzc4Mzk3MQ==&mid=2247495080&idx=1&sn=ee80a949f75f1f12ac9f8ea63859e094) - 国家互联网应急中心CNCERT - [ ] [“银狐”木马专项——恶意域名及恶意IP(五)](https://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw==&mid=2247502233&idx=1&sn=e70fb42a469b23f5dfa2c8c5959532f3) - 网络空间安全科学学报 - [ ] [重磅预告|张勇东教授将在2026年网络空间安全学术会议作主旨报告](https://mp.weixin.qq.com/s?__biz=MzI0NjU2NDMwNQ==&mid=2247509648&idx=1&sn=5b4e90369ffb865860e3733eacf88013) - [ ] [10月17日专题会议:智能计算与调度安全前沿学术会议](https://mp.weixin.qq.com/s?__biz=MzI0NjU2NDMwNQ==&mid=2247509648&idx=2&sn=873b233504af405c49aa02ac41102af4) - [ ] [10月17日专题会议:网络空间智能对抗前沿学术会议](https://mp.weixin.qq.com/s?__biz=MzI0NjU2NDMwNQ==&mid=2247509648&idx=3&sn=a12375480c9835b352c6db439401d422) - [ ] [2026年网络空间安全学术会议早鸟注册倒计时2天!](https://mp.weixin.qq.com/s?__biz=MzI0NjU2NDMwNQ==&mid=2247509648&idx=4&sn=0d2cdc00aac274775fe5e56ce85c69ad) - 火绒安全 - [ ] [紧急预警|.ths勒索软件活动升温 多用户文件遭批量加密](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247538022&idx=1&sn=22ab7b25464bdb769151e1a9f9565605) - [ ] [诚邀渠道合作伙伴共启新征程](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247538022&idx=2&sn=d731747950921b60ffe5998cec6f2c8b) - 云鼎实验室 - [ ] [腾讯CodeBuddy Security发现Suricata史上首个RCE漏洞](https://mp.weixin.qq.com/s?__biz=MzU3ODAyMjg4OQ==&mid=2247497997&idx=1&sn=6c39e443ce62b477fc8784bae4ef4edc) - 情报分析师 - [ ] [这段“现场视频”是真的吗?只查了三个细节,就发现故事不对](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650569794&idx=1&sn=38c995a4ddabef087ab098046269c24d) - [ ] [多伦多大学公民实验室披露以色列承包商培训安哥拉官员开展网络影响行动,非洲舆论操控商业化、雇佣化趋势需关注](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650569794&idx=2&sn=4a49b8501c772f948d4f00a6543d4c2f) - TrustedSec - [ ] [What's New in hate_crack Since 2.0](https://trustedsec.com/blog/whats-new-in-hate-crack-since-2-0) - 慢雾科技 - [ ] [月满中秋,慢雾献礼](https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&mid=2247506239&idx=1&sn=59c062c9e84a4d2ec705556f874236da) - 奇安信病毒响应中心 - [ ] [每周勒索威胁摘要](https://mp.weixin.qq.com/s?__biz=MzI5Mzg5MDM3NQ==&mid=2247498645&idx=1&sn=5e2631b5152be4f1463a18ce6c71eccf) - huasec - [ ] [对一款Windows木马开源提示词的测评](https://mp.weixin.qq.com/s?__biz=MzIyOTY1NDE5Mg==&mid=2247485577&idx=1&sn=be26c2eb3f2fccfd20a9e030d9bf2181) - 墨菲安全 - [ ] [金融机构用好AI,需要跟上哪些变化去管住新增的安全风险?](https://mp.weixin.qq.com/s?__biz=MzkwOTM0MjI5NQ==&mid=2247488735&idx=1&sn=9aab51db53c0399c15bf63426d083a66) - 安全419 - [ ] [安全419|一周国际网安资讯:管理平台漏洞密集爆发,AI代理攻防进入新阶段](https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&mid=2247555609&idx=1&sn=a234d817f4bd26266211f05e9dfe9a51) - [ ] [(国际投稿)早期证明可能让机密数据面临高风险](https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&mid=2247555609&idx=2&sn=d852d81eacc65a7c29805db3412d46df) - DEF CON Announcements! - [ ] [DEF CON Singapore Dates!](https://defcon.org/html/defcon-34/dc-34-news.html#sing2dates) - 悬镜安全 - [ ] [持续入选《2026 网络安全十大创新方向》,问境AIST引领智能体安全治理!](https://mp.weixin.qq.com/s?__biz=MzA3NzE2ODk1Mg==&mid=2647800855&idx=1&sn=45f0fc307a50da666bb4daa782335b54) - Over Security - [ ] [MacSync malware uses public iCloud calendars to deliver new payloads](https://www.bleepingcomputer.com/news/security/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads/) - [ ] [Digital forensics firm with US federal contracts covered up ties to Russia, DOJ alleges](https://therecord.media/russia-forensics-technology-doj) - [ ] [Lawmakers introduce bill for voluntary telecom cyber rules after Salt Typhoon hacks](https://therecord.media/lawmakers-introduce-bill-for-voluntary-telecom-cyber-rules) - [ ] [Bitdefender crea una VPN per gli agenti AI](https://www.securityinfo.it/2026/09/21/bitdefender-crea-una-vpn-per-gli-agenti-ai/) - [ ] [New Carbonato malware uses AI agents to hijack exposed Docker hosts](https://www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts/) - [ ] [Rydox cybercriminal marketplace operator pleads guilty following co-conspirator brothers’s deportation](https://therecord.media/rydox-criminal-marketplace-operator-pleads-guilty) - [ ] [Trust and the enticing consultancy offer](https://blog.talosintelligence.com/trust-and-the-enticing-consultancy-offer/) - [ ] [Exposed GitLab project email addresses let attackers push code](https://www.bleepingcomputer.com/news/security/exposed-gitlab-project-email-addresses-let-attackers-push-code/) - [ ] [Caso Revolut: girano documenti di ministeri, quanto è grave](https://www.cybersecurity360.it/news/caso-revolut-girano-documenti-di-ministeri-quanto-e-grave/) - [ ] [dfir.ch](https://dfir.ch/posts/__tweet/) - [ ] [The .zshrc.zwc You Forgot to Check](http://localhost:1313/posts/compiled_zsh/) - [ ] [OpenAI, un agente AI viola un sistema governativo australiano: cosa non ha funzionato](https://www.cybersecurity360.it/news/openai-un-agente-ai-viola-un-sistema-governativo-australiano-cosa-non-ha-funzionato/) - [ ] [Quantum-safe network: perché la cybersecurity deve prepararsi all’era post-quantistica](https://www.cybersecurity360.it/soluzioni-aziendali/quantum-safe-network-perche-la-cybersecurity-deve-prepararsi-allera-post-quantistica/) - [ ] [One Tap Too Far: Using Shortcuts to Bypass Chrome for iOS Call Prompts](https://blog.doyensec.com/2026/09/24/chrome-ios-policy-bypass.html) - [ ] [FedRAMP VDR & VER: Daily Scans Are Only the Beginning](https://www.bleepingcomputer.com/news/security/fedramp-vdr-and-ver-daily-scans-are-only-the-beginning/) - [ ] [Compliance e cyber security: perché la governance non può più essere gestita a silos](https://www.cybersecurity360.it/soluzioni-aziendali/compliance-e-cyber-security-perche-la-governance-non-puo-piu-essere-gestita-a-silos/) - [ ] [Kyiv internet providers report major outages after Russian attacks damage data centers](https://therecord.media/kyiv-internet-providers-report-outages-after-russian-strikes) - [ ] [MintsLoader via PEC: falsi solleciti di pagamento per diffondere malware](https://cert-agid.gov.it/news/mintsloader-via-pec-falsi-solleciti-di-pagamento-per-diffondere-malware/) - [ ] [Astrana latest healthcare tech firm to report data breach to SEC](https://therecord.media/astrana-cyberattack-sec-ransomware) - [ ] [Hackers now exploit critical Roundcube flaw in code injection attacks](https://www.bleepingcomputer.com/news/security/critical-roundcube-flaw-now-actively-exploited-in-code-injection-attacks/) - [ ] [OpenAI agent breached Australian government health website, Albanese says](https://therecord.media/openai-australia-health-breach) - [ ] [How Can You Tell if a Domain Is Malicious?](https://bfore.ai/blog/how-to-determine-whether-a-domain-is-malicious-or-not/) - [ ] [Ionos azzera il costo del piano Plus per 12 mesi per spingere le PMI europee online](https://www.cybersecurity360.it/cultura-cyber/ionos-web-hosting-plus-zero-euro-sicurezza/) - [ ] [Windows 11 KB5124010 update released with 46 changes and fixes](https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5124010-update-released-with-46-changes-and-fixes/) - [ ] [Offerta NordVPN: sconti fino al 75% e tre mesi gratis per il cyber mese](https://www.cybersecurity360.it/cultura-cyber/nordvpn-offerta-sconto-75-per-cento-3-mesi-gratis-cybersecurity/) - [ ] [Falso sito del Servizio Sanitario Nazionale distribuisce StreamRat su Android e XWorm su Windows](https://cert-agid.gov.it/news/falso-sito-del-servizio-sanitario-nazionale-distribuisce-streamrat-su-android-e-xworm-su-windows/) - [ ] [CISA: Ransomware gangs now exploiting critical TeamCity flaw](https://www.bleepingcomputer.com/news/security/cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw/) - [ ] [MacSync under the microscope: new delivery methods and a new payload](https://securelist.com/macsync-new-version/121383/) - [ ] [ENISA Threat Landscape 2026: il rischio cyber corre lungo la supply chain](https://www.cybersecurity360.it/nuove-minacce/enisa-threat-landscape-2026-il-rischio-cyber-corre-lungo-la-supply-chain/) - [ ] [OpenAI hacked Australian Medicare govt site, probed data providers](https://www.bleepingcomputer.com/news/security/openai-hacked-australian-medicare-govt-site-probed-data-providers/) - [ ] [Apache Tomcat Update: 12 Security Flaws Fixed in Tomcat 11.0.26](https://thecyberexpress.com/apache-tomcat-update-cve-2026-87022/) - [ ] [Che cosa sono le ambasciate dei dati](https://www.guerredirete.it/che-cosa-sono-le-ambasciate-dei-dati/) - [ ] [No One Gets Phished: The New Group-IB Browser Agent Applies Predictive Intelligence At The Click.](https://www.group-ib.com/blog/no-one-gets-phished-browser-agent/) - [ ] [L’era degli hacker “Gentlemen”: perché la lotta al ransomware richiede nuove strategie difensive](https://www.cybersecurity360.it/nuove-minacce/ransomware/lera-degli-hacker-gentlemen-perche-la-lotta-al-ransomware-richiede-nuove-strategie-difensive/) - [ ] [Microsoft fixes bug that broke Windows File History backup feature](https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-windows-backup-feature-broken-by-september-updates/) - [ ] [OT Security: la resilienza industriale nell’era della convergenza con l’IT](https://www.cybersecurity360.it/legal/ot-security-la-resilienza-industriale-nellera-della-convergenza-con-lit/) - [ ] [Latvia Hacker Arrested Over TSC Data Theft and Extortion Attempt](https://thecyberexpress.com/latvia-cyberattack-hacker-arrested/) - [ ] [OpenAI AI Agent Breaches Australian Government Website, Albanese Demands Answers](https://thecyberexpress.com/openai-hack-australian-government-portal/) - [ ] [Ofcom Investigates Pornhub Parent Aylo Over Age Checks](https://thecyberexpress.com/ofcom-probes-pornhub-age-checks/) - [ ] [http://localhost:1313/posts/__tweet/](http://localhost:1313/posts/__tweet/) - [ ] [Living Inside the Shell: zsh Modules on macOS](http://localhost:1313/posts/zsh_modules/) - Yak Project - [ ] [YTray 与 Memfit 协同使用指南:多账号越权测试](https://mp.weixin.qq.com/s?__biz=Mzk0MTM4NzIxMQ==&mid=2247530404&idx=1&sn=a8b52f55a9dff5630f3b3e92484ad97c) - SANS Internet Storm Center, InfoCON: green - [ ] [One URL, Three Different Tricks, (Thu, Sep 24th)](https://isc.sans.edu/diary/rss/33366) - [ ] [ISC Stormcast For Thursday, September 24th, 2026 https://isc.sans.edu/podcastdetail/10108, (Thu, Sep 24th)](https://isc.sans.edu/diary/rss/33364) - Schneier on Security - [ ] [Malicious npm Packages That Evade Defenses](https://www.schneier.com/blog/archives/2026/09/malicious-npm-packages-that-evade-defenses.html) - Instapaper: Unread - [ ] [There's a new way to break RSA that's faster than anything we've seen before](https://arstechnica.com/security/2026/09/theres-a-new-way-to-break-rsa-thats-faster-than-anything-weve-seen-before/) - [ ] [Low-Level Extraction the Apple TV 4K 2nd Generation](https://blog.elcomsoft.com/2026/09/low-level-extraction-the-apple-tv-4k-2nd-generation/) - [ ] [Corrobora – Cross-Artifact Consistency Analysis For Windows Digital Forensics](https://www.forensicfocus.com/articles/corrobora-cross-artifact-consistency-analysis-for-windows-digital-forensics/) - [ ] [UE, il ransomware resta la principale minaccia cyber](https://www.cybersecitalia.it/ue-il-ransomware-resta-la-principale-minaccia-cyber/69815/) - [ ] [Perché il data breach all’FBI è un problema di sicurezza internazionale](https://www.agendadigitale.eu/sicurezza/perche-il-data-breach-allfbi-e-un-problema-di-sicurezza-internazionale/) - [ ] [Low-Level Extraction of the Apple Watch S4S5](https://blog.elcomsoft.com/2026/09/low-level-extraction-of-the-apple-watch-s4-s5/) - The Hacker News - [ ] [Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions](https://thehackernews.com/2026/09/unpatched-oneplus-flaws-let-installed.html) - [ ] [ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories](https://thehackernews.com/2026/09/threatsday-ai-search-poisoning-ai.html) - [ ] [Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content](https://thehackernews.com/2026/09/placeholder-third-partycom-referenced.html) - [ ] [Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer](https://thehackernews.com/2026/09/hacked-ukrainian-sites-serve-fake.html) - [ ] [Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls](https://thehackernews.com/2026/09/corp-mdm-spyware-targets-logistics.html) - [ ] [Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore](https://thehackernews.com/2026/09/secrets-sprawl-is-identity-problem-that.html) - [ ] [17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360](https://thehackernews.com/2026/09/17000-urls-reveal-how-clickfix-turns.html) - [ ] [OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files](https://thehackernews.com/2026/09/openai-agent-bypassed-australian.html) - [ ] [TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords](https://thehackernews.com/2026/09/teamfiltration-compromises-seven.html) - [ ] [Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure](https://thehackernews.com/2026/09/attackers-exploit-wordpress-cve-2026.html) - Deeplinks - [ ] [DraftKings Is Using AI to Supercharge the Harms of Online Behavioral Advertising](https://www.eff.org/deeplinks/2026/09/draftkings-using-ai-supercharge-harms-online-behavioral-advertising) - www.theregister.com - Articles - [ ] [Crook used three open source agents to break into a Fortune 500 hospitality company, a major US airline and 25+ other orgs](https://www.theregister.com/security/2026/09/25/crook-used-three-open-source-agents-to-break-into-a-fortune-500-hospitality-company-a-major-us-airline-and-25-other-orgs/5299012) - [ ] [Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing](https://www.theregister.com/security/2026/09/24/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-phishing/5298958) - [ ] [Decades-old file security flaws found in Android, Linux, macOS, and Windows](https://www.theregister.com/security/2026/09/24/decades-old-file-security-flaws-found-in-android-linux-macos-and-windows/5298672) - [ ] [CVE flood pushes Ubuntu onto weekly kernel release cycle](https://www.theregister.com/os-platforms/2026/09/24/cve-flood-pushes-ubuntu-onto-weekly-kernel-release-cycle/5298912) - [ ] [Someone went shopping in ASUS's eShop – for customer data](https://www.theregister.com/security/2026/09/24/someone-went-shopping-in-asuss-eshop-for-customer-data/5298860) - [ ] [Google to critical infra orgs: Our AI scanners won't be evil, promise](https://www.theregister.com/security/2026/09/24/google-to-critical-infra-orgs-our-ai-scanners-wont-be-evil-promise/5298685) - [ ] [Government contractor exposed path to immigration records](https://www.theregister.com/security/2026/09/24/government-contractor-exposed-path-to-immigration-records/5298689) - [ ] [OpenAI agents ‘infiltrated Australian government website’](https://www.theregister.com/security/2026/09/24/openai-agents-infiltrated-australian-government-website/5298702) - IndexSec - [ ] [SqlStealthRogue:让天底下没有难拖的数据库](https://mp.weixin.qq.com/s?__biz=MzUyOTI5MTM4OQ==&mid=2247484109&idx=1&sn=634d73c55caf75fe71ade531d1ae10a3) - Security Affairs - [ ] [Ryuk Member Karen Vardanyan Sentenced to Two Years in U.S. Prison](https://securityaffairs.com/199692/cyber-crime/ryuk-member-karen-vardanyan-sentenced-to-two-years-in-u-s-prison.html) - [ ] [AI Helps Uncover MikroTrick Attack Chain in MikroTik RouterOS](https://securityaffairs.com/199678/hacking/ai-helps-uncover-mikrotrick-attack-chain-in-mikrotik-routeros.html) - [ ] [OpenAI Agent Bypassed an Australian Government Health Portal During Internal Research](https://securityaffairs.com/199662/ai/openai-agent-bypassed-an-australian-government-health-portal-during-internal-research.html) - [ ] [CLOSEDQUORUM, the malware that asks four AI models what to do next](https://securityaffairs.com/199640/malware/closedquorum-the-malware-that-asks-four-ai-models-what-to-do-next.html) - KitPloit - PenTest Tools! - [ ] [mauidll](https://kitploit.com/en/tools/github/bishopfox/mauidll) - [ ] [Ajar](https://kitploit.com/en/tools/github/resharma/ajar) - [ ] [deleting-the-trace](https://kitploit.com/en/tools/github/usama1002/deleting-the-trace) - [ ] [dpapi-toolkit](https://kitploit.com/en/tools/github/crypt0p3g/dpapi-toolkit) - [ ] [not-a-mused](https://kitploit.com/en/tools/github/pwardle/not-a-mused) - [ ] [TBP-NETWORK](https://kitploit.com/en/tools/github/philippeabraxas-jpg/tbp-network) - [ ] [REx-skill](https://kitploit.com/en/tools/github/tihanyin/rex-skill) - [ ] [Dji_ble_vuln](https://kitploit.com/en/tools/github/feedbeef/dji_ble_vuln) - [ ] [security-portfolio](https://kitploit.com/en/tools/github/mitsu-bis/security-portfolio) - GRAHAM CLULEY - [ ] [Ukrainian ransomware developer jailed for nearly 13 years](https://www.bitdefender.com/en-us/blog/hotforsecurity/ukrainian-ransomware-developer-jailed-for-nearly-13-years) - Blackhat Library: Hacking techniques and research - [ ] [SourceHut account takeover via build logs](https://www.reddit.com/r/blackhat/comments/1wp59fj/sourcehut_account_takeover_via_build_logs/) - Daniel Miessler - [ ] [Two Upgrades to My AI Stack: Vigil and Idea-to-Video](https://danielmiessler.com/blog/vigil-and-idea-to-video?utm_source=rss&utm_medium=feed&utm_campaign=website)
每日安全资讯(2026-09-25)