# 每日安全资讯(2026-09-26) - Private Feed for M09Ic - [ ] [pydantic released v2.51.0 at pydantic/pydantic-ai](https://github.com/pydantic/pydantic-ai/releases/tag/v2.51.0) - [ ] [mgeeky starred HexRaysSA/ida-mcp](https://github.com/HexRaysSA/ida-mcp) - [ ] [bolucat released 202609252323 at bolucat/Archive](https://github.com/bolucat/Archive/releases/tag/202609252323) - [ ] [anthropics released v2.1.283 at anthropics/claude-code](https://github.com/anthropics/claude-code/releases/tag/v2.1.283) - [ ] [strands-agents released harness-cli/v0.1.4 at strands-agents/harness-sdk](https://github.com/strands-agents/harness-sdk/releases/tag/harness-cli/v0.1.4) - [ ] [timwhitez contributed to timwhitez/agent-sdk-golang](https://github.com/timwhitez/agent-sdk-golang/pull/183) - [ ] [safedv starred trailofbits/coop](https://github.com/trailofbits/coop) - [ ] [timwhitez starred google/ax](https://github.com/google/ax) - [ ] [Ridter starred tt-a1i/archify](https://github.com/tt-a1i/archify) - [ ] [pydantic released v1.0.0 at pydantic/monty](https://github.com/pydantic/monty/releases/tag/v1.0.0) - [ ] [CHYbeta starred tantosec/tturl](https://github.com/tantosec/tturl) - [ ] [chainreactors released v1.0.0-rc6 at chainreactors/cyber-harness](https://github.com/chainreactors/cyber-harness/releases/tag/v1.0.0-rc6) - [ ] [Rvn0xsy starred google/ax](https://github.com/google/ax) - [ ] [WAY29 starred koala73/worldmonitor](https://github.com/koala73/worldmonitor) - [ ] [pydantic released v2.50.0 at pydantic/pydantic-ai](https://github.com/pydantic/pydantic-ai/releases/tag/v2.50.0) - [ ] [spf13 forked spf13/go from golang/go](https://github.com/spf13/go) - SecWiki News - [ ] [SecWiki News 2026-09-25 Review](http://www.sec-wiki.com/?2026-09-25) - Hacking Articles - [ ] [Windows Privilege Escalation: SeManageVolumePrivilege](https://www.hackingarticles.in/windows-privilege-escalation-semanagevolumeprivilege/) - Der Flounder - [ ] [Apple Filing Protocol removed from macOS Golden Gate](https://derflounder.wordpress.com/2026/09/25/apple-filing-protocol-removed-from-macos-golden-gate/) - Microsoft Security Blog - [ ] [Storm-3168: Agentic-driven cloud attacks using compromised service principals](https://www.microsoft.com/en-us/security/blog/2026/09/25/storm-3168-agentic-driven-cloud-attacks-using-compromised-service-principals/) - Recent Commits to cve:main - [ ] [Update Fri Sep 25 12:23:58 UTC 2026](https://github.com/trickest/cve/commit/2832e7079fb71c43cf2c630380920c1bae1d5169) - Sploitus.com Exploits RSS Feed - [ ] [AstraRecon exploit](https://sploitus.com/exploit?id=F587A5E2-86B2-5925-9BB5-DF106F2772F3&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-96512](https://sploitus.com/exploit?id=B61E5A00-1230-5E18-BF55-19A81ED0C7A6&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-86350](https://sploitus.com/exploit?id=36E3818C-05BB-5797-A373-EA133743E98B&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-62062](https://sploitus.com/exploit?id=33F94CBD-2E88-51A0-A98F-DF6D6F27FF55&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Incorrect Implementation of Authentication Algorithm in Golang Crypto](https://sploitus.com/exploit?id=1E53DFDC-E275-5FDC-A9D0-0B9D9A2A9B7C&utm_source=rss&utm_medium=rss) - [ ] [sBOMBPath exploit](https://sploitus.com/exploit?id=12A08394-0EB6-5025-9E3D-D9F5DF1EC24A&utm_source=rss&utm_medium=rss) - [ ] [operative-framework exploit](https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-GRANIET-OPERATIVE-FRAMEWORK&utm_source=rss&utm_medium=rss) - [ ] [kasld exploit](https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-BCOLES-KASLD&utm_source=rss&utm_medium=rss) - [ ] [osint_toolkit exploit](https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-DEV-LU-OSINT_TOOLKIT&utm_source=rss&utm_medium=rss) - [ ] [ABPTTS exploit](https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-NCCGROUP-ABPTTS&utm_source=rss&utm_medium=rss) - [ ] [owasp-java-encoder exploit](https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-OWASP-OWASP-JAVA-ENCODER&utm_source=rss&utm_medium=rss) - [ ] [RMS-Runtime-Mobile-Security exploit](https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-M0BILESECURITY-RMS-RUNTIME-MOBILE-SECURITY&utm_source=rss&utm_medium=rss) - [ ] [M3UAScan exploit](https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-SIGPLOITER-M3UASCAN&utm_source=rss&utm_medium=rss) - [ ] [reversemap exploit](https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-Z00NX-REVERSEMAP&utm_source=rss&utm_medium=rss) - [ ] [C3 exploit](https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-REVERSECLABS-C3&utm_source=rss&utm_medium=rss) - [ ] [Pyrit exploit](https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-JPAULMORA-PYRIT&utm_source=rss&utm_medium=rss) - [ ] [unblob exploit](https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-ONEKEY-SEC-UNBLOB&utm_source=rss&utm_medium=rss) - [ ] [searxng exploit](https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-SEARXNG-SEARXNG&utm_source=rss&utm_medium=rss) - Kitploit — Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal! - [ ] [OsintCase](https://kitploit.com/en/tools/github/emrekybs/osintcase) - [ ] [OnTheEdge](https://kitploit.com/en/tools/github/jssngc/ontheedge) - [ ] [OmniTriage](https://kitploit.com/en/tools/github/prox0959/omnitriage) - [ ] [ubuntils](https://kitploit.com/en/tools/github/asmitdesai/ubuntils) - [ ] [disrobe](https://kitploit.com/en/tools/github/1-3-7/disrobe) - [ ] [javajive](https://kitploit.com/en/tools/github/yaklang/javajive) - [ ] [scan](https://kitploit.com/en/tools/github/atomdrift-project/scan) - [ ] [sdproxy](https://kitploit.com/en/tools/github/cbuijs/sdproxy) - [ ] [apk-reverse](https://kitploit.com/en/tools/github/newliver666/apk-reverse) - [ ] [cnspec](https://kitploit.com/en/tools/github/mondoohq/cnspec) - [ ] [anycast-census](https://kitploit.com/en/tools/github/ut-dacs/anycast-census) - [ ] [azure-pentesting-suite](https://kitploit.com/en/tools/github/hac01/azure-pentesting-suite) - [ ] [reburp](https://kitploit.com/en/tools/github/forefy/reburp) - [ ] [Ch4120N-CVE-Pulse](https://kitploit.com/en/tools/github/ch4120n/ch4120n-cve-pulse) - [ ] [NotCVE-2026-0014](https://kitploit.com/en/tools/github/cduram/notcve-2026-0014) - [ ] [ceasta](https://kitploit.com/en/tools/github/ngwg/ceasta) - [ ] [seclab-taskflows-fuzzing](https://kitploit.com/en/tools/github/githubsecuritylab/seclab-taskflows-fuzzing) - [ ] [MemGuard](https://kitploit.com/en/tools/github/prox0959/memguard) - [ ] [rdx](https://kitploit.com/en/tools/github/ch0pin/rdx) - [ ] [FinRED-paper](https://kitploit.com/en/tools/github/selectstar-ai/finred-paper) - [ ] [wavedigger](https://kitploit.com/en/tools/github/christianrowlands/wavedigger) - [ ] [ODPure](https://kitploit.com/en/tools/github/alex66366/odpure) - [ ] [WAInjectBench](https://kitploit.com/en/tools/github/norrrrrrr-lyn/wainjectbench) - [ ] [Android-Security-Masterclass](https://kitploit.com/en/tools/github/owasp/android-security-masterclass) - [ ] [CryptoClipGuard](https://kitploit.com/en/tools/github/prox0959/cryptoclipguard) - [ ] [ShadowMem](https://kitploit.com/en/tools/github/zjuwyh/shadowmem) - [ ] [malware-analysis-fake-hwmonitor](https://kitploit.com/en/tools/github/dmitry-matvienko/malware-analysis-fake-hwmonitor) - Reverse Engineering - [ ] [I reverse-engineered Crestron's AirMedia wireless-presentation protocol so I could screen-share from Ubuntu without a browser](https://www.reddit.com/r/ReverseEngineering/comments/1wpj2io/i_reverseengineered_crestrons_airmedia/) - [ ] [ceasta: open-source disassembler, decompiler and debugger in one program. with a built-in MCP server for driving it from an AI (mac, windows, linux)](https://www.reddit.com/r/ReverseEngineering/comments/1wq9kfs/ceasta_opensource_disassembler_decompiler_and/) - GuidePoint Security - [ ] [Secure AI Adoption: Close the Governance Gap to Accelerate AI in the Cloud](https://www.guidepointsecurity.com/blog/secure-ai-adoption-cloud/) - Horizon3 - [ ] [Trading Maintenance for Momentum: Scaling Security Validation Across 230+ Sites](https://horizon3.ai/customer-story/scaling-security-validation-230-sites/) - Malware-Traffic-Analysis.net - Blog Entries - [ ] [2026-09-24: Files for an ISC Diary (Macfinger ClickFix activity)](https://www.malware-traffic-analysis.net/2026/09/24/index.html) - Intigriti - [ ] [Intigriti Bug Bytes #240 - September 2026 🚀](https://www.intigriti.com/researchers/blog/bug-bytes/intigriti-bug-bytes-240-september-2026) - The Trail of Bits Blog - [ ] [Don't let TEEs break your MPC](https://blog.trailofbits.com/2026/09/25/dont-let-tees-break-your-mpc/) - daniel.haxx.se - [ ] [25 years on Apple computers](https://daniel.haxx.se/blog/2026/09/25/25-years-on-apple-computers/) - Malwarebytes - [ ] [LinkedIn adds new checks for fake profiles and work histories](https://www.malwarebytes.com/blog/news/2026/09/linkedin-adds-new-checks-for-fake-profiles-and-work-histories) - [ ] [Kothamine malware uses Tailscale’s tailcat to evade network detection](https://www.malwarebytes.com/blog/threat-intel/2026/09/kothamine-malware-uses-tailscales-tailcat-to-evade-network-detection) - [ ] [Criminals turn placeholder domain into ClickFix trap](https://www.malwarebytes.com/blog/news/2026/09/criminals-turn-placeholder-domain-into-clickfix-trap) - [ ] [That shipping rebate offer may come with a monthly charge](https://www.malwarebytes.com/blog/threat-intel/2026/09/that-shipping-rebate-offer-may-come-with-a-monthly-charge) - HAHWUL - [ ] [Why I Build Gori](https://www.hahwul.com/posts/2026/why-i-build-gori/) - 奇客Solidot–传递最新科技情报 - [ ] [大象使用药用植物治疗自己](https://www.solidot.org/story?sid=85477) - [ ] [全球平均气温每上升 1C 德国夏天气温上升 2.62C](https://www.solidot.org/story?sid=85476) - [ ] [中国各地推动 AI 视频产业化](https://www.solidot.org/story?sid=85475) - [ ] [F-Droid 2.0 发布](https://www.solidot.org/story?sid=85474) - rtl-sdr.com - [ ] [Demod Analyzer: Analyze Digital Modulation (BPSK, QPSK, 16-QAM) in IQ Files](https://www.rtl-sdr.com/demod-analyzer-analyze-digital-modulation-bpsk-qpsk-16-qam-in-iq-files/) - 白帽Wiki - 一个简单的wiki - [ ] [[2026]AI大型虫群AGENT扩展涌现的智能研究](https://key08.com/index.php/2026/09/25/3327.html) - 锦行科技 - [ ] [中秋・嘉时|秋意渐浓,喜乐相逢](https://mp.weixin.qq.com/s?__biz=MzIxNTQxMjQyNg==&mid=2247495031&idx=1&sn=c97841d37090feeda8b9b00af843a9da) - 360 Netlab Blog - Network Security Research Lab at 360 - [ ] [AI安全专题周报(20260925)](https://blog.netlab.360.com/aian-quan-zhuan-ti-zhou-bao-7/) - 黑鸟 - [ ] [TACACS+预认证远程代码执行漏洞攻击链](https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451188948&idx=1&sn=d8ba41b3eca3c94048cd8adc8062b6c1) - 白帽100安全攻防实验室 - [ ] [白帽100安全攻防实验室祝您中秋快乐](https://mp.weixin.qq.com/s?__biz=MzIxMDYyNTk3Nw==&mid=2247515500&idx=1&sn=cd6f64fd4b6b6d9f10d2c24af4a88df4) - 360漏洞云 - [ ] [月映千山开新境,桂香万里护安澜](https://mp.weixin.qq.com/s?__biz=Mzg5MTc5Mzk2OA==&mid=2247505218&idx=1&sn=17a800a414b9486c73528fe117b8ef8c) - 吾爱破解论坛 - [ ] [把乡愁写进栈帧,出栈时就是团圆](https://mp.weixin.qq.com/s?__biz=MjM5Mjc3MDM2Mw==&mid=2651144717&idx=1&sn=58ce187fcd2bda53afb9f6c6186256d5) - DataCon大数据安全分析竞赛 - [ ] [[中秋悦安]DataCon祝您中秋安康,岁岁长乐!](https://mp.weixin.qq.com/s?__biz=MzU5Njg1NzMyNw==&mid=2247489682&idx=1&sn=ecc887636b820b866cef8e1a6d2748bb) - 中国信息安全 - [ ] [前沿 | AI进核心系统,安全不能只守在软件层](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664267387&idx=1&sn=b98c1fdd879a696838526f3b8d9e0b0e) - [ ] [专家解读 | 张凌寒:《人工智能安全治理框架3.0》推进系统化治理与前瞻性布局](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664267387&idx=2&sn=fe9a1b3431a254f70996aeac0b9229f4) - [ ] [观点 | 个人信息保护分层治理体系迎来制度完善](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664267387&idx=3&sn=cf385937651f47d21c3b45101c7641ec) - [ ] [国际 | 英国拒绝为人工智能设置“紧急终止开关”](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664267387&idx=4&sn=ecbf4b39c8d0e6b8b7baec5a793e7a80) - 安全分析与研究 - [ ] [多Agent涌现风险的形式化理论](https://mp.weixin.qq.com/s?__biz=MzA4ODEyODA3MQ==&mid=2247497202&idx=1&sn=0220a363345bfda782a3606007ca11ff) - 安全圈 - [ ] [【安全圈】MikroTik 路由器曝高危攻击链:无需密码即可取得管理权限](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652079107&idx=1&sn=5712944c4f810ffca0d15071dc160407) - [ ] [【安全圈】恶意软件混入 Terraform 插件,基础设施部署依赖成攻击入口](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652079107&idx=2&sn=ea4ee6438b9b45eeb555d7995bd16de6) - [ ] [【安全圈】开发文档里的示例域名被用于攻击,假人机验证诱导执行命令](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652079107&idx=3&sn=27c8b75a75e32d9b0ea12450dc4c2a94) - 信息安全国家工程研究中心 - [ ] [中秋 | 月无缺 ·人团圆](https://mp.weixin.qq.com/s?__biz=MzU5OTQ0NzY3Ng==&mid=2247505287&idx=1&sn=9529bdd4c66d4440758de62596ea1ce6) - 极客公园 - [ ] [AI 手机只是起点,高通要为智能体铺一条全栈技术路线](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653114134&idx=1&sn=95c76efd97c33120f97b185f4159f028) - [ ] [「济公」游本昌去世;罗永浩再评小米 18 Fold;Meta 推出手持设备 Muse Charm|极客早知道](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653114142&idx=1&sn=296195777313bb24520e13b40a66c6b9) - 奇安信威胁情报中心 - [ ] [每周高级威胁情报解读(2026.09.18~09.24)](https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247520738&idx=1&sn=5ca11989b16e574f59d3ee77ff24c94b) - 看雪学苑 - [ ] [2026中秋致谢 | 月启新程,共守安澜(留言赠礼)](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458621951&idx=1&sn=2368a58281a7df9e2ba6ee31adfed3a1) - [ ] [纯静态分析DumpSDK所需的加密数据,动态定位加密UWorld、GameInstance、Object的未加密地址](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458621951&idx=2&sn=e59a7f58900fb55d57442f76aea9a62e) - 火绒安全 - [ ] [中秋节 | 中秋喜乐 人月团圆](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247538025&idx=1&sn=20f0babe3766735f4f7cdbf1e1d840a1) - [ ] [火绒小问答——「企业版」桌面控制](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247538025&idx=2&sn=f9558f443a7d28071c50385a98df2ccd) - [ ] [【火绒安全周报】HBO Max官方账号被入侵/黑客团伙称攻破FBI系统](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247538025&idx=3&sn=3b5a34baabf382dbf935f0fcafe4b1c3) - [ ] [诚邀渠道合作伙伴共启新征程](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247538025&idx=4&sn=3d118e50f4ae43594b35cb4bfdb99ab7) - 慢雾科技 - [ ] [🌕 明月寄情,共祝中秋安好!](https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&mid=2247506218&idx=1&sn=7e8180e79f42f3c4e062638cdb2c70e5) - 网络空间安全科学学报 - [ ] [2026年网络空间安全学术会议早鸟注册倒计时1天!](https://mp.weixin.qq.com/s?__biz=MzI0NjU2NDMwNQ==&mid=2247509650&idx=1&sn=099ffbf013cc9edb5ca1fdbc09da324c) - 网安国际 - [ ] [桂香伴月,共祝佳节安康](https://mp.weixin.qq.com/s?__biz=MzA4ODYzMjU0NQ==&mid=2652318608&idx=1&sn=71f6a301580991d59c23ca249dbe3223) - T00ls安全 - [ ] [T00ls祝大家中秋快乐,阖家团圆!](https://mp.weixin.qq.com/s?__biz=Mzg3NzYzODU5NQ==&mid=2247485894&idx=1&sn=f9f4a665161f794640d2aa227cf713c1) - 360数字安全 - [ ] [360数字安全集团祝您中秋安康](https://mp.weixin.qq.com/s?__biz=MzA4MTg0MDQ4Nw==&mid=2247586983&idx=1&sn=ab45a12f3150f212e530453c6c2d0dec) - OnionSec - [ ] [暂时不努力](https://mp.weixin.qq.com/s?__biz=MzUyMTUwMzI3Ng==&mid=2247486040&idx=1&sn=8840357257d0d3a6e935ab25ab15604d) - Over Security - [ ] [Kiteworks urges 6-hour server shutdown over potential zero-day attacks](https://www.bleepingcomputer.com/news/security/kiteworks-urges-6-hour-server-shutdown-over-potential-zero-day-attacks/) - [ ] [U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions](https://krebsonsecurity.com/2026/09/u-s-soldier-gets-70-months-in-prison-for-att-verizon-extortions/) - [ ] [ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw](https://www.bleepingcomputer.com/news/security/shinyhunters-hacked-clop-leak-site-using-grav-cms-path-traversal-flaw/) - [ ] [Kiteworks urges customers to stop using platform after warning from federal intelligence agencies](https://therecord.media/kiteworks-urges-customers-to-stop-using-systems-incident) - [ ] [Labcorp to overhaul data security practices, pay $2.3 million fine for cybersecurity failings](https://therecord.media/labcorp-to-overhaul-security-practices-settlement) - [ ] [Elementor WordPress flaw lets attackers create admin accounts](https://www.bleepingcomputer.com/news/security/elementor-wordpress-flaw-lets-attackers-create-admin-accounts/) - [ ] [CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks](https://www.bleepingcomputer.com/news/security/cisa-warns-of-sharepoint-wso2-adobe-commerce-flaws-exploited-in-attacks/) - [ ] [Sintesi riepilogativa delle campagne malevole nella settimana del 19 – 25 settembre](https://cert-agid.gov.it/news/sintesi-riepilogativa-delle-campagne-malevole-nella-settimana-del-19-25-settembre/) - [ ] [Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions](https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-rolls-out-up-to-250-in-free-claude-code-credits-but-only-for-cloud-sessions/) - [ ] [Crypto CEO accuses North Korea of stealing $387 million from Bitget platform](https://therecord.media/crypto-ceo-accuses-north-korea-of-387-million-theft) - [ ] [Cyber security industriale, allarme Clusit: la NIS2 non basta a costruire la resilienza](https://www.cybersecurity360.it/news/cyber-security-industriale-allarme-clusit-la-nis2-non-basta-a-costruire-la-resilienza/) - [ ] [Cyberattack hits Welsh police force, may have affected staff data](https://therecord.media/wales-cyberattack-police-breach) - [ ] [With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance](https://www.bleepingcomputer.com/news/security/with-the-rise-of-ai-agents-soc-2-should-adapt-or-risk-irrelevance/) - [ ] [OpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex](https://www.bleepingcomputer.com/news/artificial-intelligence/openai-is-preparing-a-500-chatgpt-pro-max-plan-with-faster-codex/) - [ ] [The Cyber Express Weekly Roundup: ShinyHunters’ FBI Breach Claim, North Korea’s WaterPlum Campaign, and the EU KIDS Act](https://thecyberexpress.com/weekly-roundup-shiny-hunters-fbi-waterplum/) - [ ] [Frode a Fideuram, persi 36 milioni: con l’AI la voce non basta più a verificare l’identità](https://www.cybersecurity360.it/nuove-minacce/frode-a-fideuram-persi-36-milioni-con-lai-la-voce-non-basta-piu-a-verificare-lidentita/) - [ ] [Alla ricerca della resilienza perduta](https://www.cybersecurity360.it/cultura-cyber/alla-ricerca-della-resilienza-perduta/) - [ ] [Microsoft plans to deprecate Windows Deployment Services](https://www.bleepingcomputer.com/news/microsoft/microsoft-to-deprecate-windows-deployment-services-after-windows-server-2025/) - [ ] [ANY.RUN at RootedCON Valencia 2026: Where Cybersecurity Meets the Next Wave of AI](https://any.run/cybersecurity-blog/rootedcon-valencia-2026/) - [ ] [Doubts grow over claims OpenAI agent hacked Australian Medicare portal](https://therecord.media/openai-australia-breach-cyber) - [ ] [Sam Altman at UN Security Council: 6 AI Security Risks the World Cannot Ignore](https://thecyberexpress.com/sam-altman-warns-of-6-ai-security-risks-at-un/) - [ ] [Rydox marketplace admin pleads guilty, faces 22 years in prison](https://www.bleepingcomputer.com/news/security/rydox-marketplace-admin-pleads-guilty-faces-22-years-in-prison/) - [ ] [VPN e cybersecurity: Surfshark include dispositivi illimitati nella suite One con l’85% di sconto](https://www.cybersecurity360.it/cultura-cyber/surfshark-one-sconto-85-per-cento-dispositivi-illimitati/) - [ ] [Microsoft: Recent Windows updates cause desktop loading issues](https://www.bleepingcomputer.com/news/microsoft/microsoft-recent-windows-updates-cause-desktop-loading-issues/) - [ ] [Burnaby Schools Hit by Cyberattack, Disrupting Networks and Phone Lines](https://thecyberexpress.com/burnaby-school-district-cyberattack/) - [ ] [Duelbits Hit by $7 Million Hack as Crypto Stolen Across Four Blockchains](https://thecyberexpress.com/duelbits-crypto-hack-7m-stolen-casino-offline/) - [ ] [Inside the Telecom Attack Surface: SS7, BGP Hijacking, and the Technical Reality of Nation-State Intrusions](https://cyble.com/blog/ss7-bgp-nation-state-intrusions/) - [ ] [Hackers steal $351.6 million in Bitget crypto exchange hack](https://www.bleepingcomputer.com/news/security/hackers-steal-3516-million-in-bitget-crypto-exchange-hack/) - [ ] [Videosorveglianza: come distinguere tra GDPR e trattamento dati per finalità di polizia](https://www.cybersecurity360.it/legal/privacy-dati-personali/videosorveglianza-come-distinguere-tra-gdpr-e-trattamento-dati-per-finalita-di-polizia/) - [ ] [Ecco come AI e guerra cibernetica ridefiniscono il nuovo rischio cyber](https://www.cybersecurity360.it/outlook/ecco-come-ai-e-guerra-cibernetica-ridefiniscono-il-nuovo-rischio-cyber/) - [ ] [Ban on Discord Lifted After Platform Commits to Work With DICT and CICC](https://thecyberexpress.com/ban-on-discord-lifted-dict-cicc/) - LastKnight.com Feed - [ ] [Sacrificare i bambini per l’AI è un sacrificio che sono disposto a fare](https://mgpf.it/2026/09/25/huang-bambini-matematica-ai.html) - ICT Security Magazine - [ ] [Truffa con WhatsApp e voce clonata a Fideuram: mancano ancora 36 milioni di euro](https://www.ictsecuritymagazine.com/notizie/truffa-fideuram-whatsapp-voce-clonata-ia/) - 悬镜安全 - [ ] [双节快乐|月圆赴良宵,花好人团圆。](https://mp.weixin.qq.com/s?__biz=MzA3NzE2ODk1Mg==&mid=2647800897&idx=1&sn=311ff3421846f501dff89ddf6026e09a) - SANS Internet Storm Center, InfoCON: green - [ ] [A Closer Look at Malware From the Macfinger ClickFix Campaign, (Fri, Sep 25th)](https://isc.sans.edu/diary/rss/33368) - [ ] [ISC Stormcast For Friday, September 25th, 2026 https://isc.sans.edu/podcastdetail/10110, (Fri, Sep 25th)](https://isc.sans.edu/diary/rss/33370) - Schneier on Security - [ ] [Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee](https://www.schneier.com/blog/archives/2026/09/friday-squid-blogging-participatory-squid-dissection-in-october-in-tennessee.html) - [ ] [On Anthropic’s AI Misuse Report](https://www.schneier.com/blog/archives/2026/09/on-anthropics-ai-misuse-report.html) - Coding Horror - [ ] [If we do not stop to help each other, what do we become?](https://blog.codinghorror.com/if-we-do-not-stop-to-help-each-other-what-do-we-become/) - Instapaper: Unread - [ ] [Revolut, online 85mila “file italiani”. Tra questi anche dei passaporti diplomatici](https://www.cybersecitalia.it/revolut-online-85mila-file-italiani-tra-questi-anche-dei-passaporti-diplomatici/69895/) - [ ] [Apple Biome Forensics Artifacts, Locations, and SEGB format](https://belkasoft.com/biome-forensics-artifacts) - [ ] [The Same Ten Passwords, Twenty Years Later](https://stateofsecurity.com/the-same-ten-passwords-twenty-years-later/) - [ ] [Everyone Suddenly Knew Oxygen Forensics Was Guilty](https://brettshavers.com/everyone-suddenly-knew-oxygen-forensics-was-guilty/) - [ ] [Caso Revolut girano documenti di ministeri, quanto è grave](https://www.cybersecurity360.it/news/caso-revolut-girano-documenti-di-ministeri-quanto-e-grave/) - The Hacker News - [ ] [Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware](https://thehackernews.com/2026/09/compromised-github-actions-came-back.html) - [ ] [PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence](https://thehackernews.com/2026/09/pamstealer-macos-malware-adds-live-c2.html) - [ ] [The SOC Doesn't Need to Start Over with Every Alert](https://thehackernews.com/2026/09/the-soc-doesnt-need-to-start-over-with.html) - [ ] [Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise](https://thehackernews.com/2026/09/bitget-says-suspected-north-korean.html) - [ ] [Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild](https://thehackernews.com/2026/09/roundcube-pre-auth-sql-injection-flaw.html) - [ ] [Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data](https://thehackernews.com/2026/09/cloudflare-fixes-flaw-that-let-one.html) - [ ] [WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV](https://thehackernews.com/2026/09/wso2-and-adobe-commerce-flaws-exploited.html) - Deeplinks - [ ] [EFF to Court: Trump's Use of Truth Social's Pay-To-See-Posts-First Scheme Violates Americans' 1st Amendment Equal Access Rights](https://www.eff.org/deeplinks/2026/09/ff-court-trumps-use-truth-socials-pay-see-posts-first-scheme-violates-americans) - TorrentFreak - [ ] [Nintendo Wins $4.5 Million Judgment Against r/SwitchPirates Mod ‘Archbox’](https://torrentfreak.com/nintendo-wins-4-5-million-judgment-against-r-switchpirates-mod-archbox/) - Security Affairs - [ ] [U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog](https://securityaffairs.com/199777/hacking/u-s-cisa-adds-microsoft-sharepoint-and-mikrotik-routeros-flaws-to-its-known-exploited-vulnerabilities-catalog.html) - [ ] [Cryptocurrency exchange Bitget Says North Korea-Linked Hackers Stole $351.6 Million](https://securityaffairs.com/199754/cyber-crime/cryptocurrency-exchange-bitget-says-north-korea-linked-hackers-stole-351-6-million.html) - [ ] [ClickFix Campaign Abuses Trusted Websites to Deploy Psychedelic Stealer](https://securityaffairs.com/199731/malware/clickfix-campaign-abuses-trusted-websites-to-deploy-psychedelic-stealer.html) - [ ] [AI-Powered CARBONATO Botnet Steals Credentials to Fund Its Own LLM Gateway](https://securityaffairs.com/199716/malware/ai-powered-carbonato-botnet-steals-credentials-to-fund-its-own-llm-gateway.html) - [ ] [U.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog](https://securityaffairs.com/199704/hacking/u-s-cisa-adds-adobe-and-wso2-flaws-to-its-known-exploited-vulnerabilities-catalog.html) - 360威胁情报中心 - [ ] [Sorry勒索软件新变种来袭](https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247508942&idx=1&sn=f827e689d16fb53bf3f2adfe8eea9642) - Krebs on Security - [ ] [U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions](https://krebsonsecurity.com/2026/09/u-s-soldier-gets-70-months-in-prison-for-att-verizon-extortions/) - Daniel Miessler - [ ] [How Jev Picks the Model and Effort for Every Prompt](https://danielmiessler.com/blog/glance-routes-model-and-effort?utm_source=rss&utm_medium=feed&utm_campaign=website) - www.theregister.com - Articles - [ ] [Fake Google Security Team ad says 'no script reading' in voice phishing - then prints the script](https://www.theregister.com/security/2026/09/25/fake-google-security-team-ad-says-no-script-reading-in-voice-phishing-then-prints-the-script/5299264) - [ ] [ShinyHunters tells The Reg: We hacked the FBI to 'protect our business'](https://www.theregister.com/cyber-crime/2026/09/25/shinyhunters-tells-the-reg-we-hacked-the-fbi-to-protect-our-business/5299250) - [ ] [Crooks use fake desktop apps to fool HR staff into giving them remote access](https://www.theregister.com/security/2026/09/25/crooks-use-fake-desktop-apps-to-fool-hr-staff-into-giving-them-remote-access/5299226) - [ ] [Bitget blames North Korea for $387.5M crypto wallet raid](https://www.theregister.com/cyber-crime/2026/09/25/bitget-blames-north-korea-for-3875m-crypto-wallet-raid/5299218) - [ ] [Which copy of that file is the real one? Dinner, off the record, in Midtown](https://www.theregister.com/storage/2026/09/25/sponsored/5299080) - KitPloit - PenTest Tools! - [ ] [OsintCase](https://kitploit.com/en/tools/github/emrekybs/osintcase) - [ ] [OnTheEdge](https://kitploit.com/en/tools/github/jssngc/ontheedge) - [ ] [OmniTriage](https://kitploit.com/en/tools/github/prox0959/omnitriage) - [ ] [ubuntils](https://kitploit.com/en/tools/github/asmitdesai/ubuntils) - [ ] [disrobe](https://kitploit.com/en/tools/github/1-3-7/disrobe) - [ ] [javajive](https://kitploit.com/en/tools/github/yaklang/javajive) - [ ] [scan](https://kitploit.com/en/tools/github/atomdrift-project/scan) - [ ] [sdproxy](https://kitploit.com/en/tools/github/cbuijs/sdproxy) - [ ] [apk-reverse](https://kitploit.com/en/tools/github/newliver666/apk-reverse) - [ ] [cnspec](https://kitploit.com/en/tools/github/mondoohq/cnspec) - [ ] [anycast-census](https://kitploit.com/en/tools/github/ut-dacs/anycast-census) - [ ] [azure-pentesting-suite](https://kitploit.com/en/tools/github/hac01/azure-pentesting-suite) - [ ] [reburp](https://kitploit.com/en/tools/github/forefy/reburp) - [ ] [Ch4120N-CVE-Pulse](https://kitploit.com/en/tools/github/ch4120n/ch4120n-cve-pulse) - [ ] [NotCVE-2026-0014](https://kitploit.com/en/tools/github/cduram/notcve-2026-0014) - [ ] [ceasta](https://kitploit.com/en/tools/github/ngwg/ceasta) - [ ] [seclab-taskflows-fuzzing](https://kitploit.com/en/tools/github/githubsecuritylab/seclab-taskflows-fuzzing) - [ ] [MemGuard](https://kitploit.com/en/tools/github/prox0959/memguard) - [ ] [rdx](https://kitploit.com/en/tools/github/ch0pin/rdx) - [ ] [FinRED-paper](https://kitploit.com/en/tools/github/selectstar-ai/finred-paper) - [ ] [wavedigger](https://kitploit.com/en/tools/github/christianrowlands/wavedigger) - [ ] [ODPure](https://kitploit.com/en/tools/github/alex66366/odpure) - [ ] [WAInjectBench](https://kitploit.com/en/tools/github/norrrrrrr-lyn/wainjectbench) - [ ] [Android-Security-Masterclass](https://kitploit.com/en/tools/github/owasp/android-security-masterclass) - [ ] [CryptoClipGuard](https://kitploit.com/en/tools/github/prox0959/cryptoclipguard) - [ ] [ShadowMem](https://kitploit.com/en/tools/github/zjuwyh/shadowmem) - [ ] [malware-analysis-fake-hwmonitor](https://kitploit.com/en/tools/github/dmitry-matvienko/malware-analysis-fake-hwmonitor)
每日安全资讯(2026-09-26)