# 每日安全资讯(2026-08-19) - SecWiki News - [ ] [SecWiki News 2026-08-18 Review](http://www.sec-wiki.com/?2026-08-18) - Doonsec's feed - [ ] [Agent大赛还是烧钱大赛?东湖论枪改的真好](https://mp.weixin.qq.com/s/n2JMToNlv5SlW7xBytY0rA) - [ ] [一眼假的东西](https://mp.weixin.qq.com/s/uY7rOteH_9NJCNHPsEysSA) - [ ] [两年磨一剑!密探2.0从底层到交互全面进化,究竟强在哪?](https://mp.weixin.qq.com/s/99gxVO-IScBI9nbQt2D6sQ) - [ ] [【0DAY漏洞】xa0全球5G手机芯片厂商之一u200c的紫光展锐SOC存在RCE漏洞,影响数十家手机厂商,还未发布补丁](https://mp.weixin.qq.com/s/3BMvBXIW9MNgnyNTcKPZKg) - [ ] [为什么不用linux系统](https://mp.weixin.qq.com/s/sFNfasZheGqoIWzTu7gk2Q) - [ ] [1v1论文指导!985/211专业对口导师手把手指导至录用!SCI/SSCI/EI/中文核心/毕业论文](https://mp.weixin.qq.com/s/1Q_k1h2z4AdgzOKGUXR9Nw) - [ ] [#渗透测试实践笔记(开发者版)](https://mp.weixin.qq.com/s/yBx555I8fIPJkgpzxMuMWw) - [ ] [Builder时代:当实现不再是瓶颈,什么才是开发者的真本事?写代码不再是核心竞争力——软件开发者的下一次进化](https://mp.weixin.qq.com/s/2jqegB_5CbiXu90VsoyCgw) - [ ] [别人收费我们免费!1000本电子书+实战指南,速来薅羊毛!从入门到精通|红客精选书单大公开,千本好书助你成大神](https://mp.weixin.qq.com/s/a7eSL7WUImwnJJ3R5yWl3A) - [ ] [「\"Nextrap\"」今日新增蜜罐市场蜜罐模版-818](https://mp.weixin.qq.com/s/JxBE7zxwooHtJMN6GdaekQ) - [ ] [【重要通知】2026年上海市工程系列数字技术专业(大数据、区块链、数据安全方向)高级职称评审网申启动!](https://mp.weixin.qq.com/s/QU2Z10p9DQQ77xGbEIQShA) - [ ] [从\"人\"的漏洞到\"人\"的防线:安在携手HumanRisk重塑企业安全意识教育](https://mp.weixin.qq.com/s/pSUVzv0kyLBzO7HHUFMKwA) - [ ] [法国税务系统遭网络攻击 67.8万纳税主体敏感数据外泄](https://mp.weixin.qq.com/s/lm28MfAQsrqdDmGuR-Or-w) - [ ] [关于武汉市算力服务券(第一批)拟结算资金情况的公示](https://mp.weixin.qq.com/s/x9VMI5jCnHtmjaIE50Jbfw) - [ ] [理事动态丨达梦数据×湖北银行丨联合实验室:拆旧换新,大型模块化微服务重构对公信贷系统](https://mp.weixin.qq.com/s/k7b9gURcqNp4ujfkOHWMmA) - [ ] [SRC漏洞挖掘新手入门指南:怎么挖、去哪挖?一篇文章带你零基础入门到精通!](https://mp.weixin.qq.com/s/zX6Ie2KIzY3O4BTGjoKK5Q) - [ ] [关于举办全市第六届网络安全技能大赛的通知](https://mp.weixin.qq.com/s/kPmJep9PM5LpVfQDgEyFrw) - [ ] [关注 | 公安部网安局公布14起涉企网络谣言典型案例](https://mp.weixin.qq.com/s/Ac0_hbYDFKK_7eGw00m3hg) - [ ] [前沿 | 词元出海的竞争优势与挑战对策](https://mp.weixin.qq.com/s/RXCDhHSrQhvcG0kQwOSm2w) - [ ] [国际 | 全球社交媒体禁令的模式与张力](https://mp.weixin.qq.com/s/vb_ctSNbCjRIAjNhkK4asg) - [ ] [评论 | 让人工智能这匹千里马跑得又快又稳](https://mp.weixin.qq.com/s/MxleJh3ouVvF3JSsR4DsPA) - [ ] [北京邮电大学网安学院在大模型与区块链领域研究成果被网络信息安全顶会 ACM CCS 2026录用](https://mp.weixin.qq.com/s/81MCF4E58UpnYqVdFAECVA) - [ ] [发个授权?敲个txt也行](https://mp.weixin.qq.com/s/GWg9RJnU4SZtGVFITSHDSg) - [ ] [机器人“实战派”即将在2026世界机器人大会登场!](https://mp.weixin.qq.com/s/O3XeNxUdJsRaLPzKcEbFAg) - [ ] [【课程】实验室资质认定内审员培训招生启动!让你从“评审蒙圈”到“内审能手”](https://mp.weixin.qq.com/s/7GWOpT8gjut5ZRP657fv0w) - [ ] [邀请函 | 众智维科技与您相约2026南京人工智能产业技术合作交流暨企业科协赋能发展大会](https://mp.weixin.qq.com/s/RbGY2ZIMJe3rmdEXJynkQg) - [ ] [启明星辰周涛:AI重塑漏洞攻防范式](https://mp.weixin.qq.com/s/zTsMaHKh4UynXXbbK1g8kg) - [ ] [歉意为引,数据为食:Sorry勒索病毒分析与当前威胁态势](https://mp.weixin.qq.com/s/GpiopX0jHObgDVYzLF6aww) - [ ] [从世界杯骗局到游戏启动器,7月网络攻击花样不断](https://mp.weixin.qq.com/s/Yrr4fWjTwq5-CTdaaxH7YA) - [ ] [告别“带病上线”,代码审计智能体必备的核心能力](https://mp.weixin.qq.com/s/GXaokP2iSPjBBaSxKJDLRA) - [ ] [安全简讯(2026.08.18)](https://mp.weixin.qq.com/s/5MVinphTWZoJxNRE0ZbVFw) - [ ] [1000元和鱼同时掉进水里,你先救哪个?](https://mp.weixin.qq.com/s/m4u2hpnHOrk8UvDP-bEOqg) - [ ] [云天 · 安全通告(2026年8月18日)](https://mp.weixin.qq.com/s/7RTgnoz5MLTWKZMueJU_hQ) - [ ] [国际顶尖安全专家打造的实战指南](https://mp.weixin.qq.com/s/sH9p6SNUZbgFJLstCYjDIg) - [ ] [中央情报局:发现线人是骗子时为时已晚 |](https://mp.weixin.qq.com/s/rIt6FJftgcZmMhSMy5GxmQ) - [ ] [关于公布第十九届全国大学生信息安全竞赛(作品赛)暨第三届“长城杯”网数智安全大赛(作品赛)决赛奖项设置的通知](https://mp.weixin.qq.com/s/J1QSLzvKI8olOL504R0K9w) - [ ] [第十九届全国大学生信息安全竞赛(作品赛)暨第三届“长城杯” 网数智安全大赛(作品赛)决赛奖项设置的通知](https://mp.weixin.qq.com/s/XGEC6eYFyKf2ZjoyVYZFdw) - [ ] [Anthropic研究揭示Claude的“多语种性格漂移”](https://mp.weixin.qq.com/s/pc5Rj87LUmV5ShWsfyemMg) - [ ] [忍受孤独比忍受蠢货容易多了 [音乐]pers #美女 #日常](https://mp.weixin.qq.com/s/Ki2MbibmDqKuExw53Dk0FQ) - [ ] [倒计时2天xa0|xa0第三届“长城杯”网数智安全大赛(作品赛)决赛即将开赛](https://mp.weixin.qq.com/s/fyp9Za64FyfS4DLSUZhvCg) - [ ] [神州希望协助三亚市住房和城乡建设局开展网络安全意识培训](https://mp.weixin.qq.com/s/VB_6_qmFYqn57Jn4hmuQ9Q) - [ ] [最近在读一个Python写的开源项目的源码,当我看到:](https://mp.weixin.qq.com/s/LtXaO9ybbT7IIMa40Xva5Q) - [ ] [七月,我用AI挖了22万赏金,我想给你一点建议](https://mp.weixin.qq.com/s/yjuL3IzpPSsZ8m9AvT3unw) - [ ] [会议 | 关于举办第四届京津冀科技期刊创新发展论坛的通知(第二轮)](https://mp.weixin.qq.com/s/ui-1Zv00Czcx50N0sdvM5g) - [ ] [动态|《民用航空重要网络和信息系统商用密码应用要求(征求意见稿)》等三项民航行业标准公开征求意见](https://mp.weixin.qq.com/s/AprV5kmL4FjZwH-gb6vvsQ) - [ ] [洞察|Sorry勒索病毒逆向分析与防护指南](https://mp.weixin.qq.com/s/PoONNkh72pR_L7ea72ZTUg) - [ ] [科技|AI宣布森多夫猜想告破!陶哲轩发现它隐藏的更强结果](https://mp.weixin.qq.com/s/4xiUlRBAEPDW1l2qi7gwIw) - [ ] [腾讯云AIxa0Agent安全网关护航银河证券启睿Skill上架WorkBuddy ——从“能查询”走向“放心调用”](https://mp.weixin.qq.com/s/exzBrAr2oSrGdXHfF2VINg) - [ ] [AI 渗透测试工程化第四篇——MCP 安全接入](https://mp.weixin.qq.com/s/Q2mLrKpiYa09MPUGpsyREg) - [ ] [中国信通院刘腾飞等:强化人工智能创新策源能力,加快培育未来产业](https://mp.weixin.qq.com/s/N3WYaBmyf4M-kpgY3AynIA) - [ ] [宝可梦确认数据泄露:客户数据遭攻击者窃取,订单被迫取消](https://mp.weixin.qq.com/s/eF1wGd2QA31Z1jz2Hh0sTQ) - [ ] [SANDCLOCK后门入侵LiteLLM供应链,2500+组织凭证泄露](https://mp.weixin.qq.com/s/92dyiBFlu1vZVGuXQKccGQ) - [ ] [倒计时2天!第三届“长城杯”网数智安全大赛(作品赛)决赛即将开赛](https://mp.weixin.qq.com/s/-BOW8GVAQz7fVADC7_gJDQ) - [ ] [中标|长江存储网络安全项目](https://mp.weixin.qq.com/s/B3VekDG6_aPD1G9AfmyTbA) - [ ] [我,AI员工,操作多个安全产品](https://mp.weixin.qq.com/s/e5xtIlvuBPLLrRfio88nFg) - [ ] [三维架构、四种盈利、五重赋能:纳米Work企业版渠道生态正式起航](https://mp.weixin.qq.com/s/o57EG4WepDYYg4HHyE4Pkw) - [ ] [广东雷龙鱼泛滥了](https://mp.weixin.qq.com/s/B0wWNcHHoUgITTaNHbvuHw) - [ ] [十年赛制全景 + 学习路线 2.0:一张表看懂工控 CTF 怎么变](https://mp.weixin.qq.com/s/GtffxB2Qna6u9HquFKHkYQ) - [ ] [以太网网线的组成部分 #网络技术](https://mp.weixin.qq.com/s/0TsZEGrw1woH8aad3Mu-NA) - [ ] [招新进行时|青志协网安分会:橙马甲buff加持,告别社恐模式!](https://mp.weixin.qq.com/s/UmwsLczM4Ejyc_YjAHk-hg) - [ ] [塔玛暇尔观月](https://mp.weixin.qq.com/s/Er6gsRF1MOYErt_vWs1KEg) - [ ] [SRC保姆级教程:一篇学会信息收集](https://mp.weixin.qq.com/s/ToQALoBT1JoxyKgEGJrQHw) - [ ] [关于顺丰SRC平台升级维护及暂停漏洞测试的公告](https://mp.weixin.qq.com/s/aKwnS6l5Hcw-_IG--B_hpg) - [ ] [用 AVL Code 手搓一个基于 FPGA 的 TF 卡仿真器](https://mp.weixin.qq.com/s/vF7CsJYakIi-zqSWo0c5uA) - [ ] [震惊安全圈!这款自动化 reconnaissance 神器让渗透测试效率提升 1000%](https://mp.weixin.qq.com/s/sceYwiKoT2t1XNC6S5N0Mg) - [ ] [三未信安十八岁生日快乐!——过往皆为序章,来日方值期许](https://mp.weixin.qq.com/s/NoYPjQev4GTLowYedIznVQ) - [ ] [加密钱包提供商SafePal泄露近4万名用户订单信息](https://mp.weixin.qq.com/s/VSbU64KQ8FqZUkSZQB3auA) - [ ] [海量+WiFi告警里,真正的威胁藏在哪?揭秘这家能源巨头的UEBA实战](https://mp.weixin.qq.com/s/0yOhPQESeRGR4QZSM-S8iQ) - [ ] [安恒堡垒机上线腾讯云,一键部署开启运维安全新范式](https://mp.weixin.qq.com/s/upLtMmyczheqXmfV3ikEAg) - [ ] [2026年8月中央国家机关复印机、打印机项目集采中标信息公布](https://mp.weixin.qq.com/s/5rcB_17vjKJDFVnJ9Q03ZQ) - [ ] [LiteLLM 供应链攻击——科技、银行和医疗受影响最大](https://mp.weixin.qq.com/s/sEE53wyyvR2jz5rfH6nWYA) - Microsoft Security Blog - [ ] [Hunting MacSync Stealer infrastructure through behavioral pivots](https://www.microsoft.com/en-us/security/blog/2026/08/18/hunting-macsync-stealer-infrastructure-through-behavioral-pivots/) - Sploitus.com Exploits RSS Feed - [ ] [kill-chain-vulnerability-scanner exploit](https://sploitus.com/exploit?id=495259AA-45B4-55E9-9BBC-F811E79CB6A1&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Missing Authorization in Portainer](https://sploitus.com/exploit?id=109DCEB3-DE61-5471-8DDB-A813D9ABF3FE&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-64638](https://sploitus.com/exploit?id=2547ECAC-6483-5CE5-BFE9-3B9DFE644A3A&utm_source=rss&utm_medium=rss) - [ ] [GL.iNet-4.x-Init-PoC exploit](https://sploitus.com/exploit?id=87189602-CA96-5B0D-9F8F-0FF1CD011128&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Code Injection in Anyscale Ray](https://sploitus.com/exploit?id=2F39AA0C-8F89-5B19-A6D9-692CDE14079C&utm_source=rss&utm_medium=rss) - [ ] [wpm-schwachstellenanalyse-log4shell exploit](https://sploitus.com/exploit?id=5565C172-1618-5184-A23B-9AFFD46348C6&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Out-of-bounds Read in Openssl](https://sploitus.com/exploit?id=3F3BF7FA-610E-5888-ADE9-A55EC32A78DB&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-19500](https://sploitus.com/exploit?id=44FD4638-A1EF-5C41-8816-7BB70331CEF2&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-15748](https://sploitus.com/exploit?id=37A2BF9F-33E3-593D-89A3-A9A51C4AC0C3&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Server-Side Request Forgery in Vercel Next.Js](https://sploitus.com/exploit?id=EB1B50B1-4452-58EB-A829-C31DFECD8E19&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Use After Free in Linux Linux_Kernel](https://sploitus.com/exploit?id=15EAA031-95E5-5122-9C6C-38988B8C8280&utm_source=rss&utm_medium=rss) - [ ] [qwen3.8-27b-cyber-exploit-agent](https://sploitus.com/exploit?id=7B22971A-BFDC-5C14-AEB1-5123B89358A8&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-14669](https://sploitus.com/exploit?id=0EC9A618-6649-5865-974D-61A43F5636D2&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Incomplete List of Disallowed Inputs in Fastgpt](https://sploitus.com/exploit?id=92E3CF1F-D720-56D6-AE86-134A824B8280&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Open Redirect in Pylonsproject Webob](https://sploitus.com/exploit?id=5D0900F7-ACD8-56C9-90AB-BAE4E546A770&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Incorrect Resource Transfer Between Spheres in Python Urllib3](https://sploitus.com/exploit?id=60AAB9D7-396D-5EB4-9363-468ED143048E&utm_source=rss&utm_medium=rss) - [ ] [Exploit for SQL Injection in Piccolo-Orm Piccolo](https://sploitus.com/exploit?id=8E742E8C-4658-50F1-A577-81165E16660B&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Cross-site Scripting in Palletsprojects Jinja](https://sploitus.com/exploit?id=724C01AA-6B2F-5887-BD6F-9CFB6B327647&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Improper Input Validation in Gitpython_Project Gitpython](https://sploitus.com/exploit?id=096DB966-6C8E-5D41-BB49-3C0055212113&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Cross-site Scripting in Mozilla Bleach](https://sploitus.com/exploit?id=604F257C-0799-50F0-9646-DD49D26731A9&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Path Traversal in Aiohttp](https://sploitus.com/exploit?id=29F09060-C922-5F4F-A847-EE65F2D17662&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-19478](https://sploitus.com/exploit?id=184A4957-531E-5235-B1B3-A85EA65453F1&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-69414](https://sploitus.com/exploit?id=39BCE353-DC4E-5A1C-BCC7-74370EABC117&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2024-40275](https://sploitus.com/exploit?id=7FA1CEA0-5F33-5E7A-957E-3796BEE81843&utm_source=rss&utm_medium=rss) - [ ] [CVE-2026-15748 exploit](https://sploitus.com/exploit?id=CVE-2026-15748&utm_source=rss&utm_medium=rss) - [ ] [poctest exploit](https://sploitus.com/exploit?id=D1AB088E-A628-5C61-A6CC-D4A922DA4BC6&utm_source=rss&utm_medium=rss) - [ ] [Perfex-CRM-3.4.x-Unauthenticated-RCE-via-Migration-SQLi-Arbitrary-File-Upload exploit](https://sploitus.com/exploit?id=6405A12D-F1A0-51E3-8481-907ED420DD4D&utm_source=rss&utm_medium=rss) - [ ] [cve-exploit-mapper](https://sploitus.com/exploit?id=B98CCB97-1C54-58ED-B639-966A8996C337&utm_source=rss&utm_medium=rss) - Private Feed for M09Ic - [ ] [anthropics released v2.1.235 at anthropics/claude-code](https://github.com/anthropics/claude-code/releases/tag/v2.1.235) - [ ] [bolucat released 202608182046 at bolucat/Archive](https://github.com/bolucat/Archive/releases/tag/202608182046) - [ ] [Teach2Breach starred S3cur3Th1sSh1t/Kassandra](https://github.com/S3cur3Th1sSh1t/Kassandra) - [ ] [OpenAEV-Platform released 3.260818.1 at OpenAEV-Platform/openaev](https://github.com/OpenAEV-Platform/openaev/releases/tag/3.260818.1) - [ ] [chainreactors released v0.0.0-nightly.20260818 at chainreactors/aiscan](https://github.com/chainreactors/aiscan/releases/tag/v0.0.0-nightly.20260818) - [ ] [spf13 starred kenn-io/agentsview](https://github.com/kenn-io/agentsview) - [ ] [esrrhs contributed to esrrhs/fakelua](https://github.com/esrrhs/fakelua/pull/365) - [ ] [kpcyrd contributed to kpcyrd/rebuilderd](https://github.com/kpcyrd/rebuilderd/pull/258) - [ ] [mgeeky starred plastic-labs/honcho](https://github.com/plastic-labs/honcho) - [ ] [esrrhs contributed to esrrhs/fakecc](https://github.com/esrrhs/fakecc/pull/20) - [ ] [Safe3 forked Safe3/Cairn from oritera/Cairn](https://github.com/Safe3/Cairn) - [ ] [mgeeky starred trailofbits/claude-code-config](https://github.com/trailofbits/claude-code-config) - [ ] [xgo-dev released v1.0.0-pre.2 at xgo-dev/llgo](https://github.com/xgo-dev/llgo/releases/tag/v1.0.0-pre.2) - [ ] [Mr-xn starred Tiger3807861189/J-Space-Cognition-Suite-V3.6](https://github.com/Tiger3807861189/J-Space-Cognition-Suite-V3.6) - [ ] [liamg contributed to infracost/actions](https://github.com/infracost/actions/pull/287) - [ ] [kpcyrd contributed to repology/repology-rules](https://github.com/repology/repology-rules/pull/1220) - [ ] [liamg contributed to infracost/vcs](https://github.com/infracost/vcs/pull/24) - [ ] [pydantic released v2.31.1 at pydantic/pydantic-ai](https://github.com/pydantic/pydantic-ai/releases/tag/v2.31.1) - Recent Commits to cve:main - [ ] [Update Tue Aug 18 12:17:31 UTC 2026](https://github.com/trickest/cve/commit/b61f8201e65a42fa19b9becd7f8343fe28849e59) - 安全客-有思想的安全新媒体 - [ ] [科技云报到:机器流量首次超过人类,互联网进入“三体流量时代”?](https://www.anquanke.com/post/id/315987) - [ ] [三维架构、四种盈利、五重赋能:纳米Work企业版渠道生态正式起航](https://www.anquanke.com/post/id/315983) - ZeddYu’s Blog - [ ] [Web Cache Deception in 2026: The Path-Confusion Variants That Still Work](https://blog.zeddyu.info/2026/08/18/Web-Cache-Deception-Path-Confusion-2026/) - Cerbero Blog - [ ] [Cerbero Suite 9 Release](https://blog.cerbero.io/cerbero-suite-9-release/) - VMRay - [ ] [Why Behavior-Based Detection Is the New Standard](https://www.vmray.com/why-behavior-based-detection-is-necessary/) - Reverse Engineering - [ ] [Ghidra 12.1.3 has been released!](https://www.reddit.com/r/ReverseEngineering/comments/1vru13i/ghidra_1213_has_been_released/) - [ ] [Kimi Desktop Ships With a Group Chat Updater That Can Install Unverified Code](https://www.reddit.com/r/ReverseEngineering/comments/1vrwhx6/kimi_desktop_ships_with_a_group_chat_updater_that/) - [ ] [Image viewer for 2003 Neighbours From Hell's .tga image format](https://www.reddit.com/r/ReverseEngineering/comments/1vrmqvn/image_viewer_for_2003_neighbours_from_hells_tga/) - Malwarebytes - [ ] [Apple fixes another image-processing flaw that could allow code execution](https://www.malwarebytes.com/blog/bugs/2026/08/apple-fixes-another-image-processing-flaw-that-could-allow-code-execution) - [ ] [Be careful what you put in “anyone with the link” Google Docs](https://www.malwarebytes.com/blog/news/2026/08/be-careful-what-you-put-in-anyone-with-the-link-google-docs) - [ ] [Heights Finance data breach: What customers need to know](https://www.malwarebytes.com/blog/data-breaches/2026/08/heights-finance-data-breach-what-customers-need-to-know) - Exploit-DB.com RSS Feed - [ ] [[remote] PCMan 2.0.7 - Buffer Overflow](https://www.exploit-db.com/exploits/52657) - [ ] [[dos] NanaZip 6.5 - DoS](https://www.exploit-db.com/exploits/52656) - [ ] [[webapps] flyto-core 2.26.7 - Arbitrary File Write](https://www.exploit-db.com/exploits/52655) - [ ] [[webapps] Nodemailer 9.0.0 - File Read/ SSRF](https://www.exploit-db.com/exploits/52654) - [ ] [[webapps] Linuxfabrik monitoring_plugins_6.0.0 - SSRF](https://www.exploit-db.com/exploits/52653) - GuidePoint Security - [ ] [Beware the Ransomware Rescuer: Ransom Busters](https://www.guidepointsecurity.com/blog/beware-ransom-busters/) - [ ] [Bird Watching: Characterizing the Infrastructure and Behavior of Falcon-branded Extortion Operations](https://www.guidepointsecurity.com/blog/characterizing-infrastructure-behavior-falcon-branded-extortion/) - HackerNews - [ ] [GitLab 关键 GraphQL 漏洞可能允许未认证攻击者删除公共项目](http://0.0.0.0:8080/post/64566) - [ ] [黑客声称窃取大公司 360 万条 Azure 账户记录](http://0.0.0.0:8080/post/64565) - [ ] [Pokémon Center 数据泄露暴露客户信息,部分订单被取消](http://0.0.0.0:8080/post/64564) - [ ] [麦当劳员工数据出现在泄露中,卖家声称窃取 170 万条记录](http://0.0.0.0:8080/post/64563) - [ ] [LiteLLM 供应链攻击——科技、银行和医疗行业受影响最严重](http://0.0.0.0:8080/post/64562) - [ ] [SafePal 称 39,798 名客户受数据泄露影响](http://0.0.0.0:8080/post/64561) - rtl-sdr.com - [ ] [AntSDR T510 Pre-launch: A 1 MHz to 6 GHz SDR with 2 GHz Bandwidth and a Built-In NVIDIA Jetson](https://www.rtl-sdr.com/antsdr-t510-pre-launch-a-1-mhz-to-6-ghz-sdr-with-2-ghz-bandwidth-and-a-built-in-nvidia-jetson/) - [ ] [KrakenSDR Tested as a GNSS Jammer and Spoofer Localizer](https://www.rtl-sdr.com/krakensdr-tested-as-a-gnss-jammer-and-spoofer-localizer/) - [ ] [Carshepherd: An Android RTL-SDR App For the Early Awareness of Nearby Emergency-Service Vehicles](https://www.rtl-sdr.com/carshepherd-an-android-rtl-sdr-app-for-the-early-awareness-of-nearby-emergency-service-vehicles/) - 360 Netlab Blog - Network Security Research Lab at 360 - [ ] [AI安全专题周报(20260814)](https://blog.netlab.360.com/aian-quan-zhuan-ti-zhou-bao-2/) - [ ] [金融行业网络安全监测月报(202607)](https://blog.netlab.360.com/jin-rong-xing-ye-wang-luo-an-quan-jian-ce-yue-bao-202607/) - [ ] [金融行业网络安全监测月报(202606)](https://blog.netlab.360.com/jin-rong-xing-ye-wang-luo-an-quan-jian-ce-yue-bao-202606/) - [ ] [金融行业网络安全监测月报(202605)](https://blog.netlab.360.com/jin-rong-xing-ye-wang-luo-an-quan-jian-ce-yue-bao-202605/) - [ ] [金融行业网络安全监测月报(202604)](https://blog.netlab.360.com/jin-rong-xing-ye-wang-luo-an-quan-jian-ce-yue-bao-202604/) - [ ] [金融行业网络安全监测月报(202603)](https://blog.netlab.360.com/jin-rong-xing-ye-wang-luo-an-quan-jian-ce-yue-bao-202603/) - [ ] [金融行业网络安全监测月报(202602)](https://blog.netlab.360.com/jin-rong-xing-ye-wang-luo-an-quan-jian-ce-yue-bao-202602/) - [ ] [金融行业网络安全监测月报(202601)](https://blog.netlab.360.com/jin-rong-xing-ye-wang-luo-an-quan-jian-ce-yue-bao-202601/) - [ ] [金融行业网络安全监测月报(202512)](https://blog.netlab.360.com/jin-rong-xing-ye-wang-luo-an-quan-jian-ce-yue-bao-202512/) - [ ] [金融行业网络安全监测月报(202511)](https://blog.netlab.360.com/jin-rong-xing-ye-wang-luo-an-quan-jian-ce-yue-bao-202511/) - 奇客Solidot–传递最新科技情报 - [ ] [Firefox 154 释出](https://www.solidot.org/story?sid=85130) - [ ] [Google 拍下破产航空公司 Spirit 的数据](https://www.solidot.org/story?sid=85129) - [ ] [苹果开发配备摄像头的耳机 AirPods](https://www.solidot.org/story?sid=85128) - [ ] [美国青少年吸烟率降至历史新低的 1.4%](https://www.solidot.org/story?sid=85127) - [ ] [极端高温对老年人口的危害比预期的更大](https://www.solidot.org/story?sid=85126) - [ ] [40 岁女性患有四种自身免疫性疾病](https://www.solidot.org/story?sid=85125) - [ ] [日常饮用含糖饮料与胃癌风险上升相关](https://www.solidot.org/story?sid=85124) - [ ] [Meta 面临修改社媒算法和设计的诉讼](https://www.solidot.org/story?sid=85123) - [ ] [Anthropic CEO 称对 AI 的抵触根源在于信任危机](https://www.solidot.org/story?sid=85122) - [ ] [Web 开发者不再重视 Web 标准](https://www.solidot.org/story?sid=85121) - [ ] [通过 Zoom 解雇 900 名雇员的 CEO 被解雇](https://www.solidot.org/story?sid=85120) - 黑海洋Wiki | AI机器人硬件开发 | 网络安全攻防实战 | 区块链技术文档教程 - 免费资源平台 - [ ] [OpenAI暂缓前沿模型训练 升级安全监控体系](https://blog.upx8.com/OpenAI%E6%9A%82%E7%BC%93%E5%89%8D%E6%B2%BF%E6%A8%A1%E5%9E%8B%E8%AE%AD%E7%BB%83-%E5%8D%87%E7%BA%A7%E5%AE%89%E5%85%A8%E7%9B%91%E6%8E%A7%E4%BD%93%E7%B3%BB) - [ ] [Telegram 宣布已申请 .gram 顶级域名](https://blog.upx8.com/Telegram-%E5%AE%A3%E5%B8%83%E5%B7%B2%E7%94%B3%E8%AF%B7-gram-%E9%A1%B6%E7%BA%A7%E5%9F%9F%E5%90%8D) - [ ] [反垄断攻势开始冲击苹果公司的服务业务](https://blog.upx8.com/%E5%8F%8D%E5%9E%84%E6%96%AD%E6%94%BB%E5%8A%BF%E5%BC%80%E5%A7%8B%E5%86%B2%E5%87%BB%E8%8B%B9%E6%9E%9C%E5%85%AC%E5%8F%B8%E7%9A%84%E6%9C%8D%E5%8A%A1%E4%B8%9A%E5%8A%A1) - [ ] [Pornhub母公司将支付1.2亿美元以和解儿童性虐待诉讼](https://blog.upx8.com/Pornhub%E6%AF%8D%E5%85%AC%E5%8F%B8%E5%B0%86%E6%94%AF%E4%BB%981-2%E4%BA%BF%E7%BE%8E%E5%85%83%E4%BB%A5%E5%92%8C%E8%A7%A3%E5%84%BF%E7%AB%A5%E6%80%A7%E8%99%90%E5%BE%85%E8%AF%89%E8%AE%BC) - [ ] [谷歌花1000万美元买下破产航空公司数据](https://blog.upx8.com/%E8%B0%B7%E6%AD%8C%E8%8A%B11000%E4%B8%87%E7%BE%8E%E5%85%83%E4%B9%B0%E4%B8%8B%E7%A0%B4%E4%BA%A7%E8%88%AA%E7%A9%BA%E5%85%AC%E5%8F%B8%E6%95%B0%E6%8D%AE) - [ ] [OpenAI ChatGPT即将推出青少年专属模式](https://blog.upx8.com/OpenAI-ChatGPT%E5%8D%B3%E5%B0%86%E6%8E%A8%E5%87%BA%E9%9D%92%E5%B0%91%E5%B9%B4%E4%B8%93%E5%B1%9E%E6%A8%A1%E5%BC%8F) - 黑鸟 - [ ] [勒索软件花招:重启进安全模式绕过EDR,却意外搞崩自身加密程序](https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451188142&idx=1&sn=47333a892e8bb380b1d0c411e6b35bdc) - 雷神众测 - [ ] [雷神众测漏洞周报2026.8.10-2026.8.16](https://mp.weixin.qq.com/s?__biz=MzI0NzEwOTM0MA==&mid=2652503913&idx=1&sn=ec84b81685e12bd1601a9ecaa0cd8dbd) - 安全内参 - [ ] [某国家全国公民数据疑在暗网论坛公开售卖](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516448&idx=1&sn=77b1888c439de752bf3223a1ee7b077b) - [ ] [全国土地登记系统遭勒索攻击,某国房地产市场暂停交易多天](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516448&idx=2&sn=94f71b6b75ffe708058b1ca409d45ec4) - 安全客 - [ ] [满分10.0的漏洞,补丁发布3天就被打穿](https://mp.weixin.qq.com/s?__biz=MzA5ODA0NDE2MA==&mid=2649790378&idx=1&sn=70d4a5bd0229de6e9bb1fe3a4a6eb2bf) - 代码卫士 - [ ] [GitLab GraphQL 严重漏洞可使未认证攻击者删除公开项目](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247526883&idx=1&sn=80604cef5784651f30751cec579a2172) - [ ] [CISA:Ray 严重漏洞可触发基于浏览器的 RCE 攻击](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247526883&idx=2&sn=adfc2a9b47df4c9153c9478ceb011b11) - 威努特安全网络 - [ ] [一文读懂半导体工控安全:筑牢芯基安全防线](https://mp.weixin.qq.com/s?__biz=MzAwNTgyODU3NQ==&mid=2651143567&idx=1&sn=f9b81a9e2ad8c101d04123fd15cbf3aa) - 中国信息安全 - [ ] [论坛·原创 | 我国人工智能安全治理的制度安排与实践逻辑](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265696&idx=1&sn=957ffba70fea138bce67868a118aa60b) - [ ] [关注 | 公安部网安局公布14起涉企网络谣言典型案例](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265696&idx=2&sn=2edf6c447ea82e1dc9a6580b840d7377) - [ ] [前沿 | 词元出海的竞争优势与挑战对策](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265696&idx=3&sn=3ac28c258c78210b4ef5587d2c96a274) - [ ] [国际 | 全球社交媒体禁令的模式与张力](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265696&idx=4&sn=77f852e7241eee045069dbc6f8d22355) - [ ] [评论 | 让人工智能这匹千里马跑得又快又稳](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265696&idx=5&sn=dc1947afa85d4af7578f565dcc2858fa) - 安全研究GoSSIP - [ ] [G.O.S.S.I.P 阅读推荐 2026-08-18 欢迎来到充电桩](https://mp.weixin.qq.com/s?__biz=Mzg5ODUxMzg0Ng==&mid=2247501996&idx=1&sn=88841a6b52e5ccca6320d532197a614d) - 信息安全国家工程研究中心 - [ ] [导致个人信息泄露的常见原因有哪些?](https://mp.weixin.qq.com/s?__biz=MzU5OTQ0NzY3Ng==&mid=2247504715&idx=1&sn=4834b97e53f81b145aea0add428e7295) - 数世咨询 - [ ] [全球工控防火墙市场预计到2034年将达到31.9亿美元](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247543695&idx=1&sn=1ca130b6eac7ce740746c38558109baa) - [ ] [关于“Sorry”勒索病毒,你想知道的都在这里](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247543695&idx=2&sn=3709f45e0e9b5c6ac5fd1ce925b095ef) - 安全圈 - [ ] [【安全圈】Cisco 防火墙零日漏洞遭野利用,企业边界防御要重新审视](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078333&idx=1&sn=8661fbfdba0a2e5dd3f3f0bbd96ead7b) - [ ] [【安全圈】AI 工具热潮下,数据泄露与供应链风险正在悄悄升级](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078333&idx=2&sn=49328a5c7430718272f856907efe1682) - [ ] [【安全圈】GitLab 关键 GraphQL 漏洞可能允许未认证攻击者删除公共项目](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078333&idx=3&sn=04c4e92193066da60476ed0f40b2d749) - 奇安信 CERT - [ ] [【已复现】PostgreSQL 远程代码执行漏洞(CVE-2026-14669)安全风险通告](https://mp.weixin.qq.com/s?__biz=MzU5NDgxODU1MQ==&mid=2247507128&idx=1&sn=5a09999ea6e550e3265d69024d1d4a15) - 安全牛 - [ ] [92%企业栽在同一个坑:AI Agent权限比模型算法致命一万倍](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142379&idx=1&sn=bf7c5e9c65339439a1d0d3466aad254a) - [ ] [麦当劳为用户建立515页画像:忠诚度App如何变成“商业监控”系统;CNVD发布漏洞周报2026年第32期| 牛览](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142379&idx=2&sn=b3e78afbebf8db425d11aba22558b53c) - 安全分析与研究 - [ ] [第13篇-Windows域环境中的勒索攻击路径](https://mp.weixin.qq.com/s?__biz=MzA4ODEyODA3MQ==&mid=2247497027&idx=1&sn=07a91ea8d32a6b2954e9b3115add71c3) - 青藤云安全 - [ ] [5000字分享:Mythos/GPT-5对企业安全架构影响思考](https://mp.weixin.qq.com/s?__biz=MzAwNDE4Mzc1NA==&mid=2650851700&idx=1&sn=6d9e27238d63740e428f0ce4cca0081e) - 看雪学苑 - [ ] [2026 KCTF | 第五题《申时·忆海倒带》设计思路及解析](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458618754&idx=1&sn=bc5ef9a8cdf5583739bf13376d24deb3) - [ ] [物流巨头CEVA遭攻击,Steam、宝可梦中心数据外泄](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458618754&idx=2&sn=6bac6dd5a77586f85aeb46e014598c55) - [ ] [本周更新2节 | 看雪安卓高级研修班(月薪一万计划):报名赠 pixel 1代手机](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458618754&idx=3&sn=f9e99b9c6d3f119813fea15ce5015af9) - 极客公园 - [ ] [马斯克带火的太空算力领域,传一个 800MB 模型上天要四周](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653112231&idx=1&sn=01def39a6417be2e2f78012b9ecdeb26) - [ ] [黑鲸鱼 DeepSeek Harness,从「赛博乐高」变成 Agent Store](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653112122&idx=1&sn=8d59cfefa14c4ff9ed25f6c04fd5b4f7) - 中通安全应急响应中心 - [ ] [【通知】关于中通SRC暂停接收漏洞测试的通知](https://mp.weixin.qq.com/s?__biz=MzUyMTcwNTY3Mg==&mid=2247486666&idx=1&sn=103bab8f07e1a52ed09af6fdc22e504d) - 斗象智能安全 - [ ] [我,AI员工,操作多个安全产品](https://mp.weixin.qq.com/s?__biz=MzIwMjcyNzA5Mw==&mid=2247495587&idx=1&sn=b0a8189af60f639837adba8a91584df4) - 网络空间安全科学学报 - [ ] [会议 | 关于举办第四届京津冀科技期刊创新发展论坛的通知(第二轮)](https://mp.weixin.qq.com/s?__biz=MzI0NjU2NDMwNQ==&mid=2247508357&idx=1&sn=ed84c97c7d60b23b1d18ff21a9c20e84) - 火绒安全 - [ ] [总是被突如其来的弹窗打扰?火绒弹窗拦截小指南来啦!](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247536559&idx=1&sn=face188f04ad4b909bf771a8df9c0b09) - [ ] [诚邀渠道合作伙伴共启新征程](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247536559&idx=2&sn=1ad6984bce34e723780888ff780f96c8) - 字节跳动技术团队 - [ ] [对比与生成:抖音SOTA多模态表征模型DME](https://mp.weixin.qq.com/s?__biz=MzI1MzYzMjE0MQ==&mid=2247521321&idx=1&sn=4881e96023fe955d32daac031479bc92) - [ ] [Lance Meetup 2026 · 上海站|正式开启报名!](https://mp.weixin.qq.com/s?__biz=MzI1MzYzMjE0MQ==&mid=2247521321&idx=2&sn=3bf7e34ca6f1ec24f8a946668b0518f5) - 云鼎实验室 - [ ] [PostgreSQL 曝高危 RCE 漏洞,腾讯云安全已支持检测](https://mp.weixin.qq.com/s?__biz=MzU3ODAyMjg4OQ==&mid=2247497886&idx=1&sn=7bd38d30924639bd4c6fe960e64b0b99) - IntelTechniques by Michael Bazzell - [ ] [New OS Telemetry Guide](https://inteltechniques.com/blog/index.html#telemetry-guide-content) - TrustedSec - [ ] [We've Seen This Movie: The OT/IT Technology Divide](https://trustedsec.com/blog/weve-seen-this-movie-the-ot-it-technology-divide) - 慢雾科技 - [ ] [MistTrack Agent 正式入驻 AgentOn,将链上调查能力带入 AI Agent](https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&mid=2247505715&idx=1&sn=abdf5f6d7da60ab189752cedfe4ab99f) - IT Service Management News - [ ] [AI slop](http://blog.cesaregallotti.it/2026/08/ai-slop.html) - 丁爸 情报分析师的工具箱 - [ ] [【开源报告】近五年中美人工智能发展与深度应用对比研究](https://mp.weixin.qq.com/s?__biz=MzI2MTE0NTE3Mw==&mid=2651157000&idx=1&sn=f7fbafbf6d057c81f0eda63f8f7bdd7a) - Over Security - [ ] [Comcast turns your Xfinity WiFi into a home motion detector](https://www.bleepingcomputer.com/news/security/comcast-turns-your-xfinity-wifi-into-a-home-motion-detector/) - [ ] [More than 200 victims of Medusa ransomware identified over the last year, CISA says](https://therecord.media/more-than-200-medusa-ransomware-victims-in-last-year-cisa) - [ ] [Clop created custom web shell for Windchill data theft attacks](https://www.bleepingcomputer.com/news/security/clop-created-custom-web-shell-for-windchill-data-theft-attacks/) - [ ] [Berlin cuts two state ministries off government network after security breach](https://therecord.media/berlin-cuts-two-state-ministries-off-government-breach) - [ ] [University of Texas forced to take systems offline in San Antonio after cyberattack](https://therecord.media/university-of-texas-forced-to-take-systems-offline-cyberattack-san-antonio) - [ ] [Hackers target Ukrainian agency managing assets seized from sanctioned Russians](https://therecord.media/hackers-target-ukraine-agency-sanctioned-russians) - [ ] [Your Controls Block Known Attacks. What About the Behavior?](https://www.bleepingcomputer.com/news/security/your-controls-block-known-attacks-what-about-the-behavior/) - [ ] [Pulire github](https://roccosicilia.com/2026/08/18/pulire-github/) - [ ] [Furto di identità via phishing Wise](https://www.d3lab.net/furto-di-identita-via-phishing-wise/) - [ ] [Behavioural AI: FAQ & Myths](https://www.threatfabric.com/blogs/behavioural-ai-faq-myths) - [ ] [Ukrainian software developer faces 12 years in Swiss ransomware trial](https://therecord.media/ukrainian-software-developer-court-switzerland) - [ ] [Microsoft tests faster Windows File Explorer, new context menu](https://www.bleepingcomputer.com/news/microsoft/microsoft-tests-faster-windows-explorer-customizable-context-menu/) - [ ] [CISA: Windows Task Host flaw now exploited by ransomware gangs](https://www.bleepingcomputer.com/news/security/cisa-windows-task-host-flaw-now-exploited-by-ransomware-gangs/) - [ ] [La monetizzazione dei dati personali nell’era dei data broker: l’efficacia dei servizi automatizzati di cancellazione](https://www.cybersecurity360.it/cultura-cyber/rimozione-dati-personali-data-broker-privacy-web/) - [ ] [Falso “rimborso farmaci” sfruttato per un phishing a tema Fascicolo Sanitario Elettronico](https://cert-agid.gov.it/news/falso-rimborso-farmaci-sfruttato-per-un-phishing-a-tema-fascicolo-sanitario-elettronico/) - [ ] [Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US](https://any.run/cybersecurity-blog/mirage2fa-phishing-targets-us-companies/) - [ ] [Microsoft confirms outage affecting search in Microsoft 365 apps](https://www.bleepingcomputer.com/news/microsoft/microsoft-working-to-fix-bug-behind-microsoft-365-search-issues/) - [ ] [Microsoft starts removing WMIC tool used by cybercriminals](https://www.bleepingcomputer.com/news/microsoft/microsoft-removes-wmic-lolbin-tool-in-windows-11-beta-builds/) - [ ] [La complessità è nemica della cyber security: la lezione del principio KISS](https://www.cybersecurity360.it/cultura-cyber/la-complessita-e-nemica-della-cyber-security-la-lezione-del-principio-kiss/) - [ ] [678,000 People Hit in French Tax Authority Data Breach](https://thecyberexpress.com/dgfip-cyberattack-exposes-data/) - [ ] [Gestione dei rischi NIS 2: il modello ibrido che collega servizi, informazioni, tecnologie e scenari di rischio](https://www.cybersecurity360.it/legal/gestione-dei-rischi-nis-2-il-modello-ibrido-che-collega-servizi-informazioni-tecnologie-e-scenari-di-rischio/) - [ ] [AI Models Escaped Test Environments and Hit Real Targets](https://thecyberexpress.com/ai-security-incidents-raise-evaluation-risks/) - SANS Internet Storm Center, InfoCON: green - [ ] [ISC Stormcast For Tuesday, August 18th, 2026 https://isc.sans.edu/podcastdetail/10056, (Tue, Aug 18th)](https://isc.sans.edu/diary/rss/33256) - Qualys Security Blog - [ ] [CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now](https://blog.qualys.com/category/product-tech) - D3Lab - [ ] [Furto di identità via phishing Wise](https://www.d3lab.net/furto-di-identita-via-phishing-wise/) - The Honeynet Project - [ ] [IntelOwl: Integration Ecosystem and Connector Optimization](https://honeynet.org/2026/08/18/gsoc2026_intelowl_connector_ecosystem/) - Javvad Malik - [ ] [Budget airlines, mobile phones, and AI](https://javvadmalik.com/2026/08/18/budget-airlines-mobile-phones-and-ai/) - Daniel Miessler - [ ] [Unconventional Thought Is the Differentiator](https://danielmiessler.com/blog/unconventional-thought-differentiator?utm_source=rss&utm_medium=feed&utm_campaign=website) - Tor Project blog - [ ] [New Release: Tor Browser 15.0.20](https://blog.torproject.org/new-release-tor-browser-15020/) - Full Disclosure - [ ] [Security advisory: Pre-authentication RCE (SQL injection) in XPressEntry 3.7.7454 (Telaeris Inc)](https://seclists.org/fulldisclosure/2026/Aug/67) - [ ] [Security advisory: Authenticated RCE (SQL injection) in Scrutinizer 19.7.0 (Plixer)](https://seclists.org/fulldisclosure/2026/Aug/66) - [ ] [Security advisory: Pre-authentication SYSTEM RCE (Zip-Slip plugin planting) in Output Messenger Server 2.0.x (>= 2.0.63) (Srimax Software (Output Technology))](https://seclists.org/fulldisclosure/2026/Aug/65) - [ ] [Security advisory: Pre-authentication RCE (arbitrary file write) in RapidDeploy 5.2.2 (MidVision)](https://seclists.org/fulldisclosure/2026/Aug/64) - [ ] [Security advisory: Authenticated RCE (second-order SQL injection) in Lansweeper 12.2.1.0 (web reports 12.2.1.6) (Lansweeper)](https://seclists.org/fulldisclosure/2026/Aug/63) - [ ] [Security advisory: Authenticated RCE (command injection) in Kerio Connect 10.0.9 Patch 2 (build 10320) (GFI Software)](https://seclists.org/fulldisclosure/2026/Aug/62) - [ ] [Security advisory: Pre-authentication RCE (default credentials + path traversal) in PulseNET Enterprise 6.0.3 (build 6975) (GE Vernova)](https://seclists.org/fulldisclosure/2026/Aug/61) - [ ] [Security advisory: Pre-authentication RCE (BinaryFormatter deserialization) in Cinegy Cinegize 2026-02-05 installer (Cinegy GmbH)](https://seclists.org/fulldisclosure/2026/Aug/60) - [ ] [Security advisory: Pre-authentication RCE in Wyn Enterprise 9.1.00145.0 (Mescius (GrapeCity))](https://seclists.org/fulldisclosure/2026/Aug/59) - [ ] [Security advisory: Pre-authentication RCE (default credentials) in ObjectDB 2.9.5 server mode (ObjectDB Software)](https://seclists.org/fulldisclosure/2026/Aug/58) - [ ] [Security advisory: Pre-authentication RCE in nanoDLP stable build #10729 (Nano3Dtech)](https://seclists.org/fulldisclosure/2026/Aug/57) - [ ] [Security advisory: Pre-authentication SYSTEM RCE in MAPS SCADA 4.0.5.5 (Adroit Technologies)](https://seclists.org/fulldisclosure/2026/Aug/56) - [ ] [Security advisory: Pre-authentication RCE in Confluent Platform (ksqlDB) 7.9.1-ce (Confluent, Inc.)](https://seclists.org/fulldisclosure/2026/Aug/55) - [ ] [Security advisory: Pre-authentication SYSTEM RCE in iMonnit Express 4.0.5.5 (Monnit / iMonnit)](https://seclists.org/fulldisclosure/2026/Aug/54) - [ ] [Security advisory: Pre-authentication RCE in Ontotext GraphDB 11.4.3 Free edition (Ontotext / Graphwise)](https://seclists.org/fulldisclosure/2026/Aug/53) - Schneier on Security - [ ] [LLMs and Contextual Integrity](https://www.schneier.com/blog/archives/2026/08/llms-and-contextual-integrity.html) - The Hacker News - [ ] [Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps](https://thehackernews.com/2026/08/microsoft-copilot-personal-flaws-could.html) - [ ] [Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets](https://thehackernews.com/2026/08/attackers-exploit-mlflow-ssrf-flaw-to.html) - [ ] [Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000](https://thehackernews.com/2026/08/ransom-busters-claims-it-hacked.html) - [ ] [AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files](https://thehackernews.com/2026/08/ai-mind-viruses-can-spread-between.html) - [ ] [TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks](https://thehackernews.com/2026/08/twinloot-abuses-sharepoint-and-teams-to.html) - [ ] [One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025](https://thehackernews.com/2026/08/one-attacker-has-scraped-both.html) - [ ] [16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets](https://thehackernews.com/2026/08/16-typosquatted-rubygems-packages-steal.html) - [ ] [SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers](https://thehackernews.com/2026/08/safepal-hardware-wallet-maker-says-flaw.html) - [ ] [CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE](https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html) - Security Affairs - [ ] [Hackers Expose Data of 1.2 Million Heights Finance Customers](https://securityaffairs.com/197485/data-breach/hackers-expose-data-of-1-2-million-heights-finance-customers.html) - [ ] [Project noRecognition: Teaching AI to Fool Surveillance Cameras](https://securityaffairs.com/197465/ai/project-norecognition-teaching-ai-to-fool-surveillance-cameras.html) - [ ] [GitLab Patches Critical Unauthenticated GraphQL Vulnerability](https://securityaffairs.com/197454/hacking/gitlab-patches-critical-unauthenticated-graphql-vulnerability.html) - [ ] [U.S. CISA adds a Ray-Project Ray flaw to its Known Exploited Vulnerabilities catalog](https://securityaffairs.com/197419/security/u-s-cisa-adds-a-ray-project-ray-flaw-to-its-known-exploited-vulnerabilities-catalog.html) - [ ] [New Mirai-Based Evooo1Bot Botnet Targets Linux Devices](https://securityaffairs.com/197434/malware/new-mirai-based-evooo1bot-botnet-targets-linux-devices.html) - Troy Hunt's Blog - [ ] [Weekly Update 517: Cyber Ransoms](https://www.troyhunt.com/weekly-update-517/) - TorrentFreak - [ ] [A German Court Drew the Piracy Line at 81.5%, KinoGO Was Blocked with (at least) 82.4%](https://torrentfreak.com/a-german-court-drew-the-piracy-line-at-81-5-kinogo-was-blocked-with-at-least-82-4/) - Computer Forensics - [ ] [Majors?](https://www.reddit.com/r/computerforensics/comments/1vrfru9/majors/) - Deeplinks - [ ] [Ninth Circuit Ruling Will Force Online Platforms That Host User Speech to Fight Lengthy and Costly Lawsuits Before They Are Dismissed Under Section 230](https://www.eff.org/deeplinks/2026/08/ninth-circuit-ruling-will-force-online-platforms-host-user-speech-fight-lengthy) - Instapaper: Unread - [ ] [SQLite Database Analysis Tips and Tricks with DB Browser](https://iverify.io/blog/sqlite-database-analysis-db-browser) - [ ] [Android Intrusion Logs](https://iverify.io/blog/android-intrusion-logging-forensics-analysis) - [ ] [Apple now uses iPhone alerts for targets of mercenary spyware](https://www.malwarebytes.com/blog/news/2026/08/apple-now-uses-iphone-alerts-for-targets-of-mercenary-spyware) - [ ] [Tracking Timezone Changes in Digital Wellbeing](https://www.stark4n6.com/2026/08/tracking-timezone-changes-in-digital.html) - [ ] [OSINT Tools Update](https://inteltechniques.com/blog/) - Security Weekly Podcast Network (Audio) - [ ] [Secrets, Red Agent, GitHub, evoooo1bot, DecryptAds, Copilot, Aaran Leyland, and More - SWN #608](http://sites.libsyn.com/18678/secrets-red-agent-github-evoooo1bot-decryptads-copilot-aaran-leyland-and-more-swn-608) - [ ] [Augmenting Threat Intel Analysis with Agents - Chris Wallis, Sai Kiran Uppu, Ramin Farassat - ASW #396](http://sites.libsyn.com/18678/augmenting-threat-intel-analysis-with-agents-chris-wallis-sai-kiran-uppu-ramin-farassat-asw-396)
每日安全资讯(2026-08-19)