# 每日安全资讯(2026-08-21) - SecWiki News - [ ] [SecWiki News 2026-08-20 Review](http://www.sec-wiki.com/?2026-08-20) - Private Feed for M09Ic - [ ] [esrrhs contributed to esrrhs/fakecc](https://github.com/esrrhs/fakecc/pull/25) - [ ] [spf13 forked spf13/nemotron-bubble from snipemanmike/nemotron-bubble](https://github.com/spf13/nemotron-bubble) - [ ] [mgeeky starred max-sixty/worktrunk](https://github.com/max-sixty/worktrunk) - [ ] [anthropics released v2.1.238 at anthropics/claude-code](https://github.com/anthropics/claude-code/releases/tag/v2.1.238) - [ ] [bolucat released 202608202048 at bolucat/Archive](https://github.com/bolucat/Archive/releases/tag/202608202048) - [ ] [mgeeky starred RealAlexandreAI/pi-all-search](https://github.com/RealAlexandreAI/pi-all-search) - [ ] [shmilylty starred P4nda0s/IDA-NO-MCP](https://github.com/P4nda0s/IDA-NO-MCP) - [ ] [mgeeky starred KevinSilvester/wezterm-config](https://github.com/KevinSilvester/wezterm-config) - [ ] [Teach2Breach starred rabbitstack/fibratus](https://github.com/rabbitstack/fibratus) - [ ] [Rvn0xsy starred Electricitysheep/dsh-handbook](https://github.com/Electricitysheep/dsh-handbook) - [ ] [spf13 starred snipemanmike/nemotron-bubble](https://github.com/snipemanmike/nemotron-bubble) - [ ] [Mel0day starred zhu1090093659/dsh-web-ui](https://github.com/zhu1090093659/dsh-web-ui) - [ ] [mgeeky starred oraios/serena](https://github.com/oraios/serena) - [ ] [mgeeky starred ghostsecurity/skills](https://github.com/ghostsecurity/skills) - [ ] [wabzsy starred sickn33/agentic-awesome-skills](https://github.com/sickn33/agentic-awesome-skills) - [ ] [esrrhs starred unifyai/ivy](https://github.com/unifyai/ivy) - [ ] [rabbitmask starred mumumumuo/codexray-skill](https://github.com/mumumumuo/codexray-skill) - [ ] [veo starred Soju06/codex-lb](https://github.com/Soju06/codex-lb) - [ ] [pydantic released v2.32.1 at pydantic/pydantic-ai](https://github.com/pydantic/pydantic-ai/releases/tag/v2.32.1) - [ ] [wh0amitz starred G4sp4rCS/CVE-2026-42980-POC](https://github.com/G4sp4rCS/CVE-2026-42980-POC) - [ ] [rabbitmask starred AugustineFulgur/Agenst](https://github.com/AugustineFulgur/Agenst) - [ ] [anthropics released v2.1.237 at anthropics/claude-code](https://github.com/anthropics/claude-code/releases/tag/v2.1.237) - Recent Commits to cve:main - [ ] [Update Thu Aug 20 12:07:23 UTC 2026](https://github.com/trickest/cve/commit/f96772988005b960bdec3d73a5989349025ddf7c) - Tenable Blog - [ ] [Frequently asked questions about the active threat to Siemens S7 Series PLCs](https://www.tenable.com/blog/frequently-asked-questions-about-the-active-threat-to-siemens-s7-series-plcs) - Doonsec's feed - [ ] [分享图片](https://mp.weixin.qq.com/s/8ferWqU9j6e73-zTD9mLHA) - [ ] [《网络数据安全风险评估办法》正式施行,奇安信:企业亟待做好这几件事](https://mp.weixin.qq.com/s/Gc7Ah1Y2g9j3_vVRb1ouwA) - [ ] [XCon2026议题||AI原生的安全运营观&实践](https://mp.weixin.qq.com/s/6Akz7mdJF0L5whP1TY7xVw) - [ ] [功能安全 vs 网络安全:一文读懂 PKI 体系及其汽车落地应用](https://mp.weixin.qq.com/s/XNcQWtG-xC-TkNoCYxl_0w) - [ ] [AutoSec演讲嘉宾 | 国家互联网应急中心 网络安全技术国家工程研究中心副主任:中国数据跨境流动治理实践及新规解读](https://mp.weixin.qq.com/s/KmDejJvc9toETeIAB_YolA) - [ ] [CAN收发器的休眠唤醒--TJA1043](https://mp.weixin.qq.com/s/KvOXIn909qeejUNmp2lYlA) - [ ] [冰与火的战歌:Windows内核攻防实战(附彩蛋课堂:命令行投毒)](https://mp.weixin.qq.com/s/tiCwMub-WpgXH87TRkw_Yw) - [ ] [数据安全风险评估今起施行](https://mp.weixin.qq.com/s/oYuqozqVdwb6DxRrZZJ2wQ) - [ ] [合合信息旗下启信宝推出“AI问企”功能,用“一句话”问答降低商业数据决策门槛](https://mp.weixin.qq.com/s/4_O0e_cUDBYaiIYQ_lPYVg) - [ ] [2026年最火6大编程语言对网安人来说到底有什么用?](https://mp.weixin.qq.com/s/s_hdtSUYxVuyryGJH5TjJw) - [ ] [腾讯大数据 SuperSQL 刷新 TPC-DS 世界纪录,性能、性价比双料第一](https://mp.weixin.qq.com/s/hgTWRQHc-w5mjDhYlFXlVQ) - [ ] [众安天下获CCIA “2026网络安全优秀创新成果大赛”人工智能赛道优胜奖](https://mp.weixin.qq.com/s/qhPFytdC3dTdS9GN4cmgow) - [ ] [【免费领】SQL注入攻防实战技术教程(近400页)](https://mp.weixin.qq.com/s/s-3-zya8mxJssA8xd--LTg) - [ ] [新规今日施行 |《网络数据安全风险评估办法》学习理解划重点](https://mp.weixin.qq.com/s/3zpZWhU4RExkuutxvK-fKg) - [ ] [破局安全盲区与算力黑洞 AIStorm出席香港AI安全治理午宴 发布“安全+算力”双维治理方案](https://mp.weixin.qq.com/s/xasB1iBSaIusbBm91x4pVA) - [ ] [群英淬剑·决战金陵|2026亚信安全合作伙伴技术大比武总决赛启幕在即](https://mp.weixin.qq.com/s/VluJyHsujQZw7l7fs4GoRw) - [ ] [SFP与RJ45网络接口对比,在网络中,选择合适的接口会直接影响性能、可扩展性和成本](https://mp.weixin.qq.com/s/CBRRe_kYG1He_rCDembDPg) - [ ] [美国白宫发布《国家安全科技战略》 (中译本、英文全文下载)](https://mp.weixin.qq.com/s/iNG7eLptes-c3oA1xRT4mg) - [ ] [《网络数据安全风险评估办法》今日实施](https://mp.weixin.qq.com/s/Hi4RptNr5cCnYrzXqVnvgw) - [ ] [《网络数据安全风险评估办法》实施有关事项答记者问](https://mp.weixin.qq.com/s/DeIlGGiskrKWQG2ByOm2FA) - [ ] [湖北省2026年职业院校教师素质提高计划培训班顺利开班](https://mp.weixin.qq.com/s/GkxmeZ0Rp0Tb45Ymw70j0g) - [ ] [逼各国选边站!美国强推 AI 领域中美“二选一”](https://mp.weixin.qq.com/s/p8Dw46IZBtbRwJPAJWZ9Hg) - [ ] [欧委会发布一揽子方案,围绕“技术主权”加强关键数字领域建设](https://mp.weixin.qq.com/s/UmAEacHtBbIz_cIC_9Mslg) - [ ] [马上!加拿大渥太华号护卫舰即将抵近中国](https://mp.weixin.qq.com/s/7DkNdQ0bDPZD2V-n0uh_qQ) - [ ] [天融信AI安全防护产品获推技术发明奖!](https://mp.weixin.qq.com/s/asNSAiOjEvW8MIMtenmRyQ) - [ ] [天融信:网络数据安全风险评估进入常态化、规范化,AI加持的全流程合规方案安排→](https://mp.weixin.qq.com/s/OuSgvg6wynUMPegYEa41sg) - [ ] [被黑客攻击!紧急冲进机房,直接剪断网线!](https://mp.weixin.qq.com/s/ivwXe_GQdsrfweUfsiUq5Q) - [ ] [关注 | 词元出海的竞争优势与挑战对策](https://mp.weixin.qq.com/s/-emOiRnHQFFhGkSKGoZogA) - [ ] [动态|《数智时代的教育模式转型与实践创新》正式出版](https://mp.weixin.qq.com/s/QSOYQBq1o8oDiAbeTv4pfA) - [ ] [【01-好靶场月赛】重生为一个安全服务工程师](https://mp.weixin.qq.com/s/1cf9wqCvp-sXhT_vWDlx5w) - [ ] [月满中秋,礼谢白帽|雷神众测中秋专属礼盒活动开启](https://mp.weixin.qq.com/s/Zrf8sTddvG7hBG7t312iCQ) - [ ] [2026 | 8 月 20 日正式落地!24 号令新规来袭,数据评估不合格直接叫停业务](https://mp.weixin.qq.com/s/MiwyfJDRccE8lVy7b7q3zQ) - [ ] [安全牛十大产品创新:“问境+灵脉”系列持续引领智能体全生命周期安全治理!](https://mp.weixin.qq.com/s/w7klKPjwmH0Nspr32wN3bQ) - [ ] [中关村自主大模型产业联盟招募合作伙伴, “中国安全智能开放共创计划”正式启动](https://mp.weixin.qq.com/s/i28TL7sZiBHQjU0z52Ot-A) - [ ] [腾讯云鼎实验室助力百度安全“Agent+”攻防能力挑战赛](https://mp.weixin.qq.com/s/Dvnl7Hw4BmkCGrlJaQw2Gw) - [ ] [微信小程序存在任意用户登陆](https://mp.weixin.qq.com/s/c5MEegwI629ZJA0CCR3ZXA) - [ ] [RTX5090 堆成小山是什么体验?](https://mp.weixin.qq.com/s/1y4_-wf9LYFyu2-VAUHJvw) - [ ] [新能源重卡试验认证:GB 44495-2024合规准备与风险防控](https://mp.weixin.qq.com/s/vXz09JXXVQ75TQhGx7Nv1Q) - [ ] [邀请函|智能网联汽车电子电气架构在线研讨会2026](https://mp.weixin.qq.com/s/vqUsNFAnhMVv-sfD6vEcXA) - [ ] [基于合规性验证的汽车信息安全测试系统开发](https://mp.weixin.qq.com/s/x2BbpCcg38goIgBXoxgDzg) - [ ] [BushSEC Analysis平台测试](https://mp.weixin.qq.com/s/Qzu_DMhJOLzse4GHPkdfTQ) - [ ] [800](https://mp.weixin.qq.com/s/wEy6mns3_pzx4xggs-flPQ) - [ ] [公安部176号令倒计时:线上巡查随时可能“突袭”,你的安全体系在线吗?](https://mp.weixin.qq.com/s/1Iu5Yzlrh8ee5dM2jPPDig) - [ ] [今日起,《网络数据安全风险评估办法》正式施行!](https://mp.weixin.qq.com/s/JhVw9xVqlZT4F06SnduYag) - [ ] [等保怎么做?找谁做?手把手教你少走弯路](https://mp.weixin.qq.com/s/jJEtiamkiz7SAGkp_fB58g) - [ ] [【通知】第六届开源情报技术大会拟于2026年11月贵阳召开](https://mp.weixin.qq.com/s/V_ZHBCHMXbNvdfoMTMw_TA) - [ ] [虫洞快讯 | 荷叶丛中揪出骗子!民警现场截下14万元被骗款](https://mp.weixin.qq.com/s/Zr1hyEfsBv8Gyy1PfycJhA) - [ ] [安全快报 | 俄罗斯黑客入侵乌克兰多个城市联网摄像头以窃取军事情报和公民信息](https://mp.weixin.qq.com/s/oprN2xBE03DusF6JxD4Trw) - [ ] [吊打所有传统扫描器!这款开源工具让漏洞挖掘效率提升1000%](https://mp.weixin.qq.com/s/8qgRMizqCfzhcs1K5V_oQA) - [ ] [上半场 飙红](https://mp.weixin.qq.com/s/A731FQMkYOnV0j1WyPsjnw) - [ ] [8月20日高危CVE漏洞速报](https://mp.weixin.qq.com/s/DAiN8DCWXcmVQJslL171Hg) - [ ] [说一个关于暗网观察的暴论](https://mp.weixin.qq.com/s/JV2gldNfJavDIIu8GZbXog) - [ ] [《网络数据安全风险评估办法》来了!企业数据合规迎来\"硬指标\"](https://mp.weixin.qq.com/s/qfMUSmXsKk9aUi2rkG89Ig) - [ ] [Web漏洞扫描工具 -- Webscanner](https://mp.weixin.qq.com/s/cEWF0XVx5NW4qTzkIFoy2g) - [ ] [CNVD漏洞周报2026年第32期](https://mp.weixin.qq.com/s/-StXHrFyKVizNKs1MITHYg) - [ ] [我用WorkBuddy做了个“新生100问AI学长”](https://mp.weixin.qq.com/s/fPG-iY_djzBhfFvW3GoJeg) - [ ] [求求了别打天庭了](https://mp.weixin.qq.com/s/W8J_ei1xnq16JbJTvX4UeQ) - [ ] [一纸测评报告,从“合规证明”变成“违规证](https://mp.weixin.qq.com/s/7I5fxzDznNSSDE1bW0G7yg) - [ ] [华为云新活动,100-300代金券](https://mp.weixin.qq.com/s/IrNYGqNOfM0ODBeUgBZGhg) - [ ] [几十号人的公司,凭啥被黑客盯上?](https://mp.weixin.qq.com/s/9TCqeGn6eN3Bbe4cjmJJvg) - [ ] [800元起,拿下 3TOPS 算力!飞凌嵌入式 FCU3101 内置10多种 AI 算法,提速边缘 AI 视觉落地](https://mp.weixin.qq.com/s/g26MIH3ZccQTgrhEI4Pveg) - [ ] [首个线索研判智能体——问迹智能线索研判系统正式发布!](https://mp.weixin.qq.com/s/_4WKqNBT1ELoFB4qgu7lFQ) - [ ] [政务平台怎么建?分建、统建还是省建市用?](https://mp.weixin.qq.com/s/tWbdX1ruy1rz6MuAuO7mvA) - [ ] [【深度研判】美国海军确认弗吉尼亚级特种海底侦察潜艇配置,海底作战能力升级对我海底光缆及南海、西太平洋利益的影响](https://mp.weixin.qq.com/s/6nP71IO1l_vf_1VLgygdtw) - [ ] [数据安全||《网络数据安全风险评估办法》今天落地,评估行业新赛道,40张图多角度个人解读](https://mp.weixin.qq.com/s/H8UPsAxVL08PL6IMICW7BQ) - [ ] [亚信安全|控股孙公司亚信中国卷入 1.47 亿采购仲裁,账户被保全冻结](https://mp.weixin.qq.com/s/JoilOLwOTFbLXcFBIlLHLQ) - [ ] [永信至诚|财务负责人辞任,总经理临时代行](https://mp.weixin.qq.com/s/WJ8vTJeQWykaDeFTFeP0pg) - [ ] [格尔软件|实控人之一陆海天披露减持计划,拟减持不超过公司总股本 1.9996% 股份](https://mp.weixin.qq.com/s/nQqXos3rN_FlPHV9rTzUhg) - Sploitus.com Exploits RSS Feed - [ ] [Exploit for Protection Mechanism Failure in Mozilla Firefox](https://sploitus.com/exploit?id=B02F492E-B304-5A76-9965-EE78FFF5A5E6&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-18963](https://sploitus.com/exploit?id=A76D2FC5-1440-568B-81C2-B0213465485E&utm_source=rss&utm_medium=rss) - [ ] [pwnos2-linux-web-pentest exploit](https://sploitus.com/exploit?id=7E7A06DE-CA01-5692-BE7E-73B7F1C1DE43&utm_source=rss&utm_medium=rss) - [ ] [binary-exploitation](https://sploitus.com/exploit?id=BCA55A1A-E60E-59AC-947E-EA5464CC80DB&utm_source=rss&utm_medium=rss) - [ ] [grade-server-ctf exploit](https://sploitus.com/exploit?id=F57E9426-4997-53E1-AAE0-ABA5DDE02AE6&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-19478](https://sploitus.com/exploit?id=023A5628-2B1E-57C5-83BA-E3FB532E4A9C&utm_source=rss&utm_medium=rss) - [ ] [devsecops-poc-workflows exploit](https://sploitus.com/exploit?id=09AE58F8-EF40-5E92-8D4C-75F669557E79&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Missing Authentication for Critical Function in Coreweave Marimo](https://sploitus.com/exploit?id=C41115C4-5396-5897-BAC9-19842AA8E98D&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-18366](https://sploitus.com/exploit?id=1CC3B1B2-1609-5665-B623-F0CEA024BFAE&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Improper Input Validation in Drupal](https://sploitus.com/exploit?id=EF0710BD-5658-5AFA-B761-E8D095262D6E&utm_source=rss&utm_medium=rss) - [ ] [debugging-modern-glibc-heap exploit](https://sploitus.com/exploit?id=3717FB70-C18F-5CDC-8BC3-996702C23757&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-18315](https://sploitus.com/exploit?id=31430A8D-8381-5808-BF15-BC5D3AF3A8D7&utm_source=rss&utm_medium=rss) - [ ] [py-web-vuln-scanner exploit](https://sploitus.com/exploit?id=E4C2B1FD-E71B-50B4-93C4-1BE238173709&utm_source=rss&utm_medium=rss) - [ ] [forminator-poc-lab exploit](https://sploitus.com/exploit?id=BD4609B1-6C96-584B-81CB-38A8D42B8A2F&utm_source=rss&utm_medium=rss) - [ ] [cybersecurity-projects exploit](https://sploitus.com/exploit?id=1F3840A9-3DAE-51A5-8D48-17DA0B949B72&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-71960](https://sploitus.com/exploit?id=28FEF878-7AE8-5CC3-9535-1CF08252260B&utm_source=rss&utm_medium=rss) - [ ] [vulnerability-harness exploit](https://sploitus.com/exploit?id=06C09C28-FBF2-5688-B8B3-6A4A76AFA09B&utm_source=rss&utm_medium=rss) - [ ] [Sql-injection-payloads exploit](https://sploitus.com/exploit?id=5A3EDE07-5CAC-56BC-870A-D79E9560701E&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Type Confusion in Google Chrome](https://sploitus.com/exploit?id=5000AE00-F349-51E8-B11F-591961ECEC94&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Interpretation Conflict in Wordpress](https://sploitus.com/exploit?id=C65E8753-E53D-588C-9EB7-3F4C50AF9469&utm_source=rss&utm_medium=rss) - [ ] [poc-inteligencia-tributaria-palmas exploit](https://sploitus.com/exploit?id=6DB3A131-0E33-5C3C-A04C-C64B2A20E158&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Path Traversal in F5 Big-Ip_Access_Policy_Manager](https://sploitus.com/exploit?id=7D18D33A-EB04-5EED-AE09-4481C58B1CFE&utm_source=rss&utm_medium=rss) - [ ] [reconkg exploit](https://sploitus.com/exploit?id=E36FC2D9-F3F1-558A-BB03-1C9DC863079A&utm_source=rss&utm_medium=rss) - [ ] [Automated-Exploit-Chain](https://sploitus.com/exploit?id=4F95A9E3-7436-5A3B-BC3F-351C5F07924B&utm_source=rss&utm_medium=rss) - [ ] [Awesome-Bug-Bounty-Tools-Contents exploit](https://sploitus.com/exploit?id=7D16923C-5D60-5BAF-A173-DC93DBF4EBB2&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-8181](https://sploitus.com/exploit?id=8322E547-AFB5-561F-95D8-C504EB54EF91&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Type Confusion in Mozilla Firefox](https://sploitus.com/exploit?id=C27C317E-CC21-5FC5-8EEB-BA10DFD85D34&utm_source=rss&utm_medium=rss) - [ ] [Wargame-Exploitation-Project](https://sploitus.com/exploit?id=05CF21D0-8E19-5900-B700-A733F9C6DDA7&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Incorrect Authorization in Qualcomm Aqt1000_Firmware](https://sploitus.com/exploit?id=AA2FA77B-3D49-5C79-AB20-4A11831C6BFE&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Use After Free in Linux Linux_Kernel](https://sploitus.com/exploit?id=16F30584-5BA9-5884-B6BF-DCD9A0D518DE&utm_source=rss&utm_medium=rss) - Paper - 知道创宇404实验室 - [ ] [TwinGridShield:面向 LLM 电网智能体动作的后果感知运行时授权](https://paper.seebug.org/3512) - 小刀志 - [ ] [从 PE 到 PKCS#7:深入理解 Windows PE 数字签名机制](https://xiaodaozhi.com/security/482.html) - Kitploit - [ ] [opensoho v0.15.0](https://kitploit.com/en/posts/github-rubenbe-opensoho-v0150) - [ ] [caido v0.58.0](https://kitploit.com/en/posts/github-caido-caido-v0580) - [ ] [DockSec v2026.8.19](https://kitploit.com/en/posts/github-owasp-docksec-v2026819) - [ ] [forensictools v1.4](https://kitploit.com/en/posts/github-cristianzsh-forensictools-v14) - [ ] [faraday v5.23.2](https://kitploit.com/en/posts/github-infobyte-faraday-v5232) - [ ] [jumpserver v4.10.19](https://kitploit.com/en/posts/github-jumpserver-jumpserver-v41019) - [ ] [faction v1.8.13](https://kitploit.com/en/posts/github-factionsecurity-faction-1813) - [ ] [strelka v1.0.2](https://kitploit.com/en/posts/github-target-strelka-v102) - [ ] [numa v0.23.0](https://kitploit.com/en/posts/github-razvandimescu-numa-v0230) - [ ] [PCAPdroid v2.0.0](https://kitploit.com/en/posts/github-emanuele-f-pcapdroid-v200) - [ ] [cloudquery plugins-destination-snowflake-v5.2.14](https://kitploit.com/en/posts/github-cloudquery-cloudquery-plugins-destination-snowflake-v5214) - [ ] [BLAKE3 v1.8.7](https://kitploit.com/en/posts/github-blake3-team-blake3-187) - [ ] [Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis](https://kitploit.com/en/tools/github/kaandemir993/dropper-gcleaner-c2-infrastructure-kernel-driver-powershell-conhost-payload-analysis) - [ ] [wasm2c-tableflip](https://kitploit.com/en/tools/github/trustsig-eu/wasm2c-tableflip) - [ ] [fnprint](https://kitploit.com/en/tools/github/1rhino2/fnprint) - [ ] [lg-webos-kexec](https://kitploit.com/en/tools/github/ggfuchsi-oss/lg-webos-kexec) - [ ] [reconkg](https://kitploit.com/en/tools/github/xghst0/reconkg) - [ ] [File-Tunnel v3.5.2](https://kitploit.com/en/posts/github-fiddyschmitt-file-tunnel-v352) - [ ] [context-aware-offensive-intelligence](https://kitploit.com/en/tools/github/indoushka/context-aware-offensive-intelligence) - [ ] [Zapscape-Fix — Updated!](https://kitploit.com/en/posts/github-aoripus-ltd-zapscape-fix-6ddb101966d4021f6585a7550b3c716a6d9adbb0be052ff4d62d187783e0af39) - [ ] [audit-kernel v7.2](https://kitploit.com/en/posts/github-linux-audit-audit-kernel-72) - [ ] [linux v7.2](https://kitploit.com/en/posts/github-torvalds-linux-72) - [ ] [lsPass](https://kitploit.com/en/tools/gitlab/leestripp/lspass) - [ ] [LeakGauge](https://kitploit.com/en/tools/github/yeasen-z/leakgauge) - [ ] [BloodBash](https://kitploit.com/en/tools/github/squidsec/bloodbash) - [ ] [iron-proxy](https://kitploit.com/en/tools/github/paradigmxyz/iron-proxy) - [ ] [sentrymcp](https://kitploit.com/en/tools/github/zaydmulani09/sentrymcp) - [ ] [SecureAI-Scan v0.10.0](https://kitploit.com/en/posts/github-akanthed-secureai-scan-v0100) - [ ] [Antiphishing v32278722593](https://kitploit.com/en/posts/github-julioliraup-antiphishing-release-32278722593) - [ ] [kin v0.5.42](https://kitploit.com/en/posts/github-firelock-ai-kin-v0542) - [ ] [Specter-FlipperZero v2.7](https://kitploit.com/en/posts/github-at0m-b0mb-specter-flipperzero-v27) - [ ] [radmin-vpn-linux v1.1.0](https://kitploit.com/en/posts/github-baptisterajaut-radmin-vpn-linux-v110) - [ ] [prismor v1.43.0](https://kitploit.com/en/posts/github-prismorsec-prismor-v1430) - [ ] [agentic-threat-hunting-framework v0.19.0](https://kitploit.com/en/posts/github-nebulock-inc-agentic-threat-hunting-framework-v0190) - [ ] [so-crates v4.0.0](https://kitploit.com/en/posts/github-dougburks-so-crates-v400) - [ ] [xalgorix v4.5.153](https://kitploit.com/en/posts/github-xalgord-xalgorix-v45153) - [ ] [vigolium v0.4.3](https://kitploit.com/en/posts/github-vigolium-vigolium-v043) - [ ] [akto v2.20.1](https://kitploit.com/en/posts/github-akto-api-security-akto-v2201) - [ ] [sysreptor v2026.68](https://kitploit.com/en/posts/github-syslifters-sysreptor-202668) - [ ] [agent-scan v0.6.0](https://kitploit.com/en/posts/github-snyk-agent-scan-v060) - [ ] [nono v0.74.0](https://kitploit.com/en/posts/github-nolabs-ai-nono-v0740) - [ ] [cvelistV5 cve_2026-08-20_0000Z](https://kitploit.com/en/posts/github-cveproject-cvelistv5-cve_2026-08-20_0000z) - [ ] [codex-security npm-v0.1.15](https://kitploit.com/en/posts/github-openai-codex-security-npm-v0115) - [ ] [sshroute v0.2.11](https://kitploit.com/en/posts/github-thereisnotime-sshroute-v0211) - Horizon3 - [ ] [CVE-2026-19478 | MeGitLab CE/EE GraphQL Directive Code Injection Vulnerability](https://horizon3.ai/attack-research/vulnerabilities/cve-2026-19478/) - Reverse Engineering - [ ] [Use garlic + ai analysis encrypted apk](https://www.reddit.com/r/ReverseEngineering/comments/1vtgm7a/use_garlic_ai_analysis_encrypted_apk/) - [ ] [Patch-Less User-Mode Telemetry Hooking via Hardware Breakpoints (DR0-DR7) & VEH](https://www.reddit.com/r/ReverseEngineering/comments/1vtc093/patchless_usermode_telemetry_hooking_via_hardware/) - [ ] [Reading an offline ntds.dit with one binary](https://www.reddit.com/r/ReverseEngineering/comments/1vt9frv/reading_an_offline_ntdsdit_with_one_binary/) - Malwarebytes - [ ] [ChatGPT for Teens tackles risky chats and homework shortcuts](https://www.malwarebytes.com/blog/family-and-parenting/2026/08/chatgpt-for-teens-tackles-risky-chats-and-homework-shortcuts) - [ ] [Twitch wants your content for Amazon AI training. Here’s how to opt out](https://www.malwarebytes.com/blog/ai/2026/08/twitch-wants-your-content-for-amazon-ai-training-heres-how-to-opt-out) - [ ] [Your Mac already has a built-in firewall. Here’s how to get more from it](https://www.malwarebytes.com/blog/product/2026/08/your-mac-already-has-a-built-in-firewall-heres-how-to-get-more-from-it) - [ ] [9 million images of people’s faces exposed by reverse lookup service](https://www.malwarebytes.com/blog/privacy/2026/08/9-million-images-of-peoples-faces-exposed-by-reverse-lookup-service) - Intigriti - [ ] [Web fuzzing for hackers](https://www.intigriti.com/researchers/blog/hacking-tools/web-fuzzing-for-hackers) - Dancho Danchev's Blog - Mind Streams of Information Security Knowledge - [ ] [Joining Forces with RansomNews.com](https://ddanchev.blogspot.com/2026/08/joining-forces-with-ransomnewscom.html) - 风雪之隅 - [ ] [用Yac给WordPress做缓存:比Memcached快19%](https://www.laruence.com/2026/08/20/6420.html) - HackerNews - [ ] [Windows IKE 扩展组件高危远程代码执行漏洞已遭在野利用](http://0.0.0.0:8080/post/64578) - [ ] [美国起诉伊朗黑客,涉案 34 亿美元知识产权失窃案](http://0.0.0.0:8080/post/64577) - [ ] [医疗科技企业 CareCloud 数据泄露,波及 370 余万患者](http://0.0.0.0:8080/post/64576) - [ ] [恶意勒索软件附属团伙伪装成数据恢复企业骗取赎金](http://0.0.0.0:8080/post/64575) - [ ] [Sakura Internet 遭黑客入侵,最多 136 万账户数据存在泄露风险](http://0.0.0.0:8080/post/64574) - [ ] [美国警告:关键基础设施中正出现针对西门子 PLC 的 AI 驱动攻击](http://0.0.0.0:8080/post/64573) - 黑海洋Wiki | AI机器人硬件开发 | 网络安全攻防实战 | 区块链技术文档教程 - 免费资源平台 - [ ] [美国称黑客正借助AI攻击脆弱的供水系统](https://blog.upx8.com/%E7%BE%8E%E5%9B%BD%E7%A7%B0%E9%BB%91%E5%AE%A2%E6%AD%A3%E5%80%9F%E5%8A%A9AI%E6%94%BB%E5%87%BB%E8%84%86%E5%BC%B1%E7%9A%84%E4%BE%9B%E6%B0%B4%E7%B3%BB%E7%BB%9F) - [ ] [Waymo为其自动驾驶出租车定制了一款芯片](https://blog.upx8.com/Waymo%E4%B8%BA%E5%85%B6%E8%87%AA%E5%8A%A8%E9%A9%BE%E9%A9%B6%E5%87%BA%E7%A7%9F%E8%BD%A6%E5%AE%9A%E5%88%B6%E4%BA%86%E4%B8%80%E6%AC%BE%E8%8A%AF%E7%89%87) - [ ] [NASA“太空救援”任务失败,天文卫星将在年底前坠入地球大气层](https://blog.upx8.com/NASA-%E5%A4%AA%E7%A9%BA%E6%95%91%E6%8F%B4-%E4%BB%BB%E5%8A%A1%E5%A4%B1%E8%B4%A5-%E5%A4%A9%E6%96%87%E5%8D%AB%E6%98%9F%E5%B0%86%E5%9C%A8%E5%B9%B4%E5%BA%95%E5%89%8D%E5%9D%A0%E5%85%A5%E5%9C%B0%E7%90%83%E5%A4%A7%E6%B0%94%E5%B1%82) - [ ] [海威华芯与海特高新爆发“抢公章”闹剧](https://blog.upx8.com/%E6%B5%B7%E5%A8%81%E5%8D%8E%E8%8A%AF%E4%B8%8E%E6%B5%B7%E7%89%B9%E9%AB%98%E6%96%B0%E7%88%86%E5%8F%91-%E6%8A%A2%E5%85%AC%E7%AB%A0-%E9%97%B9%E5%89%A7) - [ ] [Meta悄然跻身微软最大AI客户,每年采购规模达数亿美元](https://blog.upx8.com/Meta%E6%82%84%E7%84%B6%E8%B7%BB%E8%BA%AB%E5%BE%AE%E8%BD%AF%E6%9C%80%E5%A4%A7AI%E5%AE%A2%E6%88%B7-%E6%AF%8F%E5%B9%B4%E9%87%87%E8%B4%AD%E8%A7%84%E6%A8%A1%E8%BE%BE%E6%95%B0%E4%BA%BF%E7%BE%8E%E5%85%83) - [ ] [骗子加大力度发iMessage钓鱼短信 新加坡受骗者损失金额近两周激增100万元](https://blog.upx8.com/%E9%AA%97%E5%AD%90%E5%8A%A0%E5%A4%A7%E5%8A%9B%E5%BA%A6%E5%8F%91iMessage%E9%92%93%E9%B1%BC%E7%9F%AD%E4%BF%A1-%E6%96%B0%E5%8A%A0%E5%9D%A1%E5%8F%97%E9%AA%97%E8%80%85%E6%8D%9F%E5%A4%B1%E9%87%91%E9%A2%9D%E8%BF%91%E4%B8%A4%E5%91%A8%E6%BF%80%E5%A2%9E100%E4%B8%87%E5%85%83) - [ ] [美国就算力期货交易公开征求意见](https://blog.upx8.com/%E7%BE%8E%E5%9B%BD%E5%B0%B1%E7%AE%97%E5%8A%9B%E6%9C%9F%E8%B4%A7%E4%BA%A4%E6%98%93%E5%85%AC%E5%BC%80%E5%BE%81%E6%B1%82%E6%84%8F%E8%A7%81) - 奇客Solidot–传递最新科技情报 - [ ] [海冰消失巨型鲸鱼进入格陵兰](https://www.solidot.org/story?sid=85151) - [ ] [AliExpress 被发现静默运行 WebAudio 指纹](https://www.solidot.org/story?sid=85150) - [ ] [Google 通过 Google Drive 提供 Android 特定源代码](https://www.solidot.org/story?sid=85149) - [ ] [AI 记录员捏造了患者服用迷幻蘑菇的经历](https://www.solidot.org/story?sid=85148) - [ ] [GitHub 公布本周八小时宕机事故原因](https://www.solidot.org/story?sid=85147) - [ ] [科学家首次实验观测到真空涨落对超导的增强效应](https://www.solidot.org/story?sid=85146) - [ ] [因 DRAM 和 eMMC 短缺 PINE64 暂停 Linux 设备生产](https://www.solidot.org/story?sid=85145) - [ ] [Stripe 以 75 亿美元收购 OpenRouter](https://www.solidot.org/story?sid=85144) - [ ] [X 算法向民主党用户推送更多激发愤怒的内容](https://www.solidot.org/story?sid=85143) - [ ] [NASA 终止 Swift 天文台的拯救任务](https://www.solidot.org/story?sid=85142) - 黑鸟 - [ ] [新型安卓恶意软件能借附近中毒手机偷偷外传数据](https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451188167&idx=1&sn=8f5d8f79dbe4ba99c383c46405599001) - 威努特安全网络 - [ ] [从“看见”到“研判”:看威努特AI安全态势感知如何落地实践](https://mp.weixin.qq.com/s?__biz=MzAwNTgyODU3NQ==&mid=2651143595&idx=1&sn=1a142c05f103a8fecdf6dbfa7c5143dc) - 微步在线研究响应中心 - [ ] [原创漏洞 | Wireshark Bluetooth AVRCP 解析器堆缓冲区溢出漏洞](https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&mid=2247508839&idx=1&sn=0e1f2177c941d178dacb82d2492d1850) - 我的安全视界观 - [ ] [【AI复盘】Anthropic Claude 入侵企业事件](https://mp.weixin.qq.com/s?__biz=MzI3Njk2OTIzOQ==&mid=2247487980&idx=1&sn=1c9cf534f84ddf916470634ade00463b) - 代码卫士 - [ ] [Citrix NetScaler 存在两个严重漏洞,无需凭证即可绕过认证机制](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247526935&idx=1&sn=07147e7ec3cbfb9ffe750a7853798e1e) - [ ] [思科:注意 CVSS 满分 Crosswork SQL 命令注入漏洞](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247526935&idx=2&sn=6df734eb52e6f93d21542cbc093f1c92) - 雷神众测 - [ ] [月满中秋,礼谢白帽|雷神众测中秋专属礼盒活动开启](https://mp.weixin.qq.com/s?__biz=MzI0NzEwOTM0MA==&mid=2652503918&idx=1&sn=1fa191244d844f37e0ae23f0f750f35b) - Shostack & Friends Blog - [ ] [Threat Modeling: A Second Edition](https://shostack.org/blog/threat-modeling-2nd-edition/) - 安全客 - [ ] [不打招呼直接锁死服务器:Sorry勒索病毒国内多点爆发,专挑中小企业下手](https://mp.weixin.qq.com/s?__biz=MzA5ODA0NDE2MA==&mid=2649790393&idx=1&sn=6981729b0c19403787fe35e1a20c94f3) - 安全内参 - [ ] [政务系统泄露全国大半民众数据,某国主管部门管理层全部辞职](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516460&idx=1&sn=28cfb5bd92fb01efff40c45a296535d2) - [ ] [美国陆军部双线推进AI智能体网络防御体系建设](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516460&idx=2&sn=e9b566c3acafc9d98fb34321ec2d04c3) - 奇安信 CERT - [ ] [【已复现】JeecgBoot 权限绕过与SQL注入组合漏洞(QVD-2026-56312)安全风险通告](https://mp.weixin.qq.com/s?__biz=MzU5NDgxODU1MQ==&mid=2247507173&idx=1&sn=31742a3353f86d4f518ddb16f2f7956f) - 信息安全国家工程研究中心 - [ ] [今日起,《网络数据安全风险评估办法》正式施行!](https://mp.weixin.qq.com/s?__biz=MzU5OTQ0NzY3Ng==&mid=2247504742&idx=1&sn=b7ab9f6eef064aecc8a3901b0b40e60c) - 微步在线 - [ ] [史上最炸裂演示!](https://mp.weixin.qq.com/s?__biz=MzI5NjA0NjI5MQ==&mid=2650187757&idx=1&sn=2ce100be66fedc739a55c7da0ceaf984) - 安全分析与研究 - [ ] [第15篇-勒索谈判与赎金支付分析](https://mp.weixin.qq.com/s?__biz=MzA4ODEyODA3MQ==&mid=2247497035&idx=1&sn=ce2803b5e4bee1f943e0c1fc33a1760f) - 安全圈 - [ ] [【安全圈】40款火狐扩展暗藏黑手:伪装Web3钱包洗劫加密资产](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078369&idx=1&sn=79e2862e15803decb3b7269b26094c80) - [ ] [【安全圈】CISA警告多项0day遭野外利用:涵盖macOS与微软组件](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078369&idx=2&sn=f702826e48d6e844afeb49bad9a1f7e9) - [ ] [【安全圈】Elementor Pro曝严重漏洞:未授权即可远程执行代码](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078369&idx=3&sn=1b94f45dc5a824daa1bf741c9527c26d) - 数世咨询 - [ ] [AI能找到零日漏洞 但仍无法写出安全的代码](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247543709&idx=1&sn=d66d30bc0cb3746783aed237926e8a72) - 默安科技 - [ ] [国家级认证+1!默安安全运营智能体入选网络安全优秀创新成果](https://mp.weixin.qq.com/s?__biz=MzIzODQxMjM2NQ==&mid=2247501978&idx=1&sn=3fa51e70dc73983dbcb474a4edb2a554) - 凌晨一点零三分 - [ ] [8月20日大饼等市场异常上涨复盘](https://mp.weixin.qq.com/s?__biz=MzIxMjI0Mzk0OQ==&mid=2247485740&idx=1&sn=35bb4d30435332cdf160ec8986ac4c3e) - 看雪学苑 - [ ] [2026 KCTF | 第六题《酉时·书院迷局》设计思路及解析](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458618817&idx=1&sn=b055cddcbb778da512e5bfe66578950f) - [ ] [Splunk批量修复17个高危漏洞,含9.1分MCP Server远程代码执行漏洞](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458618817&idx=2&sn=262cee74ca234824af3638c986cce363) - [ ] [冰与火的战歌:Windows内核攻防实战(附彩蛋课堂:命令行投毒)](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458618817&idx=3&sn=ce4c034a4ec3a0e8b0327f53a898b4c1) - 安全牛 - [ ] [账单暴增300%? AI助手越用越贵的真相:三个真实案例揭示如何把推理成本打下来](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142404&idx=1&sn=b3957ef6e5088461bed56cefffb385a1) - [ ] [《网络数据安全风险评估办法》今日实施;Google 为 Search 与 Gemini 上线多款 AI 学习工具,强化学生端 AI 能力 | 牛览](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142404&idx=2&sn=b620ee0484fb712e6ae8c0ae4516fdbf) - 极客公园 - [ ] [MiniMax,做视频领域的 Claude Code 的野心已经藏不住了](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653112369&idx=1&sn=93a4466622b59f1e8efe7d82bfbd663c) - [ ] [中国首次实现火箭陆地回收;宇树上市,市值最高超 4000 亿;蔡明同款机器人亮相,9.9 万元|极客早知道](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653112322&idx=1&sn=93875bb2ad4dd7d54f1c07e9257ea8e4) - 补天平台 - [ ] [中秋第三弹|专属SRC活动来袭,交漏洞领中秋礼盒!](https://mp.weixin.qq.com/s?__biz=MzI2NzY5MDI3NQ==&mid=2247510952&idx=1&sn=e8dc73985c029551083aa9ec891e4a03) - [ ] [中秋第二弹 | 公益活动上线,赠月圆好礼!](https://mp.weixin.qq.com/s?__biz=MzI2NzY5MDI3NQ==&mid=2247510952&idx=2&sn=b5c98ec2ff8d720e6f64d524f72594db) - [ ] [补天中秋系列活动第一弹|暖情中秋,众测相伴!](https://mp.weixin.qq.com/s?__biz=MzI2NzY5MDI3NQ==&mid=2247510952&idx=3&sn=c66739b0666b207149b2efc0cf521b0b) - 云鼎实验室 - [ ] [腾讯云鼎实验室助力百度安全“Agent+”攻防能力挑战赛](https://mp.weixin.qq.com/s?__biz=MzU3ODAyMjg4OQ==&mid=2247497904&idx=1&sn=2c4a7eaa8467f83087718d4dc684519b) - 字节跳动技术团队 - [ ] [豆包视频通话升级,火山引擎多模态传输系统提供技术支撑](https://mp.weixin.qq.com/s?__biz=MzI1MzYzMjE0MQ==&mid=2247521377&idx=1&sn=3d2f9e30616aa074c8d574c568903ba8) - 火绒安全 - [ ] [顽固文件、被占用文件如何处理?跟删不掉的文件说拜拜](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247536643&idx=1&sn=b1c48367d3929608dc75bb272519a739) - [ ] [诚邀渠道合作伙伴共启新征程](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247536643&idx=2&sn=f6863cee0c61a6402f5a264b54db2814) - 执经衡门 - [ ] [分享一个智能体安全的文章](https://mp.weixin.qq.com/s?__biz=MzUxMjkxMzY2OA==&mid=2247483886&idx=1&sn=475cbb194c81435a5896541a7a45844c) - 360数字安全 - [ ] [赋能东盟数智人才建设,360参与中印尼人工智能通识课共建项目](https://mp.weixin.qq.com/s?__biz=MzA4MTg0MDQ4Nw==&mid=2247586754&idx=1&sn=3316ade334356fc597f76eaef56dd867) - ChaMd5安全团队 - [ ] [新型 PLC 编程软件架构演进、安全风险分析](https://mp.weixin.qq.com/s?__biz=MzIzMTc1MjExOQ==&mid=2247514400&idx=1&sn=1d9e162dc68cee74825ccc93053b6351) - 丁爸 情报分析师的工具箱 - [ ] [【智库报告】美国专家又在误导世界认知](https://mp.weixin.qq.com/s?__biz=MzI2MTE0NTE3Mw==&mid=2651157017&idx=1&sn=ea77605ab19ad86d754b803979203093) - [ ] [【通知】第六届开源情报技术大会拟于2026年11月贵阳召开](https://mp.weixin.qq.com/s?__biz=MzI2MTE0NTE3Mw==&mid=2651157017&idx=2&sn=da73483b21391f975fdc1e1e96ca3fb4) - Qualys Security Blog - [ ] [CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days](https://blog.qualys.com/category/product-tech/vulnmgmt-detection-response) - 美团技术团队 - [ ] [美团搜索3.0:LLM 语义表征在排序模型的探索与应用](https://mp.weixin.qq.com/s?__biz=MjM5NjQ5MTI5OA==&mid=2651783185&idx=1&sn=0aab6d93f04e2c543903d6d6a4a98f88) - 青藤智库 - [ ] [【调研报告】10 余家政企用户实战复盘:AI 安全落地核心经验总结](https://mp.weixin.qq.com/s?__biz=MzUyOTkwNTQ5Mg==&mid=2247489491&idx=1&sn=8905223b43e3f58a70518a06ac371808) - 悬镜安全 - [ ] [安全牛十大产品创新:“问境+灵脉”系列持续引领智能体全生命周期安全治理!](https://mp.weixin.qq.com/s?__biz=MzA3NzE2ODk1Mg==&mid=2647800152&idx=1&sn=9b5a65cc1e62999d660ed2f985070f75) - 国家互联网应急中心CNCERT - [ ] [网络安全信息与动态周报2026年第33期(8月10日-8月16日)](https://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw==&mid=2247502033&idx=1&sn=5122ac425e588c49bc2713f7c2996c5d) - IntelTechniques by Michael Bazzell - [ ] [Free PDF Self-Publishing Guide](https://inteltechniques.com/publishing.html) - Over Security - [ ] [Someone targeted security researchers using a fake crypto conference as a lure](https://techcrunch.com/2026/08/20/someone-targeted-security-researchers-using-a-fake-crypto-conference-as-a-lure/) - [ ] [China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware](https://therecord.media/china-cyber-espionage-central-asia) - [ ] [Is Cyber missing the Marque?](https://blog.talosintelligence.com/is-cyber-missing-the-marque/) - [ ] [Hackers poison arrayref Rust crate to push infostealer malware](https://www.bleepingcomputer.com/news/security/hackers-poison-arrayref-rust-crate-to-push-infostealer-malware/) - [ ] [Senators press TikTok over withholding of safety features for some users](https://therecord.media/senators-press-tiktok-over-withholding-safety-features) - [ ] [Critical Elementor Pro bug exposes WordPress sites to RCE attacks](https://www.bleepingcomputer.com/news/security/critical-elementor-pro-bug-exposes-wordpress-sites-to-rce-attacks/) - [ ] [Insider Threat Report: Dark Web Recruitment & Access Trends](https://flashpoint.io/blog/insider-threat-report-dark-web-recruitment-access-trends/) - [ ] [How MSPs can catch phishing attacks email filters miss](https://www.bleepingcomputer.com/news/security/how-msps-can-catch-phishing-attacks-email-filters-miss/) - [ ] [Phishing Klarna: crescita vertiginosa](https://www.d3lab.net/phishing-klarna-crescita-vertiginosa/) - [ ] [How Easy Is It to Scan a Contactless Payment and Access Card?](https://www.mobile-hacker.com/2026/08/20/how-easy-is-it-to-scan-a-contactless-payment-and-access-card/) - [ ] [Citrix urges admins to patch new NetScaler flaws as soon as possible](https://www.bleepingcomputer.com/news/security/citrix-urges-admins-to-patch-new-netscaler-flaws-as-soon-as-possible/) - [ ] [Sanità sotto attacco: il ritorno a bit e carta, quasi una battaglia di altri tempi. Il caso Romania](https://www.cybersecurity360.it/nuove-minacce/ransomware/sanita-sotto-attacco-il-ritorno-a-bit-e-carta-quasi-una-battaglia-di-altri-tempi-il-caso-romania/) - [ ] [CISA warns of hackers exploiting critical MLflow vulnerability](https://www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploiting-critical-mlflow-vulnerability/) - [ ] [Guild Group’s Mohammad Arif on the Security Risks of Enterprise AI](https://thecyberexpress.com/the-cyber-express-mohammad-arif-interview/) - [ ] [Dalla crittografia zero-knowledge alla protezione post-quantistica: l’evoluzione della tutela dei dati personali nel cloud europeo](https://www.cybersecurity360.it/cultura-cyber/cloud-storage-zero-knowledge-crittografia-dati-personali/) - [ ] [New Manic Android malware can exfiltrate data through nearby devices](https://www.bleepingcomputer.com/news/security/new-manic-android-malware-can-exfiltrate-data-through-nearby-devices/) - [ ] [UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations](https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/) - [ ] [UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities](https://blog.talosintelligence.com/uat-10147-deploys-spectre-a-cross-platform-implant-with-linux-rootkit-and-byovd-capabilities/) - [ ] [Critical Zimbra RCE flaw now actively exploited in attacks](https://www.bleepingcomputer.com/news/security/critical-zimbra-rce-flaw-now-actively-exploited-in-attacks/) - [ ] [Archiviazione dati permanente e sovranità digitale: l’evoluzione dei modelli di storage cloud senza abbonamento](https://www.cybersecurity360.it/cultura-cyber/cloud-storage-a-vita-crittografia-sicurezza-dati-personali/) - [ ] [Manic: Blend between Banking Malware & Spyware](https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spyware) - [ ] [North Korean IT Workers Scheme: Detection IOCs and Tactics for Government and Corporate SOCs](https://any.run/cybersecurity-blog/how-to-protect-organization-against-north-korean-it-workers/) - [ ] [Sanità sotto attacco: il ritorno a bit e carta, quasi una battaglia di altri tempi. Il caso Bulgaria](https://www.cybersecurity360.it/nuove-minacce/ransomware/sanita-sotto-attacco-il-ritorno-a-bit-e-carta-quasi-una-battaglia-di-altri-tempi-il-caso-bulgaria/) - [ ] [One Adversary: Fraud Is a Network, Not a Payment](https://www.group-ib.com/blog/one-adversary-fraud-network/) - [ ] [Zero Trust nei sistemi OT: dalla teoria all’applicazione, ecco le 5 aree di rischio prioritarie](https://www.cybersecurity360.it/soluzioni-aziendali/zero-trust-nei-sistemi-ot-dalla-teoria-allapplicazione-ecco-le-5-aree-di-rischio-prioritarie/) - [ ] [Microsoft says August Windows updates may cause gaming issues](https://www.bleepingcomputer.com/news/microsoft/microsoft-august-windows-updates-may-cause-gaming-issues-reboots/) - [ ] [Oz Hair and Beauty Data Breach Exposes Customer Information](https://thecyberexpress.com/oz-hair-and-beauty-data-breach/) - [ ] [BTMOB Exposed: Inside a Fraud-as-a-Service Platform with 1400+ live servers](https://blog.quimerax.com/btmob-exposed-inside-a-fraud-as-a-service-platform-with-1400-live-servers/) - [ ] [OpenAI confirms ChatGPT is down as logins and signups fail](https://www.bleepingcomputer.com/news/artificial-intelligence/openai-confirms-chatgpt-is-down-as-logins-and-signups-fail/) - Schneier on Security - [ ] [Detailed Timeline of OpenAI’s Cyberattack on Hugging Face](https://www.schneier.com/blog/archives/2026/08/detailed-timeline-of-openais-cyberattack-on-hugging-face.html) - [ ] [Police Are Hiding Their Use of Flock Surveillance Cameras](https://www.schneier.com/blog/archives/2026/08/police-are-hiding-their-use-of-flock-surveillance-cameras.html) - D3Lab - [ ] [Phishing Klarna: crescita vertiginosa](https://www.d3lab.net/phishing-klarna-crescita-vertiginosa/) - Future of Tech and Security: Strategy & Innovation with Raffy - [ ] [What Belongs Inside the Company AI Operating System?](https://raffy.ch/blog/2026/08/20/what-belongs-inside-the-company-ai-operating-system/) - bellingcat - [ ] [Satellite Imagery Documents New Border Patrol Road Construction in Big Bend National Park](https://www.bellingcat.com/news/us-canada/2026/08/20/satellite-imagery-documents-new-border-patrol-road-construction-in-big-bend-national-park/) - Daniel Miessler - [ ] [I Only Do Anything Once](https://danielmiessler.com/blog/i-only-do-anything-once?utm_source=rss&utm_medium=feed&utm_campaign=website) - Instapaper: Unread - [ ] [Reverse-Lookup Service Exposed Millions of Photos of People’s Faces](https://www.wired.com/story/reverse-lookup-service-exposed-millions-of-photos-of-peoples-faces/) - [ ] [Spyware, Apple invia una “notifiche di minaccia” agli utenti in 110 Paesi](https://www.cybersecitalia.it/spyware-apple-invia-una-notifiche-di-minaccia-agli-utenti-in-110-paesi/68673/) - [ ] [Come funziona e-Evidence in Italia prove digitali, tempi e garanzie](https://www.agendadigitale.eu/documenti/giustizia-digitale/come-funziona-e-evidence-in-italia-prove-digitali-tempi-e-garanzie/) - [ ] [Android come raccogliere bug report, Debug Logs e Log anti-intrusioni](https://www.forenser.it/android-come-raccogliere-bug-report-debug-logs-e-log-anti-intrusioni/) - The Hacker News - [ ] [Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads](https://thehackernews.com/2026/08/rust-supply-chain-attack-puts-build.html) - [ ] [Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts](https://thehackernews.com/2026/08/suspected-russian-hackers-abuse-google.html) - [ ] [ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More](https://thehackernews.com/2026/08/threatsday-gogs-100-rce-n8n-workflow-to.html) - [ ] [AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure](https://thehackernews.com/2026/08/ai-generated-exploit-scripts-target.html) - [ ] [New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data](https://thehackernews.com/2026/08/new-cryptographic-context-injection.html) - [ ] [Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE](https://thehackernews.com/2026/08/isolated-vm-flaw-lets-sandboxed.html) - [ ] [Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers](https://thehackernews.com/2026/08/critical-netscaler-flaw-can-bypass.html) - [ ] [Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution](https://thehackernews.com/2026/08/attackers-exploit-zimbra-snmp-flaw-for.html) - [ ] [Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments](https://thehackernews.com/2026/08/zombie-card-attack-can-revive-expired.html) - [ ] [Why "Shady AI" is Security's Next Big Governance Problem](https://thehackernews.com/2026/08/why-shady-ai-is-securitys-next-big.html) - [ ] [CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification](https://thehackernews.com/2026/08/cdn-tsunami-attack-abuses-http3.html) - [ ] [Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices](https://thehackernews.com/2026/08/manic-android-malware-exfiltrates-data.html) - [ ] [NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands](https://thehackernews.com/2026/08/nasa-ait-gui-flaws-could-let.html) - [ ] [ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud](https://thehackernews.com/2026/08/toxicpanda-20-and-golddigger-expand.html) - [ ] [40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets](https://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-as.html) - [ ] [Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code](https://thehackernews.com/2026/08/elementor-pro-flaw-could-let.html) - Security Affairs - [ ] [Manic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline](https://securityaffairs.com/197570/malware/manic-the-android-malware-that-exfiltrates-data-even-when-the-phone-is-offline.html) - [ ] [NSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCs](https://securityaffairs.com/197566/ics-scada/nsa-cisa-fbi-doe-and-epa-warn-of-active-ai-assisted-attacks-on-siemens-s7-plcs.html) - [ ] [U.S. CISA adds an MLflow flaw to its Known Exploited Vulnerabilities catalog](https://securityaffairs.com/197558/hacking/u-s-cisa-adds-a-mlflow-flaw-to-its-known-exploited-vulnerabilities-catalog.html) - [ ] [US Indicts 17 Iranians Over Years-Long Cyber Espionage Campaign](https://securityaffairs.com/197551/intelligence/us-indicts-17-iranians-over-years-long-cyber-espionage-campaign.html) - [ ] [StopAndProtect Turns 2,000 Hacked WordPress Sites Into a Criminal Network](https://securityaffairs.com/197537/hacking/stopandprotect-turns-2000-hacked-wordpress-sites-into-a-criminal-network.html) - www.theregister.com - Articles - [ ] [US Bank investigates LockBit's claims as ransomware crims set pay-or-leak deadline](https://www.theregister.com/security/2026/08/20/us-bank-investigates-lockbits-claims-as-ransomware-crims-set-pay-or-leak-deadline/5290560) - [ ] [Researcher tricks Apple’s Find My into sharing location data with Linux](https://www.theregister.com/security/2026/08/20/researcher-tricks-apples-find-my-into-sharing-location-data-with-linux/5290496) - [ ] [Ransomware crook poses as recovery firm to steal payments from fellow extortionists](https://www.theregister.com/cyber-crime/2026/08/20/ransomware-crook-poses-as-recovery-firm-to-steal-payments-from-fellow-extortionists/5290344) - [ ] [Grok chat duped into swallowing injected instructions](https://www.theregister.com/ai-and-ml/2026/08/20/grok-chat-duped-into-swallowing-injected-instructions/5290019) - [ ] [French tax authority says break-in exposed data of 600K, including some private messages](https://www.theregister.com/security/2026/08/20/french-tax-authority-says-break-in-exposed-data-of-600k-including-some-private-messages/5290249) - [ ] [AI agent suggested installing a malware package. Engineer almost took its advice](https://www.theregister.com/security/2026/08/20/ai-agent-suggested-installing-a-malware-package-engineer-almost-took-its-advice/5289849) - Computer Forensics - [ ] [When is an EDR download actually worth ordering?](https://www.reddit.com/r/computerforensics/comments/1vtalim/when_is_an_edr_download_actually_worth_ordering/) - KitPloit - PenTest Tools! - [ ] [opensoho v0.15.0](https://kitploit.com/en/posts/github-rubenbe-opensoho-v0150) - [ ] [caido v0.58.0](https://kitploit.com/en/posts/github-caido-caido-v0580) - [ ] [DockSec v2026.8.19](https://kitploit.com/en/posts/github-owasp-docksec-v2026819) - [ ] [forensictools v1.4](https://kitploit.com/en/posts/github-cristianzsh-forensictools-v14) - [ ] [faraday v5.23.2](https://kitploit.com/en/posts/github-infobyte-faraday-v5232) - [ ] [jumpserver v4.10.19](https://kitploit.com/en/posts/github-jumpserver-jumpserver-v41019) - [ ] [faction v1.8.13](https://kitploit.com/en/posts/github-factionsecurity-faction-1813) - [ ] [strelka v1.0.2](https://kitploit.com/en/posts/github-target-strelka-v102) - [ ] [numa v0.23.0](https://kitploit.com/en/posts/github-razvandimescu-numa-v0230) - [ ] [PCAPdroid v2.0.0](https://kitploit.com/en/posts/github-emanuele-f-pcapdroid-v200) - [ ] [cloudquery plugins-destination-snowflake-v5.2.14](https://kitploit.com/en/posts/github-cloudquery-cloudquery-plugins-destination-snowflake-v5214) - [ ] [BLAKE3 v1.8.7](https://kitploit.com/en/posts/github-blake3-team-blake3-187) - [ ] [Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis](https://kitploit.com/en/tools/github/kaandemir993/dropper-gcleaner-c2-infrastructure-kernel-driver-powershell-conhost-payload-analysis) - [ ] [wasm2c-tableflip](https://kitploit.com/en/tools/github/trustsig-eu/wasm2c-tableflip) - [ ] [fnprint](https://kitploit.com/en/tools/github/1rhino2/fnprint) - [ ] [lg-webos-kexec](https://kitploit.com/en/tools/github/ggfuchsi-oss/lg-webos-kexec) - [ ] [reconkg](https://kitploit.com/en/tools/github/xghst0/reconkg) - [ ] [File-Tunnel v3.5.2](https://kitploit.com/en/posts/github-fiddyschmitt-file-tunnel-v352) - [ ] [context-aware-offensive-intelligence](https://kitploit.com/en/tools/github/indoushka/context-aware-offensive-intelligence) - [ ] [Zapscape-Fix — Updated!](https://kitploit.com/en/posts/github-aoripus-ltd-zapscape-fix-6ddb101966d4021f6585a7550b3c716a6d9adbb0be052ff4d62d187783e0af39) - [ ] [audit-kernel v7.2](https://kitploit.com/en/posts/github-linux-audit-audit-kernel-72) - [ ] [linux v7.2](https://kitploit.com/en/posts/github-torvalds-linux-72) - [ ] [lsPass](https://kitploit.com/en/tools/gitlab/leestripp/lspass) - [ ] [LeakGauge](https://kitploit.com/en/tools/github/yeasen-z/leakgauge) - [ ] [BloodBash](https://kitploit.com/en/tools/github/squidsec/bloodbash) - [ ] [iron-proxy](https://kitploit.com/en/tools/github/paradigmxyz/iron-proxy) - [ ] [sentrymcp](https://kitploit.com/en/tools/github/zaydmulani09/sentrymcp) - [ ] [SecureAI-Scan v0.10.0](https://kitploit.com/en/posts/github-akanthed-secureai-scan-v0100) - [ ] [Antiphishing v32278722593](https://kitploit.com/en/posts/github-julioliraup-antiphishing-release-32278722593) - [ ] [kin v0.5.42](https://kitploit.com/en/posts/github-firelock-ai-kin-v0542) - [ ] [Specter-FlipperZero v2.7](https://kitploit.com/en/posts/github-at0m-b0mb-specter-flipperzero-v27) - [ ] [radmin-vpn-linux v1.1.0](https://kitploit.com/en/posts/github-baptisterajaut-radmin-vpn-linux-v110) - [ ] [prismor v1.43.0](https://kitploit.com/en/posts/github-prismorsec-prismor-v1430) - [ ] [agentic-threat-hunting-framework v0.19.0](https://kitploit.com/en/posts/github-nebulock-inc-agentic-threat-hunting-framework-v0190) - [ ] [so-crates v4.0.0](https://kitploit.com/en/posts/github-dougburks-so-crates-v400) - [ ] [xalgorix v4.5.153](https://kitploit.com/en/posts/github-xalgord-xalgorix-v45153) - [ ] [vigolium v0.4.3](https://kitploit.com/en/posts/github-vigolium-vigolium-v043) - [ ] [akto v2.20.1](https://kitploit.com/en/posts/github-akto-api-security-akto-v2201) - [ ] [sysreptor v2026.68](https://kitploit.com/en/posts/github-syslifters-sysreptor-202668) - [ ] [agent-scan v0.6.0](https://kitploit.com/en/posts/github-snyk-agent-scan-v060) - [ ] [nono v0.74.0](https://kitploit.com/en/posts/github-nolabs-ai-nono-v0740) - [ ] [cvelistV5 cve_2026-08-20_0000Z](https://kitploit.com/en/posts/github-cveproject-cvelistv5-cve_2026-08-20_0000z) - [ ] [codex-security npm-v0.1.15](https://kitploit.com/en/posts/github-openai-codex-security-npm-v0115) - [ ] [sshroute v0.2.11](https://kitploit.com/en/posts/github-thereisnotime-sshroute-v0211) - [ ] [arkime v6.7.0](https://kitploit.com/en/posts/github-arkime-arkime-v670) - [ ] [DOMPurify v3.4.14](https://kitploit.com/en/posts/github-cure53-dompurify-3414) - [ ] [screenpipe app-v2.6.64](https://kitploit.com/en/posts/github-screenpipe-screenpipe-app-v2664) - SANS Internet Storm Center, InfoCON: green - [ ] [Using Microsoft Graph and Powershell - Risk Detection Commands, (Thu, Aug 20th)](https://isc.sans.edu/diary/rss/33266) - [ ] [Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses, (Thu, Aug 20th)](https://isc.sans.edu/diary/rss/33264) - [ ] [ISC Stormcast For Thursday, August 20th, 2026 https://isc.sans.edu/podcastdetail/10060, (Thu, Aug 20th)](https://isc.sans.edu/diary/rss/33262) - Full Disclosure - [ ] [[0day-rubbish] VMS 6.48.809 Authenticated command injection to root RCE (8.8)](https://seclists.org/fulldisclosure/2026/Aug/76) - [ ] [[0day-rubbish] ONE Reporter 13.1 Authenticated RCE / privilege escalation via CommandExecutor (8.8)](https://seclists.org/fulldisclosure/2026/Aug/75) - [ ] [[0day-rubbish] Gemini 7.3.0 Authenticated SQL injection to xp_cmdshell RCE (8.8)](https://seclists.org/fulldisclosure/2026/Aug/74) - [ ] [[0day-rubbish] RoboTask 11.0.5.1229 Unauthenticated REST API remote task execution (9.8)](https://seclists.org/fulldisclosure/2026/Aug/73) - [ ] [[0day-rubbish] ActiveFax Server 10.70 Unauthenticated LPD Ghostscript %pipe% SYSTEM RCE (9.8)](https://seclists.org/fulldisclosure/2026/Aug/72) - [ ] [[0day-rubbish] Tornado 2.11.3 Unauthenticated arbitrary file write to root RCE (storeTo=file: to cron) (9.8)](https://seclists.org/fulldisclosure/2026/Aug/71) - [ ] [[0day-rubbish] Datalore On-Premises 2026.2.3 Unauthenticated RCE via InteractiveReport access-mapping flaw (9.8)](https://seclists.org/fulldisclosure/2026/Aug/70) - [ ] [APPLE-SA-08-18-2026-1 Safari 26.6.1](https://seclists.org/fulldisclosure/2026/Aug/69) - [ ] [Cudy WR3000: Hard-coded JWT Secret to Root Command Injection](https://seclists.org/fulldisclosure/2026/Aug/68) - TorrentFreak - [ ] [‘Filmmaker’ Who Sued PTP, BTN, and Four Other Private Torrent Trackers May Be an Impostor](https://torrentfreak.com/filmmaker-who-sued-ptp-btn-and-four-other-private-torrent-trackers-may-be-an-impostor/) - Security Weekly Podcast Network (Audio) - [ ] [Rejoice In The Nostalgia - PSW #940](http://sites.libsyn.com/18678/rejoice-in-the-nostalgia-psw-940)
每日安全资讯(2026-08-21)