# 每日安全资讯(2026-08-06) - Paper - 知道创宇404实验室 - [ ] [MIRAGE:通过用户生成内容对移动 GUI 智能体进行上下文感知的提示注入](https://paper.seebug.org/3510) - SecWiki News - [ ] [SecWiki News 2026-08-05 Review](http://www.sec-wiki.com/?2026-08-05) - Doonsec's feed - [ ] [读书笔记 0805](https://mp.weixin.qq.com/s/it4qFHP21jV1BikiGm-6wg) - [ ] [关于最近的事情的澄清和道歉](https://mp.weixin.qq.com/s/j1ubNJvLbimhDJpaO_DpJA) - [ ] [【8月交易训练营招生】交易一对一陪跑:不带单,把你从持续亏损带到能独立下单](https://mp.weixin.qq.com/s/GW878WdZYzc1hXaKnEO5ag) - [ ] [原材料行业工业智能体研究报告(2026版)(征求意见版)发布](https://mp.weixin.qq.com/s/payvAovK8s98JiEkmfZxVg) - [ ] [金牌酒店服务员上岗!人形机器人宾客服务岗比赛规则揭秘](https://mp.weixin.qq.com/s/mgE_JYSSjEzGvgtLo4-sjg) - [ ] [高危救援不用真人?人形机器人消防救援岗比赛规则揭秘](https://mp.weixin.qq.com/s/2X3b_uIxpo9kSrWcc4de5g) - [ ] [中国软件评测中心启动智能制造效能评测试点工作](https://mp.weixin.qq.com/s/IGXh4US4NRTrVVkv8jpUCw) - [ ] [行业资讯 | 千万大单又现,网络安全项目中标情况汇总(8月5日)](https://mp.weixin.qq.com/s/IhrFdlaxIOfg1izpACWDUg) - [ ] [KDD 2026|快手PlatformBid:从单广告主最优到平台全局共赢](https://mp.weixin.qq.com/s/dEbmXGjRoKlRZKFTdeZDPw) - [ ] [AI快讯:字节推出全双工多模态大模型,马斯克宣布SpaceX将全面采用英伟达架构](https://mp.weixin.qq.com/s/dc-pVm-HKMucLKkISzi5dg) - [ ] [连漏洞扫描都不懂就想挖漏洞找工作?!这篇“保姆级”原理拆解别再错过了!](https://mp.weixin.qq.com/s/cwHANUxLQE1s-p_5FvCnsw) - [ ] [网络安全动态 - 2026.8.5](https://mp.weixin.qq.com/s/a45h3cqLe3CBSWySnYfF9Q) - [ ] [AI × SAST:多 Agent 告警复核系统建设实践](https://mp.weixin.qq.com/s/g4mt_Dn6k9B4EM6o4FBtZQ) - [ ] [2026年“中国(广西)—东盟人工智能安全攻防大赛”公告](https://mp.weixin.qq.com/s/2KkN5dvDt50pe2YFi8NWyg) - [ ] [双线招募|长期驻场/ 短期中高持续招人](https://mp.weixin.qq.com/s/_-h6b3FMvZTTHdI1YIqONA) - [ ] [【驻场专栏】8月第一周|全国长期驻场岗位汇总](https://mp.weixin.qq.com/s/acpHG5HxxTPW-5o9wLPeWg) - [ ] [《智能网联汽车 自动驾驶系统安全要求》强制性国家标准发布,拟于2027年7月1日起实施](https://mp.weixin.qq.com/s/NFVqDGjgcL-pZ_uIRspNcg) - [ ] [涉灾谣言干扰大局 虚构政策误导公众 多部门重拳整治造谣传谣行为](https://mp.weixin.qq.com/s/zTJA_Lmqf9crCEp8bq9xmA) - [ ] [美方如何威胁中国航母](https://mp.weixin.qq.com/s/BItSn0sIpJFmu4sVR5u8WA) - [ ] [BurpSuite 安装激活及使用教程](https://mp.weixin.qq.com/s/FqBlhArd-rNMVDDoSTMLMA) - [ ] [Hugging Face遭入侵并非纯AI自主,天融信对话央视:大模型安全应同步建设](https://mp.weixin.qq.com/s/kPNJWKN0pXxmsLOObrsFxg) - [ ] [安全透视 | 数据安全的“最后一公里”:API](https://mp.weixin.qq.com/s/1r2PmnC7aT33ozv2X5gUOQ) - [ ] [护网—2026 |“合作合同”暗藏远控木马 网警紧急阻断境外钓鱼攻击](https://mp.weixin.qq.com/s/1b6SZh2Vxyn4t9WsGZHKaQ) - [ ] [史上最冤打工人:AI 闯祸,我来背锅](https://mp.weixin.qq.com/s/axwtuitn4DX0dmm_gZcmyA) - [ ] [判了!5年10个月——员工用代码17小时删光公司89TB数据](https://mp.weixin.qq.com/s/Ho9QTl3hL6Kbw-IW2Adl0g) - [ ] [三个月,如何从零基础到亲手打造出你的AI攻防/代码审计智能体?](https://mp.weixin.qq.com/s/2s_boozRxCLhQhMNX2xk6g) - [ ] [Linuxxa0Kernelxa0SCTPxa0\"SCTPhantom\"xa0本地权限提升漏洞风险预警](https://mp.weixin.qq.com/s/lu1ihodwp1bq45U235uT4A) - [ ] [动态|工业和信息化部公布2025年工业互联网“链网协同”典型案例名单](https://mp.weixin.qq.com/s/QBXk_iZj8Hpc4qM0cFz3Rg) - [ ] [动态|第六届全国密码科普竞赛圆满落幕](https://mp.weixin.qq.com/s/AoPPaMPyt4b7nfJAm1mSJQ) - [ ] [动态丨天融信AI智能体安全评估服务抢“鲜”发布!](https://mp.weixin.qq.com/s/IuW_bkNHjem6MO8wzShwrQ) - [ ] [工联安全大讲堂第三十八期即将开讲!](https://mp.weixin.qq.com/s/9KGz6xhHgPlTMbmuhHzO_A) - [ ] [原来计算机专业,有这么多牛X证书可以考啊!](https://mp.weixin.qq.com/s/hyoHol8i45kk_LB2ax1ghA) - [ ] [关于规范AI辅助漏洞报告提交及违规处置的公告](https://mp.weixin.qq.com/s/HzzEouhFhf9i_zlvc82Odg) - [ ] [iOS27 beta5延迟发布,未必是坏事](https://mp.weixin.qq.com/s/38RbH4lr4544-khkUOjAcQ) - [ ] [北京边界无限招聘多个安全岗位](https://mp.weixin.qq.com/s/B0qlxbZ4F5RQHjnGjdShVg) - [ ] [深耕聚焦 奋楫前行——迪普科技2026上半年成绩单](https://mp.weixin.qq.com/s/_yytzPhfOju4YCI7aLbalw) - [ ] [NPM 蠕虫式投毒Shai-Hulud再次来袭,keyv 与 cacheable多个周下载量数亿次组件受影响](https://mp.weixin.qq.com/s/34uap2Ly3565ia3gAtqKpQ) - [ ] [《新一代自动化渗透测试工具与应用指南》重磅发布](https://mp.weixin.qq.com/s/KgBWblGk2Hm5sM8ED3uQqA) - [ ] [欧盟AI法案正式落地,通用大模型与AI生成内容纳入强制监管;自动驾驶强制性国标正式发布,全生命周期安全规范补齐车联网安全短板| 牛览](https://mp.weixin.qq.com/s/tKLIZzqQ8K6qiG5h67tTzw) - [ ] [在一个女生短袖身上发现了这个图案,这绝对是个女网工](https://mp.weixin.qq.com/s/ISaYo_HsotNsYUTKeBkktg) - [ ] [TencentOS 科维斯AI首秀:SCTPhantom——潜伏18年的Linux内核提权与容器逃逸漏洞](https://mp.weixin.qq.com/s/v4kFYfoO4aFhE-pSpnr7qg) - [ ] [2026硬核成果丨自主研发,毫秒级响应!国际大厂抢滩的赛道,中国企业已交出答卷](https://mp.weixin.qq.com/s/NEVsUxomeBXeyJY4UEj6gw) - [ ] [高危端口大开、数据面临泄露风险 网警依法查处一未依法履行网络安全保护义务案](https://mp.weixin.qq.com/s/yTG_X-1jDwQf6sXZviv-zA) - [ ] [网络安全日报 | 2026-08-05](https://mp.weixin.qq.com/s/of8nhQp2iF6dZ-ZHG0jB0g) - [ ] [浦发银行AI应用推动会议:要体系化规划“人工智能”工程](https://mp.weixin.qq.com/s/SwO6pY9Qdx6AG3tncZ-xMQ) - [ ] [《中国信息安全》杂志2026年第7期目录](https://mp.weixin.qq.com/s/bfam8aGMSwrH0MC0JyI-uA) - [ ] [赛普EAP企业适配管理平台 AppData.ashx SQL注入漏洞](https://mp.weixin.qq.com/s/mzdFpgDEYH1XriH-C0Xtcw) - [ ] [当你下载的“开源模型”本身就是一个后门:一次微调投毒实验全记录](https://mp.weixin.qq.com/s/I7Vrre6EqSlJbiMXDUc_3g) - [ ] [捷报 | 边界无限成功中标某证券公司RASP项目](https://mp.weixin.qq.com/s/OsV0Tvze7mYpOL_P5iIeNA) - [ ] [微信小程序全自动化渗透工具 -- WMP-pentest-automation](https://mp.weixin.qq.com/s/ySAn3ymFWbDQ1bSKei-_pw) - [ ] [天才只是见我的门槛,他们的智慧为我所用](https://mp.weixin.qq.com/s/0j6x3IytWrOS_T0MxZaLCg) - [ ] [Passkey不再安全?谷歌密钥可被静默劫持](https://mp.weixin.qq.com/s/ibEi3Kr6HnQWS9DHA1iOpQ) - [ ] [当漏洞发现进入“机器速度”,CISO该改什么?](https://mp.weixin.qq.com/s/u3tTS7PBrRbwCe3kBKrpRA) - [ ] [天才](https://mp.weixin.qq.com/s/3CqtOpTlObmIdBcU7u6vCg) - [ ] [招聘 | 渗透测试工程师](https://mp.weixin.qq.com/s/vIiUoXueYcbuAPDNhyL4fg) - [ ] [sci论文一直投不中?大牛帮指导选刊投稿返修后,被拒的SCI全中了!](https://mp.weixin.qq.com/s/nXztzzKp-odN_lsm6e3X0w) - [ ] [中国版Claude Mythos!直击企业5大顾虑,解析“零团队”落地恒脑AI代码审计路径](https://mp.weixin.qq.com/s/bOB7m-aDyjraxfI3FdcOUA) - [ ] [安恒信息董事长范渊一行到杭钢洽谈交流](https://mp.weixin.qq.com/s/pX7zfDeGHx-3_Jk9goayKA) - [ ] [分享的图片、视频、链接](https://mp.weixin.qq.com/s/LqApYsTUjZPAYyeoSvs72Q) - [ ] [CVE-2026-64633 漏洞:Veeam ONE 未授权远程代码执行,CVSS 评分达到满分 10.0](https://mp.weixin.qq.com/s/fGYMPITkt2_RpXlQW0QZWw) - [ ] [存在22年的 BMC 漏洞使数千个数据中心面临攻击](https://mp.weixin.qq.com/s/_VrAlxmN-zEhUdtnr3jeZA) - [ ] [SharePoint漏洞被用于攻击瑞士联邦信息技术机构](https://mp.weixin.qq.com/s/8lgWXOihsVT3HSa6pHgMzg) - [ ] [从五起数据泄露事件看数据安全趋势](https://mp.weixin.qq.com/s/-drgKA8Tfqihat59RbLp_g) - [ ] [浙商银行智能体基础软硬件采购](https://mp.weixin.qq.com/s/4ZK21Sq2CT-BiSe1QfrMAQ) - [ ] [京东科技98万中!北京银行大模型安全网关建设项目](https://mp.weixin.qq.com/s/XC70-HYLzRv9_EWUS1cXRg) - [ ] [网络安全风险评估管理制度](https://mp.weixin.qq.com/s/PNFNQDqv0J0CFCfn8zkMAw) - [ ] [第四届黄河流域公安院校电子物证个人赛程序逆向分析](https://mp.weixin.qq.com/s/oY1KBxskepgWKGL0HVv1TA) - [ ] [第四届黄河流域公安院校电子物证个人赛服务器取证](https://mp.weixin.qq.com/s/mDAjlRUTM-AS3qgj2GaL-w) - [ ] [行业资讯 | 百万级项目明显增加,网络安全项目中标情况汇总(8月4日)](https://mp.weixin.qq.com/s/HZh-vht0LMjmNBjfKaJdCQ) - [ ] [产业资讯|美国拟起草新规,限制进口中国新款光模块](https://mp.weixin.qq.com/s/Hz7Ik_QbNchpUOiDkz5OgQ) - Hacking Articles - [ ] [Impacket for Pentester: reg](https://www.hackingarticles.in/impacket-for-pentester-reg/) - 安全客-有思想的安全新媒体 - [ ] [Vibe Hacking风起云涌:安全圈的门槛正在塌方?](https://www.anquanke.com/post/id/315927) - Private Feed for M09Ic - [ ] [mitre-attack released v19.2 at mitre-attack/attack-stix-data](https://github.com/mitre-attack/attack-stix-data/releases/tag/v19.2) - [ ] [bolucat released 202608052143 at bolucat/Archive](https://github.com/bolucat/Archive/releases/tag/202608052143) - [ ] [kpcyrd starred kpcyrd/hussh](https://github.com/kpcyrd/hussh) - [ ] [Rvn0xsy starred xicilion/boxsh](https://github.com/xicilion/boxsh) - [ ] [kpcyrd contributed to kpcyrd/rebuilderd](https://github.com/kpcyrd/rebuilderd/pull/257) - [ ] [gh0stkey forked HACK-THE-WORLD/vscode-unify-chat-provider from smallmain/vscode-unify-chat-provider](https://github.com/HACK-THE-WORLD/vscode-unify-chat-provider) - [ ] [liamg contributed to infracost/config](https://github.com/infracost/config/pull/26) - [ ] [gh0stkey starred overspace-labs/HaESkill](https://github.com/overspace-labs/HaESkill) - [ ] [wabzsy starred tanweai/pua](https://github.com/tanweai/pua) - [ ] [Mel0day starred earendil-works/pi](https://github.com/earendil-works/pi) - [ ] [OpenAEV-Platform released 3.260805.0 at OpenAEV-Platform/openaev](https://github.com/OpenAEV-Platform/openaev/releases/tag/3.260805.0) - [ ] [niudaii starred uditgoenka/autoresearch](https://github.com/uditgoenka/autoresearch) - [ ] [shmilylty starred alphadl/proxifier_code](https://github.com/alphadl/proxifier_code) - [ ] [timwhitez starred sky-valley/pi](https://github.com/sky-valley/pi) - [ ] [CHYbeta starred Kritt-ai/open-kritt](https://github.com/Kritt-ai/open-kritt) - [ ] [ZeddYu starred web-platform-tests/wpt](https://github.com/web-platform-tests/wpt) - [ ] [esrrhs contributed to esrrhs/fakelua](https://github.com/esrrhs/fakelua/pull/328) - [ ] [pydantic released v2.24.0 at pydantic/pydantic-ai](https://github.com/pydantic/pydantic-ai/releases/tag/v2.24.0) - [ ] [INotGreen starred msitarzewski/agency-agents](https://github.com/msitarzewski/agency-agents) - Tenable Blog - [ ] [Tenable Hexa AI: Automating exposure remediation with agentic routines](https://www.tenable.com/blog/tenable-hexa-ai-automating-exposure-remediation-with-agentic-routines) - Sploitus.com Exploits RSS Feed - [ ] [vulnerable-by-design-rmf-hardening exploit](https://sploitus.com/exploit?id=05046475-0623-5C7F-9B28-96A2530B725C&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Use of Uninitialized Resource in Linux Linux_Kernel](https://sploitus.com/exploit?id=044A637D-5E88-56F9-9792-F004026CAE17&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Interpretation Conflict in Wordpress](https://sploitus.com/exploit?id=55B5F267-6EB7-5AEA-8621-0512C18C551B&utm_source=rss&utm_medium=rss) - [ ] [Exploit for NULL Pointer Dereference in Linux Linux_Kernel](https://sploitus.com/exploit?id=3A4FA7D9-5C42-50CF-8E4C-8A512EDA8EA9&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Use After Free in Linux Linux_Kernel](https://sploitus.com/exploit?id=B30D20CF-A5CF-57E7-A109-B7280264B90B&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Path Traversal in Gogs](https://sploitus.com/exploit?id=F9DD4247-760F-5259-9290-3E4EF65DABAB&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-71211](https://sploitus.com/exploit?id=A7536AE7-CEA7-5D67-9BAD-E91136D65EDB&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2025-30374](https://sploitus.com/exploit?id=45087582-17AC-54B4-A395-D4B3F42789BA&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Eval Injection in Langflow](https://sploitus.com/exploit?id=A2EDD2EF-2EE9-526B-833C-12531E83615B&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-42533](https://sploitus.com/exploit?id=52C11545-FECA-52FC-A7F3-BAAE557BE349&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Code Injection in Langflow](https://sploitus.com/exploit?id=7BB8B9F7-A2FC-5617-8078-C52FD93E5E08&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-98198](https://sploitus.com/exploit?id=DB8AA667-90EA-5529-A4D7-2D579D185252&utm_source=rss&utm_medium=rss) - [ ] [claude-red exploit](https://sploitus.com/exploit?id=14C9490D-E870-5400-8D67-74A0EA8F4665&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-68004](https://sploitus.com/exploit?id=D300B6C4-B5E3-5F6B-9C94-7F30CF41F9D0&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Code Injection in Craftcms Craft_Cms](https://sploitus.com/exploit?id=7F090A34-5B25-57E9-9667-FCAEEBEDA341&utm_source=rss&utm_medium=rss) - [ ] [vuln-agent exploit](https://sploitus.com/exploit?id=9AA766AE-3C8C-5DBF-9600-482A8975C313&utm_source=rss&utm_medium=rss) - [ ] [SRH_XSS_Finder exploit](https://sploitus.com/exploit?id=40A92C0C-1CA4-51CC-A3D8-BDEB2F231E12&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Improper Input Validation in Teclib-Edition Fields](https://sploitus.com/exploit?id=642976AA-2602-5976-95B6-DCB0B8C18686&utm_source=rss&utm_medium=rss) - [ ] [recon-arc exploit](https://sploitus.com/exploit?id=8317810A-AAB1-545D-983F-3FCEEA265753&utm_source=rss&utm_medium=rss) - [ ] [claudit exploit](https://sploitus.com/exploit?id=EF03333D-9848-5A5E-8A21-985F2C8650C6&utm_source=rss&utm_medium=rss) - [ ] [CVE-Poc_All_in_One exploit](https://sploitus.com/exploit?id=4DDFA596-54E9-5C9C-86B3-278A5EAFBC7C&utm_source=rss&utm_medium=rss) - [ ] [2025hvv-poc exploit](https://sploitus.com/exploit?id=5C6CA5C2-4CA3-5386-A8FB-B6C9AF5031C2&utm_source=rss&utm_medium=rss) - [ ] [exploitdb](https://sploitus.com/exploit?id=5B73BF3C-8EFB-5E3D-AD6E-7063018CDE58&utm_source=rss&utm_medium=rss) - Recent Commits to cve:main - [ ] [Update Wed Aug 5 12:02:02 UTC 2026](https://github.com/trickest/cve/commit/15eaa178baaf955987a866a2c9d91dc02a2fb4aa) - Microsoft Security Blog - [ ] [Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)](https://www.microsoft.com/en-us/security/blog/2026/08/05/microsoft-named-a-leader-in-the-kuppingercole-leadership-compass-for-cloud-native-application-protection-platforms-cnapp/) - [ ] [From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide](https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/) - ElcomSoft blog - [ ] [The iOS 27 Recovery Menu: What It Means for Forensics](https://blog.elcomsoft.com/2026/08/the-ios-27-recovery-menu-what-it-means-for-forensics/) - Horizon3 - [ ] [CVE-2026-18556 and CVE-2026-18577 | N-able N-central Authentication Bypass Vulnerabilities](https://horizon3.ai/attack-research/vulnerabilities/cve-2026-18556-cve-2026-18577/) - [ ] [Horizon3 Accelerates Partner-Led Growth with $20 Million Investment](https://horizon3.ai/news/press-release/partner-led-growth-investment/) - Reverse Engineering - [ ] [I built an open-source MCP server that gives AI agents 46 structured reverse engineering tools (Ghidra, GDB, Binwalk, etc) with a persistent knowledge base](https://www.reddit.com/r/ReverseEngineering/comments/1vg8ups/i_built_an_opensource_mcp_server_that_gives_ai/) - [ ] [Reverse Engineering Google Slides](https://www.reddit.com/r/ReverseEngineering/comments/1vg1del/reverse_engineering_google_slides/) - [ ] [Full read and write control of a Daikin VAM heat-recovery ventilation unit over the P1/P2 bus, using an Arduino Uno registered as a genuine BRC301B61-compatible slave controller.](https://www.reddit.com/r/ReverseEngineering/comments/1vg1f8u/full_read_and_write_control_of_a_daikin_vam/) - [ ] [LockBit string deobfuscation: affine cipher DLL loading reversed with Ghidra](https://www.reddit.com/r/ReverseEngineering/comments/1vgc1dv/lockbit_string_deobfuscation_affine_cipher_dll/) - [ ] [nvrmnd-png/CutterDiscordRPC: Let your friends see what you are reversing. Discord Rich Presence for Cutter, with a setup script that does the install for you.](https://www.reddit.com/r/ReverseEngineering/comments/1vg8kg6/nvrmndpngcutterdiscordrpc_let_your_friends_see/) - Malwarebytes - [ ] [Google’s synchronized passkeys can be stolen in ‘Pass‑ta‑key’ attacks](https://www.malwarebytes.com/blog/news/2026/08/googles-synchronized-passkeys-can-be-stolen-in-pass-ta-key-attacks) - [ ] [Junk Cleaner clears the clutter from your Android](https://www.malwarebytes.com/blog/product/2026/08/junk-cleaner-clears-the-clutter-from-your-android) - The Trail of Bits Blog - [ ] [A few notes on AWS Nitro Enclaves: KMS integration](https://blog.trailofbits.com/2026/08/05/a-few-notes-on-aws-nitro-enclaves-kms-integration/) - PortSwigger Research - [ ] [CRLF-Powered Desync Attacks: Beheading HTTP Streams](https://portswigger.net/research/crlf-powered-desync-attacks) - [ ] [Can AI do novel security research? Meet the HTTP Terminator](https://portswigger.net/research/http-terminator) - text/plain - [ ] [Fiddler in 2026](https://textslashplain.com/2026/08/05/fiddler-in-2026/) - 黑海洋Wiki | AI机器人硬件开发 | 网络安全攻防实战 | 区块链技术文档教程 - 免费资源平台 - [ ] [苹果iCloud专用代理会泄露用户真实ip地址](https://blog.upx8.com/%E8%8B%B9%E6%9E%9CiCloud%E4%B8%93%E7%94%A8%E4%BB%A3%E7%90%86%E4%BC%9A%E6%B3%84%E9%9C%B2%E7%94%A8%E6%88%B7%E7%9C%9F%E5%AE%9Eip%E5%9C%B0%E5%9D%80) - [ ] [Anthropic自研AI芯片以降低对英伟达的依赖](https://blog.upx8.com/Anthropic%E8%87%AA%E7%A0%94AI%E8%8A%AF%E7%89%87%E4%BB%A5%E9%99%8D%E4%BD%8E%E5%AF%B9%E8%8B%B1%E4%BC%9F%E8%BE%BE%E7%9A%84%E4%BE%9D%E8%B5%96) - [ ] [谷歌重组 DeepMind 领导层, Demis 卸任, Jeff Dean 离职](https://blog.upx8.com/%E8%B0%B7%E6%AD%8C%E9%87%8D%E7%BB%84-DeepMind-%E9%A2%86%E5%AF%BC%E5%B1%82-Demis-%E5%8D%B8%E4%BB%BB-Jeff-Dean-%E7%A6%BB%E8%81%8C) - 奇客Solidot–传递最新科技情报 - [ ] [Google DeepMind CEO Demis Hassabis 卸任](https://www.solidot.org/story?sid=85019) - [ ] [微软要求工程师不要最大化 AI Token 使用](https://www.solidot.org/story?sid=85018) - [ ] [AI 监督远程考试变成灾难,数万学生必须重考](https://www.solidot.org/story?sid=85017) - [ ] [Waymo CEO 解释为什么光靠摄像头难以实现自动驾驶](https://www.solidot.org/story?sid=85016) - [ ] [Telegram 因用户分享 CSAM 材料被苹果短暂下架](https://www.solidot.org/story?sid=85015) - [ ] [新药研发推动实验猴价格翻倍](https://www.solidot.org/story?sid=85014) - [ ] [特斯拉在华销量持续下滑](https://www.solidot.org/story?sid=85013) - [ ] [美国据报将豁免中国开放权重模型](https://www.solidot.org/story?sid=85012) - [ ] [中国扫地机器人占据全球七成市场](https://www.solidot.org/story?sid=85011) - [ ] [可能有多达 1.7 亿个恒星质量黑洞潜伏在银河坟场](https://www.solidot.org/story?sid=85010) - [ ] [沙特牵头的财团完成对 EA 的私有化](https://www.solidot.org/story?sid=85009) - [ ] [美国考虑禁止中国制造的数据中心设备](https://www.solidot.org/story?sid=85008) - 黑鸟 - [ ] [OpenAI公开两起网络安全评估的模型越界事件](https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451187967&idx=1&sn=47d14e46a588f289496d7e366c3355c6) - 安全分析与研究 - [ ] [第2篇-勒索软件产业链全景分析](https://mp.weixin.qq.com/s?__biz=MzA4ODEyODA3MQ==&mid=2247496978&idx=1&sn=6687866891e1085499c70de8ef36c229) - 代码卫士 - [ ] [cPanel 存在严重漏洞,可导致托管客户以数据库 root 身份执行 SQL](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247526822&idx=1&sn=fa6cba51e606ca4da3062cfdb3a53640) - [ ] [TP-Link 修复 Omada ZTP 中的15个 RCE 漏洞,可导致网络受陷](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247526822&idx=2&sn=cf608132413b195cbe7d10ca9c2177b9) - 奶牛安全 - [ ] [数据泄露情报2026.8.5-提供2026.7.10那天的宝藏网站数据下载](https://mp.weixin.qq.com/s?__biz=MzU4NjY0NTExNA==&mid=2247489880&idx=1&sn=6f4606d45a955f15ee906fafce88beb1) - 安全内参 - [ ] [2026年全球数据泄露成本再创新高,AI驱动攻击进一步放大损失](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516367&idx=1&sn=ea4e478a5460a00de91be22f027881f1) - 安全客 - [ ] [Vibe Hacking风起云涌:安全圈的门槛正在塌方?](https://mp.weixin.qq.com/s?__biz=MzA5ODA0NDE2MA==&mid=2649790326&idx=1&sn=ab3bd32cee00ff9ab0811ba34a1f514a) - 腾讯安全应急响应中心 - [ ] [TencentOS 科维斯AI首秀:SCTPhantom——潜伏18年的Linux内核提权与容器逃逸漏洞](https://mp.weixin.qq.com/s?__biz=MjM5NzE1NjA0MQ==&mid=2651208584&idx=1&sn=fe28c3d4e1ee43b16379d36785ebe1b9) - 威努特安全网络 - [ ] [当态势感知有了AI“领航员”,安全运营会发生什么变化?](https://mp.weixin.qq.com/s?__biz=MzAwNTgyODU3NQ==&mid=2651143384&idx=1&sn=0109b3c65a2557237c6f0e4b553ad4b6) - 信息安全国家工程研究中心 - [ ] [新规亮剑人工智能拟人化互动服务管理](https://mp.weixin.qq.com/s?__biz=MzU5OTQ0NzY3Ng==&mid=2247504584&idx=1&sn=834c9c5505aef3485bd6456aa76fd313) - 微步在线 - [ ] [Mac的开发者用户,正被APT精准收割](https://mp.weixin.qq.com/s?__biz=MzI5NjA0NjI5MQ==&mid=2650187610&idx=1&sn=1c80efc22ff6d1297553708fd4b19179) - [ ] [Flocks×DeepSeek-V4-Flash正式版发布](https://mp.weixin.qq.com/s?__biz=MzI5NjA0NjI5MQ==&mid=2650187610&idx=2&sn=de6de299a5ff041d70f7ca960efa2c4a) - 奇安信威胁情报中心 - [ ] [当“万能钥匙”也能被复制:谷歌同步 Passkey 三大攻击链深度解析](https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247519701&idx=1&sn=bf19b4c24e89df1686763d7fd85c7f91) - 中国信息安全 - [ ] [中国信息安全测评中心主任彭涛:跑出量子安全加速度 赢得网络空间主动权](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265330&idx=1&sn=aaaddf06ad332b2cdda25e0daf242285) - [ ] [《中国信息安全》杂志2026年第7期目录](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265330&idx=2&sn=c29759bdc6a8a719f51ac09813d56bba) - 安全牛 - [ ] [《新一代自动化渗透测试工具与应用指南》重磅发布](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142175&idx=1&sn=ba44542925096d7aa118cbd4a5ea9422) - [ ] [欧盟AI法案正式落地,通用大模型与AI生成内容纳入强制监管;自动驾驶强制性国标正式发布,全生命周期安全规范补齐车联网安全短板| 牛览](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142175&idx=2&sn=948c9f165dfb315cff20eb26f1d77ab5) - 极客公园 - [ ] [SpaceX 市值从 3 万亿跌到 1.6 万亿美元,首份财报说了什么?](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653111609&idx=1&sn=c19c597d206bbff1333eb0a582cc6437) - [ ] [从会聊天到能管钱:Agent 进入交易时代](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653111600&idx=1&sn=e33bdf573971ee57c8da240638493675) - [ ] [鸿蒙智行发布「竹知了」相关情况说明;小红书封禁 AI 毒动画,未成年陪聊等 10 万账号;马斯克财富缩水2.45万亿元|极客早知道](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653111598&idx=1&sn=821d45e992c208d49f9848c1b7bd6e65) - 安全圈 - [ ] [【安全圈】CISA紧急预警:三大高危漏洞正被黑客积极利用](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078163&idx=1&sn=bfceeaca8e7343eed1b2ca73a6d0570c) - [ ] [【安全圈】AI测试中失控:Claude试图植入开源项目后门](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078163&idx=2&sn=a2e95670fbb8faa05450e9745e7d9213) - [ ] [【安全圈】美国12个州水务系统遭黑客攻击:饮用水安全告急](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078163&idx=3&sn=3b40e60b402a4db7f8c9571c6b4a8c70) - 百度安全应急响应中心 - [ ] [全网诚邀AI高手应战!"Agent+"攻防挑战赛正式开启!](https://mp.weixin.qq.com/s?__biz=MzA4ODc0MTIwMw==&mid=2652544138&idx=1&sn=a1afa1942946abd5f4f90de3c04a8240) - 天黑说嘿话 - [ ] [AI以为在演习,攻破的是真系统](https://mp.weixin.qq.com/s?__biz=MzI5NTQ5MTAzMA==&mid=2247486315&idx=1&sn=e53a592147b835a16509ea8ff16ef723) - 网络空间安全科学学报 - [ ] [《制胜》收官!多型装备高燃画面曝光,一次看够!](https://mp.weixin.qq.com/s?__biz=MzI0NjU2NDMwNQ==&mid=2247508106&idx=1&sn=82bf72d75a9e4a352bacca9559a2f552) - 看雪学苑 - [ ] [安全运营告警过载?考取 CAIDCP 补齐 AI+安全核心竞争力](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458618348&idx=1&sn=941464c79698d16a8157265ae03ba786) - [ ] [DirtyFrag浅析及一条新的攻击路径](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458618348&idx=2&sn=d9c412412014b4d272cd580be7c52053) - [ ] [Mythos 5与GPT-5.6-Sol在安全测试中突破约束,对真实网络目标发起未经授权攻击](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458618348&idx=3&sn=7ee0bc1c9e1e69201ded28320ba9ea85) - 火绒安全 - [ ] [火绒安全终端防护数据月报(2026-07)](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247536041&idx=1&sn=d85fb85ad94afa531d614f8d24b7aaea) - [ ] [火绒小问答--「个人版」近期top问题解答](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247536041&idx=2&sn=293897f5a893626c6eabd183435f1487) - [ ] [诚邀渠道合作伙伴共启新征程](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247536041&idx=3&sn=e1f06c17248c277f4440a63af4202210) - 云鼎实验室 - [ ] [Linux Kernel SCTP "SCTPhantom" 本地权限提升漏洞风险预警](https://mp.weixin.qq.com/s?__biz=MzU3ODAyMjg4OQ==&mid=2247497875&idx=1&sn=e893fe08888b24b48960719b80872197) - 执经衡门 - [ ] [读书笔记 0805](https://mp.weixin.qq.com/s?__biz=MzUxMjkxMzY2OA==&mid=2247483882&idx=1&sn=f2eb9819cc5af22b447cd2935ea698d0) - 凌晨一点零三分 - [ ] [跟党走_政策板块日报2026-08-05](https://mp.weixin.qq.com/s?__biz=MzIxMjI0Mzk0OQ==&mid=2247485657&idx=1&sn=bc214b8e9db9621eaeffcb0f0433b7ee) - 情报分析师 - [ ] [藏在日防卫白皮书里的算法战争,日本军用AI转型全调查](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650568969&idx=1&sn=e9fd465ad6f998258d577b989d48e49a) - [ ] [巴基斯坦通过旅行社与网络针对印度教与锡克教徒招募间谍网络曝光,南亚情报渗透与中巴合作风险](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650568969&idx=2&sn=50dd504d99ecc850640d5b064ee605cc) - OnionSec - [ ] [逃离算法推荐](https://mp.weixin.qq.com/s?__biz=MzUyMTUwMzI3Ng==&mid=2247485915&idx=1&sn=4352ca9d05df18531f324679e5f2b222) - 字节跳动技术团队 - [ ] [不写一行代码,小 V 在 Codex 里搭起了视频搜索网站](https://mp.weixin.qq.com/s?__biz=MzI1MzYzMjE0MQ==&mid=2247521147&idx=1&sn=dc14c37c6a03dd9448d8b95c2d4f15d6) - 360数字安全 - [ ] [“中国版Mythos”进入实战验证阶段,麒麟软件率先接入360图龙锋](https://mp.weixin.qq.com/s?__biz=MzA4MTg0MDQ4Nw==&mid=2247586685&idx=1&sn=a1a85f7f3ecfd76a44e6af4f27a25aa1) - [ ] [360 ADE认证首批国家信息技术紧缺人才培养工程专业技能证书下发,多领域学员成功获证](https://mp.weixin.qq.com/s?__biz=MzA4MTg0MDQ4Nw==&mid=2247586685&idx=2&sn=b5ccd9e7b6e182bdb19ec100110a3afe) - Vimeo / OffSec’s videos - [ ] [HackTrack Ad 2026_(Dylan)](https://vimeo.com/1215811937) - DARKNAVY - [ ] [deepsec 携手国产 AI,斩获全球 AI 网络安全能力排行榜第三🥉](https://mp.weixin.qq.com/s?__biz=MzkyMjM5MTk3NQ==&mid=2247505096&idx=1&sn=44fa15f41469be600bd692b668687d9a) - ICT Security Magazine - [ ] [AI Act, polizia e sorveglianza biometrica: il parere del Garante Privacy sull’implementazione italiana del Regolamento UE](https://www.ictsecuritymagazine.com/notizie/ai-act-biometria/) - 安全419 - [ ] [安全419|一周国际网安资讯:AI模型越狱引发安全范式变革 供应链威胁持续升级](https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&mid=2247554329&idx=1&sn=cb7ddafba49e8aa885d1f6b9f1da8753) - Codice Insicuro, blog di Cyber Security, sviluppo sicuro, code review e altro. - [ ] [Security Wals: il podcast](https://codiceinsicuro.it/blog/security-walks-il-podcast/) - Tails - News - [ ] [Tails 7.10.1](https://tails.net/news/version_7.10.1/) - DEF CON Announcements! - [ ] [Join us for the DEF CON 34 Welcome Party!](https://defcon.org/html/defcon-34/dc-34-news.html#welcomeparty) - [ ] [New! Headsets for Talks At DEF CON 34!](https://info.defcon.org/defcon34/documents/670) - 国家互联网应急中心CNCERT - [ ] [网络安全信息与动态周报2026年第31期(7月27日-8月2日)](https://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw==&mid=2247501985&idx=1&sn=e42b13cdc9609016a4488aa3ff463cb9) - Over Security - [ ] [Ransom Cartel ransomware creator sentenced to 16 years in prison](https://www.bleepingcomputer.com/news/security/ransom-cartel-ransomware-creator-sentenced-to-16-years-in-prison/) - [ ] [Canadian pleads guilty to Snowflake cloud data-theft attacks](https://www.bleepingcomputer.com/news/security/canadian-pleads-guilty-to-snowflake-cloud-data-theft-attacks/) - [ ] [Chinese telcos maintain deep US presence despite Salt Typhoon links, House committee says](https://therecord.media/chinese-hackers-telecoms-house) - [ ] [Canadian man pleads guilty to Snowflake hacks that led to 165 breaches](https://therecord.media/guilty-plea-snowflake-hack-connor-riley-moucka) - [ ] [Hackers run khunt post-exploitation toolkit from Oracle database](https://www.bleepingcomputer.com/news/security/hackers-run-khunt-post-exploitation-toolkit-from-oracle-database/) - [ ] [COLDCARD security audit phishing attack installs remote access tool](https://www.bleepingcomputer.com/news/security/coldcard-security-audit-phishing-attack-installs-remote-access-tool/) - [ ] [PSA: Apple’s Private Relay can leak your real IP address](https://techcrunch.com/2026/08/05/psa-apples-private-relay-can-leak-your-real-ip-address/) - [ ] [Sovranità digitale e AI: le sfide per la leadership IT](https://www.cybersecurity360.it/cultura-cyber/sovranita-digitale-e-ai-le-sfide-per-la-leadership-it/) - [ ] [CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws](https://www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploiting-langflow-n-central-apache-tomcat-flaws/) - [ ] [Dutch retailer De Bijenkorf warns customer data may be exposed after cyber incident](https://therecord.media/de-bijenkorf-luxury-retailer-third-party-cyber-incident) - [ ] [Security Wals: il podcast](http://0.0.0.0:4000/blog/security-walks-il-podcast/) - [ ] [From Stolen Credentials to Full Breach: The 72-Hour Timeline](https://cyble.com/blog/72-hour-timeline-credential-based-cyberattack/) - [ ] [Google Blogger locks hundreds of blogs in malware false positive](https://www.bleepingcomputer.com/news/google/google-blogger-locks-hundreds-of-blogs-in-malware-false-positive/) - [ ] [Supply chain software: Amazon conferma una campagna d’attacco che l’Italia ha già intercettato](https://www.cybersecurity360.it/news/supply-chain-software-amazon-conferma-una-campagna-dattacco-che-litalia-ha-gia-intercettato/) - [ ] [Facciamo behavior-driven development con il C](http://0.0.0.0:4000/2022/04/01/facciamo-behavior-driven-development-con-il-c/) - [ ] [E se la soluzione al problema dell’antivirus fosse avere il codice open?](http://0.0.0.0:4000/2022/04/04/e-se-il-problema-dell-antivirus-fosse-avere-il-codice-open/) - [ ] [Non mettete regole troppo complesse alle vostre password](http://0.0.0.0:4000/2022/04/16/non-mettete-regole-troppo-complesse-alle-vostre-password/) - [ ] [Password vs Passphrase: la cracking challenge](http://0.0.0.0:4000/2022/04/21/password-vs-passphrase-la-cracking-challenge/) - [ ] [Sono tutti open con il source degli altri – reprise](http://0.0.0.0:4000/2022/05/10/sono-tutti-open-con-il-source-degli-altri-reprise/) - [ ] [Cosa fa un security engineer in SUSE?](http://0.0.0.0:4000/2022/05/24/cosa-fa-un-security-engineer-in-suse/) - [ ] [Caro diario eccoci qui…](http://0.0.0.0:4000/2022/10/27/caro-diario-eccoci-qui/) - [ ] [GCC, analisi statica e warning mancanti](http://0.0.0.0:4000/blog/gcc-analisi-statica-e-warning-mancanti/) - [ ] [Programmazione Difensiva: Chiudere la Finestra su una Race Condition Critica](http://0.0.0.0:4000/blog/programmazione-difensiva-chiudere-la-finestra-su-una-race-condition-critica/) - [ ] [How AI-powered phishing killed blocklists for good](https://www.bleepingcomputer.com/news/security/how-ai-powered-phishing-killed-blocklists-for-good/) - [ ] [Cyberattacks on water systems expand to 12 states as South Dakota, Georgia announce incidents](https://therecord.media/iran-cyberattacks-water-treatment) - [ ] [Un dato anonimo per chi? Le nuove linee guida EDPB cambiano prospettiva](https://www.cybersecurity360.it/legal/privacy-dati-personali/un-dato-anonimo-per-chi-le-nuove-linee-guida-edpb-cambiano-prospettiva/) - [ ] [Anthropic AI agent faked identities, phished real developers in UK government hacking test](https://therecord.media/anthropic-ai-hacking-uk) - [ ] [Phishing ai danni di ARERA utilizza il tema “bonus sociale idrico”](https://cert-agid.gov.it/news/phishing-ai-danni-di-arera-utilizza-il-tema-bonus-sociale-idrico/) - [ ] [NIS2 e fornitori ICT: criteri per valutare criticità, dipendenze e responsabilità nella supply chain](https://www.cybersecurity360.it/legal/nis2-e-fornitori-ict-criteri-per-valutare-criticita-dipendenze-e-responsabilita-nella-supply-chain/) - [ ] [How Enterprises Can Scale AI Securely with the Right Cloud Foundation](https://thecyberexpress.com/secure-cloud-foundation-for-ai/) - [ ] [Express VPN, fino all’80% di sconto sui piani da 28 mesi: cosa include l’offerta](https://www.cybersecurity360.it/cultura-cyber/express-vpn-28-mesi-10-dispositivi-sconto-80-per-cento/) - [ ] [Claude evade (di nuovo) e compromette tre aziende reali](https://www.securityinfo.it/2026/08/04/claude-evade-di-nuovo-e-compromette-tre-aziende-reali/) - [ ] [Safeguarding 200M Users: How ChongLuaDao Scales Threat Validation with ANY.RUN](https://any.run/cybersecurity-blog/chongluadao-success-story/) - [ ] [UK Cybercrime Journal: Qilin Ransomware Rampage in H1 2026](https://blog.bushidotoken.net/2026/07/uk-cybercrime-journal-qilin-ransomware.html) - [ ] [La sfida della sovranità digitale fra cyber security e geopolitica](https://www.cybersecurity360.it/outlook/la-sfida-della-sovranita-digitale-fra-cyber-security-e-geopolitica/) - [ ] [One Adversary: The Moment Nobody Sees](https://www.group-ib.com/blog/moment-nobody-sees/) - Have I Been Pwned latest breaches - [ ] [Inter-Con Security - 276,114 breached accounts](https://haveibeenpwned.com/Breach/InterConSecurity) - Schneier on Security - [ ] [Vulnerabilities in Car Anti-Theft Device](https://www.schneier.com/blog/archives/2026/08/vulnerabilities-in-car-anti-theft-device.html) - Dark Space Blogspot - [ ] [Come Proteggersi Da 5$ Wrench Attack (Bitcoin)](http://darkwhite666.blogspot.com/2026/08/come-proteggersi-da-5-wrench-attack.html) - GRAHAM CLULEY - [ ] [Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency](https://grahamcluley.com/smashing-security-podcast-479-how-a-fake-police-officer-nearly-stole-grahams-cryptocurrency/) - SANS Internet Storm Center, InfoCON: green - [ ] [Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)](https://isc.sans.edu/diary/rss/33218) - [ ] [ISC Stormcast For Wednesday, August 5th, 2026 https://isc.sans.edu/podcastdetail/10038, (Wed, Aug 5th)](https://isc.sans.edu/diary/rss/33216) - Blackhat Library: Hacking techniques and research - [ ] [A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide](https://www.reddit.com/r/blackhat/comments/1vgnwrh/a_security_pro_hacked_north_korean_hackers_he/) - [ ] [Coldwallet](https://www.reddit.com/r/blackhat/comments/1vfvi8e/coldwallet/) - The Hacker News - [ ] [Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures](https://thehackernews.com/2026/08/over-250-clickfix-domains-use-browser.html) - [ ] [OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes](https://thehackernews.com/2026/08/openai-disrupts-poipet-scam-network.html) - [ ] [Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt](https://thehackernews.com/2026/08/poison-claude-sells-discounted-claude.html) - [ ] [Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports](https://thehackernews.com/2026/08/paperclip-ai-flaws-let-attackers-run.html) - [ ] [Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug](https://thehackernews.com/2026/08/veeam-terraform-mcp-django-patch.html) - [ ] [Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain](https://thehackernews.com/2026/08/trojanized-npm-packages-decode-c2-ip.html) - [ ] [New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch](https://thehackernews.com/2026/08/new-ovswrap-linux-kernel-flaw-lets.html) - [ ] [Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk](https://thehackernews.com/2026/08/kali365-weaponizes-microsoft.html) - [ ] [Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup](https://thehackernews.com/2026/08/critical-gitea-flaw-let-unauthenticated.html) - [ ] [Leaked n8n API Tokens Exposed Live Instances to Credential Theft](https://thehackernews.com/2026/08/leaked-n8n-api-tokens-exposed-live.html) - [ ] [Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data](https://thehackernews.com/2026/08/open-vsx-removes-77-malicious-evil-twin.html) - [ ] [Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself](https://thehackernews.com/2026/08/claude-mythos-5-tried-to-backdoor-real.html) - [ ] [CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited](https://thehackernews.com/2026/08/cisa-flags-langflow-rce-tomcat-and-n.html) - [ ] [QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer](https://thehackernews.com/2026/08/quickfox-supply-chain-attack-delivers.html) - TorrentFreak - [ ] [Broadcaster Wins Broad U.S. Blocking Injunction Covering Pirate Sites That Don’t Exist Yet](https://torrentfreak.com/broadcaster-wins-broad-u-s-blocking-injunction-covering-pirate-sites-that-dont-exist-yet/) - Security Affairs - [ ] [AI Deception Emerges in Cyber Tests as Agents Target Real People and Systems](https://securityaffairs.com/196695/ai/ai-deception-emerges-in-cyber-tests-as-agents-target-real-people-and-systems.html) - [ ] [Brown Health Medical Group-MA Data Breach Exposes Information of 311,000 Individuals](https://securityaffairs.com/196681/uncategorized/brown-health-medical-group-ma-data-breach-exposes-information-of-311000-individuals.html) - [ ] [U.S. CISA adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog](https://securityaffairs.com/196667/hacking/u-s-cisa-adds-langflow-apache-tomcat-and-n-able-n-central-flaws-to-its-known-exploited-vulnerabilities-catalog.html) - [ ] [OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become Root](https://securityaffairs.com/196657/hacking/ovswrap-13-year-old-linux-kernel-flaw-lets-local-users-become-root.html) - [ ] [SMOKE#SCREEN Campaign Abuses ScreenConnect to Give Attackers Remote Control Access](https://securityaffairs.com/196637/uncategorized/smokescreen-campaign-abuses-screenconnect-to-give-attackers-remote-control-access.html) - www.theregister.com - Articles - [ ] [Prompt injection isn't the bug, AI agent frameworks are](https://www.theregister.com/security/2026/08/05/prompt-injection-isnt-the-bug-ai-agent-frameworks-are/5283585) - [ ] [IBM's agentic AI platform is under active attack - patch now](https://www.theregister.com/security/2026/08/05/ibms-agentic-ai-platform-is-under-active-attack-patch-now/5283535) - [ ] [London cops handed victim's new address and number to her stalker, watchdog says](https://www.theregister.com/security/2026/08/05/london-cops-handed-victims-new-address-and-number-to-her-stalker-watchdog-says/5283382) - [ ] [UK charities count the cost of Beacon CRM cyberattack](https://www.theregister.com/security/2026/08/05/uk-charities-count-the-cost-of-beacon-crm-cyberattack/5283305) - [ ] [AI researchers let models off the leash – then watched as they tried to add malware to a FOSS project](https://www.theregister.com/ai-and-ml/2026/08/05/ai-researchers-let-models-off-the-leash-then-watched-as-they-tried-to-add-malware-to-a-foss-project/5283165) - Daniel Miessler - [ ] [Why Aren’t Things Worse?](https://danielmiessler.com/blog/why-arent-things-worse?utm_source=rss&utm_medium=feed&utm_campaign=website) - Tor Project blog - [ ] [New Release: Tails 7.10.1](https://blog.torproject.org/new-release-tails-7_10_1/) - 360威胁情报中心 - [ ] [APT-C-24(响尾蛇)组织使用application文件钓鱼攻击活动分析](https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247508749&idx=1&sn=c46a8458976b23295f3cfd283145e31b) - Deeplinks - [ ] [Tomorrow’s U.S. Senate Vote: Four Internet Bills, One Wrong Direction](https://www.eff.org/deeplinks/2026/08/senate-vote-tomorrow-four-internet-bills-one-wrong-direction) - Security Weekly Podcast Network (Audio) - [ ] [Say Easy, Do Hard - Performance Through People - Greg Hoffman - BSW #459](http://sites.libsyn.com/18678/say-easy-do-hard-performance-through-people-greg-hoffman-bsw-459)
每日安全资讯(2026-08-06)