# 每日安全资讯(2026-08-14) - SecWiki News - [ ] [SecWiki News 2026-08-13 Review](http://www.sec-wiki.com/?2026-08-13) - Sploitus.com Exploits RSS Feed - [ ] [Exploit for Path Traversal in Apache Http_Server](https://sploitus.com/exploit?id=958423A8-16EB-52C6-9A18-54F1646CE3AB&utm_source=rss&utm_medium=rss) - [ ] [Exploit for SQL Injection in Metabase](https://sploitus.com/exploit?id=9CD3F74A-578C-52C5-BF2A-047D4CBE0F22&utm_source=rss&utm_medium=rss) - [ ] [wp-forge exploit](https://sploitus.com/exploit?id=7CBA8976-F87A-5F9B-93F4-C50ED3958EFA&utm_source=rss&utm_medium=rss) - [ ] [Blue-EternalBlue-Exploit](https://sploitus.com/exploit?id=5B962B99-C484-5BB8-A8F7-E255CDE1FB46&utm_source=rss&utm_medium=rss) - [ ] [xss2shell-pro exploit](https://sploitus.com/exploit?id=66584FBD-6C67-5D74-9F0D-83158ABC85EA&utm_source=rss&utm_medium=rss) - [ ] [Exploit for SQL Injection in Acymailing](https://sploitus.com/exploit?id=372636CE-CEFB-5CF4-8EF5-7A5157D27ABB&utm_source=rss&utm_medium=rss) - [ ] [IITK_Hack_Writeup_or_POC exploit](https://sploitus.com/exploit?id=EBB33570-D79E-501B-BDDB-D190F3828009&utm_source=rss&utm_medium=rss) - [ ] [cybernotes exploit](https://sploitus.com/exploit?id=35E9E356-4EC6-5246-B35E-178C0F861124&utm_source=rss&utm_medium=rss) - [ ] [clipwire exploit](https://sploitus.com/exploit?id=92CF8784-F2D4-5E44-8D6D-5D73C9E70D31&utm_source=rss&utm_medium=rss) - [ ] [internal-privesc-poc exploit](https://sploitus.com/exploit?id=31E274DE-6F21-5A6A-BBA2-BA773E68A175&utm_source=rss&utm_medium=rss) - [ ] [aipoc-ctf exploit](https://sploitus.com/exploit?id=054B1021-256B-5DBD-B8A6-AC160BDA4A8E&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Missing Authentication for Critical Function in Cpanel](https://sploitus.com/exploit?id=04BF49C5-6F55-546F-AA43-4F17B4D3F628&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-53413](https://sploitus.com/exploit?id=852FCE60-BA78-5D8E-88EB-A72403991CAC&utm_source=rss&utm_medium=rss) - [ ] [ai-threat-detection exploit](https://sploitus.com/exploit?id=D041E2F8-CB62-5A9B-B14B-B6270EFFEA12&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Eval Injection in Langflow](https://sploitus.com/exploit?id=F54C4C3A-AF7F-5FA1-902D-3BDB0D1C35CD&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Authentication Bypass by Spoofing in Frangoteam Fuxa](https://sploitus.com/exploit?id=4D21C028-A9E1-5631-A97B-76AFA5DA7D08&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Use After Free in Linux Linux_Kernel](https://sploitus.com/exploit?id=20260521-9AF1-56DF-9C39-605DFDEBA17B&utm_source=rss&utm_medium=rss) - [ ] [pdfcpu_poc exploit](https://sploitus.com/exploit?id=7542FDA4-413F-5316-932F-00D80A315372&utm_source=rss&utm_medium=rss) - [ ] [CVE-CICD-Security exploit](https://sploitus.com/exploit?id=643404F5-DEAA-54B1-B676-B3B0F613C8FE&utm_source=rss&utm_medium=rss) - [ ] [CVE-Confluence exploit](https://sploitus.com/exploit?id=0DD93339-26D6-52D0-B646-8F5B03FBC78F&utm_source=rss&utm_medium=rss) - [ ] [CVE-Web-Framework exploit](https://sploitus.com/exploit?id=48EB895C-64AD-5B2B-A3BA-69DBD7E36642&utm_source=rss&utm_medium=rss) - [ ] [CVE-Apache-Ecosystem exploit](https://sploitus.com/exploit?id=DFBAF7FB-C163-5D2C-BF9E-3F46B82BF773&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Inefficient Regular Expression Complexity in Rrrene Htmlsanitizeex](https://sploitus.com/exploit?id=23D1C12B-7D04-5A05-B0BD-A135BB76E37A&utm_source=rss&utm_medium=rss) - [ ] [wp2shell-Exploit-Waf-Bypass](https://sploitus.com/exploit?id=150C3C61-7381-546D-9390-B5927A9D73AA&utm_source=rss&utm_medium=rss) - [ ] [insecure-notes-api exploit](https://sploitus.com/exploit?id=5427A7F4-95ED-5419-AB9E-6EC577C3E361&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Improper Privilege Management in Google Chrome](https://sploitus.com/exploit?id=8E9682F7-497B-5268-8487-0C28361EC740&utm_source=rss&utm_medium=rss) - 安全客-有思想的安全新媒体 - [ ] [一张恶意SIM卡,就能接管你的充电桩:1981年的"祖传命令"正在物联网里复活](https://www.anquanke.com/post/id/315962) - [ ] [Linux服务器注意了:勒索病毒已经盯上你,国家正式预警](https://www.anquanke.com/post/id/315959) - Doonsec's feed - [ ] [校企协同育尖兵,360联合北信职打造“朝匠技弈”网络与信息安全管理员竞赛](https://mp.weixin.qq.com/s/n1rTihEYb6v6O2KGUilMzg) - [ ] [一个假“公安一网通办”App,牵出170台服务器:飞鹰与夜龙黑产武器库全揭秘](https://mp.weixin.qq.com/s/oHxJcfwyKtG3L99SrOigZw) - [ ] [XCon2026 议题||2026年的Apple Webkit漏洞挖掘和利用](https://mp.weixin.qq.com/s/qR00vZbeHPlzw01xOZqlxg) - [ ] [XCon2026全日程曝光,10张全价票限时免费送!](https://mp.weixin.qq.com/s/8CzyG-IEPyT8VYN2NQsh2Q) - [ ] [WhatsApp上线诈骗预警:AI生成话术让社工攻击更难凭直觉识别](https://mp.weixin.qq.com/s/6BW_uUO493H60d2O4_TVJg) - [ ] [Word Copilot「初稿生成」提示词优劣对比](https://mp.weixin.qq.com/s/_tZkonPIQY4ubY_otIbrcQ) - [ ] [告别机翻!Word Copilot 一键生成地道中英双语正式文档](https://mp.weixin.qq.com/s/AezLWvT7tpLNK7r2aVMM1w) - [ ] [财务分析师实操|5步用Excel Copilot搞定COGS全流程分析](https://mp.weixin.qq.com/s/-aEdCOp2-KtJharGbKxlkw) - [ ] [ChatGPT 5.6 最新模型 140 充值](https://mp.weixin.qq.com/s/kxeMZadTC82kC0HW7U6ihw) - [ ] [HW技战法丨AI原生渗透智能体的三种\"技战法\"解析](https://mp.weixin.qq.com/s/5gbI644AJaA5wpn0pD0cOA) - [ ] [重要提醒|AI及智能体赋能安全研究专题研讨会活动报名即将截止](https://mp.weixin.qq.com/s/oBC3rnnP8pLkAaKiHXrxHw) - [ ] [来浅浅测试一下蜘蛛侠:崭新之日里边彩蛋网站](https://mp.weixin.qq.com/s/mkoo0q1eDsaVFd5Bk1w5uQ) - [ ] [黑盒自动化漏洞挖掘平台正式公测](https://mp.weixin.qq.com/s/GbL6smydBOLXf7IriE7Vug) - [ ] [捷报 | 边界无限成功中标某省级群团组织机关RASP项目](https://mp.weixin.qq.com/s/b6ENoFhGYakpY_Ef5FPD3A) - [ ] [AI 真能做原创安全研究吗?聊聊 HTTP Terminator](https://mp.weixin.qq.com/s/QqdZ1M8a4PZHu6AIL8-ROg) - [ ] [特朗普授权美国政府借助私营企业网络力量打击跨国犯罪组织](https://mp.weixin.qq.com/s/bqPJvFE9C5a1WYMcsH4LLg) - [ ] [公安部新规10月1日施行:算法安全首次纳入检查,这11项请对照自查](https://mp.weixin.qq.com/s/WueoYd5gzT1H4AwamsNPUw) - [ ] [工资到账119587.68元,爱你字节!](https://mp.weixin.qq.com/s/8_WYMmbeX9Q-CoHcnBl3tA) - [ ] [【深度研判】日本正式成立国家情报局并召开国家情报会议,日本情报权力向首相官邸集中对我周边情报竞争与对日工作的潜在风险](https://mp.weixin.qq.com/s/Kt1wc7hzTp_0cA8uSJJ2Jg) - Private Feed for M09Ic - [ ] [anthropics released v2.1.232 at anthropics/claude-code](https://github.com/anthropics/claude-code/releases/tag/v2.1.232) - [ ] [liamg contributed to liamg/ariadne](https://github.com/liamg/ariadne/pull/11) - [ ] [bolucat released 202608132109 at bolucat/Archive](https://github.com/bolucat/Archive/releases/tag/202608132109) - [ ] [Teach2Breach starred MalwareSupportGroup/PolyDrop](https://github.com/MalwareSupportGroup/PolyDrop) - [ ] [chainreactors released v0.0.0-nightly.20260813 at chainreactors/aiscan](https://github.com/chainreactors/aiscan/releases/tag/v0.0.0-nightly.20260813) - [ ] [4ra1n starred deepseek-ai/deepseek-harness](https://github.com/deepseek-ai/deepseek-harness) - [ ] [timwhitez starred timwhitez/AutoRE-CLI](https://github.com/timwhitez/AutoRE-CLI) - [ ] [Mr-xn starred esengine/DeepSeek-Reasonix](https://github.com/esengine/DeepSeek-Reasonix) - [ ] [IC3-CR3AM starred deepseek-ai/deepseek-harness](https://github.com/deepseek-ai/deepseek-harness) - [ ] [whwlsfb starred deepseek-ai/deepseek-harness](https://github.com/deepseek-ai/deepseek-harness) - [ ] [liamg contributed to liamg/grabber](https://github.com/liamg/grabber/pull/45) - [ ] [Mel0day starred deepseek-ai/deepseek-harness](https://github.com/deepseek-ai/deepseek-harness) - [ ] [WAY29 starred deepseek-ai/deepseek-harness](https://github.com/deepseek-ai/deepseek-harness) - [ ] [timwhitez starred deepseek-ai/deepseek-harness](https://github.com/deepseek-ai/deepseek-harness) - [ ] [Rvn0xsy starred deepseek-ai/deepseek-harness](https://github.com/deepseek-ai/deepseek-harness) - [ ] [esrrhs contributed to esrrhs/fakelua](https://github.com/esrrhs/fakelua/pull/356) - [ ] [0xbug starred trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog) - [ ] [anthropics released v2.1.231 at anthropics/claude-code](https://github.com/anthropics/claude-code/releases/tag/v2.1.231) - [ ] [imroc released v3.61.0 at imroc/req](https://github.com/imroc/req/releases/tag/v3.61.0) - [ ] [esrrhs contributed to esrrhs/fakecc](https://github.com/esrrhs/fakecc/pull/1) - Recent Commits to cve:main - [ ] [Update Thu Aug 13 11:58:40 UTC 2026](https://github.com/trickest/cve/commit/dcf2c46637c8a904526901bbd207f8b74c0b5f82) - Horizon3 - [ ] [CVE-2026-72898 | Metabase Pre-Authentication SQL Injection Vulnerability](https://horizon3.ai/attack-research/vulnerabilities/cve-2026-72898/) - [ ] [Why Validation Changes Everything. But Isn’t Enough.](https://horizon3.ai/intelligence/blogs/why-validation-changes-everything/) - GuidePoint Security - [ ] [Understanding CMMC: Temporary Deficiencies, Enduring Exceptions, and Operational Plans of Action](https://www.guidepointsecurity.com/blog/cmmc-deficiencies-exceptions-poa/) - Malware-Traffic-Analysis.net - Blog Entries - [ ] [2026-08-12: SmartApeSG ClickFix leads to two RATs](https://www.malware-traffic-analysis.net/2026/08/12/index.html) - Malwarebytes - [ ] [New Android malware lets criminals use your bank card in real time](https://www.malwarebytes.com/blog/mobile/2026/08/new-android-malware-lets-criminals-use-your-bank-card-in-real-time) - [ ] [Parents take on Meta, TikTok, Google, and Snap in 3,000 youth safety lawsuits](https://www.malwarebytes.com/blog/privacy/2026/08/parents-take-on-meta-tiktok-google-and-snap-in-3000-youth-safety-lawsuits) - Securelist - [ ] [Armored Likho expands its cyber-espionage toolkit](https://securelist.com/armored-likho-still-toolkit/121033/) - 奇客Solidot–传递最新科技情报 - [ ] [NASA 延长旅行者2号的科学使命](https://www.solidot.org/story?sid=85089) - [ ] [科技巨头想要收集你的思想](https://www.solidot.org/story?sid=85088) - [ ] [爬楼梯有助于延寿](https://www.solidot.org/story?sid=85087) - [ ] [火星岩石中发现刚玉](https://www.solidot.org/story?sid=85086) - [ ] [Django 项目宣布采用每年发布一个版本的发布模式](https://www.solidot.org/story?sid=85085) - [ ] [图书零售商怀疑 AI 公司购买然后销毁珍本图书](https://www.solidot.org/story?sid=85084) - [ ] [Google 重组 AI 部门旨在赶上竞争对手](https://www.solidot.org/story?sid=85082) - [ ] [韦伯望远镜在银河系中心黑洞附近发现水和尘埃](https://www.solidot.org/story?sid=85081) - [ ] [社媒如何导致西班牙难民危机](https://www.solidot.org/story?sid=85080) - [ ] [企业错配系统向 @noreply.net 之类的域名发送邮件](https://www.solidot.org/story?sid=85079) - 黑海洋Wiki | AI机器人硬件开发 | 网络安全攻防实战 | 区块链技术文档教程 - 免费资源平台 - [ ] [卸任前为“美国制造”站台,库克陪同美商务部长参观Mac Mini工厂](https://blog.upx8.com/%E5%8D%B8%E4%BB%BB%E5%89%8D%E4%B8%BA-%E7%BE%8E%E5%9B%BD%E5%88%B6%E9%80%A0-%E7%AB%99%E5%8F%B0-%E5%BA%93%E5%85%8B%E9%99%AA%E5%90%8C%E7%BE%8E%E5%95%86%E5%8A%A1%E9%83%A8%E9%95%BF%E5%8F%82%E8%A7%82Mac-Mini%E5%B7%A5%E5%8E%82) - [ ] [谷歌宣布推出Gemini 3.7 Flash模型](https://blog.upx8.com/%E8%B0%B7%E6%AD%8C%E5%AE%A3%E5%B8%83%E6%8E%A8%E5%87%BAGemini-3-7-Flash%E6%A8%A1%E5%9E%8B) - [ ] [DeepSeek 发布智能体框架 DeepSeek Harness:开发者可自由组合、匹配、替换和扩展](https://blog.upx8.com/DeepSeek-%E5%8F%91%E5%B8%83%E6%99%BA%E8%83%BD%E4%BD%93%E6%A1%86%E6%9E%B6-DeepSeek-Harness-%E5%BC%80%E5%8F%91%E8%80%85%E5%8F%AF%E8%87%AA%E7%94%B1%E7%BB%84%E5%90%88-%E5%8C%B9%E9%85%8D-%E6%9B%BF%E6%8D%A2%E5%92%8C%E6%89%A9%E5%B1%95) - 黑鸟 - [ ] [找工作被要求装VPN:你可能已经被APT组织盯上](https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451188079&idx=1&sn=547b6e346f2ef85cedc4427aa95cf422) - 腾讯安全应急响应中心 - [ ] [AI能写代码,但它不懂业务规则:Vibe Coding下最危险的安全盲区](https://mp.weixin.qq.com/s?__biz=MjM5NzE1NjA0MQ==&mid=2651208642&idx=1&sn=3f908fcfe6fdba32629a2fd817d0a689) - 锦行科技 - [ ] [锦行科技入选工信部网络安全保险服务试点 亮相广东省通信产业链集体签约仪式](https://mp.weixin.qq.com/s?__biz=MzIxNTQxMjQyNg==&mid=2247494958&idx=1&sn=a094e93c25611a610ffd9b96f222a548) - 安全分析与研究 - [ ] [第10篇-AI时代的勒索软件演进趋势](https://mp.weixin.qq.com/s?__biz=MzA4ODEyODA3MQ==&mid=2247497011&idx=1&sn=8528f22a2170534c39de12d19e1ec2a3) - 安全内参 - [ ] [OpenAI公开售卖网络攻击超级AI,或冲击全球网空对抗格局](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516413&idx=1&sn=f4f31493262cfc6a8cc51f9064a7d207) - [ ] [西安某公司遭勒索攻击:核心业务数据被加密,网警应急处置](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516413&idx=2&sn=103462bb66e80882bc0f08a4c5cac22e) - 安全客 - [ ] [Linux服务器注意了:勒索病毒已经盯上你,国家正式预警](https://mp.weixin.qq.com/s?__biz=MzA5ODA0NDE2MA==&mid=2649790362&idx=1&sn=342609394ce6934e4263513a0c80ce68) - 代码卫士 - [ ] [Adobe 修复三个 CVSS 满分漏洞](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247526866&idx=1&sn=adb5f2d68c7b6168285eee413c364a6a) - 威努特安全网络 - [ ] [威努特ASG:全链路打通AI安全,构建企业AI治理体系](https://mp.weixin.qq.com/s?__biz=MzAwNTgyODU3NQ==&mid=2651143527&idx=1&sn=2ac1d1a0f9c71e1f1d9f75fc139a9a21) - 安全学术圈 - [ ] [SecDr-Darknet | 密态网络安全前沿技术(电子学报专栏)](https://mp.weixin.qq.com/s?__biz=MzU5MTM5MTQ2MA==&mid=2247495780&idx=1&sn=dc64bbb045404bd5bd519e3482730cb8) - 看雪学苑 - [ ] [网络摄像头软件去广告](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458618624&idx=1&sn=c8e240819534742b651ac3a09688faac) - [ ] [从“猫鼠游戏”到网联车安全|HG TALK 第五期:对话王志鹏 & 章意](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458618624&idx=2&sn=5fe496300db98ee1a157bda201193dad) - [ ] [Cisco防火墙零日漏洞遭野外利用,可无认证触发DoS瘫痪](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458618624&idx=3&sn=ad1379f0308b86ff67b12d02c68a237c) - 360漏洞云 - [ ] [【七夕特别活动】AI七夕 · 智造浪漫](https://mp.weixin.qq.com/s?__biz=Mzg5MTc5Mzk2OA==&mid=2247505180&idx=1&sn=fb4f15d84bc4c437619f65f94c3fc118) - 数世咨询 - [ ] [报告发布:暗网情报DWI能力白皮书 | 附下载地址](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247543676&idx=1&sn=00bfb142aa1c35e53472c20e64292102) - 绿盟科技CERT - [ ] [【安全更新】微软8月安全更新多个产品高危漏洞通告](https://mp.weixin.qq.com/s?__biz=Mzk0MjE3ODkxNg==&mid=2247493564&idx=1&sn=c5b1fb86e789a4e1a13bf7951a830c72) - 奇安信 CERT - [ ] [【已复现】Microsoft SharePoint JWT 令牌身份认证绕过漏洞(CVE-2026-55040)安全风险通告](https://mp.weixin.qq.com/s?__biz=MzU5NDgxODU1MQ==&mid=2247507089&idx=1&sn=738a25f378623a67d8bc4f5dfa6ef085) - [ ] [奇安信集团2026年08月补丁库更新通告-第一次更新](https://mp.weixin.qq.com/s?__biz=MzU5NDgxODU1MQ==&mid=2247507089&idx=2&sn=3ff58b57cd637facc495fd9057d71695) - 中国信息安全 - [ ] [专题·量子安全 | QKD筑基,PQC协同:构建量子安全融合体系](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265597&idx=1&sn=865e2ed9471cd8ef4b84f95aefb0dcbe) - [ ] [沈逸:警惕个别美企为私利扰动全球AI合作](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265597&idx=2&sn=465eff39b69983efaae6edb6aae851f1) - [ ] [专家观点 | 洪延青:人工智能立法应是一部“创新组织法”](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265597&idx=3&sn=a73ffb7f8783cf1d21933856db11ab8f) - [ ] [前沿 | 中国全方位推动人工智能全球治理走深走实](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265597&idx=4&sn=9df7c45ce5fe77cdfbed9bd4cfbee0d3) - [ ] [评论 | 别让手机APP广告沦为“数字牛皮癣”](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265597&idx=5&sn=0d87e01493d3234f4ef59faf6c018924) - DataCon大数据安全分析竞赛 - [ ] [重要提醒|AI及智能体赋能安全研究专题研讨会活动报名即将截止](https://mp.weixin.qq.com/s?__biz=MzU5Njg1NzMyNw==&mid=2247489655&idx=1&sn=63187b14feb864bad73ec109d73d9fe0) - 安全圈 - [ ] [【安全圈】737个Chrome VPN扩展被曝劫持用户流量](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078262&idx=1&sn=581a6ef0d5f88a4b3d83251017c48f44) - [ ] [【安全圈】Lazarus利用Windows零日漏洞,假招聘真窃密](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078262&idx=2&sn=dd24d6b1bffa2629060c81672365d629) - [ ] [【安全圈】SharePoint漏洞PoC刚发布,就被黑客盯上利用](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078262&idx=3&sn=0eb5e034c6ee86ec40d35df86526f829) - 信息安全国家工程研究中心 - [ ] [关于“Sorry”勒索病毒的预警报告](https://mp.weixin.qq.com/s?__biz=MzU5OTQ0NzY3Ng==&mid=2247504669&idx=1&sn=fce3a0eee21902682cf0f362d418d4ff) - 安全牛 - [ ] [同一个严重漏洞,别人拿3万你只拿1万:GitHub赏金腰斩背后的"信任市场"真相](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142352&idx=1&sn=d21e412ca69fede5b4eedf47c4f0ca5b) - [ ] [落实欧盟透明规范,Anthropic上线文本水印,复制粘贴仍可溯源AI内容;Black Hat2026:开源工具将AI智能体红队测试成本降低最高125倍|牛览](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142352&idx=2&sn=a11f5171cacfde0ab333e051ce1771f5) - 丁爸 情报分析师的工具箱 - [ ] [【工具】开源情报资源网站汇总分析报告](https://mp.weixin.qq.com/s?__biz=MzI2MTE0NTE3Mw==&mid=2651156957&idx=1&sn=91c3cde87eebf38d2e7e6cb2ee739f2e) - [ ] [【议题征集】网络犯罪打击治理实战技术研讨会议题征集正式启动! | FCTS 2026 定档9月](https://mp.weixin.qq.com/s?__biz=MzI2MTE0NTE3Mw==&mid=2651156957&idx=2&sn=1d6ce471e5db89f294db1c0bd6261cb0) - 极客公园 - [ ] [全景相机的第二个 10 年,影石想革自己的命](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653111928&idx=1&sn=7356a09fa082187760ea1598714bffd7) - [ ] [当 AI 开始批量写 HTML,WorkBuddy 想解决「生成之后」的问题](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653111923&idx=1&sn=8cf1553ea1b473c519d1cdf1ae38f487) - [ ] [Deepseek V4 Pro 正式版 API 上线,百万 Token 仅 6 元;腾讯计划近期发布 HY4 大模型;曝 iPhone18 至少涨价 2000 元起 | 极客早知道](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653111877&idx=1&sn=9011e62a8f063d1d6e7ac9a9421ccb44) - 凌晨一点零三分 - [ ] [跟党走_政策板块日报2026-08-13](https://mp.weixin.qq.com/s?__biz=MzIxMjI0Mzk0OQ==&mid=2247485705&idx=1&sn=47f62163b3e25d6e0300acd8d547a8d3) - 网安国际 - [ ] [重要提醒|AI及智能体赋能安全研究专题研讨会活动报名即将截止](https://mp.weixin.qq.com/s?__biz=MzA4ODYzMjU0NQ==&mid=2652318498&idx=1&sn=a663212d986d7fc87a63ce85541badb3) - 吴鲁加 - [ ] [极简主义](https://mp.weixin.qq.com/s?__biz=Mzg5NDY4ODM1MA==&mid=2247486148&idx=1&sn=1431d6d3bee6b51b1c172d1ccb7cc322) - 360数字安全 - [ ] [校企协同育尖兵,360联合北信职打造“朝匠技弈”网络与信息安全管理员竞赛](https://mp.weixin.qq.com/s?__biz=MzA4MTg0MDQ4Nw==&mid=2247586736&idx=1&sn=d9670e124c2d3fcde87f16f1e7efd020) - 复旦白泽战队 - [ ] [AI攻防全球第二、高校第一!复旦白泽以“效能美学”跻身世界第一梯队](https://mp.weixin.qq.com/s?__biz=MzU4NzUxOTI0OQ==&mid=2247499558&idx=1&sn=28d0ac89a624daf73aeed1f22cb2e2a0) - ChaMd5安全团队 - [ ] [通关Hackaprompt靶场第十关(提示词注入最难关之一)](https://mp.weixin.qq.com/s?__biz=MzIzMTc1MjExOQ==&mid=2247514386&idx=1&sn=9be54177eb8306b843776a4b765328fb) - 墨菲安全 - [ ] [双榜收录,覆盖5大细分赛道,墨菲安全入选安全牛两大行业全景图](https://mp.weixin.qq.com/s?__biz=MzkwOTM0MjI5NQ==&mid=2247488637&idx=1&sn=a7453eb1873cc2419ef80aa146ca29c3) - 青藤智库 - [ ] [金融行业AI重构防御体系现状与发展研究专题报告](https://mp.weixin.qq.com/s?__biz=MzUyOTkwNTQ5Mg==&mid=2247489482&idx=1&sn=bc0d781e333322741618773ca31f0fcc) - 美团技术团队 - [ ] [KDD'26 美团学术论文精选及KDD Cup'26 DataAgents赛道冠军思路解读](https://mp.weixin.qq.com/s?__biz=MjM5NjQ5MTI5OA==&mid=2651783138&idx=1&sn=31ddcb07ef2bf6c73c2415934ab288dc) - NISL实验室 - [ ] [清华大学网络研究院学生参与的Blue Water国际联队勇夺DEF CON CTF全球总决赛冠军](https://mp.weixin.qq.com/s?__biz=MzUxMTEwOTA3OA==&mid=2247485800&idx=1&sn=309029033c4b1f0e526ee3b977aa4952) - Over Security - [ ] [Flock says its new tool will help identify police abuse, but hasn’t explained how it works](https://techcrunch.com/2026/08/13/flock-says-its-new-tool-will-help-identify-police-abuse-but-hasnt-explained-how-it-works/) - [ ] [Ukraine shuts down 94 fraudulent call centers, seize millions in cash](https://www.bleepingcomputer.com/news/security/ukraine-shuts-down-94-fraudulent-call-centers-seize-millions-in-cash/) - [ ] [Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt](https://www.bleepingcomputer.com/news/security/akira-hackers-disable-edr-with-safe-mode-steal-data-but-fail-to-encrypt/) - [ ] [Curiouser and Curiouser](https://blog.talosintelligence.com/curiouser-and-curiouser/) - [ ] [Hackers breach govt webmail while running parallel crypto fraud](https://www.bleepingcomputer.com/news/security/hackers-breach-govt-webmail-while-running-parallel-crypto-fraud/) - [ ] [Microsoft patches LegacyHive Windows zero-day vulnerability](https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-legacyhive-windows-zero-day-vulnerability/) - [ ] [AI 'watermark removers' flood the web. Almost none can prove they work.](https://www.bleepingcomputer.com/news/security/ai-watermark-removers-flood-the-web-almost-none-can-prove-they-work/) - [ ] [Flock tightens privacy controls amid scandals over officer abuse](https://therecord.media/flock-safety-audit-assistance-police-departments) - [ ] [Critical VMware vCenter RCE flaw exploited for reverse SSH access](https://www.bleepingcomputer.com/news/security/critical-vmware-vcenter-rce-flaw-exploited-for-reverse-ssh-access/) - [ ] [New Mirai variant adds stealth capabilities to notorious botnet code](https://therecord.media/new-mirai-variant-adds-stealth-to-botnet-code) - [ ] [Hack back, Trump rompe il tabù: i privati entrano nella cyber offensiva, ecco i rischi](https://www.cybersecurity360.it/news/memorandum-trump-aziende-usa-possono-fare-cyber-attacchi/) - [ ] [Trezor discloses data breach affecting nearly 14,000 customers](https://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-nearly-14-000-customers/) - [ ] [GPT-5.6-Cyber trova zero-day e sviluppa exploit: la cyber difesa cambia passo](https://www.cybersecurity360.it/news/gpt-5-6-cyber-trova-zero-day-e-sviluppa-exploit-la-cyber-difesa-cambia-passo/) - [ ] [Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion](https://www.bleepingcomputer.com/news/security/who-vets-ais-code-the-scale-challenge-facing-open-source-ingestion/) - [ ] [Navigating AI-Driven Cyber Threats: Insights from Flashpoint’s 2026 GTIR Midyear Edition](https://flashpoint.io/blog/flashpoint-global-threat-intelligence-report-midyear-2026/) - [ ] [Trump taps cyber firms to go on offensive against criminals](https://therecord.media/trump-cyber-crime-offensive) - [ ] [Brazil orders Discord to suspend livestreaming after teen suicide](https://therecord.media/discord-brazil-orders-suspension-livestreaming) - [ ] [White House taps security firms for offensive hack-back operations](https://www.bleepingcomputer.com/news/security/white-house-taps-security-firms-for-offensive-hack-back-operations/) - [ ] [Come stai usando l’EDR?](https://roccosicilia.com/2026/08/13/come-stai-usando-ledr/) - [ ] [Germany moves to give spy agencies hacking and sabotage powers](https://therecord.media/germany-spy-agency-powers) - [ ] [FIRST e incident response: la resilienza cyber si costruisce facendo rete](https://www.cybersecurity360.it/soluzioni-aziendali/first-e-incident-response-la-resilienza-cyber-si-costruisce-facendo-rete/) - [ ] [WhatsApp rolls out new feature that flags potential scam messages](https://www.bleepingcomputer.com/news/security/whatsapp-rolls-out-new-feature-that-flags-potential-scam-messages/) - [ ] [RingCentral - 1,596,490 breached accounts](https://haveibeenpwned.com/Breach/RingCentral) - [ ] [Dissecting the JWR phishing framework](https://blog.talosintelligence.com/dissecting-the-jwr-phishing-framework/) - [ ] [Trasparenza VPN e giurisdizione: la sfida di Proton tra codice Open Source e audit pubblici](https://www.cybersecurity360.it/cultura-cyber/proton-vpn-open-source-audit-no-log/) - [ ] [July 2026 Cyber Attacks Statistics](https://www.hackmageddon.com/2026/08/13/july-2026-cyber-attacks-statistics/) - [ ] [July 2026 Cyber Attacks Statistics Infographic](https://www.hackmageddon.com/2026/08/13/july-2026-cyber-attacks-statistics-infographic/) - [ ] [Identificazione biometrica in tempo reale: la sfida è impedire che l’eccezione diventi la regola](https://www.cybersecurity360.it/legal/identificazione-biometrica-in-tempo-reale-la-sfida-e-impedire-che-leccezione-diventi-la-regola/) - [ ] [Smishing INPS, l’AI entra nella catena d’attacco per rendere la truffa più credibile](https://www.cybersecurity360.it/news/smishing-inps-lai-entra-nella-catena-dattacco-per-rendere-la-truffa-piu-credibile/) - [ ] [CEVA Logistics Cyberattack Disrupts European Warehouses, Exposes Customer Data](https://thecyberexpress.com/ceva-logistics-cyberattack/) - [ ] [One Adversary: The Fifteen-Minute Problem](https://www.group-ib.com/blog/15-minute-problem/) - [ ] [Armored Likho expands its cyber-espionage toolkit](https://securelist.com/armored-likho-still-toolkit/121033/) - [ ] [NIST Moves to Modernize NVD as AI Reshapes Vulnerability Management](https://thecyberexpress.com/national-vulnerability-database/) - [ ] [Internal Auditing e AI: la Cognitive Governance protegge l’autonomia del giudizio](https://www.cybersecurity360.it/legal/internal-auditing-e-ai-la-cognitive-governance-protegge-lautonomia-del-giudizio/) - [ ] [Agenti AI contro Taiwan: la guerra cyber entra nell’era degli attacchi autonomi](https://www.cybersecurity360.it/news/agenti-ai-contro-taiwan-la-guerra-cyber-entra-nellera-degli-attacchi-autonomi/) - [ ] [Hackers Target Social Media Accounts to Steal Explicit Content, FBI Warns](https://thecyberexpress.com/sexual-exploitation-actors-stealing-content/) - TrustedSec - [ ] [AI Offense is Not Noclip Mode](https://trustedsec.com/blog/ai-offense-is-not-noclip-mode) - 安全行者老霍 - [ ] [如何尽可能保持你与 ChatGPT、Gemini、Copilot 或 Claude 的对话隐私](https://mp.weixin.qq.com/s?__biz=Mzg3NjU4MDI4NQ==&mid=2247486896&idx=1&sn=d590259b5c12876a56eeffe531adf30c) - Qualys Security Blog - [ ] [Why API Discovery Is Critical for Modern AppSec Programs](https://blog.qualys.com/category/misc) - 技术猫屋 - [ ] [Transformer 之后,AI 到底在进步什么?](https://mp.weixin.qq.com/s?__biz=Mzg4MzYxODA4Mw==&mid=2247484111&idx=1&sn=a87a0e61aece53bb8b00fe1bb5bbddbc) - SANS Internet Storm Center, InfoCON: green - [ ] [ISC Stormcast For Thursday, August 13th, 2026 https://isc.sans.edu/podcastdetail/10050, (Thu, Aug 13th)](https://isc.sans.edu/diary/rss/33244) - [ ] [Using Gemma4 with Ollama - Testing File Hash Analysis and Recommendations with AI, (Wed, Aug 12th)](https://isc.sans.edu/diary/rss/33242) - Daniel Miessler - [ ] [Ilya Explains How LLMs Create a World Model](https://danielmiessler.com/blog/ilya-explains-how-llms-create-a-world-model?utm_source=rss&utm_medium=feed&utm_campaign=website) - Schneier on Security - [ ] [Separating AI’s Technological Problems from Its Capitalism Problems](https://www.schneier.com/blog/archives/2026/08/separating-ais-technological-problems-from-its-capitalism-problems.html) - Have I Been Pwned latest breaches - [ ] [RingCentral - 1,596,490 breached accounts](https://haveibeenpwned.com/Breach/RingCentral) - Full Disclosure - [ ] [APPLE-SA-08-06-2026-2 macOS Sequoia 15.7.9](https://seclists.org/fulldisclosure/2026/Aug/37) - [ ] [APPLE-SA-08-06-2026-3 macOS Sonoma 14.8.9](https://seclists.org/fulldisclosure/2026/Aug/36) - 威胁猎人Threat Hunter - [ ] [搜索“代下单”之后,我们挖出了一条快消餐饮代下黑产产业链](https://mp.weixin.qq.com/s?__biz=MzI3NDY3NDUxNg==&mid=2247505002&idx=1&sn=9b72e6a23c01f6a1888f3d979e86cd26) - Security Affairs - [ ] [Adobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public Disclosure](https://securityaffairs.com/197149/hacking/adobe-commerce-cve-2026-71362-comes-under-attack-shortly-after-public-disclosure.html) - [ ] [U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog](https://securityaffairs.com/197110/hacking/u-s-cisa-adds-metabase-windows-and-cisco-secure-firewall-flaws-to-its-known-exploited-vulnerabilities-catalog.html) - [ ] [SharePoint CVE-2026-55040 Comes Under Attack Following Public Exploit](https://securityaffairs.com/197137/hacking/sharepoint-cve-2026-55040-comes-under-attack-following-public-exploit.html) - [ ] [Storm-1175 Replaces Medusa With New StormEncryptor Ransomware](https://securityaffairs.com/197119/malware/storm-1175-replaces-medusa-with-new-stormencryptor-ransomware.html) - [ ] [North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job](https://securityaffairs.com/197098/uncategorized/north-korean-lazarus-group-uses-windows-zero-day-in-operation-dream-job.html) - www.theregister.com - Articles - [ ] [Trump wants to grant private cyber firms a license to hack back](https://www.theregister.com/security/2026/08/13/trump-wants-to-grant-private-cyber-firms-a-license-to-hack-back/5287420) - [ ] [The backup Microsoft never promised you](https://www.theregister.com/security/2026/08/13/sponsored-the-backup-microsoft-never-promised-you/5284957) - [ ] [AWS key exposed in JavaScript may have lit way to Beacon's charity data](https://www.theregister.com/security/2026/08/13/aws-key-exposed-in-javascript-may-have-lit-way-to-beacons-charity-data/5287303) - [ ] [Passwords stored in public Google Doc then showed up in search results](https://www.theregister.com/security/2026/08/13/passwords-stored-in-public-google-doc-then-showed-up-in-search-results/5287028) - [ ] [Chinese Loongson processors have leaky caches, researchers find](https://www.theregister.com/security/2026/08/13/chinese-loongson-processors-have-leaky-caches-researchers-find/5287137) - Deeplinks - [ ] [Too Little, Too Late: Flock Admits Their Technology Needs Reforms](https://www.eff.org/deeplinks/2026/08/too-little-too-late-flock-admits-their-technology-needs-reforms) - Instapaper: Unread - [ ] [Terabytes of credentials leaked in massive supply-chain attack](https://arstechnica.com/security/2026/08/terabytes-of-credentials-leaked-in-massive-supply-chain-attack/) - 悬镜安全 - [ ] [权威认可|悬镜安全持续引领《中国网络安全行业全景图(第十三版)》!](https://mp.weixin.qq.com/s?__biz=MzA3NzE2ODk1Mg==&mid=2647800120&idx=1&sn=f94e4e2531a31511c4078660c3d2cae5) - The Hacker News - [ ] [Attackers Exploit SharePoint Authentication Bypass After Public PoC Release](https://thehackernews.com/2026/08/attackers-exploit-sharepoint.html) - Security Weekly Podcast Network (Audio) - [ ] [The Breached WiFi AI Ports... What? - PSW #939](http://sites.libsyn.com/18678/the-breached-wifi-ai-ports-what-psw-939) - 网安寻路人 - [ ] [人工智能立法应是一部“创新组织法”](https://mp.weixin.qq.com/s?__biz=MzIxODM0NDU4MQ==&mid=2247508822&idx=1&sn=0d000685effdaef1f95b03fa836c21a8)
每日安全资讯(2026-08-14)