# 每日安全资讯(2026-08-18) - SecWiki News - [ ] [SecWiki News 2026-08-17 Review](http://www.sec-wiki.com/?2026-08-17) - 安全客-有思想的安全新媒体 - [ ] [1.1万个网站正被围攻!WordPress登录页惊现XSS2Shell漏洞,无需账号就能摸到服务器](https://www.anquanke.com/post/id/315980) - [ ] [满分10.0的漏洞,补丁发布3天就被打穿](https://www.anquanke.com/post/id/315976) - [ ] [40分钟,2500家企业195TB数据被洗劫:AI供应链的"至暗时刻"才刚刚开始](https://www.anquanke.com/post/id/315973) - Doonsec's feed - [ ] [codex 使用 first 的 mcp 分析小程序](https://mp.weixin.qq.com/s/Q8U-51iJprsp9UI6uzocHQ) - [ ] [习近平总书记指引企业坚定不移走高质量发展之路](https://mp.weixin.qq.com/s/qXt6uiMCXIDj0vixB9E0LQ) - [ ] [金牌酒店服务员上岗!人形机器人宾客服务岗比赛规则揭秘](https://mp.weixin.qq.com/s/Gn2UmYb0GUl89wADVnqSVQ) - [ ] [慢雾(SlowMist) × ME Group 邀您共探稳定币合规与智能体支付](https://mp.weixin.qq.com/s/hNj4my28ZAjl1xQ0ZHJk2A) - [ ] [【重要通知】2026 年上海市工程系列数字技术专业高级职称评审网申启动!](https://mp.weixin.qq.com/s/tjA54WWJAVHnZYm-BrcR7g) - [ ] [AI Agent不再依赖固定恶意软件:失败后会自动重写工具继续攻击](https://mp.weixin.qq.com/s/AKMGQSJMXRkYEShY_myTTQ) - [ ] [欧盟《网络弹性法案》(Cyber Resilience Act,简称CRA)合规检测方法](https://mp.weixin.qq.com/s/1Jkx6ASOowHfES76rmvDKg) - [ ] [矢安科技实力入选安全牛《中国网络安全行业全景图》与《AI+网络安全全景图》多项核心领域](https://mp.weixin.qq.com/s/rb4W-HMNkhDd6W8vzYkn-g) - [ ] [AI时代的API:当“合法”流量成为威胁](https://mp.weixin.qq.com/s/cg6KFGHKVpazPBACXo1ETA) - [ ] [8月17日高危CVE漏洞速报](https://mp.weixin.qq.com/s/KK4w6QmEfOkB6trnt4kdqA) - [ ] [Hugging Face事件反思:Agent攻击者已经到来](https://mp.weixin.qq.com/s/OfqMBAe8yND-0sz5kBeH1A) - [ ] [AI让漏洞暴增72%,NIST求助AI管理漏洞库](https://mp.weixin.qq.com/s/YT1YTulsAZ4LN-bEufoUBA) - [ ] [漏洞复现 | 聚恒中台 data.aspx 任意文件上传漏洞](https://mp.weixin.qq.com/s/F7YuUpgICQ1I3AIYTVGRhg) - [ ] [分享的图片、视频、链接](https://mp.weixin.qq.com/s/ljB4oJoNp-KqA6b1ED_0Fg) - [ ] [一次被客户“骂”出来的服务升级](https://mp.weixin.qq.com/s/bDukUNHNEnM_-ifslUYScg) - Private Feed for M09Ic - [ ] [esrrhs contributed to esrrhs/fakecc](https://github.com/esrrhs/fakecc/pull/16) - [ ] [esrrhs contributed to esrrhs/fakelua](https://github.com/esrrhs/fakelua/pull/362) - [ ] [mgeeky starred langfuse/langfuse](https://github.com/langfuse/langfuse) - [ ] [anthropics released v2.1.234 at anthropics/claude-code](https://github.com/anthropics/claude-code/releases/tag/v2.1.234) - [ ] [kpcyrd contributed to KillingSpark/zstd-rs](https://github.com/KillingSpark/zstd-rs/pull/119) - [ ] [bolucat released 202608172047 at bolucat/Archive](https://github.com/bolucat/Archive/releases/tag/202608172047) - [ ] [kpcyrd contributed to kpcyrd/repro-env](https://github.com/kpcyrd/repro-env/pull/59) - [ ] [kpcyrd forked kpcyrd/zstd-rs from KillingSpark/zstd-rs](https://github.com/kpcyrd/zstd-rs) - [ ] [chainreactors released v0.0.0-nightly.20260817 at chainreactors/aiscan](https://github.com/chainreactors/aiscan/releases/tag/v0.0.0-nightly.20260817) - [ ] [Mr-xn starred Forget-C/Jellyfish](https://github.com/Forget-C/Jellyfish) - [ ] [OpenAEV-Platform released 3.260817.0 at OpenAEV-Platform/openaev](https://github.com/OpenAEV-Platform/openaev/releases/tag/3.260817.0) - [ ] [shmilylty forked shmilylty/h-script-4 from 0x241/h-script-4](https://github.com/shmilylty/h-script-4) - [ ] [liamg contributed to infracost/lsp](https://github.com/infracost/lsp/pull/69) - [ ] [liamg contributed to infracost/cli](https://github.com/infracost/cli/pull/208) - [ ] [liamg contributed to infracost/actions](https://github.com/infracost/actions/pull/286) - [ ] [ManassehZhou starred cloudflare/computer](https://github.com/cloudflare/computer) - [ ] [shmilylty starred 80000v/IonCube_Decoder](https://github.com/80000v/IonCube_Decoder) - [ ] [TideSec starred kkbo8005/mitan](https://github.com/kkbo8005/mitan) - [ ] [liamg contributed to infracost/config](https://github.com/infracost/config/pull/29) - [ ] [xgo-dev released v1.0.0-pre.1 at xgo-dev/llgo](https://github.com/xgo-dev/llgo/releases/tag/v1.0.0-pre.1) - [ ] [mgeeky starred xec412/NocturneLdr](https://github.com/xec412/NocturneLdr) - Tenable Blog - [ ] [Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities](https://www.tenable.com/blog/detecting-cloud-ransomware-in-azure-with-tenable-ones-cloud-detection-and-response) - Sploitus.com Exploits RSS Feed - [ ] [Exploit for CVE-2026-19478](https://sploitus.com/exploit?id=D00C9C33-92C2-5141-945C-CEF52CA20CC6&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-15748](https://sploitus.com/exploit?id=ED194BDD-4507-54C8-935F-D3E6F1FD1EB9&utm_source=rss&utm_medium=rss) - [ ] [qwen3.8-9b-cyber-exploit-agent-uncensored](https://sploitus.com/exploit?id=00B37D2C-7FB1-5F5E-9CC5-2B6BE8F6D124&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Classic Buffer Overflow in Cisco Secure_Endpoint](https://sploitus.com/exploit?id=474F877A-64AB-5989-836A-908CAC772214&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-71518](https://sploitus.com/exploit?id=1FA99D42-7CBF-5696-9184-2296F382F906&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Authentication Bypass Using an Alternate Path or Channel in Sangoma Freepbx](https://sploitus.com/exploit?id=C040B40C-390A-5021-BCC4-B56292CD14F0&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-20079](https://sploitus.com/exploit?id=40880921-C39C-58D4-B99F-0A7459D57358&utm_source=rss&utm_medium=rss) - [ ] [CVE-2026-54284 exploit](https://sploitus.com/exploit?id=CVE-2026-54284&utm_source=rss&utm_medium=rss) - [ ] [CVE-2026-59893 exploit](https://sploitus.com/exploit?id=CVE-2026-59893&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Untrusted Pointer Dereference in Microsoft](https://sploitus.com/exploit?id=CD74BF15-81FC-5A29-8E61-DAF091D0A1CF&utm_source=rss&utm_medium=rss) - [ ] [CVE-2026-71491 exploit](https://sploitus.com/exploit?id=CVE-2026-71491&utm_source=rss&utm_medium=rss) - [ ] [CVE-2026-59894 exploit](https://sploitus.com/exploit?id=CVE-2026-59894&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-39154](https://sploitus.com/exploit?id=BC5D7707-5A5A-5786-BD0E-D288963D7239&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Exposure of Private Personal Information to an Unauthorized Actor in Mozilla Firefox](https://sploitus.com/exploit?id=4BBD844A-1D89-5DBC-A60C-E9C7B87C249C&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-13714](https://sploitus.com/exploit?id=78AF2541-3A40-56FE-9DC6-3FC9069101DB&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Incorrect Authorization in Qualcomm Aqt1000_Firmware](https://sploitus.com/exploit?id=D588D372-1BF3-5AC2-9829-495D0AE07D2A&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-40345](https://sploitus.com/exploit?id=9237F56D-2B4D-570E-81BF-CDAFEC0CC1D5&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-41042](https://sploitus.com/exploit?id=DF2CC3E3-623C-50C1-8CEE-0982B5938EC3&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Deserialization of Untrusted Data in Facebook React](https://sploitus.com/exploit?id=D8E4A8EB-1F82-5B56-95F9-55D700D8E8F3&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-59310](https://sploitus.com/exploit?id=47AAAA22-A501-52A4-912C-B1D34623A22E&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-68138](https://sploitus.com/exploit?id=34E0F961-E95A-5787-8902-6800A2580B57&utm_source=rss&utm_medium=rss) - [ ] [avicii-ghostlock exploit](https://sploitus.com/exploit?id=4B059425-25FF-5B28-94ED-5E2E3A60C91E&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Improper Resource Shutdown or Release in Microsoft](https://sploitus.com/exploit?id=772F7610-9633-5066-8D89-2502DEB81FC1&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-31367](https://sploitus.com/exploit?id=203AB413-4EA7-5DE8-A37D-8B92BD00DB32&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-74251](https://sploitus.com/exploit?id=FFED6F3F-8612-5429-8496-A121DC3A606E&utm_source=rss&utm_medium=rss) - [ ] [- exploit](https://sploitus.com/exploit?id=180C97CF-57DD-533C-9A59-03E64D9B79AB&utm_source=rss&utm_medium=rss) - [ ] [vuln-archive-skills exploit](https://sploitus.com/exploit?id=E483F65F-4B4A-5EAD-A0E6-104F862446A0&utm_source=rss&utm_medium=rss) - [ ] [ID3dr exploit](https://sploitus.com/exploit?id=7B881936-2FBE-5CBC-A15F-FBEE37C81906&utm_source=rss&utm_medium=rss) - [ ] [IX-StellaratorForge exploit](https://sploitus.com/exploit?id=1F50AF1F-24B9-53CF-8755-46F3B2EA2187&utm_source=rss&utm_medium=rss) - obaby 𝐢𝐧⃝ void - [ ] [Findu — 十年](https://zhongxiaojie.cn/2026/08/1728/) - Recent Commits to cve:main - [ ] [Update Mon Aug 17 12:13:59 UTC 2026](https://github.com/trickest/cve/commit/1f04f5c064b08fe260cb363f580d04c039b05ffd) - Bug Bounty in InfoSec Write-ups on Medium - [ ] [Hacker Holidays 2026: Day 8 Walkthrough (Towel on the Sunbed)](https://infosecwriteups.com/hacker-holidays-2026-day-8-walkthrough-towel-on-the-sunbed-4cd1f708eb3c?source=rss----7b722bfd1b8d--bug_bounty) - Malwarebytes - [ ] [ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw](https://www.malwarebytes.com/blog/bugs/2026/08/shieldbreak-bypasses-microsofts-patch-for-earlier-defender-flaw) - [ ] [Fake TikTok rewards promise cash you’ll never get](https://www.malwarebytes.com/blog/scams/2026/08/fake-tiktok-rewards-promise-cash-youll-never-get) - [ ] [Update your Mac: Screen Sharing vulnerability exploited in the wild](https://www.malwarebytes.com/blog/bugs/2026/08/update-your-mac-screen-sharing-vulnerability-exploited-in-the-wild) - [ ] [Why Facebook’s war on ad blockers could help scammers](https://www.malwarebytes.com/blog/news/2026/08/why-facebooks-war-on-ad-blockers-could-help-scammers) - [ ] [A week in security (August 10 – August 16)](https://www.malwarebytes.com/blog/news/2026/08/a-week-in-security-august-10-august-16) - daniel.haxx.se - [ ] [There’s a libcurl.dll in my system32](https://daniel.haxx.se/blog/2026/08/17/theres-a-libcurl-dll-in-my-system32/) - Exploit-DB.com RSS Feed - [ ] [[dos] NanaZip 6.5 - DoS](https://www.exploit-db.com/exploits/52652) - [ ] [[webapps] flyto_core 2.26.7 - Server-Side Request Forgery](https://www.exploit-db.com/exploits/52651) - [ ] [[webapps] Probo 0.222.2 - IDOR](https://www.exploit-db.com/exploits/52650) - [ ] [[webapps] webpack_devserver 5.2.5 - CSRF](https://www.exploit-db.com/exploits/52649) - [ ] [[remote] phpSysInfo 3.4.5 - IP Allowlist Bypass](https://www.exploit-db.com/exploits/52648) - [ ] [[dos] Nmap 7.99 - Extension Header Integer Underflow](https://www.exploit-db.com/exploits/52647) - [ ] [[webapps] Duplicati 2.2.0.3 - JWT Signing Key Leak](https://www.exploit-db.com/exploits/52646) - [ ] [[webapps] Joomla JCE_2.9.15 - Remote Code Execution](https://www.exploit-db.com/exploits/52645) - [ ] [[remote] ipTIME A3004T - Remote Code Execution](https://www.exploit-db.com/exploits/52644) - [ ] [[remote] D-Link DNS_340L - OS Command Injection](https://www.exploit-db.com/exploits/52643) - [ ] [[webapps] WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload](https://www.exploit-db.com/exploits/52642) - 黑海洋Wiki | AI机器人硬件开发 | 网络安全攻防实战 | 区块链技术文档教程 - 免费资源平台 - [ ] [Anthropic“年化营收”据传已突破650亿美元](https://blog.upx8.com/Anthropic-%E5%B9%B4%E5%8C%96%E8%90%A5%E6%94%B6-%E6%8D%AE%E4%BC%A0%E5%B7%B2%E7%AA%81%E7%A0%B4650%E4%BA%BF%E7%BE%8E%E5%85%83) - [ ] [会“飞”的车要来了?特斯拉新一代Roadster据称将于本月亮相](https://blog.upx8.com/%E4%BC%9A-%E9%A3%9E-%E7%9A%84%E8%BD%A6%E8%A6%81%E6%9D%A5%E4%BA%86-%E7%89%B9%E6%96%AF%E6%8B%89%E6%96%B0%E4%B8%80%E4%BB%A3Roadster%E6%8D%AE%E7%A7%B0%E5%B0%86%E4%BA%8E%E6%9C%AC%E6%9C%88%E4%BA%AE%E7%9B%B8) - [ ] [🖼 重要: Hurricane Electric (HE AS 6939) 与 Cloudflare (AS 13335) 断开对等互联](https://blog.upx8.com/%E9%87%8D%E8%A6%81-Hurricane-Electric-HE-AS-6939-%E4%B8%8E-Cloudflare-AS-13335-%E6%96%AD%E5%BC%80%E5%AF%B9%E7%AD%89%E4%BA%92%E8%81%94) - [ ] [亚马逊采购珍稀书籍拆解后用于AI训练](https://blog.upx8.com/%E4%BA%9A%E9%A9%AC%E9%80%8A%E9%87%87%E8%B4%AD%E7%8F%8D%E7%A8%80%E4%B9%A6%E7%B1%8D%E6%8B%86%E8%A7%A3%E5%90%8E%E7%94%A8%E4%BA%8EAI%E8%AE%AD%E7%BB%83) - [ ] [iPhone 17系列或月底前全球涨价,单台最高多花近千元](https://blog.upx8.com/iPhone-17%E7%B3%BB%E5%88%97%E6%88%96%E6%9C%88%E5%BA%95%E5%89%8D%E5%85%A8%E7%90%83%E6%B6%A8%E4%BB%B7-%E5%8D%95%E5%8F%B0%E6%9C%80%E9%AB%98%E5%A4%9A%E8%8A%B1%E8%BF%91%E5%8D%83%E5%85%83) - [ ] [阿里巴巴推出AI音乐模型“快乐虾米”](https://blog.upx8.com/%E9%98%BF%E9%87%8C%E5%B7%B4%E5%B7%B4%E6%8E%A8%E5%87%BAAI%E9%9F%B3%E4%B9%90%E6%A8%A1%E5%9E%8B-%E5%BF%AB%E4%B9%90%E8%99%BE%E7%B1%B3) - [ ] [豆包“工作任务”模式升级 支持手机远程操控电脑](https://blog.upx8.com/%E8%B1%86%E5%8C%85-%E5%B7%A5%E4%BD%9C%E4%BB%BB%E5%8A%A1-%E6%A8%A1%E5%BC%8F%E5%8D%87%E7%BA%A7-%E6%94%AF%E6%8C%81%E6%89%8B%E6%9C%BA%E8%BF%9C%E7%A8%8B%E6%93%8D%E6%8E%A7%E7%94%B5%E8%84%91) - 奇客Solidot–传递最新科技情报 - [ ] [对一批珍稀图书的跟踪显示它们进入了亚马逊的 AI 训练设施](https://www.solidot.org/story?sid=85119) - [ ] [阿里巴巴开放权重模型下载量过去半年突破 30 亿](https://www.solidot.org/story?sid=85118) - [ ] [OpenAI 举报了一名在与 ChatGPT 聊天中透露奸杀前女友计划的佛罗里达男子](https://www.solidot.org/story?sid=85117) - [ ] [谁决定中文维基条目的删除?](https://www.solidot.org/story?sid=85116) - [ ] [中国货轮开辟北极航线](https://www.solidot.org/story?sid=85115) - [ ] [GIMP 准备推出新的项目文件格式](https://www.solidot.org/story?sid=85114) - [ ] [微软将移除有 25 年历史的命令行工具 WMIC](https://www.solidot.org/story?sid=85113) - [ ] [刻薄话让你在社媒上更引人瞩目](https://www.solidot.org/story?sid=85112) - [ ] [Waymo 从中国进口了 3200 辆 Zeekr 自动驾驶汽车](https://www.solidot.org/story?sid=85111) - [ ] [美国一原告在法庭文件中植入针对 LLM 的提示词](https://www.solidot.org/story?sid=85109) - [ ] [Linux 7.2 释出](https://www.solidot.org/story?sid=85108) - rtl-sdr.com - [ ] [Detecting Dark Matter’s Mark with an RTL-SDR Based DIY Radio Telescope](https://www.rtl-sdr.com/detecting-dark-matters-mark-with-an-rtl-sdr-based-diy-radio-telescope/) - [ ] [DXLens: An iOS App Combining Shortwave Schedules, Propagation Data and Public SDRs](https://www.rtl-sdr.com/dxlens-an-ios-app-combining-shortwave-schedules-propagation-data-and-public-sdrs/) - 黑鸟 - [ ] [一梳理汇总Windows内核驱动漏洞数据的项目](https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451188129&idx=1&sn=de3e34dbedd4dad61192e0f42219e693) - 我的安全视界观 - [ ] [我的读书笔记:像经营企业一样经营自己](https://mp.weixin.qq.com/s?__biz=MzI3Njk2OTIzOQ==&mid=2247487944&idx=1&sn=25ef0fb38628396242dae990ee73f5d6) - 威努特安全网络 - [ ] [威努特水务工控“主动防护”体系建设实战复盘](https://mp.weixin.qq.com/s?__biz=MzAwNTgyODU3NQ==&mid=2651143539&idx=1&sn=45eba3513d417191fb8a23f06a3a97c5) - 风雪之隅 - [ ] [Wechatian: 让AI有事就来微信找你](https://www.laruence.com/2026/08/17/6297.html) - 安全内参 - [ ] [Claude AI文本隐形水印是如何实现的?该怎么破解?](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516436&idx=1&sn=189b73af9f2e995558defd840e65318a) - [ ] [今年首家民营银行因网络安全、数据安全等问题被罚](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516436&idx=2&sn=2efde59f62d3056cef5dcab84fdbd69a) - 安全分析与研究 - [ ] [第12篇-勒索软件加密技术解析](https://mp.weixin.qq.com/s?__biz=MzA4ODEyODA3MQ==&mid=2247497023&idx=1&sn=5d76544728b68e8852818cafa2bd527b) - 看雪学苑 - [ ] [2026 KCTF | 第四题《未时·车流困城》设计思路及解析](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458618719&idx=1&sn=6355333d9362204ee35edd228dae4422) - [ ] [奖金翻倍!荣耀终端安全奖励计划众测活动开启](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458618719&idx=2&sn=7b2b6c446153a133ad4be76e87006bf9) - [ ] [隐私加密通讯平台Threema遭大规模DDoS攻击,服务大面积瘫痪](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458618719&idx=3&sn=d1b68fa20048db75baf1f4f0de3fb73c) - 安全客 - [ ] [40分钟,2500家企业195TB数据被洗劫:AI供应链的"至暗时刻"才刚刚开始](https://mp.weixin.qq.com/s?__biz=MzA5ODA0NDE2MA==&mid=2649790372&idx=1&sn=971d2156e26988d7899b528d820b2153) - 信息安全国家工程研究中心 - [ ] [大模型安全治理面临“大考”](https://mp.weixin.qq.com/s?__biz=MzU5OTQ0NzY3Ng==&mid=2247504683&idx=1&sn=a69b35a668395233168e9f846ca94dd3) - 安全圈 - [ ] [【安全圈】微软紧急修复Defender零日漏洞ShieldBreak](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078325&idx=1&sn=93bd6a880d3d68bdabd3da207d8c6ee7) - [ ] [【安全圈】Azure数据窃取行动击中多家财富500强企业](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078325&idx=2&sn=49343f86ab9cad635bd08857d8e83588) - [ ] [【安全圈】Fortinet修复FortiWeb和FortiManager严重认证漏洞](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078325&idx=3&sn=d8bf16a89aca711acbbae0a6ed783ed1) - 君哥的体历 - [ ] [OVTP范式下的权限管控、域名异常指向溯源与AI大模型告警研判探讨|总第318周](https://mp.weixin.qq.com/s?__biz=MzI2MjQ1NTA4MA==&mid=2247492529&idx=1&sn=fcf4abba11c431a4ec172dd3e52755a4) - 天御攻防实验室 - [ ] [美国战略司令部司令:“已不存在所谓地区冲突,在信息域中,每一场冲突都是全球性的。”](https://mp.weixin.qq.com/s?__biz=MzU0MzgyMzM2Nw==&mid=2247487126&idx=1&sn=dedabaab3edcae105713ec41d06f8929) - 电子物证 - [ ] [【走近法律监督幕后的技术尖兵】](https://mp.weixin.qq.com/s?__biz=MzAwNDcwMDgzMA==&mid=2651049115&idx=1&sn=a9e947ff3354c54b73f8ffed5a7ad666) - [ ] [【Docker容器是什么】](https://mp.weixin.qq.com/s?__biz=MzAwNDcwMDgzMA==&mid=2651049115&idx=2&sn=2fb916c3a7fc94efb9cf671733c87dc9) - 数世咨询 - [ ] [快更新修复,龙芯处理器存在架构层面漏洞](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247543687&idx=1&sn=318b3875f74e2ea841085eb5de8afb17) - RapidDNS - [ ] [AI自动化漏洞挖掘赚取赏金实战(一)](https://mp.weixin.qq.com/s?__biz=Mzg4NDU0ODMxOQ==&mid=2247485867&idx=1&sn=71591fffff53c435f10fcd1f75474af3) - [ ] [红队实战利器:RapidDNS CLI + Nuclei/Httpx 打造自动化漏洞挖掘流水线](https://mp.weixin.qq.com/s?__biz=Mzg4NDU0ODMxOQ==&mid=2247485867&idx=2&sn=7e4072cd9c51be194ff1d6444991083d) - [ ] [RapidDNS Pro:高级搜索语法指南](https://mp.weixin.qq.com/s?__biz=Mzg4NDU0ODMxOQ==&mid=2247485867&idx=3&sn=a00f6a5a9b9e9e3ae48e78f96d1ddf37) - [ ] [RapidDNS Pro 上线:解锁百万级数据导出,与终身会员计划](https://mp.weixin.qq.com/s?__biz=Mzg4NDU0ODMxOQ==&mid=2247485867&idx=4&sn=54a2a848922beb91790080dc968902c2) - M01N Team - [ ] [AI安全案例分析 | 专有LLM加密推理块可被跨模型重放窃取](https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&mid=2247495414&idx=1&sn=a6fc2b5a59e87a901d122671bceaaef7) - 安全牛 - [ ] [补丁还没出,攻击已经来了:一份给一线工程师的"无补丁生存"实操清单](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142368&idx=1&sn=8fdd3476674d652bf0174589a40cce39) - [ ] [CNNVD发布信息安全漏洞周报第845期;Meta押注“人人可用”AI,Glimmer开放背后的安全与信任挑战| 牛览](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142368&idx=2&sn=911a98d80b027e5d1cd0916f01d35108) - 微步在线 - [ ] [已上线!首个AI中转站封禁神器](https://mp.weixin.qq.com/s?__biz=MzI5NjA0NjI5MQ==&mid=2650187745&idx=1&sn=eeb7119d6d6126e669088cf4bfcb58a8) - 极客公园 - [ ] [从「拍得到」到「拍得成」:大疆如何重塑全景影像天花板](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653112066&idx=1&sn=dddc1a6b20854fcb4b55f92fcf276532) - [ ] [问界「童车」上市,华为联合设计;DeepSeek 涨价策略今日实行;大学生用 AI 人脸视频盗刷 5 万元被判刑](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653112042&idx=1&sn=8022f4d749430af49530268bc98ede02) - 安全419 - [ ] [智谱GLM-5.3正式发布 国产大模型或重塑全球网络安全攻防格局](https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&mid=2247554483&idx=1&sn=405887094e6df783355fbb53708e28f3) - OnionSec - [ ] [求职意向:终端安全与安全运营治理方向](https://mp.weixin.qq.com/s?__biz=MzUyMTUwMzI3Ng==&mid=2247485942&idx=1&sn=0178437bd744c36877827bd0d4007267) - 慢雾科技 - [ ] [慢雾(SlowMist) × ME Group 邀您共探稳定币合规与智能体支付](https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&mid=2247505685&idx=1&sn=428c4ed1331b50582d1c5e726f521e97) - Krypt3ia - [ ] [Integrity Technology Group: commercial infrastructure for PRC cyber operations](https://krypt3ia.wordpress.com/2026/08/17/integrity-technology-group-commercial-infrastructure-for-prc-cyber-operations/) - 洞源实验室 - [ ] [AI会让安全岗位消失吗?DEFCON之后,两位一线研究者给出了相似的答案](https://mp.weixin.qq.com/s?__biz=Mzg4Nzk3MTg3MA==&mid=2247488762&idx=1&sn=49cdb1d27bc3b3c322fe893c9bcb15ed) - Vimeo / OffSec’s videos - [ ] [Week 8](https://vimeo.com/1218932733) - [ ] [Week 7](https://vimeo.com/1218932708) - [ ] [Week 6](https://vimeo.com/1218932683) - [ ] [Week 5](https://vimeo.com/1218932633) - SANS Internet Storm Center, InfoCON: green - [ ] [Apple Patches iOS and macOS, (Mon, Aug 17th)](https://isc.sans.edu/diary/rss/33254) - [ ] [Apple Screen Sharing Security, (Mon, Aug 17th)](https://isc.sans.edu/diary/rss/33252) - [ ] [ISC Stormcast For Monday, August 17th, 2026 https://isc.sans.edu/podcastdetail/10054, (Mon, Aug 17th)](https://isc.sans.edu/diary/rss/33250) - 凌晨一点零三分 - [ ] [跟党走_政策板块日报2026-08-17](https://mp.weixin.qq.com/s?__biz=MzIxMjI0Mzk0OQ==&mid=2247485717&idx=1&sn=a4cfdbd8ba792b3c9fe1f3a6592de976) - 情报分析师 - [ ] [别急着感动,那个很欣赏你的陌生人,可能正在写接触报告](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650569112&idx=1&sn=628850994213f7c25bf479832d9d182f) - [ ] [【深度研判】巴基斯坦三军情报局通过社交媒体网红试图在西孟加拉邦建立间谍网络,南亚情报渗透模式对我周边安全与孟加拉利益的潜在风险](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650569112&idx=2&sn=389aab42d1c04ada2d11f1ba05f49754) - Future of Tech and Security: Strategy & Innovation with Raffy - [ ] [AI Maturity Is Not About Tool Count](https://raffy.ch/blog/2026/08/17/ai-maturity-is-not-about-tool-count/) - CNVD漏洞平台 - [ ] [CNVD漏洞周报2026年第32期](https://mp.weixin.qq.com/s?__biz=MzU3ODM2NTg2Mg==&mid=2247497192&idx=1&sn=70b7291295f9b75bcae014ed7bb5cbe7) - [ ] [上周关注度较高的产品安全漏洞(20260810-20260816)](https://mp.weixin.qq.com/s?__biz=MzU3ODM2NTg2Mg==&mid=2247497192&idx=2&sn=76f390eaef8d560891eedf139f70d14d) - Schneier on Security - [ ] [Hacking Public Wi-Fi DNS to Steal Credentials](https://www.schneier.com/blog/archives/2026/08/hacking-public-wi-fi-dns-to-steal-credentials.html) - Full Disclosure - [ ] [APPLE-SA-08-17-2026-2 iOS 18.7.10 and iPadOS 18.7.10](https://seclists.org/fulldisclosure/2026/Aug/38) - Security Weekly Podcast Network (Audio) - [ ] [Sandbox Escapes with Rubrik's Zero Labs, AI recorders eroding privacy, and the news - Joe Hladik - ESW #472](http://sites.libsyn.com/18678/sandbox-escapes-with-rubriks-zero-labs-ai-recorders-eroding-privacy-and-the-news-joe-hladik-esw-472) - Security Affairs - [ ] [SafePal Says 39,798 Customers Hit by Data Breach](https://securityaffairs.com/197391/data-breach/safepal-says-39798-customers-hit-by-data-breach.html) - [ ] [LiteLLM Supply-Chain Attack – Technology, Banking and Healthcare the Most Affected](https://securityaffairs.com/197377/hacking/litellm-supply-chain-attack-technology-banking-and-healthcare-the-most-affected.html) - [ ] [Invisible AI Prompts Trigger Court Sanctions](https://securityaffairs.com/197370/ai/invisible-ai-prompts-trigger-court-sanctions.html) - [ ] [McDonald’s Employee Data Appears in Leak, Seller Claims 1.7M Records Stolen](https://securityaffairs.com/197322/cyber-crime/mcdonalds-employee-data-appears-in-leak-seller-claims-1-7m-records-stolen.html) - [ ] [Akira Ransomware Uses Safe Mode to Bypass EDR](https://securityaffairs.com/197339/malware/akira-ransomware-uses-safe-mode-to-bypass-edr.html) - The Honeynet Project - [ ] [GreedyBear: Access Payload Files](https://honeynet.org/2026/08/17/17/) - TorrentFreak - [ ] [Pirate Streaming Giant Cineby Announces Surprise Shutdown](https://torrentfreak.com/pirate-streaming-giant-cineby-announces-surprise-shutdown/) - GRAHAM CLULEY - [ ] [An “invisible” car? Researcher uses machine learning to hide vehicles from Flock cameras](https://www.bitdefender.com/en-us/blog/hotforsecurity/invisible-car-machine-learning-hide-vehicle-flock-cameras) - Tor Project blog - [ ] [Funding internet freedom together: results from our first participatory funding round](https://blog.torproject.org/funding-internet-freedom-together/) - Instapaper: Unread - [ ] [Everything is about to “go dark”](https://blog.cryptographyengineering.com/2026/08/14/everything-is-about-to-go-dark/) - Over Security - [ ] [‘Unprecedented’ number of Apple users received recent spyware alert, say investigators](https://techcrunch.com/2026/08/17/unprecedented-number-of-apple-users-received-recent-spyware-alert-say-investigators/) - [ ] [Nearly 750k had financial info, SSNs leaked in South Carolina loan company breach](https://therecord.media/financial-info-leak-debt-consolidator) - [ ] [Hacker claims 3.6 million Azure account records stolen from major companies](https://www.bleepingcomputer.com/news/security/hacker-claims-36-million-azure-account-records-stolen-from-major-companies/) - [ ] [Pokémon Center data breach exposes customer info, cancels some orders](https://www.bleepingcomputer.com/news/security/pokemon-center-data-breach-exposes-customer-info-cancels-some-orders/) - [ ] [SafePal latest crypto hardware wallet maker affected by breach, with nearly 40,000 impacted](https://therecord.media/safepal-crypto-hardware-breach) - [ ] [Poland probes MyDr healthcare software breach potentially affecting 19 million people](https://therecord.media/poland-probes-mydr-healthcare-software-breach) - [ ] [Irregular faces criticism over ‘spin’ in AI hacking postmortem](https://therecord.media/irregular-ai-hacking-model-blog) - [ ] [Brand Impersonation Takedown: From Whack-a-Mole to Managed Response](https://cyble.com/blog/brand-impersonation-takedown-managed-response/) - [ ] [Microsoft confirms GitHub is down worldwide](https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-github-is-down-worldwide/) - [ ] [Certighost and the Privilege Hiding in Your Certificate Authority](https://www.bleepingcomputer.com/news/security/certighost-and-the-privilege-hiding-in-your-certificate-authority/) - [ ] [Windows Server 2022 reaches end of mainstream support in 60 days](https://www.bleepingcomputer.com/news/microsoft/windows-server-2022-reaches-end-of-mainstream-support-in-60-days/) - [ ] [Ukraine says cyberattack hit Russian e-commerce giant Wildberries amid drone strikes](https://therecord.media/russia-wildberries-cyberattack-ukraine) - [ ] [Philips and GE investigating Clop ransomware data theft claims](https://www.bleepingcomputer.com/news/security/philips-and-ge-investigating-clop-ransomware-data-theft-claims/) - [ ] [French tax authority data breach affects 678,000 individuals](https://www.bleepingcomputer.com/news/security/french-tax-authority-data-breach-affects-678-000-individuals/) - [ ] [Identity Resilience: perché il backup di Active Directory non basta più nell’era del ransomware](https://www.cybersecurity360.it/nuove-minacce/ransomware/identity-resilience-perche-il-backup-di-active-directory-non-basta-piu-nellera-del-ransomware/) - [ ] [Oltre l’antivirus: la suite Kaspersky Premium integra VPN illimitata, IA e identity protection senza impattare sulle prestazioni](https://www.cybersecurity360.it/cultura-cyber/kaspersky-premium-protezione-vpn-identity-protection/) - [ ] [Dati personali al sicuro dall’IA delle Big Tech: come la crittografia end-to-end di Proton Drive protegge il cloud storage](https://www.cybersecurity360.it/cultura-cyber/proton-drive-cloud-storage-crittografia-end-to-end/) - [ ] [Attacchi informatici: le nuove strategie tra infiltrazione fisica e IA](https://www.cybersecurity360.it/nuove-minacce/attacchi-informatici-le-nuove-strategie-tra-infiltrazione-fisica-e-ia/) - [ ] [Microsoft working on Defender patch for ShieldBreak zero-day](https://www.bleepingcomputer.com/news/security/microsoft-working-on-defender-patch-for-shieldbreak-zero-day/) - [ ] [Software Bill of Materials per l’AI: la supply chain dell’intelligenza artificiale diventa verificabile](https://www.cybersecurity360.it/nuove-minacce/software-bill-of-materials-per-lai-la-supply-chain-dellintelligenza-artificiale-diventa-verificabile/) - [ ] [SafePal data breach impacts 39,798 customers, stolen info for sale](https://www.bleepingcomputer.com/news/security/safepal-data-breach-impacts-39-798-customers-stolen-info-for-sale/) - The Hacker News - [ ] [Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects](https://thehackernews.com/2026/08/critical-gitlab-graphql-flaw-could-let.html) - [ ] [Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection](https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets_0330881554.html) - [ ] [Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads](https://thehackernews.com/2026/08/forminator-wordpress-flaw-can-enable.html) - [ ] [Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic](https://thehackernews.com/2026/08/cavern-c2-uses-dns-and-google-apps.html) - [ ] [⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More](https://thehackernews.com/2026/08/weekly-recap-vmware-exploits-windows-0.html) - [ ] [How MCP Servers Can Expose Enterprise Secrets](https://thehackernews.com/2026/08/how-mcp-servers-can-expose-enterprise.html) - [ ] [Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access](https://thehackernews.com/2026/08/unisoc-volte-video-call-exploit-chain.html) - [ ] [Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies](https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html) - [ ] [Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware](https://thehackernews.com/2026/08/suspected-china-nexus-actor-exploits.html) - Daniel Miessler - [ ] [How to Get Started in Cybersecurity 2026](https://danielmiessler.com/blog/how-to-get-started-in-cybersecurity-2026?utm_source=rss&utm_medium=feed&utm_campaign=website) - [ ] [How AI Builders Will Get Hacked](https://danielmiessler.com/blog/how-ai-builders-get-hacked?utm_source=rss&utm_medium=feed&utm_campaign=website) - [ ] [Fix Execution, Not the SOP](https://danielmiessler.com/blog/fix-execution-not-the-sop?utm_source=rss&utm_medium=feed&utm_campaign=website) - [ ] [Stolen Authority](https://danielmiessler.com/blog/stolen-authority?utm_source=rss&utm_medium=feed&utm_campaign=website) - www.theregister.com - Articles - [ ] [Crook hawks millions of records allegedly plundered from corporate Azure tenants](https://www.theregister.com/security/2026/08/17/crook-hawks-millions-of-records-allegedly-plundered-from-corporate-azure-tenants/5288305) - [ ] [Code fixers have fired up the AI warp drive. Strange new worlds await](https://www.theregister.com/columnists/2026/08/17/code-fixers-have-fired-up-the-ai-warp-drive-strange-new-worlds-await/5287681) - [ ] [Black Hat and DEF CON are AI conferences now, too](https://www.theregister.com/security/2026/08/17/black-hat-and-def-con-are-ai-conferences-now-too/5288076) - [ ] [Microsoft blames AI for delayed Exchange update, can’t say when it will arrive](https://www.theregister.com/software/2026/08/17/microsoft-blames-ai-for-delayed-exchange-update-cant-say-when-it-will-arrive/5288227) - [ ] [Chinese AI company Zhipu claims its new model is a better bug-finder than Anthropic, OpenAI](https://www.theregister.com/security/2026/08/17/chinese-ai-company-zhipu-claims-its-new-model-is-a-better-bug-finder-than-anthropic-openai/5288203)
每日安全资讯(2026-08-18)