# 每日安全资讯(2026-03-11) - Private Feed for M09Ic - [ ] [bolucat released 202603101959 at bolucat/Archive](https://github.com/bolucat/Archive/releases/tag/202603101959) - [ ] [mgeeky starred atomiczsec/Adrenaline](https://github.com/atomiczsec/Adrenaline) - [ ] [safedv starred cloudflare/pingora](https://github.com/cloudflare/pingora) - [ ] [liamg contributed to infracost/cli](https://github.com/infracost/cli/pull/13) - [ ] [PeiQi0 starred HKUDS/CLI-Anything](https://github.com/HKUDS/CLI-Anything) - [ ] [0xbug starred D4Vinci/Scrapling](https://github.com/D4Vinci/Scrapling) - [ ] [pydantic released v0.0.8 at pydantic/monty](https://github.com/pydantic/monty/releases/tag/v0.0.8) - [ ] [IC3-CR3AM starred openclaw/openclaw](https://github.com/openclaw/openclaw) - [ ] [liamg contributed to infracost/go-proto](https://github.com/infracost/go-proto/pull/4) - [ ] [mgeeky starred uf0o/windows-ps-callbacks-experiments](https://github.com/uf0o/windows-ps-callbacks-experiments) - [ ] [niudaii starred SanMuzZzZz/LuaN1aoAgent](https://github.com/SanMuzZzZz/LuaN1aoAgent) - [ ] [gh0stkey starred RedTeamPentesting/pretender](https://github.com/RedTeamPentesting/pretender) - [ ] [PrefectHQ released 3.6.22.dev6 at PrefectHQ/prefect](https://github.com/PrefectHQ/prefect/releases/tag/3.6.22.dev6) - [ ] [Y4er starred deviantony/docker-elk](https://github.com/deviantony/docker-elk) - [ ] [uknowsec starred dalangdalang934/freedomtrader](https://github.com/dalangdalang934/freedomtrader) - [ ] [FunnyWolf starred microsoft/presidio](https://github.com/microsoft/presidio) - SecWiki News - [ ] [SecWiki News 2026-03-10 Review](http://www.sec-wiki.com/?2026-03-10) - bunnie's blog - [ ] [Baochip-1x: A Mostly-Open, 22nm SoC for High Assurance Applications](https://www.bunniestudios.com/blog/2026/baochip-1x-a-mostly-open-22nm-soc-for-high-assurance-applications/) - 安全客-有思想的安全新媒体 - [ ] [Windows 12的幻影 微软如何用AI重构取代全新系统发布](https://www.anquanke.com/post/id/315052) - [ ] [依托Polygon公链 越南黑客组织通过GitHub部署历经16代迭代的LuaJIT恶意程序](https://www.anquanke.com/post/id/315056) - [ ] [OpenAI依托ChatGPT技术打造AI搜索引擎,正面对标谷歌搜索](https://www.anquanke.com/post/id/315059) - [ ] [AVideo平台存在高危零点击命令注入漏洞 可被用于劫持直播流](https://www.anquanke.com/post/id/315062) - [ ] [恶意浏览器插件针对imToken用户窃取私钥](https://www.anquanke.com/post/id/315065) - [ ] [Viber即时通讯软件存在TLS漏洞,Cloak代理模式失效并导致用户暴露](https://www.anquanke.com/post/id/315068) - [ ] [黑客可利用间接提示注入攻击 借助外部内容操控AI智能体](https://www.anquanke.com/post/id/315071) - [ ] [海康威视与罗克韦尔自动化高危漏洞纳入CISA已知被利用漏洞清单](https://www.anquanke.com/post/id/315077) - [ ] [OpenAI发布GPT-5.4大模型,具备更强推理、编码与计算机操作能力](https://www.anquanke.com/post/id/315080) - [ ] [黑客利用OpenClaw、GitHub与Bing传播恶意软件,攻击手段极具隐蔽性](https://www.anquanke.com/post/id/315083) - paper - Last paper - [ ] [虚假 OpenClaw 安装程序如何传播 GhostSocks 恶意软件](https://paper.seebug.org/3470/) - LoRexxar's Blog | 信息技术分享 - [ ] [Re0(1) - AI变革的时代来了吗?](https://lorexxar.cn/2026/03/10/reai1/) - 嘶吼 RoarTalk – 网络安全行业综合服务平台,4hou.com - [ ] [从技术创新到实战防护:SKD AWARDS 2025年度榜单发布](https://www.4hou.com/posts/8gmr) - [ ] [AI算法在审判战争,而法律还在沉睡——老哈的故事](https://www.4hou.com/posts/42gJ) - [ ] [焕新出发|快快云安全邀您开启云安全的AI时代](https://www.4hou.com/posts/337p) - [ ] [嘶吼快讯|网安厂商动态汇(第15期)](https://www.4hou.com/posts/5MjX) - Tenable Blog - [ ] [Microsoft’s March 2026 Patch Tuesday Addresses 83 CVEs (CVE-2026-21262, CVE-2026-26127)](https://www.tenable.com/blog/microsofts-march-2026-patch-tuesday-addresses-83-cves-cve-2026-21262-cve-2026-26127) - [ ] [LeakyLooker: Hacking Google Cloud’s Data via Dangerous Looker Studio Vulnerabilities](https://www.tenable.com/blog/leakylooker-google-cloud-looker-studio-vulnerabilities) - Recent Commits to cve:main - [ ] [Update Tue Mar 10 11:16:17 UTC 2026](https://github.com/trickest/cve/commit/127710f7ec7fcfe371d4635d08c5f43065d7e3a8) - CCC Event Blog - [ ] [InselChaos 2026: Einladung & Call for Participation](https://events.ccc.de/2026/03/10/inselchaos-einladung/) - Securelist - [ ] [BeatBanker: A dual‑mode Android Trojan](https://securelist.com/beatbanker-miner-and-banker/119121/) - SentinelOne - [ ] [FortiGate Edge Intrusions | Stolen Service Accounts Lead to Rogue Workstations and Deep AD Compromise](https://www.sentinelone.com/blog/fortigate-edge-intrusions/) - Malwarebytes - [ ] [How to see your Google Search history (and delete it)](https://www.malwarebytes.com/blog/how-to/2026/03/how-to-see-your-google-search-history-and-delete-it) - [ ] [Signal and WhatsApp accounts targeted in phishing campaign](https://www.malwarebytes.com/blog/news/2026/03/signal-and-whatsapp-accounts-targeted-in-phishing-campaign) - [ ] [Hackers may have breached FBI wiretap network via supply chain](https://www.malwarebytes.com/blog/data-breaches/2026/03/hackers-may-have-breached-fbi-wiretap-network-via-supply-chain) - Reverse Engineering - [ ] [Reverse Engineering Binaries With AI](https://www.reddit.com/r/ReverseEngineering/comments/1rq5tdm/reverse_engineering_binaries_with_ai/) - [ ] [Reverse engineering FORM swim goggles: custom protobuf over BLE, 697 captured API requests, full protocol documented](https://www.reddit.com/r/ReverseEngineering/comments/1rq3bu7/reverse_engineering_form_swim_goggles_custom/) - [ ] [Released a crackme this week. Someone reconstructed the hash in Python, brute forced for an hour - then patched the jump. That was the correct solution.](https://www.reddit.com/r/ReverseEngineering/comments/1rqbpek/released_a_crackme_this_week_someone/) - [ ] [IronPE - Minimal Windows PE manual loader written in Rust.](https://www.reddit.com/r/ReverseEngineering/comments/1rprb6n/ironpe_minimal_windows_pe_manual_loader_written/) - [ ] [I've made indent guides plugin for IDA](https://www.reddit.com/r/ReverseEngineering/comments/1rq2jhb/ive_made_indent_guides_plugin_for_ida/) - [ ] [$10K in Bounties | 30-Day Runtime Enforcement Challenge Break Churchill. If you can.](https://www.reddit.com/r/ReverseEngineering/comments/1rq8jbl/10k_in_bounties_30day_runtime_enforcement/) - [ ] [Your Duolingo Is Still Talking to ByteDance: How Pangle Fingerprints You Across Apps After You Said No](https://www.reddit.com/r/ReverseEngineering/comments/1rq6qww/your_duolingo_is_still_talking_to_bytedance_how/) - Didier Stevens - [ ] [Update: search-for-compression.py 0.0.6](https://blog.didierstevens.com/2026/03/10/update-search-for-compression-py-0-0-6/) - daniel.haxx.se - [ ] [Dependency tracking is hard](https://daniel.haxx.se/blog/2026/03/10/dependency-tracking-is-hard/) - 杨龙 - [ ] [MySQL 长度较大的VARCHAR索引限制说明](https://www.yanglong.pro/mysql-%e9%95%bf%e5%ba%a6%e8%be%83%e5%a4%a7%e7%9a%84varchar%e7%b4%a2%e5%bc%95%e9%99%90%e5%88%b6%e8%af%b4%e6%98%8e/) - [ ] [mysql 表分区的不同是否会影响正常使用?](https://www.yanglong.pro/mysql-%e8%a1%a8%e5%88%86%e5%8c%ba%e7%9a%84%e4%b8%8d%e5%90%8c%e6%98%af%e5%90%a6%e4%bc%9a%e5%bd%b1%e5%93%8d%e6%ad%a3%e5%b8%b8%e4%bd%bf%e7%94%a8%ef%bc%9f/) - HackerNews - [ ] [爱立信美国公司因服务商遭黑客攻击披露数据泄露事件](https://hackernews.cc/archives/63597) - [ ] [威胁行为者利用漏洞,并使用 Elastic Cloud SIEM 管理窃取的数据](https://hackernews.cc/archives/63623) - [ ] [UNC4899 在开发者通过 AirDrop 将木马文件传输至工作设备后攻破加密货币公司](https://hackernews.cc/archives/63609) - [ ] [伪装成 OpenClaw 安装程序的恶意 npm 包部署远程控制木马并窃取 macOS 凭据](https://hackernews.cc/archives/63614) - [ ] [俄罗斯黑客试图在全球范围内攻破 Signal、WhatsApp 账号](https://hackernews.cc/archives/63619) - [ ] [Anthropic Claude Opus AI 模型发现 22 个 Firefox 漏洞](https://hackernews.cc/archives/63603) - [ ] [微软 Teams 钓鱼攻击以企业员工为目标,投放 A0Backdoor 后门恶意软件](https://hackernews.cc/archives/63592) - 黑海洋Wiki | AI机器人硬件开发 | 网络安全攻防实战 | 区块链技术文档教程 - 免费资源平台 - [ ] [美国国防部加速AI部署 谷歌Gemini智能体将进入办公体系](https://blog.upx8.com/%E7%BE%8E%E5%9B%BD%E5%9B%BD%E9%98%B2%E9%83%A8%E5%8A%A0%E9%80%9FAI%E9%83%A8%E7%BD%B2-%E8%B0%B7%E6%AD%8CGemini%E6%99%BA%E8%83%BD%E4%BD%93%E5%B0%86%E8%BF%9B%E5%85%A5%E5%8A%9E%E5%85%AC%E4%BD%93%E7%B3%BB) - [ ] [英伟达重磅投资Thinking Machines 将部署1吉瓦算力训练AI模型](https://blog.upx8.com/%E8%8B%B1%E4%BC%9F%E8%BE%BE%E9%87%8D%E7%A3%85%E6%8A%95%E8%B5%84Thinking-Machines-%E5%B0%86%E9%83%A8%E7%BD%B21%E5%90%89%E7%93%A6%E7%AE%97%E5%8A%9B%E8%AE%AD%E7%BB%83AI%E6%A8%A1%E5%9E%8B) - 奇客Solidot–传递最新科技情报 - [ ] [每年逾 500 万例死亡可归因于身体活动不足](https://www.solidot.org/story?sid=83733) - [ ] [创业公司想发射数千颗反射阳光的卫星](https://www.solidot.org/story?sid=83731) - [ ] [运动时肠道细菌会重写与大脑的化学对话](https://www.solidot.org/story?sid=83730) - [ ] [图书出版商联合起诉安娜的档案](https://www.solidot.org/story?sid=83729) - [ ] [很多国际游戏开发者计划不参加今年的 GDC](https://www.solidot.org/story?sid=83728) - [ ] [Meta 称上传盗版电子书属于合理使用](https://www.solidot.org/story?sid=83727) - [ ] [为什么高处坠落的猫总是四脚着地?](https://www.solidot.org/story?sid=83726) - [ ] [数据中心成为攻击基础设施的目标](https://www.solidot.org/story?sid=83725) - [ ] [瑞士通过修宪保障使用现金的权利](https://www.solidot.org/story?sid=83724) - [ ] [调查发现三分之一美国人认为末日将在其有生之年来临](https://www.solidot.org/story?sid=83723) - 安全分析与研究 - [ ] [伪装Chrome网站银狐黑产最新攻击样本分析](https://mp.weixin.qq.com/s?__biz=MzA4ODEyODA3MQ==&mid=2247495873&idx=1&sn=c8046fd810abb422abba9fa9e3884329) - 腾讯玄武实验室 - [ ] [每日安全动态推送(26/3/10)](https://mp.weixin.qq.com/s?__biz=MzA5NDYyNDI0MA==&mid=2651960395&idx=1&sn=fda56bb3ee7ca2f53e5b3d1d1fc60bd1) - 威努特安全网络 - [ ] [从"震网"到"咆哮之狮":美以对伊朗网络战争技术演进深度对比](https://mp.weixin.qq.com/s?__biz=MzAwNTgyODU3NQ==&mid=2651140451&idx=1&sn=75221f805c58fb057d62892acbec5966) - 雷神众测 - [ ] [雷神众测漏洞周报2026.3.2-2026.3.8](https://mp.weixin.qq.com/s?__biz=MzI0NzEwOTM0MA==&mid=2652503721&idx=1&sn=41705ec6eca57ec5d8748e66891ea39d) - 青衣十三楼飞花堂 - [ ] [初一下学期之面积最值](https://mp.weixin.qq.com/s?__biz=MzUzMjQyMDE3Ng==&mid=2247489109&idx=1&sn=13699c3f52849d5e09f8e70ce1c38f02) - 代码卫士 - [ ] [服务提供商被黑 爱立信美国公司数据遭泄露](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247525365&idx=1&sn=1a9126dfa1e655a2c586c9000ff60f7e) - [ ] [微软:AI已用于攻击的每个阶段](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247525365&idx=2&sn=dff79e089be7ac2054e918366b567b52) - 黑鸟 - [ ] [Meta AI智能眼镜深陷隐私危机,员工坦言:“我们什么都看得见”](https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451185699&idx=1&sn=782b02107dd4772a6c8934d45d0652a7) - 安全内参 - [ ] [AI没有颠覆网络安全:CrowdStrike年化收入突破360亿元叕创新高](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247515656&idx=1&sn=9314fe07d64ebc46e8b21c594b39f4ee) - [ ] [美国法律专家称授权私营进攻性网络行动需要跨越三重门槛](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247515656&idx=2&sn=a65d743a4a6992a5b436107c61948521) - 绿盟科技研究通讯 - [ ] [RSAC 2026创新沙盒-Realm Labs:洞察AI推理内核,前置防控安全风险](https://mp.weixin.qq.com/s?__biz=MzIyODYzNTU2OA==&mid=2247499519&idx=1&sn=f5bedb7faf2f044e6a6f071d7439c48b) - 天御攻防实验室 - [ ] [独家解读新版《美国网络战略》释放的危险信号](https://mp.weixin.qq.com/s?__biz=MzU0MzgyMzM2Nw==&mid=2247486777&idx=1&sn=1911cd25d5cd93c71bf17ed4d3a17d9a) - 黑哥虾撩 - [ ] [AI Agent 下半场](https://mp.weixin.qq.com/s?__biz=Mzg5OTU1NTEwMg==&mid=2247484484&idx=1&sn=f2074c8b6895179bbcc21bb5db71b712) - 天黑说嘿话 - [ ] [如何构建企业级OpenClaw,专业“养龙虾”:从部署到进阶的完整指南](https://mp.weixin.qq.com/s?__biz=MzI5NTQ5MTAzMA==&mid=2247486020&idx=1&sn=a22fe4eb79580e94e3cf44b0dffc1f04) - 安全研究GoSSIP - [ ] [G.O.S.S.I.P 阅读推荐 2026-03-10 Andriod APP的私有加密流量风险](https://mp.weixin.qq.com/s?__biz=Mzg5ODUxMzg0Ng==&mid=2247501491&idx=1&sn=95e961f2b4be8b9639031dae0f34e530) - 看雪学苑 - [ ] [AI 辅助还原自定义 VMP 保护方案](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458611998&idx=1&sn=a33d501c7e3619333d8c851518627443) - [ ] [假CleanMyMac网站诱导Mac用户运行命令,背后竟是偷密码的木马](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458611998&idx=2&sn=8b124bb76ddb4fdddb0e898bdb490e9e) - [ ] [火热招生中!系统0day安全-Web框架漏洞挖掘(第10期)](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458611998&idx=3&sn=89a9fa2d4af7c8994d25051cf5f8de6d) - 奇安信 CERT - [ ] [OpenClaw 安全风险排查指南:在效率与安全之间寻找平衡](https://mp.weixin.qq.com/s?__biz=MzU5NDgxODU1MQ==&mid=2247504724&idx=1&sn=329543a378c4a1665441557bcc647e51) - 安全圈 - [ ] [【安全圈】腾讯版小龙虾 WorkBuddy 爆火致服务不稳定,公司致歉并紧急扩容](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652074555&idx=1&sn=34ac7df2817d6d6a28a9276c0d93309f) - [ ] [【安全圈】切勿盲目跟风!有人因OpenClaw失控花费上万元](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652074555&idx=2&sn=97d3355a301471816ac3cd1c9532d399) - [ ] [【安全圈】美国教育行业高层敏感联系数据库泄露](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652074555&idx=3&sn=f61b2e905144b2bbad4c6f2a6eefc31a) - [ ] [【安全圈】微软已修复:黑客 22 万美元暗网兜售 Win10/Win11 高危漏洞](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652074555&idx=4&sn=e459cc19b5d7c01eb6275c532cacf8b2) - 吾爱破解论坛 - [ ] [【开放注册公告】吾爱破解论坛2026年3月13日十八周年开放注册公告](https://mp.weixin.qq.com/s?__biz=MjM5Mjc3MDM2Mw==&mid=2651143717&idx=1&sn=2a0810d5228d4389603afabf38f46134) - 威胁棱镜 - [ ] [Virus Bulletin 2025 议题慢递](https://mp.weixin.qq.com/s?__biz=MzkyMzE5ODExNQ==&mid=2247488440&idx=1&sn=22866492db4a3e9126a483d45e1c2bf4) - 中国信息安全 - [ ] [《欧盟网络安全法 2.0》——欧盟在ICT供应链领域对华脱钩的工具箱](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664259955&idx=1&sn=4bfd6a9115b39e47a8fed4a08c05d78c) - [ ] [关注 | 中央网信办“清朗·2026年营造喜庆祥和春节网络环境”专项行动公开曝光一批典型案例](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664259955&idx=2&sn=33c099becbd570886443d750b11501b7) - [ ] [CNCERT:关于“独狼”团伙大规模传播恶意程序的风险提示](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664259955&idx=3&sn=88dca6525f1c807ef7aad63a057186bd) - [ ] [行业 | 天融信智算云一键部署OpenClaw🦞安全养龙虾,算力不浪费!](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664259955&idx=4&sn=891d2852f657dd87da0ac73adea1a1f4) - [ ] [盘点 | 中国互联网联合辟谣平台2026年2月辟谣榜](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664259955&idx=5&sn=ecb199d9a5ccd23070e71ec2606054b3) - [ ] [关注 | 2月全国网络举报1707.2万件](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664259955&idx=6&sn=3192b87f5d35538b493c7299f673b458) - 安全牛 - [ ] [警惕!生成式 AI 成网络犯罪 “新帮凶”,13 种攻击方式盯上企业系统](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651140674&idx=1&sn=d1e21c25345262702fc958ff67c40cda) - [ ] [《后量子密码应用迁移与落地实践研究(2026版)》报告启动](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651140674&idx=2&sn=7975c83ad3b7cd5517a68b117b595292) - 青藤云安全 - [ ] [工信部提示 OpenClaw 风险:那企业“养小龙虾”更要选安全可控的 WorkClaw](https://mp.weixin.qq.com/s?__biz=MzAwNDE4Mzc1NA==&mid=2650850998&idx=1&sn=974c9996630ea1f2cb57e41dcaa58523) - 字节跳动安全中心 - [ ] [抖省省反爬专测上线!漏洞奖金1000元起步!](https://mp.weixin.qq.com/s?__biz=MzUzMzcyMDYzMw==&mid=2247496058&idx=1&sn=798b2573f8b05d6f454854b2b2ff660f) - 极客公园 - [ ] [10.3 亿美元!杨立昆融了欧洲最大一笔种子轮,他要把产品卖回 Meta](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653100690&idx=1&sn=b73bc350e761fad6122374d853faf04f) - [ ] [开源龙虾太野?青藤 WorkClaw 企业版来了:好用不折腾,安全又可控](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653100690&idx=2&sn=f5547a27c88857cab0548b1078ea4b7e) - [ ] [成立一年半累计融资超 20 亿,这个团队想搞定具身智能最难的「数据瓶颈」](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653100673&idx=1&sn=4e5dbc54c4ab00ced58db449941ab8c3) - [ ] [腾讯内测 QClaw,微信 QQ 双端接入;理想前 CTO 创业,半年融资超 20 亿;中国大模型用量连续两周超美国 | 极客早知道](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653100661&idx=1&sn=aa7e893987dc1560c694f8ca36725c18) - 嘶吼专业版 - [ ] [AI算法在审判战争,而法律还在沉睡——老哈的故事](https://mp.weixin.qq.com/s?__biz=MzI0MDY1MDU4MQ==&mid=2247587048&idx=1&sn=65cabd2b87ae39c2e9b68ca118932e9f) - [ ] [嘶吼快讯|网安厂商动态汇(第15期)](https://mp.weixin.qq.com/s?__biz=MzI0MDY1MDU4MQ==&mid=2247587048&idx=2&sn=02cc05aa8106a468a7c879b10c87fcdd) - 枇杷熟了 - [ ] [枇杷熟了-全球网络安全日报2026-03-10](https://mp.weixin.qq.com/s?__biz=MzU0MzkzOTYzOQ==&mid=2247489945&idx=1&sn=b662f172e5374a9e5e4224e5e5ad029f) - OPPO安全中心 - [ ] [【联合活动】开春第一弹!OSRC联合4大SRC开启"春日猎洞"](https://mp.weixin.qq.com/s?__biz=MzUyNzc4Mzk3MQ==&mid=2247494775&idx=1&sn=e473ac74233514468ebba81e52e5aa0c) - [ ] [【奖励公告】2026年1月&2月](https://mp.weixin.qq.com/s?__biz=MzUyNzc4Mzk3MQ==&mid=2247494775&idx=2&sn=630895b27d13f18d3f7d5f5bd99caca8) - 深信服千里目安全技术中心 - [ ] [【漏洞通告】Nginx UI 信息泄露漏洞 (CVE-2026-27944)](https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&mid=2247525086&idx=2&sn=e45679fde28a38c59eac984113ab93a8) - [ ] [网络安全信息与动态周报2026年第9期(2月23日-3月1日)](https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&mid=2247525086&idx=3&sn=8f34c977acdf3264fdc836b76f8e0992) - 安全行者老霍 - [ ] [Claude Code Security是应用程序安全领域的重大突破。但谁来监管它?](https://mp.weixin.qq.com/s?__biz=Mzg3NjU4MDI4NQ==&mid=2247486038&idx=1&sn=9ec4ef25c024836b564ce39464534ea2) - TrustedSec - [ ] [Building a Detection Foundation: Part 3 - PowerShell and Script Logging](https://trustedsec.com/blog/building-a-detection-foundation-part-3-powershell-and-script-logging) - 360数字安全 - [ ] [智能经济时代新命题:“养虾”先筑“安全坝”](https://mp.weixin.qq.com/s?__biz=MzA4MTg0MDQ4Nw==&mid=2247585273&idx=1&sn=700a0304c3f5e13eedefa71502516f5e) - LR的安全自留地 - [ ] [Re0(1) - AI变革的时代来了吗?](https://mp.weixin.qq.com/s?__biz=MzkwNzMyNjU0MQ==&mid=2247484272&idx=1&sn=8d1473a85e290595de1c3fa9a6f9368a) - 迪哥讲事 - [ ] [从信息收集到云服务器接管](https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&mid=2247499156&idx=1&sn=00d65a5e98c9cf759e049416046f86b6) - Qualys Security Blog - [ ] [Microsoft Patch Tuesday, March 2026 Security Update Review](https://blog.qualys.com/category/vulnerabilities-threat-research) - [ ] [From Shadow Models to Audit-Ready AI Security: A Practical Path with Qualys TotalAI](https://blog.qualys.com/category/product-tech) - 国家互联网应急中心CNCERT - [ ] [关于“独狼”团伙大规模传播恶意程序的风险提示](https://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw==&mid=2247501308&idx=1&sn=8dcec3481e3e60ebabb42adfe1a449f7) - Over Security - Cybersecurity news aggregator - [ ] [New ‘BlackSanta’ EDR killer spotted targeting HR departments](https://www.bleepingcomputer.com/news/security/new-blacksanta-edr-killer-spotted-targeting-hr-departments/) - [ ] [Microsoft Patch Tuesday for March 2026 — Snort rules and prominent vulnerabilities](https://blog.talosintelligence.com/microsoft-patch-tuesday-march-2026/) - [ ] [New BeatBanker Android malware poses as Starlink app to hijack devices](https://www.bleepingcomputer.com/news/security/new-beatbanker-android-malware-poses-as-starlink-app-to-hijack-devices/) - [ ] [DOGE employee stole Social Security data and put it on a thumb drive, report says](https://techcrunch.com/2026/03/10/doge-employee-stole-social-security-data-and-put-it-on-a-thumb-drive-report-says/) - [ ] [New 'Zombie ZIP' technique lets malware slip past security tools](https://www.bleepingcomputer.com/news/security/new-zombie-zip-technique-lets-malware-slip-past-security-tools/) - [ ] [Microsoft releases Windows 10 KB5078885 extended security update](https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-windows-10-kb5078885-extended-security-update/) - [ ] [U.S. military contractor likely built iPhone hacking tools used by Russian spies in Ukraine](https://techcrunch.com/2026/03/10/us-military-contractor-likely-built-iphone-hacking-tools-used-by-russian-spies-in-ukraine/) - [ ] [Microsoft March 2026 Patch Tuesday fixes 2 zero-days, 79 flaws](https://www.bleepingcomputer.com/news/microsoft/microsoft-march-2026-patch-tuesday-fixes-2-zero-days-79-flaws/) - [ ] [Cyber Resilience Act: ecco come le imprese dovranno adeguarsi](https://www.cybersecurity360.it/legal/cyber-resilience-act-ecco-come-le-imprese-dovranno-adeguarsi/) - [ ] [Fattore umano nella cyber: le lezioni tratte dalle multe per GDPR e data breach](https://www.cybersecurity360.it/nuove-minacce/fattore-umano-nella-cyber-le-lezioni-tratte-dalle-multe-per-gdpr-e-data-breach/) - [ ] [Windows 11 KB5079473 & KB5078883 cumulative updates released](https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5079473-and-kb5078883-cumulative-updates-released/) - [ ] [HPE warns of critical AOS-CX flaw allowing admin password resets](https://www.bleepingcomputer.com/news/security/hpe-warns-of-critical-aos-cx-flaw-allowing-admin-password-resets/) - [ ] [Rudd confirmed to head NSA, Cyber Command after near year-long vacancy](https://therecord.media/rudd-confirmed-nsa-cyber-command-chief) - [ ] [Asset Security e classificazione: quando un’etichetta vale più di un firewall](https://www.cybersecurity360.it/soluzioni-aziendali/asset-security-e-classificazione-quando-unetichetta-vale-piu-di-un-firewall/) - [ ] [Microsoft brings phishing-resistant Windows sign-ins via Entra passkeys](https://www.bleepingcomputer.com/news/microsoft/microsoft-entra-brings-phishing-resistant-sign-in-to-windows/) - [ ] [New KadNap botnet hijacks ASUS routers to fuel cybercrime proxy network](https://www.bleepingcomputer.com/news/security/new-kadnap-botnet-hijacks-asus-routers-to-fuel-cybercrime-proxy-network/) - [ ] [Finnish intelligence warns of persistent cyber espionage from Russia, China](https://therecord.media/finnish-intel-warns-espionage-china-russia) - [ ] [The New Turing Test: How Threats Use Geometry to Prove 'Humanness'](https://www.bleepingcomputer.com/news/security/the-new-turing-test-how-threats-use-geometry-to-prove-humanness/) - [ ] [Cybercriminals impersonating city officials to steal permit payments, FBI says](https://therecord.media/cybercriminals-impersonate-city-officials-permit-payments) - [ ] [CISA shortens patch deadline for critical Ivanti, SolarWinds bugs](https://therecord.media/cisa-shortens-patch-deadline-ivanti-solarwinds) - [ ] [UK plans to shift fraud fight onto telecoms, tech companies](https://therecord.media/uk-plans-to-shift-fraud-fight-to-telecoms-tech) - [ ] [Plug-in di Chrome cambiano proprietà e diventano malware](https://www.securityinfo.it/2026/03/10/plug-in-di-chrome-cambiano-proprieta-e-diventano-malware/) - [ ] [Russian military hackers revive advanced malware to spy on Ukraine, researchers say](https://therecord.media/russia-apt-28-revives-malware-to-spy-on-ukraine) - [ ] [CISA: Recently patched Ivanti EPM flaw now actively exploited](https://www.bleepingcomputer.com/news/security/cisa-recently-patched-ivanti-epm-flaw-now-actively-exploited/) - [ ] [OAuth Device Code Phishing: A New Microsoft 365 Account Breach Vector](https://any.run/cybersecurity-blog/oauth-device-code-phishing/) - [ ] [Microsoft to enable Windows hotpatch security updates by default](https://www.bleepingcomputer.com/news/microsoft/microsoft-to-enable-hotpatch-security-updates-by-default-in-may/) - [ ] [APT28 hackers deploy customized variant of Covenant open-source tool](https://www.bleepingcomputer.com/news/security/apt28-hackers-deploy-customized-variant-of-covenant-open-source-tool/) - [ ] [BeatBanker: A dual‑mode Android Trojan](https://securelist.com/beatbanker-miner-and-banker/119121/) - [ ] [Kali & LLM: Completely local with Ollama & 5ire](https://www.kali.org/blog/kali-llm-ollama-5ire/) - [ ] [Cyber Risk Management Starts with Understanding the Business: CISO Hannah Suarez Explains Why](https://thecyberexpress.com/cyber-risk-management-hannah-suarez-interview/) - [ ] [Cos’è vibeware, l’industrializzazione dei malware potenziata dalle AI](https://www.cybersecurity360.it/news/vibeware-apt-bitdefender/) - [ ] [Cyberattack Forces Polish Hospital Revert to Paper-Based Operations](https://thecyberexpress.com/szczecin-public-regional-hospital-cyberattack/) - [ ] [Governare l’accesso per governare il rischio: la classificazione della documentazione nella NIS 2](https://www.cybersecurity360.it/legal/governare-laccesso-per-governare-il-rischio-la-classificazione-della-documentazione-nella-nis-2/) - [ ] [AI Chatbots are Sneakily Directing Users to Illegal Online Casinos](https://thecyberexpress.com/ai-chatbots-recommending-illegal-casinos/) - [ ] [Nasscom Calls for Vigilance as Firms Brace for Impact from West Asia Conflict](https://thecyberexpress.com/nasscom-advisory-west-asia-conflict/) - [ ] [An iPhone-hacking toolkit used by Russian spies likely came from U.S military contractor](https://techcrunch.com/2026/03/09/an-iphone-hacking-toolkit-used-by-russian-spies-likely-came-from-u-s-military-contractor/) - 字节跳动技术团队 - [ ] [OpenClaw 养虾第一站,InStreet 全面开放内测!](https://mp.weixin.qq.com/s?__biz=MzI1MzYzMjE0MQ==&mid=2247518740&idx=1&sn=2a5dfc3eda094ecbe8ad6b3025268357) - [ ] [火热报名中| 首届Lance Meetup 2026 · 北京站](https://mp.weixin.qq.com/s?__biz=MzI1MzYzMjE0MQ==&mid=2247518740&idx=2&sn=336c31029f790189df7b27e2160e1233) - IT Service Management News - [ ] [L'adolescenza dell'intelligenza artificiale](http://blog.cesaregallotti.it/2026/03/ladolescenza-dellintelligenza.html) - [ ] [Attacchi ai data center Amazon in Dubai](http://blog.cesaregallotti.it/2026/03/attacchi-ai-data-center-amazon-in-dubai.html) - 安全419 - [ ] [国家信息安全漏洞库(CNNVD)重要漏洞提示 | 人工智能重要安全漏洞的通报-OpenClaw多个安全漏洞](https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&mid=2247552449&idx=1&sn=2eefcc448f78fc82ec51aaa9fd1df71c) - Kali Linux - [ ] [Kali & LLM: Completely local with Ollama & 5ire](https://www.kali.org/blog/kali-llm-ollama-5ire/) - Dark Space Blogspot - [ ] [I Migliori Libri su Trading, Investimenti, Cripto e Intelligenza Artificiale (Guida Completa)](http://darkwhite666.blogspot.com/2026/03/i-migliori-libri-su-trading.html) - Securityinfo.it - [ ] [Plug-in di Chrome cambiano proprietà e diventano malware](https://www.securityinfo.it/2026/03/10/plug-in-di-chrome-cambiano-proprieta-e-diventano-malware/?utm_source=rss&utm_medium=rss&utm_campaign=plug-in-di-chrome-cambiano-proprieta-e-diventano-malware) - ICT Security Magazine - [ ] [Estensioni Chrome AI malevole: oltre 260.000 utenti trasformati in fonti di intelligence per il cybercrime](https://www.ictsecuritymagazine.com/articoli/estensioni-chrome-ai-malevole/) - [ ] [Threat Hunting Hypothesis-Driven: metodo, pratica e maturità operativa](https://www.ictsecuritymagazine.com/articoli/threat-hunting-hypothesis-driven/) - Troy Hunt's Blog - [ ] [Weekly Update 494](https://www.troyhunt.com/weekly-update-494/) - SANS Internet Storm Center, InfoCON: green - [ ] [Microsoft Patch Tuesday March 2026, (Tue, Mar 10th)](https://isc.sans.edu/diary/rss/32782) - [ ] [ISC Stormcast For Tuesday, March 10th, 2026 https://isc.sans.edu/podcastdetail/9842, (Tue, Mar 10th)](https://isc.sans.edu/diary/rss/32780) - Lenny Zeltser - [ ] [Building Security Products for SMBs](https://zeltser.com/smb-security-product-strategy/) - 白泽安全实验室 - [ ] [黑客利用伪造OpenClaw(龙虾)安装程序展开恶意攻击活动](https://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&mid=2247492888&idx=1&sn=6bc38be07e324de8df59f0df93224702) - Schneier on Security - [ ] [Jailbreaking the F-35 Fighter Jet](https://www.schneier.com/blog/archives/2026/03/jailbreaking-the-f-35-fighter-jet.html) - 云鼎实验室 - [ ] [安心“养虾”,腾讯龙虾安全中心来了!](https://mp.weixin.qq.com/s?__biz=MzU3ODAyMjg4OQ==&mid=2247497270&idx=1&sn=4050128883431b1cecc0d13a9f3f91f7) - The Hacker News - [ ] [How to Stop AI Data Leaks: A Webinar Guide to Auditing Modern Agentic Workflows](https://thehackernews.com/2026/03/how-to-stop-ai-data-leaks-webinar-guide.html) - [ ] [FortiGate Devices Exploited to Breach Networks and Steal Service Account Credentials](https://thehackernews.com/2026/03/fortigate-devices-exploited-to-breach.html) - [ ] [KadNap Malware Infects 14,000+ Edge Devices to Power Stealth Proxy Botnet](https://thehackernews.com/2026/03/kadnap-malware-infects-14000-edge.html) - [ ] [New "LeakyLooker" Flaws in Google Looker Studio Could Enable Cross-Tenant SQL Queries](https://thehackernews.com/2026/03/new-leakylooker-flaws-in-google-looker.html) - [ ] [The Zero-Day Scramble is Avoidable: A Guide to Attack Surface Reduction](https://thehackernews.com/2026/03/the-zero-day-scramble-is-avoidable.html) - [ ] [APT28 Uses BEARDSHELL and COVENANT Malware to Spy on Ukrainian Military](https://thehackernews.com/2026/03/apt28-uses-beardshell-and-covenant.html) - [ ] [Threat Actors Mass-Scan Salesforce Experience Cloud via Modified AuraInspector Tool](https://thehackernews.com/2026/03/threat-actors-mass-scan-salesforce.html) - [ ] [CISA Flags SolarWinds, Ivanti, and Workspace One Vulnerabilities as Actively Exploited](https://thehackernews.com/2026/03/cisa-flags-solarwinds-ivanti-and.html) - NetSPI - [ ] [CVE-2025-26399 SolarWinds Web Help Desk Overview and Takeaways](https://www.netspi.com/blog/executive-blog/critical-vulnerability/cve-2025-26399-solarwinds-web-help-desk-overview-and-takeaways/) - SEI Blog - [ ] [Assessing the Feasibility and Advisability of a Civilian Cybersecurity Reserve](https://www.sei.cmu.edu/blog/assessing-the-feasibility-and-advisability-of-a-civilian-cybersecurity-reserve/?utm_source=blog&utm_medium=rss&utm_campaign=my_site_updates) - Trend Micro Research, News and Perspectives - [ ] [CISOs in a Pinch: A Security Analysis of OpenClaw](https://www.trendmicro.com/en_us/research/26/c/cisos-in-a-pinch-a-security-analysis-openclaw.html) - [ ] [Through the Lens of MDR: Analysis of KongTuke’s ClickFix Abuse of Compromised WordPress Sites](https://www.trendmicro.com/en_us/research/26/c/kongtuke-clickfix-abuse-of-compromised-wordpress-sites.html) - Deeplinks - [ ] [Copyright Bullying vs. Religious Freedom](https://www.eff.org/deeplinks/2026/03/copyright-bullying-vs-religious-freedom-0) - [ ] [Think Twice Before Buying or Using Meta’s Ray-Bans](https://www.eff.org/deeplinks/2026/03/think-twice-buying-or-using-metas-ray-bans) - [ ] [The Government Must Not Force Companies to Participate in AI-powered Surveillance](https://www.eff.org/deeplinks/2026/03/government-must-not-force-companies-participate-ai-powered-surveillance) - Security Affairs - [ ] [Microsoft Patch Tuesday security updates for March 2026 fixed 84 bugs](https://securityaffairs.com/189266/security/microsoft-patch-tuesday-security-updates-for-march-2026-fixed-84-bugs.html) - [ ] [Attackers exploit FortiGate devices to access sensitive network information](https://securityaffairs.com/189241/security/attackers-exploit-fortigate-devices-to-access-sensitive-network-information.html) - [ ] [APT28 conducts long-term espionage on Ukrainian forces using custom malware](https://securityaffairs.com/189230/apt/apt28-conducts-long-term-espionage-on-ukrainian-forces-using-custom-malware.html) - [ ] [Threat actors use custom AuraInspector to harvest data from Salesforce systems](https://securityaffairs.com/189214/security/threat-actors-use-custom-aurainspector-to-harvest-data-from-salesforce-systems.html) - [ ] [U.S. CISA adds Ivanti EPM, SolarWinds, and Omnissa Workspace One flaws to its Known Exploited Vulnerabilities catalog](https://securityaffairs.com/189172/security/u-s-cisa-adds-ivanti-epm-solarwinds-and-omnissa-workspace-one-flaws-to-its-known-exploited-vulnerabilities-catalog.html) - [ ] [Ericsson US confirms breach after third-party provider attack](https://securityaffairs.com/189197/data-breach/ericsson-us-confirms-breach-after-third-party-provider-attack.html) - [ ] [Law enforcement disrupted Tycoon 2FA phishing-as-a-service platform](https://securityaffairs.com/189205/cyber-crime/law-enforcement-disrupted-tycoon-2fa-phishing-as-a-service-platform.html) - The Register - Security - [ ] [Critical Microsoft Excel bug weaponizes Copilot Agent for zero-click information disclosure attack](https://go.theregister.com/feed/www.theregister.com/2026/03/10/zeroclick_microsoft_info_disclosure_bug/) - [ ] [Cybercrime isn't just a cover for Iran's government goons - it's a key part of their operations](https://go.theregister.com/feed/www.theregister.com/2026/03/10/cybercrime_iran_mois/) - [ ] [Crooks compromise WordPress sites to push infostealers via fake CAPTCHA prompts](https://go.theregister.com/feed/www.theregister.com/2026/03/10/crooks_hijack_wordpress_sites/) - [ ] [Fake job applications pack malware that kills EDR before stealing data](https://go.theregister.com/feed/www.theregister.com/2026/03/10/malware_targeting_hr/) - [ ] [Ericsson blames vendor vishing slip-up for breach exposing thousands of records](https://go.theregister.com/feed/www.theregister.com/2026/03/10/ericsson_blames_vendor_vishing_slipup/) - [ ] [Protecting democracy means democratizing cybersecurity. Bring on the hackers](https://go.theregister.com/feed/www.theregister.com/2026/03/10/democratizing_security_opinion/) - [ ] [Polish cops bust alleged teen DDoS kit sellers – youngest just 12](https://go.theregister.com/feed/www.theregister.com/2026/03/10/poland_ddos_teens_bust/) - Your Open Hacker Community - [ ] [Decrypting chrome passwords](https://www.reddit.com/r/HowToHack/comments/1rqb8k2/decrypting_chrome_passwords/) - [ ] [Cracking / recovering a .Rar file](https://www.reddit.com/r/HowToHack/comments/1rq1c4e/cracking_recovering_a_rar_file/) - [ ] [Can’t see a contact’s profile picture anymore—restricted or just removed?](https://www.reddit.com/r/HowToHack/comments/1rq5t8r/cant_see_a_contacts_profile_picture/) - [ ] [Running Javascript in Android pdf reader.](https://www.reddit.com/r/HowToHack/comments/1rpslw4/running_javascript_in_android_pdf_reader/) - [ ] [is a school chromebook info stealer possible?](https://www.reddit.com/r/HowToHack/comments/1rq9jg7/is_a_school_chromebook_info_stealer_possible/) - [ ] [Uhh I want to learn game cracking](https://www.reddit.com/r/HowToHack/comments/1rq4bgw/uhh_i_want_to_learn_game_cracking/) - [ ] [Hacking a unit ut60bt Multimeter](https://www.reddit.com/r/HowToHack/comments/1rpkp02/hacking_a_unit_ut60bt_multimeter/) - [ ] [Go to for binary harness setup?](https://www.reddit.com/r/HowToHack/comments/1rpje39/go_to_for_binary_harness_setup/) - [ ] [Hack Career](https://www.reddit.com/r/HowToHack/comments/1rpiti1/hack_career/) - Computer Forensics - [ ] [Can anyone tell me what I have here?](https://www.reddit.com/r/computerforensics/comments/1rq4f7s/can_anyone_tell_me_what_i_have_here/) - Blackhat Library: Hacking techniques and research - [ ] [IronPE - Minimal Windows PE manual loader written in Rust.](https://www.reddit.com/r/blackhat/comments/1rprbq7/ironpe_minimal_windows_pe_manual_loader_written/) - [ ] [DLP blocked all data outbound from USB ports, blue tooth , wifi , email , chats. How to transfer 2GB pdf data to external drive?](https://www.reddit.com/r/blackhat/comments/1rpl3b8/dlp_blocked_all_data_outbound_from_usb_ports_blue/) - Information Security - [ ] [Complete Firmwares, Drivers, Processes, Services, Registry Security Tool For Advanced Users (Windows)](https://www.reddit.com/r/Information_Security/comments/1rq39bn/complete_firmwares_drivers_processes_services/) - [ ] [How to prevent sensitive data from being shared through risky websites across endpoints](https://www.reddit.com/r/Information_Security/comments/1rptush/how_to_prevent_sensitive_data_from_being_shared/) - [ ] [WEBSITE PORTFOLIO - TRUST](https://www.reddit.com/r/Information_Security/comments/1rpsdxa/website_portfolio_trust/) - [ ] [Generating Intentionaly vulnerable application](https://www.reddit.com/r/Information_Security/comments/1rpsdpu/generating_intentionaly_vulnerable_application/) - [ ] [Are firewalls still the backbone of SMB security, or just one layer people overestimate now?](https://www.reddit.com/r/Information_Security/comments/1rpprdn/are_firewalls_still_the_backbone_of_smb_security/) - netsecstudents: Subreddit for students studying Network Security and its related subjects - [ ] [How can I simulate SIM-swap attacks in a lab environment to test account takeover defenses?](https://www.reddit.com/r/netsecstudents/comments/1rq3lcw/how_can_i_simulate_simswap_attacks_in_a_lab/) - [ ] [IronPE - Minimal Windows PE manual loader written in Rust.](https://www.reddit.com/r/netsecstudents/comments/1rprbcb/ironpe_minimal_windows_pe_manual_loader_written/) - Social Engineering - [ ] [Facts don't win arguments. Whoever controls the frame does. Here's what took me years to understand.](https://www.reddit.com/r/SocialEngineering/comments/1rqdhb5/facts_dont_win_arguments_whoever_controls_the/) - [ ] [A simple habit that completely changed how people perceive me: creating a "Fun Fact" dossier after every interaction](https://www.reddit.com/r/SocialEngineering/comments/1rqdpkh/a_simple_habit_that_completely_changed_how_people/) - [ ] [Am I thinking about social confidence the wrong way?](https://www.reddit.com/r/SocialEngineering/comments/1rpr1qc/am_i_thinking_about_social_confidence_the_wrong/) - Technical Information Security Content & Discussion - [ ] [How "Strengthening Crypto" Broke Authentication: FreshRSS and bcrypt's 72-Byte Limit](https://www.reddit.com/r/netsec/comments/1rqa9sg/how_strengthening_crypto_broke_authentication/) - [ ] [Classifying email providers of 2000+ Swiss municipalities via DNS, looking for feedback on methodology](https://www.reddit.com/r/netsec/comments/1rq8hvz/classifying_email_providers_of_2000_swiss/) - [ ] [Your Duolingo Is Still Talking to ByteDance: How Pangle Fingerprints You Across Apps After You Said No](https://www.reddit.com/r/netsec/comments/1rpqlh2/your_duolingo_is_still_talking_to_bytedance_how/) - [ ] [Electric Eye – a Rust/WASM Firefox extension to detect AitM proxies via DOM analysis, TLS fingerprinting and HTTP header inspection](https://www.reddit.com/r/netsec/comments/1rpqnpm/electric_eye_a_rustwasm_firefox_extension_to/) - [ ] [Trust no one: are one-way trusts really one way?](https://www.reddit.com/r/netsec/comments/1rpvzfh/trust_no_one_are_oneway_trusts_really_one_way/) - GRAHAM CLULEY - [ ] [Twitter suspended 800 million accounts last year – so why does manipulation remain so rampant?](https://www.bitdefender.com/en-us/blog/hotforsecurity/twitter-suspended-800-million-accounts-last-year-so-why-does-manipulation-remain-so-rampant) - TorrentFreak - [ ] [Internet Archive Faces Copyright Lawsuit Over ‘Myspace Dragon Hoard’](https://torrentfreak.com/internet-archive-faces-copyright-lawsuit-over-myspace-dragon-hoard/) - DEFION Research Labs - [ ] [Ruckus Unleashed: Multiple vulnerabilities exploited](/en/research-labs/ruckus-unleashed-multiple-vulnerabilities-exploited) - [ ] [Pwn2Own Automotive 2024: Hacking the Autel MaxiCharger](/en/research-labs/pwn2own-automotive-2024-hacking-the-autel-maxicharger) - [ ] [Pwn2Own Automotive 2024: Hacking the JuiceBox 40](/en/research-labs/pwn2own-automotive-2024-hacking-the-juicebox-40) - [ ] [Pwn2Own Automotive 2024: Hacking the ChargePoint Home Flex (and their cloud...)](/en/research-labs/pwn2own-automotive-2024-hacking-the-chargepoint-home-flex-and-their-cloud) - [ ] [DoNex/DarkRace Ransomware Decryptor](/en/research-labs/donex-darkrace-ransomware-decryptor) - [ ] [CVE-2024-20693: Windows cached code signature manipulation](/en/research-labs/cve-2024-20693-windows-cached-code-signature-manipulation) - [ ] [Bringing process injection into view(s): exploiting all macOS apps using nib files](/en/research-labs/bringing-process-injection-into-view-s-exploiting-all-macos-apps-using-nib-files) - [ ] [Don’t Talk All at Once! Elevating Privileges on macOS by Audit Token Spoofing](/en/research-labs/don-t-talk-all-at-once-elevating-privileges-on-macos-by-audit-token-spoofing) - [ ] [Getting SYSTEM on Windows in style](/en/research-labs/getting-system-on-windows-in-style) - [ ] [Technical analysis of the Genesis Market](/en/research-labs/technical-analysis-of-the-genesis-market) - [ ] [Bad things come in large packages: .pkg signature verification bypass on macOS](/en/research-labs/bad-things-come-in-large-packages-pkg-signature-verification-bypass-on-macos) - [ ] [Pwn2Own Miami 2022: ICONICS GENESIS64 Arbitrary Code Execution](/en/research-labs/pwn2own-miami-2022-iconics-genesis64-arbitrary-code-execution) - [ ] [Pwn2Own Miami 2022: Unified Automation C++ Demo Server DoS](/en/research-labs/pwn2own-miami-2022-unified-automation-c-demo-server-dos) - [ ] [Pwn2Own Miami 2022: AVEVA Edge Arbitrary Code Execution](/en/research-labs/pwn2own-miami-2022-aveva-edge-arbitrary-code-execution) - [ ] [Process injection: breaking all macOS security layers with a single vulnerability](/en/research-labs/process-injection-breaking-all-macos-security-layers-with-a-single-vulnerability) - [ ] [Pwn2Own Miami 2022: Inductive Automation Ignition Remote Code Execution](/en/research-labs/pwn2own-miami-2022-inductive-automation-ignition-remote-code-execution) - [ ] [Pwn2Own Miami 2022: OPC UA .NET Standard Trusted Application Check Bypass](/en/research-labs/pwn2own-miami-2022-opc-ua-net-standard-trusted-application-check-bypass) - [ ] [CoronaCheck App TLS certificate vulnerabilities](/en/research-labs/coronacheck-app-tls-certificate-vulnerabilities) - [ ] [Sandbox escape + privilege escalation in StorePrivilegedTaskService](/en/research-labs/sandbox-escape-privilege-escalation-in-storeprivilegedtaskservice) - [ ] [Proctorio Chrome extension Universal Cross-Site Scripting](/en/research-labs/proctorio-chrome-extension-universal-cross-site-scripting) - [ ] [Zoom RCE from Pwn2Own 2021](/en/research-labs/zoom-rce-from-pwn2own-2021) - [ ] [Adobe Acrobat privilege escalation](/en/research-labs/adobe-acrobat-privilege-escalation) - [ ] [iOS VPN support: 3 different bugs](/en/research-labs/ios-vpn-support-3-different-bugs) - [ ] [Sign in with Apple - authentication bypass](/en/research-labs/sign-in-with-apple-authentication-bypass) - [ ] [Jenkins - authentication bypass](/en/research-labs/jenkins-authentication-bypass) - [ ] [DNS rebinding for HTTPS](/en/research-labs/dns-rebinding-for-https) - [ ] [Spring Security - insufficient cryptographic randomness](/en/research-labs/spring-security-insufficient-cryptographic-randomness) - [ ] [XenServer - path traversal leading to authentication bypass](/en/research-labs/xenserver-path-traversal-leading-to-authentication-bypass) - [ ] [Volkswagen Auto Group MIB infotainment system - unauthenticated remote code execution as root](/en/research-labs/volkswagen-auto-group-mib-infotainment-system-unauthenticated-remote-code-execution-as-root) - [ ] [NAPALM - command execution on NAPLM controller from host](/en/research-labs/napalm-command-execution-on-naplm-controller-from-host) - [ ] [MySQL Connector/J - Unexpected deserialisation of Java objects](/en/research-labs/mysql-connector-j-unexpected-deserialisation-of-java-objects) - [ ] [Ansible - command execution on Ansible controller from host](/en/research-labs/ansible-command-execution-on-ansible-controller-from-host) - [ ] [Observium - unauthenticated remote code execution](/en/research-labs/observium-unauthenticated-remote-code-execution) - [ ] [cSRP/srpforjava - obtaining of hashed passwords](/en/research-labs/csrp-srpforjava-obtaining-of-hashed-passwords) - [ ] [StartEncrypt - obtaining valid SSL certificates for unauthorized domains](/en/research-labs/startencrypt-obtaining-valid-ssl-certificates-for-unauthorized-domains) - 白帽子章华鹏 - [ ] [线下闭门沙龙:探讨龙虾对企业安全的颠覆](https://mp.weixin.qq.com/s?__biz=MzIyOTAxOTYwMw==&mid=2650238862&idx=1&sn=7a4bb87865f2ef3f0132be9737878800) - Daniel Miessler - [ ] [People Got Unhappier When Life Got Easy](https://danielmiessler.com/blog/people-got-unhappier-when-life-got-easy?utm_source=rss&utm_medium=feed&utm_campaign=website) - [ ] [Why I believe in SOTA models over custom ones](https://danielmiessler.com/blog/sota-models-over-custom-ones?utm_source=rss&utm_medium=feed&utm_campaign=website) - [ ] [The Culture Series: A Complete Guide to Glanding](https://danielmiessler.com/blog/the-culture-series-complete-guide-to-glanding?utm_source=rss&utm_medium=feed&utm_campaign=website) - Security Weekly Podcast Network (Audio) - [ ] [Precious Bodily Fluids, InstallFix, CISA, Claude, Overtime, Sim Swaps, Aaran Leyland - SWN #562](http://sites.libsyn.com/18678/precious-bodily-fluids-installfix-cisa-claude-overtime-sim-swaps-aaran-leyland-swn-562) - [ ] [Making Medical Devices Secure - Tamil Mathi - ASW #373](http://sites.libsyn.com/18678/making-medical-devices-secure-tamil-mathi-asw-373)
每日安全资讯(2026-03-11)