# 每日安全资讯(2026-07-17) - SecWiki News - [ ] [SecWiki News 2026-07-16 Review](http://www.sec-wiki.com/?2026-07-16) - 先知安全技术社区 - [ ] [从“拒答辱骂”到“配合骂人”:模型微调如何悄悄拆除安全护栏](https://xz.aliyun.com/news/92529) - Paper - 知道创宇404实验室 - [ ] [通过内部归因图实现LLM越狱的机制可解释性](https://paper.seebug.org/3502) - Doonsec's feed - [ ] [年度科技风向标|30 大科技攻关方向出炉:AI 网络韧性、太空计算、6G 智能体成重点](https://mp.weixin.qq.com/s/ahpDYbnj3cQ6dyN0lqDWuw) - [ ] [DeepSentry 2.0.1 正式发布:让 AI 安全 Agent 真正跑进应急现场](https://mp.weixin.qq.com/s/jsOyLcJORUrLotkCBjGt1g) - [ ] [开源 AI Hacker 工具 strix](https://mp.weixin.qq.com/s/ChcAZ42hEL4B3n1SVlaerA) - [ ] [Wireshark键盘快捷键速查表](https://mp.weixin.qq.com/s/q-C9XlFAmb5nkLK2LdMPYA) - [ ] [李艳:借鉴网络治理经验,实现跨域风险管控](https://mp.weixin.qq.com/s/cAb7S03k9csaIyTzt-bVZw) - [ ] [通知 | 网安标委2026年41项网络安全国家标准项目立项](https://mp.weixin.qq.com/s/e0nPST9K1kKNb64Xvrbw5A) - [ ] [观点 | 加快构建数字领域涉外法治体系](https://mp.weixin.qq.com/s/cyHENWjMF_gfu_r6Ii5Kog) - [ ] [关注 | 从填表到刷脸,谁在过度收集个人信息?](https://mp.weixin.qq.com/s/oRwdbgvFqksr8wIUgC2XOg) - [ ] [评论 | 让网络测评生态清朗可信](https://mp.weixin.qq.com/s/h2xRfcEzU-Jb4dvoMksbSQ) - [ ] [AI优先时代生存法则:四个问题筛出真正有生命力的网络安全产品](https://mp.weixin.qq.com/s/xIybLVsZMRWWnx44PkTw-Q) - [ ] [进入AI时代,微软为何打算终结“周二补丁日”?](https://mp.weixin.qq.com/s/VA9yqdgv9yFcMsD5rk4U2A) - [ ] [USENIX Security 2026 — Cycle 1 论文清单与摘要(上)](https://mp.weixin.qq.com/s/HsOVvqpfQji4uZ6-4z3d5g) - [ ] [USENIX Security 2026 — Cycle 1 论文清单与摘要(下)](https://mp.weixin.qq.com/s/WBMkwRnFP0MX-nNHtqP2pA) - [ ] [奇安信与哈萨克斯坦人工智能和数字发展部签署合作备忘录](https://mp.weixin.qq.com/s/7Qx63xew1bVxCMeIpUeWGA) - [ ] [安全报告 | 恒安嘉新6月网络信息安全综合态势报告](https://mp.weixin.qq.com/s/ialvC30_UdSVXQYqLWp8sA) - [ ] [专题报告 | 恒安嘉新网络安全-APT攻击、勒索病毒及互联网漏洞专题分析报告](https://mp.weixin.qq.com/s/ZHBhcOoiwyZkUCHWuI2ydw) - [ ] [苏州市召开商用密码应用与执法业务培训研讨会](https://mp.weixin.qq.com/s/Hwkhg6pV7G6Gfx6qrf1nhg) - [ ] [AI快讯:努比亚发AI智能体手机,小米发机器人基座模型,智联招聘发AI人才报告](https://mp.weixin.qq.com/s/dopjh3f-eVDzM3R_rJIWyw) - [ ] [数码港 Web4.0 与智能体安全联盟成立,慢雾(SlowMist) 出任创始成员](https://mp.weixin.qq.com/s/cy3qCJYBJTa-BPWUzyNeEg) - [ ] [AntSRC 年度 TOP8 白帽榜单正式公布,致谢每一位安全同行者](https://mp.weixin.qq.com/s/Uwk13Yps3Y05V0DRJB6Kdg) - [ ] [企业文档安全最佳实践(四):集团权限归集与统一管理——横纵立体,密钥定界](https://mp.weixin.qq.com/s/Sym0sftp4AbYS76RDcBqeA) - [ ] [亮点前瞻 | 国家网信办将在2026年APEC数字周期间举办系列活动](https://mp.weixin.qq.com/s/TvTt9y2mkAzxeQSpUB5GuQ) - [ ] [信通院发布第五期《数字安全护航技术能力全景图》 奇安信全领域覆盖](https://mp.weixin.qq.com/s/yLjEXd5kId0s4inn4joJXA) - [ ] [AI又惹祸了?硅谷大佬Mac遭一键清空,智能体安全再敲警钟](https://mp.weixin.qq.com/s/se5RbrUn3m7A8fSm8kbWfw) - [ ] [最后一站,上海!CSOP2026·AI安全大会完美收官](https://mp.weixin.qq.com/s/v96sdbxZWhO5rg6ImY4MCQ) - [ ] [分享图片](https://mp.weixin.qq.com/s/pi3tFtc7-nu4BwPb9KOLtg) - [ ] [蔚来招聘AI云基础设施安全工程师](https://mp.weixin.qq.com/s/JZCyqT-oqmQpaY3KOZVaxg) - [ ] [Listary V7 Beta 发布!本地文件搜索体验全面进化](https://mp.weixin.qq.com/s/udoNSJuGzWFLhgYD9OKijQ) - [ ] [精品产品 | 捷普工控安全运维管理系统](https://mp.weixin.qq.com/s/XPBMGqncNtWjyowLcpioLw) - [ ] [精品产品 | 捷普工控安全集中管理系统](https://mp.weixin.qq.com/s/RxcARM9OuZmeHwv_Y95-Ug) - [ ] [精品产品 | 捷普工控安全评估系统](https://mp.weixin.qq.com/s/hDLHUhJ7-aqtigaX9BN_Fw) - [ ] [精品产品 | 捷普工控等保检查工具箱](https://mp.weixin.qq.com/s/5ncDO28r_-_yjOYYwqn8dQ) - [ ] [挖洞,再挖点Token!](https://mp.weixin.qq.com/s/ZQ5SkcIfB7vOeYxKuxGFYw) - [ ] [一篇文章告诉你:国家网络身份认证公共服务是什么](https://mp.weixin.qq.com/s/QZ2CAcyVGH5UrTkZVgKp1Q) - [ ] [文末抽奖|南开大学2026 DataCon AI安全夏令营正式开启!顶尖高校+头部大厂大咖齐聚!](https://mp.weixin.qq.com/s/ssARsOH3pcmREL4piYh8cg) - [ ] [腾讯PCG联合深圳河套学院:在全双工语音大模型领域取得重要突破,获 ACL 2026 杰出论文奖](https://mp.weixin.qq.com/s/d7TgHluCVmGM90Rjjny0Mw) - [ ] [教育行业SRC供应商漏洞变化 (2026-07-16)](https://mp.weixin.qq.com/s/-2A5Sscw0Y0eAj-4f6eUaw) - [ ] [一年花掉400小时登陆设备,这笔运维账没人算过!](https://mp.weixin.qq.com/s/YDgLkRjxf7moKjg3jQP_ZQ) - [ ] [终于有人把AI挖洞讲透了——百万赏金猎人验证的AI全链路实战课](https://mp.weixin.qq.com/s/aQ-2fnfG597XlHlBE449uA) - [ ] [智赋安全|观安信息荣登2026AI+网络安全产业图谱6项细分领域](https://mp.weixin.qq.com/s/a0GIddnBSDJu2Q2XMOo8CQ) - [ ] [天融信智算云重磅升级:兼顾通用业务与AI创新,三大技术突破构建一体化算力底座](https://mp.weixin.qq.com/s/cR7P2hosbmh8gLEwLECAww) - [ ] [密评高风险判定指引系列(二):物理和环境安全与网络和通信安全高风险判定](https://mp.weixin.qq.com/s/ifEMkQ4W62a6AXOPqGQBvw) - [ ] [安恒信息党委获评滨江两新组织产业链“攻坚先锋”荣誉称号](https://mp.weixin.qq.com/s/zlPwQ13QYUIFKt7W9BDTHg) - [ ] [【更新】BSRC业务系数调整!产品线范围更清晰!](https://mp.weixin.qq.com/s/MnOmDMLgIE6iC9f03p8uOg) - [ ] [火热报名中 | 2026年福建省信息通信行业职业技能竞赛](https://mp.weixin.qq.com/s/TSXrovcnOY0k1KNYtIuCfQ) - [ ] [OpenAI秘密开发大模型超级黑客,攻击成功率高达84%](https://mp.weixin.qq.com/s/mT66dgbyF1t1I4N7PjB43A) - [ ] [AI私人助手会被偷偷篡改记忆:揭秘隐形内存注入攻击](https://mp.weixin.qq.com/s/2J_Jl-zz3exZmZ4vko1izQ) - [ ] [CISP培训讲师申请表、维持申请表及管理办法](https://mp.weixin.qq.com/s/Uoa899_zDUP7BT71BS017A) - [ ] [巾帼聚力筑数据根基,智赋企业启数字新程|《高质量数据集构建与应用》专项培训圆满落幕](https://mp.weixin.qq.com/s/OHBmMqFLEnHafu1OgUXpCQ) - [ ] [增速第一!长亭科技跃升中国暴露面管理市场前三](https://mp.weixin.qq.com/s/PF7dECO0089Wy_GzrC5KDQ) - [ ] [招聘|中国网络安全审查认证和市场监管大数据中心2026年度公开招聘公告](https://mp.weixin.qq.com/s/Dugl86clsPIGN-zp1jQm3Q) - [ ] [关于优化数据分析师人才培养及考核的通知](https://mp.weixin.qq.com/s/BCoumtgJYpJ__wRXS9twbw) - [ ] [暗流涌动!某NGO 组织遭遇秘密监视窃听~](https://mp.weixin.qq.com/s/VyNHk0XVa18yJeXQWR5MgA) - [ ] [面向2035:人工智能与机器人技术对国家安全的影响](https://mp.weixin.qq.com/s/NlSCuCuyu7zpEJ1Jyc1M9g) - [ ] [交通运输部印发《交通运输数据安全管理办法》(附全文)](https://mp.weixin.qq.com/s/hTi2FVYnaMnIDNKa713sBA) - [ ] [现场直聘,为您的业务招募一位“企业级智能伙伴”|WAIC 2026](https://mp.weixin.qq.com/s/UD7kQKRQB_83tsySK2fYNg) - [ ] [grok-build开源,2 小时 7 千星](https://mp.weixin.qq.com/s/Z28uLLWbO1t9RF6FCHJPtQ) - [ ] [DOUBLETROUBLE: 1靶场实战](https://mp.weixin.qq.com/s/lksrrlQa7i43nNHaoarxHg) - [ ] [印度最大核电站疑遭勒索攻击 黑客泄露大量文件包括设计图纸](https://mp.weixin.qq.com/s/RQfGOKOgPPICrIOlWyfwaA) - [ ] [西湖论剑×阿里云:大赛在即,专属AI算力支持已就位](https://mp.weixin.qq.com/s/wYUTVMGgyE18KXNnS6Y5_Q) - [ ] [渗透测试从业者的新工具 潜影 TraceHarvest](https://mp.weixin.qq.com/s/wRyYs_Mtn22GfKHEQtzexg) - [ ] [南京理工大学网络空间安全学院2025级硕士生学术论文被网安领域顶会USENIX Security 2026录用](https://mp.weixin.qq.com/s/Oltj7xfNfo915i0k4EI4sA) - [ ] [网络安全日报 | 2026-07-16](https://mp.weixin.qq.com/s/Nn-gISZ1EJSsx4IFPCi-3Q) - [ ] [WAIC 2026 倒计时,合合信息展台亮点前瞻!](https://mp.weixin.qq.com/s/UNFv5PfMRv36_216PORasA) - [ ] [【情报分析】伊朗前总统艾哈迈迪内贾德为何被指认被摩萨德招募?](https://mp.weixin.qq.com/s/5sl2G1eN2j_ocbuVV4i_dg) - [ ] [科普|你了解国家网络身份认证吗?](https://mp.weixin.qq.com/s/ncM5b8hpzoqFVXWFmFHq6w) - [ ] [深信服零信任,连续5年「双料第一」](https://mp.weixin.qq.com/s/UbZfnDAFBKjGOjFsjLXjDQ) - [ ] [深度技术_AI_Agent_智能体_安全__2026年最值得学习的网络安全新方向](https://mp.weixin.qq.com/s/SJgedmH1bovvjYZCat2ntw) - [ ] [当 LLM 做了超出职责的事](https://mp.weixin.qq.com/s/uMIVkBC0z4Fe0FCS2UlKzA) - [ ] [震惊!这款工具让AI编码助手彻底沦为渗透测试神器](https://mp.weixin.qq.com/s/eWb-hSNjEEY4_WsUcY_y6g) - [ ] [Firefox、Chrome、Adobe 和 VMware 更新修复了多项关键安全漏洞](https://mp.weixin.qq.com/s/Kndq5ayLaknllpu48PedcA) - [ ] [工联安全大讲堂第三十七期即将开讲!](https://mp.weixin.qq.com/s/0KGOY3Tjqj2SJWPLUuBvWw) - [ ] [2026年5月考试成绩](https://mp.weixin.qq.com/s/JgSpmgtd4BJTC1ttx0_rNg) - [ ] [德国老牌工厂因网络攻击导致生产线停产,被迫破产](https://mp.weixin.qq.com/s/VKINglwFl9KvDJkyBRcUdQ) - [ ] [2026京麒CTF决赛 倒计时三天!](https://mp.weixin.qq.com/s/5W7ubcEbSrYJfrKmwTnv4Q) - [ ] [安全快报 | 巴基斯坦多个执法系统遭网络间谍组织恶意入侵](https://mp.weixin.qq.com/s/Br_vvGO6p3V-4EXDVyODmw) - [ ] [用AI分析Wireshark 数据包 一切变得很简单](https://mp.weixin.qq.com/s/AYxik2PgkiDOEmLvvmzv8w) - Microsoft Security Blog - [ ] [ACR Stealer: Two observed intrusion chains amid increased threat activity](https://www.microsoft.com/en-us/security/blog/2026/07/16/acr-stealer-two-observed-intrusion-chains-amid-increased-threat-activity/) - [ ] [Least privilege for AI agents: Identity, access, and tool binding](https://www.microsoft.com/en-us/security/blog/2026/07/16/least-privilege-for-ai-agents-identity-access-and-tool-binding/) - [ ] [Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery](https://www.microsoft.com/en-us/security/blog/2026/07/15/unpacking-asyncapi-npm-supply-chain-compromise-import-time-payload-delivery/) - Recent Commits to cve:main - [ ] [Update Thu Jul 16 12:01:45 UTC 2026](https://github.com/trickest/cve/commit/6e5939e8074723d33adaf5b2f8b0352edab9ba8d) - ElcomSoft blog - [ ] [Two-Factor Authentication and iCloud: A Short History, and What We Fixed in Phone Breaker 11.03](https://blog.elcomsoft.com/2026/07/two-factor-authentication-and-icloud-a-short-history-and-what-we-fixed-in-phone-breaker-11-03/) - Tenable Blog - [ ] [CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities](https://www.tenable.com/blog/cve-2026-32201-cve-2026-45659-cve-2026-56164-faq-sharepoint-server-exploitation) - [ ] [The best defenders build AI agents together: Join Tenable for Swarm at Black Hat ’26](https://www.tenable.com/blog/black-hat-2026-swarm-event-build-AI-security-agents) - Insinuator.net - [ ] [Windows Hello for Business – Full Report Has Been Released](https://insinuator.net/2026/07/windows-hello-for-business-full-report-has-been-released/) - Private Feed for M09Ic - [ ] [bolucat released 202607162121 at bolucat/Archive](https://github.com/bolucat/Archive/releases/tag/202607162121) - [ ] [esrrhs contributed to esrrhs/fakelua](https://github.com/esrrhs/fakelua/pull/249) - [ ] [CHYbeta starred irsdl/BurpSuiteSharpenerEx](https://github.com/irsdl/BurpSuiteSharpenerEx) - [ ] [OpenAEV-Platform released 2.260716.1 at OpenAEV-Platform/openaev](https://github.com/OpenAEV-Platform/openaev/releases/tag/2.260716.1) - [ ] [zema1 starred RapidAI/RapidOCR](https://github.com/RapidAI/RapidOCR) - [ ] [Rvn0xsy starred KnockOutEZ/wigolo](https://github.com/KnockOutEZ/wigolo) - [ ] [OpenAEV-Platform released 2.260716.0 at OpenAEV-Platform/openaev](https://github.com/OpenAEV-Platform/openaev/releases/tag/2.260716.0) - [ ] [agentscope-ai released v2.0.4.post1 at agentscope-ai/agentscope](https://github.com/agentscope-ai/agentscope/releases/tag/v2.0.4.post1) - [ ] [mgeeky starred zosmaai/pi-llm-wiki](https://github.com/zosmaai/pi-llm-wiki) - [ ] [Mel0day starred vectorize-io/hindsight](https://github.com/vectorize-io/hindsight) - [ ] [uknowsec starred dstours/OctoC2](https://github.com/dstours/OctoC2) - [ ] [timwhitez starred xai-org/grok-build](https://github.com/xai-org/grok-build) - [ ] [BeichenDream starred rasta-mouse/ThreatCheck](https://github.com/rasta-mouse/ThreatCheck) - [ ] [esrrhs starred xai-org/grok-build](https://github.com/xai-org/grok-build) - [ ] [gh0stkey starred apache/caldera](https://github.com/apache/caldera) - [ ] [timwhitez starred MrTiz/CET-Enum-CallStack-Spoofer](https://github.com/MrTiz/CET-Enum-CallStack-Spoofer) - [ ] [pydantic released v2.11.0 at pydantic/pydantic-ai](https://github.com/pydantic/pydantic-ai/releases/tag/v2.11.0) - [ ] [zeroclaw-labs released v0.8.3 at zeroclaw-labs/zeroclaw](https://github.com/zeroclaw-labs/zeroclaw/releases/tag/v0.8.3) - [ ] [RuoJi6 released fork-v0.5.58-audit.1 at RuoJi6/dbx-audit](https://github.com/RuoJi6/dbx-audit/releases/tag/fork-v0.5.58-audit.1) - [ ] [mgeeky starred PiLastDigit/TRIP-workflow](https://github.com/PiLastDigit/TRIP-workflow) - Horizon3.ai - [ ] [2026 SANS SOC Survey Insights: A Decade of Evolution in Cyber Defense](https://horizon3.ai/downloads/whitepapers/2026-sans-soc-survey-insights/) - Inside Stormshield - [ ] [Bienvenue dans l’aventure Stormshield !](https://stories.stormshield.com/bienvenue-dans-laventure-stormshield/) - GuidePoint Security - [ ] [Managing the Transition from SMS and Voice to Passkeys: What the Microsoft Deadline Means for Your Organization](https://www.guidepointsecurity.com/blog/managing-the-transition-from-sms-and-voice-to-passkeys-microsoft-deadline/) - Malwarebytes - [ ] [The backlash against Flock cameras is spreading](https://www.malwarebytes.com/blog/news/2026/07/the-backlash-against-flock-cameras-is-spreading) - [ ] [Security updates available for Adobe, Chrome, Firefox, VMWare, and Zoom](https://www.malwarebytes.com/blog/bugs/2026/07/security-updates-available-for-adobe-chrome-firefox-vmware-and-zoom) - [ ] [Samsung backs down on threat to delete health data](https://www.malwarebytes.com/blog/privacy/2026/07/samsung-backs-down-on-threat-to-delete-health-data) - Reverse Engineering - [ ] ["Remcos RAT – Svchost Injection, API Hooking & Obfuscated Payload Analysis"](https://www.reddit.com/r/ReverseEngineering/comments/1uy4vpu/remcos_rat_svchost_injection_api_hooking/) - [ ] [Reverse-engineering NVIDIA's cuda-checkpoint for faster cold starts](https://www.reddit.com/r/ReverseEngineering/comments/1uxu3zf/reverseengineering_nvidias_cudacheckpoint_for/) - [ ] [First firmware dump of Canon PIXMA TS3451 — AES-GCM manifest encrypted by MatrixSSL Asset Store, looking for help with key derivation](https://www.reddit.com/r/ReverseEngineering/comments/1uxmszf/first_firmware_dump_of_canon_pixma_ts3451_aesgcm/) - [ ] [ASUS bsitf.sys (CVE-2026-13585): Arbitrary Physical Memory Mapping 0-day writeup + PoC](https://www.reddit.com/r/ReverseEngineering/comments/1uxutfu/asus_bsitfsys_cve202613585_arbitrary_physical/) - [ ] [I ported Half Life 2: Deathmatch to the web. Play now!](https://www.reddit.com/r/ReverseEngineering/comments/1uyfv9i/i_ported_half_life_2_deathmatch_to_the_web_play/) - [ ] [GitHub - joshuapassos/CMF-Watch-Pro-2-BLE-Protocol](https://www.reddit.com/r/ReverseEngineering/comments/1uxmy85/github_joshuapassoscmfwatchpro2bleprotocol/) - [ ] [🔥 Apkx-Hunter v2.0.0 Released — OWASP MASVS Security Scanning Added! This version introduces **OWASP MASVS (Mobile Application Security Verification Standard)** security scanning with **15 categories** and **166 detection patterns**.](https://www.reddit.com/r/ReverseEngineering/comments/1uxnxd4/apkxhunter_v200_released_owasp_masvs_security/) - daniel.haxx.se - [ ] [Workshop Basel day three](https://daniel.haxx.se/blog/2026/07/16/workshop-basel-day-three/) - Securelist - [ ] [HelloNet campaign — new malicious modules launched through the ViPNet update system](https://securelist.com/tr/hellonet-vipnet/120700/) - [ ] [GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration](https://securelist.com/goserpent-backdoor-in-southeast-asia/120687/) - 奇客Solidot–传递最新科技情报 - [ ] [Grok Build 开源,在这之前它被发现会上传用户的完整库](https://www.solidot.org/story?sid=84848) - [ ] [马不靠声音或气味就能识别屏幕上的捕食者](https://www.solidot.org/story?sid=84847) - [ ] [图书出版商指控 Google 在训练 Gemini 过程中大规模侵犯版权](https://www.solidot.org/story?sid=84846) - [ ] [DeepSeek 计划年内申请 IPO](https://www.solidot.org/story?sid=84845) - [ ] [因意外关机和过热微软暂停向部分戴尔电脑推送七月安全更新](https://www.solidot.org/story?sid=84844) - [ ] [AI 公司高管加强个人安保](https://www.solidot.org/story?sid=84843) - 黑海洋Wiki | AI机器人硬件开发 | 网络安全攻防实战 | 区块链技术文档教程 - 免费资源平台 - [ ] [SpaceX在点火后突然中止了星舰V3发射](https://blog.upx8.com/SpaceX%E5%9C%A8%E7%82%B9%E7%81%AB%E5%90%8E%E7%AA%81%E7%84%B6%E4%B8%AD%E6%AD%A2%E4%BA%86%E6%98%9F%E8%88%B0V3%E5%8F%91%E5%B0%84) - 绿盟科技技术博客 - [ ] [微软7月安全更新多个产品高危漏洞通告](https://blog.nsfocus.net/%e5%be%ae%e8%bd%af7%e6%9c%88%e5%ae%89%e5%85%a8%e6%9b%b4%e6%96%b0%e5%a4%9a%e4%b8%aa%e4%ba%a7%e5%93%81%e9%ab%98%e5%8d%b1%e6%bc%8f%e6%b4%9e%e9%80%9a%e5%91%8a/) - HackerNews - [ ] [白宫推出 AI 驱动的"Gold Eagle"漏洞协调计划](http://0.0.0.0:8080/post/64476) - [ ] [CISA 敦促立即修补已被利用的 SharePoint 漏洞](http://0.0.0.0:8080/post/64475) - [ ] [美国起诉俄罗斯个人及公司运营网络犯罪服务](http://0.0.0.0:8080/post/64474) - [ ] [Google Gemini CLI 被滥用作黑客代理和恶意软件僵尸网络操作工具](http://0.0.0.0:8080/post/64473) - [ ] [TuxBot v3 Evolution 显示出 LLM 辅助开发 IoT 僵尸网络的迹象](http://0.0.0.0:8080/post/64472) - [ ] [OkoBot 恶意软件框架向 Ledger 和 Trezor 应用注入助记词钓鱼页面](http://0.0.0.0:8080/post/64471) - 皮相 - [ ] [用缓冲区溢出漏洞把矿卡变成 A100](https://mp.weixin.qq.com/s?__biz=MzI0NDA5MDYyNA==&mid=2648257342&idx=1&sn=dfb0ede540af1cb3a4b311414e6537a0) - 黑鸟 - [ ] [谁在运营那些小型 RPKI 服务器?藏在互联网底层的安全细节](https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451187701&idx=1&sn=27db1546569e5672e2394eeb992d6a3d) - 微步在线研究响应中心 - [ ] [微步情报局发现并协助修复Eclipse Jetty 12 路径穿越漏洞](https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&mid=2247508760&idx=1&sn=dc6529b7677375b6b25b63a962ed7fed) - 全频带阻塞干扰 - [ ] [暗流涌动!某NGO 组织遭遇秘密监视窃听~](https://mp.weixin.qq.com/s?__biz=MzIzMzE2OTQyNA==&mid=2648959404&idx=1&sn=399e28c2e2ea4ac63a277091dd8f8fa4) - 威努特安全网络 - [ ] [Linux磁盘空间不足?一文掌握LVM在线扩容](https://mp.weixin.qq.com/s?__biz=MzAwNTgyODU3NQ==&mid=2651143049&idx=1&sn=f742be0efe46e91fe00c0ec4146f53f1) - 奶牛安全 - [ ] [数据泄露情报2026.7.16 - 刚找到一个包罗万象的新TG频道](https://mp.weixin.qq.com/s?__biz=MzU4NjY0NTExNA==&mid=2247489826&idx=1&sn=716c8d547d29ba596349df2e10612a6b) - 看雪学苑 - [ ] [如何避免窗口被游戏反作弊误杀以及替代方案](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458617641&idx=1&sn=54c0bc8acd309e50f82c44be8e15d9b6) - [ ] [又撕微软!无补丁 LegacyHive 0day,低权限可读取管理员注册表数据](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458617641&idx=2&sn=c9db90ecf64e7fc1a85189aaaeff52d4) - [ ] [一考双证!360 智能体工程师(ADEA)认证](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458617641&idx=3&sn=de5e540d26b48f07f60ac63b8ea3a0a5) - 安全内参 - [ ] [OpenAI秘密开发大模型超级黑客,攻击成功率高达84%](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516274&idx=1&sn=dcebe6da07569a854bc85a3b4c349434) - [ ] [AI私人助手会被偷偷篡改记忆:揭秘隐形内存注入攻击](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516274&idx=2&sn=985eaf02edb693d50f852d4633c29f2c) - 天黑说嘿话 - [ ] [恭喜,你的声音被喜马生态企业选中做有声书兼职副业!](https://mp.weixin.qq.com/s?__biz=MzI5NTQ5MTAzMA==&mid=2247486241&idx=1&sn=cea4f47778dfcd466c7feb8c56de832a) - 青衣十三楼飞花堂 - [ ] [超级军旗再次击沉谢菲尔德号](https://mp.weixin.qq.com/s?__biz=MzUzMjQyMDE3Ng==&mid=2247489695&idx=1&sn=9c9e66cf1d64fa723c1a4880fd0094bc) - 代码卫士 - [ ] [Zoom:注意这个严重的账户接管漏洞](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247526636&idx=1&sn=7a16b14bc318e77d8eaa96cd6c7f7025) - [ ] [CISA:立即修复这些已遭利用的 SharePoint 漏洞](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247526636&idx=2&sn=fe817375b8e1b3316d7d8bc37bfe109f) - 安全学术圈 - [ ] [中科院信工所 | 基于语义–流量跨模态对齐的零样本 HTTPS 网站指纹识别](https://mp.weixin.qq.com/s?__biz=MzU5MTM5MTQ2MA==&mid=2247495640&idx=1&sn=ae63fb731f33fdb31c41423636db324a) - 丁爸 情报分析师的工具箱 - [ ] [【开源报告】美国全球供应链数据掌控与供应链安全控制分析](https://mp.weixin.qq.com/s?__biz=MzI2MTE0NTE3Mw==&mid=2651156607&idx=1&sn=3f4a7d8d36ee97dbcb592294fe5763b9) - 信息安全国家工程研究中心 - [ ] [观点 | 谨防境外AI“后门”风险](https://mp.weixin.qq.com/s?__biz=MzU5OTQ0NzY3Ng==&mid=2247504448&idx=1&sn=8731755d180d00ac5b44b071d68db117) - 数世咨询 - [ ] [捕捉恶意代码的顶级智能体反而被恶意代码欺骗](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247543511&idx=1&sn=d06a97086854322f81ae37abed9aeb6f) - 安全圈 - [ ] [【安全圈】印度核电站机密文件在暗网被叫卖](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652077869&idx=1&sn=4db9ee61cee8d53af62a11ee59e555e2) - [ ] [【安全圈】SonicWall爆出两个零日漏洞,黑客已在利用](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652077869&idx=2&sn=afe6269498d72500b766add22dac0d26) - [ ] [【安全圈】82%的恶意攻击,还是从你的邮箱进来](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652077869&idx=3&sn=68e6083d960d99e9f1ce86b730e987ee) - 漏洞战争 - [ ] [USENIX Security 2026 — Cycle 1 论文清单与摘要(上)](https://mp.weixin.qq.com/s?__biz=MzU0MzgzNTU0Mw==&mid=2247486124&idx=1&sn=5feac1df49b63f898b824fc3fd66ccd8) - [ ] [USENIX Security 2026 — Cycle 1 论文清单与摘要(下)](https://mp.weixin.qq.com/s?__biz=MzU0MzgzNTU0Mw==&mid=2247486124&idx=2&sn=725a2ac1a1c3c5eb5898347a88ea60bc) - 极客公园 - [ ] [AI 创业者,涌向张江 AI 创新小镇](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653110644&idx=1&sn=fcaf6a9f8d00e06ab2c09a6705e254a3) - [ ] [一个 152 年的家电品牌,给出 AI 营销落地新解法](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653110641&idx=1&sn=9f69f75061251fc8e2694746e67865ac) - [ ] [国行苹果 AI 终于来了,千问将作底层模型;美团、青桔、哈啰集体涨价;曝 DeepSeek 筹备 IPO|极客早知道](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653110633&idx=1&sn=9ca95c022ae4dac14321e76cecae2b7e) - 京东安全应急响应中心 - [ ] [2026京麒CTF决赛 倒计时三天!](https://mp.weixin.qq.com/s?__biz=MjM5OTk2MTMxOQ==&mid=2727851011&idx=1&sn=2b9d4833d5567c0742c25d3f46739287) - 百度安全应急响应中心 - [ ] [【更新】BSRC业务系数调整!产品线范围更清晰!](https://mp.weixin.qq.com/s?__biz=MzA4ODc0MTIwMw==&mid=2652544100&idx=1&sn=b5a8c779b8c68cb432812ca22a42d731) - 字节跳动技术团队 - [ ] [从 Data Lake 到 State Lake:面向 Agent 时代的存储基础设施重构](https://mp.weixin.qq.com/s?__biz=MzI1MzYzMjE0MQ==&mid=2247520930&idx=1&sn=bd7a4aa7ed7ce2d4ca65e807f53392f6) - [ ] [9.9 元/月,用 AgentPlan + OpenViking 给销售团队配一个不会忘事的 AI 助手](https://mp.weixin.qq.com/s?__biz=MzI1MzYzMjE0MQ==&mid=2247520930&idx=2&sn=d28d61e9a893bc39fdbe6797404755cb) - 深信服千里目安全技术中心 - [ ] [【安全公告】深信服安全公告一则](https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&mid=2247526068&idx=1&sn=da1eefaf936e0c0e9060b553119104c3) - 慢雾科技 - [ ] [Grok CLI 风险分析:一个 prompt 如何把敏感文件送上云端?](https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&mid=2247505436&idx=1&sn=a7825c0778488567fd4ad8716d09288d) - [ ] [数码港 Web4.0 与智能体安全联盟成立,慢雾(SlowMist) 出任创始成员](https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&mid=2247505436&idx=2&sn=a197680ff2950f0bf4189ad9227ed577) - 火绒安全 - [ ] [宿主级潜伏:伪装搜狗输入法渲染组件的DLL分析](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247535416&idx=1&sn=50f21b413c85703c4b614002b0225f26) - [ ] [诚邀渠道合作伙伴共启新征程](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247535416&idx=2&sn=b4209c82c6c9bf47739ad958f6f5e05c) - 情报分析师 - [ ] [伊朗媒体发布一份“复仇”暗杀名单,为什么是这13张脸,伊朗到底会用什么手段](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650568720&idx=1&sn=feb645433e85d707670017bc5b680105) - [ ] [【情报分析】伊朗前总统艾哈迈迪内贾德为何被指认被摩萨德招募?](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650568720&idx=2&sn=1dc950f3204616ff62a368c611b7c9ac) - TrustedSec - [ ] [CMMC is (Not) Cancelled](https://trustedsec.com/blog/cmmc-is-not-cancelled) - 360数字安全 - [ ] [上海见!WAIC 2026智聚长三角·AI安全赋能产业创新论坛议程一览](https://mp.weixin.qq.com/s?__biz=MzA4MTg0MDQ4Nw==&mid=2247586599&idx=1&sn=415a038536193105e587208ae3f92ff4) - 威胁猎人Threat Hunter - [ ] [2026年第二季度智能大屏终端黑产恶意流量观察|基于智能电视与电视盒子受控样本的研究](https://mp.weixin.qq.com/s?__biz=MzI3NDY3NDUxNg==&mid=2247504201&idx=1&sn=f784a03b6fd4c4ca2316bbd6cccadc11) - 悬镜安全 - [ ] [AI智能体安全|问境AIST如何实现智能体评估-验证-预警一站式闭环治理!](https://mp.weixin.qq.com/s?__biz=MzA3NzE2ODk1Mg==&mid=2647800023&idx=1&sn=03fcdcc08ebda783ebf854a80049c8e0) - bellingcat - [ ] [Identifying the Crypto Entrepreneur Linked to Popular Forum Trading in ‘Leaked’ Nudes of Women](https://www.bellingcat.com/news/2026/07/16/leakedbb-crypto-entrepreneur/) - Schneier on Security - [ ] [Protecting Privacy in an AI Era](https://www.schneier.com/blog/archives/2026/07/protecting-privacy-in-an-ai-era.html) - 网安国际 - [ ] [文末抽奖|南开大学2026 DataCon AI安全夏令营正式开启!顶尖高校+头部大厂大咖齐聚!](https://mp.weixin.qq.com/s?__biz=MzA4ODYzMjU0NQ==&mid=2652318295&idx=1&sn=95d1cdc38957ea09949753aee1d18ef7) - 吾爱破解论坛 - [ ] [暑假开放注册微信抽奖活动,先送20个账号注册码或300论坛币,下午两点开奖,目前中奖率8%,详见:【开放注册公告】吾爱破解论坛2026年7月...](https://mp.weixin.qq.com/s?__biz=MjM5Mjc3MDM2Mw==&mid=2651144636&idx=1&sn=b865d8d649c486cb45d082e75595438e) - ICT Security Magazine - [ ] [Albiriox, il RAT bancario che si finge UniCredit su Telegram](https://www.ictsecuritymagazine.com/notizie/albiriox-rat-bancario-italia/) - [ ] [Comunicazione di crisi: il lato dell’incidente che non si risolve in sala server](https://www.ictsecuritymagazine.com/cyber-security/comunicazione-di-crisi-incidente-cyber/) - Security Affairs - [ ] [Two Scattered Spider Members Sentenced to Prison Over £29 Million TfL Cyberattack](https://securityaffairs.com/195501/cyber-crime/two-scattered-spider-members-sentenced-to-prison-over-29-million-tfl-cyberattack.html) - [ ] [TuxBot v3: The IoT Botnet Built With AI – Bugs, Disclaimers and All](https://securityaffairs.com/195486/ai/tuxbot-v3-the-iot-botnet-built-with-ai-bugs-disclaimers-and-all.html) - [ ] [Claude Code and DeepSeek Powered Chinese Cyber Espionage Campaign](https://securityaffairs.com/195474/ai/claude-code-and-deepseek-powered-chinese-cyber-espionage-campaign.html) - [ ] [Zoom Fixes CVE-2026-53412, a Critical Account Takeover Bug](https://securityaffairs.com/195454/security/zoom-fixes-cve-2026-53412-a-critical-account-takeover-bug.html) - The Hacker News - [ ] [Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack](https://thehackernews.com/2026/07/two-scattered-spider-hackers-get-55.html) - [ ] [ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories](https://thehackernews.com/2026/07/threatsday-game-cheat-spyware-24-hour.html) - [ ] [n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer](https://thehackernews.com/2026/07/n8n-token-exchange-flaw-could-let.html) - [ ] [New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands](https://thehackernews.com/2026/07/new-telepuz-malware-spreads-via.html) - [ ] [New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password](https://thehackernews.com/2026/07/new-clicklock-macos-stealer-kills-apps.html) - [ ] [20+ Hijacked Government Websites Became an Attack Channel](https://thehackernews.com/2026/07/20-hijacked-government-websites.html) - [ ] [New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands](https://thehackernews.com/2026/07/new-agent-data-injection-attack-can.html) - [ ] [Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor](https://thehackernews.com/2026/07/daxin-resurfaces-in-taiwan-alongside.html) - [ ] [AI Can Find Bugs, But Human Knowledge Still Proves Them](https://thehackernews.com/2026/07/ai-can-find-bugs-but-human-knowledge.html) - [ ] [Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide](https://thehackernews.com/2026/07/unpatched-shark-vacuum-flaw-could-let.html) - [ ] [OpenAI’s GPT-Red Automates Prompt Injection Testing to Harden GPT-5.6 Sol](https://thehackernews.com/2026/07/openais-gpt-red-automates-prompt.html) - [ ] [Zoom Patches Critical Windows Flaw That Could Enable Account Takeover](https://thehackernews.com/2026/07/zoom-patches-critical-windows-flaw-that.html) - Deeplinks - [ ] [EFF and ARTICLE 19 Submission to the European Commission on the DSA Trusted Flagger Guidelines](https://www.eff.org/deeplinks/2026/07/eff-and-article-19-submission-european-commission-dsa-trusted-flagger-guidelines) - SANS Internet Storm Center, InfoCON: green - [ ] [ISC Stormcast For Thursday, July 16th, 2026 https://isc.sans.edu/podcastdetail/10010, (Thu, Jul 16th)](https://isc.sans.edu/diary/rss/33160) - Full Disclosure - [ ] [[NotCVE-2026-0001] Cloudflare Universal SSL CAA augmentation weakens RFC 8657 account binding — CVE-2026-14440 assigned 163 days after public no-CVE disclosure](https://seclists.org/fulldisclosure/2026/Jul/22) - [ ] [Subject: Advisory Submission: EZ Game Booster - Cleartext Storage of Sensitive Credentials (CWE-312)](https://seclists.org/fulldisclosure/2026/Jul/21) - [ ] [CVE-2026-56877 - Skillable SCORM userId authorisation bypass](https://seclists.org/fulldisclosure/2026/Jul/20) - Your Open Hacker Community - [ ] [been trying to crack this keepass db hash, for some reason john and hashcat are not recognising it](https://www.reddit.com/r/HowToHack/comments/1uy1ryc/been_trying_to_crack_this_keepass_db_hash_for/) - [ ] [Pokemon go spoofing](https://www.reddit.com/r/HowToHack/comments/1uy1jmr/pokemon_go_spoofing/) - [ ] [How to crack Wpa2/3 password ?](https://www.reddit.com/r/HowToHack/comments/1uy1k32/how_to_crack_wpa23_password/) - www.theregister.com - Articles - [ ] [OpenAI admits GPT-5.6 occasionally deletes files – but it's an 'honest mistake'](https://www.theregister.com/ai-and-ml/2026/07/16/openai-admits-gpt-56-occasionally-deletes-files-but-its-an-honest-mistake/5274008) - [ ] [Researcher poisons open-weight AI model for under $100](https://www.theregister.com/ai-and-ml/2026/07/16/researcher-poisons-open-weight-ai-model-for-under-100/5273880) - [ ] [C'mon, just copy this text string and paste it into your macOS Terminal – it'll fix your computer, honest](https://www.theregister.com/cyber-crime/2026/07/16/cmon-just-copy-this-text-string-and-paste-it-into-your-macos-terminal-itll-fix-your-computer-honest/5273701) - [ ] [Brit Scattered Spider duo handed tickets to prison over Transport for London attack](https://www.theregister.com/cyber-crime/2026/07/16/brit-scattered-spider-duo-handed-tickets-to-prison-over-transport-for-london-attack/5272446) - [ ] [Windows 10 refuses to die, and the security bill is coming due](https://www.theregister.com/os-platforms/2026/07/16/windows-10-refuses-to-die-and-the-security-bill-is-coming-due/5271987) - [ ] [Telegram shortlinks knocked offline over sanctioned VPN connection](https://www.theregister.com/security/2026/07/16/telegram-shortlinks-knocked-offline-over-sanctioned-vpn-connection/5271964) - [ ] [Law firm insisted on one password to rule them all](https://www.theregister.com/security/2026/07/16/law-firm-insisted-on-one-password-to-rule-them-all/5269484) - [ ] [Tech support scam caused massive data breach at Australian airline Qantas](https://www.theregister.com/cyber-crime/2026/07/16/tech-support-scam-caused-massive-data-breach-at-australian-airline-qantas/5272267) - [ ] [Cyberattack threatens utterly critical infrastructure in Japan: KFC](https://www.theregister.com/security/2026/07/16/cyberattack-threatens-utterly-critical-infrastructure-in-japan-kfc/5272220) - Security Weekly Podcast Network (Audio) - [ ] [1999 Called and It Wants It's Exploits Back - PSW #935](http://sites.libsyn.com/18678/1999-called-and-it-wants-its-exploits-back-psw-935) - 网安寻路人 - [ ] [封闭计算环境的数据流通价值:从假名化与匿名化的区分来看(报告全文)](https://mp.weixin.qq.com/s?__biz=MzIxODM0NDU4MQ==&mid=2247508733&idx=1&sn=34a9f1aac841b57de780a2119a05e8ce)
每日安全资讯(2026-07-17)