-
Notifications
You must be signed in to change notification settings - Fork 36
Open
Labels
Description
每日安全资讯(2026-01-09)
- SecWiki News
- paper - Last paper
- Doonsec's feed
- JeecgBoot积木报表getDataSourceByPage接口存在敏感信息泄露漏洞 附POC
- Apt_t00ls:Java 开发的OA设备高危漏洞集成利用工具
- InversePrompt:Claude Code 不是最后的受害者!
- 美国移民及海关执法局(ICE)的监控工具们
- 知足
- 【攻防实战10】记一次医药公司的深度穿透(一)
- 四字节的谎言:无 SMAP 保护下的内核指针信任欺骗
- 揭秘AI合成数据背后的“数字病毒”传染链!
- 众测环境下被忽视的“水洞”攻击面
- 一文读懂:GB/T 45953-2025《供应链安全管理体系规范》
- 每日课程更新
- n8n Ni8mare - 未经认证的任意文件读取到远程代码执行链 (CVSS 10.0)
- 初一期末考试即将来临
- 【AI安全】揭秘AI合成数据背后的“数字病毒”传染链!
- 美15个大型“人工智能数据中心”情况
- 从委内瑞拉事件看美国为何不敢对伊朗动手?
- 新一代Webshell 管理与后渗透平台 | 去除通信流量强特征,支持自定义流量格式实现流量伪装
- CS上线方式
- Claude Agent Skills:智能体能力的模块化扩展与高效执行
- 2026年校园舆情防控工作指南--全日制学校舆情管理操作手册
- 专题·金融安全 | 金融行业数据安全风险监测运营体系建设实践
- 当AI学会“读屏”:天御助力金融应用守住安全防线
- 【数字政府优秀案例联播】商务部:运用大模型技术构建政府网站辅助阅读体系
- 公安部通报第六个中国人民警察节有关安排
- 2025年回顾:10大数据安全事件!
- ByteSRC开年首测|火山引擎AI业务单个漏洞赏金10万元!
- 江阴农商银行大模型赋能贷前运营,20万客户享7×24小时智能服务
- AI快讯:商务部回应审查Meta收购Manus,智谱上市市值破570亿
- 财跃星辰中!国泰海通证券2026年AI投顾超级助手建设采购项目
- DLL 劫持复现记录(显式加载)
- 【吃瓜】某信内核大佬因年会没西装被董事长开除
- 【安全圈】三星 SSD 管理软件曝高危漏洞
- 【安全圈】黑客利用0Day漏洞工具包在野攻击VMware ESXi实例
- 【安全圈】安卓 / Linux 内核高危漏洞 CVE-2025-38352 验证性利用代码已公开
- 【安全圈】GoBruteforcer 僵尸网络全球攻击 Linux 服务器,5 万台公网服务器面临风险
- 【接口漏洞第三章第四节】进阶实战:如何用 Burp Intruder “暴力推理”出隐藏的API端点?
- AI智能体或成2026年政企内部最大安全隐患
- “搜打撤”在渗透测试中的运用
- 【安全锐评】信息安全并非只是网络空间安全
- 【福利赠送】ISO 22301业务连续性管理体系导入实施案例(4)组织内外因素的识别
- 【已复现】n8n 前台远程代码执行漏洞(CVE-2026-21858)
- 【已复现】ComfyUI-Manager 远程代码执行漏洞(CVE-2025-67303)
- 全国工商联 | 齐向东:“数智新程东风劲,跃马扬鞭正当时”
- “银狐”木马盯上出海中企,天守EDR护航全球业务安全
- 飞天诚信出席SAC/TC28/SC17二届四次全会并做报告(还得了奖)
- AURA创新框架自动化数据投毒方案应对AI模型窃取威胁
- 怎样看待“300元监控员工隐私”事件;企业如何开展数据保护工作 | FB甲方群话题讨论
- 黑客利用0Day漏洞工具包在野攻击VMware ESXi实例
- 间谍行动还是技术故障?委内瑞拉BGP泄漏事件真相剖析
- 武汉大学 | JBShield: 通过激活概念分析与操控防御大语言模型免受越狱攻击
- 论坛·算法治理 | 互联网信息服务算法治理:从专项行动迈向常态化长效化治理
- 通知 | 八部门印发《“人工智能+制造”专项行动实施意见》
- 公安部:严打电诈犯罪 2025年侦破案件25.8万起 抓获诈骗集团幕后“金主”、头目和骨干等542名
- 关注 | 智源研究院发布2026十大AI技术趋势:NSP范式重构世界认知,超级应用与安全并进
- 评论 | 以前瞻性统筹和系统性布局把握人工智能治理的主动
- 盘点 | 中国互联网联合辟谣平台2025年12月辟谣榜
- AI Native 产品实践:当判断力成为核心竞争力
- LevelBlue Blog
- Recent Commits to cve:main
- 先知安全技术社区
- 奇安信攻防社区
- Private Feed for M09Ic
- mgeeky starred XaFF-XaFF/Black-Angel-Rootkit
- joaoviictorti starred irsdl/ysonet
- PrefectHQ released 3.6.10 at PrefectHQ/prefect
- bolucat released 202601081937 at bolucat/Archive
- kpcyrd contributed to kpcyrd/rebuilderd
- mgeeky starred KickedDroid/bof_oxide
- Teach2Breach forked Teach2Breach/rustmm from buyukakyuz/rustmm
- Teach2Breach starred buyukakyuz/rustmm
- panjf2000 starred anthropics/skills
- joaoviictorti starred krb5/krb5
- mgeeky starred 0xedh/dumpguard_bof
- CHYbeta starred PleasePrompto/notebooklm-skill
- l3yx released v0.2.3 at l3yx/intentlang
- timwhitez starred Fission-AI/OpenSpec
- gh0stkey starred Tongyi-MAI/Z-Image
- PrefectHQ released 3.6.10.dev5 at PrefectHQ/prefect
- pathwaycom released v0.28.0 at pathwaycom/pathway
- timwhitez starred OthmanAdi/planning-with-files
- niudaii starred anomalyco/opencode
- Ridter starred The-Z-Labs/bof-launcher
- Ridter starred WinMin/evil-opencode
- Sucuri Blog
- 嘶吼 RoarTalk – 网络安全行业综合服务平台,4hou.com
- ElcomSoft blog
- Blogs on STAR Labs
- Horizon3.ai
- Malware-Traffic-Analysis.net - Blog Entries
- Malwarebytes
- blog.avast.com EN
- 奇客Solidot–传递最新科技情报
- 安全分析与研究
- 代码卫士
- 黑鸟
- 漕河泾小黑屋
- 安全内参
- 二道情报贩子
- 威努特安全网络
- 天御攻防实验室
- 长亭安全应急响应中心
- 天黑说嘿话
- 奇安信 CERT
- 中国信息安全
- 信息安全国家工程研究中心
- 网安杂谈
- 安全学术圈
- 安全圈
- 补天平台
- 吾爱破解论坛
- 数世咨询
- 微步在线
- 看雪学苑
- 阿里安全响应中心
- 嘶吼专业版
- 丁爸 情报分析师的工具箱
- 字节跳动安全中心
- 极客公园
- 美团技术团队
- 情报分析师
- TrustedSec
- Over Security - Cybersecurity news aggregator
- New China-linked hackers breach telcos using edge device exploits
- Who Benefited from the Aisuru and Kimwolf Botnets?
- FBI warns about Kimsuky hackers using QR codes to phish U.S. orgs
- xAI teases major Grok upgrade, hints at Grok Code CLI
- CISA sunsets 10 emergency directives thanks to evolution of exploited vulnerabilities catalog
- CPPA fines data broker selling lists of Alzheimer's patients
- VMware ESXi zero-days likely exploited a year before disclosure
- Texas court blocks Samsung from tracking TV viewing, then vacates order
- Cisco switches hit by reboot loops due to DNS client bug
- Critics pan spyware maker NSO’s transparency claims amid its push to enter US market
- Internet collapses in Iran amid protests over economic crisis
- Resolutions, shmesolutions (and what’s actually worked for me)
- ChatGPT Health feature draws concern from privacy critics over sensitive medical data
- Texas court blocks Samsung from collecting smart TV viewing data
- Data poisoning: cos’è e come proteggersi dall’avvelenamento dei modelli di AI generativa
- Crif, il borseggio digitale colpisce un Under30 su 5: come proteggersi
- AI nelle telecomunicazioni: agenti intelligenti per gestire gli incidenti di rete, il caso Eutelsat
- Gestione degli incidenti informatici: adesso serve avere un piano
- NSA cyber directorate gets new acting leadership
- Six for 2026: The cyber threats you can’t ignore
- Nuova ondata di attacchi GoBruteforcer, l’IA sfruttata per il brute-force
- US announces withdrawal from dozens of international treaties
- Initial Access Sales Accelerated Across Australia and New Zealand in 2025
- Microsoft Exchange Online outage blocks access to mailboxes via IMAP4
- Microsoft to enforce MFA for Microsoft 365 admin center sign-ins
- Nuova vulnerabilità critica Ni8mare in n8n: Attacco senza autenticazione
- ESXi Exploitation in the Wild | Huntress
- UAT-7290 targets high value telecommunications infrastructure in South Asia
- Q-Day: strategie di crypto-agility per la sicurezza delle infrastrutture crittografiche
- Nuova campagna di phishing su “scadenza Tessera Sanitaria” in corso
- Cisco warns of Identity Service Engine flaw with exploit code
- CISA tags max severity HPE OneView flaw as actively exploited
- Fake Browser Updates Targeting WordPress Administrators via Malicious Plugin
- 360数字安全
- IT Service Management News
- Krypt3ia
- Securityinfo.it
- TaoSecurity Blog
- SANS Internet Storm Center, InfoCON: green
- Schneier on Security
- Full Disclosure
- The Hacker News
- WhatsApp Worm Spreads Astaroth Banking Trojan Across Brazil via Contact Auto-Messaging
- China-Linked UAT-7290 Targets Telecoms with Linux Malware and ORB Nodes
- ThreatsDay Bulletin: RustFS Flaw, Iranian Ops, WebUI RCE, Cloud Leaks, and 12 More Stories
- The State of Trusted Open Source
- Cisco Patches ISE Security Vulnerability After Public PoC Exploit Release
- Researchers Uncover NodeCordRAT Hidden in npm Bitcoin-Themed Packages
- Coolify Discloses 11 Critical Flaws Enabling Full Server Compromise on Self-Hosted Instances
- OpenAI Launches ChatGPT Health with Isolated, Encrypted Health Data Controls
- CISA Flags Microsoft Office and HPE OneView Bugs as Actively Exploited
- The Register - Security
- As agents run amok, CrowdStrike's $740M SGNL deal aims to help get a grip on identity security
- Patch Cisco ISE bug now before attackers abuse proof-of-concept exploit
- Ransomware attacks kept climbing in 2025 as gangs refused to stay dead
- CISA flags actively exploited Office relic alongside fresh HPE flaw
- UK regulators swarm X after Grok generated nudes from photos
- Maximum-severity n8n flaw lets randos run your automation server
- OpenAI putting bandaids on bandaids as prompt injection problems keep festering
- Yes, criminals are using AI to vibe-code malware
- Logitech macOS mouse mayhem traced to expired dev certificate
- Cloudflare pours cold water on ‘BGP weirdness preceded US attack on Venezuela’ theory
- TorrentFreak
- Graham Cluley
- Security Affairs
- Astaroth banking Trojan spreads in Brazil via WhatsApp worm
- Public PoC prompts Cisco patch for ISE, ISE-PIC vulnerability
- U.S. CISA adds HPE OneView and Microsoft Office PowerPoint flaws to its Known Exploited Vulnerabilities catalog
- China-linked groups intensify attacks on Taiwan’s critical infrastructure, NSB warns
- Krebs on Security
- Deeplinks
- Daniel Miessler
- 云鼎实验室
- 安全攻防团队
- 白帽子章华鹏
- Security Weekly Podcast Network (Audio)