# 每日安全资讯(2026-04-15) - SecWiki News - [ ] [SecWiki News 2026-04-14 Review](http://www.sec-wiki.com/?2026-04-14) - Private Feed for M09Ic - [ ] [mgeeky starred rotki/rotki](https://github.com/rotki/rotki) - [ ] [0xbug starred ipverse/as-ip-blocks](https://github.com/ipverse/as-ip-blocks) - [ ] [liamg contributed to infracost/proto](https://github.com/infracost/proto/pull/47) - [ ] [bolucat released 202604142125 at bolucat/Archive](https://github.com/bolucat/Archive/releases/tag/202604142125) - [ ] [anthropics released v2.1.108 at anthropics/claude-code](https://github.com/anthropics/claude-code/releases/tag/v2.1.108) - [ ] [github released v0.7.0 at github/spec-kit](https://github.com/github/spec-kit/releases/tag/v0.7.0) - [ ] [Ascotbe starred eze-is/web-access](https://github.com/eze-is/web-access) - [ ] [Mel0day starred Cocoon-AI/architecture-diagram-generator](https://github.com/Cocoon-AI/architecture-diagram-generator) - [ ] [spf13 starred doors-dev/doors](https://github.com/doors-dev/doors) - [ ] [Mr-xn forked Mr-xn/Cli-Proxy-API-Management-Center from kongkongyo/Cli-Proxy-API-Management-Center](https://github.com/Mr-xn/Cli-Proxy-API-Management-Center) - [ ] [niudaii starred mwnickerson/bloodhound_mcp](https://github.com/mwnickerson/bloodhound_mcp) - [ ] [pydantic released v0.0.12 at pydantic/monty](https://github.com/pydantic/monty/releases/tag/v0.0.12) - [ ] [PrefectHQ released 3.6.27.dev2 at PrefectHQ/prefect](https://github.com/PrefectHQ/prefect/releases/tag/3.6.27.dev2) - [ ] [anthropics released v2.1.107 at anthropics/claude-code](https://github.com/anthropics/claude-code/releases/tag/v2.1.107) - [ ] [LoRexxar starred NousResearch/hermes-agent](https://github.com/NousResearch/hermes-agent) - [ ] [ZeddYu starred KKKKhazix/khazix-skills](https://github.com/KKKKhazix/khazix-skills) - [ ] [gh0stkey starred aaif-goose/goose](https://github.com/aaif-goose/goose) - [ ] [Rvn0xsy starred cloudwego/eino](https://github.com/cloudwego/eino) - [ ] [WAY29 starred HKUDS/DeepTutor](https://github.com/HKUDS/DeepTutor) - obaby 𝐢𝐧⃝ void - [ ] [Baby Press — 前后端分离的WP系统](https://zhongxiaojie.cn/2026/04/933/) - Tenable Blog - [ ] [Claude Mythos: Prepare for your board’s cybersecurity questions about the latest AI model from Anthropic](https://www.tenable.com/blog/claude-mythos-prepare-for-AI-cybersecurity-questions-from-your-board-of-directors) - [ ] [Microsoft’s April 2026 Patch Tuesday Addresses 163 CVEs (CVE-2026-32201)](https://www.tenable.com/blog/microsofts-april-2026-patch-tuesday-addresses-163-cves-cve-2026-32201) - ElcomSoft blog - [ ] [Low-Level Extraction for iOS 17 and 18](https://blog.elcomsoft.com/2026/04/low-level-extraction-for-ios-17-and-18/) - Doonsec's feed - [ ] [GetX 仓库消失?别担心,镜像版本来袭!让我们一起守护Flutter生态](https://mp.weixin.qq.com/s/ViaoM1lMzxOSmyYp8POwGg) - [ ] [浏览器抓包新选择!Hx0 鹰眼 V1.0.1 正式上线](https://mp.weixin.qq.com/s/xBVAXULIKdJ_x7c8WEC5Sg) - [ ] [frida-labs经典12道题目](https://mp.weixin.qq.com/s/I64LwJ5vXkQtjMVhm5-7uw) - [ ] [ES::Tools出品ESP+ESD官方辅助工具——Redstone](https://mp.weixin.qq.com/s/qmHDKteVX_yisWnRHyBvRA) - [ ] [Handala曝光了摩萨德和辛贝特领导人的住所](https://mp.weixin.qq.com/s/v4B3POoimrA37fhxOiHqxg) - [ ] [【实战】自制开源情报AI工具集](https://mp.weixin.qq.com/s/v4hY6K9381kHI1GyltPSzQ) - [ ] [用豆包买保险被骗1620元,AI幻觉出现了!](https://mp.weixin.qq.com/s/4qqlu7IftmlxeN7M63tRyQ) - [ ] [论文研读与思考|面向测试时强化学习的验证工具](https://mp.weixin.qq.com/s/xa6nJv7ysNpeWOuF8SlPhg) - [ ] [据报CIA在伊朗营救行动使用以色列间谍软件](https://mp.weixin.qq.com/s/bglHxlqy6npRUXKAY8aNPw) - [ ] [某大厂小领导:年薪八十多万,每天的工作就是催20个外包兄弟通宵改BUG,自己喝着咖啡刷手机“摘果子”,最后良心不安到上网哭诉。](https://mp.weixin.qq.com/s/MueBNNBykCvaROnxteQDIg) - [ ] [【AI安全】硬核!Claude 泄露 12 大智能体细节](https://mp.weixin.qq.com/s/kryXA5AOXZWwz0iGWm9mpg) - [ ] [LLM OWASP Top 10入门初探](https://mp.weixin.qq.com/s/6EgDUOBDlFY-wM4UAY-xaQ) - [ ] [全民国家安全教育日 | 小信息,大安全——守好个人信息“安全门”,夯实国家安全“奠基石”](https://mp.weixin.qq.com/s/c0fIxdMP8q26sIxR0mZKRA) - [ ] [Windows凭证提取技术](https://mp.weixin.qq.com/s/WExm9ZvNeMcnAv__5lIT1Q) - [ ] [全球最大在线旅游公司 Booking.com 遭黑客入侵,旅客姓名 / 电话号码等隐私信息外泄](https://mp.weixin.qq.com/s/Zyo1iTJnpJrLD-_u_8lQpA) - [ ] [重温“4.19”重要讲话十周年系列(2):“菁英计划” 实战化经验分享](https://mp.weixin.qq.com/s/4ync1Q7aWoC7bQoXXMO4YA) - [ ] [【译】在 Google Cloud 中执行远程命令并删除单个目录](https://mp.weixin.qq.com/s/6-c6LJhsxrpYRzq08LtuLg) - [ ] [F5 安全公告:NGINX ngx_http_dav_module 漏洞 CVE-2026-27654](https://mp.weixin.qq.com/s/jHtxeaXbEGVLcgGvQ8v8kg) - [ ] [好家伙,Everything 居然还有 1.5a 隐藏版本](https://mp.weixin.qq.com/s/dNrFl3p60fWMbf3gTKqGkw) - [ ] [免费代理的代价:当攻击者成为猎物](https://mp.weixin.qq.com/s/7yXQOys5MT5VRfrhQcU_7A) - [ ] [IATF 16949: 2016 标准详解与实施(55)8.2.2.1 与产品和服务要求的确定—补充](https://mp.weixin.qq.com/s/x9Pn1KUKAGDGgEwTC3b0_Q) - [ ] [IATF 16949: 2016 标准详解与实施(54)8.2.2 产品和服务要求的确定](https://mp.weixin.qq.com/s/a9VVPdoKB9w8hhBPTIsEaQ) - [ ] [【工业控制系统网络安全系列课程】第3课-工业控制系统的网络安全风险-网络防御、检测和分析](https://mp.weixin.qq.com/s/VnayJbjLfQeNgnQBJpplmA) - [ ] [最大程度获取网站JS的工具](https://mp.weixin.qq.com/s/86L-SsuqO-0uatIGoQbrxg) - [ ] [AI编程助手“说瞎话”,背后隐藏的攻击手段](https://mp.weixin.qq.com/s/37P6dmOlIRpDgcSlGPPO5w) - [ ] [我用AI写了3年代码,直到公司数据库被脱库](https://mp.weixin.qq.com/s/KmUpQABmLunPmE-NQ0huxw) - [ ] [[送书]TRAE+Cursor:AI 全栈从 0 到 1](https://mp.weixin.qq.com/s/DB9vcpb1n2W6ZlS1Agd_VA) - [ ] [RedTeam-Agent:让 AI 直接化身黑客的自动化红队框架来了](https://mp.weixin.qq.com/s/_1mJ2iFi7OE1S6UiDnn6Hw) - [ ] [C3朋友圈丨领袖同频,共话2026年C3新程](https://mp.weixin.qq.com/s/47Zxi4-EY0rBaj4zUYprBw) - [ ] [2026年3月企业必须安全漏洞清单](https://mp.weixin.qq.com/s/CsjqffVcf0J1SCmQnJT5yQ) - [ ] [360亮相2026世界互联网大会亚太峰会 智能体成果引行业关注](https://mp.weixin.qq.com/s/BBaSv9lTx7Ui6qILCMjQrA) - [ ] [月薪35-50k*16薪!真心建议物联网人冲一冲行业垂直相关新兴岗位,工资高前景好,人才缺口极大!](https://mp.weixin.qq.com/s/R0xq9Kt_6G0sR5__i-ACnw) - [ ] [美国网络安全和基础设施安全局 (CISA) 警告:Fortinet SQL 注入漏洞正被积极利用](https://mp.weixin.qq.com/s/2tQ27h8o403qrzyeaDBRHQ) - [ ] [W3LL钓鱼工具包被查封,全球凭证窃取和多因素身份验证绕过行动受挫](https://mp.weixin.qq.com/s/vRDYzlEBd_zFTKSZgA5-QA) - [ ] [农行打造“农银智+”平台,以三类AI应用形态赋能发展](https://mp.weixin.qq.com/s/pnoVPdLsc_JWaHq6ARNqrg) - [ ] [AI快讯:火山引擎Seedance 2.0全面开放API服务,微软确认开发“龙虾”产品](https://mp.weixin.qq.com/s/g7-6t7HBlFzb66_M-dYMhg) - [ ] [博英科技67.9万中!金谷国际信托2026年智能双录系统升级项目](https://mp.weixin.qq.com/s/MVznJa0p5frlwRs2RGz1OQ) - [ ] [斯坦福2026年AI指数报告解读:中美差距几乎消失(附全文下载链接)](https://mp.weixin.qq.com/s/dcQhMED6NHCiwLWmMohQ_g) - [ ] [【安全圈】金山毒霸、360 安全卫士被曝存在内核驱动高危漏洞](https://mp.weixin.qq.com/s/y0N3ebgcZeQZmMnoCBDLLg) - [ ] [【安全圈】开源监控平台 Grafana 曝漏洞,黑客可诱导 AI 助手泄露企业数据](https://mp.weixin.qq.com/s/FtQ_p2gxVHxHQ4Ibwfot-w) - [ ] [【安全圈】旅游平台 Booking.com 遭黑客入侵,旅客姓名电话号码等信息外泄](https://mp.weixin.qq.com/s/KSL0X-EO0kODB25M7Rk3tA) - [ ] [Spring/Tomcat畸形表单分析](https://mp.weixin.qq.com/s/omlK0ugRLk6tHJEPWHxXGA) - [ ] [NCTF 2026-鸡爪流高手(游戏服务器程序逆向 下溢出漏洞)](https://mp.weixin.qq.com/s/ljO0hWB4u-NMj25gcDihQA) - [ ] [迷雾中的航行:Fog 勒索软件关联攻击者工具链深度剖析](https://mp.weixin.qq.com/s/lblfGcqrSikqBwBxNxfz2Q) - [ ] [第三方 SDK 重大漏洞曝光:超 3000 万加密货币钱包面临数据泄露风险](https://mp.weixin.qq.com/s/4QAet8nXJrFpOiJ1jZmsZQ) - [ ] [从\"鲁迅为什么暴打周树人\"看AI\"真相\"](https://mp.weixin.qq.com/s/rpyW4Zr0h1oU3nyNabsQhA) - [ ] [网络安全最火的五个就业方向,来看看哪个是你的菜?](https://mp.weixin.qq.com/s/83ktEOZHaIFCvs8Epxo9bQ) - [ ] [终端是AI安全唯一的\"战场\"](https://mp.weixin.qq.com/s/ZhlMyEVTjdLM3sPiQqIHcA) - [ ] [JWT认证漏洞实战解析](https://mp.weixin.qq.com/s/AZZMN6ojyX0-hOEBGxyiCg) - [ ] [你这就有点吓人了](https://mp.weixin.qq.com/s/jO5lrAEAtKvK0KquMkK2vw) - [ ] [加权费马点挑战题](https://mp.weixin.qq.com/s/oeybFzNoNl19CDXpJB12vg) - [ ] [Apache Tomcat 紧急修复多个漏洞](https://mp.weixin.qq.com/s/4hkGV7Iqj6ZD-hHXDfVZcg) - [ ] [Axios 严重漏洞可导致 RCE](https://mp.weixin.qq.com/s/zkBXYkmDlHMNQtxkdCOwZQ) - [ ] [腾讯云发布 Token 防刷解决方案,精准狙击大模型黑产](https://mp.weixin.qq.com/s/LNkpcGz_W-Isg6xb73akpw) - [ ] [广州,集合!腾讯邀请你来玩龙虾](https://mp.weixin.qq.com/s/Lc2ImnObWK_Y66ibqSo3-A) - [ ] [等保标准再扩新篇,数据安全系列公安行标解析(四)](https://mp.weixin.qq.com/s/gUI14xVzDOFYgTsQVP2ARg) - [ ] [这显卡估计可以买台车了,各位师傅认同不?](https://mp.weixin.qq.com/s/H8SYWRMCR3in4msnNi0rSQ) - CXSECURITY Database RSS Feed - CXSecurity.com - [ ] [WordPress Madara Local File Inclusion](https://cxsecurity.com/issue/WLB-2026040012) - [ ] [FortiWeb 8.0.2 Remote Code Execution](https://cxsecurity.com/issue/WLB-2026040011) - [ ] [Easy File Sharing Web Server v7.2 Buffer Overflow](https://cxsecurity.com/issue/WLB-2026040010) - [ ] [NetBT e-Fatura Privilege Escalation](https://cxsecurity.com/issue/WLB-2026040009) - Recent Commits to cve:main - [ ] [Update Tue Apr 14 11:18:05 UTC 2026](https://github.com/trickest/cve/commit/6881aed9b2336f53de747f8abd4c0028c4ada32a) - Bug Bounty in InfoSec Write-ups on Medium - [ ] [I Tricked an AI Into Deleting a User Account (No Direct Access Needed)](https://infosecwriteups.com/i-tricked-an-ai-into-deleting-a-user-account-no-direct-access-needed-3d64528a648b?source=rss----7b722bfd1b8d--bug_bounty) - [ ] [GraphQL RCE: The Kill Chain to Cloud Identity…!](https://infosecwriteups.com/graphql-rce-the-kill-chain-to-cloud-identity-324699602931?source=rss----7b722bfd1b8d--bug_bounty) - [ ] [How Dark Web Intelligence Helped Me Prioritize High-Value Targets](https://infosecwriteups.com/how-dark-web-intelligence-helped-me-prioritize-high-value-targets-57401b8f3d96?source=rss----7b722bfd1b8d--bug_bounty) - [ ] [Master Advanced Netcat Usage for Hackers: Techniques Beyond Reverse Shells](https://infosecwriteups.com/master-advanced-netcat-usage-for-hackers-techniques-beyond-reverse-shells-89f5e29776cb?source=rss----7b722bfd1b8d--bug_bounty) - [ ] [Exploiting LLM APIs for OS Command Injection (PortSwigger Lab Write-up)](https://infosecwriteups.com/exploiting-llm-apis-for-os-command-injection-portswigger-lab-write-up-cb8738d8aa44?source=rss----7b722bfd1b8d--bug_bounty) - Malware-Traffic-Analysis.net - Blog Entries - [ ] [2026-04-13: XLoader (Formbook) infection](https://www.malware-traffic-analysis.net/2026/04/13/index.html) - Reverse Engineering - [ ] [Claude Code / Codex Skill for Ghidra](https://www.reddit.com/r/ReverseEngineering/comments/1sljub4/claude_code_codex_skill_for_ghidra/) - VMRay - [ ] [The Top 12 Free Threat Intelligence Feeds to Follow in 2026](https://www.vmray.com/best-threat-intelligence-feeds/) - SentinelOne - [ ] [Securing the Software Supply Chain: How SentinelOne’s AI EDR Autonomously Blocked the CPU-Z Watering Hole Cyber Attack](https://www.sentinelone.com/blog/securing-the-software-supply-chain-how-sentinelones-ai-edr-autonomously-blocked-the-cpu-z-watering-hole-cyber-attack/) - Malwarebytes - [ ] [Omnistealer uses the blockchain to steal everything it can](https://www.malwarebytes.com/blog/news/2026/04/omnistealer-uses-the-blockchain-to-steal-everything-it-can) - [ ] [ChatGPT under scrutiny as Florida investigates campus shooting](https://www.malwarebytes.com/blog/ai/2026/04/chatgpt-under-scrutiny-as-florida-investigates-campus-shooting) - rtl-sdr.com - [ ] [BrowSDR: Turn Your HackRF or RTL-SDR Into a Browser-Based Remote WebSDR](https://www.rtl-sdr.com/browsdr-turn-your-hackrf-or-rtl-sdr-into-a-browser-based-remote-websdr/) - 奇客Solidot–传递最新科技情报 - [ ] [Google 将惩罚“后退按钮劫持”行为](https://www.solidot.org/story?sid=84046) - [ ] [德国主权科技基金向 Mastodon 资助 61.4 万欧元](https://www.solidot.org/story?sid=84045) - [ ] [OpenSSL 4.0 释出](https://www.solidot.org/story?sid=84044) - [ ] [Servo 发布首个 crates.io 版本](https://www.solidot.org/story?sid=84043) - [ ] [斯坦福的 AI 报告认为中美差距微乎其微](https://www.solidot.org/story?sid=84042) - [ ] [人类止痛药对龙虾有效](https://www.solidot.org/story?sid=84041) - [ ] [含氟自来水对 IQ 和大脑功能没有影响](https://www.solidot.org/story?sid=84040) - [ ] [31 个 WordPress 插件被收购后植入了后门](https://www.solidot.org/story?sid=84039) - [ ] [FBI 搜查朝 Sam Altman 住宅扔燃烧瓶的男子家](https://www.solidot.org/story?sid=84038) - [ ] [黑客入侵 a16z 投资的手机农场,试图让手机农场账号发帖称 a16z 是反基督](https://www.solidot.org/story?sid=84037) - 黑海洋Wiki | AI机器人硬件开发 | 网络安全攻防实战 | 区块链技术文档教程 - 免费资源平台 - [ ] [美财政部官员力推接入Anthropic新模型](https://blog.upx8.com/%E7%BE%8E%E8%B4%A2%E6%94%BF%E9%83%A8%E5%AE%98%E5%91%98%E5%8A%9B%E6%8E%A8%E6%8E%A5%E5%85%A5Anthropic%E6%96%B0%E6%A8%A1%E5%9E%8B) - 黑鸟 - [ ] [据报CIA在伊朗营救行动使用以色列间谍软件](https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451186383&idx=1&sn=44727b731158bc509ff447ee5cb83637) - 威努特安全网络 - [ ] [Mac版来了!安全龙虾WinClaw已支持双平台!](https://mp.weixin.qq.com/s?__biz=MzAwNTgyODU3NQ==&mid=2651141332&idx=1&sn=c84c3ee2fbae7a9197299a954fd56559) - 虎符智库 - [ ] [从RSAC 2026创新沙盒,看AI时代网络安全创新创业的国际风向与中国路径](https://mp.weixin.qq.com/s?__biz=MzIwNjYwMTMyNQ==&mid=2247493775&idx=1&sn=b3a20134a90cd51c246503893c9ccea5) - 安全内参 - [ ] [关基部门预算暴涨!美国联邦政府2027财年网络安全拟投入超830亿元](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247515814&idx=1&sn=aa20a193e8004cb24453bbe36b95643c) - [ ] [美英报告称Mythos模型无限压缩漏洞披露到武器化时间窗口](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247515814&idx=2&sn=c4add54fd603fad96df85c248460e2f1) - 代码卫士 - [ ] [Apache Tomcat 紧急修复多个漏洞](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247525768&idx=1&sn=1c34f092d86b657532a27c79a93f83a3) - [ ] [Axios 严重漏洞可导致 RCE](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247525768&idx=2&sn=b8967ced3022f4f88a311a652e635650) - Shostack & Friends Blog - [ ] [Adam reflects on BSides SF and RSAC](https://shostack.org/blog/adam-reflections-on-rsac26/) - 看雪学苑 - [ ] [ivanti CVE-2025-0282 漏洞复现](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458613407&idx=1&sn=30bf32e1f57fead35b98087dc646ed4d) - [ ] [Rockstar Games确认遭供应链攻击,第三方SaaS成数据泄漏跳板](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458613407&idx=2&sn=a698c9b0dcc0d6aef4d0971e0c2cac2a) - [ ] [天才程序员上线:AI 逆向与安全开发全栈实战](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458613407&idx=3&sn=c5fc96050347797a9e72f11a01e8039e) - 青衣十三楼飞花堂 - [ ] [加权费马点挑战题](https://mp.weixin.qq.com/s?__biz=MzUzMjQyMDE3Ng==&mid=2247489293&idx=1&sn=b0de9e182b7298d09d60383c2a1a5495) - 安全学术圈 - [ ] [北京大学 | KnowHow:面向可解释且准确溯源分析的高层CTI知识自动应用方法](https://mp.weixin.qq.com/s?__biz=MzU5MTM5MTQ2MA==&mid=2247495249&idx=1&sn=d2c557e4914d44e74fb24b743a4f4198) - 安全圈 - [ ] [【安全圈】金山毒霸、360 安全卫士被曝存在内核驱动高危漏洞](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652075647&idx=1&sn=fa2ee897d05ae80591734bbcffa07abd) - [ ] [【安全圈】开源监控平台 Grafana 曝漏洞,黑客可诱导 AI 助手泄露企业数据](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652075647&idx=2&sn=8b9601124f9fd4627498d6920d66e5c9) - [ ] [【安全圈】旅游平台 Booking.com 遭黑客入侵,旅客姓名电话号码等信息外泄](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652075647&idx=3&sn=9b8138c91b5833096a9a449b6af37b4c) - 漕河泾小黑屋 - [ ] [免费代理的代价:当攻击者成为猎物](https://mp.weixin.qq.com/s?__biz=MzA4NzQwNzY3OQ==&mid=2247484058&idx=1&sn=b2495529052869ae7bf3ce778f831c40) - 微步在线研究响应中心 - [ ] [Axios爆SSRF漏洞,特定条件下可导致RCE](https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&mid=2247508614&idx=1&sn=b0d4f042ae9147e26d0eb657c7bcb744) - 数世咨询 - [ ] [内部威胁卷土重来](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247542559&idx=1&sn=82575ce88d732764ef0b845ac578d8cf) - [ ] [直播预约|第二届智能渗透挑战赛,龙虾黑客巅峰对决](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247542559&idx=2&sn=b8551dd77b416ad87db50d16642fc1b5) - 微步在线 - [ ] [Mythos风暴将至,250位CISO闭门交出可落地方案](https://mp.weixin.qq.com/s?__biz=MzI5NjA0NjI5MQ==&mid=2650186194&idx=1&sn=7a127bbd55513da6c35afce111035594) - 软件安全与逆向分析 - [ ] [ARM64动态指令追踪工具使用与实现分析](https://mp.weixin.qq.com/s?__biz=MzU3MTY5MzQxMA==&mid=2247485117&idx=1&sn=5c5a103b1863aad7dac6b6e40c9bb470) - 极客公园 - [ ] [进入超 300 户家庭,为什么这个 3 万+的机器人值得买?](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653103909&idx=1&sn=772be808341938150680c6faa88a427e) - [ ] [Anthropic最强模型被质疑夸大找漏洞能力;奥尔特曼住所一周内两次遇袭;需求火爆,苹果提升初代Macbook Neo产量至1000 万台|极客早知道](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653103896&idx=1&sn=b5cd7865838919d54b32379edcb138a1) - 信息安全国家工程研究中心 - [ ] [4·15全民国家安全教育日主题海报](https://mp.weixin.qq.com/s?__biz=MzU5OTQ0NzY3Ng==&mid=2247503545&idx=1&sn=7d0fd1fe3fc953eb9ddcff28da6536cc) - 安全牛 - [ ] [Claude Mythos Preview 因能力过强暂不公开发布,对传统安全厂商形成降维打击,行业格局剧变](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651141029&idx=1&sn=b6dea14cd33573b48cf4800b109c7ea6) - [ ] [中央网信办发布直播打赏规范通知 明确平台主体责任与监管要求;Meta 打造扎克伯格AI 数字分身,员工可全天候与虚拟 CEO 交互| 牛览](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651141029&idx=2&sn=ce92737ec62fef97dc68aa3180bef612) - Tide安全团队 - [ ] [基于AI的自动化测试工具的探索](https://mp.weixin.qq.com/s?__biz=Mzg2NTA4OTI5NA==&mid=2247521979&idx=1&sn=d5eef7917f68e56b9f9f6eb9da12e73e) - 恒脑与AI - [ ] [“AI黑客”单兵作战:1人2模型,利用Claude 和ChatGPT,攻陷墨西哥9个核心政府机构](https://mp.weixin.qq.com/s?__biz=MzI1MDU5NjYwNg==&mid=2247497435&idx=1&sn=66ef26af6510096c5d698e9523d52647) - ChaMd5安全团队 - [ ] [Agent Security 沙箱可持久化深度报告](https://mp.weixin.qq.com/s?__biz=MzIzMTc1MjExOQ==&mid=2247514257&idx=1&sn=a5d45921107ff3b185a7a94717993f0b) - 枇杷熟了 - [ ] [没错,我的枇杷比她甜!](https://mp.weixin.qq.com/s?__biz=MzU0MzkzOTYzOQ==&mid=2247490018&idx=1&sn=39fe7e9694b1e1874713488486739ad4) - 天御攻防实验室 - [ ] [一名美国国家安全局分析师对其约会女友进行监视](https://mp.weixin.qq.com/s?__biz=MzU0MzgyMzM2Nw==&mid=2247486910&idx=1&sn=d32ba3428df3ef2ae59e5e00994c7e82) - 深信服千里目安全技术中心 - [ ] [【漏洞通告】Marimo WebSocket 认证绕过漏洞(CVE-2026-39987)](https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&mid=2247525306&idx=1&sn=73f3462b7398a6cb2d7de0318e6aa81c) - Desync InfoSec - [ ] [迷雾中的航行:Fog 勒索软件关联攻击者工具链深度剖析](https://mp.weixin.qq.com/s?__biz=MzkzMDE3ODc1Mw==&mid=2247490000&idx=1&sn=3702f7221734a63e365a11700a883774) - [ ] [第三方 SDK 重大漏洞曝光:超 3000 万加密货币钱包面临数据泄露风险](https://mp.weixin.qq.com/s?__biz=MzkzMDE3ODc1Mw==&mid=2247490000&idx=2&sn=3ba228aaa0d3a1b9e2f1e6e41eebae23) - 360数字安全 - [ ] [360亮相2026世界互联网大会亚太峰会 智能体成果引行业关注](https://mp.weixin.qq.com/s?__biz=MzA4MTg0MDQ4Nw==&mid=2247585693&idx=1&sn=55047066b073b716f9b19dca0a73bccf) - 安全419 - [ ] [安全419|一周国际网安资讯:供应链波及OpenAI APT盯上关键设施](https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&mid=2247552937&idx=1&sn=56c9d8c1151e34a584d445fb1657487c) - 青藤云安全 - [ ] [终端是AI安全唯一的"战场"](https://mp.weixin.qq.com/s?__biz=MzAwNDE4Mzc1NA==&mid=2650851123&idx=1&sn=46e0b1069ed327c0fc98a40a7af5e921) - Over Security - Cybersecurity news aggregator - [ ] [Microsoft adds Windows protections for malicious Remote Desktop files](https://www.bleepingcomputer.com/news/microsoft/microsoft-adds-windows-protections-for-malicious-remote-desktop-files/) - [ ] [Crypto-exchange Kraken extorted by hackers after insider breach](https://www.bleepingcomputer.com/news/security/crypto-exchange-kraken-extorted-by-hackers-after-insider-breach/) - [ ] [Patch Tuesday, April 2026 Edition](https://krebsonsecurity.com/2026/04/patch-tuesday-april-2026-edition/) - [ ] [Over 100 Chrome extensions in Web Store target users accounts and data](https://www.bleepingcomputer.com/news/security/over-100-chrome-extensions-in-web-store-target-users-accounts-and-data/) - [ ] [Microsoft Patch Tuesday for April 2026 - Snort Rule and Prominent Vulnerabilities](https://blog.talosintelligence.com/microsoft-patch-tuesday-april-2026/) - [ ] [New ‘JanaWare’ ransomware targeting Turkish citizens as cybercriminal ecosystem fragments](https://therecord.media/new-janaware-ransomware-targeting-turkey) - [ ] [Chasing Phantoms: How a Multi-Stage Stealer Abuses Signed Binaries to…](https://binarydefense.com/resources/blog/chasing-phantoms-how-a-multi-stage-stealer-abuses-signed-binaries-to-disappear) - [ ] [McGraw-Hill confirms data breach following extortion threat](https://www.bleepingcomputer.com/news/security/mcgraw-hill-confirms-data-breach-following-extortion-threat/) - [ ] [Microsoft releases Windows 10 KB5082200 extended security update](https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-windows-10-kb5082200-extended-security-update/) - [ ] [Windows 11 cumulative updates KB5083769 & KB5082052 released](https://www.bleepingcomputer.com/news/microsoft/windows-11-cumulative-updates-kb5083769-and-kb5082052-released/) - [ ] [Microsoft April 2026 Patch Tuesday fixes 167 flaws, 2 zero-days](https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2026-patch-tuesday-fixes-167-flaws-2-zero-days/) - [ ] [Virginia enacts ban on precise geolocation data sales as momentum for similar prohibitions builds](https://therecord.media/virginia-enacts-ban-on-precise-geolocation-data) - [ ] [Fake Ledger Live app on Apple’s App Store stole $9.5M in crypto](https://www.bleepingcomputer.com/news/security/fake-ledger-live-app-on-apples-app-store-stole-95m-in-crypto/) - [ ] [Fornitori rilevanti NIS: ecco le FAQ per una loro corretta individuazione](https://www.cybersecurity360.it/legal/fornitori-rilevanti-nis-ecco-le-faq-per-una-loro-corretta-individuazione/) - [ ] [Microsoft rolls out fast-track to reinstate Windows hardware dev accounts](https://www.bleepingcomputer.com/news/microsoft/microsoft-rolls-out-fast-track-to-reinstate-windows-hardware-dev-accounts/) - [ ] [Controlli di sicurezza granulari: proteggere e-mail e backup senza bloccare il business è un’arte](https://www.cybersecurity360.it/soluzioni-aziendali/controlli-di-sicurezza-granulari-proteggere-e-mail-e-backup-senza-bloccare-il-business-e-unarte/) - [ ] [Donne e cybersecurity: crescono le nuove leve e alcune sfide](https://www.securityinfo.it/2026/04/14/donne-e-cybersecurity-crescono-le-nuove-leve-e-alcune-sfide/) - [ ] [5 Ways Zero Trust Maximizes Identity Security](https://www.bleepingcomputer.com/news/security/5-ways-zero-trust-maximizes-identity-security/) - [ ] [Russia appears to block social media platform Bluesky amid wider internet restrictions](https://therecord.media/russia-cracks-down-bluesky-internet) - [ ] [State-sponsored threats: Different objectives, similar access paths](https://blog.talosintelligence.com/state-sponsored-threats-different-objectives-similar-access-paths/) - [ ] [Ristrutturazione aziendale e dati dei lavoratori: la lezione dalla sanzione a ITA e Alitalia](https://www.cybersecurity360.it/news/ristrutturazione-aziendale-e-dati-dei-lavoratori-la-lezione-dalla-sanzione-a-ita-e-alitalia/) - [ ] [16-31 March 2025 Cyber Attacks Timeline](https://www.hackmageddon.com/2026/04/14/16-31-march-2025-cyber-attacks-timeline/) - [ ] [Utenti Booking attaccati, che succede e come difendersi](https://www.cybersecurity360.it/news/utenti-booking-attaccati-che-succede-e-come-difendersi/) - [ ] [When Trust Becomes a Weapon: Google Cloud Storage Phishing Deploying Remcos RAT](https://any.run/cybersecurity-blog/phishing-google-drive-remcos/) - [ ] [Goldman Sachs ‘Hyperaware’ of AI Risks; Working with Anthropic on Mythos](https://thecyberexpress.com/goldman-sachs-ai-risks-anthropic-and-mythos/) - [ ] [Progetti che falliscono, processi che stagnano: gli errori da evitare nella cyber security](https://www.cybersecurity360.it/cultura-cyber/progetti-che-falliscono-processi-che-stagnano-best-practice-ed-errori-da-evitare-nella-cyber-security/) - [ ] [Common Entra ID Security Assessment Findings – Part 4: Weak Conditional Access Policies](https://blog.compass-security.com/2026/04/common-entra-id-security-assessment-findings-part-4-weak-conditional-access-policies/) - [ ] [NIS2, le categorizzazioni ancora assenti frenano documentazione e risk analysis](https://www.cybersecurity360.it/news/nis2-le-categorizzazioni-ancora-assenti-frenano-documentazione-e-risk-analysis/) - [ ] [Hackers Exploit Kali Forms Vulnerability to Take Over WordPress Sites](https://thecyberexpress.com/kali-forms-vulnerability-wordpress-plugin/) - [ ] [Australia Social Media Ban Faces Questions as Over 60% of Kids Remain Online](https://thecyberexpress.com/australia-social-media-ban-faces-question/) - [ ] [Identity Management Day 2026: scomparso il perimetro di rete, focus sulle identità non umane](https://www.cybersecurity360.it/news/identity-management-day-2026-scomparso-il-perimetro-di-rete-focus-sulle-identita-non-umane/) - [ ] [Dark Web Article Contest Offers $10,000 for Exploit Writing on TierOne Forum](https://thecyberexpress.com/dark-web-article-contest/) - [ ] [Massive Cyberattack Hits Europe’s Largest Fitness Chain, Member Data Exposed](https://thecyberexpress.com/basic-fit-data-breach-exposes-member-data/) - [ ] [The AlphaGo moment for vulnerability research?](https://vincenzoiozzo.com/blog/alphago-moment-vuln-research) - TrustedSec - [ ] [Benchmarking Self-Hosted LLMs for Offensive Security](https://trustedsec.com/blog/benchmarking-self-hosted-llms-for-offensive-security) - ICT Security Magazine - [ ] [Gestione del rischio cyber 2026: rilevare l’invisibile per mitigare la superficie di attacco](https://www.ictsecuritymagazine.com/notizie/gestione-del-rischio-cyber-2026-osservatorio-cyberoo/) - [ ] [Shadow AI, compliance e responsabilità: verso un modello minimo di governance](https://www.ictsecuritymagazine.com/articoli/shadow-ai/) - Qualys Security Blog - [ ] [Microsoft and Adobe Patch Tuesday, April 2026 Security Update Review](https://blog.qualys.com/category/vulnerabilities-threat-research) - 迪哥讲事 - [ ] [【SRC实战】利用js多赚1000](https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&mid=2247499311&idx=1&sn=71af729ab1f0cc8a9a77d1eb86399a9a) - 云鼎实验室 - [ ] [2026年3月企业必修安全漏洞清单](https://mp.weixin.qq.com/s?__biz=MzU3ODAyMjg4OQ==&mid=2247497462&idx=1&sn=5b9db9b15e768352ad174eb07d2948ac) - Schneier on Security - [ ] [Upcoming Speaking Engagements](https://www.schneier.com/blog/archives/2026/04/upcoming-speaking-engagements-55.html) - [ ] [How Hackers Are Thinking About AI](https://www.schneier.com/blog/archives/2026/04/how-hackers-are-thinking-about-ai.html) - Troy Hunt's Blog - [ ] [Weekly Update 499](https://www.troyhunt.com/weekly-update-499/) - SANS Internet Storm Center, InfoCON: green - [ ] [Microsoft Patch Tuesday April 2026., (Tue, Apr 14th)](https://isc.sans.edu/diary/rss/32898) - [ ] [ISC Stormcast For Tuesday, April 14th, 2026 https://isc.sans.edu/podcastdetail/9890, (Tue, Apr 14th)](https://isc.sans.edu/diary/rss/32894) - HACKMAGEDDON - [ ] [16-31 March 2025 Cyber Attacks Timeline](https://www.hackmageddon.com/2026/04/14/16-31-march-2025-cyber-attacks-timeline/) - Instapaper: Unread - [ ] [Why DFIR teams need to look beyond the MBR when analyzing modern wipers](https://andreafortuna.org/2026/04/13/wiper-disk-evolution/) - [ ] [Deleted File Recovery in Ext4](https://digitalinvestigator.blogspot.com/2026/04/deleted-file-recovery-in-ext4.html) - [ ] [DFIR Backlogs, Burnout And Cognitive Fatigue The Silent Operational Risk](https://www.forensicfocus.com/articles/dfir-backlogs-burnout-and-cognitive-fatigue-the-silent-operational-risk/) - [ ] [NTFS Forensics Reconstruction of File System History](https://digitalinvestigator.blogspot.com/2026/04/ntfs-forensics-reconstruction-of-file.html) - [ ] [Italia e spyware, il lato oscuro dell'industria italiana della cybersicurezza](https://www.wired.it/article/italia-spyware-primato-mercato-software-governativi-app/) - Lenny Zeltser - [ ] [How Modern Design Principles Strengthen Security](https://zeltser.com/modern-design-security) - The Hacker News - [ ] [New PHP Composer Flaws Enable Arbitrary Command Execution — Patches Released](https://thehackernews.com/2026/04/new-php-composer-flaws-enable-arbitrary.html) - [ ] [Google Adds Rust-Based DNS Parser into Pixel 10 Modem to Enhance Security](https://thehackernews.com/2026/04/google-adds-rust-based-dns-parser-into.html) - [ ] [AI-Driven Pushpaganda Scam Exploits Google Discover to Spread Scareware and Ad Fraud](https://thehackernews.com/2026/04/ai-driven-pushpaganda-scam-exploits.html) - [ ] [Mirax Android RAT Turns Devices into SOCKS5 Proxies, Reaching 220,000 via Meta Ads](https://thehackernews.com/2026/04/mirax-android-rat-turns-devices-into.html) - [ ] [Analysis of 216M Security Findings Shows a 4x Increase In Critical Risk (2026 Report)](https://thehackernews.com/2026/04/analysis-of-216m-security-findings.html) - [ ] [108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20,000 Users](https://thehackernews.com/2026/04/108-malicious-chrome-extensions-steal.html) - [ ] [ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers](https://thehackernews.com/2026/04/showdoc-rce-flaw-cve-2025-0520-actively.html) - [ ] [CISA Adds 6 Known Exploited Flaws in Fortinet, Microsoft, and Adobe Software](https://thehackernews.com/2026/04/cisa-adds-6-known-exploited-flaws-in.html) - Krebs on Security - [ ] [Patch Tuesday, April 2026 Edition](https://krebsonsecurity.com/2026/04/patch-tuesday-april-2026-edition/) - Full Disclosure - [ ] [CyberDanube Security Research 20260408-1 | Multiple Vulnerabilities in Siemens SICAM A8000](https://seclists.org/fulldisclosure/2026/Apr/7) - [ ] [CyberDanube Security Research 20260408-0 | Remote Operation Denial of Service in Siemens SICAM A8000](https://seclists.org/fulldisclosure/2026/Apr/6) - [ ] [SEC Consult SA-20260414-0 :: Improper Enforcement of Locked Accounts in WebUI (SSO) in Kiuwan SAST on-premise (KOP) & cloud/SaaS](https://seclists.org/fulldisclosure/2026/Apr/5) - Securityinfo.it - [ ] [Donne e cybersecurity: crescono le nuove leve e alcune sfide](https://www.securityinfo.it/2026/04/14/donne-e-cybersecurity-crescono-le-nuove-leve-e-alcune-sfide/?utm_source=rss&utm_medium=rss&utm_campaign=donne-e-cybersecurity-crescono-le-nuove-leve-e-alcune-sfide) - Information Security - [ ] [Data aggregators and brokers are kind of terrifying](https://www.reddit.com/r/Information_Security/comments/1slk9z7/data_aggregators_and_brokers_are_kind_of/) - [ ] [Forget ransomware. These guys just steal your data and go straight for your reputation](https://www.reddit.com/r/Information_Security/comments/1slh3ki/forget_ransomware_these_guys_just_steal_your_data/) - [ ] [Booking.com data breach: What to do?](https://www.reddit.com/r/Information_Security/comments/1sl9e4p/bookingcom_data_breach_what_to_do/) - [ ] [Problema su Safari: “connessione non sicura”](https://www.reddit.com/r/Information_Security/comments/1sl7yqg/problema_su_safari_connessione_non_sicura/) - [ ] [외부 협업 환경에서 데이터 보호 전략에 대한 고민](https://www.reddit.com/r/Information_Security/comments/1sl16za/외부_협업_환경에서_데이터_보호_전략에_대한_고민/) - Social Engineering - [ ] [Person Identification with Text Description](https://www.reddit.com/r/SocialEngineering/comments/1sl5m94/person_identification_with_text_description/) - [ ] [If I called you right now, said your name, your bank, your last transaction — and asked for an OTP in 30 seconds, would you actually stop yourself?](https://www.reddit.com/r/SocialEngineering/comments/1sl53kd/if_i_called_you_right_now_said_your_name_your/) - netsecstudents: Subreddit for students studying Network Security and its related subjects - [ ] [Is a virtual CISO actually effective, or is it just a watered-down version of having a real security leader? Genuine question from a CTO.](https://www.reddit.com/r/netsecstudents/comments/1sl4rfg/is_a_virtual_ciso_actually_effective_or_is_it/) - [ ] [Looking for teammates for CTF@CIT](https://www.reddit.com/r/netsecstudents/comments/1sl79r0/looking_for_teammates_for_ctfcit/) - [ ] [Built a Telegram scam honeypot bot for detection research — looking for feedback/testers](https://www.reddit.com/r/netsecstudents/comments/1sl3fs0/built_a_telegram_scam_honeypot_bot_for_detection/) - [ ] [Fulbright for UCF MS Cybersecurity with zero cyber XP — should I take it?](https://www.reddit.com/r/netsecstudents/comments/1skucpg/fulbright_for_ucf_ms_cybersecurity_with_zero/) - [ ] [[ Removed by Reddit ]](https://www.reddit.com/r/netsecstudents/comments/1sl0i8y/removed_by_reddit/) - The Register - Security - [ ] [Commvault has a Ctrl+Z for rogue AI agents](https://go.theregister.com/feed/www.theregister.com/2026/04/14/commvault_has_a_ctrlz_for/) - [ ] [Microsoft's massive Patch Tuesday: It's raining bugs](https://go.theregister.com/feed/www.theregister.com/2026/04/14/microsofts_massive_patch_tuesday/) - [ ] [No honor among thieves as 0APT threatens rival ransomware gang Krybit](https://go.theregister.com/feed/www.theregister.com/2026/04/14/0apt_krybit_spat/) - Deeplinks - [ ] [Google Broke Its Promise to Me. Now ICE Has My Data.](https://www.eff.org/deeplinks/2026/04/google-broke-its-promise-me-now-ice-has-my-data) - [ ] [EFF to State AGs: Investigate Google's Broken Promise to Users Targeted by the Government](https://www.eff.org/press/releases/eff-state-ags-investigate-googles-broken-promise-users-targeted-government) - DEFION Research Labs - [ ] [Ruckus Unleashed: Multiple vulnerabilities exploited](/en/research-labs/ruckus-unleashed-multiple-vulnerabilities-exploited) - [ ] [Pwn2Own Automotive 2024: Hacking the Autel MaxiCharger](/en/research-labs/pwn2own-automotive-2024-hacking-the-autel-maxicharger) - [ ] [Pwn2Own Automotive 2024: Hacking the JuiceBox 40](/en/research-labs/pwn2own-automotive-2024-hacking-the-juicebox-40) - [ ] [Pwn2Own Automotive 2024: Hacking the ChargePoint Home Flex (and their cloud...)](/en/research-labs/pwn2own-automotive-2024-hacking-the-chargepoint-home-flex-and-their-cloud) - [ ] [DoNex/DarkRace Ransomware Decryptor](/en/research-labs/donex-darkrace-ransomware-decryptor) - [ ] [CVE-2024-20693: Windows cached code signature manipulation](/en/research-labs/cve-2024-20693-windows-cached-code-signature-manipulation) - [ ] [Bringing process injection into view(s): exploiting all macOS apps using nib files](/en/research-labs/bringing-process-injection-into-view-s-exploiting-all-macos-apps-using-nib-files) - [ ] [Don’t Talk All at Once! Elevating Privileges on macOS by Audit Token Spoofing](/en/research-labs/don-t-talk-all-at-once-elevating-privileges-on-macos-by-audit-token-spoofing) - [ ] [Getting SYSTEM on Windows in style](/en/research-labs/getting-system-on-windows-in-style) - [ ] [Technical analysis of the Genesis Market](/en/research-labs/technical-analysis-of-the-genesis-market) - [ ] [Bad things come in large packages: .pkg signature verification bypass on macOS](/en/research-labs/bad-things-come-in-large-packages-pkg-signature-verification-bypass-on-macos) - [ ] [Pwn2Own Miami 2022: ICONICS GENESIS64 Arbitrary Code Execution](/en/research-labs/pwn2own-miami-2022-iconics-genesis64-arbitrary-code-execution) - [ ] [Pwn2Own Miami 2022: Unified Automation C++ Demo Server DoS](/en/research-labs/pwn2own-miami-2022-unified-automation-c-demo-server-dos) - [ ] [Pwn2Own Miami 2022: AVEVA Edge Arbitrary Code Execution](/en/research-labs/pwn2own-miami-2022-aveva-edge-arbitrary-code-execution) - [ ] [Process injection: breaking all macOS security layers with a single vulnerability](/en/research-labs/process-injection-breaking-all-macos-security-layers-with-a-single-vulnerability) - [ ] [Pwn2Own Miami 2022: Inductive Automation Ignition Remote Code Execution](/en/research-labs/pwn2own-miami-2022-inductive-automation-ignition-remote-code-execution) - [ ] [Pwn2Own Miami 2022: OPC UA .NET Standard Trusted Application Check Bypass](/en/research-labs/pwn2own-miami-2022-opc-ua-net-standard-trusted-application-check-bypass) - [ ] [CoronaCheck App TLS certificate vulnerabilities](/en/research-labs/coronacheck-app-tls-certificate-vulnerabilities) - [ ] [Sandbox escape + privilege escalation in StorePrivilegedTaskService](/en/research-labs/sandbox-escape-privilege-escalation-in-storeprivilegedtaskservice) - [ ] [Proctorio Chrome extension Universal Cross-Site Scripting](/en/research-labs/proctorio-chrome-extension-universal-cross-site-scripting) - [ ] [Zoom RCE from Pwn2Own 2021](/en/research-labs/zoom-rce-from-pwn2own-2021) - [ ] [iOS VPN support: 3 different bugs](/en/research-labs/ios-vpn-support-3-different-bugs) - [ ] [Sign in with Apple - authentication bypass](/en/research-labs/sign-in-with-apple-authentication-bypass) - [ ] [Jenkins - authentication bypass](/en/research-labs/jenkins-authentication-bypass) - [ ] [DNS rebinding for HTTPS](/en/research-labs/dns-rebinding-for-https) - [ ] [Spring Security - insufficient cryptographic randomness](/en/research-labs/spring-security-insufficient-cryptographic-randomness) - [ ] [XenServer - path traversal leading to authentication bypass](/en/research-labs/xenserver-path-traversal-leading-to-authentication-bypass) - [ ] [Volkswagen Auto Group MIB infotainment system - unauthenticated remote code execution as root](/en/research-labs/volkswagen-auto-group-mib-infotainment-system-unauthenticated-remote-code-execution-as-root) - [ ] [NAPALM - command execution on NAPLM controller from host](/en/research-labs/napalm-command-execution-on-naplm-controller-from-host) - [ ] [MySQL Connector/J - Unexpected deserialisation of Java objects](/en/research-labs/mysql-connector-j-unexpected-deserialisation-of-java-objects) - [ ] [Ansible - command execution on Ansible controller from host](/en/research-labs/ansible-command-execution-on-ansible-controller-from-host) - [ ] [Observium - unauthenticated remote code execution](/en/research-labs/observium-unauthenticated-remote-code-execution) - [ ] [cSRP/srpforjava - obtaining of hashed passwords](/en/research-labs/csrp-srpforjava-obtaining-of-hashed-passwords) - [ ] [StartEncrypt - obtaining valid SSL certificates for unauthorized domains](/en/research-labs/startencrypt-obtaining-valid-ssl-certificates-for-unauthorized-domains) - Computer Forensics - [ ] [Crow-eye v0.9.0 is out! Now with Direct Forensic Image Parsing, a rebuilt Timeline, and full Linux support.](https://www.reddit.com/r/computerforensics/comments/1slmjvo/croweye_v090_is_out_now_with_direct_forensic/) - Blackhat Library: Hacking techniques and research - [ ] [SROP-Assisted Cross-Memory Attach (CMA) Injection via Direct Syscalls.](https://www.reddit.com/r/blackhat/comments/1sky45h/sropassisted_crossmemory_attach_cma_injection_via/) - Technical Information Security Content & Discussion - [ ] [Common Entra ID Security Assessment Findings – Part 4: Weak Conditional Access Policies](https://www.reddit.com/r/netsec/comments/1sla6ju/common_entra_id_security_assessment_findings_part/) - [ ] [Using Nix or Docker for reproducible Development Environments](https://www.reddit.com/r/netsec/comments/1sllxth/using_nix_or_docker_for_reproducible_development/) - [ ] [Codex Hacked a Samsung TV](https://www.reddit.com/r/netsec/comments/1skwr2x/codex_hacked_a_samsung_tv/) - TorrentFreak - [ ] [EU Pirate Site-Blocking Is Broken: Report Calls for IP Blocking Ban and Rightsholder Liability](https://torrentfreak.com/eu-pirate-site-blocking-is-broken-report-calls-for-ip-blocking-ban-and-rightsholder-liability/) - Security Affairs - [ ] [Personal data of 1 million gym members compromised in Basic-Fit security incident](https://securityaffairs.com/190815/data-breach/personal-data-of-1-million-gym-members-compromised-in-basic-fit-security-incident.html) - [ ] [US, UK and Canada disrupt $45M crypto theft in Operation Atlantic](https://securityaffairs.com/190805/cyber-crime/us-uk-and-canada-disrupt-45m-crypto-theft-in-operation-atlantic.html) - [ ] [ShinyHunters claim the hack of Rockstar Games breach and started leaking data](https://securityaffairs.com/190796/data-breach/shinyhunters-claim-the-hack-of-rockstar-games-breach-and-started-leaking-data.html) - [ ] [Attackers target unpatched ShowDoc servers via CVE-2025-0520](https://securityaffairs.com/190790/hacking/attackers-target-unpatched-showdoc-servers-via-cve-2025-0520.html) - [ ] [U.S. CISA adds Adobe, Fortinet, Microsoft Exchange Server, and Microsoft Windows flaws to its Known Exploited Vulnerabilities catalog](https://securityaffairs.com/190775/security/u-s-cisa-adds-adobe-fortinet-microsoft-windows-microsoft-exchange-server-and-microsoft-windows-flaws-to-its-known-exploited-vulnerabilities-catalog.html) - [ ] [Fake Claude AI installer abuses DLL sideloading to deploy PlugX](https://securityaffairs.com/190754/malware/fake-claude-ai-installer-abuses-dll-sideloading-to-deploy-plugx.html) - Deep Web - [ ] [Need response for my thesis on dark web](https://www.reddit.com/r/deepweb/comments/1slg5z1/need_response_for_my_thesis_on_dark_web/) - [ ] [looking for the link list](https://www.reddit.com/r/deepweb/comments/1slc56g/looking_for_the_link_list/) - [ ] [Anyone know Unsensored Ai](https://www.reddit.com/r/deepweb/comments/1skykiq/anyone_know_unsensored_ai/) - Daniel Miessler - [ ] [Good and Bad Harness Engineering](https://danielmiessler.com/blog/good-and-bad-harness-engineering?utm_source=rss&utm_medium=feed&utm_campaign=website) - Security Weekly Podcast Network (Audio) - [ ] [Zuckbot, Rockstar, Klaude, Browsers Galore, Microsoft 365, ATC, Kieran Human and more - Kieran Human - SWN #572](http://sites.libsyn.com/18678/zuckbot-rockstar-klaude-browsers-galore-microsoft-365-atc-kieran-human-and-more-kieran-human-swn-572) - [ ] [Securing Software's Journey with the OWASP SPVS - Ido Geffen, Rohan Ravindranath, Cameron W., Farshad Abasi - ASW #378](http://sites.libsyn.com/18678/securing-softwares-journey-with-the-owasp-spvs-ido-geffen-rohan-ravindranath-cameron-w-farshad-abasi-asw-378)
每日安全资讯(2026-04-15)