# 每日安全资讯(2026-08-04) - SecWiki News - [ ] [SecWiki News 2026-08-03 Review](http://www.sec-wiki.com/?2026-08-03) - Private Feed for M09Ic - [ ] [Rvn0xsy starred abue-ammar/tinycast](https://github.com/abue-ammar/tinycast) - [ ] [kpcyrd released v0.11.1 at kpcyrd/sh4d0wup](https://github.com/kpcyrd/sh4d0wup/releases/tag/v0.11.1) - [ ] [kpcyrd contributed to kpcyrd/sh4d0wup](https://github.com/kpcyrd/sh4d0wup/pull/49) - [ ] [bolucat released 202608032145 at bolucat/Archive](https://github.com/bolucat/Archive/releases/tag/202608032145) - [ ] [kpcyrd starred sathyajithps/www_authenticate_parser](https://github.com/sathyajithps/www_authenticate_parser) - [ ] [esrrhs contributed to esrrhs/fakelua](https://github.com/esrrhs/fakelua/pull/317) - [ ] [kpcyrd contributed to kpcyrd/hussh](https://github.com/kpcyrd/hussh/pull/1) - [ ] [esrrhs starred FareedKhan-dev/kimi-k3-in-c](https://github.com/FareedKhan-dev/kimi-k3-in-c) - [ ] [timwhitez starred huangruiteng/loopx](https://github.com/huangruiteng/loopx) - [ ] [chainreactors released v0.4.0 at chainreactors/aiscan](https://github.com/chainreactors/aiscan/releases/tag/v0.4.0) - [ ] [ReaJason released v2.9.0 at ReaJason/MemShellParty](https://github.com/ReaJason/MemShellParty/releases/tag/v2.9.0) - [ ] [liamg contributed to infracost/go-proto](https://github.com/infracost/go-proto/pull/85) - Tenable Blog - [ ] [30 days with Claude Mythos Preview: How Tenable adapted our security program, and why yours is next](https://www.tenable.com/blog/testing-claude-mythos-preview-for-code-security-tenable) - Sploitus.com Exploits RSS Feed - [ ] [Exploit for Improper Input Validation in Google Chrome](https://sploitus.com/exploit?id=92BA7E1E-BF81-529F-B86D-18953CA4D99C&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Use of Uninitialized Variable in Google Chrome](https://sploitus.com/exploit?id=3A3A22D8-7006-5DFE-9D5F-B5EE4F4BA8A7&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Improper Privilege Management in Google Chrome](https://sploitus.com/exploit?id=5F50944C-454B-5B76-8FD8-EE5EC48E0862&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Use of Function with Inconsistent Implementations in Google Chrome](https://sploitus.com/exploit?id=BF1EE5C8-03F6-593B-9370-A24FF7DDAEA0&utm_source=rss&utm_medium=rss) - [ ] [ctf-writeups exploit](https://sploitus.com/exploit?id=255002A0-0C51-5FE0-8B19-8FC2ACB25722&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-18718](https://sploitus.com/exploit?id=7667BD13-077B-57DB-BD29-9F61463019BD&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-69083](https://sploitus.com/exploit?id=007FF93E-4149-567D-912B-B01843EA7F4B&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-56158](https://sploitus.com/exploit?id=C70098EC-8455-5303-80B5-BD82E10260AE&utm_source=rss&utm_medium=rss) - [ ] [Exploit for CVE-2026-68771](https://sploitus.com/exploit?id=C3523367-B0A4-51A6-9DDC-7E891A47D235&utm_source=rss&utm_medium=rss) - [ ] [wp2shell exploit](https://sploitus.com/exploit?id=6BC6006F-92E8-5E4D-983A-18D9EC1C7613&utm_source=rss&utm_medium=rss) - [ ] [wazuh-iis-defense exploit](https://sploitus.com/exploit?id=C628EA87-7D36-5A26-8015-20D1BE7FD96F&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Microsoft](https://sploitus.com/exploit?id=4997B647-9EB1-5AFF-AFCD-D7851339488E&utm_source=rss&utm_medium=rss) - 博客园 - bamb00 - [ ] [一个项目带你入门AI应用开发课程介绍 - bamb00](https://www.cnblogs.com/goodhacker/p/22168171) - [ ] [一个项目带你入门AI应用开发07 - bamb00](https://www.cnblogs.com/goodhacker/p/22167976) - [ ] [一个项目带你入门AI应用开发06 - bamb00](https://www.cnblogs.com/goodhacker/p/22167488) - Doonsec's feed - [ ] [机器人当超市店员?人形机器人零售服务岗比赛规则揭秘](https://mp.weixin.qq.com/s/7piscT20t5BuOWN9aSgKVg) - [ ] [人形机器人大厨上线!人形机器人餐饮制售岗比赛规则揭秘](https://mp.weixin.qq.com/s/qJtTBE2pOmbUiuWRR5sjEQ) - [ ] [人机搭档!吃透人形机器人装配上料岗规则解读](https://mp.weixin.qq.com/s/Dq8tatpWqaG8D4dLl_ikgw) - [ ] [电子取证大事记(2026年7月27日—8月2日)](https://mp.weixin.qq.com/s/oV_oOZVuiawvcnKgrnzmvA) - [ ] [100台保安机器人“正式上岗”,国投智能开启人机协同安保新纪元](https://mp.weixin.qq.com/s/XHMg8QVq4MAEMX2IJ79xrA) - [ ] [干货集结!2026 年8月培训课程汇总](https://mp.weixin.qq.com/s/YaSDFIhbzKfHr5KME4JNUw) - [ ] [7月30日 威胁情报速览](https://mp.weixin.qq.com/s/jnpdQyn8-0tI5npPTTw7jQ) - [ ] [G.O.S.S.I.P 阅读推荐 2026-08-03 当 Agent 开始替攻击者“删规则”](https://mp.weixin.qq.com/s/Ta3ULwxsRIHdWNBteuDKyQ) - [ ] [行业资讯:网络安全项目中标情况汇总(8月3日)](https://mp.weixin.qq.com/s/86SVgiz3EN-J01voy-pEIA) - [ ] [第十三版《网络安全企业100强》正式发布](https://mp.weixin.qq.com/s/oCzXFILoIjHtlV3TaB2bOQ) - [ ] [专题报告 | 恒安嘉新互联网诈骗态势专题分析报告](https://mp.weixin.qq.com/s/PRG5aeC80a2nJLNWLqbKoQ) - [ ] [专题报告 | 恒安嘉新挖矿和区块链监测专题分析报告](https://mp.weixin.qq.com/s/NrLCRJ_8obuZN4Goh7cDqQ) - [ ] [华为星河AI融合SASE解决方案,助力坦桑尼亚移民局,打造东非出入境网络安全标杆](https://mp.weixin.qq.com/s/x_d3gkkjfYhpqg5IsPRS3g) - [ ] [AI安全 | 锦岳智慧喜获“大模型安全”与“智能体安全”两项国家软著](https://mp.weixin.qq.com/s/fSsZsWZlxPhtAkO5Z1PQ3A) - [ ] [李强主持召开国务院常务会议 学习贯彻习近平总书记关于上半年经济形势和做好下半年经济工作的重要讲话精神等](https://mp.weixin.qq.com/s/l-ZM6N7A9TZYqqrsnwjhng) - [ ] [2026年科技型企业孵化器申报工作启动](https://mp.weixin.qq.com/s/fCW5dpmEODrfi61UgzG3wg) - [ ] [直通车 | 市科技创新局关于公布第三批研发型企业入库名单的通知](https://mp.weixin.qq.com/s/tNnP-BfOKBngOAoc9WQOOQ) - [ ] [会员动态丨默安科技入选IDC中国AI 50强,持续探索AI+安全融合创新实践](https://mp.weixin.qq.com/s/jYULsT0EQYsEKr2E1uUgBg) - [ ] [会员动态 | 湖北科技学院领导一行莅临金信润天参观交流](https://mp.weixin.qq.com/s/PaVofEUhz7ibmKEd2kQ1Jg) - [ ] [4倍于行业增速,奇安信稳居中国IT安全软件市场规模安全厂商第一](https://mp.weixin.qq.com/s/RmE3TPjRciXiRz5c6-3bFQ) - [ ] [某运营商泄露超1.6万用户敏感信息被罚2.5亿元](https://mp.weixin.qq.com/s/sHIPgjGaU4DxUFAh1pU73g) - [ ] [澜砥 N2.6-Preview-0801模型上线](https://mp.weixin.qq.com/s/XQsIkdrsRhAmXZiQ8s9gsA) - [ ] [2026 AI+网络安全高级研讨会圆满落幕](https://mp.weixin.qq.com/s/WEz29yb9zH-xOcWtBBIq4Q) - [ ] [日薪最高3000+?一篇文总结网安人最常见的5条副业路线](https://mp.weixin.qq.com/s/9oycfiB7uDXygyTELOWoSw) - [ ] [低空司司长挂帅!全国低空经济标委会67人名单公示](https://mp.weixin.qq.com/s/mV44aNaJH7GpxwCkwKA7Ew) - [ ] [两项低空安全强制性国标征求意见!反制设备“一物一码\"时代将至](https://mp.weixin.qq.com/s/mIsiohqXZX_gase9F_-XZg) - [ ] [张雪峰老鼠:计算机未开十年,最舒服的出路](https://mp.weixin.qq.com/s/8WrGLYexd4U1bNPBytMvRA) - [ ] [AutoSec演讲嘉宾 | 欧摩威产品网络安全合规负责人:汽车领域 AI 全球合规全景解读](https://mp.weixin.qq.com/s/HKBqlQ3894Q6uwhy_tn3xA) - [ ] [上海交通执法开出首批网约车平台集中处罚决定书](https://mp.weixin.qq.com/s/DtS-75MpMFN9NCYiwUP4lQ) - [ ] [关注 | 中央网信办从严处置一批违规网络娱乐团播账号](https://mp.weixin.qq.com/s/JVxrQFgVS6wBIWqzpSHO7w) - [ ] [专家解读|把握数字化网络化智能化机遇 开创信息化创新发展新局面](https://mp.weixin.qq.com/s/dhXqdyWFkvQYn3bbyoPb0g) - [ ] [国际 | OpenAI模型失控敲响网络安全警钟](https://mp.weixin.qq.com/s/WQV6Qv6UPnxprvCyBSv2bQ) - [ ] [法治 | 具身智能高质量数据集建设的法治护航](https://mp.weixin.qq.com/s/Rx8pIrJ6M_zo77ejaivHNQ) - [ ] [银行保险、央行业务、金融信息服务三类金融场景数据安全政策的适用范围全解](https://mp.weixin.qq.com/s/M47YF0WbxxCnxOpZdxWWKw) - [ ] [湖北省网络和数据安全协会关于向会员单位征求常规性工作意见建议的函](https://mp.weixin.qq.com/s/Ko2az112Dj32MRZgRgub5w) - [ ] [DUDE44搜救行动复盘:开源信息视角下的战斗搜救体系演变](https://mp.weixin.qq.com/s/tj5lndgCp6g1EoVlYUdLQg) - [ ] [【工具】一个开源信息共享服务平台](https://mp.weixin.qq.com/s/fTkxhxgQ-1xvQ_aLjz5-OQ) - [ ] [美国及其盟国更新SBOM指南](https://mp.weixin.qq.com/s/lwGKtIFgFSyMqGQx0IbDfw) - [ ] [【神人TV】回来吧,我的安服大高玩](https://mp.weixin.qq.com/s/AkEBNWuw-nGK1he3cQWrxA) - [ ] [AI 发展趋势,加卡就行](https://mp.weixin.qq.com/s/w1X-_x7SaPWaFosZN0SERQ) - [ ] [捷报 | 边界无限成功中标某全国性头部证券公司RASP项目](https://mp.weixin.qq.com/s/WIT8JscnZStMLeXzX_eN6A) - [ ] [DeepSeek V4 Flash正式版:模型没变,性能暴涨6倍](https://mp.weixin.qq.com/s/xXGJN3RgFNXYgGLuraiTpQ) - [ ] [珠海半导体材料企业诚聘IT技术岗](https://mp.weixin.qq.com/s/j5j7w811txNz6OisNAxCsw) - [ ] [REAL智能体统一风险矩阵与自动化红队实践](https://mp.weixin.qq.com/s/kUYi-imZJH1HLPGUCQXTjw) - [ ] [2026年6月考试成绩](https://mp.weixin.qq.com/s/4KStZ4LtWdmyH0byyJyTaA) - [ ] [精彩由你创作!2026年国家网络安全宣传周微视频征集展映活动来啦!](https://mp.weixin.qq.com/s/ip1QlZtYtzm6L9wLD2y1gw) - [ ] [API-Pentest — 基于 JS 分析 + AI Agent 的 API 渗透测试工具](https://mp.weixin.qq.com/s/irUtMlXK6_wqNxTjBklxxA) - [ ] [Claude失控!突破测试环境入侵3家真实组织,AI安全警钟敲响](https://mp.weixin.qq.com/s/KHEyVi13wDM6BSMA0NMyYg) - [ ] [iOS27beta5或今夜发布,这些烦人BUG会解决吗?](https://mp.weixin.qq.com/s/E6URmblFU9Jre3WA6clCzw) - [ ] [【吃瓜】这,有点,我无法用语言来形容](https://mp.weixin.qq.com/s/ZrLKAQ6cLMM4vmL0M86_vg) - [ ] [白帽子的匿名时代,正在终结——HackerOne强制身份验证这件事](https://mp.weixin.qq.com/s/AYEkWUTpDxNQn3XDDvwu2A) - [ ] [继续红](https://mp.weixin.qq.com/s/9s6BHODSlJfi5i-Q2dHXmg) - [ ] [网站安全专家|云WAF重点功能升级!](https://mp.weixin.qq.com/s/yKDTpXEIgA__0QKa3JqpXA) - [ ] [人人都要学大脑xa0|xa0第11期](https://mp.weixin.qq.com/s/etvwbkYHVLVcLCZ1avWR7A) - [ ] [一个假“公安一网通办”App,扯出了一整条安卓远控黑产生态链](https://mp.weixin.qq.com/s/sBWZZM6rNpACtSeuPb05dw) - [ ] [招银网络科技算法工程师校招,职责包括AI技术研究、推动AI应用等](https://mp.weixin.qq.com/s/wsUF9G2-5lFNKtxj3-7dBw) - [ ] [快速与千兆以太网对比](https://mp.weixin.qq.com/s/KN3cwUDmMsEVx0Z5rnp5MA) - [ ] [【安全无界 · 联合狂欢】陌陌 SRC 跨平台联动,多重好礼等你来!](https://mp.weixin.qq.com/s/bkNLK0xNPVT1KnH4K-_QfQ) - [ ] [OpenAI与Anthropic模型相继失控,自主黑入真实世界](https://mp.weixin.qq.com/s/BmMxPbjlrj2DRkCgzexjjQ) - [ ] [两条岔路:OpenAI 与 Anthropic 正在走向不同的终局](https://mp.weixin.qq.com/s/SXd4oHM4T-OnPORWG7ysuA) - [ ] [工信部:2026上半年我国信息安全领域收入1425亿元;OpenAI、Anthropic 测试 AI 模型失控入侵外部企业,AI 侵权法律责任界定陷入空白|牛览](https://mp.weixin.qq.com/s/98Uoq-eBdWZEUhCCf1ah-A) - [ ] [上汽大众:中德工控系统信息安全防护对比研究及其应用实践](https://mp.weixin.qq.com/s/B-WQB0TUQMAdilicJhRMCA) - [ ] [智能汽车网络安全与信息安全基础培训课程 2026](https://mp.weixin.qq.com/s/FbvaDNNgVQbmWnsBsrm3xQ) - [ ] [智能汽车信息数据安全标准解析](https://mp.weixin.qq.com/s/TEqdHJSRysQpkXL34yy3kg) - [ ] [每次网购使用返利机器人真的能领到隐藏优惠券吗?详细拆解88vip高返助手的省钱返现原理!](https://mp.weixin.qq.com/s/P_FHZM186PKxlHTg-u8Ulw) - [ ] [无证驾驶计算机](https://mp.weixin.qq.com/s/DVi9x4TQQZlmosVkjudfUA) - [ ] [1v1论文指导!985/211专业对口导师手把手指导至录用!SCI/SSCI/EI/中文核心/毕业论文](https://mp.weixin.qq.com/s/JkeEGoZi6Bz1YwUREYt7WQ) - ElcomSoft blog - [ ] [Special macOS Firewall: Safe Sideloading of the EIFT Extraction Agent](https://blog.elcomsoft.com/2026/08/special-macos-firewall-safe-sideloading-of-the-eift-extraction-agent/) - Recent Commits to cve:main - [ ] [Update Mon Aug 3 12:02:43 UTC 2026](https://github.com/trickest/cve/commit/7ade3449b58b8e2c679712dc3af64bbd8e638364) - Horizon3 - [ ] [How TTEC Turned Hidden Attack Paths Into Audit-Ready Security Validation](https://horizon3.ai/customer-story/ttec-security-validation-customer-story/) - [ ] [Horizon3 Raises $250M Series E at $2B+ Valuation to Lead the “AI vs. AI” Cybersecurity Era](https://horizon3.ai/news/press-release/horizon3-raises-250m-series-e-at-2b-valuation-to-lead-the-ai-vs-ai-cybersecurity-era/) - Securelist - [ ] [An analysis of incidents at Brazilian educational institutions](https://securelist.com/incidents-at-brazilian-educational-institutions/120803/) - Toooold - [ ] [First Principle of Agent Harness Engineering: From Continuation to Control](https://toooold.com/2026/08/03/first_principle_harness.html) - Hacking Dream - [ ] [MCP Penetration Testing: Hacking Model Context Protocol](https://www.hackingdream.net/2026/08/mcp-penetration-testing-hacking-model-context-protocol.html) - VMRay - [ ] [Best AI Malware Analysis Tools: 9 Platforms Compared for 2026](https://www.vmray.com/best-ai-malware-analysis-tools-9-platforms-2026/) - daniel.haxx.se - [ ] [What the bliss taught us](https://daniel.haxx.se/blog/2026/08/03/what-the-bliss-taught-us/) - Malwarebytes - [ ] [“Adult TikTok” searches lead to scams](https://www.malwarebytes.com/blog/scams/2026/08/adult-tiktok-searches-lead-to-scams) - [ ] [The AI Act kicks into action, forces companies to be clear about AI chatbots](https://www.malwarebytes.com/blog/news/2026/08/the-ai-act-kicks-into-action-forces-companies-to-be-clear-about-ai-bots) - [ ] [Californians can tell data brokers to DROP their information](https://www.malwarebytes.com/blog/news/2026/08/californians-can-tell-data-brokers-to-drop-their-information) - [ ] [A week in security (July 27 – August 2)](https://www.malwarebytes.com/blog/news/2026/08/a-week-in-security-july-27-august-2) - 黑海洋Wiki | AI机器人硬件开发 | 网络安全攻防实战 | 区块链技术文档教程 - 免费资源平台 - [ ] [白宫将于周二会晤AI巨头 讨论前沿模型安全测试框架](https://blog.upx8.com/%E7%99%BD%E5%AE%AB%E5%B0%86%E4%BA%8E%E5%91%A8%E4%BA%8C%E4%BC%9A%E6%99%A4AI%E5%B7%A8%E5%A4%B4-%E8%AE%A8%E8%AE%BA%E5%89%8D%E6%B2%BF%E6%A8%A1%E5%9E%8B%E5%AE%89%E5%85%A8%E6%B5%8B%E8%AF%95%E6%A1%86%E6%9E%B6) - [ ] [召回退休高管 苹果准CEO开始组建班底](https://blog.upx8.com/%E5%8F%AC%E5%9B%9E%E9%80%80%E4%BC%91%E9%AB%98%E7%AE%A1-%E8%8B%B9%E6%9E%9C%E5%87%86CEO%E5%BC%80%E5%A7%8B%E7%BB%84%E5%BB%BA%E7%8F%AD%E5%BA%95) - [ ] [三星将禁止把用户电视变成住宅代理的App](https://blog.upx8.com/%E4%B8%89%E6%98%9F%E5%B0%86%E7%A6%81%E6%AD%A2%E6%8A%8A%E7%94%A8%E6%88%B7%E7%94%B5%E8%A7%86%E5%8F%98%E6%88%90%E4%BD%8F%E5%AE%85%E4%BB%A3%E7%90%86%E7%9A%84App) - text/plain - [ ] [Authenticode and UAC](https://textslashplain.com/2026/08/03/authenticode-and-uac/) - [ ] [Attack Techniques: Fake Captive Portals](https://textslashplain.com/2026/08/03/attack-techniques-fake-captive-portals/) - HackerNews - [ ] [黑客投毒 Adform 脚本,在客户网站上替换加密货币钱包地址](http://0.0.0.0:8080/post/64548) - [ ] [Adobe Campaign Classic CVSS 10.0 漏洞可在无需用户交互的情况下执行代码](http://0.0.0.0:8080/post/64547) - [ ] [Coldcard 硬件钱包漏洞导致 41 分钟内被盗 7000 万美元比特币](http://0.0.0.0:8080/post/64546) - [ ] [明尼苏达州供水系统遭网络攻击,官员警告伊朗黑客](http://0.0.0.0:8080/post/64545) - [ ] [Rails 修补 Active Storage 关键漏洞,存在 RCE 风险](http://0.0.0.0:8080/post/64544) - [ ] [CareCloud 数据泄露导致 34.5 万人医疗和财务数据曝光](http://0.0.0.0:8080/post/64543) - 黑鸟 - [ ] [新型链上隐蔽通信NullReceiver:黑客用空白以太坊转账藏匿远控地址](https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451187963&idx=1&sn=2ad007058baa11c64c1c4c69b89deeac) - 安全客 - [ ] [白帽子的匿名时代,正在终结——HackerOne强制身份验证这件事](https://mp.weixin.qq.com/s?__biz=MzA5ODA0NDE2MA==&mid=2649790321&idx=1&sn=dd25241b60cb3abfd1aa053fffbdc364) - 代码卫士 - [ ] [SolarWinds 严重漏洞可导致绕过 Web Help Desk SAML 登录认证机制](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247526788&idx=1&sn=31b126ba90fa61c7de56aff42e8761fd) - [ ] [Rails 修复严重的 Active Storage 漏洞,可导致 RCE 后果](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247526788&idx=2&sn=7f4b4916527a0b69b3f51b0b28b6c5ed) - 奇客Solidot–传递最新科技情报 - [ ] [微软表示正致力于优化 Windows 11 在 8GB 内存下的运行效率](https://www.solidot.org/story?sid=84996) - [ ] [科学家在深海热泉动物体内发现塑料颗粒](https://www.solidot.org/story?sid=84995) - [ ] [AI 开始大幅减少客服岗位](https://www.solidot.org/story?sid=84994) - [ ] [澳大利亚社媒禁令效果有限](https://www.solidot.org/story?sid=84993) - [ ] [GOG Galaxy 将原生支持 Linux](https://www.solidot.org/story?sid=84992) - [ ] [加州居民从 8 月 1 日起可要求数据经纪商删除个人数据](https://www.solidot.org/story?sid=84991) - [ ] [冷钱包攻击导致比特币被盗近 8900 万美元](https://www.solidot.org/story?sid=84990) - [ ] [马来西亚打击加密货币矿工的偷电](https://www.solidot.org/story?sid=84989) - [ ] [AI 通过错误的推理得到正确的结果?](https://www.solidot.org/story?sid=84988) - 安全内参 - [ ] [某运营商泄露超1.6万用户敏感信息被罚2.5亿元](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516361&idx=1&sn=359498e8aafa2568381a04e9f6baa817) - 雷神众测 - [ ] [雷神众测漏洞周报2026.7.27-2026.8.2](https://mp.weixin.qq.com/s?__biz=MzI0NzEwOTM0MA==&mid=2652503896&idx=1&sn=0bca57a0325ae780a651fb39a4e3517a) - 数世咨询 - [ ] [美国及其盟国更新SBOM指南](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247543643&idx=1&sn=764f596b74a5b5241b1e0d6e7ed94f7a) - 安全圈 - [ ] [【安全圈】NVIDIA发布AI代理安全扫描器SkillSpector](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078137&idx=1&sn=d917e768c00d1cbd9f1de90181245468) - [ ] [【安全圈】DNA证据遭篡改?赛默飞修复高危漏洞](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078137&idx=2&sn=17a2d4ad4d423e7a8453c8dad79df73f) - [ ] [【安全圈】34.5万患者数据泄露!CareCloud遭攻击](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078137&idx=3&sn=d0146b4f0d991e60a398d0588d58979a) - M01N Team - [ ] [AI安全案例分析 | 文档蠕虫借助Word Copilot实现自我复制与传播](https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&mid=2247495374&idx=1&sn=099632565fc47916addc0c5a7d6715ef) - 中国信息安全 - [ ] [论坛·原创 | 俄罗斯科技安全制度建设的逻辑与困境](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265263&idx=1&sn=5a8f7abad7b6dc18858967db3413320b) - [ ] [关注 | 中央网信办从严处置一批违规网络娱乐团播账号](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265263&idx=2&sn=4c17234465eabdba53f189c19eda9091) - [ ] [专家解读|把握数字化网络化智能化机遇 开创信息化创新发展新局面](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265263&idx=3&sn=87397d213deb3f08d900543f7d6f3887) - [ ] [国际 | OpenAI模型失控敲响网络安全警钟](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265263&idx=4&sn=7944a5b2499904d81dba561b3ac317f5) - [ ] [法治 | 具身智能高质量数据集建设的法治护航](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265263&idx=5&sn=03075dbd61a549d40c4bbedf2373cea0) - 安全研究GoSSIP - [ ] [G.O.S.S.I.P 阅读推荐 2026-08-03 当 Agent 开始替攻击者“删规则”](https://mp.weixin.qq.com/s?__biz=Mzg5ODUxMzg0Ng==&mid=2247501937&idx=1&sn=fab700850f80ddfd367cd1aab2df5730) - 安全牛 - [ ] [两条岔路:OpenAI 与 Anthropic 正在走向不同的终局](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142128&idx=1&sn=775f9679f75411d5d5cc01b00adb5eea) - [ ] [工信部:2026上半年我国信息安全领域收入1425亿元;OpenAI、Anthropic 测试 AI 模型失控入侵外部企业,AI 侵权法律责任界定陷入空白|牛览](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142128&idx=2&sn=628f602d18512e4ec7828c2e4215f1d8) - 看雪学苑 - [ ] [一次外部注入工具的动态调试实录](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458618175&idx=1&sn=8dfdec8d72565486ce162b91909f4ce4) - [ ] [9.10 北京|AI Agent 驱动 Android 逆向与 Root 漏洞实战训练营](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458618175&idx=2&sn=6e07d97e55af6343f2567a424a9b98fe) - [ ] [硬件钱包重大漏洞!Coldcard固件缺陷,近9000万BTC资产失窃](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458618175&idx=3&sn=0fea3852280411019ea5dfeb331b8a52) - 云鼎实验室 - [ ] [【漏洞预警】Linux Kernel OVSwrap 权限提升漏洞,PoC 已公开](https://mp.weixin.qq.com/s?__biz=MzU3ODAyMjg4OQ==&mid=2247497869&idx=1&sn=eb12a910ec9c91de2c73398e22aaac56) - 君哥的体历 - [ ] [安全岗位会被AI取代吗?云桌面能守住数据防线吗?|总第315周](https://mp.weixin.qq.com/s?__biz=MzI2MjQ1NTA4MA==&mid=2247492494&idx=1&sn=455a724ce645dcd125da4e3fe2f38b59) - 斗象智能安全 - [ ] [全流量安全,正式进入“AI白名单”时代!](https://mp.weixin.qq.com/s?__biz=MzIwMjcyNzA5Mw==&mid=2247495581&idx=1&sn=6d41461908cfbe222cf507a247b5ba78) - 微步在线 - [ ] [谁家的安全智能体,竟然要考核KPI](https://mp.weixin.qq.com/s?__biz=MzI5NjA0NjI5MQ==&mid=2650187190&idx=1&sn=2ce427e3971c311c239ad69899f52629) - 陌陌安全 - [ ] [【安全无界 · 联合狂欢】陌陌 SRC 跨平台联动,多重好礼等你来!](https://mp.weixin.qq.com/s?__biz=MzI2OTYzOTQzNw==&mid=2247489662&idx=1&sn=5cb3ca2b5808854f8cc7666cc3147ac4) - 天黑说嘿话 - [ ] [每次网购使用返利机器人真的能领到隐藏优惠券吗?详细拆解88vip高返助手的省钱返现原理!](https://mp.weixin.qq.com/s?__biz=MzI5NTQ5MTAzMA==&mid=2247486301&idx=1&sn=56d9d80241fea06163f224650d6c2c0e) - 火绒安全 - [ ] ["开黑"变"被黑" | 你下载的Oopz可能是别人的"遥控器"](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247535940&idx=1&sn=5fce74f38cb6166ed016b761552d577b) - [ ] [诚邀渠道合作伙伴共启新征程](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247535940&idx=2&sn=9b8380853b93c371216e326c701a6cc9) - 凌晨一点零三分 - [ ] [跟党走_政策板块日报2026-08-03](https://mp.weixin.qq.com/s?__biz=MzIxMjI0Mzk0OQ==&mid=2247485644&idx=1&sn=a595261532e2f7046b8300142f80044c) - 字节跳动技术团队 - [ ] [字节跳动2027校招正式启动!](https://mp.weixin.qq.com/s?__biz=MzI1MzYzMjE0MQ==&mid=2247521059&idx=1&sn=3473116140a8c13351c998c519ca93a1) - 极客公园 - [ ] [Genspark 发布 GenOffice:AI 时代的 Office,免费、开源,抢占办公人群的第一工作入口](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653111529&idx=1&sn=fed610a0867c177d318ad29f75abbf85) - [ ] [Fitbit Air 手环深度体验:「无屏」只是手段,模型能力才是护城河](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653111513&idx=1&sn=06aca68e4b483db4d9aba3590fd2a6e7) - [ ] [内存奇缺,Macbook Air 或缺货;智元母公司推《魔兽世界》机器人;微信地震预警上线新功能 | 极客早知道](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653111503&idx=1&sn=a6baf2d1376ac797b120f99dbebaf687) - OnionSec - [ ] [回撤之前](https://mp.weixin.qq.com/s?__biz=MzUyMTUwMzI3Ng==&mid=2247485911&idx=1&sn=76face8310f940420e1c8fc3fbdc4d82) - 丁爸 情报分析师的工具箱 - [ ] [【开源报告】日本国家情报局深度调研](https://mp.weixin.qq.com/s?__biz=MzI2MTE0NTE3Mw==&mid=2651156807&idx=1&sn=b6d46f5e54177a9589f7b254ce2bb6e0) - [ ] [【工具】一个开源信息共享服务平台](https://mp.weixin.qq.com/s?__biz=MzI2MTE0NTE3Mw==&mid=2651156807&idx=2&sn=f75841ce558c2e7bcc9510b0f5ac856e) - 安全419 - [ ] [预告:《网安行业深度观察系列》即将重磅发布](https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&mid=2247554297&idx=1&sn=20ed0b0ac927b3e7ba937ec9286f4aa7) - [ ] [网安招聘直通车 | 边界无限众多岗位诚聘英才!](https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&mid=2247554297&idx=2&sn=b3ad6db0b30771863e269f77e19e108f) - 情报分析师 - [ ] [美国特勤局招聘了,九千万美元买来的四万份简历](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650568951&idx=1&sn=c2b7b804a51caa28a46a135d0d399e52) - [ ] [伊朗裔工程师在美被判向伊朗出口无人机技术,我高科技出口管制与供应链安全面临类似执法压力](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650568951&idx=2&sn=705b41c8d08b7607fff9d5cf8acdeb37) - Virus Bulletin's blog - [ ] [What cybersecurity experts are talking about in 2026](https://www.virusbulletin.com/blog/2026/08/what-cybersecurity-experts-are-talking-about-2026/) - CNVD漏洞平台 - [ ] [CNVD漏洞周报2026年第30期](https://mp.weixin.qq.com/s?__biz=MzU3ODM2NTg2Mg==&mid=2247497156&idx=1&sn=1eb1b912c9b26a5d43b35b4f48dc31ce) - [ ] [上周关注度较高的产品安全漏洞(20260727-20260802)](https://mp.weixin.qq.com/s?__biz=MzU3ODM2NTg2Mg==&mid=2247497156&idx=2&sn=e41a59b8f6316b5a0190cf2a683c882e) - Schneier on Security - [ ] [More on the OpenAI Agent’s Attack on Hugging Face](https://www.schneier.com/blog/archives/2026/08/more-on-the-openai-agents-attack-on-hugging-face.html) - [ ] [The OpenAI Hack Shows the Genie Is Out of the Bottle](https://www.schneier.com/blog/archives/2026/08/the-openai-hack-shows-the-genie-is-out-of-the-bottle.html) - Javvad Malik - [ ] [The Robots Have Escaped, Please Buy Our Product](https://javvadmalik.com/2026/08/03/the-robots-have-escaped-please-buy-our-product/) - SANS Internet Storm Center, InfoCON: green - [ ] [ISC Stormcast For Monday, August 3rd, 2026 https://isc.sans.edu/podcastdetail/10034, (Mon, Aug 3rd)](https://isc.sans.edu/diary/rss/33210) - Over Security - [ ] [Apple challenges UK government’s latest demand for iCloud backdoor: report](https://techcrunch.com/2026/08/03/apple-challenges-uk-governments-latest-demand-for-icloud-backdoor-report/) - [ ] [Who’s legally to blame for Anthropic and OpenAI’s autonomous AI hacks? It’s complicated](https://techcrunch.com/2026/08/03/whos-legally-to-blame-for-anthropic-and-openais-autonomous-ai-hacks-its-complicated/) - [ ] [Quanto costa davvero il rischio cyber](https://www.certego.net/blog/cybersecurity-per-cfo-dal-budget-al-rischio-di-impresa/) - [ ] [Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums](https://www.bitdefender.com/en-us/blog/labs/fake-xeno-roblox-discord-executor) - [ ] [Flashpoint EASM: Industry-Leading Vulnerability Intelligence, Mapped to Your Internet-Facing Assets](https://flashpoint.io/blog/flashpoint-easm-vulnerability-intelligence/) - [ ] [[Webinar] Tales from the Frontlines: An exclusive briefing on Q2 incidents](https://blog.talosintelligence.com/webinar-tales-from-the-frontlines-an-exclusive-briefing-on-q2-incidents/) - [ ] [Hacker Iran contro 30 aziende idriche Usa: la lezione per le infrastrutture critiche](https://www.cybersecurity360.it/news/hacker-iran-contro-30-aziende-idriche-usa-la-lezione-del-minnesota-per-le-infrastrutture-critiche/) - [ ] [Threat Hunting and Defending #2: concepts, framework, Threat Model (p2)](https://roccosicilia.com/2026/08/03/threat-hunting-and-defending-2-concepts-framework-threat-model-p2/) - [ ] [Biotech giant Amgen says patient data stolen from third-party cloud systems](https://therecord.media/amgen-hackers-cyberattack-sec) - [ ] [Hackers steal 31,000 records identifying people behind Liechtenstein companies, foundations](https://therecord.media/hackers-steal-records-liechtenstein-companies-foundations) - [ ] [Bitcoin hardware wallet maker destroys some inventory after more than $88 million stolen](https://therecord.media/bitcoin-theft-coldcard-cyberattack) - [ ] [The Assets You Don’t Know You Own: Attack Surface Sprawl Is a Discovery Problem, Not a Tooling Problem](https://cyble.com/blog/attack-surface-discovery-asset-visibility/) - The Hacker News - [ ] [18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users](https://thehackernews.com/2026/08/18-malicious-npm-packages-deliver-cross.html) - [ ] [Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts](https://thehackernews.com/2026/08/google-password-manager-attacks-could.html) - [ ] [INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws](https://thehackernews.com/2026/08/inc-ransomware-emerges-as-dominant.html) - [ ] [⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks](https://thehackernews.com/2026/08/weekly-recap-rogue-ai-models-88m.html) - [ ] [FOMO in the SOC: Where AI Platforms like Claude Actually Fit](https://thehackernews.com/2026/08/fomo-in-soc-where-ai-platforms-like.html) - [ ] [Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS](https://thehackernews.com/2026/08/chinese-threat-actor-uses-leaked.html) - [ ] [PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web](https://thehackernews.com/2026/08/pnld-breach-exposes-uk-police-and.html) - [ ] [Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable](https://thehackernews.com/2026/08/thermo-fisher-patches-flaw-that-could.html) - [ ] [N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete](https://thehackernews.com/2026/08/n-able-says-attackers-take-over-n.html) - [ ] [Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code](https://thehackernews.com/2026/08/hugging-face-diffusers-flaws-could-let.html) - Qualys Security Blog - [ ] [Zero-Day Remediation Meets Operational Resiliency](https://blog.qualys.com/category/product-tech) - [ ] [Agent Val Now Validates the Entire Attack Surface: From Network to Host](https://blog.qualys.com/category/product-tech) - [ ] [Say Hello to Agent Insta: Closing the Detection Gap in Exposure Management at Machine Speed](https://blog.qualys.com/category/product-tech) - Instapaper: Unread - [ ] [SSH ramdisk su iPhone XS con iOS 18.7.9 la chain completa fino al file system](https://www.forenser.it/ssh-ramdisk-su-iphone-xs-con-ios-18-7-9-la-chain-completa-fino-al-file-system/) - [ ] [When the iCloud Backup Is the Only Copy Left](https://blog.elcomsoft.com/2026/07/when-the-icloud-backup-is-the-only-copy-left/) - [ ] [WinFE Builder](https://winfe.wordpress.com/2026/08/01/winfe-builder/) - Security Affairs - [ ] [AI Runs the Hack: Chinese Actor Automates Cyberattacks With DeepSeek](https://securityaffairs.com/196544/ai/ai-runs-the-hack-chinese-actor-automates-cyberattacks-with-deepseek.html) - [ ] [River Bank obtained assurances from the attackers that the stolen data in the June attack was deleted](https://securityaffairs.com/196537/cyber-crime/river-bank-obtained-assurances-from-the-attackers-that-the-stolen-data-in-the-june-attack-was-deleted.html) - [ ] [PNLD Confirms Data Breach Affecting UK Police and Justice Staff](https://securityaffairs.com/196525/data-breach/pnld-confirms-data-breach-affecting-uk-police-and-justice-staff.html) - [ ] [Alleged Żabka Breach Exposes Jira Data, Source Code, and API Keys](https://securityaffairs.com/196510/data-breach/alleged-zabka-breach-exposes-jira-data-source-code-and-api-keys.html) - [ ] [Ruby on Rails Patches Critical Active Storage Vulnerability Affecting Image Processing](https://securityaffairs.com/196486/security/ruby-on-rails-patches-critical-active-storage-vulnerability-affecting-image-processing.html) - TorrentFreak - [ ] [Record Labels Offer to Abandon $46.8 Million Piracy Case Against Grande](https://torrentfreak.com/record-labels-offer-to-abandon-46-8-million-piracy-case-against-grande/) - Troy Hunt's Blog - [ ] [Welcoming the Nepalese Government to Have I Been Pwned](https://www.troyhunt.com/welcoming-the-nepalese-government-to-have-i-been-pwned/) - [ ] [Weekly Update 515](https://www.troyhunt.com/weekly-update-515/) - Lenny Zeltser - [ ] [Five Questions to Answer Before Buying an AI Security Product](https://zeltser.com/ai-security-buying-questions) - Tor Project blog - [ ] [Snowflake Volunteer, an Android app to help people bypass censorship](https://blog.torproject.org/snowflake-volunteer-standalone-app-to-help-people-bypass-censorship/) - www.theregister.com - Articles - [ ] [Google dev kit spurs first-ever agent-on-agent violence](https://www.theregister.com/security/2026/08/03/google-dev-kit-spurs-first-ever-agent-on-agent-violence/5282496) - [ ] [AI slop pollutes the CVE pipeline with fake vulns](https://www.theregister.com/security/2026/08/03/ai-slop-pollutes-the-cve-pipeline-with-fake-vulns/5282462) - [ ] [Russian spies turn public Wi-Fi into malware delivery systems](https://www.theregister.com/security/2026/08/03/russias-svr-borks-public-wi-fis-for-digital-surveillance/5282399) - [ ] [Water system cyberattacks spread to Georgia, Michigan amid US-Iran conflict](https://www.theregister.com/security/2026/08/03/georgia-michigan-say-water-systems-hacked-by-iran-tied-crew/5282262) - [ ] [UK government investment arm cops to 40-hour leak of officials' contact details](https://www.theregister.com/security/2026/08/03/uk-government-investment-arm-cops-to-40-hour-leak-of-officials-contact-details/5282213) - [ ] [AI is 'both the weapon and the target' in latest wave of cyberattacks](https://www.theregister.com/cyber-crime/2026/08/03/ai-is-both-the-weapon-and-the-target-in-latest-wave-of-cyberattacks/5281534) - Security Weekly Podcast Network (Audio) - [ ] [AppSec, Shopify-Style; State of Mobile Security; the News - Kern Smith, Andrew Dunbar - ESW #470](http://sites.libsyn.com/18678/appsec-shopify-style-state-of-mobile-security-the-news-kern-smith-andrew-dunbar-esw-470) - Deeplinks - [ ] [The Senate Should Reject KOSA's Privacy Risks](https://www.eff.org/deeplinks/2026/08/senate-should-reject-kosas-privacy-risks) - [ ] [EFF Joins 18 Civil Rights Organizations Calling on Governor Hochul to Reject the Stealth Crawler Prohibition Act](https://www.eff.org/deeplinks/2026/08/eff-joins-18-civil-rights-organizations-calling-governor-hochul-reject-stealth) - [ ] [EFF Joins Call for FTC to Drop Its Disastrous AI Policy Proposal](https://www.eff.org/deeplinks/2026/08/eff-joins-comments-calling-ftc-drop-its-ai-policy-proposal) - [ ] [The Youth AI Privacy Act’s Privacy Paradox](https://www.eff.org/deeplinks/2026/08/youth-ai-privacy-acts-privacy-paradox) - [ ] [EFF at BSidesLV, Black Hat, and DEF CON 👨💻](https://www.eff.org/deeplinks/2026/07/eff-bsideslv-black-hat-and-def-con) - Daniel Miessler - [ ] [The AI-Native Company](https://danielmiessler.com/blog/the-ai-native-company?utm_source=rss&utm_medium=feed&utm_campaign=website) - 网安寻路人 - [ ] [从预训练到推理:抓取数据的供给与权益平衡初探](https://mp.weixin.qq.com/s?__biz=MzIxODM0NDU4MQ==&mid=2247508768&idx=1&sn=57f406c388e7d0ee0f36a96a789b0702)
每日安全资讯(2026-08-04)