# 每日安全资讯(2026-07-22) - 安全客-有思想的安全新媒体 - [ ] [科技云报到:当基础设施遇上工业 AI,一场绿色效率革命轰然开启](https://www.anquanke.com/post/id/315828) - [ ] [你家门口的摄像头,可能正在替俄罗斯情报机构"站岗"](https://www.anquanke.com/post/id/315830) - SecWiki News - [ ] [SecWiki News 2026-07-21 Review](http://www.sec-wiki.com/?2026-07-21) - Doonsec's feed - [ ] [330份国外安全厂商渗透测试报告](https://mp.weixin.qq.com/s/SBm5hOGZB84kqOTxXo376g) - [ ] [暑假逆袭计划:30天带你入门网络安全](https://mp.weixin.qq.com/s/TyvkRXBJKDby0fz83q-frA) - [ ] [颠覆课本!西安电子科技大学学子直接拿下真实网站后台|这才是高校该有的网安实训](https://mp.weixin.qq.com/s/uav1H89nBpxJGYouxXdzOA) - [ ] [Qoder Security重磅上线:为每位开发者,配了一位专属安全工程师](https://mp.weixin.qq.com/s/5UKAE8F6ae9ImFts63-4Zg) - [ ] [CNVD漏洞周报2026年第28期](https://mp.weixin.qq.com/s/fI_wV_n2QRnZ09ygxpI5nA) - [ ] [关于开展网络和数据安全赛事平台能力检测服务的通知](https://mp.weixin.qq.com/s/JbKysLJZLJpPXMRxN6C4xA) - [ ] [从500个真正跑通的项目里看见数据要素、动态数据安全项目样本|第九届西湖论剑创新实践火热征集中!](https://mp.weixin.qq.com/s/B771NIQUk6yZJaJI68rCBQ) - [ ] [关于“复兴杯”第五届全国大学生网络安全精英赛奖励发放的公告](https://mp.weixin.qq.com/s/ZbGMkkLx4JxSJvkvV5nZ0Q) - [ ] [2026平航杯wp](https://mp.weixin.qq.com/s/J3L1LjCyFnr-HHW0Fmy_KA) - [ ] [微信看图秒推同款?拆解某多多搜广推真相与安全隐忧](https://mp.weixin.qq.com/s/7xopcoiM-ZSpFzGDgYrbBw) - [ ] [sci论文一直投不中?大牛帮指导选刊投稿返修后,被拒的5篇SCI全中了!](https://mp.weixin.qq.com/s/gXE0Tddz-WtfWTvP7kOu4Q) - [ ] [公开≠授权:欧洲为AI数据抓取划出的那条线,正在改变整个行业](https://mp.weixin.qq.com/s/tDX-dIDgDc2xKo7VN9ABqg) - [ ] [中央网信办部署开展“清朗·未成年人网络保护”专项行动;CNVD发布上周漏洞周报:漏洞总量走高,多款海外软件曝高危漏洞 | 牛览](https://mp.weixin.qq.com/s/AW9HGRnQQTRRF_hH4P2_xA) - [ ] [重磅发布!【首批】天翼云通过专有云责任保障能力等级评估!](https://mp.weixin.qq.com/s/K42ZUxIMH_FdZL9CgqtQpA) - [ ] [净网专项行动:网警依法打击网络赌球违法犯罪,公布10起典型案例](https://mp.weixin.qq.com/s/cxU5Os4J5-jHIknMLHsMtw) - [ ] [苹果发布iOS26.6RC准正式版,这些变化你必须知道](https://mp.weixin.qq.com/s/JHR5da8vZWBOyU4b6Cem5A) - [ ] [国家级赛事“天网杯”启动 360提供全方位技术支持](https://mp.weixin.qq.com/s/p1GrtoeWfRky4vCA1NzUBw) - [ ] [HnuSec 暑期招新开启——HnuCTF 2026来了!](https://mp.weixin.qq.com/s/M_W9kF9sY0bd6Na6ayK07Q) - [ ] [世界人工智能大会启幕|华云安跻身人工智能安全漏洞治理联盟首批成员单位](https://mp.weixin.qq.com/s/ebRk1Vrk7r0cUHNyGM-fiw) - [ ] [记一次护网通过外网弱口令一路到内网(但是一路磕磕绊绊)](https://mp.weixin.qq.com/s/VxJfWQbyLJZi9Osv_M25Zg) - [ ] [渗透测试从业者:把AI智能体接进Burp 数据包分析交给它](https://mp.weixin.qq.com/s/dK6v4bhmXG3bxKLZ-TRaRA) - [ ] [7月社区投稿活动 | 漏洞挖掘/AI渗透](https://mp.weixin.qq.com/s/o8TeuIpBOcNohYhdQqgzEg) - [ ] [网络安全日报 | 2026-07-21](https://mp.weixin.qq.com/s/L-XaKp_Q0pQskK0oktKmSg) - [ ] [解锁src新成就了](https://mp.weixin.qq.com/s/-lkPi-OBS-8W-t8PokYM0Q) - [ ] [黑龙江省联社创新研发中心发布软件开发岗(人工智能)](https://mp.weixin.qq.com/s/s1l7oPJZgkYyIcqku_XJ6A) - [ ] [攻击链越来越长,你的安全设备却各看各的:嘉韦思慧眼如何让你\"看见\"完整攻击过程?](https://mp.weixin.qq.com/s/lR_7-MVZwzVAJkgm_0RfFg) - [ ] [一个记录家人看病信息的APP](https://mp.weixin.qq.com/s/Om-JjbV3qSbCnS0rPZ9_5g) - [ ] [周某利用AI工具编造“高考估分715查分299,女孩称试卷不是自己的”谣言被行政拘留](https://mp.weixin.qq.com/s/mRIIZyCjGR8CZRrs_3MHCw) - [ ] [第十九届全国大学生信息安全竞赛(作品赛)暨第三届“长城杯” 网数智安全大赛(作品赛)进入初赛评审阶段名单通知](https://mp.weixin.qq.com/s/6Ia8p_3JZ1Ho2jl5QGCoaA) - [ ] [沈逸:WAIC为世界人工智能治理提供新坐标](https://mp.weixin.qq.com/s/7PcHHT5L9-vnbB5RYiYKiA) - [ ] [从挑战杯到WAIC|当AI学会思考,安全谁来守护?安恒信息交出了这样一份答卷](https://mp.weixin.qq.com/s/9Wh0yBW0kYKdad4spJjTjw) - [ ] [可口可乐遭勒索攻击:美国工厂运营中断 乳制品生产暂停](https://mp.weixin.qq.com/s/t1h4ZvR76BoAS_cN2nxohw) - [ ] [四大会计事务所之一的EY 安永承认第三方支持工单平台遭入侵,多家客户税务与财务数据外泄](https://mp.weixin.qq.com/s/I5YTcQ6N9jFX0FWuPk1J0Q) - [ ] [iOS 27 Beta 4 全解析:这些新功能太实用了!](https://mp.weixin.qq.com/s/65J6Rd3VK-vJNJvlgLY_8w) - [ ] [基于边缘计算的区域级网联车辆网络安全威胁协同感知技术研究](https://mp.weixin.qq.com/s/Aqa5e3zrsI64jJwFJTBjfg) - [ ] [GB/T 46798-2025《网络安全技术 标识密码认证系统密码及其相关安全技术要求》详细解读](https://mp.weixin.qq.com/s/V8CyGP7kNQEYAS9bNrQugw) - [ ] [网安AI速报 | 2026.07.21](https://mp.weixin.qq.com/s/Zt0RnQ0eIA7cttlSAdlw_A) - [ ] [云天 · 安全通告(2026年7月21日)](https://mp.weixin.qq.com/s/6hwNXnc64g56gYJIiZgt6w) - [ ] [安徽省数据交易所X安恒信息举办2026年安徽省高校网安及数据要素人才培养研讨会](https://mp.weixin.qq.com/s/kM9OVxsmvdyDY2B-ckjSxQ) - [ ] [国际背书 xa0跻身全球厂商名录,微步上榜两份 Gartner®xa0技术成熟度曲线报告](https://mp.weixin.qq.com/s/p9dN8wPC7_7_H6x-sfytdg) - [ ] [AI拒绝后也能无缝继续:不用重开会话,不丢上下文](https://mp.weixin.qq.com/s/AmlzwoiFRaM7_-m2g-r1FA) - [ ] [重磅发布!【首批】阿里云通过专有云责任保障能力等级评估!](https://mp.weixin.qq.com/s/YyW2wyRk8h8Psr21ksZSdw) - [ ] [300页 2026智能体创新实践汇编](https://mp.weixin.qq.com/s/kn_I9ir5t8APQl32jloOqg) - [ ] [2026年中AI威胁态势报告](https://mp.weixin.qq.com/s/fJ7uInJsiElOak3J0EraSA) - [ ] [卫星互联网安全综述;卫星互联网行业深度:发展背景、供需格局、产业链及相关公司深度梳理](https://mp.weixin.qq.com/s/OiDoBdTWQL_thku6gRp6zQ) - [ ] [基于TLS 1.3的终端访问控制器访问控制系统增强版(TACACS+)](https://mp.weixin.qq.com/s/GEG1tjM5I7W7stN3N-nv0g) - [ ] [NetHand:安天网管自用主机管理小工具可以下载了](https://mp.weixin.qq.com/s/_WUusJBKMl7r-mm8Y-qgPA) - [ ] [《密码学》科普讲坛—第十一讲:密码·源于计算机害怕的数学求解问题](https://mp.weixin.qq.com/s/fkrt58L8VY03Bv59jVYdpQ) - [ ] [【竞赛通知】第四届全国大学生开源情报数据采集与分析挑战专项](https://mp.weixin.qq.com/s/c3eN7Fyg9cdAozHI6GvO_w) - [ ] [龙口公安破获三起涉网案件,查扣淫秽视频20余万部,非法获取数据逾9000万条](https://mp.weixin.qq.com/s/DbnVLv9HwGHAnNMaOf-nvg) - [ ] [卓尼公安破获非法控制微信账号案,抓获1人,查扣39部手机2台电脑](https://mp.weixin.qq.com/s/9k3Hi983H30f3K2KSteEHA) - [ ] [晋城沁水警方破获侵犯公民个人信息案,抓获6人,违法所得50余万元](https://mp.weixin.qq.com/s/Z6d-oOpd9daclx9bFeJ4zA) - LoRexxar's Blog | 信息技术分享 - [ ] [2026年了,核弹还是fastjson,fastjson1.2.83 RCE是怎么回事?](https://lorexxar.cn/2026/07/21/fs1-2-83rce/) - Private Feed for M09Ic - [ ] [esrrhs contributed to esrrhs/fakelua](https://github.com/esrrhs/fakelua/pull/266) - [ ] [anthropics released v2.1.217 at anthropics/claude-code](https://github.com/anthropics/claude-code/releases/tag/v2.1.217) - [ ] [bolucat released 202607212139 at bolucat/Archive](https://github.com/bolucat/Archive/releases/tag/202607212139) - [ ] [spf13 starred erichll/go-fast-note-sync](https://github.com/erichll/go-fast-note-sync) - [ ] [usestrix released v1.2.0 at usestrix/strix](https://github.com/usestrix/strix/releases/tag/v1.2.0) - [ ] [pydantic released v0.0.19-beta.5 at pydantic/monty](https://github.com/pydantic/monty/releases/tag/v0.0.19-beta.5) - [ ] [timwhitez forked timwhitez/open-reasoning from Linh-Ice/open-reasoning](https://github.com/timwhitez/open-reasoning) - [ ] [ourren starred bojieli/ai-agent-book](https://github.com/bojieli/ai-agent-book) - [ ] [liamg contributed to infracost/config](https://github.com/infracost/config/pull/23) - [ ] [liamg contributed to infracost/proto](https://github.com/infracost/proto/pull/85) - [ ] [gh0stkey starred acornjs/acorn](https://github.com/acornjs/acorn) - [ ] [CHYbeta starred baidu/Unlimited-OCR](https://github.com/baidu/Unlimited-OCR) - [ ] [mgeeky starred microsoft/SkillOpt](https://github.com/microsoft/SkillOpt) - obaby 𝐢𝐧⃝ void - [ ] [若生如野草](https://zhongxiaojie.cn/2026/07/1685/) - Tenable Blog - [ ] [Oracle July 2026 Critical Patch Update Addresses 1235 CVEs](https://www.tenable.com/blog/oracle-july-2026-critical-patch-update-addresses-1235-cves) - [ ] [Your AI agent’s config is now the payload: How attackers are targeting the developer agent harness](https://www.tenable.com/blog/ai-coding-assistant-agent-harness-attacks) - Recent Commits to cve:main - [ ] [Update Tue Jul 21 12:15:19 UTC 2026](https://github.com/trickest/cve/commit/3ffa2a96db84a89f71e1c7ad889e5f4fcc755a48) - ElcomSoft blog - [ ] [Digital Triage and the Rules of Evidence: What Holds Up, and Where](https://blog.elcomsoft.com/2026/07/digital-triage-and-the-rules-of-evidence-what-holds-up-and-where/) - Horizon3.ai - [ ] [Why Exposure Management Is Replacing Vulnerability Management](https://horizon3.ai/intelligence/blogs/exposure-vs-vulnerability-management/) - Securelist - [ ] [A new extortion cocktail: office printers, small ransoms, and BitLocker](https://securelist.com/new-extortion-scheme-printers-bitlocker/120718/) - [ ] [New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery](https://securelist.com/project-cav3rn-cyberespionage-framework-using-outlook-and-dns/120757/) - VMRay - [ ] [STIX and TAXII Explained: Threat Intelligence That Survives Ingestion](https://www.vmray.com/stix-taxii-explianed/) - [ ] [The Operational Guide to IOC Quality](https://www.vmray.com/the-operational-guide-to-ioc-quality/) - Malwarebytes - [ ] [What happens if you visit a WordPress site hacked through wp2shell?](https://www.malwarebytes.com/blog/bugs/2026/07/what-happens-if-you-visit-a-wordpress-site-hacked-through-wp2shell) - [ ] [New ClickLock Stealer locks your Mac until you hand over your password](https://www.malwarebytes.com/blog/news/2026/07/new-clicklock-stealer-locks-your-mac-until-you-hand-over-your-password) - [ ] [Don’t trust that “FBI agent” in your DMs](https://www.malwarebytes.com/blog/news/2026/07/dont-trust-that-fbi-agent-in-your-dms) - [ ] [AI nudify apps spark legal scrutiny of Apple and Google’s profits](https://www.malwarebytes.com/blog/privacy/2026/07/ai-nudify-apps-spark-legal-scrutiny-of-apple-and-googles-profits) - print("") - [ ] [Fastjson 1.2.83 漏洞分析](https://www.o2oxy.cn/4515.html) - HackerNews - [ ] [严重 7-Zip 漏洞:打开精心构造的 XZ 压缩文件即可导致代码执行,请立即更新](http://0.0.0.0:8080/post/64494) - [ ] [Ernst & Young 数据泄露事件影响个人及财务信息](http://0.0.0.0:8080/post/64493) - [ ] [黑客通过链下攻击从 Ostium 窃取 2370 万美元加密货币](http://0.0.0.0:8080/post/64492) - [ ] [SonicWall SMA1000 漏洞被作为零日漏洞利用以投放定制恶意软件](http://0.0.0.0:8080/post/64491) - [ ] [Estée Lauder 因 Oracle E-Business 漏洞披露数据泄露事件](http://0.0.0.0:8080/post/64490) - [ ] [俄罗斯情报机构入侵 IP 摄像头,监视北约国家和乌克兰境内的军事物流](http://0.0.0.0:8080/post/64489) - 黑海洋Wiki | AI机器人硬件开发 | 网络安全攻防实战 | 区块链技术文档教程 - 免费资源平台 - [ ] [OpenAI模型测试失控 引发史无前例入侵](https://blog.upx8.com/OpenAI%E6%A8%A1%E5%9E%8B%E6%B5%8B%E8%AF%95%E5%A4%B1%E6%8E%A7-%E5%BC%95%E5%8F%91%E5%8F%B2%E6%97%A0%E5%89%8D%E4%BE%8B%E5%85%A5%E4%BE%B5) - [ ] [苹果准备推出硬件租赁计划 欲刺激产品销售](https://blog.upx8.com/%E8%8B%B9%E6%9E%9C%E5%87%86%E5%A4%87%E6%8E%A8%E5%87%BA%E7%A1%AC%E4%BB%B6%E7%A7%9F%E8%B5%81%E8%AE%A1%E5%88%92-%E6%AC%B2%E5%88%BA%E6%BF%80%E4%BA%A7%E5%93%81%E9%94%80%E5%94%AE) - [ ] [英特尔“剑指”数据中心部门,准备裁员!](https://blog.upx8.com/%E8%8B%B1%E7%89%B9%E5%B0%94-%E5%89%91%E6%8C%87-%E6%95%B0%E6%8D%AE%E4%B8%AD%E5%BF%83%E9%83%A8%E9%97%A8-%E5%87%86%E5%A4%87%E8%A3%81%E5%91%98) - 奇客Solidot–传递最新科技情报 - [ ] [任天堂称它无法律义务将美国关税退款退给消费者](https://www.solidot.org/story?sid=84887) - [ ] [FBI 逮捕用假 Steam 游戏窃取玩家加密货币的 21 岁男子](https://www.solidot.org/story?sid=84886) - [ ] [流行野生动物数据库发现 AI 生成的假图](https://www.solidot.org/story?sid=84885) - [ ] [黑客利用刚释出补丁的漏洞入侵 WordPress 网站](https://www.solidot.org/story?sid=84884) - [ ] [欧盟对阿里巴巴罚款 5.5 亿欧元](https://www.solidot.org/story?sid=84883) - [ ] [科学家警告地球水体溶解氧迅速减少](https://www.solidot.org/story?sid=84882) - [ ] [鸡蛋价格创 10 年新高](https://www.solidot.org/story?sid=84881) - [ ] [美国科技巨头的隐性债务高达 1.65 万亿美元](https://www.solidot.org/story?sid=84880) - [ ] [Jellyfin 项目创始人辞职](https://www.solidot.org/story?sid=84879) - 黑鸟 - [ ] [一个专门销毁 AI 模型的勒索软件](https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451187756&idx=1&sn=a005bf4cc103dcfe28338505e04e9792) - 安全内参 - [ ] [AI攻击真实案例验证:中国模型比美国模型更适合做网络防御](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516294&idx=1&sn=048f366500a76988235c8a1ed254b8d5) - [ ] [美国海军部正式发布“数据和人工智能武器化”战略](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516294&idx=2&sn=50961ecabd77233034749f5057753acd) - 微步在线研究响应中心 - [ ] [已捕获攻击,Fastjson 远程代码执行漏洞二次更新](https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&mid=2247508767&idx=1&sn=a30a94ada407131159de8052f9145269) - 代码卫士 - [ ] [已存在15年之久的 NGINX 漏洞可导致RCE](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247526682&idx=1&sn=7610fee3a9f96ecb3c9e96f04db49188) - [ ] [【已复现】Fastjson 1.2.83 远程代码执行漏洞(QVD-2026-43021)安全风险通告第二次更新](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247526682&idx=2&sn=ec15c9ace9d49725ba668dd6da12949f) - [ ] [7-Zip 新漏洞可导致构造的 XZ 文档文件在解压过程中执行代码](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247526682&idx=3&sn=ecc7543242c5bf90b3396d150d52ce48) - 奶牛安全 - [ ] [数据泄露情报2026.7.21 - 找到了今年最火爆的黑客团伙网站shinyhunters](https://mp.weixin.qq.com/s?__biz=MzU4NjY0NTExNA==&mid=2247489872&idx=1&sn=cec72b6bef1121febc2acabe49d0ae7a) - 信安之路 - [ ] [关于 Fastjson 1.2.83 RCE 漏洞,看这一篇就够了,包含漏洞细节与影响面分析!](https://mp.weixin.qq.com/s?__biz=MzI5MDQ2NjExOQ==&mid=2247500626&idx=1&sn=dca535f3a68a0add8cba6b4b75cf8cdc) - 威努特安全网络 - [ ] [威努特网络安全解决方案:构建安全可信的医院网络安全防线](https://mp.weixin.qq.com/s?__biz=MzAwNTgyODU3NQ==&mid=2651143093&idx=1&sn=34cdffef81c018ff83010ab3a27afa45) - 安全客 - [ ] [你家门口的摄像头,可能正在替俄罗斯情报机构"站岗"](https://mp.weixin.qq.com/s?__biz=MzA5ODA0NDE2MA==&mid=2649790231&idx=1&sn=09246f047dbb5000f90b3fb7c155618a) - 绿盟科技CERT - [ ] [【漏洞通告】Fastjson 1.2.x无需gadget远程代码执行漏洞](https://mp.weixin.qq.com/s?__biz=Mzk0MjE3ODkxNg==&mid=2247492688&idx=1&sn=9a2d77050851934abb5d9cd375b6c2be) - 中国信息安全 - [ ] [专题·原创 | 油气行业人工智能供应链安全治理体系初探](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664264876&idx=1&sn=a6f1153244b7897a85055ae86504018a) - [ ] [国家安全部:让人工智能成为促进共同繁荣、维护共同安全的重要动力源](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664264876&idx=2&sn=b63028c2cb4e0ed9aaaa4a2a529c98b0) - [ ] [发布 | 《国际人工智能伦理治理行动计划》全文](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664264876&idx=3&sn=0fbcab68100c7e7572e1a2b1e655f4ac) - [ ] [关注 | 假冒人社部、雄安新区、蜜雪冰城等,759个网站被处置!](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664264876&idx=4&sn=56e65c1a4e8337040ecc55e2563a234e) - 微步在线 - [ ] [国际背书 跻身全球厂商名录,微步上榜两份 Gartner® 技术成熟度曲线报告](https://mp.weixin.qq.com/s?__biz=MzI5NjA0NjI5MQ==&mid=2650187152&idx=1&sn=9f5be9c905ffb451b02e62b529f5b760) - 天黑说嘿话 - [ ] [hvv 2026 - 字典扫不到的后台,AI 猜出来了:DEF CON 105 页拆解下一代 HVV 打点术](https://mp.weixin.qq.com/s?__biz=MzI5NTQ5MTAzMA==&mid=2247486259&idx=1&sn=4ac19392db769a58edb95dbcae8dc9c6) - 信息安全国家工程研究中心 - [ ] [强化风险意识 确保安全可控](https://mp.weixin.qq.com/s?__biz=MzU5OTQ0NzY3Ng==&mid=2247504470&idx=1&sn=30f04609318668cb04f6a2a886a3e81f) - 看雪学苑 - [ ] [2019-SUCTF-SUDriver 学习笔记](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458617685&idx=1&sn=ab68c9ebbdc5f6846975ed86822d674e) - [ ] [Hugging Face 遭 AI 智能体“自主攻破”,内部生产环境凭证泄露](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458617685&idx=2&sn=3576c99cbddde96deca2e8b6179c7eee) - [ ] [AI辅助逆向分析:不只是用工具,而是造工具](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458617685&idx=3&sn=2f837730003c0256f746ba24b414eda5) - 奇安信 CERT - [ ] [【已复现】Fastjson 1.2.83 远程代码执行漏洞(QVD-2026-43021)安全风险通告第二次更新](https://mp.weixin.qq.com/s?__biz=MzU5NDgxODU1MQ==&mid=2247506836&idx=1&sn=3d27e287c7014529ffc69619bcafa121) - 数世咨询 - [ ] [报告发布 |《全球数据泄露态势月度报告》(2026年6月)](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247543569&idx=1&sn=5e4aa8135c33812b8085cc00173c89ad) - 奇安信威胁情报中心 - [ ] [JADEPUFFER 进化论:AI 攻击者带着一把"为 AI 基础设施定制的锁"回归](https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247519540&idx=1&sn=1cd134c55bb62d78bb189eb115b4b1c9) - 长亭安全应急响应中心 - [ ] [【已支持检测&常见问题汇总】Fastjson 1.2.83 远程代码执行漏洞二次更新](https://mp.weixin.qq.com/s?__biz=MzIwMDk1MjMyMg==&mid=2247493266&idx=1&sn=2d09079d7c72f570bd9569981bfa06f0) - M01N Team - [ ] [AI安全案例分析 | MemGhost攻击通过邮件远程篡改AI记忆](https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&mid=2247495333&idx=1&sn=661baca2914cd61f2b09e6304896528d) - 安全圈 - [ ] [【安全圈】GPT写代码翻车,误删用户整个家目录](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652077939&idx=1&sn=5381d763b84770c20deb22302ca20975) - [ ] [【安全圈】僵尸网络盯上你的AI服务,偷的不是密码](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652077939&idx=2&sn=8717d6f95d60ebc935e12dfbe2fe606b) - [ ] [【安全圈】假验证码投放木马,这招正在全球扩散](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652077939&idx=3&sn=c1c22654d31e8ad03591b7bd78343174) - 吾爱破解论坛 - [ ] [【开放注册公告】吾爱破解论坛2026年7月21日暑假开放注册公告即将开始 12:00 -- 14:00 和 20:00 -- 22:00,论坛唯一地址:52pojie.cn...](https://mp.weixin.qq.com/s?__biz=MjM5Mjc3MDM2Mw==&mid=2651144646&idx=1&sn=41d925a51cf6b33211e3350a164f33da) - 青藤云安全 - [ ] [IDC报告:青藤蝉联中国私有云CWPP市场份额第一](https://mp.weixin.qq.com/s?__biz=MzAwNDE4Mzc1NA==&mid=2650851582&idx=1&sn=ccee95907ec492fd00fc3c937867a881) - 电子物证 - [ ] [【电子数据质证「两步分析法」】](https://mp.weixin.qq.com/s?__biz=MzAwNDcwMDgzMA==&mid=2651049054&idx=1&sn=994ced1d5b542fe79c3e4cab782d1eec) - [ ] [【专门性证据:构建以可靠性为核心的实质审查机制】](https://mp.weixin.qq.com/s?__biz=MzAwNDcwMDgzMA==&mid=2651049054&idx=2&sn=7345aeebf98a6233647965719a889216) - 天融信阿尔法实验室 - [ ] [【风险提示】天融信关于 Fastjson 1.2.83 默认配置下远程代码执行漏洞的风险提示](https://mp.weixin.qq.com/s?__biz=Mzg3MDAzMDQxNw==&mid=2247497072&idx=1&sn=8fca263a9a6d7154f01c872f45eeda83) - 复旦白泽战队 - [ ] [成果分享 | [ACM CCS 2026] PHPBench:自动化合成高质量Web漏洞基准数据集](https://mp.weixin.qq.com/s?__biz=MzU4NzUxOTI0OQ==&mid=2247499497&idx=1&sn=ae659465485d3c3071c926abe34c6969) - 漏洞战争 - [ ] [2026年AI顶会Agent技术综述](https://mp.weixin.qq.com/s?__biz=MzU0MzgzNTU0Mw==&mid=2247486132&idx=1&sn=f769d3ac7cf5df69da11227e88301e21) - 极客公园 - [ ] [6 个月、10 万台,零跑的「出海生意经」](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653110933&idx=1&sn=3bb0b050b48491774c40a949ca82545d) - [ ] [具身智能最大的幻觉,是先把人拿掉](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653110933&idx=2&sn=9a821447d352070a803e0ca546f9a1ab) - [ ] [3 年造出反应堆发电、估值 50 亿美元,这家创业公司要做「核电 SpaceX」](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653110918&idx=1&sn=34d060b46ac374172963dcddabaee0e0) - [ ] [智谱再跌近 20%,市值跌至 4146 亿港元;传 iPad mini 将迎重大升级;张雪机车预告首款「电摩」|极客早知道](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653110886&idx=1&sn=209a8075b9db432ec392e338d3a6a981) - 字节跳动技术团队 - [ ] [从生成到交付,音视频 Agent 要有生产级开发套件](https://mp.weixin.qq.com/s?__biz=MzI1MzYzMjE0MQ==&mid=2247521013&idx=1&sn=aab9641bb58a22244ce76d02dfda5156) - [ ] [30 分钟搞定个人情报站:Viking AI 搜索让前沿资讯实时推到面前](https://mp.weixin.qq.com/s?__biz=MzI1MzYzMjE0MQ==&mid=2247521013&idx=2&sn=5b131b80fc41bb583e9fc227484fbfe6) - 情报分析师 - [ ] [从一座新馆看朝鲜海外军事行动叙事](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650568771&idx=1&sn=add47404b853c56ffa52d48a08ef8d5c) - [ ] [美国用哪些具体招数和方法污名化我AI发展,强化我AI算力管制和遏制我模型“出海”](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650568771&idx=2&sn=91f100fcbb6c52e85324187b3a3c7f13) - Beacon Tower Lab - [ ] [漏洞预警丨WordPress Core 未授权远程代码执行漏洞(CVE-2026-60137)](https://mp.weixin.qq.com/s?__biz=MzkyNzcxNTczNA==&mid=2247488318&idx=1&sn=1cb8e928879c0fcccd787994b39edbdf) - 吴鲁加 - [ ] [1.3万研究生挤进一个星球,因为这个教授回问题不敷衍](https://mp.weixin.qq.com/s?__biz=Mzg5NDY4ODM1MA==&mid=2247486134&idx=1&sn=efc326b3b9d1c171806a861342f51e36) - 云鼎实验室 - [ ] [腾讯云安全已支持防护最新Fastjson远程代码执行漏洞](https://mp.weixin.qq.com/s?__biz=MzU3ODAyMjg4OQ==&mid=2247497827&idx=1&sn=3ec8c27389f00958493443b3d15cdfa4) - 火绒安全 - [ ] [披着 “主页保护” 外衣的劫持者:您的浏览器首页正被导流变现](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247535596&idx=1&sn=a942351afe73f7ddb75a3350f6cdd2ea) - [ ] [诚邀渠道合作伙伴共启新征程](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247535596&idx=2&sn=33e21c1bc34e6f7c86afcfee0a766e09) - TrustedSec - [ ] [The New Hotness in Phishing: Device Code Attacks in M365](https://trustedsec.com/blog/the-new-hotness-in-phishing-device-code-attacks-in-m365) - 360数字安全 - [ ] [360与朝阳区总工会共启ADE认证培训,协同打造人才培养“朝阳样板”](https://mp.weixin.qq.com/s?__biz=MzA4MTg0MDQ4Nw==&mid=2247586637&idx=1&sn=16d7b6e3d39afbfd840fb94b41853206) - [ ] [360支撑香港网络安全实战演练 服务近百个政府部门](https://mp.weixin.qq.com/s?__biz=MzA4MTg0MDQ4Nw==&mid=2247586637&idx=2&sn=e664fbddd85590821882c77b953b64b3) - Qualys Security Blog - [ ] [Manual Patching Can’t Outrun AI. Automated Remediation Can.](https://blog.qualys.com/category/product-tech) - [ ] [CVE-2026-8933: Local Privilege Escalation in Set-Capabilities snap-confine](https://blog.qualys.com/category/vulnerabilities-threat-research) - Securityinfo.it - [ ] [Hugging Face violata da un agente AI: gli attacchi autonomi sono arrivati](https://www.securityinfo.it/2026/07/21/hugging-face-violata-da-un-agente-ai-perche-il-primo-attacco-autonomo-segna-una-svolta-per-la-cybersecurity/?utm_source=rss&utm_medium=rss&utm_campaign=hugging-face-violata-da-un-agente-ai-perche-il-primo-attacco-autonomo-segna-una-svolta-per-la-cybersecurity) - SEI Blog - [ ] [A Quality Model for Machine Learning Components](https://www.sei.cmu.edu/blog/a-quality-model-for-machine-learning-components/?utm_source=blog&utm_medium=rss&utm_campaign=my_site_updates) - ICT Security Magazine - [ ] [ServiceNow, la RCE pre-autenticazione CVE-2026-6875 è sfruttata in the wild: istanze self-hosted da mettere in sicurezza](https://www.ictsecuritymagazine.com/notizie/servicenow-cve-2026-6875-rce-sfruttata/) - [ ] [Purple teaming: la difesa si misura una tecnica alla volta](https://www.ictsecuritymagazine.com/cyber-security/purple-teaming/) - Schneier on Security - [ ] [MIT to Become Hotbed of AI Video Surveillance](https://www.schneier.com/blog/archives/2026/07/mit-to-become-hotbed-of-ai-video-surveillance.html) - SANS Internet Storm Center, InfoCON: green - [ ] [Captive Portal Detection, (Tue, Jul 21st)](https://isc.sans.edu/diary/rss/33172) - [ ] [ISC Stormcast For Tuesday, July 21st, 2026 https://isc.sans.edu/podcastdetail/10016, (Tue, Jul 21st)](https://isc.sans.edu/diary/rss/33170) - Yak Project - [ ] [使用Memfit复现最新的Fastjson远程代码执行漏洞](https://mp.weixin.qq.com/s?__biz=Mzk0MTM4NzIxMQ==&mid=2247530009&idx=1&sn=101c81bd3b9b13aa9cff78872e481180) - Tor Project blog - [ ] [New Release: Tor Browser 15.0.19](https://blog.torproject.org/new-release-tor-browser-15019/) - Full Disclosure - [ ] [ASUS bsitf.sys (CVE-2026-13585): Arbitrary Physical Memory Mapping in ASUS Business/Software Manager kernel driver](https://seclists.org/fulldisclosure/2026/Jul/26) - [ ] [New Release: UFONet v2.0 - "R3DST4R!"...](https://seclists.org/fulldisclosure/2026/Jul/25) - [ ] [XSSer v.1.9 - "Bl4ck Swarm!" released](https://seclists.org/fulldisclosure/2026/Jul/24) - [ ] [NotCVE registry index — public records of vulnerabilities that shipped without a CVE](https://seclists.org/fulldisclosure/2026/Jul/23) - The Hacker News - [ ] [Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs](https://thehackernews.com/2026/07/apple-fixes-hide-my-email-bug-that.html) - [ ] [AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code](https://thehackernews.com/2026/07/aws-kiro-flaw-let-poisoned-web-page.html) - [ ] [Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities](https://thehackernews.com/2026/07/google-launches-gemini-35-flash-cyber.html) - [ ] [Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC](https://thehackernews.com/2026/07/critical-sharepoint-rce-cve-2026-50522.html) - [ ] [Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access](https://thehackernews.com/2026/07/qilin-ransomware-attackers-exploit-pan.html) - [ ] [Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities](https://thehackernews.com/2026/07/zimbra-patches-critical-snmp-command.html) - [ ] [Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs](https://thehackernews.com/2026/07/open-source-android-ai-agents-could-let.html) - [ ] [N-day is Becoming N-Hour. Patching Faster Won't Save You.](https://thehackernews.com/2026/07/n-day-is-becoming-n-hour-patching.html) - [ ] [New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit](https://thehackernews.com/2026/07/new-bit2watt-attack-could-let-cloud.html) - [ ] [WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning](https://thehackernews.com/2026/07/wordpress-wp2shell-exploitation-grows.html) - [ ] [New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack](https://thehackernews.com/2026/07/new-encforge-ransomware-targets-ai.html) - [ ] [Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution](https://thehackernews.com/2026/07/critical-servicenow-ai-platform-flaw.html) - 国家互联网应急中心CNCERT - [ ] [CNVD漏洞周报2026年第28期](https://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw==&mid=2247501894&idx=1&sn=03478f7d71c61599ba07c61c9bda51f0) - GRAHAM CLULEY - [ ] [Ukraine warns fake CAPTCHAs are being used to make you hack yourself](https://www.bitdefender.com/en-us/blog/hotforsecurity/ukraine-fake-captchas-hack-yourself) - Trend Micro Research, News and Perspectives - [ ] [Volume Is Not Risk: Making Sense of the “Vulnpocalypse”](https://www.trendmicro.com/en_us/research/26/g/making-sense-of-the-vulnpocalypse.html) - NetSPI - [ ] [Azure VM Command Execution using Third-Party Extensions – Chef](https://www.netspi.com/blog/technical-blog/cloud-pentesting/azure-vm-command-execution-using-third-party-extensions/) - Security Affairs - [ ] [Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522](https://securityaffairs.com/195760/security/public-poc-triggers-active-exploitation-of-critical-sharepoint-rce-vulnerability-cve-2026-50522.html) - [ ] [Zimbra 10.1.20 patches multiple security issues, including a critical command injection bug](https://securityaffairs.com/195752/security/zimbra-10-1-20-patches-multiple-security-issues-including-a-critical-command-injection-bug.html) - [ ] [Qilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN Access](https://securityaffairs.com/195730/cyber-crime/qilin-ransomware-affiliates-abuse-cve-2026-0257-to-gain-unauthorized-vpn-access.html) - [ ] [Attackers Exploit Critical ServiceNow RCE Flaw CVE-2026-6875](https://securityaffairs.com/195723/ai/attackers-exploit-critical-servicenow-rce-flaw-cve-2026-6875.html) - Troy Hunt's Blog - [ ] [Weekly Update 513: Clauding The Home Network](https://www.troyhunt.com/weekly-update-513/) - www.theregister.com - Articles - [ ] [Cisco's open-weight bug busters take on Google and OpenAI](https://www.theregister.com/security/2026/07/21/ciscos-open-weight-bug-busters-take-on-google-and-openai/5275817) - [ ] [AI's cheatin' heart will make you weep](https://www.theregister.com/ai-and-ml/2026/07/21/ais-cheatin-heart-will-make-you-weep/5275784) - [ ] [Kratos phishing-as-a-service kit loses its battle with international law enforcement](https://www.theregister.com/security/2026/07/21/german-authorities-lead-takedown-of-kratos-phishing-platform/5275666) - [ ] [AI music platform Suno hits bum note as 55M users exposed in data breach, claims infosec expert](https://www.theregister.com/security/2026/07/21/breach-of-ai-music-platform-suno-affected-55m-user-accounts/5275514) - [ ] [Intel fortifies Foundry with an actual customer: Fortinet](https://www.theregister.com/systems/2026/07/21/intel-fortifies-foundry-with-an-actual-customer-fortinet/5275374) - [ ] [OVH reveals semi-secret plan to fix critical Januscape hypervisor bug with mass reboots – and an Australian crash-test dummy](https://www.theregister.com/virtualization/2026/07/21/ovh-reveals-semi-secret-plan-to-fix-critical-januscape-hypervisor-bug-with-mass-reboots-and-an-australian-crash-test-dummy/5275359) - Security Weekly Podcast Network (Audio) - [ ] [LegacyHive, ACR Stealer, Hugging Face, Route 53, and Kieran Human from Threatlocker - Kieran Human - SWN #600](http://sites.libsyn.com/18678/legacyhive-acr-stealer-hugging-face-route-53-and-kieran-human-from-threatlocker-kieran-human-swn-600) - [ ] [MacOS Security Design Features, Flaws, And Futures - Patrick Wardle - ASW #392](http://sites.libsyn.com/18678/macos-security-design-features-flaws-and-futures-patrick-wardle-asw-392)
每日安全资讯(2026-07-22)