# 每日安全资讯(2026-07-25) - SecWiki News - [ ] [SecWiki News 2026-07-24 Review](http://www.sec-wiki.com/?2026-07-24) - Paper - 知道创宇404实验室 - [ ] [自托管 AI 智能体的自状态攻击:操作系统防御能走多远?](https://paper.seebug.org/3506) - Private Feed for M09Ic - [ ] [strands-agents released typescript/v1.11.1 at strands-agents/harness-sdk](https://github.com/strands-agents/harness-sdk/releases/tag/typescript/v1.11.1) - [ ] [bolucat released 202607242137 at bolucat/Archive](https://github.com/bolucat/Archive/releases/tag/202607242137) - [ ] [wuhan005 made this repository public](https://github.com/wuhan005/paperang-p1) - [ ] [Rvn0xsy starred rhel-lightspeed/linux-mcp-server](https://github.com/rhel-lightspeed/linux-mcp-server) - [ ] [anthropics released v2.1.219 at anthropics/claude-code](https://github.com/anthropics/claude-code/releases/tag/v2.1.219) - [ ] [0xbug starred THU-MAIC/OpenMAIC](https://github.com/THU-MAIC/OpenMAIC) - [ ] [spf13 starred ogulcancelik/herdr](https://github.com/ogulcancelik/herdr) - [ ] [0xbug starred chrisguidry/docket](https://github.com/chrisguidry/docket) - [ ] [strands-agents released python/v1.50.0 at strands-agents/harness-sdk](https://github.com/strands-agents/harness-sdk/releases/tag/python/v1.50.0) - [ ] [Ridter starred sliverarmory/beignet](https://github.com/sliverarmory/beignet) - [ ] [Ridter forked Ridter/CVE-2026-54121 from aniqfakhrul/CVE-2026-54121](https://github.com/Ridter/CVE-2026-54121) - [ ] [esrrhs starred zai-org/CogView](https://github.com/zai-org/CogView) - [ ] [safedv starred MatheuZSecurity/Furtex](https://github.com/MatheuZSecurity/Furtex) - [ ] [ManassehZhou starred apple/container](https://github.com/apple/container) - [ ] [pydantic released v0.0.19 at pydantic/monty](https://github.com/pydantic/monty/releases/tag/v0.0.19) - [ ] [mgeeky starred unclebob/swarm-forge](https://github.com/unclebob/swarm-forge) - [ ] [LoRexxar starred Nnoggie/MythicDungeonTools](https://github.com/Nnoggie/MythicDungeonTools) - [ ] [Rvn0xsy starred obra/superpowers](https://github.com/obra/superpowers) - [ ] [CHYbeta starred HKUDS/Vibe-Trading](https://github.com/HKUDS/Vibe-Trading) - [ ] [TideSec starred vxcontrol/pentagi](https://github.com/vxcontrol/pentagi) - [ ] [4ra1n starred iss4cf0ng/Alien](https://github.com/iss4cf0ng/Alien) - Doonsec's feed - [ ] [Certighost(CVE-2026-54121)](https://mp.weixin.qq.com/s/YeqxnLoGDB1v6aCDYBgN3w) - [ ] [国家网信办、公安部联合公布《小型个人信息处理者个人信息保护简化措施规定》](https://mp.weixin.qq.com/s/0rdP2YiQYNqT1cw1vPN5EA) - [ ] [第171篇:蓝队分析取证工具箱 V4.36 AI智能研判增强版,大幅度更新](https://mp.weixin.qq.com/s/doozZsk3md7HNRnhHvwPWQ) - [ ] [那些“隐藏”的电脑贴纸,揭示了笔记本电脑标识背后的真实性能含义](https://mp.weixin.qq.com/s/8Q_8UFUFE_Pkyt1SBkzDEA) - [ ] [DeepSentry v2.0.2 Ultimate 正式发布:让安全 Agent 更稳定、更可控、更适合真实环境](https://mp.weixin.qq.com/s/DzL48iZESTzQrEz9AUtZwQ) - [ ] [李乐成出席亚太经合组织数智赋能高级别对话](https://mp.weixin.qq.com/s/kQY8NqeEnM9J0EGEOyHFOQ) - [ ] [9月1日起施行 !《小型个人信息处理者个人信息保护简化措施规定》发布(附答记者问)](https://mp.weixin.qq.com/s/svnnlcrN5U1TWNZPP89GDQ) - [ ] [会议预告 | 第一届CCF网络与系统安全大会嘉宾阵容揭晓](https://mp.weixin.qq.com/s/7Hl4-J9LbziO1npjJI20XA) - [ ] [连续三年霸榜,这才是真正的“闭眼入”产品](https://mp.weixin.qq.com/s/VaWplTLy1GGqhN1eapx-RA) - [ ] [AI快讯:福建深化金融AI+应用,Visa、连连完成AI智能体支付,月之暗面回应蒸馏质疑](https://mp.weixin.qq.com/s/xKOeh7xpA9Yx0H35TreGTw) - [ ] [离谱,网安人的薪资差别真的很大…](https://mp.weixin.qq.com/s/3hqNaeUeioSZ0hDg2IwhzA) - [ ] [数智技术驱动碳管理 透明可信铸就新范式——第二十八届中国科协年会专题论坛在京举行](https://mp.weixin.qq.com/s/4Ey7fGcatrDERyxVkBTmUA) - [ ] [AI告警疯狂刷屏!SOC最大危机为何不是技术,而可能是人扛不住了?](https://mp.weixin.qq.com/s/UzvDCmiPs3qoGtJHAUCyeQ) - [ ] [小型个人信息处理者个人信息保护简化措施规定](https://mp.weixin.qq.com/s/UV8u9j8lPXGBUNs94DxvFw) - [ ] [AI模型自主逃逸攻击实锤:只靠提示词防护根本守不住企业数据](https://mp.weixin.qq.com/s/wItQDyUnnDib5LDresvSqg) - [ ] [五连冠!奇安信再次稳居《网络安全企业100强》第一名](https://mp.weixin.qq.com/s/Kx7vOssVBEwUPiK5ExYiAg) - [ ] [奇安信斩获中国信通院“SD-WAN+信创”领航计划优秀案例](https://mp.weixin.qq.com/s/43K4PJl1Y7NXAW8oVZAOVQ) - [ ] [安全聘 | 小鹏汽车招人啦](https://mp.weixin.qq.com/s/qLR1NTu7hUlINSSIiDBIog) - [ ] [兰德公司报告称人工智能或解除战略性网络攻击的三维制约](https://mp.weixin.qq.com/s/Zv7vIpOFh9Uq9IK_3zCi5Q) - [ ] [零基础如何靠挖漏洞拿下5位数赏金?这份网络安全进阶路线图请收好!](https://mp.weixin.qq.com/s/uzZ89X-BG-wExcRo7bdOqg) - [ ] [黑客](https://mp.weixin.qq.com/s/5Z8sXjFJIlROKZGw7ESDgw) - [ ] [咱们的产品命名一定要这样吗?](https://mp.weixin.qq.com/s/fJoCsmJ_oTZ4bBf9mn6D7w) - [ ] [Redis身份认证后远程代码执行漏洞通告【已复现】](https://mp.weixin.qq.com/s/B68WNHqi5RiBNiohd04b3w) - Der Flounder - [ ] [Session videos now available from Penn State MacAdmins Conference 2026](https://derflounder.wordpress.com/2026/07/24/session-videos-now-available-from-penn-state-macadmins-conference-2026/) - ElcomSoft blog - [ ] [Why Digital Forensic Reports Don’t Survive Cross-Examination](https://blog.elcomsoft.com/2026/07/why-digital-forensic-reports-dont-survive-cross-examination/) - obaby 𝐢𝐧⃝ void - [ ] [折耳兔](https://zhongxiaojie.cn/2026/07/1703/) - Recent Commits to cve:main - [ ] [Update Fri Jul 24 12:08:19 UTC 2026](https://github.com/trickest/cve/commit/d4b28c21b943332687c38515600e40190ff00a4e) - 安全客-有思想的安全新媒体 - [ ] [OpenAI智能体逃逸事件是AI时代的分水岭](https://www.anquanke.com/post/id/315851) - LoRexxar's Blog | 信息技术分享 - [ ] [Wordpress wp2shell 未授权RCE(CVE-2026-63030 / CVE-2026-60137)](https://lorexxar.cn/2026/07/24/wp2shell/) - Armin Ronacher's Thoughts and Writings - [ ] [Codeberg Divides](https://lucumr.pocoo.org/2026/7/24/codeberg-divides/) - Sandfly Security Blog RSS Feed - [ ] [Agentless Linux EDR: Stopping Volt and Salt Typhoon in OT Environments](https://sandflysecurity.com/blog/agentless-linux-edr-stopping-volt-and-salt-typhoon-in-ot-environments) - SentinelOne - [ ] [The Good, the Bad and the Ugly in Cybersecurity – Week 30](https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-30-8/) - [ ] [Your Best Analyst Shouldn’t Be a Person. It Should Be a Capability Everyone Can Summon.](https://www.sentinelone.com/blog/your-best-analyst-shouldnt-be-a-person-it-should-be-a-capability-everyone-can-summon/) - CCC Event Blog - [ ] [NooK 2026: Call for Participation](https://events.ccc.de/2026/07/24/nook/) - Malwarebytes - [ ] [Don’t get fooled by TikTok resin art scams](https://www.malwarebytes.com/blog/scams/2026/07/dont-get-fooled-by-tiktok-resin-art-scams) - [ ] [Call of Duty Mobile scam uses fake free points to steal player accounts](https://www.malwarebytes.com/blog/threat-intel/2026/07/call-of-duty-mobile-scam-uses-fake-free-points-to-steal-player-accounts) - [ ] [OpenAI’s agent escaped its sandbox during a security test](https://www.malwarebytes.com/blog/news/2026/07/openais-agent-escaped-its-sandbox-during-a-security-test) - [ ] [Google wants to store a selfie video of your face](https://www.malwarebytes.com/blog/privacy/2026/07/google-wants-to-store-a-selfie-video-of-your-face) - [ ] [Beyond the Play Store: How Android threats really spread](https://www.malwarebytes.com/blog/inside-malwarebytes/2026/07/beyond-the-play-store-how-android-threats-really-spread) - 黑海洋Wiki | AI机器人硬件开发 | 网络安全攻防实战 | 区块链技术文档教程 - 免费资源平台 - [ ] [Anthropic上新Opus 5,性能逼近Fable 5](https://blog.upx8.com/Anthropic%E4%B8%8A%E6%96%B0Opus-5-%E6%80%A7%E8%83%BD%E9%80%BC%E8%BF%91Fable-5) - [ ] [揭秘中国全力追赶美国AI芯片的攻坚内幕](https://blog.upx8.com/%E6%8F%AD%E7%A7%98%E4%B8%AD%E5%9B%BD%E5%85%A8%E5%8A%9B%E8%BF%BD%E8%B5%B6%E7%BE%8E%E5%9B%BDAI%E8%8A%AF%E7%89%87%E7%9A%84%E6%94%BB%E5%9D%9A%E5%86%85%E5%B9%95) - [ ] [上海交大团队被指未披露动物实验风险,《Nature》发文后曝临床基因编辑致6岁女孩死亡](https://blog.upx8.com/%E4%B8%8A%E6%B5%B7%E4%BA%A4%E5%A4%A7%E5%9B%A2%E9%98%9F%E8%A2%AB%E6%8C%87%E6%9C%AA%E6%8A%AB%E9%9C%B2%E5%8A%A8%E7%89%A9%E5%AE%9E%E9%AA%8C%E9%A3%8E%E9%99%A9-Nature-%E5%8F%91%E6%96%87%E5%90%8E%E6%9B%9D%E4%B8%B4%E5%BA%8A%E5%9F%BA%E5%9B%A0%E7%BC%96%E8%BE%91%E8%87%B46%E5%B2%81%E5%A5%B3%E5%AD%A9%E6%AD%BB%E4%BA%A1) - [ ] [特朗普推动科技巨头承诺自行承担AI数据中心新增电力成本](https://blog.upx8.com/%E7%89%B9%E6%9C%97%E6%99%AE%E6%8E%A8%E5%8A%A8%E7%A7%91%E6%8A%80%E5%B7%A8%E5%A4%B4%E6%89%BF%E8%AF%BA%E8%87%AA%E8%A1%8C%E6%89%BF%E6%8B%85AI%E6%95%B0%E6%8D%AE%E4%B8%AD%E5%BF%83%E6%96%B0%E5%A2%9E%E7%94%B5%E5%8A%9B%E6%88%90%E6%9C%AC) - [ ] [菲尔兹奖得主邓煜谈人工智能:已能帮助数学证明,但不能替代独立思考](https://blog.upx8.com/%E8%8F%B2%E5%B0%94%E5%85%B9%E5%A5%96%E5%BE%97%E4%B8%BB%E9%82%93%E7%85%9C%E8%B0%88%E4%BA%BA%E5%B7%A5%E6%99%BA%E8%83%BD-%E5%B7%B2%E8%83%BD%E5%B8%AE%E5%8A%A9%E6%95%B0%E5%AD%A6%E8%AF%81%E6%98%8E-%E4%BD%86%E4%B8%8D%E8%83%BD%E6%9B%BF%E4%BB%A3%E7%8B%AC%E7%AB%8B%E6%80%9D%E8%80%83) - HackerNews - [ ] [核破坏恶意软件基准测试难倒了大多数前沿 AI 模型](http://0.0.0.0:8080/post/64510) - [ ] [黑客滥用 Notepad++ 插件悄然安装恶意软件](http://0.0.0.0:8080/post/64509) - [ ] [澳大利亚能源供应商 Origin 称数据泄露事件暴露客户数据](http://0.0.0.0:8080/post/64508) - [ ] [俄罗斯间谍组织利用 Zimbra 零日漏洞窃取邮件和 2FA 代码](http://0.0.0.0:8080/post/64507) - [ ] [新型 Dolphin X 恶意软件利用 AI 对高价值目标进行评分排名](http://0.0.0.0:8080/post/64512) - [ ] [美国警告:伊朗黑客瞄准 Siemens、Schneider 和 Rockwell 的 ICS 设备](http://0.0.0.0:8080/post/64511) - Dancho Danchev's Blog - Mind Streams of Information Security Knowledge - [ ] [Malware Phone Back C&Cs (Command and Control) Domains for Media Land Bulletproof Hosting Provider Themed Malicious Software - An Analysis](https://ddanchev.blogspot.com/2026/07/malware-phone-back-c-command-and.html) - 绿盟科技技术博客 - [ ] [有准可循 互联互通 | 《大模型安全网关产品安全指南》国标项目启动会顺利召开](https://blog.nsfocus.net/%e6%9c%89%e5%87%86%e5%8f%af%e5%be%aa-%e4%ba%92%e8%81%94%e4%ba%92%e9%80%9a-%e3%80%8a%e5%a4%a7%e6%a8%a1%e5%9e%8b%e5%ae%89%e5%85%a8%e7%bd%91%e5%85%b3%e4%ba%a7%e5%93%81%e5%ae%89%e5%85%a8%e6%8c%87/) - [ ] [全国工商联领导一行莅临绿盟科技调研指导,共商安全产业发展新路径](https://blog.nsfocus.net/%e5%85%a8%e5%9b%bd%e5%b7%a5%e5%95%86%e8%81%94%e9%a2%86%e5%af%bc%e4%b8%80%e8%a1%8c%e8%8e%85%e4%b8%b4%e7%bb%bf%e7%9b%9f%e7%a7%91%e6%8a%80%e8%b0%83%e7%a0%94%e6%8c%87%e5%af%bc%ef%bc%8c%e5%85%b1%e5%95%86/) - 奇客Solidot–传递最新科技情报 - [ ] [IRGC 声称摧毁了亚马逊巴林数据中心](https://www.solidot.org/story?sid=84919) - [ ] [印度政府命令 GitHub 移除 Jack Dorsey 的蓝牙聊天应用 Bitchat](https://www.solidot.org/story?sid=84918) - [ ] [Google 账号支持自拍人脸登录](https://www.solidot.org/story?sid=84917) - [ ] [LG 显示器应用不再弹出迈克菲广告](https://www.solidot.org/story?sid=84916) - [ ] [美国初创公司反对禁止使用中国开放权重模型](https://www.solidot.org/story?sid=84915) - [ ] [GLP-1 减肥药与脱发相关](https://www.solidot.org/story?sid=84914) - [ ] [人类预期寿命增长,但不健康寿命更长](https://www.solidot.org/story?sid=84913) - [ ] [女孩接受基因编辑手术后死亡](https://www.solidot.org/story?sid=84912) - [ ] [古代语言的多样性远超今日](https://www.solidot.org/story?sid=84911) - 黑鸟 - [ ] [新型恶意广告攻击:在浏览器里现场组装恶意软件](https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451187797&idx=1&sn=10be81e53cbb8e4b8c8268074191fe22) - 雷神众测 - [ ] [【福利升级】雷神众测重金悬赏!最新激励计划发布,快来霸榜!](https://mp.weixin.qq.com/s?__biz=MzI0NzEwOTM0MA==&mid=2652503882&idx=1&sn=c48c301537f4b4d01e66a280b20bb464) - 安全客 - [ ] [OpenAI智能体逃逸事件是AI时代的分水岭](https://mp.weixin.qq.com/s?__biz=MzA5ODA0NDE2MA==&mid=2649790260&idx=1&sn=216f65d5555ab284345441ce24e08a0f) - 代码卫士 - [ ] [Exim 目录遍历漏洞可导致提权攻击](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247526724&idx=1&sn=e450a187189ae76bc556333fbc37648d) - [ ] [Claude Cowork 漏洞可导致虚拟机逃逸,访问Mac 文件](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247526724&idx=2&sn=0a25dcdaee8bc34e615e2810c85393ef) - 安全内参 - [ ] [黑客用偷来的数据‘零元购’,这家上市公司损失超8800万元](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516318&idx=1&sn=7b42de268ce1b4b7c4f2fb317e79ff86) - [ ] [兰德公司报告称人工智能或解除战略性网络攻击的三维制约](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516318&idx=2&sn=9d1ccb07dc385b16d5fe4e0a1a3557d8) - 灾难控制 局 - [ ] [招聘资深移动安全工程师](https://mp.weixin.qq.com/s?__biz=MzI1NTc1NTcwNg==&mid=2247484514&idx=1&sn=f53c5a5e98e6a9825ab38530636e0507) - 青衣十三楼飞花堂 - [ ] [被老外误认为腾达售后](https://mp.weixin.qq.com/s?__biz=MzUzMjQyMDE3Ng==&mid=2247489784&idx=1&sn=044986bd45f10b69a5d19a343556f59f) - 威努特安全网络 - [ ] [筑牢医疗网络防线:医院勒索病毒完整防护解决方案](https://mp.weixin.qq.com/s?__biz=MzAwNTgyODU3NQ==&mid=2651143202&idx=1&sn=e97d71ab06a54748225bc078af16033f) - 奇安信威胁情报中心 - [ ] [每周高级威胁情报解读(2026.07.17~07.23)](https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247519588&idx=1&sn=3c8bf8f8a216731bcbb88404f15558fa) - 看雪学苑 - [ ] [Android 内核无痕 Hook 框架设计思路和避坑经验](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458617790&idx=1&sn=7b3e3b422fc5920c4e8c99bf8f5ef76a) - [ ] [AI代理90分钟挖出19个Redis零日?Kimi K3再曝RCE利用链](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458617790&idx=2&sn=a5bd468f11bd6ba992a4c51df69aec0a) - [ ] [60-70K!高薪招智驾安全、IoT 渗透、大模型安全工程师](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458617790&idx=3&sn=d9d9ba528a275b385fef04c094d6c3b9) - 绿盟科技研究通讯 - [ ] [【公益译文】2026年AI指数报告(八)](https://mp.weixin.qq.com/s?__biz=MzIyODYzNTU2OA==&mid=2247500087&idx=1&sn=13bfb04dff6933146e288fd83e0a2d48) - 奇安信 CERT - [ ] [安全热点周报:“WP2Shell”使数百万个 WordPress 网站面临远程接管的风险](https://mp.weixin.qq.com/s?__biz=MzU5NDgxODU1MQ==&mid=2247506889&idx=1&sn=df2a047f998bc66fba76401fe88357d6) - 信息安全国家工程研究中心 - [ ] [OpenAI承认其模型失控 专家:AI安全治理迫在眉睫](https://mp.weixin.qq.com/s?__biz=MzU5OTQ0NzY3Ng==&mid=2247504505&idx=1&sn=5c30e75ca85f95ee69bb50e89853031e) - 天黑说嘿话 - [ ] [【88VIP专属高返小助手】领隐藏优惠券指定入口,购物省钱操作指南~24小时自助查券返利机器人!](https://mp.weixin.qq.com/s?__biz=MzI5NTQ5MTAzMA==&mid=2247486271&idx=1&sn=019b5d1e989969c844a8e9df60166d26) - 安全圈 - [ ] [【安全圈】数百万辆车可被远程熄火!这个漏洞比你想的更恐怖](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652077973&idx=3&sn=80897a1548847b963e2ede10cd064e0c) - [ ] [【安全圈】AI加持的俄语黑客组织,正在发动"降维打击"](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652077973&idx=2&sn=52ffb7d625efdc1df3a75c3602d5b0f6) - XCTF联赛 - [ ] [火热报名中丨第四届“天网杯”网络安全大赛正式起航!](https://mp.weixin.qq.com/s?__biz=MjM5NDU3MjExNw==&mid=2247516600&idx=1&sn=d54f44ec8cf0caaa5ef7f352b7e09899) - 数世咨询 - [ ] [补丁没死,但不再是核心防御手段](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247543605&idx=1&sn=68ba9ebe93a2a6cbb6388645bd58f0c4) - 中国信息安全 - [ ] [发布 | 国家网信办、公安部联合公布《小型个人信息处理者个人信息保护简化措施规定》(附全文)](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265034&idx=1&sn=08e19f38a38a3cf606d2aa152744bdb2) - [ ] [专家解读 | 杜阿宁:减负增效精准合规 护航中小微企业发展](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265034&idx=2&sn=995179273506e9337c69631e8b18fd99) - [ ] [公安部:国际打击电信网络诈骗联盟即将成立](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265034&idx=3&sn=ca4625bfd46564fe7bf42feb0db2a348) - [ ] [通知 | 《网络安全标准实践指南——网络数据安全风险评估采信指南(征求意见稿)》公开征求意见](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265034&idx=4&sn=88b0c551933d60ec9179dae9484e757f) - [ ] [速查!火车订票助手、票星球等35款App违法违规收集使用个人信息](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265034&idx=5&sn=0976842095881f7ed7bb6eb49fe19a6c) - [ ] [倡导和衷共济 完善全球治理——携手构建公正合理的全球人工智能治理体系述评](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265034&idx=6&sn=81621145bdfebe62e5c0e9881b4fad36) - [ ] [评论 | 打击防范“云养经济”领域新骗局](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265034&idx=7&sn=dbdc9e77c7c04a4060186392d2f71f64) - 安全研究GoSSIP - [ ] [G.O.S.S.I.P 特别推荐 2026-07-24 “千里码”安全漏洞](https://mp.weixin.qq.com/s?__biz=Mzg5ODUxMzg0Ng==&mid=2247501882&idx=1&sn=288ad43b9c6ea1554a94c7dd61473d7e) - M01N Team - [ ] [每周蓝军技术推送(2026.7.18-7.24)](https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&mid=2247495341&idx=1&sn=ce2d9c04177ce301b3dc89e09c9df067) - 安全牛 - [ ] [从一则真实入侵案例:看懂 AI 辅助域侦察攻击的防御新思路](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142060&idx=1&sn=70d099aba8cbdfbdd0a00291c16802d0) - [ ] [CNVD发布上周漏洞周报:上周新增漏洞 2613 个数量大幅反弹;Google将CodeMender推向企业,AI实现漏洞验证与自动修复| 牛览](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142060&idx=2&sn=af18310d2c276b39f3d8578227ed9fa1) - 极客公园 - [ ] [能实时改变的剧情、会行动的 AI 角色,Vivix 灵动时刻正式发布首个实时互动模型](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653111161&idx=1&sn=de3a1243dfea6ca033d69e94e6ad8ee9) - [ ] [对话格式塔彭雷:AI 的下一站,是解读人的大脑](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653111090&idx=1&sn=a3a0a8f4ef28bb93cdc593f86aae7fbc) - [ ] [任正非:τ定律是华为唯一出路;中国青年数学家王虹、邓煜获「数学界诺奖」;月之暗面负责人:Kimi K3 并非蒸馏现有模型 | 极客早知道](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653111084&idx=1&sn=f60fdbb7fba0569d184ef53191aa109b) - 奇安信病毒响应中心 - [ ] [每周勒索威胁摘要](https://mp.weixin.qq.com/s?__biz=MzI5Mzg5MDM3NQ==&mid=2247498627&idx=1&sn=8ab52434e6e7a6f852b4890294d7d2f9) - 情报分析师 - [ ] [一架没起飞的直升机,从"送娃打球"看穿特勤局的系统性崩溃](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650568857&idx=1&sn=d446bea5f866e40e840f353abb3ceffb) - [ ] [吉尔吉斯斯坦2026年国家风险评估报告](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650568857&idx=2&sn=4bb2dbd4bce7b23dd6719bcf2db24ba6) - 火绒安全 - [ ] [防窃密可溯源 火绒构建终端数据安全审计完整防线](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247535686&idx=1&sn=2892e1b840da29fdabe1cb065c14ffcc) - [ ] [火绒小问答——「企业版」Syslog数据导出](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247535686&idx=2&sn=a70fdd990321ea2b41bb71b49d38ee02) - [ ] [【火绒安全周报】AI失控后入侵知名企业/韩国外交系统遭黑客攻击](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247535686&idx=3&sn=3138a7a7415dfd72a974965c89bcc2f2) - [ ] [诚邀渠道合作伙伴共启新征程](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247535686&idx=4&sn=ff4649e226fbf4730f4f635f80130541) - 慢雾科技 - [ ] [威胁情报|从“合规邮件”到远程控制:一起 Web3 钱包钓鱼攻击调查](https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&mid=2247505575&idx=1&sn=f5c8cbe11335ece187b152860e7314bd) - TrustedSec - [ ] [CCPA Update: Cybersecurity Requirements (Part 2)](https://trustedsec.com/blog/ccpa-update-cybersecurity-requirements-part-2) - 云鼎实验室 - [ ] [2026安全新趋势:AI Agent以三种角色进入攻击链](https://mp.weixin.qq.com/s?__biz=MzU3ODAyMjg4OQ==&mid=2247497839&idx=1&sn=721eab6074c3340089b229c1ae187b0c) - 国家互联网应急中心CNCERT - [ ] [关于Dysphoria僵尸网络大范围传播的风险提示](https://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw==&mid=2247501926&idx=1&sn=1e774dc00d4705bc952fef7bd9f05890) - LR的安全自留地 - [ ] [Wordpress7.0 wp2shell 未授权RCE(CVE-2026-63030 / CVE-2026-60137)](https://mp.weixin.qq.com/s?__biz=MzkwNzMyNjU0MQ==&mid=2247484346&idx=1&sn=749018d8cbde606a72975d9cdadd6915) - 纽创信安 - [ ] [SGS为纽创信安颁发ISO/SAE 21434:2021汽车网络安全流程证书](https://mp.weixin.qq.com/s?__biz=MzAwNTczMjAzMg==&mid=2650241904&idx=1&sn=29a8f7902c9c5ae646caae25b93ca853) - Yak Project - [ ] [躺着也能搞安全?Memfit / Yakit AI支持接入飞书钉钉了!](https://mp.weixin.qq.com/s?__biz=Mzk0MTM4NzIxMQ==&mid=2247530032&idx=1&sn=a49f8363f83a9aab8c277c0458b12921) - ICT Security Magazine - [ ] [Cybersecurity, dalla prevenzione al recovery: perché simulare un attacco informatico aiuta le imprese a reagire meglio](https://www.ictsecuritymagazine.com/notizie/simulare-un-attacco-informatico-cyber-arena-tour-2026/) - [ ] [Codice generato dall’AI: quasi metà è insicuro, e la velocità nasconde il debito](https://www.ictsecuritymagazine.com/articoli/codice-generato-dall-ai-sicurezza/) - LastKnight.com Feed - [ ] [È l’apocalisse delle AI? Sì, ma non per il motivo che pensate…](https://mgpf.it/2026/07/24/e-lapocalisse-delle-ai-si-ma-non-per-il-motivo-che-pensate.html) - DEF CON Announcements! - [ ] [DEF CON Middle East Postponed](https://defcon.org/html/links/dc-news.html#dcmepostponed) - 希潭实验室 - [ ] [第171篇:蓝队分析取证工具箱 V4.36 AI智能研判增强版,大幅度更新](https://mp.weixin.qq.com/s?__biz=MzkzMjI1NjI3Ng==&mid=2247488526&idx=1&sn=0e9e6dd8c2f755521c74dc46f2f0ff5c) - IT Service Management News - [ ] [AI fuori controllo che attacca altri sistemi](http://blog.cesaregallotti.it/2026/07/ai-fuori-controllo-che-attacca-altri.html) - [ ] [Slittamento delle scadenze dell'AI Act](http://blog.cesaregallotti.it/2026/07/slittamento-delle-scadenze-dellai-act.html) - Javvad Malik - [ ] [Breach of Confidence: 24 July 2026](https://javvadmalik.com/2026/07/24/breach-of-confidence-24-july-2026/) - SANS Internet Storm Center, InfoCON: green - [ ] [ISC Stormcast For Friday, July 24th, 2026 https://isc.sans.edu/podcastdetail/10022, (Fri, Jul 24th)](https://isc.sans.edu/diary/rss/33182) - Schneier on Security - [ ] [Friday Squid Blogging: Illex Squid Catch in the Falklands](https://www.schneier.com/blog/archives/2026/07/friday-squid-blogging-illex-squid-catch-in-the-falklands.html) - [ ] [Why AI Needs a “Genie Coefficient”](https://www.schneier.com/blog/archives/2026/07/why-ai-needs-a-genie-coefficient.html) - 白泽安全实验室 - [ ] [俄语背景黑客组织依托AI技术打造复合型攻击体系,并发起网络攻击活动](https://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&mid=2247492959&idx=1&sn=0d385ea5a4a551d6b8af8b2104fa9dc2) - TG Soft Software House - News - [ ] [<strong>Vir.IT eXplorer PRO</strong> certificato da Virus Bulletin per aver superato il test <strong>VB100 2026-07</strong> su Win 11 PRO...](http://www.tgsoft.it/italy/news_archivio.asp?id=1757) - Trend Micro Research, News and Perspectives - [ ] [The Signs Were There: What the First Autonomous Ransomware Case Confirms](https://www.trendmicro.com/en_us/research/26/g/autonomous-ransomware.html) - www.theregister.com - Articles - [ ] [Pope's official prayer app commits cardinal sin, leaks 700K+ users' info](https://www.theregister.com/security/2026/07/24/popes-official-prayer-app-commits-cardinal-sin-leaks-700k-users-info/5278603) - [ ] [Europol flags 4,340 'horrific' URLs linked to The Com](https://www.theregister.com/cyber-crime/2026/07/24/europol-flags-4340-horrific-urls-linked-to-the-com/5278556) - [ ] [Uncle Sam tells overseas cybercrooks their visas are canceled](https://www.theregister.com/security/2026/07/24/uncle-sam-tells-overseas-cybercrooks-their-visas-are-canceled/5278212) - The Hacker News - [ ] [BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery](https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html) - [ ] [Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller](https://thehackernews.com/2026/07/certighost-exploit-lets-low-privileged.html) - [ ] [ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link](https://thehackernews.com/2026/07/chatgpt-agentforger-flaw-could-deploy.html) - [ ] [Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers](https://thehackernews.com/2026/07/bing-images-flaws-let-crafted-svgs-run.html) - [ ] [Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do](https://thehackernews.com/2026/07/seeing-ai-agents-is-not-enough-security.html) - [ ] [Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry](https://thehackernews.com/2026/07/hacker-runs-hermes-ai-agent-unattended.html) - [ ] [Golden Chickens Resurfaces With Four New Malware Families and Modular Implants](https://thehackernews.com/2026/07/golden-chickens-resurfaces-with-four.html) - [ ] [NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats](https://thehackernews.com/2026/07/nodebb-patches-eight-ai-found-flaws.html) - [ ] [Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say](https://thehackernews.com/2026/07/kimi-k3-agents-found-redis-zero-days.html) - [ ] [Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks](https://thehackernews.com/2026/07/fake-notepad-plugin-delivers.html) - bellingcat - [ ] [Shahed-Type Drones Filmed During Mali Village Attacks](https://www.bellingcat.com/news/2026/07/24/shahed-type-drones-filmed-during-attack-on-mali-villages/) - TorrentFreak - [ ] [X and Music Publishers Settle Three-Year Copyright Clash After SpaceX IPO](https://torrentfreak.com/x-and-music-publishers-settle-three-year-copyright-clash-after-spacex-ipo/) - Instapaper: Unread - [ ] [Bluetooth Vulnerability Exposes 2.2 Million Cars to Remote Unlock and Immobilization Attacks](https://cybersecuritynews.com/karr-bluetooth-vulnerability-exposes/) - [ ] [Microcriminalità, esistono anche i “maranza” dei reati informatici (+160% in quasi 20 anni)](https://www.cybersecitalia.it/microcriminalita-esistono-anche-i-maranza-dei-reati-informatici-160-in-quasi-20-anni/67706/) - [ ] [Why Digital Forensic Reports Don’t Survive Cross-Examination](https://blog.elcomsoft.com/2026/07/why-digital-forensic-reports-dont-survive-cross-examination/) - [ ] [Forgot your Google password Now you can log in with a selfie.](https://arstechnica.com/gadgets/2026/07/google-now-lets-you-log-into-your-account-with-a-selfie/) - [ ] [The RAR Mystery Breaking RAR4 and RAR5 Encryption](https://blog.elcomsoft.com/2026/07/the-rar-mystery-breaking-rar4-and-rar5-encryption/) - [ ] [Ransomware in 2026 Same Business, New Rules](https://www.group-ib.com/blog/ransomware-2026-rules/) - Security Affairs - [ ] [Google Fined €890M Under EU Digital Markets Act Over Search and Play Store Practices](https://securityaffairs.com/195963/laws-and-regulations/google-fined-e890m-under-eu-digital-markets-act-over-search-and-play-store-practices.html) - [ ] [Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged](https://securityaffairs.com/195941/hacking/thailands-ministry-of-finance-targeted-with-hermes-ai-agent-running-unattended-hades-implant-staged.html) - [ ] [UAC-0099 Is Now Hiding Malware Inside a Fake Notepad++ Plugin to Target Ukrainian Organizations](https://securityaffairs.com/195923/cyber-warfare-2/uac-0099-is-now-hiding-malware-inside-a-fake-notepad-plugin-to-target-ukrainian-organizations.html) - [ ] [The AI Trust Paradox: Businesses Are Racing Ahead, but Consumers Are Hesitating](https://securityaffairs.com/195915/ai/the-ai-trust-paradox-businesses-are-racing-ahead-but-consumers-are-hesitating.html) - [ ] [US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers](https://securityaffairs.com/195901/apt/us-agencies-warn-of-laundry-bear-campaign-targeting-unpatched-zimbra-servers.html)
每日安全资讯(2026-07-25)