-
Notifications
You must be signed in to change notification settings - Fork 37
Open
Labels
Description
每日安全资讯(2026-03-12)
- Private Feed for M09Ic
- github released v0.2.1 at github/spec-kit
- bolucat released 202603112007 at bolucat/Archive
- mgeeky starred anmolksachan/AI-ML-Free-Resources-for-Security-and-Prompt-Injection
- strands-agents released v1.30.0 at strands-agents/sdk-python
- anthropics released v2.1.73 at anthropics/claude-code
- zeroclaw-labs released v0.1.7-beta.30 at zeroclaw-labs/zeroclaw
- lz520520 starred oxfemale/CVE-2026-20817
- liamg starred infracost/agent-skills
- jar-analyzer released 5.16 at jar-analyzer/jar-analyzer
- Mr-xn starred tanweai/pua
- mgeeky starred soufianetahiri/dnspy-mcp
- LoRexxar starred upstash/context7
- Ridter starred P4nda0s/reverse-skills
- Mel0day starred larksuite/openclaw-lark
- PrefectHQ released 3.6.22.dev7 at PrefectHQ/prefect
- zema1 starred Wei-Shaw/sub2api
- niudaii starred HKUDS/CLI-Anything
- CHYbeta starred photon-hq/qclaw-wechat-client
- timwhitez starred Eric-Ant/SelfInjectPE
- wh0amitz starred koala73/worldmonitor
- pmiaowu starred trailofbits/skills
- gh0stkey starred netease-youdao/LobsterAI
- future-architect released v0.38.6 at future-architect/vuls
- 安全客-有思想的安全新媒体
- 侧边栏里的间谍假冒AI浏览器插件窃取90万用户数据
- Kubernetes安全预警Ingress-Nginx注入漏洞可致集群密钥全局泄露
- Budibase存在高危漏洞 可导致生产环境密钥全面泄露
- Radware推出Alteon Protect实现云级ADC应用安全防护
- 研究人员打造AI智能体 可全自动实施诈骗通话
- 黑客利用微软Teams诱骗员工开放远程访问权限
- 微软推出365 E5升级套件与Agent 365 AI管控平台
- GhostClaw伪装成OpenClaw窃取开发者设备数据
- OpenAI将安全初创企业纳入核心架构 强化AI安全防护能力
- SAP发布重要安全更新 修复高危远程代码执行漏洞
- 科技云报到:从北京到内蒙,xCloud联想智能云3年“数字迁徙”背后的密码
- LoRexxar's Blog | 信息技术分享
- SecWiki News
- Tenable Blog
- Microsoft Security Blog
- 嘶吼 RoarTalk – 网络安全行业综合服务平台,4hou.com
- Darknet – Hacking Tools, Hacker News & Cyber Security
- Recent Commits to cve:main
- paper - Last paper
- Bug Bounty in InfoSec Write-ups on Medium
- PostMessage Misconfiguration + AI Prompt Injection + Sandbox Escape = XSS & Data Exfiltration
- ️Turning Directory Data into Domain Access
- XSS Bypass to Zero Click Account Takeover in AI Chatbot
- Citrix Bleed: How a Single Bug Leaked Corporate Secrets (CVE-2023–4966)
- Zomato Privacy Flaw: How the ‘Friend Recommendations’ Feature Enables Location Stalking
- I Found a Bug That Exposed Private Instagram Posts to Anyone.
- Chaining the Boredom: How a Quiet Weekday Led to a Full Database Heist
- Hackviser — Cryptanalysis walkthrough
- GuidePoint Security
- Didier Stevens
- The Trail of Bits Blog
- Horizon3.ai
- PortSwigger Blog
- Malwarebytes
- Intigriti
- Hacking Dream
- daniel.haxx.se
- Offensive Security Blog: Latest Trends in Hacking | Praetorian
- Black Hills Information Security, Inc.
- 奇客Solidot–传递最新科技情报
- 安全分析与研究
- 黑海洋Wiki | AI机器人硬件开发 | 网络安全攻防实战 | 区块链技术文档教程 - 免费资源平台
- 黑鸟
- 看雪学苑
- 代码卫士
- 丁爸 情报分析师的工具箱
- 奇安信威胁情报中心
- Flanker论安全
- 奇安信 CERT
- 安全客
- 信安之路
- 安全内参
- 黑哥虾撩
- 中国信息安全
- Wallarm
- XCTF联赛
- 天黑说嘿话
- 安全牛
- 微步在线
- 信息安全国家工程研究中心
- 天御攻防实验室
- 安全圈
- 嘶吼专业版
- 火绒安全
- 国家互联网应急中心CNCERT
- 深信服千里目安全技术中心
- 360数字安全
- 唯品会安全应急响应中心
- 迪哥讲事
- 数世咨询
- 威努特安全网络
- 安全行者老霍
- 极客公园
- 枇杷熟了
- 阿里安全响应中心
- 纽创信安
- 情报分析师
- 慢雾科技
- Over Security - Cybersecurity news aggregator
- Rapporto Clusit 2026: cresce l’impatto degli attacchi cyber, ma anche le difficoltà di analisi
- DirectX, OpenFOAM, Libbiosig vulnerabilities
- WhatsApp introduces parent-managed accounts for pre-teens
- SQLi flaw in Elementor Ally plugin impacts 250k+ WordPress sites
- Pro-Iran hacktivist group says it is behind attack on medical tech giant Stryker
- Medical device giant Stryker confirms cyberattack as employees say devices were wiped
- CISA orders feds to patch n8n RCE flaw exploited in attacks
- Hacker broke into FBI and compromised Epstein files, report says
- Medtech giant Stryker offline after Iran-linked wiper malware attack
- Dal porta a porta alla sanzione: Acea Energia paga 2 milioni di euro per violazioni GDPR
- New PhantomRaven NPM attack wave steals dev data via 88 packages
- Dal Vishing al Domain Controller
- Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker
- Web Filtering
- Iran-linked hackers claim cyberattack on Albania’s parliament email systems
- Navigating 2026’s Converged Threats: Insights from Flashpoint’s Global Threat Intelligence Report
- Meta adds new WhatsApp, Facebook, and Messenger anti-scam tools
- 235,000 affected by cyberattack on largest ambulance provider in Wisconsin
- Iranian influence operation using fake personas to deceive US Instagram users disrupted, Meta says
- Meta says it culled millions of scam ads amid accusations that it profits from them
- Aggiornamenti Microsoft: corrette due zero-day e la prima vulnerabilità scoperta dall’IA
- Phishing EasyPark: il brand sfruttato per sottrarre dati di pagamento e documenti di identità
- Tutte le minacce del 2025 e le priorità di difesa nel nuovo anno
- Spinning complex ideas into clear docs with Kri Dontje
- Agentic AI security: Why you need to know about autonomous agents now
- Microsoft Patch Tuesday March 2026: Two Zero-Days and Critical RCE Bugs Fixed
- Finland Warns Russia and China Cyber Espionage Ops Targeting Tech Sector
- L’Iran ha cominciato la contro-guerra cyber: dai Ddos ai sabotaggi, ecco cosa bisogna sapere
- FBI Flags Phishing Campaign Collecting Planning and Zoning Permit Payments
- Iran’s Fake “Shelter Danger” Calls Part of Psychological Cyber Warfare Playbook
- Microsoft Patch Tuesday, March 2026 Edition
- Handala and the release of strategic information regarding Israeli organizations
- 京东安全应急响应中心
- Krypt3ia
- Arturo Di Corinto
- bellingcat
- LR的安全自留地
- 悬镜安全
- Securityinfo.it
- ICT Security Magazine
- SANS Internet Storm Center, InfoCON: green
- Schneier on Security
- 赛博昆仑CERT
- 绿盟科技技术博客
- Tor Project blog
- The Register - Security
- Iran plots 'infrastructure warfare' against US tech giants
- Iran-linked cyber crew says they hit US med-tech firm
- Meta, international cops use handcuffs and AI to stop scammers
- ICO fines Police Scotland over data-sharing debacle in gross misconduct case
- Swiss e-voting pilot can't count 2,048 ballots after USB keys fail to decrypt them
- Dutch cops bust teen suspected of posing as bank staff to steal cards
- EU legal eagle says banks should refund cybercrime victims first, argue later
- Building the UK’s next generation of cyber talent
- 白帽子章华鹏
- Instapaper: Unread
- Security Affairs
- Pro-Palestinian hacktivist group Handala targets Stryker in global disruption
- BeatBanker malware targets Android users with banking Trojan and crypto miner
- Hewlett Packard Enterprise fixes critical authentication bypass in Aruba AOS-CX
- KadNap bot compromises 14,000+ devices to route malicious traffic
- Security Weekly Podcast Network (Audio)
- Krebs on Security
- D3Lab
- Deeplinks
- The Hacker News
- Researchers Trick Perplexity's Comet AI Browser Into Phishing Scam in Under Four Minutes
- Critical n8n Flaws Allow Remote Code Execution and Exposure of Stored Credentials
- Meta Disables 150K Accounts Linked to Southeast Asia Scam Centers in Global Crackdown
- Dozens of Vendors Patch Security Flaws Across Enterprise Software and Network Devices
- What Boards Must Demand in the Age of AI-Automated Exploitation
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days
- UNC6426 Exploits nx npm Supply-Chain Attack to Gain AWS Admin Access in 72 Hours
- Five Malicious Rust Crates and AI Bot Exploit CI/CD Pipelines to Steal Developer Secrets
- DEFION Research Labs
- Ruckus Unleashed: Multiple vulnerabilities exploited
- Pwn2Own Automotive 2024: Hacking the Autel MaxiCharger
- Pwn2Own Automotive 2024: Hacking the JuiceBox 40
- Pwn2Own Automotive 2024: Hacking the ChargePoint Home Flex (and their cloud...)
- DoNex/DarkRace Ransomware Decryptor
- CVE-2024-20693: Windows cached code signature manipulation
- Bringing process injection into view(s): exploiting all macOS apps using nib files
- Don’t Talk All at Once! Elevating Privileges on macOS by Audit Token Spoofing
- Getting SYSTEM on Windows in style
- Technical analysis of the Genesis Market
- Bad things come in large packages: .pkg signature verification bypass on macOS
- Pwn2Own Miami 2022: ICONICS GENESIS64 Arbitrary Code Execution
- Pwn2Own Miami 2022: Unified Automation C++ Demo Server DoS
- Pwn2Own Miami 2022: AVEVA Edge Arbitrary Code Execution
- Process injection: breaking all macOS security layers with a single vulnerability
- Pwn2Own Miami 2022: Inductive Automation Ignition Remote Code Execution
- Pwn2Own Miami 2022: OPC UA .NET Standard Trusted Application Check Bypass
- CoronaCheck App TLS certificate vulnerabilities
- Sandbox escape + privilege escalation in StorePrivilegedTaskService
- Proctorio Chrome extension Universal Cross-Site Scripting
- Zoom RCE from Pwn2Own 2021
- Adobe Acrobat privilege escalation
- iOS VPN support: 3 different bugs
- Sign in with Apple - authentication bypass
- Jenkins - authentication bypass
- DNS rebinding for HTTPS
- Spring Security - insufficient cryptographic randomness
- XenServer - path traversal leading to authentication bypass
- Volkswagen Auto Group MIB infotainment system - unauthenticated remote code execution as root
- NAPALM - command execution on NAPLM controller from host
- MySQL Connector/J - Unexpected deserialisation of Java objects
- Ansible - command execution on Ansible controller from host
- Observium - unauthenticated remote code execution
- cSRP/srpforjava - obtaining of hashed passwords
- StartEncrypt - obtaining valid SSL certificates for unauthorized domains
- 安全419
Reactions are currently unavailable