# 每日安全资讯(2026-03-19) - SecWiki News - [ ] [SecWiki News 2026-03-18 Review](http://www.sec-wiki.com/?2026-03-18) - Private Feed for M09Ic - [ ] [Rvn0xsy starred lightpanda-io/browser](https://github.com/lightpanda-io/browser) - [ ] [anthropics released v2.1.79 at anthropics/claude-code](https://github.com/anthropics/claude-code/releases/tag/v2.1.79) - [ ] [zeroclaw-labs released v0.5.0-beta.364 at zeroclaw-labs/zeroclaw](https://github.com/zeroclaw-labs/zeroclaw/releases/tag/v0.5.0-beta.364) - [ ] [memN0ps starred MEhrn00/boflink](https://github.com/MEhrn00/boflink) - [ ] [bolucat released 202603182010 at bolucat/Archive](https://github.com/bolucat/Archive/releases/tag/202603182010) - [ ] [mgeeky starred smtg-ai/claude-squad](https://github.com/smtg-ai/claude-squad) - [ ] [IC3-CR3AM starred mrphrazer/agentic-malware-analysis](https://github.com/mrphrazer/agentic-malware-analysis) - [ ] [INotGreen starred shareAI-lab/learn-claude-code](https://github.com/shareAI-lab/learn-claude-code) - [ ] [zeroclaw-labs released v0.5.0-beta.351 at zeroclaw-labs/zeroclaw](https://github.com/zeroclaw-labs/zeroclaw/releases/tag/v0.5.0-beta.351) - [ ] [IC3-CR3AM forked IC3-CR3AM/intelligence from ctrlaltint3l/intelligence](https://github.com/IC3-CR3AM/intelligence) - [ ] [mgeeky starred six2dez/burp-ai-agent](https://github.com/six2dez/burp-ai-agent) - [ ] [4ra1n starred ZeroPathAI/validation-benchmarks](https://github.com/ZeroPathAI/validation-benchmarks) - [ ] [niudaii starred Esonhugh/pydoll-cf-waf-bypasser-skills](https://github.com/Esonhugh/pydoll-cf-waf-bypasser-skills) - [ ] [uknowsec starred RuoJi6/java-decompile-mcp](https://github.com/RuoJi6/java-decompile-mcp) - [ ] [Rvn0xsy starred whatevertogo/FeiShuSkill](https://github.com/whatevertogo/FeiShuSkill) - [ ] [gh0stkey starred unslothai/unsloth-studio](https://github.com/unslothai/unsloth-studio) - [ ] [PrefectHQ released 3.6.23.dev3 at PrefectHQ/prefect](https://github.com/PrefectHQ/prefect/releases/tag/3.6.23.dev3) - [ ] [ZeddYu starred aiming-lab/AutoResearchClaw](https://github.com/aiming-lab/AutoResearchClaw) - [ ] [niudaii starred shareAI-lab/learn-claude-code](https://github.com/shareAI-lab/learn-claude-code) - [ ] [safedv starred andreisss/KslDump](https://github.com/andreisss/KslDump) - [ ] [zeroclaw-labs released v0.5.0 at zeroclaw-labs/zeroclaw](https://github.com/zeroclaw-labs/zeroclaw/releases/tag/v0.5.0) - [ ] [su18 starred shareAI-lab/learn-claude-code](https://github.com/shareAI-lab/learn-claude-code) - CXSECURITY Database RSS Feed - CXSecurity.com - [ ] [Kanboard < = 1.2.50 Authenticated SQL Injection](https://cxsecurity.com/issue/WLB-2026030027) - [ ] [Glances < = 4.5.2 OS Command Injection via Mustache Template Fields](https://cxsecurity.com/issue/WLB-2026030026) - Doonsec's feed - [ ] [Rust for Malware Development:一个值得研究的Rust对抗技术仓库](https://mp.weixin.qq.com/s/ny_nSH7yFY8eW0RLJCk32Q) - [ ] [告别手动排查应急响应一键采集与可视化分析的自动化应急响应利器](https://mp.weixin.qq.com/s/DXNdBHCom1VH5IyblTMsIg) - [ ] [CTF WEB-Jeewms](https://mp.weixin.qq.com/s/JITu3oyIFADI-aUDypYpNQ) - [ ] [DarkEsn 通知/授权 | Darkesnvip最新通知](https://mp.weixin.qq.com/s/Ew9aFRB7ITzCqiHEfdNJOw) - [ ] [网易回应清退全部外包的传言](https://mp.weixin.qq.com/s/0j9CadTjqopCrCZTvCMVeQ) - [ ] [紧急!你的Chrome可能正在\"裸奔\"](https://mp.weixin.qq.com/s/pMsnViXscmWN-uBuqmZRxQ) - [ ] [快普M6 GetPositionOfStaff接口存在sql注入漏洞 附POC](https://mp.weixin.qq.com/s/Ju3JvUI3f7FQtB4iEgi4NA) - [ ] [老婆是一个小公司的hr兼行政,工作繁琐经常加班,我经常写一些小工具给她用。现在老婆要离职,老板要求这些工具必须留下。这合理吗?](https://mp.weixin.qq.com/s/xYyZFMukT6CNUZMui9Mo3w) - [ ] [什么是信息安全,网络安全,数据安全](https://mp.weixin.qq.com/s/k886sP6F0sgAhBB-4eKbVw) - [ ] [聊一下我的“多源日志采集与智能分析平台”:支持两种 syslog 日志外发啦!](https://mp.weixin.qq.com/s/SBZq0k9AZLM_eZTZ_0Hcgg) - [ ] [美以空袭疑似炸死了伊朗黑客组织头目](https://mp.weixin.qq.com/s/-t_SurkR2piDLAcEKY3_Uw) - [ ] [别浪费!iPhone这些隐藏功能不用等于白买](https://mp.weixin.qq.com/s/Sdv9PaaB1UGgU2o_yoJOSw) - [ ] [H6-3-逆向工程(Ghidra)长期支持维护基础环境设施知识共享](https://mp.weixin.qq.com/s/tfmmwt1eFpZtuBlu6yb-Dg) - [ ] [苹果iOS26.3.1a正式版发布!投屏教程+版本亮点一次看懂](https://mp.weixin.qq.com/s/DenC0Vc3Xmt77vT1z6fI0A) - [ ] [利用skill解决CTF的逆向题](https://mp.weixin.qq.com/s/MdQf4ED9ROVQ8cqQ5v-7rQ) - [ ] [吾爱破解论坛精华集2025](https://mp.weixin.qq.com/s/0j2Q3bMD92hfxb9DVR6Hpg) - [ ] [[EDU]动动手指的高危](https://mp.weixin.qq.com/s/CAyp4Cm3lrcR8K_dy1aoWg) - [ ] [新课更新](https://mp.weixin.qq.com/s/M7GRlspTwX8efw-1bZxwPQ) - [ ] [Burp插件--MaR](https://mp.weixin.qq.com/s/4ZTyk-bBu4TzTowj7j4mMg) - [ ] [某CMS XSS漏洞代码审计](https://mp.weixin.qq.com/s/dkmSXkbDu3z28swYvLta8A) - [ ] [智谱龙虾套餐可以用glm5-turbo了](https://mp.weixin.qq.com/s/_wEKlkHztP7iCv5tQix6UA) - [ ] [2026年国际网络安全奥林匹克中国区学术(NCO)活动正式启动](https://mp.weixin.qq.com/s/iprL2SX7LT_if3jKjf-fWA) - [ ] [北美校园医院警报!朝鲜APT新武器Dohdoor偷袭,病历成绩全被偷。](https://mp.weixin.qq.com/s/25tbovAh6Q_dDgGGWrB7vQ) - [ ] [AI Guardrails:大模型安全护栏架构初探](https://mp.weixin.qq.com/s/JhhorGnR0ARUuILaIX1i4Q) - [ ] [《经济半小时》| 守护安全 奇安信“龙虾安全伴侣”获央视关注](https://mp.weixin.qq.com/s/rACKcrLXEDQYg7pqs-4uyA) - [ ] [奇安云镜发布:一天不到1毛钱,为中小企业打造专属“智能安全管家”](https://mp.weixin.qq.com/s/wsiPk9WpsSLUGKHEZsi-xg) - [ ] [CTFshow-Pwn入门格式化字符串(91-100)](https://mp.weixin.qq.com/s/ZYNKgcz-vU3avl8brKO19A) - [ ] [鹈鹕、Three.js 与 Rebecca](https://mp.weixin.qq.com/s/1twnEdEby-serqZiA3oUvg) - [ ] [攻防中前端加密的分析与突破](https://mp.weixin.qq.com/s/UfGnWAmeYZH53fTDPH23dw) - [ ] [Agent开发|从0实现Agent(一):50行代码实现Mini Claude Code(工具与执行篇)](https://mp.weixin.qq.com/s/1H-IJ7ChlP5jZ3r1zXBS9w) - [ ] [别再手动压缩图片了,来看看「自动挡」时代的正确做法!](https://mp.weixin.qq.com/s/4feWETtr2MfLjFBIURAyHQ) - [ ] [[吃瓜速递]某大厂又开始裁员??](https://mp.weixin.qq.com/s/jKK0o5IJXG0-zEZZ6pRz6Q) - [ ] [结构化思维、架构化认知--最重要的实力保障](https://mp.weixin.qq.com/s/AFNL3zZGW-ZZ-cqtSnzAvA) - [ ] [拆解机器人,分析其软硬件弱点(1)](https://mp.weixin.qq.com/s/kU0XYhP0zhr-kMgcJmYT4g) - [ ] [腾讯财报:人均年薪112万!](https://mp.weixin.qq.com/s/YzG7a7-XxH53iaHdrZvQUw) - [ ] [17岁深圳少年破解AI底层难题,马斯克点赞:中国下一代程序员正在崛起](https://mp.weixin.qq.com/s/WZFpHDUvnqC-Pot4G1LiVg) - [ ] [信创私有化,源码交付!AIoT 大模型智慧城市生命线一网统管,涵盖城管住建、综合执法、智慧社区、水利水务、生态环保、应急安全](https://mp.weixin.qq.com/s/dyvaiNeQHZsYZAv5O1oD7Q) - [ ] [突破防御极限!《APT攻击原理深度刨析》第二批课程](https://mp.weixin.qq.com/s/9f7IRPGvKWz5TblsxgsEwA) - [ ] [开源!PromptFoo 让 AI 安全测试告别盲测](https://mp.weixin.qq.com/s/DT6kWjxk5igg0SrhT9A3jw) - [ ] [Ubuntu Desktop 24.04及更高版本存在本地权限提升漏洞,可导致未授权用户获取root权限](https://mp.weixin.qq.com/s/K2XGRMr0VeG3o-L46fOnhQ) - [ ] [RegPwn:一种 Windows 注册表弱点](https://mp.weixin.qq.com/s/4kMt6vdgetx33qA5mfCf6Q) - [ ] [沼泽蛇组织发起多波次间谍活动,目标直指外交官和关键基础设施](https://mp.weixin.qq.com/s/FgpwsQZhOk7A4EMACUOS3g) - [ ] [华为中国合作伙伴大会2026|华为星河AI网络安全参会指南一图掌握!](https://mp.weixin.qq.com/s/eJDOTtQzLpSwcWX2soQjNA) - [ ] [2月银行AI项目动态:广西北部湾银行连推3项目,最高金额回落至三百余万](https://mp.weixin.qq.com/s/rIZH2l-uXCfENCXtCXVEtw) - [ ] [AI快讯:金融智能体标准编制启动,阿里云、百度云AI算力等产品涨价](https://mp.weixin.qq.com/s/dqRoNOmIs-SN3rHbxx9sdw) - [ ] [银雁科技第一中选!中行安徽省分行AI远程银行(云维)项目人员外包服务项目](https://mp.weixin.qq.com/s/fbkDyrVNKp88HTAOng8BPg) - [ ] [专题·原创 | 《中华人民共和国网络安全法》修改的背景、内容、创新之处及实施路径研究](https://mp.weixin.qq.com/s/Kfoly2cZj0XIVHhKV6Jf_w) - [ ] [专家解读 | 筑牢数据产权制度基石 护航数据要素价值释放](https://mp.weixin.qq.com/s/fdQpnJ6R2S2flS_d1JrC3g) - [ ] [最高法:审理未成年人“充值”“打赏”案件应充分考虑各种因素综合判断](https://mp.weixin.qq.com/s/JMt9RJlrWGxnzBR-l0LQBA) - [ ] [前沿 | OpenClaw爆火背后:个人Agent狂欢更需警惕安全风险](https://mp.weixin.qq.com/s/1cD8gxrsbZMyH6mJ_cVBgA) - [ ] [专家观点丨政策驱动全链条防护:我国工控安全撑起新型工业化“安全伞”](https://mp.weixin.qq.com/s/yOxZiXU1vaY60s8w0ltnKQ) - [ ] [可信数据丨建设面向AI赋能的高质量行业数据集!工信部启动工业数据筑基行动](https://mp.weixin.qq.com/s/hTWniYKgB_YtBs4ID0RCoA) - [ ] [Flashpoint:从暗网里长出来的情报公司,如何在\"史诗狂怒\"前夜发出全球威胁最强音](https://mp.weixin.qq.com/s/-8FjDJzfDBuWI8_1mE4Lkg) - [ ] [龙虾归笼,筑牢底座:CSA GCR大会嘉宾揭晓](https://mp.weixin.qq.com/s/U9hqhmzvSl_DdLAzg9Tozg) - [ ] [AI 安全的“插件革命”:深度拆解 730+ 个 Anthropic 风格原子化技能库](https://mp.weixin.qq.com/s/tIk3O2Wevk02NCN7KVPqKg) - [ ] [老师,我想学渗透测试](https://mp.weixin.qq.com/s/2q3Lt9t96I8Mra7_eZfbBw) - [ ] [智行千里,安防于心|中机博也在AutoSec十周年荣获标杆企业](https://mp.weixin.qq.com/s/nS8RP1n1xcUHiyzNBnsJRA) - [ ] [前端加密测不动?全局热加载帮你自动接管签名流程](https://mp.weixin.qq.com/s/vYzIXAIQXlmuQD8Mb8xZyw) - [ ] [现在学网安真的是49年入国军吗?](https://mp.weixin.qq.com/s/PJdMlCmdX1e1DWix6UXgTg) - [ ] [AI+安全,问鼎国际!默安科技斩获日内瓦国际发明展金奖](https://mp.weixin.qq.com/s/WjDnu3wMZLEMpu_rnB0aIA) - [ ] [【高危AI漏洞预警】OpenClaw Agent平台远程代码执行漏洞CVE-2026-30741](https://mp.weixin.qq.com/s/nc7XTVQYs5XYyBL-hsYP9w) - [ ] [某安全应急响应中心群发导致493个邮箱地址泄露](https://mp.weixin.qq.com/s/ll6MZ0P7Ir3P2VjXnZr7vg) - [ ] [无数挖坑题的反面](https://mp.weixin.qq.com/s/sgfE-VaugCEAcpqwUOI_bA) - [ ] [龙信手机取证新突破:TG提取恢复再加强(70款变种支持)与主流输入法(含维语)提取全覆盖!](https://mp.weixin.qq.com/s/kzof8cFjgNTf0CQINgPgoQ) - [ ] [央视曝光AI“投毒”,工信部紧急预警:AI浪潮下,企业如何看清“隐形威胁”?](https://mp.weixin.qq.com/s/02us2Jr-MVOr5yonr_wtyg) - [ ] [英伟达发布“安全版龙虾”NemoClaw](https://mp.weixin.qq.com/s/btzuryyexuyKfHUhF4ZDbg) - [ ] [OpenClaw安全公告激增;Claude Code Security重塑网安企业 | 2025网安行业优质播客精选集⑮](https://mp.weixin.qq.com/s/OHZdrmzEgO8HA8coziP8pA) - [ ] [从Windows转向macOS:ClickFix攻击利用ChatGPT诱饵升级战术](https://mp.weixin.qq.com/s/1fmm5nCI0ZqojoJfPDrG7g) - [ ] [攻击者入侵史赛克微软系统,远程擦除数万台设备](https://mp.weixin.qq.com/s/8zkuE49dMrtR8tjBEu5aTg) - [ ] [公开课 | 区块链安全(第三讲)](https://mp.weixin.qq.com/s/xmT4d61_Oa00RSNHifFLfw) - [ ] [字节跳动被曝在内部推出 ByteClaw 并发布“龙虾”安全规范,应对 AI 智能体安全风险](https://mp.weixin.qq.com/s/sEF5HlZvLNTYnZi-tx0nwA) - [ ] [稳步推进 聚力筑盾——武汉市网络安全协会两项团体标准编制工作取得阶段性进展](https://mp.weixin.qq.com/s/Hgh00lYMY70Ma8pXYAUo_A) - [ ] [国家互联网信息办公室关于发布生成式人工智能服务已备案信息的公告](https://mp.weixin.qq.com/s/jWDg86MtbHpLZxIdm4Cwaw) - [ ] [奇安信发布“龙虾安全伴侣”,破解企业“想用不敢用”难题](https://mp.weixin.qq.com/s/KJoQM8Us9cCphAqCzijp5A) - [ ] [会员动态 | 陈宇调研光谷信息](https://mp.weixin.qq.com/s/6VL79n21wUUIMyt0SwX8hg) - [ ] [合规领航·智赋新安 | 任子行AI驱动全面赋能393号文基础电信企业数据安全技术能力建设](https://mp.weixin.qq.com/s/S_MBAj_9EXt3_kNyvHhxww) - [ ] [移动安全警报:AI驱动攻击、虚拟化逃逸、无感知盗刷来袭……梆梆安全防御能力全面升级!](https://mp.weixin.qq.com/s/uKh4q70wtQrw7OY76KXHIw) - [ ] [登榜IDC双图谱!亚信安全以AI原生实力筑牢智能体安全底座](https://mp.weixin.qq.com/s/ND6VOhJyPVdQqsJMOhfIMw) - [ ] [OpenClaw被曝多项高危风险?观安智能体管控平台带你告别AI“裸奔”!](https://mp.weixin.qq.com/s/_TRtHQh_MmfYBPATSas3rg) - [ ] [fastcms-v0.1.5代码审计](https://mp.weixin.qq.com/s/xmpM_v-Ozvccw2vJyLIyEQ) - [ ] [生成式人工智能训练语料的法律风险及治理](https://mp.weixin.qq.com/s/yuGUMgR--WoBWI56TOkGZA) - [ ] [预警丨防范思科Catalyst SD-WAN管理软件多个漏洞](https://mp.weixin.qq.com/s/0uzwKQ7ShKY1py9C-FSdKQ) - [ ] [OpenClaw安全解决方案:安全与办公提效兼得](https://mp.weixin.qq.com/s/42SSyMGYg-iqTvaTjVpzvg) - [ ] [火山引擎ArkClaw开启安全专测!顶尖赏金与限量周边奉上!](https://mp.weixin.qq.com/s/JiGxP4fiqdpgxNIqXIr1fQ) - [ ] [网络安全行业有哪些“含金量高”的证书?一次讲清楚](https://mp.weixin.qq.com/s/0GvYXkTvdBtRPWQRjv3QCw) - [ ] [2026年成都市政府工作安排](https://mp.weixin.qq.com/s/y-kDKzRHpeOMN7QJhSVjxQ) - 嘶吼 RoarTalk – 网络安全行业综合服务平台,4hou.com - [ ] [360龙虾卫士上线:九大能力专治OpenClaw“裸奔”](https://www.4hou.com/posts/OG1E) - [ ] [AI时代中国网络安全产业的五年变局|| 网络安全投融资的残酷分流](https://www.4hou.com/posts/MXY1) - [ ] [嘶吼安全动态|360回应“安全龙虾”私钥泄露:已吊销证书,系发布失误微博 Delta工业通信系统曝高危漏洞](https://www.4hou.com/posts/NGZ8) - Microsoft Security Blog - [ ] [Observability for AI Systems: Strengthening visibility for proactive risk detection](https://www.microsoft.com/en-us/security/blog/2026/03/18/observability-ai-systems-strengthening-visibility-proactive-risk-detection/) - Der Flounder - [ ] [Managing Background Security Improvements for macOS using Blueprints in Jamf Pro](https://derflounder.wordpress.com/2026/03/18/managing-background-security-improvements-for-macos-using-blueprints-in-jamf-pro/) - Recent Commits to cve:main - [ ] [Update Wed Mar 18 11:18:23 UTC 2026](https://github.com/trickest/cve/commit/e12191e7caafc22e35a4f638e0b2c5f5523ff4ad) - Insinuator.net - [ ] [Vulnerabilities in Broadcom VMware Aria Operations: Privilege Escalation (CVE-2025-41245 / CVE-2026-22721)](https://insinuator.net/2026/03/vulnerabilities-in-broadcom-vmware-aria-operations-privilege-escalation-cve-2025-41245-cve-2026-22721/) - Sandfly Security Blog RSS Feed - [ ] [Sandfly Security and Carahsoft Partner to Bring Agentless Linux EDR to the Public Sector](https://sandflysecurity.com/blog/sandfly-security-and-carahsoft-partner) - Bug Bounty in InfoSec Write-ups on Medium - [ ] [How I Found a Critical Authentication Bypass in a Lightning Network SDK (CVSS 9.8)](https://infosecwriteups.com/how-i-found-a-critical-authentication-bypass-in-a-lightning-network-sdk-cvss-9-8-79f76eda1d84?source=rss----7b722bfd1b8d--bug_bounty) - [ ] [How I Discovered a Complete CSRF Protection Bypass on a Major Crypto Exchange And What Happened…](https://infosecwriteups.com/how-i-discovered-a-complete-csrf-protection-bypass-on-a-major-crypto-exchange-and-what-happened-10c7fc794324?source=rss----7b722bfd1b8d--bug_bounty) - Malware-Traffic-Analysis.net - Blog Entries - [ ] [2026-03-12: Files for an ISC diary (SmartApeSG ClickFix pushes Remcos RAT)](https://www.malware-traffic-analysis.net/2026/03/12/index.html) - Securelist - [ ] [The SOC Files: Time to “Sapecar”. Unpacking a new Horabot campaign in Mexico](https://securelist.com/horabot-campaign/119033/) - Malwarebytes - [ ] [Researchers found font-rendering trick to hide malicious commands](https://www.malwarebytes.com/blog/news/2026/03/researchers-found-font-rendering-trick-to-hide-malicious-commands) - [ ] [Apple patches WebKit bug that could let sites access your data](https://www.malwarebytes.com/blog/news/2026/03/apple-patches-webkit-bug-that-could-let-sites-access-your-data) - [ ] [Inside a network of 20,000+ fake shops](https://www.malwarebytes.com/blog/scams/2026/03/inside-a-network-of-20000-fake-shops) - 绿盟科技技术博客 - [ ] [“影子AI”危机?绿盟威胁情报“三把锁”,构筑OpenClaw防御体系](https://blog.nsfocus.net/%e5%bd%b1%e5%ad%90ai%e5%8d%b1%e6%9c%ba%ef%bc%9f%e7%bb%bf%e7%9b%9f%e5%a8%81%e8%83%81%e6%83%85%e6%8a%a5%e4%b8%89%e6%8a%8a%e9%94%81%ef%bc%8c%e6%9e%84%e7%ad%91openclaw/) - [ ] [RSAC 2026创新沙盒 | Charm Security:构建面向新型诈骗的AI反欺诈平台](https://blog.nsfocus.net/rsac-2026%e5%88%9b%e6%96%b0%e6%b2%99%e7%9b%92-charm-security%ef%bc%9a%e6%9e%84%e5%bb%ba%e9%9d%a2%e5%90%91%e6%96%b0%e5%9e%8b%e8%af%88%e9%aa%97%e7%9a%84ai%e5%8f%8d%e6%ac%ba%e8%af%88%e5%b9%b3%e5%8f%b0/) - 奇客Solidot–传递最新科技情报 - [ ] [瑞士构建 BGP 的安全替代](https://www.solidot.org/story?sid=83798) - [ ] [GTC 2026 重磅 AI 会议推荐:注册观看还有机会获得 NVIDIA 定制装备](https://www.solidot.org/story?sid=83797) - [ ] [韩国游戏发行商 CEO 为避免支付合同承诺的 2.5 亿美元而求助于 ChatGPT](https://www.solidot.org/story?sid=83796) - [ ] [法官裁决苹果可以以任何理由下架应用](https://www.solidot.org/story?sid=83795) - Offensive Security Blog: Latest Trends in Hacking | Praetorian - [ ] [When HttpOnly Isn’t Enough: Chaining XSS and GhostScript for Full RCE Compromise](https://www.praetorian.com/blog/httponly-cookie-bypass-xss-ghostscript-rce/) - 黑海洋Wiki | AI机器人硬件开发 | 网络安全攻防实战 | 区块链技术文档教程 - 免费资源平台 - [ ] [美光表示需要投入巨资才能满足内存需求](https://blog.upx8.com/%E7%BE%8E%E5%85%89%E8%A1%A8%E7%A4%BA%E9%9C%80%E8%A6%81%E6%8A%95%E5%85%A5%E5%B7%A8%E8%B5%84%E6%89%8D%E8%83%BD%E6%BB%A1%E8%B6%B3%E5%86%85%E5%AD%98%E9%9C%80%E6%B1%82) - rtl-sdr.com - [ ] [Ground Station: An Open Source SDR Orchestration Platform for Satellite Tracking and Decoding](https://www.rtl-sdr.com/ground-station-an-open-source-sdr-orchestration-platform-for-satellite-tracking-and-decoding/) - [ ] [Automatic Signal Recognition with AI Machine Learning and RTL-SDR](https://www.rtl-sdr.com/automatic-signal-recognition-with-ai-machine-learning-and-rtl-sdr/) - [ ] [Integrive-100: A Standalone MIMO SDR for Real-Time Precision](https://www.rtl-sdr.com/integrive-100-a-standalone-mimo-sdr-for-real-time-precision/) - 安全分析与研究 - [ ] [EDR对抗策略概览——攻防博弈的艺术](https://mp.weixin.qq.com/s?__biz=MzA4ODEyODA3MQ==&mid=2247496570&idx=1&sn=7d603eda78969cab96487cc6820592dc) - 吾爱破解论坛 - [ ] [心流鼠标手势已上架火狐商店](https://mp.weixin.qq.com/s?__biz=MjM5Mjc3MDM2Mw==&mid=2651143747&idx=1&sn=e317f34eaaeb618298161413779a87eb) - 看雪学苑 - [ ] [特别预警|开发者请注意:使用OpenAI Codex 可能被攻击](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458612312&idx=1&sn=fbdcc7d2c5e82d2f8c263921066c0eec) - [ ] [今晚7点!安全圈顶流 “养虾局”:AI Agent 安全养虾实战,教你敏捷落地](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458612312&idx=2&sn=4cb03698c61b1c40f5504246bd8a112c) - [ ] [苹果紧急发布WebKit安全修复,同源策略绕过漏洞影响iOS/macOS](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458612312&idx=3&sn=695fb5c7dad0f5c246b1676d8956efc9) - Black Hills Information Security, Inc. - [ ] [How to Lead Effective Tabletops](https://www.blackhillsinfosec.com/how-to-lead-effective-cybersecurity-tabletops/) - 代码卫士 - [ ] [简单的自定义字体渲染即可投毒 ChatGPT、Claude、Gemini 等 AI 系统](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247525496&idx=1&sn=6253a0da55749336eda176e1d005d061) - [ ] [File Browser 满分漏洞可用于完全控制管理员权限](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247525496&idx=2&sn=8b4589e0dd8a4476339a143d7ead5a5b) - 安全内参 - [ ] [知名巨头近8万台设备所有数据被攻击者一键清空](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247515691&idx=1&sn=78e2677fb53550114e3493275ebd3933) - [ ] [特朗普政府澄清无意让私营公司直接参与进攻性网络行动](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247515691&idx=2&sn=3365f0cb4b3a028a0c66daf525110657) - 漕河泾小黑屋 - [ ] [鹈鹕、Three.js 与 Rebecca](https://mp.weixin.qq.com/s?__biz=MzA4NzQwNzY3OQ==&mid=2247484016&idx=1&sn=a05936dab7c764cc6b6c49e0722ceb3c) - 威努特安全网络 - [ ] [煤矿行业数据备份与恢复:从被动应对走向主动建设](https://mp.weixin.qq.com/s?__biz=MzAwNTgyODU3NQ==&mid=2651141028&idx=1&sn=2c4c04bc06318b7e24619423967b39d5) - 先进攻防 - [ ] [硅谷一线工程师已经集体换语言了,而你还在用 Python 让 AI 写代码](https://mp.weixin.qq.com/s?__biz=MzI1MDA1MjcxMw==&mid=2649908857&idx=1&sn=40b4dbef22cfea743f40ad915026f642) - 黑鸟 - [ ] [美以空袭疑似炸死了伊朗黑客组织头目](https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451185829&idx=1&sn=e7d590503981d4d98c6fc49f250bac31) - 青衣十三楼飞花堂 - [ ] [无数挖坑题的反面](https://mp.weixin.qq.com/s?__biz=MzUzMjQyMDE3Ng==&mid=2247489159&idx=1&sn=5f2cb6420d032394e665d3e67b5ea0ae) - 丁爸 情报分析师的工具箱 - [ ] [【资料】美以伊战争动态](https://mp.weixin.qq.com/s?__biz=MzI2MTE0NTE3Mw==&mid=2651154833&idx=1&sn=81839c22790732e035df057353ec68ec) - 奇安信 CERT - [ ] [今日(2026年3月18日)OpenClaw 最新安全动态总结](https://mp.weixin.qq.com/s?__biz=MzU5NDgxODU1MQ==&mid=2247504790&idx=1&sn=af8d5570d849bbfa5164ccc16391ef5a) - 信安之路 - [ ] [这类漏洞危害有点低,SRC 好像不收录!](https://mp.weixin.qq.com/s?__biz=MzI5MDQ2NjExOQ==&mid=2247500439&idx=1&sn=7b38c27d13109e978fb38bf66b8a513c) - 天黑说嘿话 - [ ] [Claude悄悄更新了Skills生成器,这绝对是一次史诗级升级。](https://mp.weixin.qq.com/s?__biz=MzI5NTQ5MTAzMA==&mid=2247486028&idx=1&sn=4637bc3371996e9bf44e5bd698f108bc) - 君哥的体历 - [ ] [大模型业务隔离与公共WiFi安全合规挑战|总第310周](https://mp.weixin.qq.com/s?__biz=MzI2MjQ1NTA4MA==&mid=2247492376&idx=1&sn=75d00976f9887f6fa24eff950c559c0b) - 安全圈 - [ ] [【安全圈】“ AI 刺客”漏洞披露:小字等方式伪装实现执行恶意代码](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652074842&idx=1&sn=7ee374e3e9bd7db9d13be0e70464f9c8) - [ ] [【安全圈】亲俄黑客:已成功入侵乌克兰所有地区监控摄像头](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652074842&idx=2&sn=2f4aeabae7303769f7ad876ad1ea406b) - [ ] [【安全圈】以色列多个情报和核位置坐标涉嫌数据泄露](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652074842&idx=3&sn=30c015e3ce27284c6d87a40e8044ca1f) - 微步在线 - [ ] [真快!网安人又开始备战了](https://mp.weixin.qq.com/s?__biz=MzI5NjA0NjI5MQ==&mid=2650185651&idx=1&sn=13ec8f4c71ed70a5e7877524d28312d2) - 补天平台 - [ ] [人生第一洞·补天生日季·赢13周年定制鼠标垫!](https://mp.weixin.qq.com/s?__biz=MzI2NzY5MDI3NQ==&mid=2247510411&idx=1&sn=df1888dd422de047b915f3af6d86c1f6) - XCTF联赛 - [ ] [SUCTF 2026 落幕,F1ux战队夺冠!](https://mp.weixin.qq.com/s?__biz=MjM5NDU3MjExNw==&mid=2247516216&idx=1&sn=688fd221986ed17083ac51e198879936) - 字节跳动安全中心 - [ ] [火山引擎ArkClaw开启安全专测!顶尖赏金与限量周边奉上!](https://mp.weixin.qq.com/s?__biz=MzUzMzcyMDYzMw==&mid=2247496097&idx=1&sn=e2cc17a684110a175c97971102e4210c) - 中国信息安全 - [ ] [专题·原创 | 《中华人民共和国网络安全法》修改的背景、内容、创新之处及实施路径研究](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664260382&idx=1&sn=edfa89378365d8dd06e18e3e38b4638b) - [ ] [专家解读 | 筑牢数据产权制度基石 护航数据要素价值释放](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664260382&idx=2&sn=89e197dc47b31080b1c40d5b67ca87e6) - [ ] [最高法:审理未成年人“充值”“打赏”案件应充分考虑各种因素综合判断](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664260382&idx=3&sn=b05f9513c2ea08f007a0796f9a4ea279) - [ ] [前沿 | OpenClaw爆火背后:个人Agent狂欢更需警惕安全风险](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664260382&idx=4&sn=f82e16f2d56e75376eedd3de96ee5d94) - 默安科技 - [ ] [AI+安全,问鼎国际!默安科技斩获日内瓦国际发明展金奖](https://mp.weixin.qq.com/s?__biz=MzIzODQxMjM2NQ==&mid=2247501715&idx=1&sn=2de6a6805e12f8474f029c9fd9c3606f) - 极客公园 - [ ] [OpenClaw 爆火之后,我体验了全球第一个 AI 员工](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653101553&idx=1&sn=1ae1654e9404ef8b6b88f562ff84ebbc) - [ ] [「推理之王」黄仁勋:你们都误会了,1 万亿美元其实很保守](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653101538&idx=1&sn=7cbbaf3b2326a52db86e01f5738750fc) - [ ] [王兴兴:今年机器人会比博尔特更快;QClaw 即将公测,微信入口全面升级;AI 大厂月薪三万疯抢文科生 | 极客早知道](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653101517&idx=1&sn=cebb06637d7e13b0ef83905f48570a33) - dotNet安全矩阵 - [ ] [一文读懂 .NET 中的全局 Global.asax 文件](https://mp.weixin.qq.com/s?__biz=MzUyOTc3NTQ5MA==&mid=2247500961&idx=1&sn=f46c7539e9552d90d99cfd88c0ef3a93) - [ ] [从会话管理模式解读 .NET 身份验证绕过漏洞](https://mp.weixin.qq.com/s?__biz=MzUyOTc3NTQ5MA==&mid=2247500961&idx=2&sn=2d55fe082f1b8c010fce3edbb83f9404) - 阿里安全响应中心 - [ ] [校企联动,实战赋能 | “阿里安全课堂——网络安全实战课”启动仪式顺利举行](https://mp.weixin.qq.com/s?__biz=MzIxMjEwNTc4NA==&mid=2652998719&idx=1&sn=0310d322cf35ac3611e189a0f9422285) - 百度安全应急响应中心 - [ ] [百度“龙虾”全家桶开张 🦞 安全虾正式上岗!](https://mp.weixin.qq.com/s?__biz=MzA4ODc0MTIwMw==&mid=2652543993&idx=1&sn=a791483aa590376688d24950018f2b18) - [ ] [养龙虾,别“虾”浪!直击龙虾市集 PLUS「安全实战工坊」!](https://mp.weixin.qq.com/s?__biz=MzA4ODc0MTIwMw==&mid=2652543993&idx=2&sn=7ccb6152e3812fa9ea653703dd786067) - 嘶吼专业版 - [ ] [AI时代中国网络安全产业的五年变局|| 网络安全投融资的残酷分流](https://mp.weixin.qq.com/s?__biz=MzI0MDY1MDU4MQ==&mid=2247587192&idx=1&sn=9249672f878a7569760533a4b1702e08) - [ ] [嘶吼安全动态|360回应“安全龙虾”私钥泄露:已吊销证书,系发布失误微博Delta工业通信系统曝高危漏洞](https://mp.weixin.qq.com/s?__biz=MzI0MDY1MDU4MQ==&mid=2247587192&idx=2&sn=d5708b179033ace845fbf6c326179368) - 数世咨询 - [ ] [智能体时代 漏洞管理要跃迁到10.0版本](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247542152&idx=1&sn=e4f8d27e7483ea61c05cb216315a205b) - [ ] [RSAC 2026创新沙盒 | Charm Security:构建面向新型诈骗的AI反欺诈平台](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247542152&idx=2&sn=13b44720cd63ef9657740c9a55a3536b) - 火绒安全 - [ ] [火绒小问答——「企业版」升级提示需要SHA-2签名补丁](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247531498&idx=1&sn=6960ff377eb1fdcf8f8e1c31bc6878a7) - [ ] [诚邀渠道合作伙伴共启新征程](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247531498&idx=2&sn=0d7d7d60d47b84d7c1f97115f97aae30) - 枇杷熟了 - [ ] [枇杷熟了-全球网络安全日报2026-03-18](https://mp.weixin.qq.com/s?__biz=MzU0MzkzOTYzOQ==&mid=2247489991&idx=1&sn=71d6806bff3de9fec3fb202318ca463f) - 慢雾科技 - [ ] [SlowMist × Bitget AI 安全报告:把钱交给“龙虾”等 AI Agent 真的安全吗?](https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&mid=2247504477&idx=1&sn=57f7323b9460df2d03b15f39de4e4dd1) - 京东安全应急响应中心 - [ ] [春日活动开启 漏洞挖掘奖励翻倍!](https://mp.weixin.qq.com/s?__biz=MjM5OTk2MTMxOQ==&mid=2727850679&idx=1&sn=aaa05bacb10d70d6c87c7df11161606e) - ChaMd5安全团队 - [ ] [2026SUCTF Writeup by Mini-Venom](https://mp.weixin.qq.com/s?__biz=MzIzMTc1MjExOQ==&mid=2247514199&idx=1&sn=23642f4e23ebda5d4e4288e85df33aa3) - 360数字安全 - [ ] [政企"养虾"遭遇安全暗礁?360终端安全智能体为"龙虾"穿上防弹衣](https://mp.weixin.qq.com/s?__biz=MzA4MTg0MDQ4Nw==&mid=2247585445&idx=1&sn=80d95bd79404a43e105263a84976666a) - 情报分析师 - [ ] ["伊朗无迫切威胁",一份情报评估如何在战争前夜被扔进废纸篓](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650567083&idx=1&sn=6b802fadfbf031a90743567fcf1778ec) - 威胁猎人Threat Hunter - [ ] [【信贷欺诈】2026年消费贷骗贷新变化:“真实补缴”成为主流手法](https://mp.weixin.qq.com/s?__biz=MzI3NDY3NDUxNg==&mid=2247503012&idx=1&sn=158dd4bdd37c58e0b89baa3f5635a719) - 迪哥讲事 - [ ] [【SRC实战】JS逆向到成功注入](https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&mid=2247499184&idx=1&sn=8dab95bb1d5d8ef2641743d6a1d33d57) - 安全行者老霍 - [ ] [人工智能驱动的机器人入侵 GitHub Actions Workflows](https://mp.weixin.qq.com/s?__biz=Mzg3NjU4MDI4NQ==&mid=2247486146&idx=1&sn=d807cac09d9e5208b0fe8a1f3c697476) - Qualys Security Blog - [ ] [5 Steps to Turn Compliance Checks into Audit Outcomes](https://blog.qualys.com/category/product-tech) - 国家互联网应急中心CNCERT - [ ] [网络安全信息与动态周报2026年第11期(3月9日-3月15日)](https://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw==&mid=2247501338&idx=1&sn=66aa356734dfb5c7a086817e03aca355) - DEF CON Announcements! - [ ] [Call for Hosts: Hacker Jeopardy at DEF CON Singapore](https://defcon.org/html/defcon-singapore/dc-singapore-cfhjh.html) - 字节跳动技术团队 - [ ] [如何让你的 Agent 更准确:MCP 工具设计技巧](https://mp.weixin.qq.com/s?__biz=MzI1MzYzMjE0MQ==&mid=2247518900&idx=1&sn=59be28fe7297a2833af1d548464a899a) - [ ] [【养虾人必读】告别黑盒!让你的 OpenClaw 像水晶一样透明](https://mp.weixin.qq.com/s?__biz=MzI1MzYzMjE0MQ==&mid=2247518900&idx=2&sn=a2cbb2b36c97873db034e76b66bf5b90) - 云鼎实验室 - [ ] [铸刃止戈,以智御危|第二届腾讯云黑客松智能渗透挑战赛等你来战!](https://mp.weixin.qq.com/s?__biz=MzU3ODAyMjg4OQ==&mid=2247497377&idx=1&sn=65ac55e18ace67362a053e603f405d28) - Over Security - Cybersecurity news aggregator - [ ] [Aura confirms data breach exposing 900,000 marketing contacts](https://www.bleepingcomputer.com/news/security/aura-confirms-data-breach-exposing-900-000-marketing-contacts/) - [ ] [Russia-linked hackers use advanced iPhone exploit to target Ukrainians](https://therecord.media/russia-linked-hackers-use-iphone-exploit-ukraine) - [ ] [CISA orders feds to patch Zimbra XSS flaw exploited in attacks](https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-zimbra-xss-flaw-exploited-in-attacks/) - [ ] [DHS nominee Mullin pressed on restoring CISA staffing](https://therecord.media/dhs-mullin-pressed-on-restoring-cisa-staffing) - [ ] [US intelligence chief grilled on absence of election threats in security assessment](https://therecord.media/us-intel-chief-senate-election-security-threat-assessment) - [ ] [ConnectWise patches new flaw allowing ScreenConnect hijacking](https://www.bleepingcomputer.com/news/security/connectwise-patches-new-flaw-allowing-screenconnect-hijacking/) - [ ] [Bank software vendor Marquis says more than 670,000 impacted by August breach](https://therecord.media/marquis-bank-vendor-data-breach) - [ ] [Ransomware gang exploits Cisco flaw in zero-day attacks since January](https://www.bleepingcomputer.com/news/security/interlock-ransomware-exploited-secure-fmc-flaw-in-zero-day-attacks-since-january/) - [ ] [Cyble and Optiv Partner to Bring Digital Risk Protection to Managed Security Operations](https://cyble.com/blog/cyble-and-optiv-partner-to-bring-digital-risk-protection-to-managed-security-operations/) - [ ] [Storm-2561 e il SEO poisoning: così con falsi client VPN rubano credenziali](https://www.cybersecurity360.it/news/storm-2561-e-il-seo-poisoning-cosi-con-falsi-client-vpn-rubano-credenziali/) - [ ] [Marquis: Ransomware gang stole data of 672K people in cyberattack](https://www.bleepingcomputer.com/news/security/marquis-ransomware-gang-stole-data-of-672-000-people-in-2025-cyberattack/) - [ ] [Apple corregge WebKit senza aggiornare iOS: debuttano i Background Security Improvements](https://www.cybersecurity360.it/news/apple-corregge-webkit-senza-aggiornare-ios-debuttano-i-background-security-improvements/) - [ ] [Russians caught stealing personal data from Ukrainians with new advanced iPhone hacking tools](https://techcrunch.com/2026/03/18/russians-caught-stealing-personal-data-from-ukrainians-with-new-advanced-iphone-hacking-tools/) - [ ] [CISA official says agency has not seen uptick in cyber threats amid Iran war](https://therecord.media/cisa-official-says-agency-has-not-seen-uptick-cyber-threats-iran) - [ ] [Inside DarkSword: A New iOS Exploit Kit Delivered Via Compromised Legitimate Websites](https://iverify.io/blog/darksword-ios-exploit-kit-explained) - [ ] [New “Darksword” iOS exploit used in infostealer attack on iPhones](https://www.bleepingcomputer.com/news/security/new-darksword-ios-exploit-used-in-infostealer-attack-on-iphones/) - [ ] [The Refund Fraud Economy: Exploiting Major Retailers and Payment Platforms](https://www.bleepingcomputer.com/news/security/the-refund-fraud-economy-exploiting-major-retailers-and-payment-platforms/) - [ ] [Nordstrom's email system abused to send crypto scams to customers](https://www.bleepingcomputer.com/news/security/nordstroms-email-system-abused-to-send-crypto-scams-to-customers/) - [ ] [Handala, cosa sapere del cyber gruppo iraniano che attacca l’Occidente](https://www.cybersecurity360.it/nuove-minacce/handala-cosa-saper-del-cyber-gruppo-iraniano-che-attacca-loccidente/) - [ ] [Moscow seeks to limit internet to state-approved websites amid ongoing outages](https://therecord.media/moscow-seeks-to-limit-internet-to-state-approved-sites) - [ ] [Agentic AI Run Fraud Campaigns Earning 4.5 Times More: Interpol](https://thecyberexpress.com/agentic-ai-run-fraud-campaigns-interpol/) - [ ] [AI-Powered Cyber Warfare: How Autonomous Attack Agents Are Changing the Threat Landscape](https://cyble.com/blog/ai-powered-cyber-warfare-attack-agents/) - [ ] [The SOC Files: Time to “Sapecar”. Unpacking a new Horabot campaign in Mexico](https://securelist.com/horabot-campaign/119033/) - [ ] [Maxi truffe travestite da informazioni finanziarie sfruttano l’advertising di Meta: come proteggersi](https://www.cybersecurity360.it/news/maxi-truffe-travestite-da-informazioni-finanziarie-sfruttano-ladvertising-di-meta-come-proteggersi/) - [ ] [L’AI nella kill chain: i vantaggi e le perplessità nella guerra in Iran](https://www.cybersecurity360.it/nuove-minacce/lai-nella-kill-chain-i-vantaggi-e-le-perplessita-nella-guerra-in-iran/) - [ ] [How a Ukrainian Vishing Ring Stole €2M From EU Citizens — and Nearly Got Away](https://thecyberexpress.com/ukraine-based-vishing-ring/) - [ ] [How to Reduce MTTR in Your SOC with Better Threat Intelligence](https://any.run/cybersecurity-blog/reduce-soc-mttr-with-ti/) - [ ] [La sicurezza dell’Active Directory come pilastro della cyber security](https://www.cybersecurity360.it/outlook/la-sicurezza-dellactive-directory-come-pilastro-della-cyber-security/) - [ ] [Transparent COM instrumentation for malware analysis](https://blog.talosintelligence.com/transparent-com-instrumentation-for-malware-analysis/) - [ ] [Fusion Fireside #17: Inside the Chinese Smishing Triad with Gary Warner](https://www.threatfabric.com/blogs/fusion-fireside-17-inside-the-chinese-smishing-triad-with-gary-warner) - [ ] [CRIL Flags Growing Threat of Middle East Cyber Attacks and Hacktivist Campaigns](https://thecyberexpress.com/middle-east-cyber-warfare-escalates-rapidly/) - [ ] [How Cortex XDR BIOC Rules Could Become an Attack Surface](https://thecyberexpress.com/cortex-xdr-bioc-rules-security-risk/) - [ ] [‘Give to Gain’ is Relevant for Security and Resilience: Bonnie Butlin, Chats with TCE](https://thecyberexpress.com/bonnie-butlin-interview/) - [ ] [FBI Intensifies Crackdown on Thai Scam Centers Targeting Americans](https://thecyberexpress.com/fbi-in-thailand-scam-centers/) - [ ] [Aura - 903,080 breached accounts](https://haveibeenpwned.com/Breach/Aura) - [ ] [Crypto e-commerce platform Bitrefill accuses North Korea of stealing 18,500 purchase records](https://therecord.media/crypto-platform-accuses-north-korea-hack) - [ ] [Apple pushes first Background Security Improvements update to fix WebKit flaw](https://www.bleepingcomputer.com/news/security/apple-pushes-first-background-security-improvements-update-to-fix-webkit-flaw/) - [ ] [Rischio AI: falle in Amazon Bedrock, LangSmith e SGLang](https://www.securityinfo.it/2026/03/17/rischio-ai-falle-in-amazon-bedrock-langsmith-e-sglang/) - ICT Security Magazine - [ ] [Supply chain software, attacco npm PyPI: 454.000 pacchetti malevoli e il primo worm autoreplicante che ha cambiato tutto](https://www.ictsecuritymagazine.com/articoli/supply-chain-software/) - [ ] [Data Breach sanitari: minacce informatiche e protezione dati personali nel sistema sanitario italiano](https://www.ictsecuritymagazine.com/articoli/data-breach-sanitari/) - JUMPSEC - [ ] [ALBIROX Malware Analysis](https://www.jumpsec.com/guides/albirox-malware-analysis/) - SANS Internet Storm Center, InfoCON: green - [ ] [Scans for "adminer", (Wed, Mar 18th)](https://isc.sans.edu/diary/rss/32808) - [ ] [ISC Stormcast For Wednesday, March 18th, 2026 https://isc.sans.edu/podcastdetail/9854, (Wed, Mar 18th)](https://isc.sans.edu/diary/rss/32806) - Have I Been Pwned latest breaches - [ ] [Aura - 903,080 breached accounts](https://haveibeenpwned.com/Breach/Aura) - Schneier on Security - [ ] [Meta’s AI Glasses and Privacy](https://www.schneier.com/blog/archives/2026/03/metas-ai-glasses-and-privacy.html) - Instapaper: Unread - [ ] [Hundreds of Millions of iPhones Can Be Hacked With a New Tool Found in the Wild](https://www.wired.com/story/hundreds-of-millions-of-iphones-can-be-hacked-with-a-new-tool-found-in-the-wild/) - [ ] [Mac Imaging Made Easy with Fuji](https://www.youtube.com/watch?v=9ZkLdFodhzM) - [ ] [A Study in DFIR Open-Source, Enterprise, and the Art of Analysis](https://bakerstreetforensics.com/2026/03/18/a-study-in-dfir-open-source-enterprise-and-the-art-of-analysis/) - [ ] [Looks Can Lie Is That Really an NVMe Drive](https://blog.elcomsoft.com/2026/03/looks-can-lie-is-that-really-an-nvme-drive/) - TorrentFreak - [ ] [Cloudflare Challenges Legality of Italy’s “Piracy Shield”, Appeals €14 Million Fine](https://torrentfreak.com/cloudflare-challenges-legality-of-italys-piracy-shield-appeals-e14-million-fine/) - Trend Micro Research, News and Perspectives - [ ] [Why East-West Visibility Matters for Grid Security](https://www.trendmicro.com/en_us/research/26/c/why-east-west-visibility-matters-for-grid-security.html) - [ ] [From Misconfigured Spring Boot Actuator to SharePoint Exfiltration: How Stolen Credentials Bypass MFA](https://www.trendmicro.com/en_us/research/26/c/from-misconfigured-spring-boot-actuator-to-sharepoint-exfiltrati.html) - Security Affairs - [ ] [U.S. CISA adds Microsoft SharePoint and Zimbra flaws to its Known Exploited Vulnerabilities catalog](https://securityaffairs.com/189628/security/u-s-cisa-adds-microsoft-sharepoint-and-zimbra-flaws-to-its-known-exploited-vulnerabilities-catalog.html) - [ ] [Researchers warn of unpatched, critical Telnetd flaw affecting all versions](https://securityaffairs.com/189620/hacking/researchers-warn-of-unpatched-critical-telnetd-flaw-affecting-all-versions.html) - [ ] [CVE-2026-3888: Ubuntu Desktop 24.04+ vulnerable to Root exploit](https://securityaffairs.com/189614/security/cve-2026-3888-ubuntu-desktop-24-04-vulnerable-to-root-exploit.html) - [ ] [Robotic surgery firm Intuitive reports data breach after targeted phishing attack](https://securityaffairs.com/189598/data-breach/robotic-surgery-firm-intuitive-reports-data-breach-after-targeted-phishing-attack.html) - [ ] [Tracking the Iran War: A Month of Escalation and Regional Impact](https://securityaffairs.com/189604/cyber-warfare-2/tracking-the-iran-war-a-month-of-escalation-and-regional-impact.html) - Securityinfo.it - [ ] [DarkSword: exploit chain iOS tra zero-day, spyware e cybercrime finanziario](https://www.securityinfo.it/2026/03/18/darksword-exploit-chain-ios-tra-zero-day-spyware-e-cybercrime-finanziario/?utm_source=rss&utm_medium=rss&utm_campaign=darksword-exploit-chain-ios-tra-zero-day-spyware-e-cybercrime-finanziario) - The Hacker News - [ ] [OFAC Sanctions DPRK IT Worker Network Funding WMD Programs Through Fake Remote Jobs](https://thehackernews.com/2026/03/ofac-sanctions-dprk-it-worker-network.html) - [ ] [Interlock Ransomware Exploits Cisco FMC Zero-Day CVE-2026-20131 for Root Access](https://thehackernews.com/2026/03/interlock-ransomware-exploits-cisco-fmc.html) - [ ] [Critical Unpatched Telnetd Flaw (CVE-2026-32746) Enables Unauthenticated Root RCE](https://thehackernews.com/2026/03/critical-telnetd-flaw-cve-2026-32746.html) - [ ] [Claude Code Security and Magecart: Getting the Threat Model Right](https://thehackernews.com/2026/03/claude-code-security-and-magecart.html) - [ ] [9 Critical IP KVM Flaws Enable Unauthenticated Root Access Across Four Vendors](https://thehackernews.com/2026/03/9-critical-ip-kvm-flaws-enable.html) - [ ] [Product Walkthrough: How Mesh CSMA Reveals and Breaks Attack Paths to Crown Jewels](https://thehackernews.com/2026/03/product-walkthrough-how-mesh-csma.html) - [ ] [Ubuntu CVE-2026-3888 Bug Lets Attackers Gain Root via systemd Cleanup Timing Exploit](https://thehackernews.com/2026/03/ubuntu-cve-2026-3888-bug-lets-attackers.html) - [ ] [Apple Fixes WebKit Vulnerability Enabling Same-Origin Policy Bypass on iOS and macOS](https://thehackernews.com/2026/03/apple-fixes-webkit-vulnerability.html) - NetSPI - [ ] [Meet NetSPI’s Modern Pentesting Experience: Use Case-Driven, AI-Accelerated](https://www.netspi.com/blog/executive-blog/netspi-updates/netspis-modern-pentesting-experience-use-case-driven-ai-accelerated/) - The Register - Security - [ ] [Okta made a nightmare micromanager for your AI agents](https://go.theregister.com/feed/www.theregister.com/2026/03/18/okta_agent_micromanager/) - [ ] [State snoops and spyware vendors planting info-stealing malware on iPhones, Google warns](https://go.theregister.com/feed/www.theregister.com/2026/03/18/darksword_exploit_kit_steals_iphone/) - [ ] [Amazon security boss says crims abused max-security Cisco firewall flaw weeks before disclosure](https://go.theregister.com/feed/www.theregister.com/2026/03/18/amazon_cisco_firewall_0_day_ransomware/) - [ ] [North Korea's 100,000-strong fake IT worker army rake in $500M a year for Kim Jong Un](https://go.theregister.com/feed/www.theregister.com/2026/03/18/researchers_lift_the_lid_on/) - [ ] [Britain's satellite-watching gap to be plugged with £17.5M eyeball in Cyprus](https://go.theregister.com/feed/www.theregister.com/2026/03/18/miniastry_of_defence_to_spend/) - [ ] [Iran's cyberattack against med tech firm is 'just the beginning'](https://go.theregister.com/feed/www.theregister.com/2026/03/18/irans_cyberattack_against_stryker/) - [ ] [Linux Foundation kicks off effort to shield FOSS maintainers from AI slop bug reports](https://go.theregister.com/feed/www.theregister.com/2026/03/18/linux_foundation_ai_slop_defense/) - [ ] [Japan to allow ‘proactive cyber-defense’ from October 1st](https://go.theregister.com/feed/www.theregister.com/2026/03/18/japan_proactive_cyber_defense_enabled/) - DEFION Research Labs - [ ] [Ruckus Unleashed: Multiple vulnerabilities exploited](/en/research-labs/ruckus-unleashed-multiple-vulnerabilities-exploited) - [ ] [Pwn2Own Automotive 2024: Hacking the Autel MaxiCharger](/en/research-labs/pwn2own-automotive-2024-hacking-the-autel-maxicharger) - [ ] [Pwn2Own Automotive 2024: Hacking the JuiceBox 40](/en/research-labs/pwn2own-automotive-2024-hacking-the-juicebox-40) - [ ] [Pwn2Own Automotive 2024: Hacking the ChargePoint Home Flex (and their cloud...)](/en/research-labs/pwn2own-automotive-2024-hacking-the-chargepoint-home-flex-and-their-cloud) - [ ] [DoNex/DarkRace Ransomware Decryptor](/en/research-labs/donex-darkrace-ransomware-decryptor) - [ ] [CVE-2024-20693: Windows cached code signature manipulation](/en/research-labs/cve-2024-20693-windows-cached-code-signature-manipulation) - [ ] [Bringing process injection into view(s): exploiting all macOS apps using nib files](/en/research-labs/bringing-process-injection-into-view-s-exploiting-all-macos-apps-using-nib-files) - [ ] [Don’t Talk All at Once! Elevating Privileges on macOS by Audit Token Spoofing](/en/research-labs/don-t-talk-all-at-once-elevating-privileges-on-macos-by-audit-token-spoofing) - [ ] [Getting SYSTEM on Windows in style](/en/research-labs/getting-system-on-windows-in-style) - [ ] [Technical analysis of the Genesis Market](/en/research-labs/technical-analysis-of-the-genesis-market) - [ ] [Bad things come in large packages: .pkg signature verification bypass on macOS](/en/research-labs/bad-things-come-in-large-packages-pkg-signature-verification-bypass-on-macos) - [ ] [Pwn2Own Miami 2022: ICONICS GENESIS64 Arbitrary Code Execution](/en/research-labs/pwn2own-miami-2022-iconics-genesis64-arbitrary-code-execution) - [ ] [Pwn2Own Miami 2022: Unified Automation C++ Demo Server DoS](/en/research-labs/pwn2own-miami-2022-unified-automation-c-demo-server-dos) - [ ] [Pwn2Own Miami 2022: AVEVA Edge Arbitrary Code Execution](/en/research-labs/pwn2own-miami-2022-aveva-edge-arbitrary-code-execution) - [ ] [Process injection: breaking all macOS security layers with a single vulnerability](/en/research-labs/process-injection-breaking-all-macos-security-layers-with-a-single-vulnerability) - [ ] [Pwn2Own Miami 2022: Inductive Automation Ignition Remote Code Execution](/en/research-labs/pwn2own-miami-2022-inductive-automation-ignition-remote-code-execution) - [ ] [Pwn2Own Miami 2022: OPC UA .NET Standard Trusted Application Check Bypass](/en/research-labs/pwn2own-miami-2022-opc-ua-net-standard-trusted-application-check-bypass) - [ ] [CoronaCheck App TLS certificate vulnerabilities](/en/research-labs/coronacheck-app-tls-certificate-vulnerabilities) - [ ] [Sandbox escape + privilege escalation in StorePrivilegedTaskService](/en/research-labs/sandbox-escape-privilege-escalation-in-storeprivilegedtaskservice) - [ ] [Proctorio Chrome extension Universal Cross-Site Scripting](/en/research-labs/proctorio-chrome-extension-universal-cross-site-scripting) - [ ] [Zoom RCE from Pwn2Own 2021](/en/research-labs/zoom-rce-from-pwn2own-2021) - [ ] [Adobe Acrobat privilege escalation](/en/research-labs/adobe-acrobat-privilege-escalation) - [ ] [iOS VPN support: 3 different bugs](/en/research-labs/ios-vpn-support-3-different-bugs) - [ ] [Sign in with Apple - authentication bypass](/en/research-labs/sign-in-with-apple-authentication-bypass) - [ ] [Jenkins - authentication bypass](/en/research-labs/jenkins-authentication-bypass) - [ ] [DNS rebinding for HTTPS](/en/research-labs/dns-rebinding-for-https) - [ ] [Spring Security - insufficient cryptographic randomness](/en/research-labs/spring-security-insufficient-cryptographic-randomness) - [ ] [XenServer - path traversal leading to authentication bypass](/en/research-labs/xenserver-path-traversal-leading-to-authentication-bypass) - [ ] [Volkswagen Auto Group MIB infotainment system - unauthenticated remote code execution as root](/en/research-labs/volkswagen-auto-group-mib-infotainment-system-unauthenticated-remote-code-execution-as-root) - [ ] [NAPALM - command execution on NAPLM controller from host](/en/research-labs/napalm-command-execution-on-naplm-controller-from-host) - [ ] [MySQL Connector/J - Unexpected deserialisation of Java objects](/en/research-labs/mysql-connector-j-unexpected-deserialisation-of-java-objects) - [ ] [Ansible - command execution on Ansible controller from host](/en/research-labs/ansible-command-execution-on-ansible-controller-from-host) - [ ] [Observium - unauthenticated remote code execution](/en/research-labs/observium-unauthenticated-remote-code-execution) - [ ] [cSRP/srpforjava - obtaining of hashed passwords](/en/research-labs/csrp-srpforjava-obtaining-of-hashed-passwords) - [ ] [StartEncrypt - obtaining valid SSL certificates for unauthorized domains](/en/research-labs/startencrypt-obtaining-valid-ssl-certificates-for-unauthorized-domains) - Yak Project - [ ] [前端加密测不动?全局热加载帮你自动接管签名流程](https://mp.weixin.qq.com/s?__biz=Mzk0MTM4NzIxMQ==&mid=2247529542&idx=1&sn=842ef4d1b0ac87a8dd4a234ee88e7be5) - Security Weekly Podcast Network (Audio) - [ ] [Language of the Board as CISO-Board Time Falls Short and CISOs Struggle with Risk - Ben Wilcox - BSW #439](http://sites.libsyn.com/18678/language-of-the-board-as-ciso-board-time-falls-short-and-cisos-struggle-with-risk-ben-wilcox-bsw-439)
每日安全资讯(2026-03-19)