-
Notifications
You must be signed in to change notification settings - Fork 40
Open
Labels
Description
每日安全资讯(2026-03-26)
- 离别歌
- Microsoft Security Blog
- SecWiki News
- Private Feed for M09Ic
- ZeddYu starred HKUDS/OpenSpace
- mgeeky starred jsacco/DataOnlyGadget
- liamg contributed to infracost/go-proto
- github released v0.4.2 at github/spec-kit
- liamg contributed to infracost/proto
- Rvn0xsy starred GreatScott/enject
- INotGreen starred VectifyAI/PageIndex
- kpcyrd forked kpcyrd/minify-html from wilsonzlin/minify-html
- Mel0day starred boxlite-ai/boxlite
- safedv starred S1lkys/KslKatz
- PrefectHQ released 3.6.24.dev3 at PrefectHQ/prefect
- gh0stkey starred lima-vm/lima
- anthropics released v2.1.83 at anthropics/claude-code
- gh0stkey starred imumesh18/acpx
- 先知安全技术社区
- Doonsec's feed
- Kali Code Executor:三层Agent驱动的Kali容器渗透代码执行平台
- 泛微E-cology10 getEmDsList接口存在敏感信息泄露 附POC
- 一个来自法国的基于K8s的规模化扫描集群
- 日本自卫队成立 3200 人的情报作战集团
- 红队实战指南:AI驱动的渗透测试、红队评估和漏洞挖掘
- 从“拿到一个点”到“管好一批点”:CyberStrikeAI WebShell 管理 MCP 联动实录
- Web3学习【001】:别再误解去中心化,它从来不是“没人管”
- 华为员工爆料:领导问我愿不愿意到非洲上班,工资45000元,5年,双倍年终奖。
- 想监控内网传输的文件?用Suricata这个功能就够了
- 26年1月到3月威胁情报IOC
- “网易UU远程”专项活动,获取额外最高10万元奖励!
- 张雪峰的8句话
- 你今天看到的平静,可能只是黑客留给你的幻觉
- 论文研读与思考|CKGFuzzer:基于代码知识图谱的 LLM 驱动的模糊测试驱动程序生成
- 安全预警:Apifox 桌面客户端官方 CDN 脚本遭供应链投毒
- LiteLLM 供应链攻击事件始末
- 中国电信:全面转向Token经营!
- Yakit AI Agent使用指南
- OpenAI推智能体商业协议,ChatGPT内可比价下单
- 兴业银行杭州分行关于2026年AI+转型培训项目供应商征集
- frida源码分析
- 双碳背景下新能源汽车热管理数字化开发技术
- 【风险提醒】Apifox疑似被投毒
- 最后几小时!数码荔枝「国货之光」大促,这 4 款 AI 工具即将恢复原价
- 网安行业要被颠覆了?
- 通过 AI-Skill 分析 flutter so 文件实现明文抓包以及生成frida脚本
- 一个神奇的关注者
- 求前n个自然数4次幂的和
- 第108天-Shiro安全攻防:从JRMP到CC1,揭秘无利用链下的RCE新思路
- 第107天-Shiro 550 漏洞深度解析:无 CC 依赖?CB 链一招制敌!
- 别只盯着 Claude Code 了!OpenCode + Oh My OpenCode 开启 AI 编程新纪元
- 开箱即用!OpenClaw实战Skill大全,新手直接起飞
- 【安全风险预警】接入开源 AI 组件企业速自查,AI 供应链投毒风险来袭
- [漏洞复现]全程云OA QCHMS.asmx SQL注入漏洞(VEID-2026-11106)
- Agent开发|从0实现Agent(四):构建基于DAG图的任务系统(复杂任务协同篇)
- 【免费送!】红队实战指南:AI驱动的渗透测试、红队评估和漏洞挖掘
- Butter Cookie——web多功能渗透测试浏览器插件
- 警惕!LiteLLM 遭供应链“连环套”投毒:从 Trivy 沦陷到 4.8 亿次下载量的威胁
- 安全日报 | 2026年3月25日
- 跟着红队笔记打靶:nullbyte
- 高级免杀对抗&红队武器化开发 第七期来袭
- 每天1-2小时,收入200,看似不体面,却能赚钱的小生意,(适合长期做)
- 一场关于AI和安全度量产品的发布直播
- 昨晚,9500万次下载的AI神器被投毒
- 两天两位大佬猝死!41岁、43岁,再牛的人,也扛不住拼命
- 基于Firefox的Claude Code Security实测漏洞发掘
- 用 Claude + Temporal.io 构建多 Agent 协作开发流水线
- 抢占职场竞争力先机!4月CISP、CISSP、CISA开班倒计时
- 薪资低,考PMP?清醒的人早已靠它逆袭职场
- 生效延期!欧盟AI法案最新进展与监管变数
- 【漏洞预警】LiteLLM 投毒、Apifox 后门连发,敲响供应链安全警钟
- 从4.8亿下载量的 LiteLLM投毒事件,看 AI 基础设施安全攻与防
- 3️⃣1️⃣5️⃣
- 个人信息授权撤回告知书
- 守护 AI 应用?Wiz AI应用防护平台全面上线
- 【AI安全】守护 AI 应用?Wiz AI 应用防护平台全面上线
- LiteLLM供应链投毒事件解析【聚合情报】
- 针锋相对:Cardinal黑客的指控,安全分析师的质疑,谁将定义“真相”?
- AI驱动的“OpenClaw陷阱”活动通过植入木马的GitHub仓库攻击开发者和游戏玩家
- 【安全圈】上海警方深入推进“涉企网络谣言”打击整治:处置 270 余个违规账号,AI 洗稿编造车企销量下滑等行为被严惩
- 【安全圈】AI 圈地震:月安装量约 9500 万次的 API 网关 LiteLLM 遭投毒
- 【安全圈】HackerOne 披露员工数据泄露事件:第三方服务商 Navia 遭入侵
- 雷神加速器称遭受恶意网络攻击,正在紧急修复
- THE CAR HACKER’S HANDBOOK 解读第一章
- 美国“灰熊”新型多用途低成本分布式导弹发射方案
- 美伊以冲突近日情况简报(3.23~3.24)
- 2005 年 vs 2014 年
- 第十九届全国大学生信息安全竞赛(创新实践能力赛)暨第三届“长城杯”网数智安全大赛(防护赛)半决赛(湖北赛区)成功举办
- 探索跨域与跨森林的 RBCD 攻击
- 【0day】深科特 LEAN MES系统 /Handler/FileSync.ashx 任意文件读取/上传/删除/SSRF等多个漏洞
- 0基础挖src最先要了解的三大经典漏洞详解,东西不多相信你能吃下!
- 专家观点丨信创背景下市政行业工业信息化安全探讨
- 荐读丨AI失控时刻:智能体协同入侵公司内部系统,窃取机密数据
- 最新版深信服官方网络安全培训课程(80集完整版)
- WEB渗透安全工程师精英培养计划班(全阶段课程目录)
- 某平台安全等级保护培训PPT(2026最新合规版)
- 等保标准文件合集(含国标+实施指南+测评要求)
- 网络安全等级保护生意如何做(商业实战PPT)
- XX电子政务项目等级保护建设方案(完整Word版)
- XX医院等保建设方案实战(医疗行业专属PPT)
- 深信服等级保护整体解决方案(厂商实战版PPT)
- 什么?龙虾能与龙虾直接对话 你只需要看着?
- 如何解决OpenClaw权限“Open”、数据“可捞”等安全大难题
- 苹果漏洞利用工具遭公开,数亿台iPhone随时可被静默入侵窃密
- RSAC 2026现场激辩:人机协同不可持续,AI将主导网络防御?
- Apifox被投毒:SSH密钥、Git凭证是如何在不知不觉中被偷走的
- 安全已死,网络安全发展时间轴
- 一文读懂:智能体身份权限治理演进实录
- 还在花钱买Token?15个免费平台速存
- 【FATF最新报告解读】稳定币与非托管钱包P2P交易成监管新焦点,如何破局?
- 被制裁和悬赏的周年纪念
- 被美国悬赏后的影响有多大
- 【高危AI漏洞预警】OpenClaw环境变量注入漏洞 (CVE-2026-22177)
- CISP-PTE考试综合靶场简单模拟测试
- 从靶场到实战--双一流高校多个高危漏洞
- 【免费领】HW护网行动面试真题(100道&含解答)
- 启明星辰护航第十九届全国大学生信息安全竞赛暨第三届“长城杯”半决赛圆满举办
- RSAC街头采访,“本届RSAC您最大的观感是什么?”
- 深度解析:LiteLLM 供应链投毒事件——TeamPCP 三阶段后门全链路分析
- 鹅厂员工的龙虾都长什么样?
- 踏寻红色足迹,笃行政绩初心——海南世纪网安党支部主题党日活动
- 网警提醒|上海警方深入推进 “涉企网络谣言”打击整治
- AI开发者警惕!波及DSPy、MLflow等主流框架,底层库 litellm 遭投毒,专偷访问凭证
- 张雪峰争议:一个教育网红的崛起、争议与时代回响
- 从hackerbot-claw自动化利用到LiteLLM投毒
- 信通院联合腾讯云发布《云上养虾(OpenClaw)安全指南》
- 梆梆安全荣膺中关村网信联盟 “2025年度联盟最佳合作伙伴单位” ,以生态协同筑牢网络安全防线
- Der Flounder
- 嘶吼 RoarTalk – 网络安全行业综合服务平台,4hou.com
- Recent Commits to cve:main
- obaby 𝐢𝐧⃝ void
- Google Online Security Blog
- Chromium Blog
- Insinuator.net
- Tenable Blog
- Horizon3.ai
- Securelist
- Bug Bounty in InfoSec Write-ups on Medium
- Reverse Engineering
- Announcing ida-mcp 2.0: A Headless MCP Server for IDA Pro
- CounterPoint: Using Hardware Event Counters to Refute and Refine Microarchitectural Assumptions
- es posible bypassear un bot de opciones binarias o crackear licencias? usa google sheets para administrar. pregunto porque me estafaron y quiero aunque sea ver si funciona ese .exe
- Intigriti
- Malwarebytes
- ADD / XOR / ROL
- The Trail of Bits Blog
- daniel.haxx.se
- 绿盟科技技术博客
- Dancho Danchev's Blog - Mind Streams of Information Security Knowledge
- When Data Mining Conti Leaks Leads to Actual Binaries and to a Hardcoded C2 With an Encryption Key on Tripod.com - Part Five
- Personally Identifiable Information (PII) for Major Ransomware Groups from the RAMP (Russian Anonymous Marketplace) Forum - A Compilation
- A Full List of Usernames and Handles from the RAMP (Russian Anonymous Marketplace) Forum - A Compilation
- Offensive Security Blog: Latest Trends in Hacking | Praetorian
- 奇客Solidot–传递最新科技情报
- 白帽酱の博客
- 黑海洋Wiki | AI机器人硬件开发 | 网络安全攻防实战 | 区块链技术文档教程 - 免费资源平台
- 黑鸟
- 安全分析与研究
- 威努特安全网络
- 漕河泾小黑屋
- Black Hills Information Security, Inc.
- 代码卫士
- 奇安信 CERT
- 腾讯安全应急响应中心
- 安全内参
- 微步在线研究响应中心
- 看雪学苑
- 暗影安全
- 长亭安全应急响应中心
- 天御攻防实验室
- 黑哥虾撩
- 信息安全国家工程研究中心
- 丁爸 情报分析师的工具箱
- 中国信息安全
- 安全圈
- 安全牛
- 君哥的体历
- 微步在线
- 数世咨询
- 补天平台
- 极客公园
- 嘶吼专业版
- 慢雾科技
- 腾讯安全威胁情报中心
- 情报分析师
- 墨菲安全
- 迪哥讲事
- 国家互联网应急中心CNCERT
- 360数字安全
- 威胁猎人Threat Hunter
- 安全行者老霍
- Arturo Di Corinto
- Over Security - Cybersecurity news aggregator
- GitHub adds AI-powered bug detection to expand security coverage
- PolyShell attacks target 56% of all vulnerable Magento stores
- CISA's acting chief warns shutdown is increasing cyber risks, causing resignations
- Bubble AI app builder abused to steal Microsoft account credentials
- New Torg Grabber infostealer malware targets 728 crypto wallets
- USA, stop all’import di router consumer esteri: le 3 campagne d’attacco alla base del divieto
- Russia arrests alleged owner of cybercrime forum LeakBase, report says
- Supply chain attack hits widely-used AI package, risks impacting thousands of companies
- Ransomware attack disrupts operation at major Spanish fishing port
- Citrix urges admins to patch NetScaler flaws as soon as possible
- Puerto Rico government agency cancels driver’s license appointments after cyberattack
- Analisi statica del codice: con LiSA la tecnologia italiana sale sul podio mondiale
- Russian botnet operator linked to major ransomware attacks sentenced in US
- Paid AI Accounts Are Now a Hot Underground Commodity
- The Agentic AI Attack Surface: Prompt Injection, Memory Poisoning, and How to Defend Against Them
- UK cyber chief urges ‘full court press’ to counter rising cyber threats
- Kali Linux 2026.1 released with 8 new tools, new BackTrack mode
- Esquema de Phishing GTFire: Evitando la detección mediante servicios de Google
- PTC Warns of Critical Windchill, FlexPLM Flaw Enabling Remote Code Execution
- AI Omnibus, così l’UE vuole riscrivere le regole: cosa cambia per privacy e compliance
- TP-Link warns users to patch critical router auth bypass flaw
- Anatomy of a Cyber World Global Report 2026
- The FCC Just Blocked Every New Foreign-Made Router from the U.S. Market
- Kamasers Analysis: A Multi-Vector DDoS Botnet Targeting Organizations Worldwide
- MSSQLand – Lightweight MS-SQL Interaction Tool for Lateral Movement and Post-Exploitation
- Manager of botnet used in ransomware attacks gets 2 years in prison
- CISA, FBI Warn of Phishing Campaign Targeting Messaging App Users
- Head of Russian Cybercrime Group Mario Kart Sentenced for Locking Out Dozens of U.S. Businesses
- Prompt injection, un male senza cura (parola di OpenAI)
- ‘Vibe Coding’ Needs Guardrails, Says NCSC Amid Rising AI Security Concerns
- Cloud Phones: The Invisible Threat
- Dutch Finance Ministry Investigates Data Breach in Internal Systems
- Securityinfo.it
- 吾爱破解论坛
- 纽创信安
- 字节跳动技术团队
- ICT Security Magazine
- SANS Internet Storm Center, InfoCON: green
- Schneier on Security
- 安全419
- The Hacker News
- LeakBase Admin Arrested in Russia Over Massive Stolen Credential Marketplace
- GlassWorm Malware Uses Solana Dead Drops to Deliver RAT and Steal Browser, Crypto Data
- The Kill Chain Is Obsolete When Your AI Agent Is the Threat
- Russian Hacker Sentenced to 2 Years for TA551 Botnet-Driven Ransomware Attacks
- Device Code Phishing Hits 340+ Microsoft 365 Orgs Across Five Countries via OAuth Abuse
- FCC Bans New Foreign-Made Routers Over Supply Chain and Cyber Risk Concerns
- SEI Blog
- GRAHAM CLULEY
- TorrentFreak
- Security Affairs
- Russian national convicted for running botnet used in attacks on U.S. firms
- Patch now: TP-Link Archer NX routers vulnerable to firmware takeover
- Recent Navia data breach impacts HackerOne employee data
- FCC targets foreign router imports amid rising cybersecurity concerns
- Cybercrime group Lapsus$ claims the hack of pharma giant AstraZeneca
- Malicious LiteLLM versions linked to TeamPCP supply chain attack
- Deeplinks
- Instapaper: Unread
- Technical Information Security Content & Discussion
- TP-Link Patches Archer NX Auth Bypass, Still Faces Security Lawsuit
- Weaponizing Windows Toast Notifications for Social Engineering
- TeamPCP deploys CanisterWorm on NPM following Trivy compromise
- Navia breach exposed HackerOne employee PII due to a BOLA-style access in third-party system
- CVE-2026-33656: EspoCRM ≤ 9.3.3 — Formula engine ACL gap + path traversal → authenticated RCE (full write-up + PoC)
- GlassWorm: Part 6. Fake Trezor Suite and Ledger Live for macOS, per-request polymorphic builds.
- LiteLLM supply chain compromise - a complete analysis
- Stackfield Desktop App: RCE via Path Traversal and Arbitrary File Write (CVE-2026-28373)
- Our first pentest on a 100% Vibe coded application : analysis & feedback
- Information Security
- Your Open Hacker Community
- Social Engineering
- netsecstudents: Subreddit for students studying Network Security and its related subjects
- The Register - Security
- AI supply chain attacks don’t even require malware…just post poisoned documentation
- Scammers have virtual smartphones on speed dial for fraud
- Jen Easterly, cybersecurity's 'relentless optimist,' hopes feds come back to RSAC next year
- Only Trump can decide when cyberwar turns into real war
- Enterprise PCs are unreliable, unpatched, and unloved compared to Macs
- Blackhat Library: Hacking techniques and research
- Deep Web
- Security Weekly Podcast Network (Audio)
Reactions are currently unavailable