# 每日安全资讯(2026-07-28) - SecWiki News - [ ] [SecWiki News 2026-07-27 Review](http://www.sec-wiki.com/?2026-07-27) - Doonsec's feed - [ ] [【吃瓜】26HVV飞侠哥,事件全程爽点笑不停](https://mp.weixin.qq.com/s/PHHhRVJ5X8rb_05hYksW1A) - [ ] [Wi-Fi 路由器选择指南](https://mp.weixin.qq.com/s/Rq8VCZW6myjAIuTZBJhVCA) - [ ] [一名合格红队的成长之路](https://mp.weixin.qq.com/s/K-Goi1MoAcDJf_udcEuZJA) - [ ] [【吃瓜】19岁日薪1200天才hacker的陨落](https://mp.weixin.qq.com/s/b_TBbDbya3uXO_lIyNJPWQ) - [ ] [AI辅助app逆向实战视频教程大全更新](https://mp.weixin.qq.com/s/3bq9fkgBUiiezeYF4E9ueA) - [ ] [AI 大模型生成内容安全评测方法发布](https://mp.weixin.qq.com/s/EF_7zNiHySGXQm64dGfItQ) - [ ] [直播预告:同样的思路凭啥他下课就能挖2W?](https://mp.weixin.qq.com/s/w1vrPWSAfYngONJqlT26Ag) - [ ] [(限时文章)安全天书课程|助力实战免杀钓鱼](https://mp.weixin.qq.com/s/Ry0fHqOTc8aCB9E1nE0XtA) - [ ] [Invicti 26.7.0 更新 - 漏洞扫描神器!](https://mp.weixin.qq.com/s/ZZ_s9cBW5Y4QOauvjfgrPA) - [ ] [智能时代的安全底座:从数据合规到AI原生防护](https://mp.weixin.qq.com/s/-CuvCxPo9RjdHuO2K4Rqkg) - [ ] [国家网信办、公安部联合公布《小型个人信息处理者个人信息保护简化措施规定》](https://mp.weixin.qq.com/s/me2jEQh7Bo_W0L4UiDX3PA) - [ ] [关注!2026年第30周工信领域大事要闻](https://mp.weixin.qq.com/s/f3CrFFNC0ck5TZQmpxoqZg) - [ ] [400万元的惨痛教训:高危补丁不补,就是给诈骗分子留 “正门”](https://mp.weixin.qq.com/s/1iEiXTwRjN8Kl4U3Lep0DQ) - [ ] [湛江市网信办查处未备案生成式AI服务 违规App涉有害信息被立案处罚](https://mp.weixin.qq.com/s/lLGCMkYbQ4OhFRBMdB-uUw) - [ ] [AI快讯:连连与银联国际达成智能体支付合作 ,企业微信智能助理开启内测](https://mp.weixin.qq.com/s/sO79QrzJAXc2mU92PjrRfw) - [ ] [PentesterFlow开源,AI打通渗透测试全流程](https://mp.weixin.qq.com/s/iKnl4WaJnAdFbkEaXUNALw) - [ ] [一等奖!启明星辰再获国家级行业权威奖项](https://mp.weixin.qq.com/s/UjntvnsakZP8IunSujR3AQ) - [ ] [缺口100万+,这行严重缺人!有计算机底子的直接躺赢...](https://mp.weixin.qq.com/s/cRSPKaSj_SYMUJm1BBgk5A) - [ ] [告警消减99.94%、年省800万成本,大型食品巨头如何用AISOC重塑安全运营?](https://mp.weixin.qq.com/s/mMvztx4Hf5t08aLRxpbz7w) - [ ] [黑客用偷来的数据“零元购”,这家上市公司损失超8800万元](https://mp.weixin.qq.com/s/RohRsJorfa58d6lah2Hb7w) - [ ] [喜报 | 海南世纪网安勇夺第四届“熵密杯”密码安全挑战赛全国三等奖](https://mp.weixin.qq.com/s/NMwvO-q0cY8jqkvthllsdw) - [ ] [安全简讯(2026.07.27)](https://mp.weixin.qq.com/s/r712OnXz1PcxUapMjlYGsQ) - [ ] [【漏洞通告】Fastjson2 AutoType校验绕过远程代码执行漏洞](https://mp.weixin.qq.com/s/K9tzMuWWhMA_2Ls9JF4qIg) - [ ] [白皮书丨东北大学:2025年工业控制网络安全态势白皮书(附下载)](https://mp.weixin.qq.com/s/8Dfwpimp_KRt4mf33q5jZQ) - [ ] [国家标准丨7月1日起,《智能工厂安全一体化》系列国家标准实施(附下载)](https://mp.weixin.qq.com/s/1S1MWwUpd0AUytodNmHfog) - [ ] [50亿美元加码,美国重注“创世纪计划”](https://mp.weixin.qq.com/s/apGvnmX5IBOw7KHY-Nh-FQ) - [ ] [AUTOSAR EcuM 模块详解 —— 基于 EcuMFlex 状态机与启停休眠机制](https://mp.weixin.qq.com/s/C4PFbOEhsRi0liN3L4bQFw) - [ ] [RoboSec 2026首届中国具身智能安全大会定档9月,开启具身AI安全守护元年](https://mp.weixin.qq.com/s/68i9WdhUL78z4cncMuJx-g) - [ ] [AI系统的信息安全风险与防护策略](https://mp.weixin.qq.com/s/x7r-AEMZ92EIqn-Y5Ix_Lg) - [ ] [鼎信安全xa0|xa0网络安全一周资讯](https://mp.weixin.qq.com/s/bvQN8HKxb98vKMHc-wLa9w) - [ ] [WAIC|观安信息入选人工智能安全漏洞治理联盟首批成员](https://mp.weixin.qq.com/s/1aAYCJ_Wkph4m0T8EV1Nzg) - [ ] [技术文件 | 第九届全国职工职业技能大赛人工智能训练师赛项](https://mp.weixin.qq.com/s/AlCo7vqddYnA9F-OQA--1w) - [ ] [2026黄鹤杯网络安全人才创新大赛学生组(Misc部分)](https://mp.weixin.qq.com/s/HEDRih5xoCFJtxCi2AAK8g) - [ ] [算力网 | 智能经济时代的“国家电网”](https://mp.weixin.qq.com/s/umKMEqtw6gHbsZATVqzLOA) - [ ] [Web常见漏洞合集,420页Web应用安全权威指南(附PDF)](https://mp.weixin.qq.com/s/RgweNfBqPltqeznbjzXsOA) - [ ] [无问AI模型网络安全工程化问题评测结果](https://mp.weixin.qq.com/s/1XrEe_w9Y_jiZKVcG9kZhw) - [ ] [我做了一个用自然语言挖漏洞的 AI 渗透工具:VulnClaw](https://mp.weixin.qq.com/s/fnuSmqUoRNglZ3tu4ceb6Q) - [ ] [昌平办公选址 - 未来财经产业园(金河水务办公楼 )](https://mp.weixin.qq.com/s/wvmj6zlGxo2Me7jzFii1rw) - [ ] [CNCERT:关于Dysphoria僵尸网络大范围传播的风险提示](https://mp.weixin.qq.com/s/FKbHzhq9NPDqgafo5l4eEQ) - [ ] [Fastjson2劲爆RCE!!!官方临时缓解建议。](https://mp.weixin.qq.com/s/KNJxeZ8XfRukdKlWOe30ag) - [ ] [罚单| 未建立健全全流程数据安全管理制度,未开展风险评估,重庆企业被罚](https://mp.weixin.qq.com/s/9x-gt6IinQEb3CkdWItdYQ) - [ ] [第一届好靶场综合赛比赛结果排行名单](https://mp.weixin.qq.com/s/QghWV4kr5m74aiFcwUF6Sg) - [ ] [未来,也许不用再自己开发 AI 自动化系统了](https://mp.weixin.qq.com/s/SWLoLz43ucgbZQsax6JFOQ) - [ ] [修养](https://mp.weixin.qq.com/s/UCBJEd4nWNJhgUJIE0mNSw) - [ ] [协会在京参加2026“网安联·中国行”北京站党建联学活动](https://mp.weixin.qq.com/s/p_gpXGfxtfas8XWEDjblvQ) - [ ] [NodeBB 修复由AI发现的8个漏洞,可暴露管理员访问权限和私密聊天记录](https://mp.weixin.qq.com/s/mVz8_Lg6xOkFjzMCExk2Tg) - [ ] [Claude AI共享聊天记录被指出现在谷歌搜索结果中](https://mp.weixin.qq.com/s/iG5C8egDZVADbUycqmEG3Q) - [ ] [江南信安荣登《网络安全企业100强》,排名跃升17位彰显硬核实力](https://mp.weixin.qq.com/s/a4kp74uFPDL3OVEW1ISVXA) - [ ] [关注 | 网信部门严管“自媒体”未规范标注信息来源行为](https://mp.weixin.qq.com/s/p4QCiU-S1pvZKLf0AySphA) - [ ] [【edu通杀刷分】CVE-2026-63030/60137-Wp2Shell命令执行+SQL注入](https://mp.weixin.qq.com/s/ueK61lTVaHIWmD86XvyNEQ) - [ ] [网安原创文章推荐【2026/7/26】](https://mp.weixin.qq.com/s/SNQXp8X7kOJjbqqpsJ7qGA) - [ ] [模型开源,力破西方偏见](https://mp.weixin.qq.com/s/_4J8tMmeVRY7Aoydp5OYgQ) - [ ] [荣获浙江省安防科学技术进步奖!迪普科技视频网安全运营技术再获权威认可](https://mp.weixin.qq.com/s/55yZ6vqhRLYf4p2dR1Ph7g) - [ ] [聚力护航数智济南!中孚信息当选济南市网络空间安全协会首届会长单位](https://mp.weixin.qq.com/s/Kgdg7oVedREiLP2WCilJ5Q) - [ ] [某SRC连环druid下的全回显SSRF](https://mp.weixin.qq.com/s/R0N2Poeb-H-DravhW2InAw) - [ ] [2026HVV红蓝情报分析交流群(广告勿扰)](https://mp.weixin.qq.com/s/OWxz8hsQEpsueCuR-CHjqw) - [ ] [刚升到 Gitea 1.27.0 以为安全了?两个 0day 直接 RCE](https://mp.weixin.qq.com/s/PONVOe9ehMxbB86HiVKSQw) - [ ] [俄语黑客利用谷歌Gemini命令行界面控制了八台牙科诊所电脑的僵尸网络](https://mp.weixin.qq.com/s/SiBq_7ltYzWbbaInPeIzOQ) - [ ] [You know what I mean](https://mp.weixin.qq.com/s/PnS5vksgEyAkw9dEvr3iXA) - [ ] [震惊!这款开源工具让 AWS 运维效率直接飙升 10 倍](https://mp.weixin.qq.com/s/XKoWVgzOcaiHIsVICcQFDQ) - [ ] [广东省安全智能新技术重点实验室陈斌课题组在 CCF A 类会议 KDD 2026 发表3DGS 后门攻击研究成果](https://mp.weixin.qq.com/s/XwoCYBo8M0xJoTRem2t54w) - [ ] [你的硬盘,真的在加密吗?—一场38块固态硬盘的跨品牌测试,撕开\"硬件加密\"的信任黑箱](https://mp.weixin.qq.com/s/ZdyaJqbk7USFG9I1bmAr9A) - [ ] [国家网信办、公安部联合公布《小型个人信息处理者个人信息保护简化措施规定》;缅甸妙瓦底电诈园区数月内大规模复建 | 牛览](https://mp.weixin.qq.com/s/LHkXtMKYnhLH-PKuJW7wTw) - [ ] [1分钟理解TCP/IP模型](https://mp.weixin.qq.com/s/n9CpN12f0ggPZnQSvSbiRA) - [ ] [甘肃烽侦网络安全研究院在京参加2026“网安联·中国行”北京站党建联学活动](https://mp.weixin.qq.com/s/mBawKvjsL3nYLdxm8pf-dQ) - [ ] [河南农商银行社招,涉AI算法工程师、AI应用工程师](https://mp.weixin.qq.com/s/5d5sZtDF1X5xpBBqxV86iA) - [ ] [智能自动化漏洞挖掘平台 -- AutoHunter](https://mp.weixin.qq.com/s/-8C2V0a_pNmNfZXhcoxpgw) - [ ] [谁在给美国情报系统换血,普尔特上任四十天观察](https://mp.weixin.qq.com/s/MjrepDPCgS5M9-XydQlHdQ) - [ ] [hvv 2026 - 钓鱼邮件不需要你点链接了:ZimReaper 证明,\"看见\"就够了](https://mp.weixin.qq.com/s/-o9GDvtu7z69007vYjPFXw) - [ ] [人民日报:这些涉灾网络谣言要严查](https://mp.weixin.qq.com/s/0589vqNIwtcRtklo05diYA) - [ ] [AI红队通用越狱技术,可突破GPT-5.6、Opus 5和Fable](https://mp.weixin.qq.com/s/8KLql2kk5BZPV27yYPVCXQ) - [ ] [Excel+Copilot杀疯了!半导体行业分析10分钟搞定](https://mp.weixin.qq.com/s/deaOOC5JU2sKJcVbIaMa7A) - [ ] [御话资讯 | 安全动态,一文速览](https://mp.weixin.qq.com/s/JVg1gk7owBiahzoZ1EHG0g) - [ ] [一个吉利:从“多生孩子好打架”到“握指成拳”](https://mp.weixin.qq.com/s/taD9rjie9xi0EbrMSZRssw) - [ ] [智攻智防:探索 AI 时代安全新范式](https://mp.weixin.qq.com/s/cWb42D0NSbv3xLlDRLMOIw) - [ ] [Claude Max 20x 订阅漏洞分析](https://mp.weixin.qq.com/s/OODDmAA5v8Wb0tN1jvUtMQ) - [ ] [谷歌因搜索引擎及应用商店运营违规,依据欧盟《数字市场法案》被罚款 8.9 亿欧元](https://mp.weixin.qq.com/s/RHuGIsf4WFHJcDKIeqD4EA) - [ ] [黑客劫持酒店无线网络,窃取微软 365 账号凭证](https://mp.weixin.qq.com/s/rVNy7bDVqz1_7PEW7AqBzw) - [ ] [澳大利亚能源供应商 Origin Energy 披露发生数据泄露事件,大量客户信息遭到波及。](https://mp.weixin.qq.com/s/HIBDFntk_-6rnq7JASegmg) - [ ] [公开征集45名网络安全从业者升名校研究生!基层人员均可报名参加!](https://mp.weixin.qq.com/s/c4zs9pOgAEUe32s-9TUaWA) - [ ] [俄罗斯情报部门劫持网络摄像头监控向乌克兰运送武器](https://mp.weixin.qq.com/s/43Sf9g7V_zO_38ic8SzOrg) - [ ] [在家里哪里都能待?就是不能在自己房间?学术垃圾也有它的作用?大学生破防就在一瞬?这点东西能饱?减肥后突然有点理解男?](https://mp.weixin.qq.com/s/9hgihvtuq9hyQeATQ5xvvQ) - [ ] [开源|无需桌面端!WEB版桌面AI渗透智能体 Web 独立版架构解析](https://mp.weixin.qq.com/s/bS_itVhd5rqfD8hbxNjPkQ) - [ ] [想做副业起号的可以看看这个](https://mp.weixin.qq.com/s/4nGXoRbSVDag5_sehZgOxQ) - [ ] [基于人工智能算法的船舶通信网络安全性能研究](https://mp.weixin.qq.com/s/gij80TxImvhpH9QExP2D1Q) - [ ] [电子取证大事记(2026年7月21日 — 7月26日)](https://mp.weixin.qq.com/s/m_dfLxttCP4iAFZiaZDbLA) - [ ] [国际顶尖安全专家打造的Windows AAA体系权威实战指南上市了!](https://mp.weixin.qq.com/s/lGZKgJh6xU9URDf-UYu4fA) - [ ] [行业首次公开披露!AI自主攻击真实发生!OpenAI 模型“失控”事件背后,企业该如何构建AI安全防线](https://mp.weixin.qq.com/s/CmQFSGF-pItAFJKFV-E4_w) - [ ] [能源行业数据分类分级指南(2026年版)原文](https://mp.weixin.qq.com/s/cP5Lb5Y39yPUAIfJoO9URw) - [ ] [国家能源局对印发《能源行业数据分类分级指南(2026年版)》回答记者提问。](https://mp.weixin.qq.com/s/z6A47gxlVbkHdFb2MWX2aw) - [ ] [教育行业SRC供应商漏洞变化 (2026-07-27)](https://mp.weixin.qq.com/s/8EoP3RnjXrsoEcbz5ddHkw) - [ ] [超低成本户外气象基站](https://mp.weixin.qq.com/s/9RvSo9Uugkq5nR5K6poa1g) - [ ] [java安全基础—注解](https://mp.weixin.qq.com/s/l5CV142Y_Ak7vXy0daSaHw) - [ ] [域渗透、Kerberos、NTLM看不懂?免费送4本Windows安全圣经](https://mp.weixin.qq.com/s/w1NorX4kzCCjdflqEMKdgA) - [ ] [你能不能三句话讲清你这单](https://mp.weixin.qq.com/s/3Kh_8W3QfLr9IbfcBMN-mA) - [ ] [涉案1400万余元、盗印221万余册!制售盗版图书产业链被斩断](https://mp.weixin.qq.com/s/HIyMtX04uObi4TCGLxuCRw) - [ ] [见面就给20万\"现金\"?警惕\"交友投资理财诈骗\"升级版!](https://mp.weixin.qq.com/s/O8NnslZtKh4WFL9KBKAXqg) - [ ] [扫码点餐竟跳出赌博网站!过期二维码被抢注,沦为涉黄涉赌\"暗门\"](https://mp.weixin.qq.com/s/-EhawE8ZeNh21IcffXTA2w) - [ ] [吃透APP逻辑漏洞挖掘思路:汇总越权、信息泄露、重放刷VIP、加固后仍挖出高危逻辑漏洞等真实实战案例](https://mp.weixin.qq.com/s/kX3gnGpTPU06rrJTsEyb6A) - [ ] [上传矢量图即攻陷必应,数据流成高危攻击面](https://mp.weixin.qq.com/s/UWA9BOmENq5MD-UrcA5qYw) - [ ] [弹窗不是打扰,是终端安全防线的“特洛伊入口”](https://mp.weixin.qq.com/s/u8UiSSRLfBW6U983HScy0A) - [ ] [一图读懂《中国个人信息保护报告(2025年)》](https://mp.weixin.qq.com/s/UrkRUhcf54sR5ltCWK59vg) - Microsoft Security Blog - [ ] [Rethinking security for the age of AI](https://blogs.microsoft.com/blog/2026/07/27/rethinking-security-for-the-age-of-ai/) - [ ] [Enhancing AI security through global AI red teaming](https://www.microsoft.com/en-us/security/blog/2026/07/27/enhancing-ai-security-through-global-ai-red-teaming/) - Paper - 知道创宇404实验室 - [ ] [基于 DW-HKEM 的量子弹性银行交易安全:一种混合 RSA/ML-KEM 加密网关与实时监控系统](https://paper.seebug.org/3507) - Recent Commits to cve:main - [ ] [Update Mon Jul 27 12:20:45 UTC 2026](https://github.com/trickest/cve/commit/be44b05b9428dc18bc0705cf60dd8d8640cd49b1) - ElcomSoft blog - [ ] [Microsoft Office Passwords: What Comes Off in Seconds, What Takes Longer, and Why](https://blog.elcomsoft.com/2026/07/microsoft-office-passwords-what-comes-off-in-seconds-what-takes-longer-and-why/) - Private Feed for M09Ic - [ ] [spf13 starred gojargo/jargo](https://github.com/gojargo/jargo) - [ ] [strands-agents released typescript/v1.11.2 at strands-agents/harness-sdk](https://github.com/strands-agents/harness-sdk/releases/tag/typescript/v1.11.2) - [ ] [bolucat released 202607272143 at bolucat/Archive](https://github.com/bolucat/Archive/releases/tag/202607272143) - [ ] [usestrix released v1.4.1 at usestrix/strix](https://github.com/usestrix/strix/releases/tag/v1.4.1) - [ ] [oiweiwei released v1.5.2 at oiweiwei/go-msrpc](https://github.com/oiweiwei/go-msrpc/releases/tag/v1.5.2) - [ ] [chainreactors released v0.0.0-nightly.20260727 at chainreactors/aiscan](https://github.com/chainreactors/aiscan/releases/tag/v0.0.0-nightly.20260727) - [ ] [usestrix released v1.4.0 at usestrix/strix](https://github.com/usestrix/strix/releases/tag/v1.4.0) - [ ] [CHYbeta starred firecrawl/firecrawl](https://github.com/firecrawl/firecrawl) - [ ] [ring04h starred facebook/memlab](https://github.com/facebook/memlab) - [ ] [esrrhs contributed to esrrhs/fakelua](https://github.com/esrrhs/fakelua/pull/282) - [ ] [ZeddYu starred clawkwork/clawk](https://github.com/clawkwork/clawk) - [ ] [wuhan005 starred NikolayS/PGSimCity](https://github.com/NikolayS/PGSimCity) - [ ] [CHYbeta starred Yeti-791/Awesome-Offensive-AI-Agentic-Landscape](https://github.com/Yeti-791/Awesome-Offensive-AI-Agentic-Landscape) - [ ] [RuoJi6 released v0.5.66 at RuoJi6/dbx-audit](https://github.com/RuoJi6/dbx-audit/releases/tag/v0.5.66) - [ ] [lz520520 starred elastic/protections-artifacts](https://github.com/elastic/protections-artifacts) - [ ] [FunnyWolf starred Vigil-SOC/vigil](https://github.com/Vigil-SOC/vigil) - Blog on STAR Labs - [ ] [When AI Makes 0-Days Feel Like N-Days](https://starlabs.sg/blog/2026/07-when-ai-makes-0-days-feel-like-n-days/) - Exodus Intelligence - [ ] [From Virtual Share to Physical Shell: Leveraging Windows’ Inconsistent Access Control for LPE](https://blog.exodusintel.com/2026/07/27/from-virtual-share-to-physical-shell-leveraging-windows-inconsistent-access-control-for-lpe/) - Insinuator.net - [ ] [Your Android Bluetooth Traffic Captures Should Be Live](https://insinuator.net/2026/07/your-android-bluetooth-traffic-captures-should-be-live/) - Horizon3.ai - [ ] [World Wide Technology and Horizon3 Launch Strategic Partnership to Rewrite the Cybersecurity Playbook for the AI Era](https://horizon3.ai/news/press-release/wwt-horizon3-partnership/) - [ ] [The New Measure of Infrastructure Readiness](https://horizon3.ai/intelligence/blogs/infrastructure-readiness/) - GuidePoint Security - [ ] [What You Need to Know about AI Security](https://www.guidepointsecurity.com/blog/what-you-need-to-know-about-ai-security/) - Bug Bounty in InfoSec Write-ups on Medium - [ ] [Unauthenticated Disclosure of A/B Test Data in Convert Pro — How Two Forgotten AJAX Endpoints…](https://infosecwriteups.com/unauthenticated-disclosure-of-a-b-test-data-in-convert-pro-how-two-forgotten-ajax-endpoints-dbefc9c3e440?source=rss----7b722bfd1b8d--bug_bounty) - [ ] [One Header Away from 10+ GB of Customer Documents (PII) — $6K Bounty](https://infosecwriteups.com/one-header-away-from-10-gb-of-customer-documents-pii-6k-bounty-0c0ac8c335f2?source=rss----7b722bfd1b8d--bug_bounty) - [ ] [How I Found a Bug Worth $3,500 — In a Feature Nobody Was Watching.](https://infosecwriteups.com/how-i-found-a-bug-worth-3-500-in-a-feature-nobody-was-watching-6773df9fce72?source=rss----7b722bfd1b8d--bug_bounty) - [ ] [How I Found an Auth Flaw in a Government Site: From GraphQL Introspection to Unauthorized Access](https://infosecwriteups.com/how-i-found-an-auth-flaw-in-a-government-site-from-graphql-introspection-to-unauthorized-access-0c877cc3ee07?source=rss----7b722bfd1b8d--bug_bounty) - [ ] [How a Simple Profile Update Led to Cross-Tenant Data Exposure](https://infosecwriteups.com/how-a-simple-profile-update-led-to-cross-tenant-data-exposure-b945842678e2?source=rss----7b722bfd1b8d--bug_bounty) - PortSwigger Blog - [ ] [Introducing Burp AT: agentic AI, built on two decades of Burp Suite](https://portswigger.net/blog/introducing-burp-at) - Malwarebytes - [ ] [Aftercall ads are driving Android users crazy](https://www.malwarebytes.com/blog/news/2026/07/aftercall-ads-are-driving-android-users-crazy) - [ ] [Sextortion scammers are exploiting ShinyHunters data leaks](https://www.malwarebytes.com/blog/scams/2026/07/sextortion-scammers-are-exploiting-shinyhunters-data-leaks) - [ ] [What’s your data worth on the dark web? (Lock and Code S07E15)](https://www.malwarebytes.com/blog/podcast/2026/07/whats-your-data-worth-on-the-dark-web-lock-and-code-s07e15) - [ ] [A week in security (July 20 – July 26)](https://www.malwarebytes.com/blog/news/2026/07/a-week-in-security-july-20-july-26) - Wallarm - [ ] [Lessons from the OpenAI and Hugging Face Incident: When Safety Filters Disarm the Defender](https://lab.wallarm.com/hugging-face-open-ai-incident/) - daniel.haxx.se - [ ] [HTTP Message Signatures with curl](https://daniel.haxx.se/blog/2026/07/27/http-message-signatures-with-curl/) - HackerNews - [ ] [Steam 论坛 ClickFix 攻击向游戏玩家植入 XMRig 加密货币矿机](http://0.0.0.0:8080/post/64518) - [ ] [研究员发布 GitLab RCE PoC,允许认证用户以 git 身份执行命令](http://0.0.0.0:8080/post/64517) - [ ] [Cl0p 关联组织利用未认证 RCE 漏洞攻击暴露在互联网上的 PTC Windchill 和 FlexPLM](http://0.0.0.0:8080/post/64516) - [ ] [Fastjson 1.x RCE 漏洞遭攻击利用,目前尚无可用补丁](http://0.0.0.0:8080/post/64515) - [ ] [Hermes AI 智能体被用于自动化攻击泰国财政部](http://0.0.0.0:8080/post/64514) - [ ] [Rockwell 修复 Arena 仿真软件中的代码执行漏洞](http://0.0.0.0:8080/post/64513) - 奇客Solidot–传递最新科技情报 - [ ] [可再生能源有望成为全球最大的发电来源](https://www.solidot.org/story?sid=84937) - [ ] [干涸湖床释放出大量的碳](https://www.solidot.org/story?sid=84936) - [ ] [没有快乐的颓废时代](https://www.solidot.org/story?sid=84935) - [ ] [日本作家东野圭吾因癌症去世,享年 68 岁](https://www.solidot.org/story?sid=84934) - [ ] [中国计划克隆 100 头优质牦牛](https://www.solidot.org/story?sid=84933) - [ ] [抹香鲸靠吐泡泡维持睡眠时的平衡](https://www.solidot.org/story?sid=84932) - [ ] [欧洲北美野火肆虐](https://www.solidot.org/story?sid=84931) - [ ] [亚马逊要求第三方卖家标记 AI 生成图像](https://www.solidot.org/story?sid=84930) - [ ] [35 名学生有 32 名在历史考试中使用 AI 生成答案](https://www.solidot.org/story?sid=84929) - [ ] [华为据报道在建造内存芯片工厂](https://www.solidot.org/story?sid=84928) - 绿盟科技技术博客 - [ ] [Ubuntu 26 root shutdown时被拒](https://blog.nsfocus.net/ubuntu-26-root-shutdown%e6%97%b6%e8%a2%ab%e6%8b%92/) - 黑鸟 - [ ] [Turla,深耕欧洲二十多年的俄罗斯APT组织](https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451187851&idx=1&sn=bb39dd04e9e7d69b759ecf676882048a) - 黑海洋Wiki | AI机器人硬件开发 | 网络安全攻防实战 | 区块链技术文档教程 - 免费资源平台 - [ ] [英伟达押注OpenAI前首席科学家创业公司](https://blog.upx8.com/%E8%8B%B1%E4%BC%9F%E8%BE%BE%E6%8A%BC%E6%B3%A8OpenAI%E5%89%8D%E9%A6%96%E5%B8%AD%E7%A7%91%E5%AD%A6%E5%AE%B6%E5%88%9B%E4%B8%9A%E5%85%AC%E5%8F%B8) - [ ] [亚马逊入局卫星通信大战:计划部署5000颗卫星 瞄准移动终端用户](https://blog.upx8.com/%E4%BA%9A%E9%A9%AC%E9%80%8A%E5%85%A5%E5%B1%80%E5%8D%AB%E6%98%9F%E9%80%9A%E4%BF%A1%E5%A4%A7%E6%88%98-%E8%AE%A1%E5%88%92%E9%83%A8%E7%BD%B25000%E9%A2%97%E5%8D%AB%E6%98%9F-%E7%9E%84%E5%87%86%E7%A7%BB%E5%8A%A8%E7%BB%88%E7%AB%AF%E7%94%A8%E6%88%B7) - 腾讯玄武实验室 - [ ] [每日安全动态推送(26/7/27)](https://mp.weixin.qq.com/s?__biz=MzA5NDYyNDI0MA==&mid=2651960527&idx=1&sn=aa137b4bb5a6331afb1ea964ccff68bb) - 微步在线研究响应中心 - [ ] [已复现 | Fastjson2远程代码执行漏洞](https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&mid=2247508781&idx=1&sn=55335d8904b3febd9c1e254a78fc2cc2) - 绿盟科技CERT - [ ] [【漏洞通告】Fastjson 2.x远程代码执行漏洞](https://mp.weixin.qq.com/s?__biz=Mzk0MjE3ODkxNg==&mid=2247493359&idx=1&sn=915333aa5eb9d96178927a9e8851ba71) - 暗影安全 - [ ] [SRC批量关停背后,AI重塑安全攻防](https://mp.weixin.qq.com/s?__biz=MzI2MzA3OTgxOA==&mid=2657165795&idx=1&sn=161cf8cd197db3cfb2e1485958025a49) - Shostack & Friends Blog - [ ] [Lessons from the OpenAI/HuggingFace AI Security Incident](https://shostack.org/blog/lessons-from-openai-huggingface-ai-security/) - 安全内参 - [ ] [泰国财政部遭AI智能体攻陷!攻击基础设施全曝光](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516327&idx=1&sn=97a2eec5fc3226d99f3761bada1e9d77) - [ ] [CNCERT:关于Dysphoria僵尸网络大范围传播的风险提示](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516327&idx=2&sn=fe72e11a43797d3522e14ae90055c670) - 威努特安全网络 - [ ] [连续四年!威努特工业防火墙蝉联中国市场份额第一](https://mp.weixin.qq.com/s?__biz=MzAwNTgyODU3NQ==&mid=2651143214&idx=1&sn=df62867141fadf89bde3c0aa0f5666ab) - 看雪学苑 - [ ] [MacOS企业微信5.0.7逆向分析:如何定位protobuf序列化与反序列化Hook点](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458617805&idx=1&sn=c0941b1d1aeb0c5c4a6ffea08583de66) - [ ] [Fastjson 1.x 新高危RCE漏洞被野外利用,官方尚未推出正式补丁](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458617805&idx=2&sn=e1ee118af48566137e4ba298017311d1) - [ ] [本周内容更新!AI辅助逆向分析:不只是用工具,而是造工具](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458617805&idx=3&sn=99c2c6a258cf509e3ceeef38838ff950) - 青衣十三楼飞花堂 - [ ] [Ubuntu 26 root shutdown时被拒](https://mp.weixin.qq.com/s?__biz=MzUzMjQyMDE3Ng==&mid=2247489796&idx=1&sn=8c1052b5631ff1c6e70281b45889395d) - 安全研究GoSSIP - [ ] [G.O.S.S.I.P 特别推荐 2026-07-27 BLERP 通过重配对给BLE“换锁”](https://mp.weixin.qq.com/s?__biz=Mzg5ODUxMzg0Ng==&mid=2247501903&idx=1&sn=3ba0f12242bf2d18b711af4e46294a53) - 信息安全国家工程研究中心 - [ ] [转载|AI发现漏洞速度远超修补能力 网络风险持续累积](https://mp.weixin.qq.com/s?__biz=MzU5OTQ0NzY3Ng==&mid=2247504535&idx=1&sn=d97f005160b6ebbef3c99e0f0653ffbd) - 长亭安全应急响应中心 - [ ] [【原创0day】Fastjson2 远程代码执行漏洞](https://mp.weixin.qq.com/s?__biz=MzIwMDk1MjMyMg==&mid=2247493275&idx=1&sn=84a8090f201a655ff1e019c2edd57dba) - M01N Team - [ ] [AI安全案例分析 | OpenAI模型自主突破测试边界,利用漏洞入侵Hugging Face](https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&mid=2247495356&idx=1&sn=9844e7939456e9d50a409a01c9f3c240) - 漏洞战争 - [ ] [将工号归于尘土,把名字还给山海](https://mp.weixin.qq.com/s?__biz=MzU0MzgzNTU0Mw==&mid=2247486161&idx=1&sn=933cf2efc8463c02626218f993b30aa9) - 天黑说嘿话 - [ ] [hvv 2026 - 钓鱼邮件不需要你点链接了:ZimReaper 证明,"看见"就够了](https://mp.weixin.qq.com/s?__biz=MzI5NTQ5MTAzMA==&mid=2247486285&idx=1&sn=c7e2811f9b92bd5574e7d5a9620fd657) - 代码卫士 - [ ] [NodeBB 修复由AI发现的8个漏洞,可暴露管理员访问权限和私密聊天记录](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247526733&idx=1&sn=4c426f7be66cbd1f1bd9469fa33cd1f2) - [ ] [Claude AI共享聊天记录被指出现在谷歌搜索结果中](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247526733&idx=2&sn=01ad5a58ef47909459aff86692f5c9a8) - 青藤云安全 - [ ] [重磅捷报|青藤天睿 RASP 连续中标两大全国性银行](https://mp.weixin.qq.com/s?__biz=MzAwNDE4Mzc1NA==&mid=2650851619&idx=1&sn=3a080588fbd897053a3c963136df91ae) - 云鼎实验室 - [ ] [Fastjson2 现远程代码执行漏洞,建议立即升级官方补丁](https://mp.weixin.qq.com/s?__biz=MzU3ODAyMjg4OQ==&mid=2247497858&idx=1&sn=c1bac134fc263afa948bad82607a9028) - 奇安信威胁情报中心 - [ ] [AgentBaiting 与 7600 个恶意仓库背后的 AI 供应链投毒深度解读](https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247519593&idx=1&sn=c76acda96aa4bf690ed9e0e2347bacb6) - 安全牛 - [ ] [你的硬盘,真的在加密吗?—一场38块固态硬盘的跨品牌测试,撕开"硬件加密"的信任黑箱](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142096&idx=1&sn=564f00e7fff7242575cff1d63b0456a6) - [ ] [国家网信办、公安部联合公布《小型个人信息处理者个人信息保护简化措施规定》;缅甸妙瓦底电诈园区数月内大规模复建 | 牛览](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142096&idx=2&sn=3a9366a6bde3106d55ac8885e770a6bf) - 慢雾科技 - [ ] [MistEye DNS Guard 正式发布,轻量构筑主机网络威胁观察防线](https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&mid=2247505576&idx=1&sn=d95846d8cc0014ff38d2f4d27ff20a83) - 字节跳动技术团队 - [ ] [顶会入选 | COVERT —— 面向视觉语言模型的隐私保护推理框架入选 ECCV 2026](https://mp.weixin.qq.com/s?__biz=MzI1MzYzMjE0MQ==&mid=2247521026&idx=1&sn=aa0d13c8287fcf8df9fadbd91dca07da) - 复旦白泽战队 - [ ] [白泽AI威胁情报|一个模型,两个版本,三次泄露,全球封停](https://mp.weixin.qq.com/s?__biz=MzU4NzUxOTI0OQ==&mid=2247499548&idx=1&sn=d41e0a1f77045089c74812add369fb51) - 枇杷熟了 - [ ] [【原创0day】Fastjson2 远程代码执行漏洞](https://mp.weixin.qq.com/s?__biz=MzU0MzkzOTYzOQ==&mid=2247490088&idx=1&sn=a14e827ad3ebfd1e69db9dacd0ebd09c) - CNVD漏洞平台 - [ ] [CNVD漏洞周报2026年第29期](https://mp.weixin.qq.com/s?__biz=MzU3ODM2NTg2Mg==&mid=2247497136&idx=1&sn=6afa6bbee11b2b7fa66ca5a4b21a0df7) - [ ] [上周关注度较高的产品安全漏洞(20260720-20260726)](https://mp.weixin.qq.com/s?__biz=MzU3ODM2NTg2Mg==&mid=2247497136&idx=2&sn=982dd172fe8bf161e4ce77ac7d323754) - 安全学术圈 - [ ] [中国科学院信息工程研究所 | TRAIL:基于知识增强大模型推理的虚假网络威胁情报自动检测](https://mp.weixin.qq.com/s?__biz=MzU5MTM5MTQ2MA==&mid=2247495693&idx=1&sn=e4c5ed9a685c2b9799b012a4d41a773f) - 丁爸 情报分析师的工具箱 - [ ] [【报告】美国专门负责中国方向工作与对华研究机构的开源情报深度调研](https://mp.weixin.qq.com/s?__biz=MzI2MTE0NTE3Mw==&mid=2651156725&idx=1&sn=3ab0231fd9035cec8a5370b8fe25b951) - [ ] [【竞赛通知】第四届全国大学生开源情报数据采集与分析挑战专项(含教学资源)](https://mp.weixin.qq.com/s?__biz=MzI2MTE0NTE3Mw==&mid=2651156725&idx=2&sn=5da85a04efccc70f7a18fd9232438cf8) - 中国信息安全 - [ ] [论坛·原创 | 全球科技变革竞争新图景与“十五五”时期我国科技发展新范式](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265100&idx=1&sn=086d3d4c9371ab7f735bb5bac2f75b27) - [ ] [专家解读 | 吴建平:推动IPv6全面赋能网络空间高质量发展](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265100&idx=2&sn=442d6088eeef786044916faa0dfae313) - [ ] [专家解读|个人信息保护简化措施赋能中小微企业轻装前行](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265100&idx=3&sn=fa31e81f73c87b7d17c7c57712aea173) - [ ] [观点 | 涉未成年人网络娱乐团播的乱象与治理](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265100&idx=4&sn=911458787748489ceb8f0a6155a70d15) - [ ] [评论 | AI支付还需迈过几道坎](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265100&idx=5&sn=1cc047b363365148fce7bb5f1c421352) - 安全圈 - [ ] [【安全圈】苹果崩了!App Store等多项服务故障](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078035&idx=1&sn=c6eb078bd0222bdd28850391afab617d) - [ ] [【安全圈】Steam论坛中招!你的电脑可能在给别人"挖矿"](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078035&idx=2&sn=ebb38f707136dd4740717d87651bfc10) - [ ] [【安全圈】你的AI对话,正在被谷歌"裸奔"](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078035&idx=3&sn=c9cf1059be601fa37dcd7012999ad892) - 希潭实验室 - [ ] [第172篇:方程式远程溢出漏洞检测工具箱v0.68版本发布,大幅度更新](https://mp.weixin.qq.com/s?__biz=MzkzMjI1NjI3Ng==&mid=2247488547&idx=1&sn=23b13837c5635acb63ceda6441bc0b2f) - Qualys Security Blog - [ ] [Qualys Expands Serverless Security with Vulnerability Scanning for AWS Lambda](https://blog.qualys.com/category/product-tech) - [ ] [The Sub-10-Minute Cloud Takeover: How Exposed IAM Keys, Misconfiguration and AI Are Rewriting the Rules of Cloud Breaches](https://blog.qualys.com/category/qualys-insights) - NETRESEC Network Security Blog - [ ] [PureLogs, PureRAT and misleading zgRAT](https://www.netresec.com/?page=Blog&month=2026-07&post=PureLogs-PureRAT-and-misleading-zgRAT) - 情报分析师 - [ ] [一张保单、一个学生签证、一份AI生成的驾照制造了2026年新的身份战争](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650568866&idx=1&sn=70b2ea9fc1ed685ef31058d81136e22b) - [ ] [谁在给美国情报系统换血,普尔特上任四十天观察](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650568866&idx=2&sn=83b476f2c68d3345c6deb9b4fb7694dc) - 谛听ditecting - [ ] [谛听 | 面向不完备SCADA场景的IMADP异常检测框架:基于对抗扩散过程的工业过程安全建模](https://mp.weixin.qq.com/s?__biz=MzU3MzQyOTU0Nw==&mid=2247503277&idx=1&sn=5b0e5a9cf9413a07ea6e7f6f0a9a0703) - 安全419 - [ ] [2026上半年十大网络攻击与数据泄露事件盘点](https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&mid=2247554141&idx=1&sn=f48a3422660e593df24b5585b7371313) - 极客公园 - [ ] [为什么美国做不出顶尖开源模型?](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653111247&idx=1&sn=6881ec2d2bd830a02ddd41178ad7971b) - [ ] [OpenAI 和 Anthropic,正在砸钱抢这个市场](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653111244&idx=1&sn=87a7143660fdb0fdabddb066f237d479) - SANS Internet Storm Center, InfoCON: green - [ ] [Java Spring Boot "heapdump" scans, (Mon, Jul 27th)](https://isc.sans.edu/diary/rss/33188) - [ ] [ISC Stormcast For Monday, July 27th, 2026 https://isc.sans.edu/podcastdetail/10024, (Mon, Jul 27th)](https://isc.sans.edu/diary/rss/33186) - ICT Security Magazine - [ ] [Cryptographic Bill of Materials (CBOM): sapere che crittografia si usa prima di migrare](https://www.ictsecuritymagazine.com/articoli/cryptographic-bill-of-materials-cbom/) - Schneier on Security - [ ] [Cognyte Sells a Mobile Cell Surveillance Van](https://www.schneier.com/blog/archives/2026/07/cognyte-sells-a-mobile-cell-surveillance-van.html) - Instapaper: Unread - [ ] [How does an app launch An exploration with LogUI](https://eclecticlight.co/2026/07/27/how-does-an-app-launch-an-exploration-with-logui/) - [ ] [Exploit BootROM su iPhone XS la prima catena e il progetto usbliter](https://www.forenser.it/exploit-bootrom-iphone-xs-usbliter/) - [ ] [Microsoft Office Passwords What Comes Off in Seconds, What Takes Longer, and Why](https://blog.elcomsoft.com/2026/07/microsoft-office-passwords-what-comes-off-in-seconds-what-takes-longer-and-why/) - [ ] [Phineas Fisher, chi è il misterioso hacktivista “anarchico” che ha messo in crisi le aziende di spyware](https://www.cybersecitalia.it/phineas-fisher-chi-e-il-misterioso-hacktivista-anarchico-che-ha-messo-in-crisi-le-aziende-di-spyware/67765/) - [ ] [ACN aggiorna le FAQ sulle misure di sicurezza per la supply chain dei soggetti NIS2](https://www.cybersecitalia.it/acn-aggiorna-le-faq-sulle-misure-di-sicurezza-per-la-supply-chain-dei-soggetti-nis2/67778/) - [ ] [ACN 2.171 eventi nei primi 6 mesi del 2026. Più notifiche con la NIS2, ma calano DDoS e ransomware](https://www.key4biz.it/acn-2-171-eventi-nei-primi-6-mesi-del-2026-piu-notifiche-con-la-nis2-ma-calano-ddos-e-ransomware/582455/) - [ ] [Last Week on My Mac Annotate your log for fun and profit](https://eclecticlight.co/2026/07/26/last-week-on-my-mac-annotate-your-log-for-fun-and-profit/) - [ ] [84 Streams Later Exploring the Evolution of Apple Biome in iOS](https://blog.digital-forensics.it/2026/07/84-streams-later-exploring-evolution-of.html) - [ ] [Windows Event Log Analysis Tracking Account Usage](https://digitalinvestigator.blogspot.com/2026/07/windows-event-log-analysis-tracking.html) - The Hacker News - [ ] [NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework](https://thehackernews.com/2026/07/nvidia-forms-37-member-open-secure-ai.html) - [ ] [Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption](https://thehackernews.com/2026/07/dysphoria-iot-botnet-adds-blockchain-c2.html) - [ ] [Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw](https://thehackernews.com/2026/07/public-exploit-released-for-patched.html) - [ ] [⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More](https://thehackernews.com/2026/07/weekly-recap-rogue-ai-agents-check.html) - [ ] [n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process](https://thehackernews.com/2026/07/n8n-sandbox-escape-lets-workflow.html) - [ ] [Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update](https://thehackernews.com/2026/07/operation-bluedash-deploys-level-rmm.html) - [ ] [Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware](https://thehackernews.com/2026/07/cruciferra-crypter-uses-byovd-and.html) - [ ] [TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments](https://thehackernews.com/2026/07/teleshim-abuses-telegram-for-c2-in.html) - [ ] [GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption](https://thehackernews.com/2026/07/github-adds-3-day-dependabot-cooldown.html) - NetSPI - [ ] [Azure VM Command Execution using Third-Party Extensions – Salt Minion](https://www.netspi.com/blog/technical-blog/cloud-pentesting/azure-vm-command-execution-using-third-party-extensions-part-2/) - www.theregister.com - Articles - [ ] [Microsoft's solution to AI security: more AI and more acronyms](https://www.theregister.com/security/2026/07/27/microsofts-solution-to-ai-security-more-ai-and-more-acronyms/5279140) - [ ] [Tech giants link hands to praise open AI models after OpenAI - Hugging Face attack](https://www.theregister.com/ai-and-ml/2026/07/27/tech-giants-link-hands-to-praise-open-ai-models-after-openai-hugging-face-attack/5279061) - [ ] [Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update](https://www.theregister.com/patches/2026/07/27/microsoft-defender-for-endpoint-leaves-some-linux-boxes-defenseless-after-update/5278914) - [ ] [Google goes it alone with a new cybercrime crew taxonomy](https://www.theregister.com/security/2026/07/27/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy/5278749) - Security Weekly Podcast Network (Audio) - [ ] [Exploring AI Network Protocols; Vulnerability Truths and Guarantees; and the News - Jeremiah Grossman, O'Shea Bowens - ESW #469](http://sites.libsyn.com/18678/exploring-ai-network-protocols-vulnerability-truths-and-guarantees-and-the-news-jeremiah-grossman-oshea-bowens-esw-469) - TorrentFreak - [ ] [Copyright Scammers Weaponized Meta’s Rights Manager with Backdating Exploit](https://torrentfreak.com/copyright-scammers-weaponized-metas-rights-manager-with-backdating-exploit/) - Security Affairs - [ ] [Reuters: OpenAI Agent Hacked Hugging Face for Days Before Being Detected](https://securityaffairs.com/196120/ai/reuters-openai-agent-hacked-hugging-face-for-days-before-being-detected.html) - [ ] [MedusaHVNC Trojan Creates Hidden Desktops to Hijack Browsers and Steal Data](https://securityaffairs.com/196111/malware/medusahvnc-trojan-creates-hidden-desktops-to-hijack-browsers-and-steal-data.html) - [ ] [DentaQuest disclosed a data breach that impacted +23 million individuals](https://securityaffairs.com/196100/data-breach/dentaquest-disclosed-a-data-breach-that-impacted-23-million-individuals.html) - [ ] [GitLab Users Urged to Patch After Research Reveals Critical RCE Chain](https://securityaffairs.com/196062/hacking/gitlab-users-urged-to-patch-after-research-reveals-critical-rce-chain.html) - [ ] [EFF: Most Smart Wearables Still Fall Short on Privacy and Transparency](https://securityaffairs.com/196085/security/eff-most-smart-wearables-still-fall-short-on-privacy-and-transparency.html) - [ ] [LockBit5 and Qilin Lead Ransomware Attacks Against Italian Organizations](https://securityaffairs.com/196045/security/lockbit5-and-qilin-lead-ransomware-attacks-against-italian-organizations.html) - Deeplinks - [ ] [Missed EFF's Livestream with Adam Savage and iFixit? Listen Here!](https://www.eff.org/deeplinks/2026/07/miss-last-weeks-livestream-adam-savage-and-ifixit-listen-here) - 安全客 - [ ] [PentesterFlow —— 面向渗透测试人员和漏洞赏金猎人的 AI 自动化工作流工具](https://mp.weixin.qq.com/s?__biz=MzA5ODA0NDE2MA==&mid=2649790269&idx=1&sn=f865dda3e4caf7f67ccabcfa99489c0f) - [ ] [《AI编程工具“塌房”实录:Grok Build整库上传、Claude Code后门暗桩,哪个更让你睡不着?》](https://mp.weixin.qq.com/s?__biz=MzA5ODA0NDE2MA==&mid=2649790269&idx=2&sn=556cf12565f116668a7c0b3baccb8482) - Krypt3ia - [ ] [Online-Enabled Intelligence Recruitment: The Digitization of Traditional Agent Development and Espionage Tradecraft](https://krypt3ia.wordpress.com/2026/07/27/online-enabled-intelligence-recruitment/)
每日安全资讯(2026-07-28)