# 每日安全资讯(2026-04-04) - SecWiki News - [ ] [SecWiki News 2026-04-03 Review](http://www.sec-wiki.com/?2026-04-03) - Private Feed for M09Ic - [ ] [joaoviictorti starred ergrelet/windiff](https://github.com/ergrelet/windiff) - [ ] [bolucat released 202604032057 at bolucat/Archive](https://github.com/bolucat/Archive/releases/tag/202604032057) - [ ] [PrefectHQ released 3.6.25 at PrefectHQ/prefect](https://github.com/PrefectHQ/prefect/releases/tag/3.6.25) - [ ] [IC3-CR3AM starred paoloanzn/free-code](https://github.com/paoloanzn/free-code) - [ ] [CHYbeta starred praetorian-inc/vespasian](https://github.com/praetorian-inc/vespasian) - [ ] [Mr-xn starred Mr-xn/sunlogin_rce](https://github.com/Mr-xn/sunlogin_rce) - [ ] [su18 starred yaklang/memfit-home](https://github.com/yaklang/memfit-home) - [ ] [Ridter starred Muz1K1zuM/kslkatz_bof](https://github.com/Muz1K1zuM/kslkatz_bof) - [ ] [rabbitmask made this repository public](https://github.com/Encore-SOC/.github) - [ ] [PrefectHQ released 3.6.25.dev7 at PrefectHQ/prefect](https://github.com/PrefectHQ/prefect/releases/tag/3.6.25.dev7) - [ ] [0xbug starred microsoft/VibeVoice](https://github.com/microsoft/VibeVoice) - [ ] [Mr-xn contributed to Mr-xn/mr-xn.github.io](https://github.com/Mr-xn/mr-xn.github.io/pull/4) - [ ] [gh0stkey starred khoj-ai/khoj](https://github.com/khoj-ai/khoj) - [ ] [mgeeky starred elastic/supply-chain-monitor](https://github.com/elastic/supply-chain-monitor) - [ ] [CHYbeta starred noperator/slice](https://github.com/noperator/slice) - [ ] [timwhitez starred timwhitez/ida-pro-skill](https://github.com/timwhitez/ida-pro-skill) - [ ] [kyxiaxiang starred ghostbyt3/nday-automation-ai](https://github.com/ghostbyt3/nday-automation-ai) - [ ] [Mel0day starred therealXiaomanChu/ex-skill](https://github.com/therealXiaomanChu/ex-skill) - [ ] [rebeyond forked rebeyond/DeepLearning from Mikoto10032/DeepLearning](https://github.com/rebeyond/DeepLearning) - [ ] [0xbug starred anthropics/knowledge-work-plugins](https://github.com/anthropics/knowledge-work-plugins) - [ ] [Wh0ale starred CTFTraining/CTFTraining](https://github.com/CTFTraining/CTFTraining) - [ ] [gh0stkey starred logancyang/obsidian-copilot](https://github.com/logancyang/obsidian-copilot) - CXSECURITY Database RSS Feed - CXSecurity.com - [ ] [astrojs/vercel < = 10.0.0 - Unauthenticated x-astro-path Header Path Override](https://cxsecurity.com/issue/WLB-2026040002) - [ ] [Microsoft SQL Server Privilege Elevation Through](https://cxsecurity.com/issue/WLB-2026040001) - paper - Last paper - [ ] [GUARD‑SLM:面向小语言模型、基于令牌激活的越狱攻击防御方法](https://paper.seebug.org/3476/) - Tenable Blog - [ ] [The developer credential economy: Why exposure data is the new front line in the supply chain war](https://www.tenable.com/blog/the-developer-credential-economy-exposure-data-is-the-new-front-line-in-the-supply-chain-war) - 安全客-有思想的安全新媒体 - [ ] [科技云报到:AI算力革命,终结云计算20年降价史](https://www.anquanke.com/post/id/315253) - 嘶吼 RoarTalk – 网络安全行业综合服务平台,4hou.com - [ ] [邮件安全网关选型怎么做?企业采购避坑指南与评估清单](https://www.4hou.com/posts/EyrW) - [ ] [应对iOS安全威胁新挑战,梆梆安全 “源到源” 加固全面护航移动应用安全](https://www.4hou.com/posts/nln5) - [ ] [国家计算机病毒应急处理中心通报71款应用违规背后:隐私合规风险全面下沉,合规审计刻不容缓](https://www.4hou.com/posts/ompY) - [ ] [PolyShell高危漏洞可致电商Magento系统遭遇未授权远程代码执行](https://www.4hou.com/posts/jBG4) - [ ] [嘶吼安全动态|中央网信办等三部门开展2026年个人信息保护系列专项行动 Axios供应链攻击事件系朝鲜黑客组织所为](https://www.4hou.com/posts/GAyK) - Doonsec's feed - [ ] [Chrome浏览器的Dawn组件0day漏洞已被利用](https://mp.weixin.qq.com/s/jGLggmLUlOw3YAiZCI6Z-Q) - [ ] [【紧急呼吁】告别高息网贷!工行、邮储、交行、北京银行、南京银行五大行低息贷来了,最高1000万救企于水火,助力中小微破浪前行!](https://mp.weixin.qq.com/s/6SGx79PcPZkJk9m2oLVTfA) - [ ] [来来来, 让我手把手教你如何正确配置OpenClaw,让微信机器人稳定跑起来嘛~](https://mp.weixin.qq.com/s/ErRok_ouppifGqrJ3fnUNg) - [ ] [国内首次发布AI红队!谋乐Elliot开创人机攻防新赛道](https://mp.weixin.qq.com/s/YIt5mL9sN_CyUYh758HJvA) - [ ] [朝鲜黑客通过Axios供应链攻击OpenClaw](https://mp.weixin.qq.com/s/LUSwo9AFR4PDMUjyFE_-WA) - [ ] [漏洞发布2026年第四期](https://mp.weixin.qq.com/s/gX0r1Zalb2aU8TdUtcGWmQ) - [ ] [2025年 第3卷 第5期](https://mp.weixin.qq.com/s/2iQDOniFIt16_PJZAKzUpw) - [ ] [誓立目标 使命必达|渝融云2026年一季度工作总结大会圆满召开](https://mp.weixin.qq.com/s/ea1s8sQYC8wiUszrx2P-5Q) - [ ] [思科大震荡:起底ShinyHunters漏洞事件与Trivy供应链崩塌](https://mp.weixin.qq.com/s/rymmWmyeE6qiKcHiQusgZg) - [ ] [harmonyOS开发基础之标题栏(HdsNavigation)](https://mp.weixin.qq.com/s/uZEfYbAlz225OvaAIDYwOA) - [ ] [[漏洞播报]紧急提醒!!!工信部呼吁立即升级,iphone的这些iOS版本存在高危漏洞](https://mp.weixin.qq.com/s/fA_UCNfK83JQ6buNmOFf4Q) - [ ] [AI挖洞让赏金模式停摆?——HackerOne暂停漏洞收购的分析](https://mp.weixin.qq.com/s/WIoBr8LWD0Xf_zBQOW1agA) - [ ] [废墟中的破碎与重构:一些碎碎念](https://mp.weixin.qq.com/s/2Oz0PFYulvWSdM9Z8mpA7Q) - [ ] [PHPJM混淆解解析与还原](https://mp.weixin.qq.com/s/Ihc4xqQhQ-gbYXBd4OK4pA) - [ ] [反蒸馏](https://mp.weixin.qq.com/s/VjpTMj-uHfWk45j3bPf5tw) - [ ] [ubuntu勒索病毒应急 - vulntarget-n](https://mp.weixin.qq.com/s/JfvoAd2ToirhrFf1xB7a3A) - [ ] [Claude code cheatsheet](https://mp.weixin.qq.com/s/95juRYGpW1kuHEYFhMTJkA) - [ ] [网安行业首发!长亭系列产品 CLI 开源发布!](https://mp.weixin.qq.com/s/9V5YI0sJloIcssUch0wB2w) - [ ] [iPhone高危漏洞!立刻升级](https://mp.weixin.qq.com/s/AUOkcKImIOcZVI3TEPirQA) - [ ] [Claude Code 这10个Skills最能打,装完效率直接起飞](https://mp.weixin.qq.com/s/V572eHqDu3oj7OeTZa2wZQ) - [ ] [AI推荐投毒,操纵AI助手记忆牟利](https://mp.weixin.qq.com/s/BNjF5GXrV5hKxgYbiU_ikg) - [ ] [对标一下!NASA 阿尔忒弥斯任务控制中心,到底用了哪些 IT 设备?](https://mp.weixin.qq.com/s/otUyM984RhOMkCbLJjAnsw) - [ ] [每天烧掉120万亿Token,字节跳动在赌什么?](https://mp.weixin.qq.com/s/URHJgA-zIA9qszWFZKHM3w) - [ ] [藏不住了!虎符技术专家李俊君,在全区AI智能体大赛中脱颖而出](https://mp.weixin.qq.com/s/wu5Kf4NMuoCB3f-_ZhGdrw) - [ ] [关于手搓C2这回事](https://mp.weixin.qq.com/s/XQt5NGhR3AArZ9cwaFT9FA) - [ ] [白帽成长培养体系上线!BSRC奖励规则v9.0来咯!](https://mp.weixin.qq.com/s/ag3ccUdNXHeyfks7_TbUXw) - [ ] [深圳网安协会权威发布!极安云荣耀入选《2026年网络与信息安全行业全景图》,护航数字中国!](https://mp.weixin.qq.com/s/iGXfdOeVW_kHj0-hMgEuZg) - [ ] [重磅 | 《自动化博览》2026年3月刊上线!聚焦新质生产力、智能制造~](https://mp.weixin.qq.com/s/K_DlnGf5dnz5Kjz0AP7vqw) - [ ] [征求意见丨《数据 基础术语(征求意见稿)》等22项国家标准](https://mp.weixin.qq.com/s/uoPltDDKR4rOYSsEkFKOvQ) - [ ] [黑客利用 React2Shell 漏洞入侵了 700 多台 Next.js 服务器](https://mp.weixin.qq.com/s/FLJ69EfeBYuFCV5UxwbGVQ) - [ ] [国内网络监管升级,“机场”频频被查,灰色产业收紧,从“翻墙整治”到互联网生态重塑,一次讲清背后的逻辑](https://mp.weixin.qq.com/s/9UYM1qYVCtVPQDfspbb1BQ) - [ ] [TP-Link 多个漏洞使攻击者能够触发拒绝服务攻击并导致路由器崩溃](https://mp.weixin.qq.com/s/Pkn3e0RZ3ZNYV7iPhWPLmw) - [ ] [工行大模型体系落地500+AI应用场景,将升级为数智工行(AI-ICBC)](https://mp.weixin.qq.com/s/dHPkz5CcIvAI2z_h9FPJ3A) - [ ] [AI快讯:银联发布智能体支付开放协议框架,谷歌发布Gemma 4开源大模型](https://mp.weixin.qq.com/s/brjoewiPy2P5erBolrZ9jw) - [ ] [金智维中!万家基金2026年度RPA系统服务项目](https://mp.weixin.qq.com/s/UHGjCZ30cXyOpg0HQ8ClFg) - [ ] [WMPFDebugger 微信小程序调试神器](https://mp.weixin.qq.com/s/Vs4oPx7CwQKtk_ov3FHMYQ) - [ ] [【提权基础入门第十节】在Windows Credentials Manager里发现的“定时炸弹”](https://mp.weixin.qq.com/s/AQUrVeFkWFibQe4oYQpQ1A) - [ ] [员工未授权访问客户数据超2年,银行巨头被罚超2.5亿元](https://mp.weixin.qq.com/s/26sKNKyYiNiT9kJKUTGHYQ) - [ ] [美国政府通过“破例”与“破壁”全面升级全球亲美信息战](https://mp.weixin.qq.com/s/8SVOa-KvBp10apRiSB4eiQ) - [ ] [苹果发布iOS 18.7.7更新以防御DarkSword漏洞](https://mp.weixin.qq.com/s/hseKSGXo2ZfqwM3eY6IX3Q) - [ ] [星巴克漏洞事件](https://mp.weixin.qq.com/s/Msagzh8x7ftnUewe_CTXWA) - [ ] [记某edusrc相同站点相同打法的二次高危挖掘](https://mp.weixin.qq.com/s/0P2-L6acwNt5fyrjOpsB0Q) - [ ] [专题·具身智能安全 | 具身智能保险箍:从风险感知到风险熔断](https://mp.weixin.qq.com/s/kbFn3dzEiPstTGMBZL2PBQ) - [ ] [通知 | 十部门印发《人工智能科技伦理审查与服务办法(试行)》(附全文)](https://mp.weixin.qq.com/s/AzpU7JmNa7l0KFOQG8S9GA) - [ ] [通知 | 国家网信办就《小型个人信息处理者个人信息保护简化措施规定(征求意见稿)》公开征求意见](https://mp.weixin.qq.com/s/-Cd3qornwri1PF_hpT8pZQ) - [ ] [通知 | 国家网信办就《数字虚拟人信息服务管理办法(征求意见稿)》公开征求意见](https://mp.weixin.qq.com/s/C-UiZtL-cQV5C4LHNHBgwA) - [ ] [专家解读|黄永峰:筑牢数字虚拟人安全屏障 引领产业创新融合发展](https://mp.weixin.qq.com/s/_HsdbCKoOea8swZJ-yzf5Q) - [ ] [安全争锋・QFSRC 众测挑战](https://mp.weixin.qq.com/s/zyRt6-s7vzWxO8Rax77Maw) - [ ] [Web前端组件漏洞总结,安服水洞必备](https://mp.weixin.qq.com/s/JJPKbDIW90AIB4gdafBhNg) - [ ] [清明节值守安排](https://mp.weixin.qq.com/s/PTrGoaP-BQumtjor58Tj6g) - [ ] [中央网信办、工业和信息化部、公安部关于开展2026年个人信息保护系列专项行动的公告](https://mp.weixin.qq.com/s/dGK5G394GEH2yYwSE7CZjA) - [ ] [【成功复现】OpenCode远程代码执行漏洞(CVE-2026-22812)](https://mp.weixin.qq.com/s/L86RCrNlpz6LGqQSlcCMVw) - [ ] [捷普清明节放假保障通知请查收!](https://mp.weixin.qq.com/s/QAJKFXZQvZoUJJXn64vD1A) - [ ] [Cocos2d-x iOS游戏逆向分析实战](https://mp.weixin.qq.com/s/3UPlvNfctvuaee_et2W0LQ) - [ ] [2026春季招聘-点击投递](https://mp.weixin.qq.com/s/3UlRRSSACkshF9wTDrAWzQ) - [ ] [React2Shell漏洞被批量利用:超700台Next.js服务器凭证大规模失窃](https://mp.weixin.qq.com/s/Sl224HcVcNLF5Ou9LTCMMQ) - [ ] [本周更新-环境篇!冰与火的战歌:Windows内核攻防实战](https://mp.weixin.qq.com/s/gCC_B7ziDhByqW8Ah-Vexw) - [ ] [APP不做等保会出现的危害](https://mp.weixin.qq.com/s/KuqgRNEi2ItEtw8YdGakcA) - [ ] [图解信息安全技术 网络安全等级保护基本要求第7部分:大数据系统安全扩展要求](https://mp.weixin.qq.com/s/yl7xmSkSOhJzWc6MdR53TQ) - [ ] [【放假通知】清明安康,假期服务不停歇!](https://mp.weixin.qq.com/s/TE-YCJerh4OBfSJF97Maug) - [ ] [CSA大中华区大会|观安信息斩获双项殊荣 解码智能体安全之道](https://mp.weixin.qq.com/s/rtbXmDQIyjcEC-9mQJ8mdw) - [ ] [BlockSec 安全周报|八起攻击,漏洞都藏在哪?(3.23–3.29)](https://mp.weixin.qq.com/s/4VRmCfM6um2mRGIe5mSy5w) - [ ] [有赞SRC清明活动](https://mp.weixin.qq.com/s/zuFyDtuthzp209vgZOdRgA) - [ ] [Google gemma 4速度还是可以的](https://mp.weixin.qq.com/s/I6okcf-xLVf8IO5jUm9OzA) - [ ] [图解安全意识:OpenClaw平台深度安全体系建设](https://mp.weixin.qq.com/s/nI5d08KWScM2kPhKmHDK0A) - [ ] [当篮球遇见AI:阿里云为“我的NBA手办”装上AI安全护栏](https://mp.weixin.qq.com/s/pboWMwO70TTRoumDlhAsXA) - [ ] [免费赠送 | 企业办公安全意识培训科普素材(第二十一期)](https://mp.weixin.qq.com/s/acae9Cy-f93H-5bijS6BYQ) - [ ] [数据中心机架架构](https://mp.weixin.qq.com/s/4N_V6XvQQ_rXyAit9OitUw) - [ ] [Memfit AI 长期记忆:让渗透 Agent 告别 “失忆”,练就实战肌肉记忆](https://mp.weixin.qq.com/s/yCM2jpi_iHGZr_RuwvPP0w) - [ ] [从开源仓库到链上C2:一起利用GitHub与AI热点的规模化攻击活动分析](https://mp.weixin.qq.com/s/04ZOdzOawFnQmaCPV04xfg) - [ ] [低空产业高质量发展路径与策略研究报告](https://mp.weixin.qq.com/s/cKZ1YMVnT9zthp0lxgt6kw) - [ ] [国际观察 | 78% 制造企业有攻击经历,制造业安全防线亟待加固](https://mp.weixin.qq.com/s/8rOOJKiPXbp6EMV-UUUJJg) - [ ] [金盾资讯丨数据要素要闻播报 2026年4月(总第4期)](https://mp.weixin.qq.com/s/ii42BcB81ZoRPX4x8duZsg) - [ ] [国家网信办发布《数字虚拟人信息服务管理办法(征求意见稿)》](https://mp.weixin.qq.com/s/ZBQxPb5RWrhnzHN5xLla6Q) - [ ] [国家网信办发布《小型个人信息处理者个人信息保护简化措施规定(征求意见稿)》](https://mp.weixin.qq.com/s/RMaICOhoU_D84w_LmL0VgA) - [ ] [给大模型通过RAG挂上知识库](https://mp.weixin.qq.com/s/o_EtmHGCn6MZZ2Kp_CPktw) - [ ] [【免费领】SQL Server最佳安全配置实操教程(含检测及修复)](https://mp.weixin.qq.com/s/VoFqz0S_fk2FrDiS3V6wMw) - [ ] [「AI开源组件安全风险」系列二:VulnAgent发现 NVIDIA 3个AI基础设施漏洞,并获官方致谢](https://mp.weixin.qq.com/s/XEp4P3hxLCny3Ii1FWqP0w) - [ ] [2026盘古石取证-清明假期值班安排](https://mp.weixin.qq.com/s/loD6cYBBdZOQDj48YYEALg) - [ ] [专题•特别策划|美国人工智能产业全球扩张的LLMs-NVIDIA模式及对我影响](https://mp.weixin.qq.com/s/lB93k323kwWUANbOCSUfOQ) - [ ] [最高检:14人侵犯Wi-Fi芯片商业秘密,主犯获刑六年](https://mp.weixin.qq.com/s/Q6zGkCWUPkM1MUL4ofTlEQ) - [ ] [警惕弱口令,否则你的账号会“门户大开”!](https://mp.weixin.qq.com/s/V6ilHr4jyerW52Uba5OyPA) - [ ] [Mercor 卷入 LiteLLM 供应链攻击,Lapsus$ 叫卖 4TB 招聘数据](https://mp.weixin.qq.com/s/ZOh9I1yWKfsqvevos1MPAg) - [ ] [安全热点周报:谷歌修复了第四个在 2026 年被利用的 Chrome 零日漏洞](https://mp.weixin.qq.com/s/bUv7mo9dhg-rNUe8ZEyvTA) - [ ] [2.8 亿美元一夜归零 | DeFi 热潮下,你漏掉了这几道安全锁](https://mp.weixin.qq.com/s/Ji-iPtN4BIY2BKww0zRAug) - [ ] [烽火狼烟丨暗网数据及攻击威胁情报分析周报(03/30-04/03)](https://mp.weixin.qq.com/s/yXaDnsslTpvpu_7grOzYVQ) - [ ] [网络安全信息与动态周报2026年第13期(3月23日-3月29日)](https://mp.weixin.qq.com/s/ihl8RDx_RTeiXQJ6l_9u7Q) - [ ] [以智御变,实战向新:盛邦安全研发体系全面拥抱AI](https://mp.weixin.qq.com/s/ZLjwRdO11FbkezqTPyPQiQ) - [ ] [OffSec与德勤葡萄牙宣布建立战略合作伙伴关系](https://mp.weixin.qq.com/s/GqJq6hw8sjN3GgVkx6gXCQ) - [ ] [别被热点晃了眼,普通人还是平淡地活下去吧](https://mp.weixin.qq.com/s/DsH1bfi_WAE3UmOqMwPMGA) - [ ] [反蒸馏skill](https://mp.weixin.qq.com/s/5moTqKzLOVYxUmj0asXKxw) - [ ] [增强espscan对openclaw的指纹识别](https://mp.weixin.qq.com/s/7pKyDHRDM1cCw3Pr3hErug) - [ ] [告别\"假闭环\",看大型央企的漏洞管理真实践](https://mp.weixin.qq.com/s/gCiTbTuIfp-HTth53D6fBw) - [ ] [实力见证!魔方安全入选《2026年网络与信息安全行业全景图》](https://mp.weixin.qq.com/s/20lRkv1pphKDQOxrcnlGJg) - [ ] [前沿 | 在数字时代修路架桥——世界数据组织成立的现实意义与中国贡献](https://mp.weixin.qq.com/s/RidnsGB9JEUeRGm-sT-eZA) - [ ] [CNNVD | 通报OpenClaw多个安全漏洞](https://mp.weixin.qq.com/s/VZe-2EuXfVCHlivqLqZrLg) - [ ] [合合信息亮相2026金融AI联盟大会,携手阿里云共同启动“超级智能体计划”](https://mp.weixin.qq.com/s/1-X-IQwKTPmLJheXzddXaw) - [ ] [安全预警丨OpenClaw 多项高危安全漏洞预警](https://mp.weixin.qq.com/s/et3YPRYda6D2CciWuHXyrw) - [ ] [零检出威胁再升级:蔓灵花APT2026新型攻击链与高级逃逸技术深度分析](https://mp.weixin.qq.com/s/h_G2AL9-QyKfyixXV3QrfQ) - [ ] [hw开始了,第一批开始招人](https://mp.weixin.qq.com/s/TxHQomkWZrN-Gh8OLzRoMA) - [ ] [Flocks狂撒万亿Token,奖励为安全奋战的你](https://mp.weixin.qq.com/s/OPa_jbBFhhcFeYgn_HH3lw) - [ ] [一次渗透学员母校捡漏通杀?](https://mp.weixin.qq.com/s/itoWbHHrelIkj4fVkfUQKA) - [ ] [苹果扩展iOS 18.7.7更新到更多设备以阻止暗剑漏洞](https://mp.weixin.qq.com/s/BWaW2zk5MtJSFOl5KOfOzw) - [ ] [2026-3月Solar应急响应公益月赛排名及官方题解](https://mp.weixin.qq.com/s/2mnpzKlVuQi-AhszjZ642Q) - [ ] [阿里P7被裁3年,现在小国企年薪28万!收入巅峰永远停在了2022年,125万](https://mp.weixin.qq.com/s/3ZnGvyp9Uke3yFWfbBFcCw) - [ ] [议程抢先看 | 美国2026 RSAC热点研讨暨第十八届信息安全高级论坛诚邀莅临](https://mp.weixin.qq.com/s/Z7N714ShvFe5aGEAeltEXw) - [ ] [绿盟科技斩获CSA 2025多项大奖,实力引领AI安全新征程](https://mp.weixin.qq.com/s/0Gmqs_A-IqUIgLnDj5K31w) - [ ] [国际认可 | 绿盟科技跻身亚太区OT安全代表厂商](https://mp.weixin.qq.com/s/2fJw0D7FgL6xOAMqL2SB_Q) - [ ] [安全资讯汇总:2026.3.30-2026.4.3](https://mp.weixin.qq.com/s/dwzz00Exkk4ubxhaJD_O7w) - [ ] [网警打谣记 | 公安部网安局公布3起网络谣言典型案例](https://mp.weixin.qq.com/s/CeWx2B8R_IZqug8JLNvROg) - [ ] [AI大模型API网关](https://mp.weixin.qq.com/s/jzx0ukZ_86p27EwqPaVjSA) - [ ] [丝享Talk沙龙·人机共潮生|四叶草安全朱利军解析智能体安全核心解法](https://mp.weixin.qq.com/s/ZMKM4MwPi2eHFJNiypEEhA) - [ ] [Kali 2026.1 重磅发布!来看看都更新了什么](https://mp.weixin.qq.com/s/hkiCzxZ2IhvpHahnvnKclQ) - [ ] [信息安全漏洞周报【第068期】](https://mp.weixin.qq.com/s/e3Alv9ruS5kHS_A0YOjjug) - [ ] [教育部教育管理信息中心教育信创实验室天津适配测试中心工作推进会召开](https://mp.weixin.qq.com/s/Xv2CZIfbJQ2oq4Me-SE4wg) - [ ] [【北京】教育系统网络安全保障专业人员(ECSP-G)培训开班信息](https://mp.weixin.qq.com/s/82cIoqd-AFRGQMSoQrV0Dw) - [ ] [【江苏】教育系统网络安全保障专业人员(ECSP-M/AISEC)培训开班信息](https://mp.weixin.qq.com/s/GANFVkEkEbn7PAQxvR_3VA) - Recent Commits to cve:main - [ ] [Update Fri Apr 3 11:21:16 UTC 2026](https://github.com/trickest/cve/commit/9d9ccc1447d501d14d086b6c8eb2c3bb7dbcc138) - ElcomSoft blog - [ ] [Compelled Decryption: The East Asian Region](https://blog.elcomsoft.com/2026/04/compelled-decryption-the-east-asian-region/) - Cerbero Blog - [ ] [UBI Format Package](https://blog.cerbero.io/ubi-format-package/) - Bug Bounty in InfoSec Write-ups on Medium - [ ] [Reverse Engineering a WhatsApp 0-Click Vulnerability: A Deep Dive into CVE-2025–43300](https://infosecwriteups.com/reverse-engineering-a-whatsapp-0-click-vulnerability-a-deep-dive-into-cve-2025-43300-d8d425644fe9?source=rss----7b722bfd1b8d--bug_bounty) - Reverse Engineering - [ ] [Open source runtime that deep-inspects AI agent protocol traffic (MCP/ACP) — Rust](https://www.reddit.com/r/ReverseEngineering/comments/1sbbh75/open_source_runtime_that_deepinspects_ai_agent/) - The Trail of Bits Blog - [ ] [Simplifying MBA obfuscation with CoBRA](https://blog.trailofbits.com/2026/04/03/simplifying-mba-obfuscation-with-cobra/) - NVISO Labs - [ ] [The Axios npm supply chain incident: fake dependency, real backdoor](https://blog.nviso.eu/2026/04/03/the-axios-npm-supply-chain-incident-fake-dependency-real-backdoor/) - SentinelOne - [ ] [The Good, the Bad and the Ugly in Cybersecurity – Week 14](https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-14-6/) - Malwarebytes - [ ] [That dream job offer from Coca-Cola or Ferrari? It’s a trap for your passwords](https://www.malwarebytes.com/blog/threat-intel/2026/04/that-dream-job-offer-from-coca-cola-or-ferrari-its-a-trap-for-your-passwords) - [ ] [Blocking children from social media is a badly executed good idea](https://www.malwarebytes.com/blog/news/2026/04/blocking-children-from-social-media-is-a-badly-executed-good-idea) - 绿盟科技技术博客 - [ ] [绿盟科技斩获CSA 2025多项大奖,实力引领AI安全新征程](https://blog.nsfocus.net/%e7%bb%bf%e7%9b%9f%e7%a7%91%e6%8a%80%e6%96%a9%e8%8e%b7csa-2025%e5%a4%9a%e9%a1%b9%e5%a4%a7%e5%a5%96%ef%bc%8c%e5%ae%9e%e5%8a%9b%e5%bc%95%e9%a2%86ai%e5%ae%89%e5%85%a8%e6%96%b0%e5%be%81%e7%a8%8b/) - [ ] [国际认可 | 绿盟科技跻身亚太区OT安全代表厂商](https://blog.nsfocus.net/%e5%9b%bd%e9%99%85%e8%ae%a4%e5%8f%af-%e7%bb%bf%e7%9b%9f%e7%a7%91%e6%8a%80%e8%b7%bb%e8%ba%ab%e4%ba%9a%e5%a4%aa%e5%8c%baot%e5%ae%89%e5%85%a8%e4%bb%a3%e8%a1%a8%e5%8e%82%e5%95%86/) - rtl-sdr.com - [ ] [Echo: KiwiSDR, OpenWebRX, WebSDR and FM-DX iOS Browser App now Officially Released](https://www.rtl-sdr.com/echo-kiwisdr-openwebrx-websdr-and-fm-dx-ios-browser-app-now-officially-released/) - Offensive Security Blog: Latest Trends in Hacking | Praetorian - [ ] [Meet Vespasian. It Sees What Static Analysis Can’t.](https://www.praetorian.com/blog/vespasian-api-endpoint-discovery-tool/) - 黑海洋Wiki | AI机器人硬件开发 | 网络安全攻防实战 | 区块链技术文档教程 - 免费资源平台 - [ ] [ElevenLabs发布了一款全新AI音乐生成应用](https://blog.upx8.com/ElevenLabs%E5%8F%91%E5%B8%83%E4%BA%86%E4%B8%80%E6%AC%BE%E5%85%A8%E6%96%B0AI%E9%9F%B3%E4%B9%90%E7%94%9F%E6%88%90%E5%BA%94%E7%94%A8) - [ ] [OpenAI COO转岗,AGI业务负责人因病休假](https://blog.upx8.com/OpenAI-COO%E8%BD%AC%E5%B2%97-AGI%E4%B8%9A%E5%8A%A1%E8%B4%9F%E8%B4%A3%E4%BA%BA%E5%9B%A0%E7%97%85%E4%BC%91%E5%81%87) - [ ] [同人小说网站AO3历经17年终于结束公测](https://blog.upx8.com/%E5%90%8C%E4%BA%BA%E5%B0%8F%E8%AF%B4%E7%BD%91%E7%AB%99AO3%E5%8E%86%E7%BB%8F17%E5%B9%B4%E7%BB%88%E4%BA%8E%E7%BB%93%E6%9D%9F%E5%85%AC%E6%B5%8B) - [ ] [爱尔兰测试数字身份以验证社媒用户年龄](https://blog.upx8.com/%E7%88%B1%E5%B0%94%E5%85%B0%E6%B5%8B%E8%AF%95%E6%95%B0%E5%AD%97%E8%BA%AB%E4%BB%BD%E4%BB%A5%E9%AA%8C%E8%AF%81%E7%A4%BE%E5%AA%92%E7%94%A8%E6%88%B7%E5%B9%B4%E9%BE%84) - [ ] [全日空与日航拟上调国际航线燃油附加费](https://blog.upx8.com/%E5%85%A8%E6%97%A5%E7%A9%BA%E4%B8%8E%E6%97%A5%E8%88%AA%E6%8B%9F%E4%B8%8A%E8%B0%83%E5%9B%BD%E9%99%85%E8%88%AA%E7%BA%BF%E7%87%83%E6%B2%B9%E9%99%84%E5%8A%A0%E8%B4%B9) - [ ] [中国机器人企业开出逾1亿高薪招聘科学家](https://blog.upx8.com/%E4%B8%AD%E5%9B%BD%E6%9C%BA%E5%99%A8%E4%BA%BA%E4%BC%81%E4%B8%9A%E5%BC%80%E5%87%BA%E9%80%BE1%E4%BA%BF%E9%AB%98%E8%96%AA%E6%8B%9B%E8%81%98%E7%A7%91%E5%AD%A6%E5%AE%B6) - 奇客Solidot–传递最新科技情报 - [ ] [微软更新服务条款声明 Copilot 仅供娱乐](https://www.solidot.org/story?sid=83959) - [ ] [可再生能源新增装机容量占全球新增装机容量的八成以上](https://www.solidot.org/story?sid=83958) - [ ] [考古学家在北美发现距今至少 1.2 万年的骰子](https://www.solidot.org/story?sid=83957) - [ ] [人们日常说话的单词量比上一年减少 300 个单词](https://www.solidot.org/story?sid=83956) - [ ] [AO3 结束公测](https://www.solidot.org/story?sid=83955) - [ ] [最富 0.1% 人口的离岸财富超过最穷半数人口的财富总和](https://www.solidot.org/story?sid=83954) - [ ] [雄章鱼交接腕兼具感觉和交配功能](https://www.solidot.org/story?sid=83953) - [ ] [Artemis II 的厕所是月球任务的一大里程碑](https://www.solidot.org/story?sid=83952) - [ ] [Google 发布开放权重模型 Gemma 4](https://www.solidot.org/story?sid=83951) - [ ] [Artemis II 宇航员发现电脑上有两个 Outlook 但没有一个能用](https://www.solidot.org/story?sid=83950) - 奇安信 CERT - [ ] [今日(2026年4月3日)OpenClaw 最新安全动态总结](https://mp.weixin.qq.com/s?__biz=MzU5NDgxODU1MQ==&mid=2247505016&idx=1&sn=7fa7c9f2b1551543100e3d1bcc11bc00) - 黑鸟 - [ ] [Chrome浏览器的Dawn组件0day漏洞已被利用](https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451186162&idx=1&sn=a68cfdbb6be44e191236f85fbff0cd30) - 代码卫士 - [ ] [思科 IMC 中存在严重的认证绕过漏洞,可用于获取管理员权限](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247525643&idx=1&sn=123aa4e38d29ce29d7107d5e7378e00f) - [ ] [Progress ShareFile 漏洞可用于发动预认证 RCE 攻击](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247525643&idx=2&sn=46f21b64114594cdb5db7473129e09a8) - 威努特安全网络 - [ ] [定义第三代防火墙:AI智能体安全网关(ASG)](https://mp.weixin.qq.com/s?__biz=MzAwNTgyODU3NQ==&mid=2651141198&idx=1&sn=d5076738948a98420f9fab8b57f82a14) - 安全分析与研究 - [ ] [UAC绕过技术——权限提升的艺术](https://mp.weixin.qq.com/s?__biz=MzA4ODEyODA3MQ==&mid=2247496629&idx=1&sn=79875d7e69a1376f0252ce5b7847f2f8) - 安全内参 - [ ] [员工未授权访问客户数据超2年,银行巨头被罚超2.5亿元](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247515763&idx=1&sn=313b34af1fe1654de2abbcc963179a3d) - [ ] [美国政府通过“破例”与“破壁”全面升级全球亲美信息战](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247515763&idx=2&sn=5e0a83cadba978addd50d68dca2c1fd4) - 看雪学苑 - [ ] [Cocos2d-x iOS游戏逆向分析实战](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458613033&idx=1&sn=252c03caeb98b3ac58c0bfe6b1980160) - [ ] [2026春季招聘-点击投递](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458613033&idx=2&sn=b9391129cbc6168f4b4a2e6419da9d1c) - [ ] [React2Shell漏洞被批量利用:超700台Next.js服务器凭证大规模失窃](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458613033&idx=3&sn=1dc818bb4a6a1e53f68c6deb22fc2203) - [ ] [本周更新-环境篇!冰与火的战歌:Windows内核攻防实战](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458613033&idx=4&sn=567bb23f8b62dc031ba68833a0a556b6) - 绿盟科技研究通讯 - [ ] [开放与安全的博弈:OpenClaw爆火后的安全挑战](https://mp.weixin.qq.com/s?__biz=MzIyODYzNTU2OA==&mid=2247499780&idx=1&sn=aa453d7969e5261d79ca799c84b85a68) - 奇安信病毒响应中心 - [ ] [每周勒索威胁摘要](https://mp.weixin.qq.com/s?__biz=MzI5Mzg5MDM3NQ==&mid=2247498592&idx=1&sn=228891626a093e4e123abfd94b0f00f3) - 奇安信威胁情报中心 - [ ] [每周高级威胁情报解读(2026.03.27~04.02)](https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247518221&idx=1&sn=e9b865330e1af38784b1daa277fe74e9) - 电子物证 - [ ] [【数字世界,一切皆有痕迹】](https://mp.weixin.qq.com/s?__biz=MzAwNDcwMDgzMA==&mid=2651048965&idx=1&sn=79a177a2e59f1703a5fda888ca98b681) - [ ] [【关于数字资产强制执行的几点思考】](https://mp.weixin.qq.com/s?__biz=MzAwNDcwMDgzMA==&mid=2651048965&idx=2&sn=3b363c1ea09ff0748b9891c06f4ede62) - 中国信息安全 - [ ] [前沿 | 在数字时代修路架桥——世界数据组织成立的现实意义与中国贡献](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664260988&idx=1&sn=9e8da911e48d31a716cc9a6515208fe1) - [ ] [CNNVD | 通报OpenClaw多个安全漏洞](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664260988&idx=2&sn=04b93b54c595b4abaaf01d91d7660ff5) - 安全圈 - [ ] [【安全圈】星巴克数据泄露事件:攻击者宣称窃取10GB源代码](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652075319&idx=1&sn=0bc8efb18594b6c441a0f0fcef0d2774) - [ ] [【安全圈】AI 招聘公司 Mercor 遭 LiteLLM 供应链攻击,Lapsus$ 声称窃取 4TB 数据](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652075319&idx=2&sn=dbadb06af4cbcead4607dad3e6b107c7) - [ ] [【安全圈】研究人员发现利用 ISO 诱饵传播远控木马和挖矿程序的运营活动](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652075319&idx=3&sn=eb6020644ffc58453b6ccf59fadf2b77) - 极客公园 - [ ] [对话特赞范凌:我亲手「杀死」了过去的自己,AI 时代所有的留恋都是负担](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653102756&idx=1&sn=26ffbcc7e78923eb6a8d3f109b9879d7) - [ ] [vivo X300 Ultra 体验:「V 单」第二年,vivo 开始构建一套「影像系统」](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653102718&idx=1&sn=f61c963cd3ca69de879d503bce2f3c00) - [ ] [当 AI 视频创作进入「下半场」](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653102718&idx=2&sn=980c25f3ef00ee6299ce7ab8498168e6) - [ ] [谷歌发布新一代「最智能」开源模型 Gemma4;曝豆包二季度发布二代 AI 手机;商务部回应 Manus 收购案 | 极客早知道](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653102688&idx=1&sn=5f7c17f1117059b372bef8583de7af81) - 长亭科技 - [ ] [网安行业首发!长亭系列产品 CLI 开源发布!](https://mp.weixin.qq.com/s?__biz=MzIwNDA2NDk5OQ==&mid=2651390301&idx=1&sn=b8d36f576a619d227c17a999a70604f9) - 网络空间安全科学学报 - [ ] [2025年 第3卷 第5期](https://mp.weixin.qq.com/s?__biz=MzI0NjU2NDMwNQ==&mid=2247507384&idx=1&sn=f06dd114d9a78770cc5ed73f85169da9) - 补天平台 - [ ] [4月补天战神榜奖励继续!千元现金等你来拿!](https://mp.weixin.qq.com/s?__biz=MzI2NzY5MDI3NQ==&mid=2247510634&idx=1&sn=587bd6f3ee97936ebdb7f6e824c15c4e) - 数世咨询 - [ ] [人工智能的确很重要,但尚未看到回报](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247542464&idx=1&sn=341c83ecea8a97079b2a6153d66006e8) - [ ] [中央网信办、工业和信息化部、公安部关于开展2026年个人信息保护系列专项行动的公告](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247542464&idx=2&sn=3ea3bf923363f4c969741442d665ecbc) - 百度安全应急响应中心 - [ ] [白帽成长培养体系上线!BSRC奖励规则v9.0来咯!](https://mp.weixin.qq.com/s?__biz=MzA4ODc0MTIwMw==&mid=2652544011&idx=1&sn=c26d9ef7d9354ac880aafdfc2001664f) - 嘶吼专业版 - [ ] [PolyShell高危漏洞可致电商Magento系统遭遇未授权远程代码执行](https://mp.weixin.qq.com/s?__biz=MzI0MDY1MDU4MQ==&mid=2247587535&idx=1&sn=3f0d70d2c23c4a658381dbc97ef1e3fb) - [ ] [嘶吼安全动态|中央网信办等三部门开展2026年个人信息保护系列专项行动 Axios供应链攻击事件系朝鲜黑客组织所为](https://mp.weixin.qq.com/s?__biz=MzI0MDY1MDU4MQ==&mid=2247587535&idx=2&sn=9de4541ee0948f4548e8f43dd0f63a27) - 火绒安全 - [ ] [火绒安全终端防护数据月报(2026-03)](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247531885&idx=1&sn=1dd262fc221bb4a7fe22ba6446019aaf) - [ ] [火绒小问答——「企业版」离线升级工具如何使用](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247531885&idx=2&sn=d196fa0f6ef096b9346cbc7158e3a474) - [ ] [【火绒安全周报】思科开发环境遭黑客攻破/美国FBI局长邮箱遭入侵](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247531885&idx=3&sn=0d8e6d07affc7a79a986b6fe501d5b37) - [ ] [诚邀渠道合作伙伴共启新征程](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247531885&idx=4&sn=3fdec58f01693b153c951009f0b1a6e9) - 情报分析师 - [ ] [俄在暗中出手了,向伊朗输送无人机,中东战争或生变局](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650567423&idx=1&sn=d671445fb9088fa398f627c2a2f56ca3) - [ ] [五角大楼"金融特种部队",美式国家资本主义的战略逻辑与对我博弈新棋局](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650567423&idx=2&sn=08c4ac6d5540961edc8f8afab57205e4) - [ ] [一个谷歌翻译,摧毁了俄罗斯最机密的杀手特工部队](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650567423&idx=3&sn=e74c4444732ed5cda7287978621b250c) - [ ] [首尔想绕开华盛顿,用法国技术造核潜艇](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650567423&idx=4&sn=0131ec544289389b4711968d0ed8924b) - M01N Team - [ ] [每周蓝军技术推送(2026.3.28-2026.4.3)](https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&mid=2247494916&idx=1&sn=b01106658b570c0d850fb0a21ccbb036) - 腾讯安全威胁情报中心 - [ ] [借"码"行凶 | Claude Code 源码泄露引爆供应链投毒,窃密木马暗度陈仓](https://mp.weixin.qq.com/s?__biz=MzI5ODk3OTM1Ng==&mid=2247511607&idx=1&sn=67a18e00bf624c50e18463ca7ca4f5b5) - 迪哥讲事 - [ ] [sql注入新思路](https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&mid=2247499277&idx=1&sn=087a81e9901dc3ee269d85b1e7c889ba) - 威胁猎人Threat Hunter - [ ] [2026年3月全球恶意手机号趋势报告](https://mp.weixin.qq.com/s?__biz=MzI3NDY3NDUxNg==&mid=2247503089&idx=1&sn=e5de020e95be296457d417639f8309c1) - 360数字安全 - [ ] [智能体自动篡改敏感文件?360龙虾卫士一键防治资产“裸奔”](https://mp.weixin.qq.com/s?__biz=MzA4MTg0MDQ4Nw==&mid=2247585610&idx=1&sn=881b15ef23f8cdf5131922607edb43df) - Over Security - Cybersecurity news aggregator - [ ] [LinkedIn secretely scans for 6,000+ Chrome extensions, collects data](https://www.bleepingcomputer.com/news/security/linkedin-secretely-scans-for-6-000-plus-chrome-extensions-collects-data/) - [ ] [CISA gives agencies two weeks to patch video conferencing bug exploited by Chinese hackers](https://therecord.media/trueconf-cyberattack-cisa-hackers) - [ ] [FCC proposes $4.5 million fine for voice service provider hosting ‘suspicious’ foreign call traffic](https://therecord.media/fcc-proposes-5-million-fine-robocall) - [ ] [EU cyber agency attributes major data breach to TeamPCP hacking group](https://therecord.media/european-commission-cyberattack-teampcp) - [ ] [Hims & Hers warns of data breach after Zendesk support ticket breach](https://www.bleepingcomputer.com/news/security/hims-and-hers-warns-of-data-breach-after-zendesk-support-ticket-breach/) - [ ] [Do not get high(jacked) off your own supply (chain)](https://blog.talosintelligence.com/protecting-supply-chain-2026/) - [ ] [Uffizi nel mirino degli hacker: si riaccende il dibattito sulla cyber security del patrimonio culturale](https://www.cybersecurity360.it/nuove-minacce/uffizi-nel-mirino-degli-hacker-si-riaccende-il-dibattito-sulla-cyber-security-del-patrimonio-culturale/) - [ ] [Axois NPM Supply Chain Incident](https://blog.talosintelligence.com/axois-npm-supply-chain-incident/) - [ ] [Die Linke German political party confirms data stolen by Qilin ransomware](https://www.bleepingcomputer.com/news/security/die-linke-german-political-party-confirms-data-stolen-by-qilin-ransomware/) - [ ] [Europe’s cyber agency blames hacking gangs for massive data breach and leak](https://techcrunch.com/2026/04/03/europes-cyber-agency-blames-hacking-gangs-for-massive-data-breach-and-leak/) - [ ] [Sintesi riepilogativa delle campagne malevole nella settimana del 28 marzo – 3 aprile](https://cert-agid.gov.it/news/sintesi-riepilogativa-delle-campagne-malevole-nella-settimana-del-28-marzo-3-aprile/) - [ ] [Rilasciati su Telegram oltre 500 MB di documenti d’identità italiani rubati](https://cert-agid.gov.it/news/anonymous-algeria-rilascia-oltre-500-mb-di-documenti-didentita-italiani-rubati/) - [ ] [Derapate AI-driven](https://www.cybersecurity360.it/cultura-cyber/derapate-ai-driven/) - [ ] [Strategia cybersecurity USA verso un modello più assertivo e industriale](https://www.securityinfo.it/2026/04/03/strategia-cybersecurity-usa-verso-un-modello-piu-assertivo-e-industriale/) - [ ] [L’Attacco alla Supply Chain di Axios e il RAT Multipiattaforma di Sapphire Sleet](https://blog.lobsec.com/2026/04/analisi-tecnica-attacco-supply-chain-axios-rat/) - [ ] [Massachusetts emergency communications system impacted by cyberattack](https://therecord.media/massachusetts-emergency-alert-cyberattack) - [ ] [Evolution of Ransomware: Multi-Extortion Ransomware Attacks](https://www.bleepingcomputer.com/news/security/evolution-of-ransomware-multi-extortion-ransomware-attacks/) - [ ] [Ukraine warns Russian hackers are revisiting past breaches to prepare new attacks](https://therecord.media/ukraine-warns-russian-hackers-revisiting-old-attacks) - [ ] [Venom Stealer: la nuova era del cybercrime e l’industrializzazione del furto digitale](https://www.cybersecurity360.it/news/venom-stealer-lindustrializzazione-del-furto-digitale/) - [ ] [Microsoft still working to fix Exchange Online mailbox access issues](https://www.bleepingcomputer.com/news/microsoft/microsoft-still-working-to-fix-exchange-online-mailbox-access-issues/) - [ ] [Il primo computer quantistico si avvicina: urgente la transizione alla crittografia post-quantistica](https://www.cybersecurity360.it/nuove-minacce/il-primo-computer-quantistico-si-avvicina-urgente-la-transizione-alla-crittografia-post-quantistica/) - [ ] [Man admits to locking thousands of Windows devices in extortion plot](https://www.bleepingcomputer.com/news/security/man-admits-to-extortion-plot-locking-coworkers-out-of-thousands-of-windows-devices/) - [ ] [Cyber security: perché è centrale l’autonomia strategica europea](https://www.cybersecurity360.it/cultura-cyber/cyber-security-perche-e-centrale-lautonomia-strategica-europea/) - [ ] [Microsoft now force upgrades unmanaged Windows 11 24H2 PCs](https://www.bleepingcomputer.com/news/microsoft/microsoft-now-force-upgrades-unmanaged-windows-11-24h2-pcs/) - [ ] [The Cyber Express Weekly Roundup: Ransomware, and Supply Chain Breaches Surge](https://thecyberexpress.com/tce-weekly-roundup-ransomware-supply-chain/) - [ ] [NIS2, arrivano le categorizzazioni: cosa cambia davvero per aziende, PA e risk analysis](https://www.cybersecurity360.it/legal/nis2-arrivano-le-categorizzazioni-cosa-cambia-davvero-per-aziende-pa-e-risk-analysis/) - [ ] [Operation NoVoice: Rootkit Tells No Tales | McAfee Blog](https://www.mcafee.com/blogs/other-blogs/mcafee-labs/new-research-operation-novoice-rootkit-malware-android/) - [ ] [CERT-EU: European Commission hack exposes data of 30 EU entities](https://www.bleepingcomputer.com/news/security/cert-eu-european-commission-hack-exposes-data-of-30-eu-entities/) - [ ] [Drift loses $280 million North Korean hackers seize Security Council powers](https://www.bleepingcomputer.com/news/security/drift-loses-280-million-north-korean-hackers-seize-security-council-powers/) - 字节跳动技术团队 - [ ] [让老手机刷抖音也流畅:我们做对了这三件事](https://mp.weixin.qq.com/s?__biz=MzI1MzYzMjE0MQ==&mid=2247519187&idx=1&sn=21e592f0aa2e4abc0202ea82e7df975b) - Securityinfo.it - [ ] [Strategia cybersecurity USA verso un modello più assertivo e industriale](https://www.securityinfo.it/2026/04/03/strategia-cybersecurity-usa-verso-un-modello-piu-assertivo-e-industriale/?utm_source=rss&utm_medium=rss&utm_campaign=strategia-cybersecurity-usa-verso-un-modello-piu-assertivo-e-industriale) - Javvad Malik - [ ] [Breach of Confidence: 3 April 2026](https://javvadmalik.com/2026/04/03/breach-of-confidence-3-april-2026/) - 安全行者老霍 - [ ] [LotAI:攻击者如何利用AI助手进行数据窃取](https://mp.weixin.qq.com/s?__biz=Mzg3NjU4MDI4NQ==&mid=2247486283&idx=1&sn=e3ed78aff2343ac81941d95160bc44c3) - ICT Security Magazine - [ ] [Prompt injection negli agenti AI aziendali: il nuovo vettore che i SOC non stanno monitorando](https://www.ictsecuritymagazine.com/notizie/prompt-injection-negli-agenti-ai/) - 白泽安全实验室 - [ ] [APT28组织利用多个Windows 0Day漏洞开展攻击活动分析](https://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&mid=2247492909&idx=1&sn=54c0d7d9fa6b0a93c21f1ebb2cdc8d44) - 云鼎实验室 - [ ] [「AI开源组件安全风险」系列二:VulnAgent发现 NVIDIA 3个AI基础设施漏洞,并获官方致谢](https://mp.weixin.qq.com/s?__biz=MzU3ODAyMjg4OQ==&mid=2247497433&idx=1&sn=77d0db9bdf75c8d28f231e0cdfc7be9e) - Schneier on Security - [ ] [Friday Squid Blogging: Jurassic Fish Chokes on Squid](https://www.schneier.com/blog/archives/2026/04/friday-squid-blogging-jurassic-fish-chokes-on-squid.html) - [ ] [Company that Secretly Records and Publishes Zoom Meetings](https://www.schneier.com/blog/archives/2026/04/company-that-secretly-records-and-publishes-zoom-meetings.html) - SANS Internet Storm Center, InfoCON: green - [ ] [TeamPCP Supply Chain Campaign: Update 006 - CERT-EU Confirms European Commission Cloud Breach, Sportradar Details Emerge, and Mandiant Quantifies Campaign at 1,000+ SaaS Environments, (Fri, Apr 3rd)](https://isc.sans.edu/diary/rss/32864) - [ ] [ISC Stormcast For Friday, April 3rd, 2026 https://isc.sans.edu/podcastdetail/9878, (Fri, Apr 3rd)](https://isc.sans.edu/diary/rss/32862) - Yak Project - [ ] [Memfit AI 长期记忆:让渗透 Agent 告别 “失忆”,练就实战肌肉记忆](https://mp.weixin.qq.com/s?__biz=Mzk0MTM4NzIxMQ==&mid=2247529629&idx=1&sn=72c6bf22ebf1c7d91db25a14d02f659e) - The Hacker News - [ ] [China-Linked TA416 Targets European Governments with PlugX and OAuth-Based Phishing](https://thehackernews.com/2026/04/china-linked-ta416-targets-european.html) - [ ] [Microsoft Details Cookie-Controlled PHP Web Shells Persisting via Cron on Linux Servers](https://thehackernews.com/2026/04/microsoft-details-cookie-controlled-php.html) - [ ] [UNC1069 Social Engineering of Axios Maintainer Led to npm Supply Chain Attack](https://thehackernews.com/2026/04/unc1069-social-engineering-of-axios.html) - [ ] [Why Third-Party Risk Is the Biggest Gap in Your Clients' Security Posture](https://thehackernews.com/2026/04/why-third-party-risk-is-biggest-gap-in.html) - [ ] [New SparkCat Variant in iOS, Android Apps Steals Crypto Wallet Recovery Phrase Images](https://thehackernews.com/2026/04/new-sparkcat-variant-in-ios-android.html) - [ ] [Drift Loses $285 Million in Durable Nonce Social Engineering Attack Linked to DPRK](https://thehackernews.com/2026/04/drift-loses-285-million-in-durable.html) - GRAHAM CLULEY - [ ] [Nigerian romance scammer jailed after being caught out by fellow fraudster](https://www.bitdefender.com/en-us/blog/hotforsecurity/nigerian-romance-scammer-jailed) - The Register - Security - [ ] [Trump wants to take a battle axe to CISA again and slash $707M from budget](https://go.theregister.com/feed/www.theregister.com/2026/04/03/trump_cisa_budget/) - [ ] [Hybrid work, expanded risk: what needs to change](https://go.theregister.com/feed/www.theregister.com/2026/04/03/hybrid_work_expanded_risk/) - Blackhat Library: Hacking techniques and research - [ ] [Axios supply chain attacks initial access revealed (insane North Korean tactic)](https://www.reddit.com/r/blackhat/comments/1sbgdns/axios_supply_chain_attacks_initial_access/) - [ ] [Infostealers ULP (url:login:password) Data Is Burning Out SOC Teams and Killing Automation](https://www.reddit.com/r/blackhat/comments/1sbh4zr/infostealers_ulp_urlloginpassword_data_is_burning/) - Full Disclosure - [ ] [SEC Consult SA-20260401-0 :: Broken Access Control in Open WebUI](https://seclists.org/fulldisclosure/2026/Apr/4) - [ ] [SEC Consult SA-20260326-0 :: Local Privilege Escalation in Vienna Assistant (MacOS) - Vienna Symphonic Library](https://seclists.org/fulldisclosure/2026/Apr/3) - [ ] [Apple OHTTP Relay: 14 Third-Party Endpoints, 6 Countries, Zero User Visibility](https://seclists.org/fulldisclosure/2026/Apr/2) - [ ] [[KIS-2026-06] MetInfo CMS <= 8.1 (weixinreply.class.php) PHP Code Injection Vulnerability](https://seclists.org/fulldisclosure/2026/Apr/1) - [ ] [[CVE-2026-33691] OWASP CRS whitespace padding bypass vulnerability](https://seclists.org/fulldisclosure/2026/Apr/0) - Instapaper: Unread - [ ] [Hackerata Gmail del direttore FBI, la 2FA non basta più. Serve attivare la Protezione Avanzata](https://www.cybersecitalia.it/hackerata-gmail-del-direttore-fbi-la-2fa-non-basta-piu-serve-attivare-la-protezione-avanzata/61679/) - [ ] [Italian spyware vendor creates Fake WhatsApp app, targeting 200 users](https://securityaffairs.com/190276/malware/italian-spyware-vendor-creates-fake-whatsapp-app-targeting-200-users.html) - [ ] [Kubernetes forensics 13 what the container](https://synacktiv.com/publications/kubernetes-forensics-13-what-the-container) - [ ] [Rilasciati su Telegram oltre 500 MB di documenti d’identità italiani rubati](https://cert-agid.gov.it/news/anonymous-algeria-rilascia-oltre-500-mb-di-documenti-didentita-italiani-rubati/) - [ ] [iOS Lockdown mode and forensic analysis a technical perspective](https://andreafortuna.org/2026/03/29/ios-lockdown-mode-forensics/) - [ ] [Arrested by AI](https://blog.elcomsoft.com/2026/03/arrested-by-an-algorithm/) - Information Security - [ ] [Built a self-hosted expiration monitoring tool for certificates, secrets, API keys, and licenses](https://www.reddit.com/r/Information_Security/comments/1sbor7m/built_a_selfhosted_expiration_monitoring_tool_for/) - [ ] [Is cyber security training with job placement actually worth it, or just marketing hype?](https://www.reddit.com/r/Information_Security/comments/1sbd7r1/is_cyber_security_training_with_job_placement/) - [ ] [Open source runtime security for AI agents — zero trust model with 8 deterministic layers](https://www.reddit.com/r/Information_Security/comments/1sbbea0/open_source_runtime_security_for_ai_agents_zero/) - TorrentFreak - [ ] [Yout.com Hopes Supreme Court’s Cox Ruling Helps Its Case; RIAA Disagrees](https://torrentfreak.com/yout-com-hopes-supreme-courts-cox-ruling-helps-its-case-riaa-disagrees/) - Technical Information Security Content & Discussion - [ ] [Using undocumented AWS CodeBuild endpoints to extract privileged tokens from AWS CodeConnections allowing lateral movement and privilege escalation through an organisation's codebase](https://www.reddit.com/r/netsec/comments/1sbe9tn/using_undocumented_aws_codebuild_endpoints_to/) - [ ] [ShieldNet Trust Posture](https://www.reddit.com/r/netsec/comments/1sbti2s/shieldnet_trust_posture/) - [ ] [A threat actor who goes by the name "Mr. Raccoon" has claimed to hack Adobe support via 3rd party Indian BPO firm](https://www.reddit.com/r/netsec/comments/1sb7man/a_threat_actor_who_goes_by_the_name_mr_raccoon/) - [ ] [New RCE in Control Web Panel (CVE-2025-70951)](https://www.reddit.com/r/netsec/comments/1sb7pr4/new_rce_in_control_web_panel_cve202570951/) - [ ] [Claude Code Found a Linux Vulnerability Hidden for 23 Years](https://www.reddit.com/r/netsec/comments/1sbfq4u/claude_code_found_a_linux_vulnerability_hidden/) - Social Engineering - [ ] [Every Path Leads Here.](https://www.reddit.com/r/SocialEngineering/comments/1sbod36/every_path_leads_here/) - Desync InfoSec - [ ] [微软深度分析:威胁行为者将AI从工具升级为网络攻击表面](https://mp.weixin.qq.com/s?__biz=MzkzMDE3ODc1Mw==&mid=2247489707&idx=1&sn=570ead353d64a241f595b5dc32ec49d5) - Trend Micro Research, News and Perspectives - [ ] [Weaponizing Trust Signals: Claude Code Lures and GitHub Release Payloads](https://www.trendmicro.com/en_us/research/26/d/weaponizing-trust-signals-claude-code-lures-and-github-release-payloads.html) - Security Affairs - [ ] [North Korea–linked hackers drain $285M from Drift in sophisticated attack](https://securityaffairs.com/190330/hacking/north-korea-linked-hackers-drain-285m-from-drift-in-sophisticated-attack.html) - [ ] [CrystalX RAT: new MaaS malware combines spyware, stealer, and remote access](https://securityaffairs.com/190310/cyber-crime/crystalx-rat-new-maas-malware-combines-spyware-stealer-and-remote-access.html) - [ ] [Pro-Iran Handala group breached Israeli defence contractor PSK Wind Technologies](https://securityaffairs.com/190319/data-breach/pro-iran-handala-group-breached-israeli-defence-contractor-psk-wind-technologies.html) - netsecstudents: Subreddit for students studying Network Security and its related subjects - [ ] [I built a penetration testing assistant that uses a fine-tuned Qwen 3.5 model via Ollama — runs 100% offline](https://www.reddit.com/r/netsecstudents/comments/1sazx9y/i_built_a_penetration_testing_assistant_that_uses/) - [ ] [Is T-Pot actually worth deploying on a small VPS?](https://www.reddit.com/r/netsecstudents/comments/1sb33d0/is_tpot_actually_worth_deploying_on_a_small_vps/) - Computer Forensics - [ ] [At what point does a PDF stop being trustworthy as financial evidence?](https://www.reddit.com/r/computerforensics/comments/1sb95ah/at_what_point_does_a_pdf_stop_being_trustworthy/) - Deeplinks - [ ] [Triple Header for Privacy’s Defender in New York](https://www.eff.org/deeplinks/2026/04/triple-header-privacys-defender-new-york) - [ ] [The FAA’s “Temporary” Flight Restriction for Drones is a Blatant Attempt to Criminalize Filming ICE](https://www.eff.org/deeplinks/2026/04/faas-temporary-flight-restriction-drones-blatant-attempt-criminalize-filming-ice) - [ ] [Tech Nonprofits to Feds: Don’t Weaponize Procurement to Undermine AI Trust and Safety](https://www.eff.org/deeplinks/2026/04/tech-nonprofits-feds-dont-weaponize-procurement-undermine-ai-trust-and-safety) - [ ] [Double Shot of Privacy's Defender in D.C.](https://www.eff.org/deeplinks/2026/04/double-shot-privacys-defender-dc) - Your Open Hacker Community - [ ] [Found a vulnerability and got admin access to a website, what to do now?](https://www.reddit.com/r/HowToHack/comments/1sbr0c6/found_a_vulnerability_and_got_admin_access_to_a/) - [ ] [NEED HELP](https://www.reddit.com/r/HowToHack/comments/1sbqalz/need_help/) - [ ] [Getting into cybersecurity — Flipper Zero or T-Embed?](https://www.reddit.com/r/HowToHack/comments/1sbr3mm/getting_into_cybersecurity_flipper_zero_or_tembed/) - [ ] [OverTheWire Bandit: How do you improve problem-solving, not just commands?](https://www.reddit.com/r/HowToHack/comments/1sb56jd/overthewire_bandit_how_do_you_improve/) - [ ] [Android 15](https://www.reddit.com/r/HowToHack/comments/1sbh9u2/android_15/) - [ ] [Got scammed on “CarPlay/Android Auto” head unit — any way to get CarPlay working on a fake Android unit?](https://www.reddit.com/r/HowToHack/comments/1sb9bh0/got_scammed_on_carplayandroid_auto_head_unit_any/) - [ ] [BBA Graduate Trying to Enter Cybersecurity — Is It Possible](https://www.reddit.com/r/HowToHack/comments/1sb520q/bba_graduate_trying_to_enter_cybersecurity_is_it/) - [ ] [HYPOTHETICAL STUDENT COUNCIL ELECTION FRAUD](https://www.reddit.com/r/HowToHack/comments/1sbn63r/hypothetical_student_council_election_fraud/) - [ ] [is there anyway to hack into a wifi without a pc iknow hackibg into wifi is almost impossible but can anyone help me](https://www.reddit.com/r/HowToHack/comments/1sbieqv/is_there_anyway_to_hack_into_a_wifi_without_a_pc/) - [ ] [How to exploit a vulnerabilitie](https://www.reddit.com/r/HowToHack/comments/1sb7036/how_to_exploit_a_vulnerabilitie/) - [ ] [I’m building an iPhone app to hack WPA3 WiFi. Do you think I can get it into the App Store?](https://www.reddit.com/r/HowToHack/comments/1sb53s0/im_building_an_iphone_app_to_hack_wpa3_wifi_do/) - 白帽子章华鹏 - [ ] [聊聊Claude code和Agent运行时安全](https://mp.weixin.qq.com/s?__biz=MzIyOTAxOTYwMw==&mid=2650238966&idx=1&sn=82ec68e539ecc33ed4ba526c9571543a) - DEFION Research Labs - [ ] [Ruckus Unleashed: Multiple vulnerabilities exploited](/en/research-labs/ruckus-unleashed-multiple-vulnerabilities-exploited) - [ ] [Pwn2Own Automotive 2024: Hacking the Autel MaxiCharger](/en/research-labs/pwn2own-automotive-2024-hacking-the-autel-maxicharger) - [ ] [Pwn2Own Automotive 2024: Hacking the JuiceBox 40](/en/research-labs/pwn2own-automotive-2024-hacking-the-juicebox-40) - [ ] [Pwn2Own Automotive 2024: Hacking the ChargePoint Home Flex (and their cloud...)](/en/research-labs/pwn2own-automotive-2024-hacking-the-chargepoint-home-flex-and-their-cloud) - [ ] [DoNex/DarkRace Ransomware Decryptor](/en/research-labs/donex-darkrace-ransomware-decryptor) - [ ] [CVE-2024-20693: Windows cached code signature manipulation](/en/research-labs/cve-2024-20693-windows-cached-code-signature-manipulation) - [ ] [Bringing process injection into view(s): exploiting all macOS apps using nib files](/en/research-labs/bringing-process-injection-into-view-s-exploiting-all-macos-apps-using-nib-files) - [ ] [Don’t Talk All at Once! Elevating Privileges on macOS by Audit Token Spoofing](/en/research-labs/don-t-talk-all-at-once-elevating-privileges-on-macos-by-audit-token-spoofing) - [ ] [Getting SYSTEM on Windows in style](/en/research-labs/getting-system-on-windows-in-style) - [ ] [Technical analysis of the Genesis Market](/en/research-labs/technical-analysis-of-the-genesis-market) - [ ] [Bad things come in large packages: .pkg signature verification bypass on macOS](/en/research-labs/bad-things-come-in-large-packages-pkg-signature-verification-bypass-on-macos) - [ ] [Pwn2Own Miami 2022: ICONICS GENESIS64 Arbitrary Code Execution](/en/research-labs/pwn2own-miami-2022-iconics-genesis64-arbitrary-code-execution) - [ ] [Pwn2Own Miami 2022: Unified Automation C++ Demo Server DoS](/en/research-labs/pwn2own-miami-2022-unified-automation-c-demo-server-dos) - [ ] [Pwn2Own Miami 2022: AVEVA Edge Arbitrary Code Execution](/en/research-labs/pwn2own-miami-2022-aveva-edge-arbitrary-code-execution) - [ ] [Process injection: breaking all macOS security layers with a single vulnerability](/en/research-labs/process-injection-breaking-all-macos-security-layers-with-a-single-vulnerability) - [ ] [Pwn2Own Miami 2022: Inductive Automation Ignition Remote Code Execution](/en/research-labs/pwn2own-miami-2022-inductive-automation-ignition-remote-code-execution) - [ ] [Pwn2Own Miami 2022: OPC UA .NET Standard Trusted Application Check Bypass](/en/research-labs/pwn2own-miami-2022-opc-ua-net-standard-trusted-application-check-bypass) - [ ] [CoronaCheck App TLS certificate vulnerabilities](/en/research-labs/coronacheck-app-tls-certificate-vulnerabilities) - [ ] [Sandbox escape + privilege escalation in StorePrivilegedTaskService](/en/research-labs/sandbox-escape-privilege-escalation-in-storeprivilegedtaskservice) - [ ] [Proctorio Chrome extension Universal Cross-Site Scripting](/en/research-labs/proctorio-chrome-extension-universal-cross-site-scripting) - [ ] [Zoom RCE from Pwn2Own 2021](/en/research-labs/zoom-rce-from-pwn2own-2021) - [ ] [Adobe Acrobat privilege escalation](/en/research-labs/adobe-acrobat-privilege-escalation) - [ ] [iOS VPN support: 3 different bugs](/en/research-labs/ios-vpn-support-3-different-bugs) - [ ] [Sign in with Apple - authentication bypass](/en/research-labs/sign-in-with-apple-authentication-bypass) - [ ] [Jenkins - authentication bypass](/en/research-labs/jenkins-authentication-bypass) - [ ] [DNS rebinding for HTTPS](/en/research-labs/dns-rebinding-for-https) - [ ] [Spring Security - insufficient cryptographic randomness](/en/research-labs/spring-security-insufficient-cryptographic-randomness) - [ ] [XenServer - path traversal leading to authentication bypass](/en/research-labs/xenserver-path-traversal-leading-to-authentication-bypass) - [ ] [Volkswagen Auto Group MIB infotainment system - unauthenticated remote code execution as root](/en/research-labs/volkswagen-auto-group-mib-infotainment-system-unauthenticated-remote-code-execution-as-root) - [ ] [NAPALM - command execution on NAPLM controller from host](/en/research-labs/napalm-command-execution-on-naplm-controller-from-host) - [ ] [MySQL Connector/J - Unexpected deserialisation of Java objects](/en/research-labs/mysql-connector-j-unexpected-deserialisation-of-java-objects) - [ ] [Ansible - command execution on Ansible controller from host](/en/research-labs/ansible-command-execution-on-ansible-controller-from-host) - [ ] [Observium - unauthenticated remote code execution](/en/research-labs/observium-unauthenticated-remote-code-execution) - [ ] [cSRP/srpforjava - obtaining of hashed passwords](/en/research-labs/csrp-srpforjava-obtaining-of-hashed-passwords) - [ ] [StartEncrypt - obtaining valid SSL certificates for unauthorized domains](/en/research-labs/startencrypt-obtaining-valid-ssl-certificates-for-unauthorized-domains) - 安全攻防团队 - [ ] [「AI开源组件安全风险」系列二:VulnAgent发现 NVIDIA 3个AI基础设施漏洞,并获官方致谢](https://mp.weixin.qq.com/s?__biz=MzkzNTI4NjU1Mw==&mid=2247485145&idx=1&sn=a715bdf057310c8fa51676cfd6976a84)
每日安全资讯(2026-04-04)