# 每日安全资讯(2026-04-10) - SecWiki News - [ ] [SecWiki News 2026-04-09 Review](http://www.sec-wiki.com/?2026-04-09) - Private Feed for M09Ic - [ ] [WAY29 starred uditgoenka/autoresearch](https://github.com/uditgoenka/autoresearch) - [ ] [mgeeky starred xaitax/TotalRecall](https://github.com/xaitax/TotalRecall) - [ ] [airbus-seclab released v4.8.2 at airbus-seclab/soxy](https://github.com/airbus-seclab/soxy/releases/tag/v4.8.2) - [ ] [bolucat released 202604092117 at bolucat/Archive](https://github.com/bolucat/Archive/releases/tag/202604092117) - [ ] [anthropics released v2.1.98 at anthropics/claude-code](https://github.com/anthropics/claude-code/releases/tag/v2.1.98) - [ ] [github released v0.6.0 at github/spec-kit](https://github.com/github/spec-kit/releases/tag/v0.6.0) - [ ] [safedv starred jonaslejon/malicious-pdf](https://github.com/jonaslejon/malicious-pdf) - [ ] [kpcyrd starred uutils/coreutils](https://github.com/uutils/coreutils) - [ ] [Mel0day starred TauricResearch/TradingAgents](https://github.com/TauricResearch/TradingAgents) - [ ] [Rvn0xsy starred webadderall/Recordly](https://github.com/webadderall/Recordly) - [ ] [pydantic released v0.0.10 at pydantic/monty](https://github.com/pydantic/monty/releases/tag/v0.0.10) - [ ] [DVKunion starred Keytoyze/ossdata](https://github.com/Keytoyze/ossdata) - [ ] [PrefectHQ released 3.6.26.dev5 at PrefectHQ/prefect](https://github.com/PrefectHQ/prefect/releases/tag/3.6.26.dev5) - [ ] [rabbitmask starred anthropics/skills](https://github.com/anthropics/skills) - [ ] [zema1 starred mutagen-io/mutagen](https://github.com/mutagen-io/mutagen) - [ ] [0xbug starred 0x676e67/wreq-python](https://github.com/0x676e67/wreq-python) - [ ] [gh0stkey starred Yeachan-Heo/oh-my-claudecode](https://github.com/Yeachan-Heo/oh-my-claudecode) - [ ] [pmiaowu starred yaklang/hack-skills](https://github.com/yaklang/hack-skills) - [ ] [Rvn0xsy forked Rvn0xsy/superfile from yorukot/superfile](https://github.com/Rvn0xsy/superfile) - Doonsec's feed - [ ] [渗透测试人员必备:浏览器 JWT 利用工具](https://mp.weixin.qq.com/s/2CzDUcuIIUJXc7I2qYuNog) - [ ] [30 秒接管苹果账号!中东记者被跨国网络间谍攻击,背后竟是这个APT组织](https://mp.weixin.qq.com/s/rk0l-0CUIoXPWax4lF6iwQ) - [ ] [原创—为啥说过去是绝大多数的穷人养活着极少数的资本家,未来是极少数的资本家养活着极少数的穷人](https://mp.weixin.qq.com/s/BDciLpT-G5fVPFlhoV3aXw) - [ ] [AI Agent沙箱之ANOLISA内置沙箱](https://mp.weixin.qq.com/s/NYSUVq8lINtxBFc8hqSyMA) - [ ] [Drift Protocol遭史诗级攻击](https://mp.weixin.qq.com/s/xJwLw26p_EQIm6kVNXti0w) - [ ] [新手机踩坑体验](https://mp.weixin.qq.com/s/xGuMdazn8kfvWcob9_7YNg) - [ ] [张雪峰妻子突然发声,回应一切](https://mp.weixin.qq.com/s/agKX1mZJgKm9L9oIfJx7iA) - [ ] [传统黑客渗透测试与Ai智能体自动化的完整对接- AI只是用于(我)优化和提升效率的工具](https://mp.weixin.qq.com/s/BNU-jiGH86Zby3oLBlEz-w) - [ ] [GoAttack——网络安全扫描分析平台](https://mp.weixin.qq.com/s/Z393AgudDtloFDhY5F-B7A) - [ ] [运维人主流职业方向选择指南](https://mp.weixin.qq.com/s/AdbnPWetKO0e2-DeUO0AqQ) - [ ] [朝鲜黑客组织的分布式运作架构、安全漏洞与加密货币洗钱链路](https://mp.weixin.qq.com/s/fbQ0WINl2pb-zkOd9UDb6g) - [ ] [frida源码分析教程更新](https://mp.weixin.qq.com/s/54H-sv8cNoMM5YgErQHxOA) - [ ] [网安公司的研发组织如何构建?AI时代的安全研发模式升级指南](https://mp.weixin.qq.com/s/vrPDLZe5rGkkRESJiCYp0w) - [ ] [别让低效率的 AI成为你技术进阶的精神枷锁](https://mp.weixin.qq.com/s/fAm83YDDUOMvNz1Euj7n3Q) - [ ] [2025平航杯服务器取证部分](https://mp.weixin.qq.com/s/KRDsD1c32zuXe3JHL4P26Q) - [ ] [大湾区大学 | 网络与信息安全研究中心招聘博士后](https://mp.weixin.qq.com/s/PHb4gfHZPiUIZufLs-Njfg) - [ ] [【AI安全】大模型反杀黑客!投喂“假药”秒破越狱](https://mp.weixin.qq.com/s/dA-h70uKEPIUw9ChOMNOmA) - [ ] [某中心网络安全保险数据智能化处理系统开发服务,145万,金睛云华中标。](https://mp.weixin.qq.com/s/szgPHOlAecBpx-kxOgvQSg) - [ ] [暗网情报技术能力框架及参考指标体系(指导性技术文件2026版)](https://mp.weixin.qq.com/s/fQCVKbxERf-NgD-CdEqU8A) - [ ] [用 AI Agent 自动化 JavaScript 加密逆向分析](https://mp.weixin.qq.com/s/ESavpqR8av08_t2qtVrbAA) - [ ] [CTF和护网都搞不懂,还学什么网安?](https://mp.weixin.qq.com/s/79dNuxwhvxT7pYfubJB9nA) - [ ] [抖音出事了,内部50余人被抓](https://mp.weixin.qq.com/s/lyJbGahWpwm8iAm3pT4KYg) - [ ] [一图读懂安博通2025年年报](https://mp.weixin.qq.com/s/kHTdzo4Zc5xvTRdbqjhxbA) - [ ] [《纽约时报》再次宣布「找到了中本聪」](https://mp.weixin.qq.com/s/v6YK8DHoKpHE7e9elQp8aQ) - [ ] [蓄势待发!一线便携实战利器,带来全新体验](https://mp.weixin.qq.com/s/Ovgw7nxrn_SDFfH0_C8Qcw) - [ ] [国投智能培训基地4月培训计划火热开启!](https://mp.weixin.qq.com/s/xCr9yD_rqLrYyttb3Cd_ZA) - [ ] [(07)4.1 理解组织及其环境 — 企业信息安全负责人必读系列丛书书稿《ISO/IEC 42001: 2023人工智能管理体系标准的谬误辨析与实施详解》](https://mp.weixin.qq.com/s/8-OBcNR20kRaawBwRrK4hA) - [ ] [【福利赠送】ISO 22301业务连续性管理体系导入实施案例(12)业务影响分析和风险评估的培训](https://mp.weixin.qq.com/s/mL7y2GfR9wqkT15xRWyrsw) - [ ] [学习笔记|读懂COBIT模型,搞定IT治理核心逻辑](https://mp.weixin.qq.com/s/yqnpa8aFnxIt3PJHKfEa9A) - [ ] [黑客.skill](https://mp.weixin.qq.com/s/nVU1ll7MDVVHOS7rl5t34Q) - [ ] [光大银行打造“9×10”大模型智能助手矩阵,RPA累计应用场景1700+](https://mp.weixin.qq.com/s/ggulNEYG9AFvBsu_U_xmAA) - [ ] [AI快讯:微信支付发布AI接入工具箱,浦发银行打造“浦银智启”大模型服务矩阵](https://mp.weixin.qq.com/s/watnBnMuHoVYVbB0tnnF0Q) - [ ] [火山引擎388万中!国信证券财富业务AI应用建设(二期)项目](https://mp.weixin.qq.com/s/SJNBjJgiPNpNiGt3kinGzQ) - [ ] [GZCTF的搭建和CTF题目的出题](https://mp.weixin.qq.com/s/Z9t4H39-cCGloPxaZPs-1g) - [ ] [兰德观点:中美人工智能竞争格局](https://mp.weixin.qq.com/s/euV8hthZP-PzU_AEWQpyUw) - [ ] [从分类洞察到长效运营,游戏私服治理的进阶之路](https://mp.weixin.qq.com/s/I2ShInQcbzgIVCVVH5ZCyQ) - [ ] [Hermes Agent vs OpenClaw:下一代 Agent 竞争,已经不是功能之争](https://mp.weixin.qq.com/s/7Xm79lze6thwE6z_d0VEBA) - [ ] [Chrome浏览器存在严重漏洞,攻击者可利用这些漏洞执行任意代码](https://mp.weixin.qq.com/s/pXUt7ewNu1U1AJj3y3EC4A) - [ ] [AI仅用4小时攻破“全球最安全系统”](https://mp.weixin.qq.com/s/gKyekZHsG5VM5Cd61COvcg) - [ ] [政策解读 | 中国信通院刘阳:从万物互联到万物智联,推动物联网高质量发展](https://mp.weixin.qq.com/s/jPEEDBgyDNjK-OOKd5FYeQ) - [ ] [【安全圈】盗用他人信息注册账号卖给未成年人,上海警方捣毁一“游戏账号工厂”黑产链](https://mp.weixin.qq.com/s/R-wMw9h_O0fMECjQLS4wsg) - [ ] [【安全圈】AI 数据独角兽遭黑客攻击,一周内吃了 5 场官司,Meta 紧急暂停合作](https://mp.weixin.qq.com/s/stjWO0x8awF11M7IhU428w) - [ ] [【安全圈】洛杉矶市律师系统遭入侵,敏感警局文件泄露](https://mp.weixin.qq.com/s/FR6j6LKxf0q0QC9Rsf_4cA) - [ ] [AgentEscape:MCP服务器如何让AI助手读取你的私钥](https://mp.weixin.qq.com/s/Dw-KF6lYU0eRd3zycP_q_A) - [ ] [永信至诚发布「定心」产品乘服务解决方案,让数据安全风险可控、可管、可闭环](https://mp.weixin.qq.com/s/VElWCImLF4g9RdHNhCOYsA) - [ ] [专家解读|以人为本划定数字虚拟人服务边界,助力智能经济高质量发展](https://mp.weixin.qq.com/s/jp7AhmOq1GjaTDyjtnBv2Q) - [ ] [通知 | 网安标委就《网络安全技术 物理不可克隆功能安全技术规范(征求意见稿)》等3项国家标准征求意见(附下载)](https://mp.weixin.qq.com/s/Cq4Bifu64ulHJIpwQmAcKw) - [ ] [评论 | 词元安全关乎国家数据安全](https://mp.weixin.qq.com/s/Qe2OiyatILk8w2iX827Ahg) - [ ] [盘点 | 中国互联网联合辟谣平台2026年3月辟谣榜](https://mp.weixin.qq.com/s/mvkAMEFRSDAPHDwKf0KZeg) - [ ] [微软0day-漏洞的之“你们这些天才自己就能搞明白”后续问题········](https://mp.weixin.qq.com/s/wBvlYltxQoV-rNsho9qzlQ) - [ ] [能源水务等关基工控设施遭破坏性网络攻击,美国政府紧急发布警报](https://mp.weixin.qq.com/s/XJpOIpXJi6_bi4v7-1Y7KQ) - [ ] [飓风安全发现OpenClaw高危漏洞](https://mp.weixin.qq.com/s/sfcq1xDLLoh5pgujdjs2qg) - [ ] [已存在13年的Apache ActiveMQ 严重漏洞可用于远程执行命令](https://mp.weixin.qq.com/s/AXG9IXCFNtX7C7lMrS4YIg) - [ ] [CISA:须在周日前修复已遭利用的 Ivanti EPMM 漏洞](https://mp.weixin.qq.com/s/vV0zHzicF_AGGftp8zqLow) - [ ] [中央企业网络安全态势月报 (2026年3月)](https://mp.weixin.qq.com/s/R0ZFN8zA-Zgtpu0Q4ptjyA) - [ ] [Hermes Agent - 咱们的赫妹小助理十分钟上手体验](https://mp.weixin.qq.com/s/brxTyYDWMgwaUul-YKYB4A) - [ ] [我发现不上班真的会上瘾,今天躺在家挖漏洞,入手500](https://mp.weixin.qq.com/s/vnrIlRMeJjwohSfozQ-SSg) - [ ] [19,000份未公开原档在手:Handala黑客曝光以军前总长哈莱维影像资料](https://mp.weixin.qq.com/s/f96VkZUVdhC7K44iaSFiUQ) - [ ] [启明星辰首批通过中国信通院OpenClaw类智能体安全防护产品能力评测](https://mp.weixin.qq.com/s/2rxvGTOa6tL3aekxz2nfhA) - [ ] [发现 33 个 OpenClaw 与 Linux 内核漏洞后,我们也从 Claude Mythos 看到了安全攻防的下半场](https://mp.weixin.qq.com/s/Nh8sx89AaMTlhSu4YdtqWA) - [ ] [入选全国 TOP100 案例!360 企业级智能体为高校数智化提供可复制路径](https://mp.weixin.qq.com/s/-Q2sqbXzunhoph8lbVhQtg) - [ ] [启明星辰ADLab |xa0从美以伊冲突观察AI驱动网络战形态变革](https://mp.weixin.qq.com/s/AgADRkedobYw9zSK0_jSww) - [ ] [威胁通缉令 · 红桃K丨Tomcat RCE漏洞(新增)](https://mp.weixin.qq.com/s/1RbtA-LfqXDATwfqKeCOaA) - [ ] [桌面软件暗藏后门?不懂代码也能看懂的黑客攻防](https://mp.weixin.qq.com/s/Q4mtvNRzeZ007xDD9aGGCA) - [ ] [暗网传上海某芯片企业遭“s1ic3r”入侵](https://mp.weixin.qq.com/s/pBlBwjzt7dd6v1ZoMytyRA) - [ ] [BlockSec 安全周报|九起攻击,从合约漏洞到治理失守(3.30–4.05)](https://mp.weixin.qq.com/s/jg7FxhBvWtr0XEDg2obQCg) - [ ] [构建动态感知与主动防御体系,打造智能制造全域可控安全新格局](https://mp.weixin.qq.com/s/6j9wsBqiBKN6lSvyQRgMKg) - [ ] [【安全研究】银狐远控远程屏幕使用场景和优化建议](https://mp.weixin.qq.com/s/eZaOYvjxsM0KQfq1WBoKMQ) - [ ] [计算机的进化](https://mp.weixin.qq.com/s/k1CkLAi2Hry7YxWM9kuCFg) - [ ] [《2025年度中小企业发展环境评估报告》发布](https://mp.weixin.qq.com/s/jRquoUajl66LNmw4BXillw) - [ ] [xa0中本聪真身曝光!已死](https://mp.weixin.qq.com/s/WvCGE7KR5mcwNfqubEe1CQ) - [ ] [特朗普.skill 上线了!](https://mp.weixin.qq.com/s/oh88sein-ax4W5nOAb4k2g) - [ ] [从内部打造并强化安全防线,领取CISSP会员推荐专属福利](https://mp.weixin.qq.com/s/rKRVhPh3BytupZT3UBz2Pg) - [ ] [技术教科书:顶级开发团队设计的Harness工程项目源码什么样](https://mp.weixin.qq.com/s/MKWckXraK1irNvMgCIJXZw) - [ ] [给你的“龙虾”穿上铠甲!飞天诚信OpenClaw身份认证解决方案](https://mp.weixin.qq.com/s/6mMYXil3T9F7J3r1a1ZyDw) - [ ] [【论文速读】|RuleForge:面向大规模 Web 漏洞检测的规则自动生成与验证](https://mp.weixin.qq.com/s/uky7CJGa8fFQy_G3y8pELA) - [ ] [好好吃饭 打好基础之初遇wsdl](https://mp.weixin.qq.com/s/80LZSVA1G-7ISl-mEirn8w) - [ ] [【免费领】超700页!CISSP官方权威学习指导手册(中文版)](https://mp.weixin.qq.com/s/jOdkjFN_zlcfipCSCmgR6g) - [ ] [万山磅礴看主峰|习近平论网络内容建设](https://mp.weixin.qq.com/s/Cc2R7rnL64OvIfeLEL3jRQ) - [ ] [俄军成立无人装备部队促进新质战斗力生成](https://mp.weixin.qq.com/s/bDs7SIec2xyFp-n5I4exOA) - [ ] [美国农业部启动“农业科技验证网络”,推动AI等技术落地应用](https://mp.weixin.qq.com/s/1fM1i7MO3t4SdvbGjw8eXw) - Tenable Blog - [ ] [What to Know About CyberAv3ngers: The IRGC-Linked Group Targeting Critical Infrastructure](https://www.tenable.com/blog/what-to-know-about-cyberav3ngers-the-irgc-linked-group-targeting-critical-infrastructure) - CXSECURITY Database RSS Feed - CXSecurity.com - [ ] [Docker Desktop 4.44.3 Unauthenticated API Exposure](https://cxsecurity.com/issue/WLB-2026040008) - [ ] [MaNGOSWebV4 4.0.6 Reflected XSS](https://cxsecurity.com/issue/WLB-2026040007) - [ ] [Grafana 11.6.0 SSRF](https://cxsecurity.com/issue/WLB-2026040006) - [ ] [OctoPrint 1.11.2 File Upload](https://cxsecurity.com/issue/WLB-2026040005) - [ ] [esm-dev 136 Path Traversal](https://cxsecurity.com/issue/WLB-2026040004) - Microsoft Security Blog - [ ] [The agentic SOC—Rethinking SecOps for the next decade](https://www.microsoft.com/en-us/security/blog/2026/04/09/the-agentic-soc-rethinking-secops-for-the-next-decade/) - [ ] [Investigating Storm-2755: “Payroll pirate” attacks targeting Canadian employees](https://www.microsoft.com/en-us/security/blog/2026/04/09/investigating-storm-2755-payroll-pirate-attacks-targeting-canadian-employees/) - [ ] [Intent redirection vulnerability in third-party SDK exposed millions of Android wallets to potential risk](https://www.microsoft.com/en-us/security/blog/2026/04/09/intent-redirection-vulnerability-third-party-sdk-android/) - paper - Last paper - [ ] [SkillTrojan:针对基于技能的智能体系统的后门攻击](https://paper.seebug.org/3477/) - 嘶吼 RoarTalk – 网络安全行业综合服务平台,4hou.com - [ ] [新型CrystalRAT恶意软件新增远程控制、数据窃取等功能](https://www.4hou.com/posts/LGMD) - [ ] [嘶吼安全动态|中央网信办召开全国网络法治工作会议 设备码钓鱼攻击暴增36倍,新型攻击工具在网上大肆扩散](https://www.4hou.com/posts/6MLO) - ongoing by Tim Bray - [ ] [Password Manager Angst](https://www.tbray.org/ongoing/When/202x/2026/04/09/Password-Manager-Angst) - Recent Commits to cve:main - [ ] [Update Thu Apr 9 11:20:06 UTC 2026](https://github.com/trickest/cve/commit/603904ef7dcd1d8e17ad3f48da92c4b8c0e1b6fe) - Google Online Security Blog - [ ] [Protecting Cookies with Device Bound Session Credentials](http://security.googleblog.com/2026/04/protecting-cookies-with-device-bound.html) - Sandfly Security Blog RSS Feed - [ ] [Agentless Linux EDR for Government and Critical Infrastructure](https://sandflysecurity.com/blog/webinar-5-linux-security-blind-spots-putting-government-agencies-at-risk) - Bug Bounty in InfoSec Write-ups on Medium - [ ] [So… You Thought Your VPN Was Keeping You Safe and Secure? Think Again (Hacker’s Edition)](https://infosecwriteups.com/so-you-thought-your-vpn-was-keeping-you-safe-and-secure-think-again-hackers-edition-375e88188221?source=rss----7b722bfd1b8d--bug_bounty) - [ ] [CI/CD Takeover & Supply Chain Risk! $$$$ Bounty](https://infosecwriteups.com/linktrees-entire-mobile-infrastructure-exposed-hardcoded-secrets-in-strings-xml-bb881b0a86d7?source=rss----7b722bfd1b8d--bug_bounty) - Securelist - [ ] [The long road to your crypto: ClipBanker and its marathon infection chain](https://securelist.com/clipbanker-malware-distributed-via-trojanized-proxifier/119341/) - SentinelOne - [ ] [Edge Decay: How a Failing Perimeter Is Fueling Modern Intrusions](https://www.sentinelone.com/blog/edge-decay-how-a-failing-perimeter-is-fueling-modern-intrusions/) - VMRay - [ ] [Release Highlights: VMRay Platform 2026.2.0](https://www.vmray.com/release-highlights-vmray-platform-2026-2-multi-stage-malware-analysis/) - The Trail of Bits Blog - [ ] [Master C and C++ with our new Testing Handbook chapter](https://blog.trailofbits.com/2026/04/09/master-c-and-c-with-our-new-testing-handbook-chapter/) - Exploit-DB.com RSS Feed - [ ] [[webapps] React Server 19.2.0 - Remote Code Execution](https://www.exploit-db.com/exploits/52506) - [ ] [[webapps] RomM 4.4.0 - XSS_CSRF Chain](https://www.exploit-db.com/exploits/52505) - [ ] [[webapps] Jumbo Website Manager - Remote Code Execution](https://www.exploit-db.com/exploits/52504) - [ ] [[local] ZSH 5.9 - RCE](https://www.exploit-db.com/exploits/52503) - Malwarebytes - [ ] [Scammers pose as Amazon support to steal your account](https://www.malwarebytes.com/blog/news/2026/04/scammers-pose-as-amazon-support-to-steal-your-account) - [ ] [NSFW app leak exposes 70,000 prompts linked to individual users](https://www.malwarebytes.com/blog/news/2026/04/nsfw-app-leak-exposes-70000-prompts-linked-to-individual-users) - [ ] [30,000 private Facebook images allegedly downloaded by Meta employee](https://www.malwarebytes.com/blog/data-breaches/2026/04/30000-private-facebook-images-allegedly-downloaded-by-meta-employee) - [ ] [This fake Windows support website delivers password-stealing malware](https://www.malwarebytes.com/blog/scams/2026/04/this-fake-windows-support-website-delivers-password-stealing-malware) - bishopfox.com - [ ] [Inside Cirro: Attack Paths, Cloud Graphs, and Extensible Schemas](https://bishopfox.com/blog/inside-cirro-attack-paths-cloud-graphs-and-extensible-schemas) - HackerNews - [ ] [洛杉矶市律师系统遭入侵,敏感警局文件泄露](https://hackernews.cc/archives/64067) - [ ] [Apache ActiveMQ Classic 潜伏 13 年的 RCE 漏洞曝光](https://hackernews.cc/archives/64066) - [ ] [OpenSSL 修复数据泄露等七处漏洞](https://hackernews.cc/archives/64065) - [ ] [Masjesu 僵尸网络隐蔽攻击物联网设备,专注持久化而非大规模感染](https://hackernews.cc/archives/64064) - [ ] [美国马萨诸塞州医院遭网络攻击,被迫分流救护车](https://hackernews.cc/archives/64063) - [ ] [Anthropic 推出 Claude Mythos 模型,发现数千零日漏洞](https://hackernews.cc/archives/64062) - 奇客Solidot–传递最新科技情报 - [ ] [NASA 宇航员的笔记本电脑运行 VLC](https://www.solidot.org/story?sid=84006) - [ ] [欧洲男性过去一万年摄入的肉量一直多于女性](https://www.solidot.org/story?sid=84005) - [ ] [英国科学家量化交通对城市温度的贡献](https://www.solidot.org/story?sid=84004) - [ ] [FBI 称 2025 年美国因网络犯罪损失 210 亿美元](https://www.solidot.org/story?sid=84003) - [ ] [LinkedIn 扫描浏览器扩展面临集体诉讼](https://www.solidot.org/story?sid=84002) - [ ] [免费领取价值30/90美金的NVIDIA DLI自学课程并测试获得证书](https://www.solidot.org/story?sid=84001) - [ ] [大电芯降本、AI算力“施压”,谁来替储能系统兜底这笔“物理账”?](https://www.solidot.org/story?sid=83999) - [ ] [两个超大质量黑洞可能在百年内合并](https://www.solidot.org/story?sid=83998) - [ ] [科学家捏造了一种病,AI 告诉人们这是真的](https://www.solidot.org/story?sid=83997) - [ ] [W玻色子质量测量结果与标准模型一致](https://www.solidot.org/story?sid=83996) - [ ] [微软考虑加固数据中心以抵御战火](https://www.solidot.org/story?sid=83995) - [ ] [微软终止 VeraCrypt 账户 Windows 版本更新暂停](https://www.solidot.org/story?sid=83994) - [ ] [纽时记者称 Adam Back 是中本聪](https://www.solidot.org/story?sid=83993) - 威努特安全网络 - [ ] [安全龙虾WinClaw:一句话搞定全网200+搜索引擎](https://mp.weixin.qq.com/s?__biz=MzAwNTgyODU3NQ==&mid=2651141270&idx=1&sn=f026162fd572f7ac6bb38693e07c48c3) - [ ] [WinClaw安全龙虾🦞|10000名用户Token永久免费!](https://mp.weixin.qq.com/s?__biz=MzAwNTgyODU3NQ==&mid=2651141270&idx=2&sn=97a684f202a9946291788a022608f953) - 黑鸟 - [ ] [30 秒接管苹果账号!中东记者被跨国网络间谍攻击,背后竟是这个APT组织](https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451186289&idx=1&sn=e186333deab9f0bd6426aba68cac7db1) - 奇安信 CERT - [ ] [【已复现】OpenPrinting CUPS 多个高危漏洞安全风险通告](https://mp.weixin.qq.com/s?__biz=MzU5NDgxODU1MQ==&mid=2247505186&idx=1&sn=751723948fc9f225730b57f1fb8b0fba) - [ ] [【已复现】OpenAM 远程代码执行漏洞(CVE-2026-33439)安全风险通告](https://mp.weixin.qq.com/s?__biz=MzU5NDgxODU1MQ==&mid=2247505186&idx=2&sn=72d008e6d01b20a4f5665f9ab8d2b570) - 青衣十三楼飞花堂 - [ ] [三角形的内角和等于180度吗](https://mp.weixin.qq.com/s?__biz=MzUzMjQyMDE3Ng==&mid=2247489288&idx=1&sn=568ff90c116626d3917c1182fa8d344d) - 代码卫士 - [ ] [已存在13年的Apache ActiveMQ 严重漏洞可用于远程执行命令](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247525686&idx=1&sn=51e7e391e06000c6fad494187241de39) - [ ] [CISA:须在周日前修复已遭利用的 Ivanti EPMM 漏洞](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247525686&idx=2&sn=a7cb71292f83e55b49f1e23a7f775864) - 安全内参 - [ ] [能源水务等关基工控设施遭破坏性网络攻击,美国政府紧急发布警报](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247515788&idx=1&sn=81d72b88950c341fe7c4b76824a88c77) - [ ] [打破传统边界:乌克兰战后网络防御转型对北约现代战争准备的三大启示](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247515788&idx=2&sn=b85199784bc00dd8df7154a798a1a840) - 绿盟科技研究通讯 - [ ] [无需认证即可执行:Langflow CVE-2026-33017 未授权远程代码执行漏洞深度剖析与靶标实战](https://mp.weixin.qq.com/s?__biz=MzIyODYzNTU2OA==&mid=2247499810&idx=1&sn=7375526e25605ffefa701ee5b2d5b474) - 微步在线研究响应中心 - [ ] [漏洞通告 | ActiveMQ远程代码执行漏洞](https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&mid=2247508577&idx=1&sn=9b54d7cab51cf308ac60ce38eaeeba12) - 腾讯安全应急响应中心 - [ ] [发现 33 个 OpenClaw 与 Linux 内核漏洞后,我们也从 Claude Mythos 看到了安全攻防的下半场](https://mp.weixin.qq.com/s?__biz=MjM5NzE1NjA0MQ==&mid=2651208316&idx=1&sn=159300723ea3cb7e287573f5c1cd9653) - 安全学术圈 - [ ] [大湾区大学 | 网络与信息安全研究中心招聘博士后](https://mp.weixin.qq.com/s?__biz=MzU5MTM5MTQ2MA==&mid=2247495227&idx=1&sn=7ed11119a9ed6fd7317820e0783910d6) - 网安杂谈 - [ ] [【资料】无糖信息《2026网络犯罪趋势研究报告》:人工智能加持下的网络犯罪生态对抗2.0时代](https://mp.weixin.qq.com/s?__biz=MzAwMTMzMDUwNg==&mid=2650890285&idx=1&sn=b8461bb441c598bd7338713cc5f977cc) - 安全圈 - [ ] [【安全圈】盗用他人信息注册账号卖给未成年人,上海警方捣毁一“游戏账号工厂”黑产链](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652075478&idx=1&sn=c93535d7b2a2b89b99903d6dc17e4432) - [ ] [【安全圈】AI 数据独角兽遭黑客攻击,一周内吃了 5 场官司,Meta 紧急暂停合作](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652075478&idx=2&sn=b3409e6f0339373e1243bfd5e9dda0dd) - [ ] [【安全圈】洛杉矶市律师系统遭入侵,敏感警局文件泄露](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652075478&idx=3&sn=1b33eb8b422566f8a907f30cc21e0c66) - 看雪学苑 - [ ] [天才程序员上线:AI 逆向与安全开发全栈实战](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458613203&idx=1&sn=af97f110f6cd3563072ee349bb998914) - [ ] [间接提示词注入和供应链投毒,正在威胁你的 AI Agent](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458613203&idx=2&sn=0c165669d97bf7e09c7e678481a87156) - [ ] [未完全修复旧漏洞!Docker Engine新漏洞可致容器逃逸与主机接管](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458613203&idx=3&sn=6eb93ad2f08d3e6ef4629b8c9e5e0660) - 威胁棱镜 - [ ] [思科如何基于 Llama 3.1 构建安全原生推理大模型](https://mp.weixin.qq.com/s?__biz=MzkyMzE5ODExNQ==&mid=2247488608&idx=1&sn=07289b545dc4a6145fed23123a955d9c) - 网络空间安全科学学报 - [ ] [学术前沿 | 基于ATT&CK框架的技术关联分析方法综述](https://mp.weixin.qq.com/s?__biz=MzI0NjU2NDMwNQ==&mid=2247507406&idx=1&sn=9f98acb6ee1a5bfe8b48140eb92f3a45) - 微步在线 - [ ] [攻击已持续5个月!黑客利用PDF让Adobe Reader执行恶意代码](https://mp.weixin.qq.com/s?__biz=MzI5NjA0NjI5MQ==&mid=2650186156&idx=1&sn=95bccdf47207d54411cc9fbb18b80c56) - 极客公园 - [ ] [放弃把算力硬塞进眼镜,这家公司用「便携空间主机」拿下千万美元融资](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653103673&idx=2&sn=76c72eb8f2199a03f5fb246f5df3b6eb) - [ ] [ropet 完成超千万美元融资:跨过 AI 宠物的「价格、销量、留存」不可能三角](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653102999&idx=1&sn=a48a5e75dc57fd377611595f9046a36a) - [ ] [DeepSeek 网页升级,上线「专家模式」;腾讯上线「浏览器龙虾」;传比特币之父「中本聪」真实身份曝光|极客早知道](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653102980&idx=1&sn=d06a2260dd06d949a28409a1f43e3def) - 字节跳动安全中心 - [ ] [抖音生活服务邀你来测!单个漏洞奖励10万元!](https://mp.weixin.qq.com/s?__biz=MzUzMzcyMDYzMw==&mid=2247496148&idx=1&sn=fb2fd4d520333d0575983a48395c5bc0) - 情报分析师 - [ ] [卫星图像免费获取平台汇总——情报人员案头必备的7个信源](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650567527&idx=1&sn=da60593ee8051b45edc6e6a6ac1a474c) - [ ] [美国科学家离奇失踪或死亡案例增至8起,我获前FBI局长公开点名,警惕美国对我系统性污名化风险](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650567527&idx=2&sn=b64dcea31deeaad2dbbbfd54e12a37a1) - [ ] [【热点研判】美财政部"通用许可证"明确将我排除在委内瑞拉矿产交易之外/菲对南海131个岛礁地物实施菲律宾命名/日法联合声明强调T海问题](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650567527&idx=3&sn=0d2b426000e41c072dd4fe209f8a672e) - 嘶吼专业版 - [ ] [新型CrystalRAT恶意软件新增远程控制、数据窃取等功能](https://mp.weixin.qq.com/s?__biz=MzI0MDY1MDU4MQ==&mid=2247587621&idx=1&sn=593a28a611f799cce58e63d2ae9a5ce9) - [ ] [嘶吼安全动态|中央网信办召开全国网络法治工作会议 设备码钓鱼攻击暴增36倍,新型攻击工具在网上大肆扩散](https://mp.weixin.qq.com/s?__biz=MzI0MDY1MDU4MQ==&mid=2247587621&idx=2&sn=aa4d3d047a0fae8f512b6f507c96e482) - 数世咨询 - [ ] [报告发布 | 暗网情报技术能力框架及参考指标体系](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247542493&idx=1&sn=8afea6968add3a5407a4ce05f9d516f3) - [ ] [永信至诚发布「定心」产品乘服务解决方案,让数据安全风险可控、可管、可闭环](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247542493&idx=2&sn=ecf55496f1f4f2795d82848110753622) - 枇杷熟了 - [ ] [别让低效率的 AI成为你技术进阶的精神枷锁](https://mp.weixin.qq.com/s?__biz=MzU0MzkzOTYzOQ==&mid=2247490013&idx=1&sn=4cdd6058ab1980154e90e06e0fef1b6d) - 美团技术团队 - [ ] [2025-2026 | 美团科研合作优秀课题获得者名单公布](https://mp.weixin.qq.com/s?__biz=MjM5NjQ5MTI5OA==&mid=2651782453&idx=1&sn=aabdfef9c2bc3cc7469378ab0b25e973) - [ ] [2026 美团 LongCat 大模型 | 北斗实习计划](https://mp.weixin.qq.com/s?__biz=MjM5NjQ5MTI5OA==&mid=2651782453&idx=2&sn=1eebb9cc1d047199061a2cec4a6eaf20) - [ ] [2026 美团科研合作课题 | 公开征集进行中](https://mp.weixin.qq.com/s?__biz=MjM5NjQ5MTI5OA==&mid=2651782453&idx=3&sn=7851037f25c5972076cdcb2e355005ac) - 国家互联网应急中心CNCERT - [ ] [网络安全信息与动态周报2026年第14期(3月30日-4月5日)](https://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw==&mid=2247501406&idx=1&sn=f2e30d65d7bacb2eae51bde67d6b1ed8) - 360数字安全 - [ ] [入选全国 TOP100 案例!360 企业级智能体为高校数智化提供可复制路径](https://mp.weixin.qq.com/s?__biz=MzA4MTg0MDQ4Nw==&mid=2247585654&idx=1&sn=07be610f146106bd039dcffacbabf8f4) - 迪哥讲事 - [ ] [一次400美元赏金的实战挖掘之旅](https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&mid=2247499297&idx=1&sn=5ac2f9062021e0433fed833277d1c2ec) - Desync InfoSec - [ ] [Rapid7一线实录:CVE-2025-59718 FortiGate 防火墙入侵事件深度剖析](https://mp.weixin.qq.com/s?__biz=MzkzMDE3ODc1Mw==&mid=2247489917&idx=1&sn=44598525c50ceac6773a8d3fa9a37421) - [ ] [KongTuke FileFix 攻击链:新型 PHP 版 Interlock RAT 深度剖析](https://mp.weixin.qq.com/s?__biz=MzkzMDE3ODc1Mw==&mid=2247489917&idx=2&sn=b56241db37d4cba39b4fcb6163d92e20) - Qualys Security Blog - [ ] [Scaling Modern AppSec: Moving from Static Profiles to AI-Powered Scan Optimization](https://blog.qualys.com/category/product-tech) - [ ] [12 Best Practices for Securing AWS Cloud in 2026](https://blog.qualys.com/category/product-tech) - Over Security - Cybersecurity news aggregator - [ ] [New ‘LucidRook’ malware used in targeted attacks on NGOs, universities](https://www.bleepingcomputer.com/news/security/new-lucidrook-malware-used-in-targeted-attacks-on-ngos-universities/) - [ ] [New VENOM phishing attacks steal senior executives' Microsoft logins](https://www.bleepingcomputer.com/news/security/new-venom-phishing-attacks-steal-senior-executives-microsoft-logins/) - [ ] [Brockton Hospital cyberattack: Anubis names victim publicly and launches countdown, new details emerge](https://www.suspectfile.com/brockton-hospital-cyberattack-anubis-names-victim-publicly-and-launches-countdown-new-details-emerge/) - [ ] [Tax Refund Fraud in 2026: How Threat Actors Exploit Identity, Verification, and Cash-Out Channels](https://flashpoint.io/blog/tax-refund-fraud-in-2026-how-threat-actors-exploit-identity-verification-and-cash-out-channels/) - [ ] [FCC proposes new rule to further crackdown on illegal robocalls](https://therecord.media/fcc-proposes-new-rule-robocall-crackdown) - [ ] [Healthcare IT solutions provider ChipSoft hit by ransomware attack](https://www.bleepingcomputer.com/news/security/healthcare-it-solutions-provider-chipsoft-hit-by-ransomware-attack/) - [ ] [Google Chrome adds infostealer protection against session cookie theft](https://www.bleepingcomputer.com/news/security/google-chrome-adds-infostealer-protection-against-session-cookie-theft/) - [ ] [The threat hunter’s gambit](https://blog.talosintelligence.com/the-threat-hunters-gambit/) - [ ] [Treasury Department announces crypto industry cyber threat sharing initiative](https://therecord.media/treasury-department-announces-crypto-info-sharing) - [ ] [Smart Slider updates hijacked to push malicious WordPress, Joomla versions](https://www.bleepingcomputer.com/news/security/smart-slider-updates-hijacked-to-push-malicious-wordpress-joomla-versions/) - [ ] [Cosa impariamo dal Paese UE più massacrato dalla disinformazione russa](https://www.cybersecurity360.it/cybersecurity-nazionale/cosa-impariamo-dal-paese-ue-piu-massacrato-dalla-disinformazione-russa/) - [ ] [L’hub cinese del supercomputing colpito da una massiccia violazione di dati: cosa sappiamo](https://www.cybersecurity360.it/news/cyber-attacco-supercomputing-cina-esfiltrazione-dati/) - [ ] [Russia accuses former Radio Free Europe journalist of aiding cyberattacks for Ukraine](https://therecord.media/russia-accuses-radio-free-europe-journalist-aiding-ukraine-cyberattack) - [ ] [Hundreds of Malicious Google Play-Hosted Apps Bypassed Android 13 Security With Ease](https://www.bitdefender.com/en-us/blog/labs/malicious-google-play-apps-bypassed-android-security) - [ ] [Active Subscription Scam Campaigns Flooding the Internet](https://www.bitdefender.com/en-us/blog/labs/active-subscription-scam-campaigns-flooding-the-internet) - [ ] [Weaponizing Facebook Ads: Inside the Multi-Stage Malware Campaign Exploiting Cryptocurrency Brands](https://www.bitdefender.com/en-us/blog/labs/weaponizing-facebook-ads-inside-the-multi-stage-malware-campaign-exploiting-cryptocurrency-brands) - [ ] [Vulnerabilities Identified in Dahua Hero C1 Smart Cameras](https://www.bitdefender.com/en-us/blog/labs/vulnerabilities-identified-in-dahua-hero-c1-smart-cameras) - [ ] [Malvertising Campaign on Meta Expands to Android, Pushing Advanced Crypto-Stealing Malware to Users Worldwide](https://www.bitdefender.com/en-us/blog/labs/malvertising-campaign-on-meta-expands-to-android-pushing-advanced-crypto-stealing-malware-to-users-worldwide) - [ ] [The Scam That Won’t Quit: Malicious “TradingView Premium” Ads Jump from Meta to Google and YouTube](https://www.bitdefender.com/en-us/blog/labs/the-scam-that-wont-quit-malicious-tradingview-premium-ads-jump-from-meta-to-google-and-youtube) - [ ] [Fake Battlefield 6 Pirated Versions and Game Trainers Used to Deploy Stealers and C2 Agents](https://www.bitdefender.com/en-us/blog/labs/fake-battlefield-6-pirated-games-trainers) - [ ] [CVE-2025-55182 Exploitation Hits the Smart Home](https://www.bitdefender.com/en-us/blog/labs/cve-2025-55182-exploitation-hits-the-smart-home) - [ ] [Fake Leonardo DiCaprio Movie Torrent Drops Agent Tesla Through Layered PowerShell Chain](https://www.bitdefender.com/en-us/blog/labs/fake-leonardo-dicaprio-movie-torrent-agent-tesla-powershell) - [ ] [Android Trojan Campaign Uses Hugging Face Hosting for RAT Payload Delivery](https://www.bitdefender.com/en-us/blog/labs/android-trojan-campaign-hugging-face-hosting-rat-payload) - [ ] [Helpful Skills or Hidden Payloads? Bitdefender Labs Dives Deep into the OpenClaw Malicious Skill Trap](https://www.bitdefender.com/en-us/blog/labs/helpful-skills-or-hidden-payloads-bitdefender-labs-dives-deep-into-the-openclaw-malicious-skill-trap) - [ ] [LummaStealer Is Getting a Second Life Alongside CastleLoader](https://www.bitdefender.com/en-us/blog/labs/lummastealer-second-life-castleloader) - [ ] [Global Scam Machines: Inside a Meta-Powered Investment Fraud Ecosystem Spanning 25 Countries](https://www.bitdefender.com/en-us/blog/labs/global-investment-scam-network-using-meta-ads) - [ ] [Windows and macOS Malware Spreads via Fake “Claude Code” Google Ads](https://www.bitdefender.com/en-us/blog/labs/fake-claude-code-google-ads-malware) - [ ] [Windsurf IDE Extension Drops Malware via Solana Blockchain](https://www.bitdefender.com/en-us/blog/labs/windsurf-extension-malware-solana) - [ ] [Data breach cloud in Europa: TeamPCP svela la fragilità strutturale della sicurezza multi-tenant](https://www.cybersecurity360.it/news/data-breach-cloud-in-europa-teampcp-svela-la-fragilita-strutturale-della-sicurezza-multi-tenant/) - [ ] [When attackers already have the keys, MFA is just another door to open](https://www.bleepingcomputer.com/news/security/when-attackers-already-have-the-keys-mfa-is-just-another-door-to-open/) - [ ] [L’attacco invisibile a Axios: quando la sicurezza fallisce nella supply chain del software](https://www.cybersecurity360.it/news/lattacco-invisibile-a-axios-quando-la-sicurezza-fallisce-nella-supply-chain-del-software/) - [ ] [Cryptocurrency ATM giant Bitcoin Depot reports $3.6 million stolen in cyberattack](https://therecord.media/crypto-atm-bitcoin-depot-reports-cyberattack) - [ ] [UNC6783 Turns BPO Providers into Cyberattack Gateways](https://thecyberexpress.com/unc6783-bpo-providers-as-cyberattack-gateways/) - [ ] [Webinar: From noise to signal - What threat actors are targeting next](https://www.bleepingcomputer.com/news/security/webinar-from-noise-to-signal-what-threat-actors-are-targeting-next/) - [ ] [Russian Hackers Exploit SOHO Routers for DNS Hijacking Campaign](https://thecyberexpress.com/soho-router-compromise-forest-blizzard/) - [ ] [How Phishing Is Targeting Germany’s Economy: Active Threats from Finance to Manufacturing](https://any.run/cybersecurity-blog/german-industries-attack-cases/) - [ ] [Eurail says December data breach impacts 300,000 individuals](https://www.bleepingcomputer.com/news/security/eurail-says-december-data-breach-impacts-300-000-individuals/) - [ ] [Cybercriminals target accountants to drain Russian firms’ bank accounts](https://therecord.media/cybercriminals-hack-russian-accountants-to-steal-millions) - [ ] [From the field to the report and back again: How incident responders can use the Year in Review](https://blog.talosintelligence.com/from-the-field-to-the-report-and-back-again-how-incident-responders-can-use-the-year-in-review/) - [ ] [The long road to your crypto: ClipBanker and its marathon infection chain](https://securelist.com/clipbanker-malware-distributed-via-trojanized-proxifier/119341/) - [ ] [Seven Signals Cyber Experts Agreed on at FIRST Paris 2026](https://www.group-ib.com/blog/seven-cyber-signals-first-paris-2026/) - [ ] [Hackers exploiting Acrobat Reader zero-day flaw since December](https://www.bleepingcomputer.com/news/security/hackers-exploiting-acrobat-reader-zero-day-flaw-since-december/) - [ ] [Signature Healthcare Cyberattack Causes Service Disruptions, Treatment Delays](https://thecyberexpress.com/signature-healthcare-cyberattack/) - [ ] [The Week in Vulnerabilities: OpenClaw, FreeBSD, F5 BIG-IP, and Critical ICS Bugs](https://cyble.com/blog/cyble-weekly-vulnerability-report-apr-08/) - [ ] [Are Risks Revealed in Actions or Activity? Understanding Behavioral Analytics in Cybersecurity](https://www.group-ib.com/blog/behavioral-analytics-cybersecurity/) - [ ] [Calcolo quantistico: caratteristiche, servizi cloud e applicazioni emergenti](https://www.cybersecurity360.it/cultura-cyber/calcolo-quantistico-caratteristiche-servizi-cloud-e-applicazioni-emergenti/) - [ ] [Hackers steal $3.6 million from crypto ATM giant Bitcoin Depot](https://www.bleepingcomputer.com/news/security/crypto-atm-giant-bitcoin-depot-says-hackers-stole-36-million-from-its-wallets/) - [ ] [Bitcoin Depot Discloses $3.6 Million Crypto Theft Following System Breach](https://thecyberexpress.com/bitcoin-depot-cyberattack/) - [ ] [Microsoft suspends dev accounts for high-profile open source projects](https://www.bleepingcomputer.com/news/microsoft/microsoft-suspends-dev-accounts-for-high-profile-open-source-projects/) - TrustedSec - [ ] [IAM the Captain Now – Hijacking Azure Identity Access](https://trustedsec.com/blog/iam-the-captain-now-hijacking-azure-identity-access) - 安全行者老霍 - [ ] [你的 AI 智能体正在传输敏感数据。你知道流向何处吗?](https://mp.weixin.qq.com/s?__biz=Mzg3NjU4MDI4NQ==&mid=2247486397&idx=1&sn=27dddcd66713b090bf4065d6c97d4018) - 字节跳动技术团队 - [ ] [扣子2.5,开启全新 Agent World!](https://mp.weixin.qq.com/s?__biz=MzI1MzYzMjE0MQ==&mid=2247519214&idx=1&sn=6098fd7a3aa2f47bd2c0b6687bd28084) - Arturo Di Corinto - [ ] [Fnsi, il 16 aprile sciopero per il contratto. E domani in piazza a Roma per l’equo compenso](https://dicorinto.it/associazionismo/fnsi-il-16-aprile-sciopero-per-il-contratto-e-domani-in-piazza-a-roma-per-lequo-compenso/) - ICT Security Magazine - [ ] [Iran nel cyberspazio: operazioni ibride tra Medio Oriente, infrastrutture OT e Cloud Microsoft 365](https://www.ictsecuritymagazine.com/notizie/iran-cyberspazio-war/) - [ ] [Supply Chain Attack nordcoreano, Contagious Interview prende di mira gli sviluppatori: 1.700 pacchetti malevoli in cinque ecosistemi open source](https://www.ictsecuritymagazine.com/notizie/supply-chain-attack-nordcorea/) - [ ] [APT28 e la campagna FrostArmada: come il GRU russo ruba credenziali Microsoft senza installare malware](https://www.ictsecuritymagazine.com/notizie/apt28-frostarmada-microsoft/) - [ ] [Ransomware senza cifratura: come il data extortion sta sostituendo l’attacco classico](https://www.ictsecuritymagazine.com/notizie/ransomware-senza-cifratura/) - SANS Internet Storm Center, InfoCON: green - [ ] [ISC Stormcast For Thursday, April 9th, 2026 https://isc.sans.edu/podcastdetail/9886, (Thu, Apr 9th)](https://isc.sans.edu/diary/rss/32882) - [ ] [Number Usage in Passwords: Take Two, (Thu, Apr 9th)](https://isc.sans.edu/diary/rss/32866) - bellingcat - [ ] [‘Snoopy’, ‘Adolf’ and ‘Password’: The Hungarian Government Passwords Exposed Online](https://www.bellingcat.com/news/2026/04/09/the-hungarian-government-passwords-exposed-online/) - Future of Tech and Security: Strategy & Innovation with Raffy - [ ] [AI SOC and SIEM Are Being Repriced](https://raffy.ch/blog/2026/04/09/ai-soc-and-siem-are-being-repriced/) - Rasta Mouse - [ ] [Crystal Mask](https://rastamouse.me/crystal-mask/) - Lenny Zeltser - [ ] [When Executives Reject Your Security Recommendation](https://zeltser.com/rejected-security-recommendations) - Schneier on Security - [ ] [On Microsoft’s Lousy Cloud Security](https://www.schneier.com/blog/archives/2026/04/on-microsofts-lousy-cloud-security.html) - Krypt3ia - [ ] [Threat Analysis Report: AI Enhanced Infrastructure Attacks At Scale on Critical Infrastructure](https://krypt3ia.wordpress.com/2026/04/09/threat-analysis-report-ai-enhanced-infrastructure-attacks-at-scale-on-critical-infrastructure/) - The Hacker News - [ ] [EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallets](https://thehackernews.com/2026/04/engagelab-sdk-flaw-exposed-50m-android.html) - [ ] [UAT-10362 Targets Taiwanese NGOs with LucidRook Malware in Spear-Phishing Campaigns](https://thehackernews.com/2026/04/uat-10362-targets-taiwanese-ngos-with.html) - [ ] [ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories](https://thehackernews.com/2026/04/threatsday-bulletin-hybrid-p2p-botnet.html) - [ ] [The Hidden Security Risks of Shadow AI in Enterprises](https://thehackernews.com/2026/04/the-hidden-security-risks-of-shadow-ai.html) - [ ] [Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025](https://thehackernews.com/2026/04/adobe-reader-zero-day-exploited-via.html) - [ ] [Bitter-Linked Hack-for-Hire Campaign Targets Journalists Across MENA Region](https://thehackernews.com/2026/04/bitter-linked-hack-for-hire-campaign.html) - TorrentFreak - [ ] [Kocowa Secures Win Against Dramacool Pirates, U.S. Court Grants Domain Takeovers](https://torrentfreak.com/kocowa-secures-win-against-dramacool-pirates-u-s-court-grants-domain-takeovers/) - 360威胁情报中心 - [ ] [APT-C-49(OilRig)以伊朗最新社会热点事件为诱饵的多阶段钓鱼攻击活动分析](https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247508255&idx=1&sn=b3b6cc3d274945427e44605621251b68) - The Register - Security - [ ] [Crypto? Huh. Good gawd y'all, what is it good for? $45M in this case](https://go.theregister.com/feed/www.theregister.com/2026/04/09/crypto_fraud_scam_45_million/) - [ ] ['Several dozen' high-value corporations hit by new extortion crew in helpdesk phishing spree](https://go.theregister.com/feed/www.theregister.com/2026/04/09/several_dozen_highvalue_corporations_targeted/) - [ ] [Chevin pulls the handbrake on FleetWave software after security scare](https://go.theregister.com/feed/www.theregister.com/2026/04/09/chevin_fleetwave_security_incident/) - [ ] [Months-old Adobe Reader zero-day uses PDFs to size up targets](https://go.theregister.com/feed/www.theregister.com/2026/04/09/monthsold_adobe_reader_zeroday_uses/) - [ ] [Microsoft locks out VeraCrypt and WireGuard devs, blames verification process](https://go.theregister.com/feed/www.theregister.com/2026/04/09/microsoft_dev_account_deactivations/) - [ ] [Security researchers tricked Apple Intelligence into cursing at users. It could have been a lot worse](https://go.theregister.com/feed/www.theregister.com/2026/04/09/security_researchers_tricked_apple_intelligence/) - [ ] [Zephyr Energy loses £700K in cyber hit that rerouted contractor payment](https://go.theregister.com/feed/www.theregister.com/2026/04/09/zephyr_energy_cyberattack/) - [ ] [Sticky-note security turned gym into hall of '80s horrors](https://go.theregister.com/feed/www.theregister.com/2026/04/09/pwned/) - [ ] [Cryptographers place $5,000 bet whether quantum will matter](https://go.theregister.com/feed/www.theregister.com/2026/04/09/cryptograhpers_quantum_bet/) - Security Affairs - [ ] [Eurail data breach impacted 308,777 people](https://securityaffairs.com/190570/data-breach/eurail-data-breach-impacted-308777-people.html) - [ ] [Malicious PDF reveals active Adobe Reader zero-day in the wild](https://securityaffairs.com/190558/hacking/malicious-pdf-reveals-active-adobe-reader-zero-day-in-the-wild.html) - [ ] [Masjesu botnet targets IoT devices while evading high-profile networks](https://securityaffairs.com/190548/malware/masjesu-botnet-targets-iot-devices-while-evading-high-profile-networks.html) - [ ] [The alleged breach of China’s National Supercomputing Center can have serious geopolitical consequences](https://securityaffairs.com/190536/hacking/the-alleged-breach-of-chinas-national-supercomputing-center-can-have-serious-geopolitical-consequences.html) - [ ] [Internet-Exposed ICS Devices Raise Alarm for Critical Sectors](https://securityaffairs.com/190525/ics-scada/internet-exposed-ics-devices-raise-alarm-for-critical-sectors.html) - Deeplinks - [ ] [Yikes, Encryption’s Y2K Moment is Coming Years Early](https://www.eff.org/deeplinks/2026/04/yikes-encryptions-y2k-moment-coming-years-early) - [ ] [Comparison Shopping Is Not a (Computer) Crime](https://www.eff.org/deeplinks/2026/04/comparison-shopping-not-computer-crime) - [ ] [EFF is Leaving X](https://www.eff.org/deeplinks/2026/04/eff-leaving-x) - DEFION Research Labs - [ ] [Ruckus Unleashed: Multiple vulnerabilities exploited](/en/research-labs/ruckus-unleashed-multiple-vulnerabilities-exploited) - [ ] [Pwn2Own Automotive 2024: Hacking the Autel MaxiCharger](/en/research-labs/pwn2own-automotive-2024-hacking-the-autel-maxicharger) - [ ] [Pwn2Own Automotive 2024: Hacking the JuiceBox 40](/en/research-labs/pwn2own-automotive-2024-hacking-the-juicebox-40) - [ ] [Pwn2Own Automotive 2024: Hacking the ChargePoint Home Flex (and their cloud...)](/en/research-labs/pwn2own-automotive-2024-hacking-the-chargepoint-home-flex-and-their-cloud) - [ ] [DoNex/DarkRace Ransomware Decryptor](/en/research-labs/donex-darkrace-ransomware-decryptor) - [ ] [CVE-2024-20693: Windows cached code signature manipulation](/en/research-labs/cve-2024-20693-windows-cached-code-signature-manipulation) - [ ] [Bringing process injection into view(s): exploiting all macOS apps using nib files](/en/research-labs/bringing-process-injection-into-view-s-exploiting-all-macos-apps-using-nib-files) - [ ] [Don’t Talk All at Once! Elevating Privileges on macOS by Audit Token Spoofing](/en/research-labs/don-t-talk-all-at-once-elevating-privileges-on-macos-by-audit-token-spoofing) - [ ] [Getting SYSTEM on Windows in style](/en/research-labs/getting-system-on-windows-in-style) - [ ] [Technical analysis of the Genesis Market](/en/research-labs/technical-analysis-of-the-genesis-market) - [ ] [Bad things come in large packages: .pkg signature verification bypass on macOS](/en/research-labs/bad-things-come-in-large-packages-pkg-signature-verification-bypass-on-macos) - [ ] [Pwn2Own Miami 2022: ICONICS GENESIS64 Arbitrary Code Execution](/en/research-labs/pwn2own-miami-2022-iconics-genesis64-arbitrary-code-execution) - [ ] [Pwn2Own Miami 2022: Unified Automation C++ Demo Server DoS](/en/research-labs/pwn2own-miami-2022-unified-automation-c-demo-server-dos) - [ ] [Pwn2Own Miami 2022: AVEVA Edge Arbitrary Code Execution](/en/research-labs/pwn2own-miami-2022-aveva-edge-arbitrary-code-execution) - [ ] [Process injection: breaking all macOS security layers with a single vulnerability](/en/research-labs/process-injection-breaking-all-macos-security-layers-with-a-single-vulnerability) - [ ] [Pwn2Own Miami 2022: Inductive Automation Ignition Remote Code Execution](/en/research-labs/pwn2own-miami-2022-inductive-automation-ignition-remote-code-execution) - [ ] [Pwn2Own Miami 2022: OPC UA .NET Standard Trusted Application Check Bypass](/en/research-labs/pwn2own-miami-2022-opc-ua-net-standard-trusted-application-check-bypass) - [ ] [CoronaCheck App TLS certificate vulnerabilities](/en/research-labs/coronacheck-app-tls-certificate-vulnerabilities) - [ ] [Sandbox escape + privilege escalation in StorePrivilegedTaskService](/en/research-labs/sandbox-escape-privilege-escalation-in-storeprivilegedtaskservice) - [ ] [Proctorio Chrome extension Universal Cross-Site Scripting](/en/research-labs/proctorio-chrome-extension-universal-cross-site-scripting) - [ ] [Zoom RCE from Pwn2Own 2021](/en/research-labs/zoom-rce-from-pwn2own-2021) - [ ] [iOS VPN support: 3 different bugs](/en/research-labs/ios-vpn-support-3-different-bugs) - [ ] [Sign in with Apple - authentication bypass](/en/research-labs/sign-in-with-apple-authentication-bypass) - [ ] [Jenkins - authentication bypass](/en/research-labs/jenkins-authentication-bypass) - [ ] [DNS rebinding for HTTPS](/en/research-labs/dns-rebinding-for-https) - [ ] [Spring Security - insufficient cryptographic randomness](/en/research-labs/spring-security-insufficient-cryptographic-randomness) - [ ] [XenServer - path traversal leading to authentication bypass](/en/research-labs/xenserver-path-traversal-leading-to-authentication-bypass) - [ ] [Volkswagen Auto Group MIB infotainment system - unauthenticated remote code execution as root](/en/research-labs/volkswagen-auto-group-mib-infotainment-system-unauthenticated-remote-code-execution-as-root) - [ ] [NAPALM - command execution on NAPLM controller from host](/en/research-labs/napalm-command-execution-on-naplm-controller-from-host) - [ ] [MySQL Connector/J - Unexpected deserialisation of Java objects](/en/research-labs/mysql-connector-j-unexpected-deserialisation-of-java-objects) - [ ] [Ansible - command execution on Ansible controller from host](/en/research-labs/ansible-command-execution-on-ansible-controller-from-host) - [ ] [Observium - unauthenticated remote code execution](/en/research-labs/observium-unauthenticated-remote-code-execution) - [ ] [cSRP/srpforjava - obtaining of hashed passwords](/en/research-labs/csrp-srpforjava-obtaining-of-hashed-passwords) - [ ] [StartEncrypt - obtaining valid SSL certificates for unauthorized domains](/en/research-labs/startencrypt-obtaining-valid-ssl-certificates-for-unauthorized-domains) - 吾爱破解论坛 - [ ] [心流鼠标手势 FlowMouse正式登陆 Edge扩展商店](https://mp.weixin.qq.com/s?__biz=MjM5Mjc3MDM2Mw==&mid=2651144244&idx=1&sn=7a466d35733e347c9a9de66ccc14827e) - 网安寻路人 - [ ] [人脸识别的双轨治理与通向智能技术的治理适配框架(学术专论)](https://mp.weixin.qq.com/s?__biz=MzIxODM0NDU4MQ==&mid=2247508320&idx=1&sn=d5ee88aa1a83a662162014e903107b41)
每日安全资讯(2026-04-10)