# 每日安全资讯(2026-05-22) - SecWiki News - [ ] [SecWiki News 2026-05-21 Review](http://www.sec-wiki.com/?2026-05-21) - Doonsec's feed - [ ] [TeamPCP:正在以 前所未有的规模污染开源代码的黑客组织](https://mp.weixin.qq.com/s/jkqt2bsBpZsWhOXIgYoW0A) - [ ] [你用的 AI 中转站,安全吗?研究揭 API 中转站「暗藏后门」](https://mp.weixin.qq.com/s/0HO6J_DYVI7u3tlW-l828g) - [ ] [分享图片](https://mp.weixin.qq.com/s/RTPy4_MarMr1qeh993e8mA) - [ ] [又一家网安公司上市!三年收入19亿,却亏了2个亿](https://mp.weixin.qq.com/s/hTnMzR6ilSu6vxTTvO4dAw) - [ ] [分享的图片、视频、链接](https://mp.weixin.qq.com/s/6B6-K4s4y2VP051B_q-aNQ) - [ ] [《影-2160:当相伴百年的AI搭档,在深渊尽头向你伸出成神的手……》](https://mp.weixin.qq.com/s/rfGsWrXYeRQz1fcleoE9hQ) - [ ] [Gitea存在敏感信息泄露漏洞(用户名枚举) 附POC](https://mp.weixin.qq.com/s/rdsK-2f8_bZiY2Kqcs2JUA) - [ ] [免杀门槛被打破!用这个方法小白也能轻松上手!](https://mp.weixin.qq.com/s/CNeagVbBdJ-bWRFKBoH7tA) - [ ] [2026年,用好AI就能让你告别古法渗透,为什么你还不再试一次?](https://mp.weixin.qq.com/s/_Pj6PL3Z_SzZ1iJAXHsOvA) - [ ] [适合网安人的速成古法加解密逆向教程](https://mp.weixin.qq.com/s/Dz2TwThYBpTac-VqMpNvUA) - [ ] [法治在线|辽宁沈阳“女孩被离异父母双双拒收”系为博取流量,拍摄虚假视频,号主已被行政处罚](https://mp.weixin.qq.com/s/UK6pz3hgdbyWhA_MBJSZKg) - [ ] [别让你的OpenClaw,只是个“高级摆件”](https://mp.weixin.qq.com/s/HnPMdPdEeEQ0yjs_i15Zew) - [ ] [完整的30天Kubernetes学习计划](https://mp.weixin.qq.com/s/_p2HIjzNraa01OhTPxzZOw) - [ ] [我用Claude Code写了个脚本,把一个月的活5个小时干完了](https://mp.weixin.qq.com/s/Si7H5WZNQEPWzDIpp_Rsmg) - [ ] [Re·3-1— 以分析单机游戏作弊者的眼光去了解软件中的“内存”](https://mp.weixin.qq.com/s/G00OAiIBXB2thYLkouxdNQ) - [ ] [owasp top10 2025版本](https://mp.weixin.qq.com/s/3vss1tvKd22tBpnfdLKVmQ) - [ ] [【重磅深度】2026威瑞森DBIR安全报告解析:漏洞利用首超凭证窃取,影子AI成为最大内部威胁!](https://mp.weixin.qq.com/s/HvTph9ylwEIFCFcVbgNxuw) - [ ] [2021年买了这台T480,配备了升级的1080p显示屏、16GB内存(还有一个空的16GB内存插槽)、i5-8250处理器和500GB存储空间,唯一需要更换的](https://mp.weixin.qq.com/s/bYaxNiuywNaZI3JH1NfDIA) - [ ] [基于firefox源码添加的无痕抓包器更新进度](https://mp.weixin.qq.com/s/0EBycopI15opkxJXBIVuVg) - [ ] [什么是云访问安全代理(CASB)?](https://mp.weixin.qq.com/s/IJ4Fj2CXRowIom-S0NdH_w) - [ ] [黑色五月连环劫:GitHub 被黑始末](https://mp.weixin.qq.com/s/IYg4fY2XbXb2sD_daE3cqQ) - [ ] [Hx0 数据卫士上线:浏览器里的敏感信息扫描与输入防泄漏工具](https://mp.weixin.qq.com/s/wb3MhH1rhBnyjkMcg875IA) - [ ] [AICryptoProxy:AI 驱动的 JS 逆向分析渗透测试自动化代理框架](https://mp.weixin.qq.com/s/l6YxR4KQkCS-_0BojVJWRA) - [ ] [郑州xa0vsxa0合肥 两个\"押注未来\"的城市 投资机会有什么不同?](https://mp.weixin.qq.com/s/N1LPNBHvF2-_-lNt6RLcLg) - [ ] [保守机密,慎之又慎](https://mp.weixin.qq.com/s/XFWxtzGoEfBd-QH96hshrQ) - [ ] [什么??还有人不会AI漏洞挖掘](https://mp.weixin.qq.com/s/e-6ptPnBm28L0jT4Ll7qAA) - [ ] [fscan免杀研究,过国内所有最新版杀软以及Defender](https://mp.weixin.qq.com/s/ImVANdkjqg6UQtlb7r0pUw) - [ ] [电子取证场景下K8S集群的重建与分析](https://mp.weixin.qq.com/s/8K_UczKclwjuvtX8Hm7HtQ) - [ ] [邮件钓鱼免杀完全指南(2026 实战版)六、企业级防御体系建设](https://mp.weixin.qq.com/s/Nwyz47QvBMHPfhZR1y7ojQ) - [ ] [静刃-一款好用的安服工具](https://mp.weixin.qq.com/s/L9KFjfdZDv7-QE9OCzA0Hw) - [ ] [中国民航大学第十二届信息安全技术竞赛](https://mp.weixin.qq.com/s/lB06AD_BRbO9jpCqThhZHw) - [ ] [关于针对我国用户的“银狐”系列木马病毒攻击活动的预警报告](https://mp.weixin.qq.com/s/lqeA9hD_1O_MDx-QwU6o_g) - [ ] [Nginx 最新0day](https://mp.weixin.qq.com/s/IFFeSo41KUSeOHRKk6n1MA) - [ ] [滴滴多篇论文入选 ICML2026,值得一读!](https://mp.weixin.qq.com/s/cBQnS-ThQgLLc12flLW8ug) - [ ] [气味会留下记忆](https://mp.weixin.qq.com/s/SIyUJ3JWcb4g3jM6FiOWqg) - [ ] [李乐成主持召开工业和信息化部就业促进工作领导小组2026年全体会议](https://mp.weixin.qq.com/s/_DKTeu3AB69s8L0dfSiS_g) - [ ] [一种对抗AI自动化攻击的低成本防御方案](https://mp.weixin.qq.com/s/BVtLjAo8Vxc8flnqXefHpg) - [ ] [Cisco 安全工作负载中的关键漏洞威胁企业 API 安全](https://mp.weixin.qq.com/s/ix43LSr6BnMQNN5pqX4OfQ) - [ ] [CobaltStrike流量分析实战](https://mp.weixin.qq.com/s/a8SqttZX18OsGC7eHKCzBw) - [ ] [BadIIS恶意软件劫持IIS服务器,将用户重定向到非法网站](https://mp.weixin.qq.com/s/HADgWzNC7UIRofmhfP6QPA) - [ ] [论坛·数据安全治理 | 我国人工智能数据安全风险及监管模式研究](https://mp.weixin.qq.com/s/B0oQzzTeYHGPvyHrwI-0BQ) - [ ] [专家解读|江明涛:筑牢人工智能伦理底线 护航产业负责任创新](https://mp.weixin.qq.com/s/dxYu5gwbDbaP2hqdeiN0og) - [ ] [通知 | 这31款APP及SDK被通报!](https://mp.weixin.qq.com/s/iA0ebHxKj7Jogo42Eup1xA) - [ ] [专家观点 | 筑牢可信可控的数字安全屏障](https://mp.weixin.qq.com/s/CCCq4DhzBdNBplhSDKYD9Q) - [ ] [关注 | 警惕盲盒卡牌“概率陷阱” 中消协发布“六一”涉儿童消费提示](https://mp.weixin.qq.com/s/M157x-rORxTfGEegdJRNKg) - [ ] [我的训练营被盗版了](https://mp.weixin.qq.com/s/bDLg-Yl3zDI8xBq-mDf1aw) - [ ] [奇安信蝉联国家信息安全漏洞库CNNVD最高等级技术支撑单位](https://mp.weixin.qq.com/s/CrdpvVzNKTNRj-1Y0r5RWA) - [ ] [齐向东:法治让民营经济立得住、走得稳、行得远](https://mp.weixin.qq.com/s/USN_rkmPtj_IZOvPO5724g) - [ ] [电子签章系统核心原理与工作流程](https://mp.weixin.qq.com/s/iK4XvJmbJhFo1LjEHEzrvw) - [ ] [晋商银行成立数智创新团队探索AI应用场景,保函审核平均时间已缩短至2小时](https://mp.weixin.qq.com/s/gNG36flOxRNM5-jAGoWhog) - [ ] [AI快讯:Anthropic或Q2首次盈利,OpenAI拟明天递交IPO招股书](https://mp.weixin.qq.com/s/8b_wv3eQ2sceMivTyEl5nA) - [ ] [0164.我是如何通过 XSS 和开放重定向发现账户盗用 (ATO) 的](https://mp.weixin.qq.com/s/D3FVRT6QtmaSVL9DZk8Bdg) - [ ] [AI Agent 如何重构游戏增长?AI+游戏分论坛现场揭晓!](https://mp.weixin.qq.com/s/tc1e_amRbhCoUplBb-eBfw) - [ ] [群发5.8亿条短信,金额180亿:多家电信服务商竟与短信公司合伙钓鱼](https://mp.weixin.qq.com/s/WrOg1fC0ySXYIZC7FWQ8-A) - [ ] [活动报名 | 2026“工赋砺网”AI安全专场培训](https://mp.weixin.qq.com/s/AVsn37gO6FpndV9Duhyy6A) - [ ] [AI换脸速度已达毫秒级,视频通话已达真假难辨地步](https://mp.weixin.qq.com/s/a-Stod6yAKXAzBKg1OAWcw) - [ ] [AI安全无小事,移动云联合启明星辰为大模型装上一把“安全锁”](https://mp.weixin.qq.com/s/jUaHMxybgw7UkORzMFhq3A) - [ ] [3 款工具打通两台电脑,从此告别「文件传输助手」!](https://mp.weixin.qq.com/s/IKIfFtu8KyD6OXjfxN98hA) - [ ] [70%复杂文档防护失效?AI语义识别——破解传统DLP漏报困局](https://mp.weixin.qq.com/s/QuE7nC5VJnHRhzvhQujccw) - [ ] [AI智能体安全评估(2):基座模型的安全合规与对抗评估](https://mp.weixin.qq.com/s/6veOL3PUWcY7iUWSGchM5Q) - [ ] [央视《真相来了》:这些涉及柳州地震的信息是谣言](https://mp.weixin.qq.com/s/G2O6c7lY41THmTqfoAFAsA) - [ ] [Next.js 服务器端请求伪造漏洞 | CVE-2026-44578复现&研究](https://mp.weixin.qq.com/s/s9hDc0HgZFDW_hxQSmUVSA) - [ ] [亚信全球化品牌AIStorm首秀香港 以AI原生方式重塑安全的确定性](https://mp.weixin.qq.com/s/KRYxg2Fc2cydbYiS_pJxSQ) - [ ] [GitHub 已被 TeamPCP 攻击](https://mp.weixin.qq.com/s/MKz7QC3GSpwbmBs9KkwMTA) - [ ] [以色列情报老兵的秘密副业:卖AI认知战即服务](https://mp.weixin.qq.com/s/GE_DnTDlffqCtcA6f_x1Ug) - [ ] [终端是AI安全唯一的\"战场\"](https://mp.weixin.qq.com/s/eYpgKvqOsePg-vthNUfWZw) - [ ] [【漏洞通告】Linux Kernel PinTheft 权限提升漏洞](https://mp.weixin.qq.com/s/yN0FKhITnBCTwZj0dbRsyA) - [ ] [网络安全信息与动态周报2026年第20期(5月11日-5月17日)](https://mp.weixin.qq.com/s/n-RN-brQi6IuqHUcsAr24A) - [ ] [TCP和UDP最形象的区别](https://mp.weixin.qq.com/s/6dSAXYcqP-Pun-tyxqgPZA) - [ ] [开发者工作站沦陷:史上最高调的IDE扩展供应链攻击深度解析](https://mp.weixin.qq.com/s/15I3VSQpY3ftkjCVcE2T0g) - [ ] [初中学历、早年辍学,凭什么能霸榜 SRC,靠挖漏洞开上 BBA?](https://mp.weixin.qq.com/s/nkDKEFApysP_kNEa90pW3g) - [ ] [美国人工智能数据中心发展与电网承载的核心挑战及治理路径](https://mp.weixin.qq.com/s/lA2SngL7GrFoUflR30mU2w) - [ ] [美国与东盟举行首次人工智能部长级会议,推进人工智能合作与供应链协同](https://mp.weixin.qq.com/s/sV6O8OpAW6ZmeaPFmWmaKA) - [ ] [让算力易治理,高效能!深信服AI算力网关正式上线](https://mp.weixin.qq.com/s/-fsIoNUdKHUH_Epf2T464g) - [ ] [赋能智能金融,筑牢合规屏障|海云安受邀出席成都数字金融供需对接活动并做专题分享](https://mp.weixin.qq.com/s/P6_2hXwxE_Y4YNeSqdPEEQ) - [ ] [AI 治理、数据泄露、深度伪造、物理安全全面爆发](https://mp.weixin.qq.com/s/GFgOJQiC7LAw225l7H6KKA) - [ ] [中国信通院牵头编制IEEE《产品数字护照技术发展报告(2026)》国际研究报告正式发布](https://mp.weixin.qq.com/s/u08Mz9h_pObwxdTxB3pAcw) - [ ] [WIHscan二次开发内部版本上线,支持自定义js敏感信息扫描规则](https://mp.weixin.qq.com/s/KRFBDsc0u-hDFgF5pNWwDg) - [ ] [AI赋能安全&&一句话进行js逆向&&配合mitmproxy进行简单测试](https://mp.weixin.qq.com/s/zPD_f5Equ8SeCdrsOLomYw) - [ ] [郑商所120家期货公司技术培训,长亭科技解析AI攻防新格局](https://mp.weixin.qq.com/s/YXvD1zj0kG0m-cYYg_8IMw) - [ ] [【重磅】五部门联发新规|医疗数据合规进入强监管时代!](https://mp.weixin.qq.com/s/1V7GKGGBt3WNvOWuy-XY0w) - [ ] [可信安全 | 可信软件物料清单(SBOM)评估通过名单&证书信息](https://mp.weixin.qq.com/s/ZnpPVyL_65Af2izrFLU2KA) - [ ] [预警报告丨针对我国用户的“银狐”系列木马病毒攻击活动](https://mp.weixin.qq.com/s/ewKKMEiwekkc_DJ6LRZ4AQ) - [ ] [违规收集个人信息、窗口乱跳转……这31款APP及SDK被通报](https://mp.weixin.qq.com/s/30ys5x6I50vcUVbeUOqHUw) - [ ] [7大类27项丨信安世纪入围嘶吼2026网络安全产业图谱](https://mp.weixin.qq.com/s/by7qMlD5OdZvjzGgSQL0TQ) - [ ] [黑客利用 CVE-2026-26980 攻陷 Ghost CMS,大量站点沦为 ClickFix 攻击帮凶](https://mp.weixin.qq.com/s/9lTmEDWuciP536ZOn_lSAA) - [ ] [别把安全变监控!“永不信任”的冷酷架构正在逼走优秀员工](https://mp.weixin.qq.com/s/8hc1KP9ipOxkGAoVQQBk2w) - [ ] [个人微信接入 CyberStrikeAI(扫码绑定)](https://mp.weixin.qq.com/s/ISmldITQvZ4ObIVQLvA8ag) - [ ] [安全天书课程|助力实战免杀钓鱼](https://mp.weixin.qq.com/s/LbjpbLGwSOZfRZMg_w4k9g) - [ ] [零信任→“零信任+”:是升级还是全新进化?](https://mp.weixin.qq.com/s/5ucW_8bEi-eEctHjFnMjNw) - [ ] [为什么数据安全工作举步维艰](https://mp.weixin.qq.com/s/onGMkipXNUS_Wed8E_a8hA) - [ ] [AxonCog智能实验室:寒武纪计划 正式启动](https://mp.weixin.qq.com/s/WlPLamKwTYMpzjMkAdvFog) - [ ] [【好靶场狂欢活动】1000个靶场目标达成](https://mp.weixin.qq.com/s/woOFMSDBnVyBM1RGrQpw9Q) - [ ] [首次揭秘:网络武器如何篡改核试验数据,破坏核武器研制](https://mp.weixin.qq.com/s/kTSvic8wOuQlxdR8Sl44cQ) - [ ] [Cloudflare大裁员20%:基于特征的网络安全时代终结,AI特工时代来临](https://mp.weixin.qq.com/s/YpeSjJW2En5tVDUCLyDI_A) - [ ] [三个 CVE 与 2026 年 5 月那条被无视的利用链](https://mp.weixin.qq.com/s/PBSxXmTFJUv6zCx4u9oC0g) - [ ] [重新审视\"两发\"内核 Shellcode 执行:从控制流劫持到绕过 CR Pinning](https://mp.weixin.qq.com/s/uKaqgVLb7BCB8EBGqModrw) - [ ] [虚假摆拍,哪些行为涉嫌违法,哪些可能构成犯罪?](https://mp.weixin.qq.com/s/IPNwwFbaUntruMEM9O2jmA) - [ ] [共拓水利市场 | 中泓智水与乾冠安全战略合作签约](https://mp.weixin.qq.com/s/D5TF3kfBgk8QQPDrBvPHSQ) - [ ] [网安协会成功协办2026年中国网络文明大会人工智能赋能网络文明建设论坛](https://mp.weixin.qq.com/s/V1Gv1ydSREWQ2tMMETFVjw) - [ ] [江南信安连续多年入选《2026网络安全产业图谱》,核心领域实力获权威认可](https://mp.weixin.qq.com/s/TLHTGRdmzf-WwyalelukCw) - [ ] [二十四节气:今日小满](https://mp.weixin.qq.com/s/xYF2-uXrz2ZolLe_S2y_ZQ) - [ ] [[前沿技术] EDR 绕过技术综述](https://mp.weixin.qq.com/s/eLwH7lZuPqiz_-Y751voWQ) - [ ] [[前沿技术] OAuth 2.0 授权码劫持](https://mp.weixin.qq.com/s/1EAxFUpvo4zAV6Vb2NqJCA) - [ ] [[前沿技术] 智能合约常见漏洞审计](https://mp.weixin.qq.com/s/UyawPASH1AlJZfqabG7Huw) - [ ] [凝心聚力启新程—— 物联网与信息安全团队2023级研究生毕业答辩圆满举行](https://mp.weixin.qq.com/s/LqInCtifSuoCVjRqz7rXTA) - [ ] [动态|工信部:2025年度工业和信息化质量提升与品牌建设典型案例拟入选名单](https://mp.weixin.qq.com/s/sPprrobYZwuCzVDZz9dKYA) - [ ] [AI时代的供应链安全:从CISA指南看企业风险管理的新边界](https://mp.weixin.qq.com/s/Bp8GQaFV-dTo1An0eFghFA) - [ ] [动态|发布《全国数据标准化技术委员会标准化研究项目清单》](https://mp.weixin.qq.com/s/ylTucmEEChLslEVkKG3Jlg) - [ ] [下一个网络安全难题:智能体验证](https://mp.weixin.qq.com/s/_iLr7ShB1wquoAOWN2Uu9Q) - [ ] [产业|山石网科2026媒体圆桌会顺利召开,锚定高质量发展新征程](https://mp.weixin.qq.com/s/KoOOFEKgoVKYjx1CVcQE-A) - [ ] [MCP安全-AI-Agent接入工具后的权限边界](https://mp.weixin.qq.com/s/-U0wrLDoU4tyn72OsSrLdA) - [ ] [思科:速修复满分 Secure Workload 未授权 API 访问漏洞](https://mp.weixin.qq.com/s/Jg4C4E4krDlg0bI1VTLMLA) - [ ] [GitHub 被黑或因员工安装 Nx Console 恶意扩展引发,更多详情待调查](https://mp.weixin.qq.com/s/Nyd964qJDIplLdY98vr8Kg) - [ ] [沙特加入F-35俱乐部:美国中东军售政策的重大转向与全球冲击](https://mp.weixin.qq.com/s/4ZtUDu9YmE-j-_aklMFWZw) - [ ] [【上新】美国海外主要军事基地与试验训练场全彩图册(增补第3册)](https://mp.weixin.qq.com/s/bjqbWTImTm27MRiqZZ1zaA) - [ ] [【推荐】知远全球军事基地设施全彩图册](https://mp.weixin.qq.com/s/pVFykJMtX6DHwK7DA0KU4w) - [ ] [知远防务论坛 | “印太地区美军燃料供应链韧性”兵棋推演邀请](https://mp.weixin.qq.com/s/GiMd4apGA72iK2pMjsyt8Q) - [ ] [我一开始选择了 Xfce 桌面环境,用的是 dist-kernel 桌面环境](https://mp.weixin.qq.com/s/BXohBWbXii6dWH93Vn2Xuw) - [ ] [AI 不是让漏洞变多,而是让漏洞更难藏](https://mp.weixin.qq.com/s/DJ41Rq86j3Lpyd62ddr1HA) - [ ] [硬核自研|HunTianDB 混天DB:Rust原生工业级时序安全数据库全技术拆解](https://mp.weixin.qq.com/s/cHq3B_fuZEr-EpuR0NdL-Q) - [ ] [疑似Coruna卷土重来:npm包art-template遭供应链攻击沦为iOS漏洞投送工具](https://mp.weixin.qq.com/s/qFXVV3_oZ51SPghQZ9hHVg) - [ ] [AI 攻击进入秒级,古法安全运营正在失效,我们该怎么办?](https://mp.weixin.qq.com/s/EaVDb8hH2dRoeu8l2-0MXA) - [ ] [双A领航・智优芯生|2026年白金合作伙伴走进山石网科](https://mp.weixin.qq.com/s/p1fRArY0Ho3KNUNDMKJUaQ) - [ ] [山石方案|教育行业-校园网边界安全案例](https://mp.weixin.qq.com/s/KcNTnTmySWv1jPsZjMiKxg) - [ ] [深度解析:YARA规模化应用——为何顶级威胁狩猎工具被低估,连续文件情报如何填补空白](https://mp.weixin.qq.com/s/4GiNfUB8ZIK2bFYa3HWGMg) - [ ] [疑似 Nginx 新 0day RCE,无补丁,无上下文](https://mp.weixin.qq.com/s/KREBr3NjeQ_OQZu_pyhQBw) - [ ] [PHP-文件操作类代码审计](https://mp.weixin.qq.com/s/6WJJ2qrgam-DHOxBEQd4cA) - [ ] [突发!SpaceX递交史上最大IPO:募资750亿、估值2万亿,马斯克要成全球首个万亿富翁](https://mp.weixin.qq.com/s/kZyB2_Ycpw7o4vZysNEgmQ) - [ ] [苹果iPhone 18 Pro手机壳曝光:相机又大了一圈,旧壳全废](https://mp.weixin.qq.com/s/3-4p0udAIXj5cR41VYRkYg) - [ ] [Java安全必学习类加载机制](https://mp.weixin.qq.com/s/YPZhj8Y_X653PUahJFK5rg) - [ ] [央视《真相来了》:网传在福建龙岩拍摄到“野生华南虎”系谣言xa0网警依法查处](https://mp.weixin.qq.com/s/WTY03G_KgIAApAbYPQtAIQ) - [ ] [北京软件和信息服务业协会第十一届第五次常务理事会暨理事开放日活动在天融信成功举办](https://mp.weixin.qq.com/s/urIlSas4A4-wvEjq6Xdp5g) - [ ] [当美国情报局把卫星分析外包给硅谷](https://mp.weixin.qq.com/s/7Z02p3fN-ZAiYyfS4LfVzg) - [ ] [【深度研判】金正恩\"南部边境堡垒化\"战略的深层逻辑与半岛安全态势评估](https://mp.weixin.qq.com/s/iWebsPX_r81hl3M1aBeWoA) - [ ] [Python语言的逆向分析](https://mp.weixin.qq.com/s/cVrtYE6h2DBmgnDFwMTlmw) - [ ] [无问AI网安模型接入方法详解](https://mp.weixin.qq.com/s/XmVh4uFKJ9YLtippo8N91w) - [ ] [陌陌白帽赏金赛正式开赛!](https://mp.weixin.qq.com/s/z4bTrhCtn5Cs_PCIKDT6RQ) - [ ] [广汽:汽车远程诊断的信息安全设计与研究](https://mp.weixin.qq.com/s/D5eRiE0GkNK9YQPOdmg87Q) - [ ] [上汽:基于T-BOX模块的汽车远程诊断系统的构建](https://mp.weixin.qq.com/s/VDpM5zXFCbqNvOkzkuPsyQ) - [ ] [智能汽车网络安全与信息安全基础培训课程 2026](https://mp.weixin.qq.com/s/aK4ABCYZ4SgQHHy0hZi23w) - [ ] [一封随意的邮件如何让我发现了别人的租户——未经授权的个人信息访问](https://mp.weixin.qq.com/s/PLfSZvJX8bAfg53WUhL1Ug) - [ ] [绕过网络边界:通过Webhook错误配置实现盲目SSRF到云实例入侵](https://mp.weixin.qq.com/s/DhGrEyrcnNeZucCWRSIvsg) - [ ] [小满](https://mp.weixin.qq.com/s/iyAZD5dttiPRqwvwzHYCtw) - [ ] [SRC每日漏洞复现学习系列(第6篇)信息泄露漏洞+ 漏洞报告模板](https://mp.weixin.qq.com/s/MD-uP0L73S0wGu6OvhgE9w) - [ ] [实战分享——从简单前端加解密对抗到高危任意文件读取](https://mp.weixin.qq.com/s/uoBx7gYM5BI2ZtEOuTzVPw) - [ ] [狼人杀式APT!伊朗APT Dust Specter新工具曝光:靠文档投毒、精准猎杀中东政企](https://mp.weixin.qq.com/s/C_jKOlRgov66KOx6mHaElw) - [ ] [[无境原创] Dawn Breaker 域靶机 官方wp发布](https://mp.weixin.qq.com/s/OZfUKQC0ueX_1qt-NvgQaA) - [ ] [Copilot PPT一键翻译,你找对地方了吗](https://mp.weixin.qq.com/s/2Au57qym-wr1aXZ-mcXkgQ) - [ ] [\"秦盾·黑客说\":2026 网络安全技术沙龙暨青年人才交流会【议题征集】](https://mp.weixin.qq.com/s/duwO-wZfk5FYOJQzYpFF_A) - [ ] [美国网络司令部新特遣部队将加快引入尖端人工智能工具](https://mp.weixin.qq.com/s/YeuXSVP4iodKORFMi0u_cg) - [ ] [什么是边缘计算?](https://mp.weixin.qq.com/s/tZ0kUaT30yzkG-us_OPJTw) - Recent Commits to cve:main - [ ] [Update Thu May 21 11:52:37 UTC 2026](https://github.com/trickest/cve/commit/e38cdc4e6d427a0453695a32a8af5a36f37c4d97) - Microsoft Security Blog - [ ] [What’s new in Microsoft Security: May 2026](https://www.microsoft.com/en-us/security/blog/2026/05/21/whats-new-in-microsoft-security-may-2026/) - Private Feed for M09Ic - [ ] [anthropics released v2.1.147 at anthropics/claude-code](https://github.com/anthropics/claude-code/releases/tag/v2.1.147) - [ ] [bolucat released 202605212201 at bolucat/Archive](https://github.com/bolucat/Archive/releases/tag/202605212201) - [ ] [kpcyrd starred d10n/mullvad-tui](https://github.com/d10n/mullvad-tui) - [ ] [github released v0.8.13 at github/spec-kit](https://github.com/github/spec-kit/releases/tag/v0.8.13) - [ ] [4ra1n forked 4ra1n/security-site from apache/security-site](https://github.com/4ra1n/security-site) - [ ] [Mr-xn forked Mr-xn/CPA-Helper from walkingddd/CPA-Helper](https://github.com/Mr-xn/CPA-Helper) - [ ] [strands-agents released v1.41.0 at strands-agents/sdk-python](https://github.com/strands-agents/sdk-python/releases/tag/v1.41.0) - [ ] [OpenAEV-Platform released 2.260521.0 at OpenAEV-Platform/openaev](https://github.com/OpenAEV-Platform/openaev/releases/tag/2.260521.0) - [ ] [mgeeky starred D7EAD/mkPIVM](https://github.com/D7EAD/mkPIVM) - [ ] [liamg contributed to infracost/go-proto](https://github.com/infracost/go-proto/pull/63) - [ ] [timwhitez starred Ed1s0nZ/CyberStrikeAI](https://github.com/Ed1s0nZ/CyberStrikeAI) - [ ] [CHYbeta starred Yeti-791/Tsec-Hackathon](https://github.com/Yeti-791/Tsec-Hackathon) - [ ] [spf13 starred addyosmani/agent-skills](https://github.com/addyosmani/agent-skills) - [ ] [gh0stkey starred velopack/velopack](https://github.com/velopack/velopack) - [ ] [Ridter starred D7EAD/mkPIVM](https://github.com/D7EAD/mkPIVM) - [ ] [LoRexxar contributed to LoRexxar/Kunlun-M](https://github.com/LoRexxar/Kunlun-M/pull/328) - [ ] [timwhitez forked timwhitez/codex-general from openai/codex](https://github.com/timwhitez/codex-general) - [ ] [PrefectHQ released 3.7.2.dev4 at PrefectHQ/prefect](https://github.com/PrefectHQ/prefect/releases/tag/3.7.2.dev4) - [ ] [LoRexxar starred 0xHJK/dumpall](https://github.com/0xHJK/dumpall) - [ ] [LoRexxar forked LoRexxar/Ljoern from joernio/joern](https://github.com/LoRexxar/Ljoern) - 安全客-有思想的安全新媒体 - [ ] [瑞数信息入选IDC《中国智能体威胁检测技术评估,2026》](https://www.anquanke.com/post/id/315562) - [ ] [GitHub 被黑,3800个内部仓库外泄:从一枚恶意VS Code扩展说起](https://www.anquanke.com/post/id/315560) - Hacking Articles - [ ] [Windows Privilege Escalation: Bypass UAC](https://www.hackingarticles.in/windows-privilege-escalation-bypass-uac/) - obaby 𝐢𝐧⃝ void - [ ] [520,521](https://zhongxiaojie.cn/2026/05/1287/) - Tenable Blog - [ ] [Mini Shai-Hulud: Frequently asked questions about the TeamPCP npm and PyPI supply chain campaign](https://www.tenable.com/blog/mini-shai-hulud-frequently-asked-questions) - [ ] [CVE-2026-9082: Highly Critical SQL Injection Vulnerability in Drupal Core (SA-CORE-2026-004)](https://www.tenable.com/blog/cve-2026-9082-highly-critical-sql-injection-vulnerability-in-drupal-core-sa-core-2026-004) - [ ] [Tenable One deepens third-party integrations with new Open Connector for unified risk visibility](https://www.tenable.com/blog/new-tenable-one-open-connector-extends-third-party-integrations-unified-risk-visibility) - Cerbero Blog - [ ] [CDEX Format Package](https://blog.cerbero.io/cdex-format-package/) - Insinuator.net - [ ] [Insights into Entra ID’s (Un)Conditional Access](https://insinuator.net/2026/05/insights-into-entra-ids-unconditional-access/) - GuidePoint Security - [ ] [Continuous Security Validation Best Practices: A Practical Guide for Security Teams](https://www.guidepointsecurity.com/blog/continuous-security-validation-best-practices-a-practical-guide-for-security-teams/) - Horizon3.ai - [ ] [CVE-2026-9082 | Drupal SQL Injection Vulnerability](https://horizon3.ai/attack-research/vulnerabilities/cve-2026-9082/) - [ ] [CVE-2026-23734 | XWiki Path Traversal Vulnerability](https://horizon3.ai/attack-research/vulnerabilities/cve-2026-23734/) - VMRay - [ ] [April 2026 Detection Highlights: 7 New VTIs, AutoUI Support for Fake CAPTCHA Campaigns, and 20+ New YARA Rules](https://www.vmray.com/april-2026-detection-highlights-7-new-vtis-autoui-support-for-fake-captcha-campaigns-and-20-new-yara-rules/) - Reverse Engineering - [ ] [CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox](https://www.reddit.com/r/ReverseEngineering/comments/1tjozw8/cve202640369_twelve_bytes_to_escape_the_browser/) - [ ] [I got so sick of Android taking forever to calculate folder sizes, I built a custom C++/Rust storage visualizer to bypass MTP](https://www.reddit.com/r/ReverseEngineering/comments/1tjr2qv/i_got_so_sick_of_android_taking_forever_to/) - [ ] [Post-Quantum Cryptographic Algorithm Examined in Developmental Ransomware](https://www.reddit.com/r/ReverseEngineering/comments/1tjss7d/postquantum_cryptographic_algorithm_examined_in/) - [ ] [I built 99 adversarial PE fixtures to stress‑test parsers — here’s what they reveal about malformed binaries](https://www.reddit.com/r/ReverseEngineering/comments/1tjgfof/i_built_99_adversarial_pe_fixtures_to_stresstest/) - Intigriti - [ ] [How Triage Assist is raising the bar in crowdsourced security](https://www.intigriti.com/blog/product-updates/how-triage-assist-is-raising-the-bar-in-crowdsourced-security) - Malwarebytes - [ ] [Microsoft Defender vulnerabilities are being exploited in the wild](https://www.malwarebytes.com/blog/bugs/2026/05/microsoft-defender-vulnerabilities-are-being-exploited-in-the-wild) - [ ] [TikTok, YouTube, and Roblox face scrutiny, but age gates won’t fix child safety](https://www.malwarebytes.com/blog/family-and-parenting/2026/05/tiktok-youtube-and-roblox-face-scrutiny-but-age-gates-wont-fix-child-safety) - [ ] [Catch spyware in the act with Windows Webcam Monitoring](https://www.malwarebytes.com/blog/product/2026/05/catch-spyware-in-the-act-with-windows-webcam-monitoring) - [ ] [Researchers left AI agents alone in a virtual town and watched it all unravel](https://www.malwarebytes.com/blog/ai/2026/05/researchers-left-ai-agents-alone-in-a-virtual-town-and-watched-it-all-unravel) - Exploit-DB.com RSS Feed - [ ] [[webapps] Cockpit 359 - RCE](https://www.exploit-db.com/exploits/52572) - [ ] [[webapps] BookStack 25.12.1 - Denial of Service](https://www.exploit-db.com/exploits/52571) - [ ] [[local] Lenovo LegionSpace 1.7.11.2 - 'DAService' Unquoted Service Path](https://www.exploit-db.com/exploits/52570) - [ ] [[webapps] solaredge - (CSRF-OOB-Injection)](https://www.exploit-db.com/exploits/52569) - [ ] [[webapps] FUXA 1.2.9 - RCE](https://www.exploit-db.com/exploits/52568) - 奇客Solidot–传递最新科技情报 - [ ] [Google 宣布在 AI 模式下加入更多广告](https://www.solidot.org/story?sid=84365) - [ ] [NASA 预计中国将在 2027 年执行载人绕月飞行任务](https://www.solidot.org/story?sid=84364) - [ ] [Vivaldi 8.0 释出](https://www.solidot.org/story?sid=84363) - [ ] [SpaceX 最大的收入来源是与 Anthropic 达成的数据中心交易](https://www.solidot.org/story?sid=84362) - [ ] [Google 的 AI 搜索容易被人为操纵](https://www.solidot.org/story?sid=84361) - [ ] [RTX 5090DV2 显卡列入封禁清单](https://www.solidot.org/story?sid=84360) - [ ] [Google 意外公开了未修复 Chromium 漏洞的利用代码](https://www.solidot.org/story?sid=84359) - [ ] [三星电子劳资谈判达成初步协议,罢工终止](https://www.solidot.org/story?sid=84358) - 半块西瓜皮 - [ ] [Linux ELF Shellcode 生成与 Fileless 实战](https://guage.cool/linux-shellcode.html) - 黑鸟 - [ ] [TeamPCP:正在以 前所未有的规模污染开源代码的黑客组织](https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451186770&idx=1&sn=8374614e0cc8b70d57cd07408d95c2ea) - rtl-sdr.com - [ ] [RPITX-UI: A Modernized, Easier to Use Fork of the RPITX Raspberry Pi Transmitter Software](https://www.rtl-sdr.com/rpitx-ui-a-modernized-easier-to-use-fork-of-the-rpitx-raspberry-pi-transmitter-software/) - [ ] [No-SDR: A New Open Source Multi-User WebSDR for RTL-SDR](https://www.rtl-sdr.com/no-sdr-a-new-open-source-multi-user-websdr-for-rtl-sdr/) - [ ] [sdrrat: An SDR receiver Terminal User Interface for RTL-SDR & HackRF](https://www.rtl-sdr.com/sdrrat-an-sdr-receiver-terminal-user-interface-for-rtl-sdr-hackrf/) - Shostack & Friends Blog - [ ] [PHANTOM-B goes to Black Hat](https://shostack.org/blog/blackhat-phantom-b/) - 绿盟科技研究通讯 - [ ] [AI靶场安全实战系列:从对话到指令劫持——输入与指令安全深度剖析](https://mp.weixin.qq.com/s?__biz=MzIyODYzNTU2OA==&mid=2247499927&idx=1&sn=405df79b3d7a6aefeb439a85961a4c3f) - 青山青吖 - [ ] [【复盘】我拿的第一只经典川量形态票 | 股是股非](https://mp.weixin.qq.com/s?__biz=MzI5NzAzMDg0NA==&mid=2650698716&idx=1&sn=ebf5e92cc5b42b6a545ba879fd0c0323) - 代码卫士 - [ ] [思科:速修复满分 Secure Workload 未授权 API 访问漏洞](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247526078&idx=1&sn=2b669f642fd4b13d42c79cc8a544e482) - [ ] [GitHub 被黑或因员工安装 Nx Console 恶意扩展引发,更多详情待调查](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247526078&idx=2&sn=23c01cd3ffaa8a2a7421ffb9fe242d2a) - 360漏洞云 - [ ] [360漏洞云携安全龙虾亮相HPW白帽世界大会](https://mp.weixin.qq.com/s?__biz=Mzg5MTc5Mzk2OA==&mid=2247505129&idx=1&sn=b886267049920b17ef845f225e9e6f37) - 看雪学苑 - [ ] [上海急缺的“人工智能训练师”到底是个什么职业?](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458615386&idx=1&sn=0e02f3e64820631685e0080a6ebdf9d3) - [ ] [第二届软件系统安全赛 robo_admin 题解](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458615386&idx=2&sn=cc5edcd65f3d277ba25629b95a5071f2) - [ ] [“银狐”木马新变种爆发!伪装人事文件定向攻击国内用户](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458615386&idx=3&sn=a0b34129d4be3e55433eaf7ab28456be) - 奇安信威胁情报中心 - [ ] [疑似Coruna卷土重来:npm包art-template遭供应链攻击沦为iOS漏洞投送工具](https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247518848&idx=1&sn=90b15138b9f9cc9e7698039e29fbcdce) - 安全内参 - [ ] [AI重塑网络攻击:漏洞利用成最流行手段,利用门槛被大幅拉低](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247515978&idx=1&sn=33f216e51504edd839dc8b5e44ae380b) - [ ] [美国网络司令部正系统打造支撑网络攻防作战的核心平台与能力体系](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247515978&idx=2&sn=20f5cdf462fc68419f125585de107ac7) - 奇安信 CERT - [ ] [【已复现】FreeBSD setcred(2) 栈缓冲区溢出漏洞(CVE-2026-45250)安全风险通告](https://mp.weixin.qq.com/s?__biz=MzU5NDgxODU1MQ==&mid=2247505952&idx=1&sn=c7636af71cd3a1470ad313b5274a038d) - 威努特安全网络 - [ ] [钢铁“智”造必看,这套闭环网络安全方案守护生产命脉](https://mp.weixin.qq.com/s?__biz=MzAwNTgyODU3NQ==&mid=2651141722&idx=1&sn=c358473cf6591215ca11ba18251d59ec) - 威胁棱镜 - [ ] [从文本到情报:自动化 STIX 实体与关系提取](https://mp.weixin.qq.com/s?__biz=MzkyMzE5ODExNQ==&mid=2247488643&idx=1&sn=da78529d1d8ca6dc996b70ca4cde722e) - 信息安全国家工程研究中心 - [ ] [筑牢AI伦理安全基石:《人工智能应用伦理安全指引1.0》正式发布](https://mp.weixin.qq.com/s?__biz=MzU5OTQ0NzY3Ng==&mid=2247503934&idx=1&sn=c1334e85fd5bf97af4965016ca54e85b) - 补天平台 - [ ] [补天端午活动第二弹|专属SRC来袭,5大厂商奖励翻倍!](https://mp.weixin.qq.com/s?__biz=MzI2NzY5MDI3NQ==&mid=2247510758&idx=1&sn=2414b2b2b4aa885daa532eec28ce9fd8) - [ ] [补天端午活动第一弹 | “粽”测有礼](https://mp.weixin.qq.com/s?__biz=MzI2NzY5MDI3NQ==&mid=2247510758&idx=2&sn=fd8c89ff3e7446c83dacbebe959e2382) - secret club - [ ] [Striga: Lifting x86 to LLVM IR with Python](https://secret.club/2026/05/21/striga.html) - 极客公园 - [ ] [七岁的剪映,长大成人](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653106962&idx=1&sn=6f7b10cd8acfa159538c9768ddb0327b) - [ ] [对话 Moka CEO 李国兴:AI 不是 SaaS 公司的绝命,是改命](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653106960&idx=1&sn=73829db2ad466753f4a4b860d50f4455) - [ ] [雷军:YU7 GT为时代精英设计,小贵;阿里曝光 AI 芯片真武 M890;英伟达 Q1 利润 583.21 亿美元,暴增 211%|极客早知道](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653106930&idx=1&sn=c08313a72cfff793c2ec646c72a42597) - 深信服千里目安全技术中心 - [ ] [【漏洞通告】Linux Kernel PinTheft 权限提升漏洞](https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&mid=2247525764&idx=1&sn=694c58e134be2843b714a5e85ae2c533) - [ ] [网络安全信息与动态周报2026年第20期(5月11日-5月17日)](https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&mid=2247525764&idx=2&sn=b3d6313afbccfae9df85ad80e8ddafc3) - Tide安全团队 - [ ] [某OA密码加密方式分析](https://mp.weixin.qq.com/s?__biz=Mzg2NTA4OTI5NA==&mid=2247522198&idx=1&sn=b546e2365ec709b17c00092c894a277a) - 数世咨询 - [ ] [AI时代的供应链安全:从CISA指南看企业风险管理的新边界](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247542930&idx=1&sn=3783342f30f0d4caa3075647408f9052) - [ ] [下一个网络安全难题:智能体验证](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247542930&idx=2&sn=ab63263a4a8c764e234544176de0e329) - Beacon Tower Lab - [ ] [漏洞预警 | Linux内核RDS零拷贝与io_uring组合本地提权漏洞(PinTheft)](https://mp.weixin.qq.com/s?__biz=MzkyNzcxNTczNA==&mid=2247488075&idx=1&sn=ac894fe8c8f2cb13199b50fa048474fa) - 火绒安全 - [ ] [小满 | 小满已至 谨护网安](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247533497&idx=1&sn=0f882f106027ade68cc481394b79200f) - [ ] [诚邀渠道合作伙伴共启新征程](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247533497&idx=2&sn=68f39775636c2cd429568ff5fb547b60) - 安全圈 - [ ] [【安全圈】间谍利用路由器窃密!快自查你的设备是否安全](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652076710&idx=1&sn=8486b45483e17417ac95a396764113cb) - [ ] [【安全圈】黑客团伙公开叫卖GitHub核心代码,3800个内部仓库遭窃取,事件细节曝光!](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652076710&idx=2&sn=61f1c86aba0ca609e6ed58d71c15f47c) - [ ] [【安全圈】美组织要求 FTC 对 Roblox 展开调查:是否强迫未成年人过度充钱](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652076710&idx=3&sn=781e1ea679e99b5bbb21f65b1598510c) - 国家互联网应急中心CNCERT - [ ] [网络安全信息与动态周报2026年第20期(5月11日-5月17日)](https://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw==&mid=2247501625&idx=1&sn=f80436b90c6578762c1f619183d8a444) - OnionSec - [ ] [气味会留下记忆](https://mp.weixin.qq.com/s?__biz=MzUyMTUwMzI3Ng==&mid=2247485775&idx=1&sn=95c76e2bb182f769f052a8a76fd78a92) - 迪哥讲事 - [ ] [dom-xss绕过](https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&mid=2247499467&idx=1&sn=a3d2e0f15c991fa06a5d2e71a8a7b8f9) - 安全牛 - [ ] [Cloudflare大裁员20%:基于特征的网络安全时代终结,AI特工时代来临](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651141420&idx=1&sn=ea4f1b0b6063e2d3acf4e116ff581a2f) - [ ] [国家计算机病毒应急处理中心提醒“银狐木马借裁员违纪话题钓鱼,远程窃密风险高” ;微软发布两款 AI 红队工具,强化智能体安全测试|牛览](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651141420&idx=2&sn=2ad30b10c60ac6c18d232901c87c8cee) - 青藤智库 - [ ] [终端是AI安全唯一的"战场"](https://mp.weixin.qq.com/s?__biz=MzUyOTkwNTQ5Mg==&mid=2247489475&idx=1&sn=c79b973b110b5893e3a0444389fc52b5) - 情报分析师 - [ ] [当美国情报局把卫星分析外包给硅谷](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650567937&idx=1&sn=bdc1baadce500f10e928c695aa3ff3b0) - [ ] [【深度研判】金正恩"南部边境堡垒化"战略的深层逻辑与半岛安全态势评估](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650567937&idx=2&sn=921862f45050be424ce25f05dcde3d0a) - TrustedSec - [ ] [Shai-Hulud Is Back, and This Time It Ate the Whole Ecosystem](https://trustedsec.com/blog/shai-hulud-is-back) - Over Security - [ ] [Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada](https://krebsonsecurity.com/2026/05/alleged-kimwolf-botmaster-dort-arrested-charged-in-u-s-and-canada/) - [ ] [Law enforcement shuts down VPN service used by two dozen ransomware gangs](https://techcrunch.com/2026/05/21/law-enforcement-shuts-down-vpn-service-used-by-two-dozen-ransomware-gangs/) - [ ] [Tech giants promise British regulator they will tweak platforms to protect kids online](https://therecord.media/tech-giants-promise-ofcom-regulator-changes-child-access) - [ ] [Two Americans plead guilty to assisting India-based tech support scam centers](https://therecord.media/two-americans-plead-guilty-india-call-center-scams) - [ ] [Google accidentally exposed details of unfixed Chromium flaw](https://www.bleepingcomputer.com/news/security/google-accidentally-exposed-details-of-unfixed-chromium-flaw/) - [ ] [The art of being ungovernable](https://blog.talosintelligence.com/the-art-of-being-ungovernable/) - [ ] [Apple blocked over $11 billion in App Store fraud in 6 years](https://www.bleepingcomputer.com/news/apple/apple-blocked-22-billion-in-fraudulent-app-store-transactions-in-2025/) - [ ] [UK plans for cybercrime law reform would protect almost no one, experts warn](https://therecord.media/uk-plans-for-cybercrime-law-reform-limited-protections) - [ ] [AI agentiche nella cyber e nell’area della cognizione umana: vediamo se siamo preparati](https://www.cybersecurity360.it/news/ai-agentiche-nella-cyber-e-nellarea-della-cognizione-umana-vediamo-se-siamo-preparati/) - [ ] [JOMANGY: INJ3CTOR3’s Self-Healing FreePBX Toll Fraud Campaign](https://cyble.com/blog/jomangy-inj3ctor3s-self-healing-freepbx-toll-fraud-campaign/) - [ ] [Max severity Cisco Secure Workload flaw gives Site Admin privileges](https://www.bleepingcomputer.com/news/security/cisco-max-severity-secure-workload-flaw-gives-hackers-site-admin-privileges/) - [ ] [Chinese hackers target telcos with new Linux, Windows malware](https://www.bleepingcomputer.com/news/security/chinese-hackers-target-telcos-with-new-linux-windows-malware/) - [ ] [Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet](https://www.bleepingcomputer.com/news/security/inside-a-crypto-drainer-how-to-spot-it-before-it-empties-your-wallet/) - [ ] [Europe dismantles VPN service used by cybercriminals to hide ransomware attacks](https://therecord.media/europe-dismantles-first-vpn) - [ ] [Police seize “First VPN” service used in ransomware, data theft attacks](https://www.bleepingcomputer.com/news/security/police-seize-first-vpn-service-used-in-ransomware-data-theft-attacks/) - [ ] [VPN su Fire TV Stick: guida alla scelta tra sicurezza, velocità e consumo CPU](https://www.cybersecurity360.it/cultura-cyber/vpn-su-fire-tv-stick-guida-alla-scelta-tra-sicurezza-velocita-e-consumo-cpu/) - [ ] [Striga: Lifting x86 to LLVM IR with Python](https://secret.club/2026/05/21/striga.html) - [ ] [Flipper One — we need your help](https://blog.flipper.net/flipper-one-we-need-your-help/) - [ ] [Flipper One project needs community help to build open Linux platform](https://www.bleepingcomputer.com/news/hardware/flipper-one-project-needs-community-help-to-build-open-linux-platform/) - [ ] [Direttiva NIS2: guida pratica alla conformità e responsabilità del CdA](https://www.cybersecurity360.it/legal/direttiva-nis2-guida-pratica-alla-conformita-e-responsabilita-del-cda/) - [ ] [Xi and Putin pledge closer cooperation on AI, cyberspace and satellite systems](https://therecord.media/russia-and-china-pledge-cooperation-2026) - [ ] [Iperammortamento 2026–2028: la leva fiscale che accelera cyber e innovazione sostenibile](https://www.cybersecurity360.it/legal/iperammortamento-2026-2028-la-leva-fiscale-che-accelera-cyber-e-innovazione-sostenibile/) - [ ] [Hackers Exploit Butter Network Bridge to Mint Massive MAPO Supply](https://thecyberexpress.com/mapo-token-crash/) - [ ] [1-15 May 2026 Cyber Attacks Timeline](https://www.hackmageddon.com/2026/05/21/1-15-may-2026-cyber-attacks-timeline/) - [ ] [Recovery scam, l’architettura della re-vittimizzazione](https://www.cybersecurity360.it/news/recovery-scam-re-vittimizzazione/) - [ ] [Microsoft warns of new Defender zero-days exploited in attacks](https://www.bleepingcomputer.com/news/security/microsoft-warns-of-new-defender-zero-days-exploited-in-attacks/) - [ ] [AI Agent nelle organizzazioni: le 4 aree critiche](https://www.cybersecurity360.it/nuove-minacce/ai-agent-nelle-organizzazioni-le-4-aree-critiche/) - [ ] [Discord Launches End-to-End Encryption for Voice and Video Calls](https://thecyberexpress.com/end-to-end-encryption-on-discord-platform/) - [ ] [GitHub links repo breach to TanStack npm supply-chain attack](https://www.bleepingcomputer.com/news/security/github-links-repo-breach-to-tanstack-npm-supply-chain-attack/) - [ ] [Pardus Linux Vulnerability Chain Enables Complete System Takeover](https://thecyberexpress.com/cve-2026-5140-pardus-linux-root-access-flaw/) - [ ] [GitHub Confirms Cyberattack Targeting Thousands of Internal Repositories](https://thecyberexpress.com/github-cyberattack-teampcp/) - [ ] [Ukraine Busts Massive Cybercrime Scheme Behind 28,000 Stolen Accounts](https://thecyberexpress.com/account-theft-scheme-ukraine-cyber-police/) - [ ] [Dragonica Lunaris - 126,293 breached accounts](https://haveibeenpwned.com/Breach/Dragonica) - [ ] [FTC Cracks Down on AI Nudify Platforms Under TAKE IT DOWN Act](https://thecyberexpress.com/take-it-down-act-drives-ftc-against-ai-content/) - [ ] [Windows93 / Myspace93 - 46,105 breached accounts](https://haveibeenpwned.com/Breach/Windows93) - 360数字安全 - [ ] [上架麒麟软件、统信应用商店,360安全卫士(信创版)加快融入信创生态](https://mp.weixin.qq.com/s?__biz=MzA4MTg0MDQ4Nw==&mid=2247586006&idx=1&sn=abd86232bbc1946b9d0eb0d01ce77b7e) - Securityinfo.it - [ ] [HackerOne taglia drasticamente le ricompense dei bug bounty](https://www.securityinfo.it/2026/05/21/hackerone-taglia-drasticamente-le-ricompense-dei-bug-bounty/?utm_source=rss&utm_medium=rss&utm_campaign=hackerone-taglia-drasticamente-le-ricompense-dei-bug-bounty) - 大兵说安全 - [ ] [小满](https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&mid=2247485800&idx=1&sn=04016ed961b1555c077faa60c8510d26) - Have I Been Pwned latest breaches - [ ] [Dragonica Lunaris - 126,293 breached accounts](https://haveibeenpwned.com/Breach/Dragonica) - [ ] [Windows93 / Myspace93 - 46,105 breached accounts](https://haveibeenpwned.com/Breach/Windows93) - SANS Internet Storm Center, InfoCON: green - [ ] [Selective HTTP Proxying in Linux, (Thu, May 21st)](https://isc.sans.edu/diary/rss/33002) - [ ] [ISC Stormcast For Thursday, May 21st, 2026 https://isc.sans.edu/podcastdetail/9940, (Thu, May 21st)](https://isc.sans.edu/diary/rss/33000) - ICT Security Magazine - [ ] [Geopolitica e Cybercrime: quando il codice diventa strumento di potere tra Stati](https://www.ictsecuritymagazine.com/articoli/geopolitica-e-cybercrime/) - [ ] [From Hunter to Hunted: come il BKA priva i cybercriminali delle loro fondamenta](https://www.ictsecuritymagazine.com/articoli/meywirth-bka-cybercriminali/) - [ ] [Forum Cyber 4.0 2026: istituzioni, imprese e ricerca a confronto sulle sfide della cybersecurity](https://www.ictsecuritymagazine.com/notizie/forum-cyber-4-0-2026/) - [ ] [Pipeline sotto assedio: come i threat actor nation-state stanno compromettendo la software supply chain](https://www.ictsecuritymagazine.com/articoli/software-supply-chain-attacchi/) - [ ] [Hacking dei sistemi AI: prompt injection, model poisoning e la nuova superficie d’attacco](https://www.ictsecuritymagazine.com/articoli/hacking-dei-sistemi-ai/) - TG Soft Software House - News - [ ] [<strong>Vir.IT eXplorer PRO</strong><strong> </strong>supera con il massimo risultato, l'ultimo <strong>test</strong> effettuato a<strong> marzo 2026</strong> da <strong>AppEsteem </strong>per i <strong>prodotti AV DeceptorFighters</strong>](http://www.tgsoft.it/italy/news_archivio.asp?id=1740) - Instapaper: Unread - [ ] [Empirical Assessment of Apple Health Activity Data Accuracy, Granularity, and Database Artifacts](https://metadataperspective.com/2026/05/19/empirical-assessment-of-apple-health-activity-data-accuracy-granularity-and-database-artifacts/) - NetSPI - [ ] [Emulating & Exploiting UEFI: Unveiling Vulnerabilities in Firmware Security](https://www.netspi.com/blog/technical-blog/hardware-and-embedded-systems-penetration-testing/emulating-and-exploiting-uefi/) - Trend Micro Research, News and Perspectives - [ ] [One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign](https://www.trendmicro.com/en_us/research/26/e/inside-the-influence-and-fraud-patriot-bait-campaign.html) - The Hacker News - [ ] [Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor](https://thehackernews.com/2026/05/showboat-linux-malware-hits-middle-east.html) - [ ] [ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories](https://thehackernews.com/2026/05/threatsday-bulletin-linux-rootkits.html) - [ ] [Microsoft Warns of Two Actively Exploited Defender Vulnerabilities](https://thehackernews.com/2026/05/microsoft-warns-of-two-actively.html) - [ ] [When Identity is the Attack Path](https://thehackernews.com/2026/05/when-identity-is-attack-path.html) - [ ] [9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros](https://thehackernews.com/2026/05/9-year-old-linux-kernel-flaw-enables.html) - [ ] [GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension](https://thehackernews.com/2026/05/github-internal-repositories-breached.html) - [ ] [Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks](https://thehackernews.com/2026/05/highly-critical-drupal-core-flaw.html) - TorrentFreak - [ ] [Hollywood Secures Broad “Omnibus” Pirate Site Blocking Order in UK High Court](https://torrentfreak.com/hollywood-secures-broad-omnibus-pirate-site-blocking-order-in-uk-high-court/) - Tails - News - [ ] [Tails 7.8](https://tails.net/news/version_7.8/) - Security Affairs - [ ] [U.S. CISA adds Microsoft and Adobe flaws to its Known Exploited Vulnerabilities catalog](https://securityaffairs.com/192508/security/u-s-cisa-adds-microsoft-and-adobe-flaws-to-its-known-exploited-vulnerabilities-catalog.html) - [ ] [Global law enforcement operation takes First VPN offline](https://securityaffairs.com/192491/cyber-crime/global-law-enforcement-operation-takes-first-vpn-offline.html) - [ ] [Apple Blocks Over 2 Million Apps in 2025 Fraud Crackdown](https://securityaffairs.com/192484/security/apple-blocks-over-2-million-apps-in-2025-fraud-crackdown.html) - [ ] [Attackers are bypassing MFA on SonicWall VPNs because something was wrong with previous fix](https://securityaffairs.com/192477/hacking/attackers-are-bypassing-mfa-on-sonicwall-vpns-because-something-was-wrong-with-previous-fix.html) - [ ] [Cisco fixed maximum severity flaw CVE-2026-20223 in Secure Workload](https://securityaffairs.com/192473/security/cisco-fixed-maximum-severity-flaw-cve-2026-20223-in-secure-workload.html) - [ ] [Discord adds end-to-end encryption to voice and video calls by default](https://securityaffairs.com/192463/security/discord-adds-end-to-end-encryption-to-voice-and-video-calls-by-default.html) - Schneier on Security - [ ] [macOS Kernel Memory Corruption Exploit](https://www.schneier.com/blog/archives/2026/05/macos-kernel-memory-corruption-exploit.html) - Krebs on Security - [ ] [Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada](https://krebsonsecurity.com/2026/05/alleged-kimwolf-botmaster-dort-arrested-charged-in-u-s-and-canada/) - Social Engineering - [ ] [A social app that locks at 31 people.](https://www.reddit.com/r/SocialEngineering/comments/1tjxila/a_social_app_that_locks_at_31_people/) - [ ] [🧠 Expose Manipulation Instantly With THIS](https://www.reddit.com/r/SocialEngineering/comments/1tjvmm9/expose_manipulation_instantly_with_this/) - GRAHAM CLULEY - [ ] [Defenders fall behind, as AI rewrites the rules of a data breach](https://www.fortra.com/blog/defenders-fall-behind-ai-rewrites-rules-data-breach) - www.theregister.com - Articles - [ ] [Dems slam Trump for making cybersecurity hold out the tin cup while splurging on ballroom and Jan. 6 'slush fund'](https://www.theregister.com/security/2026/05/22/dems-slam-trump-cyber-cuts-amid-ballroom-jan-6-slush-fund/5244618) - [ ] [Threat hunters find Google API keys still usable 23 minutes after deletion](https://www.theregister.com/devops/2026/05/21/threat-hunters-find-google-api-keys-still-usable-23-minutes-after-deletion/5244504) - [ ] [HackerOne takes an axe to its bug bounty rewards](https://www.theregister.com/security/2026/05/21/hackerone-takes-an-axe-to-its-bug-bounty-rewards/5244458) - [ ] [Attackers spill plaintext passwords of 46k Myspace93 users after 2021 breach](https://www.theregister.com/security/2026/05/21/46k-plaintext-passwords-pwned-in-myspace93-breach/5244024) - [ ] [Cisco serves up yet another perfect 10 bug with Secure Workload admin flaw](https://www.theregister.com/security/2026/05/21/cisco-serves-up-yet-another-perfect-10-bug-with-secure-workload-admin-flaw/5244012) - [ ] [Microsoft storms RAMPART, adds Clarity to agentic AI safety](https://www.theregister.com/security/2026/05/21/microsoft-open-sources-agentic-ai-safety-tools/5243822) - [ ] [Zombie user account let hackers control the city’s water](https://www.theregister.com/security/2026/05/21/zombie-user-account-let-hackers-control-the-citys-water/5243724) - Information Security - [ ] [Is it Safe to Copy Code from AI?](https://www.reddit.com/r/Information_Security/comments/1tjp9iz/is_it_safe_to_copy_code_from_ai/) - [ ] [𝗟𝗲𝗴𝗶𝘁𝗶𝗺𝗮𝘁𝗲 𝗕𝟮𝗕 𝗪𝗲𝗯𝘀𝗶𝘁𝗲𝘀 𝗔𝗯𝘂𝘀𝗲𝗱 𝗳𝗼𝗿 𝗙𝗶𝗹𝗲𝗹𝗲𝘀𝘀 𝗠𝗮𝗹𝘄𝗮𝗿𝗲 𝗗𝗲𝗹𝗶𝘃𝗲𝗿𝘆: 𝗗𝗲𝘁𝗲𝗰𝘁 𝗜𝘁 𝗘𝗮𝗿𝗹𝘆](https://www.reddit.com/r/Information_Security/comments/1tjvw2c/𝗟𝗲𝗴𝗶𝘁𝗶𝗺𝗮𝘁𝗲_𝗕𝟮𝗕_𝗪𝗲𝗯𝘀𝗶𝘁𝗲𝘀_𝗔𝗯𝘂𝘀𝗲𝗱_𝗳𝗼𝗿_𝗙𝗶𝗹𝗲𝗹𝗲𝘀𝘀/) - [ ] [Developer Credentials Are Becoming the Weakest Link in the Supply Chain](https://www.reddit.com/r/Information_Security/comments/1tjkan9/developer_credentials_are_becoming_the_weakest/) - [ ] [Which cyber security course is best for getting placement quickly?](https://www.reddit.com/r/Information_Security/comments/1tjjs0p/which_cyber_security_course_is_best_for_getting/) - [ ] [GitHub confirms breach of 3,800 repos via malicious VSCode extension](https://www.reddit.com/r/Information_Security/comments/1tja4bq/github_confirms_breach_of_3800_repos_via/) - [ ] [How to handle device fingerprint validation bottlenecks during massive traffic spikes?](https://www.reddit.com/r/Information_Security/comments/1tjaxc1/how_to_handle_device_fingerprint_validation/) - Tor Project blog - [ ] [New Release: Tails 7.8](https://blog.torproject.org/new-release-tails-7_8/) - Security Weekly Podcast Network (Audio) - [ ] [FCC, Github, MiniShai-hulud, Stated of Supply Chain, Itron, CRA, NIS2, and more!! - PSW #927](http://sites.libsyn.com/18678/fcc-github-minishai-hulud-stated-of-supply-chain-itron-cra-nis2-and-more-psw-927) - Technical Information Security Content & Discussion - [ ] [CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox](https://www.reddit.com/r/netsec/comments/1tjow98/cve202640369_twelve_bytes_to_escape_the_browser/) - [ ] [durabletask (Microsoft's Python Durable Task client) compromised by TeamPCP | same Mini Shai-Hulud payload as last week's TanStack wave](https://www.reddit.com/r/netsec/comments/1tjvryy/durabletask_microsofts_python_durable_task_client/) - [ ] [GitHub Actions Cache Poisoning is eating open source](https://www.reddit.com/r/netsec/comments/1tjptvi/github_actions_cache_poisoning_is_eating_open/) - [ ] [CVE-2026-34474: Pre-auth credential disclosure in ZTE H298A / H108N via ETHCheat](https://www.reddit.com/r/netsec/comments/1tjojra/cve202634474_preauth_credential_disclosure_in_zte/) - [ ] [GitHub ~3,800 internal repos compromised through a malicious VS Code extension](https://www.reddit.com/r/netsec/comments/1tjfjjv/github_3800_internal_repos_compromised_through_a/) - Your Open Hacker Community - [ ] [JAVASCRIPT Function](https://www.reddit.com/r/HowToHack/comments/1tjbb80/javascript_function/) - [ ] [My website got hacked... What can I do ?](https://www.reddit.com/r/HowToHack/comments/1tjh8c6/my_website_got_hacked_what_can_i_do/) - [ ] [Tools for remote access](https://www.reddit.com/r/HowToHack/comments/1tj5od2/tools_for_remote_access/) - Deep Web - [ ] [[ Removed by Reddit ]](https://www.reddit.com/r/deepweb/comments/1tj5mv2/removed_by_reddit/) - Blackhat Library: Hacking techniques and research - [ ] [A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale](https://www.reddit.com/r/blackhat/comments/1tjhtm2/a_hacker_group_is_poisoning_open_source_code_at/) - [ ] [vibecodingsecurity to discuss AI Automation security issues](https://www.reddit.com/r/blackhat/comments/1tjwx3n/vibecodingsecurity_to_discuss_ai_automation/) - [ ] [“What I Learned About the LCS ‘Attacks’ and How I Started Beating the Fear Loop”](https://www.reddit.com/r/blackhat/comments/1tk0ixx/what_i_learned_about_the_lcs_attacks_and_how_i/)
每日安全资讯(2026-05-22)