# 每日安全资讯(2026-09-30) - Private Feed for M09Ic - [ ] [anthropics released v2.1.285 at anthropics/claude-code](https://github.com/anthropics/claude-code/releases/tag/v2.1.285) - [ ] [freqtrade released 2026.9 at freqtrade/freqtrade](https://github.com/freqtrade/freqtrade/releases/tag/2026.9) - [ ] [timwhitez contributed to timwhitez/neocloud-sec](https://github.com/timwhitez/neocloud-sec/pull/23) - [ ] [Fplyth0ner-Combie starred ekkoo-z/Z-Godzilla_ekp](https://github.com/ekkoo-z/Z-Godzilla_ekp) - [ ] [killeven starred TanStack/query](https://github.com/TanStack/query) - [ ] [gh0stkey starred yetone/magpie](https://github.com/yetone/magpie) - [ ] [future-architect released v0.41.0-rc.2 at future-architect/vuls](https://github.com/future-architect/vuls/releases/tag/v0.41.0-rc.2) - [ ] [liamg contributed to infracost/proto](https://github.com/infracost/proto/pull/101) - [ ] [esrrhs contributed to esrrhs/fakecc](https://github.com/esrrhs/fakecc/pull/86) - [ ] [Gaurav-Gosain released v0.8.1 at Gaurav-Gosain/tuios](https://github.com/Gaurav-Gosain/tuios/releases/tag/v0.8.1) - [ ] [gh0stkey starred longbridge/gpui-fast](https://github.com/longbridge/gpui-fast) - [ ] [timwhitez starred elder-plinius/T3MP3ST](https://github.com/elder-plinius/T3MP3ST) - [ ] [esrrhs contributed to esrrhs/fakelua](https://github.com/esrrhs/fakelua/pull/19) - SecWiki News - [ ] [SecWiki News 2026-09-29 Review](http://www.sec-wiki.com/?2026-09-29) - bunnie's blog - [ ] [Name that Ware, September 2026](https://www.bunniestudios.com/blog/2026/name-that-ware-september-2026/) - [ ] [Winner, Name that Ware August 2026](https://www.bunniestudios.com/blog/2026/winner-name-that-ware-august-2026/) - Sploitus.com Exploits RSS Feed - [ ] [xss-methodology exploit](https://sploitus.com/exploit?id=8024CEEA-518F-5B6B-94B5-1F697CA4A522&utm_source=rss&utm_medium=rss) - [ ] [Relapse-Exploit](https://sploitus.com/exploit?id=8A9E0782-7097-56A3-AE0C-397F6619E92A&utm_source=rss&utm_medium=rss) - [ ] [ps5 exploit](https://sploitus.com/exploit?id=F834CB8A-EA79-5292-88F7-F732B3046883&utm_source=rss&utm_medium=rss) - [ ] [Exploit for Injection in Arjunsharda Searchor](https://sploitus.com/exploit?id=4F53287C-2F9A-58F5-8FCA-E5857E0D4330&utm_source=rss&utm_medium=rss) - [ ] [exploit](https://sploitus.com/exploit?id=88BC7F11-7D2A-5D4A-B05A-1A93F5BDE925&utm_source=rss&utm_medium=rss) - [ ] [Relapse-Exploit-13.40-local](https://sploitus.com/exploit?id=9D536A3F-C037-52D7-BDF6-588600FC53AD&utm_source=rss&utm_medium=rss) - [ ] [Relapse-Exploit-Before](https://sploitus.com/exploit?id=CFCC80C9-B0D7-554C-B00F-0234993FBC18&utm_source=rss&utm_medium=rss) - [ ] [Exploit for PHP Remote File Inclusion in Wordpress](https://sploitus.com/exploit?id=569311D0-BF9F-5EF7-8C56-E61EADA98014&utm_source=rss&utm_medium=rss) - [ ] [vestigium exploit](https://sploitus.com/exploit?id=E022B7F3-C006-547C-B5F1-121245F6559D&utm_source=rss&utm_medium=rss) - [ ] [MyModel exploit](https://sploitus.com/exploit?id=CC9AFB87-74D3-5CA9-8283-855373FE0232&utm_source=rss&utm_medium=rss) - [ ] [SymaX5SW-Rx-Tx exploit](https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-INFOBYTE-SYMAX5SW-RX-TX&utm_source=rss&utm_medium=rss) - [ ] [bulk_extractor exploit](https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-SIMSONG-BULK_EXTRACTOR&utm_source=rss&utm_medium=rss) - [ ] [Mortimer exploit](https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-NCCGROUP-MORTIMER&utm_source=rss&utm_medium=rss) - [ ] [relapse-exploit](https://sploitus.com/exploit?id=F2353DB9-73A1-503F-AA87-AB0EDAD63AEA&utm_source=rss&utm_medium=rss) - [ ] [kali-rpi-luks-crypt exploit](https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-TOTHI-KALI-RPI-LUKS-CRYPT&utm_source=rss&utm_medium=rss) - [ ] [OWASPBugBounty exploit](https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-OWASP-OWASPBUGBOUNTY&utm_source=rss&utm_medium=rss) - [ ] [ngxray exploit](https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-CALIFIO-NGXRAY&utm_source=rss&utm_medium=rss) - [ ] [CVE-2019-8781-macOS exploit](https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-TRUNGNGUYEN1909-CVE-2019-8781-MACOS&utm_source=rss&utm_medium=rss) - [ ] [CVE-2025-1094-PoC-Postgre-SQLi exploit](https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-ISHWARDEEPP-CVE-2025-1094-POC-POSTGRE-SQLI&utm_source=rss&utm_medium=rss) - [ ] [sshroute exploit](https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-THEREISNOTIME-SSHROUTE&utm_source=rss&utm_medium=rss) - Armin Ronacher's Thoughts and Writings - [ ] [Deser: Rethinking Rust Serialization](https://lucumr.pocoo.org/2026/9/29/deser/) - Doonsec's feed - [ ] [每周文章分享-278](https://mp.weixin.qq.com/s/mGP9yOUsf_aEy8ld475ydA) - [ ] [2026湾区杯 web部分](https://mp.weixin.qq.com/s/bv12JUojm5Oa0nc1PAbFLg) - [ ] [解密对话式AI背后的广告追踪风险](https://mp.weixin.qq.com/s/L1K1HuKGQZUqTbb-Czt6Zw) - [ ] [不用安装,一次import就中招?MemTensor 投毒拆解](https://mp.weixin.qq.com/s/LnsfGMb_Olw3fo2ZbJSgMg) - [ ] [article](https://mp.weixin.qq.com/s/Th8ajr-yWYs3bE5DVTr1Xg) - [ ] [【高危漏洞预警】Citrix NetScaler ADC / NetScaler Gateway预认证命令注入远程代码执行漏洞CVE-2026-88771](https://mp.weixin.qq.com/s/EXwz-HaHLoo0eFcG4zU4Ew) - [ ] [CVE-2026-101909 深度解析:Axios 不是漏洞入口,而是原型污染的「放大器」](https://mp.weixin.qq.com/s/Ll2JAkr35FbwNOc03QtQ8Q) - [ ] [前大疆员工爆料:不管你在哪上班,如果你现在处在一个“冷淡”的办公环境,大家都淡淡的,各干各的,这可能才是最舒服健康的环境。](https://mp.weixin.qq.com/s/9ckxtQ3rIf97e-hmN0F9MQ) - [ ] [【地图大师的代码审计之路 第二篇】从代码层看懂越权与未授权漏洞为何如此高发](https://mp.weixin.qq.com/s/mdK_IcZ5LHMz6vzd_zQeiA) - [ ] [架构安全的理论基础](https://mp.weixin.qq.com/s/skhHdFpXp-eZaAZLzUucsg) - [ ] [Win11安装的若干Tips](https://mp.weixin.qq.com/s/ZU-13LsrT1Yhyt7bKUsTMg) - [ ] [全新版本-天书安全捆绑工具](https://mp.weixin.qq.com/s/BeDW3CJ-RGbDNTx8ou5jbQ) - [ ] [DeepSeek 新论文,支撑大规模Agent训练的沙箱基础设施](https://mp.weixin.qq.com/s/K69ObJLR-aoitheGXMa3oA) - [ ] [当Claude遇上Metasploit:一句话从Root Shell到域控SYSTEM全流程](https://mp.weixin.qq.com/s/Y21NeplNnhF0BX5jbTK58Q) - [ ] [半价活动](https://mp.weixin.qq.com/s/v5-pnFHpPsBaxAm73aWVqQ) - [ ] [重磅预告|许进教授将在2026年网络空间安全学术会议作主旨报告](https://mp.weixin.qq.com/s/3ZFaF1NKs7qk3XHvhxsdDQ) - [ ] [【漏洞预警】Citrix NetScaler 命令注入漏洞](https://mp.weixin.qq.com/s/XLId0bCdiNJaRoTSMN0c1A) - [ ] [Master V3.0 专为后渗透而生-结合agent首发](https://mp.weixin.qq.com/s/I9qWdYLFGJ4-ErfW7MTauw) - [ ] [54款大模型测出873个漏洞,网安生该学什么?](https://mp.weixin.qq.com/s/Psj1IUoiG1_oab5VgHZRNQ) - [ ] [iOS 26.7.1 发布了:一个已经被用过的漏洞](https://mp.weixin.qq.com/s/vPfYBWQgkcMIAm9KGcUPXg) - [ ] [电子取证大事记(2026年9月21日 — 9月27日)](https://mp.weixin.qq.com/s/xO-hf60_lDoLhrh6JZdyzw) - Microsoft Security Blog - [ ] [Phishing Abuses RMM Tools for Persistent Access](https://www.microsoft.com/en-us/security/blog/2026/09/29/phishing-abuses-rmm-tools-persistent-access/) - [ ] [Beyond source code: A path to the keys to the kingdom](https://www.microsoft.com/en-us/security/blog/2026/09/29/beyond-source-code-a-path-to-the-keys-to-the-kingdom/) - [ ] [Star Blizzard refines phishing and malware delivery with the RedFlick technique](https://www.microsoft.com/en-us/security/blog/2026/09/29/star-blizzard-refines-phishing-and-malware-delivery-with-the-redflick-technique/) - 安全客-有思想的安全新媒体 - [ ] [3.5亿美元一夜蒸发!黑客没偷密钥,Bitget是怎么被掏空的](https://www.anquanke.com/post/id/316193) - [ ] [机器开始自己越权了:AI 智能体一年 17 次"翻墙",英伟达紧急下场装护栏](https://www.anquanke.com/post/id/316190) - Recent Commits to cve:main - [ ] [Update Tue Sep 29 12:42:37 UTC 2026](https://github.com/trickest/cve/commit/1250fa801122f60dbfb96c2c7a2852d5bbad6d27) - Kitploit — Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal! - [ ] [ip-obfuscation](https://kitploit.com/en/tools/github/hackinglz/ip-obfuscation) - [ ] [Relapse-Exploit](https://kitploit.com/en/tools/github/ntfargo/relapse-exploit) - [ ] [resterm v1.10.2](https://kitploit.com/en/posts/resterm-386ff414d5db835f) - [ ] [RedTeamSimmer](https://kitploit.com/en/tools/github/breachsimrange/redteamsimmer) - [ ] [blindxss-lite](https://kitploit.com/en/tools/github/yuyudhn/blindxss-lite) - [ ] [0](https://kitploit.com/en/tools/github/0sec-labs/0) - [ ] [IPA](https://kitploit.com/en/tools/github/seekbytes/ipa) - [ ] [ptxNinja](https://kitploit.com/en/tools/github/seekbytes/ptxninja) - [ ] [obfuscation_analysis](https://kitploit.com/en/tools/github/mrphrazer/obfuscation_analysis) - [ ] [bugbounty-lab101](https://kitploit.com/en/tools/github/devcop95/bugbounty-lab101) - [ ] [fish-live-in-trees](https://kitploit.com/en/tools/github/loophole-llc/fish-live-in-trees) - [ ] [jailbreaks](https://kitploit.com/en/tools/github/togg53192-cmd/jailbreaks) - [ ] [security-harness](https://kitploit.com/en/tools/github/dmdhrumilmistry/security-harness) - [ ] [VulnForge](https://kitploit.com/en/tools/github/rootless-ghost/vulnforge) - [ ] [phantom-grid](https://kitploit.com/en/tools/github/haidang-infosec/phantom-grid) - GuidePoint Security - [ ] [Managing Agentic AI: Why the Control Plane Problem Is an AI Problem](https://www.guidepointsecurity.com/blog/managing_agentic_ai/) - CCC Event Blog - [ ] [Abheben zum chaos.jetzt-Geekend #jetzt15 in Frankfurt (Main)](https://events.ccc.de/2026/09/29/jetzt15-geekend/) - Binary Ninja - [ ] [Debugger Conditional Breakpoints and the Expression Parser That Backs Them](https://binary.ninja/2026/09/29/debugger-conditional-breakpoint.html) - Intigriti - [ ] [10 years of Intigriti](https://www.intigriti.com/blog/news/10-years-of-intigriti) - Malwarebytes - [ ] [Meta’s Muse sent a Facebook Marketplace buyer to a seller’s home](https://www.malwarebytes.com/blog/news/2026/09/metas-muse-sent-a-facebook-marketplace-buyer-to-a-sellers-home) - [ ] [Update your iPhone, iPad, or Mac: Flaw could run attackers’ code](https://www.malwarebytes.com/blog/bugs/2026/09/update-your-iphone-ipad-or-mac-flaw-could-run-attackers-code) - [ ] [Fake iPhone Duo preorder scam triggers DarkSword attack](https://www.malwarebytes.com/blog/threat-intel/2026/09/fake-iphone-duo-preorder-scam-triggers-darksword-attack) - [ ] [Humans are reviewing Copilot users’ bizarre and abusive image-editing requests](https://www.malwarebytes.com/blog/ai/2026/09/humans-are-reviewing-copilot-users-bizarre-and-abusive-image-editing-requests) - Reverse Engineering - [ ] [80 Days Reversing an IoT DVR: Stripped ARM32 Firmware, Hardcoded AES Keys & Post-Mortem here is my write up love yall.](https://www.reddit.com/r/ReverseEngineering/comments/1wtcusg/80_days_reversing_an_iot_dvr_stripped_arm32/) - [ ] [Intel C/C++ Compiler 4.0](https://www.reddit.com/r/ReverseEngineering/comments/1wtaapk/intel_cc_compiler_40/) - [ ] [Reverse engineered a Chinese dashcam/AA head unit (TF790 / OBDPEAK K2) running open source media controller on it](https://www.reddit.com/r/ReverseEngineering/comments/1wtdans/reverse_engineered_a_chinese_dashcamaa_head_unit/) - [ ] [Flare-On13 discussion](https://www.reddit.com/r/ReverseEngineering/comments/1wt2xj5/flareon13_discussion/) - [ ] [QUICKSURFACE AI - QUICKSURFACE](https://www.reddit.com/r/ReverseEngineering/comments/1wteme8/quicksurface_ai_quicksurface/) - [ ] [I dare you to decode this: 392.2 -219.6 2 0 386.2 -67.3 2 1 192.7 128.9 1 2 543.7 116 1 3 135 434 3 4 608.5 303.5 1 5 438.2 444.4 2 6;0 1 0 1 3 2 1 2 1 2 4 1 3 4 2 3 5 1 2 5 2 5 6 0 6 4 0;8 0](https://www.reddit.com/r/ReverseEngineering/comments/1wtafyg/i_dare_you_to_decode_this_3922_2196_2_0_3862_673/) - rtl-sdr.com - [ ] [Echo Pro: KiwiSDR, OpenWebRX, WebSDR and FM-DX iOS Browser App now with Live Transcription and Translation](https://www.rtl-sdr.com/echo-sdr-pro-kiwisdr-openwebrx-websdr-and-fm-dx-ios-browser-app-now-with-live-transcription-and-translation/) - [ ] [RTL-SDR Pager: Android App for Receiving and Decoding POCSAG and FLEX Pager Messages](https://www.rtl-sdr.com/rtl-sdr-pager-android-app-for-receiving-and-decoding-pocsag-and-flex-pager-messages/) - HackerNews - [ ] [Bitget 在 3.875 亿美元加密货币被盗后恢复比特币提现](http://0.0.0.0:8080/post/64743) - [ ] [超过 16,000 个 Supabase 数据库暴露 PII、密码和身份验证令牌](http://0.0.0.0:8080/post/64742) - [ ] [荷兰警方证实在 ShinyHunters 黑客调查中实施逮捕](http://0.0.0.0:8080/post/64741) - [ ] [Times Car 证实数据泄露影响 660 万用户账户](http://0.0.0.0:8080/post/64740) - [ ] [日本 Keio 证实遭勒索软件攻击,业务系统中断](http://0.0.0.0:8080/post/64739) - [ ] [Apple 修复 CoreGraphics 漏洞,该漏洞可能在定向攻击中被利用](http://0.0.0.0:8080/post/64738) - 奇客Solidot–传递最新科技情报 - [ ] [八分之一癌症病例由感染引起](https://www.solidot.org/story?sid=85507) - [ ] [银行高管被 Deepfake 语音骗走 1 亿美元](https://www.solidot.org/story?sid=85506) - [ ] [美光台工厂工会准备罢工](https://www.solidot.org/story?sid=85505) - [ ] [Firefox 157 释出](https://www.solidot.org/story?sid=85504) - [ ] [微软告诉非营利组织他们被删除的数据无法恢复](https://www.solidot.org/story?sid=85503) - [ ] [不易变黑的香蕉准备上市](https://www.solidot.org/story?sid=85502) - [ ] [AMD 以 82 亿美元收购李飞飞的 World Labs](https://www.solidot.org/story?sid=85501) - [ ] [Google 计划到 2034 年停止支持 ChromeOS](https://www.solidot.org/story?sid=85500) - [ ] [Windows 10 更新 bug 远少于 Windows 11](https://www.solidot.org/story?sid=85499) - [ ] [中国冰川大幅减少](https://www.solidot.org/story?sid=85498) - 白帽Wiki - 一个简单的wiki - [ ] [[2026]anthropic的追踪SUB2API技巧](https://key08.com/index.php/2026/09/30/3339.html) - 绿盟科技技术博客 - [ ] [四次进化,绿盟科技将开拓怎样的安全新境?](https://blog.nsfocus.net/%e5%9b%9b%e6%ac%a1%e8%bf%9b%e5%8c%96%ef%bc%8c%e7%bb%bf%e7%9b%9f%e7%a7%91%e6%8a%80%e5%b0%86%e5%bc%80%e6%8b%93%e6%80%8e%e6%a0%b7%e7%9a%84%e5%ae%89%e5%85%a8%e6%96%b0%e5%a2%83%ef%bc%9f/) - [ ] [微软9月安全更新多个产品高危漏洞通告](https://blog.nsfocus.net/%e5%be%ae%e8%bd%af9%e6%9c%88%e5%ae%89%e5%85%a8%e6%9b%b4%e6%96%b0%e5%a4%9a%e4%b8%aa%e4%ba%a7%e5%93%81%e9%ab%98%e5%8d%b1%e6%bc%8f%e6%b4%9e%e9%80%9a%e5%91%8a/) - [ ] [微软8月安全更新多个产品高危漏洞通告](https://blog.nsfocus.net/%e5%be%ae%e8%bd%af8%e6%9c%88%e5%ae%89%e5%85%a8%e6%9b%b4%e6%96%b0%e5%a4%9a%e4%b8%aa%e4%ba%a7%e5%93%81%e9%ab%98%e5%8d%b1%e6%bc%8f%e6%b4%9e%e9%80%9a%e5%91%8a/) - [ ] [Fastjson 2.x远程代码执行漏洞通告](https://blog.nsfocus.net/fastjson-2-x%e8%bf%9c%e7%a8%8b%e4%bb%a3%e7%a0%81%e6%89%a7%e8%a1%8c%e6%bc%8f%e6%b4%9e%e9%80%9a%e5%91%8a/) - [ ] [Fastjson 1.2.x无需gadget远程代码执行漏洞通告](https://blog.nsfocus.net/fastjson-1-2-x%e6%97%a0%e9%9c%80gadget%e8%bf%9c%e7%a8%8b%e4%bb%a3%e7%a0%81%e6%89%a7%e8%a1%8c%e6%bc%8f%e6%b4%9e%e9%80%9a%e5%91%8a/) - [ ] [使用Ubuntu 26远程桌面](https://blog.nsfocus.net/%e4%bd%bf%e7%94%a8ubuntu-26%e8%bf%9c%e7%a8%8b%e6%a1%8c%e9%9d%a2/) - [ ] [给英文版Ubuntu 26安装中文输入法](https://blog.nsfocus.net/%e7%bb%99%e8%8b%b1%e6%96%87%e7%89%88ubuntu-26%e5%ae%89%e8%a3%85%e4%b8%ad%e6%96%87%e8%be%93%e5%85%a5%e6%b3%95/) - Qualys Security Blog - [ ] [Autonomous Remediation Is Already Running at Enterprise Scale](https://blog.qualys.com/category/qualys-insights) - [ ] [Lessons from Microsoft Patch KB5002907: Two Layers of Patch Control in Qualys TruRisk Eliminate](https://blog.qualys.com/category/product-tech) - Over Security - [ ] [Signal adds encypted local backup support to iOS, desktop apps](https://www.bleepingcomputer.com/news/security/signal-adds-encypted-local-backup-support-to-ios-desktop-apps/) - [ ] [US Air Force members given over 6 years in prison for cyber theft of more than $2 million](https://therecord.media/us-air-force-members-given-6-year-sentence-cyber) - [ ] [Custom ChatGPTs push ClickFix attacks to deploy RAT malware](https://www.bleepingcomputer.com/news/security/custom-chatgpts-push-clickfix-attacks-to-deploy-rat-malware/) - [ ] [Controversial spyware firm Paragon to go public by end of year](https://therecord.media/controversial-spyware-firm-paragon-to-go-public) - [ ] [ShinyHunters vs. Cl0p: The Attack on the Site, the Dispute, and Qilin’s Position](https://www.suspectfile.com/shinyhunters-vs-cl0p-the-attack-on-the-site-the-dispute-and-qilins-position/) - [ ] [FBI tells ShinyHunters members to turn themselves in after recent arrest](https://www.bleepingcomputer.com/news/security/fbi-tells-shinyhunters-members-to-turn-themselves-in-after-recent-arrest/) - [ ] [OpenAI apologizes for agents breaching Australian government websites without authorization](https://therecord.media/openai-apologizes-australia-medicare-breach) - [ ] [Hackers exploit Citrix NetScaler zero-day to deploy web shells](https://www.bleepingcomputer.com/news/security/hackers-exploit-citrix-netscaler-zero-day-to-deploy-web-shells/) - [ ] [Former US Air Force members sent to prison over BEC attacks](https://www.bleepingcomputer.com/news/security/former-us-air-force-members-sent-to-prison-over-bec-attacks/) - [ ] [Windows 11 2026 Update released, here's everything you need to know](https://www.bleepingcomputer.com/news/microsoft/windows-11-2026-update-released-heres-everything-you-need-to-know/) - [ ] [New Spectre v2 attack variant leaks Linux root password hash in minutes](https://www.bleepingcomputer.com/news/security/new-spectre-v2-attack-variant-leaks-linux-root-password-hash-in-minutes/) - [ ] [Errore umano nella cyber: perché non è quasi mai la vera causa dell’incidente](https://www.cybersecurity360.it/nuove-minacce/errore-umano-nella-cyber-perche-non-e-quasi-mai-la-vera-causa-dellincidente/) - [ ] [Automated AI agent used to breach cybersecurity nonprofit DIVD](https://www.bleepingcomputer.com/news/security/automated-ai-agent-used-to-breach-cybersecurity-nonprofit-divd/) - [ ] [GPT-6.1 Astra, OpenAI blocca il rilascio per motivi di sicurezza: la posta in gioco](https://www.cybersecurity360.it/nuove-minacce/gpt-6-1-astra-openai-blocca-il-rilascio-per-motivi-di-sicurezza-la-posta-in-gioco/) - [ ] [Cyber security, compliance e resilienza: a it-sa 2026 la sicurezza diventa governance](https://www.cybersecurity360.it/cultura-cyber/cyber-security-compliance-e-resilienza-a-it-sa-2026-la-sicurezza-diventa-governance/) - [ ] [louis-rs Security Audit](https://www.shielder.com/blog/2026/09/louis-rs-security-audit/) - [ ] [Catch threats before they escalate with real-time Identity Telemetry](https://www.bleepingcomputer.com/news/security/catch-threats-before-they-escalate-with-real-time-identity-telemetry/) - [ ] [Servizi di ascolto e GDPR: come proteggere i dati durante il ciclo di vita della segnalazione](https://www.cybersecurity360.it/legal/privacy-dati-personali/servizi-di-ascolto-e-gdpr-come-proteggere-i-dati-durante-il-ciclo-di-vita-della-segnalazione/) - [ ] [Arizona Supreme Court says hackers stole residents’ personal data](https://therecord.media/arizona-supreme-court-says-hackers-stole-data) - [ ] [Russian pizza chain with 1,500 locations confirms cyberattack following hacker claims](https://therecord.media/russian-pizza-chain-dodo-confirms-data-breach) - [ ] [Kaspersky Small Office Security Premium: protezione ransomware, VPN e Security Awareness per le PMI senza team IT](https://www.cybersecurity360.it/cultura-cyber/kaspersky-small-office-security-premium-protezione-pmi-ransomware/) - [ ] [Vietnamese man charged in $16 million 'pig butchering' crypto scam](https://www.bleepingcomputer.com/news/security/vietnamese-man-charged-in-16-million-pig-butchering-crypto-scam/) - [ ] [Securing the keys to the kingdom: Announcing Executive Threat Detection](https://blog.talosintelligence.com/securing-the-keys-to-the-kingdom-announcing-executive-threat-detection/) - [ ] [AI penetration testing: dalla vulnerabilità rilevata all’exploit realmente validato](https://www.cybersecurity360.it/soluzioni-aziendali/ai-penetration-testing-dalla-vulnerabilita-rilevata-allexploit-realmente-validato/) - [ ] [Kiteworks patches critical flaw, brings customer systems online](https://www.bleepingcomputer.com/news/security/kiteworks-lifts-shutdown-warning-after-patching-critical-flaw/) - [ ] [Hackers Are Stealing AI Keys. The Cost Can Reach $600,000](https://thecyberexpress.com/ai-service-security-how-attackers-exploit-keys/) - [ ] [France Awards Airbus 25-Year Contract for Military Network Gateways](https://thecyberexpress.com/airbus-cybersecurity-sas-paracom-contract/) - [ ] [Polish Medical Software Hit by Cyberattack, Patient Data Stolen](https://thecyberexpress.com/medyc-cyberattack-exposes-polish-patients-data/) - [ ] [Apple Fixes CoreGraphics Flaw Used in Targeted Attacks](https://thecyberexpress.com/apple-fixes-cve-2026-86950-ios-ipados/) - [ ] [September 2026 Cyber Attacks Timeline](https://www.hackmageddon.com/2026/09/29/september-2026-cyber-attacks-timeline/) - [ ] [Major Cyber Attacks in September 2026: US and EU Face Session Theft, Remote Access, and Payment Fraud](https://any.run/cybersecurity-blog/major-cyber-attacks-september-2026/) - [ ] [Attacchi LLM-jacking: hacker dirottano account aziendali per colpire terzi a costi irrisori](https://www.cybersecurity360.it/nuove-minacce/attacchi-llm-jacking-hacker-dirottano-account-aziendali-per-colpire-terzi-a-costi-irrisori/) - [ ] [Apple patches CoreGraphics zero-day flaw exploited in attacks](https://www.bleepingcomputer.com/news/security/apple-patches-coregraphics-zero-day-flaw-exploited-in-attacks/) - [ ] [GPT-6 Astra e l’attacco alla supply chain: quando l’AI viola le regole](https://www.cybersecurity360.it/nuove-minacce/gpt-6-astra-e-lattacco-alla-supply-chain-quando-lai-viola-le-regole/) - Blog on Shielder - [ ] [louis-rs Security Audit](https://www.shielder.com/blog/2026/09/louis-rs-security-audit/) - Krypt3ia - [ ] [Weekly Cyber Espionage Intelligence Brief 9.29.26](https://krypt3ia.wordpress.com/2026/09/29/weekly-cyber-espionage-intelligence-brief-9-29-26/) - [ ] [Weekly All-Source Espionage Intelligence Brief 9.29.26](https://krypt3ia.wordpress.com/2026/09/29/weekly-all-source-espionage-intelligence-brief-9-29-26/) - ICT Security Magazine - [ ] [Operational Summary ACN agosto 2026: incidenti stabili, sistemi a rischio quasi triplicati da una vulnerabilità di cPanel](https://www.ictsecuritymagazine.com/cyber-security/operational-summary-acn-agosto-2026/) - [ ] [Minacce spaziali, la nuova decisione UE abroga la STRA del 2021: cosa cambia per Stati membri e sicurezza informatica](https://www.ictsecuritymagazine.com/notizie/stra-minacce-spaziali-ue/) - [ ] [Prove digitali e intelligenza artificiale: deepfake, provenance e scenari critici verso una forensics AI-resistant](https://www.ictsecuritymagazine.com/articoli/prove-digitali-ai/) - Schneier on Security - [ ] [Using Device Linking to Eavesdrop on WhatsApp and Signal](https://www.schneier.com/blog/archives/2026/09/using-device-linking-to-eavesdrop-on-whatsapp-and-signal.html) - SANS Internet Storm Center, InfoCON: green - [ ] [Scans for Wordfence Protected Websites, (Tue, Sep 29th)](https://isc.sans.edu/diary/rss/33382) - [ ] [ISC Stormcast For Tuesday, September 29th, 2026 https://isc.sans.edu/podcastdetail/10114, (Tue, Sep 29th)](https://isc.sans.edu/diary/rss/33378) - The Hacker News - [ ] [French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks](https://thehackernews.com/2026/09/french-tax-data-theft-using-stolen.html) - [ ] [New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses](https://thehackernews.com/2026/09/new-spectre-v2-btr-attack-leaks-linux.html) - [ ] [Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor](https://thehackernews.com/2026/09/russias-star-blizzard-targets-100.html) - [ ] [Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown](https://thehackernews.com/2026/09/kiteworks-fixes-critical-flaw-found.html) - [ ] [101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent](https://thehackernews.com/2026/09/101-malicious-npm-packages-add.html) - [ ] [Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation](https://thehackernews.com/2026/09/dutch-police-arrest-24-year-old.html) - [ ] [Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials](https://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html) - [ ] [OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions](https://thehackernews.com/2026/09/openai-shelves-gpt-61-astra-after-tests.html) - [ ] [OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot](https://thehackernews.com/2026/09/openai-pauses-tool-use-after-agent.html) - KitPloit - PenTest Tools! - [ ] [ip-obfuscation](https://kitploit.com/en/tools/github/hackinglz/ip-obfuscation) - [ ] [Relapse-Exploit](https://kitploit.com/en/tools/github/ntfargo/relapse-exploit) - [ ] [resterm v1.10.2](https://kitploit.com/en/posts/resterm-386ff414d5db835f) - [ ] [RedTeamSimmer](https://kitploit.com/en/tools/github/breachsimrange/redteamsimmer) - [ ] [blindxss-lite](https://kitploit.com/en/tools/github/yuyudhn/blindxss-lite) - [ ] [0](https://kitploit.com/en/tools/github/0sec-labs/0) - [ ] [IPA](https://kitploit.com/en/tools/github/seekbytes/ipa) - [ ] [ptxNinja](https://kitploit.com/en/tools/github/seekbytes/ptxninja) - [ ] [obfuscation_analysis](https://kitploit.com/en/tools/github/mrphrazer/obfuscation_analysis) - [ ] [bugbounty-lab101](https://kitploit.com/en/tools/github/devcop95/bugbounty-lab101) - [ ] [fish-live-in-trees](https://kitploit.com/en/tools/github/loophole-llc/fish-live-in-trees) - [ ] [jailbreaks](https://kitploit.com/en/tools/github/togg53192-cmd/jailbreaks) - [ ] [security-harness](https://kitploit.com/en/tools/github/dmdhrumilmistry/security-harness) - [ ] [VulnForge](https://kitploit.com/en/tools/github/rootless-ghost/vulnforge) - [ ] [phantom-grid](https://kitploit.com/en/tools/github/haidang-infosec/phantom-grid) - Tor Project blog - [ ] [New Release: Tor Browser 15.0.24](https://blog.torproject.org/new-release-tor-browser-15024/) - Security Affairs - [ ] [Japanese railway operators Keio Corporation and Tokyo Metro disclose security breaches](https://securityaffairs.com/200027/data-breach/japanese-railway-operators-keio-corporation-and-tokyo-metro-disclose-security-breaches.html) - [ ] [Three Million Affected in Pentagon Personnel Agency Data Breach](https://securityaffairs.com/200017/uncategorized/three-million-affected-in-pentagon-personnel-agency-data-breach.html) - [ ] [Apple Patches CoreGraphics Zero-Day Linked to Sophisticated Targeted Attacks](https://securityaffairs.com/200001/hacking/apple-patches-coregraphics-zero-day-linked-to-sophisticated-targeted-attacks.html) - [ ] [24-Year-Old Arrested in Dutch Investigation Into ShinyHunters](https://securityaffairs.com/199979/cyber-crime/24-year-old-arrested-in-dutch-investigation-into-shinyhunters.html) - [ ] [GPT-6 Astra and the Supply Chain Attack It Wasn’t Asked to Launch](https://securityaffairs.com/199947/ai/gpt-6-astra-and-the-supply-chain-attack-it-wasnt-asked-to-launch.html) - Full Disclosure - [ ] [APPLE-SA-09-28-2026-3 macOS Sequoia 15.8.1](https://seclists.org/fulldisclosure/2026/Sep/91) - [ ] [APPLE-SA-09-28-2026-2 macOS Tahoe 26.7.1](https://seclists.org/fulldisclosure/2026/Sep/90) - [ ] [APPLE-SA-09-28-2026-1 iOS 26.7.1 and iPadOS 26.7.1](https://seclists.org/fulldisclosure/2026/Sep/89) - Deeplinks - [ ] [While the Country Rejects ALPR Mass Surveillance, SF Settles for Weak Safeguards](https://www.eff.org/deeplinks/2026/09/while-country-rejects-alpr-mass-surveillance-sf-settles-weak-safeguards) - [ ] [Privacy’s Defenders Podcast: Cowboys, Cypherpunks and Visionaries](https://www.eff.org/deeplinks/2026/09/privacys-defenders-podcast-cowboys-cypherpunks-and-visionaries) - Deep Web - [ ] [Ummmm I’m nervous bout if I’m hacked orrrr](https://www.reddit.com/r/deepweb/comments/1wtnqsu/ummmm_im_nervous_bout_if_im_hacked_orrrr/) - [ ] [OS helppp](https://www.reddit.com/r/deepweb/comments/1wsw2s9/os_helppp/) - Instapaper: Unread - [ ] [Dati rubati sempre disponibili il salto industriale del cybercrime](https://www.agendadigitale.eu/sicurezza/dati-rubati-sempre-disponibili-il-salto-industriale-del-cybercrime/) - [ ] [Caso Revolut, cosa sappiamo dopo l’intervento alla Camera della Sottosegretaria all’Interno](https://www.cybersecitalia.it/caso-revolut-cosa-sappiamo-dopo-lintervento-alla-camera/70060/) - [ ] [Così Mosca imita i media occidentali per diffondere falsi contenuti. Il rapporto NewsGuard](https://formiche.net/2026/09/cosi-mosca-imita-i-media-occidentali-per-diffondere-falsi-contenuti-il-rapporto-newsguard/) - [ ] [Windows Memory Acquisition Methods, Tools, and Forensic Considerations for DFIR Practitioners](https://digitalinvestigator.blogspot.com/2026/09/windows-memory-acquisition-methods.html) - [ ] [Green Meets Blue A Brief RCS Forensic Excursion](https://www.forensicfocus.com/articles/green-meets-blue-a-brief-rcs-forensic-excursion/) - www.theregister.com - Articles - [ ] [Add one more AI worry to the nightmare scenario: self-replicating prompt injections](https://www.theregister.com/security/2026/09/29/add-one-more-ai-worry-to-the-nightmare-scenario-self-replicating-prompt-injections/5299922) - [ ] [FBI to ShinyHunters: 'We know how to find you'](https://www.theregister.com/security/2026/09/29/fbi-to-shinyhunters-we-know-how-to-find-you/5299901) - [ ] [Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services](https://www.theregister.com/security/2026/09/29/custom-malware-used-in-citrix-0-day-attacks-targeting-govt-banks-professional-services/5299867) - [ ] [AI models keep posting screenshots showing sensitive data from inside tech companies](https://www.theregister.com/ai-and-ml/2026/09/29/ai-models-keep-posting-screenshots-showing-sensitive-data-from-inside-tech-companies/5299640) - [ ] [Apple patches CoreGraphics zero-day already exploited in targeted attacks](https://www.theregister.com/security/2026/09/29/apple-patches-coregraphics-zero-day-already-exploited-in-targeted-attacks/5299721) - [ ] [OpenAI benches GPT-6.1 Astra for overstepping the mark](https://www.theregister.com/ai-and-ml/2026/09/29/openai-benches-gpt-61-astra-for-overstepping-the-mark/5299743) - [ ] [Former X-Force hackers chase the offensive cyber gold rush](https://www.theregister.com/security/2026/09/29/former-x-force-hackers-chase-the-offensive-cyber-gold-rush/5299662) - [ ] [OpenAI’s dirty deeds Down Under included security bypass attempts, using exposed keys, source code siphon](https://www.theregister.com/ai-and-ml/2026/09/29/openais-dirty-deeds-down-under-included-security-bypass-attempts-using-exposed-keys-source-code-siphon/5299666) - TorrentFreak - [ ] [IFPI Wants Open Source YouTube Downloader yt-dlp on EU Piracy Watch List](https://torrentfreak.com/ifpi-wants-open-source-youtube-downloader-yt-dlp-on-eu-piracy-watch-list/) - Daniel Miessler - [ ] [AI State of the Union (October 2026)](https://danielmiessler.com/blog/ai-state-of-the-union?utm_source=rss&utm_medium=feed&utm_campaign=website)
每日安全资讯(2026-09-30)