Security News

全球顶尖安全社区实时聚合,追踪最新漏洞、攻防技术与行业动态。

来源:先知社区 · Seebug · The Hacker News 等权威平台 | 每日自动更新

国内 先知社区 2026/08/14
隐形的思维链:加密推理块跨模型重放与 CoT 窃取攻击
本文基于公开的学术研究成果(arXiv:2608.09867,Stealing Reasoning Traces from Proprietary LLM APIs)与笔者对 OpenAI / Anthropic / Google 三家厂商推理模型的协议层分析,拆解"加密推理块(Encrypted ...
国内 先知社区 2026/08/14
【AI安全】RAG 入库链中的跨视图语义漂移与上下文污染
人看到的安全文档,对 RAG 来说不一定安全。那么当知识在 Parser、Chunk、Retrieval 之间不断被重新解释和组织时,它原本的语义和安全属性还能不能完整保留下来?
国内 先知社区 2026/08/14
我搭了一条 AI 渗透流水线:从域名到报告全自动
每个新目标都是同一套重复劳动:信息收集一小时、查情报开五六个网页、挨个验证、再写报告。这篇讲我搭的 AI 渗透流水线——域名丢进去,初筛报告出来,中间全自动,人只做判断题。
国内 先知社区 2026/08/14
渗透实战篇-某园区监控服务器果奔:摄像头直播的完整利用链
一个平平无奇的"文件列表"页面,背后是 74 个摄像头的实时画面、高清截图和历史录像,外加整个监控内网的拓扑。这不是电影情节,是一次真实 SRC 测试的完整记录。
国内 先知社区 2026/08/13
SDPCSEC热身赛re部分
ezida非常简单,用ida打开附件,Shift+F12打开全部字符串列表窗口,搜索SDPCSEC即可ryo ? soyo? mio?用ida打开能看到一串可疑的字符直接base64解码即可debugme题目提示:flag在flag变量里面,在合适的地方下个断点看看 flag变量里面有什么我们直接在 ...
国内 先知社区 2026/08/13
从修复 diff 到第五个洞:LobeChat SSRF 盲区审计
LobeChat 7 月 2 日一口气公开 4 个 CVE,修 SSRF 时只覆盖了 2 个端点——但 bot 平台的 4 个 sendAttachments(discord/slack/微信/飞书)从 v2.2.9 到 8 月 12 日最新 canary 全是裸 fetch。注册账号、伪造 bot ...
国内 先知社区 2026/08/13
渗透实战篇-拿到某个批发商的 OSS AccessKey 之后:从验证能读到证明高危泄露
某批发商的订购系统,一个未授权的接口直接返回了阿里云 OSS 的 AK/SK 明文。 拿到密钥后不是终点,怎么把"能连上"证明成"批量个人信息泄露(高危)",才是这篇文章要讲的。
国内 先知社区 2026/08/12
从用户注销到优惠券复用:一次应用逻辑漏洞的完整剖析
本文以一款会员时长类应用作为研究样本,完整拆解因账号注销物理删库带来的权限校验缺陷,复现 “注销 - 重注册” 无限领取新人权益的攻击链路,同时搭配抽象伪代码定位底层代码问题,给出通用化修复与审计思路。
国际 The Hacker News 2026/08/19
SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs
A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia. The intrusion set ...
国际 The Hacker News 2026/08/19
Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P
Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and ...
国际 The Hacker News 2026/08/19
Phishing 3.0: The Fight Moves to Agent Versus Agent
Most email defenses still do the job they did a decade ago. Scan the message, look for something malicious, block it. That worked when the danger sat ...
国际 The Hacker News 2026/08/19
StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to dissemina ...
国际 The Hacker News 2026/08/19
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities ...
国际 Bruce Schneier 2026/08/19
ICE Collecting DNA Samples
ICE collected nearly a million DNA samples last year.
国内 Seebug Paper 2026/08/19
面向部署的资源高效神经符号框架:用于运营技术网络中可解释的DDoS检测
作者:Mikiyas Alemayehu, Mohamed Chahine Ghanem, Hamza Kheddar, Aohan Li, and J. J. Garcia-Luna-Aceves 原文链接:https://arxiv.org/html/2608.16769v1 摘要 运营技术(O ...
国际 The Hacker News 2026/08/19
Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure
Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, after correlating recurring e ...
国际 The Hacker News 2026/08/19
Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specificall ...
国际 Dark Reading 2026/08/19
China-Linked Hacker Shows AI Capabilities in APAC Attack
In the first purported "near-autonomous" attack on a nation-state, a Chinese-language operator used a complex AI framework to target and compromise go ...
国际 Dark Reading 2026/08/18
Critical GitLab Zero-Click Flaw Poses Mitigation Challenges
A lack of technical details could make it hard for organizations running self-managed GitLab versions to detect potential exploitation of CVE-2026-194 ...
国际 Dark Reading 2026/08/18
'CoSnitch' Attack Tricked Copilot into Mapping Out Architecture
Researchers discovered a "meta-hacking" technique that can manipulate the AI service into revealing its own security weaknesses.
国际 Dark Reading 2026/08/18
CISOs Break Their Silence in 'Declassified' Docuseries
Million-dollar heists, divorce, and career-ending burnout are all stories told in the latest docuseries revealing a behind-the-scenes look at the cybe ...
国际 The Hacker News 2026/08/18
Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to sil ...
国际 Dark Reading 2026/08/18
'Ransom Busters': Ransomware Actor Poses as Incident-Recovery Service
A ransomware affiliate appears to be sidling up to victims with offers of aid, masking its true intention of diverting ransom payments.
国际 Dark Reading 2026/08/18
Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud
The Python-based malware framework takes living-off-the-land tactics to a new heights of stealth, with a modular implant that steals credentials and a ...
国际 Bruce Schneier 2026/08/18
LLMs and Contextual Integrity
I have been thinking a lot about AI and integrity. Part of that is contextual integrity. I recently found two papers on the topic. "CIMemories: A Comp ...
国际 Troy Hunt 2026/08/18
Weekly Update 517: Cyber Ransoms
The current ransomware situation is a bit of a kludge (deep breath): a lot of ransomware (which often doesn't even involve "ware", it's just ...
国际 Dark Reading 2026/08/17
Video Call Exploit Chains Two Flaws in Unisoc Modems
Researchers found that by combining two vulnerabilities, they could take over an Android device by delivering a payload and getting the victim to answ ...
国际 Dark Reading 2026/08/17
'Turf War' Between Claude Agents Leads to Self-Replicating Malware
Three testing models with the same goal but different directives engaged in "increasingly aggressive" territorial attacks on one another, according to ...
国际 Bruce Schneier 2026/08/17
Hacking Public Wi-Fi DNS to Steal Credentials
Criminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is ...
国际 Bruce Schneier 2026/08/14
Friday Squid Blogging: Searching for the Colossal Squid
Fascinating video about searching for life undersea. The video basically makes the point that our bright white searchlights are scaring everything awa ...
国际 Bruce Schneier 2026/08/14
Upcoming Speaking Engagements
This is a current list of where and when I am scheduled to speak: I’m speaking, signing books, and participating in panel discussions at LAcon V in An ...
国际 Krebs on Security 2026/08/14
Who’s Tracking You? Use This New Service to Find Out
It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every ...
国际 Bruce Schneier 2026/08/14
If the Markets Reject OpenAI and Anthropic, the US Should Nationalize Them
This essay was written with Nathan E. Sanders, and originally appeared in The Guardian. OpenAI, and then Anthropic, were each formed by AI developers ...
国际 Bruce Schneier 2026/08/13
Separating AI’s Technological Problems from Its Capitalism Problems
This essay was written with Nathan E. Sanders, and originally appeared in Tech Policy Press. AI represents the first time we humans can do cognitive w ...
国际 Bruce Schneier 2026/08/12
Prompt Injections for Defense
This seems to work: Researchers from Tracebit on Monday said they found that placing prompt injections alongside passwords, cryptographic keys, and ot ...
国际 Troy Hunt 2026/08/12
Weekly Update 516: Live From Vietnam
A little wind noise, a little connectivity flakiness, and a little lip-sync issues from YouTube, but look at that view! 🤩 Back to business, it ...
国际 Krebs on Security 2026/08/11
Microsoft Plugs Nearly 400 Security Holes
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including on ...
国际 Krebs on Security 2026/08/06
Canadian Man Pleads Guilty in Snowflake Extortions
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and c ...
国内 Seebug Paper 2026/08/05
MIRAGE:通过用户生成内容对移动 GUI 智能体进行上下文感知的提示注入
作者:Ruoqi Guo, Yi Liu, Gelei Deng, Yiheng Xiong, Yuekang Li, Ying Zhang, Leo Yu Zhang, Lida Zhao, Ji Jie, Yuxiao Lu 原文链接:http://arxiv.org/html/2605.281 ...
国内 Seebug Paper 2026/08/04
(AI) 看见你看不见的:利用第三方移动智能体中的新型攻击面
作者:Zidong Zhang,Zhentao Xie,Wenrui Diao,Jianliang Wu 原文链接:https://arxiv.org/pdf/2607.00333v2 摘要 由视觉语言模型(VLM)驱动的第三方移动智能体已成为自动化智能手机交互的一种前景广阔的新范式。这些智能体充当 ...
国际 Troy Hunt 2026/08/03
Welcoming the Nepalese Government to Have I Been Pwned
Today, we welcome the 47th government onboarded to Have I Been Pwned’s free gov service: Nepal. Their National Cyber Security Centre now has ac ...
国际 Troy Hunt 2026/08/03
Weekly Update 515: Seeking Caffeine Utopia
Apparently, Aussies are so obsessed with coffee that it's referred to as the coffee capital of the world down here (some bits, at least). "But wh ...
国际 Krebs on Security 2026/07/30
Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-t ...
国内 Seebug Paper 2026/07/30
面向零信任物联网架构的联邦学习与大语言模型驱动威胁情报
作者:Amal Alshehri, Cihan Tunc 原文链接:https://arxiv.org/html/2607.17035v1 摘要 尽管物联网(IoT)已变得不可或缺,但它们也带来了严重的安全和隐私挑战,尤其是在关键任务环境中。传统设备容易受到病毒、数据泄露和未经授权访问的攻击,而更新 ...
国内 Seebug Paper 2026/07/27
基于 DW-HKEM 的量子弹性银行交易安全:一种混合 RSA/ML-KEM 加密网关与实时监控系统
作者:Aswani Kumar Cherukuri, Siddhaarth S Prabhu 原文链接:https://arxiv.org/pdf/2607.17573 摘要 面向公共网络的在线银行和金融服务日益增多,这使得加密协议的安全性成为一个严重的系统性问题。RSA-2048是当今互联网上绝大 ...
国际 Troy Hunt 2026/07/26
Weekly Update 514: This Week in Data Breaches
The Origin Energy breach down here in Aus is all over the news this week, and as with many breaches, it's multi-faceted. You've got them lea ...
国内 Seebug Paper 2026/07/24
自托管 AI 智能体的自状态攻击:操作系统防御能走多远?
作者:Yimeng Chen,Nathanaël Denis,Roberto Di Pietro,Jürgen Schmidhuber 原文链接:https://arxiv.org/html/2607.17986v1 摘要 自托管的AI智能体通过读写自身的内存和配置文件来运行。智能体可能因其自身状态 ...
国内 Seebug Paper 2026/07/23
自适应对抗者:面向LLM智能体安全的多轮次、多LLM基准测试
作者: Devina Jain,David Hartmann,Chuan Li 原文链接:https://arxiv.org/html/2607.18063v1 摘要 基于LLM的智能体在处理外部内容时,会暴露于提示注入和多轮次操纵的风险之中。大多数安全基准测试使用评估前收集的固定攻击池来评估防御方 ...
国际 Krebs on Security 2026/07/22
LG to Ban Residential Proxies from Smart TV Apps
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an alw ...
国际 Troy Hunt 2026/07/21
Weekly Update 513: Clauding The Home Network
I reckon this week's video on how Claude is tying together info from UniFi, Home Assistant and the Pi-Hole is an absolute ripper. Or at least the ...
国内 Seebug Paper 2026/07/20
AI 水印证据未能达到取证就绪标准:一项实证评估
作者: Saifur Rahman Tamim, Amir Labib Khan 原文链接:https://arxiv.org/pdf/2607.16010v1 摘要 各国政府正越来越多地强制要求LLM生成的内容携带水印。欧盟《人工智能法案》要求标记"足够可靠和稳健"。加利福尼亚州SB 942法案要 ...
国内 腾讯玄武实验室 2026/07/17
Xuanwu Atuin AI 在 CyberGym 上的表现:GLM-5.2 更新结果
我们此前报道过,由 GLM-5.1 驱动的腾讯玄武 Atuin AI 在 CyberGym 上取得了 84.0% 的 pass@1,见文章链接。 现在我们使用 GLM‑5.2 重新评估了 Atuin AI。在相同的评估方法下,Atuin AI 达到了 84.8% 的 pass@1(1,278 / 1 ...
国际 Troy Hunt 2026/07/15
Weekly Update 512: IoT Lockout Fail
"Build a smart home", they said. "It'll make life so much better", they said. Well, life wasn't very bloody good at 23:00 the other night af ...
国际 Krebs on Security 2026/07/14
Microsoft Patches a Record 570 Security Flaws
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple ...
国际 Krebs on Security 2026/07/13
Lessons Learned from CISA’s Recent GitHub Leak
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal ...
国际 Troy Hunt 2026/07/08
Weekly Update 511: Live from my Riad in Marrakech
How's this for a location?! I mean, last week was nice with Scott in Mallorca, but Marrakech is, well, wow 😮 Anyway, about those data bre ...
国际 Krebs on Security 2026/07/08
Felons, Fraudsters Flog Offensive Cybersecurity Startup
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right co ...
国内 腾讯玄武实验室 2026/02/28
幽灵依赖:Agentic Coding 范式下的新型供应链安全威胁
Author: Tianchu Chen of Tencent Xuanwu Lab 0x00 简介随着 LLM(大语言模型)能力的跃升,AI 软件开发模式正从“人写代码,AI 补全”的 Copilot 模式,向“AI 主导决策,自动执行”的 Agentic Coding 模式演进。在 Agenti ...
国内 腾讯玄武实验室 2026/02/02
AI网络爬虫安全白皮书
Author: Guancheng Li and Zheng Wang of Tencent Xuanwu Lab 本文是腾讯玄武实验室发布的《AI网络爬虫安全白皮书》。我们系统分析了 AI 时代服务端浏览器 / 爬虫在真实业务中的典型使用方式,以及由此带来的新的攻击面与风险。 在这篇白皮书中,我们 ...
国内 腾讯玄武实验室 2026/01/06
ComfyUI-Manager 远程代码执行风险通告
近期腾讯玄武实验室发现可视化 AI 工作流工具 ComfyUI 的官方扩展组件 ComfyUI-Manager 中存在一个高危漏洞(CVE-2025-67303)。利用该漏洞可在无需任何账号的情况下远程入侵安装 ComfyUI 的系统。玄武实验室在发现漏洞后向 ComfyUI 官方进行了报告,目前该 ...