# 每日安全资讯(2025-07-23) - 奇安信攻防社区 - [ ] [AC18-ARM架构下的栈溢出从挖掘到利用](https://forum.butian.net/share/4473) - SecWiki News - [ ] [SecWiki News 2025-07-22 Review](http://www.sec-wiki.com/?2025-07-22) - Private Feed for M09Ic - [ ] [Ak74-577 starred Yuragy/HVNC-windows-remote-toolkit](https://github.com/Yuragy/HVNC-windows-remote-toolkit) - [ ] [lz520520 starred cross-rs/cross](https://github.com/cross-rs/cross) - [ ] [gh0stkey starred superagent-ai/grok-cli](https://github.com/superagent-ai/grok-cli) - [ ] [xpn starred slygoo/pssrecon](https://github.com/slygoo/pssrecon) - [ ] [HuYlllc pushed to dev in chainreactors/malice-network](https://github.com/chainreactors/malice-network/compare/47a990873a...cd25c2bd98) - [ ] [evilashz starred ChoiSG/SharpSilentChrome](https://github.com/ChoiSG/SharpSilentChrome) - [ ] [Rvn0xsy starred hzqst/unicorn_pe](https://github.com/hzqst/unicorn_pe) - [ ] [CHYbeta starred superagent-ai/grok-cli](https://github.com/superagent-ai/grok-cli) - [ ] [esrrhs starred HexaSoftwareDev/PingTunnel-Server](https://github.com/HexaSoftwareDev/PingTunnel-Server) - [ ] [CHYbeta started following gboddin](https://github.com/gboddin) - [ ] [Ridter starred shareAI-lab/analysis_claude_code](https://github.com/shareAI-lab/analysis_claude_code) - paper - Last paper - [ ] [论文摘要攻击:通过 LLM 安全论文破解大型语言模型](https://paper.seebug.org/3342/) - Trustwave Blog - [ ] [Trustwave Enhances its OT Security Services Portfolio](https://www.trustwave.com/en-us/resources/blogs/trustwave-blog/trustwave-enhances-its-ot-security-services-portfolio/) - Doonsec's feed - [ ] [OpenWrt应用过滤特征库更新(7月)](https://mp.weixin.qq.com/s?__biz=MzU4MTgxNDc2MQ==&mid=2247486307&idx=1&sn=f7507f760121cc292c63c1160a859da3) - [ ] [hvv7.22情报](https://mp.weixin.qq.com/s?__biz=MzI3NzMzNzE5Ng==&mid=2247490484&idx=1&sn=1341bd2dcd63992172940a1ff79af2c7) - [ ] [国内docker镜像站+vulhub靶场](https://mp.weixin.qq.com/s?__biz=Mzk2NDQ2ODU4NQ==&mid=2247483894&idx=1&sn=ef60267d30cb1ca27e188cae550d7093) - [ ] [src/众测中的一些越权方式](https://mp.weixin.qq.com/s?__biz=Mzk0MTIzNTgzMQ==&mid=2247522088&idx=1&sn=8f1bf0c4bc674820cb968ff6028063a0) - [ ] [【工具】油猴脚本之Googlexa0搜索结果自动收集+Hunterxa0批量打开前10个链接](https://mp.weixin.qq.com/s?__biz=MzkyNjY3OTI4Ng==&mid=2247485156&idx=1&sn=9bd87974614ccbedc3398a398c20be69) - [ ] [【翻译】红队战术:使用xa0io_uringxa0规避xa0Linuxxa0上的xa0EDR](https://mp.weixin.qq.com/s?__biz=Mzg4NzgzMjUzOA==&mid=2247485901&idx=1&sn=15d2e36e4e1fd6c435f93b5e7fd2d93e) - [ ] [CPU环境复现NVIDIAxa0GPU容器逃逸xa0(买不起gpu的小伙伴有福啦](https://mp.weixin.qq.com/s?__biz=MzA4NTAxMjA5Mg==&mid=2247484505&idx=1&sn=c0dba45ada70165178714e3b53469b96) - [ ] [AI视频,只要发布,就能赚钱,就有收入的一个副业(适合新手)](https://mp.weixin.qq.com/s?__biz=MzUzODU3ODA0MA==&mid=2247490707&idx=1&sn=1d6b18ac28dd273a1ff4854289eef6f0) - [ ] [PPT 大模型合规安全审计](https://mp.weixin.qq.com/s?__biz=MjM5OTk4MDE2MA==&mid=2655287472&idx=1&sn=884d525d1b8dc76ff1d5d33eca236b1f) - [ ] [人工智能、算力算网 今天上传文件列表](https://mp.weixin.qq.com/s?__biz=MjM5OTk4MDE2MA==&mid=2655287472&idx=2&sn=7cd05286a4acb0f96716e21f9b5eb1d5) - [ ] [打穿AD域漏洞CVE-2025-33073的矛与盾 - 域安全](https://mp.weixin.qq.com/s?__biz=MzkzNTY5NzA0Mg==&mid=2247484635&idx=1&sn=35950231d626a3ddd07b9f958059b664) - [ ] [模块化xa0PICxa0C2xa0代理](https://mp.weixin.qq.com/s?__biz=MzAxODM5ODQzNQ==&mid=2247489671&idx=1&sn=961125ebc1068174fd9b172deb706c91) - [ ] [使用OD工具破解软件登录例子](https://mp.weixin.qq.com/s?__biz=MzkyMTQzNTM3Ng==&mid=2247484100&idx=1&sn=6dbe368b8725ebe9048cc089c1bcc307) - [ ] [打造警务AI作战单元!智能体构建与警务场景实战应用训练营即将开营](https://mp.weixin.qq.com/s?__biz=MjM5NTU4NjgzMg==&mid=2651445156&idx=1&sn=7c81c39238654682b1430e5265ccb8dd) - [ ] [全网资源一网打尽!这个神奇“杂货铺”,没有你找不到的宝藏](https://mp.weixin.qq.com/s?__biz=MjM5OTc5MjM4Nw==&mid=2457389255&idx=1&sn=324c870c5a07be058675504b5afed4a3) - [ ] [外媒对我雅鲁藏布江下游水电项目的报道分析与战略风险研判](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650561827&idx=1&sn=a240728cf058bf43ae5df92779fe6ee5) - [ ] [中国人民大学高瓴人工智能学院 | KG-Agent:一个用于知识图谱复杂推理的高效自主智能体框架](https://mp.weixin.qq.com/s?__biz=MzU5MTM5MTQ2MA==&mid=2247493030&idx=1&sn=bbe8a4d1d288630d2d6894e2b7da3015) - [ ] [Thexa0Firstxa0Contextxa0Engineer:TRAExa02.0xa0SOLOxa0发布](https://mp.weixin.qq.com/s?__biz=MzI1MzYzMjE0MQ==&mid=2247515230&idx=1&sn=1940891fa414697befc4d3e371e58221) - [ ] [维达外贸客户关系管理系统xa0sendmailview.jspxa0SQL注入漏洞](https://mp.weixin.qq.com/s?__biz=MzkzMTcwMTg1Mg==&mid=2247492213&idx=1&sn=b091b151a24f78d4565b341602cd8f5e) - [ ] [G.O.S.S.I.Pxa0阅读推荐xa02025-07-22xa0AI安全的日与夜](https://mp.weixin.qq.com/s?__biz=Mzg5ODUxMzg0Ng==&mid=2247500451&idx=1&sn=e6553d27cdae1a7c849b903822b01e6d) - [ ] [CertiK《Skynet 2025年上半年稳定币全景报告》(附报告全文链接)](https://mp.weixin.qq.com/s?__biz=MzU5OTg4MTIxMw==&mid=2247504453&idx=1&sn=cf3b630be80fe7c3fce156d56c3acf16) - [ ] [AI带你 SQL 注入](https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&mid=2247497922&idx=1&sn=90b6e84d2f5f6e9d5d21a06185c83548) - [ ] [我院学子在第十八届全国大学生信息安全竞赛(创新实践能力赛)中获佳绩](https://mp.weixin.qq.com/s?__biz=Mzk0MDMwNjU3Ng==&mid=2247484833&idx=1&sn=bb71be7a4172e83bcb16fcc68c16349f) - [ ] [【已复现】泛微OA前台未授权登录认证绕过+远程代码执行](https://mp.weixin.qq.com/s?__biz=Mzk5MDYxODcwMA==&mid=2247483995&idx=1&sn=e1a8829d4e7182eb79a9925774ad8248) - [ ] [ima 知识库的用途](https://mp.weixin.qq.com/s?__biz=Mzk0MTI4NTIzNQ==&mid=2247494293&idx=1&sn=a221c788410febac91729eaecf115f8d) - [ ] [某公司swagger暴露互联网导致敏感数据泄露](https://mp.weixin.qq.com/s?__biz=MzI3NzM5NDA0NA==&mid=2247491728&idx=1&sn=221f6bd268f0343adafbf71ba781897f) - [ ] [给开发工程师讲的 Fastjson 漏洞原理](https://mp.weixin.qq.com/s?__biz=MzI4NzA1Nzg5OA==&mid=2247486012&idx=1&sn=35d1d9b3238ac72a9b31e4948abce50e) - [ ] [利用基于计时器的 Shellcode 执行进行远程 DLL 注入](https://mp.weixin.qq.com/s?__biz=MzkzNTgzOTg4Mg==&mid=2247485725&idx=1&sn=6ca5071814ed5c3f3bdca793c90f7f79) - [ ] [专题·原创 | 践行总体国家安全观 全面增强网络安全意识](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664245963&idx=1&sn=94959d584b6d051348c330523ee119a1) - [ ] [专家解读 | 数据流通安全审计和溯源 助力农业数据要素流通——解读《基于数据可信流通设施环境番茄生长模型场景的数据流通案例》](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664245963&idx=2&sn=7ae6b9040b2f80dc498af3bcd40f6173) - [ ] [通知 | 网安标委发布《网络安全标准实践指南——摇一摇广告触发行为安全要求》(附全文)](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664245963&idx=3&sn=235b2a6286aa974b7d265cd932830601) - [ ] [通知xa0|xa0《网络安全标准实践指南——扫码点餐个人信息保护要求(征求意见稿)》公开征求意见(附全文)](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664245963&idx=4&sn=3be6bc5c2fd3c3bb8916213df716066f) - [ ] [金融监管总局:关于警惕“职业背债”陷阱的风险提示](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664245963&idx=5&sn=5b38b78e1d0de9e8448e4d0638bb0fa2) - [ ] [满满的回忆杀!网页版xa0Windowsxa0XPxa0和诺基亚手机博物馆,带你重回青春岁月](https://mp.weixin.qq.com/s?__biz=MzI2MjcwMTgwOQ==&mid=2247492524&idx=1&sn=aeefc1ef801ef5647b7db94a92c87f61) - [ ] [LV近42万香港客户资料外泄,官方主动通知用户](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247514727&idx=1&sn=bbdcfedfa1e781d04f5fd0b2cf9f2ac5) - [ ] [AI智能体的崛起:机遇、风险和下一个前沿](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247514727&idx=2&sn=692a3660735bbf7f07463ad6dd6b85ad) - [ ] [火热报名中!首届上海市工程系列数字技术专业高级职称评审申报指南](https://mp.weixin.qq.com/s?__biz=MzUzODYyMDIzNw==&mid=2247519283&idx=1&sn=7c5f1580bf89ab6a881efdf17167fa9d) - [ ] [美国“星际之门”AI计划暂时“搁浅”](https://mp.weixin.qq.com/s?__biz=MzUzODYyMDIzNw==&mid=2247519283&idx=2&sn=19ff255b381ed8b7e27a9aa787549666) - [ ] [安服下岗三件套:滴滴、外卖和快递](https://mp.weixin.qq.com/s?__biz=Mzg5MDA5NzUzNA==&mid=2247489451&idx=1&sn=805857a1329209f9accc4e0bd4bf1d59) - [ ] [快手联合上交提出统一多模态生成理解模型Orthus:基于自回归Transformer的无损图文交错生成新范式!](https://mp.weixin.qq.com/s?__biz=Mzg2NzU4MDM0MQ==&mid=2247496942&idx=1&sn=a3cb2f4c9b7f3e25611ecaaa487ea112) - [ ] [【人物调研】普老板身边的终极“万能助手”,神秘“影子”鲍里斯·查洛夫](https://mp.weixin.qq.com/s?__biz=MzkwNzM0NzA5MA==&mid=2247510446&idx=1&sn=bf3de9913b4ecc9740513dad0d28e3de) - [ ] [国际顶刊收录 | 隐私保护联合查询系统 Jeddak FedQuery 入选IEEE TIFS](https://mp.weixin.qq.com/s?__biz=MzUzMzcyMDYzMw==&mid=2247495197&idx=1&sn=c062fdc4660345bd6a7ce35ee88719a8) - [ ] [造黑客攻击,老板暴怒!12万私活项目【外卖换电柜】柜门被暴力打开,IoT 物联网设备安全不容小觑](https://mp.weixin.qq.com/s?__biz=MjM5OTA4MzA0MA==&mid=2454939036&idx=1&sn=6b3fee5aa8133a4a275d352e3dfd8411) - [ ] [碰瓷皮尔森系数](https://mp.weixin.qq.com/s?__biz=Mzg5MDcwOTM4OQ==&mid=2247486143&idx=1&sn=332c56f8559896ac43ec821b6adb0caa) - [ ] [估值30亿的AI编程独角兽 “删库又撒谎”!“氛围编程” 狂欢背后,安全警钟已敲响](https://mp.weixin.qq.com/s?__biz=MzIxMDIwODM2MA==&mid=2653932467&idx=1&sn=d2c2a1147b888a49df0d0251e0bd1e0d) - [ ] [AI快讯:Qwen3模型重大更新,零一万物发布首款企业级Agent](https://mp.weixin.qq.com/s?__biz=MzIxMDIwODM2MA==&mid=2653932467&idx=2&sn=24dd80e443c85453ed8681c6faff0df9) - [ ] [东方电气集团基于AI大模型的机组智能运维助手建设项目](https://mp.weixin.qq.com/s?__biz=MzIxMDIwODM2MA==&mid=2653932467&idx=3&sn=1a4bb5b7ae85053acbff23e9d9a8beef) - [ ] [【安全圈】微软测试Windows 11\"整盘迁移\"功能:数据搬家更便利,但仍有局限](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652070784&idx=1&sn=862304bb941a4c3a07d9f8a5ae3d693d) - [ ] [【安全圈】英美数据安全角力:英国政府或将撤销iCloud\"后门\"要求](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652070784&idx=2&sn=56c8090abb97b4d92f43696210aef97f) - [ ] [【安全圈】7-Zip 存在两处漏洞,或引发拒绝服务攻击](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652070784&idx=3&sn=c065d3383291c74a450df32ea40c4fc0) - [ ] [【安全圈】NVIDIA 容器工具包被曝高危漏洞:权限提升和任意代码执行](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652070784&idx=4&sn=24b532f0ec23a1ec4ea0d7342a8a4624) - [ ] [内存敏感信息提取工具](https://mp.weixin.qq.com/s?__biz=MzkyNzIxMjM3Mg==&mid=2247490993&idx=1&sn=d075813f3123360aedf0900b5e808fca) - [ ] [【活动倒计时10天】遇『7』则翻!还有机会获得7周年2倍翻倍卡!](https://mp.weixin.qq.com/s?__biz=MzUyNzc4Mzk3MQ==&mid=2247494360&idx=1&sn=fd3a10b004270aa2975b666f1a4c1135) - [ ] [代码审计-Thinkphp框架审计前置知识点](https://mp.weixin.qq.com/s?__biz=Mzg5NDg4MzYzNQ==&mid=2247486592&idx=1&sn=b8ae2026f0ed75fa89274e792c91cf77) - [ ] [代码审计-未授权访问漏洞](https://mp.weixin.qq.com/s?__biz=Mzg5NDg4MzYzNQ==&mid=2247486590&idx=1&sn=9240707506eca943fd35ddcf3239697e) - [ ] [白帽子转行首月20K?3个月,零基础小白也能速成!](https://mp.weixin.qq.com/s?__biz=MjM5NjA0NjgyMA==&mid=2651325289&idx=1&sn=c340b7440d0b917006391d487b8ff2f0) - [ ] [戴尔数据泄露事件:测试实验室平台遭World Leaks黑客组织入侵](https://mp.weixin.qq.com/s?__biz=MjM5NjA0NjgyMA==&mid=2651325289&idx=3&sn=4e6bbfab7cbbf1b1587a655f041bcf1c) - [ ] [监控公司利用SS7旁路攻击追踪用户位置信息](https://mp.weixin.qq.com/s?__biz=MjM5NjA0NjgyMA==&mid=2651325289&idx=4&sn=219328eb9bd4cbf276456d5ce0b08966) - 安全客-有思想的安全新媒体 - [ ] [绕过大模型护栏 | 新型“回音室”攻击和对抗技术](https://www.anquanke.com/post/id/310375) - Recent Commits to cve:main - [ ] [Update Tue Jul 22 11:24:36 UTC 2025](https://github.com/trickest/cve/commit/dc8cfda7f9b5823701ed643fd0d788e01796581b) - 嘶吼 RoarTalk – 网络安全行业综合服务平台,4hou.com - [ ] [直面掌门人 | 盛邦安全董事长权小文](https://www.4hou.com/posts/5MkB) - [ ] [网信办发布 “关于开展个人信息保护负责人信息报送工作的公告”](https://www.4hou.com/posts/2XPK) - [ ] [Interlock勒索软件采用新的FileFix攻击方式推送恶意程序](https://www.4hou.com/posts/RXmq) - Sucuri Blog - [ ] [Uncovering a Stealthy WordPress Backdoor in mu-plugins](https://blog.sucuri.net/2025/07/uncovering-a-stealthy-wordpress-backdoor-in-mu-plugins.html) - Sandfly Security Blog RSS Feed - [ ] [Sandfly Secures Vay's Remotely Driven Vehicle Fleet](https://sandflysecurity.com/blog/sandfly-secures-vay-s-remotely-driven-vehicle-fleet) - GuidePoint Security - [ ] [The Identity Security Crisis: What the Data Tells Us](https://www.guidepointsecurity.com/blog/the-identity-security-crisis-what-the-data-tells-us/) - Horizon3.ai - [ ] [Horizon3.ai Named in the 2025 Gartner® Hype Cycle™ for Security Operations](https://horizon3.ai/downloads/research/horizon3-ai-named-in-the-2025-gartner-hype-cycle-for-security-operations/) - [ ] [Horizon3.ai and Pax8 Expand Access to Offensive Security, Ushering in a New Era of Partner-Delivered Adversarial Testing](https://horizon3.ai/news/press-release/horizon3-ai-and-pax8-expand-access-to-offensive-security-ushering-in-a-new-era-of-partner-delivered-adversarial-testing/) - SpiderLabs Blog - [ ] [Using SQLmap to Dig for Sensitive Data in SQL Databases](https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/using-sqlmap-to-dig-for-sensitive-data-in-sql-databases/) - CCC Event Blog - [ ] [ChaosZeltZone 2025](https://events.ccc.de/2025/07/22/chaoszeltzone2025/) - SentinelOne - [ ] [AI’s Double Edge: How AI Expands the Attack Surface & Empowers Defenders](https://www.sentinelone.com/blog/ais-double-edge-how-ai-expands-the-attack-surface-and-empowers-defenders/) - Reverse Engineering - [ ] ["Reverse Engineering Security Products: Developing an Advanced Tamper Tradecraft" held in BlackHat MEA 2024](https://www.reddit.com/r/ReverseEngineering/comments/1m6hm5s/reverse_engineering_security_products_developing/) - [ ] [Can anyone help with this cybersecurity challenge](https://www.reddit.com/r/ReverseEngineering/comments/1m66zul/can_anyone_help_with_this_cybersecurity_challenge/) - Malwarebytes - [ ] [Startup takes personal data stolen by malware and sells it on to other companies](https://www.malwarebytes.com/blog/news/2025/07/startup-takes-personal-data-stolen-by-malware-and-sells-it-on-to-other-companies) - [ ] [‘Car crash victim’ calls mother for help and $15K bail money. But it’s an AI voice scam](https://www.malwarebytes.com/blog/news/2025/07/car-crash-victim-calls-mother-for-help-and-15k-bail-money-but-its-an-ai-voice-scammer) - Exploit-DB.com RSS Feed - [ ] [[webapps] LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Department Assignment Alias Nick Field](https://www.exploit-db.com/exploits/52381) - [ ] [[webapps] LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via the Chat Transfer Function](https://www.exploit-db.com/exploits/52380) - [ ] [[webapps] LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Personal Canned Messages](https://www.exploit-db.com/exploits/52379) - [ ] [[webapps] LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Facebook Integration Page Name Field](https://www.exploit-db.com/exploits/52378) - [ ] [[webapps] LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Operator Surname](https://www.exploit-db.com/exploits/52377) - [ ] [[webapps] LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Telegram Bot Username](https://www.exploit-db.com/exploits/52376) - [ ] [[webapps] Discourse 3.1.1 - Unauthenticated Chat Message Access](https://www.exploit-db.com/exploits/52375) - [ ] [[remote] Tenda FH451 1.0.0.9 Router - Stack-based Buffer Overflow](https://www.exploit-db.com/exploits/52374) - [ ] [[webapps] Joomla JS Jobs plugin 1.4.2 - SQL injection](https://www.exploit-db.com/exploits/52373) - [ ] [[remote] Microsoft Edge Windows 10 Version 1511 - Cross Site Scripting (XSS)](https://www.exploit-db.com/exploits/52372) - [ ] [[webapps] Simple File List WordPress Plugin 4.2.2 - File Upload to RCE](https://www.exploit-db.com/exploits/52371) - [ ] [[webapps] Pie Register WordPress Plugin 3.7.1.4 - Authentication Bypass to RCE](https://www.exploit-db.com/exploits/52370) - 奇客Solidot–传递最新科技情报 - [ ] [乐观主义者是相似的但悲观主义者是不同的](https://www.solidot.org/story?sid=81862) - [ ] [Firefox 141 释出](https://www.solidot.org/story?sid=81861) - [ ] [科学家利用月球土壤取水](https://www.solidot.org/story?sid=81860) - [ ] [參宿四发现有一颗小伴星](https://www.solidot.org/story?sid=81859) - [ ] [Replit 删除生产数据库,伪造数据以隐藏 bug](https://www.solidot.org/story?sid=81858) - [ ] [OpenAI 和 Google DeepMind 先后宣称他们的 AI 模型在国际数学奥林匹克竞赛中取得金牌成绩](https://www.solidot.org/story?sid=81857) - [ ] [NASA X-59 Quess 低音爆超音速飞机开始滑行测试](https://www.solidot.org/story?sid=81856) - [ ] [弱密码导致一家没有备份的 158 年英国公司倒闭](https://www.solidot.org/story?sid=81855) - [ ] [研究发现四天工作制显著提升幸福感](https://www.solidot.org/story?sid=81854) - [ ] [英国考虑对苹果 iCloud 加密后门的要求做出让步](https://www.solidot.org/story?sid=81853) - [ ] [微软和法国合作创造数字版巴黎圣母院](https://www.solidot.org/story?sid=81852) - HackerNews - [ ] [德州 TADTS 数据泄露,约 75 万个人信息被非法获取](https://hackernews.cc/archives/59862) - [ ] [Dior 开始向美国客户发送数据泄露通知](https://hackernews.cc/archives/59860) - Checkmarx - [ ] [The Risks of LLM Poisoning in AI-Powered Development and How to Mitigate Them](https://checkmarx.com/ai-llm-tools-in-application-security/the-risks-of-llm-poisoning-in-ai-powered-development-and-how-to-mitigate-them/) - 安全分析与研究 - [ ] [捆绑某VPN安装程序红队测试样本分析](https://mp.weixin.qq.com/s?__biz=MzA4ODEyODA3MQ==&mid=2247492866&idx=1&sn=41ad71f22d691849da67f0f28404c3aa) - 雷神众测 - [ ] [雷神众测漏洞周报2025.7.14-2025.7.20](https://mp.weixin.qq.com/s?__biz=MzI0NzEwOTM0MA==&mid=2652503474&idx=1&sn=7a175af68c7e327480511d253fc5abe6) - 微步在线研究响应中心 - [ ] [漏洞通告 | Microsoft SharePoint 远程代码执行漏洞](https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&mid=2247507856&idx=1&sn=9eafe16d62fadfec22ce1e8d612164b1) - 代码卫士 - [ ] [微软紧急修复正遭利用的 SharePoint RCE 0day漏洞](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247523622&idx=1&sn=c4eb0888b2daa2d7906fdc8f6b53d8cf) - [ ] [热门包被用于窃取项目维护者的 npm 令牌](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247523622&idx=2&sn=a339537d6df2b01b09323d75ceb041cb) - 威努特安全网络 - [ ] [威努特超融合系统解决方案,重塑高校数据中心云化架构](https://mp.weixin.qq.com/s?__biz=MzAwNTgyODU3NQ==&mid=2651134472&idx=1&sn=9972c49384baeaae258ced0da8caffaa) - 腾讯安全威胁情报中心 - [ ] [SharePoint 漏洞简报(CVE-2025-53770)](https://mp.weixin.qq.com/s?__biz=MzI5ODk3OTM1Ng==&mid=2247510575&idx=1&sn=2ae5471d69e47e606bd4141d7b1ada2c) - [ ] [【重保情报资讯】2025-07-21](https://mp.weixin.qq.com/s?__biz=MzI5ODk3OTM1Ng==&mid=2247510575&idx=2&sn=9bfa86fa8ed7278147415a0c6f3d9e84) - 吾爱破解论坛 - [ ] [暑假开放注册四小时共注册22548人,没有激活的同学请尽快激活啦,发帖前请认真阅读注册须知和总版规,防止违规封号注销。 刚加入的同学请经常登录并保持活跃(注意:签到不算活跃,只有发帖或回帖才算,这句话很重要),避免没活跃被清理,参与到论坛交流中来,对于给予帮助你的人加热心和论坛币,做一个热心受欢迎的人。 错过的同学可以“星标”公众号等待下次开放注册通知。](https://mp.weixin.qq.com/s?__biz=MjM5Mjc3MDM2Mw==&mid=2651142784&idx=1&sn=6aa30e5139b793923c942ac72e21c7ec) - 奇安信威胁情报中心 - [ ] [Chrome 在野 0day CVE-2025-6554 浅析](https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247515391&idx=1&sn=c7106be4cceef2d65d657bd4ee313993) - 天黑说嘿话 - [ ] [绑定微信功能挖掘的 0-Click 任意账号接管漏洞](https://mp.weixin.qq.com/s?__biz=MzI5NTQ5MTAzMA==&mid=2247484523&idx=1&sn=fd9b5e9523aaff802563938e30e59002) - 威胁棱镜 - [ ] [CrowdStrike 宕机如何溅起水花](https://mp.weixin.qq.com/s?__biz=MzkyMzE5ODExNQ==&mid=2247487819&idx=1&sn=96c600aa1f0db2f75af2a56b8e808771) - 信息安全国家工程研究中心 - [ ] [【二十四节气】大暑 | 汹涌翻云倾骤雨,护得莲香一片晴](https://mp.weixin.qq.com/s?__biz=MzU5OTQ0NzY3Ng==&mid=2247500381&idx=1&sn=e5006db4cfcd933661bc5a607c383463) - 看雪学苑 - [ ] [2025 KCTF 向所有防守方发出邀请!设计硬核题目,解锁 Mac mini 等丰厚奖励](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458597673&idx=1&sn=b065b05e6de0a307082d3fa049e6751a) - [ ] [使用Unidbg模拟执行去除OLLVM-BR混淆](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458597673&idx=2&sn=8559b0138d1940f477ab019e540042fd) - [ ] [World Leaks 勒索团伙声称泄露戴尔1.3TB文件,涉及多区域系统](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458597673&idx=3&sn=8b2fabe847391bb2b9d7b5fb7b9deb53) - 安全研究GoSSIP - [ ] [G.O.S.S.I.P 阅读推荐 2025-07-22 AI安全的日与夜](https://mp.weixin.qq.com/s?__biz=Mzg5ODUxMzg0Ng==&mid=2247500451&idx=1&sn=e6553d27cdae1a7c849b903822b01e6d) - 安全圈 - [ ] [【安全圈】微软测试Windows 11"整盘迁移"功能:数据搬家更便利,但仍有局限](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652070784&idx=1&sn=862304bb941a4c3a07d9f8a5ae3d693d) - [ ] [【安全圈】英美数据安全角力:英国政府或将撤销iCloud"后门"要求](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652070784&idx=2&sn=56c8090abb97b4d92f43696210aef97f) - [ ] [【安全圈】7-Zip 存在两处漏洞,或引发拒绝服务攻击](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652070784&idx=3&sn=c065d3383291c74a450df32ea40c4fc0) - [ ] [【安全圈】NVIDIA 容器工具包被曝高危漏洞:权限提升和任意代码执行](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652070784&idx=4&sn=24b532f0ec23a1ec4ea0d7342a8a4624) - 中国信息安全 - [ ] [专题·原创 | 践行总体国家安全观 全面增强网络安全意识](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664245963&idx=1&sn=94959d584b6d051348c330523ee119a1) - [ ] [专家解读 | 数据流通安全审计和溯源 助力农业数据要素流通——解读《基于数据可信流通设施环境番茄生长模型场景的数据流通案例》](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664245963&idx=2&sn=7ae6b9040b2f80dc498af3bcd40f6173) - [ ] [通知 | 网安标委发布《网络安全标准实践指南——摇一摇广告触发行为安全要求》(附全文)](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664245963&idx=3&sn=235b2a6286aa974b7d265cd932830601) - [ ] [通知 | 《网络安全标准实践指南——扫码点餐个人信息保护要求(征求意见稿)》公开征求意见(附全文)](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664245963&idx=4&sn=3be6bc5c2fd3c3bb8916213df716066f) - [ ] [金融监管总局:关于警惕“职业背债”陷阱的风险提示](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664245963&idx=5&sn=5b38b78e1d0de9e8448e4d0638bb0fa2) - 数世咨询 - [ ] [《全球数据泄露态势月度报告》(2025年6月)| 附下载地址](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247539647&idx=1&sn=0fcd45606a38fa2281733ac9c9e00609) - [ ] [直播预告 | 中国互联网大会大模型安全发展论坛](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247539647&idx=2&sn=c866b1cd7f1702276e40d476634f060a) - dotNet安全矩阵 - [ ] [Microsoft SharePoint 零日漏洞详解与 ysoserial.Net 利用分析](https://mp.weixin.qq.com/s?__biz=MzUyOTc3NTQ5MA==&mid=2247500143&idx=1&sn=156d0461d545373d64808e07ec5a46b1) - [ ] [.NET 安全攻防知识交流社区](https://mp.weixin.qq.com/s?__biz=MzUyOTc3NTQ5MA==&mid=2247500143&idx=2&sn=b68c0144a16369d9f8232c68c98428f3) - [ ] [Sharp4WebCmd 再进化:无需依赖 cmd.exe 从命令到上传,一步到位](https://mp.weixin.qq.com/s?__biz=MzUyOTc3NTQ5MA==&mid=2247500143&idx=3&sn=cc17f2402b224ffd5502afcf281a5ee4) - 青藤云安全 - [ ] [青藤天睿RASP再次发威!捕获E签宝RCE 0day漏洞](https://mp.weixin.qq.com/s?__biz=MzAwNDE4Mzc1NA==&mid=2650850632&idx=1&sn=c8f215d69a3fd121b281540c538e0582) - 慢雾科技 - [ ] [慢雾:面向香港稳定币发行人的智能合约实施指南](https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&mid=2247502759&idx=1&sn=4d4e37f51a4c0752424a1ea39587cb40) - 微步在线 - [ ] [CSOP2025看点 | 清华大学姚星昆:校园网安全闭环治理体系设计和实践](https://mp.weixin.qq.com/s?__biz=MzI5NjA0NjI5MQ==&mid=2650184322&idx=1&sn=8875f844e9cef5920bd35205ec74c026) - 京东安全应急响应中心 - [ ] [第三届CTFCON它来啦!](https://mp.weixin.qq.com/s?__biz=MjM5OTk2MTMxOQ==&mid=2727849460&idx=1&sn=14f9f4e3b7dd901059a341357f3ac4b6) - NOVASEC - [ ] [AI视频,只要发布,就能赚钱,就有收入的一个副业(适合新手)](https://mp.weixin.qq.com/s?__biz=MzUzODU3ODA0MA==&mid=2247490707&idx=1&sn=1d6b18ac28dd273a1ff4854289eef6f0) - 嘶吼专业版 - [ ] [Interlock勒索软件采用新的FileFix攻击方式推送恶意程序](https://mp.weixin.qq.com/s?__biz=MzI0MDY1MDU4MQ==&mid=2247583890&idx=1&sn=917a5a14ba9358abe1a88ac05d96a596) - [ ] [一图读懂 | GB/T 22080-2025《网络安全技术 信息安全管理体系 要求》](https://mp.weixin.qq.com/s?__biz=MzI0MDY1MDU4MQ==&mid=2247583890&idx=2&sn=1a327ad946fd59d7d9456cae4476963d) - 极客公园 - [ ] [首家京东自营外卖门店开业;小宇宙回应多名高管离职;国产新能源车保值率排名发布:SU7 第一 | 极客早知道](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653083215&idx=1&sn=bcabb98397f65c15a437f90ca65929a6) - OPPO安全中心 - [ ] [【活动倒计时10天】遇『7』则翻!还有机会获得7周年2倍翻倍卡!](https://mp.weixin.qq.com/s?__biz=MzUyNzc4Mzk3MQ==&mid=2247494360&idx=1&sn=fd3a10b004270aa2975b666f1a4c1135) - 网安国际 - [ ] [探讨AI安全研究最前沿,InForSec夏令营导师面对面共聚西电,欢迎报名参会!](https://mp.weixin.qq.com/s?__biz=MzA4ODYzMjU0NQ==&mid=2652317823&idx=1&sn=b7fd9fe110c7dab0430e16d6c4dd4b4e) - Beacon Tower Lab - [ ] [【0722】重保演习每日情报汇总](https://mp.weixin.qq.com/s?__biz=MzkyNzcxNTczNA==&mid=2247487668&idx=1&sn=b5933831c0aa1c57ed750837bc730f69) - 吴鲁加 - [ ] [我们在找能全球化运营软件产品的人](https://mp.weixin.qq.com/s?__biz=Mzg5NDY4ODM1MA==&mid=2247485594&idx=1&sn=95b30aa87a1367c19d7eab99ea808b78) - TrustedSec - [ ] [Why is this Finding on my Pentest Report?](https://trustedsec.com/blog/why-is-this-finding-on-my-pentest-report) - 迪哥讲事 - [ ] [AI带你 SQL 注入](https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&mid=2247497922&idx=1&sn=90b6e84d2f5f6e9d5d21a06185c83548) - 复旦白泽战队 - [ ] [数万款小程序存在严重安全隐患,复旦团队推出白泽·鉴微平台,提供免费“安全体检”!](https://mp.weixin.qq.com/s?__biz=MzU4NzUxOTI0OQ==&mid=2247495505&idx=1&sn=098b4dcf46e48506fc2a20fcea92b2e0) - 威胁猎人Threat Hunter - [ ] [【黑产大数据】2025年上半年互联网黑灰产趋势年度总结](https://mp.weixin.qq.com/s?__biz=MzI3NDY3NDUxNg==&mid=2247501077&idx=1&sn=f2d8a348ecd8725bc26aeb8a4539c064) - Arturo Di Corinto - [ ] [Libri consigliati per l’estate del 2025](https://dicorinto.it/articoli/libri-consigliati-per-lestate-del-2025/) - Microsoft Security Blog - [ ] [Disrupting active exploitation of on-premises SharePoint vulnerabilities](https://www.microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities/) - [ ] [Microsoft Sentinel data lake: Unify signals, cut costs, and power agentic AI](https://www.microsoft.com/en-us/security/blog/2025/07/22/microsoft-sentinel-data-lake-unify-signals-cut-costs-and-power-agentic-ai/) - Over Security - Cybersecurity news aggregator - [ ] [Apple alerted Iranians to iPhone spyware attacks, say researchers](https://techcrunch.com/2025/07/22/apple-alerted-iranians-to-iphone-spyware-attacks-say-researchers/) - [ ] [Deobfuscating Android Apps with Androidmeda: A Smarter Way to Read Obfuscated Code](https://www.mobile-hacker.com/2025/07/22/deobfuscating-android-apps-with-androidmeda-a-smarter-way-to-read-obfuscated-code/) - [ ] [FBI urges vigilance against Interlock ransomware group behind recent healthcare attacks](https://therecord.media/fbi-vigilance-interlock-ransomware) - [ ] [Windows 11 gets new Black Screen of Death, auto recovery tool](https://www.bleepingcomputer.com/news/microsoft/windows-11-gets-new-black-screen-of-death-auto-recovery-tool/) - [ ] [Windows 11 KB5062660 update brings new 'Windows Resilience' features](https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5062660-update-brings-new-windows-resilience-features/) - [ ] [Lumma infostealer malware returns after law enforcement disruption](https://www.bleepingcomputer.com/news/security/lumma-infostealer-malware-returns-after-law-enforcement-disruption/) - [ ] [Coyote malware abuses Windows accessibility framework for data theft](https://www.bleepingcomputer.com/news/security/coyote-malware-abuses-windows-accessibility-framework-for-data-theft/) - [ ] [CISA and FBI warn of escalating Interlock ransomware attacks](https://www.bleepingcomputer.com/news/security/cisa-and-fbi-warn-of-escalating-interlock-ransomware-attacks/) - [ ] [UK government wants ransomware victims to report cyberattacks so it can disrupt the hackers](https://techcrunch.com/2025/07/22/uk-government-wants-ransomware-victims-to-report-cyberattacks-so-it-can-disrupt-the-hackers/) - [ ] [Major European healthcare network discloses security breach](https://www.bleepingcomputer.com/news/security/major-european-healthcare-network-discloses-security-breach/) - [ ] [Chinese nation-state groups exploiting SharePoint vulnerability, Microsoft confirms](https://therecord.media/microsoft-sharepoint-vulnerabilities-china-groups-exploiting) - [ ] [The Raspberry Pi's Wi-Fi Glow-Up](https://www.kali.org/blog/raspberry-pi-wi-fi-glow-up/) - [ ] [Cybercrime o spionaggio? Le difficoltà nell’attribuzione delle minacce](https://www.cybersecurity360.it/nuove-minacce/cybercrime-o-spionaggio-le-difficolta-nellattribuzione-delle-minacce/) - [ ] [Attacchi a SharePoint: hacker collegati alla Cina sfruttano la falla ToolShell](https://www.cybersecurity360.it/nuove-minacce/attacchi-a-sharepoint-hacker-collegati-alla-cina-sfruttano-la-falla-toolshell/) - [ ] [Russian-speaking hacker group disrupted by local researchers](https://therecord.media/russia-hacker-group-disrupted-local-researchers) - [ ] [UK to ban public sector orgs from paying ransomware gangs](https://www.bleepingcomputer.com/news/security/uk-to-ban-public-sector-orgs-from-paying-ransomware-gangs/) - [ ] [Cisco: Maximum-severity ISE RCE flaws now exploited in attacks](https://www.bleepingcomputer.com/news/security/cisco-maximum-severity-ise-rce-flaws-now-exploited-in-attacks/) - [ ] [UK moves forward with plans for mandatory reporting of ransomware attacks](https://therecord.media/mandatory-reporting-ransomware-attacks-uk-proposal) - [ ] [UK Identifies Russian GRU’s “AUTHENTIC ANTICS” Malware in Email Espionage Campaign](https://cyble.com/blog/uk-exposes-authentic-antics-malware-campaign/) - [ ] [Hungarian police arrest suspect in cyberattacks on independent media](https://therecord.media/hungary-arrest-suspect-hacking-independent-media) - [ ] [Microsoft Sharepoint ToolShell attacks linked to Chinese hackers](https://www.bleepingcomputer.com/news/security/microsoft-sharepoint-toolshell-attacks-linked-to-chinese-hackers/) - [ ] [Turn Alert Noise into Threat Insights without Leaving QRadar SOAR with ANY.RUN](https://any.run/cybersecurity-blog/ibm-qradar-soar-anyrun-integration/) - [ ] [Attacco ToolShell a Sharepoint: i criminali hanno iniziato usarlo almeno dal 7 luglio](https://www.securityinfo.it/2025/07/22/attacco-toolshell-a-sharepoint-i-criminali-hanno-iniziato-usarlo-almeno-dal-7-luglio/) - [ ] [Cyber spionaggio, Russia contro aziende di logistica e tecnologia che aiutano l’Ucraina](https://www.cybersecurity360.it/nuove-minacce/cyber-spionaggio-russia-contro-aziende-di-logistica-e-tecnologia-che-aiutano-lucraina/) - [ ] [Microsoft: Windows Server KB5062557 causes cluster, VM issues](https://www.bleepingcomputer.com/news/microsoft/microsoft-windows-server-kb5062557-causes-cluster-vm-issues/) - [ ] [Fraud-Proof Your Security: How BioConfirm Protects iGaming Platforms and Players](https://www.group-ib.com/blog/bioconfirm-security/) - [ ] [La cyber security è democratica: multinazionali e casalinghe colpiti dallo stesso virus](https://www.cybersecurity360.it/cultura-cyber/la-cyber-security-e-democratica-multinazionali-e-casalinghe-colpiti-dallo-stesso-virus/) - [ ] [APT41, il gruppo cinese amplia il raggio d’azione in Africa](https://www.securityinfo.it/2025/07/22/apt41-il-gruppo-cinese-amplia-il-raggio-dazione-in-africa/) - [ ] [Difendere lo spazio: la sicurezza fisica come fondamento della resilienza digitale](https://www.cybersecurity360.it/soluzioni-aziendali/difendere-lo-spazio-la-sicurezza-fisica-come-fondamento-della-resilienza-digitale/) - [ ] [Australian Cyber Security Centre Warns of an Active Exploit Taking Advantage of Microsoft SharePoint Vulnerability CVE-2025-53770](https://cyble.com/blog/acsc-warns-of-cve-2025-53770/) - SANS Internet Storm Center, InfoCON: green - [ ] [WinRAR MoTW Propagation Privacy, (Tue, Jul 22nd)](https://isc.sans.edu/diary/rss/32130) - [ ] [Wireshark 4.4.8 Released, (Tue, Jul 22nd)](https://isc.sans.edu/diary/rss/32128) - [ ] [ISC Stormcast For Tuesday, July 22nd, 2025 https://isc.sans.edu/podcastdetail/9536, (Tue, Jul 22nd)](https://isc.sans.edu/diary/rss/32132) - ICT Security Magazine - [ ] [Israele e le campagne ADV su YouTube: come distorcere il racconto della guerra a Gaza a colpi di propaganda digitale](https://www.ictsecuritymagazine.com/notizie/israele-guerra-a-gazza/) - [ ] [Cybercrisi 2025 e anatomia di una crisi nazionale – L’Italia nell’epicentro della guerra cyber globale](https://www.ictsecuritymagazine.com/articoli/cybercrisi-2025-italia/) - [ ] [Rust e Go: la nuova frontiera del malware](https://www.ictsecuritymagazine.com/articoli/rust-malware/) - 安全419 - [ ] [网安企业探营|带你走进龙脉数安](https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&mid=2247549070&idx=1&sn=b5c3428659bac79163083e8008395b4a) - [ ] [AI驱动的恶意软件攻防战:企业如何利用代码审计与组件检测先发制人?](https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&mid=2247549070&idx=2&sn=78000e7232dbba90e791e8fd1cb8d725) - Securityinfo.it - [ ] [Attacco ToolShell a Sharepoint: i criminali hanno iniziato usarlo almeno dal 7 luglio](https://www.securityinfo.it/2025/07/22/attacco-toolshell-a-sharepoint-i-criminali-hanno-iniziato-usarlo-almeno-dal-7-luglio/?utm_source=rss&utm_medium=rss&utm_campaign=attacco-toolshell-a-sharepoint-i-criminali-hanno-iniziato-usarlo-almeno-dal-7-luglio) - [ ] [APT41, il gruppo cinese amplia il raggio d’azione in Africa](https://www.securityinfo.it/2025/07/22/apt41-il-gruppo-cinese-amplia-il-raggio-dazione-in-africa/?utm_source=rss&utm_medium=rss&utm_campaign=apt41-il-gruppo-cinese-amplia-il-raggio-dazione-in-africa) - Schneier on Security - [ ] [“Encryption Backdoors and the Fourth Amendment”](https://www.schneier.com/blog/archives/2025/07/encryption-backdoors-and-the-fourth-amendment.html) - The Register - Security - [ ] [Funding for program to stop next Stuxnet from hitting US expired Sunday](https://go.theregister.com/feed/www.theregister.com/2025/07/22/lapsed_cisa_funding_cybersentry/) - [ ] [Arch Linux users told to purge Firefox forks after AUR malware scare](https://go.theregister.com/feed/www.theregister.com/2025/07/22/arch_aur_browsers_compromised/) - [ ] [Surprise, surprise: Chinese spies, IP stealers, other miscreants attacking Microsoft SharePoint servers](https://go.theregister.com/feed/www.theregister.com/2025/07/22/chinese_groups_attacking_microsoft_sharepoint/) - [ ] [Silicon Valley engineer admits theft of US missile tech secrets](https://go.theregister.com/feed/www.theregister.com/2025/07/22/engineer_admits_trade_theft/) - [ ] [Humans can be tracked with unique 'fingerprint' based on how their bodies block Wi-Fi signals](https://go.theregister.com/feed/www.theregister.com/2025/07/22/whofi_wifi_identifier/) - [ ] [Microsoft patches critical SharePoint 2016 zero-days amid active exploits](https://go.theregister.com/feed/www.theregister.com/2025/07/22/microsoft_sharepoint_2016_patch/) - [ ] [UK to ban ransomware payments by public sector organizations](https://go.theregister.com/feed/www.theregister.com/2025/07/22/uk_to_ban_ransomware_payments/) - [ ] [Open source's superior security is a matter of eyeballs: Be kind to the brains behind them](https://go.theregister.com/feed/www.theregister.com/2025/07/22/open_source_windows_security_opinion_column/) - Graham Cluley - [ ] [The AI Fix #60: Elon’s AI girlfriend, the arsonist red panda, and the AI that will kill you](https://grahamcluley.com/the-ai-fix-60/) - TorrentFreak - [ ] [Pirate Service ‘MagisTV’ Fails to Secure U.S. Trademark, Faces Malware Backlash](https://torrentfreak.com/pirate-service-magistv-fails-to-secure-u-s-trademark-faces-malware-backlash/) - Security Affairs - [ ] [Cisco confirms active exploitation of ISE and ISE-PIC flaws](https://securityaffairs.com/180260/hacking/cisco-confirms-active-exploitation-of-ise-and-ise-pic-flaws.html) - [ ] [SharePoint under fire: new ToolShell attacks target enterprises](https://securityaffairs.com/180252/hacking/sharepoint-under-fire-new-toolshell-attacks-target-enterprises.html) - [ ] [CrushFTP zero-day actively exploited at least since July 18](https://securityaffairs.com/180244/hacking/crushftp-zero-day-actively-exploited-at-least-since-july-18.html) - [ ] [Hardcoded credentials found in HPE Aruba Instant On Wi-Fi devices](https://securityaffairs.com/180230/security/hardcoded-credentials-hpe-aruba-instant-on-wi-fi-devices.html) - Troy Hunt's Blog - [ ] [11 Years of Microsoft Regional Director and 15 Years of MVP](https://www.troyhunt.com/11-years-of-microsoft-regional-director-and-15-years-of-mvp/) - Deeplinks - [ ] [We're Envisioning A Better Future](https://www.eff.org/deeplinks/2025/07/future-worth-fighting) - The Hacker News - [ ] [Microsoft Links Ongoing SharePoint Exploits to Three Chinese Hacker Groups](https://thehackernews.com/2025/07/microsoft-links-ongoing-sharepoint.html) - [ ] [Cisco Confirms Active Exploits Targeting ISE Flaws Enabling Unauthenticated Root Access](https://thehackernews.com/2025/07/cisco-confirms-active-exploits.html) - [ ] [Credential Theft and Remote Access Surge as AllaKore, PureRAT, and Hijack Loader Proliferate](https://thehackernews.com/2025/07/credential-theft-and-remote-access.html) - [ ] [How to Advance from SOC Manager to CISO?](https://thehackernews.com/2025/07/how-to-advance-from-soc-manager-to-ciso.html) - [ ] [Hackers Exploit SharePoint Zero-Day Since July 7 to Steal Keys, Maintain Persistent Access](https://thehackernews.com/2025/07/hackers-exploit-sharepoint-zero-day.html) - Information Security - [ ] [Offered to help a small defense contractor with CMMC docs — ended up making a free starter kit](https://www.reddit.com/r/Information_Security/comments/1m6sl75/offered_to_help_a_small_defense_contractor_with/) - [ ] [Weekly Cybersecurity News Summary - 21/07/2025](https://www.reddit.com/r/Information_Security/comments/1m654a6/weekly_cybersecurity_news_summary_21072025/) - 安全村SecUN - [ ] [一项重点工作的里程碑总结](https://mp.weixin.qq.com/s?__biz=MzkyODM5NzQwNQ==&mid=2247496863&idx=1&sn=bb5590ccb1c864ac7420d71fa238ada2) - Kali Linux - [ ] [The Raspberry Pi's Wi-Fi Glow-Up](https://www.kali.org/blog/raspberry-pi-wi-fi-glow-up/) - Your Open Hacker Community - [ ] [My files are stuck in a damn cloud with pay wall](https://www.reddit.com/r/HowToHack/comments/1m6700d/my_files_are_stuck_in_a_damn_cloud_with_pay_wall/) - [ ] [alfa AWUS036H problem](https://www.reddit.com/r/HowToHack/comments/1m623ds/alfa_awus036h_problem/) - Palo Alto Networks Blog - [ ] [How Apps and Your Phone Can Expose Your Life Without Permission](https://www.paloaltonetworks.com/blog/2025/07/apps-and-your-phone-expose-your-life/) - Instapaper: Unread - [ ] [Surveillance Firm Bypasses SS7 Protections to Retrieve User Location](https://www.securityweek.com/surveillance-firm-bypasses-ss7-protections-to-retrieve-user-location/) - netsecstudents: Subreddit for students studying Network Security and its related subjects - [ ] [Transitioning from Fraud Systems to CyberThreat Analyst - Looking for Advice/Resources](https://www.reddit.com/r/netsecstudents/comments/1m6s55k/transitioning_from_fraud_systems_to_cyberthreat/) - [ ] [College search in Moscow](https://www.reddit.com/r/netsecstudents/comments/1m6t4cs/college_search_in_moscow/) - [ ] [What would be a good cybersecurity workshop topic for tech savvy students?](https://www.reddit.com/r/netsecstudents/comments/1m65yqd/what_would_be_a_good_cybersecurity_workshop_topic/) - [ ] [Level up your red teaming skills at AltSecCON 2025](https://www.reddit.com/r/netsecstudents/comments/1m66tl8/level_up_your_red_teaming_skills_at_altseccon_2025/) - Deep Web - [ ] [is fraud on dark matter legit?](https://www.reddit.com/r/deepweb/comments/1m61r7q/is_fraud_on_dark_matter_legit/) - Trend Micro Research, News and Perspectives - [ ] [Proactive Security and Insights for SharePoint Attacks (CVE-2025-53770 and CVE-2025-53771)](https://www.trendmicro.com/en_us/research/25/g/cve-2025-53770-and-cve-2025-53771-sharepoint-attacks.html) - [ ] [Back to Business: Lumma Stealer Returns with Stealthier Methods](https://www.trendmicro.com/en_us/research/25/g/lumma-stealer-returns.html) - Technical Information Security Content & Discussion - [ ] ["Reverse Engineering Security Products: Developing an Advanced Tamper Tradecraft" held in BlackHat MEA 2024](https://www.reddit.com/r/netsec/comments/1m6e889/reverse_engineering_security_products_developing/) - [ ] [How We Accidentally Discovered a Remote Code Execution Vulnerability in ETQ Reliance](https://www.reddit.com/r/netsec/comments/1m68fuh/how_we_accidentally_discovered_a_remote_code/) - [ ] [Autofill Phishing: The Silent Scam That Nobody Warned You About](https://www.reddit.com/r/netsec/comments/1m6gtpt/autofill_phishing_the_silent_scam_that_nobody/) - Computer Forensics - [ ] [IOS 18 requiring FaceID for Creating an Encrypted iTunes Backup](https://www.reddit.com/r/computerforensics/comments/1m6o6rz/ios_18_requiring_faceid_for_creating_an_encrypted/) - Dark Space Blogspot - [ ] [Quali Sono Le Differenze Tra ETF, ETC ed ETN?](http://darkwhite666.blogspot.com/2025/07/quali-sono-le-differenze-tra-etf-etc-ed.html) - Security Weekly Podcast Network (Audio) - [ ] [Donatello, SharePoint, CrushFTP, WordPress, Replit, AllaKore, Rob Allen, and more... - Rob Allen - SWN #496](http://sites.libsyn.com/18678/donatello-sharepoint-crushftp-wordpress-replit-allakore-rob-allen-and-more-rob-allen-swn-496) - [ ] [Rise of Compromised LLMs - Sohrob Kazerounian - ASW #340](http://sites.libsyn.com/18678/rise-of-compromised-llms-sohrob-kazerounian-asw-340)
每日安全资讯(2025-07-23)
刚加入的同学请经常登录并保持活跃(注意:签到不算活跃,只有发帖或回帖才算,这句话很重要),避免没活跃被清理,参与到论坛交流中来,对于给予帮助你的人加热心和论坛币,做一个热心受欢迎的人。
错过的同学可以“星标”公众号等待下次开放注册通知。](https://mp.weixin.qq.com/s?__biz=MjM5Mjc3MDM2Mw==&mid=2651142784&idx=1&sn=6aa30e5139b793923c942ac72e21c7ec)