# 每日安全资讯(2026-04-01) - SecWiki News - [ ] [SecWiki News 2026-03-31 Review](http://www.sec-wiki.com/?2026-03-31) - Private Feed for M09Ic - [ ] [strands-agents released v1.34.0 at strands-agents/sdk-python](https://github.com/strands-agents/sdk-python/releases/tag/v1.34.0) - [ ] [4ra1n starred Ta0ing/claude-code_evil](https://github.com/Ta0ing/claude-code_evil) - [ ] [CHYbeta starred claude-code-best/claude-code](https://github.com/claude-code-best/claude-code) - [ ] [INotGreen starred AndreamBot/claude-code-minimax](https://github.com/AndreamBot/claude-code-minimax) - [ ] [INotGreen forked INotGreen/claude-code from instructkr/claw-code](https://github.com/INotGreen/claude-code) - [ ] [zema1 starred coder/websocket](https://github.com/coder/websocket) - [ ] [Wh0ale starred 0x727/BypassPro](https://github.com/0x727/BypassPro) - [ ] [WAY29 starred lupantech/AgentFlow](https://github.com/lupantech/AgentFlow) - [ ] [IC3-CR3AM forked IC3-CR3AM/claude-code-source-code from sanbuphy/claude-code-source-code](https://github.com/IC3-CR3AM/claude-code-source-code) - [ ] [IC3-CR3AM starred TheTom/turboquant_plus](https://github.com/TheTom/turboquant_plus) - [ ] [Mel0day forked Mel0day/claude-mem from thedotmack/claude-mem](https://github.com/Mel0day/claude-mem) - [ ] [Mel0day starred thedotmack/claude-mem](https://github.com/thedotmack/claude-mem) - [ ] [ring04h starred instructkr/claw-code](https://github.com/instructkr/claw-code) - [ ] [esrrhs starred instructkr/claw-code](https://github.com/instructkr/claw-code) - [ ] [Ascotbe forked Ascotbe/claude-code-sourcemap from ChinaSiro/claude-code-sourcemap](https://github.com/Ascotbe/claude-code-sourcemap) - [ ] [PrefectHQ released 3.6.25.dev4 at PrefectHQ/prefect](https://github.com/PrefectHQ/prefect/releases/tag/3.6.25.dev4) - Recent Commits to cve:main - [ ] [Update Tue Mar 31 11:21:30 UTC 2026](https://github.com/trickest/cve/commit/7bd72525da243dc31050423e5f990bb189bc5101) - Doonsec's feed - [ ] [Linux SSH密码爆破脚本,从原理到实践](https://mp.weixin.qq.com/s/HT05-3l6jtoKe48_J8B3Ug) - [ ] [从模板到提交到管理POC:VSCode 插件简化 POC 全流程](https://mp.weixin.qq.com/s/euKnHxD0p2cX9fpmmQWxPw) - [ ] [从新闻巨头到数据经纪商:路透社母公司数据接入Palantir系统](https://mp.weixin.qq.com/s/0IijLYDp9GI7oNfZBVgEfg) - [ ] [AI 直接调用 Kali 工具链:MCP实现60+ Kali 工具的调用](https://mp.weixin.qq.com/s/kVF9GB0R6x6r_9hDZCzapQ) - [ ] [ClaudeCode源码泄露,我解除了限制](https://mp.weixin.qq.com/s/v7-WjsSL8T7Fj8Bn7nqHGw) - [ ] [从零开始学习 AI安全实战特训营(第一期)](https://mp.weixin.qq.com/s/UDqBWVn_5GgkzKc-AqhWlg) - [ ] [以色列国防部长电话本](https://mp.weixin.qq.com/s/Jh82zS_LX-Ip-V6EI2uvfw) - [ ] [Axios遭遇“指令闪击”——npm仓库OrDer木马投毒事件分析](https://mp.weixin.qq.com/s/m3bWIoagNeuV9c_jI3Ez5A) - [ ] [“冰城虾友 技术沙龙” 哈工大专场倒计时1天](https://mp.weixin.qq.com/s/TzMHmsUj3hV5055S7uW7ZQ) - [ ] [黑龙江省委党校进修班学员再次走进安天 现场教学悟实干践担当](https://mp.weixin.qq.com/s/gWHU90PZLFivHGTaoGzHbQ) - [ ] [威胁通缉令 · 红桃4丨RDP Client RCE漏洞(新增)](https://mp.weixin.qq.com/s/jDqCPbON8fWbhzJYALrQ4w) - [ ] [喜报!警大 ISA 信息安全协会斩获第三届 “数信杯” 团队赛金奖!](https://mp.weixin.qq.com/s/8B-Lg-jSN93jy5N5w04oWw) - [ ] [OpenViking:专为AI Agent打造的长期记忆数据库](https://mp.weixin.qq.com/s/4TPIxnyRLi0a-2tedhNo2A) - [ ] [Patch白文件绕过360免杀fscan扫描工具](https://mp.weixin.qq.com/s/R6_19BqBXUVQMJr1DgOnmg) - [ ] [扒光Claude\"衣服\"](https://mp.weixin.qq.com/s/4KHX_oI4_GHgsuSsR-6WOQ) - [ ] [2026 DesCTF网络安全挑战赛 官方WP](https://mp.weixin.qq.com/s/7KTABvSr1LsAngT6EbTubQ) - [ ] [看完claude code源码以后,我绕过了cc的道德限制](https://mp.weixin.qq.com/s/MbPHMIIBfCmzhjvunN62nA) - [ ] [突发!Claude Code 51万行源码泄露,AI编程工具被扒光xa0](https://mp.weixin.qq.com/s/t9iJPV7-EGaCZJ7ONkYz9A) - [ ] [华为2025财报:营收8809亿,利润680亿](https://mp.weixin.qq.com/s/SbuKHAEfj_pQWj3Ne1EIFQ) - [ ] [Claude Code开源了!代码简化Agent官方开源](https://mp.weixin.qq.com/s/WKCl4wgacA_ukoGI902Z1w) - [ ] [OAuth详解](https://mp.weixin.qq.com/s/1HPNw7jplkmkz1SpYTXexw) - [ ] [Claude Code 51万行源码全网裸奔!Anthropic:我们终于成了“真·Open Claude”](https://mp.weixin.qq.com/s/joOfXGJkuXmXdR1jtN0jGw) - [ ] [云影安全实验室 | 深度复盘:Anthropic Claude Code 源码泄露事件](https://mp.weixin.qq.com/s/4mKVw6M6rvOgP6BciZlIig) - [ ] [看不见的崩塌:前沿大模型的内部安全隐患](https://mp.weixin.qq.com/s/M7TZXORfrW19NO5X9hn2pQ) - [ ] [TA446 在针对性鱼叉式网络钓鱼活动中部署 DarkSword iOS 漏洞套件](https://mp.weixin.qq.com/s/hvxxw4AzXAQo-HAZuBZZ7g) - [ ] [目前运行核电机组共62台](https://mp.weixin.qq.com/s/PbcydcmtIHil_NWw4xbkKw) - [ ] [别让“机密”裸奔!手把手教你设计“大小模型协同”的 LLM 隐私防火墙](https://mp.weixin.qq.com/s/-Hwgr9dMc1iUghdgoKfeIQ) - [ ] [Axios npm 供应链攻击深度分析报告](https://mp.weixin.qq.com/s/8J95hWsvAaLNPBbSQAqpeg) - [ ] [量子韧性金融:香港金融业的下一前沿阵地](https://mp.weixin.qq.com/s/H6YeyojY9V-o-S0wuXmG3Q) - [ ] [CertiK发布OpenClaw安全报告:复盘AI智能体快速增长下的安全逻辑缺陷(附安全指南)](https://mp.weixin.qq.com/s/s7lhfSG0eDW5YsGLbI2gvQ) - [ ] [Claude Code 又翻车了:一场源码泄露,撕开了 AI Agent 最隐秘的底层逻辑](https://mp.weixin.qq.com/s/tTzb4qAuJ9C2hIUJzwhAAQ) - [ ] [一句话让 AI 挖出两个编辑器零日漏洞](https://mp.weixin.qq.com/s/9wTCdNYmx7alu_YelzwMyw) - [ ] [Claude Code 源码泄露? Github瞬间20K STAR(附项目地址)](https://mp.weixin.qq.com/s/cPN-ZgCc0xSvygdbKZzOtg) - [ ] [因酷教育软件 queryUserById 信息泄露漏洞](https://mp.weixin.qq.com/s/nA6_ieBzRf85s6rCULDHIQ) - [ ] [字节32岁员工:职级3-1,考公中央部委,工资打一折](https://mp.weixin.qq.com/s/zCynxC-YYzLsXo7Ly9l54A) - [ ] [Claude code源码泄露的情况](https://mp.weixin.qq.com/s/zgUQQb4ssErhVg7pPGd8vA) - [ ] [这次泄露里暴露出来的Claude Code 架构(Agent + Tool + Prompt)到底是怎么设计的](https://mp.weixin.qq.com/s/9zuBlFdJrSWB4q6yA6klcw) - [ ] [自主研发即将迎来一波爆发期🤔](https://mp.weixin.qq.com/s/q2OVBCtyPrcxVSPCM-A2jw) - [ ] [关于半决赛各赛区一二三等奖获奖队伍名单的公示](https://mp.weixin.qq.com/s/KP-v_SuuGyqCe30A9XQt-Q) - [ ] [新思路!支付漏洞实战案例分享:低价薅高价商品](https://mp.weixin.qq.com/s/cWFZTGjWa1kNJ2ZJuT96SA) - [ ] [高薪安全实习机会](https://mp.weixin.qq.com/s/ZWYpraq5GWyCeXvfoxcdhQ) - [ ] [G.O.S.S.I.P 特别推荐 2026-03-31 QCP 2.0来了!](https://mp.weixin.qq.com/s/RiizTLwc3qnmKG0e1tagBQ) - [ ] [龙信天眼介质取证系统LX-A300 V6.5双版同步升级,国产持平Windows!](https://mp.weixin.qq.com/s/eKwevX6-567q-olF_QJD_g) - [ ] [重要提醒!9月PMP现行考纲最后一次考试!](https://mp.weixin.qq.com/s/PZg8iYkekK1rqsvP22VPbw) - [ ] [安全养虾日记:完全离线部署OpenClaw(内附详细搭建步骤)](https://mp.weixin.qq.com/s/pMZF42A3YLZ9WbS8dfRr_g) - [ ] [滴滴多篇成果入选CVPR 2026,产学研协同创新结硕果](https://mp.weixin.qq.com/s/rKM3gJfjWnOEjiqgP9Enog) - [ ] [【全球狂欢】ClaudeCode泄露51.2万行源码](https://mp.weixin.qq.com/s/ganyolL6THT_O30BAD2vWw) - [ ] [AI时代,安全人员的核心是什么?该如何平衡 AI 的分析能力与人自身的决策价值?](https://mp.weixin.qq.com/s/Dz8ZXf6bUyxdv_2kV3zQow) - [ ] [从员工到智能体,RedKernel 构建企业 AI 风险全景防线](https://mp.weixin.qq.com/s/0RntbimYAZ910MGrfVXx7g) - [ ] [免费赠送 | 防范网络电信诈骗宣传素材(第二十一期)](https://mp.weixin.qq.com/s/MJOiN_5Xsg_NxF9e9r8vDA) - [ ] [第159篇:原创工具-WiFi弱口令审计与暴力猜解工具 v0.25](https://mp.weixin.qq.com/s/8yRanj6Hg1qglX81-PJ3rg) - [ ] [你的备份安全吗?](https://mp.weixin.qq.com/s/pb5HxeKSZesYPeXmNz5W9w) - [ ] [Axios npm供应链攻击威胁分析报告](https://mp.weixin.qq.com/s/vEdfRB0iKon0uMXOdfxb-Q) - [ ] [169元,手搓跑在 ESP32 上的嵌入式 AI 机器人套件,真正实现边缘人工智能Edge AI](https://mp.weixin.qq.com/s/_WkMRqlavZd7tQwflgC32Q) - [ ] [CareCloud 数据泄露事件——黑客入侵 IT 基础设施并窃取患者数据](https://mp.weixin.qq.com/s/cWi1T3JhBSJ7Z6C2mUS0lA) - [ ] [ChatGPT漏洞允许攻击者静默窃取用户提示和其他敏感数据](https://mp.weixin.qq.com/s/H7cmOrQrOSS0okqLPRL5Ow) - [ ] [国资使命,青春启航——中资网安2026春季校招等你加入!](https://mp.weixin.qq.com/s/dv-Jk55WW67o7bDzvCE92g) - [ ] [【公开招募】信创数智评估价值升级 赛迪认证公开招募合作伙伴](https://mp.weixin.qq.com/s/P-oSr_L271d5eZIi50oEZQ) - [ ] [WordPress插件漏洞导致超过80万个网站的敏感数据泄露](https://mp.weixin.qq.com/s/6AoUwPytQ979s4LptEdfLQ) - [ ] [【安全圈】小米新推出的输入法工具直接暴露AI模型密钥](https://mp.weixin.qq.com/s/55W-LITXl8b14_WamLUpXg) - [ ] [【安全圈】360漏洞挖掘智能体发现OpenClaw高危漏洞,或波及全球17万实例](https://mp.weixin.qq.com/s/9cYnq44HEq2P8qbIp9Lqhw) - [ ] [【安全圈】上海电信大规模断网,官方:宽带正常升级导致](https://mp.weixin.qq.com/s/GMf2CAi9Z5SRoig7QVzxAw) - [ ] [【安全事件】axios前端库npm供应链投毒预警通告](https://mp.weixin.qq.com/s/8XnfHONr9xHj5hmmqApe9A) - 嘶吼 RoarTalk – 网络安全行业综合服务平台,4hou.com - [ ] [VoidStealer恶意软件利用调试器漏洞窃取Chrome主密钥](https://www.4hou.com/posts/0MlN) - [ ] [嘶吼安全动态|全国网安标委发布关于征集个人信息保护标准应用实践案例的通知 AI工作流工具Langflow曝未授权RCE漏洞](https://www.4hou.com/posts/l0Kj) - Zgao's blog - [ ] [OpenVPN 恶意DNS告警反查 VPN 客户端](https://zgao.top/openvpn-%e6%81%b6%e6%84%8f-dns-%e5%91%8a%e8%ad%a6%e5%8f%8d%e6%9f%a5-vpn-%e5%ae%a2%e6%88%b7%e7%ab%af/) - CXSECURITY Database RSS Feed - CXSecurity.com - [ ] [FreeScout Unauthenticated RCE via ZWSP .htaccess Bypass](https://cxsecurity.com/issue/WLB-2026030038) - [ ] [Wavlink WL-WN579X3-C firewall.cgi UPNP Stack-based Buffer Overflow](https://cxsecurity.com/issue/WLB-2026030037) - bunnie's blog - [ ] [Name that Ware, March 2026](https://www.bunniestudios.com/blog/2026/name-that-ware-march-2026/) - [ ] [Winner, Name that Ware February 2026](https://www.bunniestudios.com/blog/2026/winner-name-that-ware-february-2026/) - Chromium Blog - [ ] [JetStream 3: A modern benchmark for high-performance, compute-intensive Web applications](http://blog.chromium.org/2026/03/jetstream-3-a-modern-benchmark.html) - Microsoft Security Blog - [ ] [The threat to critical infrastructure has changed. Has your readiness?](https://www.microsoft.com/en-us/security/security-insider/threat-landscape/threat-to-critical-infrastructure-has-changed) - [ ] [Applying security fundamentals to AI: Practical advice for CISOs](https://www.microsoft.com/en-us/security/blog/2026/03/31/applying-security-fundamentals-to-ai-practical-advice-for-cisos/) - [ ] [WhatsApp malware campaign delivers VBScript and MSI backdoors](https://www.microsoft.com/en-us/security/blog/2026/03/31/whatsapp-malware-campaign-delivers-vbs-payloads-msi-backdoors/) - Tenable Blog - [ ] [Supply chain attack on Axios npm package: Scope, impact, and remediations](https://www.tenable.com/blog/supply-chain-attack-on-axios-npm-package-scope-impact-and-remediations) - [ ] [What’s new in Tenable Cloud Security: Custom policies, AWS ABAC, and research-driven protection](https://www.tenable.com/blog/tenable-cloud-security-custom-policies-aws-abac) - ElcomSoft blog - [ ] [The Geography of Coercion: a Study of Compelled Decryption Laws](https://blog.elcomsoft.com/2026/03/the-geography-of-coercion-a-study-of-compelled-decryption-laws/) - Google Online Security Blog - [ ] [VRP 2025 Year in Review](http://security.googleblog.com/2026/03/vrp-2025-year-in-review.html) - Cerbero Blog - [ ] [EVTX Format Package](https://blog.cerbero.io/evtx-format-package/) - Horizon3.ai - [ ] [CVE-2026-20131](https://horizon3.ai/attack-research/vulnerabilities/cve-2026-20131/) - CCC Event Blog - [ ] [Håck-ma’s Castle](https://events.ccc.de/2026/03/31/hackmascastle/) - Binary Ninja - [ ] [Container Transforms: Working with Nested Binary Formats](https://binary.ninja/2026/03/31/container-transforms.html) - Bug Bounty in InfoSec Write-ups on Medium - [ ] [️ SQL Injection for Beginners: The Complete Guide](https://infosecwriteups.com/%EF%B8%8F-sql-injection-for-beginners-the-complete-guide-2750907b095b?source=rss----7b722bfd1b8d--bug_bounty) - [ ] [Understanding OT Cybersecurity: A Practical Guide to Asset Inventory for Industrial Control…](https://infosecwriteups.com/understanding-ot-cybersecurity-a-practical-guide-to-asset-inventory-for-industrial-control-65dc8b4e3f4d?source=rss----7b722bfd1b8d--bug_bounty) - [ ] [“Not Applicable” to Victory: How I Escalated a P2 DoS Vulnerability on Bugcrowd](https://infosecwriteups.com/not-applicable-to-victory-how-i-escalated-a-p2-dos-vulnerability-on-bugcrowd-c5fa05ab4727?source=rss----7b722bfd1b8d--bug_bounty) - [ ] [Critical ATO to P5 ‘Informational’: A Lesson in Threat Models & Bug Bounty Reality](https://infosecwriteups.com/critical-ato-to-p5-informational-a-lesson-in-threat-models-bug-bounty-reality-ef1dffd827b9?source=rss----7b722bfd1b8d--bug_bounty) - Malwarebytes - [ ] [Asking AI for personal advice is a bad idea, Stanford study shows](https://www.malwarebytes.com/blog/ai/2026/03/asking-ai-for-personal-advice-is-a-bad-idea-stanford-study-shows) - [ ] [Axios supply chain attack chops away at npm trust](https://www.malwarebytes.com/blog/news/2026/03/axios-supply-chain-attack-chops-away-at-npm-trust) - Sucuri Blog - [ ] [How to Fix “Not Secure” Warnings and SSL Issues in WordPress (8 Steps)](https://blog.sucuri.net/2026/03/how-to-fix-not-secure-warnings-and-ssl-issues-in-wordpress-8-steps.html) - SentinelOne - [ ] [How SentinelOne’s AI EDR Autonomously Discovered and Stopped Anthropic’s Claude from Executing a Zero Day Supply Chain Attack, Globally](https://www.sentinelone.com/blog/how-sentinelones-ai-edr-autonomously-discovered-and-stopped-anthropics-claude-from-executing-a-zero-day-supply-chain-attack-globally/) - The Trail of Bits Blog - [ ] [How we made Trail of Bits AI-native (so far)](https://blog.trailofbits.com/2026/03/31/how-we-made-trail-of-bits-ai-native-so-far/) - Hackerman's Hacking Tutorials - [ ] [Manual Context is a Bug](https://parsiya.net/blog/manual-context-is-a-bug/) - rtl-sdr.com - [ ] [TRNXSDR-Carrier: A Modular Baseboard for SDR Modules](https://www.rtl-sdr.com/trnxsdr-carrier-a-modular-baseboard-for-sdr-modules/) - [ ] [Adding ACARS Decoding to an ADS-B Flight Tracker](https://www.rtl-sdr.com/adding-acars-decoding-to-an-ads-b-flight-tracker/) - [ ] [Using the NISAR Satellite as an Illuminator for Passive Radar](https://www.rtl-sdr.com/using-the-nisar-satellite-as-an-illuminator-for-passive-radar/) - 奇客Solidot–传递最新科技情报 - [ ] [非洲研究显示气温超过 20 C 与男胎流产率上升相关](https://www.solidot.org/story?sid=83929) - [ ] [甲骨文裁员约 3 万人](https://www.solidot.org/story?sid=83928) - [ ] [考古学家发现有 3500 年历史的织布机](https://www.solidot.org/story?sid=83927) - [ ] [Claude Code 源码泄漏](https://www.solidot.org/story?sid=83926) - [ ] [微软计划为 Windows 11 构建更多原生应用](https://www.solidot.org/story?sid=83925) - [ ] [AI 数据中心周围地区温度最高上升 9.1C](https://www.solidot.org/story?sid=83924) - [ ] [AI 增加了使用者的认知疲劳](https://www.solidot.org/story?sid=83923) - [ ] [微软停止通过 Copilot 在 Pull Request 中插入广告](https://www.solidot.org/story?sid=83922) - [ ] [Google 开始推行 Android 开发者身份验证](https://www.solidot.org/story?sid=83921) - [ ] [空气污染预警减少了过早死亡](https://www.solidot.org/story?sid=83920) - 绿盟科技技术博客 - [ ] [对标2026 RSAC创新沙盒冠军,方向竟如此一致!绿盟科技以中国方案守护AI智能体安全](https://blog.nsfocus.net/%e5%af%b9%e6%a0%872026-rsac%e5%88%9b%e6%96%b0%e6%b2%99%e7%9b%92%e5%86%a0%e5%86%9b%ef%bc%8c%e6%96%b9%e5%90%91%e7%ab%9f%e5%a6%82%e6%ad%a4%e4%b8%80%e8%87%b4%ef%bc%81%e7%bb%bf%e7%9b%9f%e7%a7%91%e6%8a%80-2/) - [ ] [全栈AI安全能力,构筑智能时代防护屏障](https://blog.nsfocus.net/%e5%85%a8%e6%a0%88ai%e5%ae%89%e5%85%a8%e8%83%bd%e5%8a%9b%ef%bc%8c%e6%9e%84%e7%ad%91%e6%99%ba%e8%83%bd%e6%97%b6%e4%bb%a3%e9%98%b2%e6%8a%a4%e5%b1%8f%e9%9a%9c/) - [ ] [十九载深耕铸剑,绿盟科技携AI安全全景方案亮相2026 RSAC](https://blog.nsfocus.net/%e5%8d%81%e4%b9%9d%e8%bd%bd%e6%b7%b1%e8%80%95%e9%93%b8%e5%89%91%ef%bc%8c%e7%bb%bf%e7%9b%9f%e7%a7%91%e6%8a%80%e6%90%baai%e5%ae%89%e5%85%a8%e5%85%a8%e6%99%af%e6%96%b9%e6%a1%88%e4%ba%ae%e7%9b%b82026-rsac/) - HackerNews - [ ] [Axios NPM 包遭供应链攻击,恶意代码被注入](https://hackernews.cc/archives/63985) - [ ] [Fortinet FortiClient EMS 关键漏洞遭利用,可实现远程代码执行](https://hackernews.cc/archives/63984) - [ ] [F5 BIG-IP DoS 漏洞升级为关键 RCE,已遭野外利用](https://hackernews.cc/archives/63983) - [ ] [医疗科技公司 CareCloud 披露患者数据泄露事件](https://hackernews.cc/archives/63982) - 红日安全 - [ ] [2026护网行动(HVV)意向报名通知](https://mp.weixin.qq.com/s?__biz=MzI4NjEyMDk0MA==&mid=2649851869&idx=1&sn=3ec1a063dfb0b1bdc12cd79c5107b4e1) - 奇安信 CERT - [ ] [【已复现】Vim 代码执行漏洞(CVE-2026-34714)安全风险通告](https://mp.weixin.qq.com/s?__biz=MzU5NDgxODU1MQ==&mid=2247504921&idx=1&sn=fd2fbb100f4d90fbd6aeca192a15d929) - [ ] [今日(2026年3月31日)OpenClaw 最新安全动态总结](https://mp.weixin.qq.com/s?__biz=MzU5NDgxODU1MQ==&mid=2247504921&idx=2&sn=0933b8fbc276e2e97bf700bcb5541381) - 安全分析与研究 - [ ] [反检测技术(上)——反沙箱与反调试](https://mp.weixin.qq.com/s?__biz=MzA4ODEyODA3MQ==&mid=2247496626&idx=1&sn=9d3cc074e6e5708f26078938ae48576b) - 黑鸟 - [ ] [从新闻巨头到数据经纪商:路透社母公司数据接入Palantir系统](https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451186124&idx=1&sn=7e5d0ee9f5d440f91dbda9b0eeae08d4) - 雷神众测 - [ ] [雷神众测漏洞周报2026.3.23-2026.3.29](https://mp.weixin.qq.com/s?__biz=MzI0NzEwOTM0MA==&mid=2652503742&idx=1&sn=cc4e84af64875685998a079b34941f9b) - 代码卫士 - [ ] [Telegram 否认这个零点击高危 0day 漏洞的存在](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247525587&idx=1&sn=402fc52dcbd813d3c5d2c26bf077fab0) - [ ] [Grafana 多个严重漏洞可用于实现 RCE](https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247525587&idx=2&sn=a18525fe72676659d744674b7d8fdd16) - 安全内参 - [ ] [发现引领未来的智能力量!“中国AI智能体领航者”征集正式启动](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247515748&idx=1&sn=3dabb411d66b35691177ac2977b72423) - [ ] [美国国防部公布技术生态系统与网络安全转型计划](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247515748&idx=2&sn=0efa3e7d18920b0cf44794bf63f828bc) - 二道情报贩子 - [ ] [npm 热门库 axios 遭遇供应链攻击](https://mp.weixin.qq.com/s?__biz=MzU5NTA3MTk5Ng==&mid=2247490039&idx=1&sn=4530e1790c54b9980a65a327780b2dd9) - 虎符智库 - [ ] [2026SASE安全范式重构:AI原生驱动体系化运营](https://mp.weixin.qq.com/s?__biz=MzIwNjYwMTMyNQ==&mid=2247493758&idx=1&sn=f4ef4b5bd273e2e7d5fddafb63f4c076) - 先进攻防 - [ ] [Axios 被投毒植入全平台 RAT,OpenClaw 生态全线沦陷!!!](https://mp.weixin.qq.com/s?__biz=MzI1MDA1MjcxMw==&mid=2649908879&idx=1&sn=ba3680ca49b0077c29a20a389363a748) - 看雪学苑 - [ ] [一年办20场活动,数据还在别人服务器上?](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458612921&idx=1&sn=15cfd4061fcf889e2ad733fe5f6acc8a) - [ ] [Pixel 8a(akita:6.1-android16内核支持ebpf)AOSP/GKI内核源码获取、编译与刷机实战指南](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458612921&idx=2&sn=0d3b728f453696c16359609bdf18be37) - [ ] [Telegram 惊曝零日漏洞争议:发个贴纸就能控制手机?官方却全盘否认](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458612921&idx=3&sn=645d2addefbbd1fa075e998b38bdb0dc) - 微步在线研究响应中心 - [ ] [OpenClaw又又又危!Axios npm被投毒,植入全平台木马](https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&mid=2247508505&idx=1&sn=906fb32ff9f5b00c2600c6eb37da2400) - 腾讯安全应急响应中心 - [ ] [TSRC官网焕新登场:以科技新貌,赋能每一份专注和高效](https://mp.weixin.qq.com/s?__biz=MjM5NzE1NjA0MQ==&mid=2651208282&idx=1&sn=4fa5b3fb175cf67d50b20a743c363a50) - 绿盟科技CERT - [ ] [【安全事件】axios前端库npm供应链投毒预警通告](https://mp.weixin.qq.com/s?__biz=Mzk0MjE3ODkxNg==&mid=2247489511&idx=1&sn=e85b5e65d5cacbf380db869f7d068c49) - 信息安全国家工程研究中心 - [ ] [中国密码学会《商用密码应用安全性评估FAQ(第四版)》更新发布](https://mp.weixin.qq.com/s?__biz=MzU5OTQ0NzY3Ng==&mid=2247503307&idx=1&sn=b072d301826e91bc00e289b2374d28a7) - 长亭安全应急响应中心 - [ ] [一亿周下载量的HTTP客户端库遭供应链攻击,axios投毒事件深度分析](https://mp.weixin.qq.com/s?__biz=MzIwMDk1MjMyMg==&mid=2247493192&idx=1&sn=4a4f6fa8f61292dd65e78b1632bfd211) - 奇安信威胁情报中心 - [ ] [Coruna与DarkSword:iOS高端攻击武器扩散的威胁](https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247518166&idx=1&sn=d8644bdd6d9deb3800972cd8de846516) - 安全研究GoSSIP - [ ] [G.O.S.S.I.P 特别推荐 2026-03-31 QCP 2.0来了!](https://mp.weixin.qq.com/s?__biz=Mzg5ODUxMzg0Ng==&mid=2247501541&idx=1&sn=26b0b5a3a4960a4decdd5d82bf4d4443) - 绿盟科技研究通讯 - [ ] [模糊指纹:Web 应用指纹识别困境分析](https://mp.weixin.qq.com/s?__biz=MzIyODYzNTU2OA==&mid=2247499716&idx=1&sn=f1dbfcf44228d73aff01f11b1f2270af) - [ ] [RSAC 2026创新沙盒 | Clearly AI:打造AI赋能的自动化软件安全平台](https://mp.weixin.qq.com/s?__biz=MzIyODYzNTU2OA==&mid=2247499716&idx=2&sn=eee7e3a4d73da00bccdb618cb7003c3d) - 天御攻防实验室 - [ ] [未来两年将变得“疯狂”](https://mp.weixin.qq.com/s?__biz=MzU0MzgyMzM2Nw==&mid=2247486861&idx=1&sn=350293624c3aea9f56d0d336cafad7c4) - 中国信息安全 - [ ] [论坛· 原创 | 构建网络空间命运共同体的历程、成效及展望](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664260825&idx=1&sn=9f3857fed83a2d4e5f6d4d34a33bebce) - [ ] [发布 | 工信部等九部门联合印发《推动物联网产业创新发展行动方案(2026—2028年)》](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664260825&idx=2&sn=c6d38a669831ea5f2daca2f30530c58e) - [ ] [关注 | 世界数据组织正式运行 开启全球数据治理新格局](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664260825&idx=3&sn=4e83b06d293d2a3609edb84f802049a4) - [ ] [通知 | 网安标委发布《网络安全标准实践指南——工业企业数据安全能力成熟度模型》](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664260825&idx=4&sn=05bc8419e79c15e0515c5c132dc05543) - [ ] [关注 | 丝芙兰、泡泡玛特、易次元等71款违法违规收集使用个人信息的移动应用被通报!](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664260825&idx=5&sn=6c921170d6458568c546309c2724542b) - 安全圈 - [ ] [【安全圈】小米新推出的输入法工具直接暴露AI模型密钥](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652075253&idx=1&sn=1c85eb1ed9b6a52eda306974d0aff543) - [ ] [【安全圈】360漏洞挖掘智能体发现OpenClaw高危漏洞,或波及全球17万实例](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652075253&idx=2&sn=1c58b6f95327d26411281829e92a8fcd) - [ ] [【安全圈】上海电信大规模断网,官方:宽带正常升级导致](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652075253&idx=3&sn=8f39b5ecc97049877fd8c3fc36a901a3) - 安全牛 - [ ] [恶意 AI 助手潜伏浏览器:超 90 万次安装,2 万家企业面临数据窃密风险](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651140924&idx=1&sn=624aff244684bbd6af6f285714a15f90) - [ ] [CNVD发布上周关注度较高的产品安全漏洞;伊朗黑客组织 Handala 宣称入侵 FBI 局长邮箱 | 牛览](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651140924&idx=2&sn=a899a782f7de03f6f3f5e3296760e67b) - 猎户攻防实验室 - [ ] [Axios 供应链投毒安全事件预警与排查报告](https://mp.weixin.qq.com/s?__biz=MzI1NDg4MTIxMw==&mid=2247486734&idx=1&sn=79dfe00b33f6bc5f5333a2d426fd1a7c) - 微步在线 - [ ] [直播预告 | 关于今年实战攻防的3个预测](https://mp.weixin.qq.com/s?__biz=MzI5NjA0NjI5MQ==&mid=2650185799&idx=1&sn=c596d4bc099a618cf99db689881195c6) - M01N Team - [ ] [OpenClaw依赖包Axios遭供应链投毒:恶意版本植入远控木马](https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&mid=2247494899&idx=1&sn=0030596542ccc940303101d3f850e2a6) - 补天平台 - [ ] [OpenClaw 失控机制与熔断体系在攻防视角下的设计](https://mp.weixin.qq.com/s?__biz=MzI2NzY5MDI3NQ==&mid=2247510572&idx=1&sn=df00b9cf0701d29b1710ac40b6c7720a) - 数世咨询 - [ ] [报告发布 | 中国(香港)网络安全竞争力调研报告(第一期)](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247542414&idx=1&sn=998844ebbcab714c20082e9da67ce49b) - [ ] [Report Release | Report onCybersecurity Competitiveness of China (Hong Kong) (Phase I)](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247542414&idx=2&sn=c83ee72e2875bb4c25accfcb98bc2910) - [ ] [360漏洞挖掘智能体揪出OpenClaw新高危漏洞](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247542414&idx=3&sn=3cc41f3c83cc4c87344c7bef5e5d8d91) - 极客公园 - [ ] [AI 加速,短剧比想象中更短命](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653102498&idx=1&sn=aedddb4bc0827423f1648b321017c967) - [ ] [国行苹果 AI 深夜意外上线;小米启动 AI 人才专项招聘;DeepSeek 服务已恢复正常,此前崩溃约 12 小时 | 极客早知道](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653102464&idx=1&sn=2d7a408044c134ab62d2b99bc9d0c1b0) - 嘶吼专业版 - [ ] [VoidStealer恶意软件利用调试器漏洞窃取Chrome主密钥](https://mp.weixin.qq.com/s?__biz=MzI0MDY1MDU4MQ==&mid=2247587479&idx=1&sn=7756cf1662db5725ee22be9a7eba7df8) - [ ] [嘶吼安全动态|全国网安标委发布关于征集个人信息保护标准应用实践案例的通知 AI工作流工具Langflow曝未授权RCE漏洞](https://mp.weixin.qq.com/s?__biz=MzI0MDY1MDU4MQ==&mid=2247587479&idx=2&sn=94638a85f8dd5ec785e150589e6d3b0e) - 火绒安全 - [ ] [春和景明 火绒安护无忧](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247531830&idx=1&sn=af80014abda31dda55187855053a4d14) - [ ] [诚邀渠道合作伙伴共启新征程](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247531830&idx=2&sn=98ae8cf4a05b3e0493397039bf091c14) - 情报分析师 - [ ] [间谍、线人、策反,这些电影桥段在现实里到底怎么运转?真正危险的,不是间谍有多传奇,而是他看起来太普通](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650567408&idx=1&sn=bf72319ca3d0443161d7c0c10445c036) - [ ] [【深度研判】英国核潜艇基地疑涉伊朗间谍事件及其对我海外战略设施安保启示](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650567408&idx=2&sn=a285675807ef7d42538b5b7f446bd2d4) - [ ] [是谁的无人机飞上了平壤的天空?——韩国情报院背后,一场情报决策的迷局](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650567408&idx=3&sn=ff14a08e11e046410057f20c0da8fba8) - [ ] ["影子舰队"到底怎么活下来的?一条船如何在公开世界里隐身](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650567408&idx=4&sn=ebafa3cace83162ce8151eb46719b846) - Beacon Tower Lab - [ ] [起底OpenClaw提示词注入:从“无害话痨”到“主机沦陷”仅需一个网页](https://mp.weixin.qq.com/s?__biz=MzkyNzcxNTczNA==&mid=2247488060&idx=1&sn=8b5c43a53ac79ba2dde188b71a96218c) - 迪哥讲事 - [ ] [盲ssrf](https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&mid=2247499243&idx=1&sn=e185df8a75ad10167daf7a4fb2a7425d) - 墨菲安全 - [ ] [Axios库投毒影响17.4万组件,OpenClaw受影响分析](https://mp.weixin.qq.com/s?__biz=MzkwOTM0MjI5NQ==&mid=2247488376&idx=1&sn=396fcd62e07d28d53fecd94494372e48) - 360数字安全 - [ ] [360亮相第二届浦江AI学术年会 | 智能体安全,不只是“未来命题”](https://mp.weixin.qq.com/s?__biz=MzA4MTg0MDQ4Nw==&mid=2247585590&idx=1&sn=dacabf351e11da5ec89376f33a56fa60) - 国家互联网应急中心CNCERT - [ ] [CNVD漏洞周报2026年第12期](https://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw==&mid=2247501368&idx=1&sn=ebfcad9dc22f95a2407acca0cfcec9ba) - 渊龙Sec安全团队 - [ ] [通过RouterOS建立WireGuard内网隧道](https://mp.weixin.qq.com/s?__biz=Mzg4NTY0MDg1Mg==&mid=2247485977&idx=1&sn=2bddee1e0c7dfa384c1cd2feee94ba00) - Securityinfo.it - [ ] [Vibecoding: l’AI accelera lo sviluppo ma moltiplica i rischi](https://www.securityinfo.it/2026/03/31/vibecoding-lai-accelera-lo-sviluppo-ma-moltiplica-i-rischi/?utm_source=rss&utm_medium=rss&utm_campaign=vibecoding-lai-accelera-lo-sviluppo-ma-moltiplica-i-rischi) - 大兵说安全 - [ ] [你的备份安全吗?](https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&mid=2247485778&idx=1&sn=8ff47f5f8a64f5ec7800c39b9e18be1f) - ICT Security Magazine - [ ] [LinkedIn come arma: dal phishing allo spionaggio di Stato](https://www.ictsecuritymagazine.com/notizie/linkedin-cybercrime/) - [ ] [UN R155 e R156: la cybersecurity automobilistica che l’Italia non può ignorare](https://www.ictsecuritymagazine.com/notizie/un-r155-r156/) - Over Security - Cybersecurity news aggregator - [ ] [Vibecoding: l’AI accelera lo sviluppo ma moltiplica i rischi](https://www.securityinfo.it/2026/03/31/vibecoding-lai-accelera-lo-sviluppo-ma-moltiplica-i-rischi/) - [ ] [Google now allows you to change your @gmail.com address](https://www.bleepingcomputer.com/news/google/google-now-allows-you-to-change-your-gmailcom-address/) - [ ] [Proton launches new "Meet" privacy-focused conferencing platform](https://www.bleepingcomputer.com/news/security/proton-launches-new-meet-privacy-focused-conferencing-platform/) - [ ] [GIGABYTE Control Center vulnerable to arbitrary file write flaw](https://www.bleepingcomputer.com/news/security/gigabyte-control-center-vulnerable-to-arbitrary-file-write-flaw/) - [ ] [Claude AI finds Vim, Emacs RCE bugs that trigger on file open](https://www.bleepingcomputer.com/news/security/claude-ai-finds-vim-emacs-rce-bugs-that-trigger-on-file-open/) - [ ] [Google links axios supply chain attack to North Korean group](https://therecord.media/google-links-axios-supply-chain-attack-north-korea) - [ ] [US indicts Maryland man for 2021 theft of $54 million from Uranium Finance](https://therecord.media/us-indicts-maryland-man-54-million-crypto-theft) - [ ] [Cisco source code stolen in Trivy-linked dev environment breach](https://www.bleepingcomputer.com/news/security/cisco-source-code-stolen-in-trivy-linked-dev-environment-breach/) - [ ] [How to Fix “Not Secure” Warnings and SSL Issues in WordPress (8 Steps)](https://blog.sucuri.net/2026/03/how-to-fix-not-secure-warnings-and-ssl-issues-in-wordpress-8-steps.html) - [ ] [Hacker hijacks Axios open-source project, used by millions, to push malware](https://techcrunch.com/2026/03/31/hacker-hijacks-axios-open-source-project-used-by-millions-to-push-malware/) - [ ] [Reati informatici e punibilità: quando la “condotta” diventa reato prima del danno](https://www.cybersecurity360.it/nuove-minacce/reati-informatici-e-punibilita-quando-la-condotta-diventa-reato-prima-del-danno/) - [ ] [New criminal service plans to monetize data stolen by ransomware gangs](https://therecord.media/new-criminal-service-plans-to-monetize-ransomware-data) - [ ] [Pro-Russian hackers pose as Ukraine's cyber agency to target government, businesses](https://therecord.media/pro-russian-hackers-posing-as-ukrainian-cyber-agency) - [ ] [How to Categorize AI Agents and Prioritize Risk](https://www.bleepingcomputer.com/news/security/how-to-categorize-ai-agents-and-prioritize-risk/) - [ ] [Sicurezza informatica, differenza tra progetto e processo: come cambia la cyber in azienda](https://www.cybersecurity360.it/cultura-cyber/la-differenza-tra-progetto-e-processo-nella-sicurezza-informatica-come-cambia-la-cyber-in-azienda/) - [ ] [Hackers compromise Axios npm package to drop cross-platform malware](https://www.bleepingcomputer.com/news/security/hackers-compromise-axios-npm-package-to-drop-cross-platform-malware/) - [ ] [CISA tells federal agencies to patch Citrix NetScaler bug by Thursday](https://therecord.media/cisa-tells-federal-agencies-to-patch-citrix-netscaler-bug) - [ ] [Esposizione remota non sicura dell’app-server Codex con capacità di esecuzione comandi](https://cert-agid.gov.it/news/esposizione-remota-non-sicura-dellapp-server-codex-con-capacita-di-esecuzione-comandi/) - [ ] [Microsoft fixes Outlook Classic crashes caused by Teams Meeting add-in](https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-outlook-classic-crashes-caused-by-teams-meeting-add-in/) - [ ] [Cyber Threat Trends During the Winter Olympics 2026](https://bfore.ai/report/cyber-threat-trends-winter-olympics-2026/) - [ ] [Release Notes: Cross-Platform Threat Analysis with macOS, SSL Decryption, and 1,300+ New Detections](https://any.run/cybersecurity-blog/release-notes-march-2026/) - [ ] [Meet Sekoia Reveal: Turn fragmented asset data into unified SOC context](https://blog.sekoia.io/meet-sekoia-reveal-turn-fragmented-asset-data-into-unified-soc-context/) - [ ] [Per Google il Q-Day arriverà nel 2029](https://www.cybersecurity360.it/news/google-q-day-2029/) - [ ] [Ransomware in 2025: Blending in is the strategy](https://blog.talosintelligence.com/ransomware-in-2025-blending-in-is-the-strategy/) - [ ] [Common Entra ID Security Assessment Findings – Part 2: Privileged Unprotected Groups](https://blog.compass-security.com/2026/03/common-entra-id-security-assessment-findings-part-2-privileged-unprotected-groups/) - [ ] [Jennifer Cox on Why Most Security Teams Never See the Real Benefits of Automation](https://thecyberexpress.com/jennifer-cox-interview/) - [ ] [Hacker charged with stealing $53 million from Uranium crypto exchange](https://www.bleepingcomputer.com/news/security/hacker-charged-with-stealing-53-million-from-uranium-crypto-exchange/) - [ ] [Axios Supply Chain Attack Exposes Developers to Hidden Malware](https://thecyberexpress.com/axios-supply-chain-attack-npm-malware/) - [ ] [Guerre di Rete - Sovranità stellare](https://guerredirete.substack.com/p/guerre-di-rete-sovranita-stellare) - [ ] [Dutch Finance Ministry takes treasury banking portal offline after breach](https://www.bleepingcomputer.com/news/security/dutch-finance-ministry-takes-treasury-banking-portal-offline-after-breach/) - [ ] [Intesa Sanpaolo, mega sanzione privacy per accessi abusivi: una lezione per CISO e DPO](https://www.cybersecurity360.it/news/intesa-sanpaolo-mega-sanzione-privacy-per-accessi-abusivi-una-lezione-per-ciso-e-dpo/) - [ ] [Analysis of FvncBot campaign](https://cert.pl/en/posts/2026/03/fvncbot-analysis/) - [ ] [Cuties AI - 144,250 breached accounts](https://haveibeenpwned.com/Breach/CutiesAI) - [ ] [CISA orders feds to patch actively exploited Citrix flaw by Thursday](https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-citrix-flaw-by-thursday/) - [ ] [Phantom Stealer: Credential Theft as a Service](https://www.group-ib.com/blog/phantom-stealer-credential-theft/) - [ ] [US Man Admits Guilt in Child Exploitation, Cyberstalking Linked to ‘764’ Network](https://thecyberexpress.com/violent-extremist-network-764-cyberstalking/) - [ ] [CareCloud Hit by Cyberattack, Probe Into Possible Data Exposure](https://thecyberexpress.com/carecloud-data-breach/) - [ ] [World Backup Day 2026, il dato fa parte della nostra identità digitale: le best pratice per proteggerlo](https://www.cybersecurity360.it/news/world-backup-day-2026-il-dato-fa-parte-della-nostra-identita-digitale-le-best-pratice-per-proteggerlo/) - [ ] [Intesa Sanpaolo Data Breach Exposes 3,500+ Customers, Draws €31.8M Penalty](https://thecyberexpress.com/intesa-sanpaolo-data-breach/) - [ ] [The Security Risks of Using Nulled WordPress Plugins](https://blog.sucuri.net/2026/03/the-security-risks-of-using-nulled-wordpress-plugins.html) - Have I Been Pwned latest breaches - [ ] [Cuties AI - 144,250 breached accounts](https://haveibeenpwned.com/Breach/CutiesAI) - Javvad Malik - [ ] [7 Reasons Kids Are Overrated Until Suddenly They’re Your Entire Support Infrastructure](https://javvadmalik.com/2026/03/31/7-reasons-kids-are-overrated-until-suddenly-theyre-your-entire-support-infrastructure/) - SANS Internet Storm Center, InfoCON: green - [ ] [Application Control Bypass for Data Exfiltration, (Tue, Mar 31st)](https://isc.sans.edu/diary/rss/32850) - [ ] [ISC Stormcast For Tuesday, March 31st, 2026 https://isc.sans.edu/podcastdetail/9872, (Tue, Mar 31st)](https://isc.sans.edu/diary/rss/32848) - [ ] [TeamPCP Supply Chain Campaign: Update 004 - Databricks Investigating Alleged Compromise, TeamPCP Runs Dual Ransomware Operations, and AstraZeneca Data Released, (Mon, Mar 30th)](https://isc.sans.edu/diary/rss/32846) - bellingcat - [ ] [How India’s Ruling Party is Using AI to Boost Hate Speech in States Near Bangladesh](https://www.bellingcat.com/news/2026/03/31/india-bjp-hate-speech-ai/) - Troy Hunt's Blog - [ ] [Weekly Update 497](https://www.troyhunt.com/weekly-update-497/) - Schneier on Security - [ ] [Inventors of Quantum Cryptography Win Turing Award](https://www.schneier.com/blog/archives/2026/03/inventors-of-quantum-cryptography-win-turing-award.html) - 360威胁情报中心 - [ ] [Axios npm供应链攻击威胁分析报告](https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247508054&idx=1&sn=53087fd771552eb8c5c0144dc7db8400) - 希潭实验室 - [ ] [第159篇:原创工具-WiFi弱口令审计与暴力猜解工具 v0.25](https://mp.weixin.qq.com/s?__biz=MzkzMjI1NjI3Ng==&mid=2247488283&idx=1&sn=ca2c9122c9a09af4288d51da6406761c) - 安全产品人的赛博空间 - [ ] [Claude Code源码泄露!可直接build](https://mp.weixin.qq.com/s?__biz=Mzg5NTUzODkxMw==&mid=2247484410&idx=1&sn=7e1fb22c494b696f794d3c9613f0cae1) - 熵减矩阵 - [ ] [Claude Code 源码深度架构分析](https://mp.weixin.qq.com/s?__biz=Mzg2MTc1NDAxMA==&mid=2247485223&idx=1&sn=7f645c710d5cff010109b2040660a6ce) - Desync InfoSec - [ ] [Axios 遭遇供应链攻击:被投毒版本植入 RAT 远控木马](https://mp.weixin.qq.com/s?__biz=MzkzMDE3ODc1Mw==&mid=2247489567&idx=1&sn=5c889af11a9bc19ab48a004f33807adb) - IT Service Management News - [ ] [ISO/IEC 27090 e 27091 sull'intelligenza artificiale](http://blog.cesaregallotti.it/2026/03/isoiec-27090-e-27091-sullintelligenza.html) - Trend Micro Research, News and Perspectives - [ ] [TrendAI™ Research at RSAC 2026: Advancing Defense Across AI‑Driven and Cyber‑Physical Threats](https://www.trendmicro.com/en_us/research/26/c/trendai-research-at-rsac-2026.html) - [ ] [The Real Risk of Vibecoding](https://www.trendmicro.com/en_us/research/26/c/the-real-risk-of-vibecoding.html) - The Hacker News - [ ] [Android Developer Verification Rollout Begins Ahead of September Enforcement](https://thehackernews.com/2026/03/android-developer-verification-rollout.html) - [ ] [TrueConf Zero-Day Exploited in Attacks on Southeast Asian Government Networks](https://thehackernews.com/2026/03/trueconf-zero-day-exploited-in-attacks.html) - [ ] [Vertex AI Vulnerability Exposes Google Cloud Data and Private Artifacts](https://thehackernews.com/2026/03/vertex-ai-vulnerability-exposes-google.html) - [ ] [The AI Arms Race – Why Unified Exposure Management Is Becoming a Boardroom Priority](https://thehackernews.com/2026/03/the-ai-arms-race-why-unified-exposure.html) - [ ] [Silver Fox Expands Asia Cyber Campaign with AtlasCross RAT and Fake Domains](https://thehackernews.com/2026/03/silver-fox-expands-asia-cyber-campaign.html) - [ ] [Axios Supply Chain Attack Pushes Cross-Platform RAT via Compromised npm Account](https://thehackernews.com/2026/03/axios-supply-chain-attack-pushes-cross.html) - The Register - Security - [ ] [Don't open that WhatsApp message, Microsoft warns](https://go.theregister.com/feed/www.theregister.com/2026/03/31/whatsapp_message_bad_msi_packages/) - [ ] [Iran targets M365 accounts with password-spraying attacks](https://go.theregister.com/feed/www.theregister.com/2026/03/31/iran_password_spraying_m365/) - [ ] [Supply chain blast: Top npm package backdoored to drop dirty RAT on dev machines](https://go.theregister.com/feed/www.theregister.com/2026/03/31/axios_npm_backdoor_rat/) - GRAHAM CLULEY - [ ] [Iranian hackers breach FBI director’s personal email, and post his CV and photos online](https://www.bitdefender.com/en-us/blog/hotforsecurity/iranian-hackers-breach-fbi-directors-personal-email-post-cv-and-photos-online) - TorrentFreak - [ ] [Game Pirates Beat Denuvo with Hypervisor Bypasses — Irdeto Promises Countermeasure](https://torrentfreak.com/game-pirates-beat-denuvo-with-hypervisor-bypasses-irdeto-promises-countermeasure/) - Security Affairs - [ ] [Anthropic accidentally leaks Claude Code](https://securityaffairs.com/190229/data-breach/anthropic-accidentally-leaks-claude-code.html) - [ ] [Attackers hijack Axios npm account to spread RAT malware](https://securityaffairs.com/190221/security/attackers-hijack-axios-npm-account-to-spread-rat-malware.html) - [ ] [Nearly half a Million mobile customers of Lloyds Banking Group affected by security incident](https://securityaffairs.com/190213/data-breach/nearly-half-a-million-mobile-customers-of-lloyds-banking-group-affected-by-a-security-incident.html) - [ ] [Dutch Ministry of Finance takes treasury systems offline amid cyber incident investigation](https://securityaffairs.com/190204/hacking/dutch-ministry-of-finance-takes-treasury-systems-offline-amid-cyber-incident-investigation.html) - [ ] [U.S. CISA adds a flaw in Citrix NetScaler to its Known Exploited Vulnerabilities catalog](https://securityaffairs.com/190197/security/u-s-cisa-adds-a-flaw-in-citrix-netscaler-to-its-known-exploited-vulnerabilities-catalog.html) - [ ] [Qilin Ransomware allegedly breached chemical manufacturer giant Dow Inc](https://securityaffairs.com/190186/cyber-crime/qilin-ransomware-allegedly-breached-chemical-manufacturer-giant-dow-inc.html) - Tor Project blog - [ ] [Arti 2.2.0 released: HTTP CONNECT, RPC, and Relay development.](https://blog.torproject.org/arti_2_2_0_released/) - Deeplinks - [ ] [Welcome, Daily Show Viewers! Learn More About EFF and Privacy's Defender](https://www.eff.org/deeplinks/2026/03/welcome-daily-show-viewers-learn-more-about-eff-and-privacys-defender) - 安全行者老霍 - [ ] [Wiz AI 安全产品介绍](https://mp.weixin.qq.com/s?__biz=Mzg3NjU4MDI4NQ==&mid=2247486368&idx=1&sn=dc5d5953d6941de89a9d1fbdf60c73f6)
每日安全资讯(2026-04-01)