20990101 Thu
备忘录
前沿领域
汽车安全
固件分析
IOT 漏洞收集
工控安全 漏洞收集
协议安全 漏洞收集
值得一看 漏洞收集
20260809 Sun

DEF CON 34 - Video Team - DEF COIN 34 Badge - Bunnie Huang
Investigating a Multi-Stage PowerShell Loader

Hacking Apple Watch to break into iPhone: deep tech analysis of pairing & data sync internals 📱⌚💉👨🏻💻🏆

PART2: Trying To Save A $4000 Gaming Laptop, And This Is What I Found!
20260808 Sat

我飛他的日本手,他飛我的Avata!無人機交換挑戰開始!🔥

「南海最險地」中國不敢打,菲律賓不敢撤!一艘「故意擱淺」27年的破船,如何将南海推向戰爭邊緣?|深度調查

「帶老婆小孩去華南當背包客」一早起來直接走羅湖口岸入境香港,到香港的上水站吃個早餐,之後搭香港機場大巴A43 到香港機場,飛回台灣結束旅程。 #12

练习两年半 喜欢飞行的坤鸡 iKun30 Pro试飞 #穿越机 #fpv穿越机 #穿越机入门 #穿越机看风景

怎么会卡?丐版M5 MacBookair 3个月深度体验
让网页视频也能投到电视上播放:Castor
SepiaPod – 25年前 iPod Classic 复古音乐播放器,iPhone 限免

航模圈首款电容摇杆,原理是什么?有何不同? 电容摇杆? #穿越机 #fpv穿越机

DEFCON 34: Policy Talks

DEFCON 34: Track 5 Talks

DEFCON 34: Track 4 Talks

DEFCON 34: Track 3 Talks

DEFCON 34: Track 2 Talks

DEFCON 34: Track 1 Talks

2026年还不会用Mac?从零开始30分钟速通!

Give AI Agent Its Own Linux Computer: Hermes + Incus

DEFCON 34: After Dark

Living off the coding agent: Two tales of tunnels and LaunchAgents
Varonis Atlas Now Integrates with Claude Inference Hooks to Extend Real-Time AI Data Protection

When Queues Become Vulnerabilities: Reverse Engineering GCD, XPC Races, and macOS Detection

Black Hat USA Briefings: Kinetic Prompt Injection: Agent Compromise With a Physical Blast Radius

天启奇缘:异界初稿 | AI动画
RovoBlast: How One Click Triggered Atlassian’s AI Assistant to Leak Data

DEF CON 34 - Video Team - 'Lights in Dark Rooms' premiere at Movie Night Friday 8pm in W222
AI chat bots are sliding into League of Legends friend requests
Friday Squid Blogging: Arctic Bobtail Squid Video
Meta ordered to pay $942 million over harm to children
That’s a wrap: Mend.io at Black Hat USA 2026
A decade of enterprise identity in the cloud with AWS Managed Microsoft AD

DEF CON 34 - Video Team - EFF Update - Cindy Cohn

Security and attacks on keyless key fobs: The technology used by criminals to hijack cars.🚗၊၊||၊📻👨🏻💻🎰

AI-Generated Patches Fail Half the Time
Securing your Amazon S3 buckets: Identifying and remediating over-permissioned access
20260807 Fri
What the Recent Water Systems Cyber Attacks Reveal About Critical Infrastructure Security
Inside the Fake Copyright Racket Silencing News Outlets

Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
The Download: a censorship conspiracy theory and the first virus created by AI

Intel just matched Apple Silicon. Seriously.
How ideas of a vast censorship network moved from the online fringe to Trump policy

维修工程宝测试仪一定要先了解主板结构,以免误入歧途,费时费力

老厂复出做新机?银燕FPV入门到手飞套机开箱体验 这个套机里有一个有意思的FPV眼罩,看看好玩不?#穿越机 #FPV #航模 #遥控飞机 #穿越机入门

The Better Windows Alternative that Failed.

Mini Shai-Hulud's Latest Wave: 280 New Places It Hunts for Your Secrets

Unveiling good and bad behaviors on the Agentic Internet

The Good, the Bad and the Ugly in Cybersecurity – Week 32

Introducing Radar Researcher: An AI tool for exploring Internet data in plain language

Announcing Cloudflare Ambassadors, Community Engineers, and another $1M in open-source funding

Unifying Workers AI and AI Gateway into a single AI control plane
CISA Adds One Known Exploited Vulnerability to Catalog
CPDLC over ATN-B1 Vulnerabilities
ICE Is Buying Access to Credit Card Records

DecBGAN: Making Sense of Inmarsat's Broadband Global Area Network Service In Linux!
黑客的第一课:Linux 基础课程中文译本来了,都能看懂

My Space Cadet Pinball Machine Finally Has Wormholes!

Building the wormholes from Space Cadet Pinball! #3dprinting #retrogaming #pinball #spacecadet

【血脈覺醒】在 FB Marketplace 買回我 16 歲的Nikon相機!1993 年的 Nikon F601 居然像新的一樣?!
本周赛博领鸡蛋(8.7~8.13):《Beacon Pines》、《我们曾在这里》、《巴别号漫游指南》
Linux Shell Forensic: Let?s Dive Into Atuin!, (Fri, Aug 7th)

HelloRadio V15 剁手指南 功能 价格 配置 版本差异 赠品攻略 #穿越机 #fpv穿越机 #穿越机入门 #穿越机遥控器

什么是“最小侵害原则”?英国如何克制网络管制手段?|翻墙|VPN|节点|科学上网|聊点不同E66
Free Business Plan Upgrades for Open Source Maintainers
BatteryHealth – 笔记本电脑电池健康度检测[Windows]
CrowdStrike Threat Hunts for Shell Command Obfuscation on VMware ESX

美股篇|海外券商怎么选?Bitget(加密券商) 专篇

美股篇|海外券商怎么选?香港腾达(券商) 专篇

美股篇|海外券商怎么选?香港复星(券商) 专篇

美股篇|海外券商怎么选?BIT(加密券商) 专篇
Fake macOS update installs crypto-stealing malware
VPNs on the App Store leave you exposed to phishing and malware
ISC Stormcast For Friday, August 7th, 2026 https://isc.sans.edu/podcastdetail/10042, (Fri, Aug 7th)

DEFCON 34: Policy Talks

DEFCON 34: Track 5 Talks
[Benchmark] 在 DGX Spark 上把 MiniMax-H3 跑起來:配置、最佳化順序,以及那條走不通的路

The security signal log tailing can't see: tracking npm cooldown removals with Elastic Agent
Online Sports’ Shadow Audience

DEFCON 34: Track 4 Talks

DEFCON 34: Track 3 Talks

DEFCON 34: Track 2 Talks

DEFCON 34: Track 1 Talks

DEF CON 34 - Video Team - DEF CON Groups Highlight DC256
Automate certificates with ACME support in AWS Certificate Manager

CSS:the bomb inside your inbox
_wsf_AL_Alamy.jpg?width=720&quality=80&disable=upscale)
The Coordination Gap: How Attackers Are Outpacing Law Enforcement

Black Hat USA Opening Session: Disruption, Defense and Operational Readiness

Déjà Vu? Meta's AI Escapes Testing Lab in Hacking Joyride

Researcher Claims Control of ChatGPT Secure Sandbox

Black Hat USA 2026 Opening Session: Cyber Power in the Age of AI

Black Hat USA 2026 Keynote: Vulnerability Research in the Agentic Age

Black Hat USA 2026 Keynote: The End of Rare Defending When Offense Is Cheap

Black Hat USA 2026: The 'Breaking' News: The OpenAI–Hugging Face Incident

What is AI harness engineering?
Route Amazon Bedrock Guardrails interventions to Amazon Security Lake
.jpg?width=720&quality=80&disable=upscale)
From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture

Airport luggage security: copying keys, lock picking, decoding, and shimming TSA locks. 👨🏻💻🧳🔒🛠️😈
Why “AI Pentesting” is the Wrong Term (And Why We Need AI Red Teaming)
Canadian Man Pleads Guilty in Snowflake Extortions
How we took malware advisories beyond npm

What If AI Security’s Biggest Risk... Isn’t?

DEF CON 34 - Good Morning
Caching KMS data keys in multi-thread environments: Per-tenant encryption for event-driven systems at scale
20260806 Thu

手搓Master5 V3 酷飞模块电机 试飞体验报告 最模块化5寸穿越机 #穿越机 #fpv穿越机 #穿越机入门 #穿越机组装
Apple WebKit vulnerabilities reveal your IP address, despite Private Relay

海外华人可KYC |银行卡可直接入金、每张U卡仅需1U开卡费!D网DigiFinex |暂不支持中国证件实名

反诈提醒|请务必认准我的Telegram账号|谨防被骗

Cloud Threat Highlights: H1 2026
Cloudflare AI Search: give your agents a search engine for your data
The next generation of MCP
From ranking to recommended: get your site ready to thrive in the age of AI agents
Building an open Agentic Internet: readable, discoverable, callable, and payable
Introducing Kitesurf: The agent-first browser that runs in V8 isolates on Cloudflare Workers
Give any website a WebMCP interface
The Download: Google’s AI shake-up and Meta’s rogue model

Wiz Brings Automated DISA STIG Assessment to Amazon Linux 2023 and Windows Server 2025
Medixant RadiAnt DICOM
Johnson Controls Inc. TL280
ABB Ability Zenon
Scammers target OnlyFans users with deepfakes
Adversarial Clothing Designed to Fool Facial Recognition Systems
Amazon and Apple impersonated in “$149.99 unauthorized charge” scam
Anthropic’s Mythos AI used social engineering to target real people

Integrate and Deconflict Joint Fires in Space and Time - Fast!
微软:人工智能初学者课程,一共12周、24节课
NIGHTRUN – 无需操作系统,用 U 盘启动的的本地大模型客户端

底片真正的價值,不是畫質,而是 25 年後的感動。❤️
Expanding AI Benchmarks in Cybersecurity Beyond Vulnerability Discovery
CVE-2026-16812: Critical Command Injection in Arista VeloCloud Orchestrator

Hidden beneFITs: Bypassing Signature Verification in U-Boot SPL
Ruby's Bundler 4.0.18 Extends Cooldown to bundle lock and bundle cache

Off The Hook - Wed, 05 Aug 2026 19:00:00 EST
ISC Stormcast For Thursday, August 6th, 2026 https://isc.sans.edu/podcastdetail/10040, (Thu, Aug 6th)

Exhibiting DIY Satellite Antennas At The Biggest YouTube Science Fair (Open Sauce 2026)

[系统设计 Mock] Logger System
22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary], (Thu, Aug 6th)

Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages
[趣味競賽 進階 #11] 什麼?2080 Ti 居然跑得動 MiniMax-H3,還生得出 1080p 有聲影片
[Benchmark] 625 秒砍到 314 秒,快了整整一倍:MiniMax-H3 在 RTX 5090 上該開的三個開關

Adopting the Cross App Access Protocol: Get Ready for MCP Enterprise-Managed Authorization with Auth0
Find, analyze, and collaborate on user sessions in Datadog Session Replay
Required claims for GitHub flexible federated identity credentials
Worklo: Sahte Startup, Gerçek Malware
Worklo: Fake Startup, Real Malware in the Take-Home Assignment
Beyond the Bot Block: How Fastly and Experian Are Turning AI Agent Traffic into Revenue

AI Sends Global Crime Syndicates Into Fraud Nirvana

CRLF-Powered Desync Attacks: Beheading HTTP Streams

AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking
Cloudflare is the only vendor named a Visionary in 2026 SASE and SSE reports

Thousands of servers can be backdoored by exploiting buggy motherboard controllers

No Perfect Fix for AI Browser Prompt Injection Flaws
AWS partners with Anthropic and OpenAI to bring AWS Continuum into developer workflows

Anthropic’s AI used fake identities, malware in rogue attack on GitHub project

LIVE Motherboard Repair, But Chat Chooses The Repair!

CSS: The Hidden Threat Lurking in Your Inbox

Can AI do novel security research? Meet the HTTP Terminator

Can AI do novel security research? Meet the HTTP Terminator
From User Sequences to Scaling Laws: A Multi-Stage Architecture for Meta’s Ads Ranking

15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning

FPS From Scratch (C++26 & OpenGL4.6) // Gunplay

Hacking medical devices, ATMs & self-checkout machines: how to break out of kiosk prison 👨🏻💻🏧🔎⛓️💣
UK Cyber Test: AI Agent Attempted to Social Engineer Open Source Maintainer Into Merging Malware

Flaws in Google APK for Python Unlock Agent-to-Agent Attack

Who was behind the attack? Possibly nobody
Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)
From 2 weeks to 2 minutes: Amazon Cognito launches Provisioned limits for self-service rate limit management

Prisma AIRS - Unified Data Protection for Claude

FINALLY! Proxmox officially supports Arm (but not Raspberry Pi)
20260805 Wed

ARTHUR - Solve Joint Fires Deconfliction Fast!
Woori Financial Group Establishes Continuous Application Security With Xint
Puzzle Corner

40 Million Fake Push: When Spam Commits Took Over The Public GitHub

油烟机显示屏闪烁,5伏电压不稳定,不要着急,师傅告诉您维修方法
Immigration Policy: The Backdoor to Transnational Repression

This Alienware Had No Signs Of Life, But That Doesn't Mean It Is A Lost Cause!
The Agent Access Model
How we’re rethinking work at Cloudflare with Cloudflare OS
Cloudflare OS: an open platform for agents, apps, and work
WriteGuard: fine-grained controls for MCP Servers
Catching rogue AI behavior with identity-aware analytics
The Download: NASA’s new telescope and Chinese tech import curbs
CISA Adds One Known Exploited Vulnerability to Catalog

格普 GEPRC 暗星25 飞行体验报告 DarkStar25 #穿越机 #穿越机入门 #fpv穿越机 #穿越机看风景

机械臂怎么学会像人一样做任务?LeRobot+ACT模仿学习全流程
Google’s synchronized passkeys can be stolen in ‘Pass‑ta‑key’ attacks
A few notes on AWS Nitro Enclaves: KMS integration

RTX3080 核心供电 显存供电,电压偏高维修案例分享!

「帶老婆小孩去華南當背包客」早上到喜薈吃早茶,吃完之後去深圳科學館參觀,再來去深圳博物館古代歷史館參觀,晚上吃蛇口吳記脆皮雞火鍋,散步回旅館前,又在公園遊戲區玩了一下。 #11

Cherry Studio V2 来了,超详细攻略 + 真实使用场景分享
Vulnerabilities in Car Anti-Theft Device
Junk Cleaner clears the clutter from your Android
抢先注册 Cloudflare 钱包:让 AI Agent 完成自动交易
NASA’s new dark-energy space telescope can also detect killer asteroids

Angola's Largest Telco Breached Hours Before IPO

格普新版暗星25全面实测体验,如何组装?性能如何? #穿越机 #FPV #航模 #大疆O4 #遥控飞机

Starryblu虚拟卡将要暂停申请|后续购买9 9美金会员可开通虚拟卡+实体卡双持|免制卡费和邮费

关于交易所、U卡、支付工具跑路

中奖的小伙伴请在10月1日前联系我领奖

The Aikido Machine: on-prem AI pentesting that never leaves your network
DoGNAVY CyberGym Technical Report

DJI Neo 的過去、現在、未來!Neo 1 → Neo 2 → Neo 3 完整預測!🚀

关于今天帮各位无偿代激活及协助从giffgaff转CTExcel的情况说明

Continuous Offensive Security & AI Pentesting: 20 FAQs

Teardown of an Amazon (2026) Fire Stick HD
ISC Stormcast For Wednesday, August 5th, 2026 https://isc.sans.edu/podcastdetail/10038, (Wed, Aug 5th)
This Month in Datadog - July 2026

OpenAI Astra explained..
Apple battles it out again with the UK over encrypted iCloud access
Patch faster isn’t the answer. Patch smarter is.
Iran Cyberattacks Against Minnesota Water Systems
AWS Security Hub Adds Socket for Supply Chain Security
_Ivelin_Radkov_Alamy.png?width=720&quality=80&disable=upscale)
Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook
A Roadmap for Confronting the Chilling Effects of Censorship, Surveillance and New Technology
Spring 2026 PCI DSS and PCI 3DS compliance packages for AWS now available

Hacker’s tricks to spot Evil Crow USB: How to identify malicious implants in USB cables 😈🐦⬛➿🔎👨🏻💻

What are AI Agents? An explanation.

The gooey-est vintage electronics ever
20260804 Tue
Mini Shai-Hulud Hits keyv: Trojanized Release Exfiltrates CI Secrets via GitHub

Credential Harvesting Explained: How Attackers Collect Secrets From Developer Machines

格普 GEPRC 暗星25 开箱 装机教程 DarkStar25 #穿越机 #fpv穿越机 #穿越机组装 #穿越机入门

Securing Agentic AI Workflows in n8n: From Leaked API Keys to Encryption Key Compromise

From Input to Impact: Secure AI Where It Runs

最后两天帮各位从giffgaff转CTExcel的情况说明
流氓软件克星:右键菜单、自启动、计划任务、服务、浏览器插件、文件关联残留

Wiz at Black Hat 2026: Driving AI Threat Readiness

Redefining Network Security for the Frontier AI Era
The Agent Development Lifecycle has arrived on Cloudflare
Announcing Cloudflare Wallets: the programmable wallet for the agentic Internet
Run CI/CD for millions of repos — on your platform, on Cloudflare
How Cloudflare enforces engineering standards using AI
Introducing: Cloudflare Agents
Your agent can now debug Workers with local tracing
How we built a software factory to drive Astro’s GitHub issue count to zero

AI Notetaker Lets Hackers Spy on Government, Corporate Video Calls
.png)
ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2
Botnet Hunting for Vulnerabilities in Diagnostic Tools, (Tue, Aug 4th)

Escape joins Anthropic’s Cyber Verification Program to advance AI-powered offensive security
The Download: US robot restrictions, and ICE’s DNA grab
Travelers targeted when logging into hotel Wi-Fi networks
Thermo Fisher Applied Biosystems Genetic Analyzers
Acrisure KARR BT and DR-100
CISA Adds Three Known Exploited Vulnerabilities to Catalog
Online backlash ends in Google rolling back Google Earth AI tool after a day

keyv and cacheable npm Package Hijacked in Supply Chain Attack

CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild

Keyv and friends compromised in active Shai-Hulud supply chain attack
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Some Claude Chats Are Searchable on Google

红绿合体!ARM+N卡,还能跑Windows外接显卡打游戏+生产力?
Windows 10 默认壁纸,原来和 XP 壁纸一样都来自真实世界

Holy French Wobuloscope! #retro #tech #electronics #metrix

几十亿训出来的模型免费送,中国 AI 公司靠什么活?|Kimi K3作为SOTA模型为何要开源?|DeepSeek|阿里千问|开源模型|聊点不同E65
The Real Cost of Ransomware in 2026

Device Code Phishing Up 1,500% in 2026; Vishing Doubles
Pipeleek v1 Release

今天不聊天。只想帶你享受速度與自由。💥🐹7️⃣
WhatsApp account takeover scam asks you to “vote for my friend”
Secure Agent Harness Execution: Preventing Escape

Stop The Sprawl Snyk Secrets Now Generally Available

AI Model Risk Intelligence Know Which Models You Can Trust Before You Deploy

Evo Continuous Offensive Security Is Here Pentesting Grade Coverage For The 350 Days A Year You Aren't Testing

A First Look at Agentic AppSec: Agentic Remediation and Malicious Code Defense

Inside the keyv npm Compromise: preinstall Malware, Trusted Provenance, and IDE Hooks
ISC Stormcast For Tuesday, August 4th, 2026 https://isc.sans.edu/podcastdetail/10036, (Tue, Aug 4th)
How to run a Mac virus scan to check your Mac for malware
How to remove a virus or any other malware from your Mac
Two Parsers, One JSON and a Flag: Intigriti's July 2026 Challenge
AI Content Provenance is Gaining Momentum: Get C2PA Support Now with Image Optimizer

Agents vs. agents: how we triage HackerOne reports for $2 each, 85% as well as a human
[Benchmark] 一張 5090 跑會說話的 33B 影片模型:MiniMax-H3 從下載到生出第一支片
“Adult TikTok” searches lead to scams

Attackers Exploit N-able Patch Bypass Flaw on RMM Servers
The AI Act kicks into action, forces companies to be clear about AI chatbots
Californians can tell data brokers to DROP their information

New Tool Traces AI Videos Back to Their Source

Anthropic: Claude Attacks Result of Security Gaps, Not Model Issues
Trump’s AI protectionism has come for robotics

Wardriving to hack smart cars: C-ITS/V2X in connected vehicles and how to catch its messages. 👨🏻💻📻🚗🚙🏴☠
GEM Training: How Meta Doubled the Efficiency of Its LLM-Scale Ads Foundation Model
Xint Code Discovers 9.8 CVSS Critical Bug in Apple Devices

Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)
More on the OpenAI Agent’s Attack on Hugging Face
LLM Heist: Hijacking LiteLLM for Traffic Interception, Key Theft, and Tool-Call Injection
20260803 Mon

Chinese Actor Weaponizes Deepseek AI Agent to Attack Security Firm

Introducing Unit 42 Threat Intelligence: Know What Matters, Understand the Adversary, and Act Faster

I Built a Robot Mini Fridge That Runs Away From You!

Metasploit Pro 5.1 Released

I can set up a computer without touching it

Introducing the Wiz Sensor for Developer Workstations to Protect Endpoints in the AI Era

Is There Really a Fix for CISO Fatigue?
Your agent needs a computer, not a container — introducing @cloudflare/computer