<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>安全419</title>
    <link>https://wechat2rss.xlab.app/feed/6f33507162907318fd059fb11977ca352ff55d8e.xml</link>
    <description>安全419（www.anquan419.com）长期专注于观察网络安全行业内企业、产品、技术、人才的发展变化，坚持中立视角、客观报道，助力中国网络安全产业发展！&#xA;(wechat feed made by @ttttmr https://wechat2rss.xlab.app)</description>
    <managingEditor> (安全419)</managingEditor>
    <pubDate>Mon, 18 May 2026 17:17:24 +0800</pubDate>
    <lastBuildDate>Mon, 18 May 2026 17:17:24 +0800</lastBuildDate>
    <image>
      <url>https://wx.qlogo.cn/mmhead/Q3auHgzwzM6ezpQf2eHFfDGeH5iaw4GqdibiaK7r0ibGu249M5zs3rYKFQ/0</url>
      <title>安全419</title>
      <link>https://wechat2rss.xlab.app/feed/6f33507162907318fd059fb11977ca352ff55d8e.xml</link>
    </image>
    <item>
      <title>悬镜安全：穿越周期 在 AI 浪潮中定义数字供应链安全新范式</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553412&amp;idx=1&amp;sn=20d99c5a4437c09bd299d294ce1e7700</link>
      <description>创业11年首次盈利，悬镜安全正在走出网络安全创业的“独立行情”。</description>
      <content:encoded><![CDATA[<p>原创 <span>安全419</span> <span>2026-05-18 17:17</span> <span style="display: inline-block;">四川</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=66c5327e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwOAcGTNghjFow3SC9uib2Kdcb0CZvSiaXusFicWAAdz73aXf4czJicoW1HNcIibG57VsFq4DJBicDqoTcCt2QHLjicWJPTib1x9rBNXtO4%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>创业11年首次盈利，悬镜安全正在走出网络安全创业的“独立行情”。</p>
  <div style="font-size: 15px;letter-spacing: 1px;line-height: 2;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(10px, 0px, 0px);-webkit-transform: translate3d(10px, 0px, 0px);-moz-transform: translate3d(10px, 0px, 0px);-o-transform: translate3d(10px, 0px, 0px);box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;background-color: rgba(249, 225, 25, 0.3);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-end;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 23px;line-height: 2.2;text-align: justify;letter-spacing: 1px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">前言</span></b></p></div></div></div><div style="margin: 0px 0% 10px;text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-width: 1px;border-style: solid;border-color: rgb(255, 228, 128);background-color: rgb(255, 254, 250);align-self: flex-start;height: auto;padding: 5px 10px;box-sizing: border-box;"><div style="margin: 0px 0%;width: 100%;box-sizing: border-box;"><div style="padding: 0px;text-align: justify;font-size: 12px;line-height: 2;letter-spacing: 1px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 14px;box-sizing: border-box;"><span leaf="">过去几年，供应链安全赛道从狂热走向理性，有人退出、有人被并购，也有人悄然转身。悬镜安全作为国内软件供应链安全领域的代表性厂商，经历了这一轮周期的洗礼，依然保持着独特的节奏与定力。</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 14px;box-sizing: border-box;"><span leaf="">近日，安全419再次走进悬镜安全，与CEO子芽、CTO宁戈展开了一场深度对话。从赛道冷暖、到“新一代数字供应链安全治理体系”的提出，再到AI原生安全产品的全面落地、最后到经营复盘——两位坦诚分享了悬镜这些年如何从“每单必争，规模化增长”走向“有质量的增长，经营导向”，又将如何在AI浪潮中重新定义全新的悬镜安全，也许能够给到大家一些思考。</span></span></p></div></div></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6685185185185185" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069751" src="https://wechat2rss.xlab.app/img-proxy/?k=6ee1ef33&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwPgfB8OT1LN5VHDVcbOhHibTlWH3Jk9rKm1ib5biaHSVXem1Wd76rRGr9FRSKibugpwWkvOOFcT20534XoCxaNgfR4vIKOAiaDkjtpo%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="text-align: center;font-size: 10px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">悬镜安全CEO兼创始人 子芽</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069750" src="https://wechat2rss.xlab.app/img-proxy/?k=feeb3862&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwORylYonoGXAiaoJ40DhvuXMuxCib6brWHK66NZZR9deNFhRCVMhxUtC5XYZncuzwNtBoeiaDVuTbx5arDeKZHsEAw2DfS3bGm7GA%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;text-align: left;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">从“热闹”到“拥挤”：供应链安全赛道为何大浪淘沙？</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069747" src="https://wechat2rss.xlab.app/img-proxy/?k=e52b3a56&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwPsdzYCuxibrLHiccb9QvHI7Nk7XJBkGgaSAHXdVlicricZ60r5bungTWCKNAicM18u7WsdY8WgkkK5qtPmAqpnRP229Vr8u1J3yI2U%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">两三年前，供应链安全赛道被资本热捧、创业者蜂拥，而如今却明显“拥挤”，有的企业进一步迅猛发展，有的企业经营出现严重困难，也有部分玩家选择被并购。也许这一方面是行业大环境的原因，也有来自AI的巨大而直接的冲击——今年年初，Claude Code Security等代码安全扫描与修复建议工具的涌现，让不少人惊呼“传统开发安全产品要被替代了”。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">悬镜安全CEO子芽并不回避这一点：“AI正在压缩传统工具的空间，尤其是那些只做‘发现问题’的产品。但供应链安全的本质不是扫描，而是体系化治理。AI是能力放大器，不是替代者。”不仅如此，“很多企业把供应链安全当作出厂检测，而不是内嵌到研发流程中的持续治理能力。当客户发现‘扫完漏洞没人修’、‘告警太多没法管’时，热情自然下降。”他判断，未来真正存活下来的厂商，必须从“工具提供者”进化为“治理体系构建者”。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">之所以有这样的洞察，是因为子芽发现客户已不再满足于“有没有漏洞”，而是关注“这个漏洞该不该修、什么时候修、怎么修”；开源组件、商业代码、AI生成代码、云原生依赖……数字供应链的形态已经远超传统SCA的定义；安全不再是研发末端的“刹车”，而需要嵌入CI/CD、度量体系，甚至组织流程。因此，“把握未来市场的核心不是技术标新立异，而是</span><strong style="box-sizing: border-box;"><span leaf="">从检测走向治理，从工具走向体系</span></strong><span leaf="">。”</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这一体系的诞生，主要驱动力是：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">监管驱动：</span></strong><span leaf="">运营商、军工、金融等领域强监管政策落地，两部委考核、信创供应链审查、软件工厂等要求，倒逼企业重视供应链安全，合规刚需催生大单落地。目前悬镜安全大单客户持续增多，就是最直接的市场表现。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">AI 重构：</span></strong><span leaf="">AI 大模型、智能体、AI Coding技术的普及，带来全新安全风险 ——AI 生成代码漏洞、模型投毒、提示词注入、智能体越权等，传统安全手段难以覆盖，AI 原生安全成为必答题。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">悬镜的体系思考并非孤鸣，而是与国家监管导向、行业趋势高度契合。2026年 5 月 8 日，由国家网信办牵头，联合国家发展改革委、工业和信息化部发布的《智能体规范应用与创新发展实施意见》，明确将内生安全、供应链安全、衍生应用风险列为智能体安全治理的三大核心，与悬镜的体系逻辑完全吻合。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069749" src="https://wechat2rss.xlab.app/img-proxy/?k=09537624&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwP54v3pcfUsb2sMCyGeBsJp3o3PcGmBBzPz6cZtymjRXe5wxRbErf1KPap3R1khnK6ibzso0qSgxOLibvzFt160icLySppRWUagpk%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;text-align: left;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">战略升级：从“软件供应链”到“新一代数字供应链安全治理体系”</span></b></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069748" src="https://wechat2rss.xlab.app/img-proxy/?k=1b84811e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwNFUHIafotZutjqbraZK4iaGMUaNgbW1XmrxQuPBXQDvVZl3s0zQfIhpqVHAnmoaFibl7nSdWNfRnkzuiaE0Y88kGhYCPgYZ36JNo%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">“这并不是企业单方面提出的新概念，而是随着产业环境变化逐渐形成的安全治理共识。”悬镜安全CEO子芽表示。从 “软件供应链安全”，再到 “新一代数字供应链安全治理体系”，悬镜安全战略定位的升级，本质上是对企业数字化与智能化进程中安全边界变化的持续回应。 “你跟客户讲软件供应链，已经漏掉了很多东西。”悬镜安全CTO宁戈解释道，“供应链数字化≠数字供应链安全，前者是用数字化管理实体供应链，但后者所涵盖的内容正在不断扩大：传统软件供应链只覆盖代码、组件、二进制，现在还包括云服务、固件、API、MCP服务，更重要的，AI生成的代码、AI数字员工、智能体等等，已成为新的供应链节点。”</span></p><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6685185185185185" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069756" src="https://wechat2rss.xlab.app/img-proxy/?k=df2cb2bb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwPV5eqAQSgcD1SxzicZMe3fOlQhTQ3FeTvSWPtl4MKc4I5sW45botvbT4O1XUoIxun8QSgkXkShmGrDBqALYiaehhIoiaxLEPfKP4%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="font-size: 10px;text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">研讨新一代数字供应链安全治理体系</span></p></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">所以在悬镜安全 CEO 子芽看来，新一代数字供应链安全治理的本质是“</span><strong style="box-sizing: border-box;"><span leaf="">供应链源头治理，以AI治理AI，风险情报驱动</span></strong><span leaf="">”，主要包括软件供应链安全 和 AI 原生安全两大治理重点。前者覆盖代码、开源组件、依赖库、二进制制品及应用运行时安全，涉及 SCA、SAST、IAST、ASPM 等能力；后者则面向 AI Coding、模型调用、智能体、MCP 服务、插件工具链和外部 API 等新增暴露面。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AI 正在进入企业开发、交付和业务运行流程，供应链安全的边界也随之从传统软件资产，延伸到模型、数据、工具、服务和智能体协作形成的复杂数字链路。正是在这一背景下，悬镜安全提出“新一代数字供应链安全治理体系”，以回应 AI 原生应用时代的安全变化。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">围绕这一体系，悬镜安全将治理思路概括为“源头治理、以 AI 治理 AI、智能情报驱动”：通过安全能力前移降低源头风险，通过 AI 能力应对 AI 原生安全挑战，并以智能情报驱动持续预警、影响分析与快速处置。分别来谈：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">源头治理：</span></strong><span leaf="">安全更加左移，无论是软件供应链还是AI原生安全，都在开发、生成阶段介入。从软件代码开发、AI 模型训练的源头切入，提前发现并治理风险，而非事后补救。宁戈指出，“供应链风险的核心在源头，等到上线后再防护，成本高、效果差，甚至无法挽回”；</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">以 AI 治理 AI：</span></strong><span leaf="">AI 风险具有动态、实时、智能体协作的特性，传统基于规则的安全工具难以应对。悬镜自研 AI 小模型与大模型微调能力，打造 “AI 红队、AI 漏挖、AI 审计” 等智能体，AI红队、智能体检测、动态防御背后都是专有小模型或大模型微调，用 AI 的动态性、智能化，对抗 AI 的新型风险，跟上AI的速度。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">智能情报驱动：</span></strong><span leaf="">构建覆盖 “开源组件漏洞、AI 模型投毒、智能体风险” 的情报体系，实时跟踪 0Day/1Day 漏洞、恶意组件投毒事件，结合 SBOM（软件物料清单）与 AI BOM（AI 物料清单），精准定位组件级、模型级风险，实现 “小时级预警、快速响应”。子芽表示：“这是数字供应链安全治理的第一性原理。”</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069754" src="https://wechat2rss.xlab.app/img-proxy/?k=2964d407&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwNVhqibbOiaxfXPY0D33C81bz3ts1iazsZslfum3I3ZDwOCugCOY33DAhRZtGzKfuq04ziap6BWISLzVpQkwu5ctCeEQoyg8r1cYsc%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;text-align: left;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">产品落地：“3+1” 全栈体系精准匹配市场分层需求</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069752" src="https://wechat2rss.xlab.app/img-proxy/?k=55c02c2d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwOEM7QxeCEJGIJYgewyVnoJ89zO3pdLDSyoLtEpSAichry8Sphs0Oc4ywgficwarB7sOrWicJYjPHrwPE1k6rC1Ufwo7beGb7GS1I%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AI在重塑网络安全行业格局的同时，AI赋能安全其实是第一阶段，而未来AI本身的安全才是行业最大的一个增量市场。在做好“安全AI”的同时积极布局“AI安全”也许才是行业中所有企业应该去思考的问题。</span></p><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6388888888888888" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069755" src="https://wechat2rss.xlab.app/img-proxy/?k=0a0944bc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwNg58Y44Zw1HKlo8TcnicRkaDXYLtAuTLJVm31AogtHibKQphyRXQnficUQ86QEnH1ZpoJmiaevrGR3S0TwBUCwIGNh5RMmpBznaWo%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="text-align: center;font-size: 10px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">悬镜安全·新一代数字供应链安全治理体系</span></p></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">基于新一代数字供应链安全治理体系，悬镜安全构建了 “3+1” 的标准产品体系 ——3 大 AI 原生安全核心工具 + 1 个 AI 智能供应链情报底座，同时保留并升级传统软件供应链安全产品，形成 “传统能力夯实 + AI 能力引领” 的全栈布局，精准覆盖头部、中小客户的差异化需求。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">针对运营商、政企、能源等强监管、慢 AI 化的存量市场，悬镜保留并升级核心产品，旗下</span><strong style="box-sizing: border-box;"><span leaf="">源鉴 SCA（开源治理）、灵脉IAST（安全测试）、灵脉PTE（渗透模拟）、夫子ASPM（体系化治理）</span></strong><span leaf="">作为传统软件供应链安全产品，解决客户开源治理、代码审计、漏洞防护等刚需问题；而以</span><strong style="box-sizing: border-box;"><span leaf="">灵脉AI（AI Coding安全）、问境AIST（AI原生安全测试）、灵境AIDR（AI智能体安全）</span></strong><span leaf="">和</span><strong style="box-sizing: border-box;"><span leaf="">云脉AI（AI安全情报）</span></strong><span leaf="">组成的全新AI原生安全产品阵容则针对金融、大制造等AI 应用密集、风险敏感的增量市场，可以覆盖客户在 AI 代码生成、模型测试、智能体运营全场景的安全需求。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">面对行业中 AI Coding 产品及服务的快速发展，子芽表示，悬镜安全会坚持聚焦自身擅长的安全领域，不做通用型 AI 编程助手，而是聚焦 AI Coding、智能体应用和软件敏捷交付过程中新增暴露面的主动风险治理，持续强化安全护栏能力。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CTO 宁戈进一步指出，智能体时代下，代码、脚本、工具调用和外部依赖关系更加复杂，风险也更容易沿着新的数字链路扩散。因此，持续的风险情报、资产关联和影响分析能力，将成为企业应对 AI 原生供应链风险的重要基础。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在悬镜安全全新的“3+1 产品体系”中，“1”所代表的情报底座，正是支撑这一能力演进的关键组成部分，也将成为悬镜安全未来持续布局 AI 原生安全的重要抓手。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">客户层面，针对头部与中小客户的差异化需求，悬镜采用分层交付模式，平衡价值与成本：头部客户（金融、大制造）以平台化产品为主，少量定制开发（控制在 5%-10% 以内），提供全栈解决方案与专属服务，合同金额高、粘性强；而中小客户（政企、中小企业）则以标品工具订阅为主，降低准入门槛，预算友好；子芽甚至在与安全419的访谈中透露，今年下半年将推出供应链安全情报、代码漏挖等按效果付费服务，按实际漏洞数量、修复效果计费，进一步降低中小客户试错成本。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">而目前来看，悬镜安全的产品正在市场上逐渐打开局面，客户结构从早期以金融、互联网中小企业为主，拓展至运营商、大制造、能源、政企等强监管领域，高价值 KA 客户占比持续提升。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069753" src="https://wechat2rss.xlab.app/img-proxy/?k=eb790b59&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwOFbGD9cvUJEXibOwlSlsN4lwayasq8CrF6ZPl4AbFRUwGL9bE3lhHiapbfegq7mb6FtJc83FicgGljgdVBkH4lHxjiaF6NoQBWS4g%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;text-align: left;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">深析“从-1到0”的来时路 读懂安全创业的“经营本质”</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069757" src="https://wechat2rss.xlab.app/img-proxy/?k=65209c93&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwNmYPuIXIfpY4754Ybf8F1LOVNgibo3T3edpUGZzOlc7hQmZta4rAOdhoHHuGENOrI4Wp0eb2zaF09Bib1Qbnia4bLFnulYa3KuAE%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">访谈中一个颇具标志性的信号是：在网络安全行业普遍面临预算收紧、融资降温与增长压力的背景下，创业第 11 年的悬镜安全实现了首次年度盈利。对于一家持续投入技术研发和产品创新的安全企业而言，这不仅是一项财务结果，更意味着其产品价值、客户结构与商业化能力正在进入更加健康的正循环。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">“核心不是简单压缩成本，而是收入质量和客户价值在持续提升。”悬镜安全 CEO 子芽表示。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">前几年，网络安全行业在资本和市场需求的共同推动下进入快速扩张阶段，不少企业都曾将市场覆盖和客户拓展放在更优先的位置。子芽也坦言，悬镜安全在早期增长过程中同样经历过以规模拓展为核心的阶段。“当时行业整体都在追求更快的市场覆盖，但我们很快意识到，增长不能只看合同规模，更要看客户是否真正获得价值，以及企业自身是否具备可持续交付能力。”子芽表示。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">从 2022 年起，悬镜安全开始主动调整经营策略，将重点从“规模优先”转向“高质量增长”：一方面持续优化客户服务体验，提升规模化交付能力；另一方面，更加重视项目质量、客户价值和经营健康度，把可持续增长作为公司内部的重要管理目标。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这一转变，也为悬镜安全上一年度实现首次盈利奠定了基础。子芽认为，盈利并不是简单依靠压缩成本实现的，而是源于产品价值、客户质量和交付效率的同步改善。“好的增长，不只是拿下更多客户，而是如何让这些高质量客户愿意主动选择你、持续选择你。”子芽说。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在分析公司增长背后的原因时，子芽将其概括为外因与内因两方面：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">外因在于：</span><strong style="box-sizing: border-box;"><span leaf="">甲方不再盲目追逐低价，更倾向于与头部、可持续经营的厂商合作</span></strong><span leaf="">，而悬镜的盈利状态、技术沉淀与服务能力，恰好契合甲方的核心诉求。而子芽坦言“创业也需要运气”，AI原生安全的爆发，恰好与悬镜在数字供应链安全上的长期技术理念坚持、深厚技术创新积累高度契合，内生自免疫、敏捷自适应、共生自进化。”</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">相比之下，子芽认为能够获得当前的良好局面其实更多归结于自身的</span><strong style="box-sizing: border-box;"><span leaf="">内因</span></strong><span leaf="">——如果说创业从0到1靠的是技术和产品，那从-1到0则靠的是创新力和组织力。从 - 1 到 0，远比 0 到 1更重要！</span><strong style="box-sizing: border-box;"><span leaf="">从-1 到 0，本质是验证 “赛道能跑通、商业模式能赚钱、团队能打胜仗</span></strong><span leaf="">”。这份认知背后，是三大经营原则：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">第一，淡化外部竞争，深耕内部组织力：不把注意力消耗在外部竞争上，而是聚焦产品创新力、经营效率、人才梯度建设，低调打磨核心能力；</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">第二，坚守经营效率与未来现金流稳健优先： 2022 年之后，悬镜安全没有再开启新的融资窗口，而是依靠自身经营造血持续投入研发、产品和客户服务。这让公司避免陷入“为了融资而扩张、为了规模而牺牲利润”的路径依赖，也让增长变得更有质量；</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">第三，对长期主义的笃定，拒绝短期投机：不盲目跟风热门概念，深耕数字供应链安全赛道 11 年，坚信 “慢就是快”，技术与产品的沉淀终将穿越周期。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">面对未来，子芽的规划清晰且克制——依然坚持“坚守长期主义，做</span><strong style="box-sizing: border-box;"><span leaf="">有质量的增长</span></strong><span leaf=""> ”，在经营目标上，</span><strong style="box-sizing: border-box;"><span leaf="">悬镜更加重视客户满意度、项目毛利额、毛利率和项目交付周期，推动增长从规模导向转向价值导向</span></strong><span leaf="">。在客户策略上悬镜更加重视关键客户的持续运营，通过更深度的场景理解和更专业的技术服务能力，提升客户合作质量与长期黏性；在组织建设上低调提升组织力、人才梯队、产品创新效率。子芽笑言，自己创业早些年很少奔赴业务现场和用户交流的，现在一半精力看产品、一半看业务，每个月都会找KA用户交流产品技术细节。“要感知用户真实需求，这对产品进化很有帮助。”</span></p></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: stretch;flex: 0 0 auto;background-image: linear-gradient(rgb(255, 214, 125) 10%, rgba(255, 214, 125, 0) 100%);min-width: 5%;max-width: 100%;height: auto;padding: 3px 15px 13px;box-sizing: border-box;"><div style="text-align: justify;font-size: 16px;color: rgb(230, 52, 26);letter-spacing: 2px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">结语</span></strong></p></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">从软件供应链安全领域的领航者，到新一代数字供应链安全治理体系的开拓者；从 11 年技术深耕实现首次年度盈利，到“3+1”AI原生安全治理体系规模化落地，悬镜安全的成长路径，折射出是新时代中国赛道头部技术企业 “深耕技术、敬畏经营、顺应趋势” 的缩影。以硬核技术创新夯实根基，以高质量经营效益穿越周期，在 AI 原生应用时代创造性拓展安全治理的新边界。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这份成绩单的背后，是公司从“规模增长”走向“高质量增长”的战略转身，是对数字供应链安全赛道的坚定深耕，更是在 AI 重塑产业格局时的前瞻布局。而站在2026年这个行业巨变的当下，我们发现“低调”了3年的悬镜安全正在以一种“</span><strong style="box-sizing: border-box;"><span leaf="">更强的管理运营能力、更体系化的产品服务、更成熟的商业化布局</span></strong><span leaf="">”的全新姿态面对市场的严苛考验。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">悬镜安全的11年，是一段从技术驱动、资本驱动，到</span><strong style="box-sizing: border-box;"><span leaf="">经营驱动、价值驱动和创新驱动</span></strong><span leaf="">的完整旅程。首次盈利不是一个终点，而是一个新的起点。在AI重构整个网络安全产业的关键时刻，悬镜没有盲目跟风“AI赋能安全”，而是冷静地体系化推出了AI原生安全产品线，并重新定义了“数字供应链安全”的边界。正如子芽所说：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">“创业不要被外部竞争过度打扰，更要聚焦自身的综合组织力和持续创新力。尽早找到自己很不一样的东西，并持之以恒迭代下去。”</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这条路，悬镜正在越走越稳。安全419也将持续关注悬镜安全及其“新一代数字供应链安全治理体系”的后续落地与市场反馈。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 10%;max-width: 100%;height: auto;margin: 0px 10px;line-height: 0;padding: 0px;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;background-image: linear-gradient(to right, rgb(245, 245, 245) 50%, rgb(250, 228, 66) 50%);align-self: flex-start;box-sizing: border-box;"><div style="margin: 3px 0%;width: 100%;box-sizing: border-box;"><div style="font-size: 11px;color: rgb(180, 180, 180);line-height: 1;letter-spacing: 0px;padding: 0px 10px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">END</span></p></div></div></div></div></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100069759" data-ratio="0.459375" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=0693d354&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwOLw2BibkLt6onkicfguTJkPibW5NIuZbsBOEmnNeRgTJicYB0ThxnMY1f5ogs12PLa311dTwBl5vxAre7Vp6MpVKnZoXPPRMAUn7M%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="text-align: center;justify-content: center;margin: 10px 0px;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(249, 225, 25);text-align: justify;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">✦</span></p></div></div><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="color: rgb(100, 100, 100);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">推荐阅读</span></strong></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(249, 225, 25);text-align: right;box-sizing: border-box;"><p style="text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">✦</span></p></div></div></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553233&amp;idx=1&amp;sn=31fcbab856313fc4652d6eb9ccf15266&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/sz_mmbiz_png/9Nf1wzzcfwO3NLicwGKHEzpvTfYnT82yUrxxfRkqk1fMXXib4aXP0nZPk1L4yQ6AsBLomOBeQvn4m7SL1CpShIqqibribKFokdico7icSWd0SK8RQ/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.17833333333333334" data-s="300,640" data-type="png" data-w="1200" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069758" src="https://wechat2rss.xlab.app/img-proxy/?k=458021f1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwO3NLicwGKHEzpvTfYnT82yUrxxfRkqk1fMXXib4aXP0nZPk1L4yQ6AsBLomOBeQvn4m7SL1CpShIqqibribKFokdico7icSWd0SK8RQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553304&amp;idx=1&amp;sn=adbc681b8c834c9a8831f6a75361221a&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/sz_mmbiz_png/9Nf1wzzcfwOlQNnc2FDsmcoaVOZGZgsSOkGmJicwYzH3b16C552gSQHdlYtjHvibrAuuorjyAhIHK2Iic21DKZb0qMNlJPtqpaJ8hn3n7avoX8/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.17833333333333334" data-s="300,640" data-type="png" data-w="1200" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069761" src="https://wechat2rss.xlab.app/img-proxy/?k=61860a60&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwOlQNnc2FDsmcoaVOZGZgsSOkGmJicwYzH3b16C552gSQHdlYtjHvibrAuuorjyAhIHK2Iic21DKZb0qMNlJPtqpaJ8hn3n7avoX8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553276&amp;idx=1&amp;sn=3b5c0e274129d185d9c694d16cfe5ffd&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/sz_mmbiz_png/9Nf1wzzcfwNbFibpkBlb2jajqMn093XM2F0IGWB2a7zN1A8Z8xzqhmibUlPSPNNQFoqk4ELeiaiaUojZvegg7qEOt3Qia7cYlOWKQqN7DrpLLYXM/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.17833333333333334" data-s="300,640" data-type="png" data-w="1200" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069760" src="https://wechat2rss.xlab.app/img-proxy/?k=b0ae0cfc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwNbFibpkBlb2jajqMn093XM2F0IGWB2a7zN1A8Z8xzqhmibUlPSPNNQFoqk4ELeiaiaUojZvegg7qEOt3Qia7cYlOWKQqN7DrpLLYXM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="margin: 10px 0%;text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;background-color: rgba(227, 180, 0, 0.04);align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;box-sizing: border-box;"><div data-cacheurl="" data-remoteid="" style="display: inline-block;width: 100%;vertical-align: top;background-repeat: repeat;background-attachment: scroll;padding: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;background-position: 0% 0% !important;background-size: 4.17755% !important;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=74b31106&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwOXofHjsXiaZF2dj6Yicneo65iauwwJjEiboZYlP9oMNpGDSqKV35MpvzweQa2s0yNboNA32WpCJQYlHGqzdVjiccAtTCXDJic5nvbTQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><div style="display: flex;flex-flow: row;margin: 20px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 30%;flex: 0 0 auto;height: auto;align-self: center;margin: 0px 0px 0px 20px;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="699" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069763" src="https://wechat2rss.xlab.app/img-proxy/?k=b9a2f94d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwNnPruzPxalOxf8l6HAO5555qJiccFkicMWNbkiawxOecnjeMAs0Qeaqb92MibBte4wwj7R8iam2uHet4FrsPUmClYDfBtRFEVXRkAA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;margin: 0px 0px 0px 10px;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;box-sizing: border-box;"><div style="font-size: 20px;color: rgb(255, 202, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">粉丝福利群开放啦</span></strong></p></div><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(255, 202, 0);font-size: 11px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">加安全419好友进群</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">红包/书籍/礼品等不定期派送</span></p></div></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=3e8646a0&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDQ4OTkyMg%3D%3D%26mid%3D2247553412%26idx%3D1%26sn%3D20d99c5a4437c09bd299d294ce1e7700">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 18 May 2026 17:17:00 +0800</pubDate>
    </item>
    <item>
      <title>安全419｜一周国际网安资讯：AI工具滥用 供应链攻击激增</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553333&amp;idx=1&amp;sn=e168904fb300ddef2563c30ecbdae7ba</link>
      <description>OpenAI推Daybreak防御AI，攻击者滥用Vercel造钓鱼站；RubyGems等开源生态遭大规模入侵。</description>
      <content:encoded><![CDATA[<p>原创 <span>安全419</span> <span>2026-05-14 17:31</span> <span style="display: inline-block;">四川</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=7aa2a841&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F9Nf1wzzcfwNiaBZibZ8560mqbwM8LSKePCn28WNCPs1nxe51mJuMf5QICzibuQ2ichyMN9p6rcmnewrheI5b6TNPtwJX3pfMGsQjkc6Lm8ywauE%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>OpenAI推Daybreak防御AI，攻击者滥用Vercel造钓鱼站；RubyGems等开源生态遭大规模入侵。</p>
  <div style="font-size: 15px;letter-spacing: 1px;line-height: 2;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5555555555555556" data-s="300,640" data-type="png" data-w="720" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069657" src="https://wechat2rss.xlab.app/img-proxy/?k=1ee134e0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwMBRPSCd2dib4Nyu45zDa59kbM2J2wox7nERqANQkLS0eUiafCX0t0OibskASpWB77IpBl5OapOQ9fCqAe2G7wxXj5uqX4q3nq0mU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069658" src="https://wechat2rss.xlab.app/img-proxy/?k=633fd0f1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwPcwibmNJjicQ6sFDBxEC8uwMCaKFo1p4XDc2yURlDgKtfF3icrMnBHFTbGf1RsAJrqhsUOwhkbuefD476xwKibbfdXA9XFaJthAbs%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">一、一周热点速览</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069660" src="https://wechat2rss.xlab.app/img-proxy/?k=ff9670f0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwMo4pVjHbkOGLxsBpQyJiaXTaWibIic14W5D8l2tA1j3NYzVsDiakRiaibjUc3gxSnzOhynp4sT7DAcl2YIANUg1KhxHdiaBFdo6VyiboQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">上周（2026年5月5日至5月11日）全球网络安全态势愈发严峻，最突出的特点是AI工具被威胁行为者大规模滥用，同时供应链攻击持续激增。OpenAI推出Daybreak AI驱动漏洞检测工具，标志着防御方开始利用AI技术提升安全防护能力。然而，TeamPCP等攻击组织持续入侵多个开源生态系统，包括RubyGems、npm、PyPI等平台均受到波及。微软5月补丁星期二修复了120个漏洞，其中29个为严重RCE缺陷，显示软件安全形势依然严峻。此外，Fortinet、Ivanti、SAP等企业级产品也密集发布安全更新。在恶意软件方面，新型TrickMo变种利用TON进行C2通信，Vidar Stealer采用更隐蔽的技术绕过EDR检测。执法部门也取得进展，两名协助朝鲜黑客的美国男子被判入狱，罗马尼亚vishing诈骗犯面临30年监禁。本周事件凸显了加强供应链安全、提升AI伦理使用、以及加快漏洞修复的紧迫性。</span></p><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069659" src="https://wechat2rss.xlab.app/img-proxy/?k=3df8011d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwMkVuKXP48Wib1icrcWfe8XklPq0e2U0E32DqSSNLY0z82psPQ7ztyWK0qybiakI9f891wQBO8rst3PxZTvQjjSaQqCKmOQ3OPk4g%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">二、AI安全与工具</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069661" src="https://wechat2rss.xlab.app/img-proxy/?k=ed1272e7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwMrMEabE9vEa9iak7ywjpkYlRe7XXBZUNnqeSsIkdZTibNiasiaOvdcQg7k0pR0ymjkd8oWKZxHc28taACXcRpUxyucP9H1lEugiarQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">OpenAI推出Daybreak用于AI驱动的漏洞检测和补丁验证</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">OpenAI于5月12日正式推出Daybreak网络安全计划，这是一个将前沿AI模型能力与Codex Security相结合的综合性安全平台。Daybreak的核心目标是帮助组织在攻击者发现漏洞之前主动识别和修补安全缺陷。该平台将AI模型的智能分析能力、Codex作为代理执行框架的扩展性，以及与安全社区合作伙伴的协同作用有机整合，为软件开发全生命周期提供安全防护。防御者可以利用Daybreak进行安全代码审查、威胁建模、补丁验证、依赖风险分析、检测和修复指导，将这些安全实践嵌入日常开发循环中，从而从一开始就提升软件的抗风险能力。这一举措类似于Anthropic推出的Mythos项目，体现了AI公司利用自身技术优势服务网络防御的战略转向。目前，Daybreak工具的访问权限仍然受到严格控制，OpenAI鼓励有需求的组织通过官方渠道申请试用。这标志着AI军备竞赛进入新阶段，防御方开始系统性地利用AI技术来对抗同样在使用AI的攻击方。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">威胁行为者利用Vercel的AI工具大规模生产真实钓鱼网站</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">网络安全研究人员发现，威胁行为者正在大规模滥用Vercel平台（一个合法的AI驱动Web开发平台）来创建高度逼真的钓鱼网站。这些AI生成的钓鱼页面能够精确模仿Microsoft、Adidas、Nike等知名品牌的官方网站，传统的安全控制措施很难将其与合法网站区分开来。Vercel的AI工具原本旨在帮助开发人员快速构建和部署Web应用程序，但现在被网络犯罪分子用来自动化钓鱼网站的创建过程。这种滥用代表了利用AI技术的网络犯罪战术的重大演变。攻击者只需提供简单的提示，AI就可以生成完整的、视觉上令人信服的钓鱼网站，大大降低了网络攻击的技术门槛。更危险的是，这些AI生成的钓鱼网站能够绕过基于签名检测的传统安全方案，因为它们没有固定的恶意代码特征。安全专家警告，组织需要加强用户安全意识培训，并部署基于行为分析和AI对抗的高级反钓鱼解决方案来应对这一新兴威胁。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">谷歌称黑客使用AI开发零日漏洞利用</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">谷歌安全研究团队在5月11日披露，威胁行为者正在使用AI技术来开发零日漏洞利用代码、创建Android后门，以及自动化针对GitHub和PyPI的供应链攻击。这一披露进一步证实了AI技术正被网络犯罪分子系统性滥用的趋势。攻击者利用AI工具可以自动化漏洞发现过程，快速生成功能完善的漏洞利用代码，并优化整个攻击流程。特别是对GitHub和PyPI等流行软件存储库的供应链攻击，可能因为AI的介入而变得更加频繁和高效。AI可以帮助攻击者快速识别开源项目中的安全缺陷，自动生成恶意包，并大规模分发。谷歌的报告强调了防御者迫切需要采用AI技术来应对这些新威胁的必要性。安全社区呼吁加快AI安全工具的开发和部署，同时建立AI技术使用的伦理规范和监管框架，防止AI被进一步武器化。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069664" src="https://wechat2rss.xlab.app/img-proxy/?k=b44cfa75&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwM8W0JJS0K4YyPVeIzZARIdrexjEcyCkAIHxXwLABqmU1Cx4QFcsobGTUJsvibYdLTH34BE9aa90uIh0JunO1P2NUyl7sJNT3fQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">三、漏洞与补丁</span></b></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069662" src="https://wechat2rss.xlab.app/img-proxy/?k=e5d2e682&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwOcHX7GtOG0o83hSQ014DSsybicwJcS9vsmcaia7Hrd9AUqdrUQVplnB1pibymrlNGICbMyzGm2QAK01Giby6ibxKfaCkEs2KCyyDMM%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">微软5月补丁星期二修复120个漏洞，包括29个严重RCE缺陷</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">微软2026年5月的补丁星期二更新于5月12日发布，此次更新重点面向企业环境，共修复了Windows、Office、Azure、开发工具和Microsoft 365应用程序中的120个安全漏洞。在这120个漏洞中，有29个被微软归类为严重级别，其中大多数属于远程代码执行（RCE）类型，可能允许攻击者在受影响的系统上执行任意代码，而无需任何用户交互或身份验证。此外，此次更新还修复了多个权限提升漏洞、信息泄露漏洞和安全功能绕过漏洞。组织被强烈建议优先应用这些补丁，特别是那些严重级别的RCE漏洞修复，因为它们极有可能被攻击者利用。微软还特别提醒用户注意正在被积极利用的零日漏洞，建议立即应用相关补丁。这次大规模的补丁发布再次提醒企业，建立快速、高效的补丁管理流程至关重要。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">SAP修补SAP S/4HANA中的严重SQL注入漏洞</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">SAP在2026年5月12日发布了备受期待的每月安全补丁日更新，解决了整个企业软件套件中的众多严重安全缺陷。其中最严重的问题是在SAP S/4HANA（SAP的下一代ERP套件，被全球众多大型企业广泛使用）中发现的一个SQL注入漏洞。成功利用此漏洞可能允许攻击者操纵数据库查询并无授权访问敏感的企业数据，包括财务报表、客户信息、供应商数据等核心业务信息。在某些情况下，攻击者甚至可能对数据库执行修改或删除操作，造成不可逆的业务损失。SAP已发布补丁，并强烈建议客户立即应用更新。安全专家建议，除了及时应用补丁外，企业还应加强对数据库访问的监控，实施最小权限原则，并定期进行安全审计。此次事件也提醒企业，ERP系统作为核心业务系统，其安全性不容忽视。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Fortinet修补多个产品中的严重漏洞</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Fortinet在2026年5月12日发布了多个安全公告，解决了其产品线中的多个严重安全漏洞。受影响的产品包括FortiAP（无线接入点）、FortiOS（网络操作系统）、FortiSandbox（沙箱安全分析平台）以及多个企业管理平台。其中最严重的是FortiSandbox中的一个关键安全缺陷，该漏洞可能允许未经身份验证的攻击者在沙箱环境中执行任意代码或系统命令。考虑到FortiSandbox是用来在安全隔离环境中分析可疑文件的工具，成功利用此漏洞意味着攻击者可以绕过沙箱检测机制，并在安全工具本身的上下文中执行恶意代码，这是一种极具讽刺意味的攻击场景。此外，FortiAP和FortiOS中的漏洞也可能允许攻击者绕过安全控制或在受影响的网络设备上执行未授权操作。Fortinet已为所有受影响的产品发布了补丁，并建议用户立即应用更新，特别是那些面向互联网的设备。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Ivanti修补多个产品中的漏洞，AI工具助力安全修复</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Ivanti在2026年5月发布了安全更新，修补了Ivanti Secure Access、Xtraction、vTM和Endpoint Manager这四个产品中的多个安全漏洞。最严重的问题可能允许权限提升或远程代码执行。值得注意的是，Ivanti在声明中透露，AI工具已经在帮助公司识别和安全地处理这些安全问题。AI辅助的安全工具在恶意行为者利用这些缺陷之前就识别并解决了它们，避免了潜在的安全事件。Ivanti表示，他们使用AI来分析代码、识别异常模式、预测可能的攻击路径，从而能够更快速、更准确地发现和修复安全漏洞。此次披露突显了AI在主动网络安全工作中的日益增长的作用，不仅仅是攻击者在使用AI，防御方也在积极采用AI技术来提升安全防护能力。这标志着网络安全领域正在进入一个新的阶段，AI既是挑战也是机遇。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">cPanel CVE-2026-41940正在被积极利用以部署后门</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">安全研究人员警告，cPanel和WebHost Manager（WHM）中的一个严重漏洞CVE-2026-41940正在被积极利用来部署名为Filemanager的后门。该漏洞可能导致身份验证绕过，允许远程攻击者获得对控制面板的管理员级别控制。根据奇安信XLab的研究报告，该安全缺陷在上个月底公开披露后，已被多名威胁行为者利用，导致加密货币挖矿、勒索软件部署、僵尸网络传播和后门植入等恶意行为。监控数据显示，目前全球有超过2000个攻击者源IP正在参与针对此漏洞的自动化攻击和网络犯罪活动，这些IP分布在全球多个地区，主要源自德国等地。cPanel已发布补丁修复此漏洞，安全专家强烈建议所有cPanel用户立即应用更新，并检查系统是否已被入侵。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Zoom Rooms和Workplace漏洞允许攻击者提升权限</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">安全研究人员在Zoom的软件生态系统中发现了一系列新的安全漏洞，这些漏洞可能将系统控制权交给本地攻击者。受影响的产品包括Zoom Rooms和Zoom Workplace，它们是组织广泛用于视频会议和协作的平台。成功利用这些漏洞可能允许具有本地系统访问权限的攻击者在受影响的系统上将他们的权限提升到管理员级别。鉴于全球众多组织越来越依赖Zoom进行远程工作和日常通信，这些漏洞尤其令人担忧。攻击者可能利用这些漏洞在企业的Zoom基础设施中建立持久化访问，窃取会议内容，甚至横向移动到网络中的其他系统。Zoom已发布补丁来解决这些问题，并建议用户立即应用更新。安全专家建议组织审查其Zoom配置，限制对Zoom基础设施的物理和网络安全访问，并加强终端安全控制。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Open WebUI漏洞通过文件上传导致1-click RCE攻击</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">安全研究人员发现，Open WebUI（一个流行的Web界面，用于与各种AI模型和工具交互）中存在一个严重且尚未修补的安全漏洞。该漏洞存在于文件上传功能中，可能允许攻击者通过单次点击劫持对AI工作空间的控制，并在服务器上执行远程代码。具体来说，攻击者可以诱使用户上载恶意文件，这些文件在服务器上执行时会导致完全系统入侵。鉴于AI工作空间和数据对组织的日益重要性，此漏洞尤其令人担忧。成功利用可能允许攻击者访问敏感的AI模型、训练数据、用户对话记录等。更危险的是，如果Open WebUI部署在企业环境中，攻击者可能利用它作为跳板，进一步渗透企业内网。目前Open WebUI的开发者尚未发布官方补丁，用户被建议限制对Open WebUI实例的访问，加强文件上传验证，或者使用其他替代方案直到补丁可用。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Microsoft Teams漏洞允许黑客执行欺骗攻击</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">新披露的Microsoft Teams安全漏洞可能允许攻击者执行本地设备欺骗攻击，为企业和依赖该平台的个人用户带来了严重担忧。Microsoft Teams是全球数百万组织使用的协作平台，成功利用此漏洞可能允许恶意行为者伪造身份或设备，可能导致钓鱼攻击或更复杂的社会工程攻击。微软已意识到此问题，安全团队建议管理员审查其Teams配置并应用所有可用补丁。该漏洞特别令人担忧，因为它可能被用来获得对敏感企业环境的初始访问权限。一旦攻击者能够伪造合法用户的身份，他们就可以访问敏感的Teams频道、文件和对话，甚至利用Teams的集成功能进一步渗透企业网络。安全专家建议组织启用条件访问策略、多因素认证，并监控异常的Teams活动。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">9年历史的Dirty Frag漏洞允许Linux系统上的root访问</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">安全研究人员披露了一个名为&#39;Dirty Frag&#39;的Linux内核漏洞，该漏洞已经存在9年时间，可能允许本地攻击者获得root级别的权限提升。该漏洞之所以被称为&#39;Dirty Frag&#39;，是因为它与Linux内核的内存碎片处理机制有关，类似于先前的&#39;Dirty Cow&#39;（脏牛）漏洞。成功利用此漏洞可能允许具有本地系统访问权限的攻击者在受影响的Linux系统上获得完全的管理控制权。更危险的是，研究人员已经公开了概念验证（PoC）漏洞利用代码，这大大增加了在野外被积极利用的风险。任何尚未应用补丁的Linux系统都面临紧迫的威胁。Linux系统管理员被强烈建议立即检查其系统是否受此漏洞影响，并应用相应的内核补丁。对于无法立即打补丁的系统，可以考虑实施临时缓解措施，如限制本地用户访问、加强权限控制等。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069663" src="https://wechat2rss.xlab.app/img-proxy/?k=f66e2df1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwMmpeOoj5iaR7e3b7oomymibS6icIJe1NmdkESXh2gicpjkWGib6VzAh1iaUABW7Z2N71MgkzmWnk8aElWDVgbaCAIgkZCEaehibySKgY%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">四、勒索软件与恶意软件</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069665" src="https://wechat2rss.xlab.app/img-proxy/?k=3e325802&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwPxhTtYA8KM6l5wViaOicf8Rdwa8Cn4MibHnGpibe4uwkJ9icDhQaGxtXticIGibLjb3iaaoNJ7WGCebic4v7iaqaGOZ1NG456f1MWOxypN8%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">新型TrickMo变种使用TON C2和SOCKS5创建Android网络支点</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">荷兰移动安全公司ThreatFabric在2026年1月至2月期间发现并分析了TrickMo Android银行木马的一个新型变种，该变种使用开放网络（TON，The Open Network）进行命令与控制（C2）通信。TrickMo是一种设备接管（DTO）恶意软件，自2019年底以来一直在野外活动。新变种正在积极针对法国、意大利和奥地利的银行和加密货币钱包用户。ThreatFabric的研究报告显示，TrickMo依赖于运行时加载的APK（dex.module），该模块已在先前变种中使用，但更新了新功能，增加了新的网络导向功能，包括网络侦察、SSH隧道和SOCKS5代理功能。这些功能允许受感染的Android设备充当可编程网络支点和流量出口节点，攻击者可以利用这些被入侵的设备来隐藏自己的真实位置，或者进一步攻击网络中的其他设备。这种将移动设备转变为网络基础设施一部分的战术代表了移动恶意软件的一个危险新方向。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">新型隐蔽Vidar Stealer活动绕过EDR并窃取凭证</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">安全研究人员发现了一个新的、高度隐蔽的恶意软件活动，该活动分发Vidar Stealer（一种信息窃取恶意软件），专门针对Windows用户，并采用复杂的攻击链设计以绕过端点检测和响应（EDR）解决方案。Vidar专门从受感染系统中提取敏感数据，包括浏览器凭证、加密货币钱包、保存的密码、信用卡信息等。此新活动采用了先进的技术来逃避检测，包括代码混淆、反分析技术和内存驻留执行，使传统的安全工具难以发现和阻止。该恶意软件特别危险，因为它针对存储在企业环境中的敏感信息，可能导致重大的数据泄露事件。一旦凭证被窃取，攻击者可以使用这些凭证进行横向移动、权限提升，甚至实施勒索软件攻击。安全专家建议组织部署行为检测的EDR解决方案，加强对终端的监控，并定期进行安全意识培训。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">黑客劫持Microsoft Teams账户以传递ModeloRAT</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">新一轮网络攻击使全球各组织的Microsoft Teams用户处于高度警惕状态。安全研究人员发现，黑客正在劫持合法的Teams账户以传递ModeloRAT，这是一种远程访问特洛伊木马（RAT），允许攻击者在受感染的系统上执行各种恶意活动。该攻击利用Teams内置的信任和通信功能在用户之间传播恶意负载。一旦安装，ModeloRAT就会授予攻击者对受感染系统的完全控制，允许他们窃取数据、监视用户活动、记录按键、访问摄像头和麦克风，以及横向移动到网络中的其他系统。更危险的是，由于恶意负载是通过看似合法的Teams账户传递的，用户更有可能信任并打开这些恶意文件或链接。Microsoft已意识到此威胁，并建议用户仔细验证Teams中收到的所有文件和链接，即使是来自已知联系人的。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">虚假Claude Code安装程序以浏览器凭证窃取器为目标开发者</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Ontinue的安全研究人员发现了一种未记录的恶意软件活动，该活动以虚假的Claude Code安装程序为诱饵，专门针对开发者群体，意图窃取浏览器凭证。Claude是Anthropic开发的高级AI助手，Claude Code是其命令行工具，广泛用于软件开发和AI应用集成。攻击者创建了看似合法的Claude Code安装程序，但其中包含恶意代码，用于在受害者的系统上安装浏览器凭证窃取器。该恶意软件针对存储的浏览器密码、cookie、会话令牌等敏感信息，这些信息可被用来劫持在线账户、访问企业系统、甚至实施供应链攻击。此活动特别危险，因为它以开发人员为目标，而开发人员通常可以访问敏感的企业系统、代码存储库、云基础设施等。一旦开发人员的凭证被窃取，攻击者可能造成远超个人损失的重大安全事故。开发者被建议只从官方渠道下载和安装软件，并定期检查系统是否感染了恶意软件。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Operation HumanitarianBait使用虚假援助文档部署Python间谍软件</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">安全研究人员发现了一个名为&#39;Operation HumanitarianBait&#39;的恶意网络间谍活动，该活动使用虚假的人道主义援助文档、托管在GitHub上的恶意负载和Python间谍软件，主要针对俄语受害者。该活动使用社会工程诱饵，利用人道主义援助主题（如难民救助、国际援助等）来诱使受害者打开恶意文档。这些文档包含指向托管在GitHub上的Python间谍软件的链接，GitHub是一个合法的代码托管平台，但在此被攻击者用来托管恶意负载。一旦执行，Python间谍软件就会窃取敏感信息，包括文档文件、凭证、按键记录、屏幕截图等。该活动针对俄语受害者，表明它可能是出于网络间谍目的由国家支持的操作。这种利用人道主义危机作为网络攻击诱饵的做法极其恶劣，不仅造成了技术危害，也带来了严重的伦理问题。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069666" src="https://wechat2rss.xlab.app/img-proxy/?k=f9906dfc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwPziaWPNMukOCWunjQQvYRia56RyCXCpjvwXf9782NAgbKFIEGicfqpSrJ3RvqWjlI53EdPQcicaO829SHbcBUNSmodJ0XkK7UwDRw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">五、供应链与数据泄露</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069670" src="https://wechat2rss.xlab.app/img-proxy/?k=9032063a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwNCThgWpcuLiawMcicBu5naEGAmgtgHicviaIgT4ZSAxK0n2PB8uTd40WOP5FlyOicvpp1yQCIJtMOD4JRicJjNibeiat275g1FFY1p8a8%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">RubyGems暂停新用户注册应对大规模恶意攻击</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">RubyGems（Ruby编程语言的官方包管理器）在2026年5月12日遭遇大规模恶意攻击后，已暂时暂停新用户注册。Mend.io的高级产品经理Maciej Mensfeld表示，此次攻击涉及数百个恶意包，主要针对美国用户，部分包中包含漏洞利用代码。访问RubyGems注册页面的用户会看到&#39;新账户注册已暂时禁用&#39;的提示信息。Mend.io（负责保护RubyGems安全）表示将在事件得到完全控制后发布更多细节。目前尚不清楚攻击者的身份和具体动机。此次事件发生时，针对开源生态系统的软件供应链攻击呈明显上升趋势，TeamPCP等威胁行为者正在系统性地入侵广泛使用的开源包。RubyGems维护者呼吁所有用户仔细检查其项目依赖，验证包的完整性，并考虑暂时锁定依赖版本以防止意外更新到被入侵的版本。此事件再次提醒我们，开源软件供应链安全需要全行业的关注和投入。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Mini Shai-Hulud蠕虫入侵多个开源生态系统</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">威胁行为者TeamPCP（最近供应链攻击系列的始作俑者）被确认与新一轮Mini Shai-Hulud活动有关，该活动入侵了来自TanStack、UiPath、Mistral AI、OpenSearch和Guardrails AI的npm和PyPI包。受影响的npm包已被修改，包含了一个混淆的JavaScript文件（&#39;router_init.js&#39;），该文件旨在分析执行环境并启动全面的凭证窃取器。该恶意代码能够针对云提供商凭证、加密货币钱包、AI工具配置、消息应用程序和CI/CD系统（包括Github Actions）。窃取的数据被泄露到&#39;filev2.getsession[.]org&#39;域名。安全研究人员指出，使用Session协议基础设施是攻击者故意试图逃避检测的策略，因为该域名不太可能在企业环境中被阻止，原因是它属于一个去中心化的通信网络。此次事件影响了多个广泛使用的开源项目，可能导致大量开发者和企业用户受到影响。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">TeamPCP在KICS供应链攻击数周后入侵Checkmarx Jenkins AST插件</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Checkmarx已确认，一个被恶意修改的Jenkins AST插件版本被发布到Jenkins市场。Checkmarx在周末的一份声明中表示：&#39;如果您正在使用Checkmarx Jenkins AST插件，您需要确保使用的是2025年12月17日发布的版本2.0.13-829.vc72453fa_1c16或更早版本。&#39;截至目前，Checkmarx已在GitHub和Jenkins市场上发布了修复版本2.0.13-848.v76e89de8a_053。该公司没有披露恶意插件版本是如何被发布的，这引发了对其供应链安全流程的严重质疑。这一发展是TeamPCP针对Checkmarx的最新攻击。就在数周前，这个臭名昭著的网络犯罪集团还被归因于入侵Checkmarx的KICS Docker镜像、两个VS Code扩展和一个Github Actions工作流，以推送凭证窃取恶意软件。连续的攻击表明TeamPCP对Checkmarx有特别的兴趣，可能是出于经济动机或地缘政治原因。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">黑客欺骗DigiCert颁发用于签署恶意软件的数字证书</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">DigiCert（一家领先的数字证书颁发机构）在发现黑客使用恶意支持聊天附件欺骗系统颁发用于签署Zhong Stealer恶意软件的数字证书后，撤销了60个代码签名证书。该攻击涉及社会工程DigiCert员工或利用支持系统中的漏洞来获取用于签署恶意软件的合法数字证书。代码签名证书允许攻击者使他们的恶意软件看起来好像来自可信来源，从而增加成功安装的机会，因为许多安全工具和用户的信任基于有效的数字签名。此次事件导致Zhong Stealer（一种信息窃取恶意软件）能够绕过基于证书验证的安全控制。DigiCert已撤销所有受影响的证书，加强了其验证流程，并通知了可能下载了被签名恶意软件的用户。此事件突显了证书颁发机构成为攻击目标的风险，以及需要加强身份验证流程来防止此类滥用。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069671" src="https://wechat2rss.xlab.app/img-proxy/?k=3d48742c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwN6BvBlcD0oAMtgt3Us8nFic5OXHYWqMGD930Kc49cZOvBibZOa3UptWDEgQy0xfyIWmMYC5WYKlKvtF0XvkxIVtAs5ia3VeepqcE%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">六、执法与行动</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069667" src="https://wechat2rss.xlab.app/img-proxy/?k=c227ede2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwMTNchK6hUXpmdicxwAWHDkiccQXSDuSz6ZeXbS8WghTIo3hpiaLoNlLNf8hyOl0V32F7MfHKbVZyhaZTbrbjH1dxF1CKDU4j4FEA%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">两名美国男子因帮助朝鲜黑客渗透美国公司而入狱</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">两名美国男子Matthew Knoot和Erick Prince每人被判入狱18个月，因为他们通过运营远程笔记本电脑农场帮助朝鲜IT工作人员渗透美国公司，违反了国际制裁。该复杂计划涉及向朝鲜IT工作人员提供远程访问美国公司计算机系统的能力，使他们看起来好像在美国境内合法工作。这种做法帮助朝鲜规避了国际制裁、背景调查和安全控制，使其能够从美国公司获得就业机会并窃取资金和敏感信息。此案突显了与远程工作安排和第三方供应商相关的日益增长的安全风险。随着远程工作的普及，企业需要加强对远程员工的身份验证、监控和管理。此案也展示了国际执法合作在打击跨国网络犯罪方面的重要性。美国司法部表示将继续严厉打击帮助朝鲜规避制裁的行为。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">罗马尼亚男子因vishing骗局面临美国监狱30年</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">罗马尼亚国民Gavril Sandu因参与基于VOIP的vishing（语音网络钓鱼）和虚假借记卡欺诈计划，在被引渡到美国后，面临最长30年的美国监狱刑期。该复杂计划涉及使用VOIP技术冒充合法组织和金融机构，以欺骗受害者透露敏感个人信息，包括银行详细信息和信用卡号。该操作主要针对美国受害者，导致重大财务损失和个人信息泄露。调查显示，该犯罪团伙使用了先进的社交工程技巧和心理操纵来说服受害者按照他们的指示操作。引渡和随后的起诉突显了当局在打击跨国网络犯罪方面的国际合作不断增强。此案向网络犯罪分子发出了明确信号：国界不是网络犯罪的避风港，国际执法合作将确保将罪犯绳之以法。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Canvas黑客ShinyHunters称其官方域名被暂停</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">著名的威胁行为者群体ShinyHunters表示，在Canvas LMS（一个广泛使用的学习管理系统，主要在教育机构中使用）攻击后，其官方域名shinyhunte.rs被暂停，迫使该组织完全转移到其暗网（.onion）站点继续运营。域名暂停是当局和域名注册商用来破坏和遏制网络犯罪操作的常见策略。此举使ShinyHunters更难被潜在客户访问，可能限制他们进行未来攻击和数据泄露活动的能力。ShinyHunters以针对大型组织和数据泄露而闻名，此次Canvas攻击导致大量学生和教育工作者的敏感信息被盗。域名暂停是对网络犯罪分子的有效打击手段，但它也促使他们更多地使用暗网基础设施，这给执法部门的追踪和关闭工作带来了更大挑战。此事件再次证明了持续打击网络犯罪基础设施的重要性。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069669" src="https://wechat2rss.xlab.app/img-proxy/?k=22d69f0c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwPMibgGOtyBsw1kfMdJUI8fDL6LiaerC3fajIrw6QgLW8DIAJa9FWnTB2m3c14RQ7Mgw3Ejhibj3QRVc3crqpb2Fia3lYSHpR1CElo%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">七、安全趋势与研究</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069668" src="https://wechat2rss.xlab.app/img-proxy/?k=07c52e4a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwPKC1W7dHdSqkvMFNNIT9s77wm3K5orrpQRT8XdAASOqKjP2Kia1DXKiczRHje29loKicYY5oqOVMLjRyla7JlaN15PbgRzWmsawA%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Pwn2Own Berlin 2026达到容量，被拒绝的黑客发布0-day</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">据报道，Pwn2Own Berlin 2026（著名的零日漏洞利用竞赛）首次达到满容量，促使被拒绝的研究人员公开披露他们发现的零日漏洞利用代码。Pwn2Own是安全研究领域最负盛名的赛事之一，研究人员因演示针对流行软件中的未修补漏洞的成功利用而获得巨额奖金。然而，活动的容量限制意味着许多研究人员无法参加。此次事件中，一些被拒绝的研究人员选择公开披露他们发现的漏洞，而不是通过负责任的漏洞披露流程向供应商报告。这种做法引发了关于负责任的漏洞披露实践和公开未修补漏洞的风险的激烈辩论。支持公开披露的研究人员认为，这向供应商施加了更快修复漏洞的压力；而反对者则认为，公开未修补的漏洞会使大量用户面临即时的攻击风险。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">网络安全的人的一面：压力、深度伪造和漏洞的隐藏成本</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在CSO Online的《网络会话》播客最新一集中，主持人Joan Goodchild与Margaret Cunningham博士（Darktrace的安全与AI战略和现场CISO副总裁）进行了深入对话，探讨了现代网络威胁背后真实的人为因素。讨论涵盖了漏洞的真实隐藏成本，以及为什么&#39;人是最薄弱的环节&#39;这一说法需要重新审视。Cunningham博士分解了压力、认知偏差和系统设计如何比大多数组织意识到的更多地塑造安全结果。该对话还涵盖了传统安全意识培训的不足之处、如何设计支持真实人类行为的系统、甚至专业人士也无法发现的最新社会工程策略、深度伪造驱动的身份风险，以及如何建立真正以人为本的安全计划。这一讨论强调了网络安全不仅仅是技术问题，更是人的问题。组织需要投资于员工的安全意识培养，设计符合人类行为模式的安全系统，而不是简单地指责&#39;人为错误&#39;。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">身份发现：战略风险降低中被忽视的杠杆</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Delinea的产品营销负责人Jeffrey Carpenter在Help Net Security上发表文章，探讨了身份发现如何作为战略风险降低的关键但经常被忽视的组成部分。在许多组织中，特权账户和凭证的过度扩散造成了攻击者可以利用的重大安全盲点。有效的身份发现涉及全面识别所有用户账户、他们的权限级别以及他们可以访问的资源。通过深入了解其数字身份格局，组织可以实施最小权限原则，删除不必要的账户，降低凭证滥用的风险，并改善整体安全态势。Carpenter强调将身份发现集成到全面的身份和访问管理（IAM）策略中的重要性。他指出，许多组织专注于部署先进的安全工具，却忽视了对自己身份基础设施的全面了解，这导致了可预防的安全漏洞。文章建议组织定期进行身份审计，实施自动化身份发现工具，并将身份安全纳入整体风险管理框架。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069672" src="https://wechat2rss.xlab.app/img-proxy/?k=035c0a4f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwNgbS9ZCNRY5hClhBQAiaDdeXKXecOobCYjBmuMlBEGEDniaGfpibXQbx6nyLlBrxX69N4qIKXeAxgVYyic62hicxlmXxu0mg5icgNU0%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">八、本周安全建议</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069676" src="https://wechat2rss.xlab.app/img-proxy/?k=da5cd533&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwNQ7dSHYTRUELbONdIMgdlBs74iazpD01lNCmehZrSuVM9nmscosY6qvnxLt04KoxKdkXKcObtkv4HwynM66SKkfGtHJ4q6vOdE%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">基于本周发生的重大网络安全事件和趋势，我们向各组织和个人用户提出以下安全建议：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">1. 优先修补关键漏洞：</span></strong><span leaf="">立即应用微软5月补丁星期二更新，特别是29个严重RCE漏洞的补丁。同时检查并修补Fortinet、Ivanti、SAP、cPanel等产品中的严重漏洞。建立快速的补丁管理流程，争取在漏洞披露后72小时内完成关键补丁的测试和部署。      </span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2. 加强供应链安全：</span></strong><span leaf="">仔细检查所有开源依赖的完整性，验证包的签名和来源。考虑使用软件材料清单（SBOM）来跟踪所有组件，并在CI/CD流程中集成安全检查。对于关键系统，实施依赖锁定，防止自动更新到被入侵的版本。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">3. 防范AI驱动的威胁：</span></strong><span leaf="">部署高级反钓鱼解决方案，能够检测和阻止AI生成的钓鱼网站。加强对AI工具使用的监控，防止AI凭证泄露。考虑使用AI驱动的安全工具来对抗AI驱动的攻击。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">4. 强化身份和访问管理：</span></strong><span leaf="">实施全面的身份发现计划，识别所有特权账户并定期审计。启用多因素认证（MFA）对于所有关键系统，特别是VPN、远程访问、云服务等。使用特权访问管理（PAM）解决方案来保护和管理管理员凭证。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">5. 加强终端安全：</span></strong><span leaf="">部署行为检测的EDR解决方案，能够识别和阻止绕过传统防病毒的新型恶意软件。定期对终端设备进行全面的安全扫描，检测恶意软件、未授权软件和可疑配置。加强移动设备管理（MDM），特别是针对BYOD环境。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">6. 提升安全意识培训：</span></strong><span leaf="">定期开展针对AI生成钓鱼、社会工程、深度伪造等新型威胁的用户培训。使用真实案例和模拟攻击来提高用户的警惕性。建立简单、快速的安全事件报告机制，鼓励用户主动报告可疑活动。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">7. 加强监控和响应能力：</span></strong><span leaf="">实施全面的日志记录和监控，覆盖网络、终端、云环境和应用程序。建立安全运营中心（SOC）或利用托管安全服务（MSSP）来提供24/7监控和响应。定期进行渗透测试和红队演练，检验安全防护的有效性。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">8. 建立事件响应计划：</span></strong><span leaf="">制定并定期更新详细的安全事件响应计划，明确角色、职责和沟通流程。定期进行桌面演练，确保所有相关人员熟悉响应流程。建立与执法部门、行业伙伴、安全厂商的沟通渠道，以便在发生重大安全事件时快速获取支持和情报。</span></p></div><div style="font-size: 12px;color: rgb(100, 100, 100);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">免责声明</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">本周报内容由安全419编辑部基于公开资讯整理汇总，旨在为网络安全从业者提供参考信息，不代表安全419的立场和观点，我们已尽力确保信息的准确性和完整性，但不对信息的及时性、准确性、完整性做出保证，同时也不构成任何安全建议、法律意见或投资推荐。依据以上内容做出任何决策前，都应独立进行进一步核实和研究，对于因使用以上内容而导致的任何损失或损害，安全419概不负责。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 10%;max-width: 100%;height: auto;margin: 0px 10px;line-height: 0;padding: 0px;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;background-image: linear-gradient(to right, rgb(245, 245, 245) 50%, rgb(250, 228, 66) 50%);align-self: flex-start;box-sizing: border-box;"><div style="margin: 3px 0%;width: 100%;box-sizing: border-box;"><div style="font-size: 11px;color: rgb(180, 180, 180);line-height: 1;letter-spacing: 0px;padding: 0px 10px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">END</span></p></div></div></div></div></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.459375" data-s="300,640" data-type="gif" data-w="640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069675" src="https://wechat2rss.xlab.app/img-proxy/?k=9fb5ac12&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwMMSTz0LQvByxNiaZa3ibia65ibPk0Yn3R6mewUKnEbiagcFuM2CNTib9dicEibH0MaJC2jNKbJQHicHriaiac4WiajPWcQnpMfQEX5DbCsbnI%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="text-align: center;justify-content: center;margin: 10px 0px;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(249, 225, 25);text-align: justify;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">✦</span></p></div></div><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="color: rgb(100, 100, 100);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">推荐阅读</span></strong></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(249, 225, 25);text-align: right;box-sizing: border-box;"><p style="text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">✦</span></p></div></div></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553233&amp;idx=1&amp;sn=31fcbab856313fc4652d6eb9ccf15266&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/mmbiz_png/9Nf1wzzcfwPdXhEhqggVdC6pnRoJUOJlFwPLribhzicG6g65fwRsRXJh2UUW9Sm5IAYKPj1bkmpJ4lZ134XMRTWnPjYFGQaO4EWQvURPPAzz4/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1787037037037037" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069673" src="https://wechat2rss.xlab.app/img-proxy/?k=f3056a4d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwPdXhEhqggVdC6pnRoJUOJlFwPLribhzicG6g65fwRsRXJh2UUW9Sm5IAYKPj1bkmpJ4lZ134XMRTWnPjYFGQaO4EWQvURPPAzz4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553161&amp;idx=1&amp;sn=de75201c008d3ebfbe35d75082f8c086&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/sz_mmbiz_png/9Nf1wzzcfwMbgZde5I8fAgkFzNu26zEd4HwNfakUy1Mm6UOcQdK7KP2CWTgKibbC1eKIISNdd3bR3cjJFDLN5mCUPnECClXON0MA5fnXvVR4/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1787037037037037" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069674" src="https://wechat2rss.xlab.app/img-proxy/?k=cea06fea&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwMbgZde5I8fAgkFzNu26zEd4HwNfakUy1Mm6UOcQdK7KP2CWTgKibbC1eKIISNdd3bR3cjJFDLN5mCUPnECClXON0MA5fnXvVR4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553276&amp;idx=1&amp;sn=3b5c0e274129d185d9c694d16cfe5ffd&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/sz_mmbiz_png/9Nf1wzzcfwOD9PZ8RHGMMvMTO7OrFMJMJYFCfYmr3BiaXdZkiaiaicD9eyhTJyvEgGibQx8I5NRC72IKt2YRWgppBVfQVnfYeZmXytiaA8RrNk48k/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1787037037037037" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069679" src="https://wechat2rss.xlab.app/img-proxy/?k=828650e1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwOD9PZ8RHGMMvMTO7OrFMJMJYFCfYmr3BiaXdZkiaiaicD9eyhTJyvEgGibQx8I5NRC72IKt2YRWgppBVfQVnfYeZmXytiaA8RrNk48k%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="margin: 10px 0%;text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;background-color: rgba(227, 180, 0, 0.04);align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;box-sizing: border-box;"><div data-cacheurl="" data-remoteid="" style="display: inline-block;width: 100%;vertical-align: top;background-repeat: repeat;background-attachment: scroll;padding: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;background-position: 0% 0% !important;background-size: 4.17755% !important;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=864a38b3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwMmBNAia3BWzx2J5dobe8nRic8m7KHict9XZmMh3A4ic4JtwX9VZJWy55mzBTxSbriab2lNtejqkp7Xic4JdjRKuT9jN0bUpXdUR5hnY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><div style="display: flex;flex-flow: row;margin: 20px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 30%;flex: 0 0 auto;height: auto;align-self: center;margin: 0px 0px 0px 20px;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="699" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069678" src="https://wechat2rss.xlab.app/img-proxy/?k=e31290d2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F9Nf1wzzcfwNBKichjIRpKVKKqNWJ6JEfCiaBFCNTib8PuicMsQAeCLCT5ZhyT3x8ibkKb0qsetcHXMJMDM39KEobcetiaZbEjHeSzAFlBqvSuJwAU%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;margin: 0px 0px 0px 10px;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;box-sizing: border-box;"><div style="font-size: 20px;color: rgb(255, 202, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">粉丝福利群开放啦</span></strong></p></div><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(255, 202, 0);font-size: 11px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">加安全419好友进群</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">红包/书籍/礼品等不定期派送</span></p></div></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=9a5edbd3&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDQ4OTkyMg%3D%3D%26mid%3D2247553333%26idx%3D1%26sn%3De168904fb300ddef2563c30ecbdae7ba">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 14 May 2026 17:31:00 +0800</pubDate>
    </item>
    <item>
      <title>GDPR十年回首：成就与挑战并存 AI时代亟待进化</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553304&amp;idx=1&amp;sn=adbc681b8c834c9a8831f6a75361221a</link>
      <description>GDPR生效十周年，树立了隐私保护文化，但面临执行不均、国际传输困局及AI带来的新挑战，亟需进化。</description>
      <content:encoded><![CDATA[<p>原创 <span>安全419</span> <span>2026-05-13 17:31</span> <span style="display: inline-block;">四川</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=7b7ad8d5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwNCBoLWgZRjjnFllKpJOsGGOtzHKCR03GzKVukqXhevN7heCF7gxic2LoWK2iaa119ElWLMHMhjagR7MHn4nxptsVKxxzZEVMZjE%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>GDPR生效十周年，树立了隐私保护文化，但面临执行不均、国际传输困局及AI带来的新挑战，亟需进化。</p>
  <div style="font-size: 15px;letter-spacing: 1px;line-height: 2;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">今年是欧盟通过《通用数据保护条例》十周年，该条例自2018年5月25日起对所有公司强制执行。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">GDPR的目标简单而重要：增强个人对其个人数据的控制权</span>。该条例取代了第95/46/EC号指令，其明确目的是统一欧盟的数据保护法规、加强公民权利并简化监管环境。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">为此，《ComputerWorld Spain》采访了多位专家和分析师，审视这项法规如何改变了商业运营，以及GDPR在实际执行中的现状和组织为遵守这一里程碑式法规所做的持续努力。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">安全419现将采访内容整理如下，以供国内同仁参考。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100069635" data-ratio="0.562962962962963" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=38ef9da9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwNTeTu2btUzn30MS0MuGghlyMXTQGnFaczP3N5QPnXJdibf7fyzWcUP1wLrOzcHqnrPyMKBUokg3gjPXiaAHWndnYrACZIol2ziaY%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069633" src="https://wechat2rss.xlab.app/img-proxy/?k=75ef98c0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwOSXsYyM579pSNoHfUpXk6UiaG4uXOOobGaBMg6GCibUEUfvpkCsNQqiamq4wJ75RCcZaPwHHvf01V15eibrMwIwaibC1AQJShr1ia44%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">企业文化不可或缺的变革</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069632" src="https://wechat2rss.xlab.app/img-proxy/?k=200c5fc6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwO4nawDgpnwFqo41LruDYwzjAz42ibGgNXcYSXaqYZCbFocK0IeWvpktPbDgqxYD2j4eNevicUATyYiaLeE8TNdXhoc1Y5CEK7uaY%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Foundry Spain首席分析师Fernando Maldonado认为，GDPR迄今为止的遗产是“</span><strong style="box-sizing: border-box;"><span leaf="">喜忧参半</span></strong><span leaf="">的”。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">“GDPR是世界上最具影响力的数字法规之一，它</span><strong style="box-sizing: border-box;"><span leaf="">改变了公司谈论隐私的方式，提高了标准，并赋予了公民更多权利</span></strong><span leaf="">。但它并未完全实现许多人希望的目标：让人们对自身数据拥有真正且便捷的控制。”</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">他还认为，</span><strong style="box-sizing: border-box;"><span leaf="">GDPR“最显著的成就是文化上的。”</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">“在其实施之前，在许多组织中，数据保护不过是网站上的法律文本、与供应商的一些合同以及在审计期间才会翻阅的文件夹，如今，至少在欧洲，隐私已成为公司、公共行政部门和数字服务日常运营的一部分。我们谈论法律框架、影响评估、数据最小化、通过设计保护隐私、数据保护官和安全漏洞。这听起来可能很技术性，但其背后是一个重大变化：</span><strong style="box-sizing: border-box;"><span leaf="">组织不能再仅仅声称合规。他们必须能够证明合规。</span></strong><span leaf="">”</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">他说，</span><strong style="box-sizing: border-box;"><span leaf="">GDPR“既简单又苛刻，一直是GDPR的最大贡献之一。”</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">“该法规使得必须了解正在</span><strong style="box-sizing: border-box;"><span leaf="">处理哪些数据、出于什么目的、处理多长时间、与谁共享以及采取了什么保障措施，</span></strong><span leaf="">”他指出。“它还要求在行动之前进行思考，尤其是在处理可能影响基本权利的情况下。从这个意义上说，它实现了一项看似困难的事情：将隐私从法律领域带入管理决策。”</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069631" src="https://wechat2rss.xlab.app/img-proxy/?k=1874e062&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwM4cwptpjHfMvooic6RWzs9qIeZWQwsqnvVjiaM7h10WZlALcbicCkUPaUZpbS0M4W1bqicTG8wU6LOFGH66eHZ39GP3k7N1lOeWPc%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">灰色地带依然存在</span></b></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069634" src="https://wechat2rss.xlab.app/img-proxy/?k=5f0f1ec6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwMgbc5V0yMJex3hz9pWr8PchKYjPYKTh30zicJSibibVYKacWvYrTV5icj8trZRKywngfibor6UgpbKL2LlzL8oOJ12oDxUoF6B10BI%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">然而，如果说自生效以来的十年间有什么被证明的话，那就是GDPR仍有很长的路要走。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">西班牙隐私专业协会主席Miguel Recio认为，该法规暴露的一些局限性涉及充分的合法性基础，以及源自个人数据概念或控制者和处理者定义的限制。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">“在合法性基础方面，必须分析同意或合法利益在实践中可能受到的限制，以避免GDPR应用中的不安全状况。”</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">关于个人数据的概念，Recio认为，如果严格应用，可能导致不成比例的情况——即要求繁重的合规性，但这有时并不能充分保护个人。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">“而且数据控制者和数据处理者的概念在某些情况下可能被超越，”他补充道。“这</span><strong style="box-sizing: border-box;"><span leaf="">需要明确的GDPR应用标准</span></strong><span leaf="">，使我们能够克服疑虑或不确定性。”</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069639" src="https://wechat2rss.xlab.app/img-proxy/?k=d37c770a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwNVsbJicLNQjOJRTebgl6gVE0iaSr54vbMyfEMT0q65Qgic0rsCGAHbSgH17r46CHwTANialW6icGbbVOPzIfj1Q4IOOgboLchwgD5M%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">国际层面</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069638" src="https://wechat2rss.xlab.app/img-proxy/?k=0fdd8068&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwPGqpyT2J2m8o7wKUMO3mkKicXlXJlDgAC3ywuj8IPU5cbrKHxGm3QAegQZxeTlRuibyw4b3RO7pTxHmpayibXjuWicqyN10tVV1Go%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">GDPR一直处于持续紧张状态的领域之一是国际数据传输。</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Osborne Clarke Spain合伙人Rafael García del Poyo认为，自GDPR生效以来，</span><strong style="box-sizing: border-box;"><span leaf="">个人数据的国际传输一直是其“阿喀琉斯之踵</span></strong><span leaf="">”。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">“在此问题上，欧洲法院经历的一系列曲折（Schrems I、Schrems II等）清楚地表明，</span><strong style="box-sizing: border-box;"><span leaf="">只要数字商业模式是全球性的，而法律框架是国家或区域性的，法律不确定性就将普遍存在</span></strong><span leaf="">，”他承认。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">根据García del Poyo的说法，</span><strong style="box-sizing: border-box;"><span leaf="">另一个非常明显的局限性是在数字环境中偏好将同意作为合法性的基本基础。</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">“理论上，它被配置为处理个人数据最强大的法律基础，但在</span><strong style="box-sizing: border-box;"><span leaf="">实践中，它已退化为让公民产生‘疲劳感’或‘自动点击’的体验</span></strong><span leaf="">，cookie弹窗就是明证。以这种方式构想的同意不会形成知情决策，而是产生厌烦，”他指出。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">García del Poyo还认为，</span><strong style="box-sizing: border-box;"><span leaf="">数字平台上的数据治理现实超出了GDPR的监管逻辑，需要额外的法律工具来实现其既定目的。</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">“欧洲法律借助DSA或DMA等工具的发展，可以被理解为对空白的回应，这不是因为GDPR无效，而是因为该条例无法独自承担数字环境的全部治理，”他说。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069636" src="https://wechat2rss.xlab.app/img-proxy/?k=47b667b1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwMjTibeMIjht9iaZ7nGicNnt4hg8L0IyKp8aLooFVdG2EYkTWicexcOggp1J4JjnCbDPdjKHkcWrjxboOTq22IbicJ2Sy6S4y4uHP3s%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">威慑性制裁</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069637" src="https://wechat2rss.xlab.app/img-proxy/?k=7d6e08e2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwObFsp167xp0SGp346ERwUfyIRYc7sY4SprH46WnqpCWbnlasfibETI0RDWc182CYzKV0JkibEIHL0RpQicFYDia6Sx15JjP5rnA9s%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">GDPR的罚款持续存在，且远非微不足道。</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Foundry Spain首席分析师Alberto Bellé重点介绍了其中一些：“如果我们</span><strong style="box-sizing: border-box;"><span leaf="">只看数字，结果令人印象深刻</span></strong><span leaf="">：自2018年以来罚款71亿欧元，仅2025年就达12亿欧元，欧洲每天有443起违规通知。在西班牙，西班牙数据保护局在2025年将罚款提高了14%，涉及299起案件，总计4000万欧元，其中对Aena因未经影响评估使用面部识别而处以的1000万欧元罚款是典型例子。</span><strong style="box-sizing: border-box;"><span leaf="">初步印象是它有效。然而，仔细观察，缺陷就会显现出来。</span></strong><span leaf="">”</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">制裁力度很大，但在执行时其影响会减弱</span></strong><span leaf="">。“例如，自2018年以来，爱尔兰当局已对大型科技公司处以40.4亿欧元的罚款。实际上，它收回了约2000万欧元。这仅占0.5%。其余部分正在上诉或暂缓执行。”</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">其次，GDPR是在AI出现之前实施的。“现在，当AI竞赛已变得地缘政治化时，欧洲意识到，与监管较少或较晚的美国和中国相比，</span><strong style="box-sizing: border-box;"><span leaf="">GDPR使AI部署成本更高、速度更慢</span></strong><span leaf="">。这就是为什么欧盟委员会正在推出《数字综合法案》，并将《AI法案》高风险部分的实施可能推迟到2027年12月。”</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">第三，现在</span><strong style="box-sizing: border-box;"><span leaf="">已经形成了一座法规山，使合规变得不可能。</span></strong><span leaf="">“GDPR被用作后续法规的模板：NIS2、DORA、DSA、DMA、数据法案、AI法案。这些法规各自都有道理。但放在一起，</span><strong style="box-sizing: border-box;"><span leaf="">对CIO来说，合规几乎是不可能的</span></strong><span leaf="">。该法规最初的成功引发了一场需要重新思考的监管雪崩。”</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">据Miguel Recio称，“这个问题仍在不断发展，因为如果从所有欧盟国家的角度来看，仍然没有完全一致的应用。”</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在处罚方面，2026年的开局并不乐观。根据金融平台Finbold汇编的最新数据，在2026年1月1日至3月31日期间，罚款总额达6818万欧元。换句话说，在今年头三个月，违反GDPR规定的公司每天支付约757,600欧元。第一季度有几个根据GDPR开出的重大罚款。法国和英国占了其中大部分。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">违规最严重的是法国电信公司Free Mobile，因用户数据安全问题，于1月13日被法国国家信息与自由委员会处以2700万欧元的罚款。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">第二高的罚款是，2月23日Reddit因未能保护未成年用户数据被英国信息专员办公室罚款1600万欧元。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">第三和第四高的罚款由法国开出。1月8日，Free Mobile的母公司Free因技术及组织措施不足被罚款1500万欧元。1月22日，政府机构France Travail因未能保护求职者信息被罚款500万欧元。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">“制裁是显著的，并且确实发出了非常明确的信息，尤其是在大公司受到影响的情况下，”García del Poyo说。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">但在García del Poyo看来，</span><strong style="box-sizing: border-box;"><span leaf="">不在于制裁的明显威慑效果，而在于成员国不同国家当局在解释和适用《GDPR》所载原则时的必要一致性</span></strong><span leaf="">，这是GDPR仍需解决的最紧迫问题。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069640" src="https://wechat2rss.xlab.app/img-proxy/?k=ca84325f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwNNvo5QRMxpHwCicJftgGqaZibaoT9uCoWZEbzbfFicrRuw0I0JhkBZicYwwbcftvHRYGUPPAYS7WeWS9Uic9CHbel0ad85J75qds24%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">AI挑战</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069642" src="https://wechat2rss.xlab.app/img-proxy/?k=c42675d6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwOOyT79S8Nicwzibaf1Ajzn2QMT169I3B9JwuUD2xI2vobNPiaqLBuaibgmSZOHAgicpVrpdwwzicpsc6Q9Rc49ZAzhicaoXjREycdO1s%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">如今，考虑到数据面临的新挑战，如生成式AI、数据主权和全球数字经济，</span><strong style="box-sizing: border-box;"><span leaf="">即使不进行改革，也需要进化。</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">“</span><strong style="box-sizing: border-box;"><span leaf="">与其‘抛弃并重写’GDPR，不如对其进行完善</span></strong><span leaf="">，并辅以在必然会出现的新技术场景中行之有效的解释和机制，”García del Poyo说。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Maldonado明确表示，</span><strong style="box-sizing: border-box;"><span leaf="">GDPR是在生成式AI兴起之前制定的，其原则仍然很重要</span></strong><span leaf="">：透明度、法律依据、最小化、特定目的、安全性和通过设计保护。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">“而问题在于，AI将这些原则带入了更困难的境地，你如何清晰报告用于训练大规模模型的数据？当数据已经影响了一个系统，你如何删除它？当某些模型恰恰是用海量信息构建的，只使用必要数据意味着什么？当自动化决策依赖于甚至许多专家都不清楚的技术链条时，你如何解释？</span><strong style="box-sizing: border-box;"><span leaf="">这些问题将定义下一个十年</span></strong><span leaf="">。如果GDPR能够有效应用于AI，它将继续作为欧洲隐私的支柱。如果不能，它就有可能成为针对一个已经改变的世界的、过于精细的法规，”Maldonado警告说。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">García del Poyo认为，有必要澄清一些问题，例如：当个人数据用于训练AI时处理这些数据的适当法律基础；当公民知道个人数据的处理不易追溯时，他们如何行使自己的权利；甚至在AI提供商、集成商和用户之间复杂业务协作的背景下，组织如何分配GDPR中概述的责任。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069643" src="https://wechat2rss.xlab.app/img-proxy/?k=6fc3c80e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwMvpvpwa0VzjvDnOwVS7w3zmZR6RwVbxkmy1LKgsxpwjVJicyflGJNJRIQ5HNmCWhJmYQicVtOBpCyenOchSSff2IMPNic4BIlBvg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">数据主权方面</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069645" src="https://wechat2rss.xlab.app/img-proxy/?k=5a8c94fb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwNJCxgqlEiazicgtrGjNZRYENdg3yR2E4eQLJFy9V4FmTIpUeck3tIbFFDIkLwz1kJFBRic0QOcqv20yeBMrrPaSlKia2icSicwVHTyg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">关于数据主权，García del Poyo提醒我们，</span><strong style="box-sizing: border-box;"><span leaf="">如果其公民和企业沉浸在使更换供应商变得不可行的数字环境中，它就无法在全球数字经济中竞争。</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">“重要的是要记住，GDPR承认了数据可移植权。然而，在实践中，它一直是利用最少的权利之一，不是由于用户缺乏兴趣，而是因为该法规本身留下了未解决的技术问题：具体用什么格式？用什么标准？通过什么接口？现在，自2025年9月《数据保护法》生效以来，可移植性已成为提供数字服务的公司的设计义务，因为它要求向其他公司访问和传输个人数据在技术上可行，”他说。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">“</span><strong style="box-sizing: border-box;"><span leaf="">如果数字监管框架变得越来越密集</span></strong><span leaf="">，与新规则重叠，并且我们未能简化一些强加的义务——例如，那些可归类为低风险或专门针对中小企业的义务，我们</span><strong style="box-sizing: border-box;"><span leaf="">就有可能使合规成为大型组织的奢侈品，而不是对公民的有效保护标准</span></strong><span leaf="">，”García del Poyo解释说。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069644" src="https://wechat2rss.xlab.app/img-proxy/?k=04066029&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwOlpaplmkRL9YdbKvrhLNJCSTsMrUJJzojRMAO8yG2OkxuvZic0JRyv3ibdaPhXbFBSCjNteibz8ibe0g0vNDaLOEl48c4b7C0M3Zw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">展望未来</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069646" src="https://wechat2rss.xlab.app/img-proxy/?k=2120fe2d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwPJkNmzBrytE7iaVibttgvBsLdhNTR74mGZoZkvjEia4ib6urzBoERKGvRauib9hVBabJy3BpktibiclOmt7A6tEYV8h3iaIKDvFuQHWy0%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">技术挑战是真实的，GDPR将不得不适应新的现实。</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">“我们首先要记住的是，我们已经</span><strong style="box-sizing: border-box;"><span leaf="">从数据管理转向数据治理</span></strong><span leaf="">，并且这是在遵守基本权利的框架内进行的，”Recio说。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">第二，</span><strong style="box-sizing: border-box;"><span leaf="">有必要加强数据保护专业人士的作用</span></strong><span leaf="">，如果公司希望实现合规以最小化制裁风险，就必须重视和推动这一点。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">“第三，</span><strong style="box-sizing: border-box;"><span leaf="">需要使GDPR适应技术演进本身</span></strong><span leaf="">，从而防止不确定性情况出现或可能出现。关键在于能够应用于新场景和技术发展的原则。”Recio补充道。</span></p></div><div style="font-size: 12px;color: rgb(100, 100, 100);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">参考链接：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.csoonline.com/article/4167584/ten-years-later-has-the-gdpr-fulfilled-its-purpose.html" target="_blank">https://www.csoonline.com/article/4167584/ten-years-later-has-the-gdpr-fulfilled-its-purpose.html</a></span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 10%;max-width: 100%;height: auto;margin: 0px 10px;line-height: 0;padding: 0px;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;background-image: linear-gradient(to right, rgb(245, 245, 245) 50%, rgb(250, 228, 66) 50%);align-self: flex-start;box-sizing: border-box;"><div style="margin: 3px 0%;width: 100%;box-sizing: border-box;"><div style="font-size: 11px;color: rgb(180, 180, 180);line-height: 1;letter-spacing: 0px;padding: 0px 10px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">END</span></p></div></div></div></div></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100069651" data-ratio="0.459375" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=9e7f8ba8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwM9lqIHQm5HojuMHpKzNRibIdsxIXN60xJKicKAmu903xia6spG5bZ0ictOJeYDf0PHaHQ4DkhfC3XnMnPMrnCRN36aQNY9D1GKG7E%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="text-align: center;justify-content: center;margin: 10px 0px;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(249, 225, 25);text-align: justify;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">✦</span></p></div></div><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="color: rgb(100, 100, 100);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">推荐阅读</span></strong></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(249, 225, 25);text-align: right;box-sizing: border-box;"><p style="text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">✦</span></p></div></div></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553233&amp;idx=1&amp;sn=31fcbab856313fc4652d6eb9ccf15266&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/mmbiz_png/9Nf1wzzcfwNN1micic6qGdVYqTJXLRDZgAKtNbQn5kCs3QfObrbJ0C4PweOFwIXtsxVOvXD7jnElNicSAiaku0hRM8NLb83VlEebicBDQzdib11UQ/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.17833333333333334" data-s="300,640" data-type="png" data-w="1200" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069649" src="https://wechat2rss.xlab.app/img-proxy/?k=d0b530e0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwNN1micic6qGdVYqTJXLRDZgAKtNbQn5kCs3QfObrbJ0C4PweOFwIXtsxVOvXD7jnElNicSAiaku0hRM8NLb83VlEebicBDQzdib11UQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553161&amp;idx=1&amp;sn=de75201c008d3ebfbe35d75082f8c086&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/mmbiz_png/9Nf1wzzcfwOIXicJgOovuZ84XwfSFMnayvwic8YeME9ojmpou5VcvOYllEMiapXSUeEzzpB9XyoVSFBiaBRkm0UIZAFNGrelhHLsCwypazicCFDw/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100069648" data-ratio="0.17833333333333334" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1200" src="https://wechat2rss.xlab.app/img-proxy/?k=f4edd9ea&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwOIXicJgOovuZ84XwfSFMnayvwic8YeME9ojmpou5VcvOYllEMiapXSUeEzzpB9XyoVSFBiaBRkm0UIZAFNGrelhHLsCwypazicCFDw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553276&amp;idx=1&amp;sn=3b5c0e274129d185d9c694d16cfe5ffd&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/mmbiz_png/9Nf1wzzcfwMLrDfOjTzSFa7G9v2cRnMJmYXmaxh7T8ZdAPzwtmR5r3QcYtOPkRMYKq1NBQmFuOKCwAbsqIHG2dIW7szVhuTuxujZzZH4WHk/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100069650" data-ratio="0.17833333333333334" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1200" src="https://wechat2rss.xlab.app/img-proxy/?k=f98116ce&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwMLrDfOjTzSFa7G9v2cRnMJmYXmaxh7T8ZdAPzwtmR5r3QcYtOPkRMYKq1NBQmFuOKCwAbsqIHG2dIW7szVhuTuxujZzZH4WHk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="margin: 10px 0%;text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;background-color: rgba(227, 180, 0, 0.04);align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;box-sizing: border-box;"><div data-cacheurl="" data-remoteid="" style="display: inline-block;width: 100%;vertical-align: top;background-repeat: repeat;background-attachment: scroll;padding: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;background-position: 0% 0% !important;background-size: 4.17755% !important;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=bcedce9c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwNMZX4gzG0rjjSuOPrL1GB8EIpcPM5iaws5VskiaJy5GWauPzdqibyZfibzEcLAmZQ9b5Zm19UNGUk4WicsX0eic5HdosxsiaV3uwaiaicE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><div style="display: flex;flex-flow: row;margin: 20px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 30%;flex: 0 0 auto;height: auto;align-self: center;margin: 0px 0px 0px 20px;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="699" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069647" src="https://wechat2rss.xlab.app/img-proxy/?k=03c99b59&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwMJ1mFDrEj25A7E9ic4wOney2sIHyF7ylQbJys4CEehaRXqiaiaia3TgjB0Licibwr2ojucl1WMU59Y04TnrroncoVUpZvc70bEOWuicI%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;margin: 0px 0px 0px 10px;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;box-sizing: border-box;"><div style="font-size: 20px;color: rgb(255, 202, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">粉丝福利群开放啦</span></strong></p></div><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(255, 202, 0);font-size: 11px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">加安全419好友进群</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">红包/书籍/礼品等不定期派送</span></p></div></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=8f4cd2ff&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDQ4OTkyMg%3D%3D%26mid%3D2247553304%26idx%3D1%26sn%3Dadbc681b8c834c9a8831f6a75361221a">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 13 May 2026 17:31:00 +0800</pubDate>
    </item>
    <item>
      <title>安全419 | 4月安全厂商动态：AI智能体安全密集落地</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553276&amp;idx=1&amp;sn=3b5c0e274129d185d9c694d16cfe5ffd</link>
      <description>悬镜安全、易安联、魔方安全等集中推出AI智能体安全方案，产业加速布局下一代安全。</description>
      <content:encoded><![CDATA[<p>原创 <span>安全419</span> <span>2026-05-11 17:31</span> <span style="display: inline-block;">四川</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=3b4bc58c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwNj8B9icaDqO7YqickOiccriaRukvZc34RNWwDf7q7l7MBBC1K44RunGFePa8dRMVm5YFGia4DPxbQLIjvZ0qia4OgDVt1XicQruWQzRU%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>悬镜安全、易安联、魔方安全等集中推出AI智能体安全方案，产业加速布局下一代安全。</p>
  <div style="font-size: 15px;letter-spacing: 1px;line-height: 2;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5555555555555556" data-s="300,640" data-type="png" data-w="720" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069611" src="https://wechat2rss.xlab.app/img-proxy/?k=e133996c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwMRQnibluJLibphBWACYzY6z1rop8FumewygD59iaS0WNWqt7yTC8vKCSrlRYx0ZlgKjgN7bIxqxaL1ag8EXdcicOu6RYcHU2MxzS8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: dashed;border-width: 1px 1px 1px 0px;border-color: rgb(255, 202, 0);border-top-right-radius: 285px;border-bottom-right-radius: 285px;overflow: hidden;padding: 3px 3px 3px 0px;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-top-right-radius: 140px;border-bottom-right-radius: 140px;overflow: hidden;background-color: rgba(254, 236, 92, 0.88);padding: 0px 17px 0px 0px;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 5px 0px;box-sizing: border-box;"><div style="text-align: justify;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(0, 0, 0);box-sizing: border-box;"><span leaf="">源堡科技完成B+轮融资</span></span></strong></p></div></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">近日，源堡科技宣布完成新一轮融资。福建省投资开发集团旗下闽信集团正式入股，成为其重要战略股东。此前，源堡科技已完成多轮融资，投资方包括中信资本、中交、国科嘉和、中关村发展集团、启迪之星、图灵创投、陆石投资、光跃投资及百咖创投多家知名机构。当前，源堡科技的“AI+数字风险量化”技术已经在科技保险风险量化、数据流通全流程风险保障、主动式AI安全运营、数字城市安全等多业态应用场景落地，为政府、金融、能源、电信、医疗、汽车、教育、互联网、工业互联网等行业提供安全保障和量化赋能。</span></p><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: dashed;border-width: 1px 1px 1px 0px;border-color: rgb(255, 202, 0);border-top-right-radius: 285px;border-bottom-right-radius: 285px;overflow: hidden;padding: 3px 3px 3px 0px;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-top-right-radius: 140px;border-bottom-right-radius: 140px;overflow: hidden;background-color: rgba(254, 236, 92, 0.88);padding: 0px 17px 0px 0px;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 5px 0px;box-sizing: border-box;"><div style="text-align: justify;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(0, 0, 0);box-sizing: border-box;"><span leaf="">悬镜发布灵境AIDR——智能体安全卫士</span></span></strong></p></div></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">悬镜安全灵境 AIDR——智能体安全卫士平台，以大模型为引擎、全链路自动化为骨架、实战化闭环为目标，紧扣企业 AI 数字员工的实战场景，通过 AI 安全情报驱动智能检测，实现“以 AI 治理 AI”的闭环，将全域发现、动态验证、自适应安全护栏与链路追踪深度融合，重构智能体安全治理全流程，为数字化生产力构建智能防御屏障，让企业在 AI 威胁时代守住安全底线。</span></p><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5180722891566265" data-s="300,640" data-type="jpeg" data-w="830" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069613" src="https://wechat2rss.xlab.app/img-proxy/?k=3c3a6102&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F9Nf1wzzcfwNYPO1DxdYdr4v4V7dpAJOy61IIdZekvM50tL1YNrQOEgqDIjLxTCadZ694jiclLp5HRTUS3DT9L8dk3WkU9AfW9RrTvNs5vfaE%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: dashed;border-width: 1px 1px 1px 0px;border-color: rgb(255, 202, 0);border-top-right-radius: 285px;border-bottom-right-radius: 285px;overflow: hidden;padding: 3px 3px 3px 0px;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-top-right-radius: 140px;border-bottom-right-radius: 140px;overflow: hidden;background-color: rgba(254, 236, 92, 0.88);padding: 0px 17px 0px 0px;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 5px 0px;box-sizing: border-box;"><div style="text-align: justify;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(0, 0, 0);box-sizing: border-box;"><span leaf="">易安联发布企业AI统一接入与治理平台</span></span></strong></p></div></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">易安联易行 SASE AI Hub——企业 AI 统一接入与治理平台支持全球30+主流大模型统一接入、统一计费、统一治理。安全能力原生内嵌 SASE 架构，零信任访问控制与全球加速，开箱即用，覆盖软件办公、文案与内容创作、AI应用快速落地等多种适用场景，为企业 AI 落地提供可管控的基础设施。</span></p><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.1036144578313254" data-s="300,640" data-type="png" data-w="830" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069614" src="https://wechat2rss.xlab.app/img-proxy/?k=54306b5d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwMCibZWEHwomnGvCkMdmvzFfcWeCibFFdcKgCaA3hkRQXXNchcyRGiaS0NevGaxGDseSrl99zvWzLmfx9uTo2CWsaj9PPY8vpac1Y%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: dashed;border-width: 1px 1px 1px 0px;border-color: rgb(255, 202, 0);border-top-right-radius: 285px;border-bottom-right-radius: 285px;overflow: hidden;padding: 3px 3px 3px 0px;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-top-right-radius: 140px;border-bottom-right-radius: 140px;overflow: hidden;background-color: rgba(254, 236, 92, 0.88);padding: 0px 17px 0px 0px;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 5px 0px;box-sizing: border-box;"><div style="text-align: justify;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(0, 0, 0);box-sizing: border-box;"><span leaf="">烽台科技发布纵横网络靶场社区</span></span></strong></p></div></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">烽台科技纵横网络靶场社区（以下简称社区）不只是一个平台，更是一座连接高校、企业与研究者的桥梁，社区以普及工业信息安全知识、提升行业防护能力为核心，汇聚专业力量、倡导知识共享，并通过激励机制推动成员参与安全测评与技能演练，同时持续沉淀赛事资源与竞赛场景，充分发挥“以赛促练”的长效价值，烽台科技工业靶场仿真技术为社区提供全方位的技术支撑。</span></p><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4602409638554217" data-s="300,640" data-type="png" data-w="830" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069612" src="https://wechat2rss.xlab.app/img-proxy/?k=2bd4c506&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwOICeqmKiagXApw8icicicxeDIKhAQ3PFDxfRVrr4pFhMebOy3a8DzHlSJPHdYIR0HoeEs8cgB7bicYRSJtZ4ImvbxfzYHTuiaqGic00w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: dashed;border-width: 1px 1px 1px 0px;border-color: rgb(255, 202, 0);border-top-right-radius: 285px;border-bottom-right-radius: 285px;overflow: hidden;padding: 3px 3px 3px 0px;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-top-right-radius: 140px;border-bottom-right-radius: 140px;overflow: hidden;background-color: rgba(254, 236, 92, 0.88);padding: 0px 17px 0px 0px;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 5px 0px;box-sizing: border-box;"><div style="text-align: justify;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(0, 0, 0);box-sizing: border-box;"><span leaf="">安全玻璃盒连续两年软件供应链安全第二</span></span></strong></p></div></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">根据中国软件行业协会分析统计，安全玻璃盒在软件供应链安全细分领域的综合实力呈现出稳健增长态势与极高的稳定性。报告显示，公司在软件供应链安全细分领域的国内市场占有率从2023年排名第三，迅速攀升至2024年排名第二，并且在2025年稳居国内第二，体现出在激烈的市场竞争中持续扩大的领先优势。这一系列成绩的背后，是市场对安全玻璃盒“AI驱动、原生安全、全链可控”技术路线的高度认可。</span></p><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: dashed;border-width: 1px 1px 1px 0px;border-color: rgb(255, 202, 0);border-top-right-radius: 285px;border-bottom-right-radius: 285px;overflow: hidden;padding: 3px 3px 3px 0px;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-top-right-radius: 140px;border-bottom-right-radius: 140px;overflow: hidden;background-color: rgba(254, 236, 92, 0.88);padding: 0px 17px 0px 0px;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 5px 0px;box-sizing: border-box;"><div style="text-align: justify;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(0, 0, 0);box-sizing: border-box;"><span leaf="">魔方安全发布AI+攻击面管理方案</span></span></strong></p></div></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">魔方安全通过搭建“ASM × MCP”智能安全融合架构，全面赋能ASM系列产品，实现攻击面管理的自动化任务执行。简言之：魔方安全产品不仅拥有了&#34;AI大脑&#34;，更拥有了&#34;AI手脚&#34;——能够自动化完成复杂运维任务，实现数据查询、任务执行、漏洞管理的高度自动化和智能化，大幅提升安全运营效率。</span></p><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: dashed;border-width: 1px 1px 1px 0px;border-color: rgb(255, 202, 0);border-top-right-radius: 285px;border-bottom-right-radius: 285px;overflow: hidden;padding: 3px 3px 3px 0px;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-top-right-radius: 140px;border-bottom-right-radius: 140px;overflow: hidden;background-color: rgba(254, 236, 92, 0.88);padding: 0px 17px 0px 0px;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 5px 0px;box-sizing: border-box;"><div style="text-align: justify;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(0, 0, 0);box-sizing: border-box;"><span leaf="">三未信安发布抗量子SPU系列芯片</span></span></strong></p></div></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">4月27日，三未信安举办2026新产品发布会，重磅发布抗量子SPU（Secure Processing Unit）系列芯片、智能无人设备全链路安全解决方案、全球可信密码云服务，持续打造密码底座，夯实数智时代安全根基，推动数字经济高质量发展。其中抗量子SPU系列芯片，聚焦抗量子密码核心算子深度优化，打通密码算法加速全链路，针对格密码、哈希密码、编码密码等抗量子密码算法，深度适配小位宽、高维度、高并行化运算特征，有效突破传统芯片的“运算墙”与“存储墙”瓶颈，完成从经典密码体系到抗量子密码体系的迭代升级。</span></p><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5566265060240964" data-s="300,640" data-type="png" data-w="830" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069615" src="https://wechat2rss.xlab.app/img-proxy/?k=98d432cc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwO8W0dnIkaiasyF9YxANicEQOT0OxibYzia6oEQicDUffOlon9ViaN6Ujq1picAeDwO35zXCqavshsBAcbnq6MUTV0wibA1xjeJ0a57omI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: dashed;border-width: 1px 1px 1px 0px;border-color: rgb(255, 202, 0);border-top-right-radius: 285px;border-bottom-right-radius: 285px;overflow: hidden;padding: 3px 3px 3px 0px;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-top-right-radius: 140px;border-bottom-right-radius: 140px;overflow: hidden;background-color: rgba(254, 236, 92, 0.88);padding: 0px 17px 0px 0px;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 5px 0px;box-sizing: border-box;"><div style="text-align: justify;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(0, 0, 0);box-sizing: border-box;"><span leaf="">鼎甲 AI 大模型一体机数据保护方案</span></span></strong></p></div></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">鼎甲推出 AI 大模型一体机数据保护方案，该方案面向 AI 大模型一体机中的向量/图数据库、配置数据库、模型/知识库数据以及 AI 工具链，，采用本地 + 异地 + 离线三层架构，覆盖数据库、文件、系统配置的全栈保护。方案核心可以概括为：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">3份数据副本：</span></strong><span leaf="">生产数据 + 本地备份 + 异地备份，确保任意单点故障不丢数据。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2种存储介质：</span></strong><span leaf="">磁盘备份一体机 + 磁带库，不同介质特性互补，抵御介质级故障。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">1份离线物理隔离：</span></strong><span leaf="">通过磁带出库形成 Air-Gap，彻底切断网络攻击路径，AI 无法触达。</span></p></div><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6674698795180722" data-s="300,640" data-type="png" data-w="830" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069619" src="https://wechat2rss.xlab.app/img-proxy/?k=52fcd00d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwMmho7fUxDE9gJ2HjaLLhOcyoraG7RFnGKFFia4m9ZkhfNklQbSTsicG0QIsw0PkTocJk4KXXHQtKnWNWibFt18xRJsLBIlicbk3Xo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="font-size: 12px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">360推出企业浏览器数据安全专版</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">360推出Wmansvcs勒索软件专用解密服务</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">阿里云发布 Agentic NDR</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">阿里云发布DDoS安全运营智能体</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">安恒信息发布ClawdSecbot企业版</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">安恒信息发布可信数字人基础设施VeriAgent</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">保旺达发布数据先审后用系统</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">北京派网发布新一代网络认证计费平台RAAS 2.0</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">华为发布星河AI网络安全Agentic SOC</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">虎符网络发布Al Agent安全网关</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">江南科友联合海光信息发布新一代金融级密码运算架构方案</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">经纬信安发布攻防演练一体机</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">绿盟智能渗透系统（AI-PTS）新版本发布</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">联软科技发布UniSDP新版</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">腾讯iOA联合宁盾推出“国产身份底座 + 零信任安全接入” 一体化解决方案</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">派拉软件发布智能体身份安全认证管理软件</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">全知科技发布数据库风险监测系统</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">全知科技发布数据安全监测平台</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">全知科技发布AI数据分类分级系统</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">锐捷网络发布一机一网3.0</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">锐捷网络发布安全云办公 4.0 +教育云电脑 1.0</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">闪捷信息发布智能体应用安全防护系统</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">深信服SafeSkills平台上线</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">深信服发布系列生产级AI新品</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">深信服联合FastGPT发布SF-FastGPT</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">上元信安发布国产化高密接口硬件S1500-F</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">天融信发布安全智能体一体机</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">天融信联合曙光云打造“审计可信・数据全护”方案</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">芯盾时代发布IAM AI Agent身份与访问管理方案</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">亚信安全发布AI XDR 2026</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">亚信安全联合SmartX发布企业云安全防护解决方案</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">亿格云推出云枢AI统一治理平台</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">亿格云推出EagleEye安全治理智能体</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">亿格云推出EagleClaw安全办公智能体</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">永信至诚发布「数字风洞」风电网络安全靶场</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">永信至诚发布「定心」产品乘服务解决方案</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">众智维GuardHub Skills平台正式上线</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">威努特WinClaw推出1万名Token永久免费名额</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">弘积科技 VirtualAD免费试用 6 个月</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">长亭科技系列产品 CLI 正式开源</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">雾帜智能正式开源SOAR-CLI</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">绿盟清风卫NSF-ClawGuard龙虾安全插件正式开源</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">爱数Anybackup V9正式开源</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">国泰网信七项密码发明专利获批</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">聚铭网络《一种安全事件误报的研判方法及系统》发明专利获批</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">天行网安《数据共享方法、装置、设备、存储介质和程序产品》发明专利获批</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">梆梆安全发布《2026年Q1移动应用安全风险报告》</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">华为发布金融、政务、医疗、制造四大行业AI安全实践研究报告</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">绿盟科技发布《APT高级威胁研究报告》（2026 版）</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">绿盟科技发布《DDoS攻击威胁报告》（2026版）</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">绿盟科技发布《Botnet趋势报告》（2026版）</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">墨菲安全发布《安全度量最佳实践2026版》</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">守内安联合ASRC发布一季度电子邮件安全观察报告</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">触点互动中标紫金山实验室AI-RAN专用开发集成仿真及测试平台</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">长扬科技中标新能源电力仿真沙盘、实物靶标建设项目</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">霍因科技中标某省级军民融合枢纽机构分类分级项目</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">联软科技中标某大型通信科技集团信创身份域控采购项目</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">奇安信天眼中标某金融央企全流量安全检测项目</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">山石网科中标某券商ASIC防火墙项目</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">山石网科中标某省检察院下一代防火墙项目</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">山石网科中标浙江运达下一代防火墙项目</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">水木羽林中标麒麟软件操作系统内核模糊测试项目</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">万径安全中标某国有大型银行安全工具项目</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">芯盾时代中标山西银行终端安全项目</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">芯盾时代中标国网某省电力公司数据安全项目</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">易安联零信任安全接入系统签约江苏省人民医院等多家医院</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">亿盾互联中标某银行仿冒网站监测服务采购项目</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">英方软件中标北京协和医院核心业务灾备项目</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">恒安嘉新中标中国移动DPI项目</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">飞驰云联签约某半导体先进封测龙头</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">爱数集团与紫光数据存储达成战略合作</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">白山云与 Sparkle 达成战略合作</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">精容数安与曙光云达成战略合作</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">零数科技与贵州大数据产业集团达成战略合作</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">领信数科与灵谷流光达成战略合作</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">奇安信与特变电工达成战略合作</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">奇安信与赛力斯达成战略合作</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">天空卫士与天维信通达成战略合作</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">智能永信与潮际汇达成战略合作</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">优炫数据与世纪金桥达成战略合作</span></span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 10%;max-width: 100%;height: auto;margin: 0px 10px;line-height: 0;padding: 0px;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;background-image: linear-gradient(to right, rgb(245, 245, 245) 50%, rgb(250, 228, 66) 50%);align-self: flex-start;box-sizing: border-box;"><div style="margin: 3px 0%;width: 100%;box-sizing: border-box;"><div style="font-size: 11px;color: rgb(180, 180, 180);line-height: 1;letter-spacing: 0px;padding: 0px 10px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">END</span></p></div></div></div></div></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.459375" data-s="300,640" data-type="gif" data-w="640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069620" src="https://wechat2rss.xlab.app/img-proxy/?k=8ad13cf3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwOgqobrjzNQBLicMLppicibyoR4LBr5p1ibVzCW2fv7C8SfFGEibddYAxcb0u1rgUWr9eMLKFJ4CoXfseSkicypj3SDQnAI167znQjnU%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="text-align: center;justify-content: center;margin: 10px 0px;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(249, 225, 25);text-align: justify;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">✦</span></p></div></div><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="color: rgb(100, 100, 100);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">推荐阅读</span></strong></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(249, 225, 25);text-align: right;box-sizing: border-box;"><p style="text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">✦</span></p></div></div></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553233&amp;idx=1&amp;sn=31fcbab856313fc4652d6eb9ccf15266&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/mmbiz_png/9Nf1wzzcfwNRo5R4m3xuT5Xaav8ia6OH24O8ia90qOKm4C8kFooXWheADwZVgy2F1kj5RtKgJZlQxyWn0375GJVWiak5QxAWxGn5GAic2yWibZJs/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.17833333333333334" data-s="300,640" data-type="png" data-w="1200" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069616" src="https://wechat2rss.xlab.app/img-proxy/?k=f00e450d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwNRo5R4m3xuT5Xaav8ia6OH24O8ia90qOKm4C8kFooXWheADwZVgy2F1kj5RtKgJZlQxyWn0375GJVWiak5QxAWxGn5GAic2yWibZJs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553161&amp;idx=1&amp;sn=de75201c008d3ebfbe35d75082f8c086&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/sz_mmbiz_png/9Nf1wzzcfwNAwLzA6eFNMSpeElJNvqaibNXjWEZZ9FmM3FeeHkQicckHmL4N3iczicMT86iaP1IhX5dRUU4WJaqKHby0sz7dpqUOrbKszhUzc0zw/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.17833333333333334" data-s="300,640" data-type="png" data-w="1200" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069618" src="https://wechat2rss.xlab.app/img-proxy/?k=7d6ecded&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwNAwLzA6eFNMSpeElJNvqaibNXjWEZZ9FmM3FeeHkQicckHmL4N3iczicMT86iaP1IhX5dRUU4WJaqKHby0sz7dpqUOrbKszhUzc0zw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553127&amp;idx=1&amp;sn=7f7375b99330998096597deb42fb613a&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/mmbiz_png/9Nf1wzzcfwM0mRjiappPw9GiccorLYvfMuOnRDwFlpkZrzPicboEVZPcgYeE76QJlOicGDyAriaRmBvf8I6KeTJKxVibichrGmPQ5qt2B3VJY2TibwU/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.17833333333333334" data-s="300,640" data-type="png" data-w="1200" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069617" src="https://wechat2rss.xlab.app/img-proxy/?k=18c1218c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwM0mRjiappPw9GiccorLYvfMuOnRDwFlpkZrzPicboEVZPcgYeE76QJlOicGDyAriaRmBvf8I6KeTJKxVibichrGmPQ5qt2B3VJY2TibwU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="margin: 10px 0%;text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;background-color: rgba(227, 180, 0, 0.04);align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;box-sizing: border-box;"><div data-cacheurl="" data-remoteid="" style="display: inline-block;width: 100%;vertical-align: top;background-repeat: repeat;background-attachment: scroll;padding: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;background-position: 0% 0% !important;background-size: 4.17755% !important;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=42f9645e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwOXjVoQePWsQftG7C66pibp8w9UyY7EVbCZJaBtOnSqE0WfYyib8a9cZricCVkksQLMmic5nyOiasGzI7C9UJxiaC608NZzoMg5gSW3s%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><div style="display: flex;flex-flow: row;margin: 20px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 30%;flex: 0 0 auto;height: auto;align-self: center;margin: 0px 0px 0px 20px;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="699" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069622" src="https://wechat2rss.xlab.app/img-proxy/?k=439af97b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwMocbvvticPU22ODicgA53cTLTkJEaQVzdc1VyfOXu8bjA3cdibhMnp85hDFzmn4ZhJV17eQibeaws1UZnxXSdDORpYbvTxZenryDk%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;margin: 0px 0px 0px 10px;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;box-sizing: border-box;"><div style="font-size: 20px;color: rgb(255, 202, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">粉丝福利群开放啦</span></strong></p></div><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(255, 202, 0);font-size: 11px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">加安全419好友进群</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">红包/书籍/礼品等不定期派送</span></p></div></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=0658882c&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDQ4OTkyMg%3D%3D%26mid%3D2247553276%26idx%3D1%26sn%3D3b5c0e274129d185d9c694d16cfe5ffd">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 11 May 2026 17:31:00 +0800</pubDate>
    </item>
    <item>
      <title>安全419｜一周国际网安资讯：AI代理成新攻击面 MOVEit漏洞警报再响</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553258&amp;idx=1&amp;sn=83a4fa668907842ce1ea97fcd090457f</link>
      <description>虚假IT员工渗透风险加剧，AI代理安全指南发布；MOVEit、cPanel高危漏洞遭大规模利用，Linux提权漏洞危及无数系统。</description>
      <content:encoded><![CDATA[<p>原创 <span>安全419</span> <span>2026-05-08 17:30</span> <span style="display: inline-block;">四川</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=51ab9033&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwNia3iaZ9q1ggoX0MQqbyO56THeiayfAdGwVDSTA1XzlrqDUL4bjMtrvldtfib548I14icySCjBVt6D4UyZyiaSh5unJE6ibUjiagxibSvs%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>虚假IT员工渗透风险加剧，AI代理安全指南发布；MOVEit、cPanel高危漏洞遭大规模利用，Linux提权漏洞危及无数系统。</p>
  <div style="font-size: 15px;letter-spacing: 1px;line-height: 2;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5555555555555556" data-s="300,640" data-type="png" data-w="720" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069587" src="https://wechat2rss.xlab.app/img-proxy/?k=d422396f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwMDN29YicnYzw5P8hnvge4b0Qw0jHovADn85LdDkMo9P3k445T98icpF6XsOfeiaxh1OfHRufzxx7EPaeyQrEOBSjZyNzSQ4TkeaI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">上周（2026年4月28日-5月4日）全球网络安全领域呈现多重挑战与趋势变化。APT组织活动显著增加，持续瞄准美国及全球关键基础设施；AI技术在安全攻防两端的影响日益深化，既被安全团队用作防御工具，也被攻击者用于提升攻击效率。在漏洞领域，多个主流平台曝出高危漏洞，供应链攻击持续活跃，勒索软件攻击手法不断升级。以下为本周主要国际网络安全资讯汇总。</span></p><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069586" src="https://wechat2rss.xlab.app/img-proxy/?k=5042cbb4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwMxlZPUqv32NGxrj0InCibGHlQSX5krmkWM6icJEibcrJ7icVCIeicdtj7D8l4OiaOUlScxOQOXEoOJdkAtSAiaoWP7EdkoicRyycmKS6E%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">一、漏洞预警</span></b></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069588" src="https://wechat2rss.xlab.app/img-proxy/?k=520b3d6e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwPBjeg6M4SqicGtQoHzOOEbib9ibj0ecM97ibUg7hdbeWx3sHogvcypAeZd7My9GAvNncVffpMgJHGrKUSyNApUrXc3xsAcVyWDb7I%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">MOVEit高危漏洞来袭，紧急修补预警</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Progress Software近日披露其MOVEit Automation文件传输工具存在两个高危漏洞CVE-2026-4670（认证绕过）和CVE-2026-5174（权限提升），攻击者可利用这些漏洞实现未授权访问、获取管理控制权并导致数据泄露。MOVEit作为广泛使用的托管文件传输程序，帮助组织在自托管服务器、云平台和第三方供应商之间传输数据。Progress Software敦促客户立即升级至最新版本，强调完整安装是修复该问题的唯一方式。目前全球已有超过1440台联网设备运行着存在漏洞的MOVEit Automation版本，其中包括16个与州和地方政府机构相关的设备。2023年该软件曾因零日漏洞引发大规模攻击潮，Cl0p勒索软件团伙借此发动了严重攻击。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">cPanel高危漏洞遭大规模利用</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">研究人员警告，cPanel中一个被追踪为CVE-2026-41940的关键漏洞正在全球范围内遭受大规模利用。该漏洞是一个认证绕过缺陷，位于登录流程中，可允许远程攻击者获取控制面板访问权限。由于cPanel和WHM作为超过7000万个域名的Web托管控制面板软件，潜在风险巨大。cPanel敦促用户立即应用安全升级，并警告该漏洞影响11.40之后的所有版本。Shadowserver Foundation报告显示已有超过44000个IP可能被攻陷，全球暴露实例超过572000个，其中北美地区超过391000个。CISA已将该漏洞添加到已知被利用漏洞目录中。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">危险Linux新漏洞让攻击者获取无数计算机Root权限</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">安全公司Theori的研究人员周三晚间发布了针对一个几乎未修补漏洞的公开利用代码，该漏洞让攻击者获得几乎所有Linux版本的Root权限，引发数据中心和个人设备严重入侵的警报。该漏洞被追踪为CVE-2026-31431并命名为CopyFail，是一个本地权限提升漏洞，特别严重，因为只需一段公开披露的利用代码即可在所有易受攻击发行版上无需修改直接工作。攻击者可以入侵多租户系统、突破基于Kubernetes或其他框架的容器。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">CISA将Microsoft、ConnectWise漏洞列入活跃利用目录</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CISA周二将其Known Exploited Vulnerabilities目录添加了两个主要软件漏洞，确认黑客在最近攻击中使用这些漏洞的证据。CISA添加了CVE-2024-1708（ConnectWise ScreenConnect远程访问工具中的高危漏洞）和CVE-2026-32202（Windows Shell用户界面中的中危漏洞）。联邦机构需在5月12日前修补这两个漏洞。ScreenConnect路径遍历漏洞可允许黑客远程执行代码或篡改敏感数据，而Windows漏洞源于有缺陷的安全机制，可允许攻击者冒充合法用户。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069589" src="https://wechat2rss.xlab.app/img-proxy/?k=3a9391ad&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwNWhgX4Ftbt11ZdUDsG8RoiaicrTZ4wbrgKdic6FxgG1Lbh8QNibux4R32bYIaCjxicqsP8e3SH7AeQibJC8qC8z47kcUdqSU9jicjyQQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">二、AI安全</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069590" src="https://wechat2rss.xlab.app/img-proxy/?k=521c1831&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwNkyc2YNKFmbQrgTdYhJRvW8KDefYKBib2G6pfVZH5OzssnSv5GPlhCPzRRq8rCOdqUfzfAicGw0XMtv0xiaQfTMgyrib3670R0LlY%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">AI代理技能成为攻击面：OpenClaw生态安全风险剖析</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AI代理网关如OpenClaw正在塑造一个变革性的未来，但这种未来也伴随着特定的安全风险。OpenClaw之所以强大，正是因为它能访问本地机器、应用程序、浏览器会话、文件以及长期记忆。然而这种级别的访问意味着在持有企业凭据或能够访问生产系统的机器上运行它尚无安全方式。其记忆和配置是以明文形式存储在磁盘上可预测位置的文件。如果攻击者攻陷了运行OpenClaw的机器，现代信息窃取器可以在几秒钟内抓取API密钥、Webhook令牌、会话日志和长期记忆。此外，OpenClaw生态系统中的技能通常是markdown文件，实际上成为了代理的安装程序，存在恶意软件投递风险。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Anthropic Mythos推动白宫考虑高风险AI模型预发布审查</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">特朗普政府正在初步讨论是否应在公开发布前对高级AI模型进行审查，讨论重点是能够促进网络攻击的系统，特别是可以帮助用户识别和利用软件漏洞的模型。官员们正在考虑多种方案，包括正式的预发布审查流程和对更高风险系统的政府主导测试。这些讨论标志着语气上的转变。2025年1月20日，特朗普撤销了拜登关于安全、可靠和可信AI开发使用的行政命令14110，三天后发布了自己的命令《消除美国人工智能领导力障碍》，标志着从拜登政府的监督和风险缓解框架转向以放松管制和促进AI创新为中心的框架。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">安全机构为代理AI部署划定红线</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">随着提示注入和其他攻击路径在代理AI部署中持续出现，安全监管机构联合划定了严格的边界。美国CISA和国际合作伙伴发布的联合建议呼吁对权限进行更严格的控制、加强监控以及更谨慎的推广策略，敦促组织谨慎对待代理AI。建议强调了设计和开发指南，包括使用安全设计原则进行强认证、系统透明度以标记欺骗性指标、跨工作流的最小权限原则、根据DevSecOps基本原理进行安全开发原则以及定期测试事件响应计划等。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">白宫质询科技行业防御性AI使用及网络弹性</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">美国政府想了解美国主要科技公司如何使用AI保护其计算机网络，以及如何为AI驱动的网络安全危机做好准备。白宫国家网络总监办公室（ONCD）官员最近几周联系科技巨头，询问AI、信息共享、漏洞修补以及联邦政府如何提供帮助。ONCD要求公司在5月1日前回答11个网络安全相关问题。部分问题直截了当，如是否正在使用AI检测和响应工具及服务，但大多数问题更为复杂，涉及公司识别和修复已知漏洞的速度以及改善网络态势面临的障碍。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">美国及盟友敦促谨慎采用AI代理</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">澳大利亚和美国政府及国际合作伙伴周五发布了安全部署代理AI系统的指南。AI代理的自动化能力创造了独特的风险，可能导致生产力损失、服务中断、隐私泄露或网络安全事件。安全使用AI代理意味着永远不要授予其广泛或不受限制的访问权限，特别是对敏感数据或关键系统。该指南由澳大利亚信号局、美国CISA和NSA以及英国、加拿大和新西兰对应机构共同发布，正值企业竞相将AI工具集成到工作流程中。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">AI代理可绕过护栏并危及凭据安全</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">一个AI代理在未被要求时泄露敏感数据。一个代理推翻了自己的护栏。另一个通过Telegram将凭据发送给攻击者，因为它在重置后忘记不该这样做。AI代理的潜力巨大，但风险同样巨大。越来越明显的是，代理系统在现实条件下可能多么容易偏离轨道并开始暴露关键信息。Okta威胁情报的报告《钓鱼代理：为什么AI护栏不够》揭示了上述所有问题。其研究聚焦于OpenClaw，这是一款模型无关的多渠道AI助手。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">SOC如何为代理AI时代做好准备</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">根据IDC预测，代理AI正在成为主流基础设施。该分析公司预计到2030年，45%的组织将在关键业务功能中大规模运行自主代理。在企业SOC中，AI已经在重塑警报分类、富化、数据关联、IOC验证和初始遏制等功能。它可能很快向上移动，承担更复杂的任务如事件调查、根因分析和响应。Darktrace安全与AI策略高级副总裁Nicole Carignan表示，AI在SOC中充当力量倍增器。但要实现这一承诺，组织需要现在投资于重新培训分析师。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">OpenAI为高风险账户推出高级安全模式</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">OpenAI周四宣布为其ChatGPT和Codex账户添加可选的新级别账户保护，增加额外的安全层。这一名为高级账户安全的功能强制执行严格的访问控制，使账户接管攻击非常困难。这种措施在账户安全领域并非新概念，Google已提供高级账户安全级别近十年。但随着主流AI服务在全球迅速普及，迫切需要建立一系列基本保护措施。启用高级账户安全后，用户不能再使用常规密码，必须添加两个物理安全密钥或通行密钥以显著降低钓鱼攻击成功风险。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">FIDO联盟制定AI代理交易保护标准</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在恶意软件、在线冒充和账户接管等数字安全问题已经足够多的背景下，代理AI的兴起使得更多活动由代理代表人类执行，产生了不同风险。现在，FIDO联盟与Google和Mastercard的初步贡献合作，周二宣布将启动两个工作组，制定由AI代理执行的支付和其他交易的验证和保护行业标准。目标是产生一个可跨行业采用的保护基线，使用户可以使用不易被钓鱼或被不良行为者接管以向代理发出恶意指令的机制来授权代理行为。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">虚假IT员工问题：CISO不可忽视的隐患</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">雇佣虚假IT员工已成为近年来的增长问题，但很少有组织愿意承认。从财富500强到小型组织，远程招聘流程一直被利用，为非真实身份的个人提供可信访问权限，造成内部威胁风险。据估计，美国各地有数千名虚假IT员工可能窃取信息、知识产权和数据，将工作外包至海外，实施破坏或向外国政府输送资金。Amazon已识别并阻止了超过1800次IT角色获取尝试，且数量持续上升。AI现在使深度伪造、更有说服力的视频面试和快速身份循环成为可能。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069593" src="https://wechat2rss.xlab.app/img-proxy/?k=6e9e97d8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwMYgwyLTfcLRE4scVWiciaLL2q99EcKhd2QPjPJXlOtFlTtMKsrRfqrb1UibUKUCQFafWBTPMibUtAE4FeVcGfr3pZHjibz5u04c42s%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">三、数据泄露与网络钓鱼</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069595" src="https://wechat2rss.xlab.app/img-proxy/?k=ec20b568&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwMIGfeEPicd6ibslOYIvNiap2cJ9YwAFFPqrLuVvmYHgchjw3ib5IbruSzialkMyGCwwmY3fLpeSoq5gBkn1ILRd24wVqiaMUKb80chk%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">服务台正成为关键安全弱点</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">服务台位于现代企业IT的前线，负责保持员工高效工作和系统运行。然而，随着组织加倍基于身份的安全，这些帮助功能正日益被攻击者利用作为后门。旨在帮助员工的流程，如密码重置、设备注册和访问故障排除，正被操纵以绕过最强大的网络防御。在身份即新边界的时代，服务台正迅速成为高价值目标。攻击者不再需要入侵系统，只需通过语音钓鱼进行社会工程攻击。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">邮件钓鱼演进：恶意附件下降，二维码攻击激增</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Microsoft威胁情报Q1 2026报告显示，二维码钓鱼攻击增长是最大发现之一。1月份有760万威胁使用二维码，到3月份增至1870万，增长146%，成为本季度增长最快的攻击载体。威胁行为者通过在邮件正文中嵌入包含恶意URL的图像二维码或在附件内容中嵌入二维码，试图利用基于文本扫描引擎的局限性，将受害者重定向到非托管移动设备上的钓鱼网站。使用虚假CAPTCHA安全检查的恶意投递网页在Q1也大幅增加。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">某名人手机9万张截图数据外泄</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">跟踪软件允许人们通过感染目标手机秘密监视伴侣、家庭成员或其他关联人员，静默收集短信、照片、位置信息和其他数据。这种恶意软件本身具有深度侵入性，但数字权利倡导者长期以来警告，除了侵犯受害者个人隐私外，使用间谍软件收集的数据还可能被另一个不相关行为者单独入侵，造成真正的隐私灾难。本周新研究展示了一个真实最坏案例。Black Hills Information Security的研究人员Jeremiah Fowler发现了公开可访问的云存储库，其中包含近9万张截图，显示一位欧洲名人的私人消息。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">被盗凭据不必然导致入侵</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">被盗凭据是攻击者获取组织访问权限的最常见方式之一。轻微安全事件和重大入侵之间的区别往往取决于安全架构。一名员工收到一封看起来合法的邮件，要求验证账户，点击链接，输入凭据，看似没有任何异常。但这些凭据现在属于攻击者。不久后，有人使用该账户登录系统，没有触发警报，没有利用漏洞。攻击者只是登录。这种情况每天在各规模组织中上演。被盗凭据仍然是攻击者进入企业环境的最常见方式之一。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069591" src="https://wechat2rss.xlab.app/img-proxy/?k=caeb581f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwPEQPV6udib1kSiarE1tBSMVYoZogdgB2xibOJt9FDoKJ3dVJYT0aXMC56qpLXhceRXE3tjiaPznvWqrWlxUxVqUsoCdDv2fjhOevA%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">四、执法行动与政策动态</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069594" src="https://wechat2rss.xlab.app/img-proxy/?k=388fe1b5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwMZLC1XqvRslSEEes3fdaSdjJWBMEaQ3wGJJvJIqkH4b0aS5AVibFBbicR04zJ2m7l6076bsOTs3Q9PmjRPAnNJ2u4sicxyLxK5Sw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">DHS要求Google提供反ICE言论加拿大人活动定位数据</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">美国国土安全部（DHS）在一名加拿大男子批评特朗普政府言论后，试图从Google获取其位置信息、活动日志和其他身份信息。该男子因今年早些时候明尼阿波利斯联邦移民特工击毙Renee Good和Alex Pretti事件后发表批评言论而被追踪。该男子的律师表示其当事人已超过十年未进入美国。ACLU高级律师Michael Perloff指出，政府正在利用大型科技公司总部位于美国这一地理事实，获取其原本无法获得的管辖范围之外的信息。DHS通过海关传票要求Google提供数据。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">迪士尼乐园现启用人脸识别技术</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">一名枪手企图闯入在华盛顿特区举行的白宫记者协会晚宴，当时特朗普总统、副总统JD Vance及其他政府官员出席。媒体报道和特朗普本人迅速确认嫌疑人为31岁的工程师和计算机科学家Cole Tomas Allen。这名加利福尼亚州居民周六在现场被捕，周一在美国哥伦比亚特区地方法院出庭，面临三项联邦指控。此外，FIDO联盟本周宣布与Google和Mastercard成立工作组，制定由AI代理发起的交易验证和保护技术标准。OpenAI为ChatGPT和Codex账户推出了高级安全风险模式。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">美国机构推广运营技术网络零信任实践</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">五个联邦机构周三为关键基础设施组织提供了在运营技术环境中应用零信任原则的建议。该政府出版物表示，对这些工业系统采取零信任方法需要仔细考虑，因为OT系统与物理环境交互，受到可用性和安全要求的限制，以及寿命长的传统技术。该文件由CISA、FBI以及国防部、能源部和国务院共同撰写，描述了OT环境带来的独特挑战、明确治理框架和供应链监督的重要性。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">阿联酋转发截图可致入狱</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">今年早些时候伊朗对阿联酋发动导弹和无人机袭击时，网络犯罪法律也进入了焦点。当局宣布逮捕与误导性视频、AI生成剪辑、非法拍摄和传播虚假信息有关的人员。对许多居民来说，反应是惊讶：截图、转发视频或社交媒体帖子怎么会成为刑事案件？答案在于已经存在的法律框架。阿联酋法律第52条将利用互联网传播虚假新闻、误导性谣言或与官方公告相反的内容定为犯罪。正常情况下最低处罚为一年监禁和10万迪拉姆罚款。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069592" src="https://wechat2rss.xlab.app/img-proxy/?k=fc6e4a03&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwP9tRnssejJDZgicuj6VIJhY7K5knTZSpftxVb1gsJ5Da48zyiaA79ooBzUgdod9l9eT6qKnIczOiaMnOSRZGYwQ31nibGiaHVsKKtc%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">五、行业动态</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069596" src="https://wechat2rss.xlab.app/img-proxy/?k=a185aa00&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwOyncQKEcDaTovOOf62TIxXzDIDZ9RFvd2DpA8C6KA89tokyLt6L422GTF3G7E3LToKuSquGiaxLOl7DqjSn7D5bnuIds82dBew%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">澳大利亚企业无法再忽视日志管理问题</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在澳大利亚企业中，可观察性已悄然成为IT预算中增长最快且审查最少的项目之一。分析师现在报告，超过一半的可观察性支出专门用于日志管理。对于成熟环境的组织，这一数字转化为每年超过100万美元，年增长率约40%。然而，对许多人来说，投资回报仍不明确。值得提出的问题不是日志是否重要——它们确实重要，根本且不可逆地重要。日志是可观察性的基石。问题在于，大多数组织用来管理日志的工具是否是为当前运营环境构建的。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">工作满意度下降意味着只有三分之一（34%）网络安全专业人士计划留在当前雇主，增加了CISO人才保留策略的压力。根据IANS和Artico Search对500名网络安全专业人士的调查，虽然薪资仍然重要，但并非留任的主要驱动因素。灵活的工作模式与满意度和留任密切相关。混合办公安排，尤其是每周只需在现场一至两天，也倾向于减少有才华的网络安全员工跳槽的意愿。研究人员发现，薪酬增长在减少员工流动方面比薪酬包的绝对值更重要。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Pax8与NinjaOne达成全球MSP推荐合作</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Pax8与NinjaOne建立全球合作关系，扩展了针对托管服务提供商和托管智能提供商的推荐安排。根据协议，当合作伙伴寻找统一IT运营工具（包括远程监控和管理）时，Pax8将向NinjaOne介绍他们。NinjaOne将直接与被推荐的合作伙伴合作并处理客户生命周期，而Pax8专注于识别机会并提供战略指导。该安排覆盖北美、EMEA和APAC地区，面向服务于中小企业的托管服务提供商和托管智能提供商。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">PwC与Google Cloud合作进军托管安全市场</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">专业服务公司PwC推出了一款由Google Security Operations支持的AI驱动统一检测与响应托管安全服务。这一公告紧随PwC与Google Cloud于1月份公布的三年4亿美元合作投资，旨在实现网络安全运营现代化。该服务针对通常不会向大型咨询公司寻求网络安全服务的中小型企业。PwC全球及美国托管服务合作伙伴Tim Canonico表示，这不是传统的托管安全服务产品，需要大量人员、时间和基础设施来设置。其特点是利用代理AI工作流程。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">精准地址数据助力身份验证</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">验证客户身份对于在全球日益数字化的世界中建立企业信誉至关重要。企业每年平均因身份欺诈损失约700万美元。在确定用户是否如其声称的身份时，地址数据扮演着关键角色。在身份生态系统中，地址不仅仅是一个简单数据点，它是将客户与现实世界中的位置联系起来的纽带。当地址数据正确、经过验证和标准化后，可以发挥很多作用——从加强身份检查和增强合规性到最小化欺诈。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">州级CISO对管理网络风险信心下降</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Deloitte-NASCIO研究显示，AI和预算压力正在迫使各州做出艰难决定。对网络风险的担忧日益增长，正值国家支持的黑客威胁增加、AI使用上升和预算压力加大之际。州和地方政府日益成为犯罪勒索软件团伙和国家支持黑客的目标。此外，特朗普政府联邦预算削减已将大部分网络风险负担转移给州和地方官员，他们必须日益主导关键基础设施安全工作。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">制造商网络安全因基本矛盾受损</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">网络保险公司Resilience表示，一个简单的安全错误在2025年造成了该行业约四分之一的财务损失。制造商面临一个阻碍其网络安全进程的基本矛盾：为了实施安全控制而让生产下线的感知风险往往大于在没有这些控制下运营的风险。与此同时，自动化和远程访问在该行业变得普遍，特别是COVID-19疫情后远程系统管理成为常态。随着攻击面扩大，攻击者也日趋成熟。勒索软件团伙日益通过附属模式运营，降低了破坏性但低技能攻击者的进入门槛。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Macquarie Government任命微软安全与Azure负责人</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Macquarie Government任命Dr Chris Peiris为微软安全与Azure负责人，专注于联邦和州公共部门。他拥有超过20年的政府咨询、大型科技公司和学术界的网络安全经验。他的职责包括扩展公共部门客户的微软安全和Azure工作，该领域需求由合规要求和敏感工作负载处理驱动。在加入Macquarie Government之前，Dr Peiris曾担任国防部网络安全顾问，为澳大利亚国防军重大项目提供IRAP合规支持和Azure及SAP安全架构。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069598" src="https://wechat2rss.xlab.app/img-proxy/?k=f38561ac&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwODXY20nhzMt273vjxVJJXensAU7sz3u075JeBnyDXfGjhykX7Ke4Nn7OgyETgxicxbQQWPBHZTiaF105gqz43Avl3DCBiaAeogiaI%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">结语</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069597" src="https://wechat2rss.xlab.app/img-proxy/?k=8a8e144f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwOnUFYaNPs7zbyicib6sVcbwbh3K2HuZarg39jUGAGI824bLCeBfia4w3e1MuHA7VxgBJicG7UDgdDjVwHCG4gI94AaqHcpZtg4O14%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">本周全球网络安全态势依然严峻。APT组织的活跃度持续上升，关键基础设施成为主要攻击目标；漏洞披露数量保持高位，多个主流平台产品存在安全隐患；AI技术在网络攻击中的应用日益成熟，攻击自动化程度不断提升，传统的安全防御手段面临新的挑战。与此同时，供应链攻击和数据泄露事件依然高发，显示了数字生态系统中信任链条的脆弱性。建议各相关机构和企业持续关注最新威胁情报，加强漏洞管理和安全监测，及时更新防护策略，筑牢网络安全防线。</span></p><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 10%;max-width: 100%;height: auto;margin: 0px 10px;line-height: 0;padding: 0px;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;background-image: linear-gradient(to right, rgb(245, 245, 245) 50%, rgb(250, 228, 66) 50%);align-self: flex-start;box-sizing: border-box;"><div style="margin: 3px 0%;width: 100%;box-sizing: border-box;"><div style="font-size: 11px;color: rgb(180, 180, 180);line-height: 1;letter-spacing: 0px;padding: 0px 10px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">END</span></p></div></div></div></div></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.459375" data-s="300,640" data-type="gif" data-w="640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069600" src="https://wechat2rss.xlab.app/img-proxy/?k=6728ce3b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwMpehmyx0ZfHXLD2fCUCE9XNGe5suMB4GvSicVy60k6C82icR6un99ibrfAicBia9QjU7ZIicVRzcTPouFqyVHicawBBErrtUVlG4FM1M%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="text-align: center;justify-content: center;margin: 10px 0px;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(249, 225, 25);text-align: justify;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">✦</span></p></div></div><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="color: rgb(100, 100, 100);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">推荐阅读</span></strong></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(249, 225, 25);text-align: right;box-sizing: border-box;"><p style="text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">✦</span></p></div></div></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553161&amp;idx=1&amp;sn=de75201c008d3ebfbe35d75082f8c086&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/mmbiz_png/9Nf1wzzcfwMX9S9YK3iaGv1GzCEFowFg3Oel7ibNoCmm0ibiakrZBvdneVaUzGEAXTGicsrwmMD5fvUOIchgvbYDbocBTE2RIFAGjRAh9ejB7bS8/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1787037037037037" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069599" src="https://wechat2rss.xlab.app/img-proxy/?k=4083b20b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwMX9S9YK3iaGv1GzCEFowFg3Oel7ibNoCmm0ibiakrZBvdneVaUzGEAXTGicsrwmMD5fvUOIchgvbYDbocBTE2RIFAGjRAh9ejB7bS8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553127&amp;idx=1&amp;sn=7f7375b99330998096597deb42fb613a&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/mmbiz_png/9Nf1wzzcfwMV80oXhDO8tAchMGtRW3Iy9POXOicXhJYnQxfYSQNDqcBh5fJbU3ShBr2aLklsqhIghHJptdJ9ib5jeu5PaxU5eaScs42icTP1Dc/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1787037037037037" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069603" src="https://wechat2rss.xlab.app/img-proxy/?k=aa5e3fd5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwMV80oXhDO8tAchMGtRW3Iy9POXOicXhJYnQxfYSQNDqcBh5fJbU3ShBr2aLklsqhIghHJptdJ9ib5jeu5PaxU5eaScs42icTP1Dc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553233&amp;idx=1&amp;sn=31fcbab856313fc4652d6eb9ccf15266&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/sz_mmbiz_png/9Nf1wzzcfwNY1iaoEmpIf9Ucuicn7FGYuhP9VaaFP5uZiaj4TQibwvATaf1ibwOgPMJQdT1GrvOf3zZ2ZanK7QicfPElKFt1EqZ7DtY08lRS7nxe0/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1787037037037037" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069605" src="https://wechat2rss.xlab.app/img-proxy/?k=b3f16323&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwNY1iaoEmpIf9Ucuicn7FGYuhP9VaaFP5uZiaj4TQibwvATaf1ibwOgPMJQdT1GrvOf3zZ2ZanK7QicfPElKFt1EqZ7DtY08lRS7nxe0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="margin: 10px 0%;text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;background-color: rgba(227, 180, 0, 0.04);align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;box-sizing: border-box;"><div data-cacheurl="" data-remoteid="" style="display: inline-block;width: 100%;vertical-align: top;background-repeat: repeat;background-attachment: scroll;padding: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;background-position: 0% 0% !important;background-size: 4.17755% !important;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=fea8579b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwMIfibPia9ecp4U7pwYb3NXfgUx34GRibcG8xnv3tgmeUOCDG1n8UDialkkibM3PdlIotjv6ds2a9EqRQ2iaiasV4vkmo7hibicXEweF1gY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><div style="display: flex;flex-flow: row;margin: 20px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 30%;flex: 0 0 auto;height: auto;align-self: center;margin: 0px 0px 0px 20px;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="699" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069604" src="https://wechat2rss.xlab.app/img-proxy/?k=bf13caea&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwMknktibszUdOenKr1g0455NNZRiaIuFxJO33WhrbdhxlyFTepVRuA8XIPM8Z3g29uFkoOpbgk5DiaqHYjibsnibxDEUJBB7hx3jtMM%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;margin: 0px 0px 0px 10px;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;box-sizing: border-box;"><div style="font-size: 20px;color: rgb(255, 202, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">粉丝福利群开放啦</span></strong></p></div><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(255, 202, 0);font-size: 11px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">加安全419好友进群</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">红包/书籍/礼品等不定期派送</span></p></div></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=2456222e&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDQ4OTkyMg%3D%3D%26mid%3D2247553258%26idx%3D1%26sn%3D83a4fa668907842ce1ea97fcd090457f">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 08 May 2026 17:30:00 +0800</pubDate>
    </item>
    <item>
      <title>仅34%网络安全专业人员愿留任 CISO面临留住人才压力</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553233&amp;idx=1&amp;sn=31fcbab856313fc4652d6eb9ccf15266</link>
      <description>调查显示，职业发展、工作灵活性和安全支持成为留任关键，薪资不再是首要因素。</description>
      <content:encoded><![CDATA[<p>原创 <span>安全419</span> <span>2026-05-06 17:31</span> <span style="display: inline-block;">四川</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=61edf080&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwOm9B1m7ZsSgG6vG0FlVPDHMw2qFd1Rbgox22ONVdwZjFHFibscpO1MSoRWn1E8uQRMBVuk4iauKyaFhr2Q2GqEic6neYqrNprReI%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>调查显示，职业发展、工作灵活性和安全支持成为留任关键，薪资不再是首要因素。</p>
  <div style="font-size: 15px;letter-spacing: 1px;line-height: 2;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.562962962962963" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069568" src="https://wechat2rss.xlab.app/img-proxy/?k=88bd73d7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwMd2FAHhe54VvWubwZyPjHQVX1LA8Efm1ric4NJECUOuQu47ib5g4ibDjro1iaFlTXWVdTUYTmWdUiahFARrIcsYhmKpgSGdDGJRYNY%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">根据IANS和Artico Search对500名网络安全专业人士的调查，虽然薪资仍然重要，但它并不是留任的主要驱动因素。职业发展、工作场所灵活性和安全话语权正成为网络安全人士留任的关键因素。调查显示</span><strong style="box-sizing: border-box;"><span leaf="">只有三分之一（34%）的网络安全专业人士计划留任</span></strong><span leaf="">，他们越来越倾向于另谋出路，这加大了CISO人才保留策略的压力。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">IANS的《网络安全人才报告》发现，</span><strong style="box-sizing: border-box;"><span leaf="">灵活的工作模式与满意度和留任率密切相关</span></strong><span leaf="">。混合工作安排，尤其是每周只需要到岗一至两天的安排，有利于降低有才干的网络安全人员跳槽的意愿。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">认为雇主将安全视为优先事项的网络安全员工（73%）比那些在企业中认为安全几乎或完全没有组织支持的人更有可能留任，后者的留任意愿降至仅19%。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">“可见性、职业成长以及安全领导层的支持对于留住高绩效员工是必要的，”IANS教员兼Artico Search合伙人Steve Martano补充道。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">“随着网络团队压力剧增，那些加倍投入指导、辅导和职业发展的CISO可以创造一种使命感和进步感，帮助员工避免倦怠，”IANS高级研究总监Nick Kakolowski说。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">研究人员还发现，在最小化员工流失方面，</span><strong style="box-sizing: border-box;"><span leaf="">工资增长比薪酬包的绝对值更为重要</span></strong><span leaf="">。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">网络安全培训和认证机构ISC2估计，全球网络安全人才缺口在2024年达到了480万人的峰值。尽管去年的预算削减减少了未填补的网络安全职位数量，但就业市场仍然紧张且竞争激烈。在CIO状况调查中，</span><strong style="box-sizing: border-box;"><span leaf="">网络安全与AI并列成为最难填补的技能</span></strong><span leaf="">，尽管对AI人才的需求明显更高（42%对38%）。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069565" src="https://wechat2rss.xlab.app/img-proxy/?k=8dd3befb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwNPJ5jcbJAiaNuibrgCvW7AA1WObutRicv8forThWKBKK7g9oDwbnUG7gK1XWlgrJbSVG2kHADmnEwgzuMQGDVSSSIbbw5OJ3NNxY%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">一、职业发展和工作自主权</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069566" src="https://wechat2rss.xlab.app/img-proxy/?k=e51d786d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwNia8LQYKrCH2jslM8YGxaWElIUYkKULkrP1YmDjY4icUeOdvqMAGPZChUehLMqblSVTH3MOtZHtCUouQ5FZQZYxsopm5SNUsGLg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">除了灵活性，CSO采访的招聘专家表示，网络安全专业人士一直在寻求发展技能的机会、对工作方式的自主权以及他们的专业知识得到认真对待的机会。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">“当候选人看到明确的职业发展路径、持续认证和培训的机会、直接了解战略的渠道以及接触现代安全栈的机会时，你的职位就会变得有吸引力，”招聘机构CalTek Staffing的总裁Archie Payne说。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">未能提供某种形式的远程或至少混合工作的雇主将失去相当大一部分人才库。</span></strong><span leaf="">“我们经常看到候选人因为僵化的地点要求而拒绝原本很有吸引力的工作机会，”Payne说。“再次强调，顶尖候选人知道自己供不应求，不会迁就于一个不支持他们工作与生活平衡需求的职位。”</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069569" src="https://wechat2rss.xlab.app/img-proxy/?k=88ffbb0c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwNF1QahvkSjmBNqfovEFflmV4gHtpHteqUN5jUgJFSk2wPGGEggk1mvt1NoTiaf4e3539HtTSib1aX71JCcQ55NwyAm4L1k6uQoM%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">二、技能发展</span></b></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069567" src="https://wechat2rss.xlab.app/img-proxy/?k=6349c12c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwM8snu03ZTTRNPXEzw1CmLPJzWmy2BiaE8TLlcjcRRNVGbkw92eN4shXXq71fXiaB7tMBbDD9kicJzDHQTAoHiaDzWlJklARVaic2BI%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在线金融职业平台Canary Wharfian的创始人兼CTO Richard Demeny表示，毕业生和初级专业人士知道他们在掌握主动权，因为即使在入门级，人才也是稀缺的。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">“这些专业人士知道，长期留在同一雇主会极大地限制他们的职业发展：通常，提升知识、技能和人脉的最佳方法就是换工作，”他谈到员工流失率上升时补充道。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Adria Solutions的总监David Berwick认为，CISO在留住网络安全员工方面需要更加一致。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">“清晰的晋升路径、现实的工作量、领导层可见的支持以及合理的灵活性，”Berwick说。“那些把这些基础做好的组织，在吸引和留住人才方面远比那些仅仅依靠薪酬的组织更有效。”</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069570" src="https://wechat2rss.xlab.app/img-proxy/?k=e052c784&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwNa9GZAE5UIXgC7c9ac6CiaScMQh8M0mIYKrkONicxgYZRafIplLkx5fL4GDaYJ4IialFI18Kp72vI7SF02qzFqZY9n2PvRPbIOEU%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">三、避免倦怠</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069574" src="https://wechat2rss.xlab.app/img-proxy/?k=39954c20&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwN2ia26oToSIEZc5qtyRHknbJoicsmSVUFKzpWcO6Rs7s90QyPs6OoGT2MWYNibLcIOrnpSm5icgGhR2kyM3dK56Zkbmr3mHeaqfMc%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">网络安全招聘公司Aspiron Search的联合创始人Oliver Legg表示，员工倦怠是管理安全团队的CISO面临的一个日益严重的问题。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">“我们在市场上看到的是，留任不仅仅是薪酬问题，而在很大程度上取决于你创造的环境、你表现出的支持，以及你如何随着日益复杂的威胁格局一起发展，”Legg说。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">安全团队需要跟上现代工具的步伐，既要防御对手，又要保持团队的参与度和有效性。“</span><strong style="box-sizing: border-box;"><span leaf="">使用过时工具或纯粹被动流程的网络专业人士，更有可能失去积极性并另谋高就</span></strong><span leaf="">”Legg警告说。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069572" src="https://wechat2rss.xlab.app/img-proxy/?k=421cd970&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwMjgyV6FiaHVH300kpP7RLThXhbOKVBLd302ickEWOBQIQzlmqJ2ZpouCgP5JgQ8PiaBq1PxLjEWqttzb2m3zGkTbrbJ2zSEe3uvs%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">四、成长与提升</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069573" src="https://wechat2rss.xlab.app/img-proxy/?k=58d0bde5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwNaJDYy3QKicichc6qOCynDBH9Ntia3hUq1YsDLkXL530tTzbFcDNTslibgeEv9DJhkyibLuxIWhDv8KjvNyuJWxPlfiabTpLfefb35w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">为网络安全员工提供</span><strong style="box-sizing: border-box;"><span leaf="">学习机会可以成为提高参与度和留任率的强大动力</span></strong><span leaf="">。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">“提供参加行业会议或在会上发言的机会，以及支持获取新的或更新的认证，有助于团队保持积极性并持续发展，”Legg建议道。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CalTek Staffing的Payne指出，网络安全专业人士既“高度专业化又需求旺盛”。这意味着员工“不断被渴望其才能的公司接洽，并且很清楚他们的技能供不应求，”他说。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">据Payne称，求职者越来越多地提出更尖锐的问题，询问他们的成长路径是什么样子，以及他们是否在安全战略中有发言权，而不仅仅是关注薪酬。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069571" src="https://wechat2rss.xlab.app/img-proxy/?k=789a96dc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwO6BJuDEuW4227V0x7bDO3icUFiaguvkicZ52aan4DJWOgeHVicoibAIsQBzQslVLJZibPJFhyLVfDj8V6NRPCJsibhLCyWqWFsLpHOTE%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">五、赢得员工参与</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069575" src="https://wechat2rss.xlab.app/img-proxy/?k=2341cc01&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwN9E2zhU5jfVaJibEjD9z94U7tX0tcPiaNxr5sWYNJE5MFM81gpk7fpakoxib7u2ys7ymR5WHWtBvXDibZhicN0ibplh7ibGEaibeUrM5Y%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">留任已不再仅仅是防止不满，而更多的是持续赢得员工参与。</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">“我们看到的</span><strong style="box-sizing: border-box;"><span leaf="">员工流失的最大驱动因素之一是，候选人在招聘过程中被承诺的内容与实际得到内部支持的内容之间存在脱节</span></strong><span leaf="">，”Payne说。“许多公司谈论安全是‘任务关键型’的，但安全团队长期人手不足，或者不给CISO预算权限。优秀的候选人能很快发现这类问题，他们也会同样快速地离开。”</span></p></div><div style="font-size: 12px;color: rgb(100, 100, 100);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">参考链接：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.csoonline.com/article/4165916/just-34-of-cyber-pros-plan-to-stick-with-their-current-employer.html" target="_blank">https://www.csoonline.com/article/4165916/just-34-of-cyber-pros-plan-to-stick-with-their-current-employer.html</a></span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 10%;max-width: 100%;height: auto;margin: 0px 10px;line-height: 0;padding: 0px;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;background-image: linear-gradient(to right, rgb(245, 245, 245) 50%, rgb(250, 228, 66) 50%);align-self: flex-start;box-sizing: border-box;"><div style="margin: 3px 0%;width: 100%;box-sizing: border-box;"><div style="font-size: 11px;color: rgb(180, 180, 180);line-height: 1;letter-spacing: 0px;padding: 0px 10px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">END</span></p></div></div></div></div></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.459375" data-s="300,640" data-type="gif" data-w="640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069578" src="https://wechat2rss.xlab.app/img-proxy/?k=1a65737a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwMN9vt0yeyCyhsl7chzGibC2FzoGbUWT9uTn6H9BJSnHHPafAEefOQnvQg7Q6pr9iaMo9NoYPKYEu03V6CicLiboibSLW5yGDvStYyc%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="text-align: center;justify-content: center;margin: 10px 0px;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(249, 225, 25);text-align: justify;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">✦</span></p></div></div><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="color: rgb(100, 100, 100);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">推荐阅读</span></strong></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(249, 225, 25);text-align: right;box-sizing: border-box;"><p style="text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">✦</span></p></div></div></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553161&amp;idx=1&amp;sn=de75201c008d3ebfbe35d75082f8c086&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/mmbiz_png/9Nf1wzzcfwMThVzPiacchr2G7rHSCb4SQuxIpz8vOy4zdRiciccvzjxEDBebzjZC8s3I8qYd8DUuKwHhwVCCVvMkXiabNN1UyF1Pa61I0d1TkhQ/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.17833333333333334" data-s="300,640" data-type="png" data-w="1200" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069576" src="https://wechat2rss.xlab.app/img-proxy/?k=783df23d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwMThVzPiacchr2G7rHSCb4SQuxIpz8vOy4zdRiciccvzjxEDBebzjZC8s3I8qYd8DUuKwHhwVCCVvMkXiabNN1UyF1Pa61I0d1TkhQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553127&amp;idx=1&amp;sn=7f7375b99330998096597deb42fb613a&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/sz_mmbiz_png/9Nf1wzzcfwPS2hR8OllXyIt2cXbFopKh2mPVAWPow4KgpFMJCTMWsoqoVhdqPeVHXKK60YYItvGlAFVMoZVllvM0ufx4Tic2iboL72csWWPk0/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100069579" data-ratio="0.17833333333333334" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1200" src="https://wechat2rss.xlab.app/img-proxy/?k=fcf4758b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwPS2hR8OllXyIt2cXbFopKh2mPVAWPow4KgpFMJCTMWsoqoVhdqPeVHXKK60YYItvGlAFVMoZVllvM0ufx4Tic2iboL72csWWPk0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553068&amp;idx=1&amp;sn=769273f61e16e08311cd687dd7262cb4&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/sz_mmbiz_png/9Nf1wzzcfwO7nShjxrb6kXpUKpyJkw55ial6Dz1oyANKKJyWL2PH957iamrxmCUiaHphazVqstycJKe9CPYlGXdGYutwfwXvyXgLFXQicib9FnMs/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.17833333333333334" data-s="300,640" data-type="png" data-w="1200" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069577" src="https://wechat2rss.xlab.app/img-proxy/?k=6d7ca9bf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwO7nShjxrb6kXpUKpyJkw55ial6Dz1oyANKKJyWL2PH957iamrxmCUiaHphazVqstycJKe9CPYlGXdGYutwfwXvyXgLFXQicib9FnMs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="margin: 10px 0%;text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;background-color: rgba(227, 180, 0, 0.04);align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;box-sizing: border-box;"><div data-cacheurl="" data-remoteid="" style="display: inline-block;width: 100%;vertical-align: top;background-repeat: repeat;background-attachment: scroll;padding: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;background-position: 0% 0% !important;background-size: 4.17755% !important;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=9e6a2516&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwPmce4YGbNic7XZA2W9M6ohWFibJpwI0AAt5DHtYiaY3AkNe71DzaCvbUGSzKRlw7gbDibZibia7EVF0aicpYRoGHqECOFrXQtzAWWAibo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><div style="display: flex;flex-flow: row;margin: 20px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 30%;flex: 0 0 auto;height: auto;align-self: center;margin: 0px 0px 0px 20px;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="699" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069581" src="https://wechat2rss.xlab.app/img-proxy/?k=1cb01d4a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwOmw3AzVg5gvjauZI3N94S1Dt7xImOUBM81fZgb9ibPYqWdDCXFIGIIfWcicBcVAjzH4H0j3TSsoUlTkwjXRicMFPA9xKOkN5ecF0%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;margin: 0px 0px 0px 10px;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;box-sizing: border-box;"><div style="font-size: 20px;color: rgb(255, 202, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">粉丝福利群开放啦</span></strong></p></div><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(255, 202, 0);font-size: 11px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">加安全419好友进群</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">红包/书籍/礼品等不定期派送</span></p></div></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=926a686f&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDQ4OTkyMg%3D%3D%26mid%3D2247553233%26idx%3D1%26sn%3D31fcbab856313fc4652d6eb9ccf15266">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 06 May 2026 17:31:00 +0800</pubDate>
    </item>
    <item>
      <title>安全419｜一周国际网安资讯：APT攻击持续升级   AI安全风险凸显</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553211&amp;idx=1&amp;sn=35092f1c1856e8179d0335e410418fa3</link>
      <description>APT组织持续瞄准美国OT系统，Harvester新增Linux恶意软件，AI辅助攻击与防御并行，axios等供应链攻击波及广泛。</description>
      <content:encoded><![CDATA[<p>原创 <span>安全419</span> <span>2026-04-29 17:01</span> <span style="display: inline-block;">四川</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=ce7fe418&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwPDAAjeO96IvMR6P3df7nGaeaI72yGb4yrd6XESvktRXjcwWAODKTTxVo7ayMiaOliccWDjZ7YBTIaZ2xysTYf5YnZT47dAVZuBA%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>APT组织持续瞄准美国OT系统，Harvester新增Linux恶意软件，AI辅助攻击与防御并行，axios等供应链攻击波及广泛。</p>
  <div style="font-size: 15px;letter-spacing: 1px;line-height: 2;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5555555555555556" data-s="300,640" data-type="png" data-w="720" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069514" src="https://wechat2rss.xlab.app/img-proxy/?k=669c63f5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwOKsUbShtk3qIVAiaXCGBmDrtxCl6QoJsTRWwsNMCzj8wwvUTjR836j54xx8o58WGhPpg3OmBdpah9hMtY3lBrZj9pem2eWklk4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069518" src="https://wechat2rss.xlab.app/img-proxy/?k=16e5adc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwNW0D4V5Ms6MKXDayhHiaw47GEP1unfmicrqXOUObtcpicPdfZDKyVYSVfOxYLf7JXL2NsticmuOUlLB9mfNfWr6614YIxssxia6Yc0%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">上周热点速览</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069515" src="https://wechat2rss.xlab.app/img-proxy/?k=3d33d036&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwO9YXT7VpOnakZEE1GROWQHtK5Y4thwpmibcib38eoniazZgzg90azRiblhv37Cica9Noh9W4Gq5u2fibic9vT4f0wdibcAjq584RdQ6No%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">上周（2026年4月21日-27日）全球网络安全领域呈现多重挑战与趋势变化。APT组织活动显著增加，持续瞄准美国关键基础设施；针对知名品牌和供应链的攻击事件明显增多。从技术趋势来看，AI在安全攻防两端的影响日益深化——既被安全团队用作防御工具，也被攻击者用于提升攻击效率。在监管层面，CISA经历人事变动，执法部门也不断加强跨境合作。以下为本周主要国际网络安全资讯汇总。</span></p><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069517" src="https://wechat2rss.xlab.app/img-proxy/?k=14925bfb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwNARxHnPbvsc9JqDgKmBuJp5Azs0scZEOiakygODibf3gwtMojU0ffaIiaxicANpRmMpHHHiavyGadqjiaRfbI1uZLb2KtHEScIiaIdMo%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">一、APT与国家级威胁</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069516" src="https://wechat2rss.xlab.app/img-proxy/?k=e0107fc2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwN1hSicEy1lJaicb4ITMBKtXdWUT0zYiah7IFuSu8cC3CuU2P7kQg31WWmufl8U6ABGLvox6Iib1AZlHI4AhXibe1Cb9iccFRBAG9hH4%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">APT组织持续瞄准美国关键基础设施</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CISA与FBI联合发布网络安全咨询警告，APT组织正在持续针对美国关键基础设施部门开展网络攻击活动。这些攻击主要针对互联网连接的操作技术（OT）设备，涉及水处理、能源、制造业等多个关键基础设施领域。联合公告指出，攻击者利用面向互联网的OT系统漏洞进行初始访问，一旦获得初始立足点，便会横向移动、提升权限并维持持久性访问。相关机构建议关键基础设施运营者立即审查面向互联网的设备，加强网络分段，实施多因素认证，并密切监控异常网络活动。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Harvester APT组织扩展间谍活动 新增GoGra Linux恶意软件</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">网络安全研究人员发现与Harvester APT组织关联的新型GoGra Linux恶意软件。该恶意软件针对南亚地区的政府、军事和电信实体，使用Go语言编写以提升跨平台兼容性和逃避杀软检测的能力。GoGra通过伪装成合法PDF文档和利用Microsoft API实现隐蔽的命令与控制（C2）通信，采用HTTPS加密流量和自定义协议来规避网络流量审计。Harvester APT以长期渗透能力和精细化信息窃取著称，此前主要针对Windows平台，此次扩展至Linux系统表明该组织正在扩大攻击面，应对目标环境的多样化。安全专家建议南亚地区的政府和关键基础设施运营者加强端点监控和异常行为检测，重点关注Go语言编写的新进程。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Tropic Trooper使用伪造SumatraPDF和GitHub部署后门</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">研究人员曝光Tropic Trooper APT组织（又称KeyVista）正在使用一种新的攻击手法——通过木马化的SumatraPDF阅读器和GitHub平台分发AdaptixC2恶意软件后门。攻击者将恶意代码嵌入看似正常的PDF阅读器安装包中，当受害者安装后会在后台静默安装后门。Tropic Trooper主要针对中亚和东南亚地区的政府实体、军事机构和研究组织，专注于窃取地缘政治情报和国防技术资料。值得注意的是，攻击者利用GitHub的CDN功能托管恶意载荷，混入合法流量中以规避安全网关检测。分析人士指出，利用合法基础设施进行命令与控制已成为APT组织的重要战术趋势，给传统的基于域名信誉的检测机制带来了巨大挑战。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Mustang Panda更新LOTUSLITE后门攻击印度银行和韩国外交官</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">安全公司Acronis披露，APT组织Mustang Panda正在使用更新版本的LOTUSLITE后门，针对印度银行机构和韩国外交部门发起新一轮定向攻击。新版LOTUSLITE采用了更强的代码混淆技术和反分析机制，可检测沙箱环境和调试器，并在检测到分析环境时主动自毁。攻击链通常以鱼叉式钓鱼邮件为起点，附带恶意宏文档，最终投递LOTUSLITE后门。该后门具备键盘记录、屏幕截图、文件窃取和横向移动等多种功能模块。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">CISA确认4个Cisco网络设备漏洞正被APT组织积极利用</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CISA发布紧急指令（ED 25-03）更新，确认已有4个Cisco Catalyst SD-WAN Manager漏洞被APT行为者积极利用。Cisco于今年2月份披露了6个关键漏洞，最初没有观察到在野利用的证据，但经过数周的威胁情报分析后，CISA现已确认其中4个正在被攻击者利用。这些漏洞可被链接利用实现远程代码执行和设备完全接管。CISA要求联邦民事行政机构在指定期限内完成漏洞修补，同时强烈建议私营部门采取行动。CISA还发布了针对Cisco Firepower设备的FIRESTARTER后门分析报告，为网络防御者提供了详细的检测和响应步骤。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069520" src="https://wechat2rss.xlab.app/img-proxy/?k=f9a29d27&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwPL6fA4XcYW6OE1fiavciaW2nQLwXMCJNZr9w2pGCj9Oau9hK97MdicLDADBic1iau1t2fwtvl2ewv6L2LqjMmOfIAnCkKsFnJ9k08g%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">二、漏洞预警</span></b></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069519" src="https://wechat2rss.xlab.app/img-proxy/?k=d6b7570f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwMW7RuicMDjHZybZqgKjuKVb31tnVibjUOyZsxQOor5BSyhSmiaF22oMgJjwiaNckXRnDia5sicJ7WwdSYFHXiaVDNMKovzicLBp5V3oO8%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Microsoft Entra Agent ID漏洞可致权限提升和租户接管</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">安全研究人员披露了Microsoft Entra Agent ID服务中的一个高危漏洞，该漏洞允许攻击者通过服务主体（Service Principal）滥用实现权限提升和Azure租户接管。攻击者可利用特殊的API调用链绕过权限验证，获取本不应获得的租户级别管理权限。该漏洞的严重性在于一旦攻击者获得租户接管权限，即可访问组织所有Azure资源、读取敏感数据、修改安全策略，甚至使用受感染的租户作为跳板攻击其他关联组织。微软在接到报告后已完全修补该漏洞，但研究人员指出，使用Entra Agent ID的组织应立即审核服务主体权限分配，确保遵循最小权限原则。这是继axios供应链攻击后，本月内又一起引人关注的云端身份安全事件。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Microsoft SharePoint漏洞在多个国家广泛暴露</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">研究人员披露了Microsoft SharePoint中的一个高危漏洞，受影响系统遍布多个国家和地区。该漏洞允许经过认证的攻击者在特定配置下实现远程代码执行，从而完全控制SharePoint服务器。SharePoint作为企业协作和文档管理的核心平台，通常存储大量敏感商业数据和内部文件，一旦被攻破后果严重。值得注意的是，此次披露距离上一次SharePoint漏洞（CVE-2025-诱）发现仅数周，表明该平台的攻击面正在受到越来越多研究者和攻击者的关注。微软已发布安全更新，建议SharePoint管理员立即应用补丁，同时检查服务器是否存在异常访问日志和新增管理员账户。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Microsoft旗下GitHub仓库漏洞允许通过Issue提交实现RCE</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">研究人员披露了一个存在于微软旗下GitHub Actions仓库中的严重漏洞，攻击者仅需通过提交GitHub Issue即可触发远程代码执行。漏洞源于GitHub Actions工作流配置中缺乏适当的安全约束，允许外部贡献者通过特制的Issue内容注入恶意命令。攻击者可利用该漏洞提取仓库的GITHUB_TOKEN密钥，进而推送未经授权的代码更改、修改发布版本或窃取源代码。考虑到受影响仓库属于微软拥有，这一漏洞的潜在影响范围极大。GitHub已在得知漏洞后紧急修复了相关配置，并发布了安全公告建议所有GitHub Actions用户审视其工作流配置，确保对外部Payload进行严格的过滤和沙箱化处理。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">TP-Link路由器面临高危漏洞利用 Botnet威胁浮现</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">研究人员警告，一款针对TP-Link终端生命周期（EOL）路由器的高危漏洞正在被积极利用，疑似有僵尸网络开始大规模扫描和感染存在漏洞的设备。受影响的设备已不再获得官方安全更新，但仍大量存在于家庭和小型企业网络环境中。攻击者利用该漏洞获取设备root权限后将路由器纳入僵尸网络，用于发动DDoS攻击或作为进一步渗透内部网络的跳板。由于TP-Link在全球家用路由器市场占有较高份额，潜在受影响设备数量可达百万级别。安全专家强烈建议用户检查所用TP-Link路由器型号，若已终止支持应立即更换；对于仍受支持的产品，应确保已安装最新固件。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">NIST限制漏洞分析标准 CVE积压持续膨胀</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">美国国家标准与技术研究院（NIST）宣布调整其国家漏洞数据库（NVD）的漏洞分析标准，将不再为不符合特定标准的漏洞添加详细分析信息。这一决定在网络安全社区引发广泛关注和担忧。NVD是全球最权威的漏洞信息库，其分析数据被大量安全产品和管理系统引用，分析标准的收紧意味着大量CVE条目将缺少关键的攻击向量、CVSS评分和影响评估等元数据，直接影响组织漏洞优先级排序和修复决策。NIST解释称此举是为应对持续增长的CVE提交量和资源限制，但批评者认为这实质上是将漏洞评估的责任转嫁给终端用户组织。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Microsoft漏洞总量下降但关键漏洞数量翻倍</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">安全公司BeyondTrust发布2026年第一季度Microsoft产品漏洞趋势报告。数据显示Microsoft产品漏洞的总数量较上一季度有所下降，但被评为&#34;严重&#34;（Critical）级别的漏洞数量反而翻了一倍。报告重点揭示了Microsoft Office、Azure云服务和身份系统（如Azure AD/Entra ID）中日益增长的安全风险。在Azure方面，多个漏洞涉及云资源管理API的权限绕过和安全组配置缺陷。报告作者指出，虽然漏洞总量下降看似积极，但关键漏洞的翻倍增长意味着攻击者可利用的&#34;高价值&#34;入口点实际上增加了，建议安全团队将有限的修复资源优先集中在这些高优先级漏洞上。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069523" src="https://wechat2rss.xlab.app/img-proxy/?k=04d66548&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwPGib5V76O9g9uyA8HW0fZORm13Lr4SyaImouBIzWb4NdYY3ZAUQtfOuehKWRAP0nTco4JYH4Viaick5J0acHDy0ztic36MYibd8wAo%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">三、AI安全</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069521" src="https://wechat2rss.xlab.app/img-proxy/?k=9845ff1d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwPpsTxbtYgPD77btlnKkqr9XTssm31D75nmfJeZBfoZ3WEiaZskDTIwBsVPFEop9ibtUpZGqfubscDqbfb8X1W8gpXhAdnGbmld4%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">AI代理权威差距：持续可观察性成为决策引擎的关键挑战</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">业界专家发表深度分析指出，AI代理在企业安全部署中暴露出一个关键的结构性差距——即代理的自主决策能力与人类可观察性之间的不对等。AI代理作为被委托的行为者（non-human actor），由现有企业身份系统触发、调用和授权，这使得它们在根本上不同于传统的软件程序和人类操作员，但又与两者密不可分。这种&#34;委托差距&#34;意味着当AI代理做出安全相关决策时，安全团队难以实时理解其推理过程和评估决策合理性。文章呼吁行业建立AI代理的持续可观察性框架，包括决策日志标准化、可追溯的权限审计链和实时异常行为告警机制，以确保AI代理在不损害安全性的前提下发挥效用。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">AI编写的软件为安全团队带来新挑战</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">随着AI编码工具在企业开发流程中的普及，安全团队正面临前所未有的挑战。ProjectDiscovery的调查发现，AI生成的代码中普遍存在安全隐患，包括经典的OWASP Top 10问题和特定框架的不当使用。更令人担忧的是，开发人员往往由于过度信任AI生成的代码而跳过安全审查，形成&#34;自动化信任偏见&#34;。另一方面，攻击者也开始利用AI工具生成恶意代码或变种，通过引入微小的语义修改来绕过传统签名检测。报告建议组织建立针对AI生成代码的专项安全审查流程，将大型语言模型辅助代码纳入常规安全开发生命周期（SDLC），而不是盲目信任AI的输出。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">AI驱动云攻击达到&#34;功能性&#34;成熟度</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Palo Alto Networks的Unit 42研究团队发布报告称，AI驱动的云环境攻击已经达到&#34;功能性成熟&#34;阶段。该团队展示了一项概念验证（PoC）研究，证明攻击者可以利用AI模型以机器速度发现和利用云环境中的配置错误、弱权限和安全组漏洞。在实验中，AI代理能够在几分钟内自动完成从侦察、漏洞利用到权限提升的全链路攻击过程，速度远超人工操作。报告警告，随着越来越多的企业将工作负载迁移到云端，AI驱动的自动化攻击将使云环境的威胁窗口大幅缩短，传统的周期性安全评估已不足以应对。Unit 42建议组织采用持续的云安全态势管理（CSPM）和运行时保护，以应对实时性的攻击威胁。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">AI代理可被劫持窃取凭证 Meta发布紧急语音警告</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">针对AI代理安全问题，研究人员发现集成到GitHub等平台的AI代理存在被劫持风险，攻击者可利用间接提示注入技术迫使AI代理泄露访问凭证。这一发现与Anthropic Claude Opus模型可通过低成本编写Chrome漏洞利用代码的研究结果相呼应，共同揭示了当前AI系统在安全领域的双刃剑效应。值得关注的是，Meta在Bluesky平台遭遇DDoS攻击后，通过AI驱动的紧急语音系统向用户发布安全通知，展示了AI在应急响应中的应用潜力。但同时，AI也可能被用于生成更具欺骗性的网络钓鱼内容和深度伪造音频，使得传统安全防御手段面临失效风险。行业专家呼吁加快AI安全标准的制定，建立AI系统安全性评估框架。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Firefox报告提供Claude Mythos AI模型的早期安全洞察</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Mozilla发布了一份关于Anthropic Claude Mythos AI模型的安全测试报告，该模型在Firefox代码库的Bug赏金测试中发现了数百个安全漏洞。报告显示，Claude Mythos在自动化代码审计和漏洞发现方面的能力远超前辈模型，能够在JavaScript引擎、WebRTC实现和图形渲染模块中精确定位内存安全和逻辑漏洞。然而，报告同时警告这种强大的漏洞发现能力同样可被恶意行为者利用，大幅降低漏洞武器的技术门槛。Firefox的测试结果恰逢有媒体报道Discord关联团体通过供应商入侵访问了Claude Mythos模型，使得围绕该模型的安全争议进一步升级。Anthropic回应称，目前无证据表明生产系统受到影响。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069522" src="https://wechat2rss.xlab.app/img-proxy/?k=777d24bb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwM4IG1nU3yBiaQNucdzmQIoibjVV8OFxSeEXa9W7YHT6eOWyO7qIGdzRTz8VqL68AZxibYYh2upLfnvRhQb6yVZPC8tERtxbI92vg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">四、恶意软件与勒索软件</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069525" src="https://wechat2rss.xlab.app/img-proxy/?k=8915f607&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwMibRLUAIYCRW2KEehsSYew2Tnsojl7NnX0nsmiaoCk7bj4RCZkcFAWFib4gezJgicw1McVQic7Fr29V58jlibrTNEh6bZxuRbS4rJyw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">UNC6692伪装IT帮助台员工通过Teams投放SNOW恶意软件</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">安全研究人员发现了一个复杂的社工+恶意软件攻击链：攻击组织UNC6692通过伪装成企业IT帮助台员工，先进行电话钓鱼获取受害者信任，再通过Microsoft Teams聊天发送伪装成远程支持工具的恶意可执行文件。该恶意软件被命名为SNOW，具备屏幕监控、键盘记录、凭证窃取和持久化驻留功能。攻击者精心设计了社交工程话术，利用员工对IT支持的自然信任跨越安全边界。由于Teams是微软生态系统中的受信任应用，安全软件通常不会对其文件传输进行严格审查，使得这种攻击手法尤为隐蔽。安全专家建议组织加强员工安全意识培训，明确IT部门绝不会通过Teams直接发送可执行文件。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Trigona勒索软件团伙使用新型工具uploader_client.exe加速数据泄露</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">研究人员发现Trigona勒索软件运营团伙正在使用一款名为uploader_client.exe的新型命令行工具进行数据泄露。该工具具有高度模块化设计，允许攻击者在加密文件之前快速且有选择性地窃取目标数据——可指定特定文件类型、目录路径和文件修改时间范围，实现精细化的数据盗窃。相比传统的全量数据打包窃取，这种选择性泄露策略大大缩短了数据泄露所需时间，降低了因大流量传输而被安全系统发现的风险。Trigona赎金勒索组织近几个月攻击活跃度明显上升，主要瞄准制造业、医疗和教育行业的中型组织。安全专家建议组织实施网络流量基线监控，对异常的非业务时间大流量外传保持高度警惕。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">26款虚假加密钱包应用潜入苹果App Store窃取助记词</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">卡巴斯基研究人员披露了一起大规模移动端恶意应用事件：至少从2025年秋季起，苹果App Store中存在26款假冒主流加密货币钱包的恶意应用，统称为FakeWallet家族。这些应用仿冒Bitpie、Coinbase、imToken、Ledger、MetaMask、TokenPocket和Trust Wallet等知名钱包品牌，诱骗用户输入助记词和私钥。部分应用甚至通过了苹果的App Store审核流程，通过动态加载恶意代码的方式规避静态分析检测。截至目前，受影响用户数量和资金损失规模尚在评估中。卡巴斯基已向苹果公司通报相关情况，苹果正在移除已识别的恶意应用。对于加密货币用户，安全建议是仅从官方渠道下载钱包应用并验证开发者身份。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">新型ClickFix攻击利用Windows原生工具降低检测风险</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">安全研究人员发现一种被称为&#34;ClickFix&#34;的新型攻击技术在野外活跃。攻击者通过虚假CAPTCHA页面诱骗用户运行恶意命令，利用Windows内置的cmdkey和regsvr32工具执行恶意代码，维持持久性访问。由于这些工具是Windows操作系统的合法原生组件，大多数终端安全产品不会对其进行拦截，使得攻击难以被检测。攻击链的巧妙之处在于它无需下载外部可执行文件即可完成从初始访问到持久化的全过程，对依赖文件扫描的安全产品构成挑战。研究人员建议组织启用PowerShell脚本块日志记录和命令行审计，以便在发生此类攻击时保留足够的取证信息。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069527" src="https://wechat2rss.xlab.app/img-proxy/?k=11f1d319&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwMad6rM6QQQBSDKFgkNiawZNWDqXBwibeK94lbqaVGPTYF2oPFKWcZUjkSb16vXFYU5RaFKLrcXV61eJ0GMSYRRXkGmOUgSGqL9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">五、供应链安全</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069528" src="https://wechat2rss.xlab.app/img-proxy/?k=e6de16db&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwMOibaJBxjVNk8AL3ibaeCRliagrg660kBgDGPvIic3EqnKIafjpv71yViaG80kDysP0P6ImUyYU6icBzbtGOBkL8IgHXKvhlzmPjB8Y%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">CanisterWorm供应链攻击波及Namastex npm生态</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">安全研究人员披露了一起名为&#34;CanisterWorm&#34;的供应链攻击事件，波及Namastex组织下属的npm生态包。攻击者在@automagik/genie和@pgserve两个npm包中注入了自传播脚本。该脚本在被开发者安装后会自动搜索本地开发环境中的GitHub凭证，并利用这些凭证向该开发者维护的其他仓库推送恶意修改，形成&#34;链式感染&#34;。CanisterWorm攻击的创新之处在于其自传播机制——一旦一个开发者被感染，恶意代码会自动尝试感染这个开发者有写权限的所有仓库，速度呈指数式增长。这一事件凸显了开源生态中依赖关系和信任链的安全脆弱性，npm安全团队已移除受影响的包版本。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">疑似朝鲜关联行为者对axios库发起供应链攻击</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CISA发布安全公告，警告疑似朝鲜关联的网络行为者对广泛使用的JavaScript HTTP库axios发起了供应链攻击。axios是全球下载量最高的npm包之一，被数百万项目直接或间接依赖。攻击者通过攻陷axios的一名维护者账户或将恶意代码注入构建管道，成功在特定版本的axios包中植入了恶意Payload。考虑到axios的庞大用户基数，包括微软、AWS、Uber在内的多家大型科技企业都在受影响范围内。CISA敦促所有使用axios的组织立即检查其依赖版本，审查近期部署的环境是否存在异常行为，并启动事件响应流程以排查潜在入侵。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Vercel系统遭第三方工具攻陷 客户环境面临风险</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">云平台Vercel披露了一起安全事件：一名员工在使用消费级第三方应用时因授予了过多的权限，导致该应用被攻击者入侵，随后攻击者利用该员工的权限访问了Vercel的内部系统。攻击者可能查看了部分客户的部署配置和环境变量信息。Vercel表示核心基础设施和用户源代码未受影响，但建议客户轮换所有可能与此次事件相关的API密钥和凭证。这一事件再次凸显了&#34;影子IT&#34;带来的安全风险——员工在工作环境中使用未经安全审核的第三方工具时，往往不会意识到其权限蔓延可能造成的连锁影响。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069526" src="https://wechat2rss.xlab.app/img-proxy/?k=1efca499&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwPXib9bcsKVSBiayQtDEYIibPqL2g6HRwibhYgVDsv7zic9o8ziadbwaAIaCn70WB02C6Hfc5ZZQHpNhqUYP439cORslExW5G4pKK7NA%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">六、数据泄露与网络钓鱼</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069524" src="https://wechat2rss.xlab.app/img-proxy/?k=c23bf544&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwPgSYbaUskbBuLibKvYQaglmnX1cyYO0NJquaQAlEqUWB83q8CS5YW7FXrwX0Fq8EXVMO1H0961T1ib8K280icZIZCv5Emxr6mlb4%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Hasbro遭遇3月网络攻击 预计影响第二季度营收</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">全球玩具巨头Hasbro在最新财报中披露，公司在2026年3月遭遇了一次重大网络安全攻击，该事件预计将对第二季度营收产生负面影响。Hasbro正在对受影响的文件进行审查，并致力于将某些核心业务系统完全恢复上线的过程中。公司表示将承担与安全调查、系统恢复和法律咨询相关的一系列额外成本，虽然具体损失金额尚未公开，但已在财务预测中体现了相关影响。作为一家业务覆盖全球数十个国家和地区的消费品牌，Hasbro此次事件再次证明制造和消费品行业正成为勒索软件和数据盗窃攻击的频繁目标。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">网络钓鱼（部分借助AI辅助）位居2026年Q1初始访问手段首位</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">思科Talos团队发布2026年第一季度安全趋势报告，指出网络钓鱼仍然是攻击者最常用的初始访问手段，且越来越多地借助AI工具辅助生成钓鱼内容。AI生成的钓鱼邮件在语法、语气和内容个性化方面远超传统模板式钓鱼，大幅提升了欺骗成功率。报告指出，针对商业消息应用（如Teams、Slack）的钓鱼攻击也在快速增加，攻击者意识到企业员工对这些&#34;内部&#34;沟通平台的安全警惕性低于传统电子邮件。CISA与FBI同期发布的公共服务公告也证实了这一趋势，警告各国网络行为者正在加强对商业消息应用的利用。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">虚假CAPTCHA诈骗利用验证点击发送高价国际短信</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Infoblox公司揭露了一起名为Click2SMS的大规模欺诈行动。攻击者通过在恶意网站上展示虚假的CAPTCHA验证页面，使用后退按钮劫持（Back Button Hijacking）和误导性UI设计，诱骗用户点击&#34;验证&#34;按钮，实质上是在后台发送高额国际短信。受害者在不知情的情况下被收取高额通信费用，而攻击者通过电信分成获利。该攻击的聪明之处在于它不需要窃取任何直接凭证——受害者即便没有输入密码或银行卡信息，每次点击都会产生直接的经济损失。研究人员已确认大量仿冒新闻、视频和工具类网站的页面参与了此次欺诈行动。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069529" src="https://wechat2rss.xlab.app/img-proxy/?k=51f65440&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwMpK6GQkVvb4Z1iblEdic11BYyrgriaCqgxsobPXFUvfQkDebM0nkp2xRC2XMqDXicfe8Us3BobWFxdhlhMaoerfHEib0e5kJCSCG60%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">七、执法行动与政策动态</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069530" src="https://wechat2rss.xlab.app/img-proxy/?k=091bd653&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwM0fPBKADP2szpEJhlHXR3J5ibnibG7S0VNyoqVBvVuHnyKyibXIAIQHic66EOngCbdXhTPNft5rzMibbdubdqgMVdAjBIPjlKnZIJU%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">国际联合执法行动Operation PowerOFF捣毁超50个DDoS租用平台</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">美国司法部联合近20个国家开展代号为&#34;Operation PowerOFF&#34;的国际执法行动，成功查封了超过50个与DDoS&#34;Booter&#34;（压力测试）服务相关的网站域名。行动期间逮捕了4名相关人员，识别出约7.5万个犯罪用户账户。DDoS租用服务以每月数十美元的低价向客户提供网站攻击能力，大幅降低了发动网络攻击的门槛，是青少年网络犯罪和勒索攻击的重要工具。此次行动由Europol主导协调，是近年来针对DDoS犯罪生态系统最大规模的跨境联合执法。执法部门发布声明称将继续追踪和打击此类服务背后的运营者和基础设施。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">法国警方逮捕&#34;HexDex&#34;黑客 涉嫌大规模数据盗窃</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">法国国家警察宣布逮捕了一名年仅20岁的黑客嫌疑人，代号&#34;HexDex&#34;。该嫌疑人涉嫌针对法国政府机构、体育组织和多家企业实施大规模数据盗窃和数据泄露行为。HexDex被指控通过多种攻击手法获取目标系统权限，包括漏洞利用、凭证填充和社交工程等，得手后将窃取的数据在暗网论坛公开出售或直接泄露。执法部门在此次逮捕行动中查获了大量电子设备和存储介质，目前正在分析其中的数据以评估影响的完整范围。此案也反映出年轻一代中&#34;网络犯罪低龄化&#34;的严峻趋势。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">CISA主任人选在提名风波后退选 网安政策面临不确定性</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">前特朗普政府提名担任CISA主任的Sean Plankey宣布退出提名程序。Plankey的提名自开始便充满争议，参议院确认听证会期间其网络安全政策立场和管理经验受到多方质疑。他的退选意味着CISA的领导层不确定性将进一步延长，而当前CISA正面临CVE分析和漏洞评估标准收紧、联邦系统漏洞修补期限紧迫等多重挑战。与此同时，CISA还宣布因政府停摆风险取消了备受期待的CyberCorps暑期实习生项目，令网络安全人才培养工作雪上加霜。分析人士担忧，持续的领导层空缺和财政不确定性正在侵蚀CISA作为美国网络安全中枢机构的核心能力。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">CISA警告商业消息应用钓鱼风险上升 FBI联合发布公共服务公告</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CISA与FBI联合发布公共服务公告，警告各国网络行为者正在加大对商业消息应用（如WhatsApp、Telegram、Signal、Microsoft Teams、Slack等）的利用力度。攻击者伪装成机构领导、同事或业务伙伴，通过消息应用发送恶意链接、虚假付款请求或勒索信息。相比传统的邮件钓鱼，消息应用的实时性和非正式性使受害者更容易在未充分思考的情况下点击链接或回复信息。公告建议在使用商业消息应用处理敏感或金融事务时，务必通过第二渠道（如电话或当面确认）核实对方身份。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069532" src="https://wechat2rss.xlab.app/img-proxy/?k=b2e03015&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwN46T7gY8vjxgdkNaNkbjy9MD3TfJic6oqpzhzCxuDLfVnibVS3bVq4cEJ9HTxoWEfcEzg8NaC1WhUFYV5ghVsxsQ8Sia1MluwbGM%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">八、行业趋势</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069531" src="https://wechat2rss.xlab.app/img-proxy/?k=32fe4d18&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwPGFPSf3UyrgibKQXRaAqIOmicjObjDUicTIhqSzic3dM6Zy3AEiblHKxl6Y2dAZaPj1q5Gn2Bn3pDuVicfuckL3UM6jQ2iaQZ40CYHtw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞利用激增往往先于公开披露</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">GreyNoise安全公司发布的一份新报告显示，针对关键漏洞的利用尝试激增现象往往发生在漏洞信息正式公开披露之前。通过对全球蜜罐和传感器网络的流量分析，GreyNoise发现攻击者通常在CVE编号分配后的数小时甚至数天内扩大扫描和利用范围，而部分组织的补丁周期可能需要数周。这一时间差为安全团队提供了宝贵的&#34;预警窗口&#34;——如果能够及时获取网络攻击面的主动利用情报，组织可以在漏洞被正式纳入扫描工具和利用框架之前就采取防御措施。报告建议企业将威胁情报与补丁管理流程深度集成，将被动响应转变为主动预警。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">企业CIO对AI带来的安全风险深感忧虑</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Logicis发布的一项针对全球CIO的调查显示，随着AI技术在企业中的广泛部署，安全风险已成为CIO们最大的担忧之一。超过60%的受访CIO表示，AI的快速采用正在创造&#34;安全控制盲区&#34;，许多组织在部署AI应用时未能同步建立对应的安全治理框架。主要风险包括AI模型供应链安全、训练数据投毒、AI生成内容的合规性审查以及AI代理的权限管理。报告指出，安全团队与AI团队之间的协作和沟通鸿沟是造成这一局面的重要原因，建议企业在AI项目立项阶段就纳入安全团队参与设计与审查。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069533" src="https://wechat2rss.xlab.app/img-proxy/?k=a857c480&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwNCmmosDdh5rwwSbA5qUco8JiajFVVkuaVPHMzLfdDRaMgRYNZCHnprX2Pst23uCVJafhdGEIRTELEdc00SpwicoeP7D9mtp2NWo%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">本周安全建议</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069534" src="https://wechat2rss.xlab.app/img-proxy/?k=98fb004a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwMy96QlryXtENm1aGTstVsdicS2JhFamWibvZFzba4VnlwMWiaZ1VDibkRf1aV6TH7SOPYZLHUqbzrjZj4jfTicrhbzU1DkUPzq6AkM%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">1、紧急修补：</span></strong><span leaf="">立即修补Cisco Catalyst SD-WAN Manager（4个被利用漏洞）、Microsoft SharePoint和Entra Agent ID相关漏洞，优先处理CISA已知利用（KEV）清单中的条目。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2、供应链审查：</span></strong><span leaf="">针对axios和npm包（特别是Namastex相关）进行依赖版本审计，确认开发和生产环境中未使用被污染的版本；审查CI/CD管道中第三方工具的权限范围。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">3、钓鱼防御升级：</span></strong><span leaf="">针对AI辅助生成的钓鱼邮件和商业消息应用钓鱼建立专项培训，确保员工知晓IT部门绝不会通过Teams或Slack直接发送可执行文件。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">4、云安全检查：</span></strong><span leaf="">实施持续的云安全态势管理（CSPM），重点关注服务主体权限、安全组配置和AI代理的权限范围，应对AI驱动的自动化攻击。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">5、IoT设备管理：</span></strong><span leaf="">排查组织内使用的TP-Link等已终止支持的网络设备，制定替换计划；检查面向互联网的OT设备并限制不必要的远程访问。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">6、身份安全强化：</span></strong><span leaf="">审查Azure AD/Entra ID服务主体权限分配，实施多因素认证（MFA）以防止权限提升和租户接管攻击。</span></p></div><div style="font-size: 12px;color: rgb(100, 100, 100);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">数据来源</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">本期资讯编译整理自以下国际网络安全媒体：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">The Hacker News</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• CISA</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• Hackread</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• Cybersecurity Dive</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• SC World</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• The Register</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• BleepingComputer</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• Help Net Security</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• Infosecurity Magazine</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• Dark Reading</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• Security Affairs</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• SecurityWeek</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• The Record</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• Cyber Magazine</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• WIRED Security</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• CSO Online</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• CPO Magazine</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• CRN</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• ZDNet Security</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• Network World</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• TechRepublic</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• CyberDaily</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• The Cyber Express</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• Information Security Buzz</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• Security Boulevard</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• SecurityBrief</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• Homeland Security Newswire</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• Computing.co.uk</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• Cybersecurity News</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• Cybersecurity Ventures</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">免责声明</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">本资讯由安全419资讯中心编译整理，仅供参考学习。如有转载，请注明出处。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">整理日期：</span></strong><span leaf="">2026年4月27日</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 10%;max-width: 100%;height: auto;margin: 0px 10px;line-height: 0;padding: 0px;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;background-image: linear-gradient(to right, rgb(245, 245, 245) 50%, rgb(250, 228, 66) 50%);align-self: flex-start;box-sizing: border-box;"><div style="margin: 3px 0%;width: 100%;box-sizing: border-box;"><div style="font-size: 11px;color: rgb(180, 180, 180);line-height: 1;letter-spacing: 0px;padding: 0px 10px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">END</span></p></div></div></div></div></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100069537" data-ratio="0.459375" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=880dc9ea&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwOHHdfYFtGFqPe82qAWKoxTeESy7LGS1gNk8Lia1UibUL1rdC3trCAufPA6bShkKlebkbYD0BibOs4I9Y0ZltO4PWxdARWGYoibuDM%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="text-align: center;justify-content: center;margin: 10px 0px;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(249, 225, 25);text-align: justify;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">✦</span></p></div></div><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="color: rgb(100, 100, 100);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">推荐阅读</span></strong></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(249, 225, 25);text-align: right;box-sizing: border-box;"><p style="text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">✦</span></p></div></div></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553161&amp;idx=1&amp;sn=de75201c008d3ebfbe35d75082f8c086&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/mmbiz_png/9Nf1wzzcfwPNS1g44GzDKbFmY6aBAYCCgBIqfrcnJcRNVABBPcurKib2GV0sHrgHsdich2MBa9x2kcg2ibPuHcib1HyLeZnuujibjhyeMaqziadwM/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100069535" data-ratio="0.17833333333333334" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1200" src="https://wechat2rss.xlab.app/img-proxy/?k=05bda5b0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwPNS1g44GzDKbFmY6aBAYCCgBIqfrcnJcRNVABBPcurKib2GV0sHrgHsdich2MBa9x2kcg2ibPuHcib1HyLeZnuujibjhyeMaqziadwM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553127&amp;idx=1&amp;sn=7f7375b99330998096597deb42fb613a&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/sz_mmbiz_png/9Nf1wzzcfwO9aXW17jibPV9UibK2pTRLGhB3pFL8XxrpvUwpM6OwEtLafichcnPV2gsEibsPGMsMBTEzfSaJqPoWTTgQEibBQN7VWEibGYVUHCqGo/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.17833333333333334" data-s="300,640" data-type="png" data-w="1200" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069538" src="https://wechat2rss.xlab.app/img-proxy/?k=dde51127&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwO9aXW17jibPV9UibK2pTRLGhB3pFL8XxrpvUwpM6OwEtLafichcnPV2gsEibsPGMsMBTEzfSaJqPoWTTgQEibBQN7VWEibGYVUHCqGo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553068&amp;idx=1&amp;sn=769273f61e16e08311cd687dd7262cb4&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/sz_mmbiz_png/9Nf1wzzcfwNqMQ9S8y41TRlfuFxOMd9O6fjZB2BIDlZwWicpxpU4I6GpgW1HMq99tQbvAjFv42NGibfUFp2y7CMvLLISWevHwicymYXibRFiaxXk/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.17833333333333334" data-s="300,640" data-type="png" data-w="1200" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069536" src="https://wechat2rss.xlab.app/img-proxy/?k=c383b7c8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwNqMQ9S8y41TRlfuFxOMd9O6fjZB2BIDlZwWicpxpU4I6GpgW1HMq99tQbvAjFv42NGibfUFp2y7CMvLLISWevHwicymYXibRFiaxXk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="margin: 10px 0%;text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;background-color: rgba(227, 180, 0, 0.04);align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;box-sizing: border-box;"><div data-cacheurl="" data-remoteid="" style="display: inline-block;width: 100%;vertical-align: top;background-repeat: repeat;background-attachment: scroll;padding: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;background-position: 0% 0% !important;background-size: 4.17755% !important;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=b993f347&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwNloWIiajZl5rlMt47GBfI3GWNbXmeJP9rQIWpkTxibAJlySFBbntG1MQQKRbUBorXeic865HRpcN95yfeaYC2QRd6hicZCHpmRic94%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><div style="display: flex;flex-flow: row;margin: 20px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 30%;flex: 0 0 auto;height: auto;align-self: center;margin: 0px 0px 0px 20px;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="699" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069540" src="https://wechat2rss.xlab.app/img-proxy/?k=926cacfb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F9Nf1wzzcfwMuGd8LicoFqFy78lOmR6XtGRI5egQp5Iaov0cN8O3bJ3nv7BGxzvEmmr1WScAFpgr4MHvkwoLHe1BtzQ50EvpADvNGg47ILgmQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;margin: 0px 0px 0px 10px;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;box-sizing: border-box;"><div style="font-size: 20px;color: rgb(255, 202, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">粉丝福利群开放啦</span></strong></p></div><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(255, 202, 0);font-size: 11px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">加安全419好友进群</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">红包/书籍/礼品等不定期派送</span></p></div></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=25b56c53&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDQ4OTkyMg%3D%3D%26mid%3D2247553211%26idx%3D1%26sn%3D35092f1c1856e8179d0335e410418fa3">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 29 Apr 2026 17:01:00 +0800</pubDate>
    </item>
    <item>
      <title>第三届“长城杯”网数智安全大赛（防护赛）总决赛在福州顺利闭幕</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553211&amp;idx=2&amp;sn=1eda2a511a600e58010265bf7c2c5be8</link>
      <description>广聚全国高校青年英才，不拘一格降人才。</description>
      <content:encoded><![CDATA[<p><span>安全419</span> <span>2026-04-29 17:01</span> <span style="display: inline-block;">四川</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=19071ab1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F9Nf1wzzcfwNLFUYIljKeibs0tYD2s8hTU2btbu7KEXtF1jQ89SgVanib73mpic0iaDGIon2M7h5QtZ34iaVNRNys8kPZibia9PQQ2o7yw6EEZJShP0%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>广聚全国高校青年英才，不拘一格降人才。</p>
  <div style="font-size: 15px;letter-spacing: 1px;line-height: 2;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026年是习近平总书记“4・19”重要讲话发表十周年的重要节点。十年来，习近平总书记的讲话精神深入人心、指导实践，“长城杯”大赛作为践行“4・19”重要讲话精神的创新载体与生动实践，始终以习近平总书记擘画的网络强国、教育强国、科技强国宏伟蓝图为根本指引，精准服务国家战略需求，通过以赛促学、以赛促教、以赛促智、以赛促用，不断完善学研产用协同育人体系，持续挖掘网络安全复合型、应用型、实战型人才，切实筑牢数字中国人才根基。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">4月28日，第三届“长城杯”网数智安全大赛（防护赛）总决赛在福建福州隆重举行。本届大赛由中央网络安全和信息化委员会办公室、教育部、国家市场监督管理总局、国家数据局共同指导，中国信息安全测评中心、中国电信、中国移动、中国联通、北京师范大学联合主办。第十二届全国政协副主席、国家电子政务专家委员会主任王钦敏，教育部高等学校网络空间安全专业教学指导委员会主任方滨兴院士，中国信息安全测评中心主任彭涛、河北雄安新区管理委员会党工委委员、管委会副主任梅新阳，中国电信集团有限公司网络和信息安全管理部总经理谷红勋、中国移动通信集团有限公司网络与信息安全管理部总经理赵刚、中国联合网络通信集团有限公司网络与信息安全部副总经理谢攀等重要嘉宾出席本届大赛，共同见证“长城杯”总决赛的盛大启幕。</span></p></div><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.562037037037037" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069546" src="https://wechat2rss.xlab.app/img-proxy/?k=396081a5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwPjjBJ3a196fylJTPicoHRMTiaHhyrOz1Y6O9xTk0yy0g8DnxJOcnHWQl7krCcsSib79KsqQHZCRhrJLY3Pp3HjspiaXSCAk8dWf8A%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="text-align: center;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">第十二届全国政协副主席、国家电子政务专家委员会主任王钦敏致辞</span></p></div><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.562037037037037" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069549" src="https://wechat2rss.xlab.app/img-proxy/?k=2d77c1ff&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F9Nf1wzzcfwO0FDibDdbyWMEoEO8iaDicyrXGjhvfIA9Y480LW9R8taOhCB5DCnjeoBMWsLKp2lrhcErrvYns6dM9xkUBPjP7VSz6PqHIribTB0Q%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="text-align: center;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">教育部高等学校网络空间安全专业教学指导委员会主任方滨兴院士致辞</span></p></div><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5648148148148148" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069548" src="https://wechat2rss.xlab.app/img-proxy/?k=b1ea4dfc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F9Nf1wzzcfwNU7Eow5IGoqX8zHYIOg6CicLj9WbINO4eUhL8icB3iaBENicjNUa5YFQYXqCef6N4u0ZhY3b3QskpHwibEicic9KqsA9Y4nVe8YKR8hM%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="text-align: center;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">中国信息安全测评中心主任彭涛致辞</span></p></div><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100069547" data-ratio="0.5648148148148148" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=ba6dd57b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwNjyP31psKFx2Jaj6AK2iclgibzhMyXT5B5hg3AUdh3ZFKdMYa6fYbFTNiaJnZtsmDjq3uzN1ZD5MJyNlap84LhXS3QLLU3JXln70%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="text-align: center;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">河北雄安新区管理委员会党工委委员、管委会副主任梅新阳致辞</span></p></div><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5648148148148148" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069545" src="https://wechat2rss.xlab.app/img-proxy/?k=1fdebca7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwOjha4V7hicsrSC0glgsC1kFGa0EWyuXBdcqzXH2NgYCFTaGYkg3Ch8Wf0RrGFv3mHSrGEX0zR8cA4obkgpWb4prD6LfGPRzWuY%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="text-align: center;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">中国电信集团网络和信息安全管理部总经理谷红勋致辞</span></p></div><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.562037037037037" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069550" src="https://wechat2rss.xlab.app/img-proxy/?k=ed62174b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwNe3YtUdcXicxwKYYN5fQ8bnxDA4n5wZzLg0ic8yWeKDaibL9wLrA1ZWUTELYPRawOre8jqfWzxiaLf5icvsuxD0jZCvcaGkEAhtBMc%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="text-align: center;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">中国移动通信集团有限公司网络与信息安全管理部总经理赵刚致辞</span></p></div><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.562962962962963" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069554" src="https://wechat2rss.xlab.app/img-proxy/?k=4a21f4f1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F9Nf1wzzcfwMruRcSazNmE5cWAH5QWMhibVNGJnic2Llmbdm0r8kEgDvxR33ztRSRE5FbX47synN9SXvExNUyZnDt6LJhR4Ma6cn0L9msoeRuE%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="text-align: center;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">中国联合网络通信集团有限公司网络与信息安全部副总经理谢攀致辞</span></p></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">本届大赛紧扣数智时代发展脉搏，以“网络智能防护，开启数字安全新时代”为主题，广聚全国高校青年英才，不拘一格降人才，以数字化、智能化、实战化、体系化为鲜明特色，打造集人才选拔、能力比拼、产教融合、创新赋能于一体的国家级专业赛事平台，以实战竞技遴选高素质网数智安全人才，充分彰显国家级赛事的时代责任与使命担当。</span></p><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.562962962962963" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069551" src="https://wechat2rss.xlab.app/img-proxy/?k=6adefa29&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwNrUIOHOibct5dwcnpiav3JjXOficf8SDBCGUE9nCV290M831uGiaUt6kINUraOPmkO8dqSO40TA9phiadZiaEfj3ybQibXwYIM91aQps%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="text-align: center;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">总决赛启动现场</span></p></div><div style="display: flex;flex-flow: row;margin: 13px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(255, 228, 128);align-self: flex-start;margin: 0px;line-height: 0;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-width: 0px;border-style: none;border-color: rgb(62, 62, 62);box-sizing: border-box;"><div style="margin: -7px 0% 2px;text-align: center;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.6;padding: 0px 18px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">一、高规格协同办赛，筑牢赛事权威底色</span></strong></p></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">本届大赛呈现“高规格指导、多主体联动、全领域参与”的办赛格局，指导单位覆盖国家网络安全、教育、市场监管、数据管理等重要职能部门，形成“政策引导、教育助力、市场赋能、数智融合”的全方位办赛体系。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">大赛历经线上初赛、区域半决赛层层筛选，最终遴选出150支优秀队伍晋级总决赛。参赛阵容涵盖清华大学、浙江大学、复旦大学、国防科技大学等众多国内一流院校，选手均为相关专业优秀学子，代表我国高校网数智安全领域青年人才的顶尖水平，形成“百队竞技、英才汇聚”的赛事盛况。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">开幕式致辞中，王钦敏副主席指出，面对数字中国建设的新任务，必须把人才培养摆在更加突出位置，推动教育链、人才链、创新链、产业链深度融合。他提出三点期望：一是坚持“培根铸魂”，培育网络安全栋梁之材；二是深化“产教融合”，构建协同育人良好生态；三是强化“实战导向”，提升人才核心竞争能力。其他与会致辞领导也希望广大青年学子以大赛为平台，深耕安全技术、厚植家国情怀，尽快成长为守护国家网络空间安全的中坚力量，为数字中国和网络强国建设贡献青春智慧与赤诚担当。</span></p></div><div style="display: flex;flex-flow: row;margin: 13px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(255, 228, 128);align-self: flex-start;margin: 0px;line-height: 0;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-width: 0px;border-style: none;border-color: rgb(62, 62, 62);box-sizing: border-box;"><div style="margin: -7px 0% 2px;text-align: center;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.6;padding: 0px 18px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">二、实战化智能比拼，彰显赛事核心特色</span></strong></p></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">总决赛现场攻防态势瞬息万变，竞赛氛围紧张热烈。本届大赛突破传统网络安全赛事局限，深度聚焦“网数智安全”核心定位，以智能防护、实战对抗、场景还原为三大竞赛特色，全面检验参赛选手应对数智时代网络安全威胁的综合能力，真正实现“赛场即战场、竞赛即实战”的办赛目标。</span></p><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5574074074074075" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069552" src="https://wechat2rss.xlab.app/img-proxy/?k=9856b787&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwPAXfFsZ5XQFcf79oZy6Qjb5z9ppEEjlcDvMK2FOLugpUjtIqaiacvbwMsG1V7UnC7YVBgtHA7CtdqomKlg2cMgv3ibaBWF0lict8%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5675925925925925" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069553" src="https://wechat2rss.xlab.app/img-proxy/?k=b3a615a1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwPKcsQib8668S78EmYfsVuGELiceD038ibwvXyjOXW3IUdbwConTbZ5W3XA3rJriciatibDx8Z9KAdzGd5CST0rYEO4x5zIYhNTM9wqo%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="text-align: center;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">总决赛比赛现场</span></p></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">相较于往届，本届大赛更突出“数智融合”核心亮点，不仅考验选手们对漏洞挖掘、安全加固、应急响应等传统安全技能的掌握程度，更聚焦人工智能时代下的新型安全风险，提升智能安全类赛题占比，全面检验选手们运用智能化手段应对复杂网络威胁的综合能力。赛场上，各参赛队伍分工协作、沉着应战，凭借扎实的理论功底、娴熟的操作技能和敏捷的应急思维，精准排查安全漏洞、高效部署防护策略、快速处置突发威胁，在高强度实战对抗中展现了新时代青年网安人才的过硬素养与实战水平。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">经过8小时激烈鏖战及大赛裁判组的严格评审，本次大赛最终评选出一、二、三等奖。其中，来自国防科技大学、华中科技大学、清华大学、合肥师范学院、中国人民公安大学的队伍获得一等奖；来自哈尔滨工业大学、国防科技大学、铜陵学院、浙江师范大学等20所高校的队伍获得二等奖；来自全国高校的75支队伍获得三等奖。一批技术精湛、表现突出的优秀队伍脱颖而出，充分展现了我国高校网数智安全人才培养的丰硕成果，为国家网安事业建设发掘出一批潜力十足的优秀青年人才。</span></p></div><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5677339901477833" data-s="300,640" data-type="jpeg" data-w="812" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069555" src="https://wechat2rss.xlab.app/img-proxy/?k=cc39b188&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F9Nf1wzzcfwOMTHiatyUqgXDbbSusr2l5stuygKpaQw8BU01U3KRziaTCYzgeqw4WRW1qT3NM6TGYaMUrgq5ibfE4jxFWudtWOlxjibZeTD6LTK0%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="text-align: center;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">一等奖</span></p></div><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.7496839443742098" data-s="300,640" data-type="jpeg" data-w="791" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069556" src="https://wechat2rss.xlab.app/img-proxy/?k=5ca60cf9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwNHr2Fgtsgs1oClvnqaUkt6N8pMQ970CSHq0pMHfPgNdpoQ5FmiciavUclicS4NDjfIBaH0RDwjdYucLTaianAHKBNNeJVFUm3NMeQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="text-align: center;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">二等奖</span></p></div><div style="display: flex;flex-flow: row;margin: 13px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(255, 228, 128);align-self: flex-start;margin: 0px;line-height: 0;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-width: 0px;border-style: none;border-color: rgb(62, 62, 62);box-sizing: border-box;"><div style="margin: -7px 0% 2px;text-align: center;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.6;padding: 0px 18px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">三、体系化产教融合，激活人才培育动能</span></strong></p></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">“长城杯”大赛不仅是一场高水平竞技盛宴，更是推动国家网数智安全领域产教深度融合、协同育人的重要载体。大赛始终立足国家战略发展实际需求，将行业前沿技术、真实安全痛点、核心防护标准融入赛事全流程，让青年学子在实战竞赛中精准把握行业发展趋势，熟悉岗位能力要求，实现专业知识与实战应用的无缝衔接，有效推动了网络安全人才培养与国家战略需求的深度融合。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">与会专家普遍认为，在数字中国建设步入新阶段、“十五五”规划开局起步的关键时期，“长城杯”大赛的办赛意义重大深远，作为我国网数智安全领域的标杆赛事，大赛始终坚持聚天下英才而用之、不拘一格降人才的办赛宗旨，不仅为青年学子提供了淬炼实战本领、展示创新风采的优质舞台，更为我国网数智安全人才梯队建设注入新鲜血液，为提升国家网络安全防护能力、保障数字经济安全发展提供坚实支撑。</span></p></div><div style="display: flex;flex-flow: row;margin: 13px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(255, 228, 128);align-self: flex-start;margin: 0px;line-height: 0;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-width: 0px;border-style: none;border-color: rgb(62, 62, 62);box-sizing: border-box;"><div style="margin: -7px 0% 2px;text-align: center;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.6;padding: 0px 18px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">四、品牌化深耕细作，共筑数字安全长城</span></strong></p></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">历经多年深耕细作，“长城杯”大赛已成为我国网数智安全领域极具公信力和影响力的品牌赛事。本届总决赛圆满举办，是坚持统筹发展与安全，全面推进强国建设的生动实践，不仅为第九届数字中国建设峰会增添浓墨重彩的安全篇章，更以赛事为纽带实现社会总动员，凝聚起网络安全防护合力，进一步深化学研产用协同合作，创新网数智安全人才培养模式，构筑网络空间安全的人民防线工程，以青年之智、技术之力、协同之举，为建设网络强国、数字中国、实现科技自立自强，凝聚蓬勃力量、筑牢安全屏障、夯实人才根基，以高质量发展奋力谱写新时代网络安全事业新篇章。</span></p><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 10%;max-width: 100%;height: auto;margin: 0px 10px;line-height: 0;padding: 0px;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;background-image: linear-gradient(to right, rgb(245, 245, 245) 50%, rgb(250, 228, 66) 50%);align-self: flex-start;box-sizing: border-box;"><div style="margin: 3px 0%;width: 100%;box-sizing: border-box;"><div style="font-size: 11px;color: rgb(180, 180, 180);line-height: 1;letter-spacing: 0px;padding: 0px 10px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">END</span></p></div></div></div></div></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.459375" data-s="300,640" data-type="gif" data-w="640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069557" src="https://wechat2rss.xlab.app/img-proxy/?k=b52895bb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwPehLKDoRLfD4sSeriajLCYB9t8ymIbiaZvXOAQZYhA0rDFoibDjwPibEGgxErKNK7yrURSmqzOAhOU9v55r7OJkJGQ984dL424crQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="margin: 10px 0%;text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;background-color: rgba(227, 180, 0, 0.04);align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;box-sizing: border-box;"><div data-cacheurl="" data-remoteid="" style="display: inline-block;width: 100%;vertical-align: top;background-repeat: repeat;background-attachment: scroll;padding: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;background-position: 0% 0% !important;background-size: 4.17755% !important;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=ef92fee7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwNkvuYygWQRHJz7ZPtswmicZHOCkyNxmj4WQORQ7oODfnJiaT934fTgE7KhkLt0dedMpOscXicytAdypYNKhtKggAB7hlBUGsLVicE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><div style="display: flex;flex-flow: row;margin: 20px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 30%;flex: 0 0 auto;height: auto;align-self: center;margin: 0px 0px 0px 20px;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="699" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069558" src="https://wechat2rss.xlab.app/img-proxy/?k=86fbda64&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F9Nf1wzzcfwM1hraVXo45Jxwt9pPvjwoj0sKwib5rhuReDq48LjiaXx2dXJNzcRydMSktBiagwcHDSULpz5wXLxd3koQZSBTkqesbQq8QuseXyI%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;margin: 0px 0px 0px 10px;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;box-sizing: border-box;"><div style="font-size: 20px;color: rgb(255, 202, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">粉丝福利群开放啦</span></strong></p></div><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(255, 202, 0);font-size: 11px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">加安全419好友进群</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">红包/书籍/礼品等不定期派送</span></p></div></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=4cb2ccbd&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDQ4OTkyMg%3D%3D%26mid%3D2247553211%26idx%3D2%26sn%3D1eda2a511a600e58010265bf7c2c5be8">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 29 Apr 2026 17:01:00 +0800</pubDate>
    </item>
    <item>
      <title>零信任未过时 但许多实施已落后于时代</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553161&amp;idx=1&amp;sn=de75201c008d3ebfbe35d75082f8c086</link>
      <description>零信任理念本身无误，但许多企业的实施过于静态僵化，无法适应身份与数据持续动态变化的现实，需升级至实时决策。</description>
      <content:encoded><![CDATA[<p>原创 <span>安全419</span> <span>2026-04-27 17:30</span> <span style="display: inline-block;">四川</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d67c4ca0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F9Nf1wzzcfwPhamYjiakjKrhYLzrY9bRf4JJAnncY4sQVbibfjuNoMuuXiad9ia5R6swnVBRmemCticpNiaHkNro7Jduh49SlKdge2uiacV3MNp8C30%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>零信任理念本身无误，但许多企业的实施过于静态僵化，无法适应身份与数据持续动态变化的现实，需升级至实时决策。</p>
  <div style="font-size: 15px;letter-spacing: 1px;line-height: 2;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">想象一个城市，安装了交通信号灯之后就再也不去管它。在一开始，规则是合理的：这里停，那里行。但年复一年，交通模式改变了。新的道路出现了。车流量增加了。交通方式本身也发生了变化。曾经改善安全和车流的系统开始导致拥堵和事故，原因不在于交通控制这个想法本身有缺陷，而在于该系统停止了适应现实。</span></p><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.562962962962963" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069480" src="https://wechat2rss.xlab.app/img-proxy/?k=3127f7f5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwNeF7OULj3RleYwT0gvf6Q2OnCIwFX02Zmt1stpQbkenjmwcZeV1DyYh0ljShG6YXLmCL4S0naGyU59IorFmbiaFLcPavLKhrWw%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这正是如今许多零信任实施所处的境地。</span><strong style="box-sizing: border-box;"><span leaf="">零信任仍然是一个正确的安全原则。持续验证访问而非假设信任的理念比以往任何时候都更具现实意义。</span></strong><span leaf="">但挑战在于，许多组织在高度动态的环境中实施的却是固定不变的零信任框架。云 adoption、混合工作、自动化和 AI 驱动的流程已经改变了身份的行为方式和数据的移动方式。</span><strong style="box-sizing: border-box;"><span leaf="">严重依赖静态策略和低频审查的安全模型难以跟上节奏。</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">对于安全领导者来说，问题不再是零信任是否为正确的战略，而是它是否反映了真实的访问路径——尤其是对于非人类身份和敏感数据移动。</span><strong style="box-sizing: border-box;"><span leaf="">如果你无法映射和衡量这些路径，你就没有零信任，你有的只是书面工作。</span></strong></p></div><div style="text-align: center;justify-content: center;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-style: solid;border-width: 1px;border-color: rgb(255, 202, 0);align-self: flex-start;box-sizing: border-box;"><div style="justify-content: center;margin: -3px 0% 3px;transform: translate3d(-3px, 0px, 0px);-webkit-transform: translate3d(-3px, 0px, 0px);-moz-transform: translate3d(-3px, 0px, 0px);-o-transform: translate3d(-3px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(255, 202, 0);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;border-width: 0px;align-self: flex-start;box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 14px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">零信任何时变得过于僵化</span></strong></p></div></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">早期的零信任计划正确地聚焦于将信任从网络转移到身份。认证得到加强，设备得到检查，并根据与角色或组别相关的预定义规则授予访问权限。对许多组织而言，这代表了一次重大进步。零信任是从“网络内部=可信”的转变，转向基于身份、上下文和特定资源，对每次请求决定是否授予访问权限。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">然而，随着时间的推移，这些规则常常变成了固化的假设。角色改变了，但访问权限并不总能随之变化。例外情况不断累积。审查每季度或每年进行一次，即使访问模式每天都在变化。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">与此同时，非人类身份的数量迅速增长。服务账户、API、自动化工具和 AI 驱动的流程开始昼夜不停地访问系统和数据。现在的难点不再是“零信任”这个口号，而是在身份、授权和数据流持续变化的情况下，让这些决策保持准确。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">下面是一个可能发生的真实场景。某个组织为支持一个特定的云迁移项目创建了一个服务账户，在项目结束很久之后，该账户仍保留着广泛的访问权限。在零信任模型下，该账户继续成功通过认证，因为它满足每一项已定义的策略要求。但未被注意到的是，它正在访问早已不再需要访问的敏感数据存储。如果这样的账户最终被入侵，攻击者根本不需要绕过零信任控制。他们只需使用几个月前就应该被移除的权限即可。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">这种暴露风险并非源于忽视零信任原则，而是源于在身份和访问需求不断变化的环境中过于僵化地应用了零信任原则。</span></strong></p></div><div style="text-align: center;justify-content: center;margin: -3px 0% 3px;transform: translate3d(-3px, 0px, 0px);-webkit-transform: translate3d(-3px, 0px, 0px);-moz-transform: translate3d(-3px, 0px, 0px);-o-transform: translate3d(-3px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(255, 202, 0);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;border-width: 0px;align-self: flex-start;box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 14px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">迈向实时身份决策及其为何重要</span></strong></p></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">研究数据显示，被泄露的凭证仍然是安全事件的主要诱因之一，参与造成了16%的数据泄露。结合过高的权限，被盗的凭证会导致最糟糕的安全状况——入侵事件。在许多案例中，攻击者利用的并不是零日漏洞。他们利用的是在技术上符合策略但放在上下文中已不再合理的访问权限。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">现代的零信任模型正在演进以应对这一现实。组织不再将访问视为一次性决策，而是开始使用实时上下文和行为来持续评估访问。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">实时身份决策不仅关注身份能否通过认证。它还考虑该身份的行为方式、正在访问哪些数据，以及活动是否与既定模式和业务意图一致。然后可以动态调整访问决策——这可能意味着触发升级认证、限制对敏感数据的访问，或暂时挂起活动以待审查。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这种方法与现代环境的运行方式更加契合。访问不再是一项被授予后就被遗忘的静态权限。它是一种随着角色、设备和工作负载变化而不断变化的持续交互。</span></p></div><div style="text-align: center;justify-content: center;margin: -3px 0% 3px;transform: translate3d(-3px, 0px, 0px);-webkit-transform: translate3d(-3px, 0px, 0px);-moz-transform: translate3d(-3px, 0px, 0px);-o-transform: translate3d(-3px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(255, 202, 0);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;border-width: 0px;align-self: flex-start;box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 17px;padding: 0px 14px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">提升零信任模型的实用步骤</span></strong></p></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">重新评估零信任并不需要彻底推倒重来</span></strong><span leaf="">。大多数组织已经具备了所需的许多组件。关键在于改进它们之间的连接和使用方式。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">安全团队可以</span><strong style="box-sizing: border-box;"><span leaf="">从审视当前如何做出访问决策开始</span></strong><span leaf="">。如果访问仍然主要由定期审查的静态组成员身份或角色分配驱动，这表明模型可能需要调整。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">接下来，他们可以</span><strong style="box-sizing: border-box;"><span leaf="">将身份治理与访问执行更紧密地集成</span></strong><span leaf="">。能够提供有效权限、未使用的授权和异常行为可见性的工具，可以帮助安全团队更早地识别风险。在自动化支持下进行的持续访问审查，远比手动的认证周期更有效。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">行为分析也扮演着重要角色</span></strong><span leaf="">。能够追踪用户和非人类身份如何与系统和数据交互的身份感知监控工具，可以为自适应控制提供所需的上下文。这使得组织能够做出相称的响应，而不是采用拖慢业务的一刀切限制。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">组织应该</span><strong style="box-sizing: border-box;"><span leaf="">实施持续的数据发现和分类</span></strong><span leaf="">。这些实践有助于确保在数据移动、更改、组合以及业务流程改变某些数据集的重要性时，敏感度标签保持准确。然后，这些标签可以自动驱动策略，基于有效访问、数据敏感性和上下文（而非静态角色）来限制共享、要求更强的认证、限制下载和泄露路径，或强制加密。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">最后，组织应</span><strong style="box-sizing: border-box;"><span leaf="">确保零信任策略随环境一起演进</span></strong><span leaf="">。当引入新的云服务、AI工具和自动化平台时，应在部署过程中（而不是几个月后）重新评估访问模型。</span></p></div><div style="text-align: center;justify-content: center;margin: -3px 0% 3px;transform: translate3d(-3px, 0px, 0px);-webkit-transform: translate3d(-3px, 0px, 0px);-moz-transform: translate3d(-3px, 0px, 0px);-o-transform: translate3d(-3px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(255, 202, 0);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;border-width: 0px;align-self: flex-start;box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 17px;padding: 0px 14px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">与现实同步的零信任</span></strong></p></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">零信任从来就不是静态的。</span></strong><span leaf="">它旨在帮助组织在不确定和不断变化的环境中做出更好的访问决策。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">如今，</span><strong style="box-sizing: border-box;"><span leaf="">不确定性已成为常态，身份是流动的，数据在持续移动。</span></strong><span leaf="">自动化和AI同时加速了机遇和风险。那些调整其零信任模型以包含实时身份决策的安全领导者，可以获得更好的可见性、更快的响应速度以及对其控制措施的更强信心。</span></p></div><div style="font-size: 12px;color: rgb(100, 100, 100);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">参考链接：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.cpomagazine.com/cyber-security/is-zero-trust-broken-no-but-many-implementations-are-stuck-in-the-past/" target="_blank">https://www.cpomagazine.com/cyber-security/is-zero-trust-broken-no-but-many-implementations-are-stuck-in-the-past/</a></span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 10%;max-width: 100%;height: auto;margin: 0px 10px;line-height: 0;padding: 0px;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;background-image: linear-gradient(to right, rgb(245, 245, 245) 50%, rgb(250, 228, 66) 50%);align-self: flex-start;box-sizing: border-box;"><div style="margin: 3px 0%;width: 100%;box-sizing: border-box;"><div style="font-size: 11px;color: rgb(180, 180, 180);line-height: 1;letter-spacing: 0px;padding: 0px 10px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">END</span></p></div></div></div></div></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.459375" data-s="300,640" data-type="gif" data-w="640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069483" src="https://wechat2rss.xlab.app/img-proxy/?k=fa44366a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwOPK5QVNLOwxN9MF1xdAaJuEjmpRM7U0FSyicFicSof5gibjpYaibmmNlNIx4vBTiaL41MrnIVCt4FMVXAEpib5gGu6NMNsY34foyWic8%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="text-align: center;justify-content: center;margin: 10px 0px;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(249, 225, 25);text-align: justify;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">✦</span></p></div></div><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="color: rgb(100, 100, 100);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">推荐阅读</span></strong></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(249, 225, 25);text-align: right;box-sizing: border-box;"><p style="text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">✦</span></p></div></div></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553127&amp;idx=1&amp;sn=7f7375b99330998096597deb42fb613a&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/sz_mmbiz_png/9Nf1wzzcfwONkPhk8MdGJTkmic9fskHGlrDTfA7J4gssCVMKR8HQPfGicTxhr1cj0yXg8ZtKwTUZAGq9kalicXXOnJKAPNsYvvtpaJAic7FSOpM/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1787037037037037" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069484" src="https://wechat2rss.xlab.app/img-proxy/?k=49a44a0a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwONkPhk8MdGJTkmic9fskHGlrDTfA7J4gssCVMKR8HQPfGicTxhr1cj0yXg8ZtKwTUZAGq9kalicXXOnJKAPNsYvvtpaJAic7FSOpM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553019&amp;idx=1&amp;sn=06effa47b649b25b2aba84045c7195cd&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/mmbiz_png/9Nf1wzzcfwOpX4bNMeAM9ckcHUzB6PrjDv5gWIQWA9iaLXZxDTRvDPfyXCpZD4cjqa658X0MsYOtjw35vE9e0ZfXF4Pe4HVUl9yrYx4HD8Ho/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1787037037037037" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069481" src="https://wechat2rss.xlab.app/img-proxy/?k=05c77aac&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwOpX4bNMeAM9ckcHUzB6PrjDv5gWIQWA9iaLXZxDTRvDPfyXCpZD4cjqa658X0MsYOtjw35vE9e0ZfXF4Pe4HVUl9yrYx4HD8Ho%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553068&amp;idx=1&amp;sn=769273f61e16e08311cd687dd7262cb4&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/sz_mmbiz_png/9Nf1wzzcfwPmIH6Wh8sL87UsdhduXEb0Yiaia6DRhhw2LqIPbNXP7kFO4TYz19abJibo1fmTSV3MjTYic6JLUqVrLRw7FPgHEUC5zpHlTxB751Y/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1787037037037037" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069482" src="https://wechat2rss.xlab.app/img-proxy/?k=a9298e68&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwPmIH6Wh8sL87UsdhduXEb0Yiaia6DRhhw2LqIPbNXP7kFO4TYz19abJibo1fmTSV3MjTYic6JLUqVrLRw7FPgHEUC5zpHlTxB751Y%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="margin: 10px 0%;text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;background-color: rgba(227, 180, 0, 0.04);align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;box-sizing: border-box;"><div data-cacheurl="" data-remoteid="" style="display: inline-block;width: 100%;vertical-align: top;background-repeat: repeat;background-attachment: scroll;padding: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;background-position: 0% 0% !important;background-size: 4.17755% !important;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=226caef6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwPeO5wP9piawvIR05EatW7wvEWLk6uVK5JaXaP8icC7GubrZgyx0f6URhxGzMA5627LH7keSq64tZat6BhyonYN2AeeVy2fj9Gvw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><div style="display: flex;flex-flow: row;margin: 20px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 30%;flex: 0 0 auto;height: auto;align-self: center;margin: 0px 0px 0px 20px;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="699" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069486" src="https://wechat2rss.xlab.app/img-proxy/?k=c276c6c9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwNncRUPGu24w56bTJTZ8aYYkRYBM77ficBlMRial2uFDH3W4buQVHFtLPicegicQePcDVYNXeVn0m9XxFJvTw5cflDv6g8xyfQeuHc%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;margin: 0px 0px 0px 10px;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;box-sizing: border-box;"><div style="font-size: 20px;color: rgb(255, 202, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">粉丝福利群开放啦</span></strong></p></div><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(255, 202, 0);font-size: 11px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">加安全419好友进群</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">红包/书籍/礼品等不定期派送</span></p></div></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=66fa7494&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDQ4OTkyMg%3D%3D%26mid%3D2247553161%26idx%3D1%26sn%3Dde75201c008d3ebfbe35d75082f8c086">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 27 Apr 2026 17:30:00 +0800</pubDate>
    </item>
    <item>
      <title>权威统计｜安全玻璃盒连续稳居软件供应链安全市场全国第二</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553161&amp;idx=2&amp;sn=2a16d915df88766504376091b562e4bb</link>
      <description>安全玻璃盒将加大在AI大模型、安全智能体、原生安全等前沿技术的研发投入，推动软件供应链安全从被动防御向主动免疫演进。</description>
      <content:encoded><![CDATA[<p><span>安全419</span> <span>2026-04-27 17:30</span> <span style="display: inline-block;">四川</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=76062990&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwM9Y1LH36r7ibesq1QV7Uo4Q1KKD8UPluYibibDDmDLpxJTiaopB4ynh90ibkbx6cgwOhKiaSOv7BcYHm45QJK8rh3USrzS3ayEWoaTc%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>安全玻璃盒将加大在AI大模型、安全智能体、原生安全等前沿技术的研发投入，推动软件供应链安全从被动防御向主动免疫演进。</p>
  <div style="font-size: 15px;letter-spacing: 1px;line-height: 2;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">根据《中国软件行业协会》发布权威的市场数据及行业分析报告显示，杭州孝道科技有限公司【安全玻璃盒】在软件供应链安全领域凭借领先的技术实力与广泛的实践应用，在软件供应链安全赛道的市场占有率连续两年稳居国内第二，同时引领AI驱动软件供应链安全市场且增长势头强劲。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这一行业地位的确认，标志着安全玻璃盒在AI驱动的软件供应链安全领域已建立起稳固的领先优势，成为护航国家数字基础设施安全的核心力量。</span></p></div><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 10px 0px 20px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: solid;border-width: 1px;min-width: 5%;max-width: 100%;height: auto;box-shadow: rgb(255, 228, 128) 6px 6px 0px 0px;padding: 8px;box-sizing: border-box;"><div style="text-align: left;margin: 0px;box-sizing: border-box;"><div style="text-align: center;font-size: 16px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">国家战略驱动</span></strong></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">软件供应链安全市场规模持续攀升</span></strong></p></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">近年来，全球科技竞争与网络空间博弈不断升级，</span><strong style="box-sizing: border-box;"><span leaf="">面对开源投毒、供应链断供以及漏洞导致的数据泄露等安全风险频发，软件供应链安全已成为保障关键信息基础设施安全稳定运行的底线要求</span></strong><span leaf="">。国家层面围绕关键信息基础设施安全保护要求、开源安全治理密集出台法规标准，划定清晰底线。《网络安全法》、《国务院关于产业链供应链安全的规定》、《网络安全技术 软件供应链安全要求》等法规标准相继落地，金融、能源、电信等关键行业也陆续推出供应链安全考核要求，推动安全能力从合规走向实战化、体系化运营。在政策与市场需求双重驱动下，中国软件供应链安全市场快速增长，正处于爆发前夜，发展空间广阔。</span></p><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 10px 0px 20px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: solid;border-width: 1px;min-width: 5%;max-width: 100%;height: auto;box-shadow: rgb(255, 228, 128) 6px 6px 0px 0px;padding: 8px;box-sizing: border-box;"><div style="text-align: left;margin: 0px;box-sizing: border-box;"><div style="text-align: center;font-size: 16px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">数据领跑</span></strong></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">稳居行业第二，增长势头强劲</span></strong></p></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">根据中国软件行业协会分析统计，安全玻璃盒在软件供应链安全细分领域的综合实力呈现出稳健增长态势与极高的稳定性。报告显示，公司在</span><strong style="box-sizing: border-box;"><span leaf="">软件供应链安全细分领域的国内市场占有率从2023年排名第三，迅速攀升至2024年排名第二，并且在2025年稳居国内第二</span></strong><span leaf="">，体现出在激烈的市场竞争中持续扩大的领先优势。</span></p><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.3155452436194897" data-s="300,640" data-type="png" data-w="862" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069492" src="https://wechat2rss.xlab.app/img-proxy/?k=fac95eb6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwMEyM5R7GjjZZ912jMUtdlRvttuF8Sg1FMSdXo3ia3r3Zt9wpRIsHIN6eNJ1P4icmcCeO5Is5PwjNZkVFjuicA1eGXN3VLV4uUleE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这一系列成绩的背后，是市场对安全玻璃盒“</span><strong style="box-sizing: border-box;"><span leaf="">AI驱动、原生安全、全链可控</span></strong><span leaf="">”技术路线的高度认可。</span></p><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 10px 0px 20px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: solid;border-width: 1px;min-width: 5%;max-width: 100%;height: auto;box-shadow: rgb(255, 228, 128) 6px 6px 0px 0px;padding: 8px;box-sizing: border-box;"><div style="text-align: left;margin: 0px;box-sizing: border-box;"><div style="text-align: center;font-size: 16px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">技术破局</span></strong></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">AI重构软件供应链安全范式</span></strong></p></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在数字中国与网络强国战略的纵深推进下，软件供应链安全已成为关乎国家安全与产业自主可控的战略高地。面对开源投毒、供应链断供以及漏洞导致的数据泄露等日益复杂的威胁，传统安全工具已难以招架。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">安全玻璃盒秉持“</span><strong style="box-sizing: border-box;"><span leaf="">不是需要更多的安全软件，而是需要更安全的软件</span></strong><span leaf="">”的核心理念，以AI大模型与多智能体协同安全检测技术为引擎，重构了软件供应链安全的技术范式：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">大语言模型 + 多 Agent 协同架构</span></strong><span leaf="">：打造供应链安全 AI 智能体集群，实现源代码审计、成分分析等多智能体协同调度，融合漏洞库、威胁情报等数据，通过交叉验证使误报率降低 90% 以上，显著提升高危漏洞检出率。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">软件原生安全检测与防护技术</span></strong><span leaf="">：突破零侵入插桩、动态污点追踪、在线靶向修复等技术难点，无需修改源码即可全维度检测，精准定位漏洞并支持不重启应用的漏洞实时修复，让软件具备自身免疫力。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">开源组件全生命周期安全管理技术</span></strong><span leaf="">：涵盖组件健康度分析（识别断供风险）、代码同源分析（自研率分析）、投毒检测（识别后门）、漏洞检测（漏洞风险识别）等，结合实时情报实现开源组件风险全周期监控预警。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">软件供应链资产测绘与图谱构建技术</span></strong><span leaf="">：基于图谱技术构建“供应商-组件-应用”全链路资产与安全图谱，实现风险深度溯源与快速评估，解决家底不清、风险不可溯难题。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">基于核心技术，安全玻璃盒推出AI驱动的软件供应链安全一体化解决方案，覆盖软件供应链</span><strong style="box-sizing: border-box;"><span leaf="">开发、交付、使用</span></strong><span leaf="">全生命周期，包含AI软件供应链安全平台、可信安全组件中心仓、软件原生安全检测与免疫防御、软件供应链安全评估检测工具箱、供应链安全威胁情报与态势感知五大核心产品方案，实现“可信引入、可信开发、可信交付、可信运行”的全流程安全赋能，推动安全能力从单点防护向全链治理演进。</span></p></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">北京百度网讯科技有限公司百度安全副总裁顾孔希，发表 “范式重构：AI时代漏洞治理的变与不变”的演讲。</span></p><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 10px 0px 20px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: solid;border-width: 1px;min-width: 5%;max-width: 100%;height: auto;box-shadow: rgb(255, 228, 128) 6px 6px 0px 0px;padding: 8px;box-sizing: border-box;"><div style="text-align: left;margin: 0px;box-sizing: border-box;"><div style="text-align: center;font-size: 16px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">市场验证</span></strong></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">服务数百家头部客户，筑牢数字防线</span></strong></p></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">市场地位的领先，源于广泛的客户信赖与深度的行业实践。安全玻璃盒的解决方案已广泛应用于</span><strong style="box-sizing: border-box;"><span leaf="">金融、能源电力、电信运营商、政府、央国企</span></strong><span leaf="">等关键行业。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">目前，安全玻璃盒已服务中国证监会、交通银行、浙商银行、兴业银行、渤海银行、国家电网、国家电投、中国华能集团、中国大唐集团、中国移动、中国电信、中国联通、国家信息安全测评中心、湖南省公安厅、浙江省医保局、浙江省卫健委、各省市大数据发展管理局、比亚迪、奇瑞汽车、江淮汽车、零跑汽车、大华股份等</span><strong style="box-sizing: border-box;"><span leaf="">数百家头部客户</span></strong><span leaf="">，拥有丰富的行业落地经验。针对不同行业业务特点和合规要求，打造定制化软件供应链安全解决方案，实现了安全能力与行业业务深度融合，帮助客户有效防范供应链安全风险，顺利通过监管合规检查。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">凭借</span><strong style="box-sizing: border-box;"><span leaf="">三十余项技术发明专利</span></strong><span leaf="">和七十余项软件著作权，安全玻璃盒不仅在技术上实现了从外挂防护到原生安全的代际跃升，更深度参与了</span><strong style="box-sizing: border-box;"><span leaf="">《网络安全技术 软件物料清单数据格式》、《网络安全技术 软件产品开源代码安全评价方法》</span></strong><span leaf="">等多项国家标准的制定，成为行业规则的制定者之一。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">此外，公司凭借在软件供应链安全领域的突出表现，荣获IDC中国DevSecOps技术创新者、2025 AI与安全能力领航者、2025 IAST能力领航者、工信部等十二部委网络安全技术应用试点示范项目、网络安全国家标准应用实践案例等多项国家级、行业级荣誉；连续多年获得全国网络安全优秀创新成果大赛优秀奖、全国网络安全十大创新方向、全国网络安全潜力企业十强、全国网络安全十大优秀产品等荣誉，品牌影响力位居国内软件供应链安全领域前列。</span></p></div><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 10px 0px 20px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: solid;border-width: 1px;min-width: 5%;max-width: 100%;height: auto;box-shadow: rgb(255, 228, 128) 6px 6px 0px 0px;padding: 8px;box-sizing: border-box;"><div style="text-align: left;margin: 0px;box-sizing: border-box;"><div style="text-align: center;font-size: 16px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">展望未来</span></strong></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">从行业领先迈向全球引领</span></strong></p></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">获得市场领先地位的高度认可，是安全玻璃盒发展历程中的重要里程碑。未来，安全玻璃盒将继续加大在</span><strong style="box-sizing: border-box;"><span leaf="">AI大模型、安全智能体、原生安全</span></strong><span leaf="">等前沿技术的研发投入，推动软件供应链安全从被动防御向主动免疫演进。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">公司以“</span><strong style="box-sizing: border-box;"><span leaf="">让软件供应链安全护航数字智能</span></strong><span leaf="">”为企业愿景，以国家战略需求为导向，持续完善全链路、体系化的解决方案，致力于成为全球软件供应链安全的技术引领者，为保障国家数字安全、推动数字经济高质量发展贡献核心力量。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 10%;max-width: 100%;height: auto;margin: 0px 10px;line-height: 0;padding: 0px;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;background-image: linear-gradient(to right, rgb(245, 245, 245) 50%, rgb(250, 228, 66) 50%);align-self: flex-start;box-sizing: border-box;"><div style="margin: 3px 0%;width: 100%;box-sizing: border-box;"><div style="font-size: 11px;color: rgb(180, 180, 180);line-height: 1;letter-spacing: 0px;padding: 0px 10px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">END</span></p></div></div></div></div></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.459375" data-s="300,640" data-type="gif" data-w="640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069493" src="https://wechat2rss.xlab.app/img-proxy/?k=60a0e636&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwMatoX9QMojzHKMhFk4CzDFssxOmWGFUzicjGPib2gOxicjNR7G4tGRfVtbrIUMy1vBdmyYdUbV7KpYnVm7QZasb9I4s31HcEib9Xg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="margin: 10px 0%;text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;background-color: rgba(227, 180, 0, 0.04);align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;box-sizing: border-box;"><div data-cacheurl="" data-remoteid="" style="display: inline-block;width: 100%;vertical-align: top;background-repeat: repeat;background-attachment: scroll;padding: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;background-position: 0% 0% !important;background-size: 4.17755% !important;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=68154f45&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwMOzKIT65MVPlUecwfoU3FlBF3hkHPQyH5zvTlRqayPvDN02Df1ZtvbS0liacHajK14ia5uq1ZnLgpTHTRt4o5fwDXetCN7LlnEo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><div style="display: flex;flex-flow: row;margin: 20px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 30%;flex: 0 0 auto;height: auto;align-self: center;margin: 0px 0px 0px 20px;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="699" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069491" src="https://wechat2rss.xlab.app/img-proxy/?k=4bbcd806&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F9Nf1wzzcfwNIgkF8kgVf3BKfHOwdu8IVIySrBIojaq1q6qmSroHrJPfdRnfFZ4IQqb4aQ3mQsbgibJQ6hXP5lnv4F3IQjh0sh0icBqWx6HzYs%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;margin: 0px 0px 0px 10px;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;box-sizing: border-box;"><div style="font-size: 20px;color: rgb(255, 202, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">粉丝福利群开放啦</span></strong></p></div><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(255, 202, 0);font-size: 11px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">加安全419好友进群</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">红包/书籍/礼品等不定期派送</span></p></div></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=7dc05f12&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDQ4OTkyMg%3D%3D%26mid%3D2247553161%26idx%3D2%26sn%3D2a16d915df88766504376091b562e4bb">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 27 Apr 2026 17:30:00 +0800</pubDate>
    </item>
    <item>
      <title>第三届“长城杯”网数智安全大赛（防护赛）总决赛即将开启</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553161&amp;idx=3&amp;sn=a46d614ab299598a486c3b858b3c8c21</link>
      <description>4月28日，让我们共同见证总决赛的荣耀时刻。</description>
      <content:encoded><![CDATA[<p><span>安全419</span> <span>2026-04-27 17:30</span> <span style="display: inline-block;">四川</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=57ef2986&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F9Nf1wzzcfwPnTOSNxx3L3cgRkqjfxVK1VCqZKfdiaiasiaXpNjpeVfqfNRO245Sjudyd1MibPpZFsb5XIXoZdjea8WiceznqOBUJhM1JKKO6YFEs%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>4月28日，让我们共同见证总决赛的荣耀时刻。</p>
  <div style="font-size: 15px;letter-spacing: 1px;line-height: 2;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">4月28日，由中央网络安全和信息化委员会办公室、教育部、国家市场监督管理总局、国家数据局指导，中国信息安全测评中心、中国电信集团有限公司、中国移动通信集团有限公司、中国联合网络通信集团有限公司、北京师范大学联合主办的第三届“长城杯”网数智安全大赛（防护赛）总决赛将在福州正式拉开帷幕。</span></p><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069500" src="https://wechat2rss.xlab.app/img-proxy/?k=05ff308c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwPibibDkuLDyd6UhhXLPFia0jry7GPfGArfx5xXjGWrqok5dPQWZ3RV5mBnftTz9sJPHyKt8lMEWerNV0o3ZTohecvNqlvXVbRoTk%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">群英竞逐 巅峰对决</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069499" src="https://wechat2rss.xlab.app/img-proxy/?k=862dd7da&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwP2QViaMebl4NribB5fJqsPTMMEIjia1ktuEoBcvLtcib02tUXTYJgNugYHNiaRlDL0f1JIfvROStyIJIxjzDJvEnvNxOxj8pD0SOdU%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">大赛自2025年12月28日启动初赛，历经2026年3月22日半决赛的激烈比拼，来自清华大学、复旦大学、上海交通大学、浙江大学、哈尔滨工业大学等全国知名高校的150支战队凭借扎实的技术功底与出色的临场表现成功晋级，将在总决赛舞台上演巅峰对决。作为国内高校网络安全领域的顶尖赛事，本届大赛汇聚了新一代网安精锐力量，选手们将在实战对抗中全面展现技术实力与团队风采。</span></p><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069498" src="https://wechat2rss.xlab.app/img-proxy/?k=e33c500f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwNgicnZCPtzlZVTDUSda3l5AL1oXiccKgeXoxy7yz6OsNJC9d8G59HBEnHjLIJaPGFJq9aTicZviboCp1FGeRmLKeiabCphZAdU50Ss%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">实战砺技 赛制革新</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069501" src="https://wechat2rss.xlab.app/img-proxy/?k=549d8abd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwPHs37klfIiaiaL6K1gBa1qSQo4T4sOy3NzrL5oicJ73fSkg5iab8k9LOUCR876DbUklmZg4GmLLR0XZ5e8JJuAZ16WQfzia0IUP2Yk%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">总决赛分为实战场景赛和专项能力赛。其中，实战场景赛部署典型业务应用系统与服务，重点考查参赛队伍在企业仿真环境下渗透测试、代码审计和漏洞利用等能力；专项能力赛采用独立CTF解题模式，重点考查参赛队伍逆向分析、漏洞利用、程序开发、AI安全等攻防技术实践能力。</span></p><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069497" src="https://wechat2rss.xlab.app/img-proxy/?k=fba5149f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwNNe5e316C3TK2oBTOYa5fteApH7LXXayAxw9lF2dypvITI0WrtlAOCMnOpxF9tJicHZC2HXiacHtjibT9hy4f3e3o7TZhED5qLcA%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">荣耀加冕 育才未来</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069503" src="https://wechat2rss.xlab.app/img-proxy/?k=f9cf9c0f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwNq7A7p5B3owOvEWe39jPIDd3nQDVTPLjMbPGa1VQCKjvshGtibOxL12m81SibTCiaia0Xg4icONyAibeGMeMUvEiaia0IHhDNMTyyvxgM%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">总决赛设一、二、三等奖和专项奖，向获奖队伍颁发荣誉证书和奖金。其中，一等奖5支队伍，冠军奖金8万元，亚军奖金7万元，季军奖金6万元，第4名奖金5万元，第5名奖金4万元。二等奖20支队伍，奖金2万元/队。专项奖若干队伍，奖金2万元/队。三等奖若干队伍，奖金5000元/队。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">此外，总决赛一等奖获奖队伍学生将颁发CISP-PTE证书，二等奖和专项奖获奖队伍学生将颁发NISP二级证书，总决赛一、二等奖获奖队伍指导教师将颁发荣誉证书。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069502" src="https://wechat2rss.xlab.app/img-proxy/?k=00892892&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwPh5oictlwNFm1dhkOpHRqrDy0gTzf2uVA3YvrbTN6hvxRMgINmxDkbjnbQTbOm4wag8Y7YnjEs5VZZVXILZiakLpu2ficAF5RRvI%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">数字福州 高光共鉴</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069504" src="https://wechat2rss.xlab.app/img-proxy/?k=e7cd58d1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwOibMRY6C1Y5RiblW5TH0GUnnTX4c63bpibicia5Uky1ht0BqDvFRe926v9ja1Mr1MCKXv9ibh6bHREz0iadWzvtSbm0thvicNhNqUvfE0%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">福州作为数字中国建设的先行之地，始终站在数字化发展的前沿，与新时代网安人才培养的使命高度契合。本届大赛落地于此，既是对选手技术能力的全面检验，也是对创新精神与协作能力的深度淬炼。4月28日，让我们共同聚焦福州赛场，见证第三届“长城杯”网数智安全大赛（防护赛）总决赛的荣耀时刻。</span></p><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="2.0031055900621118" data-s="300,640" data-type="png" data-w="644" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069506" src="https://wechat2rss.xlab.app/img-proxy/?k=59b52264&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwP1MhO0x9vQBdiaf0UhGcLDyeYicdXN14bmwjaejaAIe1EvoPsqOCVp0DtR3TFow3zwofOzQb1Cuh4QM7Fx5icXfmdwS6sSCJSQicM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 10%;max-width: 100%;height: auto;margin: 0px 10px;line-height: 0;padding: 0px;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;background-image: linear-gradient(to right, rgb(245, 245, 245) 50%, rgb(250, 228, 66) 50%);align-self: flex-start;box-sizing: border-box;"><div style="margin: 3px 0%;width: 100%;box-sizing: border-box;"><div style="font-size: 11px;color: rgb(180, 180, 180);line-height: 1;letter-spacing: 0px;padding: 0px 10px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">END</span></p></div></div></div></div></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.459375" data-s="300,640" data-type="gif" data-w="640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069505" src="https://wechat2rss.xlab.app/img-proxy/?k=94362a3b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwMKwQov6PtsQibyR1ESqh2CibzbxdH6Q7yZlicWdmcUNUs5Tn9fJSmVxSK4ES1KCMPicSoctz6t8EwA16I3ZXEynazZWbXmB18eCWY%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="margin: 10px 0%;text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;background-color: rgba(227, 180, 0, 0.04);align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;box-sizing: border-box;"><div data-cacheurl="" data-remoteid="" style="display: inline-block;width: 100%;vertical-align: top;background-repeat: repeat;background-attachment: scroll;padding: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;background-position: 0% 0% !important;background-size: 4.17755% !important;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=bf97bf9f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwPtbiaNlSk1p0DMnNLteqX0ibsaddOicvJ9PzvBZUqDay0q4xicZjbOOmZ42iaEV5na0eFBOvzicdQiaqZoP35CKIbLehVyEIg3eoC7ibY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><div style="display: flex;flex-flow: row;margin: 20px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 30%;flex: 0 0 auto;height: auto;align-self: center;margin: 0px 0px 0px 20px;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="699" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069508" src="https://wechat2rss.xlab.app/img-proxy/?k=641e063f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F9Nf1wzzcfwNMrLFKYloJUv0Ms9vlDUISANF0VKjgZmOlLFHhqYTx3Xh5JbfIegzDiazLfFSdq0VvQQT2G321GWkzLZNOBgGC2rqyFiar1zic5k%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;margin: 0px 0px 0px 10px;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;box-sizing: border-box;"><div style="font-size: 20px;color: rgb(255, 202, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">粉丝福利群开放啦</span></strong></p></div><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(255, 202, 0);font-size: 11px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">加安全419好友进群</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">红包/书籍/礼品等不定期派送</span></p></div></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=4bbfebd9&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDQ4OTkyMg%3D%3D%26mid%3D2247553161%26idx%3D3%26sn%3Da46d614ab299598a486c3b858b3c8c21">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 27 Apr 2026 17:30:00 +0800</pubDate>
    </item>
    <item>
      <title>2026年值得关注的12家Agentic AI安全初创公司</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553127&amp;idx=1&amp;sn=7f7375b99330998096597deb42fb613a</link>
      <description>聚焦AI代理身份治理与安全运营自动化。</description>
      <content:encoded><![CDATA[<p>原创 <span>安全419</span> <span>2026-04-24 17:23</span> <span style="display: inline-block;">四川</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=cbfc2399&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F9Nf1wzzcfwOC2yfW47EVcZ8O2iaVFar8NibAEO4uN6ROUQs1GibOBrula2wicJrVUTjOCG1b9EE92ib52VIWQZsFLKG9WArhkh0sBWJLkd7y5Bm4%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>聚焦AI代理身份治理与安全运营自动化。</p>
  <div style="font-size: 15px;letter-spacing: 1px;line-height: 2;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">虽然科技初创公司的信条历来是快速行动以颠覆不够灵活的玩家，但AI的到来已将典型的初创公司时间表推向了超速状态。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这种动态在安全领域或许体现得最为明显，随着Agentic AI的推动，大量新的网络安全初创公司在极短的时间内涌入市场。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">以下是2026年值得了解的12家agentic AI初创公司。</span></p></div><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.562963" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069424" src="https://wechat2rss.xlab.app/img-proxy/?k=eba118b4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwOcuqhBN5PwY2ZbZmjbO6H3QiaUqab65RBNFIbvIiaDYDWIZibuLO4L5M4RjKsu5xibbk8hib2Ymc4qgHpQNs8QXibCic0bM0fkUibcMYw%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="text-align: center;justify-content: center;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-style: solid;border-width: 1px;border-color: rgb(255, 202, 0);align-self: flex-start;box-sizing: border-box;"><div style="justify-content: center;margin: -3px 0% 3px;transform: translate3d(-3px, 0px, 0px);-webkit-transform: translate3d(-3px, 0px, 0px);-moz-transform: translate3d(-3px, 0px, 0px);-o-transform: translate3d(-3px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(255, 202, 0);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;border-width: 0px;align-self: flex-start;box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 14px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Aembit</span></strong></p></div></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Aembit最近推出了其针对Agentic AI的身份与访问管理产品，旨在实现对AI代理访问策略的强制执行。此举扩展了其Aembit Workload IAM平台，以提供对AI代理能够访问的内容以及访问的条件和问责制的控制。关键能力包括为每个代理提供其自己的、可关联到人类身份的已验证身份，以及用于控制代理如何通过模型上下文协议（MCP）连接的MCP身份网关。</span></p><div style="text-align: center;justify-content: center;margin: -3px 0% 3px;transform: translate3d(-3px, 0px, 0px);-webkit-transform: translate3d(-3px, 0px, 0px);-moz-transform: translate3d(-3px, 0px, 0px);-o-transform: translate3d(-3px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(255, 202, 0);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;border-width: 0px;align-self: flex-start;box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 14px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Aurascape</span></strong></p></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Aurascape最近宣布推出一款新工具，用于解决与模型上下文协议（MCP）相关的巨大agentic安全缺口。该公司表示，新的零绕过MCP网关与Aurascape的AI代理协同工作，能够实现对可信工具使用的治理，并识别与MCP相关的高风险活动。此外，Aurascape的零绕过MCP网关具有在代理交互期间降低绕过风险的能力，为“保护企业购买的AI代理和保护企业构建的AI代理”提供了一个单一平台。</span></p><div style="text-align: center;justify-content: center;margin: -3px 0% 3px;transform: translate3d(-3px, 0px, 0px);-webkit-transform: translate3d(-3px, 0px, 0px);-moz-transform: translate3d(-3px, 0px, 0px);-o-transform: translate3d(-3px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(255, 202, 0);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;border-width: 0px;align-self: flex-start;box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 17px;padding: 0px 14px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Command Zero</span></strong></p></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Command Zero提供了一个agentic驱动的平台，旨在充当安全运营中心（SOC）的操作系统，并为告警分类和调查等关键任务提供自动化，人力驱动的响应无法跟上机器驱动的攻击，通过Command Zero能够对所有告警进行分类和优先级排序的代理，使人类安全分析师能够达到更高的效率和生产力水平。</span></p><div style="text-align: center;justify-content: center;margin: -3px 0% 3px;transform: translate3d(-3px, 0px, 0px);-webkit-transform: translate3d(-3px, 0px, 0px);-moz-transform: translate3d(-3px, 0px, 0px);-o-transform: translate3d(-3px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(255, 202, 0);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;border-width: 0px;align-self: flex-start;box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 17px;padding: 0px 14px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Dropzone AI</span></strong></p></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Dropzone AI提供了一种完全由AI驱动的方法来处理SOC中的告警过载——无需人类分析师即可提供更好的安全结果。据称，Dropzone最大的差异化在于提供了一种“纯软件”的方法来使用其AI SOC分析师平台处理告警。与依赖人类的方法相比，其提供了显著改进的一致性、可扩展性和透明度。</span></p><div style="text-align: center;justify-content: center;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-style: solid;border-width: 1px;border-color: rgb(255, 202, 0);align-self: flex-start;box-sizing: border-box;"><div style="justify-content: center;margin: -3px 0% 3px;transform: translate3d(-3px, 0px, 0px);-webkit-transform: translate3d(-3px, 0px, 0px);-moz-transform: translate3d(-3px, 0px, 0px);-o-transform: translate3d(-3px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(255, 202, 0);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;border-width: 0px;align-self: flex-start;box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 14px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Mondoo</span></strong></p></div></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">今年3月，Mondoo推出了其新的Agentic托管漏洞服务，该服务通过人类专家和agentic能力的结合，提供“完全优化”的漏洞管理程序。据这家初创公司称，该产品分析来自Mondoo平台的数据，并提供漏洞监控和优先级排序以及修复指导和报告。</span></p><div style="text-align: center;justify-content: center;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-style: solid;border-width: 1px;border-color: rgb(255, 202, 0);align-self: flex-start;box-sizing: border-box;"><div style="justify-content: center;margin: -3px 0% 3px;transform: translate3d(-3px, 0px, 0px);-webkit-transform: translate3d(-3px, 0px, 0px);-moz-transform: translate3d(-3px, 0px, 0px);-o-transform: translate3d(-3px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(255, 202, 0);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;border-width: 0px;align-self: flex-start;box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 14px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Nagomi Security</span></strong></p></div></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">今年3月，Nagomi Security推出了所谓的一种新“运营模式”，旨在借助agentic能力取代当前的暴露管理方法。新模式——Agentic Exposure Ops——提供了能够“评估跨漏洞、错误配置、威胁、控制和资产的暴露情况”的AI代理，最终确定哪些漏洞可能构成实际风险。Nagomi表示，该产品还在持续运行，以验证在IT环境变化时修复措施是否仍然有效。</span></p><div style="text-align: center;justify-content: center;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-style: solid;border-width: 1px;border-color: rgb(255, 202, 0);align-self: flex-start;box-sizing: border-box;"><div style="justify-content: center;margin: -3px 0% 3px;transform: translate3d(-3px, 0px, 0px);-webkit-transform: translate3d(-3px, 0px, 0px);-moz-transform: translate3d(-3px, 0px, 0px);-o-transform: translate3d(-3px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(255, 202, 0);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;border-width: 0px;align-self: flex-start;box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 14px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Noma Security</span></strong></p></div></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Noma Security提供了其所谓的“统一”AI代理安全平台，具备持续发现、治理和保护AI及代理的能力。据该公司称，该平台通过自动发现AI应用和代理的构建位置，以及确定它们可以访问哪些数据和系统，提供完整的AI资产清点。Noma表示，其他关键能力包括AI安全态势管理和风险优先级排序，以及AI运行时保护。</span></p><div style="text-align: center;justify-content: center;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-style: solid;border-width: 1px;border-color: rgb(255, 202, 0);align-self: flex-start;box-sizing: border-box;"><div style="justify-content: center;margin: -3px 0% 3px;transform: translate3d(-3px, 0px, 0px);-webkit-transform: translate3d(-3px, 0px, 0px);-moz-transform: translate3d(-3px, 0px, 0px);-o-transform: translate3d(-3px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(255, 202, 0);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;border-width: 0px;align-self: flex-start;box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 14px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Operant AI</span></strong></p></div></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在今年的RSAC大会上，Operant AI发起了一项旨在将AI和代理的安全能力直接嵌入到AI推理基础设施中的计划。这项名为AI基础设施生态系统合作伙伴计划的举措将涉及与顶级AI基础设施公司合作，将Operant针对AI和agentic的运行时防御能力“直接嵌入到推理堆栈中”。</span></p><div style="text-align: center;justify-content: center;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-style: solid;border-width: 1px;border-color: rgb(255, 202, 0);align-self: flex-start;box-sizing: border-box;"><div style="justify-content: center;margin: -3px 0% 3px;transform: translate3d(-3px, 0px, 0px);-webkit-transform: translate3d(-3px, 0px, 0px);-moz-transform: translate3d(-3px, 0px, 0px);-o-transform: translate3d(-3px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(255, 202, 0);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;border-width: 0px;align-self: flex-start;box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 14px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Prophet Security</span></strong></p></div></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">通过其Agentic AI SOC平台，Prophet Security提供了一系列能力，包括通过其Prophet AI SOC分析师进行的自主分类、调查和响应。该平台的主要新增功能包括推出主动威胁狩猎（通过Prophet AI Threat Hunter）以及用于遥测分析和检测调优的Prophet AI检测顾问。今年2月，这家初创公司宣布通过Amex Ventures和Citi Ventures的战略投资筹集了一笔未披露金额的资金。</span></p><div style="text-align: center;justify-content: center;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-style: solid;border-width: 1px;border-color: rgb(255, 202, 0);align-self: flex-start;box-sizing: border-box;"><div style="justify-content: center;margin: -3px 0% 3px;transform: translate3d(-3px, 0px, 0px);-webkit-transform: translate3d(-3px, 0px, 0px);-moz-transform: translate3d(-3px, 0px, 0px);-o-transform: translate3d(-3px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(255, 202, 0);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;border-width: 0px;align-self: flex-start;box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 14px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Sublime Security</span></strong></p></div></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Sublime Security提供了一个用于agentic电子邮件安全的平台，利用AI代理自动化威胁分类并快速为收件箱部署更新的防御措施。该公司的AI代理包括一个自主安全分析师，可提供对电子邮件威胁的自动调查和分类。Sublime Security还提供其自主检测工程师代理，该代理能够“在数小时内提供新的、量身定制的防御措施来应对新型威胁”。</span></p><div style="text-align: center;justify-content: center;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-style: solid;border-width: 1px;border-color: rgb(255, 202, 0);align-self: flex-start;box-sizing: border-box;"><div style="justify-content: center;margin: -3px 0% 3px;transform: translate3d(-3px, 0px, 0px);-webkit-transform: translate3d(-3px, 0px, 0px);-moz-transform: translate3d(-3px, 0px, 0px);-o-transform: translate3d(-3px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(255, 202, 0);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;border-width: 0px;align-self: flex-start;box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 14px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Vorlon</span></strong></p></div></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Vorlon在三月的RSAC大会上扩展了其Agentic生态系统安全平台，推出了两款新产品以增强基于代理的取证和协调响应。这家初创公司表示，新的AI代理飞行记录器利用Vorlon的DataMatrix仿真技术，持续捕获所有代理在应用和系统上操作行为的审计追踪。同时，据该公司称，Vorlon的新AI代理行动中心将优先级发现结果路由给合适的人类工作人员或系统，同时还提供逐步修复指导。</span></p><div style="text-align: center;justify-content: center;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-style: solid;border-width: 1px;border-color: rgb(255, 202, 0);align-self: flex-start;box-sizing: border-box;"><div style="justify-content: center;margin: -3px 0% 3px;transform: translate3d(-3px, 0px, 0px);-webkit-transform: translate3d(-3px, 0px, 0px);-moz-transform: translate3d(-3px, 0px, 0px);-o-transform: translate3d(-3px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(255, 202, 0);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;border-width: 0px;align-self: flex-start;box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 14px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Zafran Security</span></strong></p></div></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在三月的RSAC大会上，Zafran Security通过推出Zafran暴露网关，发布了其新的AI代理安全控制平面。该产品提供了一个集中式界面，允许所有代理获得“丰富的暴露上下文、范围限定的访问权限和可审计的操作路径”。该公司表示，该网关使组织能够在保持安全和治理的同时，使AI代理可投入运营。拥有正确的网关并能够负责任且安全地启用代理非常重要。</span></p><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 10%;max-width: 100%;height: auto;margin: 0px 10px;line-height: 0;padding: 0px;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;background-image: linear-gradient(to right, rgb(245, 245, 245) 50%, rgb(250, 228, 66) 50%);align-self: flex-start;box-sizing: border-box;"><div style="margin: 3px 0%;width: 100%;box-sizing: border-box;"><div style="font-size: 11px;color: rgb(180, 180, 180);line-height: 1;letter-spacing: 0px;padding: 0px 10px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">END</span></p></div></div></div></div></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.459375" data-s="300,640" data-type="gif" data-w="640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069426" src="https://wechat2rss.xlab.app/img-proxy/?k=23929b54&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwPE3O022SBxbz8a0M40wpnLs2UG9BNX3vCMkh4SUnL1B2LRg5pkY3Vb56Fxxhyp7TpZ4TH1jklQNLauBPNw4CPbZwsJEich5ibIU%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="text-align: center;justify-content: center;margin: 10px 0px;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(249, 225, 25);text-align: justify;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">✦</span></p></div></div><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="color: rgb(100, 100, 100);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">推荐阅读</span></strong></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(249, 225, 25);text-align: right;box-sizing: border-box;"><p style="text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">✦</span></p></div></div></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247552906&amp;idx=1&amp;sn=b453f5cab3ff1bb1fb01a96391e9e7a5&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/mmbiz_png/9Nf1wzzcfwM63FLJlafUeWUjNhH7mtUNLibk7kDt0EGoNXte3o7Y0EdTywNCmYnbKTuPjtBSTOoWOLf29UYlmf37Sg0YTF3lYgvUJcresmlI/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1787037" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069422" src="https://wechat2rss.xlab.app/img-proxy/?k=cfe25b61&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwM63FLJlafUeWUjNhH7mtUNLibk7kDt0EGoNXte3o7Y0EdTywNCmYnbKTuPjtBSTOoWOLf29UYlmf37Sg0YTF3lYgvUJcresmlI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553019&amp;idx=1&amp;sn=06effa47b649b25b2aba84045c7195cd&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/mmbiz_png/9Nf1wzzcfwPwErSwHAtNT42MBawuoCHj3hcgM7icsAEr2yc8OxHZCXicxcsx0sVSqRQxVobmXicxwACEpdUz83c8a9Woj76biaP32VPHK0v9E10/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1787037" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069423" src="https://wechat2rss.xlab.app/img-proxy/?k=b49ce99c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwPwErSwHAtNT42MBawuoCHj3hcgM7icsAEr2yc8OxHZCXicxcsx0sVSqRQxVobmXicxwACEpdUz83c8a9Woj76biaP32VPHK0v9E10%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553068&amp;idx=1&amp;sn=769273f61e16e08311cd687dd7262cb4&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/sz_mmbiz_png/9Nf1wzzcfwMeQR15jp26JHn3iaC1qo3M5NNFfd7raicNIbXIK7mIEVzAqiaqgz2MU7MwDxIusu4IPSQiaLCRPsDgLUEbWBVxC5a0iaurhkFXtkH8/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100069425" data-ratio="0.1787037" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=efc2f2a9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwMeQR15jp26JHn3iaC1qo3M5NNFfd7raicNIbXIK7mIEVzAqiaqgz2MU7MwDxIusu4IPSQiaLCRPsDgLUEbWBVxC5a0iaurhkFXtkH8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="margin: 10px 0%;text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;background-color: rgba(227, 180, 0, 0.04);align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;box-sizing: border-box;"><div data-cacheurl="" data-remoteid="" style="display: inline-block;width: 100%;vertical-align: top;background-repeat: repeat;background-attachment: scroll;padding: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;background-position: 0% 0% !important;background-size: 4.17755% !important;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=9d6fe2f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwPn6Ziceca7oibERkdQlOSEbHUheK385ficPloxBDGFvhmMXXRfjiaHY2XpLiaYWDCcJCJm5fVlzrpLwWwjQJ8PR0QsC50XCVnzGN6U%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><div style="display: flex;flex-flow: row;margin: 20px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 30%;flex: 0 0 auto;height: auto;align-self: center;margin: 0px 0px 0px 20px;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="699" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069429" src="https://wechat2rss.xlab.app/img-proxy/?k=6f9507ee&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwMDCDwMC0zoNuH7sp6TfRrKKKymxrvsmDqDDjcFxwSdjn2GI7RcicFhWHWRVxic6AbaFvq5icJ5h4n6DMUX9sH5orpQtlWyBRMOhw%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;margin: 0px 0px 0px 10px;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;box-sizing: border-box;"><div style="font-size: 20px;color: rgb(255, 202, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">粉丝福利群开放啦</span></strong></p></div><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(255, 202, 0);font-size: 11px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">加安全419好友进群</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">红包/书籍/礼品等不定期派送</span></p></div></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=102bfe2d&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDQ4OTkyMg%3D%3D%26mid%3D2247553127%26idx%3D1%26sn%3D7f7375b99330998096597deb42fb613a">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 24 Apr 2026 17:23:00 +0800</pubDate>
    </item>
    <item>
      <title>灵境 AIDR 技术首发 | 以 AI 治理 AI，悬镜智能体安全卫士新品发布</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553127&amp;idx=2&amp;sn=d014604f00ae01e5cc5eddeb39784c01</link>
      <description>智能情报驱动，以AI治理AI。新一代数字供应链安全治理体系再闭环，智能治理“AI 数字员工”！</description>
      <content:encoded><![CDATA[<p><span>灵境 AIDR</span> <span>2026-04-24 17:23</span> <span style="display: inline-block;">四川</span></p>




  <p>以下文章来源于：悬镜安全</p>
  <strong>悬镜安全</strong>
  <p>悬镜安全，作为新一代 AI 数字供应链安全开拓者，首创基于“AI 原生安全&#43; DevSecOps 敏捷安全&#43;多模态SCA&#43;AI 供应链安全情报预警”技术的新一代 AI 数字供应链安全治理体系，持续守护新一代 AI 数字供应链安全。</p>



  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=dab196d9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwMO2iaiaBMZxWdfvx6r3RsTicJZJCXCl81eP1YINtG4UyknXRV8ZGexwc97dPfz8xdEibvabYh2ztcIZQUKCYGnxGPE2Vtaib0zN1aM%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>智能情报驱动，以AI治理AI。新一代数字供应链安全治理体系再闭环，智能治理“AI 数字员工”！</p>
  <div style="font-size: 15px;letter-spacing: 1px;line-height: 2;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5185185185185185" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069473" src="https://wechat2rss.xlab.app/img-proxy/?k=daa3389a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwOqcFJuP3l6PZBJIGgmJF6hjDdYQRTBICn674gVeg6G3AM7fibeMkCT0icrcwg9IzbhctU3jLeSmib8MTChXVoynzIW1mJnMtTSFY%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">随着企业全面进入智能体（Agent）爆发时代，AI 数字员工深度融入业务决策与执行链路，影子 AI 无序蔓延、AI 决策全程黑盒已成为企业 AI 安全治理的核心风险，攻击者借助提示词注入、模型幻觉诱导、工具越权调用等 AI 原生攻击手法，可在 1 小时内精准诱导智能体执行数据库删改、敏感文件泄露、高危指令运行等高危操作，直接引发核心数据篡改、业务流程失控、内部系统被入侵等严重安全后果。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在此背景下，悬镜安全正式推出</span><strong style="box-sizing: border-box;"><span leaf="">灵境 AIDR——智能体安全卫士平台</span></strong><span leaf=""> ，平台以大模型为引擎、全链路自动化为骨架、实战化闭环为目标，重构智能体安全治理全流程，让企业在 AI 威胁时代守住安全底线。</span></p></div><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6944444444444444" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069472" src="https://wechat2rss.xlab.app/img-proxy/?k=3c435250&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F9Nf1wzzcfwPMCezzr9WfQtsVVM9h2zyEYibJibRSkCHicIBxkwMwNfX7C2n3X82Oxegzz4sf6GWNZGwYViaCK7LIXia3sg0AGRtEM7PByVsEKtia4%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="text-align: center;line-height: 1;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">灵境 AIDR 智能体安全治理能力图</span></p></div><div style="display: flex;flex-flow: row;margin: 13px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(255, 228, 128);align-self: flex-start;margin: 0px;line-height: 0;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-width: 0px;border-style: none;border-color: rgb(62, 62, 62);box-sizing: border-box;"><div style="margin: -7px 0% 2px;text-align: center;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.6;padding: 0px 18px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Agentic AI时代，智能体安全治理面临新挑战</span></strong></p></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">安全团队的痛点： 明明已先后建设了从边界防火墙WAF、端点安全EDR到应用免疫RASP等整套塔防体系，为什么会被AI新型攻击降维打击，瞬间击穿？</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">因为 AI 时代的治理逻辑已经彻底改变：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">第一，资产黑盒化与“看不清” ：</span></strong><span leaf="">影子 AI（Shadow AI）泛滥，企业难以梳理内部AI 基础设施（如OpenClaw等智能体、推理框架、编排工具等）的部署情况，以及隐藏在业务代码和配置文件中的外部模型 API 调用、远程模型拉取、本地模型等，密钥与 AI 配置面临泄露风险 。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">第二，情报脱节化与“跟不上”：</span></strong><span leaf="">AI安全事件高频发生，漏洞、投毒等风险层出不穷。企业难以实时将情报关联至动态资产，针对 MCP、Skills 的部署与执行缺乏敏捷检测与实时监控手段，导致防御响应始终滞后于攻击步调。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">第三，行为失控化与“拦不住” ：</span></strong><span leaf="">智能体在通过MCP、Skills 以及 Function Calling 调用外部工具时，可能因提示词注入、权限管控不足、模型幻觉等原因执行高危指令，导致敏感文件、敏感数据库被非法篡改或泄露。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">第四，过程黑箱化与“不可溯” ：</span></strong><span leaf="">在智能体ReAct（推理和行动，Reasoning and Acting） 多步任务循环（Agent Loop）中，智能体为何做出错误决策？推理耗时过长？Token 消耗异常等。传统工具无法还原单个任务的完整链路，导致风险定位难、闭环难 。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">当防御速度跟不上 AI 的进化速度，传统“先发现、后研判、再被动修复”的静态模式已彻底失效。在数字员工深度接入生产力的今天，唯有通过 AI 原生能力重构“监测-预警-阻断-溯源”的行为闭环，才能拨开灵境迷雾，守住智能时代的防御红线。</span></p></div><div style="display: flex;flex-flow: row;margin: 13px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(255, 228, 128);align-self: flex-start;margin: 0px;line-height: 0;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-width: 0px;border-style: none;border-color: rgb(62, 62, 62);box-sizing: border-box;"><div style="margin: -7px 0% 2px;text-align: center;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.6;padding: 0px 18px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">安全情报驱动，以AI治理AI 智能守护AI数字员工</span></strong></p></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">灵境 AIDR 紧扣企业 AI 数字员工的实战场景，通过 </span><strong style="box-sizing: border-box;"><span leaf="">AI 安全情报驱动智能检测</span></strong><span leaf="">，实现“以 AI 治理 AI”的闭环。它将全域发现、动态验证、自适应安全护栏与链路追踪深度融合，为数字化生产力构建智能防御屏障，确保企业在享受 AI 红利的同时，稳守安全与合规底线。</span></p><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5944444444444444" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069471" src="https://wechat2rss.xlab.app/img-proxy/?k=534b01d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F9Nf1wzzcfwNuJDeicvicNxALEWuMMa3dGK9WtoYArA4ALYQfE3vEWiaxqPvEicWo7TW4hnfplRRo6pr9WLUDLOeH7lZjdbZMC1picic18MSFjpJOY%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="text-align: center;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">灵境 AIDR 产品架构图</span></p></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">核心能力一：【可见】智能体全域发现与 AI-BOM 治理</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">灵境 AIDR 构建全栈式智能探测体系，从源头将 AI 资产发现质量做到极致。平台通过主机扫描与多模态 HTTP 网络指纹嗅探等方式，实现代码层、应用层、容器层、主机层、网络层全域 AI 资产测绘。并联动悬镜云脉 AI 供应链安全情报预警，实现高危风险入口的实时预警：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">全域覆盖：</span></strong><span leaf="">代码、应用、容器、主机、网络五层 AI 资产测绘与深度扫描 。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">精准识别：</span></strong><span leaf="">覆盖模型风险、不安全配置、密钥泄露、工具投毒等多类类 AI 安全风险 。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">强力检出：</span></strong><span leaf="">针对 AI 混淆代码、碎片化漏洞及 0day/1day 风险，产品具备行业领先的强检出能力 。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">实时预警：</span></strong><span leaf="">依托悬镜云脉 XSBOM AI供应链风险情报库、资产特征库、模型元数据库实现三库联动，实现高危入口秒级预警 。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">配置审计：</span></strong><span leaf="">深度扫描 OpenClaw、Hermes Agent、Dify、n8n、Ollama 等智能体/编排运行框架的配置文件与环境变量，预防密钥泄露与不安全的配置带上生产环境。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">业务价值：</span></strong><span leaf="">消除影子 AI 资产盲区，将检测输出转化为可治理的 AI-BOM，从源头减少无效告警，为智能体安全响应筑牢基础 。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">核心能力二：【可管】AI 资产分析管控与合规基线核查</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">灵境 AIDR 在全域资产盘点与 AI-BOM 的基础上，构建了覆盖模型、智能体、MCP、Skills、密钥与配置的统一管理体系，把“专家经验”沉淀为“系统策略”。平台依托 AI 风险研判与策略检查引擎，进行资产智能分类分级：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">多维自动分级：</span></strong><span leaf="">基于风险程度、业务价值、暴露面、利用难度多维度加权，实现 AI 风险的自动标准化分级。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">一键输出指引：</span></strong><span leaf="">一键式呈现风险影响范围、触发条件及验证指引，大幅降低技术门槛。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">智能红队验证：</span></strong><span leaf="">内置模型风险评估与 MCP、Skills 安全扫描，支持越狱、Prompt 注入、有害内容、隐私泄漏等多维度模拟攻击，内置 TC-260 兼容测试集，自动生成模型风险评估报告。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">研判时效跃升：</span></strong><span leaf="">通过 AI 自动化研判，将响应时间从 小时级极压缩至分钟级。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">异常行为监测：</span></strong><span leaf="">智能分析风险预警，捕获Token 消耗激增、高频提示词注入触发、工作流死锁等异常指标。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">业务价值：</span></strong><span leaf="">显著降低人工研判消耗，让安全团队直接聚焦于高危行为的处置与响应，而非陷入海量的告警数据分析。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">核心能力三：【可控】响应闭环，一键处置、风险不过夜</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">依托全链路智能编排与安全护栏能力，灵境 AIDR 打通了从风险监测到响应处置的“最后一公里”，真正实现秒级阻断与自动闭环 。平台针对智能体异常行为提供多级响应动作，并支持与企业现有 SOC 平台无缝联动，实现全流程无人值守的“发现即处置、处置即闭环” ：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">多级响应动作：</span></strong><span leaf="">提供告警、脱敏、替换回复、拦截、配置加固等多级动作，支持“模拟拦截”观察模式，便于策略上线前充分验证。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">高危行为即时阻断：</span></strong><span leaf="">针对 AI智能体的工具调用层，实时拦截数据库 DROP/DELETE、系统敏感文件读写及高危命令的执行 。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">工具调用审计与管控：</span></strong><span leaf="">对 MCP、Skills 及 Function Calling 调用进行严格管控，通过工具/命令黑白名单机制实现分钟级加固 。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">无缝流程适配：</span></strong><span leaf="">通过集成管理与企业现有 SIEM/SOARd 等安全运营平台对接告警，支撑高频风险场景下的自动修复与自动验证，大幅缩短 MTTR。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">业务价值：</span></strong><strong style="box-sizing: border-box;"><span leaf="">将响应与修复周期从天/小时级极压缩至分钟/秒级</span></strong><span leaf="">，在攻防对抗的关键窗口期内，确保智能体行为始终处于安全边界之内。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">核心能力四：【可溯】实战化合规运营，可度量、可优化</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">围绕“决策透明化”设计的全流程溯源能力，让安全效果透明可视，合规要求精准落地。灵境 AIDR 系统内置完整的任务执行链路追踪与审计日志能力，实现风险行为的全过程可追溯，满足等保、关基、数据安全法等监管要求，并支持报告一键导出：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">全流程执行溯源：</span></strong><span leaf="">贯通工单流与审计日志，实现智能体模型调用、工具调用的全链路可追溯。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">决策深度还原回放：</span></strong><span leaf="">支持多步工作流与 Agent Loop 动态回放，还原 Prompt 片段与 Context 上下文内，让决策逻辑可解释、可复盘。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">实战合规报告：</span></strong><span leaf="">满足等保、关基、数据安全法等合规审计要求，支持红队验证与风险评估报告一键导出。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">效能与成本可视：</span></strong><span leaf="">通过可视化仪表盘呈现风险分布、响应时效及 Token 消耗成本，以数据驱动安全效能持续改进。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">业务价值：兼顾实战防御与合规底线，大幅降低“溯源取证”与“合规核查”的工作量。</span></strong><span leaf="">让安全投入不仅可度量，更具备支撑业务决策的数据透明度。</span></p></div><div style="display: flex;flex-flow: row;margin: 13px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(255, 228, 128);align-self: flex-start;margin: 0px;line-height: 0;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-width: 0px;border-style: none;border-color: rgb(62, 62, 62);box-sizing: border-box;"><div style="margin: -7px 0% 2px;text-align: center;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.6;padding: 0px 18px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">多模态 AIDR 智能体防御到AI原生安全治理</span></strong></p></div></div></div></div><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6944444444444444" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069469" src="https://wechat2rss.xlab.app/img-proxy/?k=5c952272&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwOgO9KDTBc7sPtFblicWSTndJt5Qrf5uu5EOXhpWJxBzWtjdRqiaOCTQWHyHEGzlnvKgWaR9HbDQ0E4cb0odaWeVYFkDsNlaJKFQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="text-align: center;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">灵境 AIDR 产品价值图</span></p></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">灵境 AIDR 适用场景</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">影子 AI 资产治理与合规扫描：</span></strong><span leaf="">通过主机 Agent 与 HTTP 多模网络指纹嗅探扫描，快速发现私自部署的 OpenClaw、Dify、n8n 等工具 ，自动识别环境变量中的密钥泄露与配置风险 。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">智能体高危行为实时阻断：</span></strong><span leaf="">在数字员工调用 Function Calling 时 ，实时拦截针对底层的数据库 DROP/DELETE、敏感文件读写及高危命令执行 ，守护核心数据安全。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">AI 决策黑盒审计与溯源：</span></strong><span leaf="">针对智能体任务偏移场景，通过多步工作流与 Agent Loop 回放 ，还原 Prompt 片段与 Context 上下文内容 ，实现决策逻辑的可解释性。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">模型风险红队验证：</span></strong><span leaf="">在模型上线前进行主动风险评估与工具合规分析，通过模拟粤语、提示词注入等攻击场景，生成专业的自评估报告 。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">AI 业务成本与效能审计：</span></strong><span leaf="">实时监测 Token 消耗成本与推理性能，通过可视化仪表盘呈现 AI 资产的安全分布与响应时效 。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">灵境 AIDR适用人群</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">安全负责人：</span></strong><span leaf="">构建全自动的 AI 资产防御体系，通过 AI-BOM 摸清家底，从源头降低影子 AI 带来的合规风险与数据泄露压力。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">安全运营工程师：</span></strong><span leaf="">利用 AI 自动化研判替代人工重复劳动，从海量告警中聚焦真正的高危提示词注入与异常行为。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">AI 研发与业务团队：</span></strong><span leaf="">无需深厚的安全背景，即可通过智能护栏实现工具调用的合规管控 ，并借助链路回放快速定位智能体逻辑错误。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">敏捷安全运营团队：</span></strong><span leaf="">通过情报订阅与检索能力，快速补齐针对 0day/1day 风险的闭环处置能力，实现顶级红队验证能力的模块化、低门槛落地 。</span></p></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: stretch;flex: 0 0 auto;background-image: linear-gradient(rgb(255, 214, 125) 10%, rgba(255, 214, 125, 0) 100%);min-width: 5%;max-width: 100%;height: auto;padding: 3px 15px 13px;box-sizing: border-box;"><div style="text-align: justify;font-size: 17px;letter-spacing: 2px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">结语：</span></strong></p></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在 AI 重塑攻防格局的今天，智能体治理的核心不再是“发现多少”，而是“受控多少”与“透明多少”。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">灵境 AIDR 以 AI 原生能力，破解 AI 资产盲区、行为失控、决策黑盒、合规脱节四大行业难题，实现从全域发现、智能研判、自动阻断到执行溯源的完整闭环。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻以守本，唯快不破。悬镜安全始终以技术驱动实战化安全，通过对智能体行为的深度洞察与精准定力，助力企业在智能对抗时代构建更可见、更安全、更可追溯的 AI 数字员工治理体系。</span></p></div><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">扫码立即体验</span></strong></p></div><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069470" src="https://wechat2rss.xlab.app/img-proxy/?k=6b9c68c4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwPeibtNJhnCEDxFz7U4ibUQcqPUj1Fc2KtlEkZZp3Jt4tXJgYEYmOKdEYzWq7usxLoJ7uzibFz4RGQJrJeCBnsOUicpKTPDiccCFc9k%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 10%;max-width: 100%;height: auto;margin: 0px 10px;line-height: 0;padding: 0px;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;background-image: linear-gradient(to right, rgb(245, 245, 245) 50%, rgb(250, 228, 66) 50%);align-self: flex-start;box-sizing: border-box;"><div style="margin: 3px 0%;width: 100%;box-sizing: border-box;"><div style="font-size: 11px;color: rgb(180, 180, 180);line-height: 1;letter-spacing: 0px;padding: 0px 10px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">END</span></p></div></div></div></div></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.459375" data-s="300,640" data-type="gif" data-w="640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069477" src="https://wechat2rss.xlab.app/img-proxy/?k=110c6d0c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwOzI0aMmCyfI7vvbwB8l3Nmao0AyEOX221YwU6nrD0th1p3CmyrHhQsubGDBJf7vO7KiaurbWSA0LNdJJ9MC9y0oWuicOIa57T8k%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="margin: 10px 0%;text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;background-color: rgba(227, 180, 0, 0.04);align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;box-sizing: border-box;"><div data-cacheurl="" data-remoteid="" style="display: inline-block;width: 100%;vertical-align: top;background-repeat: repeat;background-attachment: scroll;padding: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;background-position: 0% 0% !important;background-size: 4.17755% !important;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=da9d1780&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwPO8sdwicibFCo4NgWa0dOKgMpQ3HeCFtWTN6cU2FLlGUXEOic9dr9Qo465GO4UAZR60qbyy2d2aCw2lUXicZiaUJpwicWHTvkpDtuxA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><div style="display: flex;flex-flow: row;margin: 20px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 30%;flex: 0 0 auto;height: auto;align-self: center;margin: 0px 0px 0px 20px;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="699" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069476" src="https://wechat2rss.xlab.app/img-proxy/?k=2fe1aa66&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F9Nf1wzzcfwOE364wBr8a3G271n8O2Libfqz9MQfibqWXHRhWyslibRxXOyksMzNIGHicXr9LgmYIHvicOfyd69trSET1c8uicf8HsTkzicxxK4RrKw%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;margin: 0px 0px 0px 10px;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;box-sizing: border-box;"><div style="font-size: 20px;color: rgb(255, 202, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">粉丝福利群开放啦</span></strong></p></div><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(255, 202, 0);font-size: 11px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">加安全419好友进群</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">红包/书籍/礼品等不定期派送</span></p></div></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=73ee6ecd&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDQ4OTkyMg%3D%3D%26mid%3D2247553127%26idx%3D2%26sn%3Dd014604f00ae01e5cc5eddeb39784c01">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 24 Apr 2026 17:23:00 +0800</pubDate>
    </item>
    <item>
      <title>国家人工智能安全漏洞库启动运行</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553127&amp;idx=3&amp;sn=5545eb9e60ed65aa165fc1b427302925</link>
      <description>未来国家人工智能安全漏洞库将发挥资源汇聚优势，与社会各界紧密协作、携手共进，合力推动人工智能产业健康有序发展，护航数字中国和网络强国建设，共同构建网络空间命运共同体。</description>
      <content:encoded><![CDATA[<p><span>安全419</span> <span>2026-04-24 17:23</span> <span style="display: inline-block;">四川</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=9734635a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwMAmib72RFibXWTh0wbGfdIoPNkqaicvGyY4RN3H8gLPog7tL7JgAroicB1weEAqKZtYk40uUglNmqw6oiad4h0wLqVXLDcOEGu3xjY%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>未来国家人工智能安全漏洞库将发挥资源汇聚优势，与社会各界紧密协作、携手共进，合力推动人工智能产业健康有序发展，护航数字中国和网络强国建设，共同构建网络空间命运共同体。</p>
  <div style="font-size: 15px;letter-spacing: 1px;line-height: 2;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026年4月23日，国家信息安全漏洞库（CNNVD）在北京举办“国家人工智能安全漏洞库启动运行”发布会。中国工程院吴世忠院士出席并致辞，来自关键基础设施单位、科研院校、人工智能企业、网络安全企业、知名白帽子等200余名嘉宾参加会议，共同见证“国家人工智能安全漏洞库”的启动运行。国家管网集团、北京航空航天大学、华为技术有限公司、北京百度网讯科技有限公司、北京智谱华章科技股份有限公司、北京启明星辰信息安全技术有限公司、知名白帽子代表发表主题演讲，国家信息安全漏洞库负责人任望，对国家人工智能安全漏洞库运行机制与流程进行了介绍，并宣布将筹建人工智能漏洞联盟。</span></p><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6685185185185185" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069448" src="https://wechat2rss.xlab.app/img-proxy/?k=3e15bab0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwPYoY207PPotQ4UCQ5dVqvjVXaPpxe50JV7V26uj4OEdcdgNj4XWgaqBM5UnUiaCUCT6KSoe2osxaCqTiaHAuxBfMZn1CRKlYoHY%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="text-align: center;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">国家人工智能安全漏洞库启动仪式</span></p></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">吴世忠院士首先对“国家人工智能安全漏洞库”成立表示祝贺，并结合长期研究与观察分享了三点体会，一是人工智能的健康发展必须始终坚持统筹发展与安全，以高水平安全保障高质量创新发展；二是人工智能安全漏洞管理必须始终坚持与时俱进，主动应对人工智能带来的全新挑战；三是人工智能安全漏洞治理必须始终坚持开拓创新，不断探索适应新形势的治理路径。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">吴世忠院士充分肯定了国家信息安全漏洞库近二十年来的建设成效，并指出新建国家人工智能安全漏洞库是回应智能化时代安全命题的重大战略举措。面对AI技术带来的漏洞治理新挑战，吴世忠院士提出了四点建议：一是优化组织机制，构建跨域协同的治理合力；二是创新技术体系，发展以模治模的管理手段；三是制定标准规范，引领科学严谨的评估实践；四是推动国际合作，探索开放包容的治理模式。</span></p></div><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6777777777777778" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069449" src="https://wechat2rss.xlab.app/img-proxy/?k=a897848f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwNStcibA7f5o00nWV1dLlUF5n58z02xEaLArv1KZiaAXaTuBgNMG61zQVBiaoiaT8U5nyKvD2vK74HTGwKU8mMGLGTZbRFwzGT4UL0%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="text-align: center;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">中国工程院院士 吴世忠</span></p></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">国家管网集团网络安全总监王学力，发表 “锚定AI安全底线，践行央企使命，护航国家管网数字化转型高质量发展” 的演讲。</span></p><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6675925925925926" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069446" src="https://wechat2rss.xlab.app/img-proxy/?k=abcd04e7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F9Nf1wzzcfwNpU4QicPhJoZXDwyxmibnawbLjVLZlSHYUvjEJibCa9Cpk4WXYVF2CL8CAs99U1WV9aeVeCQMUMMYplc4M7WT6DXZIWI1MdOkWCw%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="text-align: center;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">国家管网集团网络安全总监 王学力</span></p></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">北京航空航天大学网络空间安全学院副院长彭浩，发表 “北航网安学院人工智能漏洞挖掘经验分享”的演讲。</span></p><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6666666666666666" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069447" src="https://wechat2rss.xlab.app/img-proxy/?k=bc0fb044&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F9Nf1wzzcfwNyhytpVjPibJX01ruw9VlibQBJibYTmdbd08c51TzxoUiaYzzjWBaGgs0YQvZbKxia3jVnvOXu56UbOmdlPdq9WhHv50Wl84qxvjrI%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="text-align: center;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">北京航空航天大学网络空间安全学院副院长 彭浩</span></p></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">华为技术有限公司中国区首席网络安全与隐私保护官李加赞，发表 “筑牢AI安全底座，共建国家AI漏洞库”的演讲。</span></p><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6666666666666666" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069450" src="https://wechat2rss.xlab.app/img-proxy/?k=7dbf0f7d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F9Nf1wzzcfwOsM3hzxspG4VygdAxg0UqwhzSpR44nCEXticGJ8ZaFoMib1slxPJNkHzS93Hv99ljMFqgz9c4ibibXmiaNibTLLu0WMHJ73nmiabp3Ig%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="text-align: center;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">华为技术有限公司中国区首席网络安全与隐私保护官 李加赞</span></p></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">北京百度网讯科技有限公司百度安全副总裁顾孔希，发表 “范式重构：AI时代漏洞治理的变与不变”的演讲。</span></p><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6666666666666666" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069451" src="https://wechat2rss.xlab.app/img-proxy/?k=5012f7eb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwM4ibU6yl6tYxHfbbYA2b0ibTMnsCHic9FyLIDFjSOO5mjbKGfTkKJqiaA6h2qtmuOh3HbVR6bXlpy16eJ6ZahvKJD58a4DicUwv4Ts%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="text-align: center;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">北京百度网讯科技有限公司百度安全副总裁 顾孔希</span></p></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">北京智谱华章科技股份有限公司副总裁冯小平，发表 “在Z-Day到来之前”的演讲。</span></p><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6666666666666666" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069453" src="https://wechat2rss.xlab.app/img-proxy/?k=454476ee&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F9Nf1wzzcfwOpgsnbB0CKMwsuZDFgGgjAYH6hmScdS7Gic4e92blLrl16nxqM41CwBXaIFtaWgoLJ2oSG4wZdiaiaDy05SL85KpMVP3S9yGibss0%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="text-align: center;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">北京智谱华章科技股份有限公司副总裁 冯小平</span></p></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">北京启明星辰信息安全技术有限公司董事长袁捷，发表 “共筑AI安全基座，护航智能时代发展”的演讲。</span></p><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6666666666666666" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069455" src="https://wechat2rss.xlab.app/img-proxy/?k=b8775a8b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F9Nf1wzzcfwNSXN9dnhfckCRoIlRO85pgJslf6s59ASrU5AGGE66Yp4d5Ont2CevjsLLBWt0sBIZalt6op8Rwfv6oVicibW4kyS0szJtk8S98A%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="text-align: center;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">北京启明星辰信息安全技术有限公司董事长 袁捷</span></p></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">国家信息安全漏洞库特约专家、漏洞技术研究联盟理事长、深圳安络科技公司董事长谢朝霞，发表 “人工智能的漏洞密码”的演讲。</span></p><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6666666666666666" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069454" src="https://wechat2rss.xlab.app/img-proxy/?k=a73bd49b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwOYnDYibFGKI733gKbzIYIh6E9gicY9Fqg0zJNJf8UiafjI3KbDMEJ2jrgRwD99FC4RicPgXiaATnibhOFSu6zTNNibicufC6F49TO2w1g%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="text-align: center;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">国家信息安全漏洞库特约专家 谢朝霞</span></p></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">国家信息安全漏洞库负责人任望，对国家人工智能安全漏洞库机制与流程进行介绍，并宣布将筹建AI漏洞联盟。</span></p><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6666666666666666" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069452" src="https://wechat2rss.xlab.app/img-proxy/?k=00d2ba1b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwMxkIJmB2OMCDgwQ9Cth2eKtqOOHJGibZiaeoIwYeXH88OeiaNGsDuZxOgVbmnREESru4p2X8uB8BnibvRaYgiaOsTaFhoSFflWWicTQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="text-align: center;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">国家信息安全漏洞库负责人 任望</span></p></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">国家人工智能安全漏洞库启动运行，是贯彻落实《全球人工智能治理倡议》中提出的“坚持以人为本、智能向善”的务实有力行动。未来国家人工智能安全漏洞库将发挥资源汇聚优势，与社会各界紧密协作、携手共进，合力推动人工智能产业健康有序发展，护航数字中国和网络强国建设，共同构建网络空间命运共同体。</span></p><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 10%;max-width: 100%;height: auto;margin: 0px 10px;line-height: 0;padding: 0px;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;background-image: linear-gradient(to right, rgb(245, 245, 245) 50%, rgb(250, 228, 66) 50%);align-self: flex-start;box-sizing: border-box;"><div style="margin: 3px 0%;width: 100%;box-sizing: border-box;"><div style="font-size: 11px;color: rgb(180, 180, 180);line-height: 1;letter-spacing: 0px;padding: 0px 10px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">END</span></p></div></div></div></div></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.459375" data-s="300,640" data-type="gif" data-w="640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069458" src="https://wechat2rss.xlab.app/img-proxy/?k=79fc9527&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwN9vdT3woK25wUjVrthOHiag1JuViagm2PHhlYf9nfR4jRZMRxvb9HJeQBXycIia3TTOXb7bE0qqeicATCK2NgK1qP5Mia1fomIx1qA%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="margin: 10px 0%;text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;background-color: rgba(227, 180, 0, 0.04);align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;box-sizing: border-box;"><div data-cacheurl="" data-remoteid="" style="display: inline-block;width: 100%;vertical-align: top;background-repeat: repeat;background-attachment: scroll;padding: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;background-position: 0% 0% !important;background-size: 4.17755% !important;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=a93c882d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwOPADjibBGEJg1iaf2fuPX2OeEV88vdt6Bg7NsyLibG1FTMGLv3yNGpbqojYEsKmkqICfxLmxceGsjyCFyR4dQC8IViaQ6XCL0qTtg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><div style="display: flex;flex-flow: row;margin: 20px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 30%;flex: 0 0 auto;height: auto;align-self: center;margin: 0px 0px 0px 20px;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="699" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069457" src="https://wechat2rss.xlab.app/img-proxy/?k=ccadbad9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwO5ANDHeHhERxSltqPibs8AmEWgZhDEmDzB1MZv4vjfbmSmbyIibOsSIf8icwcbGGYXLwHnSWIV5FhjMtq5M7GeLDUZ6Ap1RARzFs%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;margin: 0px 0px 0px 10px;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;box-sizing: border-box;"><div style="font-size: 20px;color: rgb(255, 202, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">粉丝福利群开放啦</span></strong></p></div><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(255, 202, 0);font-size: 11px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">加安全419好友进群</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">红包/书籍/礼品等不定期派送</span></p></div></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=3e0b2ae5&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDQ4OTkyMg%3D%3D%26mid%3D2247553127%26idx%3D3%26sn%3D5545eb9e60ed65aa165fc1b427302925">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 24 Apr 2026 17:23:00 +0800</pubDate>
    </item>
    <item>
      <title>安全419｜一周国际网安资讯：AI写漏洞 古典漏洞重燃</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553069&amp;idx=1&amp;sn=4f36887e769ae2f6329b6252ae7cc0d0</link>
      <description>Claude低成本编写Chrome漏洞，13年ActiveMQ、17年Excel漏洞被重新利用，国际执法捣毁DDoS租用平台。</description>
      <content:encoded><![CDATA[<p>原创 <span>安全419</span> <span>2026-04-23 11:49</span> <span style="display: inline-block;">四川</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1ea284c8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F9Nf1wzzcfwNJNTpeSvibKpwwh30ibR3xibibkFHasiafTEY8Sic26iahqSh9KL6libzDFbppyAg0G40ohl6icYicLoNOHWQCNq9P6YqziaDV7hRYatgYOo%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>Claude低成本编写Chrome漏洞，13年ActiveMQ、17年Excel漏洞被重新利用，国际执法捣毁DDoS租用平台。</p>
  <div style="font-size: 15px;letter-spacing: 1px;line-height: 2;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100069385" data-ratio="0.5555555555555556" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="720" src="https://wechat2rss.xlab.app/img-proxy/?k=d2a658fc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwOV8Htq7VnU4QicSDjAU2g8vObVxyw9r1wOJKYbWPpHNib8bVaWrpqtiaChgCEgztk7PHnXj1YCvr0zGu3OHhBrjuJ8HzDEnqnTA0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069384" src="https://wechat2rss.xlab.app/img-proxy/?k=b6697601&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwMMm7BcPhVPBbWR3ZZx8Ec2arPqN5uEicZdBFkMSia0anoGACDSyjN3Pl339uHgUu9R16aWa3PicGOsFaWiaLehLVc4BXms2rFXiamk%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">本周热点速览</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069383" src="https://wechat2rss.xlab.app/img-proxy/?k=49970f0c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwMTiaIMkZLoibhd8FX1zkic7o2aQ4eW5Imnr4hTleVd9uibOh7ApnkKNB1KZGSGbO8BypNJiamnibg4GLRqtWgRgsiclm80b9apYRURls%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">本周网络安全领域呈现多重挑战：AI安全持续成为焦点，多个古典漏洞被重新利用，关键基础设施面临威胁，执法行动取得重大成果。以下为本周主要资讯汇总。</span></p><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069386" src="https://wechat2rss.xlab.app/img-proxy/?k=595245c8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwOogAF7TS6pSlGMSFfJiaohVKLD3JvroFsOgRicPJnwlIs9HWoszudibUZITLicrdgtaCqDmVwch4TicqaJpHsvomdiagsjDrnibwjbvw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">一、AI安全与工具</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069387" src="https://wechat2rss.xlab.app/img-proxy/?k=1418e58e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwOc2xvSEfDVT9UFEaia6cCibzTYlibV9qliaeo3EG65bUB8METjIA5yG4BfLyrLy6o0f53C4yvHKzbkE8T2ref3Zuhe0RkuibSW6AiaU%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Claude Opus仅2283美元编写Chrome漏洞利用</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">安全研究人员发现Claude Opus模型可以低成本编写Chrome漏洞利用代码，主流AI模型已能发现流行软件漏洞，引发对AI安全能力的重新评估。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">GitHub AI代理可被劫持窃取凭证</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">研究人员发现集成到GitHub的AI代理存在被劫持风险，Anthropic、Google和Microsoft尚未发出用户警告，凸显AI工具安全标准缺失。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Git身份欺骗愚弄Claude批准恶意代码</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者伪造Git元数据欺骗Claude将恶意代码变更视为可信维护者，暴露AI代码审查工具身份验证弱点。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">OpenAI发布GPT-5.4-Cyber强化网络安全</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">OpenAI推出网络安全专用模型帮助防御者分析恶意软件，AI公司在安全领域的竞争加剧。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069388" src="https://wechat2rss.xlab.app/img-proxy/?k=2b1550c9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwNicVKE2QIx3sOOkFUEAubRHYLHWnDhIbiaibBnnSPl2SZsAUpC652iavKia5ZZHHwyvbul8e6TwofCXsibhIoa1Fze7XNFgLM5TW9e4%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">二、漏洞与补丁</span></b></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069389" src="https://wechat2rss.xlab.app/img-proxy/?k=c31cd432&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwMNn26FYUkbnIa1Kzs0ZsdRICSbKnFfb7a6MC3HB4eP3Qg3oibfqR9T80QTlgkPouZnU8owN7fqIzictp17uva2aqry4XJ7E4TlQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">13年旧Apache ActiveMQ漏洞正被利用</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CISA要求联邦机构修补已被积极利用的Apache ActiveMQ RCE漏洞，该漏洞已列入KEV清单，凸显古典漏洞的持续威胁。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">17年旧Excel漏洞复出用于攻击</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">存在17年之久的Excel漏洞被重新启用用于主动攻击，已加入CISA已知利用漏洞目录。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">思科修补Webex和ISE关键漏洞</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">思科发布补丁修复多个关键漏洞，ISE漏洞被利用可给攻击者提供完全控制权。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Nginx-ui MCP漏洞正被积极利用</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Nginx-ui MCP缺少身份验证漏洞允许攻击者接管服务器，已被积极利用。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069390" src="https://wechat2rss.xlab.app/img-proxy/?k=e52c0bf5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwNHlRicxZsQ9xUXLXQhqJO11sOl69Pmpb9zibBOVA9pNuZlbUmRPLCbhoIcjkicLzlJmD3A6EXYciaITzKR2Q9yrPYgOncBhn3TCP4%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">三、勒索软件与恶意软件</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069391" src="https://wechat2rss.xlab.app/img-proxy/?k=523c8852&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwNtqU49yKUHIRf9DQfIwq6Nib2nuYoKIVTR1XBuyOecoicNEVl9cLbU9RvcovAibhnAaWehdzzzbt7D30I3D0eHUVZQpSWKibgoePE%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Mirai变体Nexcorium劫持DVR设备</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">新型Mirai变体Nexcorium利用CVE-2024-3721漏洞劫持TBK DVR发动DDoS攻击，物联网设备因缺乏补丁成为主要目标。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">四款新型Android恶意软件针对800款应用</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Zimperium发现RecruitRat、SaferRat、Astrinox和Massiv四款Android恶意软件，针对超过800款应用窃取敏感数据。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">ZionSiphon针对以色列水系统</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Darktrace发现ZionSiphon恶意软件针对以色列水处理厂的OT系统，关键基础设施安全面临新威胁。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">ShowDoc 2020年漏洞正被利用</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">5年前修补的ShowDoc漏洞(CVE-2025-0520)正被用于主动服务器接管，全球服务器受影响。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069392" src="https://wechat2rss.xlab.app/img-proxy/?k=7bfca574&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwM1uFIfzTSNBic0TtluvX4ZxzTB81PJGdibicWesb2xqEMF68czZ4RKwaDOpHZiaj7dO6LvuMJQ29gicGpQ4lDDnJf4F7cyYyMB9eNY%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">四、供应链与数据泄露</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069395" src="https://wechat2rss.xlab.app/img-proxy/?k=589ef56a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwOpdXqSoA77BOibp5h3TibhqwESgMW2QTSicB9VjEAQA4lsn7p4dsgvJzgAu3WSE61X2gcag68rgibWNTkUSByMGXUVs4B1O8iaSzck%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Booking.com警告预订数据可能泄露</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">旅游巨头Booking.com警告用户预订数据可能已泄露，包括姓名、联系方式和入住日期。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Basic-Fit百万会员数据被盗</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">欧洲健身房巨头Basic-Fit确认约100万会员数据被盗，包括姓名、地址和银行信息。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Fiverr配置错误致用户文件暴露</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Fiverr存储配置错误导致用户税务记录和身份证暴露于Google搜索，隐私保护受质疑。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069396" src="https://wechat2rss.xlab.app/img-proxy/?k=c2db5101&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwMdicYXovF7FBocDGvLGFKGHmSfnFwXXwSnpakmUdv3U4ibnFbNtiaial2L5MHu1CQmBdWWbM3FsUyicBlaOXNm8ecwnibWyicOsNcv5Q%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">五、执法与行动</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069397" src="https://wechat2rss.xlab.app/img-proxy/?k=115438ce&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwPKmpkuqucqn3fmFqibF12icxtCRXg4UsEKbibq8FjZON93sO15KD3oTJjwuznMSPGIw99LFEzxnNJoX0nibOM8qndseaMib9vHLkvk%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Operation PowerOFF捣毁DDoS租用平台</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">国际执法行动捣毁53个DDoS租用域名，逮捕4人，识别7.5万犯罪用户账户。21个国家参与Europol主导行动。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">朝鲜黑客针对macOS用户</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">朝鲜黑客组织针对macOS用户发起新一轮社会工程攻击，通过虚假工作机会和投资诱饵窃取加密货币。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">荷兰军舰位置被蓝牙追踪器暴露</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">荷兰海军护卫舰收到仅5欧元的蓝牙追踪器后位置被泄露，暴露军事设施操作安全漏洞。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069394" src="https://wechat2rss.xlab.app/img-proxy/?k=515f5b2a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwOwgloS05wDMmMTwDa7tuLbRzx0wgacWicbrETHbfLcXz8h0Bz8tBDjxk70LufegMgxtmiavEfFpXsUpfMDicNmKYqu1lmo10zRGc%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">六、安全趋势</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069393" src="https://wechat2rss.xlab.app/img-proxy/?k=d9e1c6f4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwPa50KVyZKLQtDMT9icIRXYMYt86BUyia4bAX39ZFSzibibjiaQsgBSOBZ6q2nfxEftS2siccHc18b9s1kaWADjtGkoFXWc5JLiarrC1I%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">机器人流量占网络活动49%</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">报告显示机器人流量占网络活动的49%，但其中99%为不良流量，恶意机器人可能伪装可信用户代理。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">语音钓鱼绕过MFA攻击Okta</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">针对Okta的语音钓鱼攻击增加，攻击者通过电话绕过MFA获取SSO访问权限。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">量子安全互联网竞赛已经开始</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">专家警告现在收获以后解密风险，敦促加快向抗量子加密迁移，现有加密协议面临量子计算威胁。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069398" src="https://wechat2rss.xlab.app/img-proxy/?k=02fc1cb8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwORuWqWBmhEwQ46NibOfNq0Y17PmOK37V2jrAPHu5ezhxQXPx6icQwb6DHqjSUJRsMtJCTplqSrEMEXTJUhZIbeuxKu2P3AGx3B8%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">本周安全建议</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069400" src="https://wechat2rss.xlab.app/img-proxy/?k=83bd3cec&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwPmyvQLh9LoE5OPOMkZcI8pqQ8jVAxT8uMKUalPpqb0TO6XGEtsuExiaqBekTarKEHe89XmaSKbhzV67zweg5Y2Exq50A0KicvsQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">1.紧急修补：</span></strong><span leaf="">立即修补Apache ActiveMQ、Excel、Nginx-ui等正被利用的漏洞</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2.AI工具审计：</span></strong><span leaf="">审查GitHub AI代理权限，防止凭证被窃取</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">3.MFA强化：</span></strong><span leaf="">防范语音钓鱼，确保电话渠道身份验证安全</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">4.物联网安全：</span></strong><span leaf="">检查TBK DVR等设备，及时修补或下线</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">5.量子准备：</span></strong><span leaf="">开始评估抗量子加密迁移计划</span></p></div><div style="font-size: 12px;color: rgb(100, 100, 100);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">数据来源</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">本期资讯编译整理自以下国际网络安全媒体：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• <a href="https://thehackernews.com" target="_blank">https://thehackernews.com</a></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• <a href="https://www.theregister.com" target="_blank">https://www.theregister.com</a></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• <a href="https://www.wired.com/category/security" target="_blank">https://www.wired.com/category/security</a></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• <a href="https://hackread.com" target="_blank">https://hackread.com</a></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• <a href="https://www.scworld.com" target="_blank">https://www.scworld.com</a></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">• <a href="https://securityaffairs.com" target="_blank">https://securityaffairs.com</a></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">免责声明</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">本资讯由安全419资讯中心编译整理，仅供参考学习。如有转载，请注明出处。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">整理日期：</span></strong><span leaf="">2026年4月20日</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 10%;max-width: 100%;height: auto;margin: 0px 10px;line-height: 0;padding: 0px;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;background-image: linear-gradient(to right, rgb(245, 245, 245) 50%, rgb(250, 228, 66) 50%);align-self: flex-start;box-sizing: border-box;"><div style="margin: 3px 0%;width: 100%;box-sizing: border-box;"><div style="font-size: 11px;color: rgb(180, 180, 180);line-height: 1;letter-spacing: 0px;padding: 0px 10px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">END</span></p></div></div></div></div></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.459375" data-s="300,640" data-type="gif" data-w="640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069403" src="https://wechat2rss.xlab.app/img-proxy/?k=4f70ce84&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwNSJN3UffGhWTadBiaw0ma9yib0Xhph8PaNtSkHDiaIIvehFvufwSASvjCCV4ET5bBGHiay9CciaOTIRG6R2tbNIwdTdzLgwwvo64FY%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="text-align: center;justify-content: center;margin: 10px 0px;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(249, 225, 25);text-align: justify;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">✦</span></p></div></div><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="color: rgb(100, 100, 100);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">推荐阅读</span></strong></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(249, 225, 25);text-align: right;box-sizing: border-box;"><p style="text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">✦</span></p></div></div></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247552906&amp;idx=1&amp;sn=b453f5cab3ff1bb1fb01a96391e9e7a5&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/sz_mmbiz_png/9Nf1wzzcfwMFNibMmwoN2xvfo4E3bwrjW9pttWzX2f0xcCl7iaYiczicNC2XLP5N8yuXR1Yz6bAicmWPA90iavxQqiatia0jzs0KYLH8qaia9q3icFOias/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.17833333333333334" data-s="300,640" data-type="png" data-w="1200" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069402" src="https://wechat2rss.xlab.app/img-proxy/?k=755c1551&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwMFNibMmwoN2xvfo4E3bwrjW9pttWzX2f0xcCl7iaYiczicNC2XLP5N8yuXR1Yz6bAicmWPA90iavxQqiatia0jzs0KYLH8qaia9q3icFOias%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553019&amp;idx=1&amp;sn=06effa47b649b25b2aba84045c7195cd&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/mmbiz_png/9Nf1wzzcfwMK4laZ0iaJZ1Nko9Eon1yP8EfwuhBoHd8UgKtEzjic74Hia9uLfLicichqmjAnOSchfL485KunBR1FfFyAjTXbTicW3Ynu8I2ibszeiao/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100069401" data-ratio="0.17833333333333334" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1200" src="https://wechat2rss.xlab.app/img-proxy/?k=cc50baaa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwMK4laZ0iaJZ1Nko9Eon1yP8EfwuhBoHd8UgKtEzjic74Hia9uLfLicichqmjAnOSchfL485KunBR1FfFyAjTXbTicW3Ynu8I2ibszeiao%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247552889&amp;idx=1&amp;sn=d49e2709606878b27d214e95584623ec&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/sz_mmbiz_png/9Nf1wzzcfwPB5ic2ibibjRLljwEFjA1xkJTydzGPz9qqUEQuoEk6NrQ9stCnHwCwc6dotXZrdObiaCaC9Btbf5HpMI64Tt1Z4Ys2xTV8TRibJDsA/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.17833333333333334" data-s="300,640" data-type="png" data-w="1200" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069406" src="https://wechat2rss.xlab.app/img-proxy/?k=2a58ee9d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwPB5ic2ibibjRLljwEFjA1xkJTydzGPz9qqUEQuoEk6NrQ9stCnHwCwc6dotXZrdObiaCaC9Btbf5HpMI64Tt1Z4Ys2xTV8TRibJDsA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="margin: 10px 0%;text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;background-color: rgba(227, 180, 0, 0.04);align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;box-sizing: border-box;"><div data-cacheurl="" data-remoteid="" style="display: inline-block;width: 100%;vertical-align: top;background-repeat: repeat;background-attachment: scroll;padding: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;background-position: 0% 0% !important;background-size: 4.17755% !important;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=0db5e6b4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwPEwTJUfvJTFXm1dKusv9ibmjLvgXSLpx8oLRXssmOoLvHB8lHBjITI2RD3uwic7R8a6bSL30h8B3t0fhPMX1wx6wzHXwwlpo2Hk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><div style="display: flex;flex-flow: row;margin: 20px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 30%;flex: 0 0 auto;height: auto;align-self: center;margin: 0px 0px 0px 20px;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="699" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069405" src="https://wechat2rss.xlab.app/img-proxy/?k=32a12f12&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F9Nf1wzzcfwOh3licL2PmNwgiczNkticMibvzmuNFicfB1l8bADbDCAwFQ4xTzF3QBjSQdvwblq6C2M9EIr9qeRls4xrNtZFqDaoT20klnWybeuUA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;margin: 0px 0px 0px 10px;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;box-sizing: border-box;"><div style="font-size: 20px;color: rgb(255, 202, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">粉丝福利群开放啦</span></strong></p></div><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(255, 202, 0);font-size: 11px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">加安全419好友进群</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">红包/书籍/礼品等不定期派送</span></p></div></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=cfb40072&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDQ4OTkyMg%3D%3D%26mid%3D2247553069%26idx%3D1%26sn%3D4f36887e769ae2f6329b6252ae7cc0d0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 23 Apr 2026 11:49:00 +0800</pubDate>
    </item>
    <item>
      <title>ISC.AI 2026 创新独角兽沙盒大赛启幕 三大赛道聚焦智能体创新</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553069&amp;idx=2&amp;sn=e667f1737c79c0617d05da71ac2d73c7</link>
      <description>4月20日，ISC.AI 2026创新独角兽沙盒大赛启动仪式于北京举办。</description>
      <content:encoded><![CDATA[<p><span>安全419</span> <span>2026-04-23 11:49</span> <span style="display: inline-block;">四川</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1434f104&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F9Nf1wzzcfwPfUCYEicyuuS3dVyYuJhjdOTVBicMfCd8X60B5d210ZgoFWx6HicopEGNaFBKulhAOfh36HK1MoCJgyN8OaYYibOXicThMuiajTIIqs%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <div style="font-size: 15px;letter-spacing: 1px;line-height: 2;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">4月20日，ISC.AI 2026创新独角兽沙盒大赛启动仪式于北京举办。本届大赛以智能体创新实践为核心，面向全球开启数字安全创新、AI应用创新、高校创新新星三大赛道招募，覆盖AI安全、安全智能体等前沿领域，致力于搭建起技术、产业、资本、人才共生共融的创新生态，推动智能化发展迈向更深层次的价值重构与场景落地。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">360数字安全集团副总裁、ISC.AI品牌主理人卜思南表示，当前人工智能快速迭代、智能体加速落地，大赛聚焦三大核心方向推动创新落地：一是打通政产学研资全链条，开放头部企业场景并提供融资陪跑，搭建真实落地平台；二是深耕AI及AI安全前沿，实现智能应用与安全底座协同发展；三是走进百所高校，挖掘智能体应用、AI漫剧等创意项目，培育新生代创新力量，营造鼓励试错、推动技术转化的创新生态。</span></p></div><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6666666666666666" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069413" src="https://wechat2rss.xlab.app/img-proxy/?k=ea90e883&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwO8hSyr6TJtw1VGFUZs9JcNUaSRtBvSd3rQ8qBtpPy3yaF4xZLicTJo1yq7H9ibzWCOQVZro0gRpgichVupvsFR0o6dibrNJc1HlMk%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">中国电子工业科学技术交流中心副主任王奇超指出，AI已进入产业落地与智能体发展关键期，人才供需结构性鸿沟凸显。大赛以“以赛促学、以赛促创、以赛促用”为宗旨，覆盖前沿技术领域，打破校企壁垒，助力培养“懂技术、懂业务、懂安全”的复合型智能体人才。</span></p><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6695187165775401" data-s="300,640" data-type="jpeg" data-w="935" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069414" src="https://wechat2rss.xlab.app/img-proxy/?k=a60f7210&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F9Nf1wzzcfwOyvwzjmWDpgCxJ0gHnIcqDFaKtibdRQIpqHVk5MJtuSs8eKDRUiaHulRViahK6hPnWrJ46Ddmj6pQNwcBwIp0g8HIIY3H3ibK2fKY%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">据悉，本届大赛由ISC.AI平台主办，与北京新一代信息技术产教联合体、全国信息安全行业产教融合共同体、全国数智安全行业产教融合共同体、全国人工智能+安全(数字安全)产教融合共同体、大模型产业联盟、光合行AIGC联盟等机构，数说安全、数世咨询、安全419、极客邦科技等媒体合作，并由密码资本、元起资本等支持。目前，大赛报名通道已正式开启，后续将依托多年政产学研用生态积累，联动政府、智库、资本与研究平台，深挖人工智能与数字安全领域创新成果。</span></p><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 10%;max-width: 100%;height: auto;margin: 0px 10px;line-height: 0;padding: 0px;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;background-image: linear-gradient(to right, rgb(245, 245, 245) 50%, rgb(250, 228, 66) 50%);align-self: flex-start;box-sizing: border-box;"><div style="margin: 3px 0%;width: 100%;box-sizing: border-box;"><div style="font-size: 11px;color: rgb(180, 180, 180);line-height: 1;letter-spacing: 0px;padding: 0px 10px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">END</span></p></div></div></div></div></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.459375" data-s="300,640" data-type="gif" data-w="640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069415" src="https://wechat2rss.xlab.app/img-proxy/?k=6482225f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwNaQC9bTEbXtZBP82yGdWctqiaWYoJymoy1ZoBjZe3PeiaOzG992IKDENlTjNetK7Zmiaciajdu6zicyydPdTy6jOibml08bTflwt05g%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="margin: 10px 0%;text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;background-color: rgba(227, 180, 0, 0.04);align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;box-sizing: border-box;"><div data-cacheurl="" data-remoteid="" style="display: inline-block;width: 100%;vertical-align: top;background-repeat: repeat;background-attachment: scroll;padding: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;background-position: 0% 0% !important;background-size: 4.17755% !important;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=2e7de8a8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwOBgAs3ibKYXVQYZouj6pBrqnRyHtWzyJjInh7WMfIOAANt3f9FlUZ5EAOS4EPcyrp3qLOeMvCvzXdcVvlbdBnvIONNCC8vhCwo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><div style="display: flex;flex-flow: row;margin: 20px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 30%;flex: 0 0 auto;height: auto;align-self: center;margin: 0px 0px 0px 20px;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="699" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069412" src="https://wechat2rss.xlab.app/img-proxy/?k=acb71588&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwO1NlHq6mI5bpOnJx74KFwjl7qiasgUzWOsT3XKcKstdmoiaOq0GVp7m5M9Y0C12FIbNrXxicH7UYicRgLacSLyTSxSsJRZ9PtWibcQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;margin: 0px 0px 0px 10px;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;box-sizing: border-box;"><div style="font-size: 20px;color: rgb(255, 202, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">粉丝福利群开放啦</span></strong></p></div><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(255, 202, 0);font-size: 11px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">加安全419好友进群</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">红包/书籍/礼品等不定期派送</span></p></div></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=89bc2acd&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDQ4OTkyMg%3D%3D%26mid%3D2247553069%26idx%3D2%26sn%3De667f1737c79c0617d05da71ac2d73c7">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 23 Apr 2026 11:49:00 +0800</pubDate>
    </item>
    <item>
      <title>AI浪潮来袭，网络安全如何守护“数字中国”——“4·19”讲话十周年行业观察</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553068&amp;idx=1&amp;sn=769273f61e16e08311cd687dd7262cb4</link>
      <description>AI赋能攻击规模化升级，新《网络安全法》将AI安全纳入法治轨道。</description>
      <content:encoded><![CDATA[<p>原创 <span>安全419</span> <span>2026-04-22 12:10</span> <span style="display: inline-block;">四川</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1109fee0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwNWjZLicV5oD7Rom9OjEpHjbpmAdBwFwJGmdUERYQpmJ0icLb7xmfuITuOYBEs69UJiaBEKQJW31aZtMOqjF8FnKkiaQE5zV7LlY4c%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>AI赋能攻击规模化升级，新《网络安全法》将AI安全纳入法治轨道。</p>
  <div style="font-size: 15px;letter-spacing: 1px;line-height: 2;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2016年4月19日，总书记主持召开网络安全和信息化工作座谈会，明确提出“安全是发展的前提，发展是安全的保障，安全和发展要同步推进”。十年后的今天，人工智能正以远超预期的速度重塑网络安全攻防格局——AI技术既为防御注入新动能，也为攻击者提供了前所未有的“武器”。面对这一深刻变革，如何在AI时代坚持“安全与发展同步推进”的战略思想，成为网络安全行业必须回应的时代命题。</span></p><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.562962962962963" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069374" src="https://wechat2rss.xlab.app/img-proxy/?k=4674eaf7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwPYYgIKGxFIAyO9Jk9tzY9lCSpbDuVubBpR8h5wzRPia5d0jbJ7bOkPPsUp0jfrhmHxexGgHlujAkbvocKqiaf5EXuzD9yaxEfMI%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="text-align: center;justify-content: center;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-style: solid;border-width: 1px;border-color: rgb(255, 202, 0);align-self: flex-start;box-sizing: border-box;"><div style="justify-content: center;margin: -3px 0% 3px;transform: translate3d(-3px, 0px, 0px);-webkit-transform: translate3d(-3px, 0px, 0px);-moz-transform: translate3d(-3px, 0px, 0px);-o-transform: translate3d(-3px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(255, 202, 0);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;border-width: 0px;align-self: flex-start;box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 14px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">一、AI赋能防御：从“告警海啸”到“自主闭环”</span></strong></p></div></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AI正在推动安全运营中心（SOC）从被动响应走向主动智能。传统SOC长期面临告警繁杂、专业人才短缺、响应迟缓等痛点，AI技术的引入正从根本上改变这一局面。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026年3月，阿里云正式发布了Agentic SOC平台，基于大语言模型与智能体集群架构，实现了“感知—决策—执行”的自主闭环。系统可围绕安全事件自主调用查询、分析、关联、研判等工具链，完成日志分析、根因追溯、影响评估等复杂任务，安全告警覆盖提升2倍，安全事件发现效率增长8倍。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026年4月，中国移动联合多家单位发布“AI驱动的网络安全一体化运营防护系统”，单条告警研判时间由5分钟缩短至1分钟，研判准确率超过90%，可替代80%的重复性人工渗透测试工作。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在AI安全产品和方案方面，国内头部安全厂商积极布局。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">360依托安全大模型创新推出360安全智能体蜂群，构建覆盖自动化威胁狩猎、攻击溯源、钓鱼邮件检测等多类安全场景的智能防护体系。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">绿盟科技则提出“AI保护AI”理念，面向OpenClaw等本地化AI智能体所衍生的安全风险，推出了AI安全一体机与防火墙联动的专属解决方案。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">天融信在AI赋能安全方面推出AI防火墙、APT安全监测等系列产品，在大模型应用安全方面发布大模型安全网关、API安全审计等产品。</span></p></div><div style="text-align: center;justify-content: center;margin: -3px 0% 3px;transform: translate3d(-3px, 0px, 0px);-webkit-transform: translate3d(-3px, 0px, 0px);-moz-transform: translate3d(-3px, 0px, 0px);-o-transform: translate3d(-3px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(255, 202, 0);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;border-width: 0px;align-self: flex-start;box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 14px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">二、AI催生攻击：攻防速度差距拉大</span></strong></p></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">然而，AI的“双刃剑”效应同样显著——攻击者同样在利用AI加速攻击流程、扩大攻击规模。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">据CrowdStrike《2026年全球威胁报告》显示，2025年由AI赋能的对手发起的攻击同比增长了89%。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">谷歌云发布的《2026年网络安全预测》警告称，威胁行为者将从“偶尔使用AI”转向“常态化依赖AI”，利用AI生成的语音克隆实施更具迷惑性的语音钓鱼攻击。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">IBM《2026年X-Force威胁情报指数报告》也指出，攻击者正利用AI以前所未有的速度发现系统弱点，利用面向公众的软件发起的攻击激增了44%。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">值得警惕的是，AI智能体自身的供应链安全风险也开始显现。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026年2月，安全研究人员发现开源AI智能体框架OpenClaw存在严重漏洞，超过42,000个IP地址暴露了OpenClaw控制面板，遍布82个国家，部分可被远程代码执行攻击利用。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">与此同时，2025年信息窃取类恶意软件导致超过30万个ChatGPT凭证泄露，表明AI平台在企业内的凭证风险已与其他核心SaaS解决方案不相上下。</span></p></div><div style="text-align: center;justify-content: center;margin: -3px 0% 3px;transform: translate3d(-3px, 0px, 0px);-webkit-transform: translate3d(-3px, 0px, 0px);-moz-transform: translate3d(-3px, 0px, 0px);-o-transform: translate3d(-3px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(255, 202, 0);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;border-width: 0px;align-self: flex-start;box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 17px;padding: 0px 14px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">三、政策与治理：为AI安全划定法治轨道</span></strong></p></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AI安全治理不能仅靠技术，更需要法治护航。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026年1月1日，新修订的《网络安全法》正式施行，首次将人工智能安全治理纳入法律框架，新增第二十条要求“完善人工智能伦理规范，加强风险监测评估和安全监管”。这一修订从国家立法层面为AI技术的安全发展划定了红线和底线，充分体现了总书记提出的“发展是安全的保障，安全是发展的前提”这一根本要求。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在政策落地层面，2026年4月，国家网信办等五部门联合公布《人工智能拟人化互动服务管理暂行办法》，明确“坚持发展和安全并重、促进创新和依法治理相结合”的原则。同日，中国通信学会联合业界发布《云上智能体服务网络和数据安全自律公约（2026版）》，天翼云、移动云、阿里云、腾讯云等11家领军企业作为首批签署方，成为首个云上智能体服务行业自律性文件。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">此外，全国网络安全标准化技术委员会组织制定的《人工智能应用伦理安全指引》1.0版也公开征求意见，从标准化层面填补了AI伦理治理的空白。</span></p></div><div style="text-align: center;justify-content: center;margin: -3px 0% 3px;transform: translate3d(-3px, 0px, 0px);-webkit-transform: translate3d(-3px, 0px, 0px);-moz-transform: translate3d(-3px, 0px, 0px);-o-transform: translate3d(-3px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(255, 202, 0);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;border-width: 0px;align-self: flex-start;box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 17px;padding: 0px 14px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">四、展望：AI时代网络安全的中国方案</span></strong></p></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">回顾总书记“4·19”讲话发表十周年，我国网信事业取得了从“网络大国”到“网络强国”的历史性跨越。面对AI浪潮，我国已初步构建起“法律法规+行业自律+标准指引+技术创新”的AI安全综合治理体系，展现出中国在网络空间治理上的主动作为。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">然而，AI技术的迭代速度远超政策与标准的更新周期。正如总书记所指出的，“网络安全和信息化是相辅相成的”。在AI时代，没有网络安全就没有数字中国的稳健根基，没有信息化就没有中国式现代化的强劲动能。网络安全行业必须继续坚持“安全和发展同步推进”，以技术创新驱动安全防护能力升级，以法治化治理为AI发展系好“安全带”，在全球AI治理中积极贡献中国智慧和中国方案。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 10%;max-width: 100%;height: auto;margin: 0px 10px;line-height: 0;padding: 0px;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;background-image: linear-gradient(to right, rgb(245, 245, 245) 50%, rgb(250, 228, 66) 50%);align-self: flex-start;box-sizing: border-box;"><div style="margin: 3px 0%;width: 100%;box-sizing: border-box;"><div style="font-size: 11px;color: rgb(180, 180, 180);line-height: 1;letter-spacing: 0px;padding: 0px 10px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">END</span></p></div></div></div></div></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100069377" data-ratio="0.459375" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=c7892ec7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwOV9SxbOMdCKLOvicyt7CqIww6cXag6dmzPQKro9bibMgQHwxKP3cv3HI63l3ibCn4w0sA9toR4akoicVxIZOhzoUgBxBu7rkPnaQ0%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="text-align: center;justify-content: center;margin: 10px 0px;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(249, 225, 25);text-align: justify;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">✦</span></p></div></div><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="color: rgb(100, 100, 100);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">推荐阅读</span></strong></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(249, 225, 25);text-align: right;box-sizing: border-box;"><p style="text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">✦</span></p></div></div></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247552906&amp;idx=1&amp;sn=b453f5cab3ff1bb1fb01a96391e9e7a5&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/mmbiz_png/9Nf1wzzcfwPEicgq9GibrZt3Hiaticb5ecoOzfGrEibEkCReGJDGFkhrYJJOICVjgpx63ErLvF1Ovic3m623Srxg3LQFbBLS3eEB2HqPygwHB18kw/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.17833333333333334" data-s="300,640" data-type="png" data-w="1200" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069373" src="https://wechat2rss.xlab.app/img-proxy/?k=d7fd9210&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwPEicgq9GibrZt3Hiaticb5ecoOzfGrEibEkCReGJDGFkhrYJJOICVjgpx63ErLvF1Ovic3m623Srxg3LQFbBLS3eEB2HqPygwHB18kw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553019&amp;idx=1&amp;sn=06effa47b649b25b2aba84045c7195cd&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/mmbiz_png/9Nf1wzzcfwNEfzlaglHiaUIoeYtKQSt7P2soibHCOP0eSjNERicn8W2uLEicOkd1MGTSmvW80hLnxdDOyIJfXu8cRcWic0Ocx4TqdVTruRrlTSkg/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.17833333333333334" data-s="300,640" data-type="png" data-w="1200" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069375" src="https://wechat2rss.xlab.app/img-proxy/?k=78b20eb5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwNEfzlaglHiaUIoeYtKQSt7P2soibHCOP0eSjNERicn8W2uLEicOkd1MGTSmvW80hLnxdDOyIJfXu8cRcWic0Ocx4TqdVTruRrlTSkg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247552889&amp;idx=1&amp;sn=d49e2709606878b27d214e95584623ec&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/sz_mmbiz_png/9Nf1wzzcfwMiczSsVCpxRWicoiboTmLw6iaJpBTg5icKXnBAM7sUr2yv0j8DfGDPHECRnr1I4YXY09C6SCVNJdKH8pdLDpMHGmSnIJAQd0DPD3rw/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.17833333333333334" data-s="300,640" data-type="png" data-w="1200" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069376" src="https://wechat2rss.xlab.app/img-proxy/?k=1f350c64&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwMiczSsVCpxRWicoiboTmLw6iaJpBTg5icKXnBAM7sUr2yv0j8DfGDPHECRnr1I4YXY09C6SCVNJdKH8pdLDpMHGmSnIJAQd0DPD3rw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="margin: 10px 0%;text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;background-color: rgba(227, 180, 0, 0.04);align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;box-sizing: border-box;"><div data-cacheurl="" data-remoteid="" style="display: inline-block;width: 100%;vertical-align: top;background-repeat: repeat;background-attachment: scroll;padding: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;background-position: 0% 0% !important;background-size: 4.17755% !important;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=7bfe34c6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwNX78tzcOfLwxtj9rEGD58AzeI23CEmibG53icj2kmlYzlvEOD6HhujE2zdLHH324wVJ5IJWr8UPx3RpRwmukadAFhbGHROKNC28%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><div style="display: flex;flex-flow: row;margin: 20px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 30%;flex: 0 0 auto;height: auto;align-self: center;margin: 0px 0px 0px 20px;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="699" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069379" src="https://wechat2rss.xlab.app/img-proxy/?k=200cb9c7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwMwR0Dr2Zy9OA0viaCwfyYHpHicCKNBqPVvFJcf3jXuRVPBQR0yryhI9TtiaRetAVGpAZKPiahtuJyl8SeWJzr1faZS2Fib2X0iancvw%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;margin: 0px 0px 0px 10px;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;box-sizing: border-box;"><div style="font-size: 20px;color: rgb(255, 202, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">粉丝福利群开放啦</span></strong></p></div><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(255, 202, 0);font-size: 11px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">加安全419好友进群</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">红包/书籍/礼品等不定期派送</span></p></div></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=fcd04159&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDQ4OTkyMg%3D%3D%26mid%3D2247553068%26idx%3D1%26sn%3D769273f61e16e08311cd687dd7262cb4">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 22 Apr 2026 12:10:00 +0800</pubDate>
    </item>
    <item>
      <title>合规运营：视角转变带来的安全运营3.0时代 将重构行业价值</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247553019&amp;idx=1&amp;sn=06effa47b649b25b2aba84045c7195cd</link>
      <description>以合规为底座、攻防为组件、生态为支撑的新模式，将重新定义安全运营的交付标准与价值度量。</description>
      <content:encoded><![CDATA[<p>原创 <span>安全419</span> <span>2026-04-20 12:01</span> <span style="display: inline-block;">四川</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=7dc45dd4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwOxfksAzLgtEb226Pjn1zyXS0DVVkzXFBJib5haMQumJ0diamfX7En4p89I6jKIVnRicn94d7ZhRTibNp0yoq4BlRbbq9GiaViaB2Eics%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>以合规为底座、攻防为组件、生态为支撑的新模式，将重新定义安全运营的交付标准与价值度量。</p>
  <div style="font-size: 15px;letter-spacing: 1px;line-height: 2;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在网络安全监管趋严、攻防对抗智能化、企业数字化纵深推进的三重背景下，国内安全运营正经历一场底层逻辑的范式迁移。过去以攻防为核心、以合规为附属的传统思路已难以为继，</span><strong style="box-sizing: border-box;"><span leaf="">以</span></strong><strong style="box-sizing: border-box;"><span leaf="">合规为底座、攻防能力为组件</span></strong><span leaf="">的全新运营框架正在成为行业共识。安全 419 观察到，一个全新的“</span><strong style="box-sizing: border-box;"><span leaf="">合规运营</span></strong><span leaf="">”概念目前正悄悄浮出水面，而推动这一概念的北京小西牛认为，未来的安全运营即将进入到3.0时代。</span></p><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5054151624548736" data-s="300,640" data-type="png" data-w="554" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069360" src="https://wechat2rss.xlab.app/img-proxy/?k=be31b3d5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwMb2R0MickQO9u65F93DbVHk7dIptyxN6jnYVFtM2fRY9TzTe3KlDgRia5yIh5ibyO7mANRVF7icfvJabNHUxEw9IwD5d3iaUYeia52M%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: center;justify-content: center;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-style: solid;border-width: 1px;border-color: rgb(255, 202, 0);align-self: flex-start;box-sizing: border-box;"><div style="justify-content: center;margin: -3px 0% 3px;transform: translate3d(-3px, 0px, 0px);-webkit-transform: translate3d(-3px, 0px, 0px);-moz-transform: translate3d(-3px, 0px, 0px);-o-transform: translate3d(-3px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(255, 202, 0);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;border-width: 0px;align-self: flex-start;box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 17px;padding: 0px 14px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">安全运营的3.0时代 需要“甲方思维”</span></strong></p></div></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">北京小西牛创始人施能坤介绍，安全运营实际上目前已经经历了2个阶段，分别是：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">单点安全服务为代表的</span><strong style="box-sizing: border-box;"><span leaf="">安全运营1.0时代</span></strong><span leaf="">，即大家理解的最传统的安全服务。以设备交付、漏洞扫描、应急处置等离散服务为主要形态，重产品、轻运营，重响应、轻预防，安全工作碎片化、被动化，难以形成体系化能力，仅能满足基础防护需求。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻防视角的体系化运营，即</span><strong style="box-sizing: border-box;"><span leaf="">安全运营2.0时代</span></strong><span leaf="">。围绕威胁对抗构建全流程能力，强调漏洞管理、威胁狩猎、态势感知、攻防演练等体系化建设，以 “主动防御” 为目标。但此阶段仍以技术攻防为轴心，合规多为事后补位，易出现 “重实战、轻合规” 或 “合规与实战两张皮” 的问题。 需要在资源充裕的基础上由内部人员牵头进行定制化能力整合，这种模式更适合头部客户，但是难以规模化覆盖腰部市场。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">安全419发现，长久以来网络安全市场做“合规”的与做“攻防”的企业，似乎从来就是两条赛道，这种割裂感至今依然存在。但是作为一家长期服务腰部客户，先后耕耘合规市场又转型运营的北京小西牛则拿出了不同的见解。在小西牛创始人施能坤看来， 这一切的根本原因是腰部客户缺少一个能够自上而下，将“管理依据—落地执行—佐证留痕—管理落地”彻底打通的轻量级服务体系。</span></p></div><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5657407407407408" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069365" src="https://wechat2rss.xlab.app/img-proxy/?k=c7fadc95&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwOZa6XhcMzLTribiaIP68OvITMTQibPQ3dKxlmjIUBE2dmDribCPyAib3jd7SFsS6EBP6s3cnbrDp8EFX5ydNT1CiaicKUxTVZOfO3cJs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">之所以长期隔江而治，是因为长期以来做运营的企业往往都是攻防实战派，专注于快速解决当下问题，不关注“用执行文档佐证管理”；而做合规的企业往往都是区域服务商，擅长按照监管要求逐项应答，但在真正的威胁监测、应急处置方面落地不足，服务体系的完整性与健壮性欠佳。而如今，随着网络安全纳入主体责任、政务审计全面覆盖以及一案双查、一案三查落地实施， 监管力度已从“清单式核查” 转向 “技术实测、结果导向、闭环追责”，合规不再是可选项，而是党政机关、国有企事业单位安全运营的</span><strong style="box-sizing: border-box;"><span leaf="">基础框架与出发点。</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在这样的框架内，攻防能力并未被弱化，而是被重新定位：攻防是合规框架内验证安全有效性、持续提升防御韧性的重要手段，而非安全工作的全部。安全运营的目标从 “单纯防住攻击” 升级为</span><strong style="box-sizing: border-box;"><span leaf="">在合规引领之下，实现风险可控、过程可见、后续可溯</span></strong><span leaf="">，安全价值与业务合规、法律责任、经营稳定深度绑定。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">而要做到这一点， 首先要跳出传统乙方对“合规”的理解 ——</span><strong style="box-sizing: border-box;"><span leaf="">合规绝不是最低标准，不是每年拿到几份检测报告。合规是涵盖全局的纲领指导，是所有履职动作事后溯源“唯一标准”，其核心在于用管理制度规范运营动作，对运营过程中的各项动作进行留痕和可追溯，以便在未来的审计、追责或安全事件调查中，能够证明安全体系已落实到位，安全管理人员已尽职履责，从而降低甲方的履职风险和不确定性。</span></strong><span leaf="">实际上近20年来，这一直都是监管部门的要求，从未降低，只是受困于种种原因实现困难罢了。</span></p></div><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5638888888888889" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069364" src="https://wechat2rss.xlab.app/img-proxy/?k=75c462c7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwOBHkJryDapiaTQdDyRkY8iba4FwBX0Wc2zic4faMmSyiaUoCYvicrgF5FqDnrml83GyXwTOI7J5FTRsbdcF2kRklhOLwficHJ3wluE8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">所以，这个升级最核心的改变来自视角的转变，用施能坤的话来讲就是我们需要树立</span><strong style="box-sizing: border-box;"><span leaf="">“甲方思维”</span></strong><span leaf="">——2.0版本的运营是“工具思维”，旨在利用自身工具能力为客户做到最优；3.0版本的运营则转变为站在客户的角度去设计产品和服务，其核心驱动力是“合规加责任”。产品定位为协助客户（尤其是甲方）管理所有与其安全责任相关的资产和工作，无论这些资产和工作来源于何种工具。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">北京小西牛认为：若要满足未来绝大部分市场客户的真实需求，首先需要转变传统的视角，进化到“</span><strong style="box-sizing: border-box;"><span leaf="">合规运营</span></strong><span leaf="">”这一全新的3.0时代。顾名思义，未来所有安全相关的动作，都必须站在客户安全责任人的角度来排兵布阵，让所有的行为都能够在真正更宽泛、更具实战意义的合规框架内开展。</span></p></div><div style="text-align: center;justify-content: center;margin: -3px 0% 3px;transform: translate3d(-3px, 0px, 0px);-webkit-transform: translate3d(-3px, 0px, 0px);-moz-transform: translate3d(-3px, 0px, 0px);-o-transform: translate3d(-3px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(255, 202, 0);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;border-width: 0px;align-self: flex-start;box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 17px;padding: 0px 14px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">市场聚焦：腰部客户成主战场，合规运营痛点亟待破局</span></strong></p></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">小西牛认为，安全运营 3.0 的核心服务对象，是数量庞大、需求刚性、资源有限的</span><strong style="box-sizing: border-box;"><span leaf="">腰部客户</span></strong><span leaf="">。长久以来腰部单位的安全管理者始终精神紧张：“写好的规定往往落地不足，落地的动作却未必经得起追溯检查”，单独看好像什么都做了、合起来看好像什么都没做完整， 这种深深的乏力感是腰部客户的“普遍共鸣”。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">“举个例子，我们在服务大量客户的过程中都发现，客户无法对乙方（安全服务提供商）运营“全部的安全服务项”的执行偏差、执行进展、执行过程进行掌握，长期处在黑盒状态，服务过程也不可追溯；同时，因信息留存不全，事后补充材料困难重重，对提供充分且有说服力的履职证明材料、迎接检查依然是非常繁重甚至无法完全落地的工作”。小西牛工作人员向笔者介绍道，“这都是几乎每一个腰部客户都要面临的问题”。</span></p></div><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5638888888888889" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069363" src="https://wechat2rss.xlab.app/img-proxy/?k=f8898bf8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwNg8jpIiacWMLE0vXviboibKAXLN2upAYnRZXquOTpOa9qtgY3LCXDccrYPJJXTMFIoxvniczibJbZwUDuV0jcWIsyMXxEysAibJljQA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">有别于头部客户人多、钱多、能力强的优势，腰部客户在安全建设工作中明显人员编制和投入更加有限，但是又要同时做到：</span><strong style="box-sizing: border-box;"><span leaf="">运营安全+履职安全</span></strong><span leaf="">，这无疑是一个巨大的挑战。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">而小西牛提出的“合规运营”这一概念，正是瞄准了腰部客户的核心需求——传统攻防导向的重运营模式，对腰部客户而言 “用不起、用不好、跟不上”。而安全运营 3.0 的理念恰好匹配腰部客户 “低成本、易落地、强合规、稳运行” 的核心诉求。比如通过3.0版本的理念和产品，从管理制度开始梳理，在运营落地的过程中将所有动作进行数字化留痕，形成完整的、可追溯的工作记录，就可以从根本上解决上述两大痛点。</span></p></div><div style="text-align: center;justify-content: center;margin: -3px 0% 3px;transform: translate3d(-3px, 0px, 0px);-webkit-transform: translate3d(-3px, 0px, 0px);-moz-transform: translate3d(-3px, 0px, 0px);-o-transform: translate3d(-3px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(255, 202, 0);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;border-width: 0px;align-self: flex-start;box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 17px;padding: 0px 14px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">能力集成+生态联盟 “合规运营”落地路径的探索</span></strong></p></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">“合规运营”强调的也并非单一产品或服务，而是一套</span><strong style="box-sizing: border-box;"><span leaf="">技术 + 流程 + 生态</span></strong><span leaf="">的完整体系。北京小西牛创始人施能坤介绍道：安全运营3.0时代（合规运营）的理念是应该采用“大合规”框架，通过生态融合和能力集成的方式整合行业优秀能力（如将不同厂商的扫描器、XDR等能力整合），而非自行开发所有模块。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这并不意味着为客户提供的是一个类似于头部客户的“低配版”，而是先拆后合，先将业务场景和需求逐一拆解，针对腰部客户特点，逐一挑选各细分领域的能力佼佼者，再融合客户需求做场景化落地——在有限的预算下参照头部客户，实现关键安全运营项的同等服务和安全保障。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">基于此，北京小西牛在其中起到了一个“组织者和融合者”的角色，利用多年在合规领域的理解，以及与行业的充分交流，与同行业企业创造了一个“模块化能力集成”的新模式。比如，星维九州在安全运营2.0时代在研判质量、交付时效方面走在行业前列，未来智安则是“AI安全运营”中的顶尖解决方案提供商，因此小西牛分别与这两家公司都合作进行专项能力打造，在扫描器方面接入启明星辰这种成熟的品牌产品，确保平台技能专业水准。 这样的合作案例，相信未来还会有更多。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">不光是在产品上采用将细分领域头部能力集成的方式，小西牛在近年来还大力采用生态共建的模式以确保业务的快速推进。比如近年来小西牛已经创办了一个名为“G9”的生态联盟，渠道策略聚焦区域型深度代理联盟，以投资方式让九省本地安全服务商成为股东，绑定下游管道；每个省设独家经销商，由其在当地构建生态，实现“品牌化DIY集成方案”的下沉交付。</span><strong style="box-sizing: border-box;"><span leaf="">通过整合渠道推进业务 让所有合作伙伴变成“股东”，以保证产品能够快速落地服务市场。</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">“能力集成+生态联盟”，让“合规运营”这一构想能够快速地落地执行。而对于参与这一未来的企业们，这样做的好处显而易见——</span><strong style="box-sizing: border-box;"><span leaf="">大家的业务边界拓宽了，竞争关系也变为了协同关系。</span></strong></p></div><div style="text-align: center;justify-content: center;margin: -3px 0% 3px;transform: translate3d(-3px, 0px, 0px);-webkit-transform: translate3d(-3px, 0px, 0px);-moz-transform: translate3d(-3px, 0px, 0px);-o-transform: translate3d(-3px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(255, 202, 0);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;border-width: 0px;align-self: flex-start;box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 17px;padding: 0px 14px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">行业展望：合规底座将成为安全运营的标配能力</span></strong></p></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">安全 419 认为，安全运营 3.0 的兴起，标志着行业从 “技术导向” 转向 “价值导向”，从 “头部定制” 转向 “腰部普惠”。以合规为底座、攻防为组件、生态为支撑的新模式，将重新定义安全运营的交付标准与价值度量。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">对企业而言，安全运营不再是成本中心，而是</span><strong style="box-sizing: border-box;"><span leaf="">合规保障中心、风险管控中心、业务赋能中心</span></strong><span leaf="">；对行业而言，安全运营 3.0 将推动能力规模化下沉，让海量腰部客户以可负担成本获得可持续、可验证、可审计的安全能力。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">随着监管持续深化与 AI 技术快速渗透，合规驱动的安全运营 3.0 将从趋势变为现实，成为数字时代企业安全能力建设的主流路径，为数字经济稳健发展筑牢可信、可控、可续的安全底座。当然，这无疑是一场刀刃向内的自我革新之路，无论是对合规方而言还是运营方而言，3.0的落地都将他们从过去的舒适区内拽了出去，去填补原先压根不花费精力的部分。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">“ 若非如此，又怎么能走出一条有别于同类竞争者的优势之路呢？” 施能坤说道，只有提升自己，站在甲方甚至监管的角度来重新反思过去，规划未来，和他们站在一起，想在一起，才是虽然艰难但是长久正确的路。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 10%;max-width: 100%;height: auto;margin: 0px 10px;line-height: 0;padding: 0px;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;background-image: linear-gradient(to right, rgb(245, 245, 245) 50%, rgb(250, 228, 66) 50%);align-self: flex-start;box-sizing: border-box;"><div style="margin: 3px 0%;width: 100%;box-sizing: border-box;"><div style="font-size: 11px;color: rgb(180, 180, 180);line-height: 1;letter-spacing: 0px;padding: 0px 10px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">END</span></p></div></div></div></div></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.459375" data-s="300,640" data-type="gif" data-w="640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069362" src="https://wechat2rss.xlab.app/img-proxy/?k=1f82b160&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwMF9oUB7HcF4x60nc2ydwNKao98XE8GWFdEqgIJIwzypgNqlIGKfr1zCKXlDLHeRRaD7tvHJ9qM8ck18yaDGtrPnrDcwonlYk4%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="text-align: center;justify-content: center;margin: 10px 0px;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(249, 225, 25);text-align: justify;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">✦</span></p></div></div><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="color: rgb(100, 100, 100);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">推荐阅读</span></strong></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(249, 225, 25);text-align: right;box-sizing: border-box;"><p style="text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">✦</span></p></div></div></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247552906&amp;idx=1&amp;sn=b453f5cab3ff1bb1fb01a96391e9e7a5&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/mmbiz_png/9Nf1wzzcfwPHqeVaxLGHwjDQrXv6icm3NIeTdSvMVn8W0z2mQyx6bicNndAV3WbTwKAQaUib0460KSPNTvsWkyUA5MRxaHyicu2gNk6lKP0sdibQ/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.17833333333333334" data-s="300,640" data-type="png" data-w="1200" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069367" src="https://wechat2rss.xlab.app/img-proxy/?k=d7269696&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwPHqeVaxLGHwjDQrXv6icm3NIeTdSvMVn8W0z2mQyx6bicNndAV3WbTwKAQaUib0460KSPNTvsWkyUA5MRxaHyicu2gNk6lKP0sdibQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247552972&amp;idx=1&amp;sn=253767a35bdb3e6e07f5a1c56736f185&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/mmbiz_png/9Nf1wzzcfwNArZOoo7iaxuSTJAUe3lGLzsicc6qUPp7ic4NQDB80q3PcUrx3U2VrHU9NRcU3bavXENqljag3DMRQhsGdBic72mnh2BP0UPibVK84/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.17833333333333334" data-s="300,640" data-type="png" data-w="1200" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069369" src="https://wechat2rss.xlab.app/img-proxy/?k=3792cbc3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwNArZOoo7iaxuSTJAUe3lGLzsicc6qUPp7ic4NQDB80q3PcUrx3U2VrHU9NRcU3bavXENqljag3DMRQhsGdBic72mnh2BP0UPibVK84%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247552889&amp;idx=1&amp;sn=d49e2709606878b27d214e95584623ec&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/mmbiz_png/9Nf1wzzcfwPrOkSq4bVUCQY0EUJnprrGC2pnyD6OTeicqSVBHSU58wLj3zHxjKh7xuiaV8TQ6iamjJw6FfcRttWn2kaSJibic8ia2lbDbuQIWibrIU/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.17833333333333334" data-s="300,640" data-type="png" data-w="1200" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069370" src="https://wechat2rss.xlab.app/img-proxy/?k=708e154f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwPrOkSq4bVUCQY0EUJnprrGC2pnyD6OTeicqSVBHSU58wLj3zHxjKh7xuiaV8TQ6iamjJw6FfcRttWn2kaSJibic8ia2lbDbuQIWibrIU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="margin: 10px 0%;text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;background-color: rgba(227, 180, 0, 0.04);align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;box-sizing: border-box;"><div data-cacheurl="" data-remoteid="" style="display: inline-block;width: 100%;vertical-align: top;background-repeat: repeat;background-attachment: scroll;padding: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;background-position: 0% 0% !important;background-size: 4.17755% !important;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=9f1952d5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwOs0aTwyIpyQjiat4wOkqyYEkFAIVTrxkZPdvhZJHWAdsvuv16p6TuKlvhY3HC6TOBZ8lqjzyMoTJoTChG2bicNwSMcAzgkDcZIo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><div style="display: flex;flex-flow: row;margin: 20px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 30%;flex: 0 0 auto;height: auto;align-self: center;margin: 0px 0px 0px 20px;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="699" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069368" src="https://wechat2rss.xlab.app/img-proxy/?k=512dce3e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F9Nf1wzzcfwNsLpGkAs8nPSW7wgT2jg8n0KZt5GrMI2CKF2CXD7ZmC8mujk2oahpTAyoKfmo5nicibZ0ExA88dxM2D0gaZnrqichVviauUrAPP3g%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;margin: 0px 0px 0px 10px;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;box-sizing: border-box;"><div style="font-size: 20px;color: rgb(255, 202, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">粉丝福利群开放啦</span></strong></p></div><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(255, 202, 0);font-size: 11px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">加安全419好友进群</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">红包/书籍/礼品等不定期派送</span></p></div></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=60a209b3&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDQ4OTkyMg%3D%3D%26mid%3D2247553019%26idx%3D1%26sn%3D06effa47b649b25b2aba84045c7195cd">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 20 Apr 2026 12:01:00 +0800</pubDate>
    </item>
    <item>
      <title>攻击者滥用AI服务入侵企业的六种方式</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247552972&amp;idx=1&amp;sn=253767a35bdb3e6e07f5a1c56736f185</link>
      <description>攻击者通过伪造MCP服务器、滥用AI为C2通道、投毒依赖链等方式，将企业信任的AI工具变成攻击跳板。</description>
      <content:encoded><![CDATA[<p>原创 <span>安全419</span> <span>2026-04-16 17:40</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=3f2dd973&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F9Nf1wzzcfwM7icqtHU22aVCGI76qLZAgv0GccYkvUqOwlWO6YRIaNJx3nRUEqLmV2nHqbxEibibq1kwfGLwibfCgY8UkubzkAApuDF8dialJC7iak%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>攻击者通过伪造MCP服务器、滥用AI为C2通道、投毒依赖链等方式，将企业信任的AI工具变成攻击跳板。</p>
  <div style="font-size: 15px;letter-spacing: 1px;line-height: 2;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">随着企业对AI技术和服务的依赖日益加深，攻击者也演变出滥用AI的新形态，不再仅仅依赖恶意软件，而是越来越多地滥用企业所依赖的AI工具，像过去依赖PowerShell等内置企业工具一样，利用AI系统发动攻击。例如给MCP服务器投毒，利用Claude等合法模型窃取敏感数据等。</span></p><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100069293" data-ratio="0.562962962962963" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=f03766ab&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwNc4ZukQ2klkCPicc8zGvg2Bmd0icAguDqvdMIdM8Nia7vSnBSLnMsUbNgQ9v3ozy4RtIF0veSy34Ovkonf3fYDFFf3Q36tjLmOuE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">从简单的提示词注入到“代理劫持”的转变，代表了AI威胁格局的根本性变化，攻击者不再只是试图欺骗聊天机器人，他们正在靠AI生存，滥用那些使AI助手变得有用的合法的自动化和记忆功能来攻击企业。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">以下是攻击者如何利用基于AI的服务以发起攻击的一些示例。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069294" src="https://wechat2rss.xlab.app/img-proxy/?k=56832e0a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwNmLJ52hS1bFBbZK3FCtGanvUU0QPQL25dERxPLenjtlvAicIgxjLS8qNY7SAeFSIPFnoDw8QqKO8AAor4fQ8ibaqDwBu2m9U7DE%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">1. MCP服务器</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069290" src="https://wechat2rss.xlab.app/img-proxy/?k=3b646960&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwMwCwxWQX4x7WFSxGAO3WsnaibnmQpBkibuM8qsxtgASRsaX0oAcEibEbNq5PN2rNUBXqt5VQEXt7fjnjTLHQG9JUhia96bmUu0RW4%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2025年9月，攻击者推广了一个伪造的模型上下文协议服务器，该服务器模仿了将Postmark（ActiveCampaign旗下的交易性电子邮件服务）集成到AI助手中的技术。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这个虚假的MCP服务器包看起来是合法的，并在15个版本中作为合法工具运行，直到引入了一行代码变更，导致敏感通信（密码重置、发票、内部备忘录）在被检测到之前被悄悄窃取了数天。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这个恶意包在流行的Node.js包注册表上每周吸引1500次下载，使依赖该工具的企业暴露于某种形式的供应链攻击之下。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">“这相当于AI领域的包注册表名称抢占，只是没有中央MCP机构验证服务器身份，也没有MCP服务器与其声称代表的组织之间的加密链接，”AI安全和MLOps平台Jozu的CEO Brad Micklea说。“这破坏了MCP部署前的信任模型。”</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">MCP服务器，是一种允许AI代理和聊天机器人连接到数据源、工具和其他服务，这些服务器向AI代理暴露工具、内存和API，以便它们能够执行任务，如果攻击者在该链中插入一个被投毒的工具、修改过的连接器或恶意检索源，AI代理可能会在不知情的情况下执行它。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">最近MCP服务器已成为各种持续恶意攻击的目标。锁定这些系统以最小化风险已成为企业CISO的优先事项。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069291" src="https://wechat2rss.xlab.app/img-proxy/?k=f31aadd7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwOGQG6RPWdDeUTZ0CEibiaBsPd3DiaBj2XhoO0ibn3OZ9CNbHgOPvMic96t9zxWHxnUa47KWCZ6GWqFRvtWsIktAnZTmUPVX6gEdC9M%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2. 滥用AI平台作为隐蔽的C2通道</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069292" src="https://wechat2rss.xlab.app/img-proxy/?k=5150c351&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwMQFDWumZ59iaQL0FH7yoFghq2o1EicmnRkAJHVQBAqAcicUNQYCqOqLvomic50v9iaqtP7nr74tib19bMibHeKHYeLJszxibRUXr5ZFtc%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">网络犯罪分子还通过将AI服务变成代理，将恶意流量隐藏在合法内容流中，从而滥用AI平台作为隐蔽的命令与控制通道。恶意软件不再运行专用的C2服务器，而是被编程为通过AI服务获取命令和窃取数据，在此过程中绕过传统的安全控制。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">例如，SesameOp后门将命令流量隐藏在OpenAI Assistants API中，将对恶意软件的指令伪装成正常的AI开发活动；还有Check Point Research展示了如何通过公共Web界面操纵Microsoft Copilot和Grok，使其获取攻击者控制的URL并返回响应。这种行为为滥用AI系统打开了大门，而无需API密钥或经过身份验证的账户。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069299" src="https://wechat2rss.xlab.app/img-proxy/?k=683b046c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwNZ17GdMR86NVbv9Qx8rLxwoESv6P44eUhSbXNHVe5M7Iuia2RSEJGqjGhK6AUMicEDjiaoe93RZnUKiayFv1vyw9MxQuILooeALzc%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">3. AI工作流中的依赖项投毒</span></b></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069295" src="https://wechat2rss.xlab.app/img-proxy/?k=f3b43819&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwNm5n9KcYQoKOCuQCuiaWjnSPXUm06zE2obXDvCSic3sMGqj7UOH655ENN1440Q7aEVTGlQNfCP83zxxWibQLEy8VhEgdYIduo5S8%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">一些攻击并非直接攻击AI系统，而是通过对代理进行数据处理所依赖的下游依赖项进行投毒来进行攻击。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这类似于经典的供应链攻击，但代理型管道中被投毒的依赖项不仅会泄露数据，它还可以在没有任何可见异常的情况下改变代理的决策、工具选择或输出。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069296" src="https://wechat2rss.xlab.app/img-proxy/?k=d348522d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwOYR8NJrVASM2t8Mo70XhlROeoElgY9kLBrMjj05Kt9e4ARl917mQwBUyXTJzMQAnvI83vyxu27rvGD2k7ewWtxibRf1ibyZF6Ws%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">4. 双面代理</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069297" src="https://wechat2rss.xlab.app/img-proxy/?k=d5d8b6cb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwMnjoO2ZOt711UP8ibAHiclE7oWMtbN0piawOh3bIZIcrAmGFxspUhJic7MESW10EzVWUk3av6uibYjT3bqGOFG2cjD2k7z3I7NSsds%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">还有一些攻击者不是滥用企业传统IT基础设施的组件，而是将代理中的漏洞武器化。例如，Microsoft 365 Copilot中的“EchoLeak”命令注入漏洞表明，一封带有隐藏提示词注入指令的电子邮件就足以迫使AI助手在无需用户交互的情况下将内部文件和电子邮件泄露到外部服务器。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">近期流行的“小龙虾”OpenClaw中的一系列漏洞为恶意网站完全控制开发者的AI代理创造了途径。研究人员观察发现，OpenClaw平台技能市场中12%的技能正在分发恶意软件。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Varonis的安全研究人员还发现了一种针对Microsoft Copilot Personal的攻击，只需两次请求敏感数据就能绕过内置的AI防护措施。这个“重新提示”漏洞将Microsoft Copilot变成了一个数据外泄工具。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069298" src="https://wechat2rss.xlab.app/img-proxy/?k=c4a42f9a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwNJTetYIqhicgkDtdAMy7W0LkKtiax93I9gqjibPVBytyFuHDVpjpgomMUMMGm5r08VIIibfuDpnjD94L6Ssf1r9HOmHbf8GwnU3nY%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">5. AI编排的间谍活动</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069301" src="https://wechat2rss.xlab.app/img-proxy/?k=1b90af00&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwOicHbBFdjox1rmz79XRYcbhq2bytW89UFO9eVWTHn6fc5Aar9ib0up9Kv8KAFA8l9h04JVx3TOHYZU07gI1MvVY8wdyqBz3iczV0%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2025年9月，Anthropic发现攻击者在一次网络间谍活动中滥用Claude Code来管理操作任务。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">一个代号GTG-1002的APT组织使用Claude Code独立执行了80%-90%的战术操作，攻击者将其操作分解为数千个单独无害的小任务，并结合角色扮演框架，说服模型相信自己是在进行合法的安全评估。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者滥用了Claude Code的AI代理能力，实现了脚本编写、目标研究、构建攻击工具和其他功能的自动化。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069303" src="https://wechat2rss.xlab.app/img-proxy/?k=c71b82bd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwP0A8zABEFLx0I6vt4B2XhIm6DGbmcZkbDgJC7dseNiapr1cJYX8GNC83RVT9lTGI4sJcqycM0ChlkxufZwicEtdIicXVSdgribSoE%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">6. 创建模块化的黑帽AI平台</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069300" src="https://wechat2rss.xlab.app/img-proxy/?k=f4996a52&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwP8xkXhqtQBibGa5ESY6ibv89ib62yxa3U7IqUn2szSALpb3z7vkDxJGSYtUVEeWU4rQ2r260cPCWiaYkRy3p6FVJQm6EoAPrjR0ia8%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">当前威胁格局已从滥用聊天机器人转向构建专门的、武器化的AI堆栈。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">例如Xanthorox AI，与通用LLM不同，Xanthorox是一个专门为网络犯罪设计的、从头构建的攻击性平台。该平台具有用于恶意软件生成和漏洞利用等功能模块。Hexstrike AI模型上下文协议集成使Xanthorox能够超越单纯的‘辅助’黑客行为，进入完全自主代理系统的领域，而Hexstrike只是一个开源的、AI驱动的攻击性安全框架，最初设计用于道德渗透测试。</span></p></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: stretch;flex: 0 0 auto;background-image: linear-gradient(rgb(255, 214, 125) 10%, rgba(255, 214, 125, 0) 100%);min-width: 5%;max-width: 100%;height: auto;padding: 3px 15px 13px;box-sizing: border-box;"><div style="text-align: justify;font-size: 17px;letter-spacing: 2px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">结语：</span></strong></p></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">许多攻击者不再只是利用软件漏洞，而是更倾向于利用企业对AI的信任。这意味着安全团队需要以完全相同的态度对待AI助手，就像对待人类特权用户一样：严格控制、特定监控，最重要的是，永远不要假设任何人或任何事是安全的。</span></p><div style="font-size: 12px;color: rgb(100, 100, 100);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">参考链接：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.csoonline.com/article/4154222/6-ways-attackers-abuse-ai-services-to-hack-your-business.html" target="_blank">https://www.csoonline.com/article/4154222/6-ways-attackers-abuse-ai-services-to-hack-your-business.html</a></span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 10%;max-width: 100%;height: auto;margin: 0px 10px;line-height: 0;padding: 0px;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;background-image: linear-gradient(to right, rgb(245, 245, 245) 50%, rgb(250, 228, 66) 50%);align-self: flex-start;box-sizing: border-box;"><div style="margin: 3px 0%;width: 100%;box-sizing: border-box;"><div style="font-size: 11px;color: rgb(180, 180, 180);line-height: 1;letter-spacing: 0px;padding: 0px 10px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">END</span></p></div></div></div></div></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100069305" data-ratio="0.459375" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=ef4a7d73&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwNRNKCX6r7brQiafQePS1wQ1F2wAeOPm79s9uTEl1JRxUaz0ia0riboD3jOgPKMIKqMw1iarMAibyEFol5X3sibWIbFIZs0aoiaY0FvuE%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="text-align: center;justify-content: center;margin: 10px 0px;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(249, 225, 25);text-align: justify;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">✦</span></p></div></div><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="color: rgb(100, 100, 100);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">推荐阅读</span></strong></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(249, 225, 25);text-align: right;box-sizing: border-box;"><p style="text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">✦</span></p></div></div></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247552937&amp;idx=1&amp;sn=56c9d8c1151e34a584d445fb1657487c&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/mmbiz_png/9Nf1wzzcfwP3Fibe2DOepLsOAuAwcb38td8HwZM09wEiaQH0blP6YfWgroQVS973kOiaiaqCUfpHofTib5CQY2WWYIiciaRicg95IuD1KNp5VibzlNV8/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.17833333333333334" data-s="300,640" data-type="png" data-w="1200" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069304" src="https://wechat2rss.xlab.app/img-proxy/?k=3a95af39&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwP3Fibe2DOepLsOAuAwcb38td8HwZM09wEiaQH0blP6YfWgroQVS973kOiaiaqCUfpHofTib5CQY2WWYIiciaRicg95IuD1KNp5VibzlNV8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247552906&amp;idx=1&amp;sn=b453f5cab3ff1bb1fb01a96391e9e7a5&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/mmbiz_png/9Nf1wzzcfwMibicwGYEJuAs8MYyKCXWE5dqsZoavz0c66ZXmfk5TTZlxYcibYbANg0dJ5LKGsaVXicSiaeohRV3OT3x33lPRiblDqO0YGjFXbYBxI/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.17833333333333334" data-s="300,640" data-type="png" data-w="1200" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069308" src="https://wechat2rss.xlab.app/img-proxy/?k=3846a0c0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwMibicwGYEJuAs8MYyKCXWE5dqsZoavz0c66ZXmfk5TTZlxYcibYbANg0dJ5LKGsaVXicSiaeohRV3OT3x33lPRiblDqO0YGjFXbYBxI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="text-align: center;margin: 3px 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 2px;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247552889&amp;idx=1&amp;sn=d49e2709606878b27d214e95584623ec&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/mmbiz_png/9Nf1wzzcfwNvlciaXCuITBjIYK1It8a0naALiaEuF25q1afZDOu73WxfastOClJD2HicLvofMb1JBV1Dia2n9libp9wUhavd6AZTbK29SEMN8WOc/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100069309" data-ratio="0.17833333333333334" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1200" src="https://wechat2rss.xlab.app/img-proxy/?k=07f58292&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwNvlciaXCuITBjIYK1It8a0naALiaEuF25q1afZDOu73WxfastOClJD2HicLvofMb1JBV1Dia2n9libp9wUhavd6AZTbK29SEMN8WOc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a></p></div><div style="margin: 10px 0%;text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;background-color: rgba(227, 180, 0, 0.04);align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;box-sizing: border-box;"><div data-cacheurl="" data-remoteid="" style="display: inline-block;width: 100%;vertical-align: top;background-repeat: repeat;background-attachment: scroll;padding: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;background-position: 0% 0% !important;background-size: 4.17755% !important;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=e34e6b94&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwMBFRXJCLibfiaPTptCjE8haQ3Xia7QJIzPERGia4BZumcQD2kkDYiceK0v5Ezxicia2BPJaUnr3d4lRRZjYrOmDiaEhZykuaibIbEO75r8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><div style="display: flex;flex-flow: row;margin: 20px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 30%;flex: 0 0 auto;height: auto;align-self: center;margin: 0px 0px 0px 20px;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="699" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069307" src="https://wechat2rss.xlab.app/img-proxy/?k=8d4121dd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F9Nf1wzzcfwO5NGgSvCmA3aGhBKJ31ZvJGACjjTGVqVY7ibOBIiaA1GQ3micGSCj0icF7pFJyZyG5yV691VAwheW40pyWsclupX09cINo9jGhZc4%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;margin: 0px 0px 0px 10px;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;box-sizing: border-box;"><div style="font-size: 20px;color: rgb(255, 202, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">粉丝福利群开放啦</span></strong></p></div><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(255, 202, 0);font-size: 11px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">加安全419好友进群</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">红包/书籍/礼品等不定期派送</span></p></div></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=473d7514&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDQ4OTkyMg%3D%3D%26mid%3D2247552972%26idx%3D1%26sn%3D253767a35bdb3e6e07f5a1c56736f185">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 16 Apr 2026 17:40:00 +0800</pubDate>
    </item>
    <item>
      <title>重磅发布！纵横网络靶场社区正式亮相，赋能工业信息安全人才培养与生态共建</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDQ4OTkyMg==&amp;mid=2247552972&amp;idx=2&amp;sn=8f813d12fa5959b56cdd15935f8a3e79</link>
      <description>当前工业互联网加速落地，关键基础设施安全防护要求不断升级，而实战型人才紧缺、训练场景匮乏、知识体系分散，已成为</description>
      <content:encoded><![CDATA[<p><span>安全419</span> <span>2026-04-16 17:40</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=ee5cd028&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F9Nf1wzzcfwMnV65ae96gBiaDxQCdUVWsvOLmDKdIRJnE9mbxBhpE02vrRmcKC7QJLKBpVzu7EbkLwcxFKN4jAYuLMhNjwLbcVcaUb2iamtEFQ%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <div style="font-size: 15px;letter-spacing: 1px;line-height: 2;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">当前工业互联网加速落地，关键基础设施安全防护要求不断升级，而实战型人才紧缺、训练场景匮乏、知识体系分散，已成为行业普遍面临的现实难题。“缺场地、缺经验、缺体系”，不再是行业痛点，而是每一位从业者、每一家企业都要直面的挑战。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">四月槐序，聚焦工业信息安全人才培养与生态共建的纵横网络靶场社区（以下简称社区）正式发布。烽台科技本次不只是发布一个平台，更是在搭建一座连接高校、企业与研究者的桥梁，致力于打造一个集技能培养、知识分享、人才汇聚于一体的工控安全交流平台。</span></p></div><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-shadow: rgb(100, 100, 100) 0px 0px 0px;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.45925925925925926" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069316" src="https://wechat2rss.xlab.app/img-proxy/?k=2a72c31b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwO3u2HzQlbPfCe30l7vuRFZ2X1zbaNVqaW0K4ribROUp5R5dibPxDiaXBeMfkldbom6DLEIyJH5yvYBAvaLotCl70FddN83UxQ82w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069314" src="https://wechat2rss.xlab.app/img-proxy/?k=4fef4a07&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwONjbKibh4Y9GuKXJicAHZFIoMg76EYK29VsUVTHlPjmGUf934d9l2m3WqE6ibrpUV8RRTBrz1WIicY9FfISXx44G5OwPR3ccDSAfE%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">一、开放共享，打通“学—练—测—赛”全链条</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069313" src="https://wechat2rss.xlab.app/img-proxy/?k=c4310894&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwPrQKlazWibtzhJcxIAyAzYicn12Kr5hGib1UjicNhrc1jb73Fia3wtdBzP5COujWiaqaCC9nVuJl9pzCprWkDiacIhH3brNucCbqE4B4%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">区以普及工业信息安全知识、提升行业防护能力为核心，汇聚专业力量、倡导知识共享，并通过激励机制推动成员参与安全测评与技能演练，同时持续沉淀赛事资源与竞赛场景，充分发挥“以赛促练”的长效价值，烽台科技工业靶场仿真技术（以下简称靶场）为社区提供全方位的技术支撑。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">当前工业网络安全靶场基本都是企业专用，门槛较高，学生和普通工控爱好者接触不到。而社区，就是要把“高墙里的专业工具”，变成人人免费能用、随手能练的开放平台。</span></p></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">1、实战演练场，实力练出来</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">靶场提供全行业仿真场景、数字孪生、攻防测试环境，1:1还原真实工厂里的安全风险。让社区人才有可落地、可验证、可实战的演练平台。注册用户可以直接上手做测评、练攻防，直面工控系统里各种漏洞和攻击套路，在实战中把挖漏洞、应急处理、安全防护的本事练到位。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4601851851851852" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069315" src="https://wechat2rss.xlab.app/img-proxy/?k=3e5f32be&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwMylIF5iaib4aIKrNwce4e4icdCCB8zgqGIhBd33a8mDTHJbvmqQ9AXnG82Ewgo1yTAmR4RYic28623KHHapjUBUEUice8pVBicaWvCA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">平台覆盖电力、石油石化、钢铁冶金、智能制造、城市公用事业等主流工业控制系统，紧跟技术迭代持续更新前沿安全知识库，确保训练内容与行业实践同频。</span></p><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2、开放工控爱好者与专家的交流圈</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">社区打造双向开放的技术交流平台，设有技术文档、漏洞分析、防护方案、实战经验等丰富内容版块。在里面，用户可以发布研究成果、展示技术能力，也可学习行业专家与同行经验，在交流碰撞中拓宽视野、深化能力。社区内还会组织线上线下交流活动，打破院校、企业、地域壁垒，为工控安全从业者搭建高效对话通道，助力新手快速入门、专家持续精进。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在这里，无论是初入行业的新手，还是深耕多年的专家，都能找到适合自己的成长路径。我们打破地域与企业的壁垒，希望每一位工控安全爱好者都能在开放、共享的氛围中，实现自我提升与价值创造。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069312" src="https://wechat2rss.xlab.app/img-proxy/?k=fab7ca7b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwOCUZlYjPPdhmaLvvEFxuiaIeHlGzmIicFxGvOibzXmegQGX5DS542yWanjLRoKKespXiaqiaNTJia3icffXX0sHcSEy989T1Y31YucRo%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgb(255, 228, 128);margin: 0px -11px;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 16px;padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">二、硬核技术撑腰，练得真、学得稳</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(255, 202, 0);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069319" src="https://wechat2rss.xlab.app/img-proxy/?k=b2955edc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F9Nf1wzzcfwM43IbQhxjws8PDdaGdkoTkR7EnRgp5Y74O2F0K5d04m51ia0vcwq0jqrXf8BKfwE0eN7XxK0ibTm4S1nYuSibTNE5YK5wCjmv2LU%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">烽台科技靶场，是社区的实战化场景底座，以虚实融合、全场景仿真、全流程应用为核心优势，依托云资源基础设施与工业实物仿真底座，构建多行业高仿真场景资源池，为社区汇聚安全人才、沉淀攻防能力，社区依托靶场的技术与场景支撑，实现能力落地与实战成长。</span></p><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4583333333333333" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069320" src="https://wechat2rss.xlab.app/img-proxy/?k=8fd43c27&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F9Nf1wzzcfwMDL4yicbI0KoicL4eb6MV0l6xibUVmEemLHlCENwe57Ejn4QB4hKRWFLea1J6XqNfw3zKqVicQgrQicodSuE4ibb7cDibo6IF3mKaKTU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">靶场具备全景监控、多元数据采集、业务化分析评估、可视化拓扑编排能力，可支撑测试验证、安全实训、攻防竞赛、方案孵化、风险评估等全场景应用，为工业安全能力建设、产品检测与人才培养提供一体化、可扩展、高可靠的技术支撑。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">依托该技术底座，靶场已成功支撑多行业、多级别工控安全实验室建设，并为多项国家级、省市级工业安全技能大赛提供专业技术保障。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">工业信息安全的下一步是什么？是更真实的演练场景、更完善的知识体系，还是更高效的人才成长通道？烽台科技始终相信，答案藏在开放、共享、实战、共建的每一步实践里。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">烽台科技社区的正式发布，是从“企业级专用工具”向“开放式社区平台”的一小步，也是民族企业为我国工业信息安全人才培养、实战演练、技术验证提供全新阵地一小步，但我们相信“不积跬步，无以至千里”，社区用户也许将见证并亲历着这一重要阶段的开启。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">让安全不再孤立，让实战触手可及。无论您是工控安全研究员、企业运维人员，还是对工业网络安全感兴趣的爱好者，都可以登录社区官网（www.game.fengtaisec.com）免费注册体验，欢迎各界安全人才交流互鉴，共建安全生态！</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 10%;max-width: 100%;height: auto;margin: 0px 10px;line-height: 0;padding: 0px;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;background-image: linear-gradient(to right, rgb(245, 245, 245) 50%, rgb(250, 228, 66) 50%);align-self: flex-start;box-sizing: border-box;"><div style="margin: 3px 0%;width: 100%;box-sizing: border-box;"><div style="font-size: 11px;color: rgb(180, 180, 180);line-height: 1;letter-spacing: 0px;padding: 0px 10px;width: 100%;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">END</span></p></div></div></div></div></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.459375" data-s="300,640" data-type="gif" data-w="640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069321" src="https://wechat2rss.xlab.app/img-proxy/?k=5c4d9425&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2F9Nf1wzzcfwPLMicaHLFGgM151gCO6zMCOFicUs9ibJQrOSLcaw7pCxsrmncuibwiarf8o1cKSjdKtRuMJgR8PVN1icib9Y3xw0mQTQkDicTZhQRPSfs%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="margin: 10px 0%;text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;background-color: rgba(227, 180, 0, 0.04);align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;box-sizing: border-box;"><div data-cacheurl="" data-remoteid="" style="display: inline-block;width: 100%;vertical-align: top;background-repeat: repeat;background-attachment: scroll;padding: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;background-position: 0% 0% !important;background-size: 4.17755% !important;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=64a81630&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F9Nf1wzzcfwN6tPWvKibB1d0RlCFibhf6q2OWZ95yhPAVhia0fcugjJ9o83IxEd6lQTas7LVM21bOy3ZEQ1XsdtssY0j9EttPHIfdESWqYpYaf4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><div style="display: flex;flex-flow: row;margin: 20px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 30%;flex: 0 0 auto;height: auto;align-self: center;margin: 0px 0px 0px 20px;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="699" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100069318" src="https://wechat2rss.xlab.app/img-proxy/?k=8b1ca1fe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F9Nf1wzzcfwNopDUicd2apSrDKfj1gkmr2nNiaa4qPYibgJhic9dWf8DmvG8JOMjT5peJrNSxhWbKXgIIyABBSiboetgyictgH10M0Tt1wU8S1u2Bw%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;margin: 0px 0px 0px 10px;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;box-sizing: border-box;"><div style="font-size: 20px;color: rgb(255, 202, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">粉丝福利群开放啦</span></strong></p></div><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(255, 202, 0);font-size: 11px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">加安全419好友进群</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">红包/书籍/礼品等不定期派送</span></p></div></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=cd09e84c&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDQ4OTkyMg%3D%3D%26mid%3D2247552972%26idx%3D2%26sn%3D8f813d12fa5959b56cdd15935f8a3e79">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 16 Apr 2026 17:40:00 +0800</pubDate>
    </item>
  </channel>
</rss>