<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	 xmlns:media="http://search.yahoo.com/mrss/" >

<channel>
	<title>研究 &#8211; PSA.NGO</title>
	<atom:link href="https://psa.ngo/news/category/research/feed/" rel="self" type="application/rss+xml" />
	<link>https://psa.ngo</link>
	<description>关注数字隐私、信息安全、知识可及性</description>
	<lastBuildDate>Thu, 11 Jun 2026 18:11:06 +0000</lastBuildDate>
	<language>zh-Hans</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://psa.ngo/wp-content/uploads/2024/07/PSA-icon-150x150.png</url>
	<title>研究 &#8211; PSA.NGO</title>
	<link>https://psa.ngo</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>与研究员交锋加剧，Microsoft在补丁日修复其曝出的两枚高危0-day</title>
		<link>https://psa.ngo/news/microsoft-patches-two-zero-days-amid-rift-with-nightmare-eclipse/</link>
		
		<dc:creator><![CDATA[psa]]></dc:creator>
		<pubDate>Thu, 11 Jun 2026 18:11:06 +0000</pubDate>
				<category><![CDATA[信息安全]]></category>
		<category><![CDATA[研究]]></category>
		<category><![CDATA[科技公司]]></category>
		<guid isPermaLink="false">https://psa.ngo/news/microsoft-patches-two-zero-days-amid-rift-with-nightmare-eclipse/</guid>

					<description><![CDATA[据报道，Microsoft在本周二的例行更新中发布修复，堵住两枚由安全研究员Nightmare Eclipse [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>据<a href="https://arstechnica.com/security/2026/06/locked-in-heated-rivalry-with-researcher-microsoft-fixes-0-day-they-disclosed/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">报道<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a>，Microsoft在本周二的例行更新中发布修复，堵住两枚由安全研究员Nightmare Eclipse披露的高危零日漏洞；此前双方因漏洞处置安排产生激烈摩擦。</p>
<p>报道提到，Nightmare Eclipse近月来接连公开数个高危缺陷并附上概念验证代码，使其在未修补前即构成“零日”。该研究员称，之所以选择公开，是因为Microsoft违背了双方就相关漏洞沟通时达成的一项安排。</p>
<p>此外，文中还称，另一枚同样由Nightmare Eclipse披露的零日似乎也已获得修补，但更多技术细节与影响范围仍有待厂商与平台进一步披露与确认。</p>
<p><a href="https://arstechnica.com/security/2026/06/locked-in-heated-rivalry-with-researcher-microsoft-fixes-0-day-they-disclosed/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">来源<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>EFF质疑以薄弱证据推动全美未成年人社媒禁令的立法冲动</title>
		<link>https://psa.ngo/news/eff-questions-evidence-behind-us-youth-social-media-bans/</link>
		
		<dc:creator><![CDATA[psa]]></dc:creator>
		<pubDate>Thu, 14 May 2026 15:11:56 +0000</pubDate>
				<category><![CDATA[可及性]]></category>
		<category><![CDATA[政治]]></category>
		<category><![CDATA[研究]]></category>
		<category><![CDATA[隐私]]></category>
		<guid isPermaLink="false">https://psa.ngo/news/eff-questions-evidence-behind-us-youth-social-media-bans/</guid>

					<description><![CDATA[数字权利组织Electronic Frontier Foundation（EFF）发布的Deeplinks博文 [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>数字权利组织Electronic Frontier Foundation（EFF）发布的<a href="https://www.eff.org/deeplinks/2026/05/science-not-settled-how-weak-evidence-fueling-national-push-ban-social-media-youth" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">Deeplinks博文<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a>指出，随着各州进入2026年立法季，从California State Assembly到Massachusetts与Minnesota，多项针对未成年人社交媒体使用的法案迅速推进，支持者将其描绘为应对“公共卫生流行病”或“心理健康危机”的举措，但相关科学证据远未定论。 </p>
<p>文章作者Rindala Alajaji（5月13日）强调，EFF虽非社会科学机构，但对现有研究的审阅显示，未成年人与社交媒体之间的关联更为复杂，尚不足以支撑大规模剥夺言论自由与隐私等宪法权利的立法。EFF称，将全面封禁或严限访问正当的数字平台，更多依赖“流行心理学”式叙事与统计缺陷明显的研究，不符合谨慎立法所需的严密标准；所谓“青少年大脑被社交媒体重塑”的单一因果说法，经更广泛学界检视并不成立。 </p>
<p>EFF提醒立法者，未成年人在原则上享有与成年人近似的表达与隐私权，并呼吁就社交媒体影响进行更严谨、可复制的研究与有针对性的政策，而非以仓促立法扩张监控和审查，伤及知识获取与基本自由。</p>
<p><a href="https://www.eff.org/deeplinks/2026/05/science-not-settled-how-weak-evidence-fueling-national-push-ban-social-media-youth" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">来源<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Anthropic推送“Mythos”预览版掀起网络安全争议：自称可自动挖洞写利用，业内警钟与质疑并存</title>
		<link>https://psa.ngo/news/anthropic-mythos-preview-cybersecurity-reckoning-claims-and-debate/</link>
		
		<dc:creator><![CDATA[psa]]></dc:creator>
		<pubDate>Sun, 12 Apr 2026 13:11:38 +0000</pubDate>
				<category><![CDATA[信息安全]]></category>
		<category><![CDATA[研究]]></category>
		<category><![CDATA[科技公司]]></category>
		<guid isPermaLink="false">https://psa.ngo/news/anthropic-mythos-preview-cybersecurity-reckoning-claims-and-debate/</guid>

					<description><![CDATA[据WIRED报道，Anthropic本周称其新模型“Claude Mythos Preview”的亮相标志着网 [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>据<a href="https://www.wired.com/story/anthropics-mythos-will-force-a-cybersecurity-reckoning-just-not-the-one-you-think/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">WIRED报道<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a>，Anthropic本周称其新模型“Claude Mythos Preview”的亮相标志着网络安全发展的关键节点，对现有软件防御策略构成“前所未有的生存级威胁”。这一表述迅速引发热议：究竟是又一轮AI炒作，还是行业真正的转折点？</p>
<p>Anthropic表示，Mythos Preview的能力已跨越门槛，几乎可在各类操作系统、浏览器及其他软件中发现漏洞，并能自主产出可用的攻击利用代码。基于潜在风险，公司目前仅将其提供给数十家机构试用，其中包括Microsoft、Apple、Google与Linux Foundation，并以“Project Glasswing”名义开展合作。</p>
<p>消息公布后，安全圈出现分歧。有声音对厂商说法持怀疑态度，也有专家将此视为对开发者的警示：长期把安全置于次要位置的做法，或将难以抵御新一代模型带来的攻防压力。</p>
<p><a href="https://www.wired.com/story/anthropics-mythos-will-force-a-cybersecurity-reckoning-just-not-the-one-you-think/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">来源<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>字体渲染新技法或可绕过AI检测，恶意指令被“隐身”</title>
		<link>https://psa.ngo/news/font-rendering-trick-bypasses-ai-detection-conceals-malicious-commands/</link>
		
		<dc:creator><![CDATA[psa]]></dc:creator>
		<pubDate>Wed, 18 Mar 2026 15:11:46 +0000</pubDate>
				<category><![CDATA[信息安全]]></category>
		<category><![CDATA[研究]]></category>
		<guid isPermaLink="false">https://psa.ngo/news/font-rendering-trick-bypasses-ai-detection-conceals-malicious-commands/</guid>

					<description><![CDATA[据BleepingComputer报道，安全研究者展示了一种利用字体渲染差异的混淆手法：文本在用户端可正常阅读 [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>据<a href="https://www.bleepingcomputer.com/news/security/new-font-rendering-trick-hides-malicious-commands-from-ai-tools/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">BleepingComputer报道<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a>，安全研究者展示了一种利用字体渲染差异的混淆手法：文本在用户端可正常阅读，但基于AI的检测、过滤或审计工具可能读取到另一套字符序列，从而遗漏被隐藏的恶意命令或触发“看不见”的指令。</p>
<p>报道指向的技术思路与对抗样本类似，核心在于操控字符呈现与模型解析之间的偏差，使“人眼所见”与“模型所读”分离。目前公开信息有限，关键实现细节、影响范围与权威缓解指引尚未完全披露，相关风险评估仍在推进中。</p>
<p>业内建议，短期内对依赖AI进行邮件审查、代码审计与内容审核的流程采取保守措施，如人机双重复核、限制可疑字体与样式渲染、在受控沙箱中执行自动化操作并最小化权限，同时关注后续技术通报与补丁更新。更多背景可见上述<a href="https://www.bleepingcomputer.com/news/security/new-font-rendering-trick-hides-malicious-commands-from-ai-tools/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">BleepingComputer报道<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a>。</p>
<p><a href="https://www.bleepingcomputer.com/news/security/new-font-rendering-trick-hides-malicious-commands-from-ai-tools/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">来源<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Google称去年有90个零日漏洞遭在野利用</title>
		<link>https://psa.ngo/news/google-says-90-zero-days-exploited-last-year/</link>
		
		<dc:creator><![CDATA[psa]]></dc:creator>
		<pubDate>Fri, 06 Mar 2026 21:11:31 +0000</pubDate>
				<category><![CDATA[信息安全]]></category>
		<category><![CDATA[研究]]></category>
		<category><![CDATA[科技公司]]></category>
		<guid isPermaLink="false">https://psa.ngo/news/google-says-90-zero-days-exploited-last-year/</guid>

					<description><![CDATA[据报道，Google发布最新统计称，去年共有90个零日漏洞在实际攻击中被利用，凸显零日利用威胁仍处高位、软件生 [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>据<a href="https://www.bleepingcomputer.com/news/security/google-says-90-zero-days-were-exploited-in-attacks-last-year/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">报道<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a>，Google发布最新统计称，去年共有90个零日漏洞在实际攻击中被利用，凸显零日利用威胁仍处高位、软件生态对及时修复与防护的持续依赖。</p>
<p>报道未在摘要中披露更详尽的分类或产品分布信息。业内人士提醒，机构与个人应持续更新系统、关注官方通告并尽快应用安全补丁，以降低暴露面与被攻破风险。</p>
<p><a href="https://www.bleepingcomputer.com/news/security/google-says-90-zero-days-were-exploited-in-attacks-last-year/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">来源<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>短命的AI窃密工具“Arkanix Stealer”曝出又匿迹</title>
		<link>https://psa.ngo/news/arkanix-stealer-ai-infostealer-short-lived-experiment/</link>
		
		<dc:creator><![CDATA[psa]]></dc:creator>
		<pubDate>Tue, 24 Feb 2026 04:11:36 +0000</pubDate>
				<category><![CDATA[信息安全]]></category>
		<category><![CDATA[研究]]></category>
		<guid isPermaLink="false">https://psa.ngo/news/arkanix-stealer-ai-infostealer-short-lived-experiment/</guid>

					<description><![CDATA[安全研究圈近日注意到，一款以AI为卖点的信息窃取器Arkanix Stealer短暂现身。 据Bleeping [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>安全研究圈近日注意到，一款以AI为卖点的信息窃取器Arkanix Stealer短暂现身。 据<a href="https://www.bleepingcomputer.com/news/security/arkanix-stealer-pops-up-as-short-lived-ai-info-stealer-experiment/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">BleepingComputer报道<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a>，该项目被形容为一次“短期实验”，出现时间不长便偃旗息鼓，相关发布渠道已下线或停止更新。</p>
<p>目前公开信息有限，尚难确认其具体窃取能力、传播路径以及是否造成实际入侵或数据损失。业内提醒，攻击者正频繁以“AI”概念包装传统信息窃取器，安全团队应加强对异常账户登录、浏览器数据外流及凭证窃取迹象的检测与响应。</p>
<p>事件仍在发展中，更多技术细节与溯源信息有待披露。</p>
<p><a href="https://www.bleepingcomputer.com/news/security/arkanix-stealer-pops-up-as-short-lived-ai-info-stealer-experiment/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">来源<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>研究警示：AI平台或被滥用于隐蔽恶意通信</title>
		<link>https://psa.ngo/news/ai-platforms-abused-for-stealthy-malware-communication/</link>
		
		<dc:creator><![CDATA[psa]]></dc:creator>
		<pubDate>Fri, 20 Feb 2026 11:11:31 +0000</pubDate>
				<category><![CDATA[信息安全]]></category>
		<category><![CDATA[研究]]></category>
		<guid isPermaLink="false">https://psa.ngo/news/ai-platforms-abused-for-stealthy-malware-communication/</guid>

					<description><![CDATA[据BleepingComputer报道，安全研究者指出，通用AI平台可能被不法分子用作恶意软件与其控制端之间的 [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>据<a href="https://www.bleepingcomputer.com/news/security/ai-platforms-can-be-abused-for-stealthy-malware-communication/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">BleepingComputer<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a>报道，安全研究者指出，通用AI平台可能被不法分子用作恶意软件与其控制端之间的隐蔽通信通道，通过将指令或数据伪装为正常的AI交互，以规避部分传统检测与阻断措施。报道提醒平台方与使用者需关注相关滥用迹象并加强监测。</p>
<p>目前报道未披露具体在野活动规模或受影响平台清单。安全专家建议组织审视与AI服务相关的网络访问策略，记录并分析异常调用模式，关注平台发布的反滥用更新与最佳实践，以降低潜在风险。</p>
<p><a href="https://www.bleepingcomputer.com/news/security/ai-platforms-can-be-abused-for-stealthy-malware-communication/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">来源<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>NRO解密冷战高轨监听计划Jumpseat：曾在北极上空长期窃听</title>
		<link>https://psa.ngo/news/nro-declassifies-jumpseat-cold-war-listening-post/</link>
		
		<dc:creator><![CDATA[psa]]></dc:creator>
		<pubDate>Thu, 05 Feb 2026 03:11:39 +0000</pubDate>
				<category><![CDATA[信息安全]]></category>
		<category><![CDATA[政治]]></category>
		<category><![CDATA[研究]]></category>
		<guid isPermaLink="false">https://psa.ngo/news/nro-declassifies-jumpseat-cold-war-listening-post/</guid>

					<description><![CDATA[美国情报卫星机构National Reconnaissance Office（NRO）宣布解密一项冷战时期的监 [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>美国情报卫星机构National Reconnaissance Office（NRO）宣布<a href="https://arstechnica.com/space/2026/01/us-spy-satellite-agency-declassifies-high-flying-cold-war-listening-post/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">解密<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a>一项冷战时期的监听计划Jumpseat，确认该项目用于截获Soviet Union的军用通信信号。</p>
<p>根据NRO公开的材料，Jumpseat属于美国第一代高度椭圆轨道（HEO）信号情报平台，卫星曾在北极一带“盘旋”以覆盖高纬度区域，对Soviet Union实施侦收。此次解密不仅给出项目的用途与研制脉络，还发布了卫星外观图片；在此之前，Jumpseat虽已因泄露与当时媒体报道而为外界所知，但官方细节从未系统披露。</p>
<p><a href="https://arstechnica.com/space/2026/01/us-spy-satellite-agency-declassifies-high-flying-cold-war-listening-post/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">来源<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Pwn2Own Automotive次日爆发：研究团队连破29个零日漏洞</title>
		<link>https://psa.ngo/news/pwn2own-automotive-day-2-29-zero-days/</link>
		
		<dc:creator><![CDATA[psa]]></dc:creator>
		<pubDate>Fri, 23 Jan 2026 06:11:10 +0000</pubDate>
				<category><![CDATA[信息安全]]></category>
		<category><![CDATA[研究]]></category>
		<guid isPermaLink="false">https://psa.ngo/news/pwn2own-automotive-day-2-29-zero-days/</guid>

					<description><![CDATA[据报道，年度汽车安全竞赛Pwn2Own Automotive第二个比赛日，参赛团队现场成功演示利用29个此前未 [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>据<a href="https://www.bleepingcomputer.com/news/security/hackers-exploit-29-zero-day-vulnerabilities-on-second-day-of-pwn2own-automotive/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">报道<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a>，年度汽车安全竞赛<a href="https://www.bleepingcomputer.com/news/security/hackers-exploit-29-zero-day-vulnerabilities-on-second-day-of-pwn2own-automotive/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">Pwn2Own Automotive<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a>第二个比赛日，参赛团队现场成功演示利用29个此前未知的零日漏洞。赛事组织方按既定流程将问题通报相关厂商，细节将在修复窗口后披露。</p>
<p>本次集中“爆零”的表现，再次凸显车载数字化生态的攻击面正在快速扩大。业内人士指出，随着联网与自动驾驶功能普及，建立更完善的漏洞响应与安全基线已成当务之急。</p>
<p><a href="https://www.bleepingcomputer.com/news/security/hackers-exploit-29-zero-day-vulnerabilities-on-second-day-of-pwn2own-automotive/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">来源<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>EPIC报告：监控与ICE执法正让患者远离就医，健康隐私陷入危机</title>
		<link>https://psa.ngo/news/epic-report-surveillance-and-ice-drive-patients-away-from-care/</link>
		
		<dc:creator><![CDATA[psa]]></dc:creator>
		<pubDate>Thu, 22 Jan 2026 10:11:27 +0000</pubDate>
				<category><![CDATA[信息安全]]></category>
		<category><![CDATA[政治]]></category>
		<category><![CDATA[研究]]></category>
		<category><![CDATA[隐私]]></category>
		<guid isPermaLink="false">https://psa.ngo/news/epic-report-surveillance-and-ice-drive-patients-away-from-care/</guid>

					<description><![CDATA[一份由Electronic Privacy Information Center (EPIC)发布、并被媒体披 [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>一份由Electronic Privacy Information Center (EPIC)发布、并被媒体披露的<a href="https://www.wired.com/story/surveillance-and-ice-are-driving-patients-away-from-medical-care-report-warns/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">新报告<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a>警告称，在美国，数据经纪与广告科技监测的蔓延，以及ICE在医院的执法行动，正共同引发“健康隐私危机”，侵蚀公众对医疗体系的信任，使患者因担忧隐私暴露而延迟或回避治疗，最终恶化健康结果。</p>
<p>报告指出，过时的隐私法规与快速扩张的数字化系统，使与健康相关的信息更易被跟踪、分析、泄露，并被私人公司和政府机构获取；而对执法边界的约束不足，进一步放大了风险。EPIC称，其结论基于对联邦与州法律、法院裁决、政府机构政策、技术研究以及案例材料的综合审视，聚焦健康数据如何被收集、共享与使用的链路与后果。</p>
<p><a href="https://www.wired.com/story/surveillance-and-ice-are-driving-patients-away-from-medical-care-report-warns/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">来源<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
