AiRedTeam

安全情报

The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration

📡 Palo Alto Unit42 · 2026-06-22 The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Threat Research Cloud Cybersecurity Research Cloud Cybersecurity Research The Global
阅读时间 16 分钟
安全情报

📊 2026-07-08 漏洞情报日报 · 200 条 · 高危 91

每日漏洞情报汇总 · 2026-07-08 📊 2026-07-08 漏洞情报日报 📋 共 200 条 🔥 高危/严重 91 条 🚨 CISA-KEV 4 条 💣 Exploit-DB-RSS 8 条 🔥2 🐙 GitHub-Advisory 74 条 🔥35 🛡️ NVD-Latest 54 条 🔥54 ⚔️ Sploitus 60 条 🤖 今日安全态势分析 🎯 今日重点关注 * Apache Camel 多组件高危链 (CVE-2026-56140, CVE-2026-53913, CVE-2026-48204 等): 今日集中披露7个CVSS 9.8的严重漏洞,覆盖AWS SNS/SQS、Keycloak、MongoDB Gridfs等多个组件。攻击者可通过输入验证缺陷或认证绕过,远程执行代码或窃取凭据,利用难度低,
阅读时间 21 分钟
安全情报

CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure

📡 Palo Alto Unit42 · 2026-06-25 CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Threat Research Malware Malware CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure 10 min read Related Products Advanced
阅读时间 13 分钟
安全情报

Threat Brief: Mitigating Large-Scale Credential Attacks

📡 Palo Alto Unit42 · 2026-06-26 Threat Brief: Mitigating Large-Scale Credential Attacks Threat Brief: Mitigating Large-Scale Credential Attacks Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center High Profile Threats General General Threat Brief: Mitigating Large-Scale Credential Attacks 5 min read Related Products Next-Generation Firewall Unit 42 Incident Response
阅读时间 8 分钟
安全情报

Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector

📡 Palo Alto Unit42 · 2026-07-01 Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Threat Research Malware Malware Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector
阅读时间 24 分钟
安全情报

A VBScript campaign distributed through WhatsApp deploying RMM software

📡 Kaspersky Securelist · 2026-06-22 A VBScript campaign distributed through WhatsApp deploying RMM software An unknown actor distributes malicious VBS scripts via WhatsApp | Securelist Solutions for: Home Products Small Business 1-50 employees Medium Business 51-999 employees Enterprise 1000+ employees by Kaspersky CompanyAccount Get In Touch Dark mode off English Russian Spanish Brazil
阅读时间 15 分钟
安全情报

StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader

📡 Kaspersky Securelist · 2026-06-24 StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader StrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike Beacon | Securelist Solutions for: Home Products Small Business 1-50 employees Medium Business 51-999 employees Enterprise 1000+ employees by Kaspersky CompanyAccount Get In Touch Dark mode off
阅读时间 25 分钟
安全情报

Beware of the license manager: how a Schneider Electric software vulnerability puts industrial facilities at risk

📡 Kaspersky Securelist · 2026-06-26 Beware of the license manager: how a Schneider Electric software vulnerability puts industrial facilities at risk CVE-2024-2658 vulnerability in Schneider Electric software: risks to industrial control systems | Securelist Solutions for: Home Products Small Business 1-50 employees Medium Business 51-999 employees Enterprise 1000+ employees by Kaspersky CompanyAccount Get
阅读时间 11 分钟
安全情报

📊 2026-07-07 漏洞情报日报 · 200 条 · 高危 97

每日漏洞情报汇总 · 2026-07-07 📊 2026-07-07 漏洞情报日报 📋 共 200 条 🔥 高危/严重 97 条 💣 Exploit-DB-RSS 7 条 🐙 GitHub-Advisory 50 条 🔥25 🛡️ NVD-Latest 72 条 🔥72 ⚔️ Sploitus 71 条 🤖 今日安全态势分析 🎯 今日重点关注 * CVE-2026-53486 (Critical):影响 Decompress 库(Tar/Zip 等多种格式)。漏洞存在于解压写入文件逻辑中,构造的恶意压缩包可导致目录穿越,实现越界写入或读取任意文件。 * CVE-2026-54769、CVE-2026-55615、CVE-2026-54760 (Critical):影响 Langroid 框架。SQLChatAgent 与 Neo4jChatAgent 因正则绕过或无验证执行,导致
阅读时间 22 分钟
APT情报

装甲狼人APT组织利用AI生成载荷,BusySnake窃密木马瞄准全球政府与能源

卡巴斯基发现Armored Likho(装甲狼人)APT组织使用AI生成载荷和BusySnake窃密木马,针对俄罗斯、巴西、哈萨克斯坦政府及电力行业。该攻击链利用GitHub托管恶意模块,通过NSIS自解压和LNK文件实现初始感染,最终窃取浏览器凭证并建立反向SSH隧道。本文深度分析攻击手法、IOC及缓解措施。
阅读时间 3 分钟
[!] CONTACT_CHANNELS

如需商务合作、技术咨询或漏洞反馈,请通过以下离岸节点联系作者。

> PING_AUTHOR (@A1RedTeam)