往事不回首,安全不停步。AiRedTeam 的安全随笔,记录那些与代码和漏洞博弈的深夜。代码为剑,漏洞为砺,守一方数字净土。以此笔墨,化作守望万物的白泽。

安全情报

CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure

📡 Palo Alto Unit42 · 2026-06-25 CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Threat Research Malware Malware CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure 10 min read Related Products Advanced
阅读时间 13 分钟
安全情报

Threat Brief: Mitigating Large-Scale Credential Attacks

📡 Palo Alto Unit42 · 2026-06-26 Threat Brief: Mitigating Large-Scale Credential Attacks Threat Brief: Mitigating Large-Scale Credential Attacks Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center High Profile Threats General General Threat Brief: Mitigating Large-Scale Credential Attacks 5 min read Related Products Next-Generation Firewall Unit 42 Incident Response
阅读时间 8 分钟
安全情报

Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector

📡 Palo Alto Unit42 · 2026-07-01 Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Threat Research Malware Malware Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector
阅读时间 24 分钟
安全情报

A VBScript campaign distributed through WhatsApp deploying RMM software

📡 Kaspersky Securelist · 2026-06-22 A VBScript campaign distributed through WhatsApp deploying RMM software An unknown actor distributes malicious VBS scripts via WhatsApp | Securelist Solutions for: Home Products Small Business 1-50 employees Medium Business 51-999 employees Enterprise 1000+ employees by Kaspersky CompanyAccount Get In Touch Dark mode off English Russian Spanish Brazil
阅读时间 15 分钟
安全情报

StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader

📡 Kaspersky Securelist · 2026-06-24 StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader StrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike Beacon | Securelist Solutions for: Home Products Small Business 1-50 employees Medium Business 51-999 employees Enterprise 1000+ employees by Kaspersky CompanyAccount Get In Touch Dark mode off
阅读时间 25 分钟
安全情报

Beware of the license manager: how a Schneider Electric software vulnerability puts industrial facilities at risk

📡 Kaspersky Securelist · 2026-06-26 Beware of the license manager: how a Schneider Electric software vulnerability puts industrial facilities at risk CVE-2024-2658 vulnerability in Schneider Electric software: risks to industrial control systems | Securelist Solutions for: Home Products Small Business 1-50 employees Medium Business 51-999 employees Enterprise 1000+ employees by Kaspersky CompanyAccount Get
阅读时间 11 分钟
安全情报

📊 2026-07-07 漏洞情报日报 · 200 条 · 高危 97

每日漏洞情报汇总 · 2026-07-07 📊 2026-07-07 漏洞情报日报 📋 共 200 条 🔥 高危/严重 97 条 💣 Exploit-DB-RSS 7 条 🐙 GitHub-Advisory 50 条 🔥25 🛡️ NVD-Latest 72 条 🔥72 ⚔️ Sploitus 71 条 🤖 今日安全态势分析 🎯 今日重点关注 * CVE-2026-53486 (Critical):影响 Decompress 库(Tar/Zip 等多种格式)。漏洞存在于解压写入文件逻辑中,构造的恶意压缩包可导致目录穿越,实现越界写入或读取任意文件。 * CVE-2026-54769、CVE-2026-55615、CVE-2026-54760 (Critical):影响 Langroid 框架。SQLChatAgent 与 Neo4jChatAgent 因正则绕过或无验证执行,导致
阅读时间 22 分钟
APT情报

装甲狼人APT组织利用AI生成载荷,BusySnake窃密木马瞄准全球政府与能源

卡巴斯基发现Armored Likho(装甲狼人)APT组织使用AI生成载荷和BusySnake窃密木马,针对俄罗斯、巴西、哈萨克斯坦政府及电力行业。该攻击链利用GitHub托管恶意模块,通过NSIS自解压和LNK文件实现初始感染,最终窃取浏览器凭证并建立反向SSH隧道。本文深度分析攻击手法、IOC及缓解措施。
阅读时间 3 分钟
安全情报

The SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaign

📡 Kaspersky Securelist · 2026-07-01 The SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaign How a single ScreenConnect incident exposed a massive campaign | Securelist Solutions for: Home Products Small Business 1-50 employees Medium Business 51-999 employees Enterprise 1000+ employees by Kaspersky CompanyAccount Get In Touch Dark mode
阅读时间 19 分钟
安全情报

Missed incidents, persistent threats, and response gaps: Insights from compromise assessment projects

📡 Kaspersky Securelist · 2026-07-02 Missed incidents, persistent threats, and response gaps: Insights from compromise assessment projects How to improve your organization’s security based on compromise assessment findings | Securelist Solutions for: Home Products Small Business 1-50 employees Medium Business 51-999 employees Enterprise 1000+ employees by Kaspersky CompanyAccount Get In Touch Dark
阅读时间 32 分钟
安全情报

Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign

📡 Kaspersky Securelist · 2026-07-03 Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign Armored Likho’s new weapon: BusySnake Stealer | Securelist Solutions for: Home Products Small Business 1-50 employees Medium Business 51-999 employees Enterprise 1000+ employees by Kaspersky CompanyAccount Get In Touch Dark mode off English Russian Spanish
阅读时间 22 分钟
安全情报

📊 2026-07-06 漏洞情报日报 · 200 条 · 高危 119

每日漏洞情报汇总 · 2026-07-06 📊 2026-07-06 漏洞情报日报 📋 共 200 条 🔥 高危/严重 119 条 🛡️ NVD-Latest 119 条 🔥119 ⚔️ Sploitus 81 条 🤖 今日安全态势分析 🎯 今日重点关注 * CVE-2026-13768 (CVSS 10.0) - Gardyn 智能花园设备:暴露了高权限的 IoTHub 所有者密钥,攻击者利用该密钥可调用 IoTHub 注册表管理功能,获取所有 Gardyn Home Kit 及 Studio 设备的连接信息,进而实施远程代码执行与内网横向移动。PoC 已公开,利用条件极低。 * CVE-2026-27419 (CVSS 9.9) - Zegen
阅读时间 24 分钟
APT情报

潜伏四年未察觉:2025年入侵评估揭示的安全盲区与响应鸿沟

卡巴斯基2025年入侵评估报告揭示:企业安全防御存在严重盲区,60%的入侵事件因缺乏高置信度告警而被遗漏,攻击者利用LoLBins和远程管理工具长期潜伏,平均超3个月才被发现。缺乏持续监控和威胁狩猎的企业,高/中危事件概率高达84-86%。报告强调定期入侵评估、备份安全审查和事件响应预案更新的重要性,为安全团队提供了从被动防御转向主动狩猎的关键洞察。
阅读时间 4 分钟
[!] CONTACT_CHANNELS

如需商务合作、技术咨询或漏洞反馈,请通过以下离岸节点联系作者。

> PING_AUTHOR (@A1RedTeam)