安全情报

A collection of 572 posts
安全情报

Progress ShareFile曝新漏洞 可组合实现未认证远程代码执行

📡 4hou · 2026-04-10 Progress ShareFile曝新漏洞 可组合实现未认证远程代码执行 CVE-2026-2699CVE-2026-2701 Progress ShareFile曝新漏洞 可组合实现未认证远程代码执行 导语:由于系统对 HTTP 重定向处理不当,攻击者可直接访问 ShareFile 管理后台界面。 最新发现,企业级安全文件传输解决方案 Progress ShareFile 存在两处漏洞,攻击者可将其组合利用,在无需身份认证的情况下从受影响环境中窃取文件。Progress ShareFile 是一款文档共享与协作产品,广泛应用于大中型企业。 此类文件传输平台历来是勒索软件团伙的重点攻击目标,此前 Clop 勒索组织就曾利用 Accellion FTA、SolarWinds Serv-U、Gladinet CentreStack、GoAnywhere MFT、MOVEit Transfer、Cleo 等产品中的漏洞实施大规模数据窃取攻击。 watchTowr 的研究人员在 Progress ShareFile
阅读时间 3 分钟
安全情报

📊 2026-05-21 漏洞情报日报 · 200 条 · 高危 99

每日漏洞情报汇总 · 2026-05-21 📊 2026-05-21 漏洞情报日报 📋 共 200 条 🔥 高危/严重 99 条 🚨 CISA-KEV 7 条 🐙 GitHub-Advisory 67 条 🔥33 🛡️ NVD-Latest 66 条 🔥66 ⚔️ Sploitus 60 条 🤖 今日安全态势分析 🎯 今日重点关注 * CVE-2026-46421 及 @beproduct/nestjs-auth 恶意包事件:影响 @cap-js/* 系列库及 npm 生态。攻击者通过泄露的发布令牌(Token)植入恶意代码,窃取凭证并自我复制。属于供应链投毒(Supply Chain Compromise),利用条件为零,已安装受影响版本的开发环境将被直接感染。 * CVE-2026-43633 (CVSS 10.
阅读时间 23 分钟
安全情报

Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure

📡 Palo Alto Unit42 · 2026-03-31 Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure CVE-2025-55182 Executive Summary Between late February and March 2026, threat group TeamPCP conducted a highly calculated, escalating sequence of supply chain threats. It systematically compromised widely trusted open-source security tools, including the vulnerability scanners
阅读时间 14 分钟
安全情报

📊 2026-05-20 漏洞情报日报 · 200 条 · 高危 89

每日漏洞情报汇总 · 2026-05-20 📊 2026-05-20 漏洞情报日报 📋 共 200 条 🔥 高危/严重 89 条 🐙 GitHub-Advisory 100 条 🔥49 🛡️ NVD-Latest 40 条 🔥40 ⚔️ Sploitus 60 条 🤖 今日安全态势分析 🎯 今日重点关注 * CVE-2026-45695 (Kopia): 备份工具Kopia的HTTP服务在未设置密码时,攻击者可通过构造恶意的SFTP存储配置,触发SSH ProxyCommand注入,实现远程代码执行(RCE)。利用条件:服务以--without-password参数启动且暴露于网络。 * CVE-2026-46339 (9router): 路由器软件9router的两个未认证API端点可被组合利用,允许网络邻近的攻击者在无需任何凭据的前提下,以进程权限执行任意操作系统命令,风险极高。 * CVE-2026-42822 (Azure Local): Microsoft Azure Local在断网操作模式下存在身份验证缺陷(CV
阅读时间 20 分钟
安全情报

Strengthening supply chain security: Preparing for the next malware campaign

📡 GitHub Security Lab · 0 Strengthening supply chain security: Preparing for the next malware campaign The open source ecosystem continues to face organized, adaptive supply chain threats that spread through compromised credentials and malicious package lifecycle scripts. The most recent example is the multi-wave Shai-Hulud campaign. While individual incidents differ in
阅读时间 4 分钟
安全情报

📊 2026-05-19 漏洞情报日报 · 200 条 · 高危 89

每日漏洞情报汇总 · 2026-05-19 📊 2026-05-19 漏洞情报日报 📋 共 200 条 🔥 高危/严重 89 条 🐙 GitHub-Advisory 50 条 🔥24 🛡️ NVD-Latest 65 条 🔥65 ⚔️ Sploitus 85 条 🤖 今日安全态势分析 🎯 今日重点关注 * CVE-2026-45697 (Formie) - 服务端模板注入漏洞。未认证用户可通过提交特制数据至Hidden字段触发Twig模板引擎解析,导致Craft CMS站点被完全接管。利用条件低,危害极高。 * GHSA-wx9m-wx4f-4cmg (mistralai PyPI) - 供应链投毒攻击。PyPI上的mistralai包2.4.6版本包含恶意dropper,在Linux系统上导入时执行。由于攻击者已成功上传恶意包,影响范围可能涉及直接或间接依赖该包的开发环境与生产系统。 * CVE-2026-45327 (TinyIce) - 未授权访问。TinyIce的WebRTC推流端点缺少身份验证,攻击者可未授权注入视频
阅读时间 20 分钟
安全情报

How to scan for vulnerabilities with GitHub Security Lab’s open source AI-powered framework

📡 GitHub Security Lab · 0 How to scan for vulnerabilities with GitHub Security Lab’s open source AI-powered framework CVE-2026-25757CVE-2026-25758CVE-2025-64487CVE-2026-28514 For the last few months, we’ve been using the GitHub Security Lab Taskflow Agent along with a new set of auditing taskflows that specialize in finding web security vulnerabilities. They
阅读时间 20 分钟
[!] CONTACT_CHANNELS

如需商务合作、技术咨询或漏洞反馈,请通过以下离岸节点联系作者。

> PING_AUTHOR (@A1RedTeam)