安全情报

A collection of 572 posts
安全情报

📊 2026-07-10 漏洞情报日报 · 4 条 · 高危 3

每日漏洞情报汇总 · 2026-07-10 📊 2026-07-10 漏洞情报日报 📋 共 4 条 🔥 高危/严重 3 条 🐙 GitHub-Advisory 4 条 🔥3 🤖 今日安全态势分析 🎯 今日重点关注 * CVE-2026-48594 (Tesla 解压炸弹):影响 Tesla HTTP 客户端。攻击者可利用服务器响应或重定向返回特制压缩数据,造成服务端内存耗尽,导致拒绝服务。无需认证,远程触发。 * CVE-2026-48595 (Tesla 认证头泄露):影响 Tesla 的重定向中间件。由于大小写校验缺陷,跨域重定向时可能未清除 Authorization 头,导致敏感凭证泄露给第三方恶意服务器。 * CVE-2026-48597 (Tesla BEAM 原子耗尽):影响 Tesla Mint 适配器。通过构造恶意的 URL
阅读时间 3 分钟
安全情报

📊 2026-07-09 漏洞情报日报 · 200 条 · 高危 99

每日漏洞情报汇总 · 2026-07-09 📊 2026-07-09 漏洞情报日报 📋 共 200 条 🔥 高危/严重 99 条 💣 Exploit-DB-RSS 12 条 🔥2 🐙 GitHub-Advisory 58 条 🔥27 🛡️ NVD-Latest 70 条 🔥70 ⚔️ Sploitus 60 条 🤖 今日安全态势分析 🎯 今日重点关注 * Discuz! X5.0 - 认证绕过 (CVE-2026-49952, CVSS 9.1):影响广泛使用的开源论坛系统,攻击者无需凭证即可绕过身份验证,直接接管管理员权限或访问敏感数据。利用公开可用,风险极高。 * Nuclio & Coolify - 多组件RCE链:Nuclio 的 cron
阅读时间 22 分钟
安全情报

The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration

📡 Palo Alto Unit42 · 2026-06-22 The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Threat Research Cloud Cybersecurity Research Cloud Cybersecurity Research The Global
阅读时间 16 分钟
安全情报

📊 2026-07-08 漏洞情报日报 · 200 条 · 高危 91

每日漏洞情报汇总 · 2026-07-08 📊 2026-07-08 漏洞情报日报 📋 共 200 条 🔥 高危/严重 91 条 🚨 CISA-KEV 4 条 💣 Exploit-DB-RSS 8 条 🔥2 🐙 GitHub-Advisory 74 条 🔥35 🛡️ NVD-Latest 54 条 🔥54 ⚔️ Sploitus 60 条 🤖 今日安全态势分析 🎯 今日重点关注 * Apache Camel 多组件高危链 (CVE-2026-56140, CVE-2026-53913, CVE-2026-48204 等): 今日集中披露7个CVSS 9.8的严重漏洞,覆盖AWS SNS/SQS、Keycloak、MongoDB Gridfs等多个组件。攻击者可通过输入验证缺陷或认证绕过,远程执行代码或窃取凭据,利用难度低,
阅读时间 21 分钟
安全情报

CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure

📡 Palo Alto Unit42 · 2026-06-25 CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Threat Research Malware Malware CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure 10 min read Related Products Advanced
阅读时间 13 分钟
安全情报

Threat Brief: Mitigating Large-Scale Credential Attacks

📡 Palo Alto Unit42 · 2026-06-26 Threat Brief: Mitigating Large-Scale Credential Attacks Threat Brief: Mitigating Large-Scale Credential Attacks Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center High Profile Threats General General Threat Brief: Mitigating Large-Scale Credential Attacks 5 min read Related Products Next-Generation Firewall Unit 42 Incident Response
阅读时间 8 分钟
安全情报

Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector

📡 Palo Alto Unit42 · 2026-07-01 Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Threat Research Malware Malware Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector
阅读时间 24 分钟
安全情报

A VBScript campaign distributed through WhatsApp deploying RMM software

📡 Kaspersky Securelist · 2026-06-22 A VBScript campaign distributed through WhatsApp deploying RMM software An unknown actor distributes malicious VBS scripts via WhatsApp | Securelist Solutions for: Home Products Small Business 1-50 employees Medium Business 51-999 employees Enterprise 1000+ employees by Kaspersky CompanyAccount Get In Touch Dark mode off English Russian Spanish Brazil
阅读时间 15 分钟
[!] CONTACT_CHANNELS

如需商务合作、技术咨询或漏洞反馈,请通过以下离岸节点联系作者。

> PING_AUTHOR (@A1RedTeam)