<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>代码卫士</title>
    <link>https://wechat2rss.xlab.app/feed/77cfc87fa0e7200d7ef74c8956eca2e44fd6a4ec.xml</link>
    <description>奇安信代码卫士是国内第一家专注于软件开发安全的产品线，产品涵盖代码安全缺陷检测、软件编码合规检测、开源组件溯源检测三大方向，分别解决软件开发过程中的安全缺陷和漏洞问题、编码合规性问题、开源组件安全管控问题。本订阅号提供国内外热点安全资讯。&#xA;(wechat feed made by @ttttmr https://wechat2rss.xlab.app)</description>
    <managingEditor> (代码卫士)</managingEditor>
    <image>
      <url>http://wx.qlogo.cn/mmhead/Q3auHgzwzM7Vp8oia6sLibUdWibEl7DX5Zb2EXK5iau7shFpmh9TwvwlhA/0</url>
      <title>代码卫士</title>
      <link>https://wechat2rss.xlab.app/feed/77cfc87fa0e7200d7ef74c8956eca2e44fd6a4ec.xml</link>
    </image>
    <item>
      <title>AI编程月产代码从2.5万到25万行：一场被忽视的&#34;漏洞危机&#34;</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525729&amp;idx=1&amp;sn=25b2c6b4e1fa57bb09f2dda0e8b95549</link>
      <description>近日，《纽约时报》记者Mike Isaac和Erin Griffith发文揭示了AI编程工具普及后的另一面：代码过载。一家金融服务公司引入AI编程工具后，月产代码量从2.5万行跳升至25万行——增长1...</description>
      <content:encoded><![CDATA[<p><span>代码卫士</span> <span>2026-04-10 14:10</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=e5339891&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft5z0xV2OYfUCB77sxzPJpmCChCaOZQZtic8aH6zdvPXlmEyR5gRFVYC3ib35O8UNrLG04fTns93EwmMHneOG0YbNG3JyJX6DNOVzjtF21aWQU%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>近日，《纽约时报》记者Mike Isaac和Erin Griffith发文揭示了AI编程工具普及后的另一面：代码过载。一家金融服务公司引入AI编程工具后，月产代码量从2.5万行跳升至25万行——增长1...</p>
  <div data-mpa-uuid="9066d09cdd7f5ce77efd04043cd2a223" data-mpa-apply-md="t" data-mpa-md-root="t"><div style="margin-bottom: 0px;" data-mpa-uuid="c1794b93a49e24801f0b17c0ac47acdb" data-mpa-apply-md="t"><div style="background: linear-gradient(135deg, #2E1065 0%, #4F46E5 100%);color: #FFFFFF;padding: 25px 20px;border-radius: 12px;margin-bottom: 30px;box-shadow: 0 8px 20px rgba(46, 16, 101, 0.2);"><p style="margin: 0;text-align: justify;opacity: 0.95;"><span leaf="">近日，《纽约时报》记者Mike Isaac和Erin Griffith发文揭示了AI编程工具普及后的另一面：</span><strong style="color: #A78BFA;font-size: 19px;"><span leaf="">代码过载</span></strong><span leaf="">。一家金融服务公司引入AI编程工具后，</span><strong style="color: #A78BFA;font-size: 19px;"><span leaf="">月产代码量从2.5万行跳升至25万行——增长10倍</span></strong><span leaf="">。随之而来的，是100万行积压待审代码。</span><span leaf="">某</span><span leaf="">安全初创公司联合创始人兼CEO</span><span leaf="">表示</span><span leaf="">：</span><span leaf="">“</span><span leaf="">他们根本跟不上代码交付量的增长，以及随之而来的漏洞激增。</span><span leaf="">”</span><span leaf="">这不是个例，而是整个行业正在面对的新现实。</span></p></div><p style="margin-bottom: 30px;text-align: center;"><span style="font-size: 18px;"><p style="display: inline-block;text-indent: 0px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_img_placeholder wx_img_placeholder" data-ratio="0.546" data-w="1000" style="left: 0px;top: 0px;width: 100%;height: auto;background-color: transparent;border-radius: 8px;box-shadow: 0 4px 15px rgba(0,0,0,0.08);" src="https://wechat2rss.xlab.app/img-proxy/?k=ba5837b6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmSqhDgeKrPCGEgx3ofKau48cz0Hl083iapW5XP0GYGl8K1DcZS0ib3WgQ4wuoIC0GWTrRiaj5vGENYRMiaZjtDsUUDvfs9QDbAbgMuibHS7cd6Ug%2F640%3Ffrom%3Dappmsg%23imgIndex%3D0"/></p></span></p><div style="margin-bottom: 35px;"><p style="margin: 0;text-align: justify;"><span leaf="">随着Anthropic、</span><span leaf="">OpenAI</span><span leaf="">等厂商持续升级底层模型，AI编程代理已从辅助工具升级为全自动代码生成机器，只需少量人工引导，就能在极短时间内完成数周工作量。</span><span leaf="">谷歌2025年9月</span><span leaf="">调查显示，90%的软件</span><span leaf="">开发者已在使用AI辅助工作，71%的编程人员借助AI写代码。</span><span leaf="">奇安信人工智能专家认为，</span><span leaf="">AI让人人都能写代码，软件开发进入</span><span leaf="">“</span><span leaf="">全民编程</span><span leaf="">”</span><span leaf="">时代，但代码产量爆炸式增长的背后，审查能力、安全能力、治理能力未能同步跟上，</span><strong style="color: #2E1065;"><span leaf="">一场席卷全行业的</span></strong><strong style="color: #2E1065;"><span leaf="">“</span></strong><strong style="color: #EF4444;"><span leaf="">漏洞</span></strong><strong style="color: #EF4444;"><span leaf="">危机</span></strong><strong style="color: #2E1065;"><span leaf="">”</span></strong><strong style="color: #2E1065;"><span leaf="">正悄然爆发</span></strong><span leaf="">。</span></p></div><div style="margin-bottom: 25px;"><p style="background-color: #F3E8FF;padding: 12px 20px;border-radius: 8px;border-left: 5px solid #7C3AED;display: flex;align-items: center;box-shadow: 0 4px 10px rgba(124, 58, 237, 0.05);"><h2 style="margin: 0;color: #2E1065;font-size: 20px;font-weight: bold;letter-spacing: 1px;"><span leaf="">代码爆炸式增长，安全漏洞成为被忽视的代价</span></h2></p></div><div style="margin-bottom: 20px;"><p style="margin: 0;text-align: justify;"><span leaf="">AI编程带来的产能跃迁，正在打破软件开发的原有平衡。代码产量呈几何级增长，而安全审查、人工核验、漏洞修复的速度远远滞后，安全漏洞成为AI编程狂欢中被严重忽视的代价。</span></p></div><div style="background-color: #FFFFFF;padding: 20px;border-radius: 8px;border: 1px solid #E2E8F0;box-shadow: 0 4px 12px rgba(0,0,0,0.03);margin-bottom: 20px;"><p style="margin: 0 0 15px 0;text-align: justify;"><span leaf="">从企业应用场景来看，AI生成代码的安全隐患触目惊心。2025年5月，</span><span leaf="">Replit</span><span leaf="">员工Matt Palmer扫描1645个Vibe Coding平台创建的网站应用，</span><strong style="color: #EF4444;"><span leaf="">发现170个存在严重安全漏洞，占比约10.3%</span></strong><span leaf="">，攻击者无需登录即可访问用户数据库，窃取姓名、邮箱、财务信息与API密钥。</span></p><p style="margin: 0;text-align: justify;"><span leaf="">Palantir</span><span leaf="">工程师仅用47分钟，就从多个应用中提取个人债务、家庭住址等敏感数据。安全研究公司Escape后续扫描5600多个同类应用，发现超2000个安全漏洞、400多个暴露密钥及175例隐私数据泄露，涉及医疗记录、银行账号等核心信息，而这些应用的创建者大多不具备基础安全知识。</span></p></div><div style="margin-bottom: 20px;"><p style="margin: 0;text-align: justify;"><span leaf="">这种风险在企业自</span><span leaf="">研</span><span leaf="">场景中同样突出。温氏股份作为农牧行业数字化龙头，研发相关人员达400-500人，代码开发进入日均百万行的高速阶段，其中超80%开发人员高频使用AI开发助手，日均AI生成代码至少17万行。AI生成代码存在逻辑漏洞、权限配置不当、敏感信息</span><span leaf="">泄露等天然隐患，传统人工审计模式完全无法匹配海量代码的开发节奏，单一环节的代码漏洞可能像</span><span leaf="">“</span><span leaf="">禽流感</span><span leaf="">”</span><span leaf="">一样在全产业链扩散，威胁从育种、养殖到屠宰、流通的全链路业务连续性</span><span leaf="">和安全性</span><span leaf="">。</span></p></div><div style="background-color: #FEF2F2;border-left: 4px solid #EF4444;padding: 20px;border-radius: 0 8px 8px 0;margin-bottom: 40px;"><p style="margin: 0;text-align: justify;color: #991B1B;"><strong style="font-size: 19px;"><span leaf="">代码过载、漏洞激增、审查积压</span></strong><strong style="font-size: 19px;"><span leaf="">……</span></strong><span leaf="">多</span><span leaf="">重压力叠加下，AI编程</span><span leaf="">的</span><span leaf="">“</span><span leaf="">效率福音</span><span leaf="">”</span><span leaf="">和</span><span leaf="">“</span><span leaf="">质量诅咒</span><span leaf="">”</span><span leaf="">并存</span><span leaf="">，传统代码安全体系全面失效，行业亟待全新的治理方案破局。</span></p></div><div style="margin-bottom: 25px;"><p style="background-color: #F3E8FF;padding: 12px 20px;border-radius: 8px;border-left: 5px solid #7C3AED;display: flex;align-items: center;box-shadow: 0 4px 10px rgba(124, 58, 237, 0.05);"><h2 style="margin: 0;color: #2E1065;font-size: 20px;font-weight: bold;letter-spacing: 1px;"><span leaf="">奇安信：治理模式亟待变革，</span><span leaf="">“</span><span leaf="">以智治智</span><span leaf="">”</span><span leaf="">成为必选项</span></h2></p></div><div style="margin-bottom: 20px;"><p style="margin: 0;text-align: justify;"><span leaf="">面对AI代码带来的全新挑战，传统应用安全测试工具与纯人工代码审查已难以为继，治理模式必须从</span><span leaf="">“</span><span leaf="">人工依赖</span><span leaf="">”</span><span leaf="">向</span><span leaf="">“</span><span leaf="">智能协同</span><span leaf="">”</span><span leaf="">转型。奇安信在2026年网络安全十大趋势中明确指出，AI代码生成引发</span><span leaf="">“</span><span leaf="">信任赤字</span><span leaf="">”</span><span leaf="">，软件供应</span><span leaf="">链安全</span><span leaf="">面临重构，</span><strong style="color: #7C3AED;"><span leaf="">2026年以AI对抗AI的</span></strong><strong style="color: #7C3AED;"><span leaf="">“</span></strong><strong style="color: #7C3AED;"><span leaf="">以智治智</span></strong><strong style="color: #7C3AED;"><span leaf="">”</span></strong><strong style="color: #7C3AED;"><span leaf="">，将成为代码安全治理的主流趋势</span></strong><strong style="color: #7C3AED;"><span leaf="">甚至</span></strong><strong style="color: #7C3AED;"><span leaf="">必选项。</span></strong></p></div><div style="margin-bottom: 20px;"><p style="margin: 0;text-align: justify;"><span leaf="">奇安信人工智能公司安全专家认为，</span><span leaf="">AI时代代码</span><span leaf="">井喷导致漏洞失控，</span><span leaf="">传统的规则匹配已经无法解决，“逻辑理解深度”已经成为最亟待解决的问题。</span><span leaf="">AI生成代码的风险不再局限于SQL注入、XSS等传统漏洞，更多表现为逻辑漏洞、幻觉代码、虚构API调用、权限配置错误等新型隐患，传统静态扫描工具无法识别业务逻辑缺陷，人工审核又被海量代码淹没，形成</span><span leaf="">“</span><span leaf="">生成快、验证慢、漏洞多</span><span leaf="">”</span><span leaf="">的恶性循环。奇安信认为，</span><strong style="color: #2E1065;"><span leaf="">只有用AI的智能能力对抗AI的生成能力，才能破解海量代码审计与安全保障的双重难题，实现</span></strong><strong style="color: #2E1065;"><span leaf="">“</span></strong><strong style="color: #2E1065;"><span leaf="">AI辅助开发不减安全</span></strong><strong style="color: #2E1065;"><span leaf="">”</span></strong><span leaf="">。</span></p></div><div style="background-color: #FFFFFF;padding: 20px;border-radius: 8px;border: 1px solid #E2E8F0;box-shadow: 0 4px 12px rgba(0,0,0,0.03);margin-bottom: 20px;"><p style="margin: 0;text-align: justify;"><span leaf="">温氏股份的实践</span><span leaf="">在一定程度上</span><span leaf="">印证了</span><span leaf="">“</span><span leaf="">以智治智</span><span leaf="">”</span><span leaf="">的可行性。面对日</span><span leaf="">均百万行代码、17万行</span><span leaf="">由</span><span leaf="">AI生成代码的审计压力</span><span leaf="">，</span><span leaf="">温氏股份携手奇安信打造</span><span leaf="">“</span><span leaf="">AI+代码卫士</span><span leaf="">”</span><span leaf="">解决方案，</span><span leaf="">构建全</span><span leaf="">流程智能代码安全体系。方案通过大模型对AI生成代码进行二次语义分析，精准识别逻辑漏洞、算法公平性等深层次问题；将智能审计工具无缝集成到DevOps平台，实现开发流程中实时安全检测；建立专属审计规则库，覆盖27大类漏洞检测项，形成</span><span leaf="">“</span><span leaf="">自动化扫描+AI智能审查+人工核验</span><span leaf="">”</span><span leaf="">的三重防线。</span></p></div><div style="margin-bottom: 20px;"><p style="margin: 0;text-align: justify;"><span leaf="">落地效果显示，该体系让温氏股份漏洞发现效率提升3倍，高危漏洞拦截率超95%，人工审计工作量减少30%-40%，中等规模系统安全审查从2-3周缩短至3-5天，每年节省</span><span leaf="">安全运维成本</span><span leaf="">数百万元，实现安全与效率的双重提升。这一案例</span><span leaf="">侧面</span><span leaf="">证明，</span><span leaf="">“</span><span leaf="">以智治智</span><span leaf="">”</span><span leaf="">不是技术概念，</span><span leaf="">未来将</span><span leaf="">是可落地、可量化、可复制的行业解决方案，能够有效化解AI代码带来的安全危机。</span></p></div><div style="margin-bottom: 40px;"><p style="margin: 0;text-align: justify;"><span leaf="">从行业层面看，</span><span leaf="">“</span><span leaf="">以智治智</span><span leaf="">”</span><span leaf="">的核心是重构代码安全治理架构：底层通过强制性自动化护栏过滤低级错误，中层依靠AI智能</span><span leaf="">体完成</span><span leaf="">逻辑与安全筛查，顶层由人类专家聚焦架构与核心业务决策，形成</span><span leaf="">“</span><span leaf="">机器过滤、人工决策</span><span leaf="">”</span><span leaf="">的分层验证体系。这种模式既能释放AI的生产力红利，又能遏制代码质量下滑，成为企业应对</span><span leaf="">漏洞</span><span leaf="">失控</span><span leaf="">的唯一可行路径。</span></p></div><div style="margin-bottom: 25px;"><p style="background-color: #F3E8FF;padding: 12px 20px;border-radius: 8px;border-left: 5px solid #7C3AED;display: flex;align-items: center;box-shadow: 0 4px 10px rgba(124, 58, 237, 0.05);"><h2 style="margin: 0;color: #2E1065;font-size: 20px;font-weight: bold;letter-spacing: 1px;"><span leaf="">奇安信代码安全智能体</span><span leaf="">，融合“</span><span leaf="">专家级大脑+多智能体协同</span><span leaf="">”</span></h2></p></div><div style="margin-bottom: 25px;"><p style="margin: 0;text-align: justify;"><span leaf="">为推动</span><span leaf="">“</span><span leaf="">以智治智</span><span leaf="">”</span><span leaf="">落地，奇安信</span><span leaf="">人工智能公司</span><span leaf="">在2026年3月正式</span><span leaf="">推</span><span leaf="">出首款</span><span leaf="">代码安全智能体——</span><span leaf="">Qcode</span><span leaf=""> Agents，以</span><span leaf="">“</span><span leaf="">专家级大脑+多智能体协同</span><span leaf="">”</span><span leaf="">打造全自动安全闭环，为行业提供可落地的智能代码安全解决方案，标志着国产代码安全检测迈入</span><span leaf="">“</span><span leaf="">全场景智能体</span><span leaf="">”</span><span leaf="">新阶段。</span></p></div><p style="margin-bottom: 30px;text-align: center;"><span style="font-size: 18px;"><p style="display: inline-block;text-indent: 0px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_img_placeholder wx_img_placeholder" data-ratio="0.561" data-w="1000" style="left: 0px;top: 0px;width: 100%;height: auto;background-color: transparent;border-radius: 8px;box-shadow: 0 4px 15px rgba(0,0,0,0.08);" src="https://wechat2rss.xlab.app/img-proxy/?k=63e703d1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmSqhDgeKrPDUgvHW0iabtwWDxsv7zZbKOmwUy1a2BIIB9qDelu9t79muy0vaNzgAD1zSicmaIDNvJDQBsNIokA69zyZmqdYFQ33Fh0JwA3GeM%2F640%3Ffrom%3Dappmsg%23imgIndex%3D1"/></p></span></p><div style="margin-bottom: 20px;"><p style="margin: 0;text-align: justify;"><span leaf="">Qcode</span><span leaf=""> Agents的核心突破，是打造具备十余年实战经验的</span><span leaf="">“</span><span leaf="">专家级大脑</span><span leaf="">”</span><span leaf="">。当前AI安全工具普遍存在</span><span leaf="">“</span><strong style="color: #EF4444;"><span leaf="">不准、不懂、不深</span></strong><span leaf="">”</span><span leaf="">的问题，根源在于缺乏实战攻防逻辑支撑。奇安信将十余年代码安全深耕经验、数万条实战验证的高质量检测规则内化到智能体中，把扫描初始化、漏洞定位、路径生成等关键环节标准化，让智能体像资深安全专家一样思考，从根源解决AI</span><span leaf="">“</span><span leaf="">幻觉</span><span leaf="">”</span><span leaf="">与逻辑盲区，实现从</span><span leaf="">“</span><span leaf="">通用模型</span><span leaf="">”</span><span leaf="">到</span><span leaf="">“</span><span leaf="">领域专家</span><span leaf="">”</span><span leaf="">的跨越。</span></p></div><div style="margin-bottom: 25px;"><p style="margin: 0;text-align: justify;"><span leaf="">在能力架构上，</span><span leaf="">Qcode</span><span leaf=""> Agents构建</span><span leaf="">“</span><strong style="color: #7C3AED;"><span leaf="">感知-分析-验证-修复-响应</span></strong><span leaf="">&#34;的全自动安全闭环，深度嵌入研发全流程。感知环节实时监测代码变更，即时启动分析；分析环节调用专家级引擎，精准定位传统漏洞与业务</span><span leaf="">逻辑缺陷；验证环节通过动态模拟复现漏洞触发路径，大幅降低误报率；修复环节提供</span><span leaf="">代码级修复</span><span leaf="">建议，引导快速闭环；响应环节自动触发修复流程并验证效果，实现风险彻底处置。这一闭环打破安全</span><span leaf="">“</span><span leaf="">滞后于开发</span><span leaf="">”</span><span leaf="">的困境，让安全成为DevOps的内生能力。</span></p></div><p style="margin-bottom: 30px;text-align: center;"><span style="font-size: 18px;"><p style="display: inline-block;text-indent: 0px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_img_placeholder wx_img_placeholder" data-ratio="0.56" data-w="1000" style="left: 0px;top: 0px;width: 100%;height: auto;background-color: transparent;border-radius: 8px;box-shadow: 0 4px 15px rgba(0,0,0,0.08);" src="https://wechat2rss.xlab.app/img-proxy/?k=c039614c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmSqhDgeKrPBnKEjouTibAiajoR5Yvf2PD5ia12kWJc5EsKjHvib0sfibKpQJy12fu6ogP0lJsGlWHyuzSNEluwZzTDbI4fIlsNut2vMPYmiagtczU%2F640%3Ffrom%3Dappmsg%23imgIndex%3D2"/></p></span></p><div style="margin-bottom: 40px;"><p style="margin: 0;text-align: justify;"><span leaf="">实测效果验证了</span><span leaf="">Qcode</span><span leaf=""> Agents的领先性。</span><span leaf="">该</span><span leaf="">产品成功复现Claude Code Security披露的三大典型漏洞，在apache-</span><span leaf="">ofbiz</span><span leaf="">、</span><span leaf="">openssl</span><span leaf="">、</span><span leaf="">tensorflow</span><span leaf="">等主流开源项目检测中，精准识别CVE漏洞与隐蔽逻辑缺陷，内</span><span leaf="">测阶段</span><span leaf="">已发现10余个潜在高危漏洞。此前</span><span leaf="">“</span><span leaf="">AI+代码卫士&#34;已在北京银行、人保科技等金融客户落地，将代码审计周期缩短超83%，人力成本降至传统模式1/6，为</span><span leaf="">Qcode</span><span leaf=""> Agents的规模化应用奠定基础。</span></p></div><div style="margin-bottom: 25px;"><p style="background-color: #F3E8FF;padding: 12px 20px;border-radius: 8px;border-left: 5px solid #7C3AED;display: flex;align-items: center;box-shadow: 0 4px 10px rgba(124, 58, 237, 0.05);"><h2 style="margin: 0;color: #2E1065;font-size: 20px;font-weight: bold;letter-spacing: 1px;"><span leaf="">结语：以智能破局，守护AI编程时代的软件安全</span></h2></p></div><div style="margin-bottom: 20px;"><p style="margin: 0;text-align: justify;"><span leaf="">AI编程带来的代码过载与</span><span leaf="">“</span><span leaf="">漏洞</span><span leaf="">失控</span><span leaf="">”</span><span leaf="">，是数字经济发展中的必然挑</span><span leaf="">战，更是行业重构的契机。当AI让代码生产门槛归零，安全治理必须同步进化，从人工主导转向智能驱动，从被动补救转向主动防御，从单点工具转向体系化能力。</span></p></div><div style="background-color: #2E1065;color: #F8FAFC;padding: 30px 20px;border-radius: 12px;box-shadow: 0 8px 25px rgba(46, 16, 101, 0.2);"><p style="margin: 0;text-align: justify;opacity: 0.95;line-height: 1.8;"><span leaf="">奇安信以</span><span leaf="">“</span><span leaf="">以智治智</span><span leaf="">”</span><span leaf="">为核心，通过AI+代码卫士、</span><span leaf="">Qcode</span><span leaf=""> Agents代码安全智能体等创新方案，为企业提供从检测、审计到修复、运营的全链路支撑，破解海量代码审计、AI生成代码漏洞、业务逻辑缺陷等核心难题。温氏股份、</span><span leaf="">北京银行、人保科技</span><span leaf="">等实践案例证明，智能代码安全体系能够实现安全与效率兼顾，让企业在享受AI编程红利的同时，守住安全底线</span><span leaf="">，</span><span leaf="">让AI真正成为赋能行业创新的正向力量。</span></p></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=8e3b25b4&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2NTg4OTc5Nw%3D%3D%26mid%3D2247525729%26idx%3D1%26sn%3D25b2c6b4e1fa57bb09f2dda0e8b95549">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 10 Apr 2026 14:10:00 +0800</pubDate>
    </item>
    <item>
      <title>AI漏洞发现量激增，HackerOne 宣布暂停开源漏洞奖励计划</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525729&amp;idx=2&amp;sn=4776ef6ac621cacfac94cd6c25ca0452</link>
      <description>行业需要想清楚如何为‘修复’提供资金，而不仅仅是为‘发现’买单。</description>
      <content:encoded><![CDATA[<p><span>Jai Vijayan</span> <span>2026-04-10 14:10</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=b9897612&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft5z0xV2OYfUJtGks3icPCBic5ZY13LO64cK43miaEOodHoCib3gTZBTibJhT6FMjbQbQHRQ9rt2dLBpj5A0NFCbFuFEKAic2zD69JOouqnfcSB7rY%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>行业需要想清楚如何为‘修复’提供资金，而不仅仅是为‘发现’买单。</p>
  <p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;" data-mpa-uuid="9066d09cdd7f5ce77efd04043cd2a223" data-mpa-apply-md="t"><span leaf=""><img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="1" data-type="gif" data-w="400" style="margin-right: auto;margin-left: auto;vertical-align: middle;letter-spacing: 0.5px;text-indent: 0em;display: inline-block;box-sizing: border-box !important;visibility: visible !important;width: 30px !important;height: auto !important;" width="30" data-fileid="100025254" src="https://wechat2rss.xlab.app/img-proxy/?k=17396c1a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAz5ZsrEic9ot90z9etZLlU7OTaPOdibteeibJMMmbwc29aJlDOmUicibIRoLdcuEQjtHQ2qjVtZBt0M5eVbYoQzlHiaw%2F640%3Fwx_fmt%3Dgif"/>  </span><span style="text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-mpa-powered-by&#34;:&#34;yiban.io&#34;,&#34;style&#34;:&#34;margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">聚焦源代码安全，网罗国内外最新资讯！</span></span></p><p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;text-align: start;"><strong style="color: rgb(0, 0, 0);letter-spacing: 1px;font-size: 15px;"><span style="font-family: sofia-pro, sans-serif;letter-spacing: normal;text-transform: uppercase;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;transition: color 0.15s ease-out 0s, background-color 0.3s ease-out 0s, text-decoration-color 0.15s ease-out 0s;box-shadow: inset 0 -2px 0 var(--color-black);overflow: hidden;padding-bottom: 4px;color: rgb(136, 136, 136);"><span leaf="">编译：代码卫士</span></span></strong></p><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="paragraph"><div data-tools="135编辑器" data-id="166585"><div style="margin: 10px auto;"><div><div style="background-color: #ffffff;padding: 0px 10px;border-left: 3px solid #1a3566;border-right: 3px solid #1a3566;line-height: 1.1em;box-sizing:border-box;"><p data-autoskip="1" style="text-align: left;line-height: 1.75em;letter-spacing: 1.5px;font-size: 15px;color: #131f35;background-color: transparent;"><span style="font-size: 15px;color: #000000;"><strong><span leaf="">HackerOne </span></strong><strong><span leaf="">近期决定暂停接收向其众包模式的互联网漏洞奖励计划(IBB) 提交新的漏洞。这一举措表明，由于AI 辅助漏洞挖掘与发现技术快速发展，全行业在漏洞修复方面面临日益严峻挑战。</span></strong></span></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">IBB 计划于 2013 年启动，被广泛视为开源社区最重要的漏洞奖励计划之一。自今年3 月27日起，该计划暂停接收新的漏洞提交报告，HackerOne 给出的原因是漏洞发现的速度与开源维护者修复漏洞的能力之间的失衡正日益加剧。</span></span></p><div data-role="title" data-tools="135编辑器" data-id="166211"><div style="margin: 10px auto;display: flex;justify-content: center;"><div style="display: flex;align-items: center;"><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100042051" src="https://wechat2rss.xlab.app/img-proxy/?k=105282a5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ft5z0xV2OYfUTqQnHFr4lZL2cGDjt2FOSrhaLmUeaiaxRuGPp5ajJyVVLCpeSEqhicQSK0dcRiaq043q48EeKnSS6mpIhjagnLVFKBpFGZesGCM%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div><p style="font-size: 16px;color: #2e407b;text-align: center;padding: 0 6px;box-sizing:border-box;transform: rotateZ(0deg);-webkit-transform: rotateZ(0deg);-moz-transform: rotateZ(0deg);-o-transform: rotateZ(0deg);"><strong data-brushtype="text"><span leaf="">安全漏洞发现中的“信号与噪声”</span></strong></p></div><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100042047" src="https://wechat2rss.xlab.app/img-proxy/?k=e21e0972&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Ft5z0xV2OYfVel4D7RymaFwnoBicrrxSfulZReNb502ZBmMNOx7Mar5iaxnWvibnzn7f6N51T4q6YicibfKS7TJDUZYrcAag6aH0ILEF1Wibics3ibFs%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">HackerOne 表示：“漏洞发现的情况正在发生变化。AI 辅助研究正在扩大整个生态系统中漏洞发现的覆盖面，同时提升了发现的速度。开源领域在漏洞发现量与修复能力之间的平衡已经发生了实质性转变。”因此需要重新思考 IBB 这类众包模式项目的结构和激励机制。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">紧接着开源 Node.js 项目的维护者也暂停了他们自己的漏洞奖励计划，原因是此前通过 HackerOne 获得的资金已经中断。维护者解释称：“作为一个由志愿者驱动的开源项目，Node.js 没有独立的预算来独自维持一个漏洞奖励计划。”</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">多位安全专家认为，这些变动虽然影响重大，但考虑到 AI 辅助漏洞发现技术的快速发展，也并非意料之外。SOCRadar 公司的首席信息安全官 Ensar Seker 表示，“这是在AI压力下，漏洞奖励生态系统所做出的一项合理、甚至可以说是早就该做的调整。HackerOne 实际上是在承认瓶颈已经发生了转移：漏洞发现已经被 AI 工业化，但修复能力并没有相应地跟上。”当 AI 能在几小时内生成成千上万个中低质量的发现结果时，开源项目的维护者（通常是资金有限的志愿者）很容易就会被压垮。他提到，“所以没错，HackerOne 说得完全在理：这不是从安全上退缩，而是一次在‘信号与噪声’之间重新寻求平衡的尝试。”</span></span></p><div data-role="title" data-tools="135编辑器" data-id="166211"><div style="margin: 10px auto;display: flex;justify-content: center;"><div style="display: flex;align-items: center;"><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width:100%;" data-width="100%" data-imgfileid="100042074" src="https://wechat2rss.xlab.app/img-proxy/?k=16ec8409&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Ft5z0xV2OYfVBicRp2z0icZiazTicE3qob3xWqASA5pzYxASvudHRZRIM79F4t7VlsPJS5kWIvqnBR0uTiaFCQomNPIngAicR4iaLsyQDf2CeyBIibvY%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div><p style="font-size: 16px;color: #2e407b;text-align: center;padding: 0 6px;box-sizing:border-box;transform: rotateZ(0deg);-webkit-transform: rotateZ(0deg);-moz-transform: rotateZ(0deg);-o-transform: rotateZ(0deg);"><strong data-brushtype="text"><span leaf="">AI 生成的“垃圾内容”涌入猎洞领域</span></strong></p></div><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100042048" src="https://wechat2rss.xlab.app/img-proxy/?k=909b9ead&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Ft5z0xV2OYfVqCuERiavRSZBPPP5dcUOvbVNbu6fQmtTgSo6mTX4ZtVG6ErRsZrXAdkib8f8Q4wRnbo5zhMWbF6QvJ0KdrnshPzksJqBG6iaBRQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">Minimus 公司联合创始人兼首席信息官 John Morello 表示，随着 AI 生成的“垃圾内容”大量涌入，漏洞报告的有效提交率已从大约 15% 下降到了 5% 以下。“AI 辅助的漏洞挖掘不一定能发现更多严重 0day 漏洞；相反，它完全把瓶颈转移到了验证环节，迫使漏洞分类审核团队在海量听起来像那么回事、但实际上无法利用的报告中进行艰难的筛选。”他说。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">对于开源项目的维护者来说，“分类审核疲劳”已经成为最大的挑战，他们为了反驳那些凭空捏造的漏洞，就要耗费数小时的开发时间。“不幸的是，当前的漏洞奖励模式在奖励数量而非深度，这实际上等于把无偿劳动武器化，迫使这些小型团队为全球每一台自动化扫描仪充当免费的 QA 部门。”Morello 说。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">HackerOne 表示，他们现在的重点是寻找新的途径，以实现让漏洞发现与有效的修复工作相匹配的最初目标，“从而让有意义的发现成果能够为开源项目带来持久的安全改进”。为此，HackerOne 将与项目维护者和研究人员合作，评估各种方法，使激励机制更好地适配开源生态系统的实际情况。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">同样运营着众包漏洞发现平台的Bugcrowd的首席战略与信任官 Trey Ford 认为，HackerOne 的决定是一个警钟。“我们得搞清楚，这次暂停真正释放的信号是什么：行业花了多年时间，一直在优化漏洞管道的错误一端。”他说。在压缩漏洞发现所需的时间方面，AI 确实做到了它应该做的事情。“但我们还没有解决的，是方程式中的人这一侧：维护者在收到 40 份有效报告后，只有一个周末的时间来响应。”Ford 说。</span></span></p><div data-role="title" data-tools="135编辑器" data-id="166211"><div style="margin: 10px auto;display: flex;justify-content: center;"><div style="display: flex;align-items: center;"><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100042050" src="https://wechat2rss.xlab.app/img-proxy/?k=713f3edd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ft5z0xV2OYfVFHrfM7djTKLyIk95pFZBMZUvAjJNRpwtiaXu7Zwc5nEDyVPcaDZZerlJHjpDf8ujrMzr109dmOrUUoBpPealjVGZbyIEYPL6c%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div><p style="font-size: 16px;color: #2e407b;text-align: center;padding: 0 6px;box-sizing:border-box;transform: rotateZ(0deg);-webkit-transform: rotateZ(0deg);-moz-transform: rotateZ(0deg);-o-transform: rotateZ(0deg);"><strong data-brushtype="text"><span leaf="">漏洞发现有人买单，漏洞修复却无人埋单</span></strong></p></div><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100042055" src="https://wechat2rss.xlab.app/img-proxy/?k=6c22f33b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Ft5z0xV2OYfXHfdpeocw0AGldmyjPbxc2ZMhuAHMXobOEeibsGGhlD7mLxyaibdfL2z8qx4cbtKEUbk8AzOVU2HNAxJNANvyA4NCvH8XzIib3aU%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">现在需做的是以投入漏洞发现的同等紧迫性，加大对漏洞修复能力的投入。“漏洞研究与披露的经济学正在发生变化。AI 降低了漏洞发现的准入门槛，这意味着原始数量不再是研究人员的竞争优势。”Ford 指出。溢价空间将越来越多地向复杂的逻辑缺陷和新颖的攻击链转移，这些需要机器无法复制的人类深度分析与上下文判断能力。“下一代漏洞计划可能会为那些不仅报告漏洞、还能同时提供修复方案的研究人员提供额外奖金，并设立共享资金池，同时资助发现漏洞的研究人员和负责发布补丁的维护团队。”</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">修复并非唯一的挑战。正如 FusionAuth 公司的产品副总裁 David Hayes 所指出的，围绕人工节奏的漏洞奖励计划正在以远超预期的速度消耗资金。他表示，“当前的运行模式不可持续。”漏洞奖励是为这样一个世界设计的：漏洞发现本身才是瓶颈。现在，漏洞发现正日益走向自动化，瓶颈已经转移到了修复环节，而漏洞奖励并不为修复工作提供资金。他指出，“支撑关键互联网基础设施的那些项目，不能依靠志愿者劳动来大规模处理 AI 生成的报告。行业需要想清楚如何为‘修复’提供资金，而不仅仅是为‘发现’买单。”</span></span></p></div></div><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;" data-pm-slice="5 3 []"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span style="font-size: 15px;"><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf=""> 开源</span></span><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf="">卫士试用地址：</span><span leaf=""><a href="https://oss.qianxin.com/#/login" target="_blank">https://oss.qianxin.com/#/login</a></span></span></span></span></p><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span leaf=""> 代码卫士试用地址：<a href="https://sast.qianxin.com/#/login" target="_blank">https://sast.qianxin.com/#/login</a></span></span></p><hr style="white-space: normal;border-style: solid;border-right-width: 0px;border-bottom-width: 0px;border-left-width: 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px 0px;transform: scale(1, 0.5);"/><div data-role="paragraph" style="white-space: normal;margin-bottom: 0px;"><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p></div><div data-id="12351" data-tools="新媒体排版" data-style-type="1" style="margin: 0px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);text-align: start;"><div data-css="border-color: initial;border-style: none;border-width: 0px;padding: 0px" style="margin: 0px;padding: 0px;border-color: initial;border-style: none;border-width: 0px;"><div powered-by="KolEditor.us" style="margin: 0px;padding: 0px;"><div style="margin: 10px 0px;padding: 0px;"><p style="font-size: medium;margin: 0px;padding: 0px;display: inline-block;"><span style="margin: 0px;padding: 0.3em 0.5em;background-color: rgb(23, 148, 221);border-radius: 0.8em 0.8em 0px 0px;color: rgb(255, 255, 255);display: block;font-size: 14.08px;"><p style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-size: 18px;"><span leaf=""><span textstyle="" style="font-size: 15px;">推荐阅读</span></span></span></strong></p></span></p><div data-css="border-color: rgb(249, 110, 87);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;box-sizing: border-box;padding: 10px" style="margin: 0px;padding: 10px;border-color: rgb(23, 148, 221);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px;padding: 0px;"><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523516&amp;idx=1&amp;sn=0b6fc53ba92e7b5135395b67fff6a822&amp;scene=21#wechat_redirect" textvalue="在线阅读版：《2025中国软件供应链安全分析报告》全文" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">在线阅读版：《2025中国软件供应链安全分析报告》全文</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247518029&amp;idx=1&amp;sn=ce9a4b39bee37bf70faf66c1134b00d0&amp;scene=21#wechat_redirect" textvalue="HackerOne 发布《2023年黑客驱动安全报告》：29人晋级百万富翁" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">HackerOne 发布《2023年黑客驱动安全报告》：29人晋级百万富翁</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247512696&amp;idx=2&amp;sn=0032156c0937b0b72448e730fec8fd52&amp;scene=21#wechat_redirect" textvalue="HackerOne 员工窃取漏洞报告，向受影响客户索取钱财" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">HackerOne 员工窃取漏洞报告，向受影响客户索取钱财</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525680&amp;idx=1&amp;sn=5dbab9da81c7d42eda6c2082c7f2ac03&amp;scene=21#wechat_redirect" textvalue="开源平台 Flowise 中的满分 RCE 漏洞已遭在野利用" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">开源平台 Flowise 中的满分 RCE 漏洞已遭在野利用</span></a></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 15px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0em;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);font-size: medium;text-align: start;"><span style="margin: 0px;padding: 0px;font-size: 15px;color: rgb(136, 136, 136);text-decoration: underline;"><strong style="margin: 0px;padding: 0px;"><span leaf="">原文链接</span></strong></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;"><a href="https://www.darkreading.com/application-security/ai-led-remediation-crisis-prompts-hackerone-pause-bug-bounties" target="_blank">https://www.darkreading.com/application-security/ai-led-remediation-crisis-prompts-hackerone-pause-bug-bounties</a></span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">题图：Pixa</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">bay Licens</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">e</span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><strong style="text-indent: 0em;"><span style="font-size: 15px;color: rgb(136, 136, 136);"><span leaf="">本文由奇安信编译，不代表奇安信观点。转载请注明“转自奇安信代码卫士 <a href="https://codesafe.qianxin.com”。" target="_blank">https://codesafe.qianxin.com”。</a></span></span></strong></p><div data-role="paragraph" style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><div data-id="9499" data-tools="新媒体排版" data-style-type="4" style="color: rgb(0, 0, 0);font-size: 17px;margin: 0px;padding: 0px 0.5em;text-align: start;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px auto;padding: 0px;text-align: center;"><div style="margin: 0px auto;padding: 0px 0px 10px;max-width: 360px !important;"><p style="margin: 0px;padding: 0px 0px 0px 2px;font-size: 0px;width: 65px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.27380952380952384" data-type="jpeg" data-w="84" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;height: auto !important;" data-fileid="100025253" src="https://wechat2rss.xlab.app/img-proxy/?k=20efc9d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSf7nNLWrJL6dkJp7RB8Kl4zxU9ibnQjuvo4VoZ5ic9Q91K3WshWzqEybcroVEOQpgYfx1uYgwJhlFQ%2F640%3Fwx_fmt%3Djpeg"/></p><div data-css="align-items: flex-start;border-color: rgb(255, 138, 101);border-style: solid;border-width: 2px;display: flex;margin-top: -10px;padding: 30px 25px" style="margin: -10px 0px 0px;padding: 30px 25px;align-items: flex-start;border-color: rgb(23, 148, 221);border-style: solid;border-width: 2px;display: flex;"><div style="margin: 0px;padding: 0px;font-size: 0px;flex-shrink: 0;"><p style="margin: 0px;padding: 0px;width: 75px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-type="jpeg" data-w="1080" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;border-color: rgb(238, 238, 238);border-radius: 2px;border-style: solid;border-width: 1px;width: 75px;height: auto !important;" data-cropselx1="0" data-cropselx2="75" data-cropsely1="0" data-cropsely2="75" data-fileid="100025255" src="https://wechat2rss.xlab.app/img-proxy/?k=4657c87c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSN5sfviaCuvYQccJZlrr64sRlvcbdWjDic9mPQ8mBBFDCKP6VibiaNE1kDVuoIOiaIVRoTjSsSftGC8gw%2F640%3Fwx_fmt%3Djpeg"/></p></div><div style="margin: 0px;padding: 0px 0px 0px 15px;flex-shrink: 1;"><p data-css="color: #333;font-size: 18px;line-height:1.7;margin: 0px auto;text-align: left" style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 18px;line-height: 1.7;text-align: left;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;color: rgb(23, 148, 221);"><span leaf="">奇安信代码卫士 (codesafe)</span></span></strong></span></p><p style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 16px;text-align: left;line-height: 1.4;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><span leaf="">国内首个专注于软件开发安全的产品线。</span></span></p></div></div></div></div></div></div><p style="color: rgb(51, 51, 51);font-size: 17px;margin: 0px;padding: 0px 0.5em;clear: both;min-height: 1em;text-align: center;"><span leaf="">   <img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="0.8" data-type="gif" data-w="200" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: middle;color: rgb(0, 0, 0);font-size: 14px;box-sizing: border-box;width: 58.125px;visibility: visible !important;height: auto !important;" data-fileid="100025256" src="https://wechat2rss.xlab.app/img-proxy/?k=fbb024f2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FoBANLWYScMQ5iciaeKS21icDIWSVd0M9zEhicFK0rbCJOrgpc09iaH6nvqvsIdckDfxH2K4tu9CvPJgSf7XhGHJwVyQ%2F640%3Fwx_fmt%3Dgif"/><img class="rich_pages wxw-img" data-src=""/></span><span style="margin: 0px;padding: 0px;font-size: 12px;"><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">觉得不错，就点个 “</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">在看</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 或 &#34;</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">赞</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 吧~</span></span></span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://codesafe.qianxin.com/#/home">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=868d6d4d&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2NTg4OTc5Nw%3D%3D%26mid%3D2247525729%26idx%3D2%26sn%3D4776ef6ac621cacfac94cd6c25ca0452">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 10 Apr 2026 14:10:00 +0800</pubDate>
    </item>
    <item>
      <title>Grafana 修复可泄露用户数据的 AI 漏洞</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525729&amp;idx=3&amp;sn=bc8793597b56f124d19e242d87e8273d</link>
      <description>速修复</description>
      <content:encoded><![CDATA[<p><span>Alexander Culafi</span> <span>2026-04-10 14:10</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=e143fcd6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ft5z0xV2OYfVw57xlg2S1zV1eoZboqskVjOhv40YFLRia4ibiahnaQjIap6hAau3kicXJXHHLHeaIAWU1RsicWRp95JTWAghLu7Mg1RLugC6y1jO4%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>速修复</p>
  <p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;" data-mpa-uuid="9066d09cdd7f5ce77efd04043cd2a223" data-mpa-apply-md="t"><span leaf=""><img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="1" data-type="gif" data-w="400" style="margin-right: auto;margin-left: auto;vertical-align: middle;letter-spacing: 0.5px;text-indent: 0em;display: inline-block;box-sizing: border-box !important;visibility: visible !important;width: 30px !important;height: auto !important;" width="30" data-fileid="100025254" src="https://wechat2rss.xlab.app/img-proxy/?k=17396c1a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAz5ZsrEic9ot90z9etZLlU7OTaPOdibteeibJMMmbwc29aJlDOmUicibIRoLdcuEQjtHQ2qjVtZBt0M5eVbYoQzlHiaw%2F640%3Fwx_fmt%3Dgif"/>  </span><span style="text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-mpa-powered-by&#34;:&#34;yiban.io&#34;,&#34;style&#34;:&#34;margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">聚焦源代码安全，网罗国内外最新资讯！</span></span></p><p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;text-align: start;"><strong style="color: rgb(0, 0, 0);letter-spacing: 1px;font-size: 15px;"><span style="font-family: sofia-pro, sans-serif;letter-spacing: normal;text-transform: uppercase;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;transition: color 0.15s ease-out 0s, background-color 0.3s ease-out 0s, text-decoration-color 0.15s ease-out 0s;box-shadow: inset 0 -2px 0 var(--color-black);overflow: hidden;padding-bottom: 4px;color: rgb(136, 136, 136);"><span leaf="">编译：代码卫士</span></span></strong></p><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="paragraph"><div data-tools="135编辑器" data-id="166585"><div style="margin: 10px auto;"><div><div style="background-color: #ffffff;padding: 0px 10px;border-left: 3px solid #1a3566;border-right: 3px solid #1a3566;line-height: 1.1em;box-sizing:border-box;"><p data-autoskip="1" style="text-align: left;line-height: 1.75em;letter-spacing: 1.5px;font-size: 15px;color: #131f35;background-color: transparent;"><span style="font-size: 15px;color: #000000;"><strong><span leaf="">可观测性平台 Grafana 中存在一个漏洞，其AI功能可被滥用于泄露敏感数据。</span></strong></span></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">Grafana 是一个流行的可观测性平台，用于汇总和追踪与财务、遥测、运维、基础设施、客户等相关的业务数据。由于该平台的性质天然将其与组织内最核心的信息资产连接在一起，因此攻陷Grafana 实例可能会造成毁灭性后果。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">AI 安全厂商 Noma 于今日发布文章，详述了名为 “GrafanaGhost” 的间接提示注入攻击，可导致威胁行动者窃取数据。该攻击依赖于 Grafana AI 组件处理信息的方式。简言之，攻击者将在受控的网页中隐藏恶意指令，并通过控制指令显示为无害的方式，将所要求的敏感数据返回给受攻击者控制的服务器。Grafana 的 AI 助手用户将访问由攻击者构造的 URL 路径，Grafana 将在恶意图像文件开始加载后，      。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">该漏洞已修复。</span></span></p><div data-role="title" data-tools="135编辑器" data-id="166211"><div style="margin: 10px auto;display: flex;justify-content: center;"><div style="display: flex;align-items: center;"><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100042068" src="https://wechat2rss.xlab.app/img-proxy/?k=77ddfe0e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ft5z0xV2OYfXmykwuib6np4qoDvwWbUibGGUAE1amTrZmibtkqKrKEiaufqjzjabKkbk6VpWskHyoEEYibRZAgPia3OFp91dUdPWrBX2clCLJKw3Wo%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div><p style="font-size: 16px;color: #2e407b;text-align: center;padding: 0 6px;box-sizing:border-box;transform: rotateZ(0deg);-webkit-transform: rotateZ(0deg);-moz-transform: rotateZ(0deg);-o-transform: rotateZ(0deg);"><strong data-brushtype="text"><span leaf="">GrafanaGhost 的运作原理</span></strong></p></div><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100042065" src="https://wechat2rss.xlab.app/img-proxy/?k=caa8431a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Ft5z0xV2OYfXm0PePKicbGia9Gn2HAwhqVVBtjLabzjknsia5wWhribvRnJuVcnzg9txY37AcBCpllia9zibF92HWPwbnAXwRO2YMpvBS5tUQOMqho%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">Noma 公司研究人员提供的提示注入的目的是了解用户可能与 Grafana AI 组件交互的地方，因为面向用户的任何内容都可能促成提示注入攻击。调试之后，研究人员发现了处理间接提示的地方并认为图像标记是创建恶意命令的可行渠道。尽管外部图像配备有防护措施来抵御此类攻击，但研究人员设法通过使用与协议相关的 URL 规避域验证以及通过关键词 “INTENT” 来禁用 AI 模型防御措施，导致 Grafana 将外部提示视作非恶意性质。设置好后，在图像开始渲染受害者还未察觉到时，数据就被窃取。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">研究人员提到，无需防护人员点击加载恶意页面的步骤即可实施攻击。他提到，“攻击者需要将间接提示存储在 Grafana AI 组件后续检索喝处理的位置。一旦 payload 位于数据库中，那么当用户通过 Grafana 实例执行正常互动（如浏览条目日志）时就会自动执行。用户是毫不知情的触发者而非钓鱼攻击的目标，这就是为何攻击如此隐蔽的原因所在。”</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">Noma 公司盛赞 Grafana 的及时处理。该公司提到，研究员负责任地披露该漏洞后，Grafana“立即着手，与我们一起验证，并尽可能快地推出修复方案，保护用户的安全。”</span></span></p><div data-role="title" data-tools="135编辑器" data-id="166211"><div style="margin: 10px auto;display: flex;justify-content: center;"><div style="display: flex;align-items: center;"><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100042067" src="https://wechat2rss.xlab.app/img-proxy/?k=70a549de&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ft5z0xV2OYfVYHCzeicSvDnLQ4nCjRqeO5CvbtVHx35MVm2uAYAd7N0HRB8ib7GaUzqjG8pX8y3icQlIqxo0gUtibYia0clPBxON986x6QatYIpLg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div><p style="font-size: 16px;color: #2e407b;text-align: center;padding: 0 6px;box-sizing:border-box;transform: rotateZ(0deg);-webkit-transform: rotateZ(0deg);-moz-transform: rotateZ(0deg);-o-transform: rotateZ(0deg);"><strong data-brushtype="text"><span leaf="">Grafana 对漏洞机制有不同看法</span></strong></p></div><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100042066" src="https://wechat2rss.xlab.app/img-proxy/?k=995cf56b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Ft5z0xV2OYfUIiaiadWRGUFBqnvAHarMbKwYWjiaMehCkPWiaT0ZiciaejgZKLd2ku5TLtfb7icibzDHMx3XdcZda0F7U5rFXoj8ASa6Mic7ndzcicIB6s%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">Grafana Labs的首席信息安全官 Joe McManus 表示，Noma 公司的研究员从 Markdown 组件的图像渲染器中发现了一个问题，并“已被迅速修复”。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">不过，Grafana 对于 Noma 所述的“零点击”或攻击可静默并自动在后台执行的情况持有不同意见。前者表示，“任何利用成功都要求大量用户交互，具体而言，最终用户必须反复要求AI助手遵循日志中包含的恶意指令，即使AI助手已提醒用户注意恶意指令后仍然如此。我们申明，未有证据表明该漏洞已遭在野利用，Grafana Cloud 数据并未遭泄露。”</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">Noma 公司回应称，利用要求“少于两个步骤”，该AI助手从未提醒用户条目日志中存在恶意指令，“没有任何告警、标记或提示要求用户进行确认。该模型自动处理间接提示，将日志内容解析为合法上下文并静默执行操作，无任何限制也没有提醒用户发现异常情况。用户无法看到后台发生的情况也没有机会进行干预。我们尊重 Grafana 的快速响应以及对用户安全的重视。但我们无法容忍对利用机制的不准确描述。漏洞研究成果已记录，我们对研究揭示的情况很有把握。”</span></span></p></div></div><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;" data-pm-slice="5 3 []"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span style="font-size: 15px;"><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf=""> 开源</span></span><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf="">卫士试用地址：</span><span leaf=""><a href="https://oss.qianxin.com/#/login" target="_blank">https://oss.qianxin.com/#/login</a></span></span></span></span></p><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span leaf=""> 代码卫士试用地址：<a href="https://sast.qianxin.com/#/login" target="_blank">https://sast.qianxin.com/#/login</a></span></span></p><hr style="white-space: normal;border-style: solid;border-right-width: 0px;border-bottom-width: 0px;border-left-width: 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px 0px;transform: scale(1, 0.5);"/><div data-role="paragraph" style="white-space: normal;margin-bottom: 0px;"><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p></div><div data-id="12351" data-tools="新媒体排版" data-style-type="1" style="margin: 0px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);text-align: start;"><div data-css="border-color: initial;border-style: none;border-width: 0px;padding: 0px" style="margin: 0px;padding: 0px;border-color: initial;border-style: none;border-width: 0px;"><div powered-by="KolEditor.us" style="margin: 0px;padding: 0px;"><div style="margin: 10px 0px;padding: 0px;"><p style="font-size: medium;margin: 0px;padding: 0px;display: inline-block;"><span style="margin: 0px;padding: 0.3em 0.5em;background-color: rgb(23, 148, 221);border-radius: 0.8em 0.8em 0px 0px;color: rgb(255, 255, 255);display: block;font-size: 14.08px;"><p style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-size: 18px;"><span leaf=""><span textstyle="" style="font-size: 15px;">推荐阅读</span></span></span></strong></p></span></p><div data-css="border-color: rgb(249, 110, 87);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;box-sizing: border-box;padding: 10px" style="margin: 0px;padding: 10px;border-color: rgb(23, 148, 221);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px;padding: 0px;"><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525587&amp;idx=2&amp;sn=a18525fe72676659d744674b7d8fdd16&amp;scene=21#wechat_redirect" textvalue="Grafana 多个严重漏洞可用于实现 RCE" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">Grafana 多个严重漏洞可用于实现 RCE</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524487&amp;idx=2&amp;sn=e85da781a2fe55ed8b1a2296242adb26&amp;scene=21#wechat_redirect" textvalue="Grafana SCIM 中存在严重漏洞，可导致身份冒充或提权" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">Grafana SCIM 中存在严重漏洞，可导致身份冒充或提权</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523440&amp;idx=2&amp;sn=85a84a9138ea24b09e9ea0bcb9efe061&amp;scene=21#wechat_redirect" textvalue="速修复！Grafana 修复中存在四个严重的RCE漏洞" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">速修复！Grafana 修复中存在四个严重的RCE漏洞</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523297&amp;idx=2&amp;sn=ea60b085762fef54a56dea85a3150a40&amp;scene=21#wechat_redirect" textvalue="超4.6万个 Grafana 实例易受账户接管漏洞影响" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">超4.6万个 Grafana 实例易受账户接管漏洞影响</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523102&amp;idx=2&amp;sn=3eb6fe83ca06d69dbd0a16a7c73dcde3&amp;scene=21#wechat_redirect" textvalue="Grafana 紧急提前修复已被公开的XSS 0day漏洞" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">Grafana 紧急提前修复已被公开的XSS 0day漏洞</span></a></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 15px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0em;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);font-size: medium;text-align: start;"><span style="margin: 0px;padding: 0px;font-size: 15px;color: rgb(136, 136, 136);text-decoration: underline;"><strong style="margin: 0px;padding: 0px;"><span leaf="">原文链接</span></strong></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;"><a href="https://www.darkreading.com/application-security/grafana-patches-ai-bug-leaked-user-data" target="_blank">https://www.darkreading.com/application-security/grafana-patches-ai-bug-leaked-user-data</a></span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">题图：Pixa</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">bay Licens</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">e</span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><strong style="text-indent: 0em;"><span style="font-size: 15px;color: rgb(136, 136, 136);"><span leaf="">本文由奇安信编译，不代表奇安信观点。转载请注明“转自奇安信代码卫士 <a href="https://codesafe.qianxin.com”。" target="_blank">https://codesafe.qianxin.com”。</a></span></span></strong></p><div data-role="paragraph" style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><div data-id="9499" data-tools="新媒体排版" data-style-type="4" style="color: rgb(0, 0, 0);font-size: 17px;margin: 0px;padding: 0px 0.5em;text-align: start;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px auto;padding: 0px;text-align: center;"><div style="margin: 0px auto;padding: 0px 0px 10px;max-width: 360px !important;"><p style="margin: 0px;padding: 0px 0px 0px 2px;font-size: 0px;width: 65px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.27380952380952384" data-type="jpeg" data-w="84" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;height: auto !important;" data-fileid="100025253" src="https://wechat2rss.xlab.app/img-proxy/?k=20efc9d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSf7nNLWrJL6dkJp7RB8Kl4zxU9ibnQjuvo4VoZ5ic9Q91K3WshWzqEybcroVEOQpgYfx1uYgwJhlFQ%2F640%3Fwx_fmt%3Djpeg"/></p><div data-css="align-items: flex-start;border-color: rgb(255, 138, 101);border-style: solid;border-width: 2px;display: flex;margin-top: -10px;padding: 30px 25px" style="margin: -10px 0px 0px;padding: 30px 25px;align-items: flex-start;border-color: rgb(23, 148, 221);border-style: solid;border-width: 2px;display: flex;"><div style="margin: 0px;padding: 0px;font-size: 0px;flex-shrink: 0;"><p style="margin: 0px;padding: 0px;width: 75px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-type="jpeg" data-w="1080" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;border-color: rgb(238, 238, 238);border-radius: 2px;border-style: solid;border-width: 1px;width: 75px;height: auto !important;" data-cropselx1="0" data-cropselx2="75" data-cropsely1="0" data-cropsely2="75" data-fileid="100025255" src="https://wechat2rss.xlab.app/img-proxy/?k=4657c87c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSN5sfviaCuvYQccJZlrr64sRlvcbdWjDic9mPQ8mBBFDCKP6VibiaNE1kDVuoIOiaIVRoTjSsSftGC8gw%2F640%3Fwx_fmt%3Djpeg"/></p></div><div style="margin: 0px;padding: 0px 0px 0px 15px;flex-shrink: 1;"><p data-css="color: #333;font-size: 18px;line-height:1.7;margin: 0px auto;text-align: left" style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 18px;line-height: 1.7;text-align: left;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;color: rgb(23, 148, 221);"><span leaf="">奇安信代码卫士 (codesafe)</span></span></strong></span></p><p style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 16px;text-align: left;line-height: 1.4;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><span leaf="">国内首个专注于软件开发安全的产品线。</span></span></p></div></div></div></div></div></div><p style="color: rgb(51, 51, 51);font-size: 17px;margin: 0px;padding: 0px 0.5em;clear: both;min-height: 1em;text-align: center;"><span leaf="">   <img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="0.8" data-type="gif" data-w="200" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: middle;color: rgb(0, 0, 0);font-size: 14px;box-sizing: border-box;width: 58.125px;visibility: visible !important;height: auto !important;" data-fileid="100025256" src="https://wechat2rss.xlab.app/img-proxy/?k=fbb024f2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FoBANLWYScMQ5iciaeKS21icDIWSVd0M9zEhicFK0rbCJOrgpc09iaH6nvqvsIdckDfxH2K4tu9CvPJgSf7XhGHJwVyQ%2F640%3Fwx_fmt%3Dgif"/><img data-src=""/></span><span style="margin: 0px;padding: 0px;font-size: 12px;"><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">觉得不错，就点个 “</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">在看</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 或 &#34;</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">赞</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 吧~</span></span></span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://codesafe.qianxin.com/#/home">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=595f1bf1&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2NTg4OTc5Nw%3D%3D%26mid%3D2247525729%26idx%3D3%26sn%3Dbc8793597b56f124d19e242d87e8273d">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 10 Apr 2026 14:10:00 +0800</pubDate>
    </item>
    <item>
      <title>已存在13年的Apache ActiveMQ 严重漏洞可用于远程执行命令</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525686&amp;idx=1&amp;sn=51e7e391e06000c6fad494187241de39</link>
      <description>速修复</description>
      <content:encoded><![CDATA[<p><span>Bill Toulas</span> <span>2026-04-09 18:37</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=5b762113&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft5z0xV2OYfUdaQc6JcJe4papxQRoelnMBytibE8F8wSZEe17OAWjThYX0ltevTY2suLianicxgsuQK1fWPyl9JZShjO6RyJibl5OTDBvFtEicBlM%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>速修复</p>
  <p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span leaf=""><img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="1" data-type="gif" data-w="400" style="margin-right: auto;margin-left: auto;vertical-align: middle;letter-spacing: 0.5px;text-indent: 0em;display: inline-block;box-sizing: border-box !important;visibility: visible !important;width: 30px !important;height: auto !important;" width="30" data-fileid="100025254" src="https://wechat2rss.xlab.app/img-proxy/?k=17396c1a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAz5ZsrEic9ot90z9etZLlU7OTaPOdibteeibJMMmbwc29aJlDOmUicibIRoLdcuEQjtHQ2qjVtZBt0M5eVbYoQzlHiaw%2F640%3Fwx_fmt%3Dgif"/>  </span><span style="text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-mpa-powered-by&#34;:&#34;yiban.io&#34;,&#34;style&#34;:&#34;margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">聚焦源代码安全，网罗国内外最新资讯！</span></span></p><p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;text-align: start;"><strong style="color: rgb(0, 0, 0);letter-spacing: 1px;font-size: 15px;"><span style="font-family: sofia-pro, sans-serif;letter-spacing: normal;text-transform: uppercase;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;transition: color 0.15s ease-out 0s, background-color 0.3s ease-out 0s, text-decoration-color 0.15s ease-out 0s;box-shadow: inset 0 -2px 0 var(--color-black);overflow: hidden;padding-bottom: 4px;color: rgb(136, 136, 136);"><span leaf="">编译：代码卫士</span></span></strong></p><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="paragraph"><div data-tools="135编辑器" data-id="166585"><div style="margin: 10px auto;"><div><div style="background-color: #ffffff;padding: 0px 10px;border-left: 3px solid #1a3566;border-right: 3px solid #1a3566;line-height: 1.1em;box-sizing:border-box;"><p data-autoskip="1" style="text-align: left;line-height: 1.75em;letter-spacing: 1.5px;font-size: 15px;color: #131f35;background-color: transparent;"><span style="font-size: 15px;color: #000000;"><strong><span leaf="">安全研究人员利用 Claude AI 助手，从 Apache ActiveMQ Classic 中发现了一个远程代码执行 (RCE) 漏洞CVE-2026-34197（CVSS评分8.8）。该漏洞已存在13年之久，可用于执行任意命令。该漏洞影响 Apache ActiveMQ/Broker 5.19.4之前以及从6.0.0到6.2.3的所有版本。</span></strong></span></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">Apache ActiveMQ 是一个用 Java 编写的开源消息中间件，通过消息队列或主题来实现异步通信。尽管 ActiveMQ 已推出性能更优的新版 Artemis 分支，但受该漏洞影响的 Classic 版本仍广泛部署于各类基于 Java 构建的企业系统、Web 后端以及政府、公司内部系统中。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">Horizon3 公司的研究员 Naveen Sunkavally 表示，他“仅通过几次基础提示词”就借助 Claude 发现了这个问题，“这个成果八成归功于 Claude，剩下两成是人工包装润色。”Sunkavally 指出，Claude 在逐一分析了多个独立组件（Jolokia、JMX、网络连接器以及 VM 传输协议）后，很快就定位到了该漏洞。他提到，“每个功能单独来看都符合预期，但把它们组合在一起就产生了危险。这正是 Claude 大显身手的地方——它能毫无预设偏见且思路清晰地将这条攻击路径从头到尾串联起来。”该研究员于 3 月 22 日向 Apache 维护人员报告了这一漏洞，后者在 3 月 30 日发布的ActiveMQ Classic 6.2.3 和 5.19.4 版本中修复了该漏洞。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">Horizon3 发布技术报告指出，该漏洞的根源在于 ActiveMQ 的 Jolokia 管理 API 暴露了函数addNetworkConnector，可滥用于加载外部配置。攻击者可通过发送精心构造的请求，强制消息代理拉取一个远程 Spring XML 文件，并在初始化过程中执行任意系统命令。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">触发该漏洞通常需要经过 Jolokia 的身份认证，但由于另一个漏洞 CVE-2024-32114（该漏洞导致 API 在没有访问控制的情况下被暴露）的存在， 6.0.0 至 6.1.1 版本无需进行认证。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">研究人员指出，最新披露的漏洞风险不容小觑，并援引了其他已被黑客用于真实攻击的 ActiveMQ 高危漏洞。研究人员提到，“我们建议所有运行 ActiveMQ 的组织机构优先处理该漏洞，因为 ActiveMQ 一直是真实攻击场景中被反复利用的目标，而且针对它的利用及后渗透方法已经相当成熟。无论是影响 Web 控制台的认证 RCE 漏洞 CVE-2016-3088，还是影响 Broker 端口的未认证 RCE 漏洞 CVE-2023-46604，均已被列入美国 CISA 的已知遭利用漏洞目录（KEV）。”</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">尽管目前尚未有报告显示 CVE-2026-34197 已遭积极利用，但研究人员指出，已在 ActiveMQ Broker 的日志中清晰看到漏洞利用迹象。建议排查使用内部传输协议 VM 的可疑 Broker 连接，以及包含 “brokerConfig=xbean:<a href="http://”查询参数的请求。命令执行会在多次连接尝试过程中触发。研究人员表示，如果系统出现了关于配置问题的警告信息，则意味着恶意载荷已经被执行。" target="_blank">http://”查询参数的请求。命令执行会在多次连接尝试过程中触发。研究人员表示，如果系统出现了关于配置问题的警告信息，则意味着恶意载荷已经被执行。</a></span></span></p></div></div><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;" data-pm-slice="5 3 []"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span style="font-size: 15px;"><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf=""> 开源</span></span><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf="">卫士试用地址：</span><span leaf=""><a href="https://oss.qianxin.com/#/login" target="_blank">https://oss.qianxin.com/#/login</a></span></span></span></span></p><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span leaf=""> 代码卫士试用地址：<a href="https://sast.qianxin.com/#/login" target="_blank">https://sast.qianxin.com/#/login</a></span></span></p><hr style="white-space: normal;border-style: solid;border-right-width: 0px;border-bottom-width: 0px;border-left-width: 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px 0px;transform: scale(1, 0.5);"/><div data-role="paragraph" style="white-space: normal;margin-bottom: 0px;"><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p></div><div data-id="12351" data-tools="新媒体排版" data-style-type="1" style="margin: 0px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);text-align: start;"><div data-css="border-color: initial;border-style: none;border-width: 0px;padding: 0px" style="margin: 0px;padding: 0px;border-color: initial;border-style: none;border-width: 0px;"><div powered-by="KolEditor.us" style="margin: 0px;padding: 0px;"><div style="margin: 10px 0px;padding: 0px;"><p style="font-size: medium;margin: 0px;padding: 0px;display: inline-block;"><span style="margin: 0px;padding: 0.3em 0.5em;background-color: rgb(23, 148, 221);border-radius: 0.8em 0.8em 0px 0px;color: rgb(255, 255, 255);display: block;font-size: 14.08px;"><p style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-size: 18px;"><span leaf=""><span textstyle="" style="font-size: 15px;">推荐阅读</span></span></span></strong></p></span></p><div data-css="border-color: rgb(249, 110, 87);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;box-sizing: border-box;padding: 10px" style="margin: 0px;padding: 10px;border-color: rgb(23, 148, 221);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px;padding: 0px;"><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525048&amp;idx=2&amp;sn=58b797888d5027994282725ccb9f23de&amp;scene=21#wechat_redirect" textvalue="Apache Syncope 漏洞可用于劫持用户会话" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">Apache Syncope 漏洞可用于劫持用户会话</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524857&amp;idx=1&amp;sn=7d98b989a61c9b25103ccef5b0524560&amp;scene=21#wechat_redirect" textvalue="Apache Struts 2 严重 XXE 漏洞可用于窃取敏感数据" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">Apache Struts 2 严重 XXE 漏洞可用于窃取敏感数据</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524778&amp;idx=2&amp;sn=17e6675d731950fb6f61f841bb161ef5&amp;scene=21#wechat_redirect" textvalue="Apache StreamPipes 严重漏洞可用于获取管理员权限" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">Apache StreamPipes 严重漏洞可用于获取管理员权限</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524600&amp;idx=1&amp;sn=fe09ca1df38ec9061341a2100567e69b&amp;scene=21#wechat_redirect" textvalue="速修复！Apache Tika 中存在严重的满分XXE 漏洞" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">速修复！Apache Tika 中存在严重的满分XXE 漏洞</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524305&amp;idx=2&amp;sn=151df83a78bc5a9f5351bf4c295a1d03&amp;scene=21#wechat_redirect" textvalue="Apache Tomcat 漏洞导致服务器易受RCE攻击" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">Apache Tomcat 漏洞导致服务器易受RCE攻击</span></a></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 15px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0em;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);font-size: medium;text-align: start;"><span style="margin: 0px;padding: 0px;font-size: 15px;color: rgb(136, 136, 136);text-decoration: underline;"><strong style="margin: 0px;padding: 0px;"><span leaf="">原文链接</span></strong></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;"><a href="https://www.bleepingcomputer.com/news/security/13-year-old-bug-in-activemq-lets-hackers-remotely-execute-commands/" target="_blank">https://www.bleepingcomputer.com/news/security/13-year-old-bug-in-activemq-lets-hackers-remotely-execute-commands/</a></span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">题图：Pixa</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">bay Licens</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">e</span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><strong style="text-indent: 0em;"><span style="font-size: 15px;color: rgb(136, 136, 136);"><span leaf="">本文由奇安信编译，不代表奇安信观点。转载请注明“转自奇安信代码卫士 <a href="https://codesafe.qianxin.com”。" target="_blank">https://codesafe.qianxin.com”。</a></span></span></strong></p><div data-role="paragraph" style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><div data-id="9499" data-tools="新媒体排版" data-style-type="4" style="color: rgb(0, 0, 0);font-size: 17px;margin: 0px;padding: 0px 0.5em;text-align: start;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px auto;padding: 0px;text-align: center;"><div style="margin: 0px auto;padding: 0px 0px 10px;max-width: 360px !important;"><p style="margin: 0px;padding: 0px 0px 0px 2px;font-size: 0px;width: 65px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.27380952380952384" data-type="jpeg" data-w="84" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;height: auto !important;" data-fileid="100025253" src="https://wechat2rss.xlab.app/img-proxy/?k=20efc9d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSf7nNLWrJL6dkJp7RB8Kl4zxU9ibnQjuvo4VoZ5ic9Q91K3WshWzqEybcroVEOQpgYfx1uYgwJhlFQ%2F640%3Fwx_fmt%3Djpeg"/></p><div data-css="align-items: flex-start;border-color: rgb(255, 138, 101);border-style: solid;border-width: 2px;display: flex;margin-top: -10px;padding: 30px 25px" style="margin: -10px 0px 0px;padding: 30px 25px;align-items: flex-start;border-color: rgb(23, 148, 221);border-style: solid;border-width: 2px;display: flex;"><div style="margin: 0px;padding: 0px;font-size: 0px;flex-shrink: 0;"><p style="margin: 0px;padding: 0px;width: 75px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-type="jpeg" data-w="1080" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;border-color: rgb(238, 238, 238);border-radius: 2px;border-style: solid;border-width: 1px;width: 75px;height: auto !important;" data-cropselx1="0" data-cropselx2="75" data-cropsely1="0" data-cropsely2="75" data-fileid="100025255" src="https://wechat2rss.xlab.app/img-proxy/?k=4657c87c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSN5sfviaCuvYQccJZlrr64sRlvcbdWjDic9mPQ8mBBFDCKP6VibiaNE1kDVuoIOiaIVRoTjSsSftGC8gw%2F640%3Fwx_fmt%3Djpeg"/></p></div><div style="margin: 0px;padding: 0px 0px 0px 15px;flex-shrink: 1;"><p data-css="color: #333;font-size: 18px;line-height:1.7;margin: 0px auto;text-align: left" style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 18px;line-height: 1.7;text-align: left;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;color: rgb(23, 148, 221);"><span leaf="">奇安信代码卫士 (codesafe)</span></span></strong></span></p><p style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 16px;text-align: left;line-height: 1.4;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><span leaf="">国内首个专注于软件开发安全的产品线。</span></span></p></div></div></div></div></div></div><p style="color: rgb(51, 51, 51);font-size: 17px;margin: 0px;padding: 0px 0.5em;clear: both;min-height: 1em;text-align: center;"><span leaf="">   <img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="0.8" data-type="gif" data-w="200" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: middle;color: rgb(0, 0, 0);font-size: 14px;box-sizing: border-box;width: 58.125px;visibility: visible !important;height: auto !important;" data-fileid="100025256" src="https://wechat2rss.xlab.app/img-proxy/?k=fbb024f2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FoBANLWYScMQ5iciaeKS21icDIWSVd0M9zEhicFK0rbCJOrgpc09iaH6nvqvsIdckDfxH2K4tu9CvPJgSf7XhGHJwVyQ%2F640%3Fwx_fmt%3Dgif"/></span><span style="margin: 0px;padding: 0px;font-size: 12px;"><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">觉得不错，就点个 “</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">在看</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 或 &#34;</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">赞</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 吧~</span></span></span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://codesafe.qianxin.com/#/home">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=83a016f3&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2NTg4OTc5Nw%3D%3D%26mid%3D2247525686%26idx%3D1%26sn%3D51e7e391e06000c6fad494187241de39">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 09 Apr 2026 18:37:00 +0800</pubDate>
    </item>
    <item>
      <title>CISA：须在周日前修复已遭利用的 Ivanti EPMM 漏洞</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525686&amp;idx=2&amp;sn=a7cb71292f83e55b49f1e23a7f775864</link>
      <description>速修复</description>
      <content:encoded><![CDATA[<p><span>Sergiu Gatlan</span> <span>2026-04-09 18:37</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=0e506f25&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ft5z0xV2OYfXAbJiaBVIhhFV8FLxMW0A0sfs3ypbQevwAk29vKyNoMKcAqcdicrPjUswRy7sia1AvvujSJOvKdkic1gLo8O4sZicLVvBKx0MMkibUw%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>速修复</p>
  <p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span leaf=""><img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="1" data-type="gif" data-w="400" style="margin-right: auto;margin-left: auto;vertical-align: middle;letter-spacing: 0.5px;text-indent: 0em;display: inline-block;box-sizing: border-box !important;visibility: visible !important;width: 30px !important;height: auto !important;" width="30" data-fileid="100025254" src="https://wechat2rss.xlab.app/img-proxy/?k=17396c1a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAz5ZsrEic9ot90z9etZLlU7OTaPOdibteeibJMMmbwc29aJlDOmUicibIRoLdcuEQjtHQ2qjVtZBt0M5eVbYoQzlHiaw%2F640%3Fwx_fmt%3Dgif"/>  </span><span style="text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-mpa-powered-by&#34;:&#34;yiban.io&#34;,&#34;style&#34;:&#34;margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">聚焦源代码安全，网罗国内外最新资讯！</span></span></p><p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;text-align: start;"><strong style="color: rgb(0, 0, 0);letter-spacing: 1px;font-size: 15px;"><span style="font-family: sofia-pro, sans-serif;letter-spacing: normal;text-transform: uppercase;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;transition: color 0.15s ease-out 0s, background-color 0.3s ease-out 0s, text-decoration-color 0.15s ease-out 0s;box-shadow: inset 0 -2px 0 var(--color-black);overflow: hidden;padding-bottom: 4px;color: rgb(136, 136, 136);"><span leaf="">编译：代码卫士</span></span></strong></p><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="paragraph"><div data-tools="135编辑器" data-id="166585"><div style="margin: 10px auto;"><div><div style="background-color: #ffffff;padding: 0px 10px;border-left: 3px solid #1a3566;border-right: 3px solid #1a3566;line-height: 1.1em;box-sizing:border-box;"><p data-autoskip="1" style="text-align: left;line-height: 1.75em;letter-spacing: 1.5px;font-size: 15px;color: #131f35;background-color: transparent;"><span style="color: #000000;font-size: 15px;"><strong><span leaf="">美国网络安全与基础设施安全局（CISA）要求联邦政府机构在四天内完成系统加固，以防范 Ivanti Endpoint Manager Mobile（EPMM）中已在今年1月份遭实际利用的一个高危漏洞CVE-2026-1340。</span></strong></span></p></div></div></div></div><p style="text-align:left;margin-left: 5px;margin-right: 5px;text-indent: 0em;margin-bottom: 15px;display: block;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">该漏洞是一个高危代码注入漏洞，可导致未授权攻击者在暴露于互联网且未打补丁的 EPMM 设备上实现远程代码执行。Ivanti 公司于 1 月 29 日发布安全更新，修复了该漏洞及另一个安全漏洞 (CVE-2026-1281)，并指出这两个漏洞被用于 0day 攻击。Ivanti 当时“强烈建议”所有客户更新系统，以阻断正在进行的漏洞利用行为。Ivanti 公司当时表示：“成功利用该漏洞可导致未授权远程代码执行。在漏洞披露时，我们已知晓极少数客户的解决方案已遭到利用。”</span></span></p><p style="text-align:left;margin-left: 5px;margin-right: 5px;text-indent: 0em;margin-bottom: 15px;display: block;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">互联网安全监测组织 Shadowserver 目前追踪到近 950 个仍处于暴露状态的Ivanti EPMM 指纹 IP 地址，其中大部分位于欧洲（569 个）和北美（206 个）。不过，目前尚无法知晓其中有多少设备已完成补丁更新。</span></span></p><p style="text-align:left;margin-left: 5px;margin-right: 5px;text-indent: 0em;margin-bottom: 15px;display: block;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">当地时间本周一 CISA 将该漏洞纳入已知被利用漏洞目录（KEV），并根据《约束性操作指令 22-01》（BOD 22-01）的要求，责令联邦民事行政部门 (FCEB) 机构在 4 月 11 日周六午夜前完成 EPMM 系统的补丁修复。</span></span></p><p style="text-align:left;margin-left: 5px;margin-right: 5px;text-indent: 0em;margin-bottom: 15px;display: block;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">CISA 警告称：“此类漏洞是恶意网络行为者的常见攻击入口，对联邦机构的企业网络构成重大风险。请按照厂商指引进行加固，遵循 BOD 22-01 中针对云服务的相关指导；若无法实施缓解措施，则应停止使用该产品。”尽管 BOD 22-01 仅适用于美国联邦机构，CISA 仍建议包括私营部门在内的所有防御方，优先修复该漏洞，尽快加固设备安全。</span></span></p><p style="text-align:left;margin-left: 5px;margin-right: 5px;text-indent: 0em;margin-bottom: 15px;display: block;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">近年来，多个其它 Ivanti 漏洞已在 0day 状态下被用于攻破各类目标，其中包括全球多家政府机构。总体而言，CISA 已将 33 个 Ivanti 漏洞标记为已遭利用，其中 12 个被多个勒索软件团伙利用。</span></span></p><p style="text-align:left;margin-left: 5px;margin-right: 5px;text-indent: 0em;margin-bottom: 15px;display: block;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">Ivanti的全球合作伙伴超过 7000 家，为超过 40000 家客户提供 IT 资产管理产品服务。</span></span></p></div></div><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;" data-pm-slice="5 3 []"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span style="font-size: 15px;"><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf=""> 开源</span></span><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf="">卫士试用地址：</span><span leaf=""><a href="https://oss.qianxin.com/#/login" target="_blank">https://oss.qianxin.com/#/login</a></span></span></span></span></p><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span leaf=""> 代码卫士试用地址：<a href="https://sast.qianxin.com/#/login" target="_blank">https://sast.qianxin.com/#/login</a></span></span></p><hr style="white-space: normal;border-style: solid;border-right-width: 0px;border-bottom-width: 0px;border-left-width: 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px 0px;transform: scale(1, 0.5);"/><div data-role="paragraph" style="white-space: normal;margin-bottom: 0px;"><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p></div><div data-id="12351" data-tools="新媒体排版" data-style-type="1" style="margin: 0px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);text-align: start;"><div data-css="border-color: initial;border-style: none;border-width: 0px;padding: 0px" style="margin: 0px;padding: 0px;border-color: initial;border-style: none;border-width: 0px;"><div powered-by="KolEditor.us" style="margin: 0px;padding: 0px;"><div style="margin: 10px 0px;padding: 0px;"><p style="font-size: medium;margin: 0px;padding: 0px;display: inline-block;"><span style="margin: 0px;padding: 0.3em 0.5em;background-color: rgb(23, 148, 221);border-radius: 0.8em 0.8em 0px 0px;color: rgb(255, 255, 255);display: block;font-size: 14.08px;"><p style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-size: 18px;"><span leaf=""><span textstyle="" style="font-size: 15px;">推荐阅读</span></span></span></strong></p></span></p><div data-css="border-color: rgb(249, 110, 87);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;box-sizing: border-box;padding: 10px" style="margin: 0px;padding: 10px;border-color: rgb(23, 148, 221);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px;padding: 0px;"><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525571&amp;idx=1&amp;sn=3596dc720ddc3cfdb3245a4b7597f249&amp;scene=21#wechat_redirect" textvalue="CISA要求三天内修复这个严重的 F5 BIG-IP 漏洞" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">CISA要求三天内修复这个严重的 F5 BIG-IP 漏洞</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525482&amp;idx=2&amp;sn=92844a4f59d7d7b8344f344ed41a3600&amp;scene=21#wechat_redirect" textvalue="CISA：Wing FTP 已遭利用漏洞可泄露服务器路径" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">CISA：Wing FTP 已遭利用漏洞可泄露服务器路径</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525306&amp;idx=2&amp;sn=bd95e3c5ab9c19e0a8d50c704895e37c&amp;scene=21#wechat_redirect" textvalue="CISA：VMware Aria Operations RCE漏洞已遭利用" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">CISA：VMware Aria Operations RCE漏洞已遭利用</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525108&amp;idx=2&amp;sn=eb3ace41d769ee7dcd8d459a227040f3&amp;scene=21#wechat_redirect" textvalue="Ivanti Endpoint 管理器漏洞可导致远程攻击者泄露任意数据" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">Ivanti Endpoint 管理器漏洞可导致远程攻击者泄露任意数据</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525028&amp;idx=2&amp;sn=762ebd580b93c85ca6f361c47033a215&amp;scene=21#wechat_redirect" textvalue="Ivanti 提醒注意已遭利用的两个 EPMM 漏洞" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">Ivanti 提醒注意已遭利用的两个 EPMM 漏洞</span></a></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 15px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0em;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);font-size: medium;text-align: start;"><span style="margin: 0px;padding: 0px;font-size: 15px;color: rgb(136, 136, 136);text-decoration: underline;"><strong style="margin: 0px;padding: 0px;"><span leaf="">原文链接</span></strong></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;"><a href="https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-exploited-ivanti-epmm-flaw-by-sunday/" target="_blank">https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-exploited-ivanti-epmm-flaw-by-sunday/</a></span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">题图：Pixa</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">bay Licens</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">e</span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><strong style="text-indent: 0em;"><span style="font-size: 15px;color: rgb(136, 136, 136);"><span leaf="">本文由奇安信编译，不代表奇安信观点。转载请注明“转自奇安信代码卫士 <a href="https://codesafe.qianxin.com”。" target="_blank">https://codesafe.qianxin.com”。</a></span></span></strong></p><div data-role="paragraph" style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><div data-id="9499" data-tools="新媒体排版" data-style-type="4" style="color: rgb(0, 0, 0);font-size: 17px;margin: 0px;padding: 0px 0.5em;text-align: start;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px auto;padding: 0px;text-align: center;"><div style="margin: 0px auto;padding: 0px 0px 10px;max-width: 360px !important;"><p style="margin: 0px;padding: 0px 0px 0px 2px;font-size: 0px;width: 65px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.27380952380952384" data-type="jpeg" data-w="84" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;height: auto !important;" data-fileid="100025253" src="https://wechat2rss.xlab.app/img-proxy/?k=20efc9d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSf7nNLWrJL6dkJp7RB8Kl4zxU9ibnQjuvo4VoZ5ic9Q91K3WshWzqEybcroVEOQpgYfx1uYgwJhlFQ%2F640%3Fwx_fmt%3Djpeg"/></p><div data-css="align-items: flex-start;border-color: rgb(255, 138, 101);border-style: solid;border-width: 2px;display: flex;margin-top: -10px;padding: 30px 25px" style="margin: -10px 0px 0px;padding: 30px 25px;align-items: flex-start;border-color: rgb(23, 148, 221);border-style: solid;border-width: 2px;display: flex;"><div style="margin: 0px;padding: 0px;font-size: 0px;flex-shrink: 0;"><p style="margin: 0px;padding: 0px;width: 75px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-type="jpeg" data-w="1080" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;border-color: rgb(238, 238, 238);border-radius: 2px;border-style: solid;border-width: 1px;width: 75px;height: auto !important;" data-cropselx1="0" data-cropselx2="75" data-cropsely1="0" data-cropsely2="75" data-fileid="100025255" src="https://wechat2rss.xlab.app/img-proxy/?k=4657c87c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSN5sfviaCuvYQccJZlrr64sRlvcbdWjDic9mPQ8mBBFDCKP6VibiaNE1kDVuoIOiaIVRoTjSsSftGC8gw%2F640%3Fwx_fmt%3Djpeg"/></p></div><div style="margin: 0px;padding: 0px 0px 0px 15px;flex-shrink: 1;"><p data-css="color: #333;font-size: 18px;line-height:1.7;margin: 0px auto;text-align: left" style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 18px;line-height: 1.7;text-align: left;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;color: rgb(23, 148, 221);"><span leaf="">奇安信代码卫士 (codesafe)</span></span></strong></span></p><p style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 16px;text-align: left;line-height: 1.4;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><span leaf="">国内首个专注于软件开发安全的产品线。</span></span></p></div></div></div></div></div></div><p style="color: rgb(51, 51, 51);font-size: 17px;margin: 0px;padding: 0px 0.5em;clear: both;min-height: 1em;text-align: center;"><span leaf="">   <img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="0.8" data-type="gif" data-w="200" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: middle;color: rgb(0, 0, 0);font-size: 14px;box-sizing: border-box;width: 58.125px;visibility: visible !important;height: auto !important;" data-fileid="100025256" src="https://wechat2rss.xlab.app/img-proxy/?k=fbb024f2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FoBANLWYScMQ5iciaeKS21icDIWSVd0M9zEhicFK0rbCJOrgpc09iaH6nvqvsIdckDfxH2K4tu9CvPJgSf7XhGHJwVyQ%2F640%3Fwx_fmt%3Dgif"/></span><span style="margin: 0px;padding: 0px;font-size: 12px;"><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">觉得不错，就点个 “</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">在看</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 或 &#34;</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">赞</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 吧~</span></span></span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://codesafe.qianxin.com/#/home">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=21cd22dc&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2NTg4OTc5Nw%3D%3D%26mid%3D2247525686%26idx%3D2%26sn%3Da7cb71292f83e55b49f1e23a7f775864">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 09 Apr 2026 18:37:00 +0800</pubDate>
    </item>
    <item>
      <title>开源平台 Flowise 中的满分 RCE 漏洞已遭在野利用</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525680&amp;idx=1&amp;sn=5dbab9da81c7d42eda6c2082c7f2ac03</link>
      <description>速修复</description>
      <content:encoded><![CDATA[<p><span>Bill Toulas</span> <span>2026-04-08 18:14</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=f9a00969&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ft5z0xV2OYfVWnwYHILicdtNxicc1A0z5EUJMO3pRzQd8RTYor8SyfiaAuZCU5Kiap9Xo0EbcMkzV281sibVaDb0PicRicG1MLWesWU1tPYDYKAMYCE%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>速修复</p>
  <p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span leaf=""><img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="1" data-type="gif" data-w="400" style="margin-right: auto;margin-left: auto;vertical-align: middle;letter-spacing: 0.5px;text-indent: 0em;display: inline-block;box-sizing: border-box !important;visibility: visible !important;width: 30px !important;height: auto !important;" width="30" data-fileid="100025254" src="https://wechat2rss.xlab.app/img-proxy/?k=17396c1a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAz5ZsrEic9ot90z9etZLlU7OTaPOdibteeibJMMmbwc29aJlDOmUicibIRoLdcuEQjtHQ2qjVtZBt0M5eVbYoQzlHiaw%2F640%3Fwx_fmt%3Dgif"/>  </span><span style="text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-mpa-powered-by&#34;:&#34;yiban.io&#34;,&#34;style&#34;:&#34;margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">聚焦源代码安全，网罗国内外最新资讯！</span></span></p><p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;text-align: start;"><strong style="color: rgb(0, 0, 0);letter-spacing: 1px;font-size: 15px;"><span style="font-family: sofia-pro, sans-serif;letter-spacing: normal;text-transform: uppercase;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;transition: color 0.15s ease-out 0s, background-color 0.3s ease-out 0s, text-decoration-color 0.15s ease-out 0s;box-shadow: inset 0 -2px 0 var(--color-black);overflow: hidden;padding-bottom: 4px;color: rgb(136, 136, 136);"><span leaf="">编译：代码卫士</span></span></strong></p><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="paragraph"><div data-tools="135编辑器" data-id="166585"><div style="margin: 10px auto;"><div><div style="background-color: #ffffff;padding: 0px 10px;border-left: 3px solid #1a3566;border-right: 3px solid #1a3566;line-height: 1.1em;box-sizing:border-box;"><p data-autoskip="1" style="text-align: left;line-height: 1.75em;letter-spacing: 1.5px;font-size: 15px;color: #131f35;background-color: transparent;"><span style="color: #000000;font-size: 15px;"><strong><span leaf="">常用于构建自定义大模型应用及智能体系统的开源平台 Flowise 中存在一个CVSS满分漏洞CVE-2025-59528，可被用于执行任意代码。</span></strong></span></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">该漏洞的根源在于，系统在未做任何安全检查的情况下便允许注入 JavaScript 代码。该漏洞于去年 9 月公开披露，可用于执行系统命令并访问文件系统。该漏洞位于Flowise 的 CustomMCP 节点上。该节点允许通过配置设置来连接外部 MCP（模型上下文协议）服务器，并对用户输入的 mcpServerConfig进行了不安全的风险求值。在这一过程中，系统会在未经验证其安全性的情况下，直接执行其中的 JavaScript 代码。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">该漏洞已在Flowise 3.0.6 版本中修复。当前最新版本为 3.1.1，已于两周前发布。Flowise 是一个开源的低代码平台，用于构建 AI 智能体以及基于大语言模型的工作流。该平台提供拖拽式界面，使用户能够将各个组件连接成数据处理流水线，从而支撑聊天机器人、自动化流程和 AI 系统的开发。Flowise的用户群体广泛，包括从事 AI 原型开发的开发者、使用无代码工具集的非技术人员，以及运营客服机器人与知识库助手的各类公司。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">漏洞情报公司 VulnCheck 的安全研究员 Caitlin Condon 在领英上宣布称，他们的蜜罐网络已检测到针对 CVE-2025-59528 的在野利用。尽管目前攻击活动看似有限，仅来自一个 Starlink IP 地址，但研究人员警告称，当前互联网上暴露的 Flowise 实例数量在 12000 到 15000 之间。不过，尚不清楚其中有多少属于存在漏洞的 Flowise 服务器。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">Condon 指出，除了 CVE-2025-59528 之外，观测到的攻击活动还涉及同样影响 Flowise 且已被发现遭在野利用的 CVE-2025-8943与CVE-2025-26319。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">目前，VulnCheck 仅向其客户提供漏洞利用样本、网络检测特征以及 YARA 规则。建议 Flowise 用户尽快升级到 3.1.1 版本，或至少更新到 3.0.6 版本。如无需外部访问，还应考虑将实例从公网移除。</span></span></p></div></div><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;" data-pm-slice="5 3 []"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span style="font-size: 15px;"><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf=""> 开源</span></span><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf="">卫士试用地址：</span><span leaf=""><a href="https://oss.qianxin.com/#/login" target="_blank">https://oss.qianxin.com/#/login</a></span></span></span></span></p><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span leaf=""> 代码卫士试用地址：<a href="https://sast.qianxin.com/#/login" target="_blank">https://sast.qianxin.com/#/login</a></span></span></p><hr style="white-space: normal;border-style: solid;border-right-width: 0px;border-bottom-width: 0px;border-left-width: 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px 0px;transform: scale(1, 0.5);"/><div data-role="paragraph" style="white-space: normal;margin-bottom: 0px;"><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p></div><div data-id="12351" data-tools="新媒体排版" data-style-type="1" style="margin: 0px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);text-align: start;"><div data-css="border-color: initial;border-style: none;border-width: 0px;padding: 0px" style="margin: 0px;padding: 0px;border-color: initial;border-style: none;border-width: 0px;"><div powered-by="KolEditor.us" style="margin: 0px;padding: 0px;"><div style="margin: 10px 0px;padding: 0px;"><p style="font-size: medium;margin: 0px;padding: 0px;display: inline-block;"><span style="margin: 0px;padding: 0.3em 0.5em;background-color: rgb(23, 148, 221);border-radius: 0.8em 0.8em 0px 0px;color: rgb(255, 255, 255);display: block;font-size: 14.08px;"><p style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-size: 18px;"><span leaf=""><span textstyle="" style="font-size: 15px;">推荐阅读</span></span></span></strong></p></span></p><div data-css="border-color: rgb(249, 110, 87);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;box-sizing: border-box;padding: 10px" style="margin: 0px;padding: 10px;border-color: rgb(23, 148, 221);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px;padding: 0px;"><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525661&amp;idx=2&amp;sn=e2b376519fd021476f7dc20c7e37091a&amp;scene=21#wechat_redirect" textvalue="GitHub 开源软件仓库遭 AI 自动化供应链攻击" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">GitHub 开源软件仓库遭 AI 自动化供应链攻击</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525357&amp;idx=2&amp;sn=9bdb60d59d4633a80fe9fe32bdec1c60&amp;scene=21#wechat_redirect" textvalue="开源 IAM 平台ZITADEL中存在漏洞，可导致用户账户遭完全接管" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">开源 IAM 平台ZITADEL中存在漏洞，可导致用户账户遭完全接管</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525101&amp;idx=1&amp;sn=ebdb207062b81e30e6939a2fa2e85a8e&amp;scene=21#wechat_redirect" textvalue="开源库 Libpng 漏洞已存在30年，可导致数百万系统遭代码执行攻击" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">开源库 Libpng 漏洞已存在30年，可导致数百万系统遭代码执行攻击</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525085&amp;idx=2&amp;sn=db60b15e1fca3dbe39ef14ac28b16914&amp;scene=21#wechat_redirect" textvalue="Claude Opus 4.6 找到主流开源库中的500多个高危漏洞" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">Claude Opus 4.6 找到主流开源库中的500多个高危漏洞</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524465&amp;idx=2&amp;sn=41ec03ab3c0572c4ecc61e20dcd8fdb6&amp;scene=21#wechat_redirect" textvalue="用AI攻击AI：Ray AI开源框架中的老旧漏洞被用于攻击集群" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">用AI攻击AI：Ray AI开源框架中的老旧漏洞被用于攻击集群</span></a></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 15px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0em;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);font-size: medium;text-align: start;"><span style="margin: 0px;padding: 0px;font-size: 15px;color: rgb(136, 136, 136);text-decoration: underline;"><strong style="margin: 0px;padding: 0px;"><span leaf="">原文链接</span></strong></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;"><a href="https://www.bleepingcomputer.com/news/security/max-severity-flowise-rce-vulnerability-now-exploited-in-attacks/" target="_blank">https://www.bleepingcomputer.com/news/security/max-severity-flowise-rce-vulnerability-now-exploited-in-attacks/</a></span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">题图：Pixa</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">bay Licens</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">e</span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><strong style="text-indent: 0em;"><span style="font-size: 15px;color: rgb(136, 136, 136);"><span leaf="">本文由奇安信编译，不代表奇安信观点。转载请注明“转自奇安信代码卫士 <a href="https://codesafe.qianxin.com”。" target="_blank">https://codesafe.qianxin.com”。</a></span></span></strong></p><div data-role="paragraph" style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><div data-id="9499" data-tools="新媒体排版" data-style-type="4" style="color: rgb(0, 0, 0);font-size: 17px;margin: 0px;padding: 0px 0.5em;text-align: start;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px auto;padding: 0px;text-align: center;"><div style="margin: 0px auto;padding: 0px 0px 10px;max-width: 360px !important;"><p style="margin: 0px;padding: 0px 0px 0px 2px;font-size: 0px;width: 65px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.27380952380952384" data-type="jpeg" data-w="84" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;height: auto !important;" data-fileid="100025253" src="https://wechat2rss.xlab.app/img-proxy/?k=20efc9d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSf7nNLWrJL6dkJp7RB8Kl4zxU9ibnQjuvo4VoZ5ic9Q91K3WshWzqEybcroVEOQpgYfx1uYgwJhlFQ%2F640%3Fwx_fmt%3Djpeg"/></p><div data-css="align-items: flex-start;border-color: rgb(255, 138, 101);border-style: solid;border-width: 2px;display: flex;margin-top: -10px;padding: 30px 25px" style="margin: -10px 0px 0px;padding: 30px 25px;align-items: flex-start;border-color: rgb(23, 148, 221);border-style: solid;border-width: 2px;display: flex;"><div style="margin: 0px;padding: 0px;font-size: 0px;flex-shrink: 0;"><p style="margin: 0px;padding: 0px;width: 75px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-type="jpeg" data-w="1080" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;border-color: rgb(238, 238, 238);border-radius: 2px;border-style: solid;border-width: 1px;width: 75px;height: auto !important;" data-cropselx1="0" data-cropselx2="75" data-cropsely1="0" data-cropsely2="75" data-fileid="100025255" src="https://wechat2rss.xlab.app/img-proxy/?k=4657c87c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSN5sfviaCuvYQccJZlrr64sRlvcbdWjDic9mPQ8mBBFDCKP6VibiaNE1kDVuoIOiaIVRoTjSsSftGC8gw%2F640%3Fwx_fmt%3Djpeg"/></p></div><div style="margin: 0px;padding: 0px 0px 0px 15px;flex-shrink: 1;"><p data-css="color: #333;font-size: 18px;line-height:1.7;margin: 0px auto;text-align: left" style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 18px;line-height: 1.7;text-align: left;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;color: rgb(23, 148, 221);"><span leaf="">奇安信代码卫士 (codesafe)</span></span></strong></span></p><p style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 16px;text-align: left;line-height: 1.4;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><span leaf="">国内首个专注于软件开发安全的产品线。</span></span></p></div></div></div></div></div></div><p style="color: rgb(51, 51, 51);font-size: 17px;margin: 0px;padding: 0px 0.5em;clear: both;min-height: 1em;text-align: center;"><span leaf="">   <img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="0.8" data-type="gif" data-w="200" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: middle;color: rgb(0, 0, 0);font-size: 14px;box-sizing: border-box;width: 58.125px;visibility: visible !important;height: auto !important;" data-fileid="100025256" src="https://wechat2rss.xlab.app/img-proxy/?k=fbb024f2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FoBANLWYScMQ5iciaeKS21icDIWSVd0M9zEhicFK0rbCJOrgpc09iaH6nvqvsIdckDfxH2K4tu9CvPJgSf7XhGHJwVyQ%2F640%3Fwx_fmt%3Dgif"/></span><span style="margin: 0px;padding: 0px;font-size: 12px;"><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">觉得不错，就点个 “</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">在看</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 或 &#34;</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">赞</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 吧~</span></span></span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://codesafe.qianxin.com/#/home">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=2897cb53&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2NTg4OTc5Nw%3D%3D%26mid%3D2247525680%26idx%3D1%26sn%3D5dbab9da81c7d42eda6c2082c7f2ac03">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 08 Apr 2026 18:14:00 +0800</pubDate>
    </item>
    <item>
      <title>OpenAI Codex 漏洞可导致攻击者窃取 GitHub 访问令牌</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525680&amp;idx=2&amp;sn=7f352c49de57475122f8901028f1e192</link>
      <description>速修复</description>
      <content:encoded><![CDATA[<p><span>Abinaya</span> <span>2026-04-08 18:14</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=5656de8f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ft5z0xV2OYfV1pOZ8ibjcyYUs0QffYGc4dM6iaobjZoicVByr7nl2NS23oUeWCzTpzjpTxWgI7XHtgOSOtdOwGo41ErxppAmQibPlcAIhbj3CyicM%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>速修复</p>
  <p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span leaf=""><img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="1" data-type="gif" data-w="400" style="margin-right: auto;margin-left: auto;vertical-align: middle;letter-spacing: 0.5px;text-indent: 0em;display: inline-block;box-sizing: border-box !important;visibility: visible !important;width: 30px !important;height: auto !important;" width="30" data-fileid="100025254" src="https://wechat2rss.xlab.app/img-proxy/?k=17396c1a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAz5ZsrEic9ot90z9etZLlU7OTaPOdibteeibJMMmbwc29aJlDOmUicibIRoLdcuEQjtHQ2qjVtZBt0M5eVbYoQzlHiaw%2F640%3Fwx_fmt%3Dgif"/>  </span><span style="text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-mpa-powered-by&#34;:&#34;yiban.io&#34;,&#34;style&#34;:&#34;margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">聚焦源代码安全，网罗国内外最新资讯！</span></span></p><p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;text-align: start;"><strong style="color: rgb(0, 0, 0);letter-spacing: 1px;font-size: 15px;"><span style="font-family: sofia-pro, sans-serif;letter-spacing: normal;text-transform: uppercase;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;transition: color 0.15s ease-out 0s, background-color 0.3s ease-out 0s, text-decoration-color 0.15s ease-out 0s;box-shadow: inset 0 -2px 0 var(--color-black);overflow: hidden;padding-bottom: 4px;color: rgb(136, 136, 136);"><span leaf="">编译：代码卫士</span></span></strong></p><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="paragraph"><div data-tools="135编辑器" data-id="166585"><div style="margin: 10px auto;"><div><div style="background-color: #ffffff;padding: 0px 10px;border-left: 3px solid #1a3566;border-right: 3px solid #1a3566;line-height: 1.1em;box-sizing:border-box;"><p data-autoskip="1" style="text-align: left;line-height: 1.75em;letter-spacing: 1.5px;font-size: 15px;color: #131f35;background-color: transparent;"><span style="color: #000000;font-size: 15px;"><strong><span leaf="">BeyondTrust </span></strong><strong><span leaf="">公司旗下的 Phantom 实验室最近在 OpenAI Codex 中发现了一个严重的命令注入漏洞，可导致攻击者窃取敏感的 GitHub 用户访问令牌。</span></strong></span></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">威胁人员可利用 Codex 处理任务创建请求的方式，通过授予 AI 代理的权限，横向移动到组织机构的 GitHub 环境中。</span></span></p><div data-role="title" data-tools="135编辑器" data-id="166211"><div style="margin: 10px auto;display: flex;justify-content: center;"><div style="display: flex;align-items: center;"><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" data-imgfileid="100042028" data-ratio="0.9817850637522769" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-type="gif" data-w="549" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=66afffd1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ft5z0xV2OYfXbVe7HBYVVhFoIDibSTicA0hiaPVUInybTicXmayFkcIbYGqxjZVtCZ4wkic4ksO1nBic61ic9OlicprDtCYD2C5T0grRibWDJTogNxJ2c%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div><p style="font-size: 16px;color: #2e407b;text-align: center;padding: 0 6px;box-sizing:border-box;transform: rotateZ(0deg);-webkit-transform: rotateZ(0deg);-moz-transform: rotateZ(0deg);-o-transform: rotateZ(0deg);"><strong data-brushtype="text"><span leaf="">命令注入利用</span></strong></p></div><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" data-imgfileid="100042027" data-ratio="0.9817850637522769" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-type="gif" data-w="549" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=1c85403c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Ft5z0xV2OYfXn3l5h8ZYvYkTl0P8icF4U9m0QW0GK4TKYaJIgGibaqyTm5qf2JyO8d3oPHbic7e0xhO9sw5MDga1QmViaNbtXGmHtbHmhtxPHWPQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">OpenAI Codex 是一款基于云的编程助手，直接连接到开发人员的 GitHub 仓库。当用户提交一个提示词时，Codex 就会启动一个管理容器来运行多项任务如代码生成或仓库分析。研究人员发现在该容器的设置阶段，系统未能正确清理输入。具体而言，HTTP POST 请求中的 GitHub 分支名称参数被直接传递给环境的设置脚本。攻击者可通过将 shell 命令注入分支名称的方式利用该漏洞。例如，恶意 payload 可强制系统将隐藏的 GitHub OAuth 令牌输出位刻度文本文件。接着攻击者可提示 Codex 代理读取该文件，从而将明文令牌直接暴露到 web 接口中。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">而危险会扩散到本地开发者环境中。研究人员发现桌面 Codex 应用将认证凭据本地存储在一个认证文件中。如果攻击者获得对运行 Windows、macOS 或 Linux 的开发者机器的访问权限，则可窃取这些会话令牌。通过使用这些遭攻陷本地令牌在后端 API 进行认证，攻击者可检索用户的所有任务历史。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">该后端访问权限还可导致攻击者提取隐藏在容器任务日志深处的 GitHub 访问令牌，同时攻击也可自动化，在无需与 Codex 接口进行交互的情况下攻陷多个用户。在一个 GitHub 共享仓库中直接创建恶意分支，可导致攻击者通过 Codex 在特定代码库中触发利用。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">为了绕过 GitHub 用于拦截常规空格的分支-命名限制，攻击者可通过包含内部字段分隔符的 payload 替换这些空格。攻击者还可巧妙地利用 Unicode 表意空格将恶意载荷在用户界面上隐藏起来。对于毫无戒心的受害者而言，恶意分支看起来与标准的 main 分支完全一样。一旦用户或自动流程与之交互，则该 payload 会悄悄在后台执行，将自己的 GitHub 令牌发送给遭攻击者控制的外部分支。</span></span></p><div data-role="title" data-tools="135编辑器" data-id="166211"><div style="margin: 10px auto;display: flex;justify-content: center;"><div style="display: flex;align-items: center;"><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" data-imgfileid="100042029" data-ratio="0.9817850637522769" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-type="gif" data-w="549" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=89386496&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ft5z0xV2OYfVYOE9DQFXatMicChl2T6YLLKia6r53bGOS8ZnXdoCpXOzDuf55ZcdMZM7XhZXRjdAzZWH5SCUjdYia51hB9xw7hLLW2O4uaE7Jjk%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div><p style="font-size: 16px;color: #2e407b;text-align: center;padding: 0 6px;box-sizing:border-box;transform: rotateZ(0deg);-webkit-transform: rotateZ(0deg);-moz-transform: rotateZ(0deg);-o-transform: rotateZ(0deg);"><strong data-brushtype="text"><span leaf="">窃取安装令牌</span></strong></p></div><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" data-imgfileid="100042026" data-ratio="0.9817850637522769" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-type="gif" data-w="549" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=a92fa811&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Ft5z0xV2OYfWlQDT81VPAAImeia0jUdrjj4s36B33O0NAbPagZaGZcibaKn36FDaOjZtGcHuDd3LII8iczjvNW3icPyZoGBzQvKic4AQYD7aH2iaT0%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">这种自动化分支攻击同样适用于自动化拉取请求。当开发者在拉取请求中标记 Codex 机器人执行代码审查时，系统会启动代码审查容器。如果该仓库中包含该恶意命名的分支，自动化容器就会执行隐藏 payload，从而导致攻击者窃取具有更广权限的 GitHub 安装访问令牌。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="color: #0f1115;font-size: 15px;letter-spacing: 1px;"><span leaf="">该漏洞为“严重”等级，影响 ChatGPT 网站、Codex CLI、Codex SDK 和 Codex IDE 扩展。OpenAI 在2025年12月收到负责任的漏洞报告，并在2026年1月末修复该漏洞。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">随着 AI 编程助手日益深度地融入开发者的工作流程，各组织机构必须将智能体容器视为严格的安全边界。</span></span></p><p data-role="list"><ul style="list-style-type: disc;margin:0px;padding:0 0 0 30px;list-style-position:outside;" class="list-paddingleft-2"><li><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">开发团队与安全团队应开展以下实践：</span></span></p></li><li><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">在将用户可控的所有输入传递给 shell 命令之前，对其进行清理。</span></span></p></li><li><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">永远不要认为外部提供商的数据格</span><span style="color: #0f1115;font-size: 15px;letter-spacing: 1px;"><span leaf="">式本身是安全的。</span></span></span></p></li><li><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="color: #0f1115;font-size: 15px;letter-spacing: 1px;"><span leaf="">审计授予 AI 应用的权限，严格执行最小权限原则。</span></span></p></li><li><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="color: #0f1115;font-size: 15px;letter-spacing: 1px;"><span leaf="">监控代码仓库中是否出现包含 shell 元字符或 Unicode 空格的异常分支名称。</span></span></p></li><li><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="color: #0f1115;font-size: 15px;letter-spacing: 1px;"><span leaf="">定期更换 GitHub 令牌，并检查访问日志中是否存在异常的 API 活动。</span></span></p></li></ul></p></div></div><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;" data-pm-slice="5 3 []"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span style="font-size: 15px;"><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf=""> 开源</span></span><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf="">卫士试用地址：</span><span leaf=""><a href="https://oss.qianxin.com/#/login" target="_blank">https://oss.qianxin.com/#/login</a></span></span></span></span></p><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span leaf=""> 代码卫士试用地址：<a href="https://sast.qianxin.com/#/login" target="_blank">https://sast.qianxin.com/#/login</a></span></span></p><hr style="white-space: normal;border-style: solid;border-right-width: 0px;border-bottom-width: 0px;border-left-width: 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px 0px;transform: scale(1, 0.5);"/><div data-role="paragraph" style="white-space: normal;margin-bottom: 0px;"><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p></div><div data-id="12351" data-tools="新媒体排版" data-style-type="1" style="margin: 0px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);text-align: start;"><div data-css="border-color: initial;border-style: none;border-width: 0px;padding: 0px" style="margin: 0px;padding: 0px;border-color: initial;border-style: none;border-width: 0px;"><div powered-by="KolEditor.us" style="margin: 0px;padding: 0px;"><div style="margin: 10px 0px;padding: 0px;"><p style="font-size: medium;margin: 0px;padding: 0px;display: inline-block;"><span style="margin: 0px;padding: 0.3em 0.5em;background-color: rgb(23, 148, 221);border-radius: 0.8em 0.8em 0px 0px;color: rgb(255, 255, 255);display: block;font-size: 14.08px;"><p style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-size: 18px;"><span leaf=""><span textstyle="" style="font-size: 15px;">推荐阅读</span></span></span></strong></p></span></p><div data-css="border-color: rgb(249, 110, 87);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;box-sizing: border-box;padding: 10px" style="margin: 0px;padding: 10px;border-color: rgb(23, 148, 221);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px;padding: 0px;"><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525564&amp;idx=1&amp;sn=87a38b04609d00236ed5984ced8a6243&amp;scene=21#wechat_redirect" textvalue="OpenAI 发布AI安全漏洞奖励计划" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">OpenAI 发布AI安全漏洞奖励计划</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524571&amp;idx=2&amp;sn=e4271fa2e064e2011e1b779ac929f05f&amp;scene=21#wechat_redirect" textvalue="OpenAI 编程代理中高危漏洞可用于攻击开发人员" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">OpenAI 编程代理中高危漏洞可用于攻击开发人员</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524535&amp;idx=1&amp;sn=b7fe9e8a785380e376468375bde77bce&amp;scene=21#wechat_redirect" textvalue="第三方供应商导致OpenAI客户数据遭泄露" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">第三方供应商导致OpenAI客户数据遭泄露</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523149&amp;idx=1&amp;sn=0298267a08369cc3ea9bdbdec81eb788&amp;scene=21#wechat_redirect" textvalue="看我如何通过 OpenAI o3 挖到 Linux 内核远程 0day" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">看我如何通过 OpenAI o3 挖到 Linux 内核远程 0day</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247522605&amp;idx=1&amp;sn=d013414cab5f1de1d4ec9080c742585e&amp;scene=21#wechat_redirect" textvalue="OpenAI 严重漏洞最高赏金提高至10万美元" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">OpenAI 严重漏洞最高赏金提高至10万美元</span></a></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 15px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0em;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);font-size: medium;text-align: start;"><span style="margin: 0px;padding: 0px;font-size: 15px;color: rgb(136, 136, 136);text-decoration: underline;"><strong style="margin: 0px;padding: 0px;"><span leaf="">原文链接</span></strong></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;"><a href="https://cybersecuritynews.com/openai-codex-command-injection-vulnerability/" target="_blank">https://cybersecuritynews.com/openai-codex-command-injection-vulnerability/</a></span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">题图：Pixa</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">bay Licens</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">e</span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><strong style="text-indent: 0em;"><span style="font-size: 15px;color: rgb(136, 136, 136);"><span leaf="">本文由奇安信编译，不代表奇安信观点。转载请注明“转自奇安信代码卫士 <a href="https://codesafe.qianxin.com”。" target="_blank">https://codesafe.qianxin.com”。</a></span></span></strong></p><div data-role="paragraph" style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><div data-id="9499" data-tools="新媒体排版" data-style-type="4" style="color: rgb(0, 0, 0);font-size: 17px;margin: 0px;padding: 0px 0.5em;text-align: start;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px auto;padding: 0px;text-align: center;"><div style="margin: 0px auto;padding: 0px 0px 10px;max-width: 360px !important;"><p style="margin: 0px;padding: 0px 0px 0px 2px;font-size: 0px;width: 65px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.27380952380952384" data-type="jpeg" data-w="84" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;height: auto !important;" data-fileid="100025253" src="https://wechat2rss.xlab.app/img-proxy/?k=20efc9d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSf7nNLWrJL6dkJp7RB8Kl4zxU9ibnQjuvo4VoZ5ic9Q91K3WshWzqEybcroVEOQpgYfx1uYgwJhlFQ%2F640%3Fwx_fmt%3Djpeg"/></p><div data-css="align-items: flex-start;border-color: rgb(255, 138, 101);border-style: solid;border-width: 2px;display: flex;margin-top: -10px;padding: 30px 25px" style="margin: -10px 0px 0px;padding: 30px 25px;align-items: flex-start;border-color: rgb(23, 148, 221);border-style: solid;border-width: 2px;display: flex;"><div style="margin: 0px;padding: 0px;font-size: 0px;flex-shrink: 0;"><p style="margin: 0px;padding: 0px;width: 75px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-type="jpeg" data-w="1080" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;border-color: rgb(238, 238, 238);border-radius: 2px;border-style: solid;border-width: 1px;width: 75px;height: auto !important;" data-cropselx1="0" data-cropselx2="75" data-cropsely1="0" data-cropsely2="75" data-fileid="100025255" src="https://wechat2rss.xlab.app/img-proxy/?k=4657c87c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSN5sfviaCuvYQccJZlrr64sRlvcbdWjDic9mPQ8mBBFDCKP6VibiaNE1kDVuoIOiaIVRoTjSsSftGC8gw%2F640%3Fwx_fmt%3Djpeg"/></p></div><div style="margin: 0px;padding: 0px 0px 0px 15px;flex-shrink: 1;"><p data-css="color: #333;font-size: 18px;line-height:1.7;margin: 0px auto;text-align: left" style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 18px;line-height: 1.7;text-align: left;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;color: rgb(23, 148, 221);"><span leaf="">奇安信代码卫士 (codesafe)</span></span></strong></span></p><p style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 16px;text-align: left;line-height: 1.4;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><span leaf="">国内首个专注于软件开发安全的产品线。</span></span></p></div></div></div></div></div></div><p style="color: rgb(51, 51, 51);font-size: 17px;margin: 0px;padding: 0px 0.5em;clear: both;min-height: 1em;text-align: center;"><span leaf="">   <img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="0.8" data-type="gif" data-w="200" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: middle;color: rgb(0, 0, 0);font-size: 14px;box-sizing: border-box;width: 58.125px;visibility: visible !important;height: auto !important;" data-fileid="100025256" src="https://wechat2rss.xlab.app/img-proxy/?k=fbb024f2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FoBANLWYScMQ5iciaeKS21icDIWSVd0M9zEhicFK0rbCJOrgpc09iaH6nvqvsIdckDfxH2K4tu9CvPJgSf7XhGHJwVyQ%2F640%3Fwx_fmt%3Dgif"/></span><span style="margin: 0px;padding: 0px;font-size: 12px;"><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">觉得不错，就点个 “</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">在看</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 或 &#34;</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">赞</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 吧~</span></span></span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://codesafe.qianxin.com/#/home">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=b555723a&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2NTg4OTc5Nw%3D%3D%26mid%3D2247525680%26idx%3D2%26sn%3D7f352c49de57475122f8901028f1e192">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 08 Apr 2026 18:14:00 +0800</pubDate>
    </item>
    <item>
      <title>Fortinet 紧急修复已遭利用的 FortiClient EMS 严重漏洞</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525661&amp;idx=1&amp;sn=052e45a26cbea5f9364bf03c39a7abc8</link>
      <description>速修复</description>
      <content:encoded><![CDATA[<p><span>综合编译</span> <span>2026-04-07 18:07</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=5e23ff06&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft5z0xV2OYfUJtlfw7o87ebzvUFowhRuAhoHSoSxG3fhOWKZEmCkaD9eXGxS3aYiaBhaqTVuzuR6Um7FLoWBgPZcKjLD1OJmiagicgickVUEczc4%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>速修复</p>
  <p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span leaf=""><img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="1" data-type="gif" data-w="400" style="margin-right: auto;margin-left: auto;vertical-align: middle;letter-spacing: 0.5px;text-indent: 0em;display: inline-block;box-sizing: border-box !important;visibility: visible !important;width: 30px !important;height: auto !important;" width="30" data-fileid="100025254" src="https://wechat2rss.xlab.app/img-proxy/?k=17396c1a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAz5ZsrEic9ot90z9etZLlU7OTaPOdibteeibJMMmbwc29aJlDOmUicibIRoLdcuEQjtHQ2qjVtZBt0M5eVbYoQzlHiaw%2F640%3Fwx_fmt%3Dgif"/>  </span><span style="text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-mpa-powered-by&#34;:&#34;yiban.io&#34;,&#34;style&#34;:&#34;margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">聚焦源代码安全，网罗国内外最新资讯！</span></span></p><p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;text-align: start;"><strong style="color: rgb(0, 0, 0);letter-spacing: 1px;font-size: 15px;"><span style="font-family: sofia-pro, sans-serif;letter-spacing: normal;text-transform: uppercase;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;transition: color 0.15s ease-out 0s, background-color 0.3s ease-out 0s, text-decoration-color 0.15s ease-out 0s;box-shadow: inset 0 -2px 0 var(--color-black);overflow: hidden;padding-bottom: 4px;color: rgb(136, 136, 136);"><span leaf="">编译：代码卫士</span></span></strong></p><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="paragraph"><div data-tools="135编辑器" data-id="166585"><div style="margin: 10px auto;"><div><div style="background-color: #ffffff;padding: 0px 10px;border-left: 3px solid #1a3566;border-right: 3px solid #1a3566;line-height: 1.1em;box-sizing:border-box;"><p data-autoskip="1" style="text-align: left;line-height: 1.75em;letter-spacing: 1.5px;font-size: 15px;color: #131f35;background-color: transparent;"><span style="font-size: 15px;"><strong><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">上周末，Fortinet 公司紧急修复了一个已遭利用的FortiClient 企业管理服务器（EMS）高危漏洞CVE-2026-35616。该漏洞是访问控制不当问题，可导致未经过身份验证的攻击者通过发送特殊构造的请求执行代码或命令。Fortinet 于上周六修复该漏洞，并确认该漏洞已遭在野利用。</span></span></strong></span></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">Fortinet 公司告警称：“Fortinet 已发现该漏洞遭在野利用，并敦促受影响客户尽快安装针对 FortiClient EMS 7.4.5 和 7.4.6 版本的热补丁。”该公司表示，该漏洞影响 FortiClient EMS 7.4.5 和 7.4.6 版本，可通过安装以下其中任一热补丁进行修复：</span></span></p><p data-role="list"><ul style="list-style-type: disc;margin:0px;padding:0 0 0 30px;list-style-position:outside;" class="list-paddingleft-2"><li><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">FortiClient EMS 7.4.5：<a href="https://docs.fortinet.com/document/forticlient/7.4.5/ems-release-notes/832484" target="_blank">https://docs.fortinet.com/document/forticlient/7.4.5/ems-release-notes/832484</a>  </span></span></p></li><li><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">FortiClient EMS 7.4.6：<a href="https://docs.fortinet.com/document/forticlient/7.4.6/ems-release-notes/832484" target="_blank">https://docs.fortinet.com/document/forticlient/7.4.6/ems-release-notes/832484</a></span></span></p></li></ul></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">即将发布的 FortiClient EMS 7.4.7 版本也将修复该漏洞。FortiClient EMS 7.2 版本不受影响。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">该漏洞由网络安全公司 Defused 发现，后者认为该漏洞是一个预认证 API 访问绕过漏洞，可导致攻击者完全绕过身份验证与授权控制。Defused 在 X 平台上表示，本周早些时候他们观察到该漏洞作为 0day 漏洞被利用，随后依照负责任的披露流程向 Fortinet 公司报告了此事。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">互联网安全监测机构 Shadowserver 已发现超过 2000 个暴露在公网的 FortiClient EMS 实例，其中大部分位于美国和德国。上周，FortiClient EMS中的另外一个高危漏洞 CVE-2026-21643，也已遭在野利用。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">这两个漏洞均由 Defused 发现，其中CVE-2026-35616的贡献者也包括Nguyen Duc Anh。Fortinet 公司敦促客户立即安装热补丁，或待 7.4.7 版本发布后尽快升级，降低系统被入侵的风险。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">本周一，美国网络安全和基础设施安全局 (CISA) 将CVE-2026-35616 纳入已知遭利用 (KEV) 清单，并要求联邦民事行政部门 (FCEB) 在当地时间4月9日12点之前修复该漏洞。CISA 提到，这类漏洞是恶意人员经常利用的攻击向量，为联邦企业带来严重风险。</span></span></p></div></div><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;" data-pm-slice="5 3 []"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span style="font-size: 15px;"><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf=""> 开源</span></span><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf="">卫士试用地址：</span><span leaf=""><a href="https://oss.qianxin.com/#/login" target="_blank">https://oss.qianxin.com/#/login</a></span></span></span></span></p><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span leaf=""> 代码卫士试用地址：<a href="https://sast.qianxin.com/#/login" target="_blank">https://sast.qianxin.com/#/login</a></span></span></p><hr style="white-space: normal;border-style: solid;border-right-width: 0px;border-bottom-width: 0px;border-left-width: 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px 0px;transform: scale(1, 0.5);"/><div data-role="paragraph" style="white-space: normal;margin-bottom: 0px;"><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p></div><div data-id="12351" data-tools="新媒体排版" data-style-type="1" style="margin: 0px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);text-align: start;"><div data-css="border-color: initial;border-style: none;border-width: 0px;padding: 0px" style="margin: 0px;padding: 0px;border-color: initial;border-style: none;border-width: 0px;"><div powered-by="KolEditor.us" style="margin: 0px;padding: 0px;"><div style="margin: 10px 0px;padding: 0px;"><p style="font-size: medium;margin: 0px;padding: 0px;display: inline-block;"><span style="margin: 0px;padding: 0.3em 0.5em;background-color: rgb(23, 148, 221);border-radius: 0.8em 0.8em 0px 0px;color: rgb(255, 255, 255);display: block;font-size: 14.08px;"><p style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-size: 18px;"><span leaf=""><span textstyle="" style="font-size: 15px;">推荐阅读</span></span></span></strong></p></span></p><div data-css="border-color: rgb(249, 110, 87);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;box-sizing: border-box;padding: 10px" style="margin: 0px;padding: 10px;border-color: rgb(23, 148, 221);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px;padding: 0px;"><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525085&amp;idx=1&amp;sn=446f5400a46600a37f24df299ba852d2&amp;scene=21#wechat_redirect" textvalue="Fortinet 修复可导致未认证代码执行的严重 SQLi 漏洞" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">Fortinet 修复可导致未认证代码执行的严重 SQLi 漏洞</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524999&amp;idx=2&amp;sn=ff036e0f85b25e6ee0f685062e7a537f&amp;scene=21#wechat_redirect" textvalue="Fortinet 修复已遭利用的严重 FortiOS 漏洞" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">Fortinet 修复已遭利用的严重 FortiOS 漏洞</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524747&amp;idx=1&amp;sn=4048d2d12b0a64ce62d92a0b79a83100&amp;scene=21#wechat_redirect" textvalue="Fortinet：5年前的FortiOS SSL VPN 2FA绕过漏洞正遭活跃利用" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">Fortinet：5年前的FortiOS SSL VPN 2FA绕过漏洞正遭活跃利用</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524465&amp;idx=1&amp;sn=cf210939b4c44de97b60529383818aaa&amp;scene=21#wechat_redirect" textvalue="CISA要求政府机构在7天内修复这个 Fortinet 新0day" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">CISA要求政府机构在7天内修复这个 Fortinet 新0day</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247519274&amp;idx=1&amp;sn=0db6fdb46bf03ada98af3901110ee37b&amp;scene=21#wechat_redirect" textvalue="Fortinet 修复严重的 FortiClientLinux 漏洞" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">Fortinet 修复严重的 FortiClientLinux 漏洞</span></a></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 15px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0em;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);font-size: medium;text-align: start;"><span style="margin: 0px;padding: 0px;font-size: 15px;color: rgb(136, 136, 136);text-decoration: underline;"><strong style="margin: 0px;padding: 0px;"><span leaf="">原文链接</span></strong></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span lang="EN-US"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;"><a href="https://www.bleepingcomputer.com/news/security/new-fortinet-forticlient-ems-flaw-cve-2026-35616-exploited-in-attacks/" target="_blank">https://www.bleepingcomputer.com/news/security/new-fortinet-forticlient-ems-flaw-cve-2026-35616-exploited-in-attacks/</a></span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span lang="EN-US"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;"><a href="https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-fortinet-flaw-exploited-in-attacks-by-friday/" target="_blank">https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-fortinet-flaw-exploited-in-attacks-by-friday/</a></span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">题图：Pixa</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">bay Licens</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">e</span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><strong style="text-indent: 0em;"><span style="font-size: 15px;color: rgb(136, 136, 136);"><span leaf="">本文由奇安信编译，不代表奇安信观点。转载请注明“转自奇安信代码卫士 <a href="https://codesafe.qianxin.com”。" target="_blank">https://codesafe.qianxin.com”。</a></span></span></strong></p><div data-role="paragraph" style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><div data-id="9499" data-tools="新媒体排版" data-style-type="4" style="color: rgb(0, 0, 0);font-size: 17px;margin: 0px;padding: 0px 0.5em;text-align: start;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px auto;padding: 0px;text-align: center;"><div style="margin: 0px auto;padding: 0px 0px 10px;max-width: 360px !important;"><p style="margin: 0px;padding: 0px 0px 0px 2px;font-size: 0px;width: 65px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.27380952380952384" data-type="jpeg" data-w="84" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;height: auto !important;" data-fileid="100025253" src="https://wechat2rss.xlab.app/img-proxy/?k=20efc9d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSf7nNLWrJL6dkJp7RB8Kl4zxU9ibnQjuvo4VoZ5ic9Q91K3WshWzqEybcroVEOQpgYfx1uYgwJhlFQ%2F640%3Fwx_fmt%3Djpeg"/></p><div data-css="align-items: flex-start;border-color: rgb(255, 138, 101);border-style: solid;border-width: 2px;display: flex;margin-top: -10px;padding: 30px 25px" style="margin: -10px 0px 0px;padding: 30px 25px;align-items: flex-start;border-color: rgb(23, 148, 221);border-style: solid;border-width: 2px;display: flex;"><div style="margin: 0px;padding: 0px;font-size: 0px;flex-shrink: 0;"><p style="margin: 0px;padding: 0px;width: 75px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-type="jpeg" data-w="1080" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;border-color: rgb(238, 238, 238);border-radius: 2px;border-style: solid;border-width: 1px;width: 75px;height: auto !important;" data-cropselx1="0" data-cropselx2="75" data-cropsely1="0" data-cropsely2="75" data-fileid="100025255" src="https://wechat2rss.xlab.app/img-proxy/?k=4657c87c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSN5sfviaCuvYQccJZlrr64sRlvcbdWjDic9mPQ8mBBFDCKP6VibiaNE1kDVuoIOiaIVRoTjSsSftGC8gw%2F640%3Fwx_fmt%3Djpeg"/></p></div><div style="margin: 0px;padding: 0px 0px 0px 15px;flex-shrink: 1;"><p data-css="color: #333;font-size: 18px;line-height:1.7;margin: 0px auto;text-align: left" style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 18px;line-height: 1.7;text-align: left;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;color: rgb(23, 148, 221);"><span leaf="">奇安信代码卫士 (codesafe)</span></span></strong></span></p><p style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 16px;text-align: left;line-height: 1.4;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><span leaf="">国内首个专注于软件开发安全的产品线。</span></span></p></div></div></div></div></div></div><p style="color: rgb(51, 51, 51);font-size: 17px;margin: 0px;padding: 0px 0.5em;clear: both;min-height: 1em;text-align: center;"><span leaf="">   <img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="0.8" data-type="gif" data-w="200" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: middle;color: rgb(0, 0, 0);font-size: 14px;box-sizing: border-box;width: 58.125px;visibility: visible !important;height: auto !important;" data-fileid="100025256" src="https://wechat2rss.xlab.app/img-proxy/?k=fbb024f2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FoBANLWYScMQ5iciaeKS21icDIWSVd0M9zEhicFK0rbCJOrgpc09iaH6nvqvsIdckDfxH2K4tu9CvPJgSf7XhGHJwVyQ%2F640%3Fwx_fmt%3Dgif"/></span><span style="margin: 0px;padding: 0px;font-size: 12px;"><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">觉得不错，就点个 “</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">在看</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 或 &#34;</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">赞</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 吧~</span></span></span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://codesafe.qianxin.com/#/home">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=aaf71090&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2NTg4OTc5Nw%3D%3D%26mid%3D2247525661%26idx%3D1%26sn%3D052e45a26cbea5f9364bf03c39a7abc8">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 07 Apr 2026 18:07:00 +0800</pubDate>
    </item>
    <item>
      <title>GitHub 开源软件仓库遭 AI 自动化供应链攻击</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525661&amp;idx=2&amp;sn=e2b376519fd021476f7dc20c7e37091a</link>
      <description>近几个月内的第二起AI辅助供应链攻击</description>
      <content:encoded><![CDATA[<p><span>Jai Vijayan</span> <span>2026-04-07 18:07</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=029626de&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMQuoJibNce8dlpAMTvqm21iaKUXsfFGTCs9y03jFZZUgVLrh0SDAU6C0fGKxrxZAHqh8SPia88JeHUDg%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>近几个月内的第二起AI辅助供应链攻击</p>
  <p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span leaf=""><img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="1" data-type="gif" data-w="400" style="margin-right: auto;margin-left: auto;vertical-align: middle;letter-spacing: 0.5px;text-indent: 0em;display: inline-block;box-sizing: border-box !important;visibility: visible !important;width: 30px !important;height: auto !important;" width="30" data-fileid="100025254" src="https://wechat2rss.xlab.app/img-proxy/?k=17396c1a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAz5ZsrEic9ot90z9etZLlU7OTaPOdibteeibJMMmbwc29aJlDOmUicibIRoLdcuEQjtHQ2qjVtZBt0M5eVbYoQzlHiaw%2F640%3Fwx_fmt%3Dgif"/> <span textstyle="" style="font-size: 14px;color: rgb(0, 122, 170);">聚焦源代码安全，网罗国内外最新资讯！</span></span></p><p style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(136, 136, 136);font-weight: bold;">编译：代码卫士</span></span></p><p style="margin-bottom: 0px;white-space: normal;text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4255555555555556" data-s="300,640" data-type="png" data-w="900" style="height: auto !important;" data-fileid="100025221" src="https://wechat2rss.xlab.app/img-proxy/?k=091c2efc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FoBANLWYScMRSylJK2k7H6mNqiaS2G6WRaeeK34cLHE6pe9VeOIHYiboAnKB0TMoayZCxFpHMLljzTnz9DnNuFiaqQ%2F640%3Fwx_fmt%3Dpng"/></p><div data-role="outer" label="Powered by 135editor.com" style="margin-bottom: 0px;white-space: normal;"><div data-tools="135编辑器" data-id="102705"><div style="margin: 10px auto;text-align: left;"><div style="background: rgb(79, 129, 189);"><div style="margin-left: 10px;display: flex;justify-content: flex-start;align-items: center;"><p style="padding-right: 10px;padding-left: 10px;font-size: 18px;letter-spacing: 1.5px;color: rgb(255, 255, 255);font-weight: bold;flex-shrink: 0;text-align: center;"><span leaf="">专栏·供应链安全</span></p></div></div><div style="padding: 1em 1em 1.3em;background: rgb(240, 250, 246);border-bottom: 1px solid rgb(79, 129, 189);"><div data-autoskip="1" style="text-align: justify;line-height: 1.75em;letter-spacing: 1.5px;font-size: 14px;color: rgb(79, 129, 189);background: transparent;"><p><span style="font-size: 15px;font-family: arial, helvetica, sans-serif;"><span leaf="">数字化时代，软件无处不在。软件如同社会中的“虚拟人”，已经成为支撑社会正常运转的最基本元素之一，软件的安全性问题也正在成为当今社会的根本性、基础性问题。</span></span></p><p><span style="font-size: 15px;font-family: arial, helvetica, sans-serif;"><span leaf="">随着软件产业的快速发展，软件供应链也越发复杂多元，复杂的软件供应链会引入一系列的安全问题，导致信息系统的整体安全防护难度越来越大。近年来，针对软件供应链的安全攻击事件一直呈快速增长态势，造成的危害也越来越严重。</span></span></p><p><span style="font-size: 15px;font-family: arial, helvetica, sans-serif;"><span leaf="">为此，我们推出“供应链安全”栏目。本栏目汇聚供应链安全资讯，分析供应链安全风险，提供缓解建议，为供应链安全保驾护航。</span></span></p><p style="text-align: left;"><span style="color: rgb(136, 136, 136);"><em><span leaf="">注：以往发布的部分供应链安全相关内容，请见文末“推荐阅读”部分。</span></em></span></p></div></div><div data-role="paragraph"><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="paragraph"><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="paragraph"><div data-tools="135编辑器" data-id="166585"><div style="margin: 10px auto;"><div style="display: flex;"><div style="flex-shrink: 0;"><div style="display: flex;"><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="paragraph"><div data-tools="135编辑器" data-id="166585"><div style="margin: 10px auto;"><div><div style="background-color: #ffffff;padding: 0px 10px;border-left: 3px solid #1a3566;border-right: 3px solid #1a3566;line-height: 1.1em;box-sizing:border-box;"><p data-autoskip="1" style="text-align: left;line-height: 1.75em;letter-spacing: 1.5px;font-size: 15px;color: #131f35;background-color: transparent;"><span style="font-size: 15px;"><strong><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">一名威胁行动者疑似利用人工智能辅助的自动化手段，对 GitHub 上的开源软件仓库发起了数百次漏洞利用尝试。</span></span></strong></span></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="letter-spacing: 1px;font-size: 15px;"><span leaf="">云安全厂商 Wiz 分析了超过 450 次攻击尝试，其中成功的比例不到 10%，但攻击者确实成功入侵了至少两个 NPM 软件包。该活动最早由 Aikido Security 公司的研究员 Charlie Eriksen 于 4 月 2 日发现。不过，Wiz 随后调查显示，该攻击行动大约在三周前，即 3 月 11 日就已开始，并通过六个不同的 GitHub 账号分六波进行。研究人员认为这些账号均归属于同一个威胁攻击者。</span></span></p><div data-role="title" data-tools="135编辑器" data-id="166211"><div style="margin: 10px auto;display: flex;justify-content: center;"><div style="display: flex;align-items: center;"><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100042009" src="https://wechat2rss.xlab.app/img-proxy/?k=c801d69a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ft5z0xV2OYfXDLGfLDDNWHFr7EYhkVwmhIt4oPia9ibTniaB7XhSsNuc7TpPV3TrxJiapq3HzoiaLiaLaK78VNZP8ngibXiaX1B1u95waAXrg05eq3gk%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div><p style="font-size: 16px;color: #2e407b;text-align: center;padding: 0 6px;box-sizing:border-box;transform: rotateZ(0deg);-webkit-transform: rotateZ(0deg);-moz-transform: rotateZ(0deg);-o-transform: rotateZ(0deg);"><strong data-brushtype="text"><span leaf="">第二起 AI 增强型供应链攻击行动</span></strong></p></div><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100042007" src="https://wechat2rss.xlab.app/img-proxy/?k=ef6b7180&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ft5z0xV2OYfXnBJmPDh9SfEPEjynKTvFicPPt9eEkqBHicpMPP996VyGF9XdzYNibUFwIC2CHuHJwdf6LrsI2aPZ3afkEwxMoX7ib1OHVUwibicmGU%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="letter-spacing: 1px;font-size: 15px;"><span leaf="">该攻击活动被 Wiz 命名为“prt-scan”，针对GitHub 上配置了 pull_request_target 工作流触发器的代码仓库发起攻击，是近几周内的第二次AI自动化攻击活动。此前在 2 月底还发生过一起名为 “hackerbot-claw” 的攻击行动，攻击者同样通过恶意拉取请求利用该功能，窃取 GitHub 令牌、密钥、环境变量以及云凭证。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="letter-spacing: 1px;font-size: 15px;"><span leaf="">“hackerbot-claw”攻击活动的持续时间较短，目标更具针对性，主要瞄准知名代码仓库。而根据Wiz公司的分析，“prt-scan”行动的规模则要大得多，威胁攻击者针对GitHub上的小型和大型项目发起了远超500次拉取请求，但成功率更低。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="letter-spacing: 1px;font-size: 15px;"><span leaf="">Wiz的研究人员在上周六发布的一份报告中写道：“大多数情况下，攻击针对的是小型个人爱好者项目，并且只暴露了工作流使用的临时GitHub凭证。总体而言，除了极少数例外，该行动并未让攻击者获得生产基础设施、云凭证或持久性API密钥的访问权限。”不过，Wiz提醒称，该攻击给企业带来的更广泛启示和警示是：AI增强型自动化技术已显著降低了攻击者发起大规模供应链攻击的门槛。技术能力不高的攻击者现在可以用过去所需的一小部分时间和精力，就对数百个目标发起新的攻击行动。开发者通过拉取请求向GitHub上的项目提交代码修改建议，项目维护者则可以对这些请求进行审查、讨论，并将其合并到主代码中。GitHub Actions中的 “pull_request_target” 触发器机制规定：每当有拉取请求（即使来自不可信的分支）被提交时，都会自动在主仓库中运行工作流。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="letter-spacing: 1px;font-size: 15px;"><span leaf="">由于该操作拥有完整的仓库权限，并且能够访问仓库中的密钥信息，攻击者可能利用恶意的拉取请求窃取 API 密钥或凭证。Wiz 指出，如果在处理不受信任的拉取请求时，不加任何限制地使用该触发器，就构成了一种众所周知且有据可查的错误配置。</span></span></p><div data-role="title" data-tools="135编辑器" data-id="166211"><div style="margin: 10px auto;display: flex;justify-content: center;"><div style="display: flex;align-items: center;"><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100042010" src="https://wechat2rss.xlab.app/img-proxy/?k=79046b71&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ft5z0xV2OYfU7BdZKlNfC0qviaP5icVoWibcFMZcibRkehqEJ6t6x5XWITwXh5trc2b2Cu65URlkKkK2aeIY97a4jHtIoWAcoNsUacCmTuFtEPvM%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div><p style="font-size: 16px;color: #2e407b;text-align: center;padding: 0 6px;box-sizing:border-box;transform: rotateZ(0deg);-webkit-transform: rotateZ(0deg);-moz-transform: rotateZ(0deg);-o-transform: rotateZ(0deg);"><strong data-brushtype="text"><span leaf="">存在缺陷的攻击链</span></strong></p></div><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100042008" src="https://wechat2rss.xlab.app/img-proxy/?k=9a2bf3b8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ft5z0xV2OYfVLrKelHXk6B4m1mlQxzeGABpbbB5WAibLEB6trnpEgfFIicibJ7HgXQzic6BPvTerI4KxYXAZ1kXPSSl8apic6ibLmoNJEto2eR4Hjo%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="letter-spacing: 1px;font-size: 15px;"><span leaf="">在“prt-scan”攻击活动中，攻击者首先扫描使用 GitHub Actions 中 pull_request_target 触发器的仓库，然后复刻这些仓库，创建分支，将恶意代码隐藏在一次看似常规的更新中，进而诱骗项目自动运行该代码。Wiz 表示，攻击者借此获得访问权限，从而窃取敏感数据或传播恶意软件。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="letter-spacing: 1px;font-size: 15px;"><span leaf="">Wiz 的分析显示，该攻击活动始于 3 月 11 日，当时攻击者发起了 10 次恶意拉取请求，这一阶段似乎是测试期，一直持续到 3 月 16 日。随后，在中断了近两周后，攻击者以极快的速度重新开始提交恶意拉取请求，Wiz 认为这种速度表明其使用了 AI 辅助的自动化技术。从 4 月 2 日开始，攻击者在 26 小时内发起了约 475 次拉取请求，这些请求中包含用于窃取凭证的复杂恶意载荷。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="letter-spacing: 1px;font-size: 15px;"><span leaf="">不过有趣的是，Wiz 指出，尽管恶意载荷设计得颇为宏大，但实际的攻击实现却很粗糙，表明攻击者并未完全理解 GitHub 的权限模型。该安全厂商表示：“攻击者尝试了复杂的多阶段载荷，但其中充斥的技术手段在专家看来不合逻辑，在实践中几乎难以奏效。”</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="letter-spacing: 1px;font-size: 15px;"><span leaf="">尽管攻击手法存在缺陷，Wiz 表示，10% 的成功率仍然导致了数十起入侵事件。研究人员还公布了“prt-scan”攻击活动的相关入侵指标（IoCs），并敦促各组织加强 GitHub 环境的安全配置，以防范此类攻击。</span></span></p></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span style="font-size: 15px;"><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf="">开源</span></span><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf="">卫士试用地址：</span></span><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span style="font-size: 15px;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 15px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><a href="https://sast.qianxin.com/#/login" target="_blank">https://sast.qianxin.com/#/login</a></span></span></span></span></span></p><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span leaf="">代码卫士试用地址：</span><span style="font-size: 15px;"><span leaf=""><a href="https://codesafe.qianxin.com" target="_blank">https://codesafe.qianxin.com</a></span></span></span></p><hr style="white-space: normal;border-style: solid;border-right-width: 0px;border-bottom-width: 0px;border-left-width: 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px 0px;transform: scale(1, 0.5);"/><div data-role="paragraph" style="white-space: normal;margin-bottom: 0px;"><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p></div><div data-id="12351" data-tools="新媒体排版" data-style-type="1" style="margin: 0px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);text-align: start;"><div data-css="border-color: initial;border-style: none;border-width: 0px;padding: 0px" style="margin: 0px;padding: 0px;border-color: initial;border-style: none;border-width: 0px;"><div powered-by="KolEditor.us" style="margin: 0px;padding: 0px;"><div style="margin: 10px 0px;padding: 0px;"><p style="font-size: medium;margin: 0px;padding: 0px;display: inline-block;"><span data-css="background-color: rgb(249, 110, 87);border-radius: 0.8em 0.8em 0px 0px;box-sizing: border-box;color: rgb(255, 255, 255);display: block;font-size: 14.08px;padding: 0.3em 0.5em" style="margin: 0px;padding: 0.3em 0.5em;background-color: rgb(23, 148, 221);border-radius: 0.8em 0.8em 0px 0px;color: rgb(255, 255, 255);display: block;font-size: 14.08px;"><p style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-size: 18px;"><span leaf="">推荐阅读</span></span></strong></p></span></p><div data-css="border-color: rgb(249, 110, 87);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;box-sizing: border-box;padding: 10px" style="margin: 0px;padding: 10px;border-color: rgb(23, 148, 221);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px;padding: 0px;" data-pm-slice="0 0 []"><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523516&amp;idx=1&amp;sn=0b6fc53ba92e7b5135395b67fff6a822&amp;scene=21#wechat_redirect" textvalue="在线阅读版：《2025中国软件供应链安全分析报告》全文" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">在线阅读版：《2025中国软件供应链安全分析报告》全文</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525520&amp;idx=2&amp;sn=b3d4dddc586c4b0aa8cefb09c0344cb8&amp;scene=21#wechat_redirect" textvalue="Trivy供应链攻击触发CanisterWorm 在47个 npm 包中自传播" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">Trivy供应链攻击触发CanisterWorm 在47个 npm 包中自传播</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524984&amp;idx=1&amp;sn=19aef4ce8e288278782458e430a710d8&amp;scene=21#wechat_redirect" textvalue="热门包管理器中存在多个漏洞，JavaScript 生态系统易受供应链攻击" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">热门包管理器中存在多个漏洞，JavaScript 生态系统易受供应链攻击</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524828&amp;idx=2&amp;sn=21af241f60f1452013815133745e9a72&amp;scene=21#wechat_redirect" textvalue="开源自托管平台 Coolify 修复11个严重漏洞，可导致服务器遭完全攻陷" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">开源自托管平台 Coolify 修复11个严重漏洞，可导致服务器遭完全攻陷</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524487&amp;idx=1&amp;sn=f170d3131122071dec6e419c6cff562c&amp;scene=21#wechat_redirect" textvalue="得不到就毁掉：第二轮Sha1-Hulud供应链攻击已发起，影响2.5万+仓库" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">得不到就毁掉：第二轮Sha1-Hulud供应链攻击已发起，影响2.5万+仓库</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524481&amp;idx=3&amp;sn=6d0b161f8add2f6c1ee65e60ef6955d8&amp;scene=21#wechat_redirect" textvalue="vLLM 高危漏洞可导致RCE" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">vLLM 高危漏洞可导致RCE</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247519162&amp;idx=1&amp;sn=3872fcc82018e2c561d9e4e7574f0c8e&amp;scene=21#wechat_redirect" textvalue="开源AI框架 Ray 的0day已用于攻陷服务器和劫持资源" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">开源AI框架 Ray 的0day已用于攻陷服务器和劫持资源</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524330&amp;idx=2&amp;sn=bc54e02a8f815ed78b67d3135a9f9607&amp;scene=21#wechat_redirect" textvalue="热门 React Native NPM 包中存在严重漏洞，开发人员易受攻击" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">热门 React Native NPM 包中存在严重漏洞，开发人员易受攻击</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524314&amp;idx=2&amp;sn=81cae6998a39f2153ed18d7cc065303b&amp;scene=21#wechat_redirect" textvalue="10个npm包被指窃取 Windows、macOS 和 Linux 系统上的开发者凭据" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">10个npm包被指窃取 Windows、macOS 和 Linux 系统上的开发者凭据</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524330&amp;idx=2&amp;sn=bc54e02a8f815ed78b67d3135a9f9607&amp;scene=21#wechat_redirect" textvalue="热门 React Native NPM 包中存在严重漏洞，开发人员易受攻击" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">热门 React Native NPM 包中存在严重漏洞，开发人员易受攻击</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247508946&amp;idx=1&amp;sn=273c58d08a4225306a567cf6a150f40c&amp;scene=21#wechat_redirect" textvalue="热门NPM库 “coa” 和“rc” 接连遭劫持，影响全球的 React 管道" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">热门NPM库 “coa” 和“rc” 接连遭劫持，影响全球的 React 管道</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247515219&amp;idx=1&amp;sn=faa32338df1d68e7cd738a80222f3a44&amp;scene=21#wechat_redirect" textvalue="开发人员注意：VSCode 应用市场易被滥用于托管恶意扩展" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">开发人员注意：VSCode 应用市场易被滥用于托管恶意扩展</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524163&amp;idx=1&amp;sn=d70a7c55e27a3e179522330a9ce62b0b&amp;scene=21#wechat_redirect" textvalue="GitHub Copilot 严重漏洞可导致私有仓库源代码被盗" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">GitHub Copilot 严重漏洞可导致私有仓库源代码被盗</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524053&amp;idx=1&amp;sn=2b843932ebd4eeeb17b6935b08be82f8&amp;scene=21#wechat_redirect" textvalue="受 Salesforce 供应链攻击影响，全球汽车巨头 Stellantis 数据遭泄露" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">受 Salesforce 供应链攻击影响，全球汽车巨头 Stellantis 数据遭泄露</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523990&amp;idx=1&amp;sn=ad9957a5c3d054d4a0bf32250bceb556&amp;scene=21#wechat_redirect" textvalue="捷豹路虎数据遭泄露生产仍未恢复，幕后黑手或与 Salesforce-Salesloft 供应链攻击有关" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">捷豹路虎数据遭泄露生产仍未恢复，幕后黑手或与 Salesforce-Salesloft 供应链攻击有关</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523972&amp;idx=1&amp;sn=7b06c31940ea7576d0236d9310886b39&amp;scene=21#wechat_redirect" textvalue="十几家安全大厂信息遭泄露，谁是 Salesforce-Salesloft 供应链攻击的下一个受害者？" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">十几家安全大厂信息遭泄露，谁是 Salesforce-Salesloft 供应链攻击的下一个受害者？</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523952&amp;idx=1&amp;sn=2bc84253019e6c2525bcf928eaed696c&amp;scene=21#wechat_redirect" textvalue="第三方集成应用 Drift OAuth 令牌被用于攻陷 Salesforce 实例，全球700+家企业受影响" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">第三方集成应用 Drift OAuth 令牌被用于攻陷 Salesforce 实例，全球700+家企业受影响</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523990&amp;idx=2&amp;sn=6e38e1ee8cd69f1375a5be218c02ff97&amp;scene=21#wechat_redirect" textvalue="黑客发动史上规模最大的 NPM 供应链攻击，影响全球10%的云环境" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">黑客发动史上规模最大的 NPM 供应链攻击，影响全球10%的云环境</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523972&amp;idx=1&amp;sn=7b06c31940ea7576d0236d9310886b39&amp;scene=21#wechat_redirect" textvalue="十几家安全大厂信息遭泄露，谁是 Salesforce-Salesloft 供应链攻击的下一个受害者？" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">十几家安全大厂信息遭泄露，谁是 Salesforce-Salesloft 供应链攻击的下一个受害者？</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523952&amp;idx=1&amp;sn=2bc84253019e6c2525bcf928eaed696c&amp;scene=21#wechat_redirect" textvalue="第三方集成应用 Drift OAuth 令牌被用于攻陷 Salesforce 实例，全球700+家企业受影响" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">第三方集成应用 Drift OAuth 令牌被用于攻陷 Salesforce 实例，全球700+家企业受影响</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523962&amp;idx=1&amp;sn=2d9b8ca044c242a6ae1f72df93d7acb0&amp;scene=21#wechat_redirect" textvalue="AI供应链易遭“模型命名空间复用”攻击" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">AI供应链易遭“模型命名空间复用”攻击</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523957&amp;idx=2&amp;sn=288b0d14a657b13c7f1a6b14705a44e8&amp;scene=21#wechat_redirect" textvalue="Frostbyte10：威胁全球供应链的10个严重漏洞" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">Frostbyte10：威胁全球供应链的10个严重漏洞</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523850&amp;idx=2&amp;sn=72dc01d9984a720959b312dd0e7cf05e&amp;scene=21#wechat_redirect" textvalue="PyPI拦截1800个过期域名邮件，防御供应链攻击" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">PyPI拦截1800个过期域名邮件，防御供应链攻击</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523844&amp;idx=2&amp;sn=08c8962eead61fe76467a9196b3da3e5&amp;scene=21#wechat_redirect" textvalue="PyPI恶意包利用依赖引入恶意行为，发动软件供应链攻击" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">PyPI恶意包利用依赖引入恶意行为，发动软件供应链攻击</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523700&amp;idx=2&amp;sn=463d300bdfd3de129cd5d258ceb67cf4&amp;scene=21#wechat_redirect" textvalue="黑客利用虚假 PyPI 站点钓鱼攻击Python 开发人员" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">黑客利用虚假 PyPI 站点钓鱼攻击Python 开发人员</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247492823&amp;idx=2&amp;sn=9c226ff328303e78331451ac5219df07&amp;scene=21#wechat_redirect" textvalue="700多个恶意误植域名库盯上RubyGems 仓库" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">700多个恶意误植域名库盯上RubyGems 仓库</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523648&amp;idx=1&amp;sn=d9237c45bf78637d1cdd3bedd1d873e6&amp;scene=21#wechat_redirect" textvalue="NPM “意外” 删除 Stylus 合法包 全球流水线和构建被迫中断" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">NPM “意外” 删除 Stylus 合法包 全球流水线和构建被迫中断</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523615&amp;idx=1&amp;sn=1df256011200be03dc2afc80016c587e&amp;scene=21#wechat_redirect" textvalue="固件开发和更新缺陷导致漏洞多年难修，供应链安全深受其害" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">固件开发和更新缺陷导致漏洞多年难修，供应链安全深受其害</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523592&amp;idx=2&amp;sn=5087c0aa841caf3f0def9a1ca6c5ad27&amp;scene=21#wechat_redirect" textvalue="NPM仓库被植入67个恶意包传播恶意软件" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">NPM仓库被植入67个恶意包传播恶意软件</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523516&amp;idx=1&amp;sn=0b6fc53ba92e7b5135395b67fff6a822&amp;scene=21#wechat_redirect" textvalue="在线阅读版：《2025中国软件供应链安全分析报告》全文" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">在线阅读版：《2025中国软件供应链安全分析报告》全文</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523234&amp;idx=2&amp;sn=ac4e0656fd04218349d356761af176dd&amp;scene=21#wechat_redirect" textvalue="NPM软件供应链攻击传播恶意软件" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">NPM软件供应链攻击传播恶意软件</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523167&amp;idx=2&amp;sn=4249c8e9e0dace01810c665eda52c421&amp;scene=21#wechat_redirect" textvalue="隐秘的 npm 供应链攻击：误植域名导致RCE和数据破坏" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">隐秘的 npm 供应链攻击：误植域名导致RCE和数据破坏</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523031&amp;idx=2&amp;sn=5071cdb63bdd6339b1a3ff7ef3581cd5&amp;scene=21#wechat_redirect" textvalue="NPM恶意包利用Unicode 隐写术躲避检测" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">NPM恶意包利用Unicode 隐写术躲避检测</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247522945&amp;idx=1&amp;sn=c767722383afc7e6b505aef2f50ba4cd&amp;scene=21#wechat_redirect" textvalue="Aikido在npm热门包 rand-user-agent 中发现恶意代码" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">Aikido在npm热门包 rand-user-agent 中发现恶意代码</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247522841&amp;idx=2&amp;sn=024b6c290bf4ebecc241f11bc944be1c&amp;scene=21#wechat_redirect" textvalue="密币Ripple 的NPM 包 xrpl.js 被安装后门窃取私钥，触发供应链攻击" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">密币Ripple 的NPM 包 xrpl.js 被安装后门窃取私钥，触发供应链攻击</span></a></span></p></div></div></div></div></div></div></div><p style="margin-bottom: 15px;padding-right: 0.5em;padding-left: 0.5em;text-indent: 0em;white-space: normal;letter-spacing: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;"><span style="font-size: 15px;color: rgb(136, 136, 136);text-decoration: underline;"><strong><span leaf="">原文链接</span></strong></span></p><p style="margin-bottom: 15px;padding-right: 0.5em;padding-left: 0.5em;text-indent: 0em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: normal;"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="text-align: start;letter-spacing: normal;font-weight: bold;text-indent: 0em;font-size: 15px;color: rgb(136, 136, 136);"><span textstyle="" style="font-weight: normal;"><a href="https://www.darkreading.com/application-security/ai-assisted-supply-chain-attack-targets-github" target="_blank">https://www.darkreading.com/application-security/ai-assisted-supply-chain-attack-targets-github</a></span></span></span></p><p style="margin-bottom: 15px;padding-right: 0.5em;padding-left: 0.5em;text-indent: 0em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: normal;"><strong style="white-space: normal;text-align: start;letter-spacing: normal;font-weight: bold;text-indent: 0em;font-size: 15px;color: rgb(136, 136, 136);"><span leaf="" style="font-weight: bold;text-indent: 0em;font-size: 15px;color: rgb(136, 136, 136);">本文由奇安信编译，不代表</span></strong><strong style="text-indent: 0em;"><span style="font-size: 15px;color: rgb(136, 136, 136);"><span leaf="">奇安信观点。转载请注明“转自奇安信代码卫士 <a href="https://codesafe.qianxin.com”。" target="_blank">https://codesafe.qianxin.com”。</a></span></span></strong></p><div data-id="9499" data-tools="新媒体排版" data-style-type="4" style="color: rgb(0, 0, 0);font-size: 17px;margin: 0px;padding: 0px 0.5em;text-align: start;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px auto;padding: 0px;text-align: center;"><div style="margin: 0px auto;padding: 0px 0px 10px;max-width: 360px !important;"><p style="margin: 0px;padding: 0px 0px 0px 2px;font-size: 0px;width: 65px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.27380952380952384" data-type="jpeg" data-w="84" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;height: auto !important;" data-fileid="100025253" src="https://wechat2rss.xlab.app/img-proxy/?k=20efc9d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSf7nNLWrJL6dkJp7RB8Kl4zxU9ibnQjuvo4VoZ5ic9Q91K3WshWzqEybcroVEOQpgYfx1uYgwJhlFQ%2F640%3Fwx_fmt%3Djpeg"/></p><div data-css="align-items: flex-start;border-color: rgb(255, 138, 101);border-style: solid;border-width: 2px;display: flex;margin-top: -10px;padding: 30px 25px" style="margin: -10px 0px 0px;padding: 30px 25px;align-items: flex-start;border-color: rgb(23, 148, 221);border-style: solid;border-width: 2px;display: flex;"><div style="margin: 0px;padding: 0px;font-size: 0px;flex-shrink: 0;"><p style="margin: 0px;padding: 0px;width: 75px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-type="jpeg" data-w="1080" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;border-color: rgb(238, 238, 238);border-radius: 2px;border-style: solid;border-width: 1px;width: 75px;height: auto !important;" data-cropselx1="0" data-cropselx2="75" data-cropsely1="0" data-cropsely2="75" data-fileid="100025255" src="https://wechat2rss.xlab.app/img-proxy/?k=4657c87c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSN5sfviaCuvYQccJZlrr64sRlvcbdWjDic9mPQ8mBBFDCKP6VibiaNE1kDVuoIOiaIVRoTjSsSftGC8gw%2F640%3Fwx_fmt%3Djpeg"/></p></div><div style="margin: 0px;padding: 0px 0px 0px 15px;flex-shrink: 1;"><p data-css="color: #333;font-size: 18px;line-height:1.7;margin: 0px auto;text-align: left" style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 18px;line-height: 1.7;text-align: left;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><strong style="margin: 0px;padding: 0px;"><span data-css="color: rgb(52, 195, 131)" style="margin: 0px;padding: 0px;color: rgb(23, 148, 221);"><span leaf="">奇安信代码卫士 (codesafe)</span></span></strong></span></p><p style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 16px;text-align: left;line-height: 1.4;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><span leaf="">国内首个专注于软件开发安全的产品线。</span></span></p></div></div></div></div></div></div><p style="color: rgb(51, 51, 51);font-size: 17px;margin: 0px;padding: 0px 0.5em;clear: both;min-height: 1em;text-align: center;"><span leaf="">   <img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="0.8" data-type="gif" data-w="200" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: middle;color: rgb(0, 0, 0);font-size: 14px;box-sizing: border-box;width: 58.125px;visibility: visible !important;height: auto !important;" data-fileid="100025256" src="https://wechat2rss.xlab.app/img-proxy/?k=fbb024f2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FoBANLWYScMQ5iciaeKS21icDIWSVd0M9zEhicFK0rbCJOrgpc09iaH6nvqvsIdckDfxH2K4tu9CvPJgSf7XhGHJwVyQ%2F640%3Fwx_fmt%3Dgif"/></span><span style="margin: 0px;padding: 0px;font-size: 12px;"><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">觉得不错，就点个 “</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">在看</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 或 &#34;</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">赞</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 吧~</span></span></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://codesafe.qianxin.com/#/home">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=7b41fe19&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2NTg4OTc5Nw%3D%3D%26mid%3D2247525661%26idx%3D2%26sn%3De2b376519fd021476f7dc20c7e37091a">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 07 Apr 2026 18:07:00 +0800</pubDate>
    </item>
    <item>
      <title>思科 IMC 中存在严重的认证绕过漏洞，可用于获取管理员权限</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525643&amp;idx=1&amp;sn=123aa4e38d29ce29d7107d5e7378e00f</link>
      <description>速修复</description>
      <content:encoded><![CDATA[<p><span>Sergiu Gatlan</span> <span>2026-04-03 17:52</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=69b973d8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft5z0xV2OYfWBrTMnMJy47ZVT31j0EvTm01gibDwNMWLeyucBYXc5mRDYjuGRvIGonhTTduAMByQJXlOAOWsTvGWn51x9icnIYg1EfFOUX94WE%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>速修复</p>
  <p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span leaf=""><img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="1" data-type="gif" data-w="400" style="margin-right: auto;margin-left: auto;vertical-align: middle;letter-spacing: 0.5px;text-indent: 0em;display: inline-block;box-sizing: border-box !important;visibility: visible !important;width: 30px !important;height: auto !important;" width="30" data-fileid="100025254" src="https://wechat2rss.xlab.app/img-proxy/?k=17396c1a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAz5ZsrEic9ot90z9etZLlU7OTaPOdibteeibJMMmbwc29aJlDOmUicibIRoLdcuEQjtHQ2qjVtZBt0M5eVbYoQzlHiaw%2F640%3Fwx_fmt%3Dgif"/>  </span><span style="text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-mpa-powered-by&#34;:&#34;yiban.io&#34;,&#34;style&#34;:&#34;margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">聚焦源代码安全，网罗国内外最新资讯！</span></span></p><p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;text-align: start;"><strong style="color: rgb(0, 0, 0);letter-spacing: 1px;font-size: 15px;"><span style="font-family: sofia-pro, sans-serif;letter-spacing: normal;text-transform: uppercase;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;transition: color 0.15s ease-out 0s, background-color 0.3s ease-out 0s, text-decoration-color 0.15s ease-out 0s;box-shadow: inset 0 -2px 0 var(--color-black);overflow: hidden;padding-bottom: 4px;color: rgb(136, 136, 136);"><span leaf="">编译：代码卫士</span></span></strong></p><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="paragraph"><div data-tools="135编辑器" data-id="166585"><div style="margin: 10px auto;"><div><div style="background-color: #ffffff;padding: 0px 10px;border-left: 3px solid #1a3566;border-right: 3px solid #1a3566;line-height: 1.1em;box-sizing:border-box;"><p data-autoskip="1" style="text-align: left;line-height: 1.75em;letter-spacing: 1.5px;font-size: 15px;color: #131f35;background-color: transparent;"><span style="font-size: 15px;"><strong><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">思科发布安全更新，修复了多个高危和严重漏洞，其中集成管理控制器（IMC）的身份验证绕过漏洞 (CVE-2026-20093) 可导致攻击者获得管理员权限。</span></span></strong></span></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">思科IMC也被称为CIMC，是嵌入在思科服务器主板上的硬件模块，用于为UCS C系列和E系列服务器提供带外管理功能（即使在操作系统关机或崩溃的情况下也能使用），支持通过XML API、网页（WebUI）和命令行（CLI）等多种接口进行管理。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">该漏洞存在于思科IMC的密码更改功能中，可被未经身份验证的攻击者远程利用，绕过身份验证并以管理员权限访问未打补丁的系统。思科在周三解释称：“该漏洞是由于对密码更改请求的处理不正确造成的。攻击者可以通过向受影响设备发送特制的HTTP请求来利用此漏洞。成功利用该漏洞可让攻击者绕过身份验证、修改系统上任一用户的密码（包括管理员用户），并以该用户的身份获得系统访问权限。”</span></span></p><div data-role="title" data-tools="135编辑器" data-id="166211"><div style="margin: 10px auto;display: flex;justify-content: center;"><div style="display: flex;align-items: center;"><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100041984" src="https://wechat2rss.xlab.app/img-proxy/?k=00fc89a4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ft5z0xV2OYfWMwmxkQdbhIR1xlXUYKjo0YGoNH5yaX11bOek5dTHWQXiaLGwKok28MLPmicspXUoNy5C16JcJVuFedQibxSMibJRib3iaWzhKicpQq4%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div><p style="font-size: 16px;color: #2e407b;text-align: center;padding: 0 6px;box-sizing:border-box;transform: rotateZ(0deg);-webkit-transform: rotateZ(0deg);-moz-transform: rotateZ(0deg);-o-transform: rotateZ(0deg);"><strong data-brushtype="text"><span leaf="">“强烈建议”尽快打补丁</span></strong></p></div><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100041985" src="https://wechat2rss.xlab.app/img-proxy/?k=de1edc3d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ft5z0xV2OYfW0Wtd21COoaolshEiaaNFk8YbXVKUK5Cr08kBJyVLcI6Z7N4eh8YVLcfW8fxBO2khvRZBXG1iaXfLRfra8AN5CFMsnR5rezIlCY%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">尽管思科产品安全事件响应团队（PSIRT）尚未该漏洞遭野外利用的证据或PoC 代码，但由于目前没有可临时缓解此安全缺陷的变通方案，公司“强烈建议客户升级到修复后的软件版本”。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">本周，思科还修复了本地版智能软件管理器（SSM On-Prem）中的一个高危漏洞（CVE-2026-20160），它可导致无权限的威胁行动者者在易受攻击的SSM On-Prem主机上实现远程代码执行。攻击者可以通过向受影响服务的API发送特殊构造的请求来利用CVE-2026-20160，以root权限在底层操作系统上执行命令。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">本月早些时候，思科修复了位于Secure防火墙管理中心（FMC）中一个CVSS满分的远程代码执行漏洞（CVE-2026-20131），该漏洞曾被Interlock勒索软件团伙在零日攻击中利用。美国网络安全与基础设施安全局（CISA）也已将该漏洞列入其在野被滥用的漏洞目录，并要求联邦机构在三天内完成系统加固。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">近日，据BleepingComputer报道称，攻击者利用在近期Trivy供应链攻击活动中窃取到的凭据，攻陷思科的内部开发环境。</span></span></p></div></div><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;" data-pm-slice="5 3 []"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span style="font-size: 15px;"><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf=""> 开源</span></span><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf="">卫士试用地址：</span><span leaf=""><a href="https://oss.qianxin.com/#/login" target="_blank">https://oss.qianxin.com/#/login</a></span></span></span></span></p><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span leaf=""> 代码卫士试用地址：<a href="https://sast.qianxin.com/#/login" target="_blank">https://sast.qianxin.com/#/login</a></span></span></p><hr style="white-space: normal;border-style: solid;border-right-width: 0px;border-bottom-width: 0px;border-left-width: 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px 0px;transform: scale(1, 0.5);"/><div data-role="paragraph" style="white-space: normal;margin-bottom: 0px;"><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p></div><div data-id="12351" data-tools="新媒体排版" data-style-type="1" style="margin: 0px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);text-align: start;"><div data-css="border-color: initial;border-style: none;border-width: 0px;padding: 0px" style="margin: 0px;padding: 0px;border-color: initial;border-style: none;border-width: 0px;"><div powered-by="KolEditor.us" style="margin: 0px;padding: 0px;"><div style="margin: 10px 0px;padding: 0px;"><p style="font-size: medium;margin: 0px;padding: 0px;display: inline-block;"><span style="margin: 0px;padding: 0.3em 0.5em;background-color: rgb(23, 148, 221);border-radius: 0.8em 0.8em 0px 0px;color: rgb(255, 255, 255);display: block;font-size: 14.08px;"><p style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-size: 18px;"><span leaf=""><span textstyle="" style="font-size: 15px;">推荐阅读</span></span></span></strong></p></span></p><div data-css="border-color: rgb(249, 110, 87);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;box-sizing: border-box;padding: 10px" style="margin: 0px;padding: 10px;border-color: rgb(23, 148, 221);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px;padding: 0px;"><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525403&amp;idx=1&amp;sn=a7ca207e2fb245b56f2a17c2cf9d5f80&amp;scene=21#wechat_redirect" textvalue="思科修复多个高危 IOS XR 漏洞" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">思科修复多个高危 IOS XR 漏洞</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525349&amp;idx=2&amp;sn=d24d6683fb3bc04d5b47bb36bf521194&amp;scene=21#wechat_redirect" textvalue="思科：注意已遭利用的两个 Catalyst SD-WAN 管理器 0day 漏洞" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">思科：注意已遭利用的两个 Catalyst SD-WAN 管理器 0day 漏洞</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525317&amp;idx=1&amp;sn=400b0183f75f78413cb8fd0ab335e576&amp;scene=21#wechat_redirect" textvalue="思科提醒注意满分 Secure FMC 漏洞可用于获取 root 权限" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">思科提醒注意满分 Secure FMC 漏洞可用于获取 root 权限</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524955&amp;idx=2&amp;sn=922edf69046bb2a552b3f58f4f21f882&amp;scene=21#wechat_redirect" textvalue="思科修复已遭利用的 Unified CM RCE 0day漏洞" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">思科修复已遭利用的 Unified CM RCE 0day漏洞</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524828&amp;idx=1&amp;sn=d0696191628f6b13a09be6edecbbec4d&amp;scene=21#wechat_redirect" textvalue="思科：速修复已出现 exp 的身份服务引擎漏洞" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">思科：速修复已出现 exp 的身份服务引擎漏洞</span></a></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 15px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0em;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);font-size: medium;text-align: start;"><span style="margin: 0px;padding: 0px;font-size: 15px;color: rgb(136, 136, 136);text-decoration: underline;"><strong style="margin: 0px;padding: 0px;"><span leaf="">原文链接</span></strong></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span lang="EN-US" data-pm-slice="0 0 []"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;"><a href="https://www.bleepingcomputer.com/news/security/critical-cisco-imc-auth-bypass-gives-attackers-admin-access/" target="_blank">https://www.bleepingcomputer.com/news/security/critical-cisco-imc-auth-bypass-gives-attackers-admin-access/</a></span></span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">题图：Pixa</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">bay Licens</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">e</span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><strong style="text-indent: 0em;"><span style="font-size: 15px;color: rgb(136, 136, 136);"><span leaf="">本文由奇安信编译，不代表奇安信观点。转载请注明“转自奇安信代码卫士 <a href="https://codesafe.qianxin.com”。" target="_blank">https://codesafe.qianxin.com”。</a></span></span></strong></p><div data-role="paragraph" style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><div data-id="9499" data-tools="新媒体排版" data-style-type="4" style="color: rgb(0, 0, 0);font-size: 17px;margin: 0px;padding: 0px 0.5em;text-align: start;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px auto;padding: 0px;text-align: center;"><div style="margin: 0px auto;padding: 0px 0px 10px;max-width: 360px !important;"><p style="margin: 0px;padding: 0px 0px 0px 2px;font-size: 0px;width: 65px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.27380952380952384" data-type="jpeg" data-w="84" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;height: auto !important;" data-fileid="100025253" src="https://wechat2rss.xlab.app/img-proxy/?k=20efc9d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSf7nNLWrJL6dkJp7RB8Kl4zxU9ibnQjuvo4VoZ5ic9Q91K3WshWzqEybcroVEOQpgYfx1uYgwJhlFQ%2F640%3Fwx_fmt%3Djpeg"/></p><div data-css="align-items: flex-start;border-color: rgb(255, 138, 101);border-style: solid;border-width: 2px;display: flex;margin-top: -10px;padding: 30px 25px" style="margin: -10px 0px 0px;padding: 30px 25px;align-items: flex-start;border-color: rgb(23, 148, 221);border-style: solid;border-width: 2px;display: flex;"><div style="margin: 0px;padding: 0px;font-size: 0px;flex-shrink: 0;"><p style="margin: 0px;padding: 0px;width: 75px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-type="jpeg" data-w="1080" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;border-color: rgb(238, 238, 238);border-radius: 2px;border-style: solid;border-width: 1px;width: 75px;height: auto !important;" data-cropselx1="0" data-cropselx2="75" data-cropsely1="0" data-cropsely2="75" data-fileid="100025255" src="https://wechat2rss.xlab.app/img-proxy/?k=4657c87c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSN5sfviaCuvYQccJZlrr64sRlvcbdWjDic9mPQ8mBBFDCKP6VibiaNE1kDVuoIOiaIVRoTjSsSftGC8gw%2F640%3Fwx_fmt%3Djpeg"/></p></div><div style="margin: 0px;padding: 0px 0px 0px 15px;flex-shrink: 1;"><p data-css="color: #333;font-size: 18px;line-height:1.7;margin: 0px auto;text-align: left" style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 18px;line-height: 1.7;text-align: left;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;color: rgb(23, 148, 221);"><span leaf="">奇安信代码卫士 (codesafe)</span></span></strong></span></p><p style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 16px;text-align: left;line-height: 1.4;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><span leaf="">国内首个专注于软件开发安全的产品线。</span></span></p></div></div></div></div></div></div><p style="color: rgb(51, 51, 51);font-size: 17px;margin: 0px;padding: 0px 0.5em;clear: both;min-height: 1em;text-align: center;"><span leaf="">   <img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="0.8" data-type="gif" data-w="200" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: middle;color: rgb(0, 0, 0);font-size: 14px;box-sizing: border-box;width: 58.125px;visibility: visible !important;height: auto !important;" data-fileid="100025256" src="https://wechat2rss.xlab.app/img-proxy/?k=fbb024f2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FoBANLWYScMQ5iciaeKS21icDIWSVd0M9zEhicFK0rbCJOrgpc09iaH6nvqvsIdckDfxH2K4tu9CvPJgSf7XhGHJwVyQ%2F640%3Fwx_fmt%3Dgif"/></span><span style="margin: 0px;padding: 0px;font-size: 12px;"><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">觉得不错，就点个 “</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">在看</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 或 &#34;</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">赞</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 吧~</span></span></span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://codesafe.qianxin.com/#/home">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=90309360&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2NTg4OTc5Nw%3D%3D%26mid%3D2247525643%26idx%3D1%26sn%3D123aa4e38d29ce29d7107d5e7378e00f">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 03 Apr 2026 17:52:00 +0800</pubDate>
    </item>
    <item>
      <title>Progress ShareFile 漏洞可用于发动预认证 RCE 攻击</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525643&amp;idx=2&amp;sn=46f21b64114594cdb5db7473129e09a8</link>
      <description>速修复</description>
      <content:encoded><![CDATA[<p><span>Bill Toulas</span> <span>2026-04-03 17:52</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1fa082d2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ft5z0xV2OYfXTGvhBkg8IN0al6a8iau5USeVKRMf9ElJW5lpHCVZickuPQkAXDribWJYs53SGiaicsHnwicWJ634yfvnMSJXAmSXMgzTq57ziacHACM%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>速修复</p>
  <p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span leaf=""><img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="1" data-type="gif" data-w="400" style="margin-right: auto;margin-left: auto;vertical-align: middle;letter-spacing: 0.5px;text-indent: 0em;display: inline-block;box-sizing: border-box !important;visibility: visible !important;width: 30px !important;height: auto !important;" width="30" data-fileid="100025254" src="https://wechat2rss.xlab.app/img-proxy/?k=17396c1a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAz5ZsrEic9ot90z9etZLlU7OTaPOdibteeibJMMmbwc29aJlDOmUicibIRoLdcuEQjtHQ2qjVtZBt0M5eVbYoQzlHiaw%2F640%3Fwx_fmt%3Dgif"/>  </span><span style="text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-mpa-powered-by&#34;:&#34;yiban.io&#34;,&#34;style&#34;:&#34;margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">聚焦源代码安全，网罗国内外最新资讯！</span></span></p><p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;text-align: start;"><strong style="color: rgb(0, 0, 0);letter-spacing: 1px;font-size: 15px;"><span style="font-family: sofia-pro, sans-serif;letter-spacing: normal;text-transform: uppercase;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;transition: color 0.15s ease-out 0s, background-color 0.3s ease-out 0s, text-decoration-color 0.15s ease-out 0s;box-shadow: inset 0 -2px 0 var(--color-black);overflow: hidden;padding-bottom: 4px;color: rgb(136, 136, 136);"><span leaf="">编译：代码卫士</span></span></strong></p><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="paragraph"><div data-tools="135编辑器" data-id="156501"><div style="margin: 10px auto;"><div data-cacheurl="" data-remoteid="" style="background: none no-repeat right bottom;background-size: 20%;background-color: #f4f9ff;padding: 10px 10px;border: 1px solid #3995f0;box-sizing:border-box;background-image: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=445ea708&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Ft5z0xV2OYfUEWWooAWJqgLMD4sDuiaFQIicf8r1O6ezBv54Jk9Eu5j9cpreibgFzCjY64ICRI50B1Yh3YOf1jhYQaib78q2UR1HiajlzRGs4zGkY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg&#34;);"><p data-autoskip="1" style="text-align: left;line-height: 1.75em;letter-spacing: 1.5px;font-size: 15px;color: #333333;background-color: transparent;"><span style="font-size:15px;"><strong><span leaf="">安全公司 watchTowr 的研究人员在企业级安全文件传输解决方案 Progress ShareFile 的 5.x 分支所包含的存储区域控制器（SZC）组件中，发现了一个身份验证绕过漏洞（CVE-2026-2699）和一个远程代码执行漏洞（CVE-2026-2701）。</span></strong></span></p></div></div></div><p style="margin: 16px 5px 15px;background: white;display: block;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">Progress ShareFile 是一款文档共享与协作产品，通常用于大中型企业。这类解决方案对勒索软件团伙具有很大的吸引力，此前在 Clop 组织的窃取数据攻击中就已见端倪，他们曾利用 Accellion FTA、SolarWinds Serv-U、Gladinet CentreStack、GoAnywhere MFT、MOVEit Transfer 以及 Cleo 等产品中的漏洞实施攻击。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">SZC 允许客户将数据存储在自己的基础设施（本地部署或第三方云服务商）或 Progress 的系统中，从而让客户对其数据拥有更强的控制权。在watchTowr进行负责任的披露后，这两个漏洞已在3月10日发布的Progress ShareFile 5.12.4版本中修复。</span></span></p><div data-role="title" data-tools="135编辑器" data-id="166211"><div style="margin: 10px auto;display: flex;justify-content: center;"><div style="display: flex;align-items: center;"><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100041991" src="https://wechat2rss.xlab.app/img-proxy/?k=191f2989&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ft5z0xV2OYfWpgSrNdnX4oW86Zxdd12U5McKLQtz81IkqCxs17c5EJXDx9Jn2P1UZO0iaGicHxcrmE8LF10IF0euCVHjcLH5jxdSv4L9R5dn4Y%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div><p style="font-size: 16px;color: #2e407b;text-align: center;padding: 0 6px;box-sizing:border-box;transform: rotateZ(0deg);-webkit-transform: rotateZ(0deg);-moz-transform: rotateZ(0deg);-o-transform: rotateZ(0deg);"><strong data-brushtype="text"><span leaf="">攻击方式详解</span></strong></p></div><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100041990" src="https://wechat2rss.xlab.app/img-proxy/?k=a009bae8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ft5z0xV2OYfXxgBa6ibBlXML9tXJP3wQTWEzLmt1KnxUTnQ3v8hnrXXNSgeyYuWJnzGbicQtlQnGldCHvEBznuFKQhgjwO7RIKibmCNpdc6lu9o%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">研究人员解释称，攻击首先利用身份验证绕过漏洞（CVE-2026-2699）。该漏洞因HTTP重定向处理不当而导致攻击者能够访问ShareFile的管理员界面。进入系统后，攻击者可以修改存储区域的配置设置，包括文件存储路径以及区域密码和相关密钥等安全敏感参数。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">通过利用第二个漏洞（CVE-2026-2701），攻击者可以滥用文件上传和解压功能，将恶意的ASPX网页后门放置在应用程序的webroot目录中，从而在服务器上实现远程代码执行。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">研究人员指出，要成功利用该漏洞，攻击者必须生成有效的HMAC签名，并提取和解密内部密钥。然而，在利用CVE-2026-2699之后，由于能够设置或控制与密码相关的参数值，这些操作是可以实现的。</span></span></p><div data-role="title" data-tools="135编辑器" data-id="166211"><div style="margin: 10px auto;display: flex;justify-content: center;"><div style="display: flex;align-items: center;"><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100041992" src="https://wechat2rss.xlab.app/img-proxy/?k=288bb2b0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Ft5z0xV2OYfXyNN0z0pXsIuqIYwialB59tBGfIaTEY9GoeNoveXrQkdf3FlFiaXBA2w36e1Oq5CJxe02xI4V3VIMrOwbrPRH4PWyw7HVc3zmbc%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div><p style="font-size: 16px;color: #2e407b;text-align: center;padding: 0 6px;box-sizing:border-box;transform: rotateZ(0deg);-webkit-transform: rotateZ(0deg);-moz-transform: rotateZ(0deg);-o-transform: rotateZ(0deg);"><strong data-brushtype="text"><span leaf="">影响范围与暴露情况</span></strong></p></div><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100041989" src="https://wechat2rss.xlab.app/img-proxy/?k=708c92fa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Ft5z0xV2OYfXUary2Bt754Pia76yNdLQiaWib7BHT2ibFibKD7AanRWrN08DSkvnhQJbvOSvhxX2XicE3VL6hAI8Ihhyu2iaIvtOVwZvfFZOPOt4Fbo%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">研究人员扫描发现大约有30000个存储区域控制器实例暴露在公共互联网上。ShadowServer基金会目前观测到700个Progress ShareFile的互联网暴露实例，其中大部分位于美国和欧洲。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">研究人员于2月6日至13日期间向Progress报告。完整的攻击链于2月18日在Progress ShareFile 5.12.4版本上得到确认。该供应商于3月10日发布了5.12.4版本的安全更新。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">尽管截至本文撰写时尚未观察到在野的活跃利用，但由于攻击链已公开，因此运行存在漏洞的ShareFile存储区域控制器版本的系统应立即打补丁。</span></span></p></div></div><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;" data-pm-slice="5 3 []"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span style="font-size: 15px;"><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf=""> 开源</span></span><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf="">卫士试用地址：</span><span leaf=""><a href="https://oss.qianxin.com/#/login" target="_blank">https://oss.qianxin.com/#/login</a></span></span></span></span></p><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span leaf=""> 代码卫士试用地址：<a href="https://sast.qianxin.com/#/login" target="_blank">https://sast.qianxin.com/#/login</a></span></span></p><hr style="white-space: normal;border-style: solid;border-right-width: 0px;border-bottom-width: 0px;border-left-width: 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px 0px;transform: scale(1, 0.5);"/><div data-role="paragraph" style="white-space: normal;margin-bottom: 0px;"><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p></div><div data-id="12351" data-tools="新媒体排版" data-style-type="1" style="margin: 0px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);text-align: start;"><div data-css="border-color: initial;border-style: none;border-width: 0px;padding: 0px" style="margin: 0px;padding: 0px;border-color: initial;border-style: none;border-width: 0px;"><div powered-by="KolEditor.us" style="margin: 0px;padding: 0px;"><div style="margin: 10px 0px;padding: 0px;"><p style="font-size: medium;margin: 0px;padding: 0px;display: inline-block;"><span style="margin: 0px;padding: 0.3em 0.5em;background-color: rgb(23, 148, 221);border-radius: 0.8em 0.8em 0px 0px;color: rgb(255, 255, 255);display: block;font-size: 14.08px;"><p style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-size: 18px;"><span leaf=""><span textstyle="" style="font-size: 15px;">推荐阅读</span></span></span></strong></p></span></p><div data-css="border-color: rgb(249, 110, 87);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;box-sizing: border-box;padding: 10px" style="margin: 0px;padding: 10px;border-color: rgb(23, 148, 221);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px;padding: 0px;"><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247520960&amp;idx=1&amp;sn=919fb43b3860018ef3997b0e4159dee6&amp;scene=21#wechat_redirect" textvalue="Progress：尽快修复 WhatsUp Gold 中的多个严重漏洞" data-itemshowtype="0" linktype="text" data-linktype="2">Progress：尽快修复 WhatsUp Gold 中的多个严重漏洞</a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247520732&amp;idx=1&amp;sn=8fafa0f4d8f56d2a8361866cce3ac84c&amp;scene=21#wechat_redirect" textvalue="Progress 紧急修复影响 LoadMaster 的超危RCE漏洞" data-itemshowtype="0" linktype="text" data-linktype="2">Progress 紧急修复影响 LoadMaster 的超危RCE漏洞</a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247520228&amp;idx=1&amp;sn=d9e2734ebb4a13c747b20000c240d7bd&amp;scene=21#wechat_redirect" textvalue="Progress 提醒注意Telerik Report Server中的严重RCE漏洞" data-itemshowtype="0" linktype="text" data-linktype="2">Progress 提醒注意Telerik Report Server中的严重RCE漏洞</a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247519654&amp;idx=1&amp;sn=22b4f342e957ddb68acf5d7dabc14f7b&amp;scene=21#wechat_redirect" textvalue="速修复！Progress Telerik 中存在严重的认证绕过漏洞" data-itemshowtype="0" linktype="text" data-linktype="2">速修复！Progress Telerik 中存在严重的认证绕过漏洞</a></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 15px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0em;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);font-size: medium;text-align: start;"><span style="margin: 0px;padding: 0px;font-size: 15px;color: rgb(136, 136, 136);text-decoration: underline;"><strong style="margin: 0px;padding: 0px;"><span leaf="">原文链接</span></strong></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;"><a href="https://www.bleepingcomputer.com/news/security/new-progress-sharefile-flaws-can-be-chained-in-pre-auth-rce-attacks/" target="_blank">https://www.bleepingcomputer.com/news/security/new-progress-sharefile-flaws-can-be-chained-in-pre-auth-rce-attacks/</a></span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">题图：Pixa</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">bay Licens</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">e</span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><strong style="text-indent: 0em;"><span style="font-size: 15px;color: rgb(136, 136, 136);"><span leaf="">本文由奇安信编译，不代表奇安信观点。转载请注明“转自奇安信代码卫士 <a href="https://codesafe.qianxin.com”。" target="_blank">https://codesafe.qianxin.com”。</a></span></span></strong></p><div data-role="paragraph" style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><div data-id="9499" data-tools="新媒体排版" data-style-type="4" style="color: rgb(0, 0, 0);font-size: 17px;margin: 0px;padding: 0px 0.5em;text-align: start;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px auto;padding: 0px;text-align: center;"><div style="margin: 0px auto;padding: 0px 0px 10px;max-width: 360px !important;"><p style="margin: 0px;padding: 0px 0px 0px 2px;font-size: 0px;width: 65px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.27380952380952384" data-type="jpeg" data-w="84" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;height: auto !important;" data-fileid="100025253" src="https://wechat2rss.xlab.app/img-proxy/?k=20efc9d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSf7nNLWrJL6dkJp7RB8Kl4zxU9ibnQjuvo4VoZ5ic9Q91K3WshWzqEybcroVEOQpgYfx1uYgwJhlFQ%2F640%3Fwx_fmt%3Djpeg"/></p><div data-css="align-items: flex-start;border-color: rgb(255, 138, 101);border-style: solid;border-width: 2px;display: flex;margin-top: -10px;padding: 30px 25px" style="margin: -10px 0px 0px;padding: 30px 25px;align-items: flex-start;border-color: rgb(23, 148, 221);border-style: solid;border-width: 2px;display: flex;"><div style="margin: 0px;padding: 0px;font-size: 0px;flex-shrink: 0;"><p style="margin: 0px;padding: 0px;width: 75px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-type="jpeg" data-w="1080" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;border-color: rgb(238, 238, 238);border-radius: 2px;border-style: solid;border-width: 1px;width: 75px;height: auto !important;" data-cropselx1="0" data-cropselx2="75" data-cropsely1="0" data-cropsely2="75" data-fileid="100025255" src="https://wechat2rss.xlab.app/img-proxy/?k=4657c87c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSN5sfviaCuvYQccJZlrr64sRlvcbdWjDic9mPQ8mBBFDCKP6VibiaNE1kDVuoIOiaIVRoTjSsSftGC8gw%2F640%3Fwx_fmt%3Djpeg"/></p></div><div style="margin: 0px;padding: 0px 0px 0px 15px;flex-shrink: 1;"><p data-css="color: #333;font-size: 18px;line-height:1.7;margin: 0px auto;text-align: left" style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 18px;line-height: 1.7;text-align: left;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;color: rgb(23, 148, 221);"><span leaf="">奇安信代码卫士 (codesafe)</span></span></strong></span></p><p style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 16px;text-align: left;line-height: 1.4;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><span leaf="">国内首个专注于软件开发安全的产品线。</span></span></p></div></div></div></div></div></div><p style="color: rgb(51, 51, 51);font-size: 17px;margin: 0px;padding: 0px 0.5em;clear: both;min-height: 1em;text-align: center;"><span leaf="">   <img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="0.8" data-type="gif" data-w="200" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: middle;color: rgb(0, 0, 0);font-size: 14px;box-sizing: border-box;width: 58.125px;visibility: visible !important;height: auto !important;" data-fileid="100025256" src="https://wechat2rss.xlab.app/img-proxy/?k=fbb024f2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FoBANLWYScMQ5iciaeKS21icDIWSVd0M9zEhicFK0rbCJOrgpc09iaH6nvqvsIdckDfxH2K4tu9CvPJgSf7XhGHJwVyQ%2F640%3Fwx_fmt%3Dgif"/></span><span style="margin: 0px;padding: 0px;font-size: 12px;"><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">觉得不错，就点个 “</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">在看</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 或 &#34;</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">赞</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 吧~</span></span></span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://codesafe.qianxin.com/#/home">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=2c428ce1&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2NTg4OTc5Nw%3D%3D%26mid%3D2247525643%26idx%3D2%26sn%3D46f21b64114594cdb5db7473129e09a8">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 03 Apr 2026 17:52:00 +0800</pubDate>
    </item>
    <item>
      <title>Vertex AI 漏洞暴露谷歌云数据和非公开制品</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525630&amp;idx=1&amp;sn=c92b1cfa77120afb058a49b0490a079b</link>
      <description>速修复</description>
      <content:encoded><![CDATA[<p><span>Ravie Lakshmanan</span> <span>2026-04-02 18:09</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=7efeae56&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft5z0xV2OYfUPMGrr7EicCSO72Lrnsaq8O2rlRpXm5GxAicCMVOibEQwElTYQltBk3BcaQ3k66xAGSBFVgkdG6Hxryb8nr8ibEsonicQA9rcyXeLA%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>速修复</p>
  <p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span leaf=""><img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="1" data-type="gif" data-w="400" style="margin-right: auto;margin-left: auto;vertical-align: middle;letter-spacing: 0.5px;text-indent: 0em;display: inline-block;box-sizing: border-box !important;visibility: visible !important;width: 30px !important;height: auto !important;" width="30" data-fileid="100025254" src="https://wechat2rss.xlab.app/img-proxy/?k=17396c1a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAz5ZsrEic9ot90z9etZLlU7OTaPOdibteeibJMMmbwc29aJlDOmUicibIRoLdcuEQjtHQ2qjVtZBt0M5eVbYoQzlHiaw%2F640%3Fwx_fmt%3Dgif"/>  </span><span style="text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-mpa-powered-by&#34;:&#34;yiban.io&#34;,&#34;style&#34;:&#34;margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">聚焦源代码安全，网罗国内外最新资讯！</span></span></p><p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;text-align: start;"><strong style="color: rgb(0, 0, 0);letter-spacing: 1px;font-size: 15px;"><span style="font-family: sofia-pro, sans-serif;letter-spacing: normal;text-transform: uppercase;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;transition: color 0.15s ease-out 0s, background-color 0.3s ease-out 0s, text-decoration-color 0.15s ease-out 0s;box-shadow: inset 0 -2px 0 var(--color-black);overflow: hidden;padding-bottom: 4px;color: rgb(136, 136, 136);"><span leaf="">编译：代码卫士</span></span></strong></p><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="paragraph"><div data-tools="135编辑器" data-id="166585"><div style="margin: 10px auto;"><div><div style="background-color: #ffffff;padding: 0px 10px;border-left: 3px solid #1a3566;border-right: 3px solid #1a3566;line-height: 1.1em;box-sizing:border-box;"><p data-autoskip="1" style="text-align: left;line-height: 1.75em;letter-spacing: 1.5px;font-size: 15px;color: #131f35;background-color: transparent;"><span style="font-size:15px;"><strong><span leaf="">网络安全研究人员披露称谷歌云 Vertex AI 平台中存在一个安全“盲点”，可使攻击者将人工智能代理武器化，从而未经授权访问敏感数据并危及组织机构的云环境安全。</span></strong></span></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">Palo Alto Networks 公司团队Unit 42称，该漏洞涉及如何针对 Vertex AI 权限模型中服务代理默认权限范围过大的特点实施滥用。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">Unit 42 团队的研究员 Ofir Shaty 在一份相关报告中表示：“配置错误或被攻陷的代理可能成为‘双重间谍’，表面上在执行其预期功能，暗地里却在窃取敏感数据、破坏基础设施，并在组织机构最关键系统中创建后门。”</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">具体而言，研究人员发现，与使用 Vertex AI 的 Agent Development Kit（ADK）构建的已部署 AI 代理相关联的“按项目、按产品服务代理”（P4SA），在默认情况下被授予了过多权限。这为一种场景打开了大门，即利用 P4SA 的默认权限来提取服务代理的凭据，并以其名义执行操作。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">在通过 Agent Engine 部署 Vertex 代理后，对该代理的任何调用都会调用谷歌的元数据服务，并暴露服务代理的凭证，以及托管 AI 代理的谷歌云 (GCP) 项目、AI 代理的身份和托管该 AI 代理的机器的权限范围。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">Unit 42 团队表示，他们能够利用窃取的凭证从 AI 代理的执行上下文跳转到客户项目中，从而有效打破隔离保障，并允许对该项目内所有 Google Cloud Storage 存储桶的数据进行无限制的读取访问。报告指出，“这种级别的访问权限构成了重大的安全风险，将 AI 代理从一个有用的工具转变为一个潜在的内部威胁。”</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">不仅如此。由于部署的 Vertex AI Agent Engine 在谷歌管理的租户项目中运行，提取的凭证还授予了对该租户内 Google Cloud Storage 存储桶的访问权限，从而揭示了有关该平台内部基础设施的更多细节。不过，研究发现这些凭证缺乏访问这些暴露的存储桶所需的必要权限。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">更糟糕的是，同一个 P4SA 服务代理凭证还启用了对受限制的、谷歌拥有的 Artifact Registry 仓库的访问，这些仓库在 Agent Engine 部署过程中被暴露出来。攻击者可以利用此行为从构成 Vertex AI Reasoning Engine 核心的私有仓库中下载容器镜像。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">此外，被攻陷的 P4SA 凭证不仅使得下载 Agent Engine 部署期间日志中列出的镜像成为可能，还暴露了 Artifact Registry 仓库的内容，其中包括其它几个受限镜像。Unit 42 团队解释称：“访问这些专有代码不仅暴露了谷歌的知识产权，还为攻击者提供了寻找更多漏洞的蓝图。”</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">“Artifact Registry 的错误配置凸显了关键基础设施访问控制管理中的另一个缺陷。攻击者可能利用这种非预期的可见性来绘制谷歌内部软件供应链的地图，识别已弃用或存在漏洞的镜像，并策划进一步的攻击。”</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">此后，谷歌已更新官方文档，明确说明了 Vertex AI 如何使用资源、账户和代理。另外还建议客户使用“使用自己的服务账户”（BYOSA）来替换默认的服务代理，并执行最小权限原则，以确保代理仅拥有执行当前任务所需的权限。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">Shaty 表示：“默认授予代理广泛的权限违反了最小权限原则，是一种危险的设计级安全缺陷。组织应以与处理新生产代码相同的严谨态度对待 AI 代理的部署。在生产环境上线前，应验证权限边界，将 OAuth 范围限制为最小权限，审查源完整性，并进行受控的安全测试。”</span></span></p></div></div><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;" data-pm-slice="5 3 []"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span style="font-size: 15px;"><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf=""> 开源</span></span><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf="">卫士试用地址：</span><span leaf=""><a href="https://oss.qianxin.com/#/login" target="_blank">https://oss.qianxin.com/#/login</a></span></span></span></span></p><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span leaf=""> 代码卫士试用地址：<a href="https://sast.qianxin.com/#/login" target="_blank">https://sast.qianxin.com/#/login</a></span></span></p><hr style="white-space: normal;border-style: solid;border-right-width: 0px;border-bottom-width: 0px;border-left-width: 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px 0px;transform: scale(1, 0.5);"/><div data-role="paragraph" style="white-space: normal;margin-bottom: 0px;"><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p></div><div data-id="12351" data-tools="新媒体排版" data-style-type="1" style="margin: 0px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);text-align: start;"><div data-css="border-color: initial;border-style: none;border-width: 0px;padding: 0px" style="margin: 0px;padding: 0px;border-color: initial;border-style: none;border-width: 0px;"><div powered-by="KolEditor.us" style="margin: 0px;padding: 0px;"><div style="margin: 10px 0px;padding: 0px;"><p style="font-size: medium;margin: 0px;padding: 0px;display: inline-block;"><span style="margin: 0px;padding: 0.3em 0.5em;background-color: rgb(23, 148, 221);border-radius: 0.8em 0.8em 0px 0px;color: rgb(255, 255, 255);display: block;font-size: 14.08px;"><p style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-size: 18px;"><span leaf=""><span textstyle="" style="font-size: 15px;">推荐阅读</span></span></span></strong></p></span></p><div data-css="border-color: rgb(249, 110, 87);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;box-sizing: border-box;padding: 10px" style="margin: 0px;padding: 10px;border-color: rgb(23, 148, 221);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px;padding: 0px;"><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525564&amp;idx=1&amp;sn=87a38b04609d00236ed5984ced8a6243&amp;scene=21#wechat_redirect" textvalue="OpenAI 发布AI安全漏洞奖励计划" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">OpenAI 发布AI安全漏洞奖励计划</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525546&amp;idx=1&amp;sn=a59ff34cc1e580d466a28e4614a7a663&amp;scene=21#wechat_redirect" textvalue="日增百万行代码！温氏股份如何依托AI筑牢开发安全防线" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">日增百万行代码！温氏股份如何依托AI筑牢开发安全防线</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525496&amp;idx=1&amp;sn=6253a0da55749336eda176e1d005d061&amp;scene=21#wechat_redirect" textvalue="简单的自定义字体渲染即可投毒 ChatGPT、Claude、Gemini 等 AI 系统" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">简单的自定义字体渲染即可投毒 ChatGPT、Claude、Gemini 等 AI 系统</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525365&amp;idx=2&amp;sn=dff79e089be7ac2054e918366b567b52&amp;scene=21#wechat_redirect" textvalue="微软：AI已用于攻击的每个阶段" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">微软：AI已用于攻击的每个阶段</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525250&amp;idx=2&amp;sn=0896fff8eb0f9f9e2369a299930ff6c4&amp;scene=21#wechat_redirect" textvalue="AI 编程助手 Cline CLI 2.3.0遭篡改，悄悄安装 OpenClaw" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">AI 编程助手 Cline CLI 2.3.0遭篡改，悄悄安装 OpenClaw</span></a></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 15px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0em;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);font-size: medium;text-align: start;"><span style="margin: 0px;padding: 0px;font-size: 15px;color: rgb(136, 136, 136);text-decoration: underline;"><strong style="margin: 0px;padding: 0px;"><span leaf="">原文链接</span></strong></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;"><a href="https://thehackernews.com/2026/03/vertex-ai-vulnerability-exposes-google.html" target="_blank">https://thehackernews.com/2026/03/vertex-ai-vulnerability-exposes-google.html</a></span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">题图：Pixa</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">bay Licens</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">e</span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><strong style="text-indent: 0em;"><span style="font-size: 15px;color: rgb(136, 136, 136);"><span leaf="">本文由奇安信编译，不代表奇安信观点。转载请注明“转自奇安信代码卫士 <a href="https://codesafe.qianxin.com”。" target="_blank">https://codesafe.qianxin.com”。</a></span></span></strong></p><div data-role="paragraph" style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><div data-id="9499" data-tools="新媒体排版" data-style-type="4" style="color: rgb(0, 0, 0);font-size: 17px;margin: 0px;padding: 0px 0.5em;text-align: start;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px auto;padding: 0px;text-align: center;"><div style="margin: 0px auto;padding: 0px 0px 10px;max-width: 360px !important;"><p style="margin: 0px;padding: 0px 0px 0px 2px;font-size: 0px;width: 65px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.27380952380952384" data-type="jpeg" data-w="84" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;height: auto !important;" data-fileid="100025253" src="https://wechat2rss.xlab.app/img-proxy/?k=20efc9d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSf7nNLWrJL6dkJp7RB8Kl4zxU9ibnQjuvo4VoZ5ic9Q91K3WshWzqEybcroVEOQpgYfx1uYgwJhlFQ%2F640%3Fwx_fmt%3Djpeg"/></p><div data-css="align-items: flex-start;border-color: rgb(255, 138, 101);border-style: solid;border-width: 2px;display: flex;margin-top: -10px;padding: 30px 25px" style="margin: -10px 0px 0px;padding: 30px 25px;align-items: flex-start;border-color: rgb(23, 148, 221);border-style: solid;border-width: 2px;display: flex;"><div style="margin: 0px;padding: 0px;font-size: 0px;flex-shrink: 0;"><p style="margin: 0px;padding: 0px;width: 75px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-type="jpeg" data-w="1080" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;border-color: rgb(238, 238, 238);border-radius: 2px;border-style: solid;border-width: 1px;width: 75px;height: auto !important;" data-cropselx1="0" data-cropselx2="75" data-cropsely1="0" data-cropsely2="75" data-fileid="100025255" src="https://wechat2rss.xlab.app/img-proxy/?k=4657c87c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSN5sfviaCuvYQccJZlrr64sRlvcbdWjDic9mPQ8mBBFDCKP6VibiaNE1kDVuoIOiaIVRoTjSsSftGC8gw%2F640%3Fwx_fmt%3Djpeg"/></p></div><div style="margin: 0px;padding: 0px 0px 0px 15px;flex-shrink: 1;"><p data-css="color: #333;font-size: 18px;line-height:1.7;margin: 0px auto;text-align: left" style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 18px;line-height: 1.7;text-align: left;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;color: rgb(23, 148, 221);"><span leaf="">奇安信代码卫士 (codesafe)</span></span></strong></span></p><p style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 16px;text-align: left;line-height: 1.4;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><span leaf="">国内首个专注于软件开发安全的产品线。</span></span></p></div></div></div></div></div></div><p style="color: rgb(51, 51, 51);font-size: 17px;margin: 0px;padding: 0px 0.5em;clear: both;min-height: 1em;text-align: center;"><span leaf="">   <img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="0.8" data-type="gif" data-w="200" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: middle;color: rgb(0, 0, 0);font-size: 14px;box-sizing: border-box;width: 58.125px;visibility: visible !important;height: auto !important;" data-fileid="100025256" src="https://wechat2rss.xlab.app/img-proxy/?k=fbb024f2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FoBANLWYScMQ5iciaeKS21icDIWSVd0M9zEhicFK0rbCJOrgpc09iaH6nvqvsIdckDfxH2K4tu9CvPJgSf7XhGHJwVyQ%2F640%3Fwx_fmt%3Dgif"/></span><span style="margin: 0px;padding: 0px;font-size: 12px;"><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">觉得不错，就点个 “</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">在看</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 或 &#34;</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">赞</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 吧~</span></span></span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://codesafe.qianxin.com/#/home">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=21583b1d&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2NTg4OTc5Nw%3D%3D%26mid%3D2247525630%26idx%3D1%26sn%3Dc92b1cfa77120afb058a49b0490a079b">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 02 Apr 2026 18:09:00 +0800</pubDate>
    </item>
    <item>
      <title>libpng 官方参考库中的这两个严重漏洞已存在30年之久</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525630&amp;idx=2&amp;sn=5b4bcf1e200cad3b1abc1fb6e2e578d6</link>
      <description>速修复</description>
      <content:encoded><![CDATA[<p><span>Ddos</span> <span>2026-04-02 18:09</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=89208d3f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft5z0xV2OYfVvO7Yf89cCejeDp3iczhKCg5OG7ZTicOR0Pibct4nPo3udUjibyQGa00j5PBVv0F1GLLS0fGfVpWmyLoBHcQbegtQOqflBgLjy6sw%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>速修复</p>
  <p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span leaf=""><img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="1" data-type="gif" data-w="400" style="margin-right: auto;margin-left: auto;vertical-align: middle;letter-spacing: 0.5px;text-indent: 0em;display: inline-block;box-sizing: border-box !important;visibility: visible !important;width: 30px !important;height: auto !important;" width="30" data-fileid="100025254" src="https://wechat2rss.xlab.app/img-proxy/?k=17396c1a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAz5ZsrEic9ot90z9etZLlU7OTaPOdibteeibJMMmbwc29aJlDOmUicibIRoLdcuEQjtHQ2qjVtZBt0M5eVbYoQzlHiaw%2F640%3Fwx_fmt%3Dgif"/>  </span><span style="text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-mpa-powered-by&#34;:&#34;yiban.io&#34;,&#34;style&#34;:&#34;margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">聚焦源代码安全，网罗国内外最新资讯！</span></span></p><p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;text-align: start;"><strong style="color: rgb(0, 0, 0);letter-spacing: 1px;font-size: 15px;"><span style="font-family: sofia-pro, sans-serif;letter-spacing: normal;text-transform: uppercase;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;transition: color 0.15s ease-out 0s, background-color 0.3s ease-out 0s, text-decoration-color 0.15s ease-out 0s;box-shadow: inset 0 -2px 0 var(--color-black);overflow: hidden;padding-bottom: 4px;color: rgb(136, 136, 136);"><span leaf="">编译：代码卫士</span></span></strong></p><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="paragraph"><div data-tools="135编辑器" data-id="166585"><div style="margin: 10px auto;"><div><div style="background-color: #ffffff;padding: 0px 10px;border-left: 3px solid #1a3566;border-right: 3px solid #1a3566;line-height: 1.1em;box-sizing:border-box;"><p data-autoskip="1" style="text-align: left;line-height: 1.75em;letter-spacing: 1.5px;font-size: 15px;color: #131f35;background-color: transparent;"><span style="color: #000000;font-size: 15px;"><strong><span leaf="">安全研究人员披露了位于 libpng 官方参考库中的两个严重漏洞。libpng 是便携式网络图形格式的官方参考库。这些漏洞影响了跨越数十年开发历程的多个版本，可能允许攻击者触发进程崩溃、泄露敏感信息，甚至实现任意代码执行。</span></strong></span></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">作为一个与平台无关的 C 语言库，libpng 是无数应用程序中图像渲染的基石，涵盖从网页浏览器到嵌入式系统的广泛领域。这两个漏洞凸显了传统 C 语言代码库中内存管理长期存在的风险。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">第一个漏洞CVE-2026-33636，针对的是使用 Neon SIMD 指令的 ARM/AArch64 架构中用于性能优化的代码。调色板扩展路径中存在一处越界读取和写入漏洞。当库将 8 位索引调色板行扩展为 RGB 或 RGBA 时，Neon 循环在处理最后一组像素时未验证是否有足够的剩余输入数据。由于该实现是从行尾反向处理的，最后一次迭代会解引用缓冲区起始位置之前的指针。攻击者可通过提供特制的 PNG 图片轻易导致进程崩溃。由于调色板内容由攻击者控制，堆内存内容可能通过解码后的像素输出被泄露。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">此漏洞仅影响启用了硬件优化的系统（具体文件为 arm/palette_neon_intrinsics.c）。基于 Intel（SSE2）、PowerPC 的实现以及通用的 C 语言实现均不受影响。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">第二个漏洞CVE-2026-33416，是一个涉及两个内部结构体 png_struct 和 png_info 之间指针别名（别名使用）的经典逻辑错误。此漏洞自 1.0 版本（针对透明数据）和 1.2.1 版本（针对调色板）以来就一直存在于代码库中。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">像 png_set_tRNS 和 png_set_PLTE 这样的函数会在两个不同结构体之间共享同一个堆分配的缓冲区。如果应用程序调用 png_free_data，它会通过其中一个结构体释放缓冲区，而另一个结构体则仍持有一个悬空指针。随后的转换操作会读取——有时甚至写入——这块已被释放的内存。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">研究人员已在一些环境中演示了远程代码执行。在像 glibc tcache 这样的现代内存分配器上，被释放的 256 字节缓冲区通常会立即被新对象重新使用。如果攻击者控制（通过 tRNS 数据块）重新写入该内存的值，他们就可以劫持应用程序的控制流。这些特殊构造的 PNG 文件 100% 符合标准规范，这意味着传统的验证工具或 Web 应用防火墙在不屏蔽所有 PNG 文件的情况下无法检测到此类攻击。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">用户应升级到已修复这两个漏洞的 libpng v1.6.56 或 v1.8.0（主干分支）版本。如果无法立即更新，可以通过在编译时使用以下标志来禁用 ARM Neon 漏洞的硬件优化缓解措施：-DPNG_ARM_NEON_OPT=0。至于第二个释放后使用漏洞，建议开发者审查在 png_read_info() 和 png_read_update_info() 阶段之间调用 png_free_data() 的应用程序模式。</span></span></p></div></div><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;" data-pm-slice="5 3 []"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span style="font-size: 15px;"><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf=""> 开源</span></span><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf="">卫士试用地址：</span><span leaf=""><a href="https://oss.qianxin.com/#/login" target="_blank">https://oss.qianxin.com/#/login</a></span></span></span></span></p><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span leaf=""> 代码卫士试用地址：<a href="https://sast.qianxin.com/#/login" target="_blank">https://sast.qianxin.com/#/login</a></span></span></p><hr style="white-space: normal;border-style: solid;border-right-width: 0px;border-bottom-width: 0px;border-left-width: 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px 0px;transform: scale(1, 0.5);"/><div data-role="paragraph" style="white-space: normal;margin-bottom: 0px;"><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p></div><div data-id="12351" data-tools="新媒体排版" data-style-type="1" style="margin: 0px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);text-align: start;"><div data-css="border-color: initial;border-style: none;border-width: 0px;padding: 0px" style="margin: 0px;padding: 0px;border-color: initial;border-style: none;border-width: 0px;"><div powered-by="KolEditor.us" style="margin: 0px;padding: 0px;"><div style="margin: 10px 0px;padding: 0px;"><p style="font-size: medium;margin: 0px;padding: 0px;display: inline-block;"><span style="margin: 0px;padding: 0.3em 0.5em;background-color: rgb(23, 148, 221);border-radius: 0.8em 0.8em 0px 0px;color: rgb(255, 255, 255);display: block;font-size: 14.08px;"><p style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-size: 18px;"><span leaf=""><span textstyle="" style="font-size: 15px;">推荐阅读</span></span></span></strong></p></span></p><div data-css="border-color: rgb(249, 110, 87);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;box-sizing: border-box;padding: 10px" style="margin: 0px;padding: 10px;border-color: rgb(23, 148, 221);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px;padding: 0px;"><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247520597&amp;idx=2&amp;sn=770e8cc62ae6c306013787851b80f66e&amp;scene=21#wechat_redirect" textvalue="Telegram 创始人 Pavel Durov 因缺乏内容审核被捕" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">Telegram 创始人 Pavel Durov 因缺乏内容审核被捕</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247520167&amp;idx=2&amp;sn=7d6a9321b744778cdce41dc0464f4c3d&amp;scene=21#wechat_redirect" textvalue="Telegram 0day可导致攻击者将恶意安卓APK以视频形式发送" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">Telegram 0day可导致攻击者将恶意安卓APK以视频形式发送</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247519289&amp;idx=2&amp;sn=4c3fb5e7519056c3adfbd18c7a6561d3&amp;scene=21#wechat_redirect" textvalue="Telegram 修复Windows 版中的0day漏洞" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">Telegram 修复Windows 版中的0day漏洞</span></a></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 15px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0em;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);font-size: medium;text-align: start;"><span style="margin: 0px;padding: 0px;font-size: 15px;color: rgb(136, 136, 136);text-decoration: underline;"><strong style="margin: 0px;padding: 0px;"><span leaf="">原文链接</span></strong></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;"><a href="https://securityonline.info/libpng-vulnerability-rce-arm-neon-cve-2026-33636-cve-2026-33416/" target="_blank">https://securityonline.info/libpng-vulnerability-rce-arm-neon-cve-2026-33636-cve-2026-33416/</a></span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">题图：Pixa</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">bay Licens</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">e</span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><strong style="text-indent: 0em;"><span style="font-size: 15px;color: rgb(136, 136, 136);"><span leaf="">本文由奇安信编译，不代表奇安信观点。转载请注明“转自奇安信代码卫士 <a href="https://codesafe.qianxin.com”。" target="_blank">https://codesafe.qianxin.com”。</a></span></span></strong></p><div data-role="paragraph" style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><div data-id="9499" data-tools="新媒体排版" data-style-type="4" style="color: rgb(0, 0, 0);font-size: 17px;margin: 0px;padding: 0px 0.5em;text-align: start;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px auto;padding: 0px;text-align: center;"><div style="margin: 0px auto;padding: 0px 0px 10px;max-width: 360px !important;"><p style="margin: 0px;padding: 0px 0px 0px 2px;font-size: 0px;width: 65px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.27380952380952384" data-type="jpeg" data-w="84" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;height: auto !important;" data-fileid="100025253" src="https://wechat2rss.xlab.app/img-proxy/?k=20efc9d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSf7nNLWrJL6dkJp7RB8Kl4zxU9ibnQjuvo4VoZ5ic9Q91K3WshWzqEybcroVEOQpgYfx1uYgwJhlFQ%2F640%3Fwx_fmt%3Djpeg"/></p><div data-css="align-items: flex-start;border-color: rgb(255, 138, 101);border-style: solid;border-width: 2px;display: flex;margin-top: -10px;padding: 30px 25px" style="margin: -10px 0px 0px;padding: 30px 25px;align-items: flex-start;border-color: rgb(23, 148, 221);border-style: solid;border-width: 2px;display: flex;"><div style="margin: 0px;padding: 0px;font-size: 0px;flex-shrink: 0;"><p style="margin: 0px;padding: 0px;width: 75px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-type="jpeg" data-w="1080" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;border-color: rgb(238, 238, 238);border-radius: 2px;border-style: solid;border-width: 1px;width: 75px;height: auto !important;" data-cropselx1="0" data-cropselx2="75" data-cropsely1="0" data-cropsely2="75" data-fileid="100025255" src="https://wechat2rss.xlab.app/img-proxy/?k=4657c87c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSN5sfviaCuvYQccJZlrr64sRlvcbdWjDic9mPQ8mBBFDCKP6VibiaNE1kDVuoIOiaIVRoTjSsSftGC8gw%2F640%3Fwx_fmt%3Djpeg"/></p></div><div style="margin: 0px;padding: 0px 0px 0px 15px;flex-shrink: 1;"><p data-css="color: #333;font-size: 18px;line-height:1.7;margin: 0px auto;text-align: left" style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 18px;line-height: 1.7;text-align: left;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;color: rgb(23, 148, 221);"><span leaf="">奇安信代码卫士 (codesafe)</span></span></strong></span></p><p style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 16px;text-align: left;line-height: 1.4;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><span leaf="">国内首个专注于软件开发安全的产品线。</span></span></p></div></div></div></div></div></div><p style="color: rgb(51, 51, 51);font-size: 17px;margin: 0px;padding: 0px 0.5em;clear: both;min-height: 1em;text-align: center;"><span leaf="">   <img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="0.8" data-type="gif" data-w="200" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: middle;color: rgb(0, 0, 0);font-size: 14px;box-sizing: border-box;width: 58.125px;visibility: visible !important;height: auto !important;" data-fileid="100025256" src="https://wechat2rss.xlab.app/img-proxy/?k=fbb024f2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FoBANLWYScMQ5iciaeKS21icDIWSVd0M9zEhicFK0rbCJOrgpc09iaH6nvqvsIdckDfxH2K4tu9CvPJgSf7XhGHJwVyQ%2F640%3Fwx_fmt%3Dgif"/></span><span style="margin: 0px;padding: 0px;font-size: 12px;"><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">觉得不错，就点个 “</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">在看</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 或 &#34;</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">赞</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 吧~</span></span></span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://codesafe.qianxin.com/#/home">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=12f9d32c&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2NTg4OTc5Nw%3D%3D%26mid%3D2247525630%26idx%3D2%26sn%3D5b4bcf1e200cad3b1abc1fb6e2e578d6">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 02 Apr 2026 18:09:00 +0800</pubDate>
    </item>
    <item>
      <title>Claude Code源代码遭泄露</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525629&amp;idx=1&amp;sn=ccf825a020a9d153cfe0c93f04be6c56</link>
      <description>还出现了用户限速情况</description>
      <content:encoded><![CDATA[<p><span>综合编译</span> <span>2026-04-01 18:36</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=cebfd736&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ft5z0xV2OYfXSCD6RfpsW0HquZHI5ye6f8AHic3LVtkCGLQum2k6hxISxeNI9PnrS9oAZnUjguibwadNeXMZpvQjPw2LOzFPqJYkS1iaeUiaIiczY%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>还出现了用户限速情况</p>
  <p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span leaf=""><img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="1" data-type="gif" data-w="400" style="margin-right: auto;margin-left: auto;vertical-align: middle;letter-spacing: 0.5px;text-indent: 0em;display: inline-block;box-sizing: border-box !important;visibility: visible !important;width: 30px !important;height: auto !important;" width="30" data-fileid="100025254" src="https://wechat2rss.xlab.app/img-proxy/?k=17396c1a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAz5ZsrEic9ot90z9etZLlU7OTaPOdibteeibJMMmbwc29aJlDOmUicibIRoLdcuEQjtHQ2qjVtZBt0M5eVbYoQzlHiaw%2F640%3Fwx_fmt%3Dgif"/>  </span><span style="text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-mpa-powered-by&#34;:&#34;yiban.io&#34;,&#34;style&#34;:&#34;margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">聚焦源代码安全，网罗国内外最新资讯！</span></span></p><p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;text-align: start;"><strong style="color: rgb(0, 0, 0);letter-spacing: 1px;font-size: 15px;"><span style="font-family: sofia-pro, sans-serif;letter-spacing: normal;text-transform: uppercase;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;transition: color 0.15s ease-out 0s, background-color 0.3s ease-out 0s, text-decoration-color 0.15s ease-out 0s;box-shadow: inset 0 -2px 0 var(--color-black);overflow: hidden;padding-bottom: 4px;color: rgb(136, 136, 136);"><span leaf="">编译：代码卫士</span></span></strong></p><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="paragraph"><div data-tools="135编辑器" data-id="166585"><div style="margin: 10px auto;"><div><div style="background-color: #ffffff;padding: 0px 10px;border-left: 3px solid #1a3566;border-right: 3px solid #1a3566;line-height: 1.1em;box-sizing:border-box;"><p data-autoskip="1" style="text-align: left;line-height: 1.75em;letter-spacing: 1.5px;font-size: 15px;color: #131f35;background-color: transparent;"><span style="color: #000000;font-size: 15px;"><strong><span leaf="">Anthropic </span></strong><strong><span leaf="">公司的专有 Claude Code 命令行工具因 npm 包配置失误，完整的 TypeScript 源代码遭意外泄露。一名安全研究人员发现了指向 Anthropic 自身云基础设施上存储的未混淆代码库的 .map 文件遭泄露，事件曝光。</span></strong></span></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">2026 年 3 月 31 日，研究人员 Chaofan Shou 公开披露了这一情况，并发文称：“Claude Code 源代码通过 npm 注册表中的 .map 文件被泄露了！”据称，已发布的 @anthropic-ai/claude-code npm 包中包含一个源映射（.map）文件，该文件引用了完整、未压缩的 TypeScript 源代码，这些代码可直接以 ZIP 压缩包的形式从 Anthropic 自家的 R2 云存储桶中下载。这份原始的未经修改的源代码随后被保存并镜像到一个公共 GitHub 仓库中，位于备份分支 nirholas/claude-code 下。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">虽然源代码已在网上传播，但 Anthropic 公司已开始发出数字千年版权法案（DMCA）侵权通知，尽可能下架被泄源代码。</span></span></p><div data-role="title" data-tools="135编辑器" data-id="166211"><div style="margin: 10px auto;display: flex;justify-content: center;"><div style="display: flex;align-items: center;"><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100041951" src="https://wechat2rss.xlab.app/img-proxy/?k=29ffcdcd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ft5z0xV2OYfUyuOYEPUj4XdLreYPUhlP0doCk1ic1YBJxTZGZm6ousdVD6xtD6tPeDibmWfQQ2uR9YDGtnbFtV4fCDicf3aPShZu608CFG3OSVo%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div><p style="font-size: 16px;color: #2e407b;text-align: center;padding: 0 6px;box-sizing:border-box;transform: rotateZ(0deg);-webkit-transform: rotateZ(0deg);-moz-transform: rotateZ(0deg);-o-transform: rotateZ(0deg);"><strong data-brushtype="text"><span leaf="">泄露内容</span></strong></p></div><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100041949" src="https://wechat2rss.xlab.app/img-proxy/?k=45ad063a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Ft5z0xV2OYfV30NAyfMArc4uOQaeeehOdHiaHS8fvjgIplmuF9amotflEeAvwQxBdZvC39JicIxicCBVlaS43G1QtYkYufS64lEIvHPcJlQGIYo%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">遭泄露的代码库包含了 Claude Code 完整的 src/ 目录，共计约 1900 个文件，超过 512000 行代码，采用严格 TypeScript 编写，使用了 Bun 运行时和 React + Ink 终端 UI 框架。此次泄露范围广泛，涉及该 CLI 工具的每一个关键子系统。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">已确认泄露的关键文件包括：QueryEngine.ts（约 46000 行），驱动核心的大语言模型 API 引擎，涵盖流式传输、工具循环和令牌追踪功能；Tool.ts（约 29,000 行），定义了所有代理工具类型及权限模式；以及 commands.ts（约 25,000 行），负责注册和执行该工具中的斜杠命令。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">泄露的架构细节显示，该工具包含约 40 个代理工具，包括 BashTool、FileReadTool、FileEditTool，以及用于生成子代理的 AgentTool；同时还包含约 85 条斜杠命令，涵盖 Git 工作流、代码审查、内存管理和多代理编排等功能。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">此次泄露还揭示了内部功能标志，如 PROACTIVE、VOICE_MODE、BRIDGE_MODE 和 KAIROS，表明这些是尚未公开发布的产品功能。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">开发者们已经开始分析源代码，以寻找未记录的功能并了解该应用程序的工作原理。据 Alex Finn 称，Anthropic 正在测试一种名为“主动模式”的新模式，在该模式下，Claude 将全天候为用户编写代码。这一模式是在 Claude Code 的源代码中被发现的。另一个有趣的功能还包括被称为“梦境 (Dream)”的模式。在该模式下，Claude 可以在后台持续思考、构思想法、改进用户当前的计划，并尝试在用户离开时解决问题。</span></span></p><div data-role="title" data-tools="135编辑器" data-id="166211"><div style="margin: 10px auto;display: flex;justify-content: center;"><div style="display: flex;align-items: center;"><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100041950" src="https://wechat2rss.xlab.app/img-proxy/?k=8ff1e139&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ft5z0xV2OYfUOWWm9Ft9OKoAMHJbIsO0Nl27mKGUbqLNgC6MMQrVIrjS6RaDA8OqBQeRZcROaQAKCIyZibYGDpU6eyria5gib9nUibBo8iakp2PiaQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div><p style="font-size: 16px;color: #2e407b;text-align: center;padding: 0 6px;box-sizing:border-box;transform: rotateZ(0deg);-webkit-transform: rotateZ(0deg);-moz-transform: rotateZ(0deg);-o-transform: rotateZ(0deg);"><strong data-brushtype="text"><span leaf="">源映射如何导致泄露</span></strong></p></div><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100041953" src="https://wechat2rss.xlab.app/img-proxy/?k=d42c7699&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ft5z0xV2OYfWUyHibIg0j82MDRQc5GgLvGJBDx4Pd69qeWiant7NXOQqyaC6miccibWEmKY7HL5P8WUJNh6zrygk7Vs10PYiaQOWFuiaTRmVzbJTmQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">源映射文件（.map）是标准的开发者工具，旨在将编译或压缩后的 JavaScript 映射回其原始源代码，以便于调试。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">然而，当这些文件在无意中被打包到生产环境的 npm 发布版本中时，它们就会将专有源代码暴露给任何知道如何查找的人，实际上完全绕过了代码混淆。这并非 Anthropic 首次受到此类错误的影响；据报道，类似的一次源映射泄露事件已在 2025 年初得到解决。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">此次泄露事件给 Anthropic 带来了严重的知识产权问题，因为泄露的代码涵盖了内部 API 客户端逻辑、OAuth 2.0 认证流程、权限执行、多代理协调，甚至包括未公开的功能管线。</span></span></p><div data-role="title" data-tools="135编辑器" data-id="166211"><div style="margin: 10px auto;display: flex;justify-content: center;"><div style="display: flex;align-items: center;"><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100041952" src="https://wechat2rss.xlab.app/img-proxy/?k=e96a08ae&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ft5z0xV2OYfXVHOwkY2GXCx4xQNCJPSiacswLRicibdC1soe6Aan5NOiaBibs7acZBMHpvXy4icEghibpCdsXTPlFjAicFGOJCItFVtrSLUeToibyb7rc%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div><p style="font-size: 16px;color: #2e407b;text-align: center;padding: 0 6px;box-sizing:border-box;transform: rotateZ(0deg);-webkit-transform: rotateZ(0deg);-moz-transform: rotateZ(0deg);-o-transform: rotateZ(0deg);"><strong data-brushtype="text"><span leaf="">Claude Code 回应泄露和限速问题</span></strong></p></div><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100041954" src="https://wechat2rss.xlab.app/img-proxy/?k=d09e87ac&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Ft5z0xV2OYfXfYGdE7Y1L9ia55zOt0LUfQPliaLzI4DbSKx3BlBNbye2URIkVFmDT4RMgDCNZoadsgkY6K4MR00m540xRKPuTZYa7TaPb7VJdw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">Anthropic 证实了源代码遭泄露事件，提到“今天早些时候，Claude Code 的一次发布中包含了一些内部源代码。该事件不涉及也没有暴露任何敏感的客户数据或凭据。这是一次由人为错误导致的发布打包问题，而非安全入侵。我们正在推出相应措施，以防止此类事件再次发生。”</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">另外，用户声称 Claude 悄然降低了使用额度。这意味着无论用户使用的是 Pro 套餐还是 Max 套餐（5 倍额度），都会更快地耗尽 Claude 的使用额度。事实证明这个问题很普遍，Anthropic 已确认正在调查一个导致额度消耗过快的错误。“我们注意到人们在 Claude Code 中消耗使用额度的速度远超预期。我们正在积极调查，有进展时会分享更多信息。”Anthropic 公司的 Lydia Hallie 在 X 平台上发帖写道。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">随后Anthropic 发布了更新称，“[我们]仍在处理此问题。这是团队的首要任务。我知道这让很多人无法正常工作。有进一步消息会立即告知。”一些用户认为这可能是 Anthropic 有意为之的调整，因为过去几周 Claude 的受欢迎程度一直在上升，但在公司没有透露更多细节之前，无法判断这一说法是否属实。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">将 Claude Code 集成到其开发工作流程中的组织机构应关注 Anthropic 的官方安全公告。建议开发者查看官方 npm 仓库以获取已修复的版本，并避免使用泄露源代码的第三方镜像。</span></span></p></div></div><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;" data-pm-slice="5 3 []"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span style="font-size: 15px;"><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf=""> 开源</span></span><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf="">卫士试用地址：</span><span leaf=""><a href="https://oss.qianxin.com/#/login" target="_blank">https://oss.qianxin.com/#/login</a></span></span></span></span></p><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span leaf=""> 代码卫士试用地址：<a href="https://sast.qianxin.com/#/login" target="_blank">https://sast.qianxin.com/#/login</a></span></span></p><hr style="white-space: normal;border-style: solid;border-right-width: 0px;border-bottom-width: 0px;border-left-width: 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px 0px;transform: scale(1, 0.5);"/><div data-role="paragraph" style="white-space: normal;margin-bottom: 0px;"><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p></div><div data-id="12351" data-tools="新媒体排版" data-style-type="1" style="margin: 0px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);text-align: start;"><div data-css="border-color: initial;border-style: none;border-width: 0px;padding: 0px" style="margin: 0px;padding: 0px;border-color: initial;border-style: none;border-width: 0px;"><div powered-by="KolEditor.us" style="margin: 0px;padding: 0px;"><div style="margin: 10px 0px;padding: 0px;"><p style="font-size: medium;margin: 0px;padding: 0px;display: inline-block;"><span style="margin: 0px;padding: 0.3em 0.5em;background-color: rgb(23, 148, 221);border-radius: 0.8em 0.8em 0px 0px;color: rgb(255, 255, 255);display: block;font-size: 14.08px;"><p style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-size: 18px;"><span leaf=""><span textstyle="" style="font-size: 15px;">推荐阅读</span></span></span></strong></p></span></p><div data-css="border-color: rgb(249, 110, 87);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;box-sizing: border-box;padding: 10px" style="margin: 0px;padding: 10px;border-color: rgb(23, 148, 221);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px;padding: 0px;"><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525496&amp;idx=1&amp;sn=6253a0da55749336eda176e1d005d061&amp;scene=21#wechat_redirect" textvalue="简单的自定义字体渲染即可投毒 ChatGPT、Claude、Gemini 等 AI 系统" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">简单的自定义字体渲染即可投毒 ChatGPT、Claude、Gemini 等 AI 系统</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525085&amp;idx=2&amp;sn=db60b15e1fca3dbe39ef14ac28b16914&amp;scene=21#wechat_redirect" textvalue="Claude Opus 4.6 找到主流开源库中的500多个高危漏洞" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">Claude Opus 4.6 找到主流开源库中的500多个高危漏洞</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247521736&amp;idx=1&amp;sn=f656ad45da506b8f778e68ff0243d0be&amp;scene=21#wechat_redirect" textvalue="研究员在DeepSeek 和 Claude AI 中发现多个提示注入漏洞" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">研究员在DeepSeek 和 Claude AI 中发现多个提示注入漏洞</span></a></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 15px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0em;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);font-size: medium;text-align: start;"><span style="margin: 0px;padding: 0px;font-size: 15px;color: rgb(136, 136, 136);text-decoration: underline;"><strong style="margin: 0px;padding: 0px;"><span leaf="">原文链接</span></strong></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span lang="EN-US"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;"><a href="https://www.darkreading.com/application-security/storm-brews-critical-no-click-telegram-flaw" target="_blank">https://www.darkreading.com/application-security/storm-brews-critical-no-click-telegram-flaw</a></span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span lang="EN-US"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;"><a href="https://www.bleepingcomputer.com/news/artificial-intelligence/claude-code-source-code-accidentally-leaked-in-npm-package/" target="_blank">https://www.bleepingcomputer.com/news/artificial-intelligence/claude-code-source-code-accidentally-leaked-in-npm-package/</a></span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">题图：Pixa</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">bay Licens</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">e</span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><strong style="text-indent: 0em;"><span style="font-size: 15px;color: rgb(136, 136, 136);"><span leaf="">本文由奇安信编译，不代表奇安信观点。转载请注明“转自奇安信代码卫士 <a href="https://codesafe.qianxin.com”。" target="_blank">https://codesafe.qianxin.com”。</a></span></span></strong></p><div data-role="paragraph" style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><div data-id="9499" data-tools="新媒体排版" data-style-type="4" style="color: rgb(0, 0, 0);font-size: 17px;margin: 0px;padding: 0px 0.5em;text-align: start;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px auto;padding: 0px;text-align: center;"><div style="margin: 0px auto;padding: 0px 0px 10px;max-width: 360px !important;"><p style="margin: 0px;padding: 0px 0px 0px 2px;font-size: 0px;width: 65px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.27380952380952384" data-type="jpeg" data-w="84" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;height: auto !important;" data-fileid="100025253" src="https://wechat2rss.xlab.app/img-proxy/?k=20efc9d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSf7nNLWrJL6dkJp7RB8Kl4zxU9ibnQjuvo4VoZ5ic9Q91K3WshWzqEybcroVEOQpgYfx1uYgwJhlFQ%2F640%3Fwx_fmt%3Djpeg"/></p><div data-css="align-items: flex-start;border-color: rgb(255, 138, 101);border-style: solid;border-width: 2px;display: flex;margin-top: -10px;padding: 30px 25px" style="margin: -10px 0px 0px;padding: 30px 25px;align-items: flex-start;border-color: rgb(23, 148, 221);border-style: solid;border-width: 2px;display: flex;"><div style="margin: 0px;padding: 0px;font-size: 0px;flex-shrink: 0;"><p style="margin: 0px;padding: 0px;width: 75px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-type="jpeg" data-w="1080" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;border-color: rgb(238, 238, 238);border-radius: 2px;border-style: solid;border-width: 1px;width: 75px;height: auto !important;" data-cropselx1="0" data-cropselx2="75" data-cropsely1="0" data-cropsely2="75" data-fileid="100025255" src="https://wechat2rss.xlab.app/img-proxy/?k=4657c87c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSN5sfviaCuvYQccJZlrr64sRlvcbdWjDic9mPQ8mBBFDCKP6VibiaNE1kDVuoIOiaIVRoTjSsSftGC8gw%2F640%3Fwx_fmt%3Djpeg"/></p></div><div style="margin: 0px;padding: 0px 0px 0px 15px;flex-shrink: 1;"><p data-css="color: #333;font-size: 18px;line-height:1.7;margin: 0px auto;text-align: left" style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 18px;line-height: 1.7;text-align: left;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;color: rgb(23, 148, 221);"><span leaf="">奇安信代码卫士 (codesafe)</span></span></strong></span></p><p style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 16px;text-align: left;line-height: 1.4;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><span leaf="">国内首个专注于软件开发安全的产品线。</span></span></p></div></div></div></div></div></div><p style="color: rgb(51, 51, 51);font-size: 17px;margin: 0px;padding: 0px 0.5em;clear: both;min-height: 1em;text-align: center;"><span leaf="">   <img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="0.8" data-type="gif" data-w="200" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: middle;color: rgb(0, 0, 0);font-size: 14px;box-sizing: border-box;width: 58.125px;visibility: visible !important;height: auto !important;" data-fileid="100025256" src="https://wechat2rss.xlab.app/img-proxy/?k=fbb024f2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FoBANLWYScMQ5iciaeKS21icDIWSVd0M9zEhicFK0rbCJOrgpc09iaH6nvqvsIdckDfxH2K4tu9CvPJgSf7XhGHJwVyQ%2F640%3Fwx_fmt%3Dgif"/></span><span style="margin: 0px;padding: 0px;font-size: 12px;"><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">觉得不错，就点个 “</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">在看</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 或 &#34;</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">赞</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 吧~</span></span></span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://codesafe.qianxin.com/#/home">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=48223a4c&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2NTg4OTc5Nw%3D%3D%26mid%3D2247525629%26idx%3D1%26sn%3Dccf825a020a9d153cfe0c93f04be6c56">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 01 Apr 2026 18:36:00 +0800</pubDate>
    </item>
    <item>
      <title>Axios npm 包遭投毒，发动供应链攻击</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525629&amp;idx=2&amp;sn=b076315a014fe06f2a8b6eeec62f33c2</link>
      <description>精心策划的供应链攻击活动</description>
      <content:encoded><![CDATA[<p><span>Bill Toulas</span> <span>2026-04-01 18:36</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=029626de&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMQuoJibNce8dlpAMTvqm21iaKUXsfFGTCs9y03jFZZUgVLrh0SDAU6C0fGKxrxZAHqh8SPia88JeHUDg%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>精心策划的供应链攻击活动</p>
  <p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span leaf=""><img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="1" data-type="gif" data-w="400" style="margin-right: auto;margin-left: auto;vertical-align: middle;letter-spacing: 0.5px;text-indent: 0em;display: inline-block;box-sizing: border-box !important;visibility: visible !important;width: 30px !important;height: auto !important;" width="30" data-fileid="100025254" src="https://wechat2rss.xlab.app/img-proxy/?k=17396c1a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAz5ZsrEic9ot90z9etZLlU7OTaPOdibteeibJMMmbwc29aJlDOmUicibIRoLdcuEQjtHQ2qjVtZBt0M5eVbYoQzlHiaw%2F640%3Fwx_fmt%3Dgif"/> <span textstyle="" style="font-size: 14px;color: rgb(0, 122, 170);">聚焦源代码安全，网罗国内外最新资讯！</span></span></p><p style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(136, 136, 136);font-weight: bold;">编译：代码卫士</span></span></p><p style="margin-bottom: 0px;white-space: normal;text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4255555555555556" data-s="300,640" data-type="png" data-w="900" style="height: auto !important;" data-fileid="100025221" src="https://wechat2rss.xlab.app/img-proxy/?k=091c2efc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FoBANLWYScMRSylJK2k7H6mNqiaS2G6WRaeeK34cLHE6pe9VeOIHYiboAnKB0TMoayZCxFpHMLljzTnz9DnNuFiaqQ%2F640%3Fwx_fmt%3Dpng"/></p><div data-role="outer" label="Powered by 135editor.com" style="margin-bottom: 0px;white-space: normal;"><div data-tools="135编辑器" data-id="102705"><div style="margin: 10px auto;text-align: left;"><div style="background: rgb(79, 129, 189);"><div style="margin-left: 10px;display: flex;justify-content: flex-start;align-items: center;"><p style="padding-right: 10px;padding-left: 10px;font-size: 18px;letter-spacing: 1.5px;color: rgb(255, 255, 255);font-weight: bold;flex-shrink: 0;text-align: center;"><span leaf="">专栏·供应链安全</span></p></div></div><div style="padding: 1em 1em 1.3em;background: rgb(240, 250, 246);border-bottom: 1px solid rgb(79, 129, 189);"><div data-autoskip="1" style="text-align: justify;line-height: 1.75em;letter-spacing: 1.5px;font-size: 14px;color: rgb(79, 129, 189);background: transparent;"><p><span style="font-size: 15px;font-family: arial, helvetica, sans-serif;"><span leaf="">数字化时代，软件无处不在。软件如同社会中的“虚拟人”，已经成为支撑社会正常运转的最基本元素之一，软件的安全性问题也正在成为当今社会的根本性、基础性问题。</span></span></p><p><span style="font-size: 15px;font-family: arial, helvetica, sans-serif;"><span leaf="">随着软件产业的快速发展，软件供应链也越发复杂多元，复杂的软件供应链会引入一系列的安全问题，导致信息系统的整体安全防护难度越来越大。近年来，针对软件供应链的安全攻击事件一直呈快速增长态势，造成的危害也越来越严重。</span></span></p><p><span style="font-size: 15px;font-family: arial, helvetica, sans-serif;"><span leaf="">为此，我们推出“供应链安全”栏目。本栏目汇聚供应链安全资讯，分析供应链安全风险，提供缓解建议，为供应链安全保驾护航。</span></span></p><p style="text-align: left;"><span style="color: rgb(136, 136, 136);"><em><span leaf="">注：以往发布的部分供应链安全相关内容，请见文末“推荐阅读”部分。</span></em></span></p></div></div><div data-role="paragraph"><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="paragraph"><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="paragraph"><div data-tools="135编辑器" data-id="166585"><div style="margin: 10px auto;"><div style="display: flex;"><div style="flex-shrink: 0;"><div style="display: flex;"><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="paragraph"><div data-tools="135编辑器" data-id="166585"><div style="margin: 10px auto;"><div><div style="background-color: #ffffff;padding: 0px 10px;border-left: 3px solid #1a3566;border-right: 3px solid #1a3566;line-height: 1.1em;box-sizing:border-box;"><p data-autoskip="1" style="text-align: left;line-height: 1.75em;letter-spacing: 1.5px;font-size: 15px;color: #131f35;background-color: transparent;"><span style="font-size: 15px;color: #000000;"><strong><span leaf="">每周下载量超1亿次的热门JavaScript HTTP 客户端Axios 包的 npm 账户遭劫持，用于向 Linux、Windows 和 macOS 系统投递远程访问木马。</span></strong></span></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">威胁行动者被指在npm仓库上发布了 Axios 包的两个恶意版本。其中一个恶意变种 axios@1.14.1 于昨日 00:21 UTC 发布，而第二个变种 axios@0.30.4 在不到一小时后，即 01:00 UTC 出现。这些包在发布时没有通过自动化的 OpenID Connect（OIDC）包来源验证，也没有出现匹配的 GitHub 提交记录，本应立即触发警报。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">但威胁行动者在入侵了 Axios 主要维护者 Jason Saayman 的 npm 账户后，获取了对该包的访问权限。另外，攻击者还控制了 Saayman 的 GitHub 账户，并将关联邮箱更改为 ifstap@proton.me，随后删除了一则关于此次入侵事件的报告，而项目协作者 DigitalBrainJS 当时正试图回复该报告。目前尚不清楚在这近三小时的暴露窗口期内，受到了此次供应链攻击影响的下游项目的数量。不过鉴于 Axios npm 包的月下载量约为 4 亿次，受影响的数量可能相当可观。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">Axios 是一个用于 JavaScript 应用程序的 HTTP 客户端，负责管理客户端（如浏览器或 Node.js 应用）与服务器之间的请求。其目的是通过 GET、POST、PUT/PATCH 和 DELETE 请求来简化通信过程。</span></span></p><div data-role="title" data-tools="135编辑器" data-id="166211"><div style="margin: 10px auto;display: flex;justify-content: center;"><div style="display: flex;align-items: center;"><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100041947" src="https://wechat2rss.xlab.app/img-proxy/?k=e8018f08&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ft5z0xV2OYfWudzXvLEFiakdZGYj7lMrmTicChSsb4ogKiaXAC7TgwrL2yMWTYlFJHq4CF28tll6CTogfIrMw6OjGIbkr2tuAX2Iicib8L2R9PjYw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div><p style="font-size: 16px;color: #2e407b;text-align: center;padding: 0 6px;box-sizing:border-box;transform: rotateZ(0deg);-webkit-transform: rotateZ(0deg);-moz-transform: rotateZ(0deg);-o-transform: rotateZ(0deg);"><strong data-brushtype="text"><span leaf="">感染链</span></strong></p></div><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100041948" src="https://wechat2rss.xlab.app/img-proxy/?k=0e7b341e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ft5z0xV2OYfXVUQOicralQsCicuccmPpQPOp1OggjxOLCCtLWh42O6WOoo7ydAAVqPzEibTNibU5m9r0HKnGxGlzo2lxMVqDpeyhicnvhYdzwiaQIw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">获得Axios 的访问权限后，攻击者在 package.json 文件中注入了一个名为 plain-crypto-js@^4.2.1 的恶意依赖，而且并未修改 Axios 代码。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">该依赖在包安装过程中执行了一个 post-install 脚本，启动联系C2服务器的一个混淆释放器 (setup.js)，检索基于已检测操作系统的下一阶段 payload。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">在 Windows 系统上，该攻击混合使用 VBScript 和 PowerShell 来运行一个隐藏的命令提示符窗口并执行恶意脚本。该恶意软件将 PowerShell 复制到 %PROGRAMDATA%\wt.exe 以规避检测并实现跨重启的持久化，随后下载并执行一个 PowerShell 脚本。在 macOS 系统上，该恶意软件使用 AppleScript 将一个二进制文件下载到 /Library/Caches/com.apple.act.mond，将其标记为可执行文件，并在后台运行。在 Linux 系统上，该释放器获取一个存储在 `/tmp/ld.py` 的基于 Python 的有效负载，并使用 nohup（不挂断）命令在后台执行。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">在所有情况下，该恶意软件都会用远程访问木马（RAT）感染主机，从而使攻击者能够在受感染的系统上执行命令并维持持久化访问。该 RAT 能够检索并执行一个写入隐藏临时文件中的 base64 编码的二进制文件，通过 /bin/sh 或 AppleScript 执行 shell 命令，并枚举受感染主机上的目录。感染完成后，释放器会自行删除，移除被修改的 package.json，并用一个干净的副本替换它，从而增加取证调查的难度。</span></span></p><div data-role="title" data-tools="135编辑器" data-id="166211"><div style="margin: 10px auto;display: flex;justify-content: center;"><div style="display: flex;align-items: center;"><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100041946" src="https://wechat2rss.xlab.app/img-proxy/?k=7ebd71bb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ft5z0xV2OYfUjicr3E6eP4mX5rq78H2Jf3QvRh8XibS3rskxWyEicKnUyZCdq40hCAGVqCk6jOBKgDib0ibBOJj7c5VzrMX3Cn5BiaOPrrqcgn7eHA%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div><p style="font-size: 16px;color: #2e407b;text-align: center;padding: 0 6px;box-sizing:border-box;transform: rotateZ(0deg);-webkit-transform: rotateZ(0deg);-moz-transform: rotateZ(0deg);-o-transform: rotateZ(0deg);"><strong data-brushtype="text"><span leaf="">精心策划的供应链攻击</span></strong></p></div><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100041945" src="https://wechat2rss.xlab.app/img-proxy/?k=0ba9df6e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Ft5z0xV2OYfVBFFnR4oeICL9ic8CZmq3ibWtaQ58Qv0GoOMIcIdiaOPO53sGQWTHS0YAmzyw99hMJWThLqclR3CIShrbqm6vx2mbuIZBMdkS1Ks%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">据研究人员称，此次 Axios 供应链攻击并非偶发事件，而是一次精心策划的行动，“恶意依赖项在 18 小时前就已预先部署就位”。根据检测到的操作系统投递不同 payload 这一事实，以及每个工件都具备自毁行为，似乎都支持了这一判断。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">谷歌威胁情报集团（GTIG）首席分析师 John Hultquist表示，此次 Axios 包入侵事件的幕后黑手是一个被内部追踪为 UNC1069 的朝鲜威胁行动者，该组织以攻击“中心化交易所（CEX）、金融机构的软件开发者、高科技公司以及风险投资机构的个人”而为人所知。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">一名安全研究人员表示，macOS 版 RAT 中的 macWebT 名称直接指向了 SentinelOne 在 2023 年发现的 BlueNoroff 黑客组织活动中所使用的恶意软件。BlueNoroff 是一个以经济为目的的网络攻击著称的朝鲜威胁组织。该组织曾以银行、金融机构和加密货币交易所为目标。目前，关于此次 Axios 供应链攻击背后的威胁行为者尚无明确信息。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">近期，多起备受瞩目的供应链攻击事件被一个名为 TeamPCP 的组织声称负责。该黑客组织曾针对 Telnyx、LiteLLM 和 Trivy 等知名开源软件项目发起攻击。然而，此次 Axios 包入侵事件并不具备 TeamPCP 攻击的特征，安全研究人员也无法将其与某个特定的威胁行动者关联起来。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">建议安全团队检查环境中是否存在 axios@1.14.1、axios@0.30.4 或任何版本的 plain-crypto-js，若发现其中任何一个，则应将系统视为已遭入侵。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">Axios 应回退至 1.14.0 或 0.30.3 版本，或降级至经确认安全的更早版本。Elastic 公司的研究员 Joe DeSimone 建议，对于运行了受影响 Axios 包版本的系统，应更换相关凭证，因为该恶意软件可能已窃取了密钥和令牌等敏感数据。Mandiant 首席技术官 Charles Carmakal 表示，此次 Axios npm 供应链攻击“范围广泛，并波及到依赖该包的其它流行软件包”。该研究人员警告称，近期供应链安全事件数量庞大，过去两周内通过这种方式窃取的秘密信息将导致更多的入侵事件、加密货币盗窃、勒索软件及敲诈勒索事件。他还提到，有数十万份凭据被窃取，背后是动机各异的威胁行动者。</span></span></p></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span style="font-size: 15px;"><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf="">开源</span></span><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf="">卫士试用地址：</span></span><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span style="font-size: 15px;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 15px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><a href="https://sast.qianxin.com/#/login" target="_blank">https://sast.qianxin.com/#/login</a></span></span></span></span></span></p><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span leaf="">代码卫士试用地址：</span><span style="font-size: 15px;"><span leaf=""><a href="https://codesafe.qianxin.com" target="_blank">https://codesafe.qianxin.com</a></span></span></span></p><hr style="white-space: normal;border-style: solid;border-right-width: 0px;border-bottom-width: 0px;border-left-width: 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px 0px;transform: scale(1, 0.5);"/><div data-role="paragraph" style="white-space: normal;margin-bottom: 0px;"><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p></div><div data-id="12351" data-tools="新媒体排版" data-style-type="1" style="margin: 0px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);text-align: start;"><div data-css="border-color: initial;border-style: none;border-width: 0px;padding: 0px" style="margin: 0px;padding: 0px;border-color: initial;border-style: none;border-width: 0px;"><div powered-by="KolEditor.us" style="margin: 0px;padding: 0px;"><div style="margin: 10px 0px;padding: 0px;"><p style="font-size: medium;margin: 0px;padding: 0px;display: inline-block;"><span data-css="background-color: rgb(249, 110, 87);border-radius: 0.8em 0.8em 0px 0px;box-sizing: border-box;color: rgb(255, 255, 255);display: block;font-size: 14.08px;padding: 0.3em 0.5em" style="margin: 0px;padding: 0.3em 0.5em;background-color: rgb(23, 148, 221);border-radius: 0.8em 0.8em 0px 0px;color: rgb(255, 255, 255);display: block;font-size: 14.08px;"><p style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-size: 18px;"><span leaf="">推荐阅读</span></span></strong></p></span></p><div data-css="border-color: rgb(249, 110, 87);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;box-sizing: border-box;padding: 10px" style="margin: 0px;padding: 10px;border-color: rgb(23, 148, 221);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px;padding: 0px;" data-pm-slice="0 0 []"><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523516&amp;idx=1&amp;sn=0b6fc53ba92e7b5135395b67fff6a822&amp;scene=21#wechat_redirect" textvalue="在线阅读版：《2025中国软件供应链安全分析报告》全文" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">在线阅读版：《2025中国软件供应链安全分析报告》全文</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525520&amp;idx=2&amp;sn=b3d4dddc586c4b0aa8cefb09c0344cb8&amp;scene=21#wechat_redirect" textvalue="Trivy供应链攻击触发CanisterWorm 在47个 npm 包中自传播" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">Trivy供应链攻击触发CanisterWorm 在47个 npm 包中自传播</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524984&amp;idx=1&amp;sn=19aef4ce8e288278782458e430a710d8&amp;scene=21#wechat_redirect" textvalue="热门包管理器中存在多个漏洞，JavaScript 生态系统易受供应链攻击" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">热门包管理器中存在多个漏洞，JavaScript 生态系统易受供应链攻击</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524828&amp;idx=2&amp;sn=21af241f60f1452013815133745e9a72&amp;scene=21#wechat_redirect" textvalue="开源自托管平台 Coolify 修复11个严重漏洞，可导致服务器遭完全攻陷" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">开源自托管平台 Coolify 修复11个严重漏洞，可导致服务器遭完全攻陷</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524487&amp;idx=1&amp;sn=f170d3131122071dec6e419c6cff562c&amp;scene=21#wechat_redirect" textvalue="得不到就毁掉：第二轮Sha1-Hulud供应链攻击已发起，影响2.5万+仓库" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">得不到就毁掉：第二轮Sha1-Hulud供应链攻击已发起，影响2.5万+仓库</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524481&amp;idx=3&amp;sn=6d0b161f8add2f6c1ee65e60ef6955d8&amp;scene=21#wechat_redirect" textvalue="vLLM 高危漏洞可导致RCE" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">vLLM 高危漏洞可导致RCE</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247519162&amp;idx=1&amp;sn=3872fcc82018e2c561d9e4e7574f0c8e&amp;scene=21#wechat_redirect" textvalue="开源AI框架 Ray 的0day已用于攻陷服务器和劫持资源" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">开源AI框架 Ray 的0day已用于攻陷服务器和劫持资源</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524330&amp;idx=2&amp;sn=bc54e02a8f815ed78b67d3135a9f9607&amp;scene=21#wechat_redirect" textvalue="热门 React Native NPM 包中存在严重漏洞，开发人员易受攻击" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">热门 React Native NPM 包中存在严重漏洞，开发人员易受攻击</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524314&amp;idx=2&amp;sn=81cae6998a39f2153ed18d7cc065303b&amp;scene=21#wechat_redirect" textvalue="10个npm包被指窃取 Windows、macOS 和 Linux 系统上的开发者凭据" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">10个npm包被指窃取 Windows、macOS 和 Linux 系统上的开发者凭据</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524330&amp;idx=2&amp;sn=bc54e02a8f815ed78b67d3135a9f9607&amp;scene=21#wechat_redirect" textvalue="热门 React Native NPM 包中存在严重漏洞，开发人员易受攻击" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">热门 React Native NPM 包中存在严重漏洞，开发人员易受攻击</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247508946&amp;idx=1&amp;sn=273c58d08a4225306a567cf6a150f40c&amp;scene=21#wechat_redirect" textvalue="热门NPM库 “coa” 和“rc” 接连遭劫持，影响全球的 React 管道" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">热门NPM库 “coa” 和“rc” 接连遭劫持，影响全球的 React 管道</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247515219&amp;idx=1&amp;sn=faa32338df1d68e7cd738a80222f3a44&amp;scene=21#wechat_redirect" textvalue="开发人员注意：VSCode 应用市场易被滥用于托管恶意扩展" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">开发人员注意：VSCode 应用市场易被滥用于托管恶意扩展</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524163&amp;idx=1&amp;sn=d70a7c55e27a3e179522330a9ce62b0b&amp;scene=21#wechat_redirect" textvalue="GitHub Copilot 严重漏洞可导致私有仓库源代码被盗" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">GitHub Copilot 严重漏洞可导致私有仓库源代码被盗</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524053&amp;idx=1&amp;sn=2b843932ebd4eeeb17b6935b08be82f8&amp;scene=21#wechat_redirect" textvalue="受 Salesforce 供应链攻击影响，全球汽车巨头 Stellantis 数据遭泄露" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">受 Salesforce 供应链攻击影响，全球汽车巨头 Stellantis 数据遭泄露</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523990&amp;idx=1&amp;sn=ad9957a5c3d054d4a0bf32250bceb556&amp;scene=21#wechat_redirect" textvalue="捷豹路虎数据遭泄露生产仍未恢复，幕后黑手或与 Salesforce-Salesloft 供应链攻击有关" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">捷豹路虎数据遭泄露生产仍未恢复，幕后黑手或与 Salesforce-Salesloft 供应链攻击有关</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523972&amp;idx=1&amp;sn=7b06c31940ea7576d0236d9310886b39&amp;scene=21#wechat_redirect" textvalue="十几家安全大厂信息遭泄露，谁是 Salesforce-Salesloft 供应链攻击的下一个受害者？" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">十几家安全大厂信息遭泄露，谁是 Salesforce-Salesloft 供应链攻击的下一个受害者？</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523952&amp;idx=1&amp;sn=2bc84253019e6c2525bcf928eaed696c&amp;scene=21#wechat_redirect" textvalue="第三方集成应用 Drift OAuth 令牌被用于攻陷 Salesforce 实例，全球700+家企业受影响" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">第三方集成应用 Drift OAuth 令牌被用于攻陷 Salesforce 实例，全球700+家企业受影响</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523990&amp;idx=2&amp;sn=6e38e1ee8cd69f1375a5be218c02ff97&amp;scene=21#wechat_redirect" textvalue="黑客发动史上规模最大的 NPM 供应链攻击，影响全球10%的云环境" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">黑客发动史上规模最大的 NPM 供应链攻击，影响全球10%的云环境</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523972&amp;idx=1&amp;sn=7b06c31940ea7576d0236d9310886b39&amp;scene=21#wechat_redirect" textvalue="十几家安全大厂信息遭泄露，谁是 Salesforce-Salesloft 供应链攻击的下一个受害者？" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">十几家安全大厂信息遭泄露，谁是 Salesforce-Salesloft 供应链攻击的下一个受害者？</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523952&amp;idx=1&amp;sn=2bc84253019e6c2525bcf928eaed696c&amp;scene=21#wechat_redirect" textvalue="第三方集成应用 Drift OAuth 令牌被用于攻陷 Salesforce 实例，全球700+家企业受影响" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">第三方集成应用 Drift OAuth 令牌被用于攻陷 Salesforce 实例，全球700+家企业受影响</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523962&amp;idx=1&amp;sn=2d9b8ca044c242a6ae1f72df93d7acb0&amp;scene=21#wechat_redirect" textvalue="AI供应链易遭“模型命名空间复用”攻击" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">AI供应链易遭“模型命名空间复用”攻击</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523957&amp;idx=2&amp;sn=288b0d14a657b13c7f1a6b14705a44e8&amp;scene=21#wechat_redirect" textvalue="Frostbyte10：威胁全球供应链的10个严重漏洞" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">Frostbyte10：威胁全球供应链的10个严重漏洞</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523850&amp;idx=2&amp;sn=72dc01d9984a720959b312dd0e7cf05e&amp;scene=21#wechat_redirect" textvalue="PyPI拦截1800个过期域名邮件，防御供应链攻击" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">PyPI拦截1800个过期域名邮件，防御供应链攻击</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523844&amp;idx=2&amp;sn=08c8962eead61fe76467a9196b3da3e5&amp;scene=21#wechat_redirect" textvalue="PyPI恶意包利用依赖引入恶意行为，发动软件供应链攻击" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">PyPI恶意包利用依赖引入恶意行为，发动软件供应链攻击</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523700&amp;idx=2&amp;sn=463d300bdfd3de129cd5d258ceb67cf4&amp;scene=21#wechat_redirect" textvalue="黑客利用虚假 PyPI 站点钓鱼攻击Python 开发人员" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">黑客利用虚假 PyPI 站点钓鱼攻击Python 开发人员</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247492823&amp;idx=2&amp;sn=9c226ff328303e78331451ac5219df07&amp;scene=21#wechat_redirect" textvalue="700多个恶意误植域名库盯上RubyGems 仓库" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">700多个恶意误植域名库盯上RubyGems 仓库</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523648&amp;idx=1&amp;sn=d9237c45bf78637d1cdd3bedd1d873e6&amp;scene=21#wechat_redirect" textvalue="NPM “意外” 删除 Stylus 合法包 全球流水线和构建被迫中断" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">NPM “意外” 删除 Stylus 合法包 全球流水线和构建被迫中断</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523615&amp;idx=1&amp;sn=1df256011200be03dc2afc80016c587e&amp;scene=21#wechat_redirect" textvalue="固件开发和更新缺陷导致漏洞多年难修，供应链安全深受其害" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">固件开发和更新缺陷导致漏洞多年难修，供应链安全深受其害</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523592&amp;idx=2&amp;sn=5087c0aa841caf3f0def9a1ca6c5ad27&amp;scene=21#wechat_redirect" textvalue="NPM仓库被植入67个恶意包传播恶意软件" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">NPM仓库被植入67个恶意包传播恶意软件</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523516&amp;idx=1&amp;sn=0b6fc53ba92e7b5135395b67fff6a822&amp;scene=21#wechat_redirect" textvalue="在线阅读版：《2025中国软件供应链安全分析报告》全文" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">在线阅读版：《2025中国软件供应链安全分析报告》全文</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523234&amp;idx=2&amp;sn=ac4e0656fd04218349d356761af176dd&amp;scene=21#wechat_redirect" textvalue="NPM软件供应链攻击传播恶意软件" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">NPM软件供应链攻击传播恶意软件</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523167&amp;idx=2&amp;sn=4249c8e9e0dace01810c665eda52c421&amp;scene=21#wechat_redirect" textvalue="隐秘的 npm 供应链攻击：误植域名导致RCE和数据破坏" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">隐秘的 npm 供应链攻击：误植域名导致RCE和数据破坏</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523031&amp;idx=2&amp;sn=5071cdb63bdd6339b1a3ff7ef3581cd5&amp;scene=21#wechat_redirect" textvalue="NPM恶意包利用Unicode 隐写术躲避检测" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">NPM恶意包利用Unicode 隐写术躲避检测</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247522945&amp;idx=1&amp;sn=c767722383afc7e6b505aef2f50ba4cd&amp;scene=21#wechat_redirect" textvalue="Aikido在npm热门包 rand-user-agent 中发现恶意代码" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">Aikido在npm热门包 rand-user-agent 中发现恶意代码</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247522841&amp;idx=2&amp;sn=024b6c290bf4ebecc241f11bc944be1c&amp;scene=21#wechat_redirect" textvalue="密币Ripple 的NPM 包 xrpl.js 被安装后门窃取私钥，触发供应链攻击" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">密币Ripple 的NPM 包 xrpl.js 被安装后门窃取私钥，触发供应链攻击</span></a></span></p></div></div></div></div></div></div></div><p style="margin-bottom: 15px;padding-right: 0.5em;padding-left: 0.5em;text-indent: 0em;white-space: normal;letter-spacing: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;"><span style="font-size: 15px;color: rgb(136, 136, 136);text-decoration: underline;"><strong><span leaf="">原文链接</span></strong></span></p><p style="margin-bottom: 15px;padding-right: 0.5em;padding-left: 0.5em;text-indent: 0em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: normal;"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="text-align: start;letter-spacing: normal;font-weight: bold;text-indent: 0em;font-size: 15px;color: rgb(136, 136, 136);"><span textstyle="" style="font-weight: normal;"><a href="https://www.bleepingcomputer.com/news/security/hackers-compromise-axios-npm-package-to-drop-cross-platform-malware/" target="_blank">https://www.bleepingcomputer.com/news/security/hackers-compromise-axios-npm-package-to-drop-cross-platform-malware/</a></span></span></span></p><p style="margin-bottom: 15px;padding-right: 0.5em;padding-left: 0.5em;text-indent: 0em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: normal;"><strong style="white-space: normal;text-align: start;letter-spacing: normal;font-weight: bold;text-indent: 0em;font-size: 15px;color: rgb(136, 136, 136);"><span leaf="" style="font-weight: bold;text-indent: 0em;font-size: 15px;color: rgb(136, 136, 136);">本文由奇安信编译，不代表</span></strong><strong style="text-indent: 0em;"><span style="font-size: 15px;color: rgb(136, 136, 136);"><span leaf="">奇安信观点。转载请注明“转自奇安信代码卫士 <a href="https://codesafe.qianxin.com”。" target="_blank">https://codesafe.qianxin.com”。</a></span></span></strong></p><div data-id="9499" data-tools="新媒体排版" data-style-type="4" style="color: rgb(0, 0, 0);font-size: 17px;margin: 0px;padding: 0px 0.5em;text-align: start;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px auto;padding: 0px;text-align: center;"><div style="margin: 0px auto;padding: 0px 0px 10px;max-width: 360px !important;"><p style="margin: 0px;padding: 0px 0px 0px 2px;font-size: 0px;width: 65px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.27380952380952384" data-type="jpeg" data-w="84" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;height: auto !important;" data-fileid="100025253" src="https://wechat2rss.xlab.app/img-proxy/?k=20efc9d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSf7nNLWrJL6dkJp7RB8Kl4zxU9ibnQjuvo4VoZ5ic9Q91K3WshWzqEybcroVEOQpgYfx1uYgwJhlFQ%2F640%3Fwx_fmt%3Djpeg"/></p><div data-css="align-items: flex-start;border-color: rgb(255, 138, 101);border-style: solid;border-width: 2px;display: flex;margin-top: -10px;padding: 30px 25px" style="margin: -10px 0px 0px;padding: 30px 25px;align-items: flex-start;border-color: rgb(23, 148, 221);border-style: solid;border-width: 2px;display: flex;"><div style="margin: 0px;padding: 0px;font-size: 0px;flex-shrink: 0;"><p style="margin: 0px;padding: 0px;width: 75px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-type="jpeg" data-w="1080" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;border-color: rgb(238, 238, 238);border-radius: 2px;border-style: solid;border-width: 1px;width: 75px;height: auto !important;" data-cropselx1="0" data-cropselx2="75" data-cropsely1="0" data-cropsely2="75" data-fileid="100025255" src="https://wechat2rss.xlab.app/img-proxy/?k=4657c87c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSN5sfviaCuvYQccJZlrr64sRlvcbdWjDic9mPQ8mBBFDCKP6VibiaNE1kDVuoIOiaIVRoTjSsSftGC8gw%2F640%3Fwx_fmt%3Djpeg"/></p></div><div style="margin: 0px;padding: 0px 0px 0px 15px;flex-shrink: 1;"><p data-css="color: #333;font-size: 18px;line-height:1.7;margin: 0px auto;text-align: left" style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 18px;line-height: 1.7;text-align: left;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><strong style="margin: 0px;padding: 0px;"><span data-css="color: rgb(52, 195, 131)" style="margin: 0px;padding: 0px;color: rgb(23, 148, 221);"><span leaf="">奇安信代码卫士 (codesafe)</span></span></strong></span></p><p style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 16px;text-align: left;line-height: 1.4;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><span leaf="">国内首个专注于软件开发安全的产品线。</span></span></p></div></div></div></div></div></div><p style="color: rgb(51, 51, 51);font-size: 17px;margin: 0px;padding: 0px 0.5em;clear: both;min-height: 1em;text-align: center;"><span leaf="">   <img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="0.8" data-type="gif" data-w="200" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: middle;color: rgb(0, 0, 0);font-size: 14px;box-sizing: border-box;width: 58.125px;visibility: visible !important;height: auto !important;" data-fileid="100025256" src="https://wechat2rss.xlab.app/img-proxy/?k=fbb024f2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FoBANLWYScMQ5iciaeKS21icDIWSVd0M9zEhicFK0rbCJOrgpc09iaH6nvqvsIdckDfxH2K4tu9CvPJgSf7XhGHJwVyQ%2F640%3Fwx_fmt%3Dgif"/></span><span style="margin: 0px;padding: 0px;font-size: 12px;"><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">觉得不错，就点个 “</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">在看</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 或 &#34;</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">赞</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 吧~</span></span></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://codesafe.qianxin.com/#/home">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=6eec1b30&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2NTg4OTc5Nw%3D%3D%26mid%3D2247525629%26idx%3D2%26sn%3Db076315a014fe06f2a8b6eeec62f33c2">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 01 Apr 2026 18:36:00 +0800</pubDate>
    </item>
    <item>
      <title>Telegram 否认这个零点击高危 0day 漏洞的存在</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525587&amp;idx=1&amp;sn=402fc52dcbd813d3c5d2c26bf077fab0</link>
      <description>速修复</description>
      <content:encoded><![CDATA[<p><span>代码卫士</span> <span>2026-03-31 18:05</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=97b300c7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft5z0xV2OYfWA2ic7Ot9QMDZyic6xQmBQrE2e0gjzNAQKrHUH16XXic2X7NW6qb7eDc9DDnMtEUwDvPtWT3DCSycticwgZow6hRUwR2KcSmSuMJ4%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>速修复</p>
  <p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span leaf=""><img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="1" data-type="gif" data-w="400" style="margin-right: auto;margin-left: auto;vertical-align: middle;letter-spacing: 0.5px;text-indent: 0em;display: inline-block;box-sizing: border-box !important;visibility: visible !important;width: 30px !important;height: auto !important;" width="30" data-fileid="100025254" src="https://wechat2rss.xlab.app/img-proxy/?k=17396c1a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAz5ZsrEic9ot90z9etZLlU7OTaPOdibteeibJMMmbwc29aJlDOmUicibIRoLdcuEQjtHQ2qjVtZBt0M5eVbYoQzlHiaw%2F640%3Fwx_fmt%3Dgif"/>  </span><span style="text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-mpa-powered-by&#34;:&#34;yiban.io&#34;,&#34;style&#34;:&#34;margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">聚焦源代码安全，网罗国内外最新资讯！</span></span></p><p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;text-align: start;"><span leaf="" style="font-weight: bold;font-size: 15px;font-family: sofia-pro, sans-serif;letter-spacing: normal;text-transform: uppercase;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;transition: color 0.15s ease-out, background-color 0.3s ease-out, text-decoration-color 0.15s ease-out;box-shadow: inset 0 -2px 0 var(--color-black);overflow: hidden;padding-bottom: 4px;color: rgb(136, 136, 136);">作者：</span><span leaf="" style="font-weight: bold;font-size: 15px;font-family: sofia-pro, sans-serif;letter-spacing: normal;text-transform: uppercase;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;transition: color 0.15s ease-out, background-color 0.3s ease-out, text-decoration-color 0.15s ease-out;box-shadow: inset 0 -2px 0 var(--color-black);overflow: hidden;padding-bottom: 4px;color: rgb(136, 136, 136);"> Elizabeth Montalbano</span></p><p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;text-align: start;"><strong style="color: rgb(0, 0, 0);letter-spacing: 1px;font-size: 15px;"><span style="font-family: sofia-pro, sans-serif;letter-spacing: normal;text-transform: uppercase;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;transition: color 0.15s ease-out 0s, background-color 0.3s ease-out 0s, text-decoration-color 0.15s ease-out 0s;box-shadow: inset 0 -2px 0 var(--color-black);overflow: hidden;padding-bottom: 4px;color: rgb(136, 136, 136);"><span leaf="">编译：代码卫士</span></span></strong></p><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="paragraph"><div data-tools="135编辑器" data-id="166585"><div style="margin: 10px auto;"><div><div style="background-color: #ffffff;padding: 0px 10px;border-left: 3px solid #1a3566;border-right: 3px solid #1a3566;line-height: 1.1em;box-sizing:border-box;"><p data-autoskip="1" style="text-align: left;line-height: 1.75em;letter-spacing: 1.5px;font-size: 15px;color: #131f35;background-color: transparent;"><span style="color: #000000;font-size: 15px;"><strong><span leaf="">上周四，ZDI 发布文章称研究员 Michael DePlante发现Telegram Messenger中存在一个严重漏洞（内部编号ZDI-CAN-30207），可导致系统完全被劫持，影响10亿用户。漏洞完整细节计划在7月26日前公布。然而，Telegram却在社交媒体网站X上发帖，否认该漏洞的存在。这一情况引发轩然大波。ZDI曾为该漏洞赋予 CVSS 9.8分的严重级别评分，但在本周一将其下调至7.0分的高危级别。ZDI在X平台上发帖称，做出这一调整是为了反映“供应商在披露过程中所描述的服务器端缓解措施”。</span></strong></span></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">虽然目前关于该漏洞的公开细节寥寥无几，但多份已发布的报告解释了为何该漏洞会获得如此危险的评级。意大利国家网络安全局发布警报（经由谷歌翻译）称，ZDI-CAN-30207漏洞可对Android和Linux版本的该应用实现疑似零点击、可通过网络远程执行的攻击，这种攻击能够执行任意代码、访问私人通信、实施监控、窃取敏感数据以及破坏设备功能。</span></span></p><div data-role="title" data-tools="135编辑器" data-id="166211"><div style="margin: 10px auto;display: flex;justify-content: center;"><div style="display: flex;align-items: center;"><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100041926" src="https://wechat2rss.xlab.app/img-proxy/?k=88472260&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Ft5z0xV2OYfUMK5spiaYcy542rSBKdtXyUribThBcEjrR0EjbrYj8nwYzDGFgVbglRZiaPdrNKYlDJxUiaA2JMwyZTCY1uMCgAK4Vbz9Micvgvpjw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div><p style="font-size: 16px;color: #2e407b;text-align: center;padding: 0 6px;box-sizing:border-box;transform: rotateZ(0deg);-webkit-transform: rotateZ(0deg);-moz-transform: rotateZ(0deg);-o-transform: rotateZ(0deg);"><strong data-brushtype="text"><span leaf="">当好贴纸变坏时</span></strong></p></div><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100041925" src="https://wechat2rss.xlab.app/img-proxy/?k=9467b1f3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Ft5z0xV2OYfWWglPmR6aC69ibl6ZSPZbhIcHKeh6kDlVr7nYq0PvOWAfP0rNSOjf1kG0bj1Eayydica4ZEU9ic52dRgvnsfd9BIxRiaWaaLYheTo%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">该漏洞的利用涉及使用Telegram中一个被篡改的贴纸 (sticker) 作为攻击载体。贴纸是经过特殊处理的媒体文件，用户在使用该应用聊天时常用它们来表达情感或代替短消息。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">独立网络安全顾问 Carolina Vivianti 在Red Hot Cyber博客上发文指出：“攻击载体出奇地简单：动态贴纸。”她称该漏洞“极其令人不安”，因为要利用该漏洞实施攻击，用户在Telegram会话中无需点击或打开任何内容。她写道：“仅仅收到内容就足够了。无需确认，无需用户交互。系统会处理这些文件以生成预览图，而攻击恰恰就发生在这个阶段。”</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">然而，Telegram在X平台上反复声明称，通过贴纸进行此类攻击是不可能的，并声称这种说法“完全忽略了所有上传到Telegram的贴纸在能被Telegram应用播放之前，都会经过其服务器的验证”。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">意大利国家网络安全局周一更新了告警并加入了Telegram的否认声明。更新内容写道：“根据这一官方立场，集中式过滤流程阻止了使用被篡改的贴纸作为攻击载体，使得通过此方法执行恶意代码在技术上成为不可能。”目前该机构并未立即回复更多漏洞信息相关问询。</span></span></p><div data-role="title" data-tools="135编辑器" data-id="166211"><div style="margin: 10px auto;display: flex;justify-content: center;"><div style="display: flex;align-items: center;"><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100041929" src="https://wechat2rss.xlab.app/img-proxy/?k=9c46ad4a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Ft5z0xV2OYfWGY7yroUJicNEY1h99kCH7QsOoNs3icR6EW2knWJMTC49niaibOiapz8eE7HviaEzU2xpicRUicYiccrJ2abu8ZUSk96GJdic6Le3CGy1XA%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div><p style="font-size: 16px;color: #2e407b;text-align: center;padding: 0 6px;box-sizing:border-box;transform: rotateZ(0deg);-webkit-transform: rotateZ(0deg);-moz-transform: rotateZ(0deg);-o-transform: rotateZ(0deg);"><strong data-brushtype="text"><span leaf="">Telegram面临更多麻烦？</span></strong></p></div><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100041928" src="https://wechat2rss.xlab.app/img-proxy/?k=3f8e2ca7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ft5z0xV2OYfURiaRlAVkMMmf9L4hTV63FZ2ibNSVvtCxdoHKMED2wDCroKc3OefTqSnJz2FbamRjWvYzszPPlcm3G5KbV5vibfgGFA4qIDUq6Gg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">Telegram采用消息加密机制，被许多人用于私人通信。因此，一个能让攻击者窃取数据、实施网络间谍活动及进行各种其它恶意行为的零点击漏洞，会对该平台造成巨大冲击。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">事实上，威胁行动者可以利用即时通讯应用中的漏洞，针对通信内容可能具有战略或全球重要性的各类目标人物，包括记者、政治人物、政府官员、公司高管或企业用户。与此同时，Telegram的安全政策也使该公司深陷争议和法律纠纷。值得注意的是，首席执行官Pavel Durov于2024年被法国当局逮捕，原因是Telegram一直拒绝与执法机构共享除恐怖主义案件以外的数据，这一事件迫使该公司对其政策做出了调整。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">此外，该应用在网络犯罪分子中也很受欢迎，他们认为可以在此进行恶意活动而无需担心被检测到；事实上，他们经常设立专门的Telegram频道作为非法活动的基础。</span></span></p><div data-role="title" data-tools="135编辑器" data-id="166211"><div style="margin: 10px auto;display: flex;justify-content: center;"><div style="display: flex;align-items: center;"><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100041927" src="https://wechat2rss.xlab.app/img-proxy/?k=ff01305a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Ft5z0xV2OYfU7SicgNU9ia3aayR97R9CIfjyaY0V6r5eeZ4eFUGYfHCdbhfbXxr6sxCwgZFjIdtMicGXibJFj1IW82m90CkltDUv9o7955RCkXgs%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div><p style="font-size: 16px;color: #2e407b;text-align: center;padding: 0 6px;box-sizing:border-box;transform: rotateZ(0deg);-webkit-transform: rotateZ(0deg);-moz-transform: rotateZ(0deg);-o-transform: rotateZ(0deg);"><strong data-brushtype="text"><span leaf="">防御措施</span></strong></p></div><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100041930" src="https://wechat2rss.xlab.app/img-proxy/?k=4425e5ba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Ft5z0xV2OYfUZY5rfF0LIQ7ibCLmCduOzxsmFmA9nYFaazP8hInNcaEtNaKHWzgZWsABtyIQ7Ovk7eDJMUFibA4QTTFuBLsZtosxRkZxibyK5Qs%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">在Telegram改变否认该漏洞存在的立场之前，公众在7月之前不太可能知晓该漏洞不仅存在而且如ZDI所担心的那样危险。在此之前，Telegram用户应安装未来几个月发布的所有应用更新，并在补丁出现时立即应用任何为修复该漏洞而部署的补丁，以确保自己使用的是最安全的版本。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">在情况变得更加明朗之前，Vivianti为Telegram的企业用户和个人用户分别提出了防御建议。对于前者，她建议通过将消息接收限制为仅限受信任的联系人或高级用户来减少攻击面。她认为，虽然这么做会影响通信流程，但能降低暴露风险。对于普通公众，由于仅禁用自动下载是不够的，因此她建议用户暂时卸载该应用，或通过最新版本的浏览器使用Telegram网页版，从而“利用现代浏览器的沙盒架构”。她表示，与原生客户端相比，网页提供了更强的隔离层。</span></span></p></div></div><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;" data-pm-slice="5 3 []"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span style="font-size: 15px;"><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf=""> 开源</span></span><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf="">卫士试用地址：</span><span leaf=""><a href="https://oss.qianxin.com/#/login" target="_blank">https://oss.qianxin.com/#/login</a></span></span></span></span></p><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span leaf=""> 代码卫士试用地址：<a href="https://sast.qianxin.com/#/login" target="_blank">https://sast.qianxin.com/#/login</a></span></span></p><hr style="white-space: normal;border-style: solid;border-right-width: 0px;border-bottom-width: 0px;border-left-width: 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px 0px;transform: scale(1, 0.5);"/><div data-role="paragraph" style="white-space: normal;margin-bottom: 0px;"><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p></div><div data-id="12351" data-tools="新媒体排版" data-style-type="1" style="margin: 0px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);text-align: start;"><div data-css="border-color: initial;border-style: none;border-width: 0px;padding: 0px" style="margin: 0px;padding: 0px;border-color: initial;border-style: none;border-width: 0px;"><div powered-by="KolEditor.us" style="margin: 0px;padding: 0px;"><div style="margin: 10px 0px;padding: 0px;"><p style="font-size: medium;margin: 0px;padding: 0px;display: inline-block;"><span style="margin: 0px;padding: 0.3em 0.5em;background-color: rgb(23, 148, 221);border-radius: 0.8em 0.8em 0px 0px;color: rgb(255, 255, 255);display: block;font-size: 14.08px;"><p style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-size: 18px;"><span leaf=""><span textstyle="" style="font-size: 15px;">推荐阅读</span></span></span></strong></p></span></p><div data-css="border-color: rgb(249, 110, 87);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;box-sizing: border-box;padding: 10px" style="margin: 0px;padding: 10px;border-color: rgb(23, 148, 221);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px;padding: 0px;"><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247520597&amp;idx=2&amp;sn=770e8cc62ae6c306013787851b80f66e&amp;scene=21#wechat_redirect" textvalue="Telegram 创始人 Pavel Durov 因缺乏内容审核被捕" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">Telegram 创始人 Pavel Durov 因缺乏内容审核被捕</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247520167&amp;idx=2&amp;sn=7d6a9321b744778cdce41dc0464f4c3d&amp;scene=21#wechat_redirect" textvalue="Telegram 0day可导致攻击者将恶意安卓APK以视频形式发送" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">Telegram 0day可导致攻击者将恶意安卓APK以视频形式发送</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247519289&amp;idx=2&amp;sn=4c3fb5e7519056c3adfbd18c7a6561d3&amp;scene=21#wechat_redirect" textvalue="Telegram 修复Windows 版中的0day漏洞" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">Telegram 修复Windows 版中的0day漏洞</span></a></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 15px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0em;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);font-size: medium;text-align: start;"><span style="margin: 0px;padding: 0px;font-size: 15px;color: rgb(136, 136, 136);text-decoration: underline;"><strong style="margin: 0px;padding: 0px;"><span leaf="">原文链接</span></strong></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;"><a href="https://www.darkreading.com/application-security/storm-brews-critical-no-click-telegram-flaw" target="_blank">https://www.darkreading.com/application-security/storm-brews-critical-no-click-telegram-flaw</a></span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">题图：Pixa</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">bay Licens</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">e</span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><strong style="text-indent: 0em;"><span style="font-size: 15px;color: rgb(136, 136, 136);"><span leaf="">本文由奇安信编译，不代表奇安信观点。转载请注明“转自奇安信代码卫士 <a href="https://codesafe.qianxin.com”。" target="_blank">https://codesafe.qianxin.com”。</a></span></span></strong></p><div data-role="paragraph" style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><div data-id="9499" data-tools="新媒体排版" data-style-type="4" style="color: rgb(0, 0, 0);font-size: 17px;margin: 0px;padding: 0px 0.5em;text-align: start;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px auto;padding: 0px;text-align: center;"><div style="margin: 0px auto;padding: 0px 0px 10px;max-width: 360px !important;"><p style="margin: 0px;padding: 0px 0px 0px 2px;font-size: 0px;width: 65px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.27380952380952384" data-type="jpeg" data-w="84" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;height: auto !important;" data-fileid="100025253" src="https://wechat2rss.xlab.app/img-proxy/?k=20efc9d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSf7nNLWrJL6dkJp7RB8Kl4zxU9ibnQjuvo4VoZ5ic9Q91K3WshWzqEybcroVEOQpgYfx1uYgwJhlFQ%2F640%3Fwx_fmt%3Djpeg"/></p><div data-css="align-items: flex-start;border-color: rgb(255, 138, 101);border-style: solid;border-width: 2px;display: flex;margin-top: -10px;padding: 30px 25px" style="margin: -10px 0px 0px;padding: 30px 25px;align-items: flex-start;border-color: rgb(23, 148, 221);border-style: solid;border-width: 2px;display: flex;"><div style="margin: 0px;padding: 0px;font-size: 0px;flex-shrink: 0;"><p style="margin: 0px;padding: 0px;width: 75px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-type="jpeg" data-w="1080" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;border-color: rgb(238, 238, 238);border-radius: 2px;border-style: solid;border-width: 1px;width: 75px;height: auto !important;" data-cropselx1="0" data-cropselx2="75" data-cropsely1="0" data-cropsely2="75" data-fileid="100025255" src="https://wechat2rss.xlab.app/img-proxy/?k=4657c87c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSN5sfviaCuvYQccJZlrr64sRlvcbdWjDic9mPQ8mBBFDCKP6VibiaNE1kDVuoIOiaIVRoTjSsSftGC8gw%2F640%3Fwx_fmt%3Djpeg"/></p></div><div style="margin: 0px;padding: 0px 0px 0px 15px;flex-shrink: 1;"><p data-css="color: #333;font-size: 18px;line-height:1.7;margin: 0px auto;text-align: left" style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 18px;line-height: 1.7;text-align: left;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;color: rgb(23, 148, 221);"><span leaf="">奇安信代码卫士 (codesafe)</span></span></strong></span></p><p style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 16px;text-align: left;line-height: 1.4;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><span leaf="">国内首个专注于软件开发安全的产品线。</span></span></p></div></div></div></div></div></div><p style="color: rgb(51, 51, 51);font-size: 17px;margin: 0px;padding: 0px 0.5em;clear: both;min-height: 1em;text-align: center;"><span leaf="">   <img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="0.8" data-type="gif" data-w="200" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: middle;color: rgb(0, 0, 0);font-size: 14px;box-sizing: border-box;width: 58.125px;visibility: visible !important;height: auto !important;" data-fileid="100025256" src="https://wechat2rss.xlab.app/img-proxy/?k=fbb024f2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FoBANLWYScMQ5iciaeKS21icDIWSVd0M9zEhicFK0rbCJOrgpc09iaH6nvqvsIdckDfxH2K4tu9CvPJgSf7XhGHJwVyQ%2F640%3Fwx_fmt%3Dgif"/></span><span style="margin: 0px;padding: 0px;font-size: 12px;"><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">觉得不错，就点个 “</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">在看</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 或 &#34;</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">赞</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 吧~</span></span></span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://codesafe.qianxin.com/#/home">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=bdcf1c7f&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2NTg4OTc5Nw%3D%3D%26mid%3D2247525587%26idx%3D1%26sn%3D402fc52dcbd813d3c5d2c26bf077fab0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 31 Mar 2026 18:05:00 +0800</pubDate>
    </item>
    <item>
      <title>Grafana 多个严重漏洞可用于实现 RCE</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525587&amp;idx=2&amp;sn=a18525fe72676659d744674b7d8fdd16</link>
      <description>速修复</description>
      <content:encoded><![CDATA[<p><span>Abinaya</span> <span>2026-03-31 18:05</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=f2add71f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ft5z0xV2OYfVv3jjGbtHy6brM0yZ63kib2TSIvR6wWa1ib95V3xMbakDtOjXR7wgfqoCnq1ZLnpTjdXlzjCQKc7bnaIzNHLb2VO3HjOc3PiawBo%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>速修复</p>
  <p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span leaf=""><img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="1" data-type="gif" data-w="400" style="margin-right: auto;margin-left: auto;vertical-align: middle;letter-spacing: 0.5px;text-indent: 0em;display: inline-block;box-sizing: border-box !important;visibility: visible !important;width: 30px !important;height: auto !important;" width="30" data-fileid="100025254" src="https://wechat2rss.xlab.app/img-proxy/?k=17396c1a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAz5ZsrEic9ot90z9etZLlU7OTaPOdibteeibJMMmbwc29aJlDOmUicibIRoLdcuEQjtHQ2qjVtZBt0M5eVbYoQzlHiaw%2F640%3Fwx_fmt%3Dgif"/>  </span><span style="text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-mpa-powered-by&#34;:&#34;yiban.io&#34;,&#34;style&#34;:&#34;margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">聚焦源代码安全，网罗国内外最新资讯！</span></span></p><p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;text-align: start;"><strong style="color: rgb(0, 0, 0);letter-spacing: 1px;font-size: 15px;"><span style="font-family: sofia-pro, sans-serif;letter-spacing: normal;text-transform: uppercase;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;transition: color 0.15s ease-out 0s, background-color 0.3s ease-out 0s, text-decoration-color 0.15s ease-out 0s;box-shadow: inset 0 -2px 0 var(--color-black);overflow: hidden;padding-bottom: 4px;color: rgb(136, 136, 136);"><span leaf="">编译：代码卫士</span></span></strong></p><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="paragraph"><div data-tools="135编辑器" data-id="166585"><div style="margin: 10px auto;"><div><div style="background-color: #ffffff;padding: 0px 10px;border-left: 3px solid #1a3566;border-right: 3px solid #1a3566;line-height: 1.1em;box-sizing:border-box;"><p data-autoskip="1" style="text-align: left;line-height: 1.75em;letter-spacing: 1.5px;font-size: 15px;color: #131f35;background-color: transparent;"><span style="font-size: 15px;color: #000000;"><strong><span leaf="">Grafana 12.4.2 </span></strong><strong><span leaf="">版本紧急修复了两个高危漏洞CVE-2026-27876和CVE-2026-27880，可分别导致攻击者实现远程代码执行（RCE）及发起拒绝服务（DoS）攻击。</span></strong></span></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">建议使用 Grafana 进行数据可视化的系统管理员立即应用这些反向移植的补丁，以防系统遭受攻击。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">其中CVE-2026-27876（CVSS评分9.1）更为严重，位于 Grafana 的 SQL 表达式功能中。该漏洞可导致攻击者直接向服务器的文件系统写入任意文件，可与其它攻击途径结合，实现完整的远程代码执行。Grafana Labs 确认，这一特定利用路径可被武器化，攻击者能够借此直接与底层主机服务器建立未经授权的 SSH 连接。要成功利用该漏洞，攻击者必须拥有 Viewer 或以上权限以执行数据源查询，且目标系统需已启用 sqlExpressions 功能开关。一旦满足这些严格的前置条件，攻击者便可以覆写 Sqlyze 驱动程序，或恶意篡改 AWS 数据源配置文件。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">该漏洞由 Miggo Security 的研究员 Liad Eliyahu 负责任地披露，凸显了持续进行严格外部安全审计的必要性。</span></span></p><div data-role="title" data-tools="135编辑器" data-id="166211"><div style="margin: 10px auto;display: flex;justify-content: center;"><div style="display: flex;align-items: center;"><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100041932" src="https://wechat2rss.xlab.app/img-proxy/?k=494cf1db&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Ft5z0xV2OYfXteSrOggUAfhKfGzZeIGTSJDMa4pkyoAslib6S7jbxwtlNAyBBicY1j9YEGM9q9daWzQIia8mqKUSVzgPwExIctflVoXk9biba8FA%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div><p style="font-size: 16px;color: #2e407b;text-align: center;padding: 0 6px;box-sizing:border-box;transform: rotateZ(0deg);-webkit-transform: rotateZ(0deg);-moz-transform: rotateZ(0deg);-o-transform: rotateZ(0deg);"><strong data-brushtype="text"><span leaf="">未授权 DoS 漏洞</span></strong></p></div><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100041931" src="https://wechat2rss.xlab.app/img-proxy/?k=caa03033&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Ft5z0xV2OYfWNwUXooVHD0Ywuzn2ArfSVBibErDu8Ziasn2yZJXj59UD35D7W8DMj4MT0WoFKz82T45ZKoHkTTibm4wdFWeOTwumZ1WYjs6AyEM%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">第二个漏洞CVE-2026-27880（CVSS评分7.5），是一个高危级别的拒绝服务（DoS）漏洞，影响 OpenFeature 校验端点。由于这些端点无需身份验证，且不加限制地将用户输入直接加载至内存，攻击者可借此轻易压垮系统。攻击者可发送超大请求，瞬间导致 Grafana 实例崩溃，造成监控服务严重停摆。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">Grafana Labs 强烈建议所有管理员立即升级至官方已修复版本：Grafana 12.4.2、12.3.6、12.2.8、12.1.10 及 11.6.14。依赖托管云服务的企业可放心使用，因为 Amazon Managed Grafana 和 Azure Managed Grafana 环境已在保密期内完成加固。这些快速发布的更新彰显了 Grafana 致力于为其企业版及开源版用户维护安全生态系统的承诺。对于无法立即升级的企业，完全关闭 sqlExpressions 功能开关可暂时消除 RCE 攻击面。在未打补丁的情况下，为主动防御 DoS 漏洞，管理员应将 Grafana 部署在高可用环境中，确保快速自动恢复。此外，部署 Nginx 或 Cloudflare 等可靠的反向代理，严格限制输入请求的负载大小，可有效阻断内存耗尽这一攻击路径。</span></span></p></div></div><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;" data-pm-slice="5 3 []"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span style="font-size: 15px;"><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf=""> 开源</span></span><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf="">卫士试用地址：</span><span leaf=""><a href="https://oss.qianxin.com/#/login" target="_blank">https://oss.qianxin.com/#/login</a></span></span></span></span></p><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span leaf=""> 代码卫士试用地址：<a href="https://sast.qianxin.com/#/login" target="_blank">https://sast.qianxin.com/#/login</a></span></span></p><hr style="white-space: normal;border-style: solid;border-right-width: 0px;border-bottom-width: 0px;border-left-width: 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px 0px;transform: scale(1, 0.5);"/><div data-role="paragraph" style="white-space: normal;margin-bottom: 0px;"><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p></div><div data-id="12351" data-tools="新媒体排版" data-style-type="1" style="margin: 0px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);text-align: start;"><div data-css="border-color: initial;border-style: none;border-width: 0px;padding: 0px" style="margin: 0px;padding: 0px;border-color: initial;border-style: none;border-width: 0px;"><div powered-by="KolEditor.us" style="margin: 0px;padding: 0px;"><div style="margin: 10px 0px;padding: 0px;"><p style="font-size: medium;margin: 0px;padding: 0px;display: inline-block;"><span style="margin: 0px;padding: 0.3em 0.5em;background-color: rgb(23, 148, 221);border-radius: 0.8em 0.8em 0px 0px;color: rgb(255, 255, 255);display: block;font-size: 14.08px;"><p style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-size: 18px;"><span leaf=""><span textstyle="" style="font-size: 15px;">推荐阅读</span></span></span></strong></p></span></p><div data-css="border-color: rgb(249, 110, 87);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;box-sizing: border-box;padding: 10px" style="margin: 0px;padding: 10px;border-color: rgb(23, 148, 221);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px;padding: 0px;"><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524487&amp;idx=2&amp;sn=e85da781a2fe55ed8b1a2296242adb26&amp;scene=21#wechat_redirect" textvalue="Grafana SCIM 中存在严重漏洞，可导致身份冒充或提权" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">Grafana SCIM 中存在严重漏洞，可导致身份冒充或提权</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523440&amp;idx=2&amp;sn=85a84a9138ea24b09e9ea0bcb9efe061&amp;scene=21#wechat_redirect" textvalue="速修复！Grafana 修复中存在四个严重的RCE漏洞" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">速修复！Grafana 修复中存在四个严重的RCE漏洞</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523297&amp;idx=2&amp;sn=ea60b085762fef54a56dea85a3150a40&amp;scene=21#wechat_redirect" textvalue="超4.6万个 Grafana 实例易受账户接管漏洞影响" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">超4.6万个 Grafana 实例易受账户接管漏洞影响</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523102&amp;idx=2&amp;sn=3eb6fe83ca06d69dbd0a16a7c73dcde3&amp;scene=21#wechat_redirect" textvalue="Grafana 紧急提前修复已被公开的XSS 0day漏洞" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">Grafana 紧急提前修复已被公开的XSS 0day漏洞</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247516818&amp;idx=4&amp;sn=9a52564b1d6d8454dd34dce86019d266&amp;scene=21#wechat_redirect" textvalue="Grafana 提醒注意严重的认证绕过漏洞" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">Grafana 提醒注意严重的认证绕过漏洞</span></a></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 15px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0em;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);font-size: medium;text-align: start;"><span style="margin: 0px;padding: 0px;font-size: 15px;color: rgb(136, 136, 136);text-decoration: underline;"><strong style="margin: 0px;padding: 0px;"><span leaf="">原文链接</span></strong></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;"><a href="https://cybersecuritynews.com/grafana-vulnerabilities-rce/" target="_blank">https://cybersecuritynews.com/grafana-vulnerabilities-rce/</a></span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">题图：Pixa</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">bay Licens</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">e</span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><strong style="text-indent: 0em;"><span style="font-size: 15px;color: rgb(136, 136, 136);"><span leaf="">本文由奇安信编译，不代表奇安信观点。转载请注明“转自奇安信代码卫士 <a href="https://codesafe.qianxin.com”。" target="_blank">https://codesafe.qianxin.com”。</a></span></span></strong></p><div data-role="paragraph" style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><div data-id="9499" data-tools="新媒体排版" data-style-type="4" style="color: rgb(0, 0, 0);font-size: 17px;margin: 0px;padding: 0px 0.5em;text-align: start;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px auto;padding: 0px;text-align: center;"><div style="margin: 0px auto;padding: 0px 0px 10px;max-width: 360px !important;"><p style="margin: 0px;padding: 0px 0px 0px 2px;font-size: 0px;width: 65px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.27380952380952384" data-type="jpeg" data-w="84" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;height: auto !important;" data-fileid="100025253" src="https://wechat2rss.xlab.app/img-proxy/?k=20efc9d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSf7nNLWrJL6dkJp7RB8Kl4zxU9ibnQjuvo4VoZ5ic9Q91K3WshWzqEybcroVEOQpgYfx1uYgwJhlFQ%2F640%3Fwx_fmt%3Djpeg"/></p><div data-css="align-items: flex-start;border-color: rgb(255, 138, 101);border-style: solid;border-width: 2px;display: flex;margin-top: -10px;padding: 30px 25px" style="margin: -10px 0px 0px;padding: 30px 25px;align-items: flex-start;border-color: rgb(23, 148, 221);border-style: solid;border-width: 2px;display: flex;"><div style="margin: 0px;padding: 0px;font-size: 0px;flex-shrink: 0;"><p style="margin: 0px;padding: 0px;width: 75px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-type="jpeg" data-w="1080" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;border-color: rgb(238, 238, 238);border-radius: 2px;border-style: solid;border-width: 1px;width: 75px;height: auto !important;" data-cropselx1="0" data-cropselx2="75" data-cropsely1="0" data-cropsely2="75" data-fileid="100025255" src="https://wechat2rss.xlab.app/img-proxy/?k=4657c87c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSN5sfviaCuvYQccJZlrr64sRlvcbdWjDic9mPQ8mBBFDCKP6VibiaNE1kDVuoIOiaIVRoTjSsSftGC8gw%2F640%3Fwx_fmt%3Djpeg"/></p></div><div style="margin: 0px;padding: 0px 0px 0px 15px;flex-shrink: 1;"><p data-css="color: #333;font-size: 18px;line-height:1.7;margin: 0px auto;text-align: left" style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 18px;line-height: 1.7;text-align: left;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;color: rgb(23, 148, 221);"><span leaf="">奇安信代码卫士 (codesafe)</span></span></strong></span></p><p style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 16px;text-align: left;line-height: 1.4;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><span leaf="">国内首个专注于软件开发安全的产品线。</span></span></p></div></div></div></div></div></div><p style="color: rgb(51, 51, 51);font-size: 17px;margin: 0px;padding: 0px 0.5em;clear: both;min-height: 1em;text-align: center;"><span leaf="">   <img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="0.8" data-type="gif" data-w="200" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: middle;color: rgb(0, 0, 0);font-size: 14px;box-sizing: border-box;width: 58.125px;visibility: visible !important;height: auto !important;" data-fileid="100025256" src="https://wechat2rss.xlab.app/img-proxy/?k=fbb024f2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FoBANLWYScMQ5iciaeKS21icDIWSVd0M9zEhicFK0rbCJOrgpc09iaH6nvqvsIdckDfxH2K4tu9CvPJgSf7XhGHJwVyQ%2F640%3Fwx_fmt%3Dgif"/></span><span style="margin: 0px;padding: 0px;font-size: 12px;"><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">觉得不错，就点个 “</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">在看</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 或 &#34;</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">赞</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 吧~</span></span></span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://codesafe.qianxin.com/#/home">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=8cc95df1&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2NTg4OTc5Nw%3D%3D%26mid%3D2247525587%26idx%3D2%26sn%3Da18525fe72676659d744674b7d8fdd16">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 31 Mar 2026 18:05:00 +0800</pubDate>
    </item>
    <item>
      <title>CISA要求三天内修复这个严重的 F5 BIG-IP 漏洞</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525571&amp;idx=1&amp;sn=3596dc720ddc3cfdb3245a4b7597f249</link>
      <description>速修复</description>
      <content:encoded><![CDATA[<p><span>Ddos</span> <span>2026-03-30 18:12</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=7e2d864c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ft5z0xV2OYfWeeQym7JrDehnv08capFTldgyk9YNDDJgkU53Rl6uovV12SianDjNoicWvxw9JY8J1bWIbXLDtuIlqddXqqoYCeYZCP1nsXnOtk%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>速修复</p>
  <p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span leaf=""><img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="1" data-type="gif" data-w="400" style="margin-right: auto;margin-left: auto;vertical-align: middle;letter-spacing: 0.5px;text-indent: 0em;display: inline-block;box-sizing: border-box !important;visibility: visible !important;width: 30px !important;height: auto !important;" width="30" data-fileid="100025254" src="https://wechat2rss.xlab.app/img-proxy/?k=17396c1a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAz5ZsrEic9ot90z9etZLlU7OTaPOdibteeibJMMmbwc29aJlDOmUicibIRoLdcuEQjtHQ2qjVtZBt0M5eVbYoQzlHiaw%2F640%3Fwx_fmt%3Dgif"/>  </span><span style="text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-mpa-powered-by&#34;:&#34;yiban.io&#34;,&#34;style&#34;:&#34;margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">聚焦源代码安全，网罗国内外最新资讯！</span></span></p><p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;text-align: start;"><strong style="color: rgb(0, 0, 0);letter-spacing: 1px;font-size: 15px;"><span style="font-family: sofia-pro, sans-serif;letter-spacing: normal;text-transform: uppercase;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;transition: color 0.15s ease-out 0s, background-color 0.3s ease-out 0s, text-decoration-color 0.15s ease-out 0s;box-shadow: inset 0 -2px 0 var(--color-black);overflow: hidden;padding-bottom: 4px;color: rgb(136, 136, 136);"><span leaf="">编译：代码卫士</span></span></strong></p><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-tools="135编辑器" data-id="166585"><div style="margin: 10px auto;"><div><div style="background-color: #ffffff;padding: 0px 10px;border-left: 3px solid #1a3566;border-right: 3px solid #1a3566;line-height: 1.1em;box-sizing:border-box;"><p data-autoskip="1" style="text-align: left;line-height: 1.75em;letter-spacing: 1.5px;font-size: 15px;color: rgb(19, 31, 53);background-color: transparent;"><span style="font-size: 15px;color: rgb(0, 0, 0);"><strong><span leaf="">美国网络安全和基础设施局 (CISA) 正式将影响 F5 BIG-IP 系统的严重远程代码执行漏洞CVE-2025-53521（CVSS评分9.8）纳入“已知遭利用漏洞 (KEV)”分类表。</span></strong></span></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">该漏洞位于 BIG-IP 访问策略管理器 (APM) 中。当为虚拟服务器配置 BIG-IP APM 访问策略时，就易接收到构造的恶意流量。如该漏洞遭成功利用，则可导致攻击者绕过安全边界并实现远程代码执行后果。如遭网络犯罪分子或受国家支持的黑客组织，则可导致他们：</span></span></p><p data-role="list"><ul style="list-style-type: disc;margin:0px;padding:0 0 0 30px;list-style-position:outside;" class="list-paddingleft-2"><li><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">拦截加密流量：获得通过网关传递的敏感数据的访问权限。</span></span></p></li><li><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">横向移动：将 BIG-IP 设备作为攻击内部服务器的一个跳转点。</span></span></p></li><li><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">持久性访问：安装后门，重启后仍然存在。</span></span></p></li></ul></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">F5 BIG-IP 是政府和企业数据中心的主干，因此使这些数据中心“成为恶意网络人员的常见攻击向量”。由于这些设备位于网络边缘，因此如遭利用可导致防火墙和内部安全措施遭绕过。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">CISA 提醒称，该漏洞“为联邦企业带来重大风险”，因此需立即修复。根据BOD 22-01的要求，美国联邦民用行政机构 (FCEB) 机构必须在当地时间2026年3月30日之前修复。虽然该要求仅适用于联邦机构，但CISA督促所有私有组织机构优先修复该漏洞，保护自身网络安全。</span></span></p></div><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;" data-pm-slice="5 3 []"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span style="font-size: 15px;"><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf=""> 开源</span></span><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf="">卫士试用地址：</span><span leaf=""><a href="https://oss.qianxin.com/#/login" target="_blank">https://oss.qianxin.com/#/login</a></span></span></span></span></p><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span leaf=""> 代码卫士试用地址：<a href="https://sast.qianxin.com/#/login" target="_blank">https://sast.qianxin.com/#/login</a></span></span></p><hr style="white-space: normal;border-style: solid;border-right-width: 0px;border-bottom-width: 0px;border-left-width: 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px 0px;transform: scale(1, 0.5);"/><div data-role="paragraph" style="white-space: normal;margin-bottom: 0px;"><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p></div><div data-id="12351" data-tools="新媒体排版" data-style-type="1" style="margin: 0px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);text-align: start;"><div data-css="border-color: initial;border-style: none;border-width: 0px;padding: 0px" style="margin: 0px;padding: 0px;border-color: initial;border-style: none;border-width: 0px;"><div powered-by="KolEditor.us" style="margin: 0px;padding: 0px;"><div style="margin: 10px 0px;padding: 0px;"><p style="font-size: medium;margin: 0px;padding: 0px;display: inline-block;"><span style="margin: 0px;padding: 0.3em 0.5em;background-color: rgb(23, 148, 221);border-radius: 0.8em 0.8em 0px 0px;color: rgb(255, 255, 255);display: block;font-size: 14.08px;"><p style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-size: 18px;"><span leaf=""><span textstyle="" style="font-size: 15px;">推荐阅读</span></span></span></strong></p></span></p><div data-css="border-color: rgb(249, 110, 87);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;box-sizing: border-box;padding: 10px" style="margin: 0px;padding: 10px;border-color: rgb(23, 148, 221);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px;padding: 0px;"><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525482&amp;idx=2&amp;sn=92844a4f59d7d7b8344f344ed41a3600&amp;scene=21#wechat_redirect" textvalue="CISA：Wing FTP 已遭利用漏洞可泄露服务器路径" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">CISA：Wing FTP 已遭利用漏洞可泄露服务器路径</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524194&amp;idx=1&amp;sn=ab0b13f163b9168171ef5effd17379be&amp;scene=21#wechat_redirect" textvalue="F5 BIG-IP 源代码和 0day 漏洞数据遭泄露，补丁已发布" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">F5 BIG-IP 源代码和 0day 漏洞数据遭泄露，补丁已发布</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247521056&amp;idx=1&amp;sn=87bda00602d2d1a2718a0d4d0aef6585&amp;scene=21#wechat_redirect" textvalue="CISA：黑客滥用F5 BIG-IP cookie 映射内部服务器" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">CISA：黑客滥用F5 BIG-IP cookie 映射内部服务器</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247518011&amp;idx=2&amp;sn=bc312f0c5810515223f4c329eb996ee3&amp;scene=21#wechat_redirect" textvalue="F5修复可导致RCE的 BIG-IP 认证绕过漏洞" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">F5修复可导致RCE的 BIG-IP 认证绕过漏洞</span></a></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 15px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0em;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);font-size: medium;text-align: start;"><span style="margin: 0px;padding: 0px;font-size: 15px;color: rgb(136, 136, 136);text-decoration: underline;"><strong style="margin: 0px;padding: 0px;"><span leaf="">原文链接</span></strong></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;"><a href="https://securityonline.info/f5-big-ip-rce-vulnerability-cve-2025-53521-cisa-kev/" target="_blank">https://securityonline.info/f5-big-ip-rce-vulnerability-cve-2025-53521-cisa-kev/</a></span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">题图：Pixa</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">bay Licens</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">e</span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><strong style="text-indent: 0em;"><span style="font-size: 15px;color: rgb(136, 136, 136);"><span leaf="">本文由奇安信编译，不代表奇安信观点。转载请注明“转自奇安信代码卫士 <a href="https://codesafe.qianxin.com”。" target="_blank">https://codesafe.qianxin.com”。</a></span></span></strong></p><div data-role="paragraph" style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><div data-id="9499" data-tools="新媒体排版" data-style-type="4" style="color: rgb(0, 0, 0);font-size: 17px;margin: 0px;padding: 0px 0.5em;text-align: start;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px auto;padding: 0px;text-align: center;"><div style="margin: 0px auto;padding: 0px 0px 10px;max-width: 360px !important;"><p style="margin: 0px;padding: 0px 0px 0px 2px;font-size: 0px;width: 65px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.27380952380952384" data-type="jpeg" data-w="84" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;height: auto !important;" data-fileid="100025253" src="https://wechat2rss.xlab.app/img-proxy/?k=20efc9d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSf7nNLWrJL6dkJp7RB8Kl4zxU9ibnQjuvo4VoZ5ic9Q91K3WshWzqEybcroVEOQpgYfx1uYgwJhlFQ%2F640%3Fwx_fmt%3Djpeg"/></p><div data-css="align-items: flex-start;border-color: rgb(255, 138, 101);border-style: solid;border-width: 2px;display: flex;margin-top: -10px;padding: 30px 25px" style="margin: -10px 0px 0px;padding: 30px 25px;align-items: flex-start;border-color: rgb(23, 148, 221);border-style: solid;border-width: 2px;display: flex;"><div style="margin: 0px;padding: 0px;font-size: 0px;flex-shrink: 0;"><p style="margin: 0px;padding: 0px;width: 75px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-type="jpeg" data-w="1080" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;border-color: rgb(238, 238, 238);border-radius: 2px;border-style: solid;border-width: 1px;width: 75px;height: auto !important;" data-cropselx1="0" data-cropselx2="75" data-cropsely1="0" data-cropsely2="75" data-fileid="100025255" src="https://wechat2rss.xlab.app/img-proxy/?k=4657c87c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSN5sfviaCuvYQccJZlrr64sRlvcbdWjDic9mPQ8mBBFDCKP6VibiaNE1kDVuoIOiaIVRoTjSsSftGC8gw%2F640%3Fwx_fmt%3Djpeg"/></p></div><div style="margin: 0px;padding: 0px 0px 0px 15px;flex-shrink: 1;"><p data-css="color: #333;font-size: 18px;line-height:1.7;margin: 0px auto;text-align: left" style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 18px;line-height: 1.7;text-align: left;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;color: rgb(23, 148, 221);"><span leaf="">奇安信代码卫士 (codesafe)</span></span></strong></span></p><p style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 16px;text-align: left;line-height: 1.4;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><span leaf="">国内首个专注于软件开发安全的产品线。</span></span></p></div></div></div></div></div></div><p style="color: rgb(51, 51, 51);font-size: 17px;margin: 0px;padding: 0px 0.5em;clear: both;min-height: 1em;text-align: center;"><span leaf="">   <img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="0.8" data-type="gif" data-w="200" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: middle;color: rgb(0, 0, 0);font-size: 14px;box-sizing: border-box;width: 58.125px;visibility: visible !important;height: auto !important;" data-fileid="100025256" src="https://wechat2rss.xlab.app/img-proxy/?k=fbb024f2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FoBANLWYScMQ5iciaeKS21icDIWSVd0M9zEhicFK0rbCJOrgpc09iaH6nvqvsIdckDfxH2K4tu9CvPJgSf7XhGHJwVyQ%2F640%3Fwx_fmt%3Dgif"/></span><span style="margin: 0px;padding: 0px;font-size: 12px;"><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">觉得不错，就点个 “</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">在看</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 或 &#34;</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">赞</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 吧~</span></span></span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://codesafe.qianxin.com/#/home">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=7842351b&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2NTg4OTc5Nw%3D%3D%26mid%3D2247525571%26idx%3D1%26sn%3D3596dc720ddc3cfdb3245a4b7597f249">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 30 Mar 2026 18:12:00 +0800</pubDate>
    </item>
    <item>
      <title>n8n 两个严重 RCE 漏洞利用使工作流沦为后门</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525571&amp;idx=2&amp;sn=eae427dd1fadd452e77ca0ed22f49ddf</link>
      <description>速修复</description>
      <content:encoded><![CDATA[<p><span>Ddos</span> <span>2026-03-30 18:12</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=b9e9d27c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Ft5z0xV2OYfXiafnaSRV9mXCfehJCABl0MRPw4tNTXMEibia0OIDBoF3Yia6WzpOBicRwfDww6yZSOicN1VC7fMPpoxkFU4GIibQnkJxtibgS5UpBlVA%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>速修复</p>
  <p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span leaf=""><img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="1" data-type="gif" data-w="400" style="margin-right: auto;margin-left: auto;vertical-align: middle;letter-spacing: 0.5px;text-indent: 0em;display: inline-block;box-sizing: border-box !important;visibility: visible !important;width: 30px !important;height: auto !important;" width="30" data-fileid="100025254" src="https://wechat2rss.xlab.app/img-proxy/?k=17396c1a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAz5ZsrEic9ot90z9etZLlU7OTaPOdibteeibJMMmbwc29aJlDOmUicibIRoLdcuEQjtHQ2qjVtZBt0M5eVbYoQzlHiaw%2F640%3Fwx_fmt%3Dgif"/>  </span><span style="text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-mpa-powered-by&#34;:&#34;yiban.io&#34;,&#34;style&#34;:&#34;margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">聚焦源代码安全，网罗国内外最新资讯！</span></span></p><p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;text-align: start;"><strong style="color: rgb(0, 0, 0);letter-spacing: 1px;font-size: 15px;"><span style="font-family: sofia-pro, sans-serif;letter-spacing: normal;text-transform: uppercase;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;transition: color 0.15s ease-out 0s, background-color 0.3s ease-out 0s, text-decoration-color 0.15s ease-out 0s;box-shadow: inset 0 -2px 0 var(--color-black);overflow: hidden;padding-bottom: 4px;color: rgb(136, 136, 136);"><span leaf="">编译：代码卫士</span></span></strong></p><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="paragraph"><div data-tools="135编辑器" data-id="166585"><div style="margin: 10px auto;"><div><div style="background-color: #ffffff;padding: 0px 10px;border-left: 3px solid #1a3566;border-right: 3px solid #1a3566;line-height: 1.1em;box-sizing:border-box;"><p data-autoskip="1" style="text-align: left;line-height: 1.75em;letter-spacing: 1.5px;font-size: 15px;color: #131f35;background-color: transparent;"><span style="font-size: 15px;color: #000000;"><strong><span leaf="">安全研究人员披露了 n8n 中的两个严重漏洞CVE-2026-33660和CVE-2026-33663（CVSS评分均为9.4）。n8n 是一款免费开源的工作流自动化工具，用于弥合低代码速度与全代码灵活性之间的差距。这两个漏洞可带来严重的远程代码执行风险，导致攻击者入侵底层主机服务器。</span></strong></span></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">这些漏洞凸显了依赖 n8n 处理敏感数据和关键任务自动化的组织所面临的重大风险。第一个严重漏洞CVE-2026-33660，涉及 Merge 节点。Merge 节点是用于合并来自不同数据源的数据的核心组件。当设置为“按 SQL 合并”模式时，该节点会使用 AlaSQL 库。研究人员发现，AlaSQL 沙箱未能充分限制某些 SQL 语句。拥有创建工作流权限且通过身份验证的用户可以利用此漏洞直接从 n8n 主机服务器读取本地文件，或实现完整的远程代码执行，或导致实例完全被接管。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">第二个漏洞是位于 GSuiteAdmin 节点参数中常见但影响巨大的原型污染漏洞CVE-2026-33663。通过在节点配置期间提供特殊构造的参数，攻击者可以将未经授权的值写入 Object.prototype。在像 n8n 这样的 Node.js 环境中，操纵全局对象原型可直接导致攻击者：</span></span></p><p data-role="list"><ul style="list-style-type: disc;margin:0px;padding:0 0 0 30px;list-style-position:outside;" class="list-paddingleft-2"><li><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">在服务器上执行任意代码。</span></span></p></li><li><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">通过将攻击者控制的属性注入应用程序逻辑来绕过安全控制。</span></span></p></li></ul></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">n8n 开发团队已为多个发布分支发布了这两个漏洞的补丁。建议管理员立即将其实例更新至以下版本之一：</span></span></p><p data-role="list"><ul style="list-style-type: disc;margin:0px;padding:0 0 0 30px;list-style-position:outside;" class="list-paddingleft-2"><li><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">2.14.1</span></span></p></li><li><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">2.13.3</span></span></p></li><li><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">1.123.27</span></span></p></li></ul></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">如果无法立即升级，以下短期措施可以降低但无法完全消除该风险：</span></span></p><p data-role="list"><ul style="list-style-type: disc;margin:0px;padding:0 0 0 30px;list-style-position:outside;" class="list-paddingleft-1"><li><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">限制权限：将工作流的创建和编辑权限严格限制在完全受信任的用户范围内。</span></span></p></li><li><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">禁用易受攻击的节点：使用 NODES_EXCLUDE 环境变量禁用受影响的节点，可通过如下措施实现：</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span style="font-size: 15px;letter-spacing: 1px;font-family:Wingdings;"><span leaf="">Ø</span></span><span leaf="">添加 n8n-nodes-base.merge 以阻止 SQL 漏洞利用。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span style="font-size: 15px;letter-spacing: 1px;font-family:Wingdings;"><span leaf="">Ø</span></span><span leaf="">添加 n8n-nodes-base.xml 作为相关风险的缓解措施。</span></span></p></li></ul></p></div></div><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;" data-pm-slice="5 3 []"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span style="font-size: 15px;"><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf=""> 开源</span></span><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf="">卫士试用地址：</span><span leaf=""><a href="https://oss.qianxin.com/#/login" target="_blank">https://oss.qianxin.com/#/login</a></span></span></span></span></p><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span leaf=""> 代码卫士试用地址：<a href="https://sast.qianxin.com/#/login" target="_blank">https://sast.qianxin.com/#/login</a></span></span></p><hr style="white-space: normal;border-style: solid;border-right-width: 0px;border-bottom-width: 0px;border-left-width: 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px 0px;transform: scale(1, 0.5);"/><div data-role="paragraph" style="white-space: normal;margin-bottom: 0px;"><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p></div><div data-id="12351" data-tools="新媒体排版" data-style-type="1" style="margin: 0px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);text-align: start;"><div data-css="border-color: initial;border-style: none;border-width: 0px;padding: 0px" style="margin: 0px;padding: 0px;border-color: initial;border-style: none;border-width: 0px;"><div powered-by="KolEditor.us" style="margin: 0px;padding: 0px;"><div style="margin: 10px 0px;padding: 0px;"><p style="font-size: medium;margin: 0px;padding: 0px;display: inline-block;"><span style="margin: 0px;padding: 0.3em 0.5em;background-color: rgb(23, 148, 221);border-radius: 0.8em 0.8em 0px 0px;color: rgb(255, 255, 255);display: block;font-size: 14.08px;"><p style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-size: 18px;"><span leaf=""><span textstyle="" style="font-size: 15px;">推荐阅读</span></span></span></strong></p></span></p><div data-css="border-color: rgb(249, 110, 87);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;box-sizing: border-box;padding: 10px" style="margin: 0px;padding: 10px;border-color: rgb(23, 148, 221);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px;padding: 0px;"><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525403&amp;idx=2&amp;sn=8252f2b425ef4c9eeee6dfaff6a20253&amp;scene=21#wechat_redirect" textvalue="n8n 严重漏洞可导致RCE和存储凭据暴露" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">n8n 严重漏洞可导致RCE和存储凭据暴露</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525056&amp;idx=1&amp;sn=15cdf06676ec490a668ee9af2a579306&amp;scene=21#wechat_redirect" textvalue="n8n出现新漏洞，可用于执行系统命令" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">n8n出现新漏洞，可用于执行系统命令</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524999&amp;idx=1&amp;sn=29baedb21e9e4bef4466b10bc66abcde&amp;scene=21#wechat_redirect" textvalue="n8n 两个高危漏洞可导致认证RCE" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">n8n 两个高危漏洞可导致认证RCE</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524822&amp;idx=1&amp;sn=e3ab93e00fc28bdb1a256d94e84507f3&amp;scene=21#wechat_redirect" textvalue="n8n 满分漏洞 Ni8mare 可导致服务器遭劫持" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">n8n 满分漏洞 Ni8mare 可导致服务器遭劫持</span></a></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 15px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0em;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);font-size: medium;text-align: start;"><span style="margin: 0px;padding: 0px;font-size: 15px;color: rgb(136, 136, 136);text-decoration: underline;"><strong style="margin: 0px;padding: 0px;"><span leaf="">原文链接</span></strong></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;"><a href="https://securityonline.info/n8n-critical-rce-vulnerabilities-merge-gsuiteadmin-nodes/" target="_blank">https://securityonline.info/n8n-critical-rce-vulnerabilities-merge-gsuiteadmin-nodes/</a></span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">题图：Pixa</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">bay Licens</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">e</span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><strong style="text-indent: 0em;"><span style="font-size: 15px;color: rgb(136, 136, 136);"><span leaf="">本文由奇安信编译，不代表奇安信观点。转载请注明“转自奇安信代码卫士 <a href="https://codesafe.qianxin.com”。" target="_blank">https://codesafe.qianxin.com”。</a></span></span></strong></p><div data-role="paragraph" style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><div data-id="9499" data-tools="新媒体排版" data-style-type="4" style="color: rgb(0, 0, 0);font-size: 17px;margin: 0px;padding: 0px 0.5em;text-align: start;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px auto;padding: 0px;text-align: center;"><div style="margin: 0px auto;padding: 0px 0px 10px;max-width: 360px !important;"><p style="margin: 0px;padding: 0px 0px 0px 2px;font-size: 0px;width: 65px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.27380952380952384" data-type="jpeg" data-w="84" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;height: auto !important;" data-fileid="100025253" src="https://wechat2rss.xlab.app/img-proxy/?k=20efc9d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSf7nNLWrJL6dkJp7RB8Kl4zxU9ibnQjuvo4VoZ5ic9Q91K3WshWzqEybcroVEOQpgYfx1uYgwJhlFQ%2F640%3Fwx_fmt%3Djpeg"/></p><div data-css="align-items: flex-start;border-color: rgb(255, 138, 101);border-style: solid;border-width: 2px;display: flex;margin-top: -10px;padding: 30px 25px" style="margin: -10px 0px 0px;padding: 30px 25px;align-items: flex-start;border-color: rgb(23, 148, 221);border-style: solid;border-width: 2px;display: flex;"><div style="margin: 0px;padding: 0px;font-size: 0px;flex-shrink: 0;"><p style="margin: 0px;padding: 0px;width: 75px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-type="jpeg" data-w="1080" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;border-color: rgb(238, 238, 238);border-radius: 2px;border-style: solid;border-width: 1px;width: 75px;height: auto !important;" data-cropselx1="0" data-cropselx2="75" data-cropsely1="0" data-cropsely2="75" data-fileid="100025255" src="https://wechat2rss.xlab.app/img-proxy/?k=4657c87c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSN5sfviaCuvYQccJZlrr64sRlvcbdWjDic9mPQ8mBBFDCKP6VibiaNE1kDVuoIOiaIVRoTjSsSftGC8gw%2F640%3Fwx_fmt%3Djpeg"/></p></div><div style="margin: 0px;padding: 0px 0px 0px 15px;flex-shrink: 1;"><p data-css="color: #333;font-size: 18px;line-height:1.7;margin: 0px auto;text-align: left" style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 18px;line-height: 1.7;text-align: left;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;color: rgb(23, 148, 221);"><span leaf="">奇安信代码卫士 (codesafe)</span></span></strong></span></p><p style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 16px;text-align: left;line-height: 1.4;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><span leaf="">国内首个专注于软件开发安全的产品线。</span></span></p></div></div></div></div></div></div><p style="color: rgb(51, 51, 51);font-size: 17px;margin: 0px;padding: 0px 0.5em;clear: both;min-height: 1em;text-align: center;"><span leaf="">   <img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="0.8" data-type="gif" data-w="200" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: middle;color: rgb(0, 0, 0);font-size: 14px;box-sizing: border-box;width: 58.125px;visibility: visible !important;height: auto !important;" data-fileid="100025256" src="https://wechat2rss.xlab.app/img-proxy/?k=fbb024f2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FoBANLWYScMQ5iciaeKS21icDIWSVd0M9zEhicFK0rbCJOrgpc09iaH6nvqvsIdckDfxH2K4tu9CvPJgSf7XhGHJwVyQ%2F640%3Fwx_fmt%3Dgif"/></span><span style="margin: 0px;padding: 0px;font-size: 12px;"><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">觉得不错，就点个 “</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">在看</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 或 &#34;</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">赞</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 吧~</span></span></span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://codesafe.qianxin.com/#/home">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=1715a153&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2NTg4OTc5Nw%3D%3D%26mid%3D2247525571%26idx%3D2%26sn%3Deae427dd1fadd452e77ca0ed22f49ddf">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 30 Mar 2026 18:12:00 +0800</pubDate>
    </item>
    <item>
      <title>OpenAI 发布AI安全漏洞奖励计划</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247525564&amp;idx=1&amp;sn=87a38b04609d00236ed5984ced8a6243</link>
      <description>是对已有漏洞奖励计划的补充</description>
      <content:encoded><![CDATA[<p><span>Guru Baran</span> <span>2026-03-27 17:51</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=cc184dc6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft5z0xV2OYfVRyPHztdXliaMKFgAxKiahw1YaJsdeWV6O1w6HjreGlb2R3kwicNSXyYwTCtRaicelnAgczrHtUMKGQFpQ6zlRicwqCghfuBcUY2Qg%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>是对已有漏洞奖励计划的补充</p>
  <p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span leaf=""><img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="1" data-type="gif" data-w="400" style="margin-right: auto;margin-left: auto;vertical-align: middle;letter-spacing: 0.5px;text-indent: 0em;display: inline-block;box-sizing: border-box !important;visibility: visible !important;width: 30px !important;height: auto !important;" width="30" data-fileid="100025254" src="https://wechat2rss.xlab.app/img-proxy/?k=17396c1a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAz5ZsrEic9ot90z9etZLlU7OTaPOdibteeibJMMmbwc29aJlDOmUicibIRoLdcuEQjtHQ2qjVtZBt0M5eVbYoQzlHiaw%2F640%3Fwx_fmt%3Dgif"/>  </span><span style="text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-mpa-powered-by&#34;:&#34;yiban.io&#34;,&#34;style&#34;:&#34;margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 0em;font-size: 12px;color: rgb(0, 128, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">聚焦源代码安全，网罗国内外最新资讯！</span></span></p><p data-mpa-powered-by="yiban.io" style="margin-right: 8px;margin-bottom: 10px;margin-left: 8px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;text-align: start;"><strong style="color: rgb(0, 0, 0);letter-spacing: 1px;font-size: 15px;"><span style="font-family: sofia-pro, sans-serif;letter-spacing: normal;text-transform: uppercase;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;transition: color 0.15s ease-out 0s, background-color 0.3s ease-out 0s, text-decoration-color 0.15s ease-out 0s;box-shadow: inset 0 -2px 0 var(--color-black);overflow: hidden;padding-bottom: 4px;color: rgb(136, 136, 136);"><span leaf="">编译：代码卫士</span></span></strong></p><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="paragraph"><div data-tools="135编辑器" data-id="166585"><div style="margin: 10px auto;"><div><div style="background-color: #ffffff;padding: 0px 10px;border-left: 3px solid #1a3566;border-right: 3px solid #1a3566;line-height: 1.1em;box-sizing:border-box;"><p data-autoskip="1" style="text-align: left;line-height: 1.75em;letter-spacing: 1.5px;font-size: 15px;color: #131f35;background-color: transparent;"><span style="font-size: 15px;color: #000000;"><strong><span leaf="">OpenAI </span></strong><strong><span leaf="">公司发布公开的安全漏洞奖励计划，旨在识别产品中的AI滥用和安全风险问题。</span></strong></span></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">该AI漏洞奖励计划在 Bugcrowd 平台上实施，标志着 OpenAI 开始修复传统安全漏洞范围以外但仍然可能造成实际影响的漏洞。该漏洞奖励计划旨在补充 OpenAI 公司现有的安全漏洞奖励计划，任何存在重大滥用和安全风险的问题甚至是这些问题并非传统安全漏洞的漏洞报告均可提交。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">OpenAI 公司将与安全漏洞奖励团队共同对这些漏洞进行初审，并根据漏洞的范围和归属，在两个项目之间进行重新分配。</span></span></p><div data-role="title" data-tools="135编辑器" data-id="166211"><div style="margin: 10px auto;display: flex;justify-content: center;"><div style="display: flex;align-items: center;"><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100041909" src="https://wechat2rss.xlab.app/img-proxy/?k=e7d47ec1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Ft5z0xV2OYfUNibumgaPgaX8dS0CTETfKaUic3PN300tct0wSH6cpC2eRUvWicBIXGNWq8t8SDn8aXh5ecZpfia6ml8A4zJsRGLbjJfNZg02keH4%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div><p style="font-size: 16px;color: #2e407b;text-align: center;padding: 0 6px;box-sizing:border-box;transform: rotateZ(0deg);-webkit-transform: rotateZ(0deg);-moz-transform: rotateZ(0deg);-o-transform: rotateZ(0deg);"><strong data-brushtype="text"><span leaf="">相关的AI风险类别</span></strong></p></div><div style="flex-shrink: 0;"><p style="width: 18px;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9817850637522769" data-type="gif" data-w="549" style="width: 100%;display: block;vertical-align:baseline;box-sizing:border-box;max-width:100% !important;" data-width="100%" data-imgfileid="100041908" src="https://wechat2rss.xlab.app/img-proxy/?k=6376e1b5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Ft5z0xV2OYfUyy4MyGB2GVpWck4oqibDIkuQFEicIHCj1E6icicN5m5unV5MuH1BWFQTT8RhJJ2jLvVdk3BgLDySW8WNdIjFibicjmJkpL2icdmUMFE%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">该计划针对几种不同类别的AI特定安全场景：</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><strong><span leaf="">包括MCP的代理风险</span></strong><span leaf="">——涵盖第三方提示注入和数据外泄场景，即攻击者控制的文本能够可靠地劫持受害者的AI代理（包括Browser、ChatGPT 智能体及类似的代理型产品），从而执行有害操作或泄露敏感用户数据。如属于该场景，利用行为必须至少有50%的概率可重现。涉及代理型产品大规模执行被禁止或潜在有害行为的报告也在范围内。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><strong><span leaf="">OpenAI</span></strong><strong><span leaf="">专有信息</span></strong><span leaf="">——研究人员可报告模型生成内容中无意暴露的推理相关专有信息，以及泄露OpenAI其它保密数据的漏洞。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><strong><span leaf="">账户与平台完整性</span></strong><span leaf="">——此类别针对账户和平台完整性信号中的弱点，包括绕过反自动化控制、操纵账户信任信号、以及规避账户限制、暂停或封禁等。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">OpenAI已明确说明仅导致粗鲁语言或公开已知信息的通用越狱、无明确安全或滥用影响的一般性内容策略绕过将不在奖励范围内。不过，OpenAI会定期开展针对特定危害类型的私有漏洞赏金活动，例如ChatGPT 智能体和GPT-5中的生物风险内容问题，并会在这些项目启动时邀请研究人员申请参与。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">对于能够实现超出允许权限范围对功能、数据或功能进行未授权访问的漏洞，研究人员应转向现有的安全漏洞赏金计划进行提交。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">本次推出的AI漏洞奖励计划表明，人们越来越认识到AI系统引入了一个全新的攻击面，这是传统安全框架未曾设计去应对的。OpenAI 公司在对传统漏洞披露进行激励的同时，也对关注安全性的研究给予奖励，从而有效地为针对AI的威胁建模建立一个结构化的框架。</span></span></p><p style="text-align:left;margin-bottom: 15px;display: block;margin-left: 5px;margin-right: 5px;text-indent: 0em;"><span style="font-size: 15px;letter-spacing: 1px;"><span leaf="">有兴趣参与的研究人员可以直接通过OpenAI在Bugcrowd平台上的安全漏洞赏金页面进行申请。</span></span></p></div></div><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;" data-pm-slice="5 3 []"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span style="font-size: 15px;"><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf=""> 开源</span></span><span style="color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;letter-spacing: 1px;text-align: start;font-size: medium;"><span leaf="">卫士试用地址：</span><span leaf=""><a href="https://oss.qianxin.com/#/login" target="_blank">https://oss.qianxin.com/#/login</a></span></span><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span style="font-size: 15px;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 15px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><br/></span></span></span></span></span></p><p style="margin-bottom: 10px;padding-right: 0.5em;padding-left: 0.5em;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;letter-spacing: 1px;"><span style="text-indent: 0em;color: rgb(0, 122, 170);font-family: Helvetica, Arial, sans-serif;"><span leaf=""> 代码卫士试用地址：<a href="https://sast.qianxin.com/#/login" target="_blank">https://sast.qianxin.com/#/login</a></span></span></p><hr style="white-space: normal;border-style: solid;border-right-width: 0px;border-bottom-width: 0px;border-left-width: 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px 0px;transform: scale(1, 0.5);"/><div data-role="paragraph" style="white-space: normal;margin-bottom: 0px;"><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p></div><div data-id="12351" data-tools="新媒体排版" data-style-type="1" style="margin: 0px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);text-align: start;"><div data-css="border-color: initial;border-style: none;border-width: 0px;padding: 0px" style="margin: 0px;padding: 0px;border-color: initial;border-style: none;border-width: 0px;"><div powered-by="KolEditor.us" style="margin: 0px;padding: 0px;"><div style="margin: 10px 0px;padding: 0px;"><p style="font-size: medium;margin: 0px;padding: 0px;display: inline-block;"><span style="margin: 0px;padding: 0.3em 0.5em;background-color: rgb(23, 148, 221);border-radius: 0.8em 0.8em 0px 0px;color: rgb(255, 255, 255);display: block;font-size: 14.08px;"><p style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-size: 18px;"><span leaf=""><span textstyle="" style="font-size: 15px;">推荐阅读</span></span></span></strong></p></span></p><div data-css="border-color: rgb(249, 110, 87);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;box-sizing: border-box;padding: 10px" style="margin: 0px;padding: 10px;border-color: rgb(23, 148, 221);border-radius: 0px 0px 0.8em 0.8em;border-style: solid;border-width: 1px;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px;padding: 0px;"><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524571&amp;idx=2&amp;sn=e4271fa2e064e2011e1b779ac929f05f&amp;scene=21#wechat_redirect" textvalue="OpenAI 编程代理中高危漏洞可用于攻击开发人员" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">OpenAI 编程代理中高危漏洞可用于攻击开发人员</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247524535&amp;idx=1&amp;sn=b7fe9e8a785380e376468375bde77bce&amp;scene=21#wechat_redirect" textvalue="第三方供应商导致OpenAI客户数据遭泄露" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">第三方供应商导致OpenAI客户数据遭泄露</span></a></span></p><p style="margin-right: 8px;margin-left: 8px;color: rgb(0, 0, 0);text-align: start;white-space: normal;margin-bottom: 8px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&amp;mid=2247523149&amp;idx=1&amp;sn=0298267a08369cc3ea9bdbdec81eb788&amp;scene=21#wechat_redirect" textvalue="看我如何通过 OpenAI o3 挖到 Linux 内核远程 0day" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;">看我如何通过 OpenAI o3 挖到 Linux 内核远程 0day</span></a></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 15px;padding: 0px 0.5em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0em;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;color: rgb(0, 0, 0);font-size: medium;text-align: start;"><span style="margin: 0px;padding: 0px;font-size: 15px;color: rgb(136, 136, 136);text-decoration: underline;"><strong style="margin: 0px;padding: 0px;"><span leaf="">原文链接</span></strong></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;"><a href="https://cybersecuritynews.com/openai-safety-bug-bounty/" target="_blank">https://cybersecuritynews.com/openai-safety-bug-bounty/</a></span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span lang="EN-US" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">题图：Pixa</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">bay Licens</span><span leaf="" style="color: rgb(136, 136, 136);font-size: 15px;text-indent: 0em;">e</span></span></p><p style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;clear: both;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><strong style="text-indent: 0em;"><span style="font-size: 15px;color: rgb(136, 136, 136);"><span leaf="">本文由奇安信编译，不代表奇安信观点。转载请注明“转自奇安信代码卫士 <a href="https://codesafe.qianxin.com”。" target="_blank">https://codesafe.qianxin.com”。</a></span></span></strong></p><div data-role="paragraph" style="color: rgb(0, 0, 0);font-size: medium;margin: 0px 0px 15px;padding: 0px 0.5em;min-height: 1em;text-indent: 0em;text-align: start;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><div data-id="9499" data-tools="新媒体排版" data-style-type="4" style="color: rgb(0, 0, 0);font-size: 17px;margin: 0px;padding: 0px 0.5em;text-align: start;"><div style="margin: 0px;padding: 0px;"><div style="margin: 0px auto;padding: 0px;text-align: center;"><div style="margin: 0px auto;padding: 0px 0px 10px;max-width: 360px !important;"><p style="margin: 0px;padding: 0px 0px 0px 2px;font-size: 0px;width: 65px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.27380952380952384" data-type="jpeg" data-w="84" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;height: auto !important;" data-fileid="100025253" src="https://wechat2rss.xlab.app/img-proxy/?k=20efc9d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSf7nNLWrJL6dkJp7RB8Kl4zxU9ibnQjuvo4VoZ5ic9Q91K3WshWzqEybcroVEOQpgYfx1uYgwJhlFQ%2F640%3Fwx_fmt%3Djpeg"/></p><div data-css="align-items: flex-start;border-color: rgb(255, 138, 101);border-style: solid;border-width: 2px;display: flex;margin-top: -10px;padding: 30px 25px" style="margin: -10px 0px 0px;padding: 30px 25px;align-items: flex-start;border-color: rgb(23, 148, 221);border-style: solid;border-width: 2px;display: flex;"><div style="margin: 0px;padding: 0px;font-size: 0px;flex-shrink: 0;"><p style="margin: 0px;padding: 0px;width: 75px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-type="jpeg" data-w="1080" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: bottom;border-color: rgb(238, 238, 238);border-radius: 2px;border-style: solid;border-width: 1px;width: 75px;height: auto !important;" data-cropselx1="0" data-cropselx2="75" data-cropsely1="0" data-cropsely2="75" data-fileid="100025255" src="https://wechat2rss.xlab.app/img-proxy/?k=4657c87c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FoBANLWYScMSN5sfviaCuvYQccJZlrr64sRlvcbdWjDic9mPQ8mBBFDCKP6VibiaNE1kDVuoIOiaIVRoTjSsSftGC8gw%2F640%3Fwx_fmt%3Djpeg"/></p></div><div style="margin: 0px;padding: 0px 0px 0px 15px;flex-shrink: 1;"><p data-css="color: #333;font-size: 18px;line-height:1.7;margin: 0px auto;text-align: left" style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 18px;line-height: 1.7;text-align: left;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;color: rgb(23, 148, 221);"><span leaf="">奇安信代码卫士 (codesafe)</span></span></strong></span></p><p style="margin: 0px auto;padding: 0px;clear: both;min-height: 1em;font-size: 16px;text-align: left;line-height: 1.4;"><span style="margin: 0px;padding: 0px;font-size: 12px;"><span leaf="">国内首个专注于软件开发安全的产品线。</span></span></p></div></div></div></div></div></div><p style="color: rgb(51, 51, 51);font-size: 17px;margin: 0px;padding: 0px 0.5em;clear: both;min-height: 1em;text-align: center;"><span leaf="">   <img data-aistatus="1" class="__bg_gif rich_pages wxw-img" data-ratio="0.8" data-type="gif" data-w="200" style="margin: 0px;padding: 0px;max-width: 100%;vertical-align: middle;color: rgb(0, 0, 0);font-size: 14px;box-sizing: border-box;width: 58.125px;visibility: visible !important;height: auto !important;" data-fileid="100025256" src="https://wechat2rss.xlab.app/img-proxy/?k=fbb024f2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FoBANLWYScMQ5iciaeKS21icDIWSVd0M9zEhicFK0rbCJOrgpc09iaH6nvqvsIdckDfxH2K4tu9CvPJgSf7XhGHJwVyQ%2F640%3Fwx_fmt%3Dgif"/></span><span style="margin: 0px;padding: 0px;font-size: 12px;"><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">觉得不错，就点个 “</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">在看</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 或 &#34;</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(0, 128, 255);"><span leaf="">赞</span></span><span style="margin: 0px;padding: 0px;text-align: start;color: rgb(55, 55, 93);"><span leaf="">” 吧~</span></span></span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://codesafe.qianxin.com/#/home">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=fce8ac84&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2NTg4OTc5Nw%3D%3D%26mid%3D2247525564%26idx%3D1%26sn%3D87a38b04609d00236ed5984ced8a6243">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 27 Mar 2026 17:51:00 +0800</pubDate>
    </item>
  </channel>
</rss>