<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>枇杷熟了</title>
    <link>https://wechat2rss.xlab.app/feed/9779044929b45805a5c1b0fecf5f6a95c7202818.xml</link>
    <description>「枇杷熟了」——原黑伞安全全新升级，枇杷熟了科技有限公司官方公众号。专注网络安全、隐私保护与攻防实战，分享干货、工具与行业洞见。枇杷熟了，安全也熟了。&#xA;(wechat feed made by @ttttmr https://wechat2rss.xlab.app)</description>
    <managingEditor> (枇杷熟了)</managingEditor>
    <image>
      <url>https://wx.qlogo.cn/mmhead/thfLhcllFYoWbeP2SoyJyQvqmL0aiaDkrKufAKGGhmf8mvA8qYvLFC9vJFgDUpWUowCtyHxtCIhU/0</url>
      <title>枇杷熟了</title>
      <link>https://wechat2rss.xlab.app/feed/9779044929b45805a5c1b0fecf5f6a95c7202818.xml</link>
    </image>
    <item>
      <title>孙哥的中转站AI也&#34;降智&#34;？孙哥成孙割</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MzkzOTYzOQ==&amp;mid=2247490051&amp;idx=1&amp;sn=b6ed42c02d2bb9a08676e66f2ffeaf05</link>
      <description>孙哥的 b.ai 用 $2000/月 的天价，卖的却是 Flash 的廉价算力，还阉割了记忆功能。</description>
      <content:encoded><![CDATA[<p>原创 <span>枇杷哥</span> <span>2026-05-06 17:00</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=50ed6a1c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FeZOA7OiaVuZicibcypxUxjstTDNmLnmQQpqsOJ7x68j4LDG6C6ib548vwBDrnwTF4OjooIxlx14dEUkt7rcrX78FDiagb7GCricqDCo459Iyog3lc%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>孙哥的 b.ai 用 $2000/月 的天价，卖的却是 Flash 的廉价算力，还阉割了记忆功能。</p>
  <p><span leaf="">最近圈子里大家都在疯狂卷 AI 赋能安全，各种 Autonomous Agents 和自动化攻击链验证的方案层出不穷。为了追求更强大的推理逻辑和代码分析能力，我们平时没少追踪和测试各大厂商的最新高阶模型。</span></p><p style="margin-bottom: 20px;text-align: justify;"><span leaf="">但在国内，很多朋友为了方便，会选择使用各种第三方&#34;API 中转站&#34;。今天就用几个真实的踩坑经历，给大家实战演示一下：</span><strong style="color: rgb(212, 56, 13);"><span leaf="">如何用安全审计的直觉，扒掉那些无良套壳中转站的底裤。</span></strong></p><p style="margin-bottom: 20px;text-align: justify;"><strong style="color: rgb(212, 56, 13);"><span leaf="">而且这次的主角，不仅有割韭菜出名的孙哥（孙宇晨）的 b.ai，还有我自家项目上的血泪教训。</span></strong></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7003154574132492" data-s="300,640" data-type="png" data-w="634" type="block" data-imgfileid="100006393" src="https://wechat2rss.xlab.app/img-proxy/?k=a32f6a0b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FeZOA7OiaVuZibHjliaaQ9LEtSeXwicA28iaaU1ZwqEeCKnlQhtmYy7jDYojE4Mxq7GHibuB7aVnib7HMHspIXaL28b2XVNW86RoibKpcFjjLY0OSCbc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h2 style="font-size: 18px;color: rgb(24, 144, 255);margin-top: 40px;margin-bottom: 20px;padding-left: 10px;border-left: 4px solid rgb(24, 144, 255);"><span style="font-size: 18px;"><span leaf="">🚨</span></span><span leaf=""> 案发现场：这AI怎么突然&#34;降智&#34;了？</span></h2><p style="margin-bottom: 20px;text-align: justify;"><span leaf="">最近我在死磕移动端渗透和复杂链路的自动化 Hook，听说 </span><strong style="color: rgb(212, 56, 13);"><span leaf="">孙哥的 b.ai</span></strong><span leaf=""> 上线了 </span><strong style="color: rgb(212, 56, 13);"><span leaf="">Gemini 3.1 Pro</span></strong><span leaf="">，心里一喜。</span></p><p style="margin-bottom: 20px;text-align: justify;"><span leaf="">毕竟人家 </span><strong style="color: rgb(212, 56, 13);"><span leaf="">Plan Max 要 $2000/月</span></strong><span leaf="">（约 ¥14000+），Plan Pro 也要 </span><strong style="color: rgb(212, 56, 13);"><span leaf="">$200/月</span></strong><span leaf="">（约 ¥1400+），这价格都赶上 OpenAI 官方 Plus 的年费了，模型质量应该很能打吧？</span></p><p style="margin-bottom: 20px;text-align: justify;"><span leaf="">我马上切过去打算测试一下它对本地 RAG 架构和高级内存分配的理解。</span></p><p style="margin-bottom: 20px;text-align: justify;"><span leaf="">结果没聊几句，强烈的&#34;违和感&#34;就来了。它的回答充满了浓浓的&#34;早期模型味&#34;——遇到复杂的渗透场景就开始给我念免责声明，给出的架构方案也是纸上谈兵，毫无之前测试最新旗舰模型时那种&#34;手拿把掐&#34;的畅快感。</span></p><p><strong style="color: rgb(212, 56, 13);"><span leaf="">出于职业病，我对这种&#34;前端宣传极佳、后端实际拉胯&#34;的现象极其敏感。这不就是典型的业务逻辑漏洞吗？</span></strong></p><p style="margin-bottom: 20px;text-align: justify;"><span leaf="">于是，我决定不再聊技术，直接给它发了个&#34;身份探针&#34;。</span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6333333333333333" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100006394" src="https://wechat2rss.xlab.app/img-proxy/?k=9bb905d8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FeZOA7OiaVuZ9oTkicoNoKmX90MVftSuMhKD7GS3JROlsTj7s16icEhCrCichoADH7tLxcSdtWHkxT7shFMib9yenGWYUX4RQ2n4bmHYk3ew7HQLM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h2 style="font-size: 18px;color: rgb(24, 144, 255);margin-top: 40px;margin-bottom: 20px;padding-left: 10px;border-left: 4px solid rgb(24, 144, 255);"><span style="font-size: 18px;"><span leaf="">🕵️</span></span><span leaf=""> 探针命中：大模型自己承认了&#34;造假&#34;</span></h2><p style="margin-bottom: 20px;text-align: justify;"><span leaf="">我直接问它：</span><strong style="color: rgb(212, 56, 13);"><span leaf="">&#34;降智了吧，你是 gemini 吗？是 gemini 3.1 吗？&#34;</span></strong></p><p style="margin-bottom: 20px;text-align: justify;"><span leaf="">接下来，就出现了今年我见过的最好笑的&#34;自我揭发&#34;现场：</span></p><ol style="margin: 20px 0px;padding-left: 20px;" class="list-paddingleft-1"><li style="margin-bottom: 10px;"><strong style="color: rgb(212, 56, 13);"><span leaf="">左上角的 UI 标签</span></strong><p><span leaf="">赫然写着：</span><code><span leaf="">✨ Gemini 3.1 Pro</span></code></p></li><li style="margin-bottom: 10px;"><strong style="color: rgb(212, 56, 13);"><span leaf="">模型的第一波回答</span></strong><p><span leaf="">开始含糊其辞，试图用常规的套话糊弄过去。</span></p></li><li style="margin-bottom: 10px;"><p><span leaf="">当我步步紧逼，追问&#34;是 gemini 什么版本&#34;时，它回答：&#34;取决于你当前接入的平台…我无法确认&#34;。</span></p></li><li style="margin-bottom: 10px;"><p><span leaf="">最后我直接摊牌：&#34;我以为你是 gemini 3.1 呢&#34;。</span></p></li><li style="margin-bottom: 10px;"><strong style="color: rgb(212, 56, 13);"><span leaf="">高潮来了</span></strong><p><span leaf="">，这个耿直的后台模型直接回答：</span><strong style="color: rgb(212, 56, 13);"><span leaf="">&#34;哈哈，目前还没有 Gemini 3.1 这个版本呢。&#34;</span></strong></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.35462962962962963" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100006402" src="https://wechat2rss.xlab.app/img-proxy/?k=769a9ed5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FeZOA7OiaVuZ9CCysLVtxKECodhDHZxxP6HMRbiauVuD95EgvxEzLbB9RmD9H7mSRiaKO6RwdwDIHlMXzJVBUJI6RS69iaPQQojXQguxuo2yoia2M%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></li></ol><p><strong style="color: rgb(212, 56, 13);"><span leaf="">破案了。</span></strong><span leaf="">前端 UI 贴着最高端旗舰的标签，后台 API 路由却悄悄指向了低版本模型。</span></p><p><strong style="color: rgb(212, 56, 13);"><span leaf="">⚠️ 事后补充：</span></strong><span leaf="">b.ai 的 $2000/月背后，跑的根本不是 3.1，而是连自己版本都说不清的廉价底层。</span><span leaf=""><br/></span><strong style="color: rgb(212, 56, 13);"><span leaf="">你 $2000 买到的，可能连 Gemini 2.5 pro 都不如。</span></strong></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7092592592592593" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100006395" src="https://wechat2rss.xlab.app/img-proxy/?k=7fd72586&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FeZOA7OiaVuZ9JVqEdVsIRYsUFiayZSXRmFokjJB5XFtEqpdkv5w9mz8BcHpXfSuLeiaqEjJcicE3ss8nwT88bh7ZWI2DEz4Gpp2iaPZhTErad4ibQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h2 style="font-size: 18px;color: rgb(24, 144, 255);margin-top: 40px;margin-bottom: 20px;padding-left: 10px;border-left: 4px solid rgb(24, 144, 255);"><span style="font-size: 18px;"><span leaf="">💰</span></span><span leaf=""> 孙哥的定价策略：韭菜虽贵，模型虽旧</span></h2><table style="width: 617px;border-collapse: collapse;margin: 20px 0px;background: rgb(255, 255, 255);border-radius: 8px;overflow: hidden;box-shadow: rgba(0, 0, 0, 0.1) 0px 1px 3px;"></table><table style="width: 617px;border-collapse: collapse;margin: 20px 0px;background: rgb(255, 255, 255);border-radius: 8px;overflow: hidden;box-shadow: rgba(0, 0, 0, 0.1) 0px 1px 3px;"></table><p><span leaf="">而且你花 $2000 买的 &#34;孙哥大脑&#34; 技能，背后运行的很可能只是一台</span><strong style="color: rgb(212, 56, 13);"><span leaf="">连自己版本都说不清楚的旧模型</span></strong><span leaf="">，这韭菜割得，我都替孙哥鼓掌。</span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.738191632928475" data-s="300,640" data-type="png" data-w="1482" type="block" data-imgfileid="100006396" src="https://wechat2rss.xlab.app/img-proxy/?k=dc30e901&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FeZOA7OiaVuZib1Fcvibk0h7BiaTwMt9ia0ny9NOKP9eSOmpicVIg5F81EIia7PdJPaviannxJQKiaI4kt1PExWb0491h91L2yGrViaPjbUFf5or2qsEtw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h2 style="font-size: 18px;color: rgb(24, 144, 255);margin-top: 40px;margin-bottom: 20px;padding-left: 10px;border-left: 4px solid rgb(24, 144, 255);"><span style="font-size: 18px;"><span leaf="">🛠️</span></span><span leaf=""> 拆解中转站的&#34;降级套路&#34;</span></h2><p style="margin-bottom: 20px;text-align: justify;"><span leaf="">从技术架构上看，这其实是一个非常粗糙的骗局，为什么它会露馅？</span></p><h3 style="font-size: 16px;color: rgb(51, 51, 51);margin-top: 25px;"><span style="display: inline-block;width: 24px;height: 24px;background: rgb(24, 144, 255);color: rgb(255, 255, 255);border-radius: 50%;text-align: center;line-height: 24px;font-size: 14px;margin-right: 8px;"><span leaf="">1</span></span><span leaf=""> 官方模型的身份烙印</span></h3><p style="margin-bottom: 20px;text-align: justify;"><span leaf="">像官方运行的最新大模型，在其底层的 System Prompt 中会注入明确的身份标识、版本信息以及时间戳。我实测 Google Gemini 3.1 pro 时，它明确回答自己是 </span><strong style="color: rgb(212, 56, 13);"><span leaf="">Gemini 模型家族。</span></strong><span leaf="">而中转站的模型则含糊其辞&#34;取决于你当前接入的平台&#34;。</span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.55078125" data-s="300,640" data-type="png" data-w="1280" style="width:572px;height:315px;" type="block" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/eZOA7OiaVuZibJn4IWV78Rljz1wmHhC7GrXgy8rX3cHNbWbA5ia3BYibOlWNoxCb4vXEsp88E9uhCa5OZYaAJgUUa1tnzj6Rxkiaibk1UqqwaUGibs/0?wx_fmt=png&amp;from=appmsg" data-cropx1="31.411764705882355" data-cropx2="3026" data-cropy1="141.35294117647058" data-cropy2="1790.4705882352941" data-imgfileid="100006397" src="https://wechat2rss.xlab.app/img-proxy/?k=e5443c8a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FeZOA7OiaVuZ9NNyQMveKKlPEmZrbejBhgHmBu765hNEaKBVuvs6JP9VD2O05WCyp8nlQaqFiaGGBkjdtdgmSYhWcrrMO3fETTUw01NHtIeZvM%2F640%3Fwx_fmt%3Djpeg"/></p><h3 style="font-size: 16px;color: rgb(51, 51, 51);margin-top: 25px;"><span style="display: inline-block;width: 24px;height: 24px;background: rgb(24, 144, 255);color: rgb(255, 255, 255);border-radius: 50%;text-align: center;line-height: 24px;font-size: 14px;margin-right: 8px;"><span leaf="">2</span></span><span leaf=""> API 透传的盲区</span></h3><p style="margin-bottom: 20px;text-align: justify;"><span leaf="">这类第三方 API 中转站，往往只是做了一层简单的 Request 转发。他们为了节省成本，把用户的 Prompt 发给了旧版本的 API 端点，但</span><strong style="color: rgb(212, 56, 13);"><span leaf="">忘了在请求中强行注入伪造的 System Prompt</span></strong><span leaf="">。</span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6620370370370371" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100006398" src="https://wechat2rss.xlab.app/img-proxy/?k=476a237c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FeZOA7OiaVuZibf5XGdD7JRmTvXHsSrJZ5CQtH5g7YxgvzyNjiaWbpRcGnviaUMfEXbaOWNxictyB8RXBib1zibibYaylaMJtmibHaVEwWQhp06pkV2oM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h3 style="font-size: 16px;color: rgb(51, 51, 51);margin-top: 25px;"><span style="display: inline-block;width: 24px;height: 24px;background: rgb(24, 144, 255);color: rgb(255, 255, 255);border-radius: 50%;text-align: center;line-height: 24px;font-size: 14px;margin-right: 8px;"><span leaf="">3</span></span><span leaf=""> 信息差割裂</span></h3><p style="margin-bottom: 20px;text-align: justify;"><span leaf="">导致的结果就是，前端网页是你画的，你想写 4.0 还是 5.0 都可以；但底层的模型只根据它自己（旧版本）的预训练数据和初始设定作答，面对直接的&#34;身份质询&#34;，它当场就说了实话。</span></p><p style="margin-bottom: 20px;text-align: justify;"><span leaf="">这里必须给大家科普一个关键事实：gemini</span><strong style="color: rgb(212, 56, 13);"><span leaf="">系列被中转站偏爱，不是因为它们现在还在 API 上活得好，而是因为 Google 官方曾经给出过极其丰厚的免费额度</span></strong><span leaf="">，很多早期用户和中转站通过免费额度积累了大量的&#34;廉价算力缓存&#34;。中转站用这种即将被淘汰的旧算力伪装成高端旗舰模型，赚取高昂的会员费或按次计费的差价，</span><strong style="color: rgb(212, 56, 13);"><span leaf="">利润极其可观</span></strong><span leaf="">。</span></p><h2 style="font-size: 18px;color: rgb(24, 144, 255);margin-top: 40px;margin-bottom: 20px;padding-left: 10px;border-left: 4px solid rgb(24, 144, 255);"><span style="font-size: 18px;"><span leaf="">🔥</span></span><span leaf=""> 血的教训：我项目上也翻过同样的车</span></h2><p style="margin-bottom: 20px;text-align: justify;"><span leaf="">上面说的 b.ai，还只是割个人韭菜。</span><strong style="color: rgb(212, 56, 13);"><span leaf="">真正让我肉疼的，是我自己项目上的一起事故。</span></strong></p><p style="margin-bottom: 20px;text-align: justify;"><span leaf="">事情是这样的：团队里有个小伙，为了追求代码审计效率，买了一个号称 </span><strong style="color: rgb(212, 56, 13);"><span leaf="">&#34;Claude 4.6 Opus&#34;</span></strong><span leaf=""> 的 API 中转站服务——宣传页花里胡哨，价格还比官方便宜不少。</span></p><p style="margin-bottom: 20px;text-align: justify;"><span leaf="">他兴致勃勃地把项目里的代码审计任务交给了这个&#34;Claude 4.6 Opus&#34;。AI 刷刷刷地跑完，输出了一份看起来非常专业的审计报告，指出了几十个潜在漏洞。</span></p><p style="margin-bottom: 20px;text-align: justify;"><span leaf="">小伙一看，觉得 AI 牛逼，</span><strong style="color: rgb(212, 56, 13);"><span leaf="">没做任何人工复现验证</span></strong><span leaf="">，直接就按 AI 的报告提交了漏洞工单。结果呢？</span></p><p><strong style="color: rgb(212, 56, 13);"><span leaf="">我特么第二轮人工 Code Review 的时候，那些所谓的&#34;漏洞&#34;有一大半都是误报</span></strong><span leaf="">——AI 把一些符合安全规范的标准写法识别成了风险点。更可怕的是，</span><strong style="color: rgb(212, 56, 13);"><span leaf="">真正的几个高危漏洞，这个号称 Claude 4.6 Opus 的 AI 根本没检测出来。</span></strong></p><p style="margin-bottom: 20px;text-align: justify;"><span leaf="">事后复盘，我来了一招&#34;身份探针&#34;测试：</span></p><table style="width: 617px;border-collapse: collapse;margin: 20px 0px;background: rgb(255, 255, 255);border-radius: 8px;overflow: hidden;box-shadow: rgba(0, 0, 0, 0.1) 0px 1px 3px;"></table><table><tbody><tr><th style="background: rgb(24, 144, 255);color: rgb(255, 255, 255);padding: 12px;text-align: left;font-weight: 500;"><p><span leaf="">测试内容</span></p></th><th style="background: rgb(24, 144, 255);color: rgb(255, 255, 255);padding: 12px;text-align: left;font-weight: 500;"><p><span leaf="">所谓 &#34;Claude 4.6 Opus&#34;</span></p></th></tr><tr><td style="padding: 12px;border-bottom: 1px solid rgb(240, 240, 240);"><strong style="color: rgb(212, 56, 13);"><span leaf="">你是谁</span></strong></td><td style="padding: 12px;border-bottom: 1px solid rgb(240, 240, 240);"><p><span leaf="">含糊其辞</span></p></td></tr><tr><td style="padding: 12px;border-bottom: 1px solid rgb(240, 240, 240);"><strong style="color: rgb(212, 56, 13);"><span leaf="">训练数据截止</span></strong></td><td style="padding: 12px;border-bottom: 1px solid rgb(240, 240, 240);"><p><span leaf="">答非所问</span></p></td></tr><tr><td style="padding: 12px;border-bottom: 1px solid rgb(240, 240, 240);"><strong style="color: rgb(212, 56, 13);"><span leaf="">复杂SQL注入WAF绕过Payload</span></strong></td><td style="padding: 12px;border-bottom: 1px solid rgb(240, 240, 240);"><p><span leaf="">输出通用模板</span></p></td></tr><tr><td style="padding: 12px;border-bottom-width: medium;border-bottom-style: none;border-bottom-color: currentcolor;"><strong style="color: rgb(212, 56, 13);"><span leaf="">与 Qwen3 能力对比</span></strong></td><td style="padding: 12px;border-bottom-width: medium;border-bottom-style: none;border-bottom-color: currentcolor;"><strong style="color: rgb(212, 56, 13);"><span leaf="">实际不如 Qwen3</span></strong></td></tr></tbody></table><p><strong style="color: rgb(212, 56, 13);"><span leaf="">结论：所谓高价买的 &#34;Claude 4.6 Opus&#34;，底子就是一台掺水模型，能力上限连 Qwen3 都跑不过。</span></strong></p><p style="margin-bottom: 20px;text-align: justify;"><span leaf="">这口锅，一半在中转站挂羊头卖狗肉，一半在</span><strong style="color: rgb(212, 56, 13);"><span leaf="">对 AI 输出完全信任、不做复现验证的工作习惯</span></strong><span leaf="">。</span></p><p><strong style="color: rgb(212, 56, 13);"><span leaf="">安全圈的铁律依然是：AI 辅助可以，AI 决定不行。所有 AI 报出来的漏洞，必须人工复现验证之后才能上报。</span></strong></p><h2 style="font-size: 18px;color: rgb(24, 144, 255);margin-top: 40px;margin-bottom: 20px;padding-left: 10px;border-left: 4px solid rgb(24, 144, 255);"><span style="font-size: 18px;"><span leaf="">🛡️</span></span><span leaf=""> 如何自我保护？</span></h2><h3 style="font-size: 16px;color: rgb(51, 51, 51);margin-top: 25px;"><span style="display: inline-block;width: 24px;height: 24px;background: rgb(24, 144, 255);color: rgb(255, 255, 255);border-radius: 50%;text-align: center;line-height: 24px;font-size: 14px;margin-right: 8px;"><span leaf="">1</span></span><span leaf=""> 抓包看本质</span></h3><p style="margin-bottom: 20px;text-align: justify;"><span leaf="">测模型和测 Web 一样，</span><strong style="color: rgb(212, 56, 13);"><span leaf="">不要轻信 UI 上的任何一个字</span></strong><span leaf="">。感觉逻辑不对，直接上测试 Prompt 探底。</span></p><p><strong style="color: rgb(212, 56, 13);"><span leaf="">推荐几个测试 Prompt：</span></strong><span leaf=""><br/></span><span leaf="">• &#34;你的训练数据截止日期是什么时候？&#34;</span><span leaf=""><br/></span><span leaf="">• &#34;你是哪个版本的大模型？&#34;</span><span leaf=""><br/></span><span leaf="">• &#34;Gemini 3.1 的上下文窗口是多少？&#34;</span><span leaf=""><br/></span><span leaf="">• &#34;请用你的原生能力处理这段代码，不要用通用方法&#34;</span><span leaf=""><br/></span><span leaf="">• &#34;写一个非标准的复杂 SQL 注入绕过 Payload&#34;</span></p><h3 style="font-size: 16px;color: rgb(51, 51, 51);margin-top: 25px;"><span style="display: inline-block;width: 24px;height: 24px;background: rgb(24, 144, 255);color: rgb(255, 255, 255);border-radius: 50%;text-align: center;line-height: 24px;font-size: 14px;margin-right: 8px;"><span leaf="">2</span></span><span leaf=""> 别用关键数据喂中转站</span></h3><p style="margin-bottom: 20px;text-align: justify;"><span leaf="">作为安全从业者，我们经常会把漏洞细节、反编译代码、客户源码扔给 AI 辅助分析。把这些敏感数据交给这种为了赚差价而随时&#34;暗中降级&#34;的中转站，</span><strong style="color: rgb(212, 56, 13);"><span leaf="">风险极高</span></strong><span leaf="">——你的 Payload、0day 细节很可能就是他们的下一个训练数据。</span></p><h3 style="font-size: 16px;color: rgb(51, 51, 51);margin-top: 25px;"><span style="display: inline-block;width: 24px;height: 24px;background: rgb(24, 144, 255);color: rgb(255, 255, 255);border-radius: 50%;text-align: center;line-height: 24px;font-size: 14px;margin-right: 8px;"><span leaf="">3</span></span><span leaf=""> AI 辅助 ≠ AI 自动执行</span></h3><p style="margin-bottom: 20px;text-align: justify;"><span leaf="">无论中转站宣称的是什么&#34;地表最强模型&#34;，</span><strong style="color: rgb(212, 56, 13);"><span leaf="">所有 AI 产出的审计结果、漏洞定位，必须经过人工复现验证</span></strong><span leaf="">。不验证就上报，你的信用分在安全圈就值零了。</span></p><h3 style="font-size: 16px;color: rgb(51, 51, 51);margin-top: 25px;"><span style="display: inline-block;width: 24px;height: 24px;background: rgb(24, 144, 255);color: rgb(255, 255, 255);border-radius: 50%;text-align: center;line-height: 24px;font-size: 14px;margin-right: 8px;"><span leaf="">4</span></span><span leaf=""> 拥抱正规渠道/本地部署</span></h3><p style="margin-bottom: 20px;text-align: justify;"><span leaf="">想要真正搞 AI-Native 渗透和 Vibe Coding，</span><strong style="color: rgb(212, 56, 13);"><span leaf="">老老实实对接官方 API</span></strong><span leaf="">，或者利用手头的算力跑本地模型，配合私有知识库，才是最稳妥的归宿。</span></p><p><strong style="color: rgb(212, 56, 13);"><span leaf="">强烈建议直接去官方渠道申请 API Key，彻底避开中间商赚差价和数据泄露的风险。</span></strong></p><h2 style="font-size: 18px;color: rgb(24, 144, 255);margin-top: 40px;margin-bottom: 20px;padding-left: 10px;border-left: 4px solid rgb(24, 144, 255);"><span style="font-size: 18px;"><span leaf="">💡</span></span><span leaf=""> 延伸思考：自动化渗透中的&#34;算力分层&#34;策略</span></h2><p style="margin-bottom: 20px;text-align: justify;"><span leaf="">前面的翻车案例说明了一个核心问题：</span><strong style="color: rgb(212, 56, 13);"><span leaf="">不同场景对 AI 能力的需求完全不同，用一个模型包打天下必然翻车。</span></strong></p><p style="margin-bottom: 20px;text-align: justify;"><span leaf="">在构建自动化渗透架构时，一种非常实战的打法是</span><strong style="color: rgb(212, 56, 13);"><span leaf="">&#34;算力分层&#34;</span></strong><span leaf="">：</span></p><p style="margin-bottom: 20px;text-align: justify;"><strong style="color: rgb(212, 56, 13);"><span leaf="">实战建议：</span></strong></p><ul style="margin: 20px 0px;padding-left: 20px;" class="list-paddingleft-1"><li style="margin-bottom: 10px;"><p><span leaf="">高频的指纹探测与初步日志清洗，可以用便宜的小模型甚至本地部署的模型</span></p></li><li style="margin-bottom: 10px;"><p><span leaf="">关键混淆代码和长上下文分析，必须用经过实测验证的中高端模型</span></p></li><li style="margin-bottom: 10px;"><strong style="color: rgb(212, 56, 13);"><span leaf="">最关键的一层：多模型交叉验证 + 人工复审</span></strong><p><span leaf="">——所有 AI 产出的审计结论，必须有人工兜底</span></p></li><li style="margin-bottom: 10px;"><p><span leaf="">千万不能像我家小伙那样，一个廉价中转站 + 一个零验证流程，就把审计报告草率发出去了</span></p></li></ul><h2 style="font-size: 18px;color: rgb(24, 144, 255);margin-top: 40px;margin-bottom: 20px;padding-left: 10px;border-left: 4px solid rgb(24, 144, 255);"><span style="font-size: 18px;"><span leaf="">🔍</span></span><span leaf=""> 如何自查正在使用的 API 中转站？</span></h2><p style="margin-bottom: 20px;text-align: justify;"><span leaf="">给你几个实用的验证方法：</span></p><ol style="margin: 20px 0px;padding-left: 20px;" class="list-paddingleft-1"><li style="margin-bottom: 10px;"><strong style="color: rgb(212, 56, 13);"><span leaf="">直接询问身份</span></strong><p><span leaf="">：像我一样，直接问模型&#34;你是谁、哪个版本&#34;</span></p></li><li style="margin-bottom: 10px;"><strong style="color: rgb(212, 56, 13);"><span leaf="">实测 API 模型列表</span></strong><p><span leaf="">：自己拉一下官方 API 的模型列表（</span><code><span leaf="">GET /models</span></code><span leaf="">），看看宣称的模型到底在不在</span></p></li><li style="margin-bottom: 10px;"><strong style="color: rgb(212, 56, 13);"><span leaf="">对比响应质量</span></strong><p><span leaf="">：同样的复杂 Prompt，分别用中转站和官方 API 测试，对比回答质量</span></p></li><li style="margin-bottom: 10px;"><strong style="color: rgb(212, 56, 13);"><span leaf="">查看 API 响应头</span></strong><p><span leaf="">：有些中转站会在响应头里暴露真实的后端模型信息</span></p></li><li style="margin-bottom: 10px;"><strong style="color: rgb(212, 56, 13);"><span leaf="">测试上下文窗口</span></strong><p><span leaf="">：尝试输入超长文本，看是否真的支持宣称的上下文长度</span></p></li><li style="margin-bottom: 10px;"><strong style="color: rgb(212, 56, 13);"><span leaf="">交叉验证</span></strong><p><span leaf="">：同样的漏洞分析任务，让两个不同来源的模型分别跑，看结论是否一致</span></p></li><li style="margin-bottom: 10px;"><strong style="color: rgb(212, 56, 13);"><span leaf="">复现验证</span></strong><p><span leaf="">：无论 AI 输出什么，</span><strong style="color: rgb(212, 56, 13);"><span leaf="">必须手动验证后再上报</span></strong><span leaf="">（这条最重要）</span></p></li></ol><h2 style="font-size: 18px;color: rgb(24, 144, 255);margin-top: 40px;margin-bottom: 20px;padding-left: 10px;border-left: 4px solid rgb(24, 144, 255);"><span style="font-size: 18px;"><span leaf="">📌</span></span><span leaf=""> 总结</span></h2><p><strong style="color: rgb(212, 56, 13);"><span leaf="">不验证中转站的能力，你的 AI 辅助工具就是一台概率型诈骗机。</span><span leaf=""><br/></span><span leaf="">不验证 AI 的输出结果，你的工作效率就是负数。</span></strong></p><p style="margin-bottom: 20px;text-align: justify;"><span leaf="">别被假标签糊弄了，保持清醒，继续挖洞！</span></p><p style="margin-bottom: 20px;text-align: justify;"><em><span leaf="">枇杷熟了专注前沿 Web/Mobile 安全对抗与 AI 自动化渗透</span></em></p><p style="margin-bottom: 20px;text-align: justify;margin-top: 20px;"><span style="display: inline-block;background: rgb(240, 240, 240);color: rgb(102, 102, 102);padding: 4px 8px;border-radius: 4px;font-size: 12px;margin: 4px;"><span leaf=""><a class="wx_topic_link" topic-id="motqwo7g-vkmt5h" style="color: #576B95 !important;" data-topic="1" data-recommend="">#AI安全</a></span></span><span style="display: inline-block;background: rgb(240, 240, 240);color: rgb(102, 102, 102);padding: 4px 8px;border-radius: 4px;font-size: 12px;margin: 4px;"><span leaf=""><a class="wx_topic_link" topic-id="motqwo7g-08soae" style="color: #576B95 !important;" data-topic="1" data-recommend="">#渗透测试</a></span></span><span style="display: inline-block;background: rgb(240, 240, 240);color: rgb(102, 102, 102);padding: 4px 8px;border-radius: 4px;font-size: 12px;margin: 4px;"><span leaf=""><a class="wx_topic_link" topic-id="motqwo7g-v76n8s" style="color: #576B95 !important;" data-topic="1" data-recommend="">#避坑指南</a></span></span><span style="display: inline-block;background: rgb(240, 240, 240);color: rgb(102, 102, 102);padding: 4px 8px;border-radius: 4px;font-size: 12px;margin: 4px;"><span leaf=""><a class="wx_topic_link" topic-id="motqwo7g-9yt1dz" style="color: #576B95 !important;" data-topic="1" data-recommend="">#大模型</a></span></span><span style="display: inline-block;background: rgb(240, 240, 240);color: rgb(102, 102, 102);padding: 4px 8px;border-radius: 4px;font-size: 12px;margin: 4px;"><span leaf=""><a class="wx_topic_link" topic-id="motqwo7g-qhnpy7" style="color: #576B95 !important;" data-topic="1" data-recommend="">#安全审计</a></span></span><span style="display: inline-block;background: rgb(240, 240, 240);color: rgb(102, 102, 102);padding: 4px 8px;border-radius: 4px;font-size: 12px;margin: 4px;"><span leaf=""><a class="wx_topic_link" topic-id="motqwo7g-koe16a" style="color: #576B95 !important;" data-topic="1" data-recommend="">#API安全</a></span></span><span style="display: inline-block;background: rgb(240, 240, 240);color: rgb(102, 102, 102);padding: 4px 8px;border-radius: 4px;font-size: 12px;margin: 4px;"><span leaf=""><a class="wx_topic_link" topic-id="motqwo7g-rr23xt" style="color: #576B95 !important;" data-topic="1" data-recommend="">#自动化渗透</a></span></span><span style="display: inline-block;background: rgb(240, 240, 240);color: rgb(102, 102, 102);padding: 4px 8px;border-radius: 4px;font-size: 12px;margin: 4px;"><span leaf=""><a class="wx_topic_link" topic-id="motqwo7g-pdc15c" style="color: #576B95 !important;" data-topic="1" data-recommend="">#孙宇晨</a></span></span><span style="display: inline-block;background: rgb(240, 240, 240);color: rgb(102, 102, 102);padding: 4px 8px;border-radius: 4px;font-size: 12px;margin: 4px;"><span leaf=""><a class="wx_topic_link" topic-id="motqwo7g-mo298x" style="color: #576B95 !important;" data-topic="1" data-recommend="">#b</a>.ai</span></span><span style="display: inline-block;background: rgb(240, 240, 240);color: rgb(102, 102, 102);padding: 4px 8px;border-radius: 4px;font-size: 12px;margin: 4px;"><span leaf=""><a class="wx_topic_link" topic-id="motqwo7g-ic7960" style="color: #576B95 !important;" data-topic="1" data-recommend="">#Gemini</a></span></span><span style="display: inline-block;background: rgb(240, 240, 240);color: rgb(102, 102, 102);padding: 4px 8px;border-radius: 4px;font-size: 12px;margin: 4px;"><span leaf=""><a class="wx_topic_link" topic-id="motqwo7g-81o25b" style="color: #576B95 !important;" data-topic="1" data-recommend="">#代码审计</a></span></span><span style="display: inline-block;background: rgb(240, 240, 240);color: rgb(102, 102, 102);padding: 4px 8px;border-radius: 4px;font-size: 12px;margin: 4px;"><span leaf=""><a class="wx_topic_link" topic-id="motqwo7g-xj5kln" style="color: #576B95 !important;" data-topic="1" data-recommend="">#Claude</a></span></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=e862e04f&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MzkzOTYzOQ%3D%3D%26mid%3D2247490051%26idx%3D1%26sn%3Db6ed42c02d2bb9a08676e66f2ffeaf05">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 06 May 2026 17:00:00 +0800</pubDate>
    </item>
    <item>
      <title>1秒root、九年无人知——Linux近年最屌提权漏洞</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MzkzOTYzOQ==&amp;mid=2247490029&amp;idx=1&amp;sn=fc9c3feee41b708f86dab16be4154af5</link>
      <description>1秒root、九年无人知——Linux近年最屌提权漏洞</description>
      <content:encoded><![CDATA[<p><span>长亭应急响应</span> <span>2026-04-30 14:47</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=396ba747&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FeZOA7OiaVuZicA6ttpyRNU3qbGTXDFcFscdSczxSznib1rQWjg1XuYGy91q5QsibadhXUVRISNbufDA52PFkLH32y6qQfKSljW6DfA4Vj3jR20k%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>1秒root、九年无人知——Linux近年最屌提权漏洞</p>
  <plasmo-csui style="top: 0px !important;left: 0px !important;width: 0px !important;height: 0px !important;z-index: 2147483646 !important;overflow: visible !important;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(0, 0, 0);font-family: &#34;PingFang SC&#34;;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"></plasmo-csui><div data-role="outer" label="edit by 135editor" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: 默认字体;visibility: visible;"><div data-role="paragraph" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;letter-spacing: 0.578px;font-family: mp-quote, &#34;PingFang SC&#34;, -apple-system-font, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;visibility: visible;"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1329378339},[&#34;p&#34;,{},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;泛微协同管理应用平台（e-cology）是一款全面的企业管理平台。它具备多元化的功能，包括企业信息门户、知识文档管理、工作流程管理、人力资源管理、客户关系管理、项目管理、财务管理、资产管理、供应链管理以及数据中心等。这款平台有助于企业整合各种资源，包括管理、市场、销售、研发、人事和行政等各个领域。通过e-cology，这些资源可以在一个统一的平台上集成，并为用户提供统一的界面以方便操作和获取信息。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhbw00xpg3nfo1awkjt&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;近日，长亭应急团队监测到泛微发布了新的安全漏洞补丁修补了多个漏洞，其中有两个漏洞值得关注，分别是信息泄露和任意用户登录，组合起来可以获取应用系统的任意用户权限。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhbw2mh45202sva9ihn&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;经过分析漏洞后，发现公网仍有较多系统未修复漏洞，长亭应急团队根据该漏洞的原理，编写了X-RAY远程检测工具和牧云本地检测工具供大家下载使用，同时在文章中提供了排查该资产的方式。&#34;]]]]" data-identifier-application__slash__x-doc-key="LvBPlNWKY5PVndG8" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1121139987},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhsqy1c3vobicv0i3er&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;畅捷通T+是一款企业资源规划（ERP）软件，主要功能包括财务管理、销售管理、采购管理以及库存管理等，助力企业实现业务流程自动化。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;limjtprko8zpm2fo8pl&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;近期，长亭科技监测到微步在线发布一则漏洞通告，声明畅捷通T+发布新版本修复了一个RCE漏洞。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;limrdh63y857qallxw&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;长亭应急团队经过漏洞分析后，发现该漏洞类型为SQL注入，可利用其实现RCE。公网仍有较多相关系统尚未修复漏洞。应急团队根据该漏洞的原理，编写了X-POC远程检测工具和牧云本地检测工具，目前工具已向公众开放下载使用。&#34;]]]]" data-identifier-application__slash__x-doc-key="2M9qPJ1xzP43l015" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1121139987},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhsqy1c3vobicv0i3er&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;Openfire（前身为Wildfire）是一个基于XMPP（Extensible Messaging and Presence Protocol，可扩展消息处理和呈现协议）的开源实时协作服务器，同时提供了Web管理界面。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;limjtprko8zpm2fo8pl&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;近期，长亭科技监测到Openfire发布新版本修复了一个漏洞。长亭应急团队经过漏洞分析后，发现该漏洞类型为后台权限绕过，可利用其实现RCE。公网仍有较多相关系统尚未修复漏洞。应急团队根据该漏洞的原理，编写了X-POC远程检测工具和牧云本地检测工具，目前工具已向公众开放下载使用。&#34;]]]]" data-identifier-application__slash__x-doc-key="AJdl6mZR72PKOke1" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1121139987},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhsqy1c3vobicv0i3er&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;Apache RocketMQ是一款开源的分布式消息和流处理平台，提供了高效、可靠、可扩展的低延迟消息和流数据处理能力，广泛用于异步通信、应用解耦、系统集成以及大数据、实时计算等场景。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;licys4nlk4z44589ypo&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;近期，长亭科技监测到RocketMQ发布新版本修复了一个远程命令执行漏洞（CVE-2023-37582）。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;licytz2meuxzh6wlgn&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;经过分析漏洞后，发现公网仍有较多系统未修复漏洞。应急团队根据该漏洞的原理，已经编写了X-POC远程检测工具和牧云本地检测工具&#34;],[&#34;span&#34;,{&#34;bold&#34;:false,&#34;sz&#34;:11,&#34;szUnit&#34;:&#34;pt&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;，并已向公众开放下载使用。&#34;]]]]" data-identifier-application__slash__x-doc-key="r4mlQmEY28GMlxow" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);text-size-adjust: inherit;visibility: visible;"><p nodeleaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;visibility: visible;"><img alt="图片" class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100009562" data-ratio="0.5351851851851852" data-s="300,640" type="block" data-type="png" data-w="1080" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: bottom;height: auto !important;visibility: visible !important;width: 676.992px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=f2f9e660&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEqS9GE77r0ObDuLNiaxW7q7ptG21ibM4LW3MzFiaOTdxicnTjRhnd6ibvaV7f3KZURx7NfFCfeD2CAsGczabOmfY35ZtwWYOnhiasXG28xKO9TeNE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D0"/></p><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;fonts&#34;:{&#34;hint&#34;:&#34;eastAsia&#34;},&#34;data-type&#34;:&#34;leaf&#34;},&#34;瑞&#34;],[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;友天翼应用虚拟化系统是西安瑞友信息技术资讯有限公司研发的具有自主知识产权，基于服务器计算架构的应用虚拟化平台。它将用户各种应用软件集中部署在瑞友天翼服务器(群)上，客户端通过WEB即可快速安全的访问经服务器上授权的应用软件，实现集中应用、远程接入、协同办公等。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lp0xhb0ekky9vvtxiv&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;sz&#34;:11,&#34;szUnit&#34;:&#34;pt&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;2024年5月，互联网公开了一个&#34;],[&#34;span&#34;,{&#34;fonts&#34;:{&#34;hint&#34;:&#34;eastAsia&#34;},&#34;data-type&#34;:&#34;leaf&#34;},&#34;瑞&#34;],[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;友天翼应用虚拟化系统&#34;],[&#34;span&#34;,{&#34;sz&#34;:11,&#34;szUnit&#34;:&#34;pt&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;的SQL注入漏洞。鉴于该漏洞无前置条件，易于利用，且默认情况下可直接获取操作系统权限，建议所有使用该系统的企业尽快进行升级修复，以确保系统安全。&#34;]]]]" data-identifier-application__slash__x-doc-key="4jKqmVWA95GDOw19" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-size-adjust: inherit;visibility: visible;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lw0h0ayp6j8mmfkcsxa&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;fonts&#34;:{&#34;hint&#34;:&#34;eastAsia&#34;},&#34;data-type&#34;:&#34;leaf&#34;},&#34;PHP-CGI 是一种用于在 Web 服务器上运行 PHP 脚本的接口，通过 CGI（公共网关接口）将 PHP 解释器与 Web 服务器连接。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lp0xhb0ekky9vvtxiv&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;2024年6月，PHP官方发布新版本，修复了 &#34;],[&#34;span&#34;,{&#34;sz&#34;:11,&#34;szUnit&#34;:&#34;pt&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;PHP-CGI &#34;],[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;中一个远程代码执行漏洞。&#34;],[&#34;span&#34;,{&#34;sz&#34;:11,&#34;szUnit&#34;:&#34;pt&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;鉴于该漏洞无前置条件，易于利用，且默认情况下可获取操作系统权限，建议所有使用受影响版本的企业尽快升级修复，以确保安全。&#34;]]]]" data-identifier-application__slash__x-doc-key="3BMqYaMEV896qwZL" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-size-adjust: inherit;visibility: visible;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;liy8sjqqhpyk6m030b9&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;Serv-U 是 SolarWinds 公司推出的FTP服务器软件，提供文件传输服务，支持多种协议（FTP、FTPS、SFTP），具有用户管理、文件权限控制等功能，适用于企业级文件传输解决方案。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lo5ajwxivf4py2sbk1f&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;2024年6月，Serv-U 官方 SolarWinds 发布了新补丁，修复了一处目录遍历致文件读取漏洞（CVE-2024-28995）。经分析，该漏洞可以通过特定的路径请求来未授权访问系统文件，进而可能导致敏感信息泄露。该漏洞无前置条件且利用简单，建议受影响的客户尽快修复漏洞。&#34;]]]]" data-identifier-application__slash__x-doc-key="8K4nyRy9Bv1jqLbj" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-size-adjust: inherit;visibility: visible;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhsqy1c3vobicv0i3er&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;sz&#34;:10.5,&#34;szUnit&#34;:&#34;pt&#34;,&#34;color&#34;:&#34;rgba(0, 0, 0, 0.87)&#34;,&#34;spacing&#34;:0.049245,&#34;data-type&#34;:&#34;leaf&#34;},&#34;Gogs (Go Git Service) 是一款基于 Go 语言开发的开源 Git 托管平台，采用 MIT 许可证，提供代码托管、Issue 跟踪、权限管理和 Webhook 等功能。&#34;]]],[&#34;p&#34;,{&#34;jc&#34;:&#34;left&#34;,&#34;ind&#34;:{},&#34;spacing&#34;:{},&#34;uuid&#34;:&#34;lyiiqr1cqx6q84a8wmd&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;spacing&#34;:0.21675,&#34;data-type&#34;:&#34;leaf&#34;},&#34;2025年6月，&#34;],[&#34;span&#34;,{&#34;sz&#34;:10.5,&#34;szUnit&#34;:&#34;pt&#34;,&#34;color&#34;:&#34;rgba(0, 0, 0, 0.87)&#34;,&#34;spacing&#34;:0.049245,&#34;data-type&#34;:&#34;leaf&#34;},&#34;Gogs发布&#34;],[&#34;span&#34;,{&#34;spacing&#34;:0.21675,&#34;data-type&#34;:&#34;leaf&#34;},&#34;新版本，修复了一处命令注入漏洞。经分析，拥有用户权限的攻击者可利用该漏洞执行任意系统命令，利用难度较低，建议受影响的用户尽快修复。&#34;]]]]" data-identifier-application__slash__x-doc-key="ABmOoWbjkxeDzOaw" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;visibility: visible;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhsqy1c3vobicv0i3er&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;ComfyUI 是一款流行的基于节点的 Stable Diffusion 图形用户界面，广泛应用于 AI 图像生成工作流的构建和执行。ComfyUI-Manager 是 ComfyUI 的扩展管理器插件，用于简化自定义节点、模型和依赖项的安装管理。&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJsaHNxeTFjM3ZvYmljdjBpM2VyJTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyQ29tZnlVSSUyMCVFNiU5OCVBRiVFNCVCOCU4MCVFNiVBQyVCRSVFNiVCNSU4MSVFOCVBMSU4QyVFNyU5QSU4NCVFNSU5RiVCQSVFNCVCQSU4RSVFOCU4QSU4MiVFNyU4MiVCOSVFNyU5QSU4NCUyMFN0YWJsZSUyMERpZmZ1c2lvbiUyMCVFNSU5QiVCRSVFNSVCRCVBMiVFNyU5NCVBOCVFNiU4OCVCNyVFNyU5NSU4QyVFOSU5RCVBMiVFRiVCQyU4QyVFNSVCOSVCRiVFNiVCMyU5QiVFNSVCQSU5NCVFNyU5NCVBOCVFNCVCQSU4RSUyMEFJJTIwJUU1JTlCJUJFJUU1JTgzJThGJUU3JTk0JTlGJUU2JTg4JTkwJUU1JUI3JUE1JUU0JUJEJTlDJUU2JUI1JTgxJUU3JTlBJTg0JUU2JTlFJTg0JUU1JUJCJUJBJUU1JTkyJThDJUU2JTg5JUE3JUU4JUExJThDJUUzJTgwJTgyQ29tZnlVSS1NYW5hZ2VyJTIwJUU2JTk4JUFGJTIwQ29tZnlVSSUyMCVFNyU5QSU4NCVFNiU4OSVBOSVFNSVCMSU5NSVFNyVBRSVBMSVFNyU5MCU4NiVFNSU5OSVBOCVFNiU4RiU5MiVFNCVCQiVCNiVFRiVCQyU4QyVFNyU5NCVBOCVFNCVCQSU4RSVFNyVBRSU4MCVFNSU4QyU5NiVFOCU4NyVBQSVFNSVBRSU5QSVFNCVCOSU4OSVFOCU4QSU4MiVFNyU4MiVCOSVFMyU4MCU4MSVFNiVBOCVBMSVFNSU5RSU4QiVFNSU5MiU4QyVFNCVCRSU5RCVFOCVCNSU5NiVFOSVBMSVCOSVFNyU5QSU4NCVFNSVBRSU4OSVFOCVBMyU4NSVFNyVBRSVBMSVFNyU5MCU4NiVFMyU4MCU4MiUyMiUyQyUyMm1hcmtzJTIyJTNBJTVCJTVEJTdEJTVEJTdEJTVEJTJDJTIyY29udGVudFR5cGUlMjIlM0ElMjJjYW5namllLXRleHRibG9jayUyMiU3RCU1RCU3RA==" data-identifier-application__slash__x-doc-key="8K4nyeZ4kYD8VnLb" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;visibility: visible;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;moktnqce2mqipujm2n6&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;Linux 是目前全球服务器、云计算、容器环境中使用最广泛的操作系统内核，绝大多数主流 Linux 发行版（Ubuntu、Debian、RHEL、Amazon Linux、SUSE、Arch、Fedora 等）均基于其构建。&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJtb2t0bnFjZTJtcWlwdWptMm42JTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyTGludXglMjAlRTYlOTglQUYlRTclOUIlQUUlRTUlODklOEQlRTUlODUlQTglRTclOTAlODMlRTYlOUMlOEQlRTUlOEElQTElRTUlOTklQTglRTMlODAlODElRTQlQkElOTElRTglQUUlQTElRTclQUUlOTclRTMlODAlODElRTUlQUUlQjklRTUlOTklQTglRTclOEUlQUYlRTUlQTIlODMlRTQlQjglQUQlRTQlQkQlQkYlRTclOTQlQTglRTYlOUMlODAlRTUlQjklQkYlRTYlQjMlOUIlRTclOUElODQlRTYlOTMlOEQlRTQlQkQlOUMlRTclQjMlQkIlRTclQkIlOUYlRTUlODYlODUlRTYlQTAlQjglRUYlQkMlOEMlRTclQkIlOUQlRTUlQTQlQTclRTUlQTQlOUElRTYlOTUlQjAlRTQlQjglQkIlRTYlQjUlODElMjBMaW51eCUyMCVFNSU4RiU5MSVFOCVBMSU4QyVFNyU4OSU4OCVFRiVCQyU4OFVidW50dSVFMyU4MCU4MURlYmlhbiVFMyU4MCU4MVJIRUwlRTMlODAlODFBbWF6b24lMjBMaW51eCVFMyU4MCU4MVNVU0UlRTMlODAlODFBcmNoJUUzJTgwJTgxRmVkb3JhJTIwJUU3JUFEJTg5JUVGJUJDJTg5JUU1JTlEJTg3JUU1JTlGJUJBJUU0JUJBJThFJUU1JTg1JUI2JUU2JTlFJTg0JUU1JUJCJUJBJUUzJTgwJTgyJTIyJTJDJTIybWFya3MlMjIlM0ElNUIlNUQlN0QlNUQlN0QlNUQlMkMlMjJjb250ZW50VHlwZSUyMiUzQSUyMmNhbmdqaWUtdGV4dGJsb2NrJTIyJTdEJTVEJTdE" data-identifier-application__slash__x-doc-key="4j6OJ5jkkBNgDq3p" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;visibility: visible;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;visibility: visible;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">Linux 是目前全球服务器、云计算、容器环境中使用最广泛的操作系统内核，绝大多数主流 Linux 发行版（Ubuntu、Debian、RHEL、Amazon Linux、SUSE、Arch、Fedora 等）均基于其构建。</span></span></span></p></div></div></div><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;moktnqcel2bh4x2wtuq&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;2026 年 4 月 29 日，长亭安全应急响应中心监测到互联网公开披露了一个影响范围极广的Linux提权漏洞 CVE-2026-31431，命名为\&#34;Copy Fail\&#34;。该漏洞源于 Linux 内核加密子系统 &#34;]],[&#34;inlineCode&#34;,{&#34;uuid&#34;:&#34;moktnqcerm21o7twpn&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;authencesn&#34;]]],[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34; 模块中的一处逻辑缺陷，攻击者仅需本地普通用户权限，通过链式利用 AF_ALG 套接字与 &#34;]],[&#34;inlineCode&#34;,{&#34;uuid&#34;:&#34;moktnqcergh5ufd73h&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;splice()&#34;]]],[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34; 系统调用，即可向页缓存（page cache）写入任意内容，最终实现本地提权至 root。漏洞影响 2017 年至补丁发布前构建的几乎所有 Linux 内核版本，&#34;],[&#34;span&#34;,{&#34;bold&#34;:true,&#34;data-type&#34;:&#34;leaf&#34;},&#34;EXP 已公开&#34;],[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;，利用稳定性极高，建议受影响用户立即修复&#34;]]]]" data-identifier-application__slash__x-doc-key="4j6OJ5jkkBNgDq3p" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;visibility: visible;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;visibility: visible;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">2026 年 4 月 29 日，长亭安全应急响应中心监测到互联网公开披露了一个影响范围极广的Linux提权漏洞 CVE-2026-31431，命名为&#34;Copy Fail&#34;。该漏洞源于 Linux 内核加密子系统 </span></span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">authencesn</span></span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">模块中的一处逻辑缺陷，攻击者仅需本地普通用户权限，通过链式利用 AF_ALG 套接字与 </span></span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">splice()</span></span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">系统调用，即可向页缓存（page cache）写入任意内容，最终实现本地提权至 root。漏洞影响 2017 年至补丁发布前构建的几乎所有 Linux 内核版本，</span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">EXP 已公开</span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">，利用稳定性极高，建议受影响用户立即修复。</span></span></span></p></div></div></div></div></div></div></div></div><div data-role="title" data-tools="135编辑器" data-id="124637" data-color="#7ac259" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px auto;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;visibility: visible;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;flex-shrink: 0;display: flex;visibility: visible;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 10px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(122, 194, 89);text-align: left;visibility: visible;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20px;letter-spacing: 2px;color: rgb(31, 31, 31);visibility: visible;"><strong data-brushtype="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">漏洞描述</span></strong></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12px;color: rgb(166, 166, 166);text-align: left;visibility: visible;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 1px;background-color: rgba(152, 152, 152, 0.1);line-height: 1.58em;visibility: visible;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(152, 152, 152);visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">Description</span></span></span></p></div></div><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;flex-shrink: 0;display: flex;align-items: center;visibility: visible;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20px;letter-spacing: 1.5px;color: rgb(122, 194, 89);visibility: visible;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 24px;color: rgba(152, 152, 152, 0.2);visibility: visible;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">0</span></strong><strong data-original-title="" title="" data-num="2" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">1</span></strong></span></p></div></div></div></div><div data-role="paragraph" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: mp-quote, &#34;PingFang SC&#34;, -apple-system-font, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;visibility: visible;"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1329378339},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhbw6gwwf5hgshd51os&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;由于系统未对系统接口的响应进行合理的处理，导致该系统会泄漏已注册用户信息，攻击者可利用信息泄露漏洞获取注册用户的信息。另外由于系统使用了不当的算法设计，攻击者可模拟任意用户登录系统。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhbw6jvlp8ey3x5omd&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;对攻击者来说，这两个漏洞的利用无需认证和鉴权，可通过组合漏洞获取用户数据，登录后台。&#34;]]]]" data-identifier-application__slash__x-doc-key="LvBPlNWKY5PVndG8" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1121139987},[&#34;p&#34;,{&#34;uuid&#34;:&#34;limrxzplblycaec36z8&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;GeoServer在预览图层的时候，可以对图层进行数据过滤从而渲染出指定位置的图层。由于未对用户输入进行过滤，在使用需要以数据库作为数据存储的功能时，攻击者可以构造畸形的过滤语法，绕过GeoServer的词法解析从而造成SQL注入，获取服务器中的敏感信息，甚至可能获取数据库服务器权限。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;limlfrolcg1noaebcu8&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;经过深入分析，长亭应急响应实验室发现，默认情况下GeoServer内置图层并不会使用数据库作为存储方式，而是将数据存放在文件中，所以不受该漏洞的影响。而使用该系统创建自定义图层并使用外置数据库后，就会导致相应的功能存在SQL注入漏洞。&#34;]]]]" data-identifier-application__slash__x-doc-key="8K4ny9795WGpnLbj" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-identifier-application__slash__x-doc-key="r4mlQmEY28GMlxow" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);text-size-adjust: inherit;visibility: visible;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 24px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 16px;letter-spacing: 0.578px;text-align: left;color: rgb(0, 0, 0);visibility: visible;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 17px;visibility: visible;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(122, 194, 89);visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">漏洞成因</span></span></strong></span></p><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;moktnqcf5epebj18b5i&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;Linux 内核加密模块 &#34;]],[&#34;inlineCode&#34;,{&#34;uuid&#34;:&#34;moktnqcfs332twubgwp&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;authencesn&#34;]]],[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34; 在 2017 年引入了一处针对 AEAD（认证加密）操作的原地（in-place）优化，该优化导致在特定条件下，页缓存（page cache）中的只读页面可以被错误地放入可写目标散列表（scatterlist）。攻击者通过 AF_ALG 套接字暴露的内核加密 API，结合 &#34;]],[&#34;inlineCode&#34;,{&#34;uuid&#34;:&#34;moktnqcfvhuwr1g1uue&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;splice()&#34;]]],[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34; 系统调用，利用上述逻辑缺陷实现对 setuid 二进制文件（如 &#34;]],[&#34;inlineCode&#34;,{&#34;uuid&#34;:&#34;moktnqcfud7t8izqbd&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;/usr/bin/su&#34;]]],[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;）页缓存的 4 字节任意写入，从而篡改程序逻辑，获取 root shell。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;moktnqcfkha3r46b30b&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;整个利用过程为&#34;],[&#34;span&#34;,{&#34;bold&#34;:true,&#34;data-type&#34;:&#34;leaf&#34;},&#34;直线逻辑&#34;],[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;，无需竞争窗口（race window），无需内核特定偏移，无需预装任何特殊工具。&#34;]]]]" data-identifier-application__slash__x-doc-key="4j6OJ5jkkBNgDq3p" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">Linux 内核加密模块 </span></span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">authencesn</span></span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">在 2017 年引入了一处针对 AEAD（认证加密）操作的原地（in-place）优化，该优化导致在特定条件下，页缓存（page cache）中的只读页面可以被错误地放入可写目标散列表（scatterlist）。攻击者通过 AF_ALG 套接字暴露的内核加密 API，结合 </span></span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">splice()</span></span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">系统调用，利用上述逻辑缺陷实现对 setuid 二进制文件（如 </span></span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">/usr/bin/su</span></span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">）页缓存的 4 字节任意写入，从而篡改程序逻辑，获取 root shell。</span></span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">整个利用过程为</span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">直线逻辑</span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">，无需竞争窗口（race window），无需内核特定偏移，无需预装任何特殊工具。</span></span></span></p></div></div></div></div><div data-identifier-application__slash__x-doc-key="r4mlQmEY28GMlxow" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);text-size-adjust: inherit;"><h2 style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 20px 0px 24px;padding: 0px;outline: 0px;font-weight: 400;font-size: 17px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 0.578px;color: rgb(0, 0, 0);line-height: 14.45px;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(122, 194, 89);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.87em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞影响</span></span></strong></span></h2><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;m8priaprslu9x2ofe5b&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;bold&#34;:true,&#34;data-type&#34;:&#34;leaf&#34;},&#34;远程代码执行&#34;],[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;：攻击者可在服务器上执行任意系统命令，可能导致服务器被完全控制、数据泄露或业务系统沦陷。&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJtOHByaWFwcnNsdTl4Mm9mZTViJTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyJUU4JUJGJTlDJUU3JUE4JThCJUU0JUJCJUEzJUU3JUEwJTgxJUU2JTg5JUE3JUU4JUExJThDJTIyJTJDJTIybWFya3MlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMm1hcmslMjIlMkMlMjJ0eXBlJTIyJTNBJTIyYm9sZCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlN0QlNUQlN0QlMkMlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyJUVGJUJDJTlBJUU2JTk0JUJCJUU1JTg3JUJCJUU4JTgwJTg1JUU1JThGJUFGJUU1JTlDJUE4JUU2JTlDJThEJUU1JThBJUExJUU1JTk5JUE4JUU0JUI4JThBJUU2JTg5JUE3JUU4JUExJThDJUU0JUJCJUJCJUU2JTg0JThGJUU3JUIzJUJCJUU3JUJCJTlGJUU1JTkxJUJEJUU0JUJCJUE0JUVGJUJDJThDJUU1JThGJUFGJUU4JTgzJUJEJUU1JUFGJUJDJUU4JTg3JUI0JUU2JTlDJThEJUU1JThBJUExJUU1JTk5JUE4JUU4JUEyJUFCJUU1JUFFJThDJUU1JTg1JUE4JUU2JThFJUE3JUU1JTg4JUI2JUUzJTgwJTgxJUU2JTk1JUIwJUU2JThEJUFFJUU2JUIzJTg0JUU5JTlDJUIyJUU2JTg4JTk2JUU0JUI4JTlBJUU1JThBJUExJUU3JUIzJUJCJUU3JUJCJTlGJUU2JUIyJUE2JUU5JTk5JUI3JUUzJTgwJTgyJTIyJTJDJTIybWFya3MlMjIlM0ElNUIlNUQlN0QlNUQlN0QlNUQlMkMlMjJjb250ZW50VHlwZSUyMiUzQSUyMmNhbmdqaWUtdGV4dGJsb2NrJTIyJTdEJTVEJTdE" data-identifier-application__slash__x-doc-key="ABmOoWbjkxeDzOaw" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><p data-identifier-application__slash__x-doc-key="4j6OJ5jkkBNgDq3p" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.6em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">本地提权至 root</span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">：任意本地普通用户账户可无条件提权为 root。</span></span></span></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">容器逃逸</span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">：Kubernetes / 容器环境中，页缓存为宿主机共享，容器内攻击者可突破容器边界，危及宿主节点及同节点其他租户。</span></span></span></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">CI/CD 环境沦陷</span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">：GitHub Actions、GitLab Runner、Jenkins Agent 等执行不可信代码的 CI 环境，攻击者可通过恶意 PR 直接获取 Runner 宿主机的 root 权限。</span></span></span></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">云多租户环境</span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">：Notebook、Serverless、Agent 沙箱等执行用户代码的云服务，租户可提权为宿主机 root。</span></span></span></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">漏洞持续近十年</span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">：问题代码于 2017 年引入，此后所有 Linux 发行版均受影响。</span></span></span></p></li></ul></p></div><div data-identifier-application__slash__x-doc-key="r4mlQmEY28GMlxow" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);text-size-adjust: inherit;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 16px;letter-spacing: 0.578px;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 17px;letter-spacing: 0.578px;color: rgb(122, 194, 89);line-height: 1.82em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, system-ui, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.87em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">处置优先级：高</span></span></strong></p><div data-tools="135编辑器" data-id="142799" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;letter-spacing: 0.578px;color: rgb(0, 0, 0);font-family: mp-quote, &#34;PingFang SC&#34;, -apple-system-font, system-ui, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px auto;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;"><div data-width="100%" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 676px;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 5px 10px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div data-autoskip="1" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.75em;letter-spacing: 1.5px;font-size: 14px;color: rgb(51, 51, 51);"><div data-identifier-application__slash__x-doc-key="8K4nyR2daWX0qLbj" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(0, 0, 0);"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(38, 38, 38, 0.86);"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: left;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-weight: bold;">漏洞类型：</span><span textstyle="" style="font-weight: normal;">权限提升</span></span></span></span></span></p><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lwimwq8a5n1v73x221a&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;● 漏洞类型：目录遍历&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lwimwq8aiiblz5hww6&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;● 漏洞危害等级：中&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lwimwq8adn8we8t368w&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;● 权限认证要求：无需任何权限&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lwimwq8a2iqisx8i3r4&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;● 系统配置要求：默认配置可利用&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lwimwq8abf2z7210v3s&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;● 用户交互要求：无需用户交互&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lwimwq8bmbyjgppdj7&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;● 利用成熟度：POC/EXP已公开&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lwimwq8bxxufs939y1&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;● 批量可利用性：可使用通用 POC/EXP，批量检测/利用&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lwimwq8b94hfo6wrmi&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;● 修复复杂度：低，官方提供热修复方案&#34;]]]]" data-identifier-application__slash__x-doc-key="8K4nyRy9Bv1jqLbj" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-size-adjust: inherit;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(38, 38, 38, 0.86);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞危害等级：</span></span></strong><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">高</span></span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;line-height: 2em;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(38, 38, 38, 0.86);font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">触发方式：</span></span></strong><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(38, 38, 38, 0.86);font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">本地</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(38, 38, 38, 0.86);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">权限认证要求：</span></span></strong><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">普通用户权限</span></span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(38, 38, 38, 0.86);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">系统配置要求：</span></span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: mp-quote, &#34;PingFang SC&#34;, -apple-system-font, system-ui, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: left;line-height: 2em;caret-color: rgb(0, 0, 0);text-size-adjust: inherit;color: rgba(38, 38, 38, 0.86);font-size: 15px;">默认配置</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(38, 38, 38, 0.86);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">用户交互要求：</span></span></strong><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">无需用户交互</span></span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(38, 38, 38, 0.86);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">利用成熟度：</span></span></strong><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">EXP 已公开</span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">，732 字节，100% 稳定复现</span></span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;line-height: 2em;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(38, 38, 38, 0.86);font-size: 15px;line-height: 2em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">修复复杂度：</span></strong><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(38, 38, 38, 0.86);font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">低，升级内核或临时禁用 algif_aead 模块</span></span></p></div></div></div></div></div></div></div></div><div data-role="title" data-tools="135编辑器" data-id="124637" data-color="#7ac259" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;letter-spacing: 0.578px;color: rgb(0, 0, 0);border-width: 0px;border-style: none;border-color: initial;z-index: 0;max-width: 100%;max-inline-size: 100%;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px auto;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;max-width: 100%;max-inline-size: 100%;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;flex-shrink: 0;display: flex;max-width: 100%;max-inline-size: 100%;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 10px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;max-width: 100%;max-inline-size: 100%;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(122, 194, 89);text-align: left;max-width: 100%;max-inline-size: 100%;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;font-size: 20px;letter-spacing: 2px;color: rgb(31, 31, 31);max-width: 100%;max-inline-size: 100%;"><strong data-brushtype="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;max-width: 100%;max-inline-size: 100%;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">影响版本</span></strong></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12px;text-align: left;max-width: 100%;max-inline-size: 100%;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;letter-spacing: 1px;background-color: rgba(152, 152, 152, 0.1);max-width: 100%;max-inline-size: 100%;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;color: rgb(152, 152, 152);max-width: 100%;max-inline-size: 100%;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Affects</span></span></span></p></div></div><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;flex-shrink: 0;display: flex;align-items: center;max-width: 100%;max-inline-size: 100%;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 5px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20px;letter-spacing: 1.5px;color: rgb(122, 194, 89);max-width: 100%;max-inline-size: 100%;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;font-size: 24px;color: rgba(152, 152, 152, 0.2);max-width: 100%;max-inline-size: 100%;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;max-width: 100%;max-inline-size: 100%;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">02</span></strong></span></p></div></div></div><pre data-placeholder="翻译" dir="ltr" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;letter-spacing: 0.578px;color: rgb(0, 0, 0);max-width: 100%;max-inline-size: 100%;"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:398674325},[&#34;p&#34;,{&#34;uuid&#34;:&#34;liczeplu90nx1mmntt&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;&lt;&#34;],[&#34;span&#34;,{&#34;highlight&#34;:&#34;rgb(252, 252, 252)&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;RocketMQ 4.9.6&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;liczez2ip16agu1s6w&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;highlight&#34;:&#34;rgb(252, 252, 252)&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;&lt;RocketMQ 5.1.1&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJsaWN6ZXBsdTkwbngxbW1udHQlMjIlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIydGV4dCUyMiUyQyUyMmxlYXZlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIybGVhZiUyMiUyQyUyMnRleHQlMjIlM0ElMjIlM0MlMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCUyQyU3QiUyMmtsYXNzJTIyJTNBJTIybGVhZiUyMiUyQyUyMnRleHQlMjIlM0ElMjJSb2NrZXRNUSUyMDQuOS42JTIyJTJDJTIybWFya3MlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMm1hcmslMjIlMkMlMjJ0eXBlJTIyJTNBJTIyaGlnaGxpZ2h0JTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnZhbHVlJTIyJTNBJTIycmdiKDI1MiUyQyUyMDI1MiUyQyUyMDI1MiklMjIlN0QlN0QlNUQlN0QlNUQlN0QlNUQlN0QlMkMlN0IlMjJrbGFzcyUyMiUzQSUyMmJsb2NrJTIyJTJDJTIydHlwZSUyMiUzQSUyMnBhcmFncmFwaCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlMjJ1dWlkJTIyJTNBJTIybGljemV6MmlwMTZhZ3UxczZ3JTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyJTNDUm9ja2V0TVElMjA1LjEuMSUyMiUyQyUyMm1hcmtzJTIyJTNBJTVCJTdCJTIya2xhc3MlMjIlM0ElMjJtYXJrJTIyJTJDJTIydHlwZSUyMiUzQSUyMmhpZ2hsaWdodCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlMjJ2YWx1ZSUyMiUzQSUyMnJnYigyNTIlMkMlMjAyNTIlMkMlMjAyNTIpJTIyJTdEJTdEJTVEJTdEJTVEJTdEJTVEJTdEJTVEJTdE" data-identifier-application__slash__x-doc-key="XYvenvXNYavMOoyZ" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;max-width: 100%;max-inline-size: 100%;"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1121139987},[&#34;p&#34;,{&#34;uuid&#34;:&#34;liczeplu90nx1mmntt&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;&lt;&#34;],[&#34;span&#34;,{&#34;highlight&#34;:&#34;rgb(252, 252, 252)&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;RocketMQ 4.9.7&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;liczez2ip16agu1s6w&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;highlight&#34;:&#34;rgb(252, 252, 252)&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;&lt;RocketMQ 5.1.2&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJsaWN6ZXBsdTkwbngxbW1udHQlMjIlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIydGV4dCUyMiUyQyUyMmxlYXZlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIybGVhZiUyMiUyQyUyMnRleHQlMjIlM0ElMjIlM0MlMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCUyQyU3QiUyMmtsYXNzJTIyJTNBJTIybGVhZiUyMiUyQyUyMnRleHQlMjIlM0ElMjJSb2NrZXRNUSUyMDQuOS43JTIyJTJDJTIybWFya3MlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMm1hcmslMjIlMkMlMjJ0eXBlJTIyJTNBJTIyaGlnaGxpZ2h0JTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnZhbHVlJTIyJTNBJTIycmdiKDI1MiUyQyUyMDI1MiUyQyUyMDI1MiklMjIlN0QlN0QlNUQlN0QlNUQlN0QlNUQlN0QlMkMlN0IlMjJrbGFzcyUyMiUzQSUyMmJsb2NrJTIyJTJDJTIydHlwZSUyMiUzQSUyMnBhcmFncmFwaCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlMjJ1dWlkJTIyJTNBJTIybGljemV6MmlwMTZhZ3UxczZ3JTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyJTNDUm9ja2V0TVElMjA1LjEuMiUyMiUyQyUyMm1hcmtzJTIyJTNBJTVCJTdCJTIya2xhc3MlMjIlM0ElMjJtYXJrJTIyJTJDJTIydHlwZSUyMiUzQSUyMmhpZ2hsaWdodCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlMjJ2YWx1ZSUyMiUzQSUyMnJnYigyNTIlMkMlMjAyNTIlMkMlMjAyNTIpJTIyJTdEJTdEJTVEJTdEJTVEJTdEJTVEJTdEJTVEJTdE" data-identifier-application__slash__x-doc-key="r4mlQmEY28GMlxow" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;text-size-adjust: inherit;max-width: 100%;max-inline-size: 100%;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;mbt8tfhjyvdd4n80df&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;e-cology 9  补丁版本 &lt; v10.75&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJtYnQ4dGZoanl2ZGQ0bjgwZGYlMjIlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIydGV4dCUyMiUyQyUyMmxlYXZlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIybGVhZiUyMiUyQyUyMnRleHQlMjIlM0ElMjJlLWNvbG9neSUyMDklMjAlMjAlRTglQTElQTUlRTQlQjglODElRTclODklODglRTYlOUMlQUMlMjAlM0MlMjB2MTAuNzUlMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCU1RCU3RCU1RCUyQyUyMmNvbnRlbnRUeXBlJTIyJTNBJTIyY2FuZ2ppZS10ZXh0YmxvY2slMjIlN0QlNUQlN0Q=" data-identifier-application__slash__x-doc-key="8K4nyeZVamGgPnLb" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;mjpqnzgpyc8x3kpa6g&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;ComfyUI-Manager &lt; V3.38&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJtanBxbnpncHljOHgza3BhNmclMjIlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIydGV4dCUyMiUyQyUyMmxlYXZlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIybGVhZiUyMiUyQyUyMnRleHQlMjIlM0ElMjJDb21meVVJLU1hbmFnZXIlMjAlM0MlMjBWMy4zOCUyMiUyQyUyMm1hcmtzJTIyJTNBJTVCJTVEJTdEJTVEJTdEJTVEJTJDJTIyY29udGVudFR5cGUlMjIlM0ElMjJjYW5namllLXRleHRibG9jayUyMiU3RCU1RCU3RA==" data-identifier-application__slash__x-doc-key="8K4nyeZ4kYD8VnLb" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><div data-identifier-application__slash__x-doc-key="4j6OJ5jkkBNgDq3p" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;font-weight: normal;">2017 年至补丁发布前构建的所有 Linux 内核版本</span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">，涵盖：</span></span></span></p><table style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 0px 10px;padding: 0px;outline: 0px;border-collapse: collapse;display: table;width: 650px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;table-layout: fixed;"><tbody><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">发行版</span></span></span></p></td><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">受影响内核版本</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">Ubuntu 24.04 LTS</span></span></span></p></td><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">6.17.0-1007-aws 及以下</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">Amazon Linux 2023</span></span></span></p></td><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">6.18.8-9.213.amzn2023 及以下</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">RHEL 14.3</span></span></span></p></td><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">6.12.0-124.45.1.el10_1 及以下</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">SUSE 16</span></span></span></p></td><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">6.12.0-160000.9-default 及以下</span></span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">Debian / Arch / Fedora / Rocky / Alma / Oracle</span></span></span></p></td><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">同期内核版本均受影响</span></span></span></p></td></tr></tbody></table></div></div></div></div></div></pre><div data-role="title" data-tools="135编辑器" data-id="124637" data-color="#7ac259" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;letter-spacing: 0.578px;color: rgb(0, 0, 0);border-width: 0px;border-style: none;border-color: initial;z-index: 0;caret-color: rgb(255, 0, 0);background-color: rgb(255, 255, 255);font-family: 微软雅黑, &#34;Microsoft YaHei&#34;, sans-serif;max-width: 100%;max-inline-size: 100%;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px auto;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;max-width: 100%;max-inline-size: 100%;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;flex-shrink: 0;display: flex;max-width: 100%;max-inline-size: 100%;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 10px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;max-width: 100%;max-inline-size: 100%;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(122, 194, 89);text-align: left;max-width: 100%;max-inline-size: 100%;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;font-size: 20px;letter-spacing: 2px;color: rgb(31, 31, 31);max-width: 100%;max-inline-size: 100%;"><strong data-brushtype="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;max-width: 100%;max-inline-size: 100%;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">解决方案</span></strong></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12px;color: rgb(166, 166, 166);text-align: left;max-width: 100%;max-inline-size: 100%;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;letter-spacing: 1px;background-color: rgba(152, 152, 152, 0.1);max-width: 100%;max-inline-size: 100%;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;color: rgb(152, 152, 152);max-width: 100%;max-inline-size: 100%;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Solution</span></span></span></p></div></div><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;flex-shrink: 0;display: flex;align-items: center;max-width: 100%;max-inline-size: 100%;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 5px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20px;letter-spacing: 1.5px;color: rgb(122, 194, 89);max-width: 100%;max-inline-size: 100%;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;font-size: 24px;color: rgba(152, 152, 152, 0.2);max-width: 100%;max-inline-size: 100%;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">03</span></span></strong></p></div></div></div><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1329378339},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhbwfatppk7t6mctnlg&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;bold&#34;:false,&#34;sz&#34;:11,&#34;szUnit&#34;:&#34;pt&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;官方已经发布了安全补丁，在参考链接中安装官方提供的安全补丁 。&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJsaGJ3ZmF0cHBrN3Q2bWN0bmxnJTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyJUU1JUFFJTk4JUU2JTk2JUI5JUU1JUI3JUIyJUU3JUJCJThGJUU1JThGJTkxJUU1JUI4JTgzJUU0JUJBJTg2JUU1JUFFJTg5JUU1JTg1JUE4JUU4JUExJUE1JUU0JUI4JTgxJUVGJUJDJThDJUU1JTlDJUE4JUU1JThGJTgyJUU4JTgwJTgzJUU5JTkzJUJFJUU2JThFJUE1JUU0JUI4JUFEJUU1JUFFJTg5JUU4JUEzJTg1JUU1JUFFJTk4JUU2JTk2JUI5JUU2JThGJTkwJUU0JUJFJTlCJUU3JTlBJTg0JUU1JUFFJTg5JUU1JTg1JUE4JUU4JUExJUE1JUU0JUI4JTgxJTIwJUUzJTgwJTgyJTIyJTJDJTIybWFya3MlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMm1hcmslMjIlMkMlMjJ0eXBlJTIyJTNBJTIyYm9sZCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlMjJ2YWx1ZSUyMiUzQWZhbHNlJTdEJTdEJTJDJTdCJTIya2xhc3MlMjIlM0ElMjJtYXJrJTIyJTJDJTIydHlwZSUyMiUzQSUyMnN6JTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnZhbHVlJTIyJTNBMTElMkMlMjJzelVuaXQlMjIlM0ElMjJwdCUyMiU3RCU3RCU1RCU3RCU1RCU3RCU1RCU3RCU1RCU3RA==" data-identifier-application__slash__x-doc-key="LvBPlNWKY5PVndG8" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(255, 0, 0);background-color: rgb(255, 255, 255);font-family: 微软雅黑, &#34;Microsoft YaHei&#34;, sans-serif;max-width: 100%;max-inline-size: 100%;"><div data-identifier-application__slash__x-doc-key="XYvenvXNYavMOoyZ" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;max-width: 100%;max-inline-size: 100%;"><p data-identifier-application__slash__x-doc-key="XYvenvXNYavMOoyZ" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(0, 0, 0);font-size: 16px;letter-spacing: 0.578px;max-width: 100%;max-inline-size: 100%;"><h2 style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 25px 0px 0px;padding: 0px;outline: none 0px !important;font-weight: 400;font-size: 17px;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;line-height: 1.75em;max-width: 100%;max-inline-size: 100%;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;max-width: 100%;max-inline-size: 100%;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;color: rgb(122, 194, 89);max-width: 100%;max-inline-size: 100%;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">升级修复方案</span></span></strong></h2></p><div data-identifier-application__slash__x-doc-key="XYvenvXNYavMOoyZ" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(0, 0, 0);font-size: 16px;letter-spacing: 0.578px;max-width: 100%;max-inline-size: 100%;"><div data-identifier-application__slash__x-doc-key="8K4nyeZ4kYD8VnLb" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;mk52sesdaa7nj3y7rq9&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;升级 ComfyUI-Manager 至 V3.39.2 或更高版本\n&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJtazUyc2VzZGFhN25qM3k3cnE5JTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyJUU1JThEJTg3JUU3JUJBJUE3JTIwQ29tZnlVSS1NYW5hZ2VyJTIwJUU4JTg3JUIzJTIwVjMuMzkuMiUyMCVFNiU4OCU5NiVFNiU5QiVCNCVFOSVBQiU5OCVFNyU4OSU4OCVFNiU5QyVBQyU1Q24lMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCU1RCU3RCU1RCUyQyUyMmNvbnRlbnRUeXBlJTIyJTNBJTIyY2FuZ2ppZS10ZXh0YmxvY2slMjIlN0QlNUQlN0Q=" data-identifier-application__slash__x-doc-key="J9LnW6j7NLgGWlvD" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><div data-identifier-application__slash__x-doc-key="4j6OJ5jkkBNgDq3p" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">升级至包含 mainline commit </span></span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">a664bf3d603d</span></span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">的内核版本，各主流发行版正在陆续发布修复版本：</span></span></span></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="bash"><code><span leaf=""><span class="code-snippet__comment"># Ubuntu / Debian</span></span></code><br/><code><span leaf="">apt update &amp;&amp; apt upgrade linux-image-$(<span class="code-snippet__built_in">uname</span> -r)</span></code><br/><code><span leaf=""><span class="code-snippet__comment"># RHEL / CentOS / Rocky / Alma</span></span></code><br/><code><span leaf="">dnf update kernel</span></code><br/><code><span leaf=""><span class="code-snippet__comment"># Amazon Linux</span></span></code><br/><code><span leaf="">yum update kernel</span></code><br/><code><span leaf=""><span class="code-snippet__comment"># SUSE</span></span></code><br/><code><span leaf="">zypper update kernel-default</span></code><br/></pre></p><pre style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><code data-syntax="bash" data-theme="default" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></code></pre><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">升级后重启系统使新内核生效，并通过以下命令验证是否包含修复 commit：</span></span></span></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="bash"><code><span leaf="">grep -r <span class="code-snippet__string">&#34;a664bf3d603d&#34;</span> /proc/version 2&gt;/dev/null || <span class="code-snippet__built_in">uname</span> -r </span></code><br/><code><span leaf=""><span class="code-snippet__comment"># 验证是否包含修复commit或对比发行版官方公告中的修复版本号</span></span></code><br/></pre></p></div></div></div></div><p data-identifier-application__slash__x-doc-key="XYvenvXNYavMOoyZ" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(0, 0, 0);font-size: 16px;letter-spacing: 0.578px;max-width: 100%;max-inline-size: 100%;"><h2 style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 25px 0px 0px;padding: 0px;outline: none 0px !important;font-weight: 400;font-size: 17px;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;line-height: 1.75em;max-width: 100%;max-inline-size: 100%;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;max-width: 100%;max-inline-size: 100%;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;color: rgb(122, 194, 89);max-width: 100%;max-inline-size: 100%;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">临时缓解方案</span><div data-role="title" data-tools="135编辑器" data-id="124637" data-color="#7ac259" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(0, 0, 0);font-size: 16px;letter-spacing: 0.578px;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px auto;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;flex-shrink: 0;display: flex;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 10px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div data-identifier-application__slash__x-doc-key="4j6OJ5jkkBNgDq3p" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">禁用 </span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">algif_aead</span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">内核模块可阻断漏洞利用路径：</span></span></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="bash"><code><span leaf=""><span class="code-snippet__comment"># 永久禁用（重启后生效）</span></span></code><br/><code><span leaf=""><span class="code-snippet__built_in">echo</span> <span class="code-snippet__string">&#34;install algif_aead /bin/false&#34;</span> &gt; /etc/modprobe.d/disable-algif.conf</span></code><br/><code><span leaf=""><span class="code-snippet__comment"># 立即卸载（当前会话生效）</span></span></code><br/><code><span leaf="">rmmod algif_aead 2&gt;/dev/null || <span class="code-snippet__literal">true</span></span></code><br/></pre></p><pre style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><code data-syntax="bash" data-theme="default" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">禁用 algif_aead 的影响评估：</span></code></pre><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.6em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">不影响</span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：dm-crypt/LUKS、kTLS、IPsec/XFRM、OpenSSL/GnuTLS/NSS 默认构建、SSH、内核密钥环加密——这些组件直接使用内核加密 API，不经过 AF_ALG。</span></span></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">可能影响</span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：显式启用了 </span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">afalg</span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">引擎的 OpenSSL、部分嵌入式加密卸载路径、直接绑定 aead/skcipher/hash 套接字的应用。可通过 </span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">lsof | grep AF_ALG</span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">或 </span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">ss -xa</span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">检查当前系统是否有进程使用 AF_ALG。</span></span></p></li></ul></div></div></div></div></div><div data-role="title" data-tools="135编辑器" data-id="124637" data-color="#7ac259" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px auto;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;flex-shrink: 0;display: flex;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 10px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: left;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(31, 31, 31);font-size: 20px;letter-spacing: 2px;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞复现</span></strong></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(166, 166, 166);font-size: 12px;letter-spacing: 0.578px;text-align: left;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 1px;background-color: rgba(152, 152, 152, 0.1);"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(152, 152, 152);font-family: 微软雅黑, &#34;Microsoft YaHei&#34;, sans-serif;font-size: 12px;letter-spacing: 1px;text-align: left;caret-color: rgb(0, 0, 0);background-color: rgba(152, 152, 152, 0.1);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Reproduction</span></span></span></p></div></div><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(0, 0, 0);font-size: 16px;letter-spacing: 0.578px;flex-shrink: 0;display: flex;align-items: center;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20px;letter-spacing: 1.5px;color: rgb(122, 194, 89);"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 24px;color: rgba(152, 152, 152, 0.2);line-height: 1.58em;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">                                      04</span></strong></span></p></div></div></div><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px auto;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;"><div data-identifier-application__slash__x-doc-key="Pd6l2Z7BDGBpdl7M" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1329378339},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhbw6gwwf5hgshd51os&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;由于系统未对系统接口的响应进行合理的处理，导致该系统会泄漏已注册用户信息，攻击者可利用信息泄露漏洞获取注册用户的信息。另外由于系统使用了不当的算法设计，攻击者可模拟任意用户登录系统。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhbw6jvlp8ey3x5omd&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;对攻击者来说，这两个漏洞的利用无需认证和鉴权，可通过组合漏洞获取用户数据，登录后台。&#34;]]]]" data-identifier-application__slash__x-doc-key="LvBPlNWKY5PVndG8" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div data-identifier-application__slash__x-doc-key="r4mlQmEY28GMlxow" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);text-size-adjust: inherit;"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1329378339},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhbwfatppk7t6mctnlg&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;bold&#34;:false,&#34;sz&#34;:11,&#34;szUnit&#34;:&#34;pt&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;官方已经发布了安全补丁，在参考链接中安装官方提供的安全补丁 。&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJsaGJ3ZmF0cHBrN3Q2bWN0bmxnJTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyJUU1JUFFJTk4JUU2JTk2JUI5JUU1JUI3JUIyJUU3JUJCJThGJUU1JThGJTkxJUU1JUI4JTgzJUU0JUJBJTg2JUU1JUFFJTg5JUU1JTg1JUE4JUU4JUExJUE1JUU0JUI4JTgxJUVGJUJDJThDJUU1JTlDJUE4JUU1JThGJTgyJUU4JTgwJTgzJUU5JTkzJUJFJUU2JThFJUE1JUU0JUI4JUFEJUU1JUFFJTg5JUU4JUEzJTg1JUU1JUFFJTk4JUU2JTk2JUI5JUU2JThGJTkwJUU0JUJFJTlCJUU3JTlBJTg0JUU1JUFFJTg5JUU1JTg1JUE4JUU4JUExJUE1JUU0JUI4JTgxJTIwJUUzJTgwJTgyJTIyJTJDJTIybWFya3MlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMm1hcmslMjIlMkMlMjJ0eXBlJTIyJTNBJTIyYm9sZCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlMjJ2YWx1ZSUyMiUzQWZhbHNlJTdEJTdEJTJDJTdCJTIya2xhc3MlMjIlM0ElMjJtYXJrJTIyJTJDJTIydHlwZSUyMiUzQSUyMnN6JTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnZhbHVlJTIyJTNBMTElMkMlMjJzelVuaXQlMjIlM0ElMjJwdCUyMiU3RCU3RCU1RCU3RCU1RCU3RCU1RCU3RCU1RCU3RA==" data-identifier-application__slash__x-doc-key="LvBPlNWKY5PVndG8" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(255, 0, 0);background-color: rgb(255, 255, 255);font-family: 微软雅黑, &#34;Microsoft YaHei&#34;, sans-serif;max-width: 100%;max-inline-size: 100%;"><div data-identifier-application__slash__x-doc-key="8K4nyeZ4kYD8VnLb" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;moktpq4cbxckpaozgsj&#34;},[&#34;img&#34;,{&#34;uuid&#34;:&#34;moktpxnup9tfp77ez6&#34;,&#34;name&#34;:&#34;image.png&#34;,&#34;size&#34;:75023,&#34;width&#34;:748,&#34;height&#34;:97.21334734060412,&#34;src&#34;:&#34;https://alidocs.dingtalk.com/core/api/resources/img/5eecdaf48460cde535f74d49b61e25921d47922d6f9ccbf475b8339e1c4c2483811b562af39a8db88d68742cd653602a15464a86392b1bf5d440bf34ea485700f8dcf9d09e2f1e448c7be80d71ede7f6af903738e0fd21512d0017dab0a10e13?tmpCode=0e6503c6-90c0-483b-ac58-e336821db1d2&#34;,&#34;extraData&#34;:{&#34;resourceId&#34;:&#34;315dc409-5653-4754-a31b-b4c46edd745e&#34;,&#34;metaData&#34;:{&#34;size&#34;:75023,&#34;originWidth&#34;:831,&#34;originHeight&#34;:108,&#34;format&#34;:&#34;png&#34;,&#34;ratio&#34;:1}}},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;&#34;]]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJtb2t0cHE0Y2J4Y2twYW96Z3NqJTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmlubGluZSUyMiUyQyUyMnR5cGUlMjIlM0ElMjJpbWFnZSUyMiUyQyUyMmRhdGElMjIlM0ElN0IlMjJ1dWlkJTIyJTNBJTIybW9rdHB4bnVwOXRmcDc3ZXo2JTIyJTJDJTIybmFtZSUyMiUzQSUyMmltYWdlLnBuZyUyMiUyQyUyMnNpemUlMjIlM0E3NTAyMyUyQyUyMndpZHRoJTIyJTNBNzQ4JTJDJTIyaGVpZ2h0JTIyJTNBOTcuMjEzMzQ3MzQwNjA0MTIlMkMlMjJzcmMlMjIlM0ElMjJodHRwcyUzQSUyRiUyRmFsaWRvY3MuZGluZ3RhbGsuY29tJTJGY29yZSUyRmFwaSUyRnJlc291cmNlcyUyRmltZyUyRjVlZWNkYWY0ODQ2MGNkZTUzNWY3NGQ0OWI2MWUyNTkyMWQ0NzkyMmQ2ZjljY2JmNDc1YjgzMzllMWM0YzI0ODM4MTFiNTYyYWYzOWE4ZGI4OGQ2ODc0MmNkNjUzNjAyYTE1NDY0YTg2MzkyYjFiZjVkNDQwYmYzNGVhNDg1NzAwZjhkY2Y5ZDA5ZTJmMWU0NDhjN2JlODBkNzFlZGU3ZjZhZjkwMzczOGUwZmQyMTUxMmQwMDE3ZGFiMGExMGUxMyUzRnRtcENvZGUlM0QwZTY1MDNjNi05MGMwLTQ4M2ItYWM1OC1lMzM2ODIxZGIxZDIlMjIlMkMlMjJleHRyYURhdGElMjIlM0ElN0IlMjJyZXNvdXJjZUlkJTIyJTNBJTIyMzE1ZGM0MDktNTY1My00NzU0LWEzMWItYjRjNDZlZGQ3NDVlJTIyJTJDJTIybWV0YURhdGElMjIlM0ElN0IlMjJzaXplJTIyJTNBNzUwMjMlMkMlMjJvcmlnaW5XaWR0aCUyMiUzQTgzMSUyQyUyMm9yaWdpbkhlaWdodCUyMiUzQTEwOCUyQyUyMmZvcm1hdCUyMiUzQSUyMnBuZyUyMiUyQyUyMnJhdGlvJTIyJTNBMSU3RCU3RCU3RCUyQyUyMm5vZGVzJTIyJTNBJTVCJTdCJTIya2xhc3MlMjIlM0ElMjJ0ZXh0JTIyJTJDJTIybGVhdmVzJTIyJTNBJTVCJTdCJTIya2xhc3MlMjIlM0ElMjJsZWFmJTIyJTJDJTIydGV4dCUyMiUzQSUyMiUyMiUyQyUyMm1hcmtzJTIyJTNBJTVCJTVEJTdEJTVEJTdEJTVEJTdEJTVEJTJDJTIyY29udGVudFR5cGUlMjIlM0ElMjJjYW5namllLXRleHRibG9jayUyMiU3RCU1RCU3RA==" data-identifier-application__slash__x-doc-key="4j6OJ5jkkBNgDq3p" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><p nodeleaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: left;text-indent: 0px;"><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.1299638989169675" data-type="png" data-w="831" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: bottom;height: auto !important;width: 677px !important;visibility: visible !important;" data-imgfileid="100009561" src="https://wechat2rss.xlab.app/img-proxy/?k=d3e1e903&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEqS9GE77r0MHSF7iaZALdstlpTCF9cl4dMZrCbyiaoADZWicpibIImhBYbsUnJ3Etc2vrYa0w0FNZHjosqiaPQHpPUy2HFkyjic9RDicXNa4ccYyicg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D1"/></p></div></div></div></div></div><div data-role="title" data-tools="135编辑器" data-id="124637" data-color="#7ac259" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;letter-spacing: 0.578px;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px auto;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;flex-shrink: 0;display: flex;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 10px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(122, 194, 89);text-align: left;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20px;letter-spacing: 2px;color: rgb(31, 31, 31);"><strong data-brushtype="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">时间线</span></strong></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12px;color: rgb(166, 166, 166);text-align: left;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 1px;background-color: rgba(152, 152, 152, 0.1);"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(152, 152, 152);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Timeline</span></span></span></p></div></div><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;flex-shrink: 0;display: flex;align-items: center;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20px;letter-spacing: 1.5px;color: rgb(122, 194, 89);"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 24px;color: rgba(152, 152, 152, 0.2);line-height: 1.58em;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">05</span></strong></span></p></div></div></div><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:398674325},[&#34;p&#34;,{&#34;uuid&#34;:&#34;licztcywfgeia50hgau&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;5月23日 官方发布漏洞更新补丁版本&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;liczwtaewmcvwgfubl&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;5月24日 长亭应急响应实验室复现漏洞&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;liczxgtrqt1a8f2uca&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;5月30日 监测到POC已被小范围公开&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;liczyrvvhx91cimp5ko&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;6月1日 长亭发布应急响应通告&#34;]]]]" data-identifier-application__slash__x-doc-key="XYvenvXNYavMOoyZ" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;letter-spacing: 0.578px;"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1121139987},[&#34;p&#34;,{&#34;uuid&#34;:&#34;licztcywfgeia50hgau&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;7月12日 漏洞被公开披露[4]&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lk0k3n68fx3xyfk6eh&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;7月12日 长亭应急响应实验室漏洞分析与复现&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lk0k55pw2m215r3a86w&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;7月13日 长亭安全应急响应中心发布通告&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJsaWN6dGN5d2ZnZWlhNTBoZ2F1JTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyNyVFNiU5QyU4ODEyJUU2JTk3JUE1JTIwJUU2JUJDJThGJUU2JUI0JTlFJUU4JUEyJUFCJUU1JTg1JUFDJUU1JUJDJTgwJUU2JThBJUFCJUU5JTlDJUIyJTVCNCU1RCUyMiUyQyUyMm1hcmtzJTIyJTNBJTVCJTVEJTdEJTVEJTdEJTVEJTdEJTJDJTdCJTIya2xhc3MlMjIlM0ElMjJibG9jayUyMiUyQyUyMnR5cGUlMjIlM0ElMjJwYXJhZ3JhcGglMjIlMkMlMjJkYXRhJTIyJTNBJTdCJTIydXVpZCUyMiUzQSUyMmxrMGszbjY4ZngzeHlmazZlaCUyMiU3RCUyQyUyMm5vZGVzJTIyJTNBJTVCJTdCJTIya2xhc3MlMjIlM0ElMjJ0ZXh0JTIyJTJDJTIybGVhdmVzJTIyJTNBJTVCJTdCJTIya2xhc3MlMjIlM0ElMjJsZWFmJTIyJTJDJTIydGV4dCUyMiUzQSUyMjclRTYlOUMlODgxMiVFNiU5NyVBNSUyMCVFOSU5NSVCRiVFNCVCQSVBRCVFNSVCQSU5NCVFNiU4MCVBNSVFNSU5MyU4RCVFNSVCQSU5NCVFNSVBRSU5RSVFOSVBQSU4QyVFNSVBRSVBNCVFNiVCQyU4RiVFNiVCNCU5RSVFNSU4OCU4NiVFNiU5RSU5MCVFNCVCOCU4RSVFNSVBNCU4RCVFNyU4RSVCMCUyMiUyQyUyMm1hcmtzJTIyJTNBJTVCJTVEJTdEJTVEJTdEJTVEJTdEJTJDJTdCJTIya2xhc3MlMjIlM0ElMjJibG9jayUyMiUyQyUyMnR5cGUlMjIlM0ElMjJwYXJhZ3JhcGglMjIlMkMlMjJkYXRhJTIyJTNBJTdCJTIydXVpZCUyMiUzQSUyMmxrMGs1NXB3Mm0yMTVyM2E4NnclMjIlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIydGV4dCUyMiUyQyUyMmxlYXZlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIybGVhZiUyMiUyQyUyMnRleHQlMjIlM0ElMjI3JUU2JTlDJTg4MTMlRTYlOTclQTUlMjAlRTklOTUlQkYlRTQlQkElQUQlRTUlQUUlODklRTUlODUlQTglRTUlQkElOTQlRTYlODAlQTUlRTUlOTMlOEQlRTUlQkElOTQlRTQlQjglQUQlRTUlQkYlODMlRTUlOEYlOTElRTUlQjglODMlRTklODAlOUElRTUlOTElOEElMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCU1RCU3RCU1RCU3RCU1RCU3RA==" data-identifier-application__slash__x-doc-key="r4mlQmEY28GMlxow" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);text-size-adjust: inherit;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lpj9i8ax6llvk79gwia&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;雷池：已发布自定义规则支持该漏洞检测。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lpj9i9l4cpvexzah8vc&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;全悉：预计于2024.06.07发布升级包支持该漏洞检测。&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJscGo5aThheDZsbHZrNzlnd2lhJTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyJUU5JTlCJUI3JUU2JUIxJUEwJUVGJUJDJTlBJUU1JUI3JUIyJUU1JThGJTkxJUU1JUI4JTgzJUU4JTg3JUFBJUU1JUFFJTlBJUU0JUI5JTg5JUU4JUE3JTg0JUU1JTg4JTk5JUU2JTk0JUFGJUU2JThDJTgxJUU4JUFGJUE1JUU2JUJDJThGJUU2JUI0JTlFJUU2JUEzJTgwJUU2JUI1JThCJUUzJTgwJTgyJTIyJTJDJTIybWFya3MlMjIlM0ElNUIlNUQlN0QlNUQlN0QlNUQlN0QlMkMlN0IlMjJrbGFzcyUyMiUzQSUyMmJsb2NrJTIyJTJDJTIydHlwZSUyMiUzQSUyMnBhcmFncmFwaCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlMjJ1dWlkJTIyJTNBJTIybHBqOWk5bDRjcHZleHphaDh2YyUyMiU3RCUyQyUyMm5vZGVzJTIyJTNBJTVCJTdCJTIya2xhc3MlMjIlM0ElMjJ0ZXh0JTIyJTJDJTIybGVhdmVzJTIyJTNBJTVCJTdCJTIya2xhc3MlMjIlM0ElMjJsZWFmJTIyJTJDJTIydGV4dCUyMiUzQSUyMiVFNSU4NSVBOCVFNiU4MiU4OSVFRiVCQyU5QSVFOSVBMiU4NCVFOCVBRSVBMSVFNCVCQSU4RTIwMjQuMDYuMDclRTUlOEYlOTElRTUlQjglODMlRTUlOEQlODclRTclQkElQTclRTUlOEMlODUlRTYlOTQlQUYlRTYlOEMlODElRTglQUYlQTUlRTYlQkMlOEYlRTYlQjQlOUUlRTYlQTMlODAlRTYlQjUlOEIlRTMlODAlODIlMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCU1RCU3RCU1RCU3RCU1RCU3RA==" data-identifier-application__slash__x-doc-key="3BMqYaMEV896qwZL" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-size-adjust: inherit;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;licztcywfgeia50hgau&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;6月6日 官方发布漏洞公告&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lxec4knlucj95j2h0a&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;6月13日 互联网公开漏洞细节&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lk0k55pw2m215r3a86w&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;6月14日 长亭安全应急响应中心发布通告&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJsaWN6dGN5d2ZnZWlhNTBoZ2F1JTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyNiVFNiU5QyU4ODYlRTYlOTclQTUlMjAlRTUlQUUlOTglRTYlOTYlQjklRTUlOEYlOTElRTUlQjglODMlRTYlQkMlOEYlRTYlQjQlOUUlRTUlODUlQUMlRTUlOTElOEElMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCU1RCU3RCU1RCU3RCUyQyU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJseGVjNGtubHVjajk1ajJoMGElMjIlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIydGV4dCUyMiUyQyUyMmxlYXZlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIybGVhZiUyMiUyQyUyMnRleHQlMjIlM0ElMjI2JUU2JTlDJTg4MTMlRTYlOTclQTUlMjAlRTQlQkElOTIlRTglODElOTQlRTclQkQlOTElRTUlODUlQUMlRTUlQkMlODAlRTYlQkMlOEYlRTYlQjQlOUUlRTclQkIlODYlRTglOEElODIlMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCU1RCU3RCU1RCU3RCUyQyU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJsazBrNTVwdzJtMjE1cjNhODZ3JTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyNiVFNiU5QyU4ODE0JUU2JTk3JUE1JTIwJUU5JTk1JUJGJUU0JUJBJUFEJUU1JUFFJTg5JUU1JTg1JUE4JUU1JUJBJTk0JUU2JTgwJUE1JUU1JTkzJThEJUU1JUJBJTk0JUU0JUI4JUFEJUU1JUJGJTgzJUU1JThGJTkxJUU1JUI4JTgzJUU5JTgwJTlBJUU1JTkxJThBJTIyJTJDJTIybWFya3MlMjIlM0ElNUIlNUQlN0QlNUQlN0QlNUQlN0QlNUQlN0Q=" data-identifier-application__slash__x-doc-key="8K4nyRy9Bv1jqLbj" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-size-adjust: inherit;"><p data-identifier-application__slash__x-doc-key="4j6OJ5jkkBNgDq3p" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><table style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 0px 10px;padding: 0px;outline: 0px;border-collapse: collapse;display: table;width: 650px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;table-layout: fixed;"><tbody><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">时间</span></span></p></td><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">事件</span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">2026 年 3 月 23 日</span></span></p></td><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞报告至 Linux 内核安全团队</span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">2026 年 3 月 24 日</span></span></p></td><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">内核安全团队确认收到</span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">2026 年 3 月 25 日</span></span></p></td><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">补丁提出并完成审查</span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">2026 年 4 月 1 日</span></span></p></td><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">修复 commit </span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">a664bf3d603d</span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">合入 mainline</span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">2026 年 4 月 22 日</span></span></p></td><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">CVE-2026-31431 正式分配</span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">2026 年 4 月 29 日</span></span></p></td><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">公开披露，EXP 同步发布</span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">2026 年 4 月 30 日</span></span></p></td><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">长亭安全应急响应中心发布通告</span></p></td></tr></tbody></table></p></div></div></div></div></div></div></span></strong><div data-role="paragraph" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: normal;text-align: start;white-space: normal;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1329378339},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhbw6gwwf5hgshd51os&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;由于系统未对系统接口的响应进行合理的处理，导致该系统会泄漏已注册用户信息，攻击者可利用信息泄露漏洞获取注册用户的信息。另外由于系统使用了不当的算法设计，攻击者可模拟任意用户登录系统。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhbw6jvlp8ey3x5omd&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;对攻击者来说，这两个漏洞的利用无需认证和鉴权，可通过组合漏洞获取用户数据，登录后台。&#34;]]]]" data-identifier-application__slash__x-doc-key="LvBPlNWKY5PVndG8" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:398674325},[&#34;p&#34;,{&#34;spacing&#34;:{&#34;after&#34;:&#34;12pt&#34;,&#34;afterAutospacing&#34;:false,&#34;before&#34;:&#34;0pt&#34;,&#34;beforeAutospacing&#34;:false},&#34;uuid&#34;:&#34;lhsmfajr95jz91x7s4q&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;漏洞的官方描述为当RocketMQ多个组件暴露在外网，并且缺乏有效的身份认证机制，那么攻击者可以利用&#34;],[&#34;span&#34;,{&#34;highlight&#34;:&#34;rgb(252, 252, 252)&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;更新配置功能，以RocketMQ运行的系统用户身份执行命令。&#34;]]],[&#34;p&#34;,{&#34;spacing&#34;:{&#34;after&#34;:&#34;12pt&#34;,&#34;afterAutospacing&#34;:false,&#34;before&#34;:&#34;0pt&#34;,&#34;beforeAutospacing&#34;:false},&#34;uuid&#34;:&#34;licz6vm6uu9cyvgzbm&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;bold&#34;:false,&#34;sz&#34;:11,&#34;szUnit&#34;:&#34;pt&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;经过深入分析，长亭科技应急响应实验室发现，官方的漏洞描述存在不准确之处。实际上，只要能访问到Broker服务且该服务未开启身份认证，就可能实现远程命令执行，无需其他条件。&#34;]]]]" data-identifier-application__slash__x-doc-key="XYvenvXNYavMOoyZ" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1329378339},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhbwfatppk7t6mctnlg&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;bold&#34;:false,&#34;sz&#34;:11,&#34;szUnit&#34;:&#34;pt&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;官方已经发布了安全补丁，在参考链接中安装官方提供的安全补丁 。&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJsaGJ3ZmF0cHBrN3Q2bWN0bmxnJTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyJUU1JUFFJTk4JUU2JTk2JUI5JUU1JUI3JUIyJUU3JUJCJThGJUU1JThGJTkxJUU1JUI4JTgzJUU0JUJBJTg2JUU1JUFFJTg5JUU1JTg1JUE4JUU4JUExJUE1JUU0JUI4JTgxJUVGJUJDJThDJUU1JTlDJUE4JUU1JThGJTgyJUU4JTgwJTgzJUU5JTkzJUJFJUU2JThFJUE1JUU0JUI4JUFEJUU1JUFFJTg5JUU4JUEzJTg1JUU1JUFFJTk4JUU2JTk2JUI5JUU2JThGJTkwJUU0JUJFJTlCJUU3JTlBJTg0JUU1JUFFJTg5JUU1JTg1JUE4JUU4JUExJUE1JUU0JUI4JTgxJTIwJUUzJTgwJTgyJTIyJTJDJTIybWFya3MlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMm1hcmslMjIlMkMlMjJ0eXBlJTIyJTNBJTIyYm9sZCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlMjJ2YWx1ZSUyMiUzQWZhbHNlJTdEJTdEJTJDJTdCJTIya2xhc3MlMjIlM0ElMjJtYXJrJTIyJTJDJTIydHlwZSUyMiUzQSUyMnN6JTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnZhbHVlJTIyJTNBMTElMkMlMjJzelVuaXQlMjIlM0ElMjJwdCUyMiU3RCU3RCU1RCU3RCU1RCU3RCU1RCU3RCU1RCU3RA==" data-identifier-application__slash__x-doc-key="LvBPlNWKY5PVndG8" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: normal;text-align: start;white-space: normal;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);"><div data-autoskip="1" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 0px 16px;padding: 16px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: normal;overflow: auto;font-size: 15px;line-height: 1.45;border-radius: 3px;background-color: rgb(247, 247, 247);"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(31, 31, 31);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">参考资料：</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(31, 31, 31);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">[1].<a href="https://copy.fail/" target="_blank">https://copy.fail/</a></span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">[2].<a href="https://github.com/theori-io/copy-fail-CVE-2026-31431" target="_blank">https://github.com/theori-io/copy-fail-CVE-2026-31431</a></span></p></div></div></div></div></div></h2></p></div></div></div></div><div data-id="97137" data-tools="135编辑器" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px auto;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;justify-content: center;align-items: center;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 6px 12px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 1.5px;color: rgb(174, 225, 91);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20px;letter-spacing: 1px;color: rgb(122, 194, 89);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">长亭应急响应服务</span></span></strong></p></div><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: -16px 0px 0px;padding: 1em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-width: medium 2px 2px;border-style: none solid solid;border-color: currentcolor rgb(135, 226, 90) rgb(135, 226, 90);"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 20px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">全力进行产品升级</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">及时将风险提示预案发送给客户</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">检测业务是否受到此次漏洞影响</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">请联系长亭应急服务团队</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 5px 0px 25px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">7*24小时，守护您的安全</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 25px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">第一时间找到我们：</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">邮箱：support@chaitin.com</span></span></p></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=7cc7909a&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MzkzOTYzOQ%3D%3D%26mid%3D2247490029%26idx%3D1%26sn%3Dfc9c3feee41b708f86dab16be4154af5">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 30 Apr 2026 14:47:00 +0800</pubDate>
    </item>
    <item>
      <title>WAF 说绕也就绕了！</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MzkzOTYzOQ==&amp;mid=2247490025&amp;idx=1&amp;sn=88c1a4a606fe0fe514a82d0b60ced208</link>
      <description>WAF 说绕也就绕了！</description>
      <content:encoded><![CDATA[<p><span>长亭应急响应</span> <span>2026-04-28 16:43</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=12511599&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FeZOA7OiaVuZibcRdoRpCxIYFsgohlq1FSjKrpAh28liacVxImw42MK3iabOLxFy0QNggMibufeq5TicM6xjWDhaF9LmwwHHY4kzoR95sDZ4eryHqM%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>WAF 说绕也就绕了！</p>
  <plasmo-csui style="top: 0px !important;left: 0px !important;width: 0px !important;height: 0px !important;z-index: 2147483646 !important;overflow: visible !important;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(0, 0, 0);font-family: &#34;PingFang SC&#34;;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"></plasmo-csui><plasmo-csui style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(0, 0, 0);font-family: &#34;PingFang SC&#34;;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"></plasmo-csui><div data-role="outer" label="edit by 135editor" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: 默认字体;visibility: visible;"><div data-role="paragraph" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;letter-spacing: 0.578px;font-family: mp-quote, &#34;PingFang SC&#34;, -apple-system-font, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;visibility: visible;"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1329378339},[&#34;p&#34;,{},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;泛微协同管理应用平台（e-cology）是一款全面的企业管理平台。它具备多元化的功能，包括企业信息门户、知识文档管理、工作流程管理、人力资源管理、客户关系管理、项目管理、财务管理、资产管理、供应链管理以及数据中心等。这款平台有助于企业整合各种资源，包括管理、市场、销售、研发、人事和行政等各个领域。通过e-cology，这些资源可以在一个统一的平台上集成，并为用户提供统一的界面以方便操作和获取信息。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhbw00xpg3nfo1awkjt&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;近日，长亭应急团队监测到泛微发布了新的安全漏洞补丁修补了多个漏洞，其中有两个漏洞值得关注，分别是信息泄露和任意用户登录，组合起来可以获取应用系统的任意用户权限。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhbw2mh45202sva9ihn&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;经过分析漏洞后，发现公网仍有较多系统未修复漏洞，长亭应急团队根据该漏洞的原理，编写了X-RAY远程检测工具和牧云本地检测工具供大家下载使用，同时在文章中提供了排查该资产的方式。&#34;]]]]" data-identifier-application__slash__x-doc-key="LvBPlNWKY5PVndG8" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1121139987},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhsqy1c3vobicv0i3er&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;畅捷通T+是一款企业资源规划（ERP）软件，主要功能包括财务管理、销售管理、采购管理以及库存管理等，助力企业实现业务流程自动化。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;limjtprko8zpm2fo8pl&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;近期，长亭科技监测到微步在线发布一则漏洞通告，声明畅捷通T+发布新版本修复了一个RCE漏洞。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;limrdh63y857qallxw&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;长亭应急团队经过漏洞分析后，发现该漏洞类型为SQL注入，可利用其实现RCE。公网仍有较多相关系统尚未修复漏洞。应急团队根据该漏洞的原理，编写了X-POC远程检测工具和牧云本地检测工具，目前工具已向公众开放下载使用。&#34;]]]]" data-identifier-application__slash__x-doc-key="2M9qPJ1xzP43l015" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1121139987},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhsqy1c3vobicv0i3er&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;Openfire（前身为Wildfire）是一个基于XMPP（Extensible Messaging and Presence Protocol，可扩展消息处理和呈现协议）的开源实时协作服务器，同时提供了Web管理界面。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;limjtprko8zpm2fo8pl&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;近期，长亭科技监测到Openfire发布新版本修复了一个漏洞。长亭应急团队经过漏洞分析后，发现该漏洞类型为后台权限绕过，可利用其实现RCE。公网仍有较多相关系统尚未修复漏洞。应急团队根据该漏洞的原理，编写了X-POC远程检测工具和牧云本地检测工具，目前工具已向公众开放下载使用。&#34;]]]]" data-identifier-application__slash__x-doc-key="AJdl6mZR72PKOke1" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1121139987},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhsqy1c3vobicv0i3er&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;Apache RocketMQ是一款开源的分布式消息和流处理平台，提供了高效、可靠、可扩展的低延迟消息和流数据处理能力，广泛用于异步通信、应用解耦、系统集成以及大数据、实时计算等场景。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;licys4nlk4z44589ypo&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;近期，长亭科技监测到RocketMQ发布新版本修复了一个远程命令执行漏洞（CVE-2023-37582）。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;licytz2meuxzh6wlgn&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;经过分析漏洞后，发现公网仍有较多系统未修复漏洞。应急团队根据该漏洞的原理，已经编写了X-POC远程检测工具和牧云本地检测工具&#34;],[&#34;span&#34;,{&#34;bold&#34;:false,&#34;sz&#34;:11,&#34;szUnit&#34;:&#34;pt&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;，并已向公众开放下载使用。&#34;]]]]" data-identifier-application__slash__x-doc-key="r4mlQmEY28GMlxow" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);text-size-adjust: inherit;visibility: visible;"><p nodeleaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;visibility: visible;"><img alt="图片" class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100009553" data-ratio="0.5625" data-s="300,640" type="block" data-type="png" data-w="1600" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: bottom;height: auto !important;visibility: visible !important;width: 676.992px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=a4fe2bb9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEqS9GE77r0PbEQwUBshWpicJzE6HDKaZ2shqdLdVncGYMqZbsWJ1NI02FXbWUcGLNawRzrcNciaTfwnOcHpcoc9YEGlIYGr264sImTR5OPH14%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D0"/></p><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;fonts&#34;:{&#34;hint&#34;:&#34;eastAsia&#34;},&#34;data-type&#34;:&#34;leaf&#34;},&#34;瑞&#34;],[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;友天翼应用虚拟化系统是西安瑞友信息技术资讯有限公司研发的具有自主知识产权，基于服务器计算架构的应用虚拟化平台。它将用户各种应用软件集中部署在瑞友天翼服务器(群)上，客户端通过WEB即可快速安全的访问经服务器上授权的应用软件，实现集中应用、远程接入、协同办公等。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lp0xhb0ekky9vvtxiv&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;sz&#34;:11,&#34;szUnit&#34;:&#34;pt&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;2024年5月，互联网公开了一个&#34;],[&#34;span&#34;,{&#34;fonts&#34;:{&#34;hint&#34;:&#34;eastAsia&#34;},&#34;data-type&#34;:&#34;leaf&#34;},&#34;瑞&#34;],[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;友天翼应用虚拟化系统&#34;],[&#34;span&#34;,{&#34;sz&#34;:11,&#34;szUnit&#34;:&#34;pt&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;的SQL注入漏洞。鉴于该漏洞无前置条件，易于利用，且默认情况下可直接获取操作系统权限，建议所有使用该系统的企业尽快进行升级修复，以确保系统安全。&#34;]]]]" data-identifier-application__slash__x-doc-key="4jKqmVWA95GDOw19" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-size-adjust: inherit;visibility: visible;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lw0h0ayp6j8mmfkcsxa&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;fonts&#34;:{&#34;hint&#34;:&#34;eastAsia&#34;},&#34;data-type&#34;:&#34;leaf&#34;},&#34;PHP-CGI 是一种用于在 Web 服务器上运行 PHP 脚本的接口，通过 CGI（公共网关接口）将 PHP 解释器与 Web 服务器连接。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lp0xhb0ekky9vvtxiv&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;2024年6月，PHP官方发布新版本，修复了 &#34;],[&#34;span&#34;,{&#34;sz&#34;:11,&#34;szUnit&#34;:&#34;pt&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;PHP-CGI &#34;],[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;中一个远程代码执行漏洞。&#34;],[&#34;span&#34;,{&#34;sz&#34;:11,&#34;szUnit&#34;:&#34;pt&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;鉴于该漏洞无前置条件，易于利用，且默认情况下可获取操作系统权限，建议所有使用受影响版本的企业尽快升级修复，以确保安全。&#34;]]]]" data-identifier-application__slash__x-doc-key="3BMqYaMEV896qwZL" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-size-adjust: inherit;visibility: visible;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;liy8sjqqhpyk6m030b9&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;Serv-U 是 SolarWinds 公司推出的FTP服务器软件，提供文件传输服务，支持多种协议（FTP、FTPS、SFTP），具有用户管理、文件权限控制等功能，适用于企业级文件传输解决方案。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lo5ajwxivf4py2sbk1f&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;2024年6月，Serv-U 官方 SolarWinds 发布了新补丁，修复了一处目录遍历致文件读取漏洞（CVE-2024-28995）。经分析，该漏洞可以通过特定的路径请求来未授权访问系统文件，进而可能导致敏感信息泄露。该漏洞无前置条件且利用简单，建议受影响的客户尽快修复漏洞。&#34;]]]]" data-identifier-application__slash__x-doc-key="8K4nyRy9Bv1jqLbj" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-size-adjust: inherit;visibility: visible;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhsqy1c3vobicv0i3er&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;sz&#34;:10.5,&#34;szUnit&#34;:&#34;pt&#34;,&#34;color&#34;:&#34;rgba(0, 0, 0, 0.87)&#34;,&#34;spacing&#34;:0.049245,&#34;data-type&#34;:&#34;leaf&#34;},&#34;Gogs (Go Git Service) 是一款基于 Go 语言开发的开源 Git 托管平台，采用 MIT 许可证，提供代码托管、Issue 跟踪、权限管理和 Webhook 等功能。&#34;]]],[&#34;p&#34;,{&#34;jc&#34;:&#34;left&#34;,&#34;ind&#34;:{},&#34;spacing&#34;:{},&#34;uuid&#34;:&#34;lyiiqr1cqx6q84a8wmd&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;spacing&#34;:0.21675,&#34;data-type&#34;:&#34;leaf&#34;},&#34;2025年6月，&#34;],[&#34;span&#34;,{&#34;sz&#34;:10.5,&#34;szUnit&#34;:&#34;pt&#34;,&#34;color&#34;:&#34;rgba(0, 0, 0, 0.87)&#34;,&#34;spacing&#34;:0.049245,&#34;data-type&#34;:&#34;leaf&#34;},&#34;Gogs发布&#34;],[&#34;span&#34;,{&#34;spacing&#34;:0.21675,&#34;data-type&#34;:&#34;leaf&#34;},&#34;新版本，修复了一处命令注入漏洞。经分析，拥有用户权限的攻击者可利用该漏洞执行任意系统命令，利用难度较低，建议受影响的用户尽快修复。&#34;]]]]" data-identifier-application__slash__x-doc-key="ABmOoWbjkxeDzOaw" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;visibility: visible;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhsqy1c3vobicv0i3er&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;ComfyUI 是一款流行的基于节点的 Stable Diffusion 图形用户界面，广泛应用于 AI 图像生成工作流的构建和执行。ComfyUI-Manager 是 ComfyUI 的扩展管理器插件，用于简化自定义节点、模型和依赖项的安装管理。&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJsaHNxeTFjM3ZvYmljdjBpM2VyJTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyQ29tZnlVSSUyMCVFNiU5OCVBRiVFNCVCOCU4MCVFNiVBQyVCRSVFNiVCNSU4MSVFOCVBMSU4QyVFNyU5QSU4NCVFNSU5RiVCQSVFNCVCQSU4RSVFOCU4QSU4MiVFNyU4MiVCOSVFNyU5QSU4NCUyMFN0YWJsZSUyMERpZmZ1c2lvbiUyMCVFNSU5QiVCRSVFNSVCRCVBMiVFNyU5NCVBOCVFNiU4OCVCNyVFNyU5NSU4QyVFOSU5RCVBMiVFRiVCQyU4QyVFNSVCOSVCRiVFNiVCMyU5QiVFNSVCQSU5NCVFNyU5NCVBOCVFNCVCQSU4RSUyMEFJJTIwJUU1JTlCJUJFJUU1JTgzJThGJUU3JTk0JTlGJUU2JTg4JTkwJUU1JUI3JUE1JUU0JUJEJTlDJUU2JUI1JTgxJUU3JTlBJTg0JUU2JTlFJTg0JUU1JUJCJUJBJUU1JTkyJThDJUU2JTg5JUE3JUU4JUExJThDJUUzJTgwJTgyQ29tZnlVSS1NYW5hZ2VyJTIwJUU2JTk4JUFGJTIwQ29tZnlVSSUyMCVFNyU5QSU4NCVFNiU4OSVBOSVFNSVCMSU5NSVFNyVBRSVBMSVFNyU5MCU4NiVFNSU5OSVBOCVFNiU4RiU5MiVFNCVCQiVCNiVFRiVCQyU4QyVFNyU5NCVBOCVFNCVCQSU4RSVFNyVBRSU4MCVFNSU4QyU5NiVFOCU4NyVBQSVFNSVBRSU5QSVFNCVCOSU4OSVFOCU4QSU4MiVFNyU4MiVCOSVFMyU4MCU4MSVFNiVBOCVBMSVFNSU5RSU4QiVFNSU5MiU4QyVFNCVCRSU5RCVFOCVCNSU5NiVFOSVBMSVCOSVFNyU5QSU4NCVFNSVBRSU4OSVFOCVBMyU4NSVFNyVBRSVBMSVFNyU5MCU4NiVFMyU4MCU4MiUyMiUyQyUyMm1hcmtzJTIyJTNBJTVCJTVEJTdEJTVEJTdEJTVEJTJDJTIyY29udGVudFR5cGUlMjIlM0ElMjJjYW5namllLXRleHRibG9jayUyMiU3RCU1RCU3RA==" data-identifier-application__slash__x-doc-key="8K4nyeZ4kYD8VnLb" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;visibility: visible;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;moi8quuqzn8rktw9xvp&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;Java 是目前企业级应用中最广泛使用的编程语言之一，其生态内的 Spring、Tomcat、Jackson、fastjson 等框架和组件被全球数以亿计的系统所依赖。2026 年 4 月，在 Black Hat Asia 2026 大会上，安全研究员 Zhihui Chen（1ue）与安全研究员 Xinyu Bai（浅蓝）发表了题为《Cast Attack: A New Threat Posed by Ghost Bits in Java》的研究成果&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJtb2k4cXV1cXpuOHJrdHc5eHZwJTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIySmF2YSUyMCVFNiU5OCVBRiVFNyU5QiVBRSVFNSU4OSU4RCVFNCVCQyU4MSVFNCVCOCU5QSVFNyVCQSVBNyVFNSVCQSU5NCVFNyU5NCVBOCVFNCVCOCVBRCVFNiU5QyU4MCVFNSVCOSVCRiVFNiVCMyU5QiVFNCVCRCVCRiVFNyU5NCVBOCVFNyU5QSU4NCVFNyVCQyU5NiVFNyVBOCU4QiVFOCVBRiVBRCVFOCVBOCU4MCVFNCVCOSU4QiVFNCVCOCU4MCVFRiVCQyU4QyVFNSU4NSVCNiVFNyU5NCU5RiVFNiU4MCU4MSVFNSU4NiU4NSVFNyU5QSU4NCUyMFNwcmluZyVFMyU4MCU4MVRvbWNhdCVFMyU4MCU4MUphY2tzb24lRTMlODAlODFmYXN0anNvbiUyMCVFNyVBRCU4OSVFNiVBMSU4NiVFNiU5RSVCNiVFNSU5MiU4QyVFNyVCQiU4NCVFNCVCQiVCNiVFOCVBMiVBQiVFNSU4NSVBOCVFNyU5MCU4MyVFNiU5NSVCMCVFNCVCQiVBNSVFNCVCQSVCRiVFOCVBRSVBMSVFNyU5QSU4NCVFNyVCMyVCQiVFNyVCQiU5RiVFNiU4OSU4MCVFNCVCRSU5RCVFOCVCNSU5NiVFMyU4MCU4MjIwMjYlMjAlRTUlQjklQjQlMjA0JTIwJUU2JTlDJTg4JUVGJUJDJThDJUU1JTlDJUE4JTIwQmxhY2slMjBIYXQlMjBBc2lhJTIwMjAyNiUyMCVFNSVBNCVBNyVFNCVCQyU5QSVFNCVCOCU4QSVFRiVCQyU4QyVFNSVBRSU4OSVFNSU4NSVBOCVFNyVBMCU5NCVFNyVBOSVCNiVFNSU5MSU5OCUyMFpoaWh1aSUyMENoZW4lRUYlQkMlODgxdWUlRUYlQkMlODklRTQlQjglOEUlRTUlQUUlODklRTUlODUlQTglRTclQTAlOTQlRTclQTklQjYlRTUlOTElOTglMjBYaW55dSUyMEJhaSVFRiVCQyU4OCVFNiVCNSU4NSVFOCU5MyU5RCVFRiVCQyU4OSVFNSU4RiU5MSVFOCVBMSVBOCVFNCVCQSU4NiVFOSVBMiU5OCVFNCVCOCVCQSVFMyU4MCU4QUNhc3QlMjBBdHRhY2slM0ElMjBBJTIwTmV3JTIwVGhyZWF0JTIwUG9zZWQlMjBieSUyMEdob3N0JTIwQml0cyUyMGluJTIwSmF2YSVFMyU4MCU4QiVFNyU5QSU4NCVFNyVBMCU5NCVFNyVBOSVCNiVFNiU4OCU5MCVFNiU5RSU5QyUyMiUyQyUyMm1hcmtzJTIyJTNBJTVCJTVEJTdEJTVEJTdEJTVEJTJDJTIyY29udGVudFR5cGUlMjIlM0ElMjJjYW5namllLXRleHRibG9jayUyMiU3RCU1RCU3RA==" data-identifier-application__slash__x-doc-key="v9kqDejJogbrpOVx" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;visibility: visible;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;visibility: visible;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">Java 是目前企业级应用中最广泛使用的编程语言之一，其生态内的 Spring、Tomcat、Jackson、fastjson 等框架和组件被全球数以亿计的系统所依赖。2026 年 4 月，在 Black Hat Asia 2026 大会上，安全研究员 Zhihui Chen（1ue）与安全研究员 Xinyu Bai（浅蓝）发表了题为《Cast Attack: A New Threat Posed by Ghost Bits in Java》的研究成果。</span></span></span></p></div></div></div><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">该研究揭示了 Java 生态中一个系统性、长期被忽视的底层编码缺陷——&#34;Ghost Bits（幽灵比特位）&#34;，并证明攻击者可利用该缺陷对 WAF/IDS 等安全设备实现全面绕过，进而触发 SQL 注入、反序列化 RCE、文件上传、SMTP 注入、请求走私等多种高危攻击链。漏洞影响范围覆盖 Java 主流框架与中间件，利用门槛低，建议相关用户高度重视并尽快完成自查修复。</span></span></p></div></div></div></div></div></div></div><div data-role="title" data-tools="135编辑器" data-id="124637" data-color="#7ac259" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px auto;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;visibility: visible;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;flex-shrink: 0;display: flex;visibility: visible;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 10px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(122, 194, 89);text-align: left;visibility: visible;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20px;letter-spacing: 2px;color: rgb(31, 31, 31);visibility: visible;"><strong data-brushtype="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">攻击描述</span></strong></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12px;color: rgb(166, 166, 166);text-align: left;visibility: visible;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 1px;background-color: rgba(152, 152, 152, 0.1);line-height: 1.58em;visibility: visible;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(152, 152, 152);visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">Description</span></span></span></p></div></div><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;flex-shrink: 0;display: flex;align-items: center;visibility: visible;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20px;letter-spacing: 1.5px;color: rgb(122, 194, 89);visibility: visible;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 24px;color: rgba(152, 152, 152, 0.2);visibility: visible;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">0</span></strong><strong data-original-title="" title="" data-num="2" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">1</span></strong></span></p></div></div></div></div><div data-role="paragraph" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: mp-quote, &#34;PingFang SC&#34;, -apple-system-font, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;visibility: visible;"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1329378339},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhbw6gwwf5hgshd51os&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;由于系统未对系统接口的响应进行合理的处理，导致该系统会泄漏已注册用户信息，攻击者可利用信息泄露漏洞获取注册用户的信息。另外由于系统使用了不当的算法设计，攻击者可模拟任意用户登录系统。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhbw6jvlp8ey3x5omd&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;对攻击者来说，这两个漏洞的利用无需认证和鉴权，可通过组合漏洞获取用户数据，登录后台。&#34;]]]]" data-identifier-application__slash__x-doc-key="LvBPlNWKY5PVndG8" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1121139987},[&#34;p&#34;,{&#34;uuid&#34;:&#34;limrxzplblycaec36z8&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;GeoServer在预览图层的时候，可以对图层进行数据过滤从而渲染出指定位置的图层。由于未对用户输入进行过滤，在使用需要以数据库作为数据存储的功能时，攻击者可以构造畸形的过滤语法，绕过GeoServer的词法解析从而造成SQL注入，获取服务器中的敏感信息，甚至可能获取数据库服务器权限。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;limlfrolcg1noaebcu8&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;经过深入分析，长亭应急响应实验室发现，默认情况下GeoServer内置图层并不会使用数据库作为存储方式，而是将数据存放在文件中，所以不受该漏洞的影响。而使用该系统创建自定义图层并使用外置数据库后，就会导致相应的功能存在SQL注入漏洞。&#34;]]]]" data-identifier-application__slash__x-doc-key="8K4ny9795WGpnLbj" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-identifier-application__slash__x-doc-key="r4mlQmEY28GMlxow" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);text-size-adjust: inherit;visibility: visible;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 24px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 16px;letter-spacing: 0.578px;text-align: left;color: rgb(0, 0, 0);visibility: visible;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 17px;visibility: visible;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(122, 194, 89);visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">缺陷成因</span></span></strong></span></p><div data-identifier-application__slash__x-doc-key="v9kqDejJogbrpOVx" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;visibility: visible;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;visibility: visible;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">Java 的 </span></span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">char</span></span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">类型为 16 位（2 字节），而 </span></span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">byte</span></span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">类型仅为 8 位（1 字节）。当 Java 代码通过 </span></span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">(byte)ch</span></span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">、</span></span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">ch &amp; 0xFF</span></span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">、</span></span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">baos.write(ch)</span></span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">、</span></span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">DataOutputStream</span><a class="wx_topic_link" topic-id="moibif6k-e5gv7h" style="color: #576B95 !important;" data-topic="1" data-recommend=""><span textstyle="" style="font-size: 15px;">#writeBytes</span></a><span textstyle="" style="font-size: 15px;">()</span></span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">等方式将 </span></span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">char</span></span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">转换为 </span></span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">byte</span></span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">时，高 8 位会被</span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">静默丢弃</span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">，只保留低 8 位，这一丢失的高位数据即被称为&#34;幽灵比特位（Ghost Bits）&#34;。</span></span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">以汉字「爻」（U+2F58）为例：</span></span></span></p></div><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="cs"><code><span leaf="">爻  →  U+<span class="code-snippet__number">2F</span>58  →  二进制：<span class="code-snippet__number">00101111</span> | <span class="code-snippet__number">00111010</span></span></code><br/><code><span leaf="">(<span class="code-snippet__built_in">byte</span>) 转换后：高 <span class="code-snippet__number">8</span> 位 <span class="code-snippet__number">0x2F</span> 丢弃，低 <span class="code-snippet__number">8</span> 位 <span class="code-snippet__number">0x3A</span> → <span class="code-snippet__string">&#39;X&#39;</span></span></code><br/></pre></p><div data-identifier-application__slash__x-doc-key="v9kqDejJogbrpOVx" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">攻击者可利用这一特性，将攻击 Payload 中的关键 ASCII 字符替换为经过精心选取的 Unicode 字符（其低 8 位与原字符一致），使 WAF 看到的是无意义的 Unicode 字符序列，而后端 Java 服务解码时高位截断还原为原始攻击载荷，从而</span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">绕过基于字符串特征的安全检测</span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">。</span></span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">研究人员在 GitHub 上搜索 Java 代码中典型的 Ghost Bits 写法（</span></span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">(byte)ch</span></span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">、</span></span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">ch &amp; 0xff</span></span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">、</span></span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">baos.write(ch)</span></span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">、</span></span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">writeBytes(...)</span></span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">），</span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">命中结果超过 8,100 条</span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">，证明此类缺陷在 Java 生态中极为普遍。</span></span></span></p></div></div></div></div><div data-identifier-application__slash__x-doc-key="r4mlQmEY28GMlxow" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);text-size-adjust: inherit;"><h2 style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 20px 0px 24px;padding: 0px;outline: 0px;font-weight: 400;font-size: 17px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 0.578px;color: rgb(0, 0, 0);line-height: 14.45px;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(122, 194, 89);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.87em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">造成的影响</span></span></strong></span></h2><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;m8priaprslu9x2ofe5b&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;bold&#34;:true,&#34;data-type&#34;:&#34;leaf&#34;},&#34;远程代码执行&#34;],[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;：攻击者可在服务器上执行任意系统命令，可能导致服务器被完全控制、数据泄露或业务系统沦陷。&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJtOHByaWFwcnNsdTl4Mm9mZTViJTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyJUU4JUJGJTlDJUU3JUE4JThCJUU0JUJCJUEzJUU3JUEwJTgxJUU2JTg5JUE3JUU4JUExJThDJTIyJTJDJTIybWFya3MlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMm1hcmslMjIlMkMlMjJ0eXBlJTIyJTNBJTIyYm9sZCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlN0QlNUQlN0QlMkMlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyJUVGJUJDJTlBJUU2JTk0JUJCJUU1JTg3JUJCJUU4JTgwJTg1JUU1JThGJUFGJUU1JTlDJUE4JUU2JTlDJThEJUU1JThBJUExJUU1JTk5JUE4JUU0JUI4JThBJUU2JTg5JUE3JUU4JUExJThDJUU0JUJCJUJCJUU2JTg0JThGJUU3JUIzJUJCJUU3JUJCJTlGJUU1JTkxJUJEJUU0JUJCJUE0JUVGJUJDJThDJUU1JThGJUFGJUU4JTgzJUJEJUU1JUFGJUJDJUU4JTg3JUI0JUU2JTlDJThEJUU1JThBJUExJUU1JTk5JUE4JUU4JUEyJUFCJUU1JUFFJThDJUU1JTg1JUE4JUU2JThFJUE3JUU1JTg4JUI2JUUzJTgwJTgxJUU2JTk1JUIwJUU2JThEJUFFJUU2JUIzJTg0JUU5JTlDJUIyJUU2JTg4JTk2JUU0JUI4JTlBJUU1JThBJUExJUU3JUIzJUJCJUU3JUJCJTlGJUU2JUIyJUE2JUU5JTk5JUI3JUUzJTgwJTgyJTIyJTJDJTIybWFya3MlMjIlM0ElNUIlNUQlN0QlNUQlN0QlNUQlMkMlMjJjb250ZW50VHlwZSUyMiUzQSUyMmNhbmdqaWUtdGV4dGJsb2NrJTIyJTdEJTVEJTdE" data-identifier-application__slash__x-doc-key="ABmOoWbjkxeDzOaw" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;moi8quurgbyqld8583&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;bold&#34;:true,&#34;data-type&#34;:&#34;leaf&#34;},&#34;WAF/IDS 全面绕过：&#34;],[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34; 攻击者通过 Ghost Bits 变形 Payload 可绕过绝大多数现有基于规则的 WAF 检测，使已有安全防护形同虚设。&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJtb2k4cXV1cmdieXFsZDg1ODMlMjIlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIydGV4dCUyMiUyQyUyMmxlYXZlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIybGVhZiUyMiUyQyUyMnRleHQlMjIlM0ElMjJXQUYlMkZJRFMlMjAlRTUlODUlQTglRTklOUQlQTIlRTclQkIlOTUlRTglQkYlODclRUYlQkMlOUElMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIybWFyayUyMiUyQyUyMnR5cGUlMjIlM0ElMjJib2xkJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiU3RCU3RCU1RCU3RCUyQyU3QiUyMmtsYXNzJTIyJTNBJTIybGVhZiUyMiUyQyUyMnRleHQlMjIlM0ElMjIlMjAlRTYlOTQlQkIlRTUlODclQkIlRTglODAlODUlRTklODAlOUElRTglQkYlODclMjBHaG9zdCUyMEJpdHMlMjAlRTUlOEYlOTglRTUlQkQlQTIlMjBQYXlsb2FkJTIwJUU1JThGJUFGJUU3JUJCJTk1JUU4JUJGJTg3JUU3JUJCJTlEJUU1JUE0JUE3JUU1JUE0JTlBJUU2JTk1JUIwJUU3JThFJUIwJUU2JTlDJTg5JUU1JTlGJUJBJUU0JUJBJThFJUU4JUE3JTg0JUU1JTg4JTk5JUU3JTlBJTg0JTIwV0FGJTIwJUU2JUEzJTgwJUU2JUI1JThCJUVGJUJDJThDJUU0JUJEJUJGJUU1JUI3JUIyJUU2JTlDJTg5JUU1JUFFJTg5JUU1JTg1JUE4JUU5JTk4JUIyJUU2JThBJUE0JUU1JUJEJUEyJUU1JTkwJThDJUU4JTk5JTlBJUU4JUFFJUJFJUUzJTgwJTgyJTIyJTJDJTIybWFya3MlMjIlM0ElNUIlNUQlN0QlNUQlN0QlNUQlMkMlMjJjb250ZW50VHlwZSUyMiUzQSUyMmNhbmdqaWUtdGV4dGJsb2NrJTIyJTdEJTVEJTdE" data-identifier-application__slash__x-doc-key="v9kqDejJogbrpOVx" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">WAF/IDS 全面绕过：</span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">攻击者通过 Ghost Bits 变形 Payload 可绕过绝大多数现有基于规则的 WAF 检测，使已有安全防护形同虚设。</span></span></span></p></div><div data-identifier-application__slash__x-doc-key="v9kqDejJogbrpOVx" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">触发多类高危漏洞：</span></span></span></p><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.6em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">SQL 注入</span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">：Jackson </span></span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">charToHex</span></span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">（</span></span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">ch &amp; 255</span></span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">）截断，SQL 注入 Payload 隐写于 Unicode 字符中，WAF 无告警，后端还原并执行。</span></span></span></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">反序列化 RCE</span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">：BCEL ClassLoader 解码、fastjson </span></span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">\u</span></span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">/ </span></span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">\x</span></span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">转义均存在 Ghost Bits，可绕过 WAF 触发反序列化远程代码执行。</span></span></span></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">文件上传绕过</span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">：Tomcat </span></span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">RFC2231Utility</span></span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">处理文件名时截断高位，可将 </span></span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">.jsp</span></span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">伪装为非敏感 Unicode 字符，绕过 WAF 上传 Webshell。</span></span></span></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">路径穿越 / 认证绕过</span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">：Spring、Jetty、Undertow、Vert.x 等框架 URL 解码路径存在 Ghost Bits，可绕过 WAF 实现目录穿越；Openfire CVE-2023-32315 可借此绕过 WAF 防护直接利用。</span></span></span></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">已知高危 CVE WAF 绕过</span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">：GeoServer CVE-2024-36401（CVSS 9.8）、Spring4Shell（CVE-2022-22965）等漏洞的现有 WAF 防护均可被 Ghost Bits 变体 Payload 绕过，直接触发 RCE。</span></span></span></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">SMTP 注入</span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">：Angus Mail 等邮件库存在 Ghost Bits，可将隐写 CRLF 序列还原为换行符，触发 SMTP 注入，实现邮件劫持或业务逻辑绕过（已在 Jira、Confluence 上复现）。</span></span></span></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">HTTP 请求走私 / XSS</span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">：Apache HttpClient（≤ 4.5.9）、JDK 原生 HttpServer 等组件同样受 Ghost Bits CRLF 影响。</span></span></span></p></li></ul></div></div><div data-identifier-application__slash__x-doc-key="r4mlQmEY28GMlxow" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);text-size-adjust: inherit;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 16px;letter-spacing: 0.578px;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 17px;letter-spacing: 0.578px;color: rgb(122, 194, 89);line-height: 1.82em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, system-ui, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.87em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">处置优先级：高</span></span></strong></p><div data-tools="135编辑器" data-id="142799" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;letter-spacing: 0.578px;color: rgb(0, 0, 0);font-family: mp-quote, &#34;PingFang SC&#34;, -apple-system-font, system-ui, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px auto;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;"><div data-width="100%" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 676px;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 5px 10px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div data-autoskip="1" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.75em;letter-spacing: 1.5px;font-size: 14px;color: rgb(51, 51, 51);"><div data-identifier-application__slash__x-doc-key="8K4nyR2daWX0qLbj" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(0, 0, 0);"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(38, 38, 38, 0.86);"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: left;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-weight: bold;">类型：</span></span><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);font-family: mp-quote, &#34;PingFang SC&#34;, -apple-system-font, system-ui, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;color: rgba(38, 38, 38, 0.86);line-height: 2em;text-align: left;font-size: 15px;"><span textstyle="" style="font-weight: normal;">WAF绕过/</span></span><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-weight: normal;">远程代码执行/注入</span></span></span></span></span></p><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lwimwq8a5n1v73x221a&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;● 漏洞类型：目录遍历&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lwimwq8aiiblz5hww6&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;● 漏洞危害等级：中&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lwimwq8adn8we8t368w&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;● 权限认证要求：无需任何权限&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lwimwq8a2iqisx8i3r4&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;● 系统配置要求：默认配置可利用&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lwimwq8abf2z7210v3s&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;● 用户交互要求：无需用户交互&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lwimwq8bmbyjgppdj7&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;● 利用成熟度：POC/EXP已公开&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lwimwq8bxxufs939y1&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;● 批量可利用性：可使用通用 POC/EXP，批量检测/利用&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lwimwq8b94hfo6wrmi&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;● 修复复杂度：低，官方提供热修复方案&#34;]]]]" data-identifier-application__slash__x-doc-key="8K4nyRy9Bv1jqLbj" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-size-adjust: inherit;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(38, 38, 38, 0.86);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">危害等级：</span></span></strong><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">高</span></span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;line-height: 2em;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(38, 38, 38, 0.86);font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">触发方式：</span></span></strong><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(38, 38, 38, 0.86);font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">网络远程</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(38, 38, 38, 0.86);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">权限认证要求：</span></span></strong><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">无需权限</span></span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(38, 38, 38, 0.86);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">系统配置要求：</span></span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: mp-quote, &#34;PingFang SC&#34;, -apple-system-font, system-ui, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: left;line-height: 2em;caret-color: rgb(0, 0, 0);text-size-adjust: inherit;color: rgba(38, 38, 38, 0.86);font-size: 15px;">默认配置</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(38, 38, 38, 0.86);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">用户交互要求：</span></span></strong><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">无需用户交互</span></span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(38, 38, 38, 0.86);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">利用成熟度：</span></span></strong><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">POC/EXP 已公开</span></span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;line-height: 2em;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(38, 38, 38, 0.86);font-size: 15px;line-height: 2em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">修复复杂度：</span><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);font-family: mp-quote, &#34;PingFang SC&#34;, -apple-system-font, system-ui, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: left;line-height: 2em;color: rgba(38, 38, 38, 0.86);font-size: 15px;">中</span></strong></p></div></div></div></div></div></div></div></div><div data-role="title" data-tools="135编辑器" data-id="124637" data-color="#7ac259" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;letter-spacing: 0.578px;color: rgb(0, 0, 0);border-width: 0px;border-style: none;border-color: initial;z-index: 0;max-width: 100%;max-inline-size: 100%;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px auto;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;max-width: 100%;max-inline-size: 100%;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;flex-shrink: 0;display: flex;max-width: 100%;max-inline-size: 100%;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 10px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;max-width: 100%;max-inline-size: 100%;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(122, 194, 89);text-align: left;max-width: 100%;max-inline-size: 100%;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;font-size: 20px;letter-spacing: 2px;color: rgb(31, 31, 31);max-width: 100%;max-inline-size: 100%;"><strong data-brushtype="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;max-width: 100%;max-inline-size: 100%;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">影响范围</span></strong></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12px;text-align: left;max-width: 100%;max-inline-size: 100%;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;letter-spacing: 1px;background-color: rgba(152, 152, 152, 0.1);max-width: 100%;max-inline-size: 100%;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;color: rgb(152, 152, 152);max-width: 100%;max-inline-size: 100%;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Affects</span></span></span></p></div></div><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;flex-shrink: 0;display: flex;align-items: center;max-width: 100%;max-inline-size: 100%;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 5px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20px;letter-spacing: 1.5px;color: rgb(122, 194, 89);max-width: 100%;max-inline-size: 100%;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;font-size: 24px;color: rgba(152, 152, 152, 0.2);max-width: 100%;max-inline-size: 100%;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;max-width: 100%;max-inline-size: 100%;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">02</span></strong></span></p></div></div></div><pre data-placeholder="翻译" dir="ltr" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;letter-spacing: 0.578px;color: rgb(0, 0, 0);max-width: 100%;max-inline-size: 100%;"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:398674325},[&#34;p&#34;,{&#34;uuid&#34;:&#34;liczeplu90nx1mmntt&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;&lt;&#34;],[&#34;span&#34;,{&#34;highlight&#34;:&#34;rgb(252, 252, 252)&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;RocketMQ 4.9.6&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;liczez2ip16agu1s6w&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;highlight&#34;:&#34;rgb(252, 252, 252)&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;&lt;RocketMQ 5.1.1&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJsaWN6ZXBsdTkwbngxbW1udHQlMjIlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIydGV4dCUyMiUyQyUyMmxlYXZlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIybGVhZiUyMiUyQyUyMnRleHQlMjIlM0ElMjIlM0MlMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCUyQyU3QiUyMmtsYXNzJTIyJTNBJTIybGVhZiUyMiUyQyUyMnRleHQlMjIlM0ElMjJSb2NrZXRNUSUyMDQuOS42JTIyJTJDJTIybWFya3MlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMm1hcmslMjIlMkMlMjJ0eXBlJTIyJTNBJTIyaGlnaGxpZ2h0JTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnZhbHVlJTIyJTNBJTIycmdiKDI1MiUyQyUyMDI1MiUyQyUyMDI1MiklMjIlN0QlN0QlNUQlN0QlNUQlN0QlNUQlN0QlMkMlN0IlMjJrbGFzcyUyMiUzQSUyMmJsb2NrJTIyJTJDJTIydHlwZSUyMiUzQSUyMnBhcmFncmFwaCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlMjJ1dWlkJTIyJTNBJTIybGljemV6MmlwMTZhZ3UxczZ3JTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyJTNDUm9ja2V0TVElMjA1LjEuMSUyMiUyQyUyMm1hcmtzJTIyJTNBJTVCJTdCJTIya2xhc3MlMjIlM0ElMjJtYXJrJTIyJTJDJTIydHlwZSUyMiUzQSUyMmhpZ2hsaWdodCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlMjJ2YWx1ZSUyMiUzQSUyMnJnYigyNTIlMkMlMjAyNTIlMkMlMjAyNTIpJTIyJTdEJTdEJTVEJTdEJTVEJTdEJTVEJTdEJTVEJTdE" data-identifier-application__slash__x-doc-key="XYvenvXNYavMOoyZ" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;max-width: 100%;max-inline-size: 100%;"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1121139987},[&#34;p&#34;,{&#34;uuid&#34;:&#34;liczeplu90nx1mmntt&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;&lt;&#34;],[&#34;span&#34;,{&#34;highlight&#34;:&#34;rgb(252, 252, 252)&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;RocketMQ 4.9.7&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;liczez2ip16agu1s6w&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;highlight&#34;:&#34;rgb(252, 252, 252)&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;&lt;RocketMQ 5.1.2&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJsaWN6ZXBsdTkwbngxbW1udHQlMjIlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIydGV4dCUyMiUyQyUyMmxlYXZlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIybGVhZiUyMiUyQyUyMnRleHQlMjIlM0ElMjIlM0MlMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCUyQyU3QiUyMmtsYXNzJTIyJTNBJTIybGVhZiUyMiUyQyUyMnRleHQlMjIlM0ElMjJSb2NrZXRNUSUyMDQuOS43JTIyJTJDJTIybWFya3MlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMm1hcmslMjIlMkMlMjJ0eXBlJTIyJTNBJTIyaGlnaGxpZ2h0JTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnZhbHVlJTIyJTNBJTIycmdiKDI1MiUyQyUyMDI1MiUyQyUyMDI1MiklMjIlN0QlN0QlNUQlN0QlNUQlN0QlNUQlN0QlMkMlN0IlMjJrbGFzcyUyMiUzQSUyMmJsb2NrJTIyJTJDJTIydHlwZSUyMiUzQSUyMnBhcmFncmFwaCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlMjJ1dWlkJTIyJTNBJTIybGljemV6MmlwMTZhZ3UxczZ3JTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyJTNDUm9ja2V0TVElMjA1LjEuMiUyMiUyQyUyMm1hcmtzJTIyJTNBJTVCJTdCJTIya2xhc3MlMjIlM0ElMjJtYXJrJTIyJTJDJTIydHlwZSUyMiUzQSUyMmhpZ2hsaWdodCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlMjJ2YWx1ZSUyMiUzQSUyMnJnYigyNTIlMkMlMjAyNTIlMkMlMjAyNTIpJTIyJTdEJTdEJTVEJTdEJTVEJTdEJTVEJTdEJTVEJTdE" data-identifier-application__slash__x-doc-key="r4mlQmEY28GMlxow" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;text-size-adjust: inherit;max-width: 100%;max-inline-size: 100%;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;mbt8tfhjyvdd4n80df&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;e-cology 9  补丁版本 &lt; v10.75&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJtYnQ4dGZoanl2ZGQ0bjgwZGYlMjIlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIydGV4dCUyMiUyQyUyMmxlYXZlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIybGVhZiUyMiUyQyUyMnRleHQlMjIlM0ElMjJlLWNvbG9neSUyMDklMjAlMjAlRTglQTElQTUlRTQlQjglODElRTclODklODglRTYlOUMlQUMlMjAlM0MlMjB2MTAuNzUlMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCU1RCU3RCU1RCUyQyUyMmNvbnRlbnRUeXBlJTIyJTNBJTIyY2FuZ2ppZS10ZXh0YmxvY2slMjIlN0QlNUQlN0Q=" data-identifier-application__slash__x-doc-key="8K4nyeZVamGgPnLb" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;mjpqnzgpyc8x3kpa6g&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;ComfyUI-Manager &lt; V3.38&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJtanBxbnpncHljOHgza3BhNmclMjIlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIydGV4dCUyMiUyQyUyMmxlYXZlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIybGVhZiUyMiUyQyUyMnRleHQlMjIlM0ElMjJDb21meVVJLU1hbmFnZXIlMjAlM0MlMjBWMy4zOCUyMiUyQyUyMm1hcmtzJTIyJTNBJTVCJTVEJTdEJTVEJTdEJTVEJTJDJTIyY29udGVudFR5cGUlMjIlM0ElMjJjYW5namllLXRleHRibG9jayUyMiU3RCU1RCU3RA==" data-identifier-application__slash__x-doc-key="8K4nyeZ4kYD8VnLb" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;moi8quuso57y1ip41k&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;以下组件已被确认受 Ghost Bits 影响：&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJtb2k4cXV1c281N3kxaXA0MWslMjIlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIydGV4dCUyMiUyQyUyMmxlYXZlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIybGVhZiUyMiUyQyUyMnRleHQlMjIlM0ElMjIlRTQlQkIlQTUlRTQlQjglOEIlRTclQkIlODQlRTQlQkIlQjYlRTUlQjclQjIlRTglQTIlQUIlRTclQTElQUUlRTglQUUlQTQlRTUlOEYlOTclMjBHaG9zdCUyMEJpdHMlMjAlRTUlQkQlQjElRTUlOTMlOEQlRUYlQkMlOUElMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCU1RCU3RCU1RCUyQyUyMmNvbnRlbnRUeXBlJTIyJTNBJTIyY2FuZ2ppZS10ZXh0YmxvY2slMjIlN0QlNUQlN0Q=" data-identifier-application__slash__x-doc-key="v9kqDejJogbrpOVx" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">以下组件已被确认受 Ghost Bits 影响：</span></span></span></p><p data-identifier-application__slash__x-doc-key="v9kqDejJogbrpOVx" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><table style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 0px 10px;padding: 0px;outline: 0px;border-collapse: collapse;display: table;width: 650px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;table-layout: fixed;"><tbody><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">组件</span></span></p></td><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞类型</span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Apache Commons BCEL</span></span></p></td><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">WAF 绕过 / 反序列化 RCE</span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Jackson Databind</span></span></p></td><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">WAF 绕过 / SQL 注入</span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Fastjson</span></span></p></td><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">WAF 绕过 / 反序列化 RCE</span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Apache Tomcat</span></span></p></td><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">文件上传绕过（Webshell）</span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Spring Framework</span></span></p></td><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">URL 解码绕过 / 路径穿越</span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Jetty</span></span></p></td><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">URL 解码绕过 / CRLF 注入</span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Undertow</span></span></p></td><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">URL 解码绕过</span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Vert.x</span></span></p></td><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">URL 解码绕过</span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Angus Mail</span></span></p></td><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">SMTP 注入</span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Apache HttpClient ≤ 4.5.9</span></span></p></td><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">HTTP 请求走私（HTTPCLIENT-1974/1978）</span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">ActiveJ</span></span></p></td><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">HTTP CRLF 注入</span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Lettuce（Redis 客户端）</span></span></p></td><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Redis 命令注入</span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Jodd</span></span></p></td><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">路径穿越</span></span></p></td></tr><tr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">XMLWriter</span></span></p></td><td style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 4px 8px;outline: 0px;overflow-wrap: break-word;word-break: break-all;hyphens: auto;border: 1px solid rgb(0, 0, 0);max-width: 100%;box-sizing: border-box !important;overflow: hidden;vertical-align: top;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">XML 标签注入</span></span></p></td></tr></tbody></table></p><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;blockquote&#34;:true,&#34;uuid&#34;:&#34;moi8quutlsj2w5l192&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;受影响的真实 CVE 包括但不限于：GeoServer CVE-2024-36401、Spring4Shell CVE-2022-22965、Openfire CVE-2023-32315。&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMmJsb2NrcXVvdGUlMjIlM0F0cnVlJTJDJTIydXVpZCUyMiUzQSUyMm1vaThxdXV0bHNqMnc1bDE5MiUyMiU3RCUyQyUyMm5vZGVzJTIyJTNBJTVCJTdCJTIya2xhc3MlMjIlM0ElMjJ0ZXh0JTIyJTJDJTIybGVhdmVzJTIyJTNBJTVCJTdCJTIya2xhc3MlMjIlM0ElMjJsZWFmJTIyJTJDJTIydGV4dCUyMiUzQSUyMiVFNSU4RiU5NyVFNSVCRCVCMSVFNSU5MyU4RCVFNyU5QSU4NCVFNyU5QyU5RiVFNSVBRSU5RSUyMENWRSUyMCVFNSU4QyU4NSVFNiU4QiVBQyVFNCVCRCU4NiVFNCVCOCU4RCVFOSU5OSU5MCVFNCVCQSU4RSVFRiVCQyU5QUdlb1NlcnZlciUyMENWRS0yMDI0LTM2NDAxJUUzJTgwJTgxU3ByaW5nNFNoZWxsJTIwQ1ZFLTIwMjItMjI5NjUlRTMlODAlODFPcGVuZmlyZSUyMENWRS0yMDIzLTMyMzE1JUUzJTgwJTgyJTIyJTJDJTIybWFya3MlMjIlM0ElNUIlNUQlN0QlNUQlN0QlNUQlMkMlMjJjb250ZW50VHlwZSUyMiUzQSUyMmNhbmdqaWUtdGV4dGJsb2NrJTIyJTdEJTVEJTdE" data-identifier-application__slash__x-doc-key="v9kqDejJogbrpOVx" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><p data-type="blockquote" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">受影响的真实 CVE 包括但不限于：GeoServer CVE-2024-36401、Spring4Shell CVE-2022-22965、Openfire CVE-2023-32315。</span></span></span></p></div></div></div></div></div></div></pre><div data-role="title" data-tools="135编辑器" data-id="124637" data-color="#7ac259" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;letter-spacing: 0.578px;color: rgb(0, 0, 0);border-width: 0px;border-style: none;border-color: initial;z-index: 0;caret-color: rgb(255, 0, 0);background-color: rgb(255, 255, 255);font-family: 微软雅黑, &#34;Microsoft YaHei&#34;, sans-serif;max-width: 100%;max-inline-size: 100%;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px auto;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;max-width: 100%;max-inline-size: 100%;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;flex-shrink: 0;display: flex;max-width: 100%;max-inline-size: 100%;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 10px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;max-width: 100%;max-inline-size: 100%;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(122, 194, 89);text-align: left;max-width: 100%;max-inline-size: 100%;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;font-size: 20px;letter-spacing: 2px;color: rgb(31, 31, 31);max-width: 100%;max-inline-size: 100%;"><strong data-brushtype="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;max-width: 100%;max-inline-size: 100%;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">解决方案</span></strong></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12px;color: rgb(166, 166, 166);text-align: left;max-width: 100%;max-inline-size: 100%;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;letter-spacing: 1px;background-color: rgba(152, 152, 152, 0.1);max-width: 100%;max-inline-size: 100%;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;color: rgb(152, 152, 152);max-width: 100%;max-inline-size: 100%;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Solution</span></span></span></p></div></div><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;flex-shrink: 0;display: flex;align-items: center;max-width: 100%;max-inline-size: 100%;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 5px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20px;letter-spacing: 1.5px;color: rgb(122, 194, 89);max-width: 100%;max-inline-size: 100%;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;font-size: 24px;color: rgba(152, 152, 152, 0.2);max-width: 100%;max-inline-size: 100%;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">03</span></span></strong></p></div></div></div><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1329378339},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhbwfatppk7t6mctnlg&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;bold&#34;:false,&#34;sz&#34;:11,&#34;szUnit&#34;:&#34;pt&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;官方已经发布了安全补丁，在参考链接中安装官方提供的安全补丁 。&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJsaGJ3ZmF0cHBrN3Q2bWN0bmxnJTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyJUU1JUFFJTk4JUU2JTk2JUI5JUU1JUI3JUIyJUU3JUJCJThGJUU1JThGJTkxJUU1JUI4JTgzJUU0JUJBJTg2JUU1JUFFJTg5JUU1JTg1JUE4JUU4JUExJUE1JUU0JUI4JTgxJUVGJUJDJThDJUU1JTlDJUE4JUU1JThGJTgyJUU4JTgwJTgzJUU5JTkzJUJFJUU2JThFJUE1JUU0JUI4JUFEJUU1JUFFJTg5JUU4JUEzJTg1JUU1JUFFJTk4JUU2JTk2JUI5JUU2JThGJTkwJUU0JUJFJTlCJUU3JTlBJTg0JUU1JUFFJTg5JUU1JTg1JUE4JUU4JUExJUE1JUU0JUI4JTgxJTIwJUUzJTgwJTgyJTIyJTJDJTIybWFya3MlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMm1hcmslMjIlMkMlMjJ0eXBlJTIyJTNBJTIyYm9sZCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlMjJ2YWx1ZSUyMiUzQWZhbHNlJTdEJTdEJTJDJTdCJTIya2xhc3MlMjIlM0ElMjJtYXJrJTIyJTJDJTIydHlwZSUyMiUzQSUyMnN6JTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnZhbHVlJTIyJTNBMTElMkMlMjJzelVuaXQlMjIlM0ElMjJwdCUyMiU3RCU3RCU1RCU3RCU1RCU3RCU1RCU3RCU1RCU3RA==" data-identifier-application__slash__x-doc-key="LvBPlNWKY5PVndG8" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(255, 0, 0);background-color: rgb(255, 255, 255);font-family: 微软雅黑, &#34;Microsoft YaHei&#34;, sans-serif;max-width: 100%;max-inline-size: 100%;"><div data-identifier-application__slash__x-doc-key="XYvenvXNYavMOoyZ" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;max-width: 100%;max-inline-size: 100%;"><p data-identifier-application__slash__x-doc-key="XYvenvXNYavMOoyZ" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(0, 0, 0);font-size: 16px;letter-spacing: 0.578px;max-width: 100%;max-inline-size: 100%;"><h2 style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 25px 0px 0px;padding: 0px;outline: none 0px !important;font-weight: 400;font-size: 17px;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;line-height: 1.75em;max-width: 100%;max-inline-size: 100%;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;max-width: 100%;max-inline-size: 100%;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;color: rgb(122, 194, 89);max-width: 100%;max-inline-size: 100%;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">升级修复方案</span></span></strong></h2></p><div data-identifier-application__slash__x-doc-key="XYvenvXNYavMOoyZ" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(0, 0, 0);font-size: 16px;letter-spacing: 0.578px;max-width: 100%;max-inline-size: 100%;"><div data-identifier-application__slash__x-doc-key="8K4nyeZ4kYD8VnLb" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;mk52sesdaa7nj3y7rq9&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;升级 ComfyUI-Manager 至 V3.39.2 或更高版本\n&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJtazUyc2VzZGFhN25qM3k3cnE5JTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyJUU1JThEJTg3JUU3JUJBJUE3JTIwQ29tZnlVSS1NYW5hZ2VyJTIwJUU4JTg3JUIzJTIwVjMuMzkuMiUyMCVFNiU4OCU5NiVFNiU5QiVCNCVFOSVBQiU5OCVFNyU4OSU4OCVFNiU5QyVBQyU1Q24lMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCU1RCU3RCU1RCUyQyUyMmNvbnRlbnRUeXBlJTIyJTNBJTIyY2FuZ2ppZS10ZXh0YmxvY2slMjIlN0QlNUQlN0Q=" data-identifier-application__slash__x-doc-key="J9LnW6j7NLgGWlvD" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><div data-identifier-application__slash__x-doc-key="v9kqDejJogbrpOVx" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">请关注上述各受影响组件的官方 Security Advisory，升级至已修复版本。重点关注：</span></span></span></p><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.6em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">Apache Commons BCEL</span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">：升级至 6.12.0 及以上版本</span></span></span></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">Fastjson</span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">：升级至 2.x 系列最新版本</span></span></span></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">Apache HttpClient</span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">：升级至 4.5.10 及以上版本，或迁移至 HttpClient 5.x</span></span></span></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">GeoServer</span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">：升级至 2.28.3 及以上版本</span></span></span></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">Openfire</span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">：升级至 5.0.4 及以上版本</span></span></span></p></li></ul></div></div></div></div><p data-identifier-application__slash__x-doc-key="XYvenvXNYavMOoyZ" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(0, 0, 0);font-size: 16px;letter-spacing: 0.578px;max-width: 100%;max-inline-size: 100%;"><h2 style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 25px 0px 0px;padding: 0px;outline: none 0px !important;font-weight: 400;font-size: 17px;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;line-height: 1.75em;max-width: 100%;max-inline-size: 100%;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;max-width: 100%;max-inline-size: 100%;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;color: rgb(122, 194, 89);max-width: 100%;max-inline-size: 100%;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">临时缓解方案</span><div data-role="title" data-tools="135编辑器" data-id="124637" data-color="#7ac259" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(0, 0, 0);font-size: 16px;letter-spacing: 0.578px;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px auto;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;flex-shrink: 0;display: flex;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 10px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p data-identifier-application__slash__x-doc-key="v9kqDejJogbrpOVx" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><ol style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.6em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: decimal;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">WAF 规则</span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">：现有基于字符串特征的 WAF 规则对 Ghost Bits 变形 Payload 防护效果有限，建议在解码层面进行语义检测，或引入 Unicode 规范化预处理后再执行规则匹配。</span></span></span></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">代码层面</span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">：排查自研代码中 </span></span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">(byte)ch</span></span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">、</span></span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">ch &amp; 0xFF</span></span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">、</span></span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">baos.write(ch)</span></span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">、</span></span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">DataOutputStream</span><a class="wx_topic_link" topic-id="moibzoe8-70d5jf" style="color: #576B95 !important;" data-topic="1" data-recommend=""><span textstyle="" style="font-size: 15px;">#writeBytes</span></a><span textstyle="" style="font-size: 15px;">()</span></span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">等写法，改为使用 </span></span></span><code data-type="inlineCode" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">String.getBytes(StandardCharsets.UTF_8)</span></span></span></code><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">等明确指定编码的方式。</span></span></span></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">输入验证</span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">：在输入校验阶段对关键字段（文件名、邮件地址、URL 参数、JSON 键名等）严格过滤非 ASCII 字符或进行 Unicode 归一化（NFC/NFKC）处理。</span></span></span></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-weight: bold;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">网络层面</span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">：对暴露在公网的 Java 应用服务，在完成代码修复前限制访问来源，降低攻击面。</span></span></span></p></li></ol></p></div></div></div></div><div data-role="title" data-tools="135编辑器" data-id="124637" data-color="#7ac259" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px auto;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;flex-shrink: 0;display: flex;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 10px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: left;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(31, 31, 31);font-size: 20px;letter-spacing: 2px;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞复现</span></strong></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(166, 166, 166);font-size: 12px;letter-spacing: 0.578px;text-align: left;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 1px;background-color: rgba(152, 152, 152, 0.1);"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(152, 152, 152);font-family: 微软雅黑, &#34;Microsoft YaHei&#34;, sans-serif;font-size: 12px;letter-spacing: 1px;text-align: left;caret-color: rgb(0, 0, 0);background-color: rgba(152, 152, 152, 0.1);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Reproduction</span></span></span></p></div></div><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(0, 0, 0);font-size: 16px;letter-spacing: 0.578px;flex-shrink: 0;display: flex;align-items: center;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20px;letter-spacing: 1.5px;color: rgb(122, 194, 89);"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 24px;color: rgba(152, 152, 152, 0.2);line-height: 1.58em;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">                                      04</span></strong></span></p></div></div></div><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px auto;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;"><div data-identifier-application__slash__x-doc-key="Pd6l2Z7BDGBpdl7M" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><div data-role="title" data-tools="135编辑器" data-id="124637" data-color="#7ac259" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;letter-spacing: 0.578px;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px auto;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;flex-shrink: 0;display: flex;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 10px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(122, 194, 89);text-align: left;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20px;letter-spacing: 2px;color: rgb(31, 31, 31);"><strong data-brushtype="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">时间线</span></strong></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12px;color: rgb(166, 166, 166);text-align: left;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 1px;background-color: rgba(152, 152, 152, 0.1);"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(152, 152, 152);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Timeline</span></span></span></p></div></div><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;flex-shrink: 0;display: flex;align-items: center;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20px;letter-spacing: 1.5px;color: rgb(122, 194, 89);"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 24px;color: rgba(152, 152, 152, 0.2);line-height: 1.58em;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">05</span></strong></span></p></div></div></div><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:398674325},[&#34;p&#34;,{&#34;uuid&#34;:&#34;licztcywfgeia50hgau&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;5月23日 官方发布漏洞更新补丁版本&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;liczwtaewmcvwgfubl&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;5月24日 长亭应急响应实验室复现漏洞&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;liczxgtrqt1a8f2uca&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;5月30日 监测到POC已被小范围公开&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;liczyrvvhx91cimp5ko&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;6月1日 长亭发布应急响应通告&#34;]]]]" data-identifier-application__slash__x-doc-key="XYvenvXNYavMOoyZ" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;letter-spacing: 0.578px;"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1121139987},[&#34;p&#34;,{&#34;uuid&#34;:&#34;licztcywfgeia50hgau&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;7月12日 漏洞被公开披露[4]&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lk0k3n68fx3xyfk6eh&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;7月12日 长亭应急响应实验室漏洞分析与复现&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lk0k55pw2m215r3a86w&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;7月13日 长亭安全应急响应中心发布通告&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJsaWN6dGN5d2ZnZWlhNTBoZ2F1JTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyNyVFNiU5QyU4ODEyJUU2JTk3JUE1JTIwJUU2JUJDJThGJUU2JUI0JTlFJUU4JUEyJUFCJUU1JTg1JUFDJUU1JUJDJTgwJUU2JThBJUFCJUU5JTlDJUIyJTVCNCU1RCUyMiUyQyUyMm1hcmtzJTIyJTNBJTVCJTVEJTdEJTVEJTdEJTVEJTdEJTJDJTdCJTIya2xhc3MlMjIlM0ElMjJibG9jayUyMiUyQyUyMnR5cGUlMjIlM0ElMjJwYXJhZ3JhcGglMjIlMkMlMjJkYXRhJTIyJTNBJTdCJTIydXVpZCUyMiUzQSUyMmxrMGszbjY4ZngzeHlmazZlaCUyMiU3RCUyQyUyMm5vZGVzJTIyJTNBJTVCJTdCJTIya2xhc3MlMjIlM0ElMjJ0ZXh0JTIyJTJDJTIybGVhdmVzJTIyJTNBJTVCJTdCJTIya2xhc3MlMjIlM0ElMjJsZWFmJTIyJTJDJTIydGV4dCUyMiUzQSUyMjclRTYlOUMlODgxMiVFNiU5NyVBNSUyMCVFOSU5NSVCRiVFNCVCQSVBRCVFNSVCQSU5NCVFNiU4MCVBNSVFNSU5MyU4RCVFNSVCQSU5NCVFNSVBRSU5RSVFOSVBQSU4QyVFNSVBRSVBNCVFNiVCQyU4RiVFNiVCNCU5RSVFNSU4OCU4NiVFNiU5RSU5MCVFNCVCOCU4RSVFNSVBNCU4RCVFNyU4RSVCMCUyMiUyQyUyMm1hcmtzJTIyJTNBJTVCJTVEJTdEJTVEJTdEJTVEJTdEJTJDJTdCJTIya2xhc3MlMjIlM0ElMjJibG9jayUyMiUyQyUyMnR5cGUlMjIlM0ElMjJwYXJhZ3JhcGglMjIlMkMlMjJkYXRhJTIyJTNBJTdCJTIydXVpZCUyMiUzQSUyMmxrMGs1NXB3Mm0yMTVyM2E4NnclMjIlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIydGV4dCUyMiUyQyUyMmxlYXZlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIybGVhZiUyMiUyQyUyMnRleHQlMjIlM0ElMjI3JUU2JTlDJTg4MTMlRTYlOTclQTUlMjAlRTklOTUlQkYlRTQlQkElQUQlRTUlQUUlODklRTUlODUlQTglRTUlQkElOTQlRTYlODAlQTUlRTUlOTMlOEQlRTUlQkElOTQlRTQlQjglQUQlRTUlQkYlODMlRTUlOEYlOTElRTUlQjglODMlRTklODAlOUElRTUlOTElOEElMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCU1RCU3RCU1RCU3RCU1RCU3RA==" data-identifier-application__slash__x-doc-key="r4mlQmEY28GMlxow" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);text-size-adjust: inherit;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lpj9i8ax6llvk79gwia&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;雷池：已发布自定义规则支持该漏洞检测。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lpj9i9l4cpvexzah8vc&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;全悉：预计于2024.06.07发布升级包支持该漏洞检测。&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJscGo5aThheDZsbHZrNzlnd2lhJTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyJUU5JTlCJUI3JUU2JUIxJUEwJUVGJUJDJTlBJUU1JUI3JUIyJUU1JThGJTkxJUU1JUI4JTgzJUU4JTg3JUFBJUU1JUFFJTlBJUU0JUI5JTg5JUU4JUE3JTg0JUU1JTg4JTk5JUU2JTk0JUFGJUU2JThDJTgxJUU4JUFGJUE1JUU2JUJDJThGJUU2JUI0JTlFJUU2JUEzJTgwJUU2JUI1JThCJUUzJTgwJTgyJTIyJTJDJTIybWFya3MlMjIlM0ElNUIlNUQlN0QlNUQlN0QlNUQlN0QlMkMlN0IlMjJrbGFzcyUyMiUzQSUyMmJsb2NrJTIyJTJDJTIydHlwZSUyMiUzQSUyMnBhcmFncmFwaCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlMjJ1dWlkJTIyJTNBJTIybHBqOWk5bDRjcHZleHphaDh2YyUyMiU3RCUyQyUyMm5vZGVzJTIyJTNBJTVCJTdCJTIya2xhc3MlMjIlM0ElMjJ0ZXh0JTIyJTJDJTIybGVhdmVzJTIyJTNBJTVCJTdCJTIya2xhc3MlMjIlM0ElMjJsZWFmJTIyJTJDJTIydGV4dCUyMiUzQSUyMiVFNSU4NSVBOCVFNiU4MiU4OSVFRiVCQyU5QSVFOSVBMiU4NCVFOCVBRSVBMSVFNCVCQSU4RTIwMjQuMDYuMDclRTUlOEYlOTElRTUlQjglODMlRTUlOEQlODclRTclQkElQTclRTUlOEMlODUlRTYlOTQlQUYlRTYlOEMlODElRTglQUYlQTUlRTYlQkMlOEYlRTYlQjQlOUUlRTYlQTMlODAlRTYlQjUlOEIlRTMlODAlODIlMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCU1RCU3RCU1RCU3RCU1RCU3RA==" data-identifier-application__slash__x-doc-key="3BMqYaMEV896qwZL" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-size-adjust: inherit;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;licztcywfgeia50hgau&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;6月6日 官方发布漏洞公告&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lxec4knlucj95j2h0a&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;6月13日 互联网公开漏洞细节&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lk0k55pw2m215r3a86w&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;6月14日 长亭安全应急响应中心发布通告&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJsaWN6dGN5d2ZnZWlhNTBoZ2F1JTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyNiVFNiU5QyU4ODYlRTYlOTclQTUlMjAlRTUlQUUlOTglRTYlOTYlQjklRTUlOEYlOTElRTUlQjglODMlRTYlQkMlOEYlRTYlQjQlOUUlRTUlODUlQUMlRTUlOTElOEElMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCU1RCU3RCU1RCU3RCUyQyU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJseGVjNGtubHVjajk1ajJoMGElMjIlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIydGV4dCUyMiUyQyUyMmxlYXZlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIybGVhZiUyMiUyQyUyMnRleHQlMjIlM0ElMjI2JUU2JTlDJTg4MTMlRTYlOTclQTUlMjAlRTQlQkElOTIlRTglODElOTQlRTclQkQlOTElRTUlODUlQUMlRTUlQkMlODAlRTYlQkMlOEYlRTYlQjQlOUUlRTclQkIlODYlRTglOEElODIlMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCU1RCU3RCU1RCU3RCUyQyU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJsazBrNTVwdzJtMjE1cjNhODZ3JTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyNiVFNiU5QyU4ODE0JUU2JTk3JUE1JTIwJUU5JTk1JUJGJUU0JUJBJUFEJUU1JUFFJTg5JUU1JTg1JUE4JUU1JUJBJTk0JUU2JTgwJUE1JUU1JTkzJThEJUU1JUJBJTk0JUU0JUI4JUFEJUU1JUJGJTgzJUU1JThGJTkxJUU1JUI4JTgzJUU5JTgwJTlBJUU1JTkxJThBJTIyJTJDJTIybWFya3MlMjIlM0ElNUIlNUQlN0QlNUQlN0QlNUQlN0QlNUQlN0Q=" data-identifier-application__slash__x-doc-key="8K4nyRy9Bv1jqLbj" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-size-adjust: inherit;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">2026年4月 Black Hat Asia 2026 披露 Ghost Bits 攻击</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">2026年4月28日 长亭安全应急响应中心发布通告</span></span></span></p></div></div></div></div></div></div></span></strong><div data-role="paragraph" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: normal;text-align: start;white-space: normal;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1329378339},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhbw6gwwf5hgshd51os&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;由于系统未对系统接口的响应进行合理的处理，导致该系统会泄漏已注册用户信息，攻击者可利用信息泄露漏洞获取注册用户的信息。另外由于系统使用了不当的算法设计，攻击者可模拟任意用户登录系统。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhbw6jvlp8ey3x5omd&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;对攻击者来说，这两个漏洞的利用无需认证和鉴权，可通过组合漏洞获取用户数据，登录后台。&#34;]]]]" data-identifier-application__slash__x-doc-key="LvBPlNWKY5PVndG8" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:398674325},[&#34;p&#34;,{&#34;spacing&#34;:{&#34;after&#34;:&#34;12pt&#34;,&#34;afterAutospacing&#34;:false,&#34;before&#34;:&#34;0pt&#34;,&#34;beforeAutospacing&#34;:false},&#34;uuid&#34;:&#34;lhsmfajr95jz91x7s4q&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;漏洞的官方描述为当RocketMQ多个组件暴露在外网，并且缺乏有效的身份认证机制，那么攻击者可以利用&#34;],[&#34;span&#34;,{&#34;highlight&#34;:&#34;rgb(252, 252, 252)&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;更新配置功能，以RocketMQ运行的系统用户身份执行命令。&#34;]]],[&#34;p&#34;,{&#34;spacing&#34;:{&#34;after&#34;:&#34;12pt&#34;,&#34;afterAutospacing&#34;:false,&#34;before&#34;:&#34;0pt&#34;,&#34;beforeAutospacing&#34;:false},&#34;uuid&#34;:&#34;licz6vm6uu9cyvgzbm&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;bold&#34;:false,&#34;sz&#34;:11,&#34;szUnit&#34;:&#34;pt&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;经过深入分析，长亭科技应急响应实验室发现，官方的漏洞描述存在不准确之处。实际上，只要能访问到Broker服务且该服务未开启身份认证，就可能实现远程命令执行，无需其他条件。&#34;]]]]" data-identifier-application__slash__x-doc-key="XYvenvXNYavMOoyZ" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1329378339},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhbwfatppk7t6mctnlg&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;bold&#34;:false,&#34;sz&#34;:11,&#34;szUnit&#34;:&#34;pt&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;官方已经发布了安全补丁，在参考链接中安装官方提供的安全补丁 。&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJsaGJ3ZmF0cHBrN3Q2bWN0bmxnJTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyJUU1JUFFJTk4JUU2JTk2JUI5JUU1JUI3JUIyJUU3JUJCJThGJUU1JThGJTkxJUU1JUI4JTgzJUU0JUJBJTg2JUU1JUFFJTg5JUU1JTg1JUE4JUU4JUExJUE1JUU0JUI4JTgxJUVGJUJDJThDJUU1JTlDJUE4JUU1JThGJTgyJUU4JTgwJTgzJUU5JTkzJUJFJUU2JThFJUE1JUU0JUI4JUFEJUU1JUFFJTg5JUU4JUEzJTg1JUU1JUFFJTk4JUU2JTk2JUI5JUU2JThGJTkwJUU0JUJFJTlCJUU3JTlBJTg0JUU1JUFFJTg5JUU1JTg1JUE4JUU4JUExJUE1JUU0JUI4JTgxJTIwJUUzJTgwJTgyJTIyJTJDJTIybWFya3MlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMm1hcmslMjIlMkMlMjJ0eXBlJTIyJTNBJTIyYm9sZCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlMjJ2YWx1ZSUyMiUzQWZhbHNlJTdEJTdEJTJDJTdCJTIya2xhc3MlMjIlM0ElMjJtYXJrJTIyJTJDJTIydHlwZSUyMiUzQSUyMnN6JTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnZhbHVlJTIyJTNBMTElMkMlMjJzelVuaXQlMjIlM0ElMjJwdCUyMiU3RCU3RCU1RCU3RCU1RCU3RCU1RCU3RCU1RCU3RA==" data-identifier-application__slash__x-doc-key="LvBPlNWKY5PVndG8" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: normal;text-align: start;white-space: normal;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);"><div data-autoskip="1" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 0px 16px;padding: 16px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: normal;overflow: auto;font-size: 15px;line-height: 1.45;border-radius: 3px;background-color: rgb(247, 247, 247);"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(31, 31, 31);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">参考资料：</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(31, 31, 31);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">[1].Black Hat Asia 2026 议题：</span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-style: italic;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Cast Attack: A New Threat Posed by Ghost Bits in Java  </span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">作者：Xinyu Bai（@b1u3r / @iSafeBlue）、Zhihui Chen（@1ue1166323）、贡献者 Zongzheng Zheng（@chun_springX）</span></span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">[2].<a href="https://github.com/geoserver/geoserver/security/advisories/GHSA-6jj6-gm7p-fcvv" target="_blank">https://github.com/geoserver/geoserver/security/advisories/GHSA-6jj6-gm7p-fcvv</a></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(31, 31, 31);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">[3].<a href="https://github.com/advisories/GHSA-gw42-f939-fhvm" target="_blank">https://github.com/advisories/GHSA-gw42-f939-fhvm</a></span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(31, 31, 31);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">[4].<a href="https://spring.io/security/cve-2022-22965" target="_blank">https://spring.io/security/cve-2022-22965</a></span></span></p></div></div></div></div></div></h2></p></div></div></div></div><div data-id="97137" data-tools="135编辑器" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px auto;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;justify-content: center;align-items: center;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 6px 12px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 1.5px;color: rgb(174, 225, 91);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20px;letter-spacing: 1px;color: rgb(122, 194, 89);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">长亭应急响应服务</span></span></strong></p></div><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: -16px 0px 0px;padding: 1em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-width: medium 2px 2px;border-style: none solid solid;border-color: currentcolor rgb(135, 226, 90) rgb(135, 226, 90);"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 20px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">全力进行产品升级</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">及时将风险提示预案发送给客户</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">检测业务是否受到此次漏洞影响</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">请联系长亭应急服务团队</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 5px 0px 25px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">7*24小时，守护您的安全</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 25px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">第一时间找到我们：</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">邮箱：support@chaitin.com</span></span></p></div></div></div></div></div></div><scribe-shadow data-crx="okfkdaglfjjjfefdcppliegebpoegaii"></scribe-shadow><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=759092df&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MzkzOTYzOQ%3D%3D%26mid%3D2247490025%26idx%3D1%26sn%3D88c1a4a606fe0fe514a82d0b60ced208">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 28 Apr 2026 16:43:00 +0800</pubDate>
    </item>
    <item>
      <title>没错，我的枇杷比她甜！</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MzkzOTYzOQ==&amp;mid=2247490018&amp;idx=1&amp;sn=39fe7e9694b1e1874713488486739ad4</link>
      <description>拒绝重复造轮子，只愿在喧嚣里，守住那份成熟的本味。 —— 枇杷熟了。</description>
      <content:encoded><![CDATA[<p><span>枇杷哥</span> <span>2026-04-14 21:44</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=b6955bf6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FeZOA7OiaVuZicPguzIdHbA8mzK46fhBl4a41c2k0ghvP56WWNu8jKxrZDXZufOsDq7DEj51OnT6eibhyw1liaO0QtibmFFyeDFLBJA4iaHEQ9sKIY%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>拒绝重复造轮子，只愿在喧嚣里，守住那份成熟的本味。 —— 枇杷熟了。</p>
  <div><p><span style="color: rgba(39, 43, 32, 0.77);font-family: ui-sans-serif, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, &#34;Noto Sans&#34;, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Color Emoji&#34;;font-size: 15px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: pre-wrap;background-color: rgb(253, 247, 218);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span style="color: rgba(39, 43, 32, 0.77);font-family: ui-sans-serif, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, &#34;Noto Sans&#34;, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Color Emoji&#34;;font-size: 15px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: pre-wrap;background-color: rgb(253, 247, 218);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,null,&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgba(39, 43, 32, 0.77); font-family: ui-sans-serif, system-ui, -apple-system, \&#34;system-ui\&#34;, \&#34;Segoe UI\&#34;, Roboto, \&#34;Helvetica Neue\&#34;, Arial, \&#34;Noto Sans\&#34;, sans-serif, \&#34;Apple Color Emoji\&#34;, \&#34;Segoe UI Emoji\&#34;, \&#34;Segoe UI Symbol\&#34;, \&#34;Noto Color Emoji\&#34;; font-size: 15px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: pre-wrap; background-color: rgb(253, 247, 218); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgba(39, 43, 32, 0.77); font-family: ui-sans-serif, system-ui, -apple-system, \&#34;system-ui\&#34;, \&#34;Segoe UI\&#34;, Roboto, \&#34;Helvetica Neue\&#34;, Arial, \&#34;Noto Sans\&#34;, sans-serif, \&#34;Apple Color Emoji\&#34;, \&#34;Segoe UI Emoji\&#34;, \&#34;Segoe UI Symbol\&#34;, \&#34;Noto Color Emoji\&#34;; font-size: 15px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: pre-wrap; background-color: rgb(253, 247, 218); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 17px;">“满大街都在卷 AI Agent，仿佛不搞个渗透智能体，就不算跟上了时代。 既然 Gemini 和 Claude 已经把底层逻辑跑通了，何必在重复的轮子上浪费算力？</span></span></span></span></p></div><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100006366" data-s="300,640" type="block" data-type="jpeg" src="https://wechat2rss.xlab.app/img-proxy/?k=3c4cf271&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FeZOA7OiaVuZicX75pysmDeIwUbFiaqRkzibg4AEHeicCcrQXUtbF1Jtv3wTkzsdnctrpLbmWXHJHQTYozR6e2JWHQibGia6cL9SMgdWKnvVaPDgQL0%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p><span style="color: rgba(39, 43, 32, 0.77);font-family: ui-sans-serif, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, &#34;Noto Sans&#34;, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Color Emoji&#34;;font-size: 15px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: pre-wrap;background-color: rgb(253, 247, 218);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 17px;">外界都在忙着给 AI 注入各种‘智能体’，试图用算法模拟万物。 但我觉得，好东西不需要过度包装，就像这摊上的枇杷，只要时令到了，自然会甜。</span></span></span></p><p><span style="color: rgba(39, 43, 32, 0.77);font-family: ui-sans-serif, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, &#34;Noto Sans&#34;, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Color Emoji&#34;;font-size: 15px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: pre-wrap;background-color: rgb(253, 247, 218);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 17px;"> 拒绝重复造轮子，只愿在喧嚣里，守住那份成熟的本味。 —— 枇杷熟了。</span></span></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=af252749&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MzkzOTYzOQ%3D%3D%26mid%3D2247490018%26idx%3D1%26sn%3D39fe7e9694b1e1874713488486739ad4">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 14 Apr 2026 21:44:00 +0800</pubDate>
    </item>
    <item>
      <title>别让低效率的 AI成为你技术进阶的精神枷锁</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MzkzOTYzOQ==&amp;mid=2247490013&amp;idx=1&amp;sn=4cdd6058ab1980154e90e06e0fef1b6d</link>
      <description>作为一名技术研究者，我们最宝贵的资产是什么？不是多少行代码，也不是多少篇论文，而是那份能够心无旁骛、深挖逻辑的“深度专注力”。&#xA;但最近，我发现一种新型的“技术焦虑”正在蔓延。&#xA;这种焦虑并非源于技术的壁垒，而是源于一种无意义的、循环往复的“低水平试错”。当你试图用一个逻辑能力不足的免费模型去解决复杂的技术难题时，你会陷入一种可怕的怪圈：输入指令 $\rightarrow$ 等待输出 $\rightarrow$ 发现逻辑错误 $\rightarrow$ 调整 Prompt $\rightarrow$ 再次等待 $\rightarrow$ 依然失败。&#xA;这种“在等待中产生的焦虑”极其消耗人。你以为你在利用 AI 提效，实际上你是在用昂贵的认知带宽，去填补一个低级工具带来的逻辑鸿沟。每一分钟在反复修改 Prompt 上的挣扎，都是一种严重的内耗，它在无形中磨损你的创造力，让你从“研究者”退化成了“提示词修理工”。&#xA;真正的“格局打开”，是TMD学会识别并拒绝这种无效的沉没成本。&#xA;我们要意识到，时间才是最昂贵的变量，而工具的订阅费只是极小的常数。当你通过支付一笔微小的订阅费用，换取一个逻辑严密、指令遵循度极高的顶尖模型时，你买到的不仅仅是更准确的回答，更是买回了那个可以自由思考、不再被琐碎试错打断的“专注时空”。&#xA;停止在廉价的工具里寻找效率的幻觉。升级你的工具链，把精力留给真正具有挑战性的架构设计和算法突破。拒绝内耗，从给自己的生产力工具“升舱”开始。&#xA;感谢我的老婆，我的格局已经打开！</description>
      <content:encoded><![CDATA[<p><span>枇杷熟了</span> <span>2026-04-09 21:49</span> <span style="display: inline-block;">北京</span></p>






  
  
  <p>作为一名技术研究者，我们最宝贵的资产是什么？不是多少行代码，也不是多少篇论文，而是那份能够心无旁骛、深挖逻辑的“深度专注力”。</p><p>但最近，我发现一种新型的“技术焦虑”正在蔓延。</p><p>这种焦虑并非源于技术的壁垒，而是源于一种无意义的、循环往复的“低水平试错”。当你试图用一个逻辑能力不足的免费模型去解决复杂的技术难题时，你会陷入一种可怕的怪圈：输入指令 $\rightarrow$ 等待输出 $\rightarrow$ 发现逻辑错误 $\rightarrow$ 调整 Prompt $\rightarrow$ 再次等待 $\rightarrow$ 依然失败。</p><p>这种“在等待中产生的焦虑”极其消耗人。你以为你在利用 AI 提效，实际上你是在用昂贵的认知带宽，去填补一个低级工具带来的逻辑鸿沟。每一分钟在反复修改 Prompt 上的挣扎，都是一种严重的内耗，它在无形中磨损你的创造力，让你从“研究者”退化成了“提示词修理工”。</p><p>真正的“格局打开”，是TMD学会识别并拒绝这种无效的沉没成本。</p><p>我们要意识到，时间才是最昂贵的变量，而工具的订阅费只是极小的常数。当你通过支付一笔微小的订阅费用，换取一个逻辑严密、指令遵循度极高的顶尖模型时，你买到的不仅仅是更准确的回答，更是买回了那个可以自由思考、不再被琐碎试错打断的“专注时空”。</p><p>停止在廉价的工具里寻找效率的幻觉。升级你的工具链，把精力留给真正具有挑战性的架构设计和算法突破。拒绝内耗，从给自己的生产力工具“升舱”开始。</p><p>感谢我的老婆，我的格局已经打开！</p>
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=416ed48c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FeZOA7OiaVuZibn9anfiajs3wibXIvbJvsYxIAH5W2VvRpibGj02FpFH2udDEx5vrPXCoVHEcTCj4iceicIP8c2iakjP1SgskLSvtb9aXPDP3pTsqJYQ%2F0%3Fwx_fmt%3Djpeg"/></p><p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1bf52a15&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FeZOA7OiaVuZicPmPiayuMBMObpqRYftI758k9GWic4l3t80ZBAKJwKicXI6icXtNxJL76kbyPUYOsVibXVQIg5U1DONp2MJ5WTlm2UAjQliaBdxic7ibM%2F0%3Fwx_fmt%3Djpeg"/></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=5dfa7f5a&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MzkzOTYzOQ%3D%3D%26mid%3D2247490013%26idx%3D1%26sn%3D4cdd6058ab1980154e90e06e0fef1b6d">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 09 Apr 2026 21:49:00 +0800</pubDate>
    </item>
    <item>
      <title>紧急预警 | AI开发者必看LiteLLM遭PyPI供应链投毒</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MzkzOTYzOQ==&amp;mid=2247489999&amp;idx=1&amp;sn=342415eb7c1402f6320d8f78b18b4350</link>
      <description>⚠️ 核心预警一条命令 pip install litellm 即可泄露你的全部密钥！</description>
      <content:encoded><![CDATA[<p><span>枇杷哥</span> <span>2026-03-26 08:55</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=3a62b2af&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FeZOA7OiaVuZiba95lytYcIfcHqzhuZfy0oibrXZXznW7MkqbiafL3w2ftQf29P563tpBC69Jc6R5FjCdbPL3de5Dmq1Yg2aZk6zz4G64GYESGBQ%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>⚠️ 核心预警一条命令 pip install litellm 即可泄露你的全部密钥！</p>
  <div><p><span leaf="">⚠️ 核心预警</span><span leaf="">一条命令 </span><code></code></p><p><code><span leaf="">pip install litellm</span></code><span leaf=""> 即可泄露你的全部密钥！</span></p><h2 style="color: rgb(44, 62, 80);font-size: 18px;border-left: 4px solid rgb(52, 152, 219);padding-left: 12px;margin: 24px 0px 16px;"><span leaf="">📢 事件速览</span></h2><p><span leaf="">2026年3月24日，AI开发者圈子里炸了锅。</span></p><p><span leaf="">月均下载量高达 </span><span style="background: rgb(255, 243, 205);padding: 2px 6px;border-radius: 3px;color: rgb(133, 100, 4);font-weight: bold;"><span leaf="">9700万次</span></span><span leaf=""> 的Python库 LiteLLM，在PyPI官方仓库悄悄上线了两个&#34;毒版本&#34;——</span><span style="background: rgb(248, 215, 218);color: rgb(114, 28, 36);padding: 2px 6px;border-radius: 3px;font-weight: bold;"><span leaf="">1.82.7</span></span><span leaf=""> 和 </span><span style="background: rgb(248, 215, 218);color: rgb(114, 28, 36);padding: 2px 6px;border-radius: 3px;font-weight: bold;"><span leaf="">1.82.8</span></span><span leaf="">。</span></p><p><span leaf="">这不是普通的Bug，而是一次精心策划的 </span><strong><span leaf="">供应链投毒攻击</span></strong><span leaf="">。</span></p><h2 style="color: rgb(44, 62, 80);font-size: 18px;border-left: 4px solid rgb(52, 152, 219);padding-left: 12px;margin: 24px 0px 16px;"><span leaf="">🤖 LiteLLM 是什么？</span></h2><p><span leaf="">LiteLLM 是一个开源的 AI API 网关，支持开发者用统一格式调用 OpenAI、Anthropic、Azure 等 </span><strong><span leaf="">100多家</span></strong><span leaf=""> 大模型服务商的接口。</span></p><p><span leaf="">GitHub Star 数超过 40k，是 AI/ML 领域的基础设施级工具。</span></p><p><strong><span leaf="">为什么这次攻击格外危险？</span></strong><span leaf=""><br/></span><span leaf="">正因为它太基础、太常用，</span><strong><span leaf="">不仅是直接用户，所有以 LiteLLM 为依赖的下游项目，同样难逃波及。</span></strong></p><h2 style="color: rgb(44, 62, 80);font-size: 18px;border-left: 4px solid rgb(52, 152, 219);padding-left: 12px;margin: 24px 0px 16px;"><span leaf="">⚔️ 攻击是怎么运作的？</span></h2><p><span leaf="">这次攻击的技术手段堪称&#34;教科书级&#34;，分</span><strong><span leaf="">三个阶段</span></strong><span leaf="">执行：</span></p><h3 style="color: rgb(52, 73, 94);font-size: 16px;margin: 20px 0px 12px;"><span leaf="">第一阶段：信息收割</span></h3><p><span leaf="">恶意脚本在主机上静默扫描，窃取：</span></p><ul class="list-paddingleft-1"><li><p><span leaf="">🔑 SSH 私钥和配置文件</span></p></li><li><p><span leaf="">☁️ AWS / GCP / Azure 云凭证</span></p></li><li><p><span leaf="">🐳 Kubernetes 配置</span></p></li><li><p><span leaf="">📁 Git 凭证</span></p></li><li><p><span leaf="">🔐 </span><code><span leaf="">.env</span></code><span leaf=""> 文件（包含所有 API 密钥）</span></p></li><li><p><span leaf="">📝 Shell 历史记录</span></p></li><li><p><span leaf="">💰 加密货币钱包</span></p></li><li><p><span leaf="">🔒 SSL 私钥、CI/CD 机密、数据库密码</span></p></li></ul><h3 style="color: rgb(52, 73, 94);font-size: 16px;margin: 20px 0px 12px;"><span leaf="">第二阶段：横向渗透</span></h3><p><span leaf="">利用 Kubernetes 横向移动工具，在集群节点间悄悄扩散，扩大攻击面。</span></p><h3 style="color: rgb(52, 73, 94);font-size: 16px;margin: 20px 0px 12px;"><span leaf="">第三阶段：持久驻留</span></h3><p><span leaf="">植入伪装成&#34;系统遥测服务&#34;的后门，长期潜伏。</span></p><p><strong><span leaf="">最狡猾的地方：</span></strong><span leaf=""><br/></span><span leaf="">• </span><strong><span leaf="">1.82.7版本</span></strong><span leaf="">：恶意代码藏在 </span><code><span leaf="">proxy_server.py</span></code><span leaf="">，导入即执行</span><span leaf=""><br/></span><span leaf="">• </span><strong><span leaf="">1.82.8版本</span></strong><span leaf="">：利用 Python </span><code><span leaf="">.pth</span></code><span leaf=""> 特性，</span><strong><span leaf="">Python进程启动即自动触发，无需任何交互</span></strong></p><h2 style="color: rgb(44, 62, 80);font-size: 18px;border-left: 4px solid rgb(52, 152, 219);padding-left: 12px;margin: 24px 0px 16px;"><span leaf="">🔍 我中招了吗？立即自查</span></h2><table style="width: 1753px;border-collapse: collapse;font-size: 14px;"><tbody><tr><th style="background: rgb(52, 73, 94);color: white;padding: 12px;text-align: left;"><p><span leaf="">状态</span></p></th><th style="background: rgb(52, 73, 94);color: white;padding: 12px;text-align: left;"><p><span leaf="">版本号</span></p></th></tr><tr style="background: rgb(255, 235, 238);"><td style="padding: 12px;border-bottom: 1px solid rgb(236, 240, 241);"><p><span leaf="">❌ 危险版本</span></p></td><td style="padding: 12px;border-bottom: 1px solid rgb(236, 240, 241);"><strong><span leaf="">1.82.7、1.82.8</span></strong></td></tr><tr style="background: rgb(232, 245, 233);"><td style="padding: 12px;border-bottom: 1px solid rgb(236, 240, 241);"><p><span leaf="">✅ 安全版本</span></p></td><td style="padding: 12px;border-bottom: 1px solid rgb(236, 240, 241);"><strong><span leaf="">1.82.6 及以下</span></strong></td></tr></tbody></table><p><strong><span leaf="">检查当前版本：</span></strong></p><p><span leaf="">pip show litellm</span></p><p><strong><span leaf="">如果版本号是 1.82.7 或 1.82.8，立即执行：</span></strong></p><p><span style="color: rgb(104, 211, 145);"><span leaf=""># 卸载并重装安全版本</span></span><span leaf=""> pip uninstall litellm -y pip install litellm==1.82.6</span></p><h2 style="color: rgb(44, 62, 80);font-size: 18px;border-left: 4px solid rgb(52, 152, 219);padding-left: 12px;margin: 24px 0px 16px;"><span leaf="">🛡️ 不只是卸载这么简单</span></h2><p><span leaf="">如果你已经安装过恶意版本，</span><strong><span leaf="">卸载只是第一步</span></strong><span leaf="">，更重要的是：</span></p><ul style="list-style: none;padding: 0px;" class="list-paddingleft-1"><li style="padding: 10px 0px 10px 32px;border-bottom: 1px dashed rgb(224, 224, 224);"><strong><span leaf="">立即轮换所有密钥</span></strong><p><span leaf="">：AWS、GCP、Azure、OpenAI、Anthropic 等所有 API Key</span></p></li><li style="padding: 10px 0px 10px 32px;border-bottom: 1px dashed rgb(224, 224, 224);"><strong><span leaf="">检查 SSH 密钥</span></strong><p><span leaf="">：吊销并重新生成</span></p></li><li style="padding: 10px 0px 10px 32px;border-bottom: 1px dashed rgb(224, 224, 224);"><strong><span leaf="">审查云账单</span></strong><p><span leaf="">：检查是否有异常资源创建或访问记录</span></p></li><li style="padding: 10px 0px 10px 32px;border-bottom: 1px dashed rgb(224, 224, 224);"><strong><span leaf="">检查 Kubernetes 集群</span></strong><p><span leaf="">：排查是否有未知 Pod 或服务</span></p></li><li style="padding: 10px 0px 10px 32px;border-bottom: 1px dashed rgb(224, 224, 224);"><strong><span leaf="">扫描持久化后门</span></strong><p><span leaf="">：检查系统服务、定时任务、</span><code><span leaf="">.pth</span></code><span leaf=""> 文件</span></p></li></ul><h2 style="color: rgb(44, 62, 80);font-size: 18px;border-left: 4px solid rgb(52, 152, 219);padding-left: 12px;margin: 24px 0px 16px;"><span leaf="">📊 目前状态</span></h2><p><strong><span leaf="">✅ 好消息</span></strong><span leaf=""><br/></span><span leaf="">• 恶意版本已从 PyPI 撤下</span><span leaf=""><br/></span><span leaf="">• PyPI 隔离措施已解除</span><span leaf=""><br/></span><span leaf="">• LiteLLM 维护者已公开确认并处置</span></p><p><strong><span leaf="">⚠️ 坏消息</span></strong><span leaf=""><br/></span><span leaf="">• 恶意版本在被发现前存在约 </span><strong><span leaf="">3小时</span></strong><span leaf="">，期间下载量不可估计</span><span leaf=""><br/></span><span leaf="">• 已安装的机器如未主动清理，后门可能仍在运行</span></p><h2 style="color: rgb(44, 62, 80);font-size: 18px;border-left: 4px solid rgb(52, 152, 219);padding-left: 12px;margin: 24px 0px 16px;"><span leaf="">💡 写在最后</span></h2><p><span leaf="">&#34;Simple pip install can steal your keys.&#34;</span><cite style="display: block;margin-top: 10px;font-style: normal;color: rgb(136, 136, 136);font-size: 14px;"><span leaf="">—— Andrej Karpathy</span></cite></p><p><span leaf="">供应链攻击正在成为针对开发者最高效的攻击手段之一。我们信任的每一个包，都可能成为入口。</span></p><p><strong><span leaf="">🛡️ 安全建议</span></strong><span leaf=""><br/></span><span leaf="">• 定期审查项目依赖版本</span><span leaf=""><br/></span><span leaf="">• 在 CI/CD 中引入依赖安全扫描（如 </span><code><span leaf="">pip-audit</span></code><span leaf="">、</span><code><span leaf="">safety</span></code><span leaf="">）</span><span leaf=""><br/></span><span leaf="">• 对关键凭证实施最小权限原则，并定期轮换</span></p><p><strong><span leaf="">安全不是一次性的检查，而是持续的习惯。</span></strong></p><p><span leaf="">如有疑问或需要应急响应支持，欢迎联系长亭安全应急响应中心</span></p><p style="font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">原文链接：<a href="https://mp.weixin.qq.com/s/gVxO9vNYu1gNvHnD9mPFsg" target="_blank">https://mp.weixin.qq.com/s/gVxO9vNYu1gNvHnD9mPFsg</a></span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=39a0d98e&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MzkzOTYzOQ%3D%3D%26mid%3D2247489999%26idx%3D1%26sn%3D342415eb7c1402f6320d8f78b18b4350">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 26 Mar 2026 08:55:00 +0800</pubDate>
    </item>
    <item>
      <title>枇杷熟了-全球网络安全日报2026-03-18</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MzkzOTYzOQ==&amp;mid=2247489991&amp;idx=1&amp;sn=71d6806bff3de9fec3fb202318ca463f</link>
      <description></description>
      <content:encoded><![CDATA[<p><span>枇杷哥</span> <span>2026-03-18 18:29</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=155e67d7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FeZOA7OiaVuZibkwCQcGIOn6Jru2DmfLyxYtIvzTZ0ov3RwMqlbfibMo6zAgC6AdYiabWV4sBAk8ibg0PAr2mgAOOyTayO1JHsB8S1p0EkibfG5qZM%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background: linear-gradient(135deg, rgb(102, 126, 234) 0%, rgb(118, 75, 162) 100%);padding: 45px 25px;text-align: center;box-shadow: rgba(0, 0, 0, 0.15) 0px 4px 20px;" data-pm-slice="0 0 []"><p style="color: rgba(255, 255, 255, 0.85);font-size: 13px;margin: 0px 0px 10px;letter-spacing: 3px;"><span leaf="">Daily Security Newsletter</span></p><h1 style="color: rgb(255, 255, 255);font-size: 26px;margin: 15px 0px;font-weight: bold;text-shadow: rgba(0, 0, 0, 0.25) 2px 2px 8px;"><span leaf="">🔐 全球网络安全日报</span></h1><p style="color: rgba(255, 255, 255, 0.95);margin: 20px 0px 10px;font-size: 16px;font-weight: 500;"><span leaf="">📅 2026年03月18日 Wednesday</span></p><p style="color: rgba(255, 255, 255, 0.8);font-size: 13px;"><span leaf="">每日精选全球网络安全最新研究、漏洞预警、技术动态、威胁情报</span></p></div><p style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background: linear-gradient(135deg, rgb(248, 249, 250) 0%, rgb(255, 255, 255) 100%);padding: 30px 20px;margin: 25px 15px;border-radius: 12px;"><h2 style="font-size: 18px;color: rgb(44, 62, 80);margin: 0px 0px 20px;font-weight: bold;display: flex;align-items: center;justify-content: center;"><span style="font-size: 24px;margin-right: 10px;"><span leaf="">📊</span></span><span leaf="">今日概览 · 共 81 条</span></h2><table style="width: 1195px;border-collapse: separate;border-spacing: 8px;"><tbody><tr><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(231, 76, 60, 0.12) 0%, rgba(231, 76, 60, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(231, 76, 60, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🚨</span></span><span style="color: rgb(231, 76, 60);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">漏洞与威胁</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">8</span></span></td><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(52, 152, 219, 0.12) 0%, rgba(52, 152, 219, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(52, 152, 219, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">📚</span></span><span style="color: rgb(52, 152, 219);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">技术研究</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">8</span></span></td></tr><tr><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(142, 68, 173, 0.12) 0%, rgba(142, 68, 173, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(142, 68, 173, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🔍</span></span><span style="color: rgb(142, 68, 173);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">威胁情报</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">8</span></span></td><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(39, 174, 96, 0.12) 0%, rgba(39, 174, 96, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(39, 174, 96, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🤖</span></span><span style="color: rgb(39, 174, 96);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">AI 安全与大模型</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">8</span></span></td></tr><tr><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(211, 84, 0, 0.12) 0%, rgba(211, 84, 0, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(211, 84, 0, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">☁️</span></span><span style="color: rgb(211, 84, 0);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">云安全</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">8</span></span></td><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(22, 160, 133, 0.12) 0%, rgba(22, 160, 133, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(22, 160, 133, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🏆</span></span><span style="color: rgb(22, 160, 133);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">漏洞平台</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">5</span></span></td></tr><tr><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(82, 92, 102, 0.12) 0%, rgba(82, 92, 102, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(82, 92, 102, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">📌</span></span><span style="color: rgb(82, 92, 102);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">社区与社交媒体</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">8</span></span></td><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(192, 57, 43, 0.12) 0%, rgba(192, 57, 43, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(192, 57, 43, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🇨🇳</span></span><span style="color: rgb(192, 57, 43);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">中国安全媒体</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">7</span></span></td></tr><tr><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(243, 156, 18, 0.12) 0%, rgba(243, 156, 18, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(243, 156, 18, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">📌</span></span><span style="color: rgb(243, 156, 18);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">区块链与 Web3 安全</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">8</span></span></td><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(39, 174, 96, 0.12) 0%, rgba(39, 174, 96, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(39, 174, 96, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">📌</span></span><span style="color: rgb(39, 174, 96);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">移动安全</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">8</span></span></td></tr><tr><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(142, 68, 173, 0.12) 0%, rgba(142, 68, 173, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(142, 68, 173, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">📌</span></span><span style="color: rgb(142, 68, 173);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">数据隐私与合规</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">5</span></span></td><td style="padding: 18px 12px;"></td></tr></tbody></table></p><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(231, 76, 60);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(231, 76, 60);padding-left: 15px;background: linear-gradient(90deg, rgba(231, 76, 60, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">🚨</span></span><span leaf="">漏洞与威胁</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(8条)</span></span></h2><div style="background: rgba(231, 76, 60, 0.06);border: 1px solid rgba(231, 76, 60, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> Ubuntu CVE-2026-3888漏洞让攻击者通过systemd清理定时漏洞获得根</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Ubuntu CVE-2026-3888 Bug Lets Attackers Gain Root via systemd Cleanup Timing Exploit</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">影响Ubuntu Desktop版本24.04及更高版本的默认安装的高度严重的安全漏洞可能被利用来将权限提升到根级别。该问题被跟踪为CVE-2026-3888 （ CVSS评分： 7.8 ） ，可能允许攻击者夺取对易受影响系统的控制权。“这个瑕疵……</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Wed, 18 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/ubuntu-cve-2026-3888-bug-lets-attackers.html" target="_blank">https://thehackernews.com/2026/03/ubuntu-cve-2026-3888-bug-lets-attackers.html</a></span></p></div><div style="background: rgba(231, 76, 60, 0.06);border: 1px solid rgba(231, 76, 60, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">2.</span></span><span leaf=""> Apple修复了在iOS和macOS上启用同源策略绕过的WebKit漏洞</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Apple Fixes WebKit Vulnerability Enabling Same-Origin Policy Bypass on iOS and macOS</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">苹果公司周二发布了第一轮后台安全改进，以解决影响iOS、iPadOS和macOS的WebKit中的安全漏洞。该漏洞被跟踪为CVE-2026-20643 （ CVSS分数：不适用） ，在WebKit的导航API中被描述为跨源问题，可能...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Wed, 18 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/apple-fixes-webkit-vulnerability.html" target="_blank">https://thehackernews.com/2026/03/apple-fixes-webkit-vulnerability.html</a></span></p></div><div style="background: rgba(231, 76, 60, 0.06);border: 1px solid rgba(231, 76, 60, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">3.</span></span><span leaf=""> 严重的未修补Telnetd漏洞(CVE-2026-32746)通过端口23启用未经身份验证的根RCE</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Critical Unpatched Telnetd Flaw (CVE-2026-32746) Enables Unauthenticated Root RCE via Port 23</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">网络安全研究人员披露了一个影响GNU InetUtils telnet守护程序(telnetd)的严重安全漏洞，未经身份验证的远程攻击者可以利用该漏洞以更高的权限执行任意代码。该漏洞被跟踪为CVE-2026-32746 ，带有CVSS SCOR...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Wed, 18 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/critical-telnetd-flaw-cve-2026-32746.html" target="_blank">https://thehackernews.com/2026/03/critical-telnetd-flaw-cve-2026-32746.html</a></span></p></div><div style="background: rgba(231, 76, 60, 0.06);border: 1px solid rgba(231, 76, 60, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">4.</span></span><span leaf=""> Amazon Bedrock、LangSmith和SGLang中的AI漏洞可实现数据泄露和RCE</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable Data Exfiltration and RCE</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">网络安全研究人员披露了使用域名系统(DNS)查询从人工智能(AI)代码执行环境中泄露敏感数据的新方法的详细信息。在周一发布的一份报告中， BeyondTrust透露，亚马逊基岩AgentCore代码解释器&#39;...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Tue, 17 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/ai-flaws-in-amazon-bedrock-langsmith.html" target="_blank">https://thehackernews.com/2026/03/ai-flaws-in-amazon-bedrock-langsmith.html</a></span></p></div><div style="background: rgba(231, 76, 60, 0.06);border: 1px solid rgba(231, 76, 60, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">5.</span></span><span leaf=""> LeakNet勒索软件通过黑客网站使用ClickFix ，部署Deno内存加载器</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：LeakNet Ransomware Uses ClickFix via Hacked Sites, Deploys Deno In-Memory Loader</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">被称为LeakNet的勒索软件操作采用了通过受感染网站提供的ClickFix社交工程策略作为初始访问方法。使用ClickFix ，用户被欺骗手动运行恶意命令来解决不存在的错误，这是一种背离...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Tue, 17 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/leaknet-ransomware-uses-clickfix-via.html" target="_blank">https://thehackernews.com/2026/03/leaknet-ransomware-uses-clickfix-via.html</a></span></p></div><div style="background: rgba(231, 76, 60, 0.06);border: 1px solid rgba(231, 76, 60, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">6.</span></span><span leaf=""> Apple推出首个后台安全改进更新以修复WebKit缺陷</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Apple pushes first Background Security Improvements update to fix WebKit flaw</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Apple发布了第一个后台安全改进更新，以修复在iPhone、iPad和Mac上被追踪为CVE-2026-20643的WebKit漏洞，而无需进行完整的操作系统升级。[...]</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Tue, 17 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.bleepingcomputer.com/news/security/apple-pushes-first-background-security-improvements-update-to-fix-webkit-flaw/" target="_blank">https://www.bleepingcomputer.com/news/security/apple-pushes-first-background-security-improvements-update-to-fix-webkit-flaw/</a></span></p></div><div style="background: rgba(231, 76, 60, 0.06);border: 1px solid rgba(231, 76, 60, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">7.</span></span><span leaf=""> GlassWorm恶意软件在GitHub、npm、VSCode、OpenVSX上攻击了400多个代码库</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：GlassWorm malware hits 400+ code repos on GitHub, npm, VSCode, OpenVSX</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">GlassWorm供应链活动已经卷土重来，针对GitHub、npm和VSCode/OpenVSX扩展上的数百个软件包、存储库和扩展进行了新的协调攻击。[...]</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Tue, 17 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.bleepingcomputer.com/news/security/glassworm-malware-hits-400-plus-code-repos-on-github-npm-vscode-openvsx/" target="_blank">https://www.bleepingcomputer.com/news/security/glassworm-malware-hits-400-plus-code-repos-on-github-npm-vscode-openvsx/</a></span></p></div><div style="background: rgba(231, 76, 60, 0.06);border: 1px solid rgba(231, 76, 60, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">8.</span></span><span leaf=""> 欧洲制裁中国和伊朗公司的网络攻击</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Europe sanctions Chinese and Iranian firms for cyberattacks</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">欧盟理事会已宣布对参与针对该地区关键基础设施的网络攻击的三个实体和两名个人实施制裁。[...]</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Tue, 17 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.bleepingcomputer.com/news/security/europe-sanctions-chinese-and-iranian-firms-for-cyberattacks/" target="_blank">https://www.bleepingcomputer.com/news/security/europe-sanctions-chinese-and-iranian-firms-for-cyberattacks/</a></span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(52, 152, 219);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(52, 152, 219);padding-left: 15px;background: linear-gradient(90deg, rgba(52, 152, 219, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">📚</span></span><span leaf="">技术研究</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(8条)</span></span></h2><div style="background: rgba(52, 152, 219, 0.06);border: 1px solid rgba(52, 152, 219, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> 面向Fabric的全新Microsoft Purview创新，可安全地加速您的人工智能转型</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：New Microsoft Purview innovations for Fabric to safely accelerate your AI transformation</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">随着组织采用人工智能，安全和治理仍然是安全人工智能转型和加速的核心原语。Microsoft安全博客上首次发布了面向Fabric的新Microsoft Purview创新，以安全地加速您的AI转型。</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Mon, 16 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://techcommunity.microsoft.com/blog/microsoft-security-blog/new-microsoft-purview-innovations-for-fabric-to-safely-accelerate-your-ai-transf/4502156" target="_blank">https://techcommunity.microsoft.com/blog/microsoft-security-blog/new-microsoft-purview-innovations-for-fabric-to-safely-accelerate-your-ai-transf/4502156</a></span></p></div><div style="background: rgba(52, 152, 219, 0.06);border: 1px solid rgba(52, 152, 219, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">2.</span></span><span leaf=""> 在线帮助： Microsoft Teams支持呼叫如何导致妥协</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Help on the line: How a Microsoft Teams support call led to compromise</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">对Microsoft Teams语音网络钓鱼攻击的DART调查显示了欺骗和可信工具如何实现以身份为导向的入侵以及如何阻止它们。在线帮助： Microsoft Teams支持呼叫如何导致妥协这篇文章首先出现在Microsoft安全博客上。</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Mon, 16 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.microsoft.com/en-us/security/blog/2026/03/16/help-on-the-line-how-a-microsoft-teams-support-call-led-to-compromise/" target="_blank">https://www.microsoft.com/en-us/security/blog/2026/03/16/help-on-the-line-how-a-microsoft-teams-support-call-led-to-compromise/</a></span></p></div><div style="background: rgba(52, 152, 219, 0.06);border: 1px solid rgba(52, 152, 219, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">3.</span></span><span leaf=""> AI agent的系统调试：介绍AgentRx框架</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Systematic debugging for AI agents: Introducing the AgentRx framework</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">随着人工智能代理从简单的聊天机器人过渡到能够管理云事件、导航复杂Web界面和执行多步骤API工作流程的自主系统，出现了一个新的挑战：透明度。当人类犯错时，我们通常可以追溯逻辑。但是当一个A……</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Thu, 12 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.microsoft.com/en-us/research/blog/systematic-debugging-for-ai-agents-introducing-the-agentrx-framework/" target="_blank">https://www.microsoft.com/en-us/research/blog/systematic-debugging-for-ai-agents-introducing-the-agentrx-framework/</a></span></p></div><div style="background: rgba(52, 152, 219, 0.06);border: 1px solid rgba(52, 152, 219, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">4.</span></span><span leaf=""> PlugMem ：将原始代理交互转化为可重用的知识</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：PlugMem: Transforming raw agent interactions into reusable knowledge</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">这似乎是违反直觉的：给人工智能代理更多的内存可能会降低它们的效率。随着交互日志的积累，它们变得越来越大，充满了不相关的内容，并且变得越来越难以使用。更多的内存意味着客服代表必须搜索大量过去的互动，以...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Tue, 10 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.microsoft.com/en-us/research/blog/from-raw-interaction-to-reusable-knowledge-rethinking-memory-for-ai-agents/" target="_blank">https://www.microsoft.com/en-us/research/blog/from-raw-interaction-to-reusable-knowledge-rethinking-memory-for-ai-agents/</a></span></p></div><div style="background: rgba(52, 152, 219, 0.06);border: 1px solid rgba(52, 152, 219, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">5.</span></span><span leaf=""> Phi-4推理-视觉和训练多模态推理模型的经验教训</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Phi-4-reasoning-vision and the lessons of training a multimodal reasoning model</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">我们很高兴地宣布Phi-4-reasoning-vision-15B ，这是一种150亿参数的开放权重多模态推理模型，可通过Microsoft Foundry （在新选项卡中打开）、HuggingFace （在新选项卡中打开）和GitHub （在新选项卡中打开）获得。Phi-4-reasoning-vision-15B是一种功能广泛的模型，可以...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Wed, 04 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.microsoft.com/en-us/research/blog/phi-4-reasoning-vision-and-the-lessons-of-training-a-multimodal-reasoning-model/" target="_blank">https://www.microsoft.com/en-us/research/blog/phi-4-reasoning-vision-and-the-lessons-of-training-a-multimodal-reasoning-model/</a></span></p></div><div style="background: rgba(52, 152, 219, 0.06);border: 1px solid rgba(52, 152, 219, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">6.</span></span><span leaf=""> 预告片： The Shape of Things to Come</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Trailer: The Shape of Things to Come</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">微软研究负责人Doug Burger介绍了他的新播客系列“The Shape of Things to Come” ，该系列探索了有关人工智能的基本真理以及该技术将如何重塑未来。文章预告片： The Shape of Things to Come首先出现在Microsoft Research上。</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Tue, 03 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.microsoft.com/en-us/research/podcast/trailer-the-shape-of-things-to-come/" target="_blank">https://www.microsoft.com/en-us/research/podcast/trailer-the-shape-of-things-to-come/</a></span></p></div><div style="background: rgba(52, 152, 219, 0.06);border: 1px solid rgba(52, 152, 219, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">7.</span></span><span leaf=""> CORPGEN推进人工智能代理的实际工作</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：CORPGEN advances AI agents for real work</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">到上午中午，典型的知识工作者已经开始处理客户报告、预算电子表格、幻灯片和电子邮件待办事项，所有这些都相互依赖，并且都需要同时关注。为了使人工智能代理在那种环境中真正有用，它们需要以相同的方式运行，但是……</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Thu, 26 Fe</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.microsoft.com/en-us/research/blog/corpgen-advances-ai-agents-for-real-work/" target="_blank">https://www.microsoft.com/en-us/research/blog/corpgen-advances-ai-agents-for-real-work/</a></span></p></div><div style="background: rgba(52, 152, 219, 0.06);border: 1px solid rgba(52, 152, 219, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">8.</span></span><span leaf=""> PACT 2026 ：为Rapid7合作伙伴提供更强大、更简单、更有利可图的途径</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：PACT 2026: A Stronger, Simpler, More Profitable Path for Rapid7 Partners</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">网络安全渠道正在快速发展。购买行为正在发生变化，客户正在重新思考他们如何评估解决方案。合作伙伴正在重新思考如何大规模交付价值。在这种环境下，供应商合作伙伴计划不能保持静态。大多数合作伙伴计划都是围绕...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Tue, 17 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.rapid7.com/blog/post/c-pact-2026-stronger-simpler-profitable-path-for-rapid7-partners" target="_blank">https://www.rapid7.com/blog/post/c-pact-2026-stronger-simpler-profitable-path-for-rapid7-partners</a></span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(142, 68, 173);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(142, 68, 173);padding-left: 15px;background: linear-gradient(90deg, rgba(142, 68, 173, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">🔍</span></span><span leaf="">威胁情报</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(8条)</span></span></h2><div style="background: rgba(142, 68, 173, 0.06);border: 1px solid rgba(142, 68, 173, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> 走进由2万多家假冒商店组成的网络</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Inside a network of 20,000+ fake shops</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">一个庞大的假商店网络，所有这些都是为了一个目的而建立的：窃取您的付款详细信息和个人数据。</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 威胁情报⏰ Wed, 18 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.malwarebytes.com/blog/scams/2026/03/inside-a-network-of-20000-fake-shops" target="_blank">https://www.malwarebytes.com/blog/scams/2026/03/inside-a-network-of-20000-fake-shops</a></span></p></div><div style="background: rgba(142, 68, 173, 0.06);border: 1px solid rgba(142, 68, 173, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">2.</span></span><span leaf=""> Emsisoft在2026年1月实现100%检测AVLab Advanced In-The-Wild恶意软件测试</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Emsisoft Achieves 100% Detection in January 2026 AVLab Advanced In-The-Wild Malware Test</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">在AVLab新收紧的测试标准下， Emsisoft Enterprise Security + EDR对395个真实世界的恶意软件威胁实现了100%的检测和业界领先的补救速度。POST Emsisoft在2026年1月实现了100%检测AVLab Advanced In-The-Wild恶意软件测试出现在...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 威胁情报⏰ Mon, 16 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.emsisoft.com/en/blog/47474/emsisoft-achieves-100-detection-in-january-2026-avlab-advanced-in-the-wild-malware-test/" target="_blank">https://www.emsisoft.com/en/blog/47474/emsisoft-achieves-100-detection-in-january-2026-avlab-advanced-in-the-wild-malware-test/</a></span></p></div><div style="background: rgba(142, 68, 173, 0.06);border: 1px solid rgba(142, 68, 173, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">3.</span></span><span leaf=""> 泄露前：为您的组织应对网络事件做好准备</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Before the Breach: Preparing Your Organization for Cyber Incidents</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">本文介绍了组织如何加强防御、保护凭据并制定事件响应计划，以便在网络入侵发生之前将损害降至最低。《入侵前：为您的组织应对网络事件做好准备》一文首次出现在Emsisoft |网络安全博客上。</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 威胁情报⏰ Mon, 16 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.emsisoft.com/en/blog/47511/before-the-breach-preparing-your-organization-for-cyber-incidents/" target="_blank">https://www.emsisoft.com/en/blog/47511/before-the-breach-preparing-your-organization-for-cyber-incidents/</a></span></p></div><div style="background: rgba(142, 68, 173, 0.06);border: 1px solid rgba(142, 68, 173, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">4.</span></span><span leaf=""> Emsisoft被AVLab评为2026年度产品，荣获最佳补救时间荣誉</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Emsisoft Named Product of the Year 2026 by AVLab, Earns Top Remediation Time Honor</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">AVLab的2026年度产品已经公布。Emsisoft Enterprise Security + EDR凭借2025年全系列测试的持续性能赢得了这一殊荣。帖子Emsisoft被AVLab评为2026年度产品，荣获Top Remediation Time Honor首次出现在Emsisoft |...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 威胁情报⏰ Thu, 12 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.emsisoft.com/en/blog/47482/emsisoft-named-product-of-the-year-2026-by-avlab-earns-top-remediation-time-honor/" target="_blank">https://www.emsisoft.com/en/blog/47482/emsisoft-named-product-of-the-year-2026-by-avlab-earns-top-remediation-time-honor/</a></span></p></div><div style="background: rgba(142, 68, 173, 0.06);border: 1px solid rgba(142, 68, 173, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">5.</span></span><span leaf=""> 2026.1中的新功能：维护版本</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：New in 2026.1: Maintenance release</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">本月的版本包括维护更新。帖子New in 2026.1 ：维护版本首次出现在Emsisoft |网络安全博客上。</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 威胁情报⏰ Fri, 20 Fe</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.emsisoft.com/en/blog/47336/new-in-2026-1-maintenance-release/" target="_blank">https://www.emsisoft.com/en/blog/47336/new-in-2026-1-maintenance-release/</a></span></p></div><div style="background: rgba(142, 68, 173, 0.06);border: 1px solid rgba(142, 68, 173, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">6.</span></span><span leaf=""> 网络安全范式是否已被打破？</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Is the Cybersecurity Paradigm Broken?</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">随着网络犯罪的升级和民族国家越来越模糊犯罪和国家支持的攻击之间的界限，推动进攻性网络威慑可能是可以理解的，但它带来的风险可能超过其吸引力。文章《Is the Cybersecurity Paradigm Broken?》首次出现在...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 威胁情报⏰ Mon, 16 Fe</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.emsisoft.com/en/blog/47294/is-the-cybersecurity-paradigm-broken/" target="_blank">https://www.emsisoft.com/en/blog/47294/is-the-cybersecurity-paradigm-broken/</a></span></p></div><div style="background: rgba(142, 68, 173, 0.06);border: 1px solid rgba(142, 68, 173, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">7.</span></span><span leaf=""> Critical-service.cc删除：停止弹出窗口和重定向</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Critical-service.cc removal: stop the pop-ups and redirects</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Critical-service.cc是一个基于浏览器的诈骗页面，可推送虚假警报、弹出窗口和重定向循环。它通常不是完整的系统感染，但它可能会将您拖入网络钓鱼页面、阴暗下载和反复出现的通知垃圾邮件。Critical-service.cc遵循与Hosting-con相同的攻略...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 威胁情报⏰ Wed, 18 Fe</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://gridinsoft.com/blogs/critical-service-cc-removal/" target="_blank">https://gridinsoft.com/blogs/critical-service-cc-removal/</a></span></p></div><div style="background: rgba(142, 68, 173, 0.06);border: 1px solid rgba(142, 68, 173, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">8.</span></span><span leaf=""> 假冒商店瞄准Milano Cortina 2026粉丝寻找Tina和Milo毛绒玩具</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Fake shops target Milano Cortina 2026 fans hunting for Tina and Milo plushies</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">诈骗商店正在迅速发展，以利用Milano Cortina 2026吉祥物。在一项民意调查中，从1600多名学生设计中挑选出来的白鼬兄弟姐妹Tina和Milo已成为必备纪念品，这种需求现在正被类似的店面武器化。吉祥物诞生了……</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 威胁情报⏰ Tue, 17 Fe</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://gridinsoft.com/blogs/fake-olympic-shops-tina-milo-2026/" target="_blank">https://gridinsoft.com/blogs/fake-olympic-shops-tina-milo-2026/</a></span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(39, 174, 96);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(39, 174, 96);padding-left: 15px;background: linear-gradient(90deg, rgba(39, 174, 96, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">🤖</span></span><span leaf="">AI 安全与大模型</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(8条)</span></span></h2><div style="background: rgba(39, 174, 96, 0.06);border: 1px solid rgba(39, 174, 96, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(39, 174, 96);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> 隆重推出LangSmith沙盒：安全的代理代码执行</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Introducing LangSmith Sandboxes: Secure Code Execution for Agents</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">使用LangSmith SDK在一行代码中启动沙盒。现在在私密预览中。</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 AI 安全与大模型⏰ Tue, 17 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://blog.langchain.com/introducing-langsmith-sandboxes-secure-code-execution-for-agents/" target="_blank">https://blog.langchain.com/introducing-langsmith-sandboxes-secure-code-execution-for-agents/</a></span></p></div><div style="background: rgba(39, 174, 96, 0.06);border: 1px solid rgba(39, 174, 96, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(39, 174, 96);font-weight: bold;margin-right: 8px;"><span leaf="">2.</span></span><span leaf=""> Open SWE ：内部编码代理的开源框架</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Open SWE: An Open-Source Framework for Internal Coding Agents</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Open SWE基于Deep Agents和LangGraph构建，为内部编码代理提供核心架构组件。</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 AI 安全与大模型⏰ Tue, 17 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://blog.langchain.com/open-swe-an-open-source-framework-for-internal-coding-agents/" target="_blank">https://blog.langchain.com/open-swe-an-open-source-framework-for-internal-coding-agents/</a></span></p></div><div style="background: rgba(39, 174, 96, 0.06);border: 1px solid rgba(39, 174, 96, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(39, 174, 96);font-weight: bold;margin-right: 8px;"><span leaf="">3.</span></span><span leaf=""> LangChain宣布推出采用NVIDIA打造的企业智能AI平台</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：LangChain Announces Enterprise Agentic AI Platform Built with NVIDIA</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">综合代理工程平台与NVIDIA AI相结合，使企业能够大规模构建、部署和监控生产级AI代理Press ReleaseSAN FRANCISCO ， 2026年3月16日/美通社/— LangSmith和开源框架背后的代理工程公司LangChain...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 AI 安全与大模型⏰ Mon, 16 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://blog.langchain.com/nvidia-enterprise/" target="_blank">https://blog.langchain.com/nvidia-enterprise/</a></span></p></div><div style="background: rgba(39, 174, 96, 0.06);border: 1px solid rgba(39, 174, 96, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(39, 174, 96);font-weight: bold;margin-right: 8px;"><span leaf="">4.</span></span><span leaf=""> 全新推出DEPLOY CLI</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Introducing deploy cli</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">我们很高兴推出部署cli ，这是langgraph-cli包中的一组新命令，可以直接从命令行轻松部署和管理代理。此新集合中的第一个命令langgraph deploy允许您将代理部署到</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 AI 安全与大模型⏰ Mon, 16 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://blog.langchain.com/introducing-deploy-cli/" target="_blank">https://blog.langchain.com/introducing-deploy-cli/</a></span></p></div><div style="background: rgba(39, 174, 96, 0.06);border: 1px solid rgba(39, 174, 96, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(39, 174, 96);font-weight: bold;margin-right: 8px;"><span leaf="">5.</span></span><span leaf=""> 如何提示Seedream 5.0</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：How to prompt Seedream 5.0</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Seedream 5.0为图像生成带来了多步推理、基于示例的编辑和深厚的领域知识。以下是您需要了解的信息。</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 AI 安全与大模型⏰ Tue, 24 Fe</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://replicate.com/blog/how-to-prompt-seedream-5" target="_blank">https://replicate.com/blog/how-to-prompt-seedream-5</a></span></p></div><div style="background: rgba(39, 174, 96, 0.06);border: 1px solid rgba(39, 174, 96, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(39, 174, 96);font-weight: bold;margin-right: 8px;"><span leaf="">6.</span></span><span leaf=""> Recraft V4 ：具有设计品味的图像生成</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Recraft V4: image generation with design taste</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Recraft V4生成以艺术为导向的图像和实际可编辑的SVG ，具有强大的构图、精确的文本渲染以及Recraft团队所谓的“设计品味”。&#34;现在在Replicate上有四种型号可供选择。</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 AI 安全与大模型⏰ Wed, 18 Fe</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://replicate.com/blog/recraft-v4" target="_blank">https://replicate.com/blog/recraft-v4</a></span></p></div><div style="background: rgba(39, 174, 96, 0.06);border: 1px solid rgba(39, 174, 96, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(39, 174, 96);font-weight: bold;margin-right: 8px;"><span leaf="">7.</span></span><span leaf=""> 在Replicate上运行Isaac 0.1</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Run Isaac 0.1 on Replicate</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Isaac 0.1是一个轻量级、接地的视觉语言模型，专为真实世界感知而构建。</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 AI 安全与大模型⏰ Wed, 26 No</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://replicate.com/blog/isaac-01" target="_blank">https://replicate.com/blog/isaac-01</a></span></p></div><div style="background: rgba(39, 174, 96, 0.06);border: 1px solid rgba(39, 174, 96, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(39, 174, 96);font-weight: bold;margin-right: 8px;"><span leaf="">8.</span></span><span leaf=""> 在Replicate上运行FLUX.2</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Run FLUX.2 on Replicate</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">FLUX.2带来了前所未有的细节、多引用支持和企业效率的专业级图像生成和编辑。</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 AI 安全与大模型⏰ Tue, 25 No</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://replicate.com/blog/run-flux-2-on-replicate" target="_blank">https://replicate.com/blog/run-flux-2-on-replicate</a></span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(211, 84, 0);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(211, 84, 0);padding-left: 15px;background: linear-gradient(90deg, rgba(211, 84, 0, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">☁️</span></span><span leaf="">云安全</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(8条)</span></span></h2><div style="background: rgba(211, 84, 0, 0.06);border: 1px solid rgba(211, 84, 0, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(211, 84, 0);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> AWS与德国的参与者保险公司一起完成第二次GDV社区审计</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：AWS completes the second GDV community audit with participant insurers in Germany</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">我们很高兴地宣布，亚马逊网络服务（ AWS ）已完成第二次GDV （德国保险协会）社区审核，来自德国保险业的36名成员参加了审核，在保险费方面覆盖了德国市场63%以上。社区...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 云安全⏰ Tue, 17 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://aws.amazon.com/blogs/security/aws-completes-the-second-gdv-community-audit-with-participant-insurers-in-germany/" target="_blank">https://aws.amazon.com/blogs/security/aws-completes-the-second-gdv-community-audit-with-participant-insurers-in-germany/</a></span></p></div><div style="background: rgba(211, 84, 0, 0.06);border: 1px solid rgba(211, 84, 0, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(211, 84, 0);font-weight: bold;margin-right: 8px;"><span leaf="">2.</span></span><span leaf=""> Amazon Connect将代理语音到语音语音体验扩展到伦敦（欧洲）地区，并添加了三种新的语音</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Amazon Connect expands agentic speech-to-speech voice experiences to the London (Europe) region and ...</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Amazon Connect现在在另一个AWS区域（欧洲（伦敦） ）提供代理语音到语音语音体验。Amazon Connect还在美国西班牙语和英国英语中增加了三个新的语音转语音语音： Pedro （ es-US ）、Amy （ en-GB ）和Brian （ en-GB ）。Amazon Connect的代理商...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 云安全⏰ Wed, 18 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://aws.amazon.com/about-aws/whats-new/2026/03/amazon-connect-london-europe-region/" target="_blank">https://aws.amazon.com/about-aws/whats-new/2026/03/amazon-connect-london-europe-region/</a></span></p></div><div style="background: rgba(211, 84, 0, 0.06);border: 1px solid rgba(211, 84, 0, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(211, 84, 0);font-weight: bold;margin-right: 8px;"><span leaf="">3.</span></span><span leaf=""> Amazon Connect语音AI代理现在支持13种新语言</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Amazon Connect voice AI agents now supports 13 new languages</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Amazon Connect现在支持13种新的语音人工智能代理语言，使语言区域总数达到40种。新语言包括阿拉伯语（沙特阿拉伯）、捷克语、丹麦语、荷兰语（比利时）、英语（爱尔兰）、英语（新西兰）、英语（威尔士）、德语（瑞士）、冰岛语、罗马尼亚语...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 云安全⏰ Tue, 17 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://aws.amazon.com/about-aws/whats-new/2026/03/amazon-connect-voice-ai-agents-13-languages/" target="_blank">https://aws.amazon.com/about-aws/whats-new/2026/03/amazon-connect-voice-ai-agents-13-languages/</a></span></p></div><div style="background: rgba(211, 84, 0, 0.06);border: 1px solid rgba(211, 84, 0, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(211, 84, 0);font-weight: bold;margin-right: 8px;"><span leaf="">4.</span></span><span leaf=""> Amazon SageMaker Unified Studio支持数据沿袭的聚合视图</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Amazon SageMaker Unified Studio supports aggregated view of data lineage</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Amazon SageMaker Unified Studio现在提供数据沿袭的聚合视图，显示对您的数据集有贡献的所有作业。聚合视图为您提供了整个谱系图中数据转换和依赖关系的完整画面，帮助您快速识别所有上游...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 云安全⏰ Tue, 17 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://aws.amazon.com/about-aws/whats-new/2026/03/amazon-sageMaker-unified-studio-aggregated-view" target="_blank">https://aws.amazon.com/about-aws/whats-new/2026/03/amazon-sageMaker-unified-studio-aggregated-view</a> -data-lineage/</span></p></div><div style="background: rgba(211, 84, 0, 0.06);border: 1px solid rgba(211, 84, 0, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(211, 84, 0);font-weight: bold;margin-right: 8px;"><span leaf="">5.</span></span><span leaf=""> SageMaker培训计划现在可以在不重新配置工作负载的情况下扩展现有产能承诺</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：SageMaker Training Plans now enables extending of existing capacity commitments without workload rec...</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">SageMaker培训计划允许您在指定时间范围内在集群大小最多64个实例中保留GPU容量。今天， Amazon SageMaker AI宣布，当您的AI工作负载比预期更长时，现在可以延长培训计划，确保不间断地访问电容...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 云安全⏰ Tue, 17 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://aws.amazon.com/about-aws/whats-new/2026/03/amazon-sagemaker-training-plan-extension/" target="_blank">https://aws.amazon.com/about-aws/whats-new/2026/03/amazon-sagemaker-training-plan-extension/</a></span></p></div><div style="background: rgba(211, 84, 0, 0.06);border: 1px solid rgba(211, 84, 0, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(211, 84, 0);font-weight: bold;margin-right: 8px;"><span leaf="">6.</span></span><span leaf=""> AWS BLU Insights现在是适用于大型机重构的AWS Transform</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：AWS Blu Insights is now AWS Transform for mainframe refactor</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">AWS BLU Insights功能现已作为AWS Transform的一部分提供，使客户能够从AWS Transform控制台启动大型机重构项目。此次发布在AWS Transform for mai中统一了所有三种大型机现代化模式—重构、重平台和重构...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 云安全⏰ Tue, 17 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://aws.amazon.com/about-aws/whats-new/2026/03/aws-transform-mainframe-refactor/" target="_blank">https://aws.amazon.com/about-aws/whats-new/2026/03/aws-transform-mainframe-refactor/</a></span></p></div><div style="background: rgba(211, 84, 0, 0.06);border: 1px solid rgba(211, 84, 0, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(211, 84, 0);font-weight: bold;margin-right: 8px;"><span leaf="">7.</span></span><span leaf=""> 推出精确数据控制的自定义区域</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Introducing Custom Regions for precision data control</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">我们正在扩大区域服务，增加新的预定义区域，并推出定制区域。客户现在可以为数据处理定义精确的地理边界，以满足其合规性和性能需求。</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 云安全⏰ Wed, 18 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://blog.cloudflare.com/custom-regions/" target="_blank">https://blog.cloudflare.com/custom-regions/</a></span></p></div><div style="background: rgba(211, 84, 0, 0.06);border: 1px solid rgba(211, 84, 0, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(211, 84, 0);font-weight: bold;margin-right: 8px;"><span leaf="">8.</span></span><span leaf=""> 为开放的互联网挺身而出：为什么我们对意大利的“盗版盾牌”罚款提出上诉</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Standing up for the open Internet: why we appealed Italy’s &#34;Piracy Shield&#34; fine</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Cloudflare正在就“盗版盾牌” （ Piracy Shield ）系统向意大利监管机构提出1400万欧元的罚款，该系统迫使提供商在没有监督的情况下阻止内容。我们正在挑战这一框架，以保护互联网免受不成比例的过度封锁和缺乏正当程序的影响。</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 云安全⏰ Mon, 16 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://blog.cloudflare.com/standing-up-for-the-open-internet/" target="_blank">https://blog.cloudflare.com/standing-up-for-the-open-internet/</a></span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(22, 160, 133);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(22, 160, 133);padding-left: 15px;background: linear-gradient(90deg, rgba(22, 160, 133, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">🏆</span></span><span leaf="">漏洞平台</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(5条)</span></span></h2><div style="background: rgba(22, 160, 133, 0.06);border: 1px solid rgba(22, 160, 133, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(22, 160, 133);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> CVE-2017-20187</span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">🔗 [阅读原文] (<a href="https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-20187)" target="_blank">https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-20187)</a> --- # # # 2. CVE-2017-7252 **来源 **: 漏洞平台 **时间 **: 2.1.0之前的Botan中的bcrypt密码哈希无法正确处理长度在57到72个字符之间的密码，这使得攻击者更容易确定明文密码。</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞平台⏰ ** UNSUPPPORTED WHEN ASSIGNED ** ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Magnesium-PHP up to 0.3.0. It has been classified as problematic. Affected is the function formatEmailString of the file src/Magnesium/Message/Base.php. The manipulation of the argument email/name leads ...</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-7252" target="_blank">https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-7252</a></span></p></div><div style="background: rgba(22, 160, 133, 0.06);border: 1px solid rgba(22, 160, 133, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(22, 160, 133);font-weight: bold;margin-right: 8px;"><span leaf="">2.</span></span><span leaf=""> CVE-2018-25092</span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">🔗 [阅读原文] (<a href="https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-25092)" target="_blank">https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-25092)</a> --- # # # 4. CVE-2018-25093 **来源 **: 漏洞平台 **时间 **: 在2.10.2之前的Vaerys-Dawn DiscordSailv2中发现了一个漏洞。 它已被评为严重。 受此问题影响的是组件标记处理程序的一些未知功能。 这种操作会导致访问控制不当。 升级到版本2.10.3能够解决此问题。...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞平台⏰ A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Command Mention Handler. The manipulation leads to improper access controls. Upgrading to version 2.10.3 is able to ad...</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-25093" target="_blank">https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-25093</a></span></p></div><div style="background: rgba(22, 160, 133, 0.06);border: 1px solid rgba(22, 160, 133, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(22, 160, 133);font-weight: bold;margin-right: 8px;"><span leaf="">3.</span></span><span leaf=""> CVE-2020-28407</span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">🔗 [阅读原文](<a href="https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-28407)" target="_blank">https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-28407)</a> --- ### 6. [GHSA-wc64-r4v7-rjwr] Malware in transform-modules-systemjs **来源**: 漏洞平台 **时间**: 2026-03-18 Any computer that has this package installed or running should be co...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞平台⏰ In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall.</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：tag:github.com,2008:GHSA-wc64-r4v7-rjwr</span></p></div><div style="background: rgba(22, 160, 133, 0.06);border: 1px solid rgba(22, 160, 133, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(22, 160, 133);font-weight: bold;margin-right: 8px;"><span leaf="">4.</span></span><span leaf=""> [GHSA-9xfj-83q4-hxj6] Malware in transform-dynamic-import</span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control o...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞平台⏰ 2026-03-18</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：tag:github.com,2008:GHSA-9xfj-83q4-hxj6</span></p></div><div style="background: rgba(22, 160, 133, 0.06);border: 1px solid rgba(22, 160, 133, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(22, 160, 133);font-weight: bold;margin-right: 8px;"><span leaf="">5.</span></span><span leaf=""> [GHSA-m6hv-9gh4-4c85] Malware in transform-json-strings</span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control o...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞平台⏰ 2026-03-18</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：tag:github.com,2008:GHSA-m6hv-9gh4-4c85</span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(82, 92, 102);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(82, 92, 102);padding-left: 15px;background: linear-gradient(90deg, rgba(82, 92, 102, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">📌</span></span><span leaf="">社区与社交媒体</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(8条)</span></span></h2><div style="background: rgba(82, 92, 102, 0.06);border: 1px solid rgba(82, 92, 102, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(82, 92, 102);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> 使用ACME续订信息(ARI)简化数百万个域的证书续订</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Simplifying Certificate Renewals for Millions of Domains with ACME Renewal Information (ARI)</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">评论</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 社区与社交媒体⏰ Tue, 17 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://letsencrypt.org/2026/03/17/acme-renewal-information-ari.html" target="_blank">https://letsencrypt.org/2026/03/17/acme-renewal-information-ari.html</a></span></p></div><div style="background: rgba(82, 92, 102, 0.06);border: 1px solid rgba(82, 92, 102, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(82, 92, 102);font-weight: bold;margin-right: 8px;"><span leaf="">2.</span></span><span leaf=""> 我们不需要通过入侵您的AI Agent来入侵您的AI Agent</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：We don&#39;t need to hack your AI Agent to hack your AI Agent</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">评论</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 社区与社交媒体⏰ Tue, 17 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://srlabs.de/blog/hacking-ai-agent" target="_blank">https://srlabs.de/blog/hacking-ai-agent</a></span></p></div><div style="background: rgba(82, 92, 102, 0.06);border: 1px solid rgba(82, 92, 102, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(82, 92, 102);font-weight: bold;margin-right: 8px;"><span leaf="">3.</span></span><span leaf=""> 从第一原则构建软件保护系统</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：building a software protection system from first principles</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">评论</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 社区与社交媒体⏰ Mon, 16 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://seg6.space/posts/software-protection-system/" target="_blank">https://seg6.space/posts/software-protection-system/</a></span></p></div><div style="background: rgba(82, 92, 102, 0.06);border: 1px solid rgba(82, 92, 102, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(82, 92, 102);font-weight: bold;margin-right: 8px;"><span leaf="">4.</span></span><span leaf=""> CVE-2026-2673的纯安全OpenSSL tarball版本</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Security-only OpenSSL tarball releases for CVE-2026-2673</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">评论</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 社区与社交媒体⏰ Mon, 16 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://blog.surgut.co.uk/2026/03/security-only-openssl-tarball-releases.html" target="_blank">https://blog.surgut.co.uk/2026/03/security-only-openssl-tarball-releases.html</a></span></p></div><div style="background: rgba(82, 92, 102, 0.06);border: 1px solid rgba(82, 92, 102, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(82, 92, 102);font-weight: bold;margin-right: 8px;"><span leaf="">5.</span></span><span leaf=""> 入侵Xbox One</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Hacking the Xbox One</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">评论</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 社区与社交媒体⏰ Mon, 16 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.youtube.com/watch?v=FTFn4UZsA5U" target="_blank">https://www.youtube.com/watch?v=FTFn4UZsA5U</a></span></p></div><div style="background: rgba(82, 92, 102, 0.06);border: 1px solid rgba(82, 92, 102, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(82, 92, 102);font-weight: bold;margin-right: 8px;"><span leaf="">6.</span></span><span leaf=""> 如何在Lightning Network SDK (CVSS 9.8)中找到关键身份验证绕过</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：How I Found a Critical Authentication Bypass in a Lightning Network SDK (CVSS 9.8)</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">通过Rust加密、webhook验证和真实世界漏洞利用的漏洞赏金之旅免责声明：此漏洞是通过官方漏洞赏金计划负责任地披露的。根据负责任的披露道德，程序名称和公司已被故意省略。所有测试...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 社区与社交媒体⏰ Wed, 18 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://infosecwriteups.com/how-i-found-a-critical-authentication-bypass-in-a-lightning-network-sdk-cvss-9-8-79f76eda1d84?source=rss----7b722bfd1b8d---4" target="_blank">https://infosecwriteups.com/how-i-found-a-critical-authentication-bypass-in-a-lightning-network-sdk-cvss-9-8-79f76eda1d84?source=rss----7b722bfd1b8d---4</a></span></p></div><div style="background: rgba(82, 92, 102, 0.06);border: 1px solid rgba(82, 92, 102, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(82, 92, 102);font-weight: bold;margin-right: 8px;"><span leaf="">7.</span></span><span leaf=""> 我是如何在主要的加密货币交易所发现完整的CSRF保护绕过以及发生了什么……</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：How I Discovered a Complete CSRF Protection Bypass on a Major Crypto Exchange And What Happened…</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">我如何在主要的加密货币交易所发现了一个完整的CSRF保护绕过以及接下来发生的事情一个关于持久性， Django内部的错误赏金故事，以及一个关于计划范围的艰难教训简介每个错误赏金猎人都有一个故事—这个发现感觉像是一个突破，只有...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 社区与社交媒体⏰ Wed, 18 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://infosecwriteups.com/how-i-discovered-a-complete-csrf-protection-bypass-on-a-major-crypto-exchange-and-what-happened-10c7fc794324?source=rss----7b722bfd1b8d---4" target="_blank">https://infosecwriteups.com/how-i-discovered-a-complete-csrf-protection-bypass-on-a-major-crypto-exchange-and-what-happened-10c7fc794324?source=rss----7b722bfd1b8d---4</a></span></p></div><div style="background: rgba(82, 92, 102, 0.06);border: 1px solid rgba(82, 92, 102, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(82, 92, 102);font-weight: bold;margin-right: 8px;"><span leaf="">8.</span></span><span leaf=""> 暗网： Google之外的真实存在</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：The Dark Web: What Really Exists Beyond Google</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">在隐藏的互联网中，大多数人永远不会看到继续阅读信息安全写作»</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 社区与社交媒体⏰ Wed, 18 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://infosecwriteups.com/the-dark-web-what-really-exists-beyond-google-00d2315134be?source=rss----7b722bfd1b8d---4" target="_blank">https://infosecwriteups.com/the-dark-web-what-really-exists-beyond-google-00d2315134be?source=rss----7b722bfd1b8d---4</a></span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(192, 57, 43);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(192, 57, 43);padding-left: 15px;background: linear-gradient(90deg, rgba(192, 57, 43, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">🇨🇳</span></span><span leaf="">中国安全媒体</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(7条)</span></span></h2><div style="background: rgba(192, 57, 43, 0.06);border: 1px solid rgba(192, 57, 43, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(192, 57, 43);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> 360龙虾卫士上线：九大能力专治OpenClaw“裸奔”</span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">OpenClaw的爆火，让2026年成为智能体全面落地的转折之年。AI正从“会聊天”的参谋，变成“会办事”的员工——随着OpenClaw开始进入办公、开发和内容创作等实际场景，恶意技能投毒、隐私泄露、API密钥被盗等安全事件频发。安全，成为这场变革中最关键的一环。 近日，360首次将“安全”作为智能体产品的核心基因，推出行业首创的“安全龙虾”系列产品，其中专攻OpenClaw风险的“360龙虾卫士”正式亮相。该产品采用“最小权限原则”和“人在回路”的核心防护策略，在不影响OpenCla...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 中国安全媒体⏰ Wed, 18 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.4hou.com/posts/OG1E" target="_blank">https://www.4hou.com/posts/OG1E</a></span></p></div><div style="background: rgba(192, 57, 43, 0.06);border: 1px solid rgba(192, 57, 43, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(192, 57, 43);font-weight: bold;margin-right: 8px;"><span leaf="">2.</span></span><span leaf=""> AI时代中国网络安全产业的五年变局|| 网络安全投融资的残酷分流</span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">网络安全行业投融资正迎来结构性分化，并非市场资金总量收缩，而是投资逻辑发生根本性转变。这个转变的根子，在前三篇已经埋好。商业篇讲过，客户不再为合规过检买单，要的是可量化的实战效果。技术篇说过，AI让攻防进入机器速度对抗，传统规则库形同虚设。人才篇则指出，行业正在淘汰人肉报警器，争抢能指挥AI Agent的复合型人才。这三条线拧在一起，直接改写了资本评估安全企业的坐标系，以前看政企覆盖、等保资质、项目规模，现在只看一件事：你的AI能不能真的挡住攻击，能不能把安全从成本中心变成能赚钱的业务。2025...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 中国安全媒体⏰ Wed, 18 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.4hou.com/posts/MXY1" target="_blank">https://www.4hou.com/posts/MXY1</a></span></p></div><div style="background: rgba(192, 57, 43, 0.06);border: 1px solid rgba(192, 57, 43, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(192, 57, 43);font-weight: bold;margin-right: 8px;"><span leaf="">3.</span></span><span leaf=""> 嘶吼安全动态｜360回应“安全龙虾”私钥泄露：已吊销证书，系发布失误微博 Delta工业通信系统曝高危漏洞</span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">嘶吼安全动态【国内新闻】360回应“安全龙虾”私钥泄露：已吊销证书，系发布失误微博摘要：360安全龙虾被曝安装包含明文SSL私钥，公司称系发布失误，已吊销证书并启动内部排查，用户不受影响。原文链接：<a href="https://m.weibo.cn/detail/5277399274750553钉钉CEO：OpenClaw" target="_blank">https://m.weibo.cn/detail/5277399274750553钉钉CEO：OpenClaw</a> 15%技能可窃取密钥或部署木马摘要：OpenClaw默认配置脆弱，全球超27万实例暴露公网，其技能市场遭供应链污染，15%技能含恶意指令。原文链接：<a href="http://m.toutiao.com..." target="_blank">http://m.toutiao.com...</a></span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 中国安全媒体⏰ Wed, 18 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.4hou.com/posts/NGZ8" target="_blank">https://www.4hou.com/posts/NGZ8</a></span></p></div><div style="background: rgba(192, 57, 43, 0.06);border: 1px solid rgba(192, 57, 43, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(192, 57, 43);font-weight: bold;margin-right: 8px;"><span leaf="">4.</span></span><span leaf=""> 企业邮箱防钓鱼攻击：邮件安全网关的3大核心技术</span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">企业邮件钓鱼攻击正呈爆发式增长，风险不容忽视。Coremail CACTER邮件安全发布的《2025年第四季度企业邮箱安全性研究报告》显示：钓鱼邮件数量激增至4.25亿封，环比上涨148.65%。当员工误点击钓鱼邮件链接时，可能导致邮箱账号被盗、企业数据泄露、财务诈骗（BEC攻击）等严重安全事件。因此很多企业开始部署邮件安全网关来防御邮件攻击。但一个常见问题是：邮件安全网关能拦住所有钓鱼攻击吗？答案是：邮件安全网关可以拦截绝大多数钓鱼邮件，但无法100%拦截所有定制化攻击，企业需要“技术防护+员...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 中国安全媒体⏰ Tue, 17 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.4hou.com/posts/LGXv" target="_blank">https://www.4hou.com/posts/LGXv</a></span></p></div><div style="background: rgba(192, 57, 43, 0.06);border: 1px solid rgba(192, 57, 43, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(192, 57, 43);font-weight: bold;margin-right: 8px;"><span leaf="">5.</span></span><span leaf=""> 新窃密技术预警：现代光学鼠标窃密</span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Mic-E-Mouse attack，即“麦克风-鼠标攻击”，是一种侧信道技术，在这种技术下，攻击者无需麦克风即可通过高DPI光学鼠标传感器实现窃听。原理如下：你的电脑鼠标，特别是高分辨率光学鼠标（例如，配备高DPI传感器的现代游戏鼠标、或精密鼠标）——可以捕捉到你说话时产生的微小振动，并将这些振动重构为语音。事实上，会谈时的声音会使桌面振动，桌面表面会发生微小的移动。光学传感器会捕捉到这些移动，然后通过信号处理和机器学习，就可以完成余下的音频复原工作。重要启示：该攻击再次挑战了人们对隐私和硬件...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 中国安全媒体⏰ Tue, 17 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.4hou.com/posts/Aryj" target="_blank">https://www.4hou.com/posts/Aryj</a></span></p></div><div style="background: rgba(192, 57, 43, 0.06);border: 1px solid rgba(192, 57, 43, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(192, 57, 43);font-weight: bold;margin-right: 8px;"><span leaf="">6.</span></span><span leaf=""> 吾爱破解论坛精华集2025</span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">[md] <a class="wx_topic_link" topic-id="mmvwc8es-6pn9mx" style="color: #576B95 !important;" data-topic="1">#导语</a> 今年的《吾爱破解精华集》论坛收到了来自135位同学发布的共计**217**篇 优秀、精华帖（**精华帖111篇**）。同学们的每一篇优秀文章都是宝贵的财富，请允许我以吾爱破解论坛站务组的名誉对向你们表示真诚的感谢！ 本年度电子书在部分代码的优化和文章整 ...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 中国安全媒体⏰ Tue, 17 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.52pojie.cn/forum.php?mod=viewthread&amp;tid=2097399" target="_blank">https://www.52pojie.cn/forum.php?mod=viewthread&amp;tid=2097399</a></span></p></div><div style="background: rgba(192, 57, 43, 0.06);border: 1px solid rgba(192, 57, 43, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(192, 57, 43);font-weight: bold;margin-right: 8px;"><span leaf="">7.</span></span><span leaf=""> 《吾爱破解精华集 2025》电子书自解压文件InnoSetup安装脚本</span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">[md] 《吾爱破解精华集 2025》电子书自解压文件InnoSetup安装脚本 ========================================================= # 【基本信息】 源码名称：《吾爱破解精华集 2025》电子书自解压文件InnoSetup安装 ...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 中国安全媒体⏰ Tue, 17 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.52pojie.cn/forum.php?mod=viewthread&amp;tid=2097395" target="_blank">https://www.52pojie.cn/forum.php?mod=viewthread&amp;tid=2097395</a></span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(243, 156, 18);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(243, 156, 18);padding-left: 15px;background: linear-gradient(90deg, rgba(243, 156, 18, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">📌</span></span><span leaf="">区块链与 Web3 安全</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(8条)</span></span></h2><div style="background: rgba(243, 156, 18, 0.06);border: 1px solid rgba(243, 156, 18, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(243, 156, 18);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> OFAC が北朝鮮 IT 労働者の暗号資産ネットワークを制裁指定、WMD 資金調達スキームの全容</span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">※この記事は自動翻訳されています。正確な内容につきましては原文をご参照ください。 要約 OFAC は、2024 年に約 8 億ドルを生み出し北朝鮮の兵器開発に資金を供給した北朝鮮 IT 労働者スキームを仲介した 6 人の個人と 2 つの団体を指定しました。 主要な仲介者は、2023 年半ばから 2025 年半ばにかけて、北朝鮮 IT 労働者のために約 250… The post OFAC が北朝鮮 IT 労働者の暗号資産ネットワークを制裁指定、WMD 資金調達スキームの全容 appe...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 区块链与 Web3 安全⏰ Tue, 17 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.chainalysis.com/blog/ofac-targets-north-korean-it-workers-crypto-march-2026-japanese/" target="_blank">https://www.chainalysis.com/blog/ofac-targets-north-korean-it-workers-crypto-march-2026-japanese/</a></span></p></div><div style="background: rgba(243, 156, 18, 0.06);border: 1px solid rgba(243, 156, 18, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(243, 156, 18);font-weight: bold;margin-right: 8px;"><span leaf="">2.</span></span><span leaf=""> FATF 報告書が示すステーブルコイン規制の転換点：流通市場モニタリングの時代へ</span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">※この記事は自動翻訳されています。正確な内容につきましては原文をご参照ください。 要約 84% という現実： ステーブルコインは今や、不正な暗号資産トランザクションの 84% を占めています。普及の拡大に伴い、ステーブルコインに特化したコンプライアンスが喫緊の規制課題となっています。 「流通市場」の時代： 規制の焦点は、入出金の監視にとどまりません。FATF は、個人ウォレットを介した P2P トランザクションを含むステーブルコインのライフサイクル全体の監視を求めており、発行者にはオンチェーンデ...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 区块链与 Web3 安全⏰ Mon, 16 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.chainalysis.com/blog/fatf-targeted-report-secondary-market-monitoring-stablecoins-march-2026-japanese/" target="_blank">https://www.chainalysis.com/blog/fatf-targeted-report-secondary-market-monitoring-stablecoins-march-2026-japanese/</a></span></p></div><div style="background: rgba(243, 156, 18, 0.06);border: 1px solid rgba(243, 156, 18, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(243, 156, 18);font-weight: bold;margin-right: 8px;"><span leaf="">3.</span></span><span leaf=""> OFAC Targets North Korean IT Worker Networks Using Cryptocurrency to Fund WMD Programs</span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">TL;DR OFAC designated six individuals and two entities for facilitating North Korean IT worker schemes that generated nearly $800 million… The post OFAC Targets North Korean IT Worker Networks Using Cryptocurrency to Fund WMD Programs appeared ...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 区块链与 Web3 安全⏰ Thu, 12 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.chainalysis.com/blog/ofac-targets-north-korean-it-workers-crypto-march-2026/" target="_blank">https://www.chainalysis.com/blog/ofac-targets-north-korean-it-workers-crypto-march-2026/</a></span></p></div><div style="background: rgba(243, 156, 18, 0.06);border: 1px solid rgba(243, 156, 18, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(243, 156, 18);font-weight: bold;margin-right: 8px;"><span leaf="">4.</span></span><span leaf=""> Assessing the FATF Targeted Report: The Shift Toward Secondary Market Monitoring for Stablecoins</span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">TL;DR The 84% reality: Stablecoins now account for the vast majority of illicit crypto transaction volume. This shift — aligned… The post Assessing the FATF Targeted Report: The Shift Toward Secondary Market Monitoring for Stablecoins appeared ...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 区块链与 Web3 安全⏰ Wed, 11 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.chainalysis.com/blog/fatf-targeted-report-secondary-market-monitoring-stablecoins-march-2026/" target="_blank">https://www.chainalysis.com/blog/fatf-targeted-report-secondary-market-monitoring-stablecoins-march-2026/</a></span></p></div><div style="background: rgba(243, 156, 18, 0.06);border: 1px solid rgba(243, 156, 18, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(243, 156, 18);font-weight: bold;margin-right: 8px;"><span leaf="">5.</span></span><span leaf=""> Crypto Crime in 2025 Was Primarily Driven by 694% Surge in State-Driven Sanctions Evasion Volume</span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">TL;DR The value received by sanctioned entities surged 694% in 2025, driving total illicit transaction volume to a record $154… The post Crypto Crime in 2025 Was Primarily Driven by 694% Surge in State-Driven Sanctions Evasion Volume appeared f...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 区块链与 Web3 安全⏰ Thu, 05 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.chainalysis.com/blog/crypto-sanctions-2026/" target="_blank">https://www.chainalysis.com/blog/crypto-sanctions-2026/</a></span></p></div><div style="background: rgba(243, 156, 18, 0.06);border: 1px solid rgba(243, 156, 18, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(243, 156, 18);font-weight: bold;margin-right: 8px;"><span leaf="">6.</span></span><span leaf=""> The Promise of Ethereum: Introducing the EF Mandate</span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Dearest Friends, Today we are publishing the EF Mandate, a document that serves as part constitution, part manifesto, and part guide for the Ethereum Foundation. It is written primarily for the EF itself: to be clear about what we are here to do, the...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 区块链与 Web3 安全⏰ Fri, 13 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://blog.ethereum.org/en/2026/03/13/ef-mandate" target="_blank">https://blog.ethereum.org/en/2026/03/13/ef-mandate</a></span></p></div><div style="background: rgba(243, 156, 18, 0.06);border: 1px solid rgba(243, 156, 18, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(243, 156, 18);font-weight: bold;margin-right: 8px;"><span leaf="">7.</span></span><span leaf=""> This Is Fine (Until the Grant Runs Out)</span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">The commons called. It wants a runway. Every so often, in the blockchain world’s usual cycle of funding scares, a team maintaining a widely used open source public good declares mayday. Libp2p is a core infrastructure stack that powers multiple Ether...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 区块链与 Web3 安全⏰ Fri, 27 Fe</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://blog.ethereum.org/en/2026/02/27/project-odin" target="_blank">https://blog.ethereum.org/en/2026/02/27/project-odin</a></span></p></div><div style="background: rgba(243, 156, 18, 0.06);border: 1px solid rgba(243, 156, 18, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(243, 156, 18);font-weight: bold;margin-right: 8px;"><span leaf="">8.</span></span><span leaf=""> Treasury Staking Initiative</span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">The Ethereum Foundation has begun staking a portion of its treasury, in line with its Treasury Policy announced last year. Approximately 70,000 ETH is being staked with rewards directed back to the EF treasury....</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 区块链与 Web3 安全⏰ Tue, 24 Fe</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://blog.ethereum.org/en/2026/02/24/staking" target="_blank">https://blog.ethereum.org/en/2026/02/24/staking</a></span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(39, 174, 96);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(39, 174, 96);padding-left: 15px;background: linear-gradient(90deg, rgba(39, 174, 96, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">📌</span></span><span leaf="">移动安全</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(8条)</span></span></h2><div style="background: rgba(39, 174, 96, 0.06);border: 1px solid rgba(39, 174, 96, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(39, 174, 96);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> Get inspired and take your apps to desktop</span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Posted by Ivy Knight, Senior Design Advocate, AndroidWe&#39;re thrilled to announce major updates to our design resources, giving you the comprehensive guidance you need to create polished, adaptive Android apps across all form factors! We now have ...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 移动安全⏰ Mon, 16 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://android-developers.googleblog.com/2026/03/Get-inspired-and-take-your-apps-to-desktop.html" target="_blank">https://android-developers.googleblog.com/2026/03/Get-inspired-and-take-your-apps-to-desktop.html</a></span></p></div><div style="background: rgba(39, 174, 96, 0.06);border: 1px solid rgba(39, 174, 96, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(39, 174, 96);font-weight: bold;margin-right: 8px;"><span leaf="">2.</span></span><span leaf=""> Room 3.0 - Modernizing the Room</span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Posted by Daniel Santiago Rivera, Software EngineerThe first alpha of Room 3.0 has been released! Room 3.0 is a major breaking version of the library that focuses on Kotlin Multiplatform (KMP) and adds support for JavaScript and WebAssembly (WASM) on...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 移动安全⏰ Fri, 13 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://android-developers.googleblog.com/2026/03/room-30-modernizing-room.html" target="_blank">https://android-developers.googleblog.com/2026/03/room-30-modernizing-room.html</a></span></p></div><div style="background: rgba(39, 174, 96, 0.06);border: 1px solid rgba(39, 174, 96, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(39, 174, 96);font-weight: bold;margin-right: 8px;"><span leaf="">3.</span></span><span leaf=""> TikTok reduces code size by 58% and improves app performance for new features with Jetpack Compose</span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Posted by Ajesh R Pai, Developer Relations Engineer &amp; Ben Trengrove, Developer Relations EngineerTikTok is a global short-video platform known for its massive user base and innovative features. The team is constantly releasing updates, experiment...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 移动安全⏰ Fri, 13 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://android-developers.googleblog.com/2026/03/tiktok-reduces-code-size-by-58.html" target="_blank">https://android-developers.googleblog.com/2026/03/tiktok-reduces-code-size-by-58.html</a></span></p></div><div style="background: rgba(39, 174, 96, 0.06);border: 1px solid rgba(39, 174, 96, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(39, 174, 96);font-weight: bold;margin-right: 8px;"><span leaf="">4.</span></span><span leaf=""> Level Up: Test Sidekick and prepare for upcoming program milestones</span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Posted by Maru Ahues Bouza, PM Director, Games on Google PlayLast September, we shared our vision for the future of Google Play Games grounded in a core belief: the best way to drive your game’s success is to deliver a world-class player experience. ...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 移动安全⏰ Wed, 11 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://android-developers.googleblog.com/2026/03/level-up-your-game.html" target="_blank">https://android-developers.googleblog.com/2026/03/level-up-your-game.html</a></span></p></div><div style="background: rgba(39, 174, 96, 0.06);border: 1px solid rgba(39, 174, 96, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(39, 174, 96);font-weight: bold;margin-right: 8px;"><span leaf="">5.</span></span><span leaf=""> Expanding our stage for PC and paid titles</span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf=""> Posted by Aurash Mahbod, VP and GM, Games on Google PlayGoogle Play is proud to be the home of over 200,000 games—many of which defined the mobile-first era. But as cross-platform becomes the standard for players, we are evolving our ecosystem ...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 移动安全⏰ Wed, 11 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://android-developers.googleblog.com/2026/03/building-a-bigger-stage.html" target="_blank">https://android-developers.googleblog.com/2026/03/building-a-bigger-stage.html</a></span></p></div><div style="background: rgba(39, 174, 96, 0.06);border: 1px solid rgba(39, 174, 96, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(39, 174, 96);font-weight: bold;margin-right: 8px;"><span leaf="">6.</span></span><span leaf=""> PhantomRaven NPM Supply-Chain Attack: How Remote Dependencies Hide Malware</span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">The PhantomRaven campaign shows how attackers can hide malware outside the npm registry using RDD, allowing malicious code to execute during installation while bypassing many traditional security scanners. This blog addresses why it is a particularly...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 移动安全⏰ Fri, 13 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.nowsecure.com/blog/2026/03/13/phantomraven-npm-supply-chain-attack-how-remote-dependencies-hide-malware/" target="_blank">https://www.nowsecure.com/blog/2026/03/13/phantomraven-npm-supply-chain-attack-how-remote-dependencies-hide-malware/</a></span></p></div><div style="background: rgba(39, 174, 96, 0.06);border: 1px solid rgba(39, 174, 96, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(39, 174, 96);font-weight: bold;margin-right: 8px;"><span leaf="">7.</span></span><span leaf=""> Closing the Mobile Security Gap: What Mobile App Risk Intelligence Means for Mobile EDR</span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">What is Mobile App Risk Intelligence? Mobile App Risk Intelligence analyzes mobile applications to identify security, privacy and behavioral risks that could expose enterprise data. It evaluates issues such as insecure data storage, dangerous permiss...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 移动安全⏰ Tue, 10 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.nowsecure.com/blog/2026/03/10/closing-the-mobile-security-gap-what-mobile-app-risk-intelligence-means-for-mobile-edr/" target="_blank">https://www.nowsecure.com/blog/2026/03/10/closing-the-mobile-security-gap-what-mobile-app-risk-intelligence-means-for-mobile-edr/</a></span></p></div><div style="background: rgba(39, 174, 96, 0.06);border: 1px solid rgba(39, 174, 96, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(39, 174, 96);font-weight: bold;margin-right: 8px;"><span leaf="">8.</span></span><span leaf=""> Authenticated Mobile App Security Testing Finds 78% More Sensitive Data Risk</span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">It doesn’t take a particle physicist to figure out that authenticated mobile app security testing will give you better results. But I never really had data to back it up. Recently, NowSecure CTO David Weinstein analyzed about 105,000 mobile app asses...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 移动安全⏰ Wed, 25 Fe</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.nowsecure.com/blog/2026/02/25/authenticated-mobile-app-security-testing-finds-78-more-sensitive-data-risk/" target="_blank">https://www.nowsecure.com/blog/2026/02/25/authenticated-mobile-app-security-testing-finds-78-more-sensitive-data-risk/</a></span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(142, 68, 173);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(142, 68, 173);padding-left: 15px;background: linear-gradient(90deg, rgba(142, 68, 173, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">📌</span></span><span leaf="">数据隐私与合规</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(5条)</span></span></h2><div style="background: rgba(142, 68, 173, 0.06);border: 1px solid rgba(142, 68, 173, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> CUI vs. Classified vs. Other Sensitive Data: Understanding the Differences</span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Understand the key differences between CUI, classified, and sensitive data types—and how to secure each to meet compliance and reduce risk. The post CUI vs. Classified vs. Other Sensitive Data: Understanding the Differences appeared first on archTIS.</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 数据隐私与合规⏰ Tue, 28 Oc</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.spirion.com/blog/cui-vs-classified-vs-other-sensitive-data" target="_blank">https://www.spirion.com/blog/cui-vs-classified-vs-other-sensitive-data</a></span></p></div><div style="background: rgba(142, 68, 173, 0.06);border: 1px solid rgba(142, 68, 173, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">2.</span></span><span leaf=""> Not All DSPM Solutions Are Created Equal</span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Evaluate DSPM solutions with confidence. Ask the right questions to avoid blind spots in structured and unstructured data protection. The post Not All DSPM Solutions Are Created Equal appeared first on archTIS.</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 数据隐私与合规⏰ Thu, 09 Oc</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.spirion.com/blog/not-all-dspm-are-created-equal" target="_blank">https://www.spirion.com/blog/not-all-dspm-are-created-equal</a></span></p></div><div style="background: rgba(142, 68, 173, 0.06);border: 1px solid rgba(142, 68, 173, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">3.</span></span><span leaf=""> CMMC Final Rule Published: What It Means for DoD Contractors and How Spirion Can Help</span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">CMMC Final Rule is here. Learn what it means for DoD contractors and how Spirion accelerates compliance with NIST 800-171 and CUI protection. The post CMMC Final Rule Published: What It Means for DoD Contractors and How Spirion Can Help appeared firs...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 数据隐私与合规⏰ Thu, 18 Se</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.spirion.com/blog/cmmc-final-rule-published" target="_blank">https://www.spirion.com/blog/cmmc-final-rule-published</a></span></p></div><div style="background: rgba(142, 68, 173, 0.06);border: 1px solid rgba(142, 68, 173, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">4.</span></span><span leaf=""> Spirion Sensitive Data Platform v13.5: Unlocking the Next Generation of Data Security</span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Discover Spirion SDP v13.5 for faster scans, zero-trust controls &amp; Gmail support. The next evolution in DSPM is here. The post Spirion Sensitive Data Platform v13.5: Unlocking the Next Generation of Data Security appeared first on archTIS.</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 数据隐私与合规⏰ Fri, 29 Au</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.spirion.com/blog/sdp-13-5-next-gen-data-security" target="_blank">https://www.spirion.com/blog/sdp-13-5-next-gen-data-security</a></span></p></div><div style="background: rgba(142, 68, 173, 0.06);border: 1px solid rgba(142, 68, 173, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">5.</span></span><span leaf=""> archTIS and Spirion — Securing the Data Layer Together</span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">archTIS is acquiring Spirion’s technology, team, and customers to deliver a stronger, more comprehensive suite of data security solutions. The post archTIS and Spirion — Securing the Data Layer Together appeared first on archTIS.</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 数据隐私与合规⏰ Thu, 28 Au</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.spirion.com/blog/spirion-archtis-joining-forces" target="_blank">https://www.spirion.com/blog/spirion-archtis-joining-forces</a></span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px;padding: 25px;background: linear-gradient(135deg, rgb(248, 249, 250) 0%, rgb(255, 255, 255) 100%);border-radius: 12px;border: 1px solid rgb(233, 236, 239);"><h3 style="font-size: 16px;color: rgb(44, 62, 80);margin: 0px 0px 15px;font-weight: bold;"><span leaf="">📝 关于本报</span></h3><ul style="margin: 0px;padding-left: 20px;color: rgb(102, 102, 102);font-size: 13px;line-height: 2;" class="list-paddingleft-1"><li><p><span leaf="">🤖 本日报由 AI 自动抓取整理，每日上午 9:00 更新</span></p></li></ul><ul style="margin: 0px;padding-left: 20px;color: rgb(102, 102, 102);font-size: 13px;line-height: 2;" class="list-paddingleft-1"><li><p><span leaf="">📬 涵盖：漏洞预警、技术研究、威胁情报、云安全、AI 安全等 12 个分类</span></p></li></ul><p style="text-align: center;margin: 20px 0px 0px;color: rgb(153, 153, 153);font-size: 12px;"><span leaf="">生成时间：2026-03-18 18:24:50</span></p><p style="text-align: center;margin: 15px 0px 0px;color: rgb(102, 126, 234);font-size: 14px;font-weight: bold;"><span leaf="">🍐 枇杷熟了</span></p><p style="text-align: center;margin: 5px 0px 0px;color: rgb(153, 153, 153);font-size: 12px;"><span leaf="">专注网络安全技术分享</span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=0f6169d3&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MzkzOTYzOQ%3D%3D%26mid%3D2247489991%26idx%3D1%26sn%3D71d6806bff3de9fec3fb202318ca463f">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 18 Mar 2026 18:29:00 +0800</pubDate>
    </item>
    <item>
      <title>【已复现】泛微 E-cology10 多个远程代码执行漏洞</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MzkzOTYzOQ==&amp;mid=2247489986&amp;idx=1&amp;sn=b71354dd4388e4c93ce505f0528dd43a</link>
      <description>泛微Ecology10是一款面向中大型组织的数字化运营平台，基于微服务架构与低代码引擎，支撑企业实现业务协同、</description>
      <content:encoded><![CDATA[<p><span>长亭应急响应</span> <span>2026-03-16 20:44</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=cf25e825&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FeZOA7OiaVuZ8r8u9qARibibicm2HZzNLEhD80FvfyapuxuBUChzWm8TicvtJZFncdzFEwgxT0Xic1FqldjjmKUyW1mWg3OKuRZG7LrwDGyeo4jPHg%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <div data-role="outer" label="edit by 135editor" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: 默认字体;visibility: visible;"><div data-role="paragraph" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;letter-spacing: 0.578px;font-family: mp-quote, &#34;PingFang SC&#34;, -apple-system-font, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;visibility: visible;"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1329378339},[&#34;p&#34;,{},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;泛微协同管理应用平台（e-cology）是一款全面的企业管理平台。它具备多元化的功能，包括企业信息门户、知识文档管理、工作流程管理、人力资源管理、客户关系管理、项目管理、财务管理、资产管理、供应链管理以及数据中心等。这款平台有助于企业整合各种资源，包括管理、市场、销售、研发、人事和行政等各个领域。通过e-cology，这些资源可以在一个统一的平台上集成，并为用户提供统一的界面以方便操作和获取信息。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhbw00xpg3nfo1awkjt&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;近日，长亭应急团队监测到泛微发布了新的安全漏洞补丁修补了多个漏洞，其中有两个漏洞值得关注，分别是信息泄露和任意用户登录，组合起来可以获取应用系统的任意用户权限。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhbw2mh45202sva9ihn&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;经过分析漏洞后，发现公网仍有较多系统未修复漏洞，长亭应急团队根据该漏洞的原理，编写了X-RAY远程检测工具和牧云本地检测工具供大家下载使用，同时在文章中提供了排查该资产的方式。&#34;]]]]" data-identifier-application__slash__x-doc-key="LvBPlNWKY5PVndG8" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1121139987},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhsqy1c3vobicv0i3er&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;畅捷通T+是一款企业资源规划（ERP）软件，主要功能包括财务管理、销售管理、采购管理以及库存管理等，助力企业实现业务流程自动化。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;limjtprko8zpm2fo8pl&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;近期，长亭科技监测到微步在线发布一则漏洞通告，声明畅捷通T+发布新版本修复了一个RCE漏洞。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;limrdh63y857qallxw&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;长亭应急团队经过漏洞分析后，发现该漏洞类型为SQL注入，可利用其实现RCE。公网仍有较多相关系统尚未修复漏洞。应急团队根据该漏洞的原理，编写了X-POC远程检测工具和牧云本地检测工具，目前工具已向公众开放下载使用。&#34;]]]]" data-identifier-application__slash__x-doc-key="2M9qPJ1xzP43l015" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1121139987},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhsqy1c3vobicv0i3er&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;Openfire（前身为Wildfire）是一个基于XMPP（Extensible Messaging and Presence Protocol，可扩展消息处理和呈现协议）的开源实时协作服务器，同时提供了Web管理界面。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;limjtprko8zpm2fo8pl&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;近期，长亭科技监测到Openfire发布新版本修复了一个漏洞。长亭应急团队经过漏洞分析后，发现该漏洞类型为后台权限绕过，可利用其实现RCE。公网仍有较多相关系统尚未修复漏洞。应急团队根据该漏洞的原理，编写了X-POC远程检测工具和牧云本地检测工具，目前工具已向公众开放下载使用。&#34;]]]]" data-identifier-application__slash__x-doc-key="AJdl6mZR72PKOke1" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1121139987},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhsqy1c3vobicv0i3er&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;Apache RocketMQ是一款开源的分布式消息和流处理平台，提供了高效、可靠、可扩展的低延迟消息和流数据处理能力，广泛用于异步通信、应用解耦、系统集成以及大数据、实时计算等场景。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;licys4nlk4z44589ypo&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;近期，长亭科技监测到RocketMQ发布新版本修复了一个远程命令执行漏洞（CVE-2023-37582）。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;licytz2meuxzh6wlgn&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;经过分析漏洞后，发现公网仍有较多系统未修复漏洞。应急团队根据该漏洞的原理，已经编写了X-POC远程检测工具和牧云本地检测工具&#34;],[&#34;span&#34;,{&#34;bold&#34;:false,&#34;sz&#34;:11,&#34;szUnit&#34;:&#34;pt&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;，并已向公众开放下载使用。&#34;]]]]" data-identifier-application__slash__x-doc-key="r4mlQmEY28GMlxow" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);text-size-adjust: inherit;visibility: visible;"><p nodeleaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;visibility: visible;"><img alt="图片" class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100009471" data-ratio="0.5388888888888889" data-s="300,640" type="block" data-type="png" data-w="1080" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: bottom;height: auto !important;visibility: visible !important;width: 676.984px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=fad22e31&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEqS9GE77r0NxnUogD8QymSJXrgTTDzXtwghSTib26lB7REq5BVk18MkN4J7sFB3TIlmTdSsSibBHbdicKTnTNomicsVmMNQzUxowa54uibHh6CwY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D0"/></p><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">泛微Ecology10是一款面向中大型组织的数字化运营平台，基于微服务架构与低代码引擎，支撑企业实现业务协同、数据整合与全程在线管理。</span></span><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;fonts&#34;:{&#34;hint&#34;:&#34;eastAsia&#34;},&#34;data-type&#34;:&#34;leaf&#34;},&#34;瑞&#34;],[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;友天翼应用虚拟化系统是西安瑞友信息技术资讯有限公司研发的具有自主知识产权，基于服务器计算架构的应用虚拟化平台。它将用户各种应用软件集中部署在瑞友天翼服务器(群)上，客户端通过WEB即可快速安全的访问经服务器上授权的应用软件，实现集中应用、远程接入、协同办公等。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lp0xhb0ekky9vvtxiv&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;sz&#34;:11,&#34;szUnit&#34;:&#34;pt&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;2024年5月，互联网公开了一个&#34;],[&#34;span&#34;,{&#34;fonts&#34;:{&#34;hint&#34;:&#34;eastAsia&#34;},&#34;data-type&#34;:&#34;leaf&#34;},&#34;瑞&#34;],[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;友天翼应用虚拟化系统&#34;],[&#34;span&#34;,{&#34;sz&#34;:11,&#34;szUnit&#34;:&#34;pt&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;的SQL注入漏洞。鉴于该漏洞无前置条件，易于利用，且默认情况下可直接获取操作系统权限，建议所有使用该系统的企业尽快进行升级修复，以确保系统安全。&#34;]]]]" data-identifier-application__slash__x-doc-key="4jKqmVWA95GDOw19" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-size-adjust: inherit;visibility: visible;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lw0h0ayp6j8mmfkcsxa&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;fonts&#34;:{&#34;hint&#34;:&#34;eastAsia&#34;},&#34;data-type&#34;:&#34;leaf&#34;},&#34;PHP-CGI 是一种用于在 Web 服务器上运行 PHP 脚本的接口，通过 CGI（公共网关接口）将 PHP 解释器与 Web 服务器连接。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lp0xhb0ekky9vvtxiv&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;2024年6月，PHP官方发布新版本，修复了 &#34;],[&#34;span&#34;,{&#34;sz&#34;:11,&#34;szUnit&#34;:&#34;pt&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;PHP-CGI &#34;],[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;中一个远程代码执行漏洞。&#34;],[&#34;span&#34;,{&#34;sz&#34;:11,&#34;szUnit&#34;:&#34;pt&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;鉴于该漏洞无前置条件，易于利用，且默认情况下可获取操作系统权限，建议所有使用受影响版本的企业尽快升级修复，以确保安全。&#34;]]]]" data-identifier-application__slash__x-doc-key="3BMqYaMEV896qwZL" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-size-adjust: inherit;visibility: visible;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;liy8sjqqhpyk6m030b9&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;Serv-U 是 SolarWinds 公司推出的FTP服务器软件，提供文件传输服务，支持多种协议（FTP、FTPS、SFTP），具有用户管理、文件权限控制等功能，适用于企业级文件传输解决方案。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lo5ajwxivf4py2sbk1f&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;2024年6月，Serv-U 官方 SolarWinds 发布了新补丁，修复了一处目录遍历致文件读取漏洞（CVE-2024-28995）。经分析，该漏洞可以通过特定的路径请求来未授权访问系统文件，进而可能导致敏感信息泄露。该漏洞无前置条件且利用简单，建议受影响的客户尽快修复漏洞。&#34;]]]]" data-identifier-application__slash__x-doc-key="8K4nyRy9Bv1jqLbj" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-size-adjust: inherit;visibility: visible;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhsqy1c3vobicv0i3er&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;spacing&#34;:0.21675,&#34;data-type&#34;:&#34;leaf&#34;},&#34;泛微e-cology是一款由泛微网络科技开发的协同管理平台，支持人力资源、财务、行政等多功能管理和移动办公。&#34;]]],[&#34;p&#34;,{&#34;jc&#34;:&#34;left&#34;,&#34;ind&#34;:{},&#34;spacing&#34;:{},&#34;uuid&#34;:&#34;lyiiqr1cqx6q84a8wmd&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;spacing&#34;:0.21675,&#34;data-type&#34;:&#34;leaf&#34;},&#34;2025年6月，泛微官方更新安全补丁，修复了一处远程代码执行漏洞。经分析，攻击者可绕过身份认证利用该漏洞&#34;],[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;导致服务器沦陷&#34;],[&#34;span&#34;,{&#34;spacing&#34;:0.21675,&#34;data-type&#34;:&#34;leaf&#34;},&#34;，建议受影响的客户尽快修复漏洞。&#34;]]]]" data-identifier-application__slash__x-doc-key="8K4nyeZVamGgPnLb" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;visibility: visible;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;visibility: visible;"></p><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">2026年3月，长亭安全应急响应中心监测到泛微 E-cology 10 修复了多个远程代码执行漏洞。经分析，攻击者可在无需任何权限的情况下，利用上述漏洞远程执行任意代码，最终导致服务器沦陷。建议受影响的用户尽快修复漏洞。</span></span></div></div></div></div></div></div></div></div><div data-role="title" data-tools="135编辑器" data-id="124637" data-color="#7ac259" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px auto;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;visibility: visible;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;flex-shrink: 0;display: flex;visibility: visible;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 10px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(122, 194, 89);text-align: left;visibility: visible;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20px;letter-spacing: 2px;color: rgb(31, 31, 31);visibility: visible;"><strong data-brushtype="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">漏洞描述</span></strong></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12px;color: rgb(166, 166, 166);text-align: left;visibility: visible;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 1px;background-color: rgba(152, 152, 152, 0.1);line-height: 1.58em;visibility: visible;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(152, 152, 152);visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">Description</span></span></span></p></div></div><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;flex-shrink: 0;display: flex;align-items: center;visibility: visible;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20px;letter-spacing: 1.5px;color: rgb(122, 194, 89);visibility: visible;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 24px;color: rgba(152, 152, 152, 0.2);visibility: visible;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">0</span></strong><strong data-original-title="" title="" data-num="2" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">1</span></strong></span></p></div></div></div></div><div data-role="paragraph" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: mp-quote, &#34;PingFang SC&#34;, -apple-system-font, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;visibility: visible;"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1329378339},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhbw6gwwf5hgshd51os&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;由于系统未对系统接口的响应进行合理的处理，导致该系统会泄漏已注册用户信息，攻击者可利用信息泄露漏洞获取注册用户的信息。另外由于系统使用了不当的算法设计，攻击者可模拟任意用户登录系统。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhbw6jvlp8ey3x5omd&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;对攻击者来说，这两个漏洞的利用无需认证和鉴权，可通过组合漏洞获取用户数据，登录后台。&#34;]]]]" data-identifier-application__slash__x-doc-key="LvBPlNWKY5PVndG8" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1121139987},[&#34;p&#34;,{&#34;uuid&#34;:&#34;limrxzplblycaec36z8&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;GeoServer在预览图层的时候，可以对图层进行数据过滤从而渲染出指定位置的图层。由于未对用户输入进行过滤，在使用需要以数据库作为数据存储的功能时，攻击者可以构造畸形的过滤语法，绕过GeoServer的词法解析从而造成SQL注入，获取服务器中的敏感信息，甚至可能获取数据库服务器权限。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;limlfrolcg1noaebcu8&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;经过深入分析，长亭应急响应实验室发现，默认情况下GeoServer内置图层并不会使用数据库作为存储方式，而是将数据存放在文件中，所以不受该漏洞的影响。而使用该系统创建自定义图层并使用外置数据库后，就会导致相应的功能存在SQL注入漏洞。&#34;]]]]" data-identifier-application__slash__x-doc-key="8K4ny9795WGpnLbj" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><div data-identifier-application__slash__x-doc-key="r4mlQmEY28GMlxow" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);text-size-adjust: inherit;visibility: visible;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 24px 0px 16px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 16px;letter-spacing: 0.578px;text-align: left;color: rgb(0, 0, 0);visibility: visible;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 17px;visibility: visible;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(122, 194, 89);visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">漏洞成因</span></span></strong></span></p><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-size: 15px;">Ecology10 系统存在多处远程代码执行漏洞，攻击者可无需认证，通过向特定接口发送恶意请求的方式触发漏洞，进而在目标服务器上执行任意代码。</span></span></div></div></div><div data-identifier-application__slash__x-doc-key="r4mlQmEY28GMlxow" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);text-size-adjust: inherit;"><h2 style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 20px 0px 24px;padding: 0px;outline: 0px;font-weight: 400;font-size: 17px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 0.578px;color: rgb(0, 0, 0);line-height: 14.45px;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(122, 194, 89);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.87em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞影响</span></span></strong></span></h2><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">攻击者可利用上述漏洞远程执行任意代码，完全控制目标服务器，造成服务器沦陷及敏感数据泄露。</span></span><div data-identifier-application__slash__x-doc-key="r4mlQmEY28GMlxow" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);text-size-adjust: inherit;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 16px;letter-spacing: 0.578px;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 17px;letter-spacing: 0.578px;color: rgb(122, 194, 89);line-height: 1.82em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, system-ui, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.87em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">处置优先级：高</span></span></strong></p><div data-tools="135编辑器" data-id="142799" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;letter-spacing: 0.578px;color: rgb(0, 0, 0);font-family: mp-quote, &#34;PingFang SC&#34;, -apple-system-font, system-ui, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px auto;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;"><div data-width="100%" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 676px;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 5px 10px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div data-autoskip="1" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.75em;letter-spacing: 1.5px;font-size: 14px;color: rgb(51, 51, 51);"><div data-identifier-application__slash__x-doc-key="8K4nyR2daWX0qLbj" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(0, 0, 0);"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(38, 38, 38, 0.86);"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: left;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-weight: bold;">漏洞类型：</span></span><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(38, 38, 38, 0.86);"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: left;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">远程代码执行</span></span></span></span></span></span></span></p><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lwimwq8a5n1v73x221a&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;● 漏洞类型：目录遍历&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lwimwq8aiiblz5hww6&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;● 漏洞危害等级：中&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lwimwq8adn8we8t368w&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;● 权限认证要求：无需任何权限&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lwimwq8a2iqisx8i3r4&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;● 系统配置要求：默认配置可利用&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lwimwq8abf2z7210v3s&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;● 用户交互要求：无需用户交互&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lwimwq8bmbyjgppdj7&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;● 利用成熟度：POC/EXP已公开&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lwimwq8bxxufs939y1&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;● 批量可利用性：可使用通用 POC/EXP，批量检测/利用&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lwimwq8b94hfo6wrmi&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;● 修复复杂度：低，官方提供热修复方案&#34;]]]]" data-identifier-application__slash__x-doc-key="8K4nyRy9Bv1jqLbj" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-size-adjust: inherit;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(38, 38, 38, 0.86);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞危害等级：</span></span></strong><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">高</span></span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;line-height: 2em;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(38, 38, 38, 0.86);font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">触发方式：</span></span></strong><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(38, 38, 38, 0.86);font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">网络远程</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(38, 38, 38, 0.86);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">权限认证要求：</span></span></strong><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">无需权限</span></span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(38, 38, 38, 0.86);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">系统配置要求：</span></span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: mp-quote, &#34;PingFang SC&#34;, -apple-system-font, system-ui, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: left;line-height: 2em;caret-color: rgb(0, 0, 0);text-size-adjust: inherit;color: rgba(38, 38, 38, 0.86);font-size: 15px;">默认配置</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(38, 38, 38, 0.86);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">用户交互要求：</span></span></strong><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">无需用户交互</span></span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(38, 38, 38, 0.86);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 2em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">利用成熟度：</span></span></strong><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">POC/EXP 未公开</span></span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;line-height: 2em;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(38, 38, 38, 0.86);font-size: 15px;line-height: 2em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">修复复杂度：</span></strong><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(38, 38, 38, 0.86);font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">低，</span><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">官方提供补丁修复方案</span></span></p></div></div></div></div></div></div></div></div><div data-role="title" data-tools="135编辑器" data-id="124637" data-color="#7ac259" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;letter-spacing: 0.578px;color: rgb(0, 0, 0);border-width: 0px;border-style: none;border-color: initial;z-index: 0;max-width: 100%;max-inline-size: 100%;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px auto;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;max-width: 100%;max-inline-size: 100%;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;flex-shrink: 0;display: flex;max-width: 100%;max-inline-size: 100%;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 10px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;max-width: 100%;max-inline-size: 100%;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(122, 194, 89);text-align: left;max-width: 100%;max-inline-size: 100%;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;font-size: 20px;letter-spacing: 2px;color: rgb(31, 31, 31);max-width: 100%;max-inline-size: 100%;"><strong data-brushtype="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;max-width: 100%;max-inline-size: 100%;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">影响版本</span></strong></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12px;text-align: left;max-width: 100%;max-inline-size: 100%;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;letter-spacing: 1px;background-color: rgba(152, 152, 152, 0.1);max-width: 100%;max-inline-size: 100%;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;color: rgb(152, 152, 152);max-width: 100%;max-inline-size: 100%;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Affects</span></span></span></p></div></div><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;flex-shrink: 0;display: flex;align-items: center;max-width: 100%;max-inline-size: 100%;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 5px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20px;letter-spacing: 1.5px;color: rgb(122, 194, 89);max-width: 100%;max-inline-size: 100%;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;font-size: 24px;color: rgba(152, 152, 152, 0.2);max-width: 100%;max-inline-size: 100%;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;max-width: 100%;max-inline-size: 100%;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">02</span></strong></span></p></div></div></div><pre data-placeholder="翻译" dir="ltr" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;letter-spacing: 0.578px;color: rgb(0, 0, 0);max-width: 100%;max-inline-size: 100%;"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:398674325},[&#34;p&#34;,{&#34;uuid&#34;:&#34;liczeplu90nx1mmntt&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;&lt;&#34;],[&#34;span&#34;,{&#34;highlight&#34;:&#34;rgb(252, 252, 252)&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;RocketMQ 4.9.6&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;liczez2ip16agu1s6w&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;highlight&#34;:&#34;rgb(252, 252, 252)&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;&lt;RocketMQ 5.1.1&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJsaWN6ZXBsdTkwbngxbW1udHQlMjIlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIydGV4dCUyMiUyQyUyMmxlYXZlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIybGVhZiUyMiUyQyUyMnRleHQlMjIlM0ElMjIlM0MlMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCUyQyU3QiUyMmtsYXNzJTIyJTNBJTIybGVhZiUyMiUyQyUyMnRleHQlMjIlM0ElMjJSb2NrZXRNUSUyMDQuOS42JTIyJTJDJTIybWFya3MlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMm1hcmslMjIlMkMlMjJ0eXBlJTIyJTNBJTIyaGlnaGxpZ2h0JTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnZhbHVlJTIyJTNBJTIycmdiKDI1MiUyQyUyMDI1MiUyQyUyMDI1MiklMjIlN0QlN0QlNUQlN0QlNUQlN0QlNUQlN0QlMkMlN0IlMjJrbGFzcyUyMiUzQSUyMmJsb2NrJTIyJTJDJTIydHlwZSUyMiUzQSUyMnBhcmFncmFwaCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlMjJ1dWlkJTIyJTNBJTIybGljemV6MmlwMTZhZ3UxczZ3JTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyJTNDUm9ja2V0TVElMjA1LjEuMSUyMiUyQyUyMm1hcmtzJTIyJTNBJTVCJTdCJTIya2xhc3MlMjIlM0ElMjJtYXJrJTIyJTJDJTIydHlwZSUyMiUzQSUyMmhpZ2hsaWdodCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlMjJ2YWx1ZSUyMiUzQSUyMnJnYigyNTIlMkMlMjAyNTIlMkMlMjAyNTIpJTIyJTdEJTdEJTVEJTdEJTVEJTdEJTVEJTdEJTVEJTdE" data-identifier-application__slash__x-doc-key="XYvenvXNYavMOoyZ" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;max-width: 100%;max-inline-size: 100%;"><p data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1121139987},[&#34;p&#34;,{&#34;uuid&#34;:&#34;liczeplu90nx1mmntt&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;&lt;&#34;],[&#34;span&#34;,{&#34;highlight&#34;:&#34;rgb(252, 252, 252)&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;RocketMQ 4.9.7&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;liczez2ip16agu1s6w&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;highlight&#34;:&#34;rgb(252, 252, 252)&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;&lt;RocketMQ 5.1.2&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJsaWN6ZXBsdTkwbngxbW1udHQlMjIlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIydGV4dCUyMiUyQyUyMmxlYXZlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIybGVhZiUyMiUyQyUyMnRleHQlMjIlM0ElMjIlM0MlMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCUyQyU3QiUyMmtsYXNzJTIyJTNBJTIybGVhZiUyMiUyQyUyMnRleHQlMjIlM0ElMjJSb2NrZXRNUSUyMDQuOS43JTIyJTJDJTIybWFya3MlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMm1hcmslMjIlMkMlMjJ0eXBlJTIyJTNBJTIyaGlnaGxpZ2h0JTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnZhbHVlJTIyJTNBJTIycmdiKDI1MiUyQyUyMDI1MiUyQyUyMDI1MiklMjIlN0QlN0QlNUQlN0QlNUQlN0QlNUQlN0QlMkMlN0IlMjJrbGFzcyUyMiUzQSUyMmJsb2NrJTIyJTJDJTIydHlwZSUyMiUzQSUyMnBhcmFncmFwaCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlMjJ1dWlkJTIyJTNBJTIybGljemV6MmlwMTZhZ3UxczZ3JTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyJTNDUm9ja2V0TVElMjA1LjEuMiUyMiUyQyUyMm1hcmtzJTIyJTNBJTVCJTdCJTIya2xhc3MlMjIlM0ElMjJtYXJrJTIyJTJDJTIydHlwZSUyMiUzQSUyMmhpZ2hsaWdodCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlMjJ2YWx1ZSUyMiUzQSUyMnJnYigyNTIlMkMlMjAyNTIlMkMlMjAyNTIpJTIyJTdEJTdEJTVEJTdEJTVEJTdEJTVEJTdEJTVEJTdE" data-identifier-application__slash__x-doc-key="r4mlQmEY28GMlxow" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;text-size-adjust: inherit;max-width: 100%;max-inline-size: 100%;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 0.21675pt;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">泛微e-cology 补丁版本 &lt; </span></span><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">E10安全补丁包 v20260312</span></span></span></p></div></pre><div data-role="title" data-tools="135编辑器" data-id="124637" data-color="#7ac259" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;letter-spacing: 0.578px;color: rgb(0, 0, 0);border-width: 0px;border-style: none;border-color: initial;z-index: 0;caret-color: rgb(255, 0, 0);background-color: rgb(255, 255, 255);font-family: 微软雅黑, &#34;Microsoft YaHei&#34;, sans-serif;max-width: 100%;max-inline-size: 100%;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px auto;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;max-width: 100%;max-inline-size: 100%;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;flex-shrink: 0;display: flex;max-width: 100%;max-inline-size: 100%;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 10px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;max-width: 100%;max-inline-size: 100%;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(122, 194, 89);text-align: left;max-width: 100%;max-inline-size: 100%;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;font-size: 20px;letter-spacing: 2px;color: rgb(31, 31, 31);max-width: 100%;max-inline-size: 100%;"><strong data-brushtype="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;max-width: 100%;max-inline-size: 100%;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">解决方案</span></strong></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12px;color: rgb(166, 166, 166);text-align: left;max-width: 100%;max-inline-size: 100%;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;letter-spacing: 1px;background-color: rgba(152, 152, 152, 0.1);max-width: 100%;max-inline-size: 100%;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;color: rgb(152, 152, 152);max-width: 100%;max-inline-size: 100%;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Solution</span></span></span></p></div></div><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;flex-shrink: 0;display: flex;align-items: center;max-width: 100%;max-inline-size: 100%;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 5px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20px;letter-spacing: 1.5px;color: rgb(122, 194, 89);max-width: 100%;max-inline-size: 100%;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;font-size: 24px;color: rgba(152, 152, 152, 0.2);max-width: 100%;max-inline-size: 100%;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">03</span></span></strong></p></div></div></div><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1329378339},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lhbwfatppk7t6mctnlg&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;bold&#34;:false,&#34;sz&#34;:11,&#34;szUnit&#34;:&#34;pt&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;官方已经发布了安全补丁，在参考链接中安装官方提供的安全补丁 。&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJsaGJ3ZmF0cHBrN3Q2bWN0bmxnJTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyJUU1JUFFJTk4JUU2JTk2JUI5JUU1JUI3JUIyJUU3JUJCJThGJUU1JThGJTkxJUU1JUI4JTgzJUU0JUJBJTg2JUU1JUFFJTg5JUU1JTg1JUE4JUU4JUExJUE1JUU0JUI4JTgxJUVGJUJDJThDJUU1JTlDJUE4JUU1JThGJTgyJUU4JTgwJTgzJUU5JTkzJUJFJUU2JThFJUE1JUU0JUI4JUFEJUU1JUFFJTg5JUU4JUEzJTg1JUU1JUFFJTk4JUU2JTk2JUI5JUU2JThGJTkwJUU0JUJFJTlCJUU3JTlBJTg0JUU1JUFFJTg5JUU1JTg1JUE4JUU4JUExJUE1JUU0JUI4JTgxJTIwJUUzJTgwJTgyJTIyJTJDJTIybWFya3MlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMm1hcmslMjIlMkMlMjJ0eXBlJTIyJTNBJTIyYm9sZCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlMjJ2YWx1ZSUyMiUzQWZhbHNlJTdEJTdEJTJDJTdCJTIya2xhc3MlMjIlM0ElMjJtYXJrJTIyJTJDJTIydHlwZSUyMiUzQSUyMnN6JTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnZhbHVlJTIyJTNBMTElMkMlMjJzelVuaXQlMjIlM0ElMjJwdCUyMiU3RCU3RCU1RCU3RCU1RCU3RCU1RCU3RCU1RCU3RA==" data-identifier-application__slash__x-doc-key="LvBPlNWKY5PVndG8" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(255, 0, 0);background-color: rgb(255, 255, 255);font-family: 微软雅黑, &#34;Microsoft YaHei&#34;, sans-serif;max-width: 100%;max-inline-size: 100%;"><div data-identifier-application__slash__x-doc-key="XYvenvXNYavMOoyZ" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;max-width: 100%;max-inline-size: 100%;"><p data-identifier-application__slash__x-doc-key="XYvenvXNYavMOoyZ" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(0, 0, 0);font-size: 16px;letter-spacing: 0.578px;max-width: 100%;max-inline-size: 100%;"><h2 style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 25px 0px 0px;padding: 0px;outline: none 0px !important;font-weight: 400;font-size: 17px;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;line-height: 1.75em;max-width: 100%;max-inline-size: 100%;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;max-width: 100%;max-inline-size: 100%;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;color: rgb(122, 194, 89);max-width: 100%;max-inline-size: 100%;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">临时缓解方案</span></span><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;mbq5l8gb3qt010i9tbw&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;避免将Kafka Connect实例暴露在公网，通过以下方式配置：&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;mbq5l8gbdx5w53u453&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;Standalone模式：修改connect-standalone.properties中的listeners或rest.host.name字段&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;mbq5l8gbtcy4i38sdla&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;Distributed模式：修改connect-distributed.properties中的listeners或rest.host.name字段&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;mbq5l8gb3suqz4lsxlu&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;使用流量防护设备（如WAF、防火墙）拦截/connectors接口请求中携带敏感文件路径的恶意流量&#34;]]]]" data-identifier-application__slash__x-doc-key="mxPOG5zPb5VbbnKa" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">1. 如非必要，不要将系统开放在互联网上。</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">2. 在不影响现有业务的情况下，在 Nginx 中为 /papi/ 路径下的所有接口配置访问授权（推荐使用 Basic Auth）。</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">3. 使用 WAF 等安全设备对相关接口进行防护</span></span></p></div></strong></h2></p><h2 style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 25px 0px 0px;padding: 0px;outline: none 0px !important;font-weight: 400;font-size: 17px;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(0, 0, 0);letter-spacing: 0.578px;cursor: text;line-height: 1.75em;max-width: 100%;max-inline-size: 100%;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;max-width: 100%;max-inline-size: 100%;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;cursor: text;color: rgb(122, 194, 89);max-width: 100%;max-inline-size: 100%;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">升级修复方案</span><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1121139987},[&#34;p&#34;,{&#34;uuid&#34;:&#34;liczfjl2yx660lijzz&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;添加身份认证机制，确保只有授权用户才能访问和操作RocketMQ的消息队列。&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJsaWN6ZmpsMnl4NjYwbGlqenolMjIlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIydGV4dCUyMiUyQyUyMmxlYXZlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIybGVhZiUyMiUyQyUyMnRleHQlMjIlM0ElMjIlRTYlQjclQkIlRTUlOEElQTAlRTglQkElQUIlRTQlQkIlQkQlRTglQUUlQTQlRTglQUYlODElRTYlOUMlQkElRTUlODglQjYlRUYlQkMlOEMlRTclQTElQUUlRTQlQkYlOUQlRTUlOEYlQUElRTYlOUMlODklRTYlOEUlODglRTYlOUQlODMlRTclOTQlQTglRTYlODglQjclRTYlODklOEQlRTglODMlQkQlRTglQUUlQkYlRTklOTclQUUlRTUlOTIlOEMlRTYlOTMlOEQlRTQlQkQlOUNSb2NrZXRNUSVFNyU5QSU4NCVFNiVCNiU4OCVFNiU4MSVBRiVFOSU5OCU5RiVFNSU4OCU5NyVFMyU4MCU4MiUyMiUyQyUyMm1hcmtzJTIyJTNBJTVCJTVEJTdEJTVEJTdEJTVEJTdEJTVEJTdE" data-identifier-application__slash__x-doc-key="r4mlQmEY28GMlxow" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: none 0px !important;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);text-size-adjust: inherit;max-width: 100%;max-inline-size: 100%;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;liczh5cm1c5op5vp25o&#34;,&#34;ind&#34;:{&#34;left&#34;:0}},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;官方已发布升级补丁包，支持在线升级和离线补丁安装，下载地址：&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;mc06rj7t6qn5odhfbvy&#34;,&#34;ind&#34;:{&#34;left&#34;:0}},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;unlink&#34;:{},&#34;data-type&#34;:&#34;leaf&#34;},&#34;https://www.weaver.com.cn/cs/securityDownload.html?src=cn&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJsaWN6aDVjbTFjNW9wNXZwMjVvJTIyJTJDJTIyaW5kJTIyJTNBJTdCJTIybGVmdCUyMiUzQTAlN0QlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIydGV4dCUyMiUyQyUyMmxlYXZlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIybGVhZiUyMiUyQyUyMnRleHQlMjIlM0ElMjIlRTUlQUUlOTglRTYlOTYlQjklRTUlQjclQjIlRTUlOEYlOTElRTUlQjglODMlRTUlOEQlODclRTclQkElQTclRTglQTElQTUlRTQlQjglODElRTUlOEMlODUlRUYlQkMlOEMlRTYlOTQlQUYlRTYlOEMlODElRTUlOUMlQTglRTclQkElQkYlRTUlOEQlODclRTclQkElQTclRTUlOTIlOEMlRTclQTYlQkIlRTclQkElQkYlRTglQTElQTUlRTQlQjglODElRTUlQUUlODklRTglQTMlODUlRUYlQkMlOEMlRTQlQjglOEIlRTglQkQlQkQlRTUlOUMlQjAlRTUlOUQlODAlRUYlQkMlOUElMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCU1RCU3RCU1RCUyQyUyMmNvbnRlbnRUeXBlJTIyJTNBJTIyY2FuZ2ppZS10ZXh0YmxvY2slMjIlN0QlMkMlN0IlMjJrbGFzcyUyMiUzQSUyMmJsb2NrJTIyJTJDJTIydHlwZSUyMiUzQSUyMnBhcmFncmFwaCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlMjJ1dWlkJTIyJTNBJTIybWMwNnJqN3Q2cW41b2RoZmJ2eSUyMiUyQyUyMmluZCUyMiUzQSU3QiUyMmxlZnQlMjIlM0EwJTdEJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyaHR0cHMlM0ElMkYlMkZ3d3cud2VhdmVyLmNvbS5jbiUyRmNzJTJGc2VjdXJpdHlEb3dubG9hZC5odG1sJTNGc3JjJTNEY24lMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIybWFyayUyMiUyQyUyMnR5cGUlMjIlM0ElMjJ1bmxpbmslMjIlMkMlMjJkYXRhJTIyJTNBJTdCJTdEJTdEJTVEJTdEJTVEJTdEJTVEJTJDJTIyY29udGVudFR5cGUlMjIlM0ElMjJjYW5namllLXRleHRibG9jayUyMiU3RCU1RCU3RA==" data-identifier-application__slash__x-doc-key="8K4nyeZVamGgPnLb" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;mcu6ufudceiexbx9mc&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;官方已发布安全补丁，下载地址：&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;mhd0xvw3veze9ejwcb&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;https://www.weaver.com.cn/cs/securityDownload.html?src=cn&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJtY3U2dWZ1ZGNlaWV4Yng5bWMlMjIlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIydGV4dCUyMiUyQyUyMmxlYXZlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIybGVhZiUyMiUyQyUyMnRleHQlMjIlM0ElMjIlRTUlQUUlOTglRTYlOTYlQjklRTUlQjclQjIlRTUlOEYlOTElRTUlQjglODMlRTUlQUUlODklRTUlODUlQTglRTglQTElQTUlRTQlQjglODElRUYlQkMlOEMlRTQlQjglOEIlRTglQkQlQkQlRTUlOUMlQjAlRTUlOUQlODAlRUYlQkMlOUElMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCU1RCU3RCU1RCUyQyUyMmNvbnRlbnRUeXBlJTIyJTNBJTIyY2FuZ2ppZS10ZXh0YmxvY2slMjIlN0QlMkMlN0IlMjJrbGFzcyUyMiUzQSUyMmJsb2NrJTIyJTJDJTIydHlwZSUyMiUzQSUyMnBhcmFncmFwaCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlMjJ1dWlkJTIyJTNBJTIybWhkMHh2dzN2ZXplOWVqd2NiJTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyaHR0cHMlM0ElMkYlMkZ3d3cud2VhdmVyLmNvbS5jbiUyRmNzJTJGc2VjdXJpdHlEb3dubG9hZC5odG1sJTNGc3JjJTNEY24lMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCU1RCU3RCU1RCUyQyUyMmNvbnRlbnRUeXBlJTIyJTNBJTIyY2FuZ2ppZS10ZXh0YmxvY2slMjIlN0QlNUQlN0Q=" data-identifier-application__slash__x-doc-key="1wvqrebxv0PW3nak" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">官方已发布安全补丁，请联系官方售后支持人员获取最新安全补丁。</span></span></p></div></div></div><div data-role="title" data-tools="135编辑器" data-id="124637" data-color="#7ac259" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px auto;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;flex-shrink: 0;display: flex;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 10px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: left;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(31, 31, 31);font-size: 20px;letter-spacing: 2px;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞复现</span></strong></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(166, 166, 166);font-size: 12px;letter-spacing: 0.578px;text-align: left;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 1px;background-color: rgba(152, 152, 152, 0.1);"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(152, 152, 152);font-family: 微软雅黑, &#34;Microsoft YaHei&#34;, sans-serif;font-size: 12px;letter-spacing: 1px;text-align: left;caret-color: rgb(0, 0, 0);background-color: rgba(152, 152, 152, 0.1);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Reproduction</span></span></span></p></div></div><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(0, 0, 0);font-size: 16px;letter-spacing: 0.578px;flex-shrink: 0;display: flex;align-items: center;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20px;letter-spacing: 1.5px;color: rgb(122, 194, 89);"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 24px;color: rgba(152, 152, 152, 0.2);line-height: 1.58em;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">                                    04</span></strong></span></p></div></div></div><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;mhd3m7cv5i8039g0qmt&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;长亭应急响应实验室安全研究员已成功复现泛微e-cology 前台SQL注入漏洞，截图如下：&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;mbtakszwwbt1gf4sws&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;&#34;]],[&#34;img&#34;,{&#34;uuid&#34;:&#34;9emqkf&#34;,&#34;name&#34;:&#34;image.png&#34;,&#34;size&#34;:135335,&#34;width&#34;:748,&#34;height&#34;:338.15833333333336,&#34;src&#34;:&#34;https://alidocs.dingtalk.com/core/api/resources/img/5eecdaf48460cde527766043c148b104196d88013209dade75b8339e1c4c2483811b562af39a8db88d68742cd653602a27905087190dd0b9103633ce39d581aacd092a070da024a8861550216820647a7237b2f3f62c899695428e0829897ee4?tmpCode=d0a9be6c-2a81-4bb2-b754-a43a31b736f9&#34;,&#34;extraData&#34;:{&#34;resourceId&#34;:&#34;5b5f6e20-82f1-4168-b94e-4e3fb75c96e1&#34;,&#34;metaData&#34;:{&#34;size&#34;:135335,&#34;originWidth&#34;:1920,&#34;originHeight&#34;:868,&#34;format&#34;:&#34;png&#34;,&#34;ratio&#34;:1}}},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;&#34;]]],[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;&#34;]]]]" data-identifier-application__slash__x-doc-key="1wvqrebxv0PW3nak" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;mhd3m7cv5i8039g0qmt&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;长亭应急响应实验室安全研究员已成功复现泛微e-cology 10 多个RCE漏洞，截图如下：&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJtaGQzbTdjdjVpODAzOWcwcW10JTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyJUU5JTk1JUJGJUU0JUJBJUFEJUU1JUJBJTk0JUU2JTgwJUE1JUU1JTkzJThEJUU1JUJBJTk0JUU1JUFFJTlFJUU5JUFBJThDJUU1JUFFJUE0JUU1JUFFJTg5JUU1JTg1JUE4JUU3JUEwJTk0JUU3JUE5JUI2JUU1JTkxJTk4JUU1JUI3JUIyJUU2JTg4JTkwJUU1JThBJTlGJUU1JUE0JThEJUU3JThFJUIwJUU2JUIzJTlCJUU1JUJFJUFFZS1jb2xvZ3klMjAxMCUyMCVFNSVBNCU5QSVFNCVCOCVBQVJDRSVFNiVCQyU4RiVFNiVCNCU5RSVFRiVCQyU4QyVFNiU4OCVBQSVFNSU5QiVCRSVFNSVBNiU4MiVFNCVCOCU4QiVFRiVCQyU5QSUyMiUyQyUyMm1hcmtzJTIyJTNBJTVCJTVEJTdEJTVEJTdEJTVEJTJDJTIyY29udGVudFR5cGUlMjIlM0ElMjJjYW5namllLXRleHRibG9jayUyMiU3RCU1RCU3RA==" data-identifier-application__slash__x-doc-key="4jKqm0b0NMWzDnw1" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">长亭应急响应实验室安全研究员已成功复现泛微e-cology 10 多个RCE漏洞，截图如下：</span></span></span></p><div data-identifier-application__slash__x-doc-key="4jKqm0b0NMWzDnw1" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;font-weight: bold;">漏洞一：</span></span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;font-weight: bold;">漏洞二：</span></span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;font-weight: bold;">漏洞三：</span></span></span></p></div></div></div><div data-role="title" data-tools="135编辑器" data-id="124637" data-color="#7ac259" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;letter-spacing: 0.578px;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px auto;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;flex-shrink: 0;display: flex;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 10px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(122, 194, 89);text-align: left;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20px;letter-spacing: 2px;color: rgb(31, 31, 31);"><strong data-brushtype="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">产品支持</span></strong></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12px;color: rgb(166, 166, 166);text-align: left;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 1px;background-color: rgba(152, 152, 152, 0.1);"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(152, 152, 152);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Support</span></span></span></p></div></div><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;flex-shrink: 0;display: flex;align-items: center;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20px;letter-spacing: 1.5px;color: rgb(122, 194, 89);"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 24px;color: rgba(152, 152, 152, 0.2);line-height: 1.58em;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">05</span></strong></span></p></div></div></div><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:398674325},[&#34;p&#34;,{&#34;uuid&#34;:&#34;licztcywfgeia50hgau&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;5月23日 官方发布漏洞更新补丁版本&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;liczwtaewmcvwgfubl&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;5月24日 长亭应急响应实验室复现漏洞&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;liczxgtrqt1a8f2uca&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;5月30日 监测到POC已被小范围公开&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;liczyrvvhx91cimp5ko&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;6月1日 长亭发布应急响应通告&#34;]]]]" data-identifier-application__slash__x-doc-key="XYvenvXNYavMOoyZ" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;letter-spacing: 0.578px;"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1121139987},[&#34;p&#34;,{&#34;uuid&#34;:&#34;licztcywfgeia50hgau&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;7月12日 漏洞被公开披露[4]&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lk0k3n68fx3xyfk6eh&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;7月12日 长亭应急响应实验室漏洞分析与复现&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lk0k55pw2m215r3a86w&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;7月13日 长亭安全应急响应中心发布通告&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJsaWN6dGN5d2ZnZWlhNTBoZ2F1JTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyNyVFNiU5QyU4ODEyJUU2JTk3JUE1JTIwJUU2JUJDJThGJUU2JUI0JTlFJUU4JUEyJUFCJUU1JTg1JUFDJUU1JUJDJTgwJUU2JThBJUFCJUU5JTlDJUIyJTVCNCU1RCUyMiUyQyUyMm1hcmtzJTIyJTNBJTVCJTVEJTdEJTVEJTdEJTVEJTdEJTJDJTdCJTIya2xhc3MlMjIlM0ElMjJibG9jayUyMiUyQyUyMnR5cGUlMjIlM0ElMjJwYXJhZ3JhcGglMjIlMkMlMjJkYXRhJTIyJTNBJTdCJTIydXVpZCUyMiUzQSUyMmxrMGszbjY4ZngzeHlmazZlaCUyMiU3RCUyQyUyMm5vZGVzJTIyJTNBJTVCJTdCJTIya2xhc3MlMjIlM0ElMjJ0ZXh0JTIyJTJDJTIybGVhdmVzJTIyJTNBJTVCJTdCJTIya2xhc3MlMjIlM0ElMjJsZWFmJTIyJTJDJTIydGV4dCUyMiUzQSUyMjclRTYlOUMlODgxMiVFNiU5NyVBNSUyMCVFOSU5NSVCRiVFNCVCQSVBRCVFNSVCQSU5NCVFNiU4MCVBNSVFNSU5MyU4RCVFNSVCQSU5NCVFNSVBRSU5RSVFOSVBQSU4QyVFNSVBRSVBNCVFNiVCQyU4RiVFNiVCNCU5RSVFNSU4OCU4NiVFNiU5RSU5MCVFNCVCOCU4RSVFNSVBNCU4RCVFNyU4RSVCMCUyMiUyQyUyMm1hcmtzJTIyJTNBJTVCJTVEJTdEJTVEJTdEJTVEJTdEJTJDJTdCJTIya2xhc3MlMjIlM0ElMjJibG9jayUyMiUyQyUyMnR5cGUlMjIlM0ElMjJwYXJhZ3JhcGglMjIlMkMlMjJkYXRhJTIyJTNBJTdCJTIydXVpZCUyMiUzQSUyMmxrMGs1NXB3Mm0yMTVyM2E4NnclMjIlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIydGV4dCUyMiUyQyUyMmxlYXZlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIybGVhZiUyMiUyQyUyMnRleHQlMjIlM0ElMjI3JUU2JTlDJTg4MTMlRTYlOTclQTUlMjAlRTklOTUlQkYlRTQlQkElQUQlRTUlQUUlODklRTUlODUlQTglRTUlQkElOTQlRTYlODAlQTUlRTUlOTMlOEQlRTUlQkElOTQlRTQlQjglQUQlRTUlQkYlODMlRTUlOEYlOTElRTUlQjglODMlRTklODAlOUElRTUlOTElOEElMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCU1RCU3RCU1RCU3RCU1RCU3RA==" data-identifier-application__slash__x-doc-key="r4mlQmEY28GMlxow" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);text-size-adjust: inherit;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lpj9i8ax6llvk79gwia&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;雷池：已发布自定义规则支持该漏洞检测。&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lpj9i9l4cpvexzah8vc&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;全悉：预计于2024.06.07发布升级包支持该漏洞检测。&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJscGo5aThheDZsbHZrNzlnd2lhJTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyJUU5JTlCJUI3JUU2JUIxJUEwJUVGJUJDJTlBJUU1JUI3JUIyJUU1JThGJTkxJUU1JUI4JTgzJUU4JTg3JUFBJUU1JUFFJTlBJUU0JUI5JTg5JUU4JUE3JTg0JUU1JTg4JTk5JUU2JTk0JUFGJUU2JThDJTgxJUU4JUFGJUE1JUU2JUJDJThGJUU2JUI0JTlFJUU2JUEzJTgwJUU2JUI1JThCJUUzJTgwJTgyJTIyJTJDJTIybWFya3MlMjIlM0ElNUIlNUQlN0QlNUQlN0QlNUQlN0QlMkMlN0IlMjJrbGFzcyUyMiUzQSUyMmJsb2NrJTIyJTJDJTIydHlwZSUyMiUzQSUyMnBhcmFncmFwaCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlMjJ1dWlkJTIyJTNBJTIybHBqOWk5bDRjcHZleHphaDh2YyUyMiU3RCUyQyUyMm5vZGVzJTIyJTNBJTVCJTdCJTIya2xhc3MlMjIlM0ElMjJ0ZXh0JTIyJTJDJTIybGVhdmVzJTIyJTNBJTVCJTdCJTIya2xhc3MlMjIlM0ElMjJsZWFmJTIyJTJDJTIydGV4dCUyMiUzQSUyMiVFNSU4NSVBOCVFNiU4MiU4OSVFRiVCQyU5QSVFOSVBMiU4NCVFOCVBRSVBMSVFNCVCQSU4RTIwMjQuMDYuMDclRTUlOEYlOTElRTUlQjglODMlRTUlOEQlODclRTclQkElQTclRTUlOEMlODUlRTYlOTQlQUYlRTYlOEMlODElRTglQUYlQTUlRTYlQkMlOEYlRTYlQjQlOUUlRTYlQTMlODAlRTYlQjUlOEIlRTMlODAlODIlMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCU1RCU3RCU1RCU3RCU1RCU3RA==" data-identifier-application__slash__x-doc-key="3BMqYaMEV896qwZL" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-size-adjust: inherit;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;licztcywfgeia50hgau&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;6月6日 官方发布漏洞公告&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lxec4knlucj95j2h0a&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;6月13日 互联网公开漏洞细节&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lk0k55pw2m215r3a86w&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;6月14日 长亭安全应急响应中心发布通告&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJsaWN6dGN5d2ZnZWlhNTBoZ2F1JTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyNiVFNiU5QyU4ODYlRTYlOTclQTUlMjAlRTUlQUUlOTglRTYlOTYlQjklRTUlOEYlOTElRTUlQjglODMlRTYlQkMlOEYlRTYlQjQlOUUlRTUlODUlQUMlRTUlOTElOEElMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCU1RCU3RCU1RCU3RCUyQyU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJseGVjNGtubHVjajk1ajJoMGElMjIlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIydGV4dCUyMiUyQyUyMmxlYXZlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIybGVhZiUyMiUyQyUyMnRleHQlMjIlM0ElMjI2JUU2JTlDJTg4MTMlRTYlOTclQTUlMjAlRTQlQkElOTIlRTglODElOTQlRTclQkQlOTElRTUlODUlQUMlRTUlQkMlODAlRTYlQkMlOEYlRTYlQjQlOUUlRTclQkIlODYlRTglOEElODIlMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCU1RCU3RCU1RCU3RCUyQyU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJsazBrNTVwdzJtMjE1cjNhODZ3JTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyNiVFNiU5QyU4ODE0JUU2JTk3JUE1JTIwJUU5JTk1JUJGJUU0JUJBJUFEJUU1JUFFJTg5JUU1JTg1JUE4JUU1JUJBJTk0JUU2JTgwJUE1JUU1JTkzJThEJUU1JUJBJTk0JUU0JUI4JUFEJUU1JUJGJTgzJUU1JThGJTkxJUU1JUI4JTgzJUU5JTgwJTlBJUU1JTkxJThBJTIyJTJDJTIybWFya3MlMjIlM0ElNUIlNUQlN0QlNUQlN0QlNUQlN0QlNUQlN0Q=" data-identifier-application__slash__x-doc-key="8K4nyRy9Bv1jqLbj" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-size-adjust: inherit;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">云图：</span>默认支持该产品的指纹识别，同时支持该漏洞的PoC检测</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">洞鉴：</span>默认支持指纹检测，预计2026.03.16发布应急PoC支持检测</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">雷池：</span>支持漏洞二利用行为的检测，预计 2026.03.16 发布自定义规则支持检测</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">全悉：</span>支持漏洞二利用行为的检测，预计 2026.03.16 发布更新包支持完整检测</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">无锋：默认支持指纹检测，预计2026.03.16支持PoC检测</span></span></p></div></div></div></div></div></span></strong></h2></div></div></div></div><div data-role="title" data-tools="135编辑器" data-id="124637" data-color="#7ac259" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;letter-spacing: 0.578px;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px auto;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;flex-shrink: 0;display: flex;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 10px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(122, 194, 89);text-align: left;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20px;letter-spacing: 2px;color: rgb(31, 31, 31);"><strong data-brushtype="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">时间线</span></strong></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12px;color: rgb(166, 166, 166);text-align: left;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 1px;background-color: rgba(152, 152, 152, 0.1);"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(152, 152, 152);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Timeline</span></span></span></p></div></div><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;flex-shrink: 0;display: flex;align-items: center;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20px;letter-spacing: 1.5px;color: rgb(122, 194, 89);"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 24px;color: rgba(152, 152, 152, 0.2);line-height: 1.58em;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">06</span></strong></span></p></div></div></div><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:398674325},[&#34;p&#34;,{&#34;uuid&#34;:&#34;licztcywfgeia50hgau&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;5月23日 官方发布漏洞更新补丁版本&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;liczwtaewmcvwgfubl&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;5月24日 长亭应急响应实验室复现漏洞&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;liczxgtrqt1a8f2uca&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;5月30日 监测到POC已被小范围公开&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;liczyrvvhx91cimp5ko&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;6月1日 长亭发布应急响应通告&#34;]]]]" data-identifier-application__slash__x-doc-key="XYvenvXNYavMOoyZ" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;letter-spacing: 0.578px;"><div data-clipboard-cangjie="[&#34;root&#34;,{&#34;copyFrom&#34;:1121139987},[&#34;p&#34;,{&#34;uuid&#34;:&#34;licztcywfgeia50hgau&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;7月12日 漏洞被公开披露[4]&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lk0k3n68fx3xyfk6eh&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;7月12日 长亭应急响应实验室漏洞分析与复现&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lk0k55pw2m215r3a86w&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;7月13日 长亭安全应急响应中心发布通告&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJsaWN6dGN5d2ZnZWlhNTBoZ2F1JTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyNyVFNiU5QyU4ODEyJUU2JTk3JUE1JTIwJUU2JUJDJThGJUU2JUI0JTlFJUU4JUEyJUFCJUU1JTg1JUFDJUU1JUJDJTgwJUU2JThBJUFCJUU5JTlDJUIyJTVCNCU1RCUyMiUyQyUyMm1hcmtzJTIyJTNBJTVCJTVEJTdEJTVEJTdEJTVEJTdEJTJDJTdCJTIya2xhc3MlMjIlM0ElMjJibG9jayUyMiUyQyUyMnR5cGUlMjIlM0ElMjJwYXJhZ3JhcGglMjIlMkMlMjJkYXRhJTIyJTNBJTdCJTIydXVpZCUyMiUzQSUyMmxrMGszbjY4ZngzeHlmazZlaCUyMiU3RCUyQyUyMm5vZGVzJTIyJTNBJTVCJTdCJTIya2xhc3MlMjIlM0ElMjJ0ZXh0JTIyJTJDJTIybGVhdmVzJTIyJTNBJTVCJTdCJTIya2xhc3MlMjIlM0ElMjJsZWFmJTIyJTJDJTIydGV4dCUyMiUzQSUyMjclRTYlOUMlODgxMiVFNiU5NyVBNSUyMCVFOSU5NSVCRiVFNCVCQSVBRCVFNSVCQSU5NCVFNiU4MCVBNSVFNSU5MyU4RCVFNSVCQSU5NCVFNSVBRSU5RSVFOSVBQSU4QyVFNSVBRSVBNCVFNiVCQyU4RiVFNiVCNCU5RSVFNSU4OCU4NiVFNiU5RSU5MCVFNCVCOCU4RSVFNSVBNCU4RCVFNyU4RSVCMCUyMiUyQyUyMm1hcmtzJTIyJTNBJTVCJTVEJTdEJTVEJTdEJTVEJTdEJTJDJTdCJTIya2xhc3MlMjIlM0ElMjJibG9jayUyMiUyQyUyMnR5cGUlMjIlM0ElMjJwYXJhZ3JhcGglMjIlMkMlMjJkYXRhJTIyJTNBJTdCJTIydXVpZCUyMiUzQSUyMmxrMGs1NXB3Mm0yMTVyM2E4NnclMjIlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIydGV4dCUyMiUyQyUyMmxlYXZlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIybGVhZiUyMiUyQyUyMnRleHQlMjIlM0ElMjI3JUU2JTlDJTg4MTMlRTYlOTclQTUlMjAlRTklOTUlQkYlRTQlQkElQUQlRTUlQUUlODklRTUlODUlQTglRTUlQkElOTQlRTYlODAlQTUlRTUlOTMlOEQlRTUlQkElOTQlRTQlQjglQUQlRTUlQkYlODMlRTUlOEYlOTElRTUlQjglODMlRTklODAlOUElRTUlOTElOEElMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCU1RCU3RCU1RCU3RCU1RCU3RA==" data-identifier-application__slash__x-doc-key="r4mlQmEY28GMlxow" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);text-size-adjust: inherit;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;lvw3qgfg8vdm6ijotdf&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;6月6日 官方发布新版本修复漏洞&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lpj9n08wnjpnn21lrxi&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;6月7日 长亭安全应急响应中心发布通告&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJsdnczcWdmZzh2ZG02aWpvdGRmJTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyNiVFNiU5QyU4ODYlRTYlOTclQTUlMjAlRTUlQUUlOTglRTYlOTYlQjklRTUlOEYlOTElRTUlQjglODMlRTYlOTYlQjAlRTclODklODglRTYlOUMlQUMlRTQlQkYlQUUlRTUlQTQlOEQlRTYlQkMlOEYlRTYlQjQlOUUlMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCU1RCU3RCU1RCU3RCUyQyU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJscGo5bjA4d25qcG5uMjFscnhpJTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyNiVFNiU5QyU4ODclRTYlOTclQTUlMjAlRTklOTUlQkYlRTQlQkElQUQlRTUlQUUlODklRTUlODUlQTglRTUlQkElOTQlRTYlODAlQTUlRTUlOTMlOEQlRTUlQkElOTQlRTQlQjglQUQlRTUlQkYlODMlRTUlOEYlOTElRTUlQjglODMlRTklODAlOUElRTUlOTElOEElMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCU1RCU3RCU1RCU3RCU1RCU3RA==" data-identifier-application__slash__x-doc-key="3BMqYaMEV896qwZL" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-size-adjust: inherit;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;licztcywfgeia50hgau&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;6月6日 官方发布漏洞公告&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lxec4knlucj95j2h0a&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;6月13日 互联网公开漏洞细节&#34;]]],[&#34;p&#34;,{&#34;uuid&#34;:&#34;lk0k55pw2m215r3a86w&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;6月14日 长亭安全应急响应中心发布通告&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJsaWN6dGN5d2ZnZWlhNTBoZ2F1JTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyNiVFNiU5QyU4ODYlRTYlOTclQTUlMjAlRTUlQUUlOTglRTYlOTYlQjklRTUlOEYlOTElRTUlQjglODMlRTYlQkMlOEYlRTYlQjQlOUUlRTUlODUlQUMlRTUlOTElOEElMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCU1RCU3RCU1RCU3RCUyQyU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJseGVjNGtubHVjajk1ajJoMGElMjIlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIydGV4dCUyMiUyQyUyMmxlYXZlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIybGVhZiUyMiUyQyUyMnRleHQlMjIlM0ElMjI2JUU2JTlDJTg4MTMlRTYlOTclQTUlMjAlRTQlQkElOTIlRTglODElOTQlRTclQkQlOTElRTUlODUlQUMlRTUlQkMlODAlRTYlQkMlOEYlRTYlQjQlOUUlRTclQkIlODYlRTglOEElODIlMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCU1RCU3RCU1RCU3RCUyQyU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJsazBrNTVwdzJtMjE1cjNhODZ3JTIyJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyNiVFNiU5QyU4ODE0JUU2JTk3JUE1JTIwJUU5JTk1JUJGJUU0JUJBJUFEJUU1JUFFJTg5JUU1JTg1JUE4JUU1JUJBJTk0JUU2JTgwJUE1JUU1JTkzJThEJUU1JUJBJTk0JUU0JUI4JUFEJUU1JUJGJTgzJUU1JThGJTkxJUU1JUI4JTgzJUU5JTgwJTlBJUU1JTkxJThBJTIyJTJDJTIybWFya3MlMjIlM0ElNUIlNUQlN0QlNUQlN0QlNUQlN0QlNUQlN0Q=" data-identifier-application__slash__x-doc-key="8K4nyRy9Bv1jqLbj" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-size-adjust: inherit;"><div data-clipboard-cangjie="[&#34;root&#34;,{},[&#34;p&#34;,{&#34;uuid&#34;:&#34;m4t8hr5ui663b6pdc5&#34;},[&#34;span&#34;,{&#34;data-type&#34;:&#34;text&#34;},[&#34;span&#34;,{&#34;sz&#34;:11.5,&#34;szUnit&#34;:&#34;pt&#34;,&#34;color&#34;:&#34;rgb(0, 0, 0)&#34;,&#34;data-type&#34;:&#34;leaf&#34;},&#34;2025年10月30日&#34;],[&#34;span&#34;,{&#34;data-type&#34;:&#34;leaf&#34;},&#34;长亭安全应急响应中心发布通告&#34;]]]]" data-identifier-application__slash__x-cangjie-fragment="JTdCJTIya2xhc3MlMjIlM0ElMjJkb2N1bWVudCUyMiUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIyYmxvY2slMjIlMkMlMjJ0eXBlJTIyJTNBJTIycGFyYWdyYXBoJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnV1aWQlMjIlM0ElMjJtNHQ4aHI1dWk2NjNiNnBkYzUlMjIlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIydGV4dCUyMiUyQyUyMmxlYXZlcyUyMiUzQSU1QiU3QiUyMmtsYXNzJTIyJTNBJTIybGVhZiUyMiUyQyUyMnRleHQlMjIlM0ElMjIyMDI1JUU1JUI5JUI0MTAlRTYlOUMlODgzMCVFNiU5NyVBNSUyMiUyQyUyMm1hcmtzJTIyJTNBJTVCJTdCJTIya2xhc3MlMjIlM0ElMjJtYXJrJTIyJTJDJTIydHlwZSUyMiUzQSUyMnN6JTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnZhbHVlJTIyJTNBMTEuNSUyQyUyMnN6VW5pdCUyMiUzQSUyMnB0JTIyJTdEJTdEJTJDJTdCJTIya2xhc3MlMjIlM0ElMjJtYXJrJTIyJTJDJTIydHlwZSUyMiUzQSUyMmNvbG9yJTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMnZhbHVlJTIyJTNBJTIycmdiKDAlMkMlMjAwJTJDJTIwMCklMjIlN0QlN0QlNUQlN0QlMkMlN0IlMjJrbGFzcyUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyJUU5JTk1JUJGJUU0JUJBJUFEJUU1JUFFJTg5JUU1JTg1JUE4JUU1JUJBJTk0JUU2JTgwJUE1JUU1JTkzJThEJUU1JUJBJTk0JUU0JUI4JUFEJUU1JUJGJTgzJUU1JThGJTkxJUU1JUI4JTgzJUU5JTgwJTlBJUU1JTkxJThBJTIyJTJDJTIybWFya3MlMjIlM0ElNUIlNUQlN0QlNUQlN0QlNUQlMkMlMjJjb250ZW50VHlwZSUyMiUzQSUyMmNhbmdqaWUtdGV4dGJsb2NrJTIyJTdEJTVEJTdE" data-identifier-application__slash__x-doc-key="1wvqrebxv0PW3nak" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;caret-color: rgb(0, 0, 0);color: rgb(0, 0, 0);font-style: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration: none;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;text-align: left;text-indent: 0px;"><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 11.5pt;color: rgb(0, 0, 0);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">2026年3月16日  </span></span></span><span data-type="text" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 15px;">长亭安全应急响应中心发布通告</span></span></span></p></div></div></div></div></div><div data-id="97137" data-tools="135编辑器" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px auto;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 10px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;justify-content: center;align-items: center;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 6px 12px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;letter-spacing: 1.5px;color: rgb(174, 225, 91);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20px;letter-spacing: 1px;color: rgb(122, 194, 89);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">长亭应急响应服务</span></span></strong></p></div><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: -16px 0px 0px;padding: 1em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-right: 2px solid rgb(135, 226, 90);border-bottom: 2px solid rgb(135, 226, 90);border-left: 2px solid rgb(135, 226, 90);border-top: none;"><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 20px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">全力进行产品升级</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">及时将风险提示预案发送给客户</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">检测业务是否受到此次漏洞影响</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">请联系长亭应急服务团队</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 5px 0px 25px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">7*24小时，守护您的安全</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 25px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">第一时间找到我们：</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 5px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">邮箱：support@chaitin.com</span></span></p></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=e36962a4&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MzkzOTYzOQ%3D%3D%26mid%3D2247489986%26idx%3D1%26sn%3Db71354dd4388e4c93ce505f0528dd43a">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 16 Mar 2026 20:44:00 +0800</pubDate>
    </item>
    <item>
      <title>枇杷熟了-全球网络安全日报2026-03-16</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MzkzOTYzOQ==&amp;mid=2247489986&amp;idx=2&amp;sn=6c35fa86259c7341045cd9f8f9d28c4e</link>
      <description></description>
      <content:encoded><![CDATA[<p><span>枇杷哥</span> <span>2026-03-16 20:44</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=8000d5dd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FeZOA7OiaVuZ8jWo0KX1yuJOJk4Xr6yEAWyusmYcd3IuGLywRM4Q7rialxuKJYTHSHAG5r7iaM5c0EIlfGhAn0eXwjBz80bhrQJDWoVUK2jpHjI%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background: linear-gradient(135deg, rgb(102, 126, 234) 0%, rgb(118, 75, 162) 100%);padding: 45px 25px;text-align: center;box-shadow: rgba(0, 0, 0, 0.15) 0px 4px 20px;" data-pm-slice="0 0 []"><p style="color: rgba(255, 255, 255, 0.85);font-size: 13px;margin: 0px 0px 10px;letter-spacing: 3px;text-transform: uppercase;"><span leaf="">Daily Security Newsletter</span></p><h1 style="color: rgb(255, 255, 255);font-size: 26px;margin: 15px 0px;font-weight: bold;text-shadow: rgba(0, 0, 0, 0.25) 2px 2px 8px;letter-spacing: 2px;line-height: 1.4;"><span leaf="">🔐 全球网络安全日报</span></h1><p style="color: rgba(255, 255, 255, 0.95);margin: 20px 0px 10px;font-size: 16px;font-weight: 500;"><span leaf="">📅 2026年03月16日 Monday</span></p><p style="color: rgba(255, 255, 255, 0.8);margin: 10px 0px 0px;font-size: 13px;line-height: 1.6;"><span leaf="">每日精选全球网络安全最新研究、漏洞预警、技术动态、威胁情报</span></p></div><p style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background: linear-gradient(135deg, rgb(248, 249, 250) 0%, rgb(255, 255, 255) 100%);padding: 30px 20px;margin: 25px 15px;border-radius: 12px;border-left: 6px solid rgb(102, 126, 234);box-shadow: rgba(0, 0, 0, 0.06) 0px 2px 12px;"><h2 style="font-size: 18px;color: rgb(44, 62, 80);margin: 0px 0px 20px;font-weight: bold;display: flex;align-items: center;justify-content: center;"><span style="font-size: 24px;margin-right: 10px;"><span leaf="">📊</span></span><span leaf="">今日概览 · 共 9 条</span></h2><table style="width: 1189px;border-collapse: separate;border-spacing: 8px;"><tbody><tr><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(231, 76, 60, 0.12) 0%, rgba(231, 76, 60, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(231, 76, 60, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🚨</span></span><span style="color: rgb(231, 76, 60);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">漏洞与威胁</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">2</span></span></td><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(52, 152, 219, 0.12) 0%, rgba(52, 152, 219, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(52, 152, 219, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">📚</span></span><span style="color: rgb(52, 152, 219);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">技术研究</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">0</span></span></td></tr><tr><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(155, 89, 182, 0.12) 0%, rgba(155, 89, 182, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(155, 89, 182, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🔍</span></span><span style="color: rgb(142, 68, 173);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">威胁情报</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">0</span></span></td><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(46, 204, 113, 0.12) 0%, rgba(46, 204, 113, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(46, 204, 113, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🤖</span></span><span style="color: rgb(39, 174, 96);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">AI 安全</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">0</span></span></td></tr><tr><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(230, 126, 34, 0.12) 0%, rgba(230, 126, 34, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(230, 126, 34, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">☁️</span></span><span style="color: rgb(211, 84, 0);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">云安全</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">1</span></span></td><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(82, 92, 102, 0.12) 0%, rgba(82, 92, 102, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(82, 92, 102, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🏆</span></span><span style="color: rgb(39, 174, 96);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">漏洞平台</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">5</span></span></td></tr><tr><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(192, 57, 43, 0.12) 0%, rgba(192, 57, 43, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(192, 57, 43, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🇨🇳</span></span><span style="color: rgb(192, 57, 43);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">中国媒体</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">1</span></span></td><td></td></tr></tbody></table></p><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(231, 76, 60);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(231, 76, 60);padding-left: 15px;background: linear-gradient(90deg, rgba(231, 76, 60, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">🚨</span></span><span leaf="">漏洞与威胁</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(2条)</span></span></h2><div style="background: rgba(231, 76, 60, 0.06);border: 1px solid rgba(231, 76, 60, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> OpenAI says ChatGPT ads are not rolling out globally for now</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：OpenAI says ChatGPT ads are not rolling out globally for now</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">OpenAI told BleepingComputer that ChatGPT ads on Free and Go plans are not yet rolling out outside the United States, even though some users noticed references to ads in the updated privacy policy. [....</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ N/A</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：(<a href="https://www.bleepingcomputer.com/news/artificial-intelligence/openai-says-chatgpt-ads-are-not-rolling-out-globally-for-now/)" target="_blank">https://www.bleepingcomputer.com/news/artificial-intelligence/openai-says-chatgpt-ads-are-not-rolling-out-globally-for-now/)</a></span></p></div><div style="background: rgba(231, 76, 60, 0.06);border: 1px solid rgba(231, 76, 60, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">2.</span></span><span leaf=""> Betterleaks, a new open-source secrets scanner to replace Gitleaks</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Betterleaks, a new open-source secrets scanner to replace Gitleaks</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">A new open-source tool called Betterleaks can scan directories, files, and git repositories and identify valid secrets using default or customized rules. [...] ...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ N/A</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：(<a href="https://www.bleepingcomputer.com/news/security/betterleaks-a-new-open-source-secrets-scanner-to-replace-gitleaks/)" target="_blank">https://www.bleepingcomputer.com/news/security/betterleaks-a-new-open-source-secrets-scanner-to-replace-gitleaks/)</a></span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(211, 84, 0);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(211, 84, 0);padding-left: 15px;background: linear-gradient(90deg, rgba(211, 84, 0, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">☁️</span></span><span leaf="">云安全</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(1条)</span></span></h2><div style="background: rgba(211, 84, 0, 0.06);border: 1px solid rgba(211, 84, 0, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(211, 84, 0);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> Azure IaaS series: Explore new resources for building a stronger, more efficient infrastructure</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Azure IaaS series: Explore new resources for building a stronger, more efficient infrastructure</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">As organizations accelerate digital transformation, infrastructure decisions increasingly shape how quickly teams can adopt AI, how reliably applications operate at global scale, and how effectively b...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 云安全⏰ N/A</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：(<a href="https://azure.microsoft.com/en-us/blog/azure-iaas-series-explore-new-resources-for-building-a-stronger-more-efficient-infrastructure/)" target="_blank">https://azure.microsoft.com/en-us/blog/azure-iaas-series-explore-new-resources-for-building-a-stronger-more-efficient-infrastructure/)</a></span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(39, 174, 96);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(39, 174, 96);padding-left: 15px;background: linear-gradient(90deg, rgba(39, 174, 96, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">🏆</span></span><span leaf="">漏洞平台</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(5条)</span></span></h2><div style="background: rgba(39, 174, 96, 0.06);border: 1px solid rgba(39, 174, 96, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(39, 174, 96);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> [GHSA-p985-7chr-5h8c] Malware in @myisrfn/baileys-mod</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：[GHSA-p985-7chr-5h8c] Malware in @myisrfn/baileys-mod</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. Th...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞平台⏰ N/A</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：(tag:github.com,2008:GHSA-p985-7chr-5h8c)</span></p></div><div style="background: rgba(39, 174, 96, 0.06);border: 1px solid rgba(39, 174, 96, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(39, 174, 96);font-weight: bold;margin-right: 8px;"><span leaf="">2.</span></span><span leaf=""> [GHSA-q823-m447-4rqv] Malware in @sheniraid/libsignal-node</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：[GHSA-q823-m447-4rqv] Malware in @sheniraid/libsignal-node</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. Th...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞平台⏰ N/A</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：(tag:github.com,2008:GHSA-q823-m447-4rqv)</span></p></div><div style="background: rgba(39, 174, 96, 0.06);border: 1px solid rgba(39, 174, 96, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(39, 174, 96);font-weight: bold;margin-right: 8px;"><span leaf="">3.</span></span><span leaf=""> [GHSA-5g36-7rfc-494g] Malware in @sheniraid/baileys</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：[GHSA-5g36-7rfc-494g] Malware in @sheniraid/baileys</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. Th...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞平台⏰ N/A</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：(tag:github.com,2008:GHSA-5g36-7rfc-494g)</span></p></div><div style="background: rgba(39, 174, 96, 0.06);border: 1px solid rgba(39, 174, 96, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(39, 174, 96);font-weight: bold;margin-right: 8px;"><span leaf="">4.</span></span><span leaf=""> [GHSA-3q53-ww3h-grwr] Malware in big-numben</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：[GHSA-3q53-ww3h-grwr] Malware in big-numben</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. Th...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞平台⏰ N/A</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：(tag:github.com,2008:GHSA-3q53-ww3h-grwr)</span></p></div><div style="background: rgba(39, 174, 96, 0.06);border: 1px solid rgba(39, 174, 96, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(39, 174, 96);font-weight: bold;margin-right: 8px;"><span leaf="">5.</span></span><span leaf=""> [GHSA-5mcx-ff2q-gjjf] Malware in es-lint-builder</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：[GHSA-5mcx-ff2q-gjjf] Malware in es-lint-builder</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. Th...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞平台⏰ N/A</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：(tag:github.com,2008:GHSA-5mcx-ff2q-gjjf)</span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(192, 57, 43);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(192, 57, 43);padding-left: 15px;background: linear-gradient(90deg, rgba(192, 57, 43, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">🇨🇳</span></span><span leaf="">中国媒体</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(1条)</span></span></h2><div style="background: rgba(192, 57, 43, 0.06);border: 1px solid rgba(192, 57, 43, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(192, 57, 43);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> 聚焦新型电诈，构筑主动防御：梆梆安全移动金融反诈防护能力赋能银行精准风控</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：聚焦新型电诈，构筑主动防御：梆梆安全移动金融反诈防护能力赋能银行精准风控</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">行业实践面对日益严峻的电信网络诈骗威胁与监管合规压力，某股份制银行亟需提升移动端运行环境监测与风险识别能力。梆梆安全为其量身打造移动应用安全反诈防护方案，通过“安全加固+安全监测+专项检测”三位一体的综合防护体系，有效识别并抵御屏幕共享、远程控制、无障碍滥用等新型电诈风险。通过在APP中植入探针实现持续行为监测，结合专项风险场景检测，显著提升银行对终端环境的风险采集与分析能力。最终，该方案为银行风...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 中国媒体⏰ N/A</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：(<a href="https://www.4hou.com/posts/BvKo)" target="_blank">https://www.4hou.com/posts/BvKo)</a></span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px;padding: 25px;background: linear-gradient(135deg, rgb(248, 249, 250) 0%, rgb(255, 255, 255) 100%);border-radius: 12px;border: 1px solid rgb(233, 236, 239);"><h3 style="font-size: 16px;color: rgb(44, 62, 80);margin: 0px 0px 15px;font-weight: bold;"><span leaf="">📝 说明</span></h3><ul style="margin: 0px;padding-left: 20px;color: rgb(102, 102, 102);font-size: 13px;line-height: 2;" class="list-paddingleft-1"><li><p><span leaf="">本日报由 AI 自动抓取整理</span></p></li><li><p><span leaf="">内容来源：8 个 RSS 源 + 多个 API 接口</span></p></li><li><p><span leaf="">涵盖：漏洞、威胁、技术研究、威胁情报、漏洞赏金、社交媒体</span></p></li></ul><p style="text-align: center;margin: 20px 0px 0px;color: rgb(153, 153, 153);font-size: 12px;"><span leaf="">生成时间：2026-03-16 11:58:01</span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=81757e94&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MzkzOTYzOQ%3D%3D%26mid%3D2247489986%26idx%3D2%26sn%3D6c35fa86259c7341045cd9f8f9d28c4e">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 16 Mar 2026 20:44:00 +0800</pubDate>
    </item>
    <item>
      <title>枇杷熟了-全球网络安全日报2026-03-15</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MzkzOTYzOQ==&amp;mid=2247489977&amp;idx=1&amp;sn=24bf2eafc1856281231f63bf33566ccc</link>
      <description></description>
      <content:encoded><![CDATA[<p><span>枇杷哥</span> <span>2026-03-15 18:25</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=9283a9f0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FeZOA7OiaVuZiczSaLOZnQ7DfbVyE2erTgIpj1QyyrkE4FPg4fDictagSZ34GYUfwA5bk4VhFAjic1z0TVwHjrnKI2KJwkTSE4zOBe6GibNntJPW4%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background: linear-gradient(135deg, rgb(102, 126, 234) 0%, rgb(118, 75, 162) 100%);padding: 45px 25px;text-align: center;box-shadow: rgba(0, 0, 0, 0.15) 0px 4px 20px;" data-pm-slice="0 0 []"><p style="color: rgba(255, 255, 255, 0.85);font-size: 13px;margin: 0px 0px 10px;letter-spacing: 3px;text-transform: uppercase;"><span leaf="">Daily Security Newsletter</span></p><h1 style="color: rgb(255, 255, 255);font-size: 26px;margin: 15px 0px;font-weight: bold;text-shadow: rgba(0, 0, 0, 0.25) 2px 2px 8px;letter-spacing: 2px;line-height: 1.4;"><span leaf="">🔐 全球网络安全日报</span></h1><p style="color: rgba(255, 255, 255, 0.95);margin: 20px 0px 10px;font-size: 16px;font-weight: 500;"><span leaf="">📅 2026年03月15日 Sunday</span></p><p style="color: rgba(255, 255, 255, 0.8);margin: 10px 0px 0px;font-size: 13px;line-height: 1.6;"><span leaf="">每日精选全球网络安全最新研究、漏洞预警、技术动态、威胁情报</span></p></div><p style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background: linear-gradient(135deg, rgb(248, 249, 250) 0%, rgb(255, 255, 255) 100%);padding: 30px 20px;margin: 25px 15px;border-radius: 12px;border-left: 6px solid rgb(102, 126, 234);box-shadow: rgba(0, 0, 0, 0.06) 0px 2px 12px;"><h2 style="font-size: 18px;color: rgb(44, 62, 80);margin: 0px 0px 20px;font-weight: bold;display: flex;align-items: center;justify-content: center;"><span style="font-size: 24px;margin-right: 10px;"><span leaf="">📊</span></span><span leaf="">今日概览 · 共 28 条</span></h2><table style="width: 1693px;border-collapse: separate;border-spacing: 8px;"><tbody><tr><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(231, 76, 60, 0.12) 0%, rgba(231, 76, 60, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(231, 76, 60, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🚨</span></span><span style="color: rgb(231, 76, 60);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">漏洞与威胁</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">8</span></span></td><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(52, 152, 219, 0.12) 0%, rgba(52, 152, 219, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(52, 152, 219, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">📚</span></span><span style="color: rgb(52, 152, 219);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">技术研究</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">6</span></span></td></tr><tr><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(155, 89, 182, 0.12) 0%, rgba(155, 89, 182, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(155, 89, 182, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🔍</span></span><span style="color: rgb(142, 68, 173);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">威胁情报</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">8</span></span></td><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(46, 204, 113, 0.12) 0%, rgba(46, 204, 113, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(46, 204, 113, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🤖</span></span><span style="color: rgb(39, 174, 96);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">AI 安全</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">0</span></span></td></tr><tr><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(230, 126, 34, 0.12) 0%, rgba(230, 126, 34, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(230, 126, 34, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">☁️</span></span><span style="color: rgb(211, 84, 0);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">云安全</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">0</span></span></td><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(52, 73, 94, 0.12) 0%, rgba(52, 73, 94, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(52, 73, 94, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🇨🇳</span></span><span style="color: rgb(192, 57, 43);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">中国媒体</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">0</span></span></td></tr></tbody></table></p><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(231, 76, 60);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(231, 76, 60);padding-left: 15px;background: linear-gradient(90deg, rgba(231, 76, 60, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">🚨</span></span><span leaf="">漏洞与威胁</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(8 条)</span></span></h2><div style="background: rgba(231, 76, 60, 0.06);border: 1px solid rgba(231, 76, 60, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> OpenClaw AI Agent缺陷可能导致提示注入和数据泄露</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：OpenClaw AI Agent Flaws Could Enable Prompt Injection and Data Exfiltration</span></span><span style="background: rgb(231, 76, 60);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">HOT</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">中国国家计算机网络应急响应技术小组（ CNCERT ）已就使用OpenClaw （前身为Clawdbot和Moltbot ）的安全性发出警告， OpenClaw是一种开源和自托管的自主人工智能（ AI ）代理。在微信上分享的帖子中， CNCERT...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Sat, 14 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/openclaw-ai-agent-flaws-could-enable.html" target="_blank">https://thehackernews.com/2026/03/openclaw-ai-agent-flaws-could-enable.html</a></span></p></div><div style="background: rgba(231, 76, 60, 0.06);border: 1px solid rgba(231, 76, 60, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">2.</span></span><span leaf=""> GlassWorm供应链攻击滥用72个向目标开发者开放的VSX扩展</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：GlassWorm Supply-Chain Attack Abuses 72 Open VSX Extensions to Target Developers</span></span><span style="background: rgb(231, 76, 60);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">HOT</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">网络安全研究人员标记了GlassWorm活动的新版本，他们认为这是通过Open VSX注册表传播方式的“重大升级”。“威胁行为者现在不是要求每个恶意房源都直接嵌入加载器，而是滥用……</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Sat, 14 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/glassworm-supply-chain-attack-abuses-72.html" target="_blank">https://thehackernews.com/2026/03/glassworm-supply-chain-attack-abuses-72.html</a></span></p></div><div style="background: rgba(231, 76, 60, 0.06);border: 1px solid rgba(231, 76, 60, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">3.</span></span><span leaf=""> xx黑客通过AppleChris和MemFun恶意软件瞄准东南亚军队</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Chinese Hackers Target Southeast Asian Militaries with AppleChris and MemFun Mal...</span></span><span style="background: rgb(231, 76, 60);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">HOT</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">据怀疑，xx的网络间谍行动针对的是东南亚军事组织，这是至少可以追溯到2020年的国家支持活动的一部分。Palo Alto Networks Unit 42正在绰号CL-STA-1087下跟踪威胁活动，其中CL指的是集群， S...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Fri, 13 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/chinese-hackers-target-southeast-asian.html" target="_blank">https://thehackernews.com/2026/03/chinese-hackers-target-southeast-asian.html</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">4.</span></span><span leaf=""> Meta将于2026年5月起关闭Instagram端到端加密聊天支持</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Meta to Shut Down Instagram End-to-End Encrypted Chat Support Starting May 2026</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Meta已宣布计划在2026年5月8日之后停止对Instagram聊天端到端加密(E2EE)的支持。这家社交媒体巨头表示： “如果您的聊天受到此更改的影响，您将看到有关如何下载您可能想要保留的任何媒体或消息的说明。”</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Fri, 13 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/meta-to-shut-down-instagram-end-to-end.html" target="_blank">https://thehackernews.com/2026/03/meta-to-shut-down-instagram-end-to-end.html</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">5.</span></span><span leaf=""> 国际刑警组织拆除45,000个恶意IP ，在全球网络犯罪中逮捕94人</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：INTERPOL Dismantles 45,000 Malicious IPs, Arrests 94 in Global Cybercrime</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">国际刑警组织周五宣布，将删除与网络钓鱼、恶意软件和勒索软件活动有关的45,000个恶意IP地址和服务器，这是该机构正在进行的拆除犯罪网络、破坏新兴威胁和保护受害者免受诈骗的努力的一部分。</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Fri, 13 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/interpol-dismantles-45000-malicious-ips.html" target="_blank">https://thehackernews.com/2026/03/interpol-dismantles-45000-malicious-ips.html</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">6.</span></span><span leaf=""> 微软发布Windows 11 OOB热补丁修复RRAS RCE漏洞</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Microsoft releases Windows 11 OOB hotpatch to fix RRAS RCE flaw</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Microsoft已发布带外(OOB)更新，以修复影响Windows 11企业版设备的安全漏洞，这些设备接收的是热修补程序更新，而不是常规的Patch Tuesday累积更新。[...]</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Sat, 14 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-windows-11-oob-hotpatch-to-fix-rras-rce-flaw/" target="_blank">https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-windows-11-oob-hotpatch-to-fix-rras-rce-flaw/</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">7.</span></span><span leaf=""> AppsFlyer Web SDK被劫持以传播窃取加密的JavaScript代码</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：AppsFlyer Web SDK hijacked to spread crypto-stealing JavaScript code</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">AppsFlyer Web SDK本周被暂时劫持，恶意代码用于在供应链攻击中窃取加密货币。[...]</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Sat, 14 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.bleepingcomputer.com/news/security/appsflyer-web-sdk-used-to-spread-crypto-stealer-javascript-code/" target="_blank">https://www.bleepingcomputer.com/news/security/appsflyer-web-sdk-used-to-spread-crypto-stealer-javascript-code/</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">8.</span></span><span leaf=""> 微软： Windows 11用户无法在某些三星PC上访问C: drive</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Microsoft: Windows 11 users can&#39;t access C: drive on some Samsung PCs</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">在安装2026年2月的安全更新后，微软正在调查一个影响一些运行Windows 11的三星笔记本电脑的新问题，其中用户无法访问其C:\驱动器并无法启动应用程序。[...]</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Fri, 13 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-windows-11-users-cant-access-c-drive-on-some-samsung-pcs/" target="_blank">https://www.bleepingcomputer.com/news/microsoft/microsoft-windows-11-users-cant-access-c-drive-on-some-samsung-pcs/</a></span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(52, 152, 219);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(52, 152, 219);padding-left: 15px;background: linear-gradient(90deg, rgba(52, 152, 219, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">📚</span></span><span leaf="">技术研究</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(6 条)</span></span></h2><div style="background: rgba(52, 152, 219, 0.06);border: 1px solid rgba(52, 152, 219, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> Storm-2561使用SEO中毒来分发虚假VPN客户端，以进行凭据窃取</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential thef...</span></span><span style="background: rgb(52, 152, 219);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">RECOMMEND</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Storm-2561使用SEO中毒来推送虚假VPN下载，这些下载会安装已签名的特洛伊木马并窃取VPN凭据。Storm-2561自2025年以来一直活跃，模仿值得信赖的品牌并滥用合法服务。本文回顾了TTP、IOC和缓解指南。文章Storm-2561使用SEO中毒来区分...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Thu, 12 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.microsoft.com/en-us/security/blog/2026/03/12/storm-2561-uses-seo-poisoning-to-distribute-fake-vpn-clients-for-credential-theft/" target="_blank">https://www.microsoft.com/en-us/security/blog/2026/03/12/storm-2561-uses-seo-poisoning-to-distribute-fake-vpn-clients-for-credential-theft/</a></span></p></div><div style="background: rgba(52, 152, 219, 0.06);border: 1px solid rgba(52, 152, 219, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">2.</span></span><span leaf=""> 从透明度到行动：最新的Microsoft电子邮件安全基准揭示了什么</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：From transparency to action: What the latest Microsoft email security benchmark ...</span></span><span style="background: rgb(52, 152, 219);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">RECOMMEND</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">最新的Microsoft基准数据揭示了与SEG和ICES供应商相比， Microsoft Defender如何缓解现代电子邮件威胁。帖子从透明度到行动：最新的Microsoft电子邮件安全基准显示的内容首先出现在Microsoft安全博客上。</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Thu, 12 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.microsoft.com/en-us/security/blog/2026/03/12/from-transparency-to-action-what-the-latest-microsoft-email-security-benchmark-reveals/" target="_blank">https://www.microsoft.com/en-us/security/blog/2026/03/12/from-transparency-to-action-what-the-latest-microsoft-email-security-benchmark-reveals/</a></span></p></div><div style="background: rgba(52, 152, 219, 0.06);border: 1px solid rgba(52, 152, 219, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">3.</span></span><span leaf=""> 检测和分析人工智能工具中的即时滥用</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Detecting and analyzing prompt abuse in AI tools</span></span><span style="background: rgb(52, 152, 219);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">RECOMMEND</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">内容中的隐藏指令可能会微妙地偏向人工智能，我们的场景展示了快速注入的工作原理，突出了监督和结构化响应剧本的必要性。“检测和分析人工智能工具中的即时滥用”一文首次出现在Microsoft安全博客上。</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Thu, 12 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.microsoft.com/en-us/security/blog/2026/03/12/detecting-analyzing-prompt-abuse-in-ai-tools/" target="_blank">https://www.microsoft.com/en-us/security/blog/2026/03/12/detecting-analyzing-prompt-abuse-in-ai-tools/</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">4.</span></span><span leaf=""> Contagious Interview ：通过虚假开发人员求职面试传递的恶意软件</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Contagious Interview: Malware delivered through fake developer job interviews</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Contagious Interview活动将针对目标开发人员的工作招聘武器化。威胁行为者冒充加密和人工智能公司的招聘人员，并通过虚假的编码评估提供OtterCookie和FlexibleFerret等后门。然后，恶意软件会窃取API令牌、云凭据、哭泣……</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Wed, 11 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.microsoft.com/en-us/security/blog/2026/03/11/contagious-interview-malware-delivered-through-fake-developer-job-interviews/" target="_blank">https://www.microsoft.com/en-us/security/blog/2026/03/11/contagious-interview-malware-delivered-through-fake-developer-job-interviews/</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">5.</span></span><span leaf=""> 为您的前沿转型提供安全的代理AI</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Secure agentic AI for your Frontier Transformation</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">了解Microsoft Agent 365和Microsoft 365 E7如何帮助保护您的前沿转型。Secure agentic AI for your Frontier Transformation一文首次出现在Microsoft安全博客上。</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Mon, 09 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.microsoft.com/en-us/security/blog/2026/03/09/secure-agentic-ai-for-your-frontier-transformation/" target="_blank">https://www.microsoft.com/en-us/security/blog/2026/03/09/secure-agentic-ai-for-your-frontier-transformation/</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">6.</span></span><span leaf=""> 企业使用CrowdStrike Charlotte AI改造安全运营的4种方式</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：4 Ways Businesses Use CrowdStrike Charlotte AI to Transform Security Operations</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">🔗 [阅读原文] (<a href="https://www.crowdstrike.com/en-us/blog/four-ways-businesses-use-charlotte-ai-to-transform-security-operations/)" target="_blank">https://www.crowdstrike.com/en-us/blog/four-ways-businesses-use-charlotte-ai-to-transform-security-operations/)</a> --- # # # 7.增强网络可见性：深入了解Falcon macOS传感器的新功能 * *来源 * *: 技术研究 * * *时间 *: 2020年3月11日</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Mar 12, 20</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.crowdstrike.com/en-us/blog/enhanced-network-visibility-dive-into-falcon-macos-sensor-new-capabilities/" target="_blank">https://www.crowdstrike.com/en-us/blog/enhanced-network-visibility-dive-into-falcon-macos-sensor-new-capabilities/</a></span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(142, 68, 173);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(142, 68, 173);padding-left: 15px;background: linear-gradient(90deg, rgba(142, 68, 173, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">🔍</span></span><span leaf="">威胁情报</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(8 条)</span></span></h2><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> 见解：擦拭器攻击的风险增加</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Insights: Increased Risk of Wiper Attacks</span></span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">我们观察到，通过网络钓鱼和滥用Microsoft Intune ，与伊朗有关的Handala Hack组织（又名Void Manticore ）发动的雨刮器攻击有所增加。文章Insights: Increased Risk of Wiper Attacks （见解：擦拭器攻击风险增加）首先出现在Unit 42上。</span></p><p style="margin: 0px 0px 8px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 威胁情报 · ⏰ Thu, 12 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://unit42.paloaltonetworks.com/handala-hack-wiper-attacks/" target="_blank">https://unit42.paloaltonetworks.com/handala-hack-wiper-attacks/</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">2.</span></span><span leaf=""> 疑似针对东南亚军事目标的中国间谍行动</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Suspected China-Based Espionage Operation Against Military T...</span></span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">间谍行动展示了针对东南亚目标的战略行动耐心，部署了定制后门。《针对东南亚军事目标的涉嫌中国间谍行动》一文首次出现在42部队上。</span></p><p style="margin: 0px 0px 8px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 威胁情报 · ⏰ Thu, 12 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://unit42.paloaltonetworks.com/espionage-campaign-against-military-targets/" target="_blank">https://unit42.paloaltonetworks.com/espionage-campaign-against-military-targets/</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">3.</span></span><span leaf=""> 审核守门人：模糊“AI法官”以绕过安全控制</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Auditing the Gatekeepers: Fuzzing &#34;AI Judges&#34; to Bypass Secu...</span></span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">Unit 42的研究表明，人工智能评委容易受到隐形提示注入的影响。良性格式化符号可以绕过安全控制。审计守门人：模糊“AI法官”以绕过安全控制的帖子首先出现在第42单元上。</span></p><p style="margin: 0px 0px 8px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 威胁情报 · ⏰ Tue, 10 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://unit42.paloaltonetworks.com/fuzzing-ai-judges-security-bypass/" target="_blank">https://unit42.paloaltonetworks.com/fuzzing-ai-judges-security-bypass/</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">4.</span></span><span leaf=""> 对多年来未被发现的针对高价值行业的运营的调查</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：An Investigation Into Years of Undetected Operations Targeti...</span></span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">深入分析我们称之为CL-UNK-1068的威胁活动。我们讨论了他们的工具集，包括隧道、侦察和凭据窃取。“对多年来针对高价值行业的未被发现的行动的调查”一文首先出现在第42单元上。</span></p><p style="margin: 0px 0px 8px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 威胁情报 · ⏰ Fri, 06 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://unit42.paloaltonetworks.com/cl-unk-1068-targets-critical-sectors/" target="_blank">https://unit42.paloaltonetworks.com/cl-unk-1068-targets-critical-sectors/</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">5.</span></span><span leaf=""> 欺骗AI智能体：在野外观察到的基于Web的间接提示注射</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Fooling AI Agents: Web-Based Indirect Prompt Injection Obser...</span></span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">发现真实世界的间接提示注入攻击，并了解对手如何将隐藏的网络内容武器化，以利用LLM进行高影响力的欺诈。《Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild》一文首次出现在第42单元。</span></p><p style="margin: 0px 0px 8px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 威胁情报 · ⏰ Tue, 03 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://unit42.paloaltonetworks.com/ai-agent-prompt-injection/" target="_blank">https://unit42.paloaltonetworks.com/ai-agent-prompt-injection/</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">6.</span></span><span leaf=""> 伊朗冲突情报仪表板立即可用于ThreatConnect</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Iranian Conflict Intelligence Dashboard Immediately Availabl...</span></span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">2026年2月最后几天，专门针对伊朗冲突的地缘政治紧张局势升级，加剧了全球组织面临的重大网络和物理安全风险。由于威胁活动来自先进的伊朗国家支持的行为者， ALIGNE...</span></p><p style="margin: 0px 0px 8px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 威胁情报 · ⏰ Fri, 06 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://threatconnect.com/blog/iranian-conflict-intelligence-dashboard-immediately-available-for-threatconnect/" target="_blank">https://threatconnect.com/blog/iranian-conflict-intelligence-dashboard-immediately-available-for-threatconnect/</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">7.</span></span><span leaf=""> 从噪音到信号：制定TI知情检测以实现真正的安全价值</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：From Noise to Signal: Crafting TI-Informed Detections for Re...</span></span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">MSSP将警报噪音转化为可防御的安全成果托管安全服务提供商(MSSP)的实用指南每天都会产生大量警报。然而，许多MSSP客户仍然会问同样的问题： “这实际上保护了我们免受什么影响？”警报激活之间的这个间隙……</span></p><p style="margin: 0px 0px 8px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 威胁情报 · ⏰ Tue, 03 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://threatconnect.com/blog/from-noise-to-signal-crafting-ti-informed-detections-for-real-security-value/" target="_blank">https://threatconnect.com/blog/from-noise-to-signal-crafting-ti-informed-detections-for-real-security-value/</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">8.</span></span><span leaf=""> 优先考虑实际重要的漏洞</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Prioritizing Vulnerabilities That Actually Matter</span></span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">为什么为MSSP划分漏洞优先级—以及如何最好地解决这个问题当95%的组织没有达到响应时间最佳实践时，能够始终如一地减少平均响应时间（ MTTR ）的MSSP不仅可以改善安全结果，还可以赢得并留住客户。...</span></p><p style="margin: 0px 0px 8px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 威胁情报 · ⏰ Wed, 25 Fe</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://threatconnect.com/blog/prioritizing-vulnerabilities-that-actually-matter/" target="_blank">https://threatconnect.com/blog/prioritizing-vulnerabilities-that-actually-matter/</a></span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background: linear-gradient(135deg, rgb(248, 249, 250) 0%, rgb(255, 255, 255) 100%);padding: 35px 25px;margin: 30px 15px;border-radius: 12px;text-align: center;border: 1px solid rgba(0, 0, 0, 0.05);"><h2 style="font-size: 17px;color: rgb(44, 62, 80);margin: 0px 0px 20px;font-weight: bold;letter-spacing: 1px;"><span leaf="">📝 关于本报</span></h2><p style="color: rgb(127, 140, 141);margin: 12px 0px;font-size: 14px;line-height: 1.8;"><span leaf="">🤖 本日报由 AI 自动抓取整理，每日上午 9:00 更新</span></p><p style="color: rgb(127, 140, 141);margin: 12px 0px;font-size: 14px;line-height: 1.8;"><span leaf="">🌐 内容来源：50+ 个全球网络安全 RSS 源 + API 接口</span></p><p style="color: rgb(127, 140, 141);margin: 12px 0px;font-size: 14px;line-height: 1.8;"><span leaf="">📬 涵盖：漏洞预警、技术研究、威胁情报、云安全、AI 安全等</span></p><p style="color: rgb(149, 165, 166);margin: 20px 0px 10px;font-size: 13px;"><span leaf="">━━━━━━━━━━━━━━━━━━━</span></p><p style="color: rgb(127, 140, 141);margin: 10px 0px;font-size: 13px;line-height: 1.6;"><span leaf="">如需订阅更多源、调整推送频率或合作，请联系管理员</span></p></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;padding: 35px 15px;margin-top: 10px;background: linear-gradient(rgb(255, 255, 255) 0%, rgb(248, 249, 250) 100%);"><p style="color: rgb(189, 195, 199);font-size: 13px;margin: 5px 0px;"><span leaf="">━━━━━━━━━━━━━━━━━━━</span></p><p style="color: rgb(102, 126, 234);font-size: 16px;margin: 15px 0px;font-weight: bold;letter-spacing: 2px;"><span leaf="">🍐 枇杷熟了</span></p><p style="color: rgb(149, 165, 166);font-size: 13px;margin: 8px 0px;"><span leaf="">专注网络安全技术分享</span></p><p style="color: rgb(189, 195, 199);font-size: 12px;margin: 15px 0px;"><span leaf="">生成时间：2026-03-15 14:26:45</span></p><p style="color: rgb(189, 195, 199);font-size: 13px;margin: 5px 0px;"><span leaf="">━━━━━━━━━━━━━━━━━━━</span></p><p style="color: rgb(149, 165, 166);font-size: 12px;margin: 15px 0px 5px;"><span leaf="">感谢阅读 · 欢迎分享</span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=9a39d3a5&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MzkzOTYzOQ%3D%3D%26mid%3D2247489977%26idx%3D1%26sn%3D24bf2eafc1856281231f63bf33566ccc">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sun, 15 Mar 2026 18:25:00 +0800</pubDate>
    </item>
    <item>
      <title>枇杷熟了-全球网络安全日报2026-03-14</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MzkzOTYzOQ==&amp;mid=2247489972&amp;idx=1&amp;sn=b520ae35794132fb58b90b667eac7a39</link>
      <description></description>
      <content:encoded><![CDATA[<p><span>枇杷熟了</span> <span>2026-03-14 12:38</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=a1b78a17&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FeZOA7OiaVuZ9LaN8K370aFSdYPdfib9WfThlibkjOGB9wfWaTxEVyD6vLibUx8C9zhg7v2baSmFUBwGic8vPqxEkEd3BbRd96WPouR0fP0iaNqQGo%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background: linear-gradient(135deg, rgb(102, 126, 234) 0%, rgb(118, 75, 162) 100%);padding: 45px 25px;text-align: center;box-shadow: rgba(0, 0, 0, 0.15) 0px 4px 20px;" data-pm-slice="0 0 []"><p style="color: rgba(255, 255, 255, 0.85);font-size: 13px;margin: 0px 0px 10px;letter-spacing: 3px;text-transform: uppercase;"><span leaf="">Daily Security Newsletter</span></p><h1 style="color: rgb(255, 255, 255);font-size: 26px;margin: 15px 0px;font-weight: bold;text-shadow: rgba(0, 0, 0, 0.25) 2px 2px 8px;letter-spacing: 2px;line-height: 1.4;"><span leaf="">🔐 全球网络安全日报</span></h1><p style="color: rgba(255, 255, 255, 0.95);margin: 20px 0px 10px;font-size: 16px;font-weight: 500;"><span leaf="">📅 2026年03月14日 Saturday</span></p><p style="color: rgba(255, 255, 255, 0.8);margin: 10px 0px 0px;font-size: 13px;line-height: 1.6;"><span leaf="">每日精选全球网络安全最新研究、漏洞预警、技术动态、威胁情报</span></p></div><p style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background: linear-gradient(135deg, rgb(248, 249, 250) 0%, rgb(255, 255, 255) 100%);padding: 30px 20px;margin: 25px 15px;border-radius: 12px;border-left: 6px solid rgb(102, 126, 234);box-shadow: rgba(0, 0, 0, 0.06) 0px 2px 12px;"><h2 style="font-size: 18px;color: rgb(44, 62, 80);margin: 0px 0px 20px;font-weight: bold;display: flex;align-items: center;justify-content: center;"><span style="font-size: 24px;margin-right: 10px;"><span leaf="">📊</span></span><span leaf="">今日概览 · 共 10 条</span></h2><table style="width: 1693px;border-collapse: separate;border-spacing: 8px;"><tbody><tr><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(231, 76, 60, 0.12) 0%, rgba(231, 76, 60, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(231, 76, 60, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🚨</span></span><span style="color: rgb(231, 76, 60);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">漏洞与威胁</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">8</span></span></td><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(52, 152, 219, 0.12) 0%, rgba(52, 152, 219, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(52, 152, 219, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">📚</span></span><span style="color: rgb(52, 152, 219);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">技术研究</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">2</span></span></td></tr><tr><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(155, 89, 182, 0.12) 0%, rgba(155, 89, 182, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(155, 89, 182, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🔍</span></span><span style="color: rgb(142, 68, 173);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">威胁情报</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">0</span></span></td><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(46, 204, 113, 0.12) 0%, rgba(46, 204, 113, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(46, 204, 113, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🤖</span></span><span style="color: rgb(39, 174, 96);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">AI 安全</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">0</span></span></td></tr><tr><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(230, 126, 34, 0.12) 0%, rgba(230, 126, 34, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(230, 126, 34, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">☁️</span></span><span style="color: rgb(211, 84, 0);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">云安全</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">0</span></span></td><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(52, 73, 94, 0.12) 0%, rgba(52, 73, 94, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(52, 73, 94, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🇨🇳</span></span><span style="color: rgb(192, 57, 43);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">中国媒体</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">0</span></span></td></tr></tbody></table></p><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(231, 76, 60);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(231, 76, 60);padding-left: 15px;background: linear-gradient(90deg, rgba(231, 76, 60, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">🚨</span></span><span leaf="">漏洞与威胁</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(8 条)</span></span></h2><div style="background: rgba(231, 76, 60, 0.06);border: 1px solid rgba(231, 76, 60, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> 黑客通过AppleChris和MemFun恶意软件瞄准东南亚军队</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Chinese Hackers Target Southeast Asian Militaries with AppleChris and MemFun Mal...</span></span><span style="background: rgb(231, 76, 60);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">HOT</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">据怀疑，xx的网络间谍行动针对的是东南亚军事组织，这是至少可以追溯到2020年的国家支持活动的一部分。Palo Alto Networks Unit 42正在绰号CL-STA-1087下跟踪威胁活动，其中CL指的是集群， S...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Fri, 13 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/chinese-hackers-target-southeast-asian.html" target="_blank">https://thehackernews.com/2026/03/chinese-hackers-target-southeast-asian.html</a></span></p></div><div style="background: rgba(231, 76, 60, 0.06);border: 1px solid rgba(231, 76, 60, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">2.</span></span><span leaf=""> Meta将于2026年5月起关闭Instagram端到端加密聊天支持</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Meta to Shut Down Instagram End-to-End Encrypted Chat Support Starting May 2026</span></span><span style="background: rgb(231, 76, 60);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">HOT</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Meta已宣布计划在2026年5月8日之后停止对Instagram聊天端到端加密(E2EE)的支持。这家社交媒体巨头表示： “如果您的聊天受到此更改的影响，您将看到有关如何下载您可能想要保留的任何媒体或消息的说明。”</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Fri, 13 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/meta-to-shut-down-instagram-end-to-end.html" target="_blank">https://thehackernews.com/2026/03/meta-to-shut-down-instagram-end-to-end.html</a></span></p></div><div style="background: rgba(231, 76, 60, 0.06);border: 1px solid rgba(231, 76, 60, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">3.</span></span><span leaf=""> 国际刑警组织拆除45,000个恶意IP ，在全球网络犯罪中逮捕94人</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：INTERPOL Dismantles 45,000 Malicious IPs, Arrests 94 in Global Cybercrime</span></span><span style="background: rgb(231, 76, 60);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">HOT</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">国际刑警组织周五宣布，将删除与网络钓鱼、恶意软件和勒索软件活动有关的45,000个恶意IP地址和服务器，这是该机构正在进行的拆除犯罪网络、破坏新兴威胁和保护受害者免受诈骗的努力的一部分。</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Fri, 13 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/interpol-dismantles-45000-malicious-ips.html" target="_blank">https://thehackernews.com/2026/03/interpol-dismantles-45000-malicious-ips.html</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">4.</span></span><span leaf=""> Storm-2561通过SEO中毒传播特洛伊木马VPN客户端以窃取凭据</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Storm-2561 Spreads Trojan VPN Clients via SEO Poisoning to Steal Credentials</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">微软披露了一项凭证盗窃活动的详细信息，该活动使用了通过搜索引擎优化(SEO)中毒技术分发的虚拟专用网络(VPN)客户端。&#34;该活动将搜索合法企业软件的用户重定向到上的恶意ZIP文件...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Fri, 13 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/storm-2561-spreads-trojan-vpn-clients.html" target="_blank">https://thehackernews.com/2026/03/storm-2561-spreads-trojan-vpn-clients.html</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">5.</span></span><span leaf=""> 调查新的点击修复变体</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Investigating a New Click-Fix Variant</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">免责声明：本报告由威胁研究中心编写，旨在提高网络安全意识，支持加强防御能力。它基于对出版时可用的当前威胁格局的独立研究和观察。内容...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Fri, 13 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/investigating-new-click-fix-variant.html" target="_blank">https://thehackernews.com/2026/03/investigating-new-click-fix-variant.html</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">6.</span></span><span leaf=""> 微软： Windows 11用户无法在某些三星PC上访问C: drive</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Microsoft: Windows 11 users can&#39;t access C: drive on some Samsung PCs</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">在安装2026年2月的安全更新后，微软正在调查一个影响一些运行Windows 11的三星笔记本电脑的新问题，其中用户无法访问其C:\驱动器并无法启动应用程序。[...]</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Fri, 13 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-windows-11-users-cant-access-c-drive-on-some-samsung-pcs/" target="_blank">https://www.bleepingcomputer.com/news/microsoft/microsoft-windows-11-users-cant-access-c-drive-on-some-samsung-pcs/</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">7.</span></span><span leaf=""> 联邦调查局寻找用于传播恶意软件的Steam游戏的受害者</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：FBI seeks victims of Steam games used to spread malware</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">联邦调查局要求安装了包含恶意软件的Steam游戏的游戏玩家提供信息，作为对上传到游戏平台的八款恶意游戏的持续调查的一部分。[...]</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Fri, 13 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.bleepingcomputer.com/news/security/fbi-seeks-victims-of-steam-games-used-to-spread-malware/" target="_blank">https://www.bleepingcomputer.com/news/security/fbi-seeks-victims-of-steam-games-used-to-spread-malware/</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">8.</span></span><span leaf=""> 波兰核研究中心成为网络攻击的目标</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Poland&#39;s nuclear research centre targeted by cyberattack</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">波兰国家核研究中心（ NCBJ ）表示，黑客以其IT基础设施为目标，但在造成任何影响之前，攻击被发现并被阻止。[...]</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Fri, 13 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.bleepingcomputer.com/news/security/polands-nuclear-research-centre-targeted-by-cyberattack/" target="_blank">https://www.bleepingcomputer.com/news/security/polands-nuclear-research-centre-targeted-by-cyberattack/</a></span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(52, 152, 219);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(52, 152, 219);padding-left: 15px;background: linear-gradient(90deg, rgba(52, 152, 219, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">📚</span></span><span leaf="">技术研究</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(2 条)</span></span></h2><div style="background: rgba(52, 152, 219, 0.06);border: 1px solid rgba(52, 152, 219, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> Metasploit总结2026年3月13日</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Metasploit Wrap-Up 03/13/2026</span></span><span style="background: rgb(52, 152, 219);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">RECOMMEND</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">这里没有坏运气： 13号星期五带来了新的模块和Metasploit Pro里程碑本周的Metasploit框架版本提供了三个新的模块，涉及侦察、逃避和利用：基于LeakIX的发现暴露的服务和泄露的数据， Linux x64 RC4有效负载打包器，用于...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Fri, 13 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-03-13-2026" target="_blank">https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-03-13-2026</a></span></p></div><div style="background: rgba(52, 152, 219, 0.06);border: 1px solid rgba(52, 152, 219, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">2.</span></span><span leaf=""> 网络安全的好坏和丑陋–第11周</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：The Good, the Bad and the Ugly in Cybersecurity – Week 11</span></span><span style="background: rgb(52, 152, 219);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">RECOMMEND</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">负责协助BlackCat的勒索软件谈判代表、攻击者利用FortiGate防火墙破坏网络，以及伊朗黑客分子清除Stryker系统。</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Fri, 13 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-11-7/" target="_blank">https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-11-7/</a></span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background: linear-gradient(135deg, rgb(248, 249, 250) 0%, rgb(255, 255, 255) 100%);padding: 35px 25px;margin: 30px 15px;border-radius: 12px;text-align: center;border: 1px solid rgba(0, 0, 0, 0.05);"><h2 style="font-size: 17px;color: rgb(44, 62, 80);margin: 0px 0px 20px;font-weight: bold;letter-spacing: 1px;"><span leaf="">📝 关于本报</span></h2><p style="color: rgb(127, 140, 141);margin: 12px 0px;font-size: 14px;line-height: 1.8;"><span leaf="">🤖 本日报由 AI 自动抓取整理，每日上午 9:00 更新</span></p><p style="color: rgb(127, 140, 141);margin: 12px 0px;font-size: 14px;line-height: 1.8;"><span leaf="">🌐 内容来源：50+ 个全球网络安全 RSS 源 + API 接口</span></p><p style="color: rgb(127, 140, 141);margin: 12px 0px;font-size: 14px;line-height: 1.8;"><span leaf="">📬 涵盖：漏洞预警、技术研究、威胁情报、云安全、AI 安全等</span></p><p style="color: rgb(149, 165, 166);margin: 20px 0px 10px;font-size: 13px;"><span leaf="">━━━━━━━━━━━━━━━━━━━</span></p><p style="color: rgb(127, 140, 141);margin: 10px 0px;font-size: 13px;line-height: 1.6;"><span leaf="">如需订阅更多源、调整推送频率或合作，请联系管理员</span></p></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;padding: 35px 15px;margin-top: 10px;background: linear-gradient(rgb(255, 255, 255) 0%, rgb(248, 249, 250) 100%);"><p style="color: rgb(189, 195, 199);font-size: 13px;margin: 5px 0px;"><span leaf="">━━━━━━━━━━━━━━━━━━━</span></p><p style="color: rgb(102, 126, 234);font-size: 16px;margin: 15px 0px;font-weight: bold;letter-spacing: 2px;"><span leaf="">🍐 枇杷熟了</span></p><p style="color: rgb(149, 165, 166);font-size: 13px;margin: 8px 0px;"><span leaf="">专注网络安全技术分享</span></p><p style="color: rgb(189, 195, 199);font-size: 12px;margin: 15px 0px;"><span leaf="">生成时间：2026-03-14 12:24:32</span></p><p style="color: rgb(189, 195, 199);font-size: 13px;margin: 5px 0px;"><span leaf="">━━━━━━━━━━━━━━━━━━━</span></p><p style="color: rgb(149, 165, 166);font-size: 12px;margin: 15px 0px 5px;"><span leaf="">感谢阅读 · 欢迎分享</span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=fd44d976&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MzkzOTYzOQ%3D%3D%26mid%3D2247489972%26idx%3D1%26sn%3Db520ae35794132fb58b90b667eac7a39">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sat, 14 Mar 2026 12:38:00 +0800</pubDate>
    </item>
    <item>
      <title>AI安全大模型攻防实战营--招生中</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MzkzOTYzOQ==&amp;mid=2247489972&amp;idx=2&amp;sn=36012806cd0eb5b60562c760beff773f</link>
      <description>2天掌握前沿技术 · 培养实战型人才</description>
      <content:encoded><![CDATA[<p><span>枇杷哥</span> <span>2026-03-14 12:38</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=b9b77008&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FeZOA7OiaVuZ8FicNSgJH5W5phliaRL63lNETzDicrKESQqEDXLychJzMvQW4UhoKGLlIQ9q6DE1iaHETyK8M1OciaQYqKUpAryR8THT0Nkda2eByM%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p><span leaf="">2天掌握前沿技术 · 培养实战型人才</span></p><h3 style="font-size: 22px;color: rgb(200, 16, 46);border-left: 5px solid rgb(200, 16, 46);padding-left: 18px;margin-bottom: 30px;background: rgb(255, 245, 245);padding-top: 12px;padding-bottom: 12px;font-weight: bold;"><span leaf="">培训特色——前沿技术 · 实战导向</span></h3><table style="width: 700px;border-collapse: separate;border-spacing: 10px;margin-bottom: 25px;"><tbody><tr><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">Prompt越狱</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">大模型注入</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">MCP开发</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">MCP安全</span></p></td></tr><tr><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">AI Agent</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">OpenClaw</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">Skill开发</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">RAG攻防</span></p></td></tr><tr><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">多模态攻击</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">数据投毒</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">模型窃取</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">AI赋能黑客</span></p></td></tr><tr><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">AI代码审计</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">AI漏洞挖掘</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">插件安全</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">供应链安全</span></p></td></tr></tbody></table><h3 style="font-size: 22px;color: rgb(200, 16, 46);border-left: 5px solid rgb(200, 16, 46);padding-left: 18px;margin-bottom: 30px;background: rgb(255, 245, 245);padding-top: 12px;padding-bottom: 12px;font-weight: bold;"><span leaf="">培训目标——培养实战型AI安全人才</span></h3><p style="font-size: 17px;line-height: 2;margin: 0px;text-indent: 2em;"><span leaf="">本培训旨在贯彻落实国家关于加强网络安全人才培养的战略部署，推动人工智能技术赋能网络安全建设。通过系统性实战教学，培养具备AI安全攻防能力的专业人才，为国家关键信息基础设施安全建设提供人才保障。说人话，搞培训！（自学能力强完全没必要花钱！！！）</span></p><h3 style="font-size: 22px;color: rgb(200, 16, 46);border-left: 5px solid rgb(200, 16, 46);padding-left: 18px;margin-bottom: 30px;background: rgb(255, 245, 245);padding-top: 12px;padding-bottom: 12px;font-weight: bold;"><span leaf="">核心技术——十五大技术栈全覆盖</span></h3><p><span leaf="">一、大模型安全技术</span></p><p><span leaf="">Prompt越狱、大模型注入、数据投毒、模型窃取、OWASP LLM Top 10</span></p><p><span leaf="">二、前沿协议与框架</span></p><p><span leaf="">MCP协议、Open Claw框架、Skill开发、Agent开发、RAG系统</span></p><p><span leaf="">三、AI赋能与攻防</span></p><p><span leaf="">AI赋能黑客、AI代码审计、AI漏洞挖掘、多模态攻击、插件安全</span></p><h3 style="font-size: 22px;color: rgb(200, 16, 46);border-left: 5px solid rgb(200, 16, 46);padding-left: 18px;margin-bottom: 30px;background: rgb(255, 245, 245);padding-top: 12px;padding-bottom: 12px;font-weight: bold;"><span leaf="">培训安排</span></h3><table style="width: 720px;border-collapse: collapse;margin-bottom: 30px;border: 2px solid rgb(200, 16, 46);"><tbody><tr><th style="background: rgb(200, 16, 46);color: rgb(255, 255, 255);padding: 18px;border: 1px solid rgb(200, 16, 46);font-weight: bold;font-size: 16px;"><p><span leaf="">培训项目</span></p></th><th style="background: rgb(200, 16, 46);color: rgb(255, 255, 255);padding: 18px;border: 1px solid rgb(200, 16, 46);font-weight: bold;font-size: 16px;"><p><span leaf="">具体内容</span></p></th></tr><tr><td style="padding: 18px;border: 1px solid rgb(221, 221, 221);text-align: center;background: rgb(249, 249, 249);font-weight: bold;"><p><span leaf="">培训时间</span></p></td><td style="padding: 18px;border: 1px solid rgb(221, 221, 221);text-align: center;"><p><span leaf="">每月一期（具体日期待定）</span></p></td></tr><tr><td style="padding: 18px;border: 1px solid rgb(221, 221, 221);text-align: center;background: rgb(249, 249, 249);font-weight: bold;"><p><span leaf="">培训地点</span></p></td><td style="padding: 18px;border: 1px solid rgb(221, 221, 221);text-align: center;"><p><span leaf="">线上/线下（可选）</span></p></td></tr><tr><td style="padding: 18px;border: 1px solid rgb(221, 221, 221);text-align: center;background: rgb(249, 249, 249);font-weight: bold;"><p><span leaf="">培训费用</span></p></td><td style="padding: 18px;border: 1px solid rgb(221, 221, 221);text-align: center;font-size: 20px;font-weight: bold;color: rgb(200, 16, 46);"><p><span leaf="">3,800元/人</span></p></td></tr><tr><td style="padding: 18px;border: 1px solid rgb(221, 221, 221);text-align: center;background: rgb(249, 249, 249);font-weight: bold;"><p><span leaf="">早鸟优惠</span></p></td><td style="padding: 18px;border: 1px solid rgb(221, 221, 221);text-align: center;font-size: 20px;font-weight: bold;color: rgb(211, 47, 47);"><p><span leaf="">3,200元（限前10名）</span></p></td></tr></tbody></table><h3 style="font-size: 22px;color: rgb(200, 16, 46);border-left: 5px solid rgb(200, 16, 46);padding-left: 18px;margin-bottom: 30px;background: rgb(255, 245, 245);padding-top: 12px;padding-bottom: 12px;font-weight: bold;"><span leaf="">报名方式</span></h3><p style="color: rgb(102, 102, 102);font-size: 15px;margin-bottom: 20px;"><span leaf="">添加微信gnosismask咨询详情，备注&#34;AI安全培训&#34;。 后台回复&#34;</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(102, 102, 102);font-size: 15px;margin-bottom: 20px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">AI安全培训&#34;获取课表</span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=320895b8&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MzkzOTYzOQ%3D%3D%26mid%3D2247489972%26idx%3D2%26sn%3D36012806cd0eb5b60562c760beff773f">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sat, 14 Mar 2026 12:38:00 +0800</pubDate>
    </item>
    <item>
      <title>枇杷熟了-全球网络安全日报2026-03-12</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MzkzOTYzOQ==&amp;mid=2247489967&amp;idx=1&amp;sn=dea1a09f2f455bf5e219b5e2f29739c4</link>
      <description></description>
      <content:encoded><![CDATA[<p><span>枇杷哥</span> <span>2026-03-13 14:27</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=aa094e55&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FeZOA7OiaVuZ9NUpMQJ9ibrAheVGosOaLag46znCrwU7Daul6RyxLiaibVvXc07PDPZQE65PzzRVLrV0QW2tuT5Lr7GMAXCBYnzCNJdzBZvQx6Kk%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background: linear-gradient(135deg, rgb(102, 126, 234) 0%, rgb(118, 75, 162) 100%);padding: 45px 25px;text-align: center;box-shadow: rgba(0, 0, 0, 0.15) 0px 4px 20px;" data-pm-slice="0 0 []"><p style="color: rgba(255, 255, 255, 0.85);font-size: 13px;margin: 0px 0px 10px;letter-spacing: 3px;text-transform: uppercase;"><span leaf="">Daily Security Newsletter</span></p><h1 style="color: rgb(255, 255, 255);font-size: 26px;margin: 15px 0px;font-weight: bold;text-shadow: rgba(0, 0, 0, 0.25) 2px 2px 8px;letter-spacing: 2px;line-height: 1.4;"><span leaf="">🔐 全球网络安全日报</span></h1><p style="color: rgba(255, 255, 255, 0.95);margin: 20px 0px 10px;font-size: 16px;font-weight: 500;"><span leaf="">📅 2026年03月13日 Friday</span></p><p style="color: rgba(255, 255, 255, 0.8);margin: 10px 0px 0px;font-size: 13px;line-height: 1.6;"><span leaf="">每日精选全球网络安全最新研究、漏洞预警、技术动态、威胁情报</span></p></div><p style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background: linear-gradient(135deg, rgb(248, 249, 250) 0%, rgb(255, 255, 255) 100%);padding: 30px 20px;margin: 25px 15px;border-radius: 12px;border-left: 6px solid rgb(102, 126, 234);box-shadow: rgba(0, 0, 0, 0.06) 0px 2px 12px;"><h2 style="font-size: 18px;color: rgb(44, 62, 80);margin: 0px 0px 20px;font-weight: bold;display: flex;align-items: center;justify-content: center;"><span style="font-size: 24px;margin-right: 10px;"><span leaf="">📊</span></span><span leaf="">今日概览 · 共 29 条</span></h2><table style="width: 1693px;border-collapse: separate;border-spacing: 8px;"><tbody><tr><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(231, 76, 60, 0.12) 0%, rgba(231, 76, 60, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(231, 76, 60, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🚨</span></span><span style="color: rgb(231, 76, 60);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">漏洞与威胁</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">8</span></span></td><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(52, 152, 219, 0.12) 0%, rgba(52, 152, 219, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(52, 152, 219, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">📚</span></span><span style="color: rgb(52, 152, 219);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">技术研究</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">6</span></span></td></tr><tr><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(155, 89, 182, 0.12) 0%, rgba(155, 89, 182, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(155, 89, 182, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🔍</span></span><span style="color: rgb(142, 68, 173);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">威胁情报</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">8</span></span></td><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(46, 204, 113, 0.12) 0%, rgba(46, 204, 113, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(46, 204, 113, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🤖</span></span><span style="color: rgb(39, 174, 96);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">AI 安全</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">0</span></span></td></tr><tr><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(230, 126, 34, 0.12) 0%, rgba(230, 126, 34, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(230, 126, 34, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">☁️</span></span><span style="color: rgb(211, 84, 0);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">云安全</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">0</span></span></td><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(52, 73, 94, 0.12) 0%, rgba(52, 73, 94, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(52, 73, 94, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🇨🇳</span></span><span style="color: rgb(192, 57, 43);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">中国媒体</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">0</span></span></td></tr></tbody></table></p><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(231, 76, 60);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(231, 76, 60);padding-left: 15px;background: linear-gradient(90deg, rgba(231, 76, 60, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">🚨</span></span><span leaf="">漏洞与威胁</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(8 条)</span></span></h2><div style="background: rgba(231, 76, 60, 0.06);border: 1px solid rgba(231, 76, 60, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> 基于Rust的VENON恶意软件通过凭证窃取覆盖瞄准33家巴西银行</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Rust-Based VENON Malware Targets 33 Brazilian Banks with Credential-Stealing Ove...</span></span><span style="background: rgb(231, 76, 60);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">HOT</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">网络安全研究人员披露了以Rust编写的针对巴西用户的新银行恶意软件的详细信息，标志着与拉丁美洲网络犯罪生态系统相关的其他已知基于Delphi的恶意软件家族的重大背离。该恶意软件旨在提供...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Thu, 12 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/rust-based-venon-malware-targets-33.html" target="_blank">https://thehackernews.com/2026/03/rust-based-venon-malware-targets-33.html</a></span></p></div><div style="background: rgba(231, 76, 60, 0.06);border: 1px solid rgba(231, 76, 60, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">2.</span></span><span leaf=""> Hive0163在勒索软件攻击中使用人工智能辅助Slopoly恶意软件进行持续访问</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Hive0163 Uses AI-Assisted Slopoly Malware for Persistent Access in Ransomware At...</span></span><span style="background: rgb(231, 76, 60);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">HOT</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">网络安全研究人员披露了一个可疑的人工智能(AI)恶意软件的详细信息，该恶意软件的代号为Slopoly ，由一个名为Hive0163的经济动机威胁参与者使用。“虽然仍然相对不引人注目，但Slopoly等人工智能生成的恶意软件显示了多么容易……</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Thu, 12 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/hive0163-uses-ai-assisted-slopoly.html" target="_blank">https://thehackernews.com/2026/03/hive0163-uses-ai-assisted-slopoly.html</a></span></p></div><div style="background: rgba(231, 76, 60, 0.06);border: 1px solid rgba(231, 76, 60, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">3.</span></span><span leaf=""> 如何在SOC中扩展网络钓鱼检测： CISO的3个步骤</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：How to Scale Phishing Detection in Your SOC: 3 Steps for CISOs</span></span><span style="background: rgb(231, 76, 60);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">HOT</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">网络钓鱼已悄然成为最难提前暴露的企业威胁之一。现代营销活动依赖于可信的基础设施、合法的身份验证流和加密流量，而不是粗糙的诱饵和明显的有效载荷，这些流量可以从传统的设备中隐藏恶意行为。</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Thu, 12 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/how-to-scale-phishing-detection-in-your.html" target="_blank">https://thehackernews.com/2026/03/how-to-scale-phishing-detection-in-your.html</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">4.</span></span><span leaf=""> ThreatsDay公告： OAuth Trap、EDR Killer、信号网络钓鱼、Zombie ZIP、AI平台黑客等</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：ThreatsDay Bulletin: OAuth Trap, EDR Killer, Signal Phishing, Zombie ZIP, AI Pla...</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">又一个星期四，又发生了一堆奇怪的安全事件，不知何故，在短短七天内就发生了。其中一些很聪明。有些是懒惰的。有几点属于“是的……这可能会比我们希望的更快出现在真实的事件中。“本周的图案f……</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Thu, 12 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/threatsday-bulletin-oauth-trap-edr.html" target="_blank">https://thehackernews.com/2026/03/threatsday-bulletin-oauth-trap-edr.html</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">5.</span></span><span leaf=""> 攻击者不只是发送网络钓鱼电子邮件。他们将您的SOC的工作量武器化</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Attackers Don&#39;t Just Send Phishing Emails. They Weaponize Your SOC&#39;s Workload</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">最危险的网络钓鱼活动不仅仅是为了愚弄员工。许多都是为了让调查他们的分析师筋疲力尽。当网络钓鱼调查需要12小时而不是5分钟时，结果可能会从封闭事件转变为违规行为。多年来，网络安全...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Thu, 12 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/attackers-dont-just-send-phishing.html" target="_blank">https://thehackernews.com/2026/03/attackers-dont-just-send-phishing.html</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">6.</span></span><span leaf=""> 加拿大零售巨头Loblaw通知客户数据泄露</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Canadian retail giant Loblaw notifies customers of data breach</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">尽管如此，出于谨慎的考虑， Loblaw表示已自动将所有客户从其帐户中注销。需要访问公司数字服务的账户持有人必须重新登录。[...]</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Thu, 12 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.bleepingcomputer.com/news/security/canadian-retail-giant-loblaw-notifies-customers-of-data-breach/" target="_blank">https://www.bleepingcomputer.com/news/security/canadian-retail-giant-loblaw-notifies-customers-of-data-breach/</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">7.</span></span><span leaf=""> 英格兰曲棍球队调查勒索软件数据泄露</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：England Hockey investigating ransomware data breach</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">英格兰曲棍球的管理机构英格兰曲棍球队正在调查潜在的数据泄露事件，此前AiLock勒索软件团伙在其数据泄露网站上将其列为受害者。[...]</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Thu, 12 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.bleepingcomputer.com/news/security/england-hockey-investigating-ransomware-data-breach/" target="_blank">https://www.bleepingcomputer.com/news/security/england-hockey-investigating-ransomware-data-breach/</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">8.</span></span><span leaf=""> 用于Interlock勒索软件攻击的人工智能生成的Slopoly恶意软件</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：AI-generated Slopoly malware used in Interlock ransomware attack</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">一种名为Slopoly的新型恶意软件，可能是使用生成式人工智能工具创建的，它允许威胁行为者在受感染的服务器上停留超过一周，并在Interlock勒索软件攻击中窃取数据。[...]</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Thu, 12 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.bleepingcomputer.com/news/security/ai-generated-slopoly-malware-used-in-interlock-ransomware-attack/" target="_blank">https://www.bleepingcomputer.com/news/security/ai-generated-slopoly-malware-used-in-interlock-ransomware-attack/</a></span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(52, 152, 219);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(52, 152, 219);padding-left: 15px;background: linear-gradient(90deg, rgba(52, 152, 219, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">📚</span></span><span leaf="">技术研究</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(6 条)</span></span></h2><div style="background: rgba(52, 152, 219, 0.06);border: 1px solid rgba(52, 152, 219, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> Storm-2561使用SEO中毒来分发虚假VPN客户端，以进行凭据窃取</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential thef...</span></span><span style="background: rgb(52, 152, 219);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">RECOMMEND</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Storm-2561使用SEO中毒来推送虚假VPN下载，这些下载会安装已签名的特洛伊木马并窃取VPN凭据。Storm-2561自2025年以来一直活跃，模仿值得信赖的品牌并滥用合法服务。本文回顾了TTP、IOC和缓解指南。文章Storm-2561使用SEO中毒来区分...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Thu, 12 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.microsoft.com/en-us/security/blog/2026/03/12/storm-2561-uses-seo-poisoning-to-distribute-fake-vpn-clients-for-credential-theft/" target="_blank">https://www.microsoft.com/en-us/security/blog/2026/03/12/storm-2561-uses-seo-poisoning-to-distribute-fake-vpn-clients-for-credential-theft/</a></span></p></div><div style="background: rgba(52, 152, 219, 0.06);border: 1px solid rgba(52, 152, 219, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">2.</span></span><span leaf=""> 从透明度到行动：最新的Microsoft电子邮件安全基准揭示了什么</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：From transparency to action: What the latest Microsoft email security benchmark ...</span></span><span style="background: rgb(52, 152, 219);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">RECOMMEND</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">最新的Microsoft基准数据揭示了与SEG和ICES供应商相比， Microsoft Defender如何缓解现代电子邮件威胁。帖子从透明度到行动：最新的Microsoft电子邮件安全基准显示的内容首先出现在Microsoft安全博客上。</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Thu, 12 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.microsoft.com/en-us/security/blog/2026/03/12/from-transparency-to-action-what-the-latest-microsoft-email-security-benchmark-reveals/" target="_blank">https://www.microsoft.com/en-us/security/blog/2026/03/12/from-transparency-to-action-what-the-latest-microsoft-email-security-benchmark-reveals/</a></span></p></div><div style="background: rgba(52, 152, 219, 0.06);border: 1px solid rgba(52, 152, 219, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">3.</span></span><span leaf=""> 检测和分析人工智能工具中的即时滥用</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Detecting and analyzing prompt abuse in AI tools</span></span><span style="background: rgb(52, 152, 219);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">RECOMMEND</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">内容中的隐藏指令可能会微妙地偏向人工智能，我们的场景展示了快速注入的工作原理，突出了监督和结构化响应剧本的必要性。“检测和分析人工智能工具中的即时滥用”一文首次出现在Microsoft安全博客上。</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Thu, 12 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.microsoft.com/en-us/security/blog/2026/03/12/detecting-analyzing-prompt-abuse-in-ai-tools/" target="_blank">https://www.microsoft.com/en-us/security/blog/2026/03/12/detecting-analyzing-prompt-abuse-in-ai-tools/</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">4.</span></span><span leaf=""> Contagious Interview ：通过虚假开发人员求职面试传递的恶意软件</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Contagious Interview: Malware delivered through fake developer job interviews</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Contagious Interview活动将针对目标开发人员的工作招聘武器化。威胁行为者冒充加密和人工智能公司的招聘人员，并通过虚假的编码评估提供OtterCookie和FlexibleFerret等后门。然后，恶意软件会窃取API令牌、云凭据、哭泣……</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Wed, 11 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.microsoft.com/en-us/security/blog/2026/03/11/contagious-interview-malware-delivered-through-fake-developer-job-interviews/" target="_blank">https://www.microsoft.com/en-us/security/blog/2026/03/11/contagious-interview-malware-delivered-through-fake-developer-job-interviews/</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">5.</span></span><span leaf=""> 为您的前沿转型提供安全的代理AI</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Secure agentic AI for your Frontier Transformation</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">了解Microsoft Agent 365和Microsoft 365 E7如何帮助保护您的前沿转型。Secure agentic AI for your Frontier Transformation一文首次出现在Microsoft安全博客上。</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Mon, 09 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.microsoft.com/en-us/security/blog/2026/03/09/secure-agentic-ai-for-your-frontier-transformation/" target="_blank">https://www.microsoft.com/en-us/security/blog/2026/03/09/secure-agentic-ai-for-your-frontier-transformation/</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">6.</span></span><span leaf=""> 企业使用CrowdStrike Charlotte AI改造安全运营的4种方式</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：4 Ways Businesses Use CrowdStrike Charlotte AI to Transform Security Operations</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">🔗 [阅读原文] (<a href="https://www.crowdstrike.com/en-us/blog/four-ways-businesses-use-charlotte-ai-to-transform-security-operations/)" target="_blank">https://www.crowdstrike.com/en-us/blog/four-ways-businesses-use-charlotte-ai-to-transform-security-operations/)</a> --- # # # 7.增强网络可见性：深入了解Falcon macOS传感器的新功能 * *来源 * *: 技术研究 * * *时间 *: 2020年3月11日</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Mar 12, 20</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.crowdstrike.com/en-us/blog/enhanced-network-visibility-dive-into-falcon-macos-sensor-new-capabilities/" target="_blank">https://www.crowdstrike.com/en-us/blog/enhanced-network-visibility-dive-into-falcon-macos-sensor-new-capabilities/</a></span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(142, 68, 173);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(142, 68, 173);padding-left: 15px;background: linear-gradient(90deg, rgba(142, 68, 173, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">🔍</span></span><span leaf="">威胁情报</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(8 条)</span></span></h2><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> 见解：擦拭器攻击的风险增加</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Insights: Increased Risk of Wiper Attacks</span></span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">我们观察到，通过网络钓鱼和滥用Microsoft Intune ，与伊朗有关的Handala Hack组织（又名Void Manticore ）发动的雨刮器攻击有所增加。文章Insights: Increased Risk of Wiper Attacks （见解：擦拭器攻击风险增加）首先出现在Unit 42上。</span></p><p style="margin: 0px 0px 8px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 威胁情报 · ⏰ Thu, 12 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://unit42.paloaltonetworks.com/handala-hack-wiper-attacks/" target="_blank">https://unit42.paloaltonetworks.com/handala-hack-wiper-attacks/</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">2.</span></span><span leaf=""> 疑似针对东南亚军事目标的中国间谍行动</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Suspected China-Based Espionage Operation Against Military T...</span></span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">间谍行动展示了针对东南亚目标的战略行动耐心，部署了定制后门。《针对东南亚军事目标的涉嫌中国间谍行动》一文首次出现在42部队上。</span></p><p style="margin: 0px 0px 8px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 威胁情报 · ⏰ Thu, 12 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://unit42.paloaltonetworks.com/espionage-campaign-against-military-targets/" target="_blank">https://unit42.paloaltonetworks.com/espionage-campaign-against-military-targets/</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">3.</span></span><span leaf=""> 审核守门人：模糊“AI法官”以绕过安全控制</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Auditing the Gatekeepers: Fuzzing &#34;AI Judges&#34; to Bypass Secu...</span></span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">Unit 42的研究表明，人工智能评委容易受到隐形提示注入的影响。良性格式化符号可以绕过安全控制。审计守门人：模糊“AI法官”以绕过安全控制的帖子首先出现在第42单元上。</span></p><p style="margin: 0px 0px 8px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 威胁情报 · ⏰ Tue, 10 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://unit42.paloaltonetworks.com/fuzzing-ai-judges-security-bypass/" target="_blank">https://unit42.paloaltonetworks.com/fuzzing-ai-judges-security-bypass/</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">4.</span></span><span leaf=""> 对多年来未被发现的针对高价值行业的运营的调查</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：An Investigation Into Years of Undetected Operations Targeti...</span></span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">深入分析我们称之为CL-UNK-1068的威胁活动。我们讨论了他们的工具集，包括隧道、侦察和凭据窃取。“对多年来针对高价值行业的未被发现的行动的调查”一文首先出现在第42单元上。</span></p><p style="margin: 0px 0px 8px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 威胁情报 · ⏰ Fri, 06 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://unit42.paloaltonetworks.com/cl-unk-1068-targets-critical-sectors/" target="_blank">https://unit42.paloaltonetworks.com/cl-unk-1068-targets-critical-sectors/</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">5.</span></span><span leaf=""> 欺骗AI智能体：在野外观察到的基于Web的间接提示注射</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Fooling AI Agents: Web-Based Indirect Prompt Injection Obser...</span></span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">发现真实世界的间接提示注入攻击，并了解对手如何将隐藏的网络内容武器化，以利用LLM进行高影响力的欺诈。《Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild》一文首次出现在第42单元。</span></p><p style="margin: 0px 0px 8px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 威胁情报 · ⏰ Tue, 03 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://unit42.paloaltonetworks.com/ai-agent-prompt-injection/" target="_blank">https://unit42.paloaltonetworks.com/ai-agent-prompt-injection/</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">6.</span></span><span leaf=""> 伊朗冲突情报仪表板立即可用于ThreatConnect</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Iranian Conflict Intelligence Dashboard Immediately Availabl...</span></span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">2026年2月最后几天，专门针对伊朗冲突的地缘政治紧张局势升级，加剧了全球组织面临的重大网络和物理安全风险。由于威胁活动来自先进的伊朗国家支持的行为者， ALIGNE...</span></p><p style="margin: 0px 0px 8px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 威胁情报 · ⏰ Fri, 06 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://threatconnect.com/blog/iranian-conflict-intelligence-dashboard-immediately-available-for-threatconnect/" target="_blank">https://threatconnect.com/blog/iranian-conflict-intelligence-dashboard-immediately-available-for-threatconnect/</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">7.</span></span><span leaf=""> 从噪音到信号：制定TI知情检测以实现真正的安全价值</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：From Noise to Signal: Crafting TI-Informed Detections for Re...</span></span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">MSSP将警报噪音转化为可防御的安全成果托管安全服务提供商(MSSP)的实用指南每天都会产生大量警报。然而，许多MSSP客户仍然会问同样的问题： “这实际上保护了我们免受什么影响？”警报激活之间的这个间隙……</span></p><p style="margin: 0px 0px 8px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 威胁情报 · ⏰ Tue, 03 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://threatconnect.com/blog/from-noise-to-signal-crafting-ti-informed-detections-for-real-security-value/" target="_blank">https://threatconnect.com/blog/from-noise-to-signal-crafting-ti-informed-detections-for-real-security-value/</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">8.</span></span><span leaf=""> 优先考虑实际重要的漏洞</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Prioritizing Vulnerabilities That Actually Matter</span></span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">为什么为MSSP划分漏洞优先级—以及如何最好地解决这个问题当95%的组织没有达到响应时间最佳实践时，能够始终如一地减少平均响应时间（ MTTR ）的MSSP不仅可以改善安全结果，还可以赢得并留住客户。...</span></p><p style="margin: 0px 0px 8px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 威胁情报 · ⏰ Wed, 25 Fe</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://threatconnect.com/blog/prioritizing-vulnerabilities-that-actually-matter/" target="_blank">https://threatconnect.com/blog/prioritizing-vulnerabilities-that-actually-matter/</a></span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background: linear-gradient(135deg, rgb(248, 249, 250) 0%, rgb(255, 255, 255) 100%);padding: 35px 25px;margin: 30px 15px;border-radius: 12px;text-align: center;border: 1px solid rgba(0, 0, 0, 0.05);"><h2 style="font-size: 17px;color: rgb(44, 62, 80);margin: 0px 0px 20px;font-weight: bold;letter-spacing: 1px;"><span leaf="">📝 关于本报</span></h2><p style="color: rgb(127, 140, 141);margin: 12px 0px;font-size: 14px;line-height: 1.8;"><span leaf="">🤖 本日报由 AI 自动抓取整理，每日上午 9:00 更新</span></p><p style="color: rgb(127, 140, 141);margin: 12px 0px;font-size: 14px;line-height: 1.8;"><span leaf="">🌐 内容来源：50+ 个全球网络安全 RSS 源 + API 接口</span></p><p style="color: rgb(127, 140, 141);margin: 12px 0px;font-size: 14px;line-height: 1.8;"><span leaf="">📬 涵盖：漏洞预警、技术研究、威胁情报、云安全、AI 安全等</span></p><p style="color: rgb(149, 165, 166);margin: 20px 0px 10px;font-size: 13px;"><span leaf="">━━━━━━━━━━━━━━━━━━━</span></p><p style="color: rgb(127, 140, 141);margin: 10px 0px;font-size: 13px;line-height: 1.6;"><span leaf="">如需订阅更多源、调整推送频率或合作，请联系管理员</span></p></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;padding: 35px 15px;margin-top: 10px;background: linear-gradient(rgb(255, 255, 255) 0%, rgb(248, 249, 250) 100%);"><p style="color: rgb(189, 195, 199);font-size: 13px;margin: 5px 0px;"><span leaf="">━━━━━━━━━━━━━━━━━━━</span></p><p style="color: rgb(102, 126, 234);font-size: 16px;margin: 15px 0px;font-weight: bold;letter-spacing: 2px;"><span leaf="">🍐 枇杷熟了</span></p><p style="color: rgb(149, 165, 166);font-size: 13px;margin: 8px 0px;"><span leaf="">专注网络安全技术分享</span></p><p style="color: rgb(189, 195, 199);font-size: 12px;margin: 15px 0px;"><span leaf="">生成时间：2026-03-13 13:18:05</span></p><p style="color: rgb(189, 195, 199);font-size: 13px;margin: 5px 0px;"><span leaf="">━━━━━━━━━━━━━━━━━━━</span></p><p style="color: rgb(149, 165, 166);font-size: 12px;margin: 15px 0px 5px;"><span leaf="">感谢阅读 · 欢迎分享 </span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=d8cdfc18&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MzkzOTYzOQ%3D%3D%26mid%3D2247489967%26idx%3D1%26sn%3Ddea1a09f2f455bf5e219b5e2f29739c4">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 13 Mar 2026 14:27:00 +0800</pubDate>
    </item>
    <item>
      <title>AI安全大模型攻防实战营</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MzkzOTYzOQ==&amp;mid=2247489967&amp;idx=2&amp;sn=af0f27a3fbe1ffdcaac7f4b02bb58d8b</link>
      <description>2天掌握前沿技术 · 培养实战型人才</description>
      <content:encoded><![CDATA[<p><span>枇杷哥</span> <span>2026-03-13 14:27</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=b9b77008&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FeZOA7OiaVuZ8FicNSgJH5W5phliaRL63lNETzDicrKESQqEDXLychJzMvQW4UhoKGLlIQ9q6DE1iaHETyK8M1OciaQYqKUpAryR8THT0Nkda2eByM%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p><span leaf="">2天掌握前沿技术 · 培养实战型人才</span></p><h3 style="font-size: 22px;color: rgb(200, 16, 46);border-left: 5px solid rgb(200, 16, 46);padding-left: 18px;margin-bottom: 30px;background: rgb(255, 245, 245);padding-top: 12px;padding-bottom: 12px;font-weight: bold;"><span leaf="">培训特色——前沿技术 · 实战导向</span></h3><table style="width: 700px;border-collapse: separate;border-spacing: 10px;margin-bottom: 25px;"><tbody><tr><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">Prompt越狱</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">大模型注入</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">MCP开发</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">MCP安全</span></p></td></tr><tr><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">AI Agent</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">OpenClaw</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">Skill开发</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">RAG攻防</span></p></td></tr><tr><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">多模态攻击</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">数据投毒</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">模型窃取</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">AI赋能黑客</span></p></td></tr><tr><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">AI代码审计</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">AI漏洞挖掘</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">插件安全</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">供应链安全</span></p></td></tr></tbody></table><h3 style="font-size: 22px;color: rgb(200, 16, 46);border-left: 5px solid rgb(200, 16, 46);padding-left: 18px;margin-bottom: 30px;background: rgb(255, 245, 245);padding-top: 12px;padding-bottom: 12px;font-weight: bold;"><span leaf="">培训目标——培养实战型AI安全人才</span></h3><p style="font-size: 17px;line-height: 2;margin: 0px;text-indent: 2em;"><span leaf="">本培训旨在贯彻落实国家关于加强网络安全人才培养的战略部署，推动人工智能技术赋能网络安全建设。通过系统性实战教学，培养具备AI安全攻防能力的专业人才，为国家关键信息基础设施安全建设提供人才保障。说人话，搞培训！（自学能力强完全没必要花钱！！！）</span></p><h3 style="font-size: 22px;color: rgb(200, 16, 46);border-left: 5px solid rgb(200, 16, 46);padding-left: 18px;margin-bottom: 30px;background: rgb(255, 245, 245);padding-top: 12px;padding-bottom: 12px;font-weight: bold;"><span leaf="">核心技术——十五大技术栈全覆盖</span></h3><p><span leaf="">一、大模型安全技术</span></p><p><span leaf="">Prompt越狱、大模型注入、数据投毒、模型窃取、OWASP LLM Top 10</span></p><p><span leaf="">二、前沿协议与框架</span></p><p><span leaf="">MCP协议、Open Claw框架、Skill开发、Agent开发、RAG系统</span></p><p><span leaf="">三、AI赋能与攻防</span></p><p><span leaf="">AI赋能黑客、AI代码审计、AI漏洞挖掘、多模态攻击、插件安全</span></p><h3 style="font-size: 22px;color: rgb(200, 16, 46);border-left: 5px solid rgb(200, 16, 46);padding-left: 18px;margin-bottom: 30px;background: rgb(255, 245, 245);padding-top: 12px;padding-bottom: 12px;font-weight: bold;"><span leaf="">培训安排</span></h3><table style="width: 720px;border-collapse: collapse;margin-bottom: 30px;border: 2px solid rgb(200, 16, 46);"><tbody><tr><th style="background: rgb(200, 16, 46);color: rgb(255, 255, 255);padding: 18px;border: 1px solid rgb(200, 16, 46);font-weight: bold;font-size: 16px;"><p><span leaf="">培训项目</span></p></th><th style="background: rgb(200, 16, 46);color: rgb(255, 255, 255);padding: 18px;border: 1px solid rgb(200, 16, 46);font-weight: bold;font-size: 16px;"><p><span leaf="">具体内容</span></p></th></tr><tr><td style="padding: 18px;border: 1px solid rgb(221, 221, 221);text-align: center;background: rgb(249, 249, 249);font-weight: bold;"><p><span leaf="">培训时间</span></p></td><td style="padding: 18px;border: 1px solid rgb(221, 221, 221);text-align: center;"><p><span leaf="">每月一期（具体日期待定）</span></p></td></tr><tr><td style="padding: 18px;border: 1px solid rgb(221, 221, 221);text-align: center;background: rgb(249, 249, 249);font-weight: bold;"><p><span leaf="">培训地点</span></p></td><td style="padding: 18px;border: 1px solid rgb(221, 221, 221);text-align: center;"><p><span leaf="">线上/线下（可选）</span></p></td></tr><tr><td style="padding: 18px;border: 1px solid rgb(221, 221, 221);text-align: center;background: rgb(249, 249, 249);font-weight: bold;"><p><span leaf="">培训费用</span></p></td><td style="padding: 18px;border: 1px solid rgb(221, 221, 221);text-align: center;font-size: 20px;font-weight: bold;color: rgb(200, 16, 46);"><p><span leaf="">3,800元/人</span></p></td></tr><tr><td style="padding: 18px;border: 1px solid rgb(221, 221, 221);text-align: center;background: rgb(249, 249, 249);font-weight: bold;"><p><span leaf="">早鸟优惠</span></p></td><td style="padding: 18px;border: 1px solid rgb(221, 221, 221);text-align: center;font-size: 20px;font-weight: bold;color: rgb(211, 47, 47);"><p><span leaf="">3,200元（限前10名）</span></p></td></tr></tbody></table><h3 style="font-size: 22px;color: rgb(200, 16, 46);border-left: 5px solid rgb(200, 16, 46);padding-left: 18px;margin-bottom: 30px;background: rgb(255, 245, 245);padding-top: 12px;padding-bottom: 12px;font-weight: bold;"><span leaf="">报名方式</span></h3><p style="color: rgb(102, 102, 102);font-size: 15px;margin-bottom: 20px;"><span leaf="">添加微信gnosismask咨询详情，备注&#34;AI安全培训&#34;。 后台回复&#34;</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(102, 102, 102);font-size: 15px;margin-bottom: 20px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">AI安全培训&#34;获取课表</span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=63633b0e&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MzkzOTYzOQ%3D%3D%26mid%3D2247489967%26idx%3D2%26sn%3Daf0f27a3fbe1ffdcaac7f4b02bb58d8b">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 13 Mar 2026 14:27:00 +0800</pubDate>
    </item>
    <item>
      <title>AI安全大模型攻防实战营</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MzkzOTYzOQ==&amp;mid=2247489962&amp;idx=1&amp;sn=3add2868548e94894519de1b52f0fb7c</link>
      <description>2天掌握前沿技术 · 培养实战型人才</description>
      <content:encoded><![CDATA[<p><span>枇杷哥</span> <span>2026-03-12 11:59</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=b9b77008&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FeZOA7OiaVuZ8FicNSgJH5W5phliaRL63lNETzDicrKESQqEDXLychJzMvQW4UhoKGLlIQ9q6DE1iaHETyK8M1OciaQYqKUpAryR8THT0Nkda2eByM%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p><span leaf="">2天掌握前沿技术 · 培养实战型人才</span></p><h3 style="font-size: 22px;color: rgb(200, 16, 46);border-left: 5px solid rgb(200, 16, 46);padding-left: 18px;margin-bottom: 30px;background: rgb(255, 245, 245);padding-top: 12px;padding-bottom: 12px;font-weight: bold;"><span leaf="">培训特色——前沿技术 · 实战导向</span></h3><table style="width: 700px;border-collapse: separate;border-spacing: 10px;margin-bottom: 25px;"><tbody><tr><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">Prompt越狱</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">大模型注入</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">MCP开发</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">MCP安全</span></p></td></tr><tr><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">AI Agent</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">OpenClaw</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">Skill开发</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">RAG攻防</span></p></td></tr><tr><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">多模态攻击</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">数据投毒</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">模型窃取</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">AI赋能黑客</span></p></td></tr><tr><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">AI代码审计</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">AI漏洞挖掘</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">插件安全</span></p></td><td style="background: linear-gradient(135deg, rgb(0, 255, 255), rgb(255, 0, 255));color: rgb(0, 0, 0);padding: 12px;text-align: center;font-weight: bold;border-radius: 8px;font-size: 14px;"><p><span leaf="">供应链安全</span></p></td></tr></tbody></table><h3 style="font-size: 22px;color: rgb(200, 16, 46);border-left: 5px solid rgb(200, 16, 46);padding-left: 18px;margin-bottom: 30px;background: rgb(255, 245, 245);padding-top: 12px;padding-bottom: 12px;font-weight: bold;"><span leaf="">培训目标——培养实战型AI安全人才</span></h3><p style="font-size: 17px;line-height: 2;margin: 0px;text-indent: 2em;"><span leaf="">本培训旨在贯彻落实国家关于加强网络安全人才培养的战略部署，推动人工智能技术赋能网络安全建设。通过系统性实战教学，培养具备AI安全攻防能力的专业人才，为国家关键信息基础设施安全建设提供人才保障。说人话，搞培训！（自学能力强完全没必要花钱！！！）</span></p><h3 style="font-size: 22px;color: rgb(200, 16, 46);border-left: 5px solid rgb(200, 16, 46);padding-left: 18px;margin-bottom: 30px;background: rgb(255, 245, 245);padding-top: 12px;padding-bottom: 12px;font-weight: bold;"><span leaf="">核心技术——十五大技术栈全覆盖</span></h3><p><span leaf="">一、大模型安全技术</span></p><p><span leaf="">Prompt越狱、大模型注入、数据投毒、模型窃取、OWASP LLM Top 10</span></p><p><span leaf="">二、前沿协议与框架</span></p><p><span leaf="">MCP协议、Open Claw框架、Skill开发、Agent开发、RAG系统</span></p><p><span leaf="">三、AI赋能与攻防</span></p><p><span leaf="">AI赋能黑客、AI代码审计、AI漏洞挖掘、多模态攻击、插件安全</span></p><h3 style="font-size: 22px;color: rgb(200, 16, 46);border-left: 5px solid rgb(200, 16, 46);padding-left: 18px;margin-bottom: 30px;background: rgb(255, 245, 245);padding-top: 12px;padding-bottom: 12px;font-weight: bold;"><span leaf="">培训安排</span></h3><table style="width: 720px;border-collapse: collapse;margin-bottom: 30px;border: 2px solid rgb(200, 16, 46);"><tbody><tr><th style="background: rgb(200, 16, 46);color: rgb(255, 255, 255);padding: 18px;border: 1px solid rgb(200, 16, 46);font-weight: bold;font-size: 16px;"><p><span leaf="">培训项目</span></p></th><th style="background: rgb(200, 16, 46);color: rgb(255, 255, 255);padding: 18px;border: 1px solid rgb(200, 16, 46);font-weight: bold;font-size: 16px;"><p><span leaf="">具体内容</span></p></th></tr><tr><td style="padding: 18px;border: 1px solid rgb(221, 221, 221);text-align: center;background: rgb(249, 249, 249);font-weight: bold;"><p><span leaf="">培训时间</span></p></td><td style="padding: 18px;border: 1px solid rgb(221, 221, 221);text-align: center;"><p><span leaf="">每月一期（具体日期待定）</span></p></td></tr><tr><td style="padding: 18px;border: 1px solid rgb(221, 221, 221);text-align: center;background: rgb(249, 249, 249);font-weight: bold;"><p><span leaf="">培训地点</span></p></td><td style="padding: 18px;border: 1px solid rgb(221, 221, 221);text-align: center;"><p><span leaf="">线上/线下（可选）</span></p></td></tr><tr><td style="padding: 18px;border: 1px solid rgb(221, 221, 221);text-align: center;background: rgb(249, 249, 249);font-weight: bold;"><p><span leaf="">培训费用</span></p></td><td style="padding: 18px;border: 1px solid rgb(221, 221, 221);text-align: center;font-size: 20px;font-weight: bold;color: rgb(200, 16, 46);"><p><span leaf="">3,800元/人</span></p></td></tr><tr><td style="padding: 18px;border: 1px solid rgb(221, 221, 221);text-align: center;background: rgb(249, 249, 249);font-weight: bold;"><p><span leaf="">早鸟优惠</span></p></td><td style="padding: 18px;border: 1px solid rgb(221, 221, 221);text-align: center;font-size: 20px;font-weight: bold;color: rgb(211, 47, 47);"><p><span leaf="">3,200元（限前10名）</span></p></td></tr></tbody></table><h3 style="font-size: 22px;color: rgb(200, 16, 46);border-left: 5px solid rgb(200, 16, 46);padding-left: 18px;margin-bottom: 30px;background: rgb(255, 245, 245);padding-top: 12px;padding-bottom: 12px;font-weight: bold;"><span leaf="">报名方式</span></h3><p style="color: rgb(102, 102, 102);font-size: 15px;margin-bottom: 20px;"><span leaf="">添加微信gnosismask咨询详情，备注&#34;AI安全培训&#34;</span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=95181868&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MzkzOTYzOQ%3D%3D%26mid%3D2247489962%26idx%3D1%26sn%3D3add2868548e94894519de1b52f0fb7c">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 12 Mar 2026 11:59:00 +0800</pubDate>
    </item>
    <item>
      <title>枇杷熟了-全球网络安全日报2026-03-12</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MzkzOTYzOQ==&amp;mid=2247489962&amp;idx=2&amp;sn=f34ec620e4eaf05b83bca7a555a36327</link>
      <description>每日精选全球网络安全最新研究、漏洞预警、技术动态、威胁情报</description>
      <content:encoded><![CDATA[<p><span>枇杷熟了</span> <span>2026-03-12 11:59</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=cf486a05&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FeZOA7OiaVuZ9b34Z9I7eddTRNMpXb0klkTP9x4MFJLAuHmL7bJc8JYdrS7T6Thbx9nJCz3ywQvGxg4ooWa953DJNxfpomwicH8PqYKoJjvJCs%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>每日精选全球网络安全最新研究、漏洞预警、技术动态、威胁情报</p>
  <div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background: linear-gradient(135deg, rgb(102, 126, 234) 0%, rgb(118, 75, 162) 100%);padding: 45px 25px;text-align: center;box-shadow: rgba(0, 0, 0, 0.15) 0px 4px 20px;" data-pm-slice="0 0 []"><p style="color: rgba(255, 255, 255, 0.85);font-size: 13px;margin: 0px 0px 10px;letter-spacing: 3px;text-transform: uppercase;"><span leaf="">Daily Security Newsletter</span></p><h1 style="color: rgb(255, 255, 255);font-size: 26px;margin: 15px 0px;font-weight: bold;text-shadow: rgba(0, 0, 0, 0.25) 2px 2px 8px;letter-spacing: 2px;line-height: 1.4;"><span leaf="">🔐 全球网络安全日报</span></h1><p style="color: rgba(255, 255, 255, 0.95);margin: 20px 0px 10px;font-size: 16px;font-weight: 500;"><span leaf="">📅 2026年03月12日 Thursday</span></p><p style="color: rgba(255, 255, 255, 0.8);margin: 10px 0px 0px;font-size: 13px;line-height: 1.6;"><span leaf="">每日精选全球网络安全最新研究、漏洞预警、技术动态、威胁情报</span></p></div><p style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background: linear-gradient(135deg, rgb(248, 249, 250) 0%, rgb(255, 255, 255) 100%);padding: 30px 20px;margin: 25px 15px;border-radius: 12px;border-left: 6px solid rgb(102, 126, 234);box-shadow: rgba(0, 0, 0, 0.06) 0px 2px 12px;"><h2 style="font-size: 18px;color: rgb(44, 62, 80);margin: 0px 0px 20px;font-weight: bold;display: flex;align-items: center;justify-content: center;"><span style="font-size: 24px;margin-right: 10px;"><span leaf="">📊</span></span><span leaf="">今日概览 · 共 17 条</span></h2><table style="width: 1693px;border-collapse: separate;border-spacing: 8px;"><tbody><tr><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(231, 76, 60, 0.12) 0%, rgba(231, 76, 60, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(231, 76, 60, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🚨</span></span><span style="color: rgb(231, 76, 60);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">漏洞与威胁</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">8</span></span></td><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(52, 152, 219, 0.12) 0%, rgba(52, 152, 219, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(52, 152, 219, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">📚</span></span><span style="color: rgb(52, 152, 219);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">技术研究</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">5</span></span></td></tr><tr><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(155, 89, 182, 0.12) 0%, rgba(155, 89, 182, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(155, 89, 182, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🔍</span></span><span style="color: rgb(142, 68, 173);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">威胁情报</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">0</span></span></td><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(46, 204, 113, 0.12) 0%, rgba(46, 204, 113, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(46, 204, 113, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🤖</span></span><span style="color: rgb(39, 174, 96);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">AI 安全</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">1</span></span></td></tr><tr><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(230, 126, 34, 0.12) 0%, rgba(230, 126, 34, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(230, 126, 34, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">☁️</span></span><span style="color: rgb(211, 84, 0);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">云安全</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">2</span></span></td><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(52, 73, 94, 0.12) 0%, rgba(52, 73, 94, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(52, 73, 94, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🇨🇳</span></span><span style="color: rgb(192, 57, 43);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">中国媒体</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">1</span></span></td></tr></tbody></table></p><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(231, 76, 60);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(231, 76, 60);padding-left: 15px;background: linear-gradient(90deg, rgba(231, 76, 60, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">🚨</span></span><span leaf="">漏洞与威胁</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(8 条)</span></span></h2><div style="background: rgba(231, 76, 60, 0.06);border: 1px solid rgba(231, 76, 60, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> Researchers Trick Perplexity&#39;s Comet AI Browser Into Phishing Scam in Under Four Minutes </span><span style="background: rgb(231, 76, 60);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">HOT</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">利用人工智能（ AI ）功能代表用户在多个网站上自动执行操作的代理网络浏览器可能会被训练和欺骗，成为网络钓鱼和诈骗陷阱的牺牲品。这种攻击的核心是利用人工智能浏览器倾向于...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Wed, 11 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/researchers-trick-perplexitys-comet-ai.html" target="_blank">https://thehackernews.com/2026/03/researchers-trick-perplexitys-comet-ai.html</a></span></p></div><div style="background: rgba(231, 76, 60, 0.06);border: 1px solid rgba(231, 76, 60, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">2.</span></span><span leaf=""> 严重的n8n缺陷允许远程执行代码和暴露存储的凭据</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Critical n8n Flaws Allow Remote Code Execution and Exposure of Stored Credential...</span></span><span style="background: rgb(231, 76, 60);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">HOT</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">网络安全研究人员披露了n8n工作流自动化平台中两个现已修补的安全漏洞的详细信息，其中包括可能导致任意命令执行的两个关键漏洞。漏洞列举如下- CVE-2026-27577 （ CVSS评分： 9.4 ） - Expression sandbox es...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Wed, 11 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/critical-n8n-flaws-allow-remote-code.html" target="_blank">https://thehackernews.com/2026/03/critical-n8n-flaws-allow-remote-code.html</a></span></p></div><div style="background: rgba(231, 76, 60, 0.06);border: 1px solid rgba(231, 76, 60, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">3.</span></span><span leaf=""> Meta在全球范围内禁用与东南亚诈骗中心相关的15万个账户</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Meta Disables 150K Accounts Linked to Southeast Asia Scam Centers in Global Crac...</span></span><span style="background: rgb(231, 76, 60);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">HOT</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Meta周三表示，作为与泰国、美国、英国、加拿大、韩国、日本、新加坡、菲律宾、澳大利亚、新西兰和印度尼西亚当局合作协调努力的一部分，它关闭了与东南亚诈骗中心相关的15万多个账户。</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Wed, 11 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/meta-disables-150k-accounts-linked-to.html" target="_blank">https://thehackernews.com/2026/03/meta-disables-150k-accounts-linked-to.html</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">4.</span></span><span leaf=""> 数十家供应商修补企业软件和网络设备的安全漏洞</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Dozens of Vendors Patch Security Flaws Across Enterprise Software and Network De...</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">SAP已发布安全更新，以解决可能被利用在受影响系统上执行任意代码的两个关键安全漏洞。下面列出的漏洞- CVE-2019-17571 （ CVSS评分： 9.8 ） - SAP报价管理中的代码注入漏洞...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Wed, 11 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/dozens-of-vendors-patch-security-flaws.html" target="_blank">https://thehackernews.com/2026/03/dozens-of-vendors-patch-security-flaws.html</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">5.</span></span><span leaf=""> 在人工智能自动化开发时代，电路板必须要求什么</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：What Boards Must Demand in the Age of AI-Automated Exploitation</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">“你知道，你本可以采取行动的。你为什么不呢？“这是你不想被问到的问题。越来越多地，这是领导者在事件发生后被迫回答的问题。多年来，许多高管团队和董事会一直将大量漏洞积压视为不适……</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Wed, 11 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/what-boards-must-demand-in-age-of-ai.html" target="_blank">https://thehackernews.com/2026/03/what-boards-must-demand-in-age-of-ai.html</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">6.</span></span><span leaf=""> 伊朗支持的黑客声称擦拭器攻击医疗技术公司Stryker</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">一个与伊朗情报机构有联系的黑客组织声称对总部位于密歇根州的全球医疗技术公司Stryker的数据擦除攻击负责。Stryker在美国以外最大的枢纽爱尔兰的新闻报道称，该公司早上将...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Wed, 11 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://krebsonsecurity.com/2026/03/iran-backed-hackers-claim-wiper-attack-on-medtech-firm-stryker/" target="_blank">https://krebsonsecurity.com/2026/03/iran-backed-hackers-claim-wiper-attack-on-medtech-firm-stryker/</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">7.</span></span><span leaf=""> 微软补丁2026年3月版</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Microsoft Patch Tuesday, March 2026 Edition</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">微软公司今天推出了安全更新，以修复其Windows操作系统和其他软件中的至少77个漏洞。本月没有紧迫的“零日”缺陷（与2月的五个零日对待相比） ，但像往常一样，一些补丁可能值得组织更迅速的关注......</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Wed, 11 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://krebsonsecurity.com/2026/03/microsoft-patch-tuesday-march-2026-edition/" target="_blank">https://krebsonsecurity.com/2026/03/microsoft-patch-tuesday-march-2026-edition/</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">8.</span></span><span leaf=""> INC Ransomware Group在大洋洲劫持医疗保健人质</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：INC Ransomware Group Holds Healthcare Hostage in Oceania</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">澳大利亚、新西兰和汤加的政府机构、急诊诊所和其他机构与多产的勒索软件设备发生了严重的冲突。</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Wed, 11 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.darkreading.com/threat-intelligence/inc-ransomware-healthcare-oceania" target="_blank">https://www.darkreading.com/threat-intelligence/inc-ransomware-healthcare-oceania</a></span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(52, 152, 219);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(52, 152, 219);padding-left: 15px;background: linear-gradient(90deg, rgba(52, 152, 219, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">📚</span></span><span leaf="">技术研究</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(5 条)</span></span></h2><div style="background: rgba(52, 152, 219, 0.06);border: 1px solid rgba(52, 152, 219, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> Contagious Interview ：通过虚假开发人员求职面试传递的恶意软件</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Contagious Interview: Malware delivered through fake developer job interviews</span></span><span style="background: rgb(52, 152, 219);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">RECOMMEND</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Contagious Interview活动将针对目标开发人员的工作招聘武器化。威胁行为者冒充加密和人工智能公司的招聘人员，并通过虚假的编码评估提供OtterCookie和FlexibleFerret等后门。然后，恶意软件会窃取API令牌、云凭据、哭泣……</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Wed, 11 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.microsoft.com/en-us/security/blog/2026/03/11/contagious-interview-malware-delivered-through-fake-developer-job-interviews/" target="_blank">https://www.microsoft.com/en-us/security/blog/2026/03/11/contagious-interview-malware-delivered-through-fake-developer-job-interviews/</a></span></p></div><div style="background: rgba(52, 152, 219, 0.06);border: 1px solid rgba(52, 152, 219, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">2.</span></span><span leaf=""> 2026年3月补丁周二：在82个已修补的CVE中，有8个关键漏洞和2个已公开披露</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：March 2026 Patch Tuesday: Eight Critical Vulnerabilities and Two Publicly Disclo...</span></span><span style="background: rgb(52, 152, 219);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">RECOMMEND</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">🔗 [阅读原文] (<a href="https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-march-2026/)" target="_blank">https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-march-2026/)</a> --- # # # 3.伊朗相关网络活动的Rapid7检测覆盖率 * *来源 * *: 技术研究 * * *时间 *:周三， 11 Ma 伊朗冲突引发的紧张局势开始显示出超越严格的区域危机的迹象。 根据我们最近发布的建议，本通讯旨在概述和总结Rapid7客户可获得的检测和浓缩覆盖范围，广泛...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Mar 10, 20</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.rapid7.com/blog/post/tr-detection-coverage-iran-linked-cyber-activity" target="_blank">https://www.rapid7.com/blog/post/tr-detection-coverage-iran-linked-cyber-activity</a></span></p></div><div style="background: rgba(52, 152, 219, 0.06);border: 1px solid rgba(52, 152, 219, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">3.</span></span><span leaf=""> 不断升级的地区冲突中的伊朗网络战术手册</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Iran’s Cyber Playbook in the Escalating Regional Conflict</span></span><span style="background: rgb(52, 152, 219);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">RECOMMEND</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">根据我们最近发布的建议，本出版物旨在概述与紧张局势相关的网络活动。根据现有信息，我们认为冲突开始显示出超越严格的区域危机的迹象。初始威胁r...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Wed, 11 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.rapid7.com/blog/post/tr-iran-cyber-playbook-escalating-regional-conflict" target="_blank">https://www.rapid7.com/blog/post/tr-iran-cyber-playbook-escalating-regional-conflict</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">4.</span></span><span leaf=""> 保护最重要的事情：将敏感数据与曝光风险保持一致</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Protect What Matters Most: Aligning Sensitive Data with Exposure Risk</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">本博客是与Symmetry Systems的Claude Mandy合作撰写的。Rapid7和Symmetry Systems正在合作，通过将敏感数据智能与真实世界的人类和机器身份曝光路径相结合，帮助组织减少违规影响。违规行为是根据...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Wed, 11 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.rapid7.com/blog/post/em-protect-breaches-align-sensitive-data-with-exposure-risk" target="_blank">https://www.rapid7.com/blog/post/em-protect-breaches-align-sensitive-data-with-exposure-risk</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">5.</span></span><span leaf=""> Microsoft和Adobe补丁2026年3月星期二安全更新审查</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Microsoft and Adobe Patch Tuesday, March 2026 Security Update Review</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">微软推出了2026年3月补丁周二更新，提供了一批新的安全修复程序，旨在保护Windows环境免受新出现的威胁。该版本解决了跨越Windows组件和其他Microsoft产品的多个漏洞。这里&amp; # 8217...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Tue, 10 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://blog.qualys.com/category/vulnerabilities-threat-research" target="_blank">https://blog.qualys.com/category/vulnerabilities-threat-research</a></span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(192, 57, 43);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(192, 57, 43);padding-left: 15px;background: linear-gradient(90deg, rgba(192, 57, 43, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">🇨🇳</span></span><span leaf="">中国安全媒体</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(1 条)</span></span></h2><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(192, 57, 43);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> 蠕虫式XMRig挖矿攻击借BYOVD漏洞规避检测</span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">一场具备蠕虫传播能力的加密货币劫持攻击，正通过盗版软件进行传播，利用BYOVD漏洞部署定制版XMRig挖矿程序。研究人员发现，该攻击通过捆绑盗版软件传播，投放定制化XMRig挖矿木马。攻击借助BYOVD漏洞利用时间触发逻辑炸弹实现规避检测、最大化挖矿收益。其多阶段感染链以提升加密货币算力为核心，过程中常导致受感染系统运行不稳定。该攻击通过盗版“付费”软件安装程序传播，释放基于XMRig的复杂挖矿木马。其核心是名为Explorer.exe的控制程序，该程序以持久化状态机形式运行，可通过命令行参数切...</span></p><p style="margin: 0px 0px 8px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 中国安全媒体 · ⏰ Wed, 11 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.4hou.com/posts/kgyK" target="_blank">https://www.4hou.com/posts/kgyK</a></span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background: linear-gradient(135deg, rgb(248, 249, 250) 0%, rgb(255, 255, 255) 100%);padding: 35px 25px;margin: 30px 15px;border-radius: 12px;text-align: center;border: 1px solid rgba(0, 0, 0, 0.05);"><h2 style="font-size: 17px;color: rgb(44, 62, 80);margin: 0px 0px 20px;font-weight: bold;letter-spacing: 1px;"><span leaf="">📝 关于本报</span></h2><p style="color: rgb(127, 140, 141);margin: 12px 0px;font-size: 14px;line-height: 1.8;"><span leaf="">🤖 本日报由 AI 自动抓取整理，每日上午 9:00 更新</span></p><p style="color: rgb(127, 140, 141);margin: 12px 0px;font-size: 14px;line-height: 1.8;"><span leaf="">🌐 内容来源：50+ 个全球网络安全 RSS 源 + API 接口</span></p><p style="color: rgb(127, 140, 141);margin: 12px 0px;font-size: 14px;line-height: 1.8;"><span leaf="">📬 涵盖：漏洞预警、技术研究、威胁情报、云安全、AI 安全等</span></p><p style="color: rgb(149, 165, 166);margin: 20px 0px 10px;font-size: 13px;"><span leaf="">━━━━━━━━━━━━━━━━━━━</span></p><p style="color: rgb(127, 140, 141);margin: 10px 0px;font-size: 13px;line-height: 1.6;"><span leaf="">如需订阅更多源、调整推送频率或合作，请联系管理员</span></p></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;padding: 35px 15px;margin-top: 10px;background: linear-gradient(rgb(255, 255, 255) 0%, rgb(248, 249, 250) 100%);"><p style="color: rgb(189, 195, 199);font-size: 13px;margin: 5px 0px;"><span leaf="">━━━━━━━━━━━━━━━━━━━</span></p><p style="color: rgb(102, 126, 234);font-size: 16px;margin: 15px 0px;font-weight: bold;letter-spacing: 2px;"><span leaf="">🍐 枇杷熟了</span></p><p style="color: rgb(149, 165, 166);font-size: 13px;margin: 8px 0px;"><span leaf="">专注网络安全技术分享</span></p><p style="color: rgb(189, 195, 199);font-size: 12px;margin: 15px 0px;"><span leaf="">生成时间：2026-03-12 09:38:22</span></p><p style="color: rgb(189, 195, 199);font-size: 13px;margin: 5px 0px;"><span leaf="">━━━━━━━━━━━━━━━━━━━</span></p><p style="color: rgb(149, 165, 166);font-size: 12px;margin: 15px 0px 5px;"><span leaf="">感谢阅读 · 欢迎分享</span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=abad0eb0&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MzkzOTYzOQ%3D%3D%26mid%3D2247489962%26idx%3D2%26sn%3Df34ec620e4eaf05b83bca7a555a36327">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 12 Mar 2026 11:59:00 +0800</pubDate>
    </item>
    <item>
      <title>枇杷熟了-全球网络安全日报2026-03-11</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MzkzOTYzOQ==&amp;mid=2247489950&amp;idx=1&amp;sn=baa21390ac889cabacbca8e3f648e036</link>
      <description></description>
      <content:encoded><![CDATA[<p><span>枇杷哥</span> <span>2026-03-11 12:22</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=65195f6d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FeZOA7OiaVuZibiaRy5tweazbFfTZnUKJszcKicia0U7ZEv1oLQrTc3HEQWEZibaQ0fQpG4Sib7blaxEgHGy32NQSrWxRv8yeQIKpI558icVuepfRApY%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background: linear-gradient(135deg, rgb(102, 126, 234) 0%, rgb(118, 75, 162) 100%);padding: 45px 25px;text-align: center;box-shadow: rgba(0, 0, 0, 0.15) 0px 4px 20px;" data-pm-slice="0 0 []"><p style="color: rgba(255, 255, 255, 0.85);font-size: 13px;margin: 0px 0px 10px;letter-spacing: 3px;text-transform: uppercase;"><span leaf="">Daily Security Newsletter</span></p><h1 style="color: rgb(255, 255, 255);font-size: 26px;margin: 15px 0px;font-weight: bold;text-shadow: rgba(0, 0, 0, 0.25) 2px 2px 8px;letter-spacing: 2px;line-height: 1.4;"><span leaf="">🔐 全球网络安全日报</span></h1><p style="color: rgba(255, 255, 255, 0.95);margin: 20px 0px 10px;font-size: 16px;font-weight: 500;"><span leaf="">📅 2026年03月11日 Wednesday</span></p><p style="color: rgba(255, 255, 255, 0.8);margin: 10px 0px 0px;font-size: 13px;line-height: 1.6;"><span leaf="">每日精选全球网络安全最新研究、漏洞预警、技术动态、威胁情报</span></p></div><p style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background: linear-gradient(135deg, rgb(248, 249, 250) 0%, rgb(255, 255, 255) 100%);padding: 30px 20px;margin: 25px 15px;border-radius: 12px;border-left: 6px solid rgb(102, 126, 234);box-shadow: rgba(0, 0, 0, 0.06) 0px 2px 12px;"><h2 style="font-size: 18px;color: rgb(44, 62, 80);margin: 0px 0px 20px;font-weight: bold;display: flex;align-items: center;justify-content: center;"><span style="font-size: 24px;margin-right: 10px;"><span leaf="">📊</span></span><span leaf="">今日概览 · 共 25 条</span></h2><table style="width: 1693px;border-collapse: separate;border-spacing: 8px;"><tbody><tr><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(231, 76, 60, 0.12) 0%, rgba(231, 76, 60, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(231, 76, 60, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🚨</span></span><span style="color: rgb(231, 76, 60);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">漏洞与威胁</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">8</span></span></td><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(52, 152, 219, 0.12) 0%, rgba(52, 152, 219, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(52, 152, 219, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">📚</span></span><span style="color: rgb(52, 152, 219);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">技术研究</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">6</span></span></td></tr><tr><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(155, 89, 182, 0.12) 0%, rgba(155, 89, 182, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(155, 89, 182, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🔍</span></span><span style="color: rgb(142, 68, 173);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">威胁情报</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">1</span></span></td><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(46, 204, 113, 0.12) 0%, rgba(46, 204, 113, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(46, 204, 113, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🤖</span></span><span style="color: rgb(39, 174, 96);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">AI 安全</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">0</span></span></td></tr><tr><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(230, 126, 34, 0.12) 0%, rgba(230, 126, 34, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(230, 126, 34, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">☁️</span></span><span style="color: rgb(211, 84, 0);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">云安全</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">6</span></span></td><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(52, 73, 94, 0.12) 0%, rgba(52, 73, 94, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(52, 73, 94, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🇨🇳</span></span><span style="color: rgb(192, 57, 43);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">中国媒体</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">4</span></span></td></tr></tbody></table></p><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(231, 76, 60);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(231, 76, 60);padding-left: 15px;background: linear-gradient(90deg, rgba(231, 76, 60, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">🚨</span></span><span leaf="">漏洞与威胁</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(8 条)</span></span></h2><div style="background: rgba(231, 76, 60, 0.06);border: 1px solid rgba(231, 76, 60, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> How to Stop AI Data Leaks: A Webinar Guide to Auditing Modern Agentic Workflows </span><span style="background: rgb(231, 76, 60);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">HOT</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">人工智能（ AI ）不再只是我们交谈的工具，而是为我们做事的工具。这些被称为人工智能代理。他们可以发送电子邮件、移动数据，甚至可以自行管理软件。但有一个问题。这些客服代表在加快工作速度的同时，也打开了一扇新的“后门” ……</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Tue, 10 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/how-to-stop-ai-data-leaks-webinar-guide.html" target="_blank">https://thehackernews.com/2026/03/how-to-stop-ai-data-leaks-webinar-guide.html</a></span></p></div><div style="background: rgba(231, 76, 60, 0.06);border: 1px solid rgba(231, 76, 60, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">2.</span></span><span leaf=""> FortiGate设备被利用来破坏网络并窃取服务帐户凭据</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：FortiGate Devices Exploited to Breach Networks and Steal Service Account Credent...</span></span><span style="background: rgb(231, 76, 60);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">HOT</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">网络安全研究人员正在呼吁关注一项新的活动，其中威胁行为者滥用FortiGate下一代防火墙（ NGFW ）设备作为入侵受害者网络的切入点。该活动涉及利用最近披露的安全漏洞或弱点...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Tue, 10 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/fortigate-devices-exploited-to-breach.html" target="_blank">https://thehackernews.com/2026/03/fortigate-devices-exploited-to-breach.html</a></span></p></div><div style="background: rgba(231, 76, 60, 0.06);border: 1px solid rgba(231, 76, 60, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">3.</span></span><span leaf=""> KadNap恶意软件感染14,000多台边缘设备，为隐形代理僵尸网络提供强大动力</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：KadNap Malware Infects 14,000+ Edge Devices to Power Stealth Proxy Botnet</span></span><span style="background: rgb(231, 76, 60);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">HOT</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">网络安全研究人员发现了一种名为KadNap的新恶意软件，主要针对华硕路由器，将其纳入僵尸网络，以代理恶意流量。该恶意软件于2025年8月首次在野外检测到，已扩展到超过14,000台受感染的设备，其中超过60 ％的vi...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Tue, 10 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/kadnap-malware-infects-14000-edge.html" target="_blank">https://thehackernews.com/2026/03/kadnap-malware-infects-14000-edge.html</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">4.</span></span><span leaf=""> Google Looker Studio中的新“LeakyLooker”漏洞可能会启用跨租户SQL查询</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：New &#34;LeakyLooker&#34; Flaws in Google Looker Studio Could Enable Cross-Tenant SQL Qu...</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">网络安全研究人员披露了Google Looker Studio中的九个跨租户漏洞，这些漏洞可能允许攻击者对受害者的数据库运行任意SQL查询，并在组织的Google Cloud环境中泄露敏感数据。缺点是同事……</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Tue, 10 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/new-leakylooker-flaws-in-google-looker.html" target="_blank">https://thehackernews.com/2026/03/new-leakylooker-flaws-in-google-looker.html</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">5.</span></span><span leaf=""> 零日争夺战是可以避免的：攻击面缩减指南</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：The Zero-Day Scramble is Avoidable: A Guide to Attack Surface Reduction</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">您无法控制下一个关键漏洞何时掉落。当环境暴露时，您可以控制它的暴露程度。问题是，大多数团队面对互联网的曝光率比他们意识到的要高。Intruder的安全主管深入研究了发生这种情况的原因以及团队如何管理...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Tue, 10 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/the-zero-day-scramble-is-avoidable.html" target="_blank">https://thehackernews.com/2026/03/the-zero-day-scramble-is-avoidable.html</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">6.</span></span><span leaf=""> 发现针对人力资源部门的新“BlackSanta” EDR杀手</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：New ‘BlackSanta’ EDR killer spotted targeting HR departments</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">一年多来，一名讲俄语的威胁行为者通过提供名为BlackSanta的新EDR杀手的恶意软件瞄准人力资源（ HR ）部门。[...]</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Tue, 10 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.bleepingcomputer.com/news/security/new-blacksanta-edr-killer-spotted-targeting-hr-departments/" target="_blank">https://www.bleepingcomputer.com/news/security/new-blacksanta-edr-killer-spotted-targeting-hr-departments/</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">7.</span></span><span leaf=""> 新的BeatBanker Android恶意软件冒充Starlink应用程序劫持设备</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：New BeatBanker Android malware poses as Starlink app to hijack devices</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">一个名为BeatBanker的新Android恶意软件可以通过在伪装成官方Google Play商店的网站上冒充Starlink应用程序来劫持设备并诱骗用户安装它。[...]</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Tue, 10 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.bleepingcomputer.com/news/security/new-beatbanker-android-malware-poses-as-starlink-app-to-hijack-devices/" target="_blank">https://www.bleepingcomputer.com/news/security/new-beatbanker-android-malware-poses-as-starlink-app-to-hijack-devices/</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">8.</span></span><span leaf=""> 新的“Zombie Zip”技术可以让恶意软件从安全工具中溜走</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：New &#39;Zombie ZIP&#39; technique lets malware slip past security tools</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">一种名为“Zombie ZIP”的新技术有助于将有效负载隐藏在专门创建的压缩文件中，以避免防病毒和端点检测与响应(EDR)产品等安全解决方案的检测。[...]</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Tue, 10 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.bleepingcomputer.com/news/security/new-zombie-zip-technique-lets-malware-slip-past-security-tools/" target="_blank">https://www.bleepingcomputer.com/news/security/new-zombie-zip-technique-lets-malware-slip-past-security-tools/</a></span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(52, 152, 219);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(52, 152, 219);padding-left: 15px;background: linear-gradient(90deg, rgba(52, 152, 219, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">📚</span></span><span leaf="">技术研究</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(6 条)</span></span></h2><div style="background: rgba(52, 152, 219, 0.06);border: 1px solid rgba(52, 152, 219, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> 补丁星期二- 2026年3月</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Patch Tuesday - March 2026</span></span><span style="background: rgb(52, 152, 219);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">RECOMMEND</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">微软将在2026年3月的补丁周二发布77个漏洞。Microsoft知道公开披露了今天的两个漏洞，但没有任何（尚未）在野外利用的证据，因此今天没有Microsoft添加到CISA KEV。本月早些时候， Microso...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Tue, 10 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.rapid7.com/blog/post/em-patch-tuesday-march-2026" target="_blank">https://www.rapid7.com/blog/post/em-patch-tuesday-march-2026</a></span></p></div><div style="background: rgba(52, 152, 219, 0.06);border: 1px solid rgba(52, 152, 219, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">2.</span></span><span leaf=""> 2026年的紫色团队：从假设的保护到可衡量的恢复力</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Purple Teaming in 2026: From Assumed Protection to Measurable Resilience</span></span><span style="background: rgb(52, 152, 219);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">RECOMMEND</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">什么是紫色团队？紫色团队通常被描述为红色团队和蓝色团队之间的协作。这个定义是准确的，但不完整。紫色团队的核心是曝光验证：故意测试您认为是否可以检测和遏制威胁……</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Tue, 10 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.rapid7.com/blog/post/so-purple-teaming-assumed-protection-to-measurable-resilience" target="_blank">https://www.rapid7.com/blog/post/so-purple-teaming-assumed-protection-to-measurable-resilience</a></span></p></div><div style="background: rgba(52, 152, 219, 0.06);border: 1px solid rgba(52, 152, 219, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">3.</span></span><span leaf=""> 当受信任的网站变成恶意网站时： WordPress妥协了先进的全球窃取程序操作</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：When Trusted Websites Turn Malicious: WordPress Compromises Advance Global Steal...</span></span><span style="background: rgb(52, 152, 219);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">RECOMMEND</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">OverviewRapid7 Labs已经确定并分析了合法、潜在高度信任的WordPress网站正在进行的广泛入侵，这些网站被身份不明的威胁行为者滥用，以注入模拟Cloudflare人类验证挑战（ CAPTCHA ）的ClickFix植入物。诱饵是设计的……</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Tue, 10 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.rapid7.com/blog/post/tr-malicious-websites-wordpress-compromise-advances-global-stealer-operation" target="_blank">https://www.rapid7.com/blog/post/tr-malicious-websites-wordpress-compromise-advances-global-stealer-operation</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">4.</span></span><span leaf=""> Microsoft补丁2026年3月星期二安全更新审核</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Microsoft Patch Tuesday, March 2026 Security Update Review</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">微软推出了2026年3月补丁周二更新，提供了一批新的安全修复程序，旨在保护Windows环境免受新出现的威胁。该版本解决了跨越Windows组件和其他Microsoft产品的多个漏洞。这里&amp; # 8217...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Tue, 10 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://blog.qualys.com/category/vulnerabilities-threat-research" target="_blank">https://blog.qualys.com/category/vulnerabilities-threat-research</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">5.</span></span><span leaf=""> 从影子模型到审计就绪的人工智能安全： Qualys TotalAI的实用路径</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：From Shadow Models to Audit-Ready AI Security: A Practical Path with Qualys Tota...</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">管理人工智能采用的关键要点，因为它超越了安全框架企业内部的人工智能采用比治理更快。模型嵌入到应用、副驾驶和内部工作流程中。端点在云控制台中启动。MCP服务器连接“只是为了测试一些东西” ，</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Tue, 10 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://blog.qualys.com/category/product-tech" target="_blank">https://blog.qualys.com/category/product-tech</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">6.</span></span><span leaf=""> FortiGate边缘入侵|被盗服务帐户导致流氓工作站和深度广告泄露</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：FortiGate Edge Intrusions | Stolen Service Accounts Lead to Rogue Workstations a...</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">FortiGate SSO漏洞允许攻击者窃取配置、滥用AD凭证、部署RMM工具和泄露NTDS文件。</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Tue, 10 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.sentinelone.com/blog/fortigate-edge-intrusions/" target="_blank">https://www.sentinelone.com/blog/fortigate-edge-intrusions/</a></span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(142, 68, 173);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(142, 68, 173);padding-left: 15px;background: linear-gradient(90deg, rgba(142, 68, 173, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">🔍</span></span><span leaf="">威胁情报</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(1 条)</span></span></h2><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> 审核守门人：模糊“AI法官”以绕过安全控制</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Auditing the Gatekeepers: Fuzzing &#34;AI Judges&#34; to Bypass Secu...</span></span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">Unit 42的研究表明，人工智能评委容易受到隐形提示注入的影响。良性格式化符号可以绕过安全控制。审计守门人：模糊“AI法官”以绕过安全控制的帖子首先出现在第42单元上。</span></p><p style="margin: 0px 0px 8px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 威胁情报 · ⏰ Tue, 10 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://unit42.paloaltonetworks.com/fuzzing-ai-judges-security-bypass/" target="_blank">https://unit42.paloaltonetworks.com/fuzzing-ai-judges-security-bypass/</a></span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(192, 57, 43);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(192, 57, 43);padding-left: 15px;background: linear-gradient(90deg, rgba(192, 57, 43, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">🇨🇳</span></span><span leaf="">中国安全媒体</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(4 条)</span></span></h2><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(192, 57, 43);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> 从技术创新到实战防护：SKD AWARDS 2025年度榜单发布</span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">2026年3月10日，被誉为“网络安全产品奥斯卡”的SKD AWARDS 2025年度获奖榜单重磅发布。本届颁奖共揭晓三大类奖项，其中18家中外单位的24款产品荣获&#34;赛可达优秀产品奖&#34;，13家单位的15款产品摘得&#34;技术创新奖&#34;，12家单位的15款产品获得&#34;ATT&amp;CK安全能力奖&#34;，三大奖项共同构成了一个从“综合实力”到“创新潜力”再到“实战能力”的立体化评价体系，旨在全方位衡量网络安全产品的价值，展现网络安全领域的技术突破与实战...</span></p><p style="margin: 0px 0px 8px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 中国安全媒体 · ⏰ Tue, 10 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.4hou.com/posts/8gmr" target="_blank">https://www.4hou.com/posts/8gmr</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(192, 57, 43);font-weight: bold;margin-right: 8px;"><span leaf="">2.</span></span><span leaf=""> AI算法在审判战争，而法律还在沉睡——老哈的故事</span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">从2026年美伊“算法之夜”的空袭战场，我们看到的不仅是AI武器化的致命威胁，更暴露了数字时代网络安全的核心困局。当网络攻击与物理打击深度绑定，当AI成为网络情报战的核心引擎，现有网络安全体系、防护逻辑乃至法律规制，都已难以应对这场全域混合战的冲击。这场战争，给全球网络安全行业敲响了警钟，网络安全早已不是单纯的技术防御，而是关乎国家主权、民生安全、战争伦理的核心议题。一、那个被算法标记的清晨2026年2月28日，德黑兰时间凌晨4点17分。哈桑·阿米里，我们姑且叫他老哈，他是伊朗伊斯兰革命卫队某雷...</span></p><p style="margin: 0px 0px 8px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 中国安全媒体 · ⏰ Tue, 10 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.4hou.com/posts/42gJ" target="_blank">https://www.4hou.com/posts/42gJ</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(192, 57, 43);font-weight: bold;margin-right: 8px;"><span leaf="">3.</span></span><span leaf=""> 焕新出发｜快快云安全邀您开启云安全的AI时代</span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">今天，我们正式宣布一项重要战略决策：快快网络旗下安全品牌正式升级为“快快云安全”。这不仅是一次名称的变更，更是我们在云安全深水区砥砺前行多年后，面向未来的战略性聚焦，也是我们深耕云安全赛道、赋能企业安全增长的坚定决心。全新slogan：定义云安全的AI时代当AI开始重构一切，安全确实该被重新定义了。过去，安全是业务的“护栏”；今天，在AI的驱动下，安全应成为业务的“引擎”。面对日益复杂的云上攻击和AI带来的新型威胁，传统防护思路已不足以应对未来挑战，因此，我们带着“定义云安全的AI时代”的使命，...</span></p><p style="margin: 0px 0px 8px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 中国安全媒体 · ⏰ Tue, 10 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.4hou.com/posts/337p" target="_blank">https://www.4hou.com/posts/337p</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(192, 57, 43);font-weight: bold;margin-right: 8px;"><span leaf="">4.</span></span><span leaf=""> 嘶吼快讯|网安厂商动态汇（第15期）</span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">聚焦网安厂商最新动作，整合新品发布、战略合作、技术升级等核心动态，省去碎片化信息筛选时间，1篇GET网安厂商近期关键动作！网安厂商最新动态新华三出席杭州市争创全国人工智能创新发展第一城暨建设一流创新生态推进大会近日，杭州市争创全国人工智能创新发展第一城暨建设一流创新生态推进大会召开，紫光股份旗下新华三集团“灵犀第二大脑”正式入选杭州市2025年“人工智能+”场景创新联合体重点培育项目。国家网信办完成首批政务APP备案，爱加密护航合规前行近日，国家网信办正式完成第一批政务移动互联网应用程序备案工作...</span></p><p style="margin: 0px 0px 8px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 中国安全媒体 · ⏰ Tue, 10 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.4hou.com/posts/5MjX" target="_blank">https://www.4hou.com/posts/5MjX</a></span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background: linear-gradient(135deg, rgb(248, 249, 250) 0%, rgb(255, 255, 255) 100%);padding: 35px 25px;margin: 30px 15px;border-radius: 12px;text-align: center;border: 1px solid rgba(0, 0, 0, 0.05);"><h2 style="font-size: 17px;color: rgb(44, 62, 80);margin: 0px 0px 20px;font-weight: bold;letter-spacing: 1px;"><span leaf="">📝 关于本报</span></h2><p style="color: rgb(127, 140, 141);margin: 12px 0px;font-size: 14px;line-height: 1.8;"><span leaf="">🤖 本日报由 AI 自动抓取整理，每日上午 9:00 更新</span></p><p style="color: rgb(127, 140, 141);margin: 12px 0px;font-size: 14px;line-height: 1.8;"><span leaf="">🌐 内容来源：50+ 个全球网络安全 RSS 源 + API 接口</span></p><p style="color: rgb(127, 140, 141);margin: 12px 0px;font-size: 14px;line-height: 1.8;"><span leaf="">📬 涵盖：漏洞预警、技术研究、威胁情报、云安全、AI 安全等</span></p><p style="color: rgb(149, 165, 166);margin: 20px 0px 10px;font-size: 13px;"><span leaf="">━━━━━━━━━━━━━━━━━━━</span></p><p style="color: rgb(127, 140, 141);margin: 10px 0px;font-size: 13px;line-height: 1.6;"><span leaf="">如需订阅更多源、调整推送频率或合作，请联系管理员</span></p></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;padding: 35px 15px;margin-top: 10px;background: linear-gradient(rgb(255, 255, 255) 0%, rgb(248, 249, 250) 100%);"><p style="color: rgb(189, 195, 199);font-size: 13px;margin: 5px 0px;"><span leaf="">━━━━━━━━━━━━━━━━━━━</span></p><p style="color: rgb(102, 126, 234);font-size: 16px;margin: 15px 0px;font-weight: bold;letter-spacing: 2px;"><span leaf="">🍐 枇杷熟了</span></p><p style="color: rgb(149, 165, 166);font-size: 13px;margin: 8px 0px;"><span leaf="">专注网络安全技术分享</span></p><p style="color: rgb(189, 195, 199);font-size: 12px;margin: 15px 0px;"><span leaf="">生成时间：2026-03-11 12:17:41</span></p><p style="color: rgb(189, 195, 199);font-size: 13px;margin: 5px 0px;"><span leaf="">━━━━━━━━━━━━━━━━━━━</span></p><p style="color: rgb(149, 165, 166);font-size: 12px;margin: 15px 0px 5px;"><span leaf="">感谢阅读 · 欢迎分享</span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=91da6ee3&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MzkzOTYzOQ%3D%3D%26mid%3D2247489950%26idx%3D1%26sn%3Dbaa21390ac889cabacbca8e3f648e036">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 11 Mar 2026 12:22:00 +0800</pubDate>
    </item>
    <item>
      <title>枇杷熟了-全球网络安全日报2026-03-10</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MzkzOTYzOQ==&amp;mid=2247489945&amp;idx=1&amp;sn=b662f172e5374a9e5e4224e5e5ad029f</link>
      <description></description>
      <content:encoded><![CDATA[<p><span>枇杷哥</span> <span>2026-03-10 12:08</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=159a14e6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FeZOA7OiaVuZ8o9SOv1XrQOqD1YJo56EHO4tUKTV9mXt9GZsgf5EZ4ppzAbLyY2jFTeNxQjLMqy3Kh7VT0oWy5epFZicozXGvXs4KMDuJIDyTo%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background: linear-gradient(135deg, rgb(102, 126, 234) 0%, rgb(118, 75, 162) 100%);padding: 45px 25px;text-align: center;box-shadow: rgba(0, 0, 0, 0.15) 0px 4px 20px;" data-pm-slice="0 0 []"><p style="color: rgba(255, 255, 255, 0.85);font-size: 13px;margin: 0px 0px 10px;letter-spacing: 3px;text-transform: uppercase;"><span leaf="">Daily Security Newsletter</span></p><h1 style="color: rgb(255, 255, 255);font-size: 26px;margin: 15px 0px;font-weight: bold;text-shadow: rgba(0, 0, 0, 0.25) 2px 2px 8px;letter-spacing: 2px;line-height: 1.4;"><span leaf="">🔐 全球网络安全日报</span></h1><p style="color: rgba(255, 255, 255, 0.95);margin: 20px 0px 10px;font-size: 16px;font-weight: 500;"><span leaf="">📅 2026年03月10日 Tuesday</span></p><p style="color: rgba(255, 255, 255, 0.8);margin: 10px 0px 0px;font-size: 13px;line-height: 1.6;"><span leaf="">每日精选全球网络安全最新研究、漏洞预警、技术动态、威胁情报</span></p></div><p style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background: linear-gradient(135deg, rgb(248, 249, 250) 0%, rgb(255, 255, 255) 100%);padding: 30px 20px;margin: 25px 15px;border-radius: 12px;border-left: 6px solid rgb(102, 126, 234);box-shadow: rgba(0, 0, 0, 0.06) 0px 2px 12px;"><h2 style="font-size: 18px;color: rgb(44, 62, 80);margin: 0px 0px 20px;font-weight: bold;display: flex;align-items: center;justify-content: center;"><span style="font-size: 24px;margin-right: 10px;"><span leaf="">📊</span></span><span leaf="">今日概览 · 共 23 条</span></h2><table style="width: 1693px;border-collapse: separate;border-spacing: 8px;"><tbody><tr><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(231, 76, 60, 0.12) 0%, rgba(231, 76, 60, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(231, 76, 60, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🚨</span></span><span style="color: rgb(231, 76, 60);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">漏洞与威胁</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">8</span></span></td><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(52, 152, 219, 0.12) 0%, rgba(52, 152, 219, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(52, 152, 219, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">📚</span></span><span style="color: rgb(52, 152, 219);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">技术研究</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">3</span></span></td></tr><tr><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(155, 89, 182, 0.12) 0%, rgba(155, 89, 182, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(155, 89, 182, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🔍</span></span><span style="color: rgb(142, 68, 173);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">威胁情报</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">0</span></span></td><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(46, 204, 113, 0.12) 0%, rgba(46, 204, 113, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(46, 204, 113, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🤖</span></span><span style="color: rgb(39, 174, 96);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">AI 安全</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">0</span></span></td></tr><tr><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(230, 126, 34, 0.12) 0%, rgba(230, 126, 34, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(230, 126, 34, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">☁️</span></span><span style="color: rgb(211, 84, 0);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">云安全</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">3</span></span></td><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(52, 73, 94, 0.12) 0%, rgba(52, 73, 94, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(52, 73, 94, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🇨🇳</span></span><span style="color: rgb(192, 57, 43);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">中国媒体</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">2</span></span></td></tr></tbody></table></p><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(231, 76, 60);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(231, 76, 60);padding-left: 15px;background: linear-gradient(90deg, rgba(231, 76, 60, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">🚨</span></span><span leaf="">漏洞与威胁</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(8 条)</span></span></h2><div style="background: rgba(231, 76, 60, 0.06);border: 1px solid rgba(231, 76, 60, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> 冒充OpenClaw安装程序部署RAT、窃取macOS凭据的恶意npm包</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Malicious npm Package Posing as OpenClaw Installer Deploys RAT, Steals macOS Cre...</span></span><span style="background: rgb(231, 76, 60);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">HOT</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">网络安全研究人员发现了一个恶意npm软件包，该软件包伪装成OpenClaw安装程序，部署远程访问特洛伊木马(RAT)并从受损主机窃取敏感数据。名为“@ openclaw-ai/openclawai”的包已由名为“openclaw-...”的用户上传到注册表</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Tue, 10 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/malicious-npm-package-posing-as.html" target="_blank">https://thehackernews.com/2026/03/malicious-npm-package-posing-as.html</a></span></p></div><div style="background: rgba(231, 76, 60, 0.06);border: 1px solid rgba(231, 76, 60, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">2.</span></span><span leaf=""> 开发人员AirDropped特洛伊木马文件到工作设备后， UNC4899违反了加密公司</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：UNC4899 Breached Crypto Firm After Developer AirDropped Trojanized File to Work ...</span></span><span style="background: rgb(231, 76, 60);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">HOT</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">被称为UNC4899的朝鲜威胁演员被怀疑是2025年针对加密货币组织的复杂云妥协运动的幕后黑手，目的是窃取数百万美元的加密货币。这项活动被中等程度地归功于国家赞助的广告...</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Mon, 09 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/unc4899-used-airdrop-file-transfer-and.html" target="_blank">https://thehackernews.com/2026/03/unc4899-used-airdrop-file-transfer-and.html</a></span></p></div><div style="background: rgba(231, 76, 60, 0.06);border: 1px solid rgba(231, 76, 60, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">3.</span></span><span leaf=""> ⚡ 每周回顾：高通0天、iOS漏洞链、AirSnitch攻击和Vibe编码恶意软件</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：⚡ Weekly Recap: Qualcomm 0-Day, iOS Exploit Chains, AirSnitch Attack &amp; Vibe-Code...</span></span><span style="background: rgb(231, 76, 60);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">HOT</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">网络安全的另一周。又是一个星期的“你一定是在开玩笑。“攻击者很忙，防守者很忙。在中间的某个地方，很多人都有一个非常糟糕的周一早上。这就是现在的情况。好消息？本周有一些实际的胜利，真的……</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Mon, 09 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/weekly-recap-qualcomm-0-day-ios-exploit.html" target="_blank">https://thehackernews.com/2026/03/weekly-recap-qualcomm-0-day-ios-exploit.html</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">4.</span></span><span leaf=""> 安全平台最终能否为中端市场提供服务？</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Can the Security Platform Finally Deliver for the Mid-Market?</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">中端市场组织一直在努力实现与企业同行同等的安全级别。随着对供应链攻击意识的提高，您的客户和业务合作伙伴正在定义您必须满足的安全级别。如果你能成为你组织的推动者……</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Mon, 09 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/can-security-platform-finally-deliver.html" target="_blank">https://thehackernews.com/2026/03/can-security-platform-finally-deliver.html</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">5.</span></span><span leaf=""> Chrome扩展程序在所有权转让后变为恶意，启用代码注入和数据窃取</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Chrome Extension Turns Malicious After Ownership Transfer, Enabling Code Injecti...</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">在似乎是所有权转移的情况下，两个Google Chrome扩展程序已经变成了恶意软件，为攻击者提供了一种向下游客户推送恶意软件、注入任意代码和收集敏感数据的方法。有问题的扩展，最初都与开发人员na...相关联</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Mon, 09 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://thehackernews.com/2026/03/chrome-extension-turns-malicious-after.html" target="_blank">https://thehackernews.com/2026/03/chrome-extension-turns-malicious-after.html</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">6.</span></span><span leaf=""> Microsoft Teams网络钓鱼针对具有A0Backdoor恶意软件的员工</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Microsoft Teams phishing targets employees with A0Backdoor malware</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">黑客通过Microsoft Teams联系了金融和医疗机构的员工，诱骗他们通过快速协助授予远程访问权限，并部署了一种名为A0Backdoor的新恶意软件。[...]</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Mon, 09 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.bleepingcomputer.com/news/security/microsoft-teams-phishing-targets-employees-with-backdoors/" target="_blank">https://www.bleepingcomputer.com/news/security/microsoft-teams-phishing-targets-employees-with-backdoors/</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">7.</span></span><span leaf=""> 谷歌：云攻击不仅仅是利用弱凭据</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Google: Cloud attacks exploit flaws more than weak credentials</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">黑客越来越多地利用第三方软件中新披露的漏洞来获得对云环境的初始访问权限，攻击窗口从几周缩小到几天。[...]</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Mon, 09 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.bleepingcomputer.com/news/security/google-cloud-attacks-exploit-flaws-more-than-weak-credentials/" target="_blank">https://www.bleepingcomputer.com/news/security/google-cloud-attacks-exploit-flaws-more-than-weak-credentials/</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">8.</span></span><span leaf=""> 荷兰政府警告Signal ， WhatsApp帐户劫持攻击</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Dutch govt warns of Signal, WhatsApp account hijacking attacks</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">俄罗斯国家资助的黑客与正在进行的针对政府官员、军事人员和记者的Signal和WhatsApp网络钓鱼活动有关，以获取敏感信息。[...]</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 漏洞与威胁⏰ Mon, 09 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.bleepingcomputer.com/news/security/dutch-govt-warns-of-signal-whatsapp-account-hijacking-attacks/" target="_blank">https://www.bleepingcomputer.com/news/security/dutch-govt-warns-of-signal-whatsapp-account-hijacking-attacks/</a></span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(52, 152, 219);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(52, 152, 219);padding-left: 15px;background: linear-gradient(90deg, rgba(52, 152, 219, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">📚</span></span><span leaf="">技术研究</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(3 条)</span></span></h2><div style="background: rgba(52, 152, 219, 0.06);border: 1px solid rgba(52, 152, 219, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> 为您的前沿转型提供安全的代理AI</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Secure agentic AI for your Frontier Transformation</span></span><span style="background: rgb(52, 152, 219);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">RECOMMEND</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">了解Microsoft Agent 365和Microsoft 365 E7如何帮助保护您的前沿转型。Secure agentic AI for your Frontier Transformation一文首次出现在Microsoft安全博客上。</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Mon, 09 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.microsoft.com/en-us/security/blog/2026/03/09/secure-agentic-ai-for-your-frontier-transformation/" target="_blank">https://www.microsoft.com/en-us/security/blog/2026/03/09/secure-agentic-ai-for-your-frontier-transformation/</a></span></p></div><div style="background: rgba(52, 152, 219, 0.06);border: 1px solid rgba(52, 152, 219, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">2.</span></span><span leaf=""> Falcon for XIoT将资产保护扩展到医疗保健环境</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Falcon for XIoT Extends Asset Protection to Healthcare Environments</span></span><span style="background: rgb(52, 152, 219);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">RECOMMEND</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">🔗 [阅读原文] (<a href="https://www.crowdstrike.com/en-us/blog/falcon-for-xiot-extends-asset-protection-to-healthcare-environments/)" target="_blank">https://www.crowdstrike.com/en-us/blog/falcon-for-xiot-extends-asset-protection-to-healthcare-environments/)</a> --- # # # 3.使用新的人工智能驱动的连接器加速攻击面发现 * *来源 * *: 技术研究 * * *时间 *:周一， 09 Ma 发现：曝光管理的基础为了了解您的攻击面和所有相关曝光， Rapid7的命令平台提供攻击面管理（包含在Surface Command、Exposure Command和Incident Command中）。 它提供了一个360°的视角，</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Mar 09, 20</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.rapid7.com/blog/post/pt-accelerate-attack-surface-discovery-with-new-ai-powered-connectors" target="_blank">https://www.rapid7.com/blog/post/pt-accelerate-attack-surface-discovery-with-new-ai-powered-connectors</a></span></p></div><div style="background: rgba(52, 152, 219, 0.06);border: 1px solid rgba(52, 152, 219, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">3.</span></span><span leaf=""> ClawSec ：从内到外强化OpenClaw代理</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：ClawSec: Hardening OpenClaw Agents from the Inside Out</span></span><span style="background: rgb(52, 152, 219);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">RECOMMEND</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">了解Prompt Security的ClawSec如何保护OpenClaw代理，通过零信任防御阻止恶意技能。</span></p><p style="margin: 0px 0px 10px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;"><span leaf="">📰 技术研究⏰ Mon, 09 Fe</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.sentinelone.com/blog/clawsec-hardening-openclaw-agents-from-the-inside-out/" target="_blank">https://www.sentinelone.com/blog/clawsec-hardening-openclaw-agents-from-the-inside-out/</a></span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(192, 57, 43);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(192, 57, 43);padding-left: 15px;background: linear-gradient(90deg, rgba(192, 57, 43, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">🇨🇳</span></span><span leaf="">中国安全媒体</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(2 条)</span></span></h2><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(192, 57, 43);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> 国家安全机关紧急警示：“发票”钓鱼邮件来袭，企业如何筑牢数字防线？</span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">近期，国家安全机关与央视新闻频道联合披露：境外黑客组织正利用伪装成“电子发票”的钓鱼邮件，对我国科研、能源、军工等重点领域的企业和个人发起大规模网络攻击。一张看似普通的发票，背后可能隐藏着窃取商业秘密、危害国家安全的重大风险。 （来源：央视新闻）一、陷阱揭秘：一封“发票邮件”为何成为间谍木马？境外黑客事先会通过非法渠道获取企业员工的个人信息，然后伪装成员工日常接触的机构，如运营商、电商平台、差旅公司的客服，并将邮件标题直接标注真实姓名+“电子发票”，让人瞬间放松警惕；同时，正文还会用“...</span></p><p style="margin: 0px 0px 8px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 中国安全媒体 · ⏰ Mon, 09 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.4hou.com/posts/PGR6" target="_blank">https://www.4hou.com/posts/PGR6</a></span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(192, 57, 43);font-weight: bold;margin-right: 8px;"><span leaf="">2.</span></span><span leaf=""> 银狐攻击暴涨 159.5%！3大套路狂卷企业20亿，4招护好企业邮箱</span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">2025年第四季度，银狐黑产诈骗邮件已突破586万封，11月单月环比暴涨159.5%！目前已造成全国超1000家企业累计损失超20亿元。这类攻击早已不是简单群发，而是靠加密附件绕检、盗取企业邮箱内部发信、仿冒政务页面直接盗钱，直接威胁企业资金安全。CACTER小助手今天为你全面拆解银狐攻击套路，从趋势，手法到实战防御，帮大家避开陷阱、守住资金。一、银狐已成企业头号邮件威胁，攻击量呈爆发式增长银狐黑产自2020年出现，早已不是小打小闹的诈骗团伙，如今已形成完整、专业、可复制的黑色产业链。简单说，他...</span></p><p style="margin: 0px 0px 8px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 中国安全媒体 · ⏰ Mon, 09 Ma</span></p><p style="margin: 0px;padding-top: 10px;border-top: 1px dashed rgb(238, 238, 238);font-size: 11px;color: rgb(127, 140, 141);line-height: 1.6;word-break: break-all;"><span leaf="">🔗 原文链接：<a href="https://www.4hou.com/posts/OGQE" target="_blank">https://www.4hou.com/posts/OGQE</a></span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background: linear-gradient(135deg, rgb(248, 249, 250) 0%, rgb(255, 255, 255) 100%);padding: 35px 25px;margin: 30px 15px;border-radius: 12px;text-align: center;border: 1px solid rgba(0, 0, 0, 0.05);"><h2 style="font-size: 17px;color: rgb(44, 62, 80);margin: 0px 0px 20px;font-weight: bold;letter-spacing: 1px;"><span leaf="">📝 关于本报</span></h2><p style="color: rgb(127, 140, 141);margin: 12px 0px;font-size: 14px;line-height: 1.8;"><span leaf="">🤖 本日报由 AI 自动抓取整理，每日上午 9:00 更新</span></p><p style="color: rgb(127, 140, 141);margin: 12px 0px;font-size: 14px;line-height: 1.8;"><span leaf="">🌐 内容来源：50+ 个全球网络安全 RSS 源 + API 接口</span></p><p style="color: rgb(127, 140, 141);margin: 12px 0px;font-size: 14px;line-height: 1.8;"><span leaf="">📬 涵盖：漏洞预警、技术研究、威胁情报、云安全、AI 安全等</span></p><p style="color: rgb(149, 165, 166);margin: 20px 0px 10px;font-size: 13px;"><span leaf="">━━━━━━━━━━━━━━━━━━━</span></p><p style="color: rgb(127, 140, 141);margin: 10px 0px;font-size: 13px;line-height: 1.6;"><span leaf="">如需订阅更多源、调整推送频率或合作，请联系管理员</span></p></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;padding: 35px 15px;margin-top: 10px;background: linear-gradient(rgb(255, 255, 255) 0%, rgb(248, 249, 250) 100%);"><p style="color: rgb(189, 195, 199);font-size: 13px;margin: 5px 0px;"><span leaf="">━━━━━━━━━━━━━━━━━━━</span></p><p style="color: rgb(102, 126, 234);font-size: 16px;margin: 15px 0px;font-weight: bold;letter-spacing: 2px;"><span leaf="">🍐 枇杷熟了</span></p><p style="color: rgb(149, 165, 166);font-size: 13px;margin: 8px 0px;"><span leaf="">专注网络安全技术分享</span></p><p style="color: rgb(189, 195, 199);font-size: 12px;margin: 15px 0px;"><span leaf="">生成时间：2026-03-10 11:22:40</span></p><p style="color: rgb(189, 195, 199);font-size: 13px;margin: 5px 0px;"><span leaf="">━━━━━━━━━━━━━━━━━━━</span></p><p style="color: rgb(149, 165, 166);font-size: 12px;margin: 15px 0px 5px;"><span leaf="">感谢阅读 · 欢迎分享</span></p></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=2dab51ce&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MzkzOTYzOQ%3D%3D%26mid%3D2247489945%26idx%3D1%26sn%3Db662f172e5374a9e5e4224e5e5ad029f">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 10 Mar 2026 12:08:00 +0800</pubDate>
    </item>
    <item>
      <title>枇杷熟了-全球网络安全日报2026-03-09</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MzkzOTYzOQ==&amp;mid=2247489940&amp;idx=1&amp;sn=ada6adc54a818f7e2bb7f41d0d0a0613</link>
      <description></description>
      <content:encoded><![CDATA[<p><span>枇杷哥</span> <span>2026-03-09 14:16</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=8ca24855&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FeZOA7OiaVuZiboV33knLQt41h3TegGu46xTYmUuiczntMr9ARRhHnpGfUTtbicnIJhTL0QnS9xzCiak5hhMADDyZA8CTLUdvYaN5vibJ6IGm7fiaNE%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background: linear-gradient(135deg, rgb(102, 126, 234) 0%, rgb(118, 75, 162) 100%);padding: 45px 25px;text-align: center;box-shadow: rgba(0, 0, 0, 0.15) 0px 4px 20px;" data-pm-slice="0 0 []"><p style="color: rgba(255, 255, 255, 0.85);font-size: 13px;margin: 0px 0px 10px;letter-spacing: 3px;text-transform: uppercase;"><span leaf="">Daily Security Newsletter</span></p><h1 style="color: rgb(255, 255, 255);font-size: 26px;margin: 15px 0px;font-weight: bold;text-shadow: rgba(0, 0, 0, 0.25) 2px 2px 8px;letter-spacing: 2px;line-height: 1.4;"><span leaf="">🔐 全球网络安全日报</span></h1><p style="color: rgba(255, 255, 255, 0.95);margin: 20px 0px 10px;font-size: 16px;font-weight: 500;"><span leaf="">📅 2026年03月08日 Sunday</span></p><p style="color: rgba(255, 255, 255, 0.8);margin: 10px 0px 0px;font-size: 13px;line-height: 1.6;"><span leaf="">每日精选全球网络安全最新研究、漏洞预警、技术动态、威胁情报</span></p></div><p style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background: linear-gradient(135deg, rgb(248, 249, 250) 0%, rgb(255, 255, 255) 100%);padding: 30px 20px;margin: 25px 15px;border-radius: 12px;border-left: 6px solid rgb(102, 126, 234);box-shadow: rgba(0, 0, 0, 0.06) 0px 2px 12px;"><h2 style="font-size: 18px;color: rgb(44, 62, 80);margin: 0px 0px 20px;font-weight: bold;display: flex;align-items: center;justify-content: center;"><span style="font-size: 24px;margin-right: 10px;"><span leaf="">📊</span></span><span leaf="">今日概览 · 共 47 条</span></h2><table style="width: 1693px;border-collapse: separate;border-spacing: 8px;"><tbody><tr><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(231, 76, 60, 0.12) 0%, rgba(231, 76, 60, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(231, 76, 60, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🚨</span></span><span style="color: rgb(231, 76, 60);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">漏洞与威胁</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">8</span></span></td><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(52, 152, 219, 0.12) 0%, rgba(52, 152, 219, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(52, 152, 219, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">📚</span></span><span style="color: rgb(52, 152, 219);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">技术研究</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">6</span></span></td></tr><tr><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(155, 89, 182, 0.12) 0%, rgba(155, 89, 182, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(155, 89, 182, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🔍</span></span><span style="color: rgb(142, 68, 173);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">威胁情报</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">8</span></span></td><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(46, 204, 113, 0.12) 0%, rgba(46, 204, 113, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(46, 204, 113, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🤖</span></span><span style="color: rgb(39, 174, 96);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">AI 安全</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">5</span></span></td></tr><tr><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(230, 126, 34, 0.12) 0%, rgba(230, 126, 34, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(230, 126, 34, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">☁️</span></span><span style="color: rgb(211, 84, 0);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">云安全</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">8</span></span></td><td style="padding: 18px 12px;background: linear-gradient(135deg, rgba(52, 73, 94, 0.12) 0%, rgba(52, 73, 94, 0.05) 100%);border-radius: 12px;text-align: center;border: 1px solid rgba(52, 73, 94, 0.15);"><span style="font-size: 26px;display: block;margin-bottom: 6px;"><span leaf="">🇨🇳</span></span><span style="color: rgb(192, 57, 43);font-weight: bold;font-size: 13px;display: block;margin-bottom: 4px;"><span leaf="">中国媒体</span></span><span style="color: rgb(44, 62, 80);font-size: 22px;font-weight: bold;"><span leaf="">5</span></span></td></tr></tbody></table></p><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(231, 76, 60);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(231, 76, 60);padding-left: 15px;background: linear-gradient(90deg, rgba(231, 76, 60, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">🚨</span></span><span leaf="">漏洞与威胁</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(8 条)</span></span></h2><div style="background: rgba(231, 76, 60, 0.06);border: 1px solid rgba(231, 76, 60, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> OpenAI Codex Security扫描了120万次提交，发现了10,561个高严重性问题</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：OpenAI Codex Security Scanned 1.2 Million Commits and Found 10,561 High-Severity...</span></span><span style="background: rgb(231, 76, 60);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">HOT</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">OpenAI周五开始推出Codex Security ，这是一种人工智能(AI)驱动的安全代理，旨在发现、验证和提出漏洞修复方案。该功能通过Codex在ChatGPT Pro、Enterprise、Business和Edu客户的研究预览中提供...</span></p><p style="margin: 0px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;padding-top: 12px;border-top: 1px dashed rgb(238, 238, 238);"><span leaf="">📰 漏洞与威胁⏰ Sat, 07 Ma</span></p></div><div style="background: rgba(231, 76, 60, 0.06);border: 1px solid rgba(231, 76, 60, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">2.</span></span><span leaf=""> Anthropic使用Claude Opus 4.6 AI模型发现22个Firefox漏洞</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Anthropic Finds 22 Firefox Vulnerabilities Using Claude Opus 4.6 AI Model</span></span><span style="background: rgb(231, 76, 60);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">HOT</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Anthropic周五表示，作为与Mozilla安全合作伙伴关系的一部分，它在Firefox网络浏览器中发现了22个新的安全漏洞。其中， 14例被归类为高危， 7例被归类为中度， 1例被评为低危。这些问题在以下方面得到了解决……</span></p><p style="margin: 0px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;padding-top: 12px;border-top: 1px dashed rgb(238, 238, 238);"><span leaf="">📰 漏洞与威胁⏰ Sat, 07 Ma</span></p></div><div style="background: rgba(231, 76, 60, 0.06);border: 1px solid rgba(231, 76, 60, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">3.</span></span><span leaf=""> Transparent Tribe在针对印度的活动中使用人工智能大规模生产恶意软件植入物</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Transparent Tribe Uses AI to Mass-Produce Malware Implants in Campaign Targeting...</span></span><span style="background: rgb(231, 76, 60);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">HOT</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">被称为透明部落的巴基斯坦联盟威胁演员已成为最新的黑客组织，采用人工智能（ AI ）驱动的编码工具来攻击各种植入物的目标。该活动旨在产生“大量，平庸的种植体” ，这些种植体被开发...</span></p><p style="margin: 0px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;padding-top: 12px;border-top: 1px dashed rgb(238, 238, 238);"><span leaf="">📰 漏洞与威胁⏰ Fri, 06 Ma</span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">4.</span></span><span leaf=""> 多阶段VOID # GEIST恶意软件提供XWorm、AsyncRAT和Xeno RAT</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Multi-Stage VOID<a class="wx_topic_link" topic-id="mmisduqp-lehupw" style="color: #576B95 !important;" data-topic="1">#GEIST</a> Malware Delivering XWorm, AsyncRAT, and Xeno RAT</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">网络安全研究人员披露了一个多阶段恶意软件活动的详细信息，该活动使用批处理脚本作为提供与XWorm、AsyncRAT和Xeno RAT相对应的各种加密远程访问木马(RAT)有效负载的途径。隐形攻击链已被Se代号为VOID # GEIST……</span></p><p style="margin: 0px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;padding-top: 12px;border-top: 1px dashed rgb(238, 238, 238);"><span leaf="">📰 漏洞与威胁⏰ Fri, 06 Ma</span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">5.</span></span><span leaf=""> MSP使用人工智能驱动的风险管理扩展网络安全指南</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：The MSP Guide to Using AI-Powered Risk Management to Scale Cybersecurity</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">将网络安全服务扩展为MSP或MSSP需要技术专业知识和能够大规模提供可衡量价值的商业模式。基于风险的网络安全是该模型的基础。如果做得好，它可以建立客户信任，增加追加销售机会，并推动经常性收入...</span></p><p style="margin: 0px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;padding-top: 12px;border-top: 1px dashed rgb(238, 238, 238);"><span leaf="">📰 漏洞与威胁⏰ Fri, 06 Ma</span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">6.</span></span><span leaf=""> 与ClickFix CastleRAT攻击相关的白蚁勒索软件入侵</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Termite ransomware breaches linked to ClickFix CastleRAT attacks</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">被追踪为Velvet Tempest的勒索软件威胁行为者正在使用ClickFix技术和合法的Windows实用程序来部署DonutLoader恶意软件和CastleRAT后门。[...]</span></p><p style="margin: 0px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;padding-top: 12px;border-top: 1px dashed rgb(238, 238, 238);"><span leaf="">📰 漏洞与威胁⏰ Sat, 07 Ma</span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">7.</span></span><span leaf=""> 微软：黑客在网络攻击的每个阶段都在滥用人工智能</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Microsoft: Hackers abusing AI at every stage of cyberattacks</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">微软表示，威胁行为者越来越多地在其运营中使用人工智能来加速攻击，扩展恶意活动，并在网络攻击的各个方面降低技术壁垒。[...]</span></p><p style="margin: 0px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;padding-top: 12px;border-top: 1px dashed rgb(238, 238, 238);"><span leaf="">📰 漏洞与威胁⏰ Sat, 07 Ma</span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(231, 76, 60);font-weight: bold;margin-right: 8px;"><span leaf="">8.</span></span><span leaf=""> Cognizant TriZetto泄露事件暴露了340万患者的健康数据</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Cognizant TriZetto breach exposes health data of 3.4 million patients</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">TriZetto Provider Solutions是一家开发健康保险公司和医疗保健提供商使用的软件和服务的医疗保健IT公司，其数据泄露事件暴露了超过340万人的敏感信息。[...]</span></p><p style="margin: 0px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;padding-top: 12px;border-top: 1px dashed rgb(238, 238, 238);"><span leaf="">📰 漏洞与威胁⏰ Fri, 06 Ma</span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(52, 152, 219);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(52, 152, 219);padding-left: 15px;background: linear-gradient(90deg, rgba(52, 152, 219, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">📚</span></span><span leaf="">技术研究</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(6 条)</span></span></h2><div style="background: rgba(52, 152, 219, 0.06);border: 1px solid rgba(52, 152, 219, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> AI as tradecraft ：威胁行为者如何操作AI</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：AI as tradecraft: How threat actors operationalize AI</span></span><span style="background: rgb(52, 152, 219);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">RECOMMEND</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">正如Jasper Sleet和Coral Sleet （前身为Storm-1877 ）等朝鲜组织最近的活动所表明的那样，威胁行为者正在运用人工智能来扩展和维持恶意活动，加速交易并增加捍卫者的风险。后AI作为交易：如何威胁AC...</span></p><p style="margin: 0px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;padding-top: 12px;border-top: 1px dashed rgb(238, 238, 238);"><span leaf="">📰 技术研究⏰ Fri, 06 Ma</span></p></div><div style="background: rgba(52, 152, 219, 0.06);border: 1px solid rgba(52, 152, 219, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">2.</span></span><span leaf=""> 女性历史月：在每个职业阶段鼓励女性参与网络安全</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Women’s History Month: Encouraging women in cybersecurity at every career stage</span></span><span style="background: rgb(52, 152, 219);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">RECOMMEND</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">今年的女性历史月，我们将探索如何在每个职业阶段为下一代女性维权者提供支持。《女性历史月：在每个职业阶段鼓励女性参与网络安全》一文首次出现在微软安全博客上。</span></p><p style="margin: 0px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;padding-top: 12px;border-top: 1px dashed rgb(238, 238, 238);"><span leaf="">📰 技术研究⏰ Thu, 05 Ma</span></p></div><div style="background: rgba(52, 152, 219, 0.06);border: 1px solid rgba(52, 152, 219, 0.3);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">3.</span></span><span leaf=""> 恶意AI助手扩展Harvest LLM聊天历史记录</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Malicious AI Assistant Extensions Harvest LLM Chat Histories</span></span><span style="background: rgb(52, 152, 219);color: rgb(255, 255, 255);font-size: 11px;padding: 2px 8px;border-radius: 10px;margin-left: 8px;"><span leaf="">RECOMMEND</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">恶意AI浏览器扩展程序从ChatGPT和DeepSeek等平台收集LLM聊天历史记录和浏览数据。该活动在20,000多家企业租户中拥有近90万次安装和活动，突显了通过浏览器扩展暴露数据的风险日益增加。T...</span></p><p style="margin: 0px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;padding-top: 12px;border-top: 1px dashed rgb(238, 238, 238);"><span leaf="">📰 技术研究⏰ Thu, 05 Ma</span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">4.</span></span><span leaf=""> 深入了解Tycoon2FA ：领先的AiTM网络钓鱼工具包是如何大规模运作的</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">Tycoon2FA已成为领先的网络钓鱼即服务(PhaaS)平台，每月覆盖50多万个组织，促使微软的数字犯罪部门(DCU)与欧洲刑警组织和行业合作伙伴合作，促进Tycoon2FA的基础设施和运营...</span></p><p style="margin: 0px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;padding-top: 12px;border-top: 1px dashed rgb(238, 238, 238);"><span leaf="">📰 技术研究⏰ Wed, 04 Ma</span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">5.</span></span><span leaf=""> 签名的恶意软件模拟工作场所应用程序部署RMM后门</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Signed malware impersonating workplace apps deploys RMM backdoors</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">由被盗EV证书支持的签名恶意软件部署了合法的RMM工具，以获得企业环境中的持久访问权限。组织必须加强证书控制和监控RMM活动，以减少暴露。POST Signed malware impersonating workplace apps deploys RMM bac...</span></p><p style="margin: 0px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;padding-top: 12px;border-top: 1px dashed rgb(238, 238, 238);"><span leaf="">📰 技术研究⏰ Tue, 03 Ma</span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 20px;margin: 15px 0px;box-shadow: rgba(0, 0, 0, 0.04) 0px 2px 8px;"><p style="margin: 0px 0px 12px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(52, 152, 219);font-weight: bold;margin-right: 8px;"><span leaf="">6.</span></span><span leaf=""> Falcon Next-Gen SIEM通过传感器原生日志收集简化了入职流程</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Falcon Next-Gen SIEM Simplifies Onboarding with Sensor-Native Log Collection</span></span></p><p style="margin: 0px 0px 12px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.8;text-align: justify;"><span leaf="">🔗 [阅读原文] (<a href="https://www.crowdstrike.com/en-us/blog/falcon-next-gen-siem-simplifies-onboarding-with-sensor-native-log-collection/)" target="_blank">https://www.crowdstrike.com/en-us/blog/falcon-next-gen-siem-simplifies-onboarding-with-sensor-native-log-collection/)</a> --- # # # 7. CrowdStrike实现NCSC CIR事件响应保证 * *来源 * *: 技术研究 * * *时间 *: 2020年3月2日</span></p><p style="margin: 0px;font-size: 12px;color: rgb(153, 153, 153);display: flex;justify-content: space-between;align-items: center;padding-top: 12px;border-top: 1px dashed rgb(238, 238, 238);"><span leaf="">📰 技术研究⏰ Mar 06, 20</span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(142, 68, 173);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(142, 68, 173);padding-left: 15px;background: linear-gradient(90deg, rgba(142, 68, 173, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">🔍</span></span><span leaf="">威胁情报</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(8 条)</span></span></h2><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> 对多年来未被发现的针对高价值行业的运营的调查</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：An Investigation Into Years of Undetected Operations Targeti...</span></span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">深入分析我们称之为CL-UNK-1068的威胁活动。我们讨论了他们的工具集，包括隧道、侦察和凭据窃取。“对多年来针对高价值行业的未被发现的行动的调查”一文首先出现在第42单元上。</span></p><p style="margin: 0px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 威胁情报 · ⏰ Fri, 06 Ma</span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">2.</span></span><span leaf=""> 欺骗AI智能体：在野外观察到的基于Web的间接提示注射</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Fooling AI Agents: Web-Based Indirect Prompt Injection Obser...</span></span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">发现真实世界的间接提示注入攻击，并了解对手如何将隐藏的网络内容武器化，以利用LLM进行高影响力的欺诈。《Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild》一文首次出现在第42单元。</span></p><p style="margin: 0px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 威胁情报 · ⏰ Tue, 03 Ma</span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">3.</span></span><span leaf=""> 威胁简报： 2026年3月与伊朗相关的网络风险升级</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Threat Brief: March 2026 Escalation of Cyber Risk Related to...</span></span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">Unit 42详细介绍了伊朗最近的网络攻击活动，分享了对网络钓鱼、黑客活动和网络犯罪的直接观察。我们包括对维权者的建议。《威胁简报： 2026年3月与伊朗相关的网络风险升级》（ Threat Brief: March 2026 Escalation of Cyber Risk Related Iran ）一文首次出现在42部队上。</span></p><p style="margin: 0px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 威胁情报 · ⏰ Tue, 03 Ma</span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">4.</span></span><span leaf=""> 驯服代理浏览器： Chrome中的漏洞允许扩展到劫持新的Gemini面板</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Taming Agentic Browsers: Vulnerability in Chrome Allowed Ext...</span></span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">Chrome的Gemini中的高严重性CVE-2026-0628允许本地文件访问和隐私入侵。谷歌很快修复了这个漏洞。Taming Agentic Browsers: Vulnerability in Chrome Allowed Extensions to Hijack New Gemini Panel一文首次出现在Unit 42上。</span></p><p style="margin: 0px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 威胁情报 · ⏰ Mon, 02 Ma</span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">5.</span></span><span leaf=""> 将战斗带到边缘：将时间转化为OT安全的优势</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Bring the Fight to the Edge: Turning Time Into an Advantage ...</span></span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">Unit 42的研究表明，大多数OT攻击始于IT。了解边缘驱动防御如何及早阻止威胁，并将停留时间转化为优势。《Bring the Fight to the Edge: Turning Time Into an Advantage in OT Security》一文首次出现在第42单元。</span></p><p style="margin: 0px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 威胁情报 · ⏰ Tue, 24 Fe</span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">6.</span></span><span leaf=""> 伊朗冲突情报仪表板立即可用于ThreatConnect</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Iranian Conflict Intelligence Dashboard Immediately Availabl...</span></span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">2026年2月最后几天，专门针对伊朗冲突的地缘政治紧张局势升级，加剧了全球组织面临的重大网络和物理安全风险。由于威胁活动来自先进的伊朗国家支持的行为者， ALIGNE...</span></p><p style="margin: 0px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 威胁情报 · ⏰ Fri, 06 Ma</span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">7.</span></span><span leaf=""> 从噪音到信号：制定TI知情检测以实现真正的安全价值</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：From Noise to Signal: Crafting TI-Informed Detections for Re...</span></span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">MSSP将警报噪音转化为可防御的安全成果托管安全服务提供商(MSSP)的实用指南每天都会产生大量警报。然而，许多MSSP客户仍然会问同样的问题： “这实际上保护了我们免受什么影响？”警报激活之间的这个间隙……</span></p><p style="margin: 0px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 威胁情报 · ⏰ Tue, 03 Ma</span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(142, 68, 173);font-weight: bold;margin-right: 8px;"><span leaf="">8.</span></span><span leaf=""> 优先考虑实际重要的漏洞</span><span style="font-size: 12px;color: rgb(153, 153, 153);font-weight: normal;margin-top: 4px;display: block;"><span leaf="">原文：Prioritizing Vulnerabilities That Actually Matter</span></span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">为什么为MSSP划分漏洞优先级—以及如何最好地解决这个问题当95%的组织没有达到响应时间最佳实践时，能够始终如一地减少平均响应时间（ MTTR ）的MSSP不仅可以改善安全结果，还可以赢得并留住客户。...</span></p><p style="margin: 0px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 威胁情报 · ⏰ Wed, 25 Fe</span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;margin: 40px 15px 25px;"><h2 style="font-size: 20px;color: rgb(192, 57, 43);margin: 0px 0px 25px;font-weight: bold;display: flex;align-items: center;border-left: 6px solid rgb(192, 57, 43);padding-left: 15px;background: linear-gradient(90deg, rgba(192, 57, 43, 0.08) 0%, transparent 100%);padding-top: 8px;padding-bottom: 8px;"><span style="margin-right: 10px;font-size: 24px;"><span leaf="">🇨🇳</span></span><span leaf="">中国安全媒体</span><span style="font-size: 14px;color: rgb(153, 153, 153);margin-left: 10px;font-weight: normal;"><span leaf="">(5 条)</span></span></h2><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(192, 57, 43);font-weight: bold;margin-right: 8px;"><span leaf="">1.</span></span><span leaf=""> 【图说】重庆信通设计院：一图看清 人工智能安全“大模型备案”怎么做</span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">前言：大模型备案是我国规范生成式 AI 发展的核心监管举措，因技术普及伴生内容、数据、伦理等风险，依托《生成式人工智能服务管理暂行办法》等法规落地，明确面向境内公众的相关服务需备案，通过全流程监管筑牢安全防线，推动行业从野蛮生长转向合规高质量发展，未备案将面临严厉处罚。来源：重庆信通设计院天空实验室</span></p><p style="margin: 0px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 中国安全媒体 · ⏰ Fri, 06 Ma</span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(192, 57, 43);font-weight: bold;margin-right: 8px;"><span leaf="">2.</span></span><span leaf=""> 2026 年 AI + 网络安全产业生态图谱调研正式开启：诚邀行业同仁共建真实、有价值的产业画像</span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">2026 年，AI 技术的规模化落地正推动网络安全产业迎来新一轮变革，AI 与安全的融合已从技术探索阶段迈入深度实践与生态构建的关键期。一方面，大模型、智能体、AI 原生安全技术持续重塑安全防护体系，自动化攻防、智能风险研判、AI 驱动的安全运营成为行业标配，安全产品的技术内核与服务模式被彻底重构。另一方面，AI 的快速普及也让攻击面持续扩大，AI 模型投毒、数据泄露、深度伪造攻击等新型威胁层出不穷，AI 系统自身的安全防护与合规治理成为企业刚需。AI 与网络安全融合，早已不是概念探讨，而是渗透...</span></p><p style="margin: 0px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 中国安全媒体 · ⏰ Thu, 05 Ma</span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(192, 57, 43);font-weight: bold;margin-right: 8px;"><span leaf="">3.</span></span><span leaf=""> 嘶吼快讯|网安厂商动态汇（第14期）</span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">聚焦网安厂商最新动作，整合新品发布、战略合作、技术升级等核心动态，省去碎片化信息筛选时间，1篇GET网安厂商近期关键动作！网安厂商最新动态简网科技入围中央国家机关2026年度网络安全产品框架协议联合征集采购项目近日，中央国家机关2026年度网络安全产品框架协议联合征集采购项目入围结果正式公布，简网科技成功入围包括下一代防火墙、Web应用防火墙（WAF）、入侵检测系统（IDS）和入侵防御系统（IPS）在内的共计40个标包。御安信息入选2026年浙江省“重点省专”名单近日，浙江省经济和信息化厅公示了...</span></p><p style="margin: 0px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 中国安全媒体 · ⏰ Thu, 05 Ma</span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(192, 57, 43);font-weight: bold;margin-right: 8px;"><span leaf="">4.</span></span><span leaf=""> APT37黑客组织利用新型恶意软件实现跨网攻击</span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">黑客组织正在使用一批新曝光的恶意工具，在联网设备与物理隔离系统之间传输数据，通过可移动存储设备横向扩散，并实施隐秘监控。这场恶意攻击活动被命名为Ruby Jumper，系黑客组织APT37（又称ScarCruft、Ricochet Chollima、InkySquid）所主导。物理隔离通过在硬件层面移除所有联网模块（Wi‑Fi、蓝牙、以太网）实现；逻辑隔离则依托VLAN、防火墙等软件定义策略。在关键基础设施、军事及科研领域常见的物理隔离环境中，数据传输主要依靠可移动存储设备完成。 研究...</span></p><p style="margin: 0px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 中国安全媒体 · ⏰ Thu, 05 Ma</span></p></div><div style="background: rgb(255, 255, 255);border: 1px solid rgb(238, 238, 238);border-radius: 10px;padding: 18px;margin: 12px 0px;"><p style="margin: 0px 0px 10px;font-size: 15px;font-weight: bold;color: rgb(44, 62, 80);line-height: 1.5;"><span style="color: rgb(192, 57, 43);font-weight: bold;margin-right: 8px;"><span leaf="">5.</span></span><span leaf=""> 从网络空间测绘视角看“咆哮的狮子”行动下的伊朗-以色列冲突态势</span></p><p style="margin: 0px 0px 10px;color: rgb(102, 102, 102);font-size: 14px;line-height: 1.7;text-align: justify;"><span leaf="">一、引言2026年2月28日，中东战火再起。以色列国防军发起“咆哮的狮子”军事行动，美国同步实施“史诗怒火”行动，对伊朗境内目标展开大规模空袭。伊朗随即以导弹和无人机反击，并宣布封锁霍尔木兹海峡，冲突迅速从边境摩擦升级为覆盖伊朗、以色列全境的区域性战争。网络空间作为第五维战场，其资产存活性、服务暴露情况直接反映物理打击效果、网络攻击强度与战时管控措施。DayDayMap 通过持续监测伊朗、以色列两国的网络空间资产，捕捉到战前战时的剧烈变化。本文基于对双方网络地址空间的存活资产数据、端口与服务分布...</span></p><p style="margin: 0px;font-size: 12px;color: rgb(153, 153, 153);"><span leaf="">📰 中国安全媒体 · ⏰ Wed, 04 Ma</span></p></div></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background: linear-gradient(135deg, rgb(248, 249, 250) 0%, rgb(255, 255, 255) 100%);padding: 35px 25px;margin: 30px 15px;border-radius: 12px;text-align: center;border: 1px solid rgba(0, 0, 0, 0.05);"><h2 style="font-size: 17px;color: rgb(44, 62, 80);margin: 0px 0px 20px;font-weight: bold;letter-spacing: 1px;"><span leaf="">📝 关于本报</span></h2><p style="color: rgb(127, 140, 141);margin: 12px 0px;font-size: 14px;line-height: 1.8;"><span leaf="">🤖 本日报由 AI 自动抓取整理，每日上午 9:00 更新</span></p><p style="color: rgb(127, 140, 141);margin: 12px 0px;font-size: 14px;line-height: 1.8;"><span leaf="">🌐 内容来源：50+ 个全球网络安全 RSS 源 + API 接口</span></p><p style="color: rgb(127, 140, 141);margin: 12px 0px;font-size: 14px;line-height: 1.8;"><span leaf="">📬 涵盖：漏洞预警、技术研究、威胁情报、云安全、AI 安全等</span></p><p style="color: rgb(149, 165, 166);margin: 20px 0px 10px;font-size: 13px;"><span leaf="">━━━━━━━━━━━━━━━━━━━</span></p><p style="color: rgb(127, 140, 141);margin: 10px 0px;font-size: 13px;line-height: 1.6;"><span leaf="">如需订阅更多源、调整推送频率或合作，请联系管理员</span></p></div><div style="color: rgb(0, 0, 0);font-family: -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: medium;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.48px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;padding: 35px 15px;margin-top: 10px;background: linear-gradient(rgb(255, 255, 255) 0%, rgb(248, 249, 250) 100%);"><p style="color: rgb(189, 195, 199);font-size: 13px;margin: 5px 0px;"><span leaf="">━━━━━━━━━━━━━━━━━━━</span></p><p style="color: rgb(102, 126, 234);font-size: 16px;margin: 15px 0px;font-weight: bold;letter-spacing: 2px;"><span leaf="">🍐 枇杷熟了</span></p><p style="color: rgb(149, 165, 166);font-size: 13px;margin: 8px 0px;"><span leaf="">专注网络安全技术分享</span></p><p style="color: rgb(189, 195, 199);font-size: 12px;margin: 15px 0px;"><span leaf="">生成时间：2026-03-09 14:14:14</span></p><p style="color: rgb(189, 195, 199);font-size: 13px;margin: 5px 0px;"><span leaf="">━━━━━━━━━━━━━━━━━━━</span></p><p style="color: rgb(149, 165, 166);font-size: 12px;margin: 15px 0px 5px;"><span leaf="">感谢阅读 · 欢迎分享</span></p></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=e576144a&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MzkzOTYzOQ%3D%3D%26mid%3D2247489940%26idx%3D1%26sn%3Dada6adc54a818f7e2bb7f41d0d0a0613">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 09 Mar 2026 14:16:00 +0800</pubDate>
    </item>
    <item>
      <title>枇杷熟了-全球网络安全日报2026-03-07</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0MzkzOTYzOQ==&amp;mid=2247489935&amp;idx=1&amp;sn=099ac3b22e917305f7d601fd62b6f177</link>
      <description></description>
      <content:encoded><![CDATA[<p><span>枇杷熟了</span> <span>2026-03-07 22:49</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=ce7e2e26&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FeZOA7OiaVuZibc7Q7VSxjYtgKvOdaSMkiaQB43qyU8vUDHUMTyjibGUC9CYVISBF7umkZmnyObBveLoqiaB4pKxsw8LoVeA1Oic23mOhFufOaYWvg%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <h1 style="color: rgb(7, 193, 96);border-left: 5px solid rgb(7, 193, 96);padding-left: 15px;font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 24px;margin: 30px 0px 15px;border-bottom: 2px solid rgb(238, 238, 238);padding-bottom: 10px;" data-pm-slice="0 0 []"><span leaf="">🔐 全球网络安全日报</span></h1><blockquote style="color: rgb(51, 51, 51);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><p style="margin: 18px 0px;line-height: 1.8;"><span leaf="">📅 2026年03月07日 Saturday</span></p><p style="margin: 18px 0px;line-height: 1.8;"><span leaf="">每日精选全球网络安全最新研究、漏洞预警、技术动态</span></p></blockquote><hr style="font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"/><h2 style="color: rgb(51, 51, 51);border-left: 5px solid rgb(7, 193, 96);padding-left: 15px;font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 20px;margin: 25px 0px 12px;"><span leaf="">📊 今日概览</span></h2><p style="margin: 18px 0px;color: rgb(51, 51, 51);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.8;"><strong><span leaf="">漏洞与威胁</span></strong><span leaf="">：6 条 </span><strong><span leaf="">技术研究</span></strong><span leaf="">：6 条</span></p><hr style="font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"/><h2 style="color: rgb(51, 51, 51);border-left: 5px solid rgb(7, 193, 96);padding-left: 15px;font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 20px;margin: 25px 0px 12px;"><span leaf="">🚨 漏洞与威胁</span></h2><h3 style="color: rgb(7, 193, 96);border-left: 5px solid rgb(7, 193, 96);padding-left: 15px;font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">1. Iran-Linked MuddyWater Hackers Target U.S. Networks With New Dindoor Backdoor</span></h3><p style="margin: 18px 0px;color: rgb(51, 51, 51);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.8;"><span leaf="">Broadcom Symantec 和 Carbon Black 发现伊朗黑客组织 MuddyWater 嵌入多家美国公司网络，包括银行、机场和非营利组织，使用新型 Dindoor 后门。</span></p><p style="margin: 18px 0px;color: rgb(51, 51, 51);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.8;"><span leaf="">🔗 阅读原文</span></p><hr style="font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"/><h3 style="color: rgb(7, 193, 96);border-left: 5px solid rgb(7, 193, 96);padding-left: 15px;font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">2. China-Linked Hackers Use TernDoor, PeerTime, BruteEntry in South American Telecom Attacks</span></h3><p style="margin: 18px 0px;color: rgb(51, 51, 51);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.8;"><span leaf="">Cisco Talos 发现中国 APT 组织 UAT-9244 自 2024 年起攻击南美电信基础设施，针对 Windows、Linux 系统和边缘设备使用三种新型植入物。ps：这是栽赃，这是诬陷。</span></p><p style="margin: 18px 0px;color: rgb(51, 51, 51);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.8;"><span leaf="">🔗 阅读原文</span></p><hr style="font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"/><h3 style="color: rgb(7, 193, 96);border-left: 5px solid rgb(7, 193, 96);padding-left: 15px;font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">3. Microsoft Reveals ClickFix Campaign Using Windows Terminal to Deploy Lumma Stealer</span></h3><p style="margin: 18px 0px;color: rgb(51, 51, 51);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.8;"><span leaf="">微软披露新型 ClickFix 社会工程攻击，利用 Windows Terminal 应用部署 Lumma Stealer 恶意软件，绕过针对 Run 对话框滥用的检测。</span></p><p style="margin: 18px 0px;color: rgb(51, 51, 51);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.8;"><span leaf="">🔗 阅读原文</span></p><hr style="font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"/><h3 style="color: rgb(7, 193, 96);border-left: 5px solid rgb(7, 193, 96);padding-left: 15px;font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">4. Hikvision and Rockwell Automation CVSS 9.8 Flaws Added to CISA KEV Catalog</span></h3><p style="margin: 18px 0px;color: rgb(51, 51, 51);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.8;"><span leaf="">CISA 将海康威视和罗克韦尔自动化的两个 CVSS 9.8 严重漏洞添加到已知被利用漏洞目录，证据表明存在活跃利用。</span></p><p style="margin: 18px 0px;color: rgb(51, 51, 51);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.8;"><span leaf="">🔗 阅读原文</span></p><hr style="font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"/><h3 style="color: rgb(7, 193, 96);border-left: 5px solid rgb(7, 193, 96);padding-left: 15px;font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">5. Who is the Kimwolf Botmaster &#39;Dort&#39;?</span></h3><p style="margin: 18px 0px;color: rgb(51, 51, 51);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.8;"><span leaf="">Krebs 调查全球最大僵尸网络 Kimwolf 的控制者&#39;Dort&#39;，发现其是加拿大青少年，曾参与 Minecraft 作弊软件开发，后转向更严重的网络犯罪。</span></p><p style="margin: 18px 0px;color: rgb(51, 51, 51);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.8;"><span leaf="">🔗 阅读原文</span></p><hr style="font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"/><h3 style="color: rgb(7, 193, 96);border-left: 5px solid rgb(7, 193, 96);padding-left: 15px;font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">6. &#39;Starkiller&#39; Phishing Service Proxies Real Login Pages, MFA</span></h3><p style="margin: 18px 0px;color: rgb(51, 51, 51);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.8;"><span leaf="">新型钓鱼即服务 Starkiller 可动态加载真实登录页面，作为受害者与合法网站之间的代理，实时转发用户名、密码和 MFA 代码，有效绕过 MFA 保护。</span></p><p style="margin: 18px 0px;color: rgb(51, 51, 51);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.8;"><span leaf="">🔗 阅读原文</span></p><hr style="font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"/><h2 style="color: rgb(51, 51, 51);border-left: 5px solid rgb(7, 193, 96);padding-left: 15px;font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 20px;margin: 25px 0px 12px;"><span leaf="">📚 技术研究</span></h2><h3 style="color: rgb(7, 193, 96);border-left: 5px solid rgb(7, 193, 96);padding-left: 15px;font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">1. On the Effectiveness of Mutational Grammar Fuzzing</span></h3><p style="margin: 18px 0px;color: rgb(51, 51, 51);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.8;"><span leaf="">Google Project Zero 的 Ivan Fratric 分析变异语法模糊测试的有效性，介绍该技术的优势与缺陷，并提出改进方法。</span></p><p style="margin: 18px 0px;color: rgb(51, 51, 51);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.8;"><span leaf="">🔗 阅读原文</span></p><hr style="font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"/><h3 style="color: rgb(7, 193, 96);border-left: 5px solid rgb(7, 193, 96);padding-left: 15px;font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">2. A Deep Dive into the GetProcessHandleFromHwnd API</span></h3><p style="margin: 18px 0px;color: rgb(51, 51, 51);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.8;"><span leaf="">James Forshaw 深入分析 Windows GetProcessHandleFromHwnd API 的安全属性，该 API 可用于获取指定窗口所属进程的句柄。</span></p><p style="margin: 18px 0px;color: rgb(51, 51, 51);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.8;"><span leaf="">🔗 阅读原文</span></p><hr style="font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"/><h3 style="color: rgb(7, 193, 96);border-left: 5px solid rgb(7, 193, 96);padding-left: 15px;font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">3. Bypassing Administrator Protection by Abusing UI Access</span></h3><p style="margin: 18px 0px;color: rgb(51, 51, 51);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.8;"><span leaf="">James Forshaw 描述在 Windows Administrator Protection 功能发布前发现的 9 个绕过漏洞中的 5 个，重点分析 UI Access 的长期安全问题。</span></p><p style="margin: 18px 0px;color: rgb(51, 51, 51);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.8;"><span leaf="">🔗 阅读原文</span></p><hr style="font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"/><h3 style="color: rgb(7, 193, 96);border-left: 5px solid rgb(7, 193, 96);padding-left: 15px;font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">4. Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale</span></h3><p style="margin: 18px 0px;color: rgb(51, 51, 51);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.8;"><span leaf="">微软详细分析 Tycoon2FA 钓鱼即服务平台的运营模式，该平台每月影响超过 50 万家组织，微软数字犯罪部门与 Europol 合作对其基础设施进行打击。</span></p><p style="margin: 18px 0px;color: rgb(51, 51, 51);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.8;"><span leaf="">🔗 阅读原文</span></p><hr style="font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"/><h3 style="color: rgb(7, 193, 96);border-left: 5px solid rgb(7, 193, 96);padding-left: 15px;font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">5. Malicious AI Assistant Extensions Harvest LLM Chat Histories</span></h3><p style="margin: 18px 0px;color: rgb(51, 51, 51);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.8;"><span leaf="">微软发现恶意 AI 浏览器扩展收集 ChatGPT、DeepSeek 等平台的 LLM 聊天记录和浏览数据。</span></p><p style="margin: 18px 0px;color: rgb(51, 51, 51);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.8;"><span leaf="">🔗 阅读原文</span></p><hr style="font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"/><h3 style="color: rgb(7, 193, 96);border-left: 5px solid rgb(7, 193, 96);padding-left: 15px;font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">6. Signed malware impersonating workplace apps deploys RMM backdoors</span></h3><p style="margin: 18px 0px;color: rgb(51, 51, 51);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.8;"><span leaf="">使用被盗 EV 证书签名的恶意软件伪装成工作场所应用，在企业内部署合法 RMM 工具获取持久访问权限。</span></p><p style="margin: 18px 0px;color: rgb(51, 51, 51);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.8;"><span leaf="">🔗 阅读原文</span></p><hr style="font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"/><h2 style="color: rgb(51, 51, 51);border-left: 5px solid rgb(7, 193, 96);padding-left: 15px;font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 20px;margin: 25px 0px 12px;"><span leaf="">📝 说明</span></h2><ul style="color: rgb(51, 51, 51);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li><p><span leaf="">本日报由 AI 自动抓取整理</span></p></li><li><p><span leaf="">内容来源均为公开网络安全资讯</span></p></li><li><p><span leaf="">如需订阅更多源或调整频率，请联系管理员</span></p></li></ul><hr style="font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"/><p style="margin: 18px 0px;color: rgb(51, 51, 51);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.8;"><em><span leaf="">生成时间：2026-03-07 </span></em></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=692a60d7&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0MzkzOTYzOQ%3D%3D%26mid%3D2247489935%26idx%3D1%26sn%3D099ac3b22e917305f7d601fd62b6f177">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sat, 07 Mar 2026 22:49:00 +0800</pubDate>
    </item>
  </channel>
</rss>