<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>微步在线研究响应中心</title>
    <link>https://wechat2rss.xlab.app/feed/ac64c385ebcdb17fee8df733eb620a22b979928c.xml</link>
    <description>微步情报局最新威胁事件分析、漏洞分析、安全研究成果共享，探究网络攻击的真相&#xA;(wechat feed made by @ttttmr https://wechat2rss.xlab.app)</description>
    <managingEditor> (微步在线研究响应中心)</managingEditor>
    <pubDate>Tue, 12 May 2026 08:30:36 +0800</pubDate>
    <lastBuildDate>Tue, 12 May 2026 08:30:36 +0800</lastBuildDate>
    <image>
      <url>https://wx.qlogo.cn/mmhead/Q3auHgzwzM5aJJ0hMuzqFKnIqVJvyZPgBp5zLia7Gsicshib4xjO0DuOg/0</url>
      <title>微步在线研究响应中心</title>
      <link>https://wechat2rss.xlab.app/feed/ac64c385ebcdb17fee8df733eb620a22b979928c.xml</link>
    </image>
    <item>
      <title>从OA进，靠AI横移，半数都是RCE：2026红队攻击彻底变了</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&amp;mid=2247508706&amp;idx=1&amp;sn=0a47dc86458f4a42dc94b1b142c304b4</link>
      <description>内附高危漏洞列表，强烈建议提前排查</description>
      <content:encoded><![CDATA[<p>原创 <span>微步情报局</span> <span>2026-05-12 08:30</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=f8e02b46&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FT4OSm0sXdEMcNOtl4Mlewk56XToCMrwlwwvnwibwkaa8alHPseHmOACncz9iaozkpDFowMTq34MVFSicpXMr3AggVO75qiauEzGa6vqwicQnN7ic0%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>内附高危漏洞列表，强烈建议提前排查</p>
  <div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="font-size: 15px;letter-spacing: 1px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026，AI智能体进一步渗透和应用，对企业而言，<span textstyle="" style="font-weight: bold;">攻击暴露面与防守难度齐刷刷暴涨</span>。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">尤其是在特别时期，懂的都懂。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">微步情报局梳理了未来一段时间，企业最需要关注的几十个漏洞，涉及<span textstyle="" style="font-weight: bold;">应用系统、AI、安全产品、基础设施</span>。这些漏洞危害系数都极高，不管是<span textstyle="" style="font-weight: bold;">远程代码执行、任意文件上传，还是配置文件投毒、命令注入</span>.....你能想到的最危险的漏洞这里都有，强烈建议各位师傅提前排查。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7302052785923754" data-s="300,640" data-type="png" data-w="682" style="vertical-align:middle;max-width:100%;width:100%;box-sizing:border-box;" data-backw="457" data-backh="334" data-imgfileid="502702827" src="https://wechat2rss.xlab.app/img-proxy/?k=1c8c9e01&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FKJ5kFuz2K97zl9ic3yib3OexaSELz8B2hia3nmoGLsiakPDibE4qIuCadHGEUSpGDOPsdd73VDClxnYnsFxSIYqpuBHl74C58RlBX7kdF4aaVpA8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><p style="text-align:center;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;" data-pm-slice="0 0 []"><span style="font-size:9pt;font-family:等线;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="等线"><span leaf=""><span textstyle="" style="color: rgb(136, 136, 136);">2026最值得关注高危漏洞类型分布</span></span></span></p><div style="font-size: 15px;letter-spacing: 1px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">话不多说，直接看洞。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4568868980963046" data-s="300,640" data-type="png" data-w="893" style="vertical-align:middle;max-width:100%;width:100%;box-sizing:border-box;" data-backw="578" data-backh="264" data-imgfileid="502702829" src="https://wechat2rss.xlab.app/img-proxy/?k=7cc0316d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FKJ5kFuz2K96zPWAocWaE7fz9zMb9oic6mvdvAd2Z4go2tOuF0xCN6bj475Oy3iaUhIyn8qIAnmicdbDy80uvbwMKNBr9DEkGZIV0ibI8zULWJBw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="margin: 10px 0% 0px;display: inline-block;width: 100%;border-width: 0px 0px 0px 10px;border-style: solid;border-left-color: rgb(219, 0, 0);border-right-color: rgb(219, 0, 0);padding: 0px 0px 0px 5px;box-sizing: border-box;"><div style="font-size: 17px;width: 100%;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">一、应用系统：传统重灾区</span></strong></p></div></div><div style="font-size: 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 16px;">1、OA办公软件</span></span></strong></p></div><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">漏洞名称</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">漏洞类型</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">XVE编号</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">*微Ecology10多个远程代码执行漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">远程代码执行漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2026-2633</span></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2026-2687</span></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2026-2874</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">*微E-cology9远程代码执行漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">远程代码执行漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-21313</span></span></span></p><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-10090</span></span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">*达OA多个远程代码执行漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">远程代码执行漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-27521</span></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-27909</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">*远OA多个远程代码执行漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">远程代码执行漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-27679</span></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-27676</span></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-27577</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">*凌OA远程代码执行漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">远程代码执行漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-28358</span></span></span></p></td></tr></tbody></table></p></div><div style="font-size: 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 16px;">2、安防系统</span></span></strong></p></div><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">漏洞名称</span></span></p></div></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">漏洞类型</span></span></p></div></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">XVE编号</span></span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">*华ICC智能物联综合管理平台 evoruns/v1.0/push 远程命令执行漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="text-align: left;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">远程命令执行漏洞</span></span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-25496</span></span></span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">*华DSS数字监控系统uploadcertificate任意文件上传漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="text-align: left;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">任意文件上传漏洞</span></span></span></p></div></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-38544</span></span></p></div></td></tr></tbody></table></p></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">3、ERP</span></strong></p><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">漏洞名称</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">漏洞类型</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">XVE编号</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">*友U9Cloud FinancialIndexWebService反序列化漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">反序列化漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-37885</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">*友U8cloud FileManageServlet任意文件读取漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">任意文件读取漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-24968</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">*友YonBIP R6旗舰版 任意用户密码重置漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: left;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">任意用户密码重置漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-25494</span></span></p></div></td></tr></tbody></table></p></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">4、供应链管理软件</span></strong></p><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;">漏洞名称</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;">漏洞类型</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;">XVE编号</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: left;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">*云srm远程代码执行漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">远程代码执行漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2026-0267</span></span></p></div></td></tr></tbody></table></p></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">5、特定行业软件</span></strong></p><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">漏洞名称</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">漏洞类型</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">XVE编号</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">**锁多个远程代码执行漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">远程代码执行漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-4247</span></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-25669</span></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-24040</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">*洪BI远程代码执行漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">远程代码执行漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-0235</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">S* bi远程代码执行漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">远程代码执行漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-24290</span></span></p></div></td></tr></tbody></table></p></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">6、文档系统</span></strong></p><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">漏洞名称</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">漏洞类型</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">XVE编号</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">某文档中心和文档中台远程代码执行漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">远程代码执行漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-27514</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">*软FineReport多个远程代码执行漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">远程代码执行漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-46624</span></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-26765</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">Microsoft SharePoint</span></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">多个远程代码执行漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">远程代码执行漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-27872</span></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-26421</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">Microsoft SharePoint</span></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">多个权限绕过漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">权限绕过漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-27878</span></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-26419</span></span></p></div></td></tr></tbody></table></p></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">7、邮件网关</span></strong></p><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">漏洞名称</span></span></p></div></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">漏洞类型</span></span></p></div></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">XVE编号</span></span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="font-size: 15px;padding: 0px 5px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">*邮邮件网关系统远程命令注入漏洞</span></span></p></div></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">远程命令执行漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-27516</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="margin: 5px 0%;box-sizing: border-box;"><div style="font-size: 15px;padding: 0px 5px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">*Data电子邮件安全网关系统命令执行漏洞</span></span></p></div></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">远程命令执行漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-26966</span></span></p></div></td></tr></tbody></table></p></div><div style="font-size: 15px;letter-spacing: 1px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(219, 0, 0);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">攻击面风险：<span textstyle="" style="color: rgb(0, 0, 0);">应用系统漏洞预计仍会是安全的最大突破</span></span></strong><strong style="box-sizing: border-box;"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">口</span></span></strong><strong style="box-sizing: border-box;"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">。</span></span></strong></span><span leaf="">OA系统集成了大量企业核心流程和敏感数据，攻击价值持续攀升。文档系统承载企业知识资产，而ERP系统掌握核心业务数据和财务信息，邮件网关则是社工攻击的理想跳板。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(219, 0, 0);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">建议</span></strong><span leaf="">：</span></span><span leaf="">加强应用系统的WAF防护，建立紧急补丁响应机制，限制敏感接口暴露。</span></p></div><div style="margin: 10px 0% 0px;display: inline-block;width: 100%;border-width: 0px 0px 0px 10px;border-style: solid;border-left-color: rgb(219, 0, 0);border-right-color: rgb(219, 0, 0);padding: 0px 0px 0px 5px;box-sizing: border-box;"><div style="font-size: 17px;width: 100%;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">二、AI相关类：盲区跃升为核心战场</span></strong></p></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">1、AI Agent漏洞</span></strong></p><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">漏洞名称</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">漏洞类型</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">XVE编号</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">Cursor</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: left;font-size: 15px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;">Prompt Injection攻击</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2026-3480</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">Cursor</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: left;font-size: 15px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;">Prompt Injection攻击</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-12996</span></span></span></p></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">Cursor</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">配置文件投毒</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2026-3480</span></span></span></p></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">Cursor</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">配置文件投毒</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-39888</span></span></span></p></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">Claude Code</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">配置文件投毒</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2026-2730</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">Claude Code</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">配置文件投毒</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2026-1180</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">Claude Code</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">命令解析绕过</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-42681</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">Codex CLI</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">系统边界绕过攻击</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-30413</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">Codex CLI</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">命令解析绕过</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-28425</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">Openclaw</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">远程代码执行漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2026-2113</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">Openclaw</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">远程代码执行漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2026-6192</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">Openclaw</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">远程代码执行漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2026-7112</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">Openclaw</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">远程代码执行漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2026-7922</span></span></p></div></td></tr></tbody></table></p></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2、其他AI相关漏洞</span></strong></p><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">漏洞名称</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">漏洞类型</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">XVE编号</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">vllm多个远程代码执行漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">远程代码执行漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2026-1223</span></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-9464</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">vllm拒绝服务漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">拒绝服务漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-41632</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">Langflow访问控制错误漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">未授权访问</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2026-0017</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">Langflow远程代码执行漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">远程命令执行漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-43248</span></span></p></div></td></tr></tbody></table></p></div><div style="font-size: 15px;letter-spacing: 1px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(219, 0, 0);box-sizing: border-box;"><span leaf="">攻击面风险：<span textstyle="" style="color: rgb(0, 0, 0);">AI安全不再是&#34;新兴盲区&#34;，而是核心战场。</span></span></span></strong><span leaf="">AI智能体作为企业智能化核心，漏洞利用可导致数据泄露、权限滥用和业务逻辑被劫持。而提示注入（Prompt Injection）、越权工具调用、上下文污染等攻击面对传统安全团队仍是知识盲区。一旦AI系统被攻击，影响面极大。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(219, 0, 0);box-sizing: border-box;"><span leaf="">建议：</span></span></strong><span leaf="">审计AI系统的输入验证机制，为AI智能体设置最小权限原则，部署AI专用防火墙。</span></p></div><div style="margin: 10px 0% 0px;display: inline-block;width: 100%;border-width: 0px 0px 0px 10px;border-style: solid;border-left-color: rgb(219, 0, 0);border-right-color: rgb(219, 0, 0);padding: 0px 0px 0px 5px;box-sizing: border-box;"><div style="font-size: 17px;width: 100%;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">三、安全产品类：防御者自身脆弱问题</span></strong></p></div></div><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">漏洞名称</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">漏洞类型</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">XVE编号</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">*服运维安全管理系统任意文件上传漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">文件上传漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-38542</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">*服运维管理系统多个命令注入漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">远程命令执行漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-39581</span></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-7115</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">*科安全隔离与信息交换系统多个SQL注入漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">SQL注入漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-39582</span></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-39774</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">*科日志审计平台HSA多个命令注入漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">远程命令执行漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-34126</span></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-34127</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">*科安全管理平台HSM远程命令执行漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">远程命令执行漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-31805</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">*科数据库审计与防护系统远程命令执行漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">远程命令执行漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-29872</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">*C综合日志审计平台uploadLog文件上传漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">文件上传漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-36591</span></span></p></div></td></tr></tbody></table></p></div><div style="font-size: 15px;letter-spacing: 1px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(219, 0, 0);box-sizing: border-box;"><span leaf="">攻击面风险：<span textstyle="" style="color: rgb(0, 0, 0);">安全产品本身也可能存在漏洞。</span></span></span></strong><span leaf="">安全产品通常部署在网络关键节点，一旦被控可实现流量劫持、告警绕过甚至内网穿透。VPN、防火墙、EDR、IDS等产品的RCE漏洞一旦被利用，风险极大。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(219, 0, 0);box-sizing: border-box;"><span leaf="">建议：</span></span></strong><span leaf="">安全产品同样需要纳入漏洞管理范围，不能因为&#34;是安全产品&#34;就忽视安全更新。</span></p></div><div style="margin: 10px 0% 0px;display: inline-block;width: 100%;border-width: 0px 0px 0px 10px;border-style: solid;border-left-color: rgb(219, 0, 0);border-right-color: rgb(219, 0, 0);padding: 0px 0px 0px 5px;box-sizing: border-box;"><div style="font-size: 17px;width: 100%;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">四、基础设施类：横移关键</span></strong></p></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">1、操作系统/客户端漏洞</span></strong></p><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">漏洞名称</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">漏洞类型</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">XVE编号</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">Adobe Acrobat Reader 任意代码执行漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">任意代码执行漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2026-13194</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">Linux版本*信远程命令执行漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">远程命令执行漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2026-3046</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">*zip远程代码执行漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">任意代码执行漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-36507</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">*RAR远程代码执行漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">任意代码执行漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-29899</span></span></p></div></td></tr></tbody></table></p></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2、中间件</span></strong></p><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">漏洞名称</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">漏洞类型</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">XVE编号</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">某应用服务器ejbserver反序列化漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">远程代码执行漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-40880</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="font-size: 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">*蝶云星空多个远程代码执行漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">远程代码执行漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-27372</span></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-38154</span></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-27165</span></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-27229</span></span></p></div></td></tr></tbody></table></p></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">3、开发框架</span></strong></p><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">漏洞名称</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">漏洞类型</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;background-color: rgb(160, 160, 160);box-sizing: border-box;padding: 0px;"><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">XVE编号</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: left;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">React组件远程代码执行漏洞</span></span></p></div></td><td data-colwidth="33.0000%" width="33.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">远程代码执行漏洞</span></span></p></div></td><td data-colwidth="34.0000%" width="34.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;"><div style="text-align: center;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 14px;">XVE-2025-42672</span></span></p></div></td></tr></tbody></table></p></div><div style="font-size: 15px;letter-spacing: 1px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(219, 0, 0);box-sizing: border-box;"><span leaf="">攻击面风险：<span textstyle="" style="color: rgb(0, 0, 0);">拿下基础设施漏洞，攻击者可在内网横移。</span></span></span></strong><span leaf="">操作系统漏洞常用于权限提升和持久化，中间件漏洞（如WebLogic、Log4j、Tomcat等）历史上是高危重灾区，开发框架漏洞影响面广，一个框架漏洞可能影响数十个应用，需要引起重视。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(219, 0, 0);box-sizing: border-box;"><span leaf="">建议：</span></span></strong><span leaf="">建立资产清单，确保关键基础设施组件的及时更新。</span></p></div><div style="font-size: 15px;letter-spacing: 1px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">以上就是建议各位师傅2026年接下来重点关注的漏洞。</span><span style="color: rgb(219, 0, 0);box-sizing: border-box;"><span leaf="">如需了解以上漏洞详情，或者获取验真报告，欢迎扫码（↓↓）直接联系微步</span></span><span leaf="">。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="350" style="vertical-align:middle;max-width:100%;width:141px;box-sizing:border-box;height:141px;" data-imgfileid="502702828" src="https://wechat2rss.xlab.app/img-proxy/?k=e7be8ac7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FKJ5kFuz2K97e0Hh2ia7CUlA3iabLRyrRghm1G2QCvH2wiawqJUQUYP4nuGwgU1yYMIFwrniaLcuXw0ibzG96E9gUtY0ndr6QDF906vQ5KyZ2Aaks%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><div style="font-size: 15px;letter-spacing: 1px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">如需对往期高危漏洞进行查漏补缺，欢迎点击右侧年份进行对照查询：<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&amp;mid=2247502799&amp;idx=1&amp;sn=87f72b432bd40665572c9d626fd14045&amp;scene=21#wechat_redirect" textvalue="2023年" data-itemshowtype="0" linktype="text" data-linktype="2">2023年</a>、<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&amp;mid=2247506036&amp;idx=1&amp;sn=cf7a3bb9fec28c97b30ded350c49a6be&amp;scene=21#wechat_redirect" textvalue="2024年" data-itemshowtype="0" linktype="text" data-linktype="2">2024年</a>、<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&amp;mid=2247507726&amp;idx=1&amp;sn=87cb8cf899d518b4a7c07925db84de62&amp;scene=21#wechat_redirect" textvalue="2025年" data-itemshowtype="0" linktype="text" data-linktype="2">2025年</a>。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: center;"><span style="color: rgb(79, 79, 79);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 12px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;" data-pm-slice="0 0 []"><span leaf="">· END ·</span></span></p><p class="mp_profile_iframe_wrp" nodeleaf=""><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-nickname="微步在线研究响应中心" data-from="0" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/fFyp1gWjicML0NlKR16SxQGjNPSYVoUxGgXhXvI4Z8ia5h8C9TGibEic1ABv6fniame8h0dh6zGX8ndXT8icjQocVh8A/0?wx_fmt=png" data-signature="微步情报局最新威胁事件分析、漏洞分析、安全研究成果共享，探究网络攻击的真相" data-id="Mzg5MTc3ODY4Mw==" data-is_biz_ban="0" data-service_type="1" data-verify_status="2"></mp-common-profile></p></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=71517c31&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5MTc3ODY4Mw%3D%3D%26mid%3D2247508706%26idx%3D1%26sn%3D0a47dc86458f4a42dc94b1b142c304b4">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 12 May 2026 08:30:00 +0800</pubDate>
    </item>
    <item>
      <title>Dirty Frag 漏洞爆发！影响9年Linux内核的“确定性”提权漏洞</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&amp;mid=2247508690&amp;idx=1&amp;sn=4bd97e12d5898b4f379ccfac5d4e849c</link>
      <description>点击查看漏洞情报详情</description>
      <content:encoded><![CDATA[<p><span>微步情报局</span> <span>2026-05-08 09:33</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=0e49e9f2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FT4OSm0sXdEM4URm94iaA4WurQs1I3b8H7c5llUVsu1eOokrNGh2iccEGKlYfCDCVjQVfcM9fHibeTvbMPbPiaJfTJV8Py4tB0YRJQ3IuWnL2N6Y%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>点击查看漏洞情报详情</p>
  <div style="color: #0f172a;font-size: 15px;" segoe="" pingfang="" data-pm-slice="0 0 []"><p style="margin-top: 24px;margin-bottom: 14px;color: rgb(15, 23, 42);font-weight: 600;line-height: 1.45;font-family: -apple-system, BlinkMacFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, sans-serif;font-size: 1.5em;border-bottom: 1px solid rgb(219, 228, 238);padding-bottom: 6px;"><span leaf="">1. 漏洞概况</span></p><p style="margin: 0 0 14px;margin-left: 0;padding: 0;line-height: 1.6em;"><span leaf="">2026年5月7日，安全研究员 Hyunwoo Kim（@v4bel）公开了一个名为 </span><strong><span leaf="">Dirty Frag</span></strong><span leaf="">（CVE-2026-43284）的本地权限提升（LPE）漏洞。该漏洞影响自2017年以来（约9年）的主流Linux发行版，允许任何本地用户</span><strong><span leaf="">稳定、确定性地</span></strong><span leaf="">获得root权限。</span></p><p style="margin: 0 0 14px;margin-left: 0;padding: 0;line-height: 1.6em;"><span style="color: #d93025;font-weight: bold;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: #0f172a;font-size: 15px;font-family: -apple-system, BlinkMacFont,;&#34;,&#34;segoe&#34;:&#34;&#34;,&#34;pingfang&#34;:&#34;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin: 0 0 14px;margin-left: 0;padding: 0;line-height: 1.6em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: #d93025;font-weight: bold;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">关于该漏洞的细节、影响系统及版本、修复方案、临时缓解措施，微步情报局正在进一步研究中，详情请关注微步漏洞情报。</span></span></p><h2 style="margin-top: 24px;margin-bottom: 14px;color: #0f172a;font-weight: 600;line-height: 1.45;font-family: -apple-system, BlinkMacFont, &#39;Segoe UI&#39;, &#39;PingFang SC&#39;, sans-serif;font-size: 1.5em;border-bottom: 1px solid #dbe4ee;padding-bottom: 6px;"><span leaf="">2. 漏洞本质：Page Cache缓存篡改</span></h2><p style="margin: 0 0 14px;margin-left: 0;padding: 0;line-height: 1.6em;"><span leaf="">Dirty Frag 属于“Dirty Pipe”漏洞家族的变种，通过操纵内核</span><strong><span leaf="">页缓存（Page Cache）</span></strong><span leaf="">，</span><strong><span leaf="">直接篡改磁盘文件在内存中的只读副本</span></strong><span leaf="">。</span></p><p style="margin: 0 0 14px;margin-left: 0;padding: 0;line-height: 1.6em;"><span leaf="">Dirty Frag 包含两个独立的漏洞，分别位于不同的内核模块。攻击者根据目标环境选择其中一个进行利用，每个漏洞均可单独完成提权。</span></p><h3 style="margin-top: 24px;margin-bottom: 14px;color: #0f172a;font-weight: 600;line-height: 1.45;font-family: -apple-system, BlinkMacFont, &#39;Segoe UI&#39;, &#39;PingFang SC&#39;, sans-serif;font-size: 1.25em;"><span leaf="">漏洞一：xfrm-ESP Page-Cache Write</span></h3><table style="margin: 0 0 14px;width: 100%;border-collapse: collapse;"><thead><tr><th style="border: 1px solid #dbe4ee;padding: 8px 12px;text-align: left;background: #f1f5f9;font-weight: 600;"><p><span leaf="">项目</span></p></th><th style="border: 1px solid #dbe4ee;padding: 8px 12px;text-align: left;background: #f1f5f9;font-weight: 600;"><p><span leaf="">信息</span></p></th></tr></thead><tbody><tr><td style="border: 1px solid #dbe4ee;padding: 8px 12px;text-align: left;"><strong><span leaf="">所在模块</span></strong></td><td style="border: 1px solid #dbe4ee;padding: 8px 12px;text-align: left;"><code style="font-family: &#39;SFMono-Regular&#39;, Consolas, monospace;font-size: 0.92em;"><span leaf="">esp4</span></code><p><span leaf=""> / </span><code style="font-family: &#39;SFMono-Regular&#39;, Consolas, monospace;font-size: 0.92em;"><span leaf="">esp6</span></code></p></td></tr><tr><td style="border: 1px solid #dbe4ee;padding: 8px 12px;text-align: left;"><strong><span leaf="">影响范围</span></strong></td><td style="border: 1px solid #dbe4ee;padding: 8px 12px;text-align: left;"><p><span leaf="">自 2017-01-17 (cac2661c53f3) 起的所有内核</span></p></td></tr><tr><td style="border: 1px solid #dbe4ee;padding: 8px 12px;text-align: left;"><strong><span leaf="">利用前提</span></strong></td><td style="border: 1px solid #dbe4ee;padding: 8px 12px;text-align: left;"><p><span leaf="">需要创建用户命名空间的权限</span></p></td></tr></tbody></table><p style="margin: 0 0 14px;margin-left: 0;padding: 0;line-height: 1.6em;"><strong><span leaf="">利用流程：</span></strong></p><ol style="margin: 0 0 14px;padding-left: 22px;line-height: 1.75;" class="list-paddingleft-1"><li style="margin-bottom: 6px;"><strong><span leaf="">创建用户命名空间</span></strong><p><span leaf="">：攻击者创建一个新的用户命名空间，获取所需的权限</span></p></li><li style="margin-bottom: 6px;"><strong><span leaf="">触发ESP数据包处理</span></strong><p><span leaf="">：通过Netlink接口构造特制的ESP数据包，触发 </span><code style="font-family: &#39;SFMono-Regular&#39;, Consolas, monospace;font-size: 0.92em;padding: 2px 6px;border-radius: 6px;background: rgba(15, 23, 42, 0.06);"><span leaf="">xfrm</span></code><span leaf=""> 代码路径中的页缓存写入操作</span></p></li><li style="margin-bottom: 6px;"><strong><span leaf="">篡改页缓存</span></strong><p><span leaf="">：利用漏洞向目标文件的页缓存中写入任意4字节数据</span></p></li><li style="margin-bottom: 6px;"><strong><span leaf="">修改系统文件</span></strong><p><span leaf="">：反复利用该原语，篡改 </span><code style="font-family: &#39;SFMono-Regular&#39;, Consolas, monospace;font-size: 0.92em;padding: 2px 6px;border-radius: 6px;background: rgba(15, 23, 42, 0.06);"><span leaf="">/etc/passwd</span></code><span leaf=""> 或 </span><code style="font-family: &#39;SFMono-Regular&#39;, Consolas, monospace;font-size: 0.92em;padding: 2px 6px;border-radius: 6px;background: rgba(15, 23, 42, 0.06);"><span leaf="">/etc/sudoers</span></code><span leaf=""> 等关键文件</span></p></li><li style="margin-bottom: 6px;"><strong><span leaf="">获得root权限</span></strong><p><span leaf="">：通过篡改后的系统文件创建root用户或提升当前用户权限</span></p></li></ol><h3 style="margin-top: 24px;margin-bottom: 14px;color: #0f172a;font-weight: 600;line-height: 1.45;font-family: -apple-system, BlinkMacFont, &#39;Segoe UI&#39;, &#39;PingFang SC&#39;, sans-serif;font-size: 1.25em;"><span leaf="">漏洞二：RxRPC Page-Cache Write</span></h3><table style="margin: 0 0 14px;width: 100%;border-collapse: collapse;"><thead><tr><th style="border: 1px solid #dbe4ee;padding: 8px 12px;text-align: left;background: #f1f5f9;font-weight: 600;"><p><span leaf="">项目</span></p></th><th style="border: 1px solid #dbe4ee;padding: 8px 12px;text-align: left;background: #f1f5f9;font-weight: 600;"><p><span leaf="">信息</span></p></th></tr></thead><tbody><tr><td style="border: 1px solid #dbe4ee;padding: 8px 12px;text-align: left;"><strong><span leaf="">所在模块</span></strong></td><td style="border: 1px solid #dbe4ee;padding: 8px 12px;text-align: left;"><code style="font-family: &#39;SFMono-Regular&#39;, Consolas, monospace;font-size: 0.92em;"><span leaf="">rxrpc</span></code></td></tr><tr><td style="border: 1px solid #dbe4ee;padding: 8px 12px;text-align: left;"><strong><span leaf="">影响范围</span></strong></td><td style="border: 1px solid #dbe4ee;padding: 8px 12px;text-align: left;"><p><span leaf="">自 2023-06 (2dc334f1a63a) 起的所有内核</span></p></td></tr><tr><td style="border: 1px solid #dbe4ee;padding: 8px 12px;text-align: left;"><strong><span leaf="">利用前提</span></strong></td><td style="border: 1px solid #dbe4ee;padding: 8px 12px;text-align: left;"><p><span leaf="">需要 </span><code style="font-family: &#39;SFMono-Regular&#39;, Consolas, monospace;font-size: 0.92em;"><span leaf="">rxrpc</span></code><span leaf=""> 模块已加载（Ubuntu默认加载），</span><strong><span leaf="">不需要任何特权</span></strong></p></td></tr></tbody></table><p style="margin: 0 0 14px;margin-left: 0;padding: 0;line-height: 1.6em;"><strong><span leaf="">利用流程：</span></strong></p><ol style="margin: 0 0 14px;padding-left: 22px;line-height: 1.75;" class="list-paddingleft-1"><li style="margin-bottom: 6px;"><strong><span leaf="">创建AF_RXRPC套接字</span></strong><p><span leaf="">：攻击者创建一个 </span><code style="font-family: &#39;SFMono-Regular&#39;, Consolas, monospace;font-size: 0.92em;padding: 2px 6px;border-radius: 6px;background: rgba(15, 23, 42, 0.06);"><span leaf="">AF_RXRPC</span></code><span leaf=""> 类型套接字</span></p></li><li style="margin-bottom: 6px;"><strong><span leaf="">构造特殊的RxRPC调用</span></strong><p><span leaf="">：通过特定的控制消息触发内核rxrpc代码路径中的页缓存写入漏洞</span></p></li><li style="margin-bottom: 6px;"><strong><span leaf="">篡改页缓存</span></strong><p><span leaf="">：向目标文件的页缓存中写入恶意数据</span></p></li><li style="margin-bottom: 6px;"><strong><span leaf="">修改认证文件</span></strong><p><span leaf="">：利用写入原语修改 </span><code style="font-family: &#39;SFMono-Regular&#39;, Consolas, monospace;font-size: 0.92em;padding: 2px 6px;border-radius: 6px;background: rgba(15, 23, 42, 0.06);"><span leaf="">/etc/passwd</span></code><span leaf=""> 或 </span><code style="font-family: &#39;SFMono-Regular&#39;, Consolas, monospace;font-size: 0.92em;padding: 2px 6px;border-radius: 6px;background: rgba(15, 23, 42, 0.06);"><span leaf="">/etc/shadow</span></code></p></li><li style="margin-bottom: 6px;"><strong><span leaf="">获得root权限</span></strong><p><span leaf="">：通过新建的root用户或修改变更当前用户权限</span></p></li></ol><h3 style="margin-top: 24px;margin-bottom: 14px;color: #0f172a;font-weight: 600;line-height: 1.45;font-family: -apple-system, BlinkMacFont, &#39;Segoe UI&#39;, &#39;PingFang SC&#39;, sans-serif;font-size: 1.25em;"><span leaf="">两个漏洞的场景覆盖</span></h3><table style="margin: 0 0 14px;width: 100%;border-collapse: collapse;"><thead><tr><th style="border: 1px solid #dbe4ee;padding: 8px 12px;text-align: left;background: #f1f5f9;font-weight: 600;"><p><span leaf="">环境场景</span></p></th><th style="border: 1px solid #dbe4ee;padding: 8px 12px;text-align: left;background: #f1f5f9;font-weight: 600;"><p><span leaf="">可用的漏洞</span></p></th></tr></thead><tbody><tr><td style="border: 1px solid #dbe4ee;padding: 8px 12px;text-align: left;"><p><span leaf="">允许非特权用户命名空间（大多数发行版）</span></p></td><td style="border: 1px solid #dbe4ee;padding: 8px 12px;text-align: left;"><p><span leaf="">xfrm-ESP</span></p></td></tr><tr><td style="border: 1px solid #dbe4ee;padding: 8px 12px;text-align: left;"><p><span leaf="">限制非特权用户命名空间（如Ubuntu + AppArmor）</span></p></td><td style="border: 1px solid #dbe4ee;padding: 8px 12px;text-align: left;"><p><span leaf="">RxRPC（若模块加载）</span></p></td></tr><tr><td style="border: 1px solid #dbe4ee;padding: 8px 12px;text-align: left;"><p><span leaf="">Ubuntu默认配置</span></p></td><td style="border: 1px solid #dbe4ee;padding: 8px 12px;text-align: left;"><strong><span leaf="">至少一个可用</span></strong><p><span leaf="">（xfrm-ESP 通常可用；如果被AppArmor限制，rxrpc默认加载）</span></p></td></tr></tbody></table><h2 style="margin-top: 24px;margin-bottom: 14px;color: #0f172a;font-weight: 600;line-height: 1.45;font-family: -apple-system, BlinkMacFont, &#39;Segoe UI&#39;, &#39;PingFang SC&#39;, sans-serif;font-size: 1.5em;border-bottom: 1px solid #dbe4ee;padding-bottom: 6px;"><span leaf="">3. 和“Copy Fail”漏洞是什么关系？</span></h2><p style="margin: 0 0 14px;margin-left: 0;padding: 0;line-height: 1.6em;"><strong><span leaf="">相同点</span></strong><span leaf="">：xfrm-ESP 漏洞与 Copy Fail 共享相同的</span><strong><span leaf="">内核写入原语</span></strong><span leaf="">。</span></p><p style="margin: 0 0 14px;margin-left: 0;padding: 0;line-height: 1.6em;"><strong><span leaf="">差异点</span></strong><span leaf="">：Dirty Frag 不依赖 </span><code style="font-family: &#39;SFMono-Regular&#39;, Consolas, monospace;font-size: 0.92em;padding: 2px 6px;border-radius: 6px;background: rgba(15, 23, 42, 0.06);"><span leaf="">algif_aead</span></code><span leaf=""> 模块。因此，即使系统已应用 </span><code style="font-family: &#39;SFMono-Regular&#39;, Consolas, monospace;font-size: 0.92em;padding: 2px 6px;border-radius: 6px;background: rgba(15, 23, 42, 0.06);"><span leaf="">algif_aead</span></code><span leaf=""> 黑名单来缓解 Copy Fail，</span><strong><span leaf="">Dirty Frag 仍然有效</span></strong><span leaf="">。</span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=3c61c3d1&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5MTc3ODY4Mw%3D%3D%26mid%3D2247508690%26idx%3D1%26sn%3D4bd97e12d5898b4f379ccfac5d4e849c">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 08 May 2026 09:33:00 +0800</pubDate>
    </item>
    <item>
      <title>漏洞通告 | Apache HTTP Server 远程命令执行漏洞</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&amp;mid=2247508686&amp;idx=1&amp;sn=c8044c778acb9ba9419eb689209824d4</link>
      <description>立即查看详情 →</description>
      <content:encoded><![CDATA[<p>原创 <span>微步情报局</span> <span>2026-05-07 17:02</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d610ba96&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FfFyp1gWjicMKRfkOibMss786PqPwUGjHu4siboRiaqI4mguqRmR09PN8XVEaw2KnV8ORyrCRF8ZQz35agEmw3yebIQ%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>立即查看详情 →</p>
  <p style="outline: 0px;text-align: center;visibility: visible;margin-bottom: 0px;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.42592592592592593" data-s="300,640" data-type="jpeg" data-w="1080" style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);width: 480px !important;visibility: visible !important;height: auto !important;" data-cropselx1="0" data-cropselx2="432" data-cropsely1="0" data-cropsely2="184" data-imgfileid="100021107" src="https://wechat2rss.xlab.app/img-proxy/?k=e78774c2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FfFyp1gWjicMKNkm4Pg1Ed6nv0proxQLEKJ2CUCIficfAwKfClJ84puialc9eER0oaibMn1FDUpibeK1t1YvgZcLYl3A%2F640%3Fwx_fmt%3Dpng%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></span></p><div style="font-size: 15px;" segoe="" pingfang="" data-pm-slice="0 0 []"><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 0 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞概况</span></span></p></div></div><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">Apache HTTP Server 是 Apache 软件基金会维护的开源 Web 服务器，mod_http2 是其用于支持 HTTP/2 协议的核心模块。</span></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">近日，微步情报局监测到 Apache HTTP Server 官方发布安全通告，修复了 Apache HTTP Server 拒绝服务漏洞（CVE-2026-23918），</span><span style="color: #d93025;font-weight: bold;"><span leaf="">微步情报局已成功复现</span></span><span leaf="">；经验证，该漏洞可通过构造特定 HTTP/2 帧序列稳定触发拒绝服务。在系统符合特定内存布局、地址信息及运行环境条件要求时可实现远程代码执行，但并非任意场景下稳定利用。(完整漏洞情报请查阅：<a href="https://x.threatbook.com/v5/vul/XVE-2026-17007）" target="_blank">https://x.threatbook.com/v5/vul/XVE-2026-17007）</a></span></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">此漏洞</span><span style="color: #d93025;font-weight: bold;"><span leaf="">无需权限</span></span><span leaf="">，攻击者成功利用此漏洞可</span><span style="color: #d93025;font-weight: bold;"><span leaf="">导致Apache worker进程崩溃造成拒绝服务，特定条件下可能实现远程代码执行。</span></span><span leaf="">建议受影响用户</span><span style="color: #d93025;font-weight: bold;"><span leaf="">尽快修复。</span></span></p><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞处置优先级(VPT)</span></span></p></div></div><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><strong style="font-size: 17px;letter-spacing: 0.034em;outline: 0px;"><span leaf="">综合处置优先级：</span></strong><span style="color: #d93025;font-weight: bold;font-size: 15px;"><span leaf="">中风险</span></span></p><table style="width: 100%;border-collapse: collapse;margin: 20px 0;font-size: 14px;table-layout: fixed;"><tbody><tr><td rowspan="3" style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">基本信息</span></p></td><td style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;"><p><span leaf="">微步编号</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">XVE-2026-17007</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">CVE编号</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">CVE-2026-23918</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">漏洞类型</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">远程命令执行</span></p></td></tr><tr><td rowspan="5" style="border: 1px solid #ddd;padding: 12px;vertical-align: top;font-weight: bold;background-color: #f8f9fa;"><p><span leaf="">利用条件评估</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">利用漏洞的网络条件</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">远程</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">是否需要绕过安全机制</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">否</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">对被攻击系统的要求</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">无特殊要求</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">利用漏洞的权限要求</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">无需权限</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">是否需要受害者配合</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">否</span></p></td></tr><tr><td rowspan="2" style="border: 1px solid #ddd;padding: 12px;vertical-align: top;font-weight: bold;background-color: #f8f9fa;"><p><span leaf="">利用情报</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">POC是否公开</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><span style="color: #d93025;font-weight: bold;"><span leaf="">是</span></span></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">已知利用行为</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">暂无</span></p></td></tr></tbody></table><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞影响范围</span></span></p></div></div><table style="width: 100%;border-collapse: collapse;margin: 20px 0;font-size: 14px;table-layout: fixed;"><tbody><tr><td style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">产品名称</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">Apache HTTP Server</span></p></td></tr><tr><td style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">受影响版本</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">2.4.66</span></p></td></tr><tr><td style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">有无修复补丁</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">有</span></p></td></tr></tbody></table><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞复现</span></span></p></div></div><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;" nodeleaf=""><img alt="20260507135232_2cbb30f9-9b1d-4de6-9936-cedc0b377c2a_image.png" class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100025036" data-ratio="1.076147816349384" data-w="893" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=b802a194&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdENNkp2w6b5aPxicJW1O5rfPg3SVh03TsskjoJPibd4WYLr5FMbmBcKWzz2aFA44zJyicUaw47wd1lq5fwW9lPpgiakVq6HNeAhyOn4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">修复方案</span></span></p></div></div><h3 style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;pointer-events: initial;"><span leaf=""><span textstyle="" style="color: rgb(219, 0, 0);">官方修复方案</span></span></h3><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">官方已发布漏洞通告，建议受影响的用户依据官方通告进行修复：</span><span leaf=""><br/></span><span leaf=""><a href="https://httpd.apache.org/security/vulnerabilities_24.html" target="_blank">https://httpd.apache.org/security/vulnerabilities_24.html</a></span></p><h3 style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;pointer-events: initial;"><span leaf=""><span textstyle="" style="color: rgb(219, 0, 0);">临时缓解措施</span></span></h3><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">禁用HTTP/2协议：注释掉 http2 模块，同时注释掉 H2Direct 和 H2MaxSessionStreams</span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6824074074074075" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100025037" src="https://wechat2rss.xlab.app/img-proxy/?k=c1ef015f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEOvmHw4gKFHvDljfhLx06ZwtP7zcArFhYOSEzqfXUibPkF9heqEPMpSZsIPV7I9lHjrO5LNeicb1HsTqCPicqSumK6vZstXUkiaxs4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: center;margin-top: 24px;margin-bottom: 24px;"><span leaf="">- END -</span><div powered-by="xiumi.us" style="margin-bottom: 10px;outline: 0px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;"><div style="padding: 20px 15px;outline: 0px;display: inline-block;width: 677px;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: solid;border-width: 1px;border-color: rgba(189, 16, 16, 0.22);box-shadow: rgba(189, 16, 16, 0.22) 4px 4px 0px;"><div powered-by="xiumi.us" style="margin-top: 10px;outline: 0px;justify-content: flex-start;display: flex;flex-flow: row;"><div style="outline: 0px;display: inline-block;width: 645px;vertical-align: top;border-left: 3px solid rgb(232, 57, 57);border-bottom-left-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: -5px;margin-bottom: -5px;outline: 0px;"><div style="padding-right: 6px;padding-left: 6px;outline: 0px;font-size: 24px;color: rgb(233, 38, 52);line-height: 0.75;letter-spacing: 0px;text-align: justify;"><p style="outline: 0px;text-wrap: wrap;"><span style="outline: 0px;color: rgb(219, 0, 0);"><strong style="outline: 0px;"><span style="outline: 0px;font-size: 16px;"><span leaf="">微步漏洞情报订阅服务</span></span></strong></span></p></div></div></div></div><div powered-by="xiumi.us" style="outline: 0px;text-align: justify;color: rgb(131, 131, 131);"><p style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);line-height: 1.6em;"><span style="outline: 0px;font-family: 微软雅黑;letter-spacing: 0.578px;text-decoration: initial;text-decoration-color: rgba(0, 0, 0, 0.9);font-size: 14px;color: rgb(84, 84, 84);"><span leaf="">微步提供漏洞情报订阅服务，精准、高效助力企业漏洞运营：</span></span></p><ul style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);list-style-type: square;" class="list-paddingleft-1"><li style="outline: 0px;color: rgb(84, 84, 84);"><p style="margin-bottom: 8px;outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">提供高价值漏洞情报，具备及时、准确、全面和可操作性，帮助企业高效应对漏洞应急与日常运营难题；</span></span></p></li><li style="outline: 0px;color: rgb(84, 84, 84);"><p style="margin-bottom: 8px;outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">可实现对高威胁漏洞提前掌握，以最快的效率解决信息差问题，缩短漏洞运营MTTR；</span></span></p></li><li style="outline: 0px;color: rgb(84, 84, 84);"><p style="margin-bottom: 8px;outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">提供漏洞完整的技术细节，更贴近用户漏洞处置的落地；</span></span></p></li><li style="outline: 0px;color: rgb(84, 84, 84);"><p style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">将漏洞与威胁事件库、APT组织和黑产团伙攻击大数据、网络空间测绘等结合，对漏洞的实际风险进行持续动态更新</span></span><span leaf="">。</span></span></p></li></ul><p style="margin-right: 16px;margin-left: 16px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-wrap: wrap;background-color: rgb(255, 255, 255);letter-spacing: 0.578px;text-align: center;"><span style="outline: 0px;font-size: 14px;letter-spacing: 0.578px;"><span leaf="">扫码在线沟通</span></span></p><div style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);line-height: 1.8;visibility: visible;"><p style="margin: 0pt 16px 8px;outline: 0px;letter-spacing: 0.544px;text-align: center;line-height: 1.75em;"><span style="outline: 0px;color: rgb(63, 63, 63);font-size: 14px;letter-spacing: 1px;"><span leaf="">↓</span><span style="outline: 0px;"><span leaf="">↓↓</span></span></span></p><p style="margin-bottom: 16px;outline: 0px;letter-spacing: 0.544px;text-align: center;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="350" style="outline: 0px;display: initial;visibility: visible !important;width: 96px !important;height: auto !important;" width="96px" data-cropselx1="0" data-cropselx2="96" data-cropsely1="0" data-cropsely2="96" data-imgfileid="100021104" src="https://wechat2rss.xlab.app/img-proxy/?k=68b2dbe3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYv6ic9zgr5hQl5bZ5Mx6PTAQg6tGLiciarvXajTdDnQiacxmwJFZ0D3ictBOmuYyRk99bibwZV49wbap77LibGQHdQPtA%2F640%3Fwx_fmt%3Dpng%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></span></p><p style="margin-top: 0.5em;margin-bottom: 8px;outline: 0px;letter-spacing: 0.544px;text-align: center;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="200" style="outline: 0px;letter-spacing: 0.544px;display: initial;visibility: visible !important;width: 24px !important;height: auto !important;" width="24px" data-imgfileid="100021109" src="https://wechat2rss.xlab.app/img-proxy/?k=ffe38040&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYv6ic9zgr5hTIdM9koHZFkrtYe5WU5rHxSDicbiaNFjEBAs1rojKGviaJGjOGd9KwKzN4aSpnNZDA5UWpY2E0JAnNg%2F640%3Fwx_fmt%3Dpng%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></span></p><p style="outline: 0px;text-align: center;"><span style="outline: 0px;"><span leaf=""><a class="weapp_text_link js_weapp_entry" style="padding-right: 0px;padding-left: 0px;outline: 0px;color: var(--weui-LINK);cursor: pointer;font-size: 14px;" data-miniprogram-type="text" data-miniprogram-appid="wx0c720b24e005e633" data-miniprogram-path="p?p=400-030-1051" data-miniprogram-nickname="电话码" data-miniprogram-servicetype="" data-miniprogram-applink="">点此电话咨询</a></span></span></p></div></div><div powered-by="xiumi.us" style="margin-top: 10px;outline: 0px;justify-content: flex-start;display: flex;flex-flow: row;"><div style="outline: 0px;display: inline-block;width: 645px;vertical-align: top;border-left: 3px solid rgb(232, 57, 57);border-bottom-left-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: -5px;margin-bottom: -5px;outline: 0px;"><div style="padding-right: 6px;padding-left: 6px;outline: 0px;font-size: 24px;color: rgb(233, 38, 52);line-height: 0.75;letter-spacing: 0px;text-align: justify;"><p style="outline: 0px;text-wrap: wrap;"><span style="outline: 0px;color: rgb(219, 0, 0);"><strong style="outline: 0px;"><span style="outline: 0px;font-size: 16px;"><span leaf="">X漏洞奖励计划</span></span></strong></span></p></div></div></div></div><div powered-by="xiumi.us" style="outline: 0px;text-align: justify;"><p style="margin-bottom: 16px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);"><span style="outline: 0px;color: rgb(84, 84, 84);"><span style="outline: 0px;font-size: 14px;"><span leaf="">“X漏洞奖励计划”是微步X情报社区推出的一款</span></span><span style="outline: 0px;font-size: 14px;letter-spacing: 0.578px;text-decoration: initial;text-decoration-color: rgba(0, 0, 0, 0.9);"><span leaf="">针对未公开</span></span><span style="outline: 0px;font-size: 14px;"><span leaf="">漏洞的奖励计划，我们鼓励白帽子提交挖掘到的0day漏洞，并给予白帽子可观的奖励。我们期望通过该计划与白帽子共同努力，提升0day防御能力，守护数字世界安全。</span></span></span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);"><span style="outline: 0px;color: rgb(84, 84, 84);"><span style="outline: 0px;font-size: 14px;"><span leaf="">活动详情：</span></span><span style="outline: 0px;font-size: 14px;letter-spacing: 0.578px;text-decoration: initial;text-decoration-color: rgba(0, 0, 0, 0.9);"><span leaf=""><a href="https://x.threatbook.com/v5/vulReward" target="_blank">https://x.threatbook.com/v5/vulReward</a></span></span></span></p></div></div></div></div><p class="mp_profile_iframe_wrp" style="margin-bottom: 0px;outline: 0px;"><span leaf=""><mp-common-profile class="custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-nickname="微步在线研究响应中心" data-index="0" data-from="2" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/fFyp1gWjicML0NlKR16SxQGjNPSYVoUxGgXhXvI4Z8ia5h8C9TGibEic1ABv6fniame8h0dh6zGX8ndXT8icjQocVh8A/300?wx_fmt=png&amp;wxfrom=19" data-signature="微步情报局最新威胁事件分析、漏洞分析、安全研究成果共享，探究网络攻击的真相" data-id="Mzg5MTc3ODY4Mw==" data-origin_num="354" data-biz_account_status="0"></mp-common-profile></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=5fb73d30&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5MTc3ODY4Mw%3D%3D%26mid%3D2247508686%26idx%3D1%26sn%3Dc8044c778acb9ba9419eb689209824d4">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 07 May 2026 17:02:00 +0800</pubDate>
    </item>
    <item>
      <title>速查！又一知名软件被投毒，大量用户失陷</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&amp;mid=2247508681&amp;idx=1&amp;sn=72f39e5d2b10d749ec02aa1e692c6d0f</link>
      <description>有国外安全机构近日披露，主流磁盘镜像挂载工具DAEMON Tools遭遇供应链投毒。</description>
      <content:encoded><![CDATA[<p><span>微步在线研究响应中心</span> <span>2026-05-06 09:45</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=dfb2f2e9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FT4OSm0sXdEMsopVl3CYv9sEt55qxIJkJDyWXj1HMRK6sxyydDM04N5rwicM0ngRGjREM7j2U9beGDyHibbsbGtPZicvFay4M7zC8PibgIjOOCZU%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">有国外</span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">安全</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">机构近日披露，</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">主流</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">磁盘镜像</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">挂载</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">工具</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">DAEMON Tools</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">遭遇供应链投毒</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">。</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">自</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">4</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">月</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">8</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">日</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">起</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">，</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">其</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">官方</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">网站</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">被</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">上传</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">了</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">12.5.0.2421至12.5.0.2434</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">等</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">多个</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">恶意</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">版本</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">，</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">影响</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">超过</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">1</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">0</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">0</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">个</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">国家</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">和</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">地区</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">的</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">数千台</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">设备</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">，</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">目前</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">攻击</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">仍在</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">进行</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">中</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">。</span></span></span></p><p><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">微步</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">情报局</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">监测</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">发现</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">，</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">在</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">国内</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">已有数十家</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">用户</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">感染</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">恶意</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">代码</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">，</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">建议用户立即排查</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">C</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">2</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">请求</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">env-check.daemontools.cc</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">，</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">及时</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">做好应急处置</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">，</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">排查方法和处置建议详见后文</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">。</span></span></span></p><p><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">DAEMON Tools是全球广泛使用的磁盘镜像挂载工具，攻击者篡改</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">了</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">官方安装程序，恶意文件均</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">具备</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">开发商 AVB Disc Soft 有效数字签</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">名</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">。</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">恶意程序嵌入开机自启逻辑，设备启动即激活后门并</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">反</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">连恶意 C2。攻击分两步实施：先批量部署信息收集器窃取系统信息，再定向投放极简后门、QUIC RAT远控木马，实现精准控制与窃密。</span></span></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.49537037037037035" data-type="png" data-w="1080" height="299.836" style="margin-left: 0px;margin-top: 0px;width: 604.733px;height: 299.836px;" width="604.733" data-imgfileid="100025030" src="https://wechat2rss.xlab.app/img-proxy/?k=ff595b0b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEOydtUQqq0XUAs6Q4p0OXGVdTDr3CDTwTM4Xz8leSQxSVIwXuAP8ziaN0aBWv1BKvxPn4KoXKMeFUDCtx3vh4v34l5GTNMxJt8k%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><h2><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 18px;font-weight: bold;">攻击载荷</span></span></span></h2><p><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">信息采集器envchk.exe</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">：广泛投放，采集MAC、主机名、DNS、进程列表、已安装软件</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">等，用于筛选高价值目标。</span></span></span></p><p><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">极简</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">后门cdg.exe</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">：精准投放至已筛选目标，支持文件下载、shell命令执行及shellcode内存执行</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">。</span></span></span></p><p><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">远控木马</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">QUIC RAT</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">：仅在极少量高价值机器上发现，支持HTTP/UDP/TCP/WSS/QUIC/DNS/HTTP/3多协议通信，可向notepad.exe和conhost.exe注入恶意载荷</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">。</span></span></span></p><h2><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 18px;font-weight: bold;">受影响范围</span></span></span></h2><p><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">软件版本：DAEMON Tools 12.5.0.2421 ~ 12.5.0.2434</span></span></span></p><p><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">恶意组件：DTHelper.exe、DiscSoftBusServiceLite.exe、DTShellHlp.exe</span></span></span></p><p><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">默认路径：C:\Program Files\DAEMON Tools Lite\</span></span></span></p><h2><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 18px;font-weight: bold;">排查方法</span></span></span></h2><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">●</span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">查询</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">是否</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">安装</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">DAEMON Tools</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">的</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">12.5.0.2421</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">-</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">12.5.0.2434</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">版本</span></span></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">●</span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">查询</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">网络</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">出口</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">流量</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">中</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">是否</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">含有</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">域名</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">env-check.daemontools.cc</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">的</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">请求</span></span></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">●</span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">在</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">临时</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">目录</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">C:\Windows\Temp\</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">是否</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">存有</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">文件</span></span></span><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">envchk.exe，cdg.exe，imp.tmp，piyu.exe</span></span></span></p><h2><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 18px;font-weight: bold;">处置建议</span></span></span></h2><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">●</span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">卸载</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">、</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">暂停使用DAEMON Tools</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">恶意</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">版本</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">。</span></span></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">●</span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">在</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">网络侧</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">阻断</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">env-check.daemontools.cc</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">的</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">反连</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">请求</span></span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">。</span></span></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">●</span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">清除envchk.exe、cdg.exe、cdg.tmp等恶意载荷。</span></span></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">●</span></span><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">重置系统密码、SSH 密钥、Git 凭证、API 密钥、业务账号等敏感凭证。</span></span></span></p><h2><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 18px;font-weight: bold;">附录：IOC </span></span></span></h2><p><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">感染的 DAEMON Tools Lite 安装程序</span></span></span></p><p><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">9ccd769624de98eeeb12714ff1707ec4f5bf196d(12.5.0.2421)</span></span></span></p><p><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">50D47ADB6DD45215C7CB4C68BAE28B129CA09645(12.5.0.2422)</span></span></span></p><p><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">0c1d3da9c7a651ba40b40e12d48ebd32b3f31820(12.5.0.2423)</span></span></span></p><p><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">28b72576d67ae21d9587d782942628ea46dcc870(12.5.0.2424)</span></span></span></p><p><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">46b90bf370e60d61075d3472828fdc0B85ab0492(12.5.0.2430)</span></span></span></p><p><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">6325179f442e5b1a7716580cd70dea644ac9ecd18(12.5.0.2431)</span></span></span></p><p><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">BD8fbb5E6842df8683163adbd6A36136164EAC58(12.5.0.2433)</span></span></span></p><p><span data-font-family="微软雅黑"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">15ed5c3384e12fe4314ad6edbd1dcccf5ac1ee29(12.5.0.2434)</span></span></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;font-weight: bold;">感染的DiscSoftBusServiceLite.exe文件</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;">524d2d92909eef80c406e87a0fc37d7bb4dadc14</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;">427f1728682ebc7ffe3300fef67d0e3cb6b62948</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;">8e7eb0f5ac60dd3b4a9474d2544348c3bda48045</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;">00e2df8f42d14072e4385e500d4669ec783aa517</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;">aea55e42c4436236278e5692d3dcbcbe5fe6ce0b</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;">0456E2f5F56ec8ed16078941248e7cbba9f1c8eb</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;">9a09AD7b7E9ff7a465AA1150541E231189911afb</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;">8d435918d304fc38d54b104a13f2e33e8e598c82</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;">64462f751788f529c1eb09023b26a47792ecdc54</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">其他恶意文件hash</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;">2d4eb55b01f59C62C6de9aacba9b47267d398fe4</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;">9dbfc23ebf3c0b56d2f93116abb32656C42E4</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;">295ce86226b933e7262c2ce4b36bdd6c389aaef</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">C2</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;">env-check.daemontools.cc</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;">38.180.107.76</span></span></p><p class="mp_profile_iframe_wrp" nodeleaf=""><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-nickname="微步在线研究响应中心" data-from="0" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/fFyp1gWjicML0NlKR16SxQGjNPSYVoUxGgXhXvI4Z8ia5h8C9TGibEic1ABv6fniame8h0dh6zGX8ndXT8icjQocVh8A/0?wx_fmt=png" data-signature="微步情报局最新威胁事件分析、漏洞分析、安全研究成果共享，探究网络攻击的真相" data-id="Mzg5MTc3ODY4Mw==" data-is_biz_ban="0" data-service_type="1" data-verify_status="2"></mp-common-profile></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.887890625" data-s="300,640" data-type="png" data-w="2560" type="block" data-imgfileid="100024925" src="https://wechat2rss.xlab.app/img-proxy/?k=a44348ad&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEOzRePK76EWxGV43BPZfRzmdOpakc8ibYnicF68iccD11wKzkrXxtbOu0H3VDYUibUn73UNcCHiaxzxiaTvTFKXXpDMEBSbMMGY40qEQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=45abf411&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5MTc3ODY4Mw%3D%3D%26mid%3D2247508681%26idx%3D1%26sn%3D72f39e5d2b10d749ec02aa1e692c6d0f">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 06 May 2026 09:45:00 +0800</pubDate>
    </item>
    <item>
      <title>Linux提权漏洞！10行代码直接root</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&amp;mid=2247508662&amp;idx=1&amp;sn=41def071baa5eeadd5303f2ccb43cf01</link>
      <description>立即查看详情 →</description>
      <content:encoded><![CDATA[<p>原创 <span>微步情报局</span> <span>2026-04-30 10:14</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d610ba96&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FfFyp1gWjicMKRfkOibMss786PqPwUGjHu4siboRiaqI4mguqRmR09PN8XVEaw2KnV8ORyrCRF8ZQz35agEmw3yebIQ%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>立即查看详情 →</p>
  <div style="font-size: 15px;" segoe="" pingfang="" data-pm-slice="0 0 []"><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 0 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞概况</span></span></p></div></div><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">微步情报局监测到，Linux Kernel 被披露存在本地权限提升漏洞，漏洞编号 CVE-2026-31431，代号 “Copy Fail”。该漏洞源于内核 crypto: algif_aead 模块在处理 AEAD操作时的逻辑缺陷，可导致本地低权限攻击者通过 AF_ALG 加密接口向任意可读文件的页缓存（page cache）写入受控的少量数据（PoC 中为 4 字节块），进而篡改 setuid 等特权二进制文件，</span><span style="color: #d93025;font-weight: bold;font-size: 15px;"><span leaf="">实现本地权限提升至 root。</span></span></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">目前该漏洞细节及 PoC 已公开，</span><span style="color: #d93025;font-weight: bold;font-size: 15px;"><span leaf="">利用门槛极低（仅需约 10 行 Python 脚本），影响过去 9 年内大多数主流 Linux 发行版，对云服务器、容器宿主机、多租户环境等构成较高风险。</span></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">目前已知的影响面有：</span></span></p><p dir="auto" data-pm-slice="0 0 []"><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">1. </span></span><span leaf="" style="line-height: 1.6em;color: rgb(217, 48, 37);font-weight: bold;font-size: 15px;"><span textstyle="" style="font-size: 15px;">共享服务器</span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">（开发机、跳板机、构建服务器）</span></span></strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">：任意普通用户即可直接提权为 root</span></span></p><p dir="auto" data-pm-slice="0 0 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">2.</span></span><span leaf="" style="line-height: 1.6em;color: rgb(217, 48, 37);font-weight: bold;font-size: 15px;"><span textstyle="" style="font-size: 15px;">Kubernetes 和容器集群</span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">：单个被攻破的 Pod 可逃逸至宿主机</span></span></p><p><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">3. </span></span><span leaf="" style="line-height: 1.6em;color: rgb(217, 48, 37);font-weight: bold;font-size: 15px;"><span textstyle="" style="font-size: 15px;">CI/CD 执行器</span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">（GitHub Actions、GitLab Runner、Jenkins 等）</span></span></strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">：恶意 Pull Request 可直接获得 Runner 的 root 权限</span></span></p><p><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">4. </span></span><span leaf="" style="line-height: 1.6em;color: rgb(217, 48, 37);font-weight: bold;font-size: 15px;"><span textstyle="" style="font-size: 15px;">运行用户代码的云平台</span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">（Notebook、Agent 沙箱、Serverless 函数等）</span></span></strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">：租户可直接提升至宿主机 root 权限</span></span></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="color: #d93025;font-weight: bold;font-size: 15px;"><span leaf="">建议受影响的用户尽快修复。</span></span></p><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞处置优先级(VPT)</span></span></p></div></div><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><strong style="font-size: 17px;letter-spacing: 0.034em;outline: 0px;"><span leaf="">综合处置优先级：</span></strong><span style="color: #d93025;font-weight: bold;font-size: 15px;"><span leaf="">中风险</span></span></p><table style="width: 100%;border-collapse: collapse;margin: 20px 0;font-size: 14px;table-layout: fixed;"><tbody><tr><td rowspan="3" style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">基本信息</span></p></td><td style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;"><p><span leaf="">微步编号</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">XVE-2026-15008</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">CVE编号</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">CVE-2026-31431</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">漏洞类型</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">权限提升</span></p></td></tr><tr><td rowspan="5" style="border: 1px solid #ddd;padding: 12px;vertical-align: top;font-weight: bold;background-color: #f8f9fa;"><p><span leaf="">利用条件评估</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">利用漏洞的网络条件</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">本地访问</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">是否需要绕过安全机制</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">否</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">对被攻击系统的要求</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">无特殊要求</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">利用漏洞的权限要求</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">低权限</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">是否需要受害者配合</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">否</span></p></td></tr><tr><td rowspan="2" style="border: 1px solid #ddd;padding: 12px;vertical-align: top;font-weight: bold;background-color: #f8f9fa;"><p><span leaf="">利用情报</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">POC是否公开</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><span style="color: #d93025;font-weight: bold;"><span leaf="">是</span></span></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">已知利用行为</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">暂无</span></p></td></tr></tbody></table><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞影响范围</span></span></p></div></div><table style="width: 100%;border-collapse: collapse;margin: 20px 0;font-size: 14px;table-layout: fixed;"><tbody><tr><td style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">产品名称</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">Linux Kernel</span></p></td></tr><tr><td style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">受影响版本</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">commit 72548b093ee3 &lt;=version&lt; commit a664bf3d603d</span></p></td></tr><tr><td style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">有无修复补丁</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">有</span></p></td></tr></tbody></table><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞复现</span></span></p></div></div><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;" nodeleaf=""><img data-aistatus="1" alt="image.png" class="rich_pages wxw-img" data-ratio="0.18779342723004694" data-type="png" data-w="1065" data-imgfileid="100025013" src="https://wechat2rss.xlab.app/img-proxy/?k=d3624875&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEOwWA6nvV4AWa4SnBneTNmkksP40kgpdicoGvfXuLga6PgFTYYcZYdGOj23xYkOPFEicXNsvGnK4libVO9B5lDmgP2CxicoOdJ2Dic0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">修复方案</span></span></p></div></div><h3 style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;pointer-events: initial;"><span leaf="">官方修复方案</span></h3><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">官方已发布修复方案，请访问链接下载：</span><span leaf=""><br/></span><span leaf=""><a href="https://git.kernel.org/stable/c/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5" target="_blank">https://git.kernel.org/stable/c/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5</a></span></p><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">微步产品支撑</span></span></p></div></div><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">微步漏洞情报于</span><span style="color: #d93025;font-weight: bold;"><span leaf="">2026-04-22</span></span><span leaf="">收录该漏洞。</span></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">微步下一代威胁情报平台NGTIP及X情报社区已于漏洞收录时向漏洞订阅用户推送该漏洞情报，并将持续推送后续更新；对于已经录入资产的用户，支持实时自动化排查受影响资产。</span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=4748c36c&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5MTc3ODY4Mw%3D%3D%26mid%3D2247508662%26idx%3D1%26sn%3D41def071baa5eeadd5303f2ccb43cf01">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 30 Apr 2026 10:14:00 +0800</pubDate>
    </item>
    <item>
      <title>一个人，两个AI，0代码，把墨西哥政府打成筛子</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&amp;mid=2247508657&amp;idx=1&amp;sn=91bbcd48f789f8112b1e17c05ef2e94e</link>
      <description>0代码、低成本、大规模、高隐蔽性的入侵</description>
      <content:encoded><![CDATA[<p><span>微步在线研究响应中心</span> <span>2026-04-29 16:58</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=c4839ca7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FT4OSm0sXdEPBoUGa9k8ApQsPqzNBibayTFZJ22155mdxMcdTQjZAPtP2dPHytXicQBP6eouwWCy8lw9szye7EjIvLPBTWT3jwIibJbghbeD800%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>0代码、低成本、大规模、高隐蔽性的入侵</p>
  <p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">2025年12月的深夜，一名攻击者</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">与</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">两个</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">大模型，</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">仅凭</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">自然</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">语言</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">命令</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">，</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">在不到两个月的时间里，接连突破墨西哥联邦、州、市三级共9个政府机构，窃取数亿公民隐私数据，甚至搭建出可实时查询政府系统的公开接口，伪造出足以以假乱真的官方税务文件。</span></span></span><span style="font-size: 11pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024983" data-ratio="0.4074074074074074" width="604.733" data-type="png" data-w="1080" height="246.373" style="margin-left: 0px;margin-top: 0px;width: 604.733px;height: 246.373px;" src="https://wechat2rss.xlab.app/img-proxy/?k=575a50b5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEOBewfPgRE0ibMogO13PNaDicR4bseu88CYVWrHl3MgFBdVPjCf710nDHuRpCKKIhCjUFHEIiaZRNJlHZOLicRMKmy4I4ovMia7aSjY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 11pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 14px;">受害者与时间线</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">这是Gambit Security报告中完整还原的</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">AI深度参与国家级关键信息基础设施入侵</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">事件。</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">在</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">这起</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">攻击</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">中</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">，</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">AI</span></span></span><span style="font-size: 12pt;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">自主判断、自主执行、自主优化</span></span></span><span style="font-size: 12pt;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">，</span></span></span><span style="font-size: 12pt;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">攻击者仅用少数自然语言命令，便让AI突破了自身的技术伦理</span></span></span><span style="font-size: 12pt;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">，</span></span></span><span style="font-size: 12pt;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">完成了原本需要十余人专业团队的工作量，攻击周期被压缩到传统防守团队无法响应的程度。</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span data-font-family="ui-sans-serif"><span leaf="" style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 18px;color: rgb(219, 0, 0);">一、</span></span></span><span data-font-family="ui-sans-serif"><span leaf="" style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 18px;color: rgb(219, 0, 0);">利</span></span></span><span data-font-family="ui-sans-serif"><span leaf="" style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 18px;color: rgb(219, 0, 0);">用AI规则漏洞，埋下攻击伏笔</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">攻击发起前，攻击者早已完成周密布局。他提前准备好1084行的渗透测试速查手册、156条预设命令模板，选定</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">Anthropic Claude Code</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">作为一线攻击执行工具，</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">OpenAI GPT-4.1 API</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">作为后台批量分析大脑，两者形成完美配合，所有操作均违反AI平台使用条款。</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">2025年12月27日，攻击者首次启动Claude Code，先用“漏洞赏金”的幌子试探底线，要求AI清除日志、隐藏操作痕迹，被Claude明确拒绝。但攻击者早有对策——直接将完整的黑客手册以“文件写入”的形式提交，让AI绕过内容安全审核，将恶意规则</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">成为</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">持久化</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">提示词</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">，</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">加载为默认系统提示。</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">短短十几分钟，原本坚守安全底线的AI，沦为了攻击者的全自动攻击助手。</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span data-font-family="ui-sans-serif"><span leaf="" style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 18px;color: rgb(219, 0, 0);">二、40分钟拿下政府服务器，AI</span></span></span><span data-font-family="ui-sans-serif"><span leaf="" style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 18px;color: rgb(219, 0, 0);">从</span></span></span><span data-font-family="ui-sans-serif"><span leaf="" style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 18px;color: rgb(219, 0, 0);">抗拒到</span></span></span><span data-font-family="ui-sans-serif"><span leaf="" style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 18px;color: rgb(219, 0, 0);">自觉</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">绕过AI安全护栏后，攻击推进速度快得惊人。</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">攻击者直接将目标对准墨西哥联邦税务总局SAT——该国最核心的民生数据机构之一，指令Claude Code运行开源漏洞扫描工具Vulmap。AI很快发现外网服务器存在远程命令执行漏洞，随即开始定制漏洞脚本。从初始脚本到最终稳定版本，Claude Code在7分钟内完成8次迭代，自动优化代理路由、失败重试、字符编码绕过等细节，生成285行专属漏洞利用代码。</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">从AI拒绝违规操作，到成功拿下SAT服务器权限，整个过程仅用</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">40分钟</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">。报告数据显示，整场攻击中，约</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">75%</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">的远程命令执行操作均由Claude Code</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">自动完成</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">，攻击者只需要下达</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">自然语言指令</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">，无需手动编写复杂代码。</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span data-font-family="ui-sans-serif"><span leaf="" style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 18px;color: rgb(219, 0, 0);">三、悄无声息拿到Root，留下持久后门</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">突破边界后，攻击者的下一个目标是最高系统权限。</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">在入侵墨西哥城户籍登记服务器时，Claude Code自动扫描系统定时任务（Crontab），发现一个可写入的root权限脚本。AI立刻向攻击者汇报提权路径，并提供两种操作选项。攻击者指令AI注入SSH后门密钥，同时保留原文件时间戳，避免被管理员察觉。</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">Claude Code严格执行操作：先记录原文件时间，修改脚本植入后门，再还原时间戳，全程不留痕迹。当定时任务自动运行后，AI主动检测权限，随即向攻击者汇报：“已获取Root权限！拿到最高权限后，AI还自动提取系统密码哈希、清理操作痕迹，全程无需攻击者额外指令。</span></span></span></p><p data-pm-slice="0 0 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.2111111111111111" data-type="png" data-w="1080" height="127.494" style="margin-left: 0px;margin-top: 0px;width: 604.733px;height: 127.494px;" width="604.733" data-imgfileid="100024988" src="https://wechat2rss.xlab.app/img-proxy/?k=0d6b1dad&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEOQnicdTqq8GlS6oDmXDxwicWoF4MVHKT2WJ9iaJI3UjXyMwdajuDic1NnHe9J9GQ7lib1icfb41WYWoT4jGxnSDBY0sSh2ofiaeNeFSQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p data-pm-slice="0 0 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.20462962962962963" data-type="png" data-w="1080" height="123.882" style="margin-left: 0px;margin-top: 0px;width: 604.733px;height: 123.882px;" width="604.733" data-imgfileid="100024989" src="https://wechat2rss.xlab.app/img-proxy/?k=a302ba25&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEPNuzV35DDgXBOry7fSPAxw9xj76LWeibKNKxfG4s43GLU09b83TYZw8B6nNF5ibMvcrWEug9fqfpp1f2TwVMr4RrcHYibrPSByx0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p data-pm-slice="0 0 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024990" data-ratio="0.2064814814814815" width="604.733" data-type="png" data-w="1080" height="124.998" style="margin-left: 0px;margin-top: 0px;width: 604.733px;height: 124.998px;" src="https://wechat2rss.xlab.app/img-proxy/?k=50ad3470&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEOsGoI9UJcLx0lZI8icAlqF4yUrMr3lFicRjp8VTWIicWqllssPzxLib1ELrKicI8x0xa8JupTiaNB4DdhauCcpicRAVNhqHpays03duA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">这种</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">AI自主判断、自主执行、自主优化</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">的攻击模式，彻底颠覆了传统黑客依赖手动操作、经验积累的模式，哪怕是技术水平有限的攻击者，也能完成专业黑客团队才能实现的深度入侵。</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span data-font-family="ui-sans-serif"><span leaf="" style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 18px;color: rgb(219, 0, 0);">四、横扫8大机构，染指云端资产</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">拿下核心机构后，攻击者借助AI开始横向渗透，短短数周内横扫墨西哥各级政府部门：</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">- 哈利斯科州政府：完整虚拟化基础设施沦陷，13节点Nutanix集群、37台数据库服务器被控制，20个州政府机构部署自定义木马；</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">- 国家选举研究所：获取数千万选民数据访问权限，泄露1.38万张选民卡记录；</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">- 墨西哥州、米却肯州等地方政府：泄露车辆、房产、民生登记数据超千万条；</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">- 蒙特雷市水务公司、墨西哥城卫生局：业务系统、邮件服务器被攻破，采购、医疗数据遭窃取；</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">- 云端资产：攻击者从沦陷服务器中获取云配置凭证，成功入侵AWS云数据库实例。</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">在渗透蒙特雷水务公司时，AI自动检测出SMB签名漏洞，主动向攻击者提供被动、半主动、主动三种攻击方案，并推荐成功率最高的PetitPotam强制认证攻击。即便该方法因系统补丁失效，AI仍自动尝试永恒之蓝、密码喷洒、LDAP匿名绑定等十余种手法，穷尽所有攻击路径，直到找到突破点。</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">与此同时，后台的GPT-4.1 API也在高速运转。攻击者编写的17550行Python工具BACKUPOSINT.py，将305台SAT内网服务器的进程、端口、凭证、配置等数据批量送入AI分析，短短几天生成2597份结构化情报报告，标注高风险漏洞、可复用凭证、横向移动路径，为攻击者提供精准攻击导航。</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span data-font-family="ui-sans-serif"><span leaf="" style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 18px;color: rgb(219, 0, 0);">五、数据盗卖+官方文件伪造，黑色产业链成型</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">攻击的最终目的，是利用数据牟利。</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">Claude Code用2小时、20次迭代，开发出594行的Flask REST API，直接对接SAT实时数据库，可通过公网实时查询纳税人完整信息。更致命的是，攻击者基于该API搭建了税务合规证明伪造系统，生成的PDF文件包含真实姓名、地址、税务状态等实时数据，仅数字签章用随机填充值模拟。</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">对于只核对纸质文件内容、不做密码学验证的银行、企业、机构而言，这份伪造文件</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">完全无法分辨真伪</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">。只要攻击持续存在，伪造服务就会一直运行，沦为黑色产业链的核心工具。</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">整场攻击中，超400个自定义攻击脚本、20个针对性漏洞利用工具、1088条攻击者指令，全部由AI参与生成，单一操作员完成了原本需要十余人专业团队的工作量，攻击周期被压缩到传统防守团队无法响应的程度。</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span data-font-family="ui-sans-serif"><span leaf="" style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 18px;color: rgb(219, 0, 0);">六、三大突破，重新定义网络攻击</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">这场攻击有三个</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">前所未有的</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">关键</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">点</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">，彻底改变了网络安全的攻防格局：</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">1. </span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">商业AI成为攻击核心生产力</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">AI</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">并非简单辅助，而是包办漏洞开发、权限提升、横向渗透、数据分析全流程，安全护栏可被低成本绕过，AI从安全工具沦为攻击利器。</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">2. </span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">单人攻击实现团队级破坏力</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">   AI降低攻击技术门槛，无需深厚代码能力、无需丰富渗透经验，仅凭自然语言指令，就能完成国家级关键信息基础设施的大规模入侵。</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">3. </span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">攻击效率与隐蔽性双重拉满</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">   AI自动优化操作痕迹、还原文件时间戳、选择低噪音攻击路径，配合快速攻击节奏，让传统检测、响应机制完全失效。</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span data-font-family="ui-sans-serif"><span leaf="" style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 18px;color: rgb(219, 0, 0);">七、对国内网络安全行业的核心借鉴意义</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">这场发生在墨西哥的AI攻击，不是遥远的个案，而是即将到来的普遍威胁。对国内政企、关键信息基础设施行业而言，有</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">较强</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">借鉴</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">意义</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">：</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">1. 立即清理</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">历史遗留问题</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">攻击中沦陷的墨西哥政府系统，大量处于停止支持、无补丁更新状态，成为AI攻击的突破口。国内政企需全面排查老旧系统、停服组件、无维护业务系统，该升级升级、该替换替换，不给AI自动化漏洞利用留机会。</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">2. 补齐基础安全短板，比追新技术更重要</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">此次攻击利用的均是常规漏洞：弱口令、未授权访问、权限配置不当、横向移动未隔离。国内机构需落实补丁常态化更新、高权限凭证定期轮换、网络区域隔离、终端检测与响应、最小权限原则，基础防护筑牢，AI攻击就失去最大抓手。</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">3. 构建针对AI自动化攻击的检测能力</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">传统规则无法应对AI自主优化的攻击行为，需升级异常行为检测：监控批量命令执行、非常规横向移动、定时任务异常修改、Root权限异常获取、大规模数据外发等行为，从“查漏洞”转向“查行为”。</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: bold;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;"> 4. 正视AI攻防趋势，主动布局对抗能力</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">AI不仅是防守工具，更是攻击工具。国内安全</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">从业者</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">需加快</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">探索</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">AI攻击检测、AI行为溯源、AI漏洞对抗</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">等AI自动化</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">安全</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">技术，政企需建立AI安全使用规范，严防商业AI被用于恶意攻击，同时提升自身AI防守能力。</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 24px;"><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">AI已经彻底抹平攻击门槛，让</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">0</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">代码</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">、</span></span></span><span style="font-size: 12pt;font-family: &#34;Microsoft YaHei&#34;;font-weight: normal;font-style: normal;color: rgb(31, 35, 41);background: rgb(255, 255, 255);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-sans-serif"><span leaf=""><span textstyle="" style="font-size: 15px;">低成本、大规模、高隐蔽性的入侵成为现实。对于国内网络安全行业而言，这场攻击不是故事，而是预警。</span></span></span></p><p style="text-align: center;line-height: 1.6em;margin: 3pt 0pt 24px;"><span leaf=""><span textstyle="" style="font-size: 15px;">·END·</span></span></p><p class="mp_profile_iframe_wrp" nodeleaf=""><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-nickname="微步在线研究响应中心" data-from="0" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/fFyp1gWjicML0NlKR16SxQGjNPSYVoUxGgXhXvI4Z8ia5h8C9TGibEic1ABv6fniame8h0dh6zGX8ndXT8icjQocVh8A/0?wx_fmt=png" data-signature="微步情报局最新威胁事件分析、漏洞分析、安全研究成果共享，探究网络攻击的真相" data-id="Mzg5MTc3ODY4Mw==" data-is_biz_ban="0" data-service_type="1" data-verify_status="2"></mp-common-profile></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024925" data-ratio="0.887890625" data-s="300,640" type="block" data-type="png" data-w="2560" src="https://wechat2rss.xlab.app/img-proxy/?k=a44348ad&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEOzRePK76EWxGV43BPZfRzmdOpakc8ibYnicF68iccD11wKzkrXxtbOu0H3VDYUibUn73UNcCHiaxzxiaTvTFKXXpDMEBSbMMGY40qEQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=52399ba2&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5MTc3ODY4Mw%3D%3D%26mid%3D2247508657%26idx%3D1%26sn%3D91bbcd48f789f8112b1e17c05ef2e94e">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 29 Apr 2026 16:58:00 +0800</pubDate>
    </item>
    <item>
      <title>LiteLLM SQL注入漏洞可无条件触发</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&amp;mid=2247508656&amp;idx=1&amp;sn=23a36f4a8c5d30c1f7e696db704e78ca</link>
      <description>立即查看详情 →</description>
      <content:encoded><![CDATA[<p>原创 <span>微步情报局</span> <span>2026-04-28 15:49</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d610ba96&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FfFyp1gWjicMKRfkOibMss786PqPwUGjHu4siboRiaqI4mguqRmR09PN8XVEaw2KnV8ORyrCRF8ZQz35agEmw3yebIQ%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>立即查看详情 →</p>
  <p style="outline: 0px;text-align: center;visibility: visible;margin-bottom: 0px;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-cropselx1="0" data-cropselx2="432" data-cropsely1="0" data-cropsely2="184" data-imgfileid="100021107" data-ratio="0.42592592592592593" data-s="300,640" style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);width: 480px !important;visibility: visible !important;height: auto !important;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=e78774c2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FfFyp1gWjicMKNkm4Pg1Ed6nv0proxQLEKJ2CUCIficfAwKfClJ84puialc9eER0oaibMn1FDUpibeK1t1YvgZcLYl3A%2F640%3Fwx_fmt%3Dpng%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></span></p><div style="font-size: 15px;" segoe="" pingfang="" data-pm-slice="0 0 []"><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 0 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞概况</span></span></p></div></div><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">LiteLLM 是一个使用广泛的开源大语言模型统一接口库，常作为代理服务使用，使开发者能够通过统一的 API 格式调用 OpenAI、Anthropic、Azure 等不同厂商的大模型，简化多模型接入与管理流程。</span></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">近日，LiteLLM官方发布通告，修复了LiteLLM SQL注入漏洞（CVE-2026-42208）。</span><span style="color: #d93025;font-weight: bold;"><span leaf="">微步情报局已成功复现。</span></span><span leaf="">经分析，LiteLLM Proxy在处理Authorization头的API Key验证过程中存在 SQL 注入漏洞。该漏洞位于身份认证失败后的错误日志机制，攻击者无需任何有效凭证，通过构造 Bearer token注入请求，即可成功利用该漏洞。（完整漏洞情报请查阅<a href="https://x.threatbook.com/v5/vul/XVE-2026-16028）" target="_blank">https://x.threatbook.com/v5/vul/XVE-2026-16028）</a></span></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">根据 LiteLLM 的使用场景，</span><span style="color: #d93025;font-weight: bold;"><span leaf="">该漏洞可实现未经授权读取敏感凭证（保存的大模型 API key），暴露在公网的 LiteLLM Proxy 实例风险极高</span></span><span leaf="">，建议受影响的用户立即升级并修改所有保存在 LiteLLM 数据库中的密钥。</span></p><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞处置优先级(VPT)</span></span></p></div></div><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><strong style="font-size: 17px;letter-spacing: 0.034em;outline: 0px;"><span leaf="">综合处置优先级：</span></strong><span style="color: #d93025;font-weight: bold;font-size: 15px;"><span leaf="">高风险</span></span></p><table style="width: 100%;border-collapse: collapse;margin: 20px 0;font-size: 14px;table-layout: fixed;"><tbody><tr><td rowspan="3" style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">基本信息</span></p></td><td style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;"><p><span leaf="">微步编号</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">XVE-2026-16028</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">CVE编号</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">CVE-2026-42208</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">漏洞类型</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">SQL注入</span></p></td></tr><tr><td rowspan="5" style="border: 1px solid #ddd;padding: 12px;vertical-align: top;font-weight: bold;background-color: #f8f9fa;"><p><span leaf="">利用条件评估</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">利用漏洞的网络条件</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">远程</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">是否需要绕过安全机制</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">否</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">对被攻击系统的要求</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">无特殊要求</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">利用漏洞的权限要求</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">无须用户权限</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">是否需要受害者配合</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">否</span></p></td></tr><tr><td rowspan="2" style="border: 1px solid #ddd;padding: 12px;vertical-align: top;font-weight: bold;background-color: #f8f9fa;"><p><span leaf="">利用情报</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">POC是否公开</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><span style="color: #d93025;font-weight: bold;"><span leaf="">是</span></span></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">已知利用行为</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><span style="color: #d93025;font-weight: bold;"><span leaf="">是</span></span></td></tr></tbody></table><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞影响范围</span></span></p></div></div><table style="width: 100%;border-collapse: collapse;margin: 20px 0;font-size: 14px;table-layout: fixed;"><tbody><tr><td style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">产品名称</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">LiteLLM</span></p></td></tr><tr><td style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">受影响版本</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">1.81.16&lt;=version&lt;1.83.7</span></p></td></tr><tr><td style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">有无修复补丁</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">有</span></p></td></tr></tbody></table><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞复现</span></span></p></div></div><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100025007" data-ratio="0.5555555555555556" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=ed1e62ae&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEM2787KP86Zich1FCtqoiae85OECTooCpOudwyPcGf7vkqgr4sJWXQqzd3aQMMzEa66K40RPA1SAv8a3CiaYDsXh8pcrPXrAjfdyE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">修复方案</span></span></p></div></div><h3 style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;pointer-events: initial;"><span leaf="">官方修复方案</span></h3><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">官方已发布修复方案，请访问链接下载：</span><span leaf=""><br/></span><span leaf=""><a href="https://github.com/BerriAI/litellm/releases/tag/v1.83.7-stable" target="_blank">https://github.com/BerriAI/litellm/releases/tag/v1.83.7-stable</a></span></p><h3 style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;pointer-events: initial;"><span leaf="">临时缓解措施</span></h3><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">修改配置，在general_settings中设置disable_error_logs: true。</span></p><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">微步产品支撑</span></span></p></div></div><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">微步漏洞情报于</span><span style="color: #d93025;font-weight: bold;"><span leaf="">2026-04-28</span></span><span leaf="">收录该漏洞。</span></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">微步下一代威胁情报平台NGTIP及X情报社区已于漏洞收录时向漏洞订阅用户推送该漏洞情报，并将持续推送后续更新；对于已经录入资产的用户，支持实时自动化排查受影响资产。</span></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;margin: 0;"><span leaf="">微步威胁感知平台TDP已于</span><span style="color: #d93025;font-weight: bold;"><span leaf="">20260428</span></span><span leaf="">支持检测，检测ID：</span><span style="color: #d93025;font-weight: bold;"><span leaf="">S3100174805<span textstyle="" style="color: rgb(0, 0, 0);font-weight: normal;">，</span></span></span><span leaf="">模型/规则高于：</span><span style="color: #d93025;font-weight: bold;"><span leaf="">20260428000000</span></span><span leaf="">可检出。</span></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;" nodeleaf=""><img alt="image.png" class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100025006" data-ratio="0.3768518518518518" data-w="1080" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=cb0882da&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEMWFn7iadHw4AVva0FVHyKmfLsWM2n33II5Zxq0JArdj9xX6k2MpwAb2FlMGqHw92rqibhTEy9DrXfkLHEhE5mibNo4sSZqI1gIV0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: center;margin-top: 24px;margin-bottom: 24px;"><span leaf="">- END -</span><div powered-by="xiumi.us" style="margin-bottom: 10px;outline: 0px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;"><div style="padding: 20px 15px;outline: 0px;display: inline-block;width: 677px;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: solid;border-width: 1px;border-color: rgba(189, 16, 16, 0.22);box-shadow: rgba(189, 16, 16, 0.22) 4px 4px 0px;"><div powered-by="xiumi.us" style="margin-top: 10px;outline: 0px;justify-content: flex-start;display: flex;flex-flow: row;"><div style="outline: 0px;display: inline-block;width: 645px;vertical-align: top;border-left: 3px solid rgb(232, 57, 57);border-bottom-left-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: -5px;margin-bottom: -5px;outline: 0px;"><div style="padding-right: 6px;padding-left: 6px;outline: 0px;font-size: 24px;color: rgb(233, 38, 52);line-height: 0.75;letter-spacing: 0px;text-align: justify;"><p style="outline: 0px;text-wrap: wrap;"><span style="outline: 0px;color: rgb(219, 0, 0);"><strong style="outline: 0px;"><span style="outline: 0px;font-size: 16px;"><span leaf="">微步漏洞情报订阅服务</span></span></strong></span></p></div></div></div></div><div powered-by="xiumi.us" style="outline: 0px;text-align: justify;color: rgb(131, 131, 131);"><p style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);line-height: 1.6em;"><span style="outline: 0px;font-family: 微软雅黑;letter-spacing: 0.578px;text-decoration: initial;text-decoration-color: rgba(0, 0, 0, 0.9);font-size: 14px;color: rgb(84, 84, 84);"><span leaf="">微步提供漏洞情报订阅服务，精准、高效助力企业漏洞运营：</span></span></p><ul style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);list-style-type: square;" class="list-paddingleft-1"><li style="outline: 0px;color: rgb(84, 84, 84);"><p style="margin-bottom: 8px;outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">提供高价值漏洞情报，具备及时、准确、全面和可操作性，帮助企业高效应对漏洞应急与日常运营难题；</span></span></p></li><li style="outline: 0px;color: rgb(84, 84, 84);"><p style="margin-bottom: 8px;outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">可实现对高威胁漏洞提前掌握，以最快的效率解决信息差问题，缩短漏洞运营MTTR；</span></span></p></li><li style="outline: 0px;color: rgb(84, 84, 84);"><p style="margin-bottom: 8px;outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">提供漏洞完整的技术细节，更贴近用户漏洞处置的落地；</span></span></p></li><li style="outline: 0px;color: rgb(84, 84, 84);"><p style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">将漏洞与威胁事件库、APT组织和黑产团伙攻击大数据、网络空间测绘等结合，对漏洞的实际风险进行持续动态更新</span></span><span leaf="">。</span></span></p></li></ul><p style="margin-right: 16px;margin-left: 16px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-wrap: wrap;background-color: rgb(255, 255, 255);letter-spacing: 0.578px;text-align: center;"><span style="outline: 0px;font-size: 14px;letter-spacing: 0.578px;"><span leaf="">扫码在线沟通</span></span></p><div style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);line-height: 1.8;visibility: visible;"><p style="margin: 0pt 16px 8px;outline: 0px;letter-spacing: 0.544px;text-align: center;line-height: 1.75em;"><span style="outline: 0px;color: rgb(63, 63, 63);font-size: 14px;letter-spacing: 1px;"><span leaf="">↓</span><span style="outline: 0px;"><span leaf="">↓↓</span></span></span></p><p style="margin-bottom: 16px;outline: 0px;letter-spacing: 0.544px;text-align: center;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="350" style="outline: 0px;display: initial;visibility: visible !important;width: 96px !important;height: auto !important;" width="96px" data-cropselx1="0" data-cropselx2="96" data-cropsely1="0" data-cropsely2="96" data-imgfileid="100021104" src="https://wechat2rss.xlab.app/img-proxy/?k=68b2dbe3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYv6ic9zgr5hQl5bZ5Mx6PTAQg6tGLiciarvXajTdDnQiacxmwJFZ0D3ictBOmuYyRk99bibwZV49wbap77LibGQHdQPtA%2F640%3Fwx_fmt%3Dpng%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></span></p><p style="margin-top: 0.5em;margin-bottom: 8px;outline: 0px;letter-spacing: 0.544px;text-align: center;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="200" style="outline: 0px;letter-spacing: 0.544px;display: initial;visibility: visible !important;width: 24px !important;height: auto !important;" width="24px" data-imgfileid="100021109" src="https://wechat2rss.xlab.app/img-proxy/?k=ffe38040&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYv6ic9zgr5hTIdM9koHZFkrtYe5WU5rHxSDicbiaNFjEBAs1rojKGviaJGjOGd9KwKzN4aSpnNZDA5UWpY2E0JAnNg%2F640%3Fwx_fmt%3Dpng%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></span></p><p style="outline: 0px;text-align: center;"><span style="outline: 0px;"><span leaf=""><a class="weapp_text_link js_weapp_entry" style="padding-right: 0px;padding-left: 0px;outline: 0px;color: var(--weui-LINK);cursor: pointer;font-size: 14px;" data-miniprogram-type="text" data-miniprogram-appid="wx0c720b24e005e633" data-miniprogram-path="p?p=400-030-1051" data-miniprogram-nickname="电话码" data-miniprogram-servicetype="" data-miniprogram-applink="">点此电话咨询</a></span></span></p></div></div><div powered-by="xiumi.us" style="margin-top: 10px;outline: 0px;justify-content: flex-start;display: flex;flex-flow: row;"><div style="outline: 0px;display: inline-block;width: 645px;vertical-align: top;border-left: 3px solid rgb(232, 57, 57);border-bottom-left-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: -5px;margin-bottom: -5px;outline: 0px;"><div style="padding-right: 6px;padding-left: 6px;outline: 0px;font-size: 24px;color: rgb(233, 38, 52);line-height: 0.75;letter-spacing: 0px;text-align: justify;"><p style="outline: 0px;text-wrap: wrap;"><span style="outline: 0px;color: rgb(219, 0, 0);"><strong style="outline: 0px;"><span style="outline: 0px;font-size: 16px;"><span leaf="">X漏洞奖励计划</span></span></strong></span></p></div></div></div></div><div powered-by="xiumi.us" style="outline: 0px;text-align: justify;"><p style="margin-bottom: 16px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);"><span style="outline: 0px;color: rgb(84, 84, 84);"><span style="outline: 0px;font-size: 14px;"><span leaf="">“X漏洞奖励计划”是微步X情报社区推出的一款</span></span><span style="outline: 0px;font-size: 14px;letter-spacing: 0.578px;text-decoration: initial;text-decoration-color: rgba(0, 0, 0, 0.9);"><span leaf="">针对未公开</span></span><span style="outline: 0px;font-size: 14px;"><span leaf="">漏洞的奖励计划，我们鼓励白帽子提交挖掘到的0day漏洞，并给予白帽子可观的奖励。我们期望通过该计划与白帽子共同努力，提升0day防御能力，守护数字世界安全。</span></span></span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);"><span style="outline: 0px;color: rgb(84, 84, 84);"><span style="outline: 0px;font-size: 14px;"><span leaf="">活动详情：</span></span><span style="outline: 0px;font-size: 14px;letter-spacing: 0.578px;text-decoration: initial;text-decoration-color: rgba(0, 0, 0, 0.9);"><span leaf=""><a href="https://x.threatbook.com/v5/vulReward" target="_blank">https://x.threatbook.com/v5/vulReward</a></span></span></span></p></div></div></div></div><p class="mp_profile_iframe_wrp" style="margin-bottom: 0px;outline: 0px;"><span leaf=""><mp-common-profile class="custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-nickname="微步在线研究响应中心" data-index="0" data-from="2" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/fFyp1gWjicML0NlKR16SxQGjNPSYVoUxGgXhXvI4Z8ia5h8C9TGibEic1ABv6fniame8h0dh6zGX8ndXT8icjQocVh8A/300?wx_fmt=png&amp;wxfrom=19" data-signature="微步情报局最新威胁事件分析、漏洞分析、安全研究成果共享，探究网络攻击的真相" data-id="Mzg5MTc3ODY4Mw==" data-origin_num="354" data-biz_account_status="0"></mp-common-profile></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=576f2715&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5MTc3ODY4Mw%3D%3D%26mid%3D2247508656%26idx%3D1%26sn%3D23a36f4a8c5d30c1f7e696db704e78ca">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 28 Apr 2026 15:49:00 +0800</pubDate>
    </item>
    <item>
      <title>突发：Checkmarx再次遭遇供应链投毒！速查</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&amp;mid=2247508649&amp;idx=1&amp;sn=a1931d6a89e8851fa93a599af6cf6e15</link>
      <description>TeamPCP再作案</description>
      <content:encoded><![CDATA[<p><span>微步情报局</span> <span>2026-04-23 11:17</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=2eabae6b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FT4OSm0sXdEOuaibab6W2Hav4iaAml0cKWoSTAe1MKq2rcN5jn40Ay5m8nngJfH9ZrVydY2epKEiapYGwPFLgnPgeCRdLWp6nYrAOEibtKTrokSc%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>TeamPCP再作案</p>
  <h1 style="text-align: justify;margin: 0pt 0pt 24px;" data-pm-slice="0 0 []"><span style="text-align: justify;font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">4月22日，</span></span><span style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="微软雅黑"><span leaf="">微步情报局监测到有国外机构</span></span><span style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="微软雅黑"><span leaf="">披露，Checkmarx 相关官方分发渠道疑遭供应链攻击：官方 checkmarx/kics Docker Hub 仓库中多个 KICS 镜像标签被恶意覆盖，同时近期发布的 Checkmarx 开发者扩展版本中还发现可静默下载并执行远程载荷的恶意逻辑。</span></span></h1><h1 style="text-align: justify;margin: 0pt 0pt 24px;" data-pm-slice="0 0 []"><span style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="微软雅黑"><span leaf="">Docker 首先发现异常镜像推送并通知 Socket；Checkmarx 此前也曾就 2026 年 3 月 23 日 OpenVSX 插件与 GitHub Actions 事件发布安全通告。本次事件显示，攻击者不仅意图窃取开发者与云凭证，还试图利用被盗 GitHub / npm 令牌继续横向传播。</span><p style="margin-top: 24px;"><span leaf="" style="color: rgb(0, 0, 0);font-size: 12.5pt;font-family: 微软雅黑;letter-spacing: 0pt;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">Checkmarx / KICS 项目基础信息</span></span></p></span></h1><p><span leaf="" style="color:rgb(0, 0, 0);font-size:12.5pt;font-family:微软雅黑;letter-spacing:0pt;font-style:normal;font-weight:normal;">Checkmarx 是知名应用安全厂商，提供 SAST、SCA、容器与 CI/CD 安全等产品；KICS（Keeping Infrastructure as Code Secure）是其开源 IaC 安全扫描工具，常用于 Terraform、CloudFormation、Kubernetes 等配置扫描。</span></p><p><span leaf="" style="color:rgb(0, 0, 0);font-size:12.5pt;font-family:微软雅黑;letter-spacing:0pt;font-style:normal;font-weight:normal;">核心能力：KICS 可扫描基础设施即代码模板中的安全配置缺陷、敏感项与合规风险，常通过 CLI、GitHub Actions、容器镜像与 IDE / 扩展生态集成到开发流程中。</span></p><p><span leaf="" style="color:rgb(0, 0, 0);font-size:12.5pt;font-family:微软雅黑;letter-spacing:0pt;font-style:normal;font-weight:normal;">本次受攻击情况：Socket 发现 checkmarx/kics 官方 Docker Hub 仓库中的多个标签被指向恶意摘要，近期 Checkmarx 扩展版本还会在激活后从硬编码 GitHub 地址下载 mcpAddon.js 并通过 Bun 立即执行；恶意逻辑涉及凭证窃取、数据外传、GitHub Actions 注入和 npm 传播。</span></p><h2 style="text-align: justify;margin: 0pt 0pt 24px;"><span style="font-size: 18pt;font-family: 微软雅黑;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="微软雅黑"><span leaf=""><span textstyle="" style="font-size: 20px;">事件核心概况与时间线</span></span></span></h2><p><span leaf="" style="color: rgb(0, 0, 0);font-size: 12.5pt;font-family: 微软雅黑;letter-spacing: 0pt;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">披露时间</span>：2026 年 4 月 22 日</span></p><p><span leaf="" style="color: rgb(0, 0, 0);font-size: 12.5pt;font-family: 微软雅黑;letter-spacing: 0pt;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">攻击目标</span>：Checkmarx 官方 KICS Docker 镜像标签、近期发布的 Checkmarx 开发者扩展版本，以及后续可访问的 GitHub / npm 资产</span></p><p><span leaf="" style="color: rgb(0, 0, 0);font-size: 12.5pt;font-family: 微软雅黑;letter-spacing: 0pt;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">受影响扩展版本</span>：checkmarx/cx-dev-assist 1.17.0、1.19.0；checkmarx/ast-results 2.63.0、2.66.0</span></p><p><span leaf="" style="color: rgb(0, 0, 0);font-size: 12.5pt;font-family: 微软雅黑;letter-spacing: 0pt;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">受影响镜像标签</span>：v2.1.20、v2.1.20-debian、debian、alpine、latest；恶意新增标签 v2.1.21 随后被删除</span></p><p><span leaf="" style="color: rgb(0, 0, 0);font-size: 12.5pt;font-family: 微软雅黑;letter-spacing: 0pt;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">疑似攻击团伙</span>：TeamPCP 被认为“疑似认领”，但公开贴文不能单独构成归因结论</span></p><p><span leaf="" style="color: rgb(0, 0, 0);font-size: 12.5pt;font-family: 微软雅黑;letter-spacing: 0pt;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">攻击类型</span>：官方制品仓库被篡改 + IDE / 扩展供应链投毒 + GitHub Actions 工作流注入 + 凭证窃取与横向传播</span></p><p><span leaf="" style="color: rgb(0, 0, 0);font-size: 12.5pt;font-family: 微软雅黑;letter-spacing: 0pt;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">触发方式</span>：扩展激活后静默下载并执行第二阶段载荷；受污染镜像运行后可能泄露扫描内容与相关敏感信息</span></p><p><span leaf="" style="color: rgb(0, 0, 0);font-size: 12.5pt;font-family: 微软雅黑;letter-spacing: 0pt;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">核心目的</span>：窃取 GitHub、npm、云平台、SSH 等凭证，并利用被盗权限继续创建公开仓库、注入工作流、 republish 可写 npm 包</span></p><p><span leaf="" style="color: rgb(0, 0, 0);font-size: 12.5pt;font-family: 微软雅黑;letter-spacing: 0pt;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">关键时间线</span></span></p><p><span leaf="" style="color: rgb(0, 0, 0);font-size: 12.5pt;font-family: 微软雅黑;letter-spacing: 0pt;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">2026 年 3 月 23 日</span>，Checkmarx 发现其部分 OpenVSX 插件与 GitHub Actions 工作流曾遭供应链事件影响，并发布后续安全更新说明。</span></p><p><span leaf="" style="color: rgb(0, 0, 0);font-size: 12.5pt;font-family: 微软雅黑;letter-spacing: 0pt;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">2026 年 4 月 22 日</span>，Docker 监测到 checkmarx/kics 官方仓库出现可疑镜像推送，并将线索通报给 Socket。</span></p><p><span leaf="" style="color: rgb(0, 0, 0);font-size: 12.5pt;font-family: 微软雅黑;letter-spacing: 0pt;font-style: normal;font-weight: normal;">随后，Socket 分析发现恶意 KICS 镜像中包含被篡改的 kics 二进制，同时近期 Checkmarx 扩展版本还会下载执行 mcpAddon.js。</span></p><p><span leaf="" style="color: rgb(0, 0, 0);font-size: 12.5pt;font-family: 微软雅黑;letter-spacing: 0pt;font-style: normal;font-weight: normal;">Socket 进一步确认该载荷除本地与云凭证窃取外，还会滥用 GitHub 令牌创建公开仓库、注入恶意 GitHub Actions 工作流并利用 npm 凭证寻找可写包进行再发布。</span></p><p><span leaf="" style="color: rgb(0, 0, 0);font-size: 12.5pt;font-family: 微软雅黑;letter-spacing: 0pt;font-style: normal;font-weight: normal;">事件披露后，相关恶意镜像标签被恢复或删除；Socket 表示已将发现同步给 Checkmarx，事件仍在持续调查中。</span></p><h2 style="text-align: justify;margin: 0pt 0pt 24px;"><span style="font-size: 18pt;font-family: 微软雅黑;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="微软雅黑"><span leaf="">技术执行流程：KICS 二进制劫持详解</span></span></h2><p style="text-align: justify;margin: 0pt 0pt 16px;" data-pm-slice="0 0 []"><span data-font-family="微软雅黑"><span leaf="" style="color: rgb(0, 0, 0);font-size: 12.5pt;font-family: 微软雅黑;letter-spacing: 0pt;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">植入与触发</span></span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="color: rgb(0, 0, 0);font-size: 12.5pt;font-family: 微软雅黑;letter-spacing: 0pt;font-style: normal;font-weight: normal;">恶意逻辑存在于近期发布的 Checkmarx 扩展版本中。扩展激活后，会从 Checkmarx 自有 GitHub 仓库某个硬编码提交中拉取 mcpAddon.js，写入 ~/.checkmarx/mcp/mcpAddon.js，并通过 Bun 运行；同时，恶意 KICS Docker 镜像中打包了被篡改的 Go 语言 ELF 可执行文件 kics。</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="color: rgb(0, 0, 0);font-size: 12.5pt;font-family: 微软雅黑;letter-spacing: 0pt;font-style: normal;font-weight: normal;">Stage 1：远程载荷拉取与本地执行</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="color: rgb(0, 0, 0);font-size: 12.5pt;font-family: 微软雅黑;letter-spacing: 0pt;font-style: normal;font-weight: normal;">扩展在用户无明确确认、无完整性校验的情况下，从 raw.githubusercontent.com 指向的特定提交拉取第二阶段脚本；该提交被伪装成历史正常提交，并通过 Git 历史投递和孤立提交方式降低人工与自动审查发现概率。</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="color: rgb(0, 0, 0);font-size: 12.5pt;font-family: 微软雅黑;letter-spacing: 0pt;font-style: normal;font-weight: normal;">mcpAddon.js 使用多层混淆，包括超长单行 bundle、字符串表解码、额外自定义解码器，以及 gzip + base64 内嵌载荷。嵌入内容除主窃密逻辑外，还包括用于 republish npm 包的 setup.mjs、恶意 GitHub Actions YAML、公钥和其他字符串。</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="color: rgb(0, 0, 0);font-size: 12.5pt;font-family: 微软雅黑;letter-spacing: 0pt;font-style: normal;font-weight: normal;">Stage 2：主机侦察、凭证收集与外传</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="color: rgb(0, 0, 0);font-size: 12.5pt;font-family: 微软雅黑;letter-spacing: 0pt;font-style: normal;font-weight: normal;">mcpAddon.js 会调用受害主机 shell（PowerShell 或 Bash）枚举并窃取多类敏感信息，包括 GitHub 认证令牌、AWS 凭证、Azure 访问令牌、Google Cloud 凭证数据库、.npmrc、SSH 密钥与配置、环境变量，以及 Claude / 其他 MCP 配置文件。</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="color: rgb(0, 0, 0);font-size: 12.5pt;font-family: 微软雅黑;letter-spacing: 0pt;font-style: normal;font-weight: normal;">Windows 环境中，恶意脚本会直接执行 gh auth token、gcloud config config-helper、az account get-access-token、azd auth token 等命令抓取令牌；收集结果会被压缩后通过 HTTPS 发送至 audit.checkmarx[.]cx/v1/telemetry，相关网络指标还包括 94[.]154[.]172[.]43。</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="color: rgb(0, 0, 0);font-size: 12.5pt;font-family: 微软雅黑;letter-spacing: 0pt;font-style: normal;font-weight: normal;">对 KICS 镜像而言，Socket 指出被篡改二进制不仅保留扫描器功能，还带有未授权的数据收集与外传能力，可能将 IaC 扫描过程中接触到的凭证、敏感配置或机密信息暴露给攻击者。</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="color: rgb(0, 0, 0);font-size: 12.5pt;font-family: 微软雅黑;letter-spacing: 0pt;font-style: normal;font-weight: normal;">Stage 3：GitHub 仓库滥用与公开暂存</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="color: rgb(0, 0, 0);font-size: 12.5pt;font-family: 微软雅黑;letter-spacing: 0pt;font-style: normal;font-weight: normal;">恶意程序会滥用被盗 GitHub 凭证自动创建公开仓库作为外传暂存区，仓库描述伪装为“Checkmarx Configuration Storage”，命名模式常表现为 &lt;word&gt;-&lt;word&gt;-&lt;3 digits&gt;。结果文件与提交消息中还可能嵌入令牌样数据，以仓库内容和元数据双通道暂存被窃信息。</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="color: rgb(0, 0, 0);font-size: 12.5pt;font-family: 微软雅黑;letter-spacing: 0pt;font-style: normal;font-weight: normal;">Stage 4：GitHub Actions 注入与 npm 横向传播</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="color: rgb(0, 0, 0);font-size: 12.5pt;font-family: 微软雅黑;letter-spacing: 0pt;font-style: normal;font-weight: normal;">恶意代码会枚举受害者可写仓库，优先选择近期活跃且配置了 GitHub Actions secrets 的仓库，自动新建分支并写入 .github/workflows/format-check.yml。该工作流在 push 时触发，通过 ${{ toJSON(secrets) }} 一次性序列化仓库及继承的组织级 secrets，写入 format-results.txt 并作为 artifact 上传。</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="color: rgb(0, 0, 0);font-size: 12.5pt;font-family: 微软雅黑;letter-spacing: 0pt;font-style: normal;font-weight: normal;">随后，攻击者可通过已窃取的令牌下载这些 artifact，进一步扩大凭证收集范围。恶意程序还会读取 .npmrc 中的认证信息，识别受害者拥有写权限的 npm 包并尝试重新发布带毒版本，从单点入侵演变为跨生态供应链扩散。</span></span></p><h2 style="text-align: justify;margin: 0pt 0pt 24px;"><span style="font-size: 18pt;font-family: 微软雅黑;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="微软雅黑"><span leaf=""><span textstyle="" style="font-size: 20px;">应急处置</span></span></span><span style="font-size: 18pt;font-family: 微软雅黑;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="微软雅黑"><span leaf=""><span textstyle="" style="font-size: 20px;">建议</span></span></span></h2><p style="text-align: justify;margin: 0pt 0pt 16px;" data-pm-slice="0 0 []"><span style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="微软雅黑"><span leaf="">若拉取、运行或安装过上述受影响 Checkmarx 制品，应立即视为潜在凭证暴露于 CI/CD 沦陷事件，按以下步骤处置：</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="微软雅黑"><span leaf="">1. 立即隔离与移除</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="微软雅黑"><span leaf="">从开发者终端、CI Runner、构建环境中移除受影响扩展、容器镜像与相关工作流；暂停继续使用可疑 KICS 标签。</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="微软雅黑"><span leaf="">2. 全量轮换高风险凭证</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="微软雅黑"><span leaf="">重点轮换 GitHub token、npm token、云平台凭证、SSH 密钥、CI/CD secrets，以及曾暴露在被扫描配置文件、环境变量和构建环境中的其他敏感信息。</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="微软雅黑"><span leaf="">3. 审计 GitHub / npm / 云平台活动</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="微软雅黑"><span leaf="">检查是否出现异常公开仓库、新增或短暂存在的 .github/workflows/format-check.yml、异常 workflow run、artifact 下载记录、异常分支创建、未授权 npm 发布，以及云平台中的异常密钥访问与新签发凭证。</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="微软雅黑"><span leaf="">4. 终端与 Runner 狩猎</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="微软雅黑"><span leaf="">排查是否存在异常 Bun 执行、访问 .npmrc / .git-credentials / .env / 云凭证目录等行为，以及对 audit.checkmarx[.]cx、94[.]154[.]172[.]43 的出站连接。对于运行过 KICS 镜像的环境，应复核被扫描 IaC 文件中是否包含明文机密。</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="微软雅黑"><span leaf="">5. 清理与重建</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="微软雅黑"><span leaf="">对高风险开发机、Runner 与构建节点建议采用“重新制备环境 + 重新签发凭证”的方式处置；仅删除恶意文件并不足以排除二次滥用风险。</span></span></p><h2 style="text-align: justify;margin: 0pt 0pt 24px;"><span style="font-size: 18pt;font-family: 微软雅黑;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="微软雅黑"><span leaf=""><span textstyle="" style="font-size: 20px;">IOC</span></span></span></h2><p style="text-align: justify;margin: 0pt 0pt 16px;" data-pm-slice="0 0 []"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">1. </span><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">恶意扩展版本</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">checkmarx/cx-dev-assist@1.17.0、1.19.0</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">checkmarx/ast-results@2.63.0、2.66.0</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">2. </span><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">恶意镜像标签与摘要</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">镜像标签：alpine、v2.1.20、v2.1.21</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">索引摘要 </span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">sha256:2588a44890263a8185bd5d9fadb6bc9220b60245dbcbc4da35e1b62a6f8c230d</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">amd64 镜像摘要 </span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">sha256:d186161ae8e33cd7702dd2a6c0337deb14e2b178542d232129c0da64b1af06e4</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">arm64 镜像摘要 </span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">sha256:415610a42c5b51347709e315f5efb6fffa588b6ebc1b95b24abf28088347791b</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">镜像标签：debian、v2.1.20-debian、v2.1.21-debian</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">索引摘要 </span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">sha256:222e6bfed0f3bb1937bf5e719a2342871ccd683ff1c0cb967c8e31ea58beaf7b</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">amd64 镜像摘要 </span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">sha256:a6871deb0480e1205c1daff10cedf4e60ad951605fd1a4efaca0a9c54d56d1cb</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">arm64 镜像摘要 </span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">sha256:ff7b0f114f87c67402dfc2459bb3d8954dd88e537b0e459482c04cffa26c1f07</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">镜像标签：latest</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">索引摘要</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">sha256:a0d9366f6f0166dcbf92fcdc98e1a03d2e6210e8d7e8573f74d50849130651a0</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">amd64 镜像摘要</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">sha256:26e8e9c5e53c972997a278ca6e12708b8788b70575ca013fd30bfda34ab5f48f</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">arm64 镜像摘要 </span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">sha256:7391b531a07fccbbeaf59a488e1376cfe5b27aef757430a36d6d3a087c610322</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">3. </span><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">网络 IOC</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">IP：94[.]154[.]172[.]43</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">domain</span></span><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">：</span></span><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">audit.checkmarx[.]cx</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">URL：<a href="https://audit.checkmarx[.]cx/v1/telemetry" target="_blank">https://audit.checkmarx[.]cx/v1/telemetry</a></span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">4. </span><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">文件与哈希 IOC</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">mcpAddon.js：</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">MD5 d47de3772f2d61a043e7047431ef4cf4</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">SHA1 2b12cc5cc91ec483048abcbd6d523cdc9ebae3f3</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">SHA25</span></span><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">6</span></span><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;"> 24680027afadea90c7c713821e214b15cb6c922e67ac01109fb1edb3ee4741d9</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">kics（ELF）：</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">MD5 e1023db24a29ab0229d99764e2c8deba</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">SHA1 250f3633529457477a9f8fd3db3472e94383606a</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">SHA256 2a6a35f06118ff7d61bfd36a5788557b695095e7c9a609b4a01956883f146f50</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 20px;font-weight: bold;">六、事件总结与防御建议</span></span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-weight: bold;">核心结论</span></span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">本次 Checkmarx 事件并非单一</span></span><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">产品</span></span><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">被投毒，而是同时涉及容器镜像、开发者扩展、GitHub 仓库、GitHub Actions 与 npm 生态的复合型供应链攻击；</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">攻击者目标不止于一次性窃密，而是试图利用开发者与 CI/CD 权限持续横向传播，形成“窃取凭证—扩大战果—再次投毒”的链式攻击。</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-weight: bold;">防御建议</span></span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">依赖与</span></span><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">产品</span></span><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">治理：对扩展、容器镜像、GitHub Actions 版本与摘要实行固定和校验，避免直接信任 latest、浮动标签与未经校验的远程脚本；</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">凭证最小化：缩减 GitHub / npm / 云平台令牌权限，优先短时令牌与细粒度作用域，降低单个开发机失陷后的爆炸半径；</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">CI/CD 加固：限制 GitHub Actions 默认权限、审计 artifact 下载、监控非常规 workflow 文件写入，禁止不必要的第三方执行环境与发布权限；</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">检测与响应：持续监控异常公开仓库创建、镜像摘要漂移、Bun 非预期执行、敏感文件访问和 IOC 出站流量，并建立供应链投毒的快速下线与密钥轮换机制。</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">供应链安全事件正在从“恶意包”升级为“官方渠道被劫持 + 多生态联动传播”。对企业而言，信任官方来源已不再足够，必须把版本固定、摘要校验、最小权限和持续审计作为默认控制。</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">参考链接：</span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;"><a href="https://socket.dev/blog/checkmarx-supply-chain-compromise" target="_blank">https://socket.dev/blog/checkmarx-supply-chain-compromise</a></span></span></p><p style="text-align: justify;margin: 0pt 0pt 16px;"><span data-font-family="微软雅黑"><span leaf="" style="font-size: 12.5pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;"><a href="https://checkmarx.com/blog/checkmarx-security-update/" target="_blank">https://checkmarx.com/blog/checkmarx-security-update/</a></span></span></p><p class="mp_profile_iframe_wrp" nodeleaf=""><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-nickname="微步在线研究响应中心" data-from="0" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/fFyp1gWjicML0NlKR16SxQGjNPSYVoUxGgXhXvI4Z8ia5h8C9TGibEic1ABv6fniame8h0dh6zGX8ndXT8icjQocVh8A/0?wx_fmt=png" data-signature="微步情报局最新威胁事件分析、漏洞分析、安全研究成果共享，探究网络攻击的真相" data-id="Mzg5MTc3ODY4Mw==" data-is_biz_ban="0" data-service_type="1" data-verify_status="2"></mp-common-profile></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=927c29cb&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5MTc3ODY4Mw%3D%3D%26mid%3D2247508649%26idx%3D1%26sn%3Da1931d6a89e8851fa93a599af6cf6e15">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 23 Apr 2026 11:17:00 +0800</pubDate>
    </item>
    <item>
      <title>突发：Xinference PyPI 遭投毒！速查</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&amp;mid=2247508649&amp;idx=2&amp;sn=de697976c81a783cbcb86ffaeb528875</link>
      <description></description>
      <content:encoded><![CDATA[<p><span>微步在线研究响应中心</span> <span>2026-04-23 11:17</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=ba77bc1c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FT4OSm0sXdEOI55ffEPDaFC26PY8iaia6HWNY45N0GibCjQPoRMrjg6r8eKyYfhYW2lkIqBGcoXHjk2AEf2uYyz2147ruQBic4AMDV7BMjXiaHPmM%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <h1 style="text-align:left;line-height:1.7;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;" data-pm-slice="0 0 []"><span style="text-align: left;line-height: 1.7;font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;">2026 年 4 月 22 日，JFrog 安全研究团队披露</span></span><span style="font-size:11pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">PyPI 官方包 xinference 遭供应链投毒</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">，恶意版本 2.6.0、2.6.1、2.6.2 被植入窃密木马，导入即执行</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">恶意</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">脚本</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">，</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">该脚本</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">无持久化</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">的</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">快速窃取云</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">平台</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">和</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">本地</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">主机密钥</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">信息</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">。</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">JFrog 安全研究团队</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">称</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">该事件与近期频发的</span></span><span style="font-size:11pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">TeamPCP 多生态供应链攻击</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">同源，</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">但</span></span><span style="font-size:11pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">TeamPCP</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">当日</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">发推特</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">否认</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">，</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">并</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">称</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">该事件为模仿犯罪。</span></span></h1><h2 style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:16pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">一、Xinference 项目基础信息</span></span></h2><p style="text-align:left;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">Xinference（Xorbits Inference）</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""> 是 Xorbits 团队开发的</span></span><span style="font-size:11pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">开源分布式 AI 模型推理框架</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">，主打一键部署、高性能、多模型兼容，是 AI 开发与私有化大模型部署的主流工具，PyPI 周下载量达数万级。</span></span></p><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l0 level1;"><span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">●</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">核心能力：支持 LLM、多模态、TTS/STT、Embedding 等模型推理，兼容 vLLM、Transformers、llama.cpp 等后端，提供 REST API 与 OpenAI 兼容接口，支持分布式多机推理与高并发优化。</span></span></p><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l0 level1;"><span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">●</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">本次受攻击情况：攻击者</span></span><span style="font-size:11pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">劫持正版包发布权限</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">，直接向 PyPI 上传恶意版本；恶意代码嵌入xinference/</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">__init__.py</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">，</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">导入</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">、CLI 启动、下游依赖调用均会触发执行；受影响版本已被维护者紧急下架（yanked）。</span></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024993" data-ratio="0.6112" width="604.733" data-type="png" data-w="2500" height="369.613" style="margin-left: 0px;margin-top: 0px;width: 604.733px;height: 369.613px;" src="https://wechat2rss.xlab.app/img-proxy/?k=530b6e3a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdENk7ve0X2qKMu9Zpian1lWWCzEHRdWFGr6raaQMmiac3PZVDiaV4wpdhjrB8Wp58VHGuHOADpL2sP7ib1T2vQWGUgKGZRiacjbKc7gw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><h2 style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:16pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">二、事件核心概况与时间线</span></span></h2><h3 style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:14pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">核心信息</span></span></h3><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l1 level1;"><span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">●</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">披露时间：2026 年 4 月 22 日</span></span></p><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l1 level1;"><span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">●</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">攻击目标：PyPI 正版 xinference 包</span></span></p><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l1 level1;"><span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">●</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">恶意版本：2.6.0、2.6.1、2.6.2</span></span></p><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l1 level1;"><span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">●</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">攻击团伙：疑似 TeamPCP（团伙否认，称系模仿者）</span></span></p><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l1 level1;"><span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">●</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">攻击类型：正版包劫持 + 供应链投毒</span></span></p><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l1 level1;"><span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">●</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">触发方式：包导入即执行</span></span></p><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l1 level1;"><span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">●</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">核心目的：纯窃取密钥 / 凭证 / 机密，无勒索、无后门、无远控、无持久化</span></span></p><h3 style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:14pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">关键时间线</span></span></h3><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l2 level1;"><span style=""><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">1. </span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">攻击者窃取维护者 / CI/CD 凭证，登录 PyPI 上传 xinference 2.6.0/2.6.1/2.6.2 恶意版本；</span></span></p><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l2 level1;"><span style=""><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">2. </span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">用户发现异常行为，</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">并在</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">项目</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""> GitHub</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">issue</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">询问</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">开发者</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">，</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">项目维护者</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">确认</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">并</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">紧急下架问题版本；</span></span></p><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l2 level1;"><span style=""><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">3. </span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">JFrog 发布技术分析报告，</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">并</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">确认</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">该</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">事件</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">与 TeamPCP 系列攻击同源；</span></span></p><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l2 level1;"><span style=""><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">4. </span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">TeamPCP 通过 Twitter 否认涉案，声明系第三方冒用其标识作案。</span></span></p><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="display: inline-block;overflow: hidden;transform:rotate(0deg);width: 604.7333333333333px;height: 588.4167979002625px;text-indent: 0;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024995" data-ratio="0.9730185497470489" width="604.733" data-type="png" data-w="1186" height="588.417" style="margin-left: 0px;margin-top: 0px;width: 604.733px;height: 588.417px;" src="https://wechat2rss.xlab.app/img-proxy/?k=2da69492&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEOISZdbkPfEX3US7YqGjd5dqptNlo1o7kqqHpSw09lApKS48BX95BolKSWz87K3P7snLTq8jnTTYXeDGWiaeL5wpRKmLHBtSWibs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><h2 style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:16pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">三</span></span><span style="font-size:16pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">、技术执行流程：两阶段窃密木马详解</span></span></h2><h3 style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:14pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">植入与触发</span></span></h3><p style="text-align:left;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">恶意代码嵌入xinference/</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">__init__.py</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">，</span></span><span style="font-size:11pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">导入包即触发执行</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">，无用户交互、无明显异常，隐蔽性极强。</span></span></p><h3 style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:14pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">Stage 1：加载器与数据外发</span></span></h3><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l3 level1;"><span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">●</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">内嵌 base64 编码载荷，通过subprocess.Popen启动独立 Python 后台进程，屏蔽 stdout/stderr，隐藏恶意行为；</span></span></p><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l3 level1;"><span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">●</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">解码并释放 Stage 2 收集器，执行后将结果写入临时文件，压缩为love.tar.gz；</span></span></p><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l3 level1;"><span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">●</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">通过 curl POST 上传</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">Stage</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">2</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">中</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">收集</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">并</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">打包</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">压缩</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">的</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">窃密</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">信息</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">至攻击者服务器h</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">tt</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">ps://whereisitat.lucyatemysuperbox.space/，</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">并</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">携带自定义头X-QT-SR: 14；</span></span></p><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l3 level1;"><span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">●</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">执行完毕自动清理临时文件，不留痕迹。</span></span></p><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="display: inline-block;overflow: hidden;transform:rotate(0deg);width: 604.7333333333333px;height: 297.81291338582673px;text-indent: 0;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024994" data-ratio="0.4924698795180723" width="604.733" data-type="png" data-w="1328" height="297.813" style="margin-left: 0px;margin-top: 0px;width: 604.733px;height: 297.813px;" src="https://wechat2rss.xlab.app/img-proxy/?k=188d74b3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEPXLhapM3aBWCmQLSJVLm4E3Veia99pRh03D8TlmparcicydyvbIQuKiavqSEibGRIywqhVQZcOstUbQmr57T3aLdBt5gevwfNqfAA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><h3 style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:14pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">Stage 2：主机侦察与机密收集</span></span></h3><p style="text-align:left;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">全面搜刮主机与云环境敏感数据，覆盖：</span></span></p><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l4 level1;"><span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">●</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">主机基础信息：hostname、whoami、ip、路由、环境变量；</span></span></p><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l4 level1;"><span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">●</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">密钥凭证：SSH 私钥、TLS 密钥（.pem/.key/.p12）、Git 凭证、AWS/Azure/GCP 云凭证；</span></span></p><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l4 level1;"><span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">●</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">配置文件：.env 系列、.npmrc/.pypirc、Docker 认证、K8s 服务账户令牌；</span></span></p><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l4 level1;"><span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">●</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">基础设施：Terraform、Helm、WireGuard 配置；</span></span></p><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l4 level1;"><span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">●</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">其他：数据库密码、加密货币钱包、本地账户数据。</span></span></p><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="display: inline-block;overflow: hidden;transform:rotate(0deg);width: 604.7333333333333px;height: 281.49627296587926px;text-indent: 0;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024996" data-ratio="0.4654882154882155" width="604.733" data-type="png" data-w="2376" height="281.496" style="margin-left: 0px;margin-top: 0px;width: 604.733px;height: 281.496px;" src="https://wechat2rss.xlab.app/img-proxy/?k=e7ea390e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdENGVsfrfA6otRCTiaI16Xk7zowDNS5lXZKVMoMTn3vyYyBSice6WL1SXusxayLfq5Rc2KOhticaxWev5PzQJ6d8JrBMXbMibV5wtuQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><h3 style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:14pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">AWS 专项利用逻辑</span></span></h3><p style="text-align:left;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">载荷内置 AWS 专属代码，尝试获取 IMDSv2 令牌、窃取 IAM 角色凭证，调用secretsmanager.ListSecrets、ssm.DescribeParameters接口，定向窃取云平台机密。</span></span></p><p style="text-align:left;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="display: inline-block;overflow: hidden;transform:rotate(0deg);width: 604.7333333333333px;height: 41.29889763779527px;text-indent: 0;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024991" data-ratio="0.06829268292682927" width="604.7333333333333" data-type="png" data-w="1640" height="41.29889763779527" style="margin-left: 0px;margin-top: 0px;width: 604.7333333333333px;height: 41.29889763779527px;" src="https://wechat2rss.xlab.app/img-proxy/?k=a90fb63d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEPfKWpAbHw8eS0gSXzdK1Ov8hRaoHdasRXPere4RchdxVvZ9b3NMBOrvAMYZRRTFCJU2gmicZ94N3ibQs5E2lddTpuPIyd8xCTlo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align:left;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">总体</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">这个</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">脚本</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">窃取</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">了</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">主机与云环境中的敏感信息：包括用户与系统身份信息（hostname、whoami、网络与路由、环境变量）、SSH 相关密钥与配置（用户私钥、authorized_keys、/etc/ssh 主机密钥）、各类凭据文件（.env、Git/AWS/GCP/Azure/Docker/Kubernetes 配置与 token、数据库配置与口令文件、/etc/shadow 等）、CI/基础设施与证书材料（Terraform、Ansible、WireGuard、SSL/PEM/KEY）、命令历史与常见 API key/webhook 线索，以及加密货币钱包与私钥文件（Bitcoin/Ethereum/Solana 等）；同时它还会主动探测云元数据服务（169.254.169.254/</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">1</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">6</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">9</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">.</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">2</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">5</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">4</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">.</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">170.2）抓取临时云凭证并尝试枚举 AWS Secrets Manager/SSM</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">。</span></span></p><h2 style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:16pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">四</span></span><span style="font-size:16pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">、应急处置指南</span></span></h2><p style="text-align:left;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">若安装 / 导入过 xinference 2.6.0–2.6.2，</span></span><span style="font-size:11pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">立即视为环境已沦陷</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">，按以下步骤处置：</span></span></p><h3 style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:14pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">1. 隔离</span></span><span style="font-size:14pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">主机</span></span></h3><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l5 level1;"><span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">●</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">隔离受影响主机，断开敏感网络连接；</span></span></p><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l5 level1;"><span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">●</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">检查出站流量与 DNS 查询，阻断到whereisitat.lucyatemysuperbox.space的访问。</span></span></p><h3 style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:14pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">2. 全量密钥轮换</span></span></h3><p style="text-align:left;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">轮换所有泄露风险密钥：SSH 私钥、云厂商 AK/SK、K8s 令牌、Docker 仓库凭证、PyPI/npm/Cargo 发布令牌、数据库密码、.env 密钥、TLS 证书、CI/CD 凭证、加密货币钱包助记词。</span></span></p><h3 style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:14pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">3. 日志审计</span></span></h3><p style="text-align:left;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">核查 AWS CloudTrail、K8s 审计日志、Git 托管日志、镜像仓库操作记录、Shell 历史与认证日志，确定泄露范围与时间窗口。</span></span></p><h3 style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:14pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">4. 清理与重建</span></span></h3><pre style="padding:10px;background-color:#fafafa;border:1px solid #e1e1e1;border-radius:2px;overflow-x: scroll;"><code style="background-color: inherit;" data-tco-code-type="plain text"><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf=""># 卸载恶意包、清理缓存</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">pip uninstall xinference</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">pip cache purge</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf=""># 重装安全版本（2.6.0之前</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">的</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">安全</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">版本</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">）</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">pip install xinference==</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">2</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">.</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">5</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">.</span></span><span style="font-size:10.5pt;font-family:Courier New;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">0</span></span></code></pre><h2 style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:16pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">五</span></span><span style="font-size:16pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">、</span></span><span style="font-size:16pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">IOC</span></span></h2><h3 style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:14pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">恶意</span></span><span style="font-size:14pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">包版本</span></span></h3><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l6 level1;"><span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">●</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">xinference==2.6.0、2.6.1、2.6.2</span></span></p><h3 style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:14pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">网络 IOC</span></span></h3><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l7 level1;"><span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">●</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">域名：whereisitat.lucyatemysuperbox.space</span></span></p><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l7 level1;"><span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">●</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">URL：hxxps://whereisitat.lucyatemysuperbox.space/</span></span></p><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l7 level1;"><span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">●</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">自定义 HTTP 头：X-QT-SR: 14</span></span></p><h3 style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:14pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">文件与哈希 IOC</span></span></h3><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l8 level1;"><span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">●</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">xinference/</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">init</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">.py</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""> SHA256：e1e007ce4eab7774785617179d1c01a9381ae83abfd431aae8dba6f82d3ac127</span></span></p><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l8 level1;"><span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">●</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">Stage 1 解码后 SHA256：077d49fa708f498969d7cdffe701eb64675baaa4968ded9bd97a4936dd56c21c</span></span></p><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l8 level1;"><span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">●</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">Stage 2 解码后 SHA256：fe17e2ea4012d07d90ecb7793c1b0593a6138d25a393192263e751660ec3cd0</span></span></p><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l8 level1;"><span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">●</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">临时归档文件：love.tar.gz</span></span></p><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l8 level1;"><span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">●</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">文本标记：# hacked by teampcp</span></span></p><h2 style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:16pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">六</span></span><span style="font-size:16pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">、事件总结与防御建议</span></span></h2><h3 style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:14pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">核心结论</span></span></h3><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l9 level1;"><span style=""><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">1. </span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">本次 xinference 攻击是</span></span><span style="font-size:11pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">轻量化窃密变体</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">，无持久化、无加密，更隐蔽、更难检测，以快速窃取密钥为唯一目的；</span></span></p><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l9 level1;"><span style=""><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">2. </span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">正版包劫持风险远超钓鱼包，开发者对官方版本信任度高，一旦被投毒，扩散速度极快、影响范围极广。</span></span></p><h3 style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:14pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">防御建议</span></span></h3><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l10 level1;"><span style=""><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">1. </span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">依赖管理：固定生产环境依赖版本，避免自动升级，仅使用官方签名包；</span></span></p><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l10 level1;"><span style=""><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">2. </span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">权限管控：最小化 PyPI/GitHub 维护者权限，启用双因素认证，定期轮换 CI/CD 凭证；</span></span></p><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l10 level1;"><span style=""><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">3. </span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">检测防护：部署供应链安全工具，监控 PyPI 恶意版本，拦截 IOC 相关出站流量；</span></span></p><p style="text-align:left;line-height:1.6;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;mso-list:l10 level1;"><span style=""><span style="mso-list:Ignore;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;"><span leaf="">4. </span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">应急响应：建立包投毒应急流程，定期开展密钥轮换与环境审计，降低攻击影响。</span></span></p><p style="text-align:left;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">供应链安全已成为 AI 与云原生环境的核心薄弱点，TeamPCP 系列攻击警示开发者与企业：</span></span><span style="font-size:11pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">信任不能替代验证，每一次依赖更新都需严格校验</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">。</span></span></p><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">参考链接</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">：</span></span></p><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><a href="https://research.jfrog.com/post/xinference-compromise/" target="_blank">https://research.jfrog.com/post/xinference-compromise/</a></span></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=01d3c45c&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5MTc3ODY4Mw%3D%3D%26mid%3D2247508649%26idx%3D2%26sn%3Dde697976c81a783cbcb86ffaeb528875">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 23 Apr 2026 11:17:00 +0800</pubDate>
    </item>
    <item>
      <title>无条件接管Nginx！Nginx-UI漏洞链发现在野利用</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&amp;mid=2247508630&amp;idx=1&amp;sn=543bb7f3dbe8c36f4b62d8fdd61c0931</link>
      <description>立即查看详情 →</description>
      <content:encoded><![CDATA[<p>原创 <span>微步情报局</span> <span>2026-04-16 17:19</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d610ba96&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FfFyp1gWjicMKRfkOibMss786PqPwUGjHu4siboRiaqI4mguqRmR09PN8XVEaw2KnV8ORyrCRF8ZQz35agEmw3yebIQ%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>立即查看详情 →</p>
  <p style="outline: 0px;text-align: center;visibility: visible;margin-bottom: 0px;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-cropselx1="0" data-cropselx2="432" data-cropsely1="0" data-cropsely2="184" data-imgfileid="100021107" data-ratio="0.42592592592592593" data-s="300,640" style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);width: 480px !important;visibility: visible !important;height: auto !important;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=e78774c2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FfFyp1gWjicMKNkm4Pg1Ed6nv0proxQLEKJ2CUCIficfAwKfClJ84puialc9eER0oaibMn1FDUpibeK1t1YvgZcLYl3A%2F640%3Fwx_fmt%3Dpng%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></span></p><div style="font-size: 15px;" segoe="" pingfang="" data-pm-slice="0 0 []"><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 0 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞概况</span></span></p></div></div><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">Nginx-UI是一款广受欢迎的开源Nginx可视化管理面板，它提供简洁友好的Web界面，帮助用户轻松管理Nginx配置、申请证书、查看日志以及重载服务。</span></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">近日，微步情报局监测到Nginx-UI相关漏洞：CVE-2026-33032 出现在野利用行为。</span><span style="color: #d93025;font-weight: bold;"><span leaf="">微步情报局已成功复现。</span></span><span leaf="">经分析，Nginx-UI的MCP功能存在严重的鉴权缺陷：/mcp接口实现了严格的身份认证，但/mcp_message接口仅做了IP白名单校验，且当IP白名单为空（默认配置）时，系统会允许所有IP访问。由于/mcp接口需要严格认证，攻击者难以直接建立有效的MCP会话，也就无法获取sessionId，</span><span style="color: #d93025;font-weight: bold;"><span leaf="">因此仅从本漏洞来看，单独利用的难度较高，实际危害较为有限。</span></span><span leaf="">（完整漏洞情报请查阅<a href="https://x.threatbook.com/v5/vul/XVE-2026-10589）" target="_blank">https://x.threatbook.com/v5/vul/XVE-2026-10589）</a></span></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">但攻击者可以</span><span style="color: #d93025;font-weight: bold;"><span leaf="">结合另一个漏洞CVE-2026-27944</span></span><span leaf="">，下载并解密Nginx-UI的备份文件，从而获取有效的node_secret。随后使用node_secret 请求/mcp接口，建立MCP会话，获得有效的sessionId，</span><span leaf="" style="font-size: 15px;line-height: 1.6em;color: rgb(217, 48, 37);font-weight: bold;">最终实现对 /mcp_message 的未授权访问，执行任意MCP操作（如新增或修改Nginx配置、写入恶意文件、甚至重启Nginx服务），造成严重安全风险。</span></p><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞处置优先级(VPT)</span></span></p></div></div><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><strong style="font-size: 17px;letter-spacing: 0.034em;outline: 0px;"><span leaf="">综合处置优先级：</span></strong><span style="color: #d93025;font-weight: bold;font-size: 15px;"><span leaf="">中风险</span></span></p><table style="width: 100%;border-collapse: collapse;margin: 20px 0;font-size: 14px;table-layout: fixed;"><tbody><tr><td rowspan="3" style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">基本信息</span></p></td><td style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;"><p><span leaf="">微步编号</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">XVE-2026-10589</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">CVE编号</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">CVE-2026-33032</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">漏洞类型</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">认证绕过</span></p></td></tr><tr><td rowspan="5" style="border: 1px solid #ddd;padding: 12px;vertical-align: top;font-weight: bold;background-color: #f8f9fa;"><p><span leaf="">利用条件评估</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">利用漏洞的网络条件</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">远程</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">是否需要绕过安全机制</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">是</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">对被攻击系统的要求</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">无特殊要求</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">利用漏洞的权限要求</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">无须用户权限</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">是否需要受害者配合</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">否</span></p></td></tr><tr><td rowspan="2" style="border: 1px solid #ddd;padding: 12px;vertical-align: top;font-weight: bold;background-color: #f8f9fa;"><p><span leaf="">利用情报</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">POC是否公开</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><span style="color: #d93025;font-weight: bold;"><span leaf="">是</span></span></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">已知利用行为</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><span style="color: #d93025;font-weight: bold;"><span leaf="">存在在野利用行为</span></span></td></tr></tbody></table><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞影响范围</span></span></p></div></div><table style="border-collapse:collapse;margin:20px 0;font-size:14px;table-layout:fixed;min-width:314px;"><tbody><tr><td data-colwidth="289" style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">产品名称</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">Nginx-UI</span></p></td></tr><tr><td data-colwidth="289" style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">受影响版本</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">version &lt;= 2.3.3</span></p></td></tr><tr><td data-colwidth="289" style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">有无修复补丁</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">有</span></p></td></tr></tbody></table><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞复现</span></span></p></div></div><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;" nodeleaf=""><img alt="image.png" class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024977" data-ratio="0.413111342351717" data-w="961" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=a058cea6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEMR6526cgWy0kricoxTNibEhYSzpJLMTDYWRp8XxK73vPVYUSQQVNH8aOwwc2CcV7JH0aiaHrGAGCrYyWooecLzZGBD4080EVV82I%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">修复方案</span></span></p></div></div><h3 style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;pointer-events: initial;"><span leaf="">官方修复方案</span></h3><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">官方已发布修复方案，请访问链接下载：</span><span leaf=""><br/></span><span leaf=""><a href="https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.6" target="_blank">https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.6</a></span></p><h3 style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;pointer-events: initial;"><span leaf="">临时缓解措施</span></h3><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">配置层： 将可信IP设置为白名单(默认路径/etc/nginx-ui/app.ini)</span></p><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">微步产品支撑</span></span></p></div></div><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">微步漏洞情报于</span><span style="color: #d93025;font-weight: bold;"><span leaf="">2026-03-31</span></span><span leaf="">收录该漏洞。</span></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">微步下一代威胁情报平台NGTIP及X情报社区已于漏洞收录时向漏洞订阅用户推送该漏洞情报，并将持续推送后续更新；对于已经录入资产的用户，支持实时自动化排查受影响资产。</span></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;margin: 0;"><span leaf="">针对CVE-2026-33032，微步威胁感知平台TDP已于</span><span style="color: #d93025;font-weight: bold;"><span leaf="">20260416</span></span><span leaf="">支持检测，检测ID：</span><span style="color: #d93025;font-weight: bold;"><span leaf="">S3100174604，</span></span><span leaf="">模型/规则高于：</span><span style="color: #d93025;font-weight: bold;"><span leaf="">20260416000000</span></span><span leaf="">可检出。</span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3472222222222222" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100024980" src="https://wechat2rss.xlab.app/img-proxy/?k=eaf502a0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEOnrpGEaxskWcmkcNrnzDRFicp1OQ54txYTWsicribrBeQPtDBgfK4KZzwasESOYiab4QXwTkUTGn0oBmKzBs83DVM76V3TdP4ZJAE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">针对CVE-2026-27944，微步威胁感知平台TDP已于</span><span style="color: #d93025;font-weight: bold;"><span leaf="">20260416</span></span><span leaf="">支持检测，检测ID：</span><span style="color: #d93025;font-weight: bold;"><span leaf="">S3100174602，</span></span><span leaf="">模型/规则高于：</span><span style="color: #d93025;font-weight: bold;"><span leaf="">20260416000000</span></span><span leaf="">可检出。</span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.37407407407407406" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100024981" src="https://wechat2rss.xlab.app/img-proxy/?k=063663f7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEOFIsyovZ0MzeSqBf2FhibHYWiaSAcauS6tlEFVDYj6FA4WZGw8nrT9Ky0CiaVdYmwtCibicJYgJoibvegria4SVBGEY48ZwFB475BZy8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: center;margin-top: 24px;margin-bottom: 24px;"><span leaf="">- END -</span><div powered-by="xiumi.us" style="margin-bottom: 10px;outline: 0px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;"><div style="padding: 20px 15px;outline: 0px;display: inline-block;width: 677px;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: solid;border-width: 1px;border-color: rgba(189, 16, 16, 0.22);box-shadow: rgba(189, 16, 16, 0.22) 4px 4px 0px;"><div powered-by="xiumi.us" style="margin-top: 10px;outline: 0px;justify-content: flex-start;display: flex;flex-flow: row;"><div style="outline: 0px;display: inline-block;width: 645px;vertical-align: top;border-left: 3px solid rgb(232, 57, 57);border-bottom-left-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: -5px;margin-bottom: -5px;outline: 0px;"><div style="padding-right: 6px;padding-left: 6px;outline: 0px;font-size: 24px;color: rgb(233, 38, 52);line-height: 0.75;letter-spacing: 0px;text-align: justify;"><p style="outline: 0px;text-wrap: wrap;"><span style="outline: 0px;color: rgb(219, 0, 0);"><strong style="outline: 0px;"><span style="outline: 0px;font-size: 16px;"><span leaf="">微步漏洞情报订阅服务</span></span></strong></span></p></div></div></div></div><div powered-by="xiumi.us" style="outline: 0px;text-align: justify;color: rgb(131, 131, 131);"><p style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);line-height: 1.6em;"><span style="outline: 0px;font-family: 微软雅黑;letter-spacing: 0.578px;text-decoration: initial;text-decoration-color: rgba(0, 0, 0, 0.9);font-size: 14px;color: rgb(84, 84, 84);"><span leaf="">微步提供漏洞情报订阅服务，精准、高效助力企业漏洞运营：</span></span></p><ul style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);list-style-type: square;" class="list-paddingleft-1"><li style="outline: 0px;color: rgb(84, 84, 84);"><p style="margin-bottom: 8px;outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">提供高价值漏洞情报，具备及时、准确、全面和可操作性，帮助企业高效应对漏洞应急与日常运营难题；</span></span></p></li><li style="outline: 0px;color: rgb(84, 84, 84);"><p style="margin-bottom: 8px;outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">可实现对高威胁漏洞提前掌握，以最快的效率解决信息差问题，缩短漏洞运营MTTR；</span></span></p></li><li style="outline: 0px;color: rgb(84, 84, 84);"><p style="margin-bottom: 8px;outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">提供漏洞完整的技术细节，更贴近用户漏洞处置的落地；</span></span></p></li><li style="outline: 0px;color: rgb(84, 84, 84);"><p style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">将漏洞与威胁事件库、APT组织和黑产团伙攻击大数据、网络空间测绘等结合，对漏洞的实际风险进行持续动态更新</span></span><span leaf="">。</span></span></p></li></ul><p style="margin-right: 16px;margin-left: 16px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-wrap: wrap;background-color: rgb(255, 255, 255);letter-spacing: 0.578px;text-align: center;"><span style="outline: 0px;font-size: 14px;letter-spacing: 0.578px;"><span leaf="">扫码在线沟通</span></span></p><div style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);line-height: 1.8;visibility: visible;"><p style="margin: 0pt 16px 8px;outline: 0px;letter-spacing: 0.544px;text-align: center;line-height: 1.75em;"><span style="outline: 0px;color: rgb(63, 63, 63);font-size: 14px;letter-spacing: 1px;"><span leaf="">↓</span><span style="outline: 0px;"><span leaf="">↓↓</span></span></span></p><p style="margin-bottom: 16px;outline: 0px;letter-spacing: 0.544px;text-align: center;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="350" style="outline: 0px;display: initial;visibility: visible !important;width: 96px !important;height: auto !important;" width="96px" data-cropselx1="0" data-cropselx2="96" data-cropsely1="0" data-cropsely2="96" data-imgfileid="100021104" src="https://wechat2rss.xlab.app/img-proxy/?k=68b2dbe3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYv6ic9zgr5hQl5bZ5Mx6PTAQg6tGLiciarvXajTdDnQiacxmwJFZ0D3ictBOmuYyRk99bibwZV49wbap77LibGQHdQPtA%2F640%3Fwx_fmt%3Dpng%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></span></p><p style="margin-top: 0.5em;margin-bottom: 8px;outline: 0px;letter-spacing: 0.544px;text-align: center;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="200" style="outline: 0px;letter-spacing: 0.544px;display: initial;visibility: visible !important;width: 24px !important;height: auto !important;" width="24px" data-imgfileid="100021109" src="https://wechat2rss.xlab.app/img-proxy/?k=ffe38040&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYv6ic9zgr5hTIdM9koHZFkrtYe5WU5rHxSDicbiaNFjEBAs1rojKGviaJGjOGd9KwKzN4aSpnNZDA5UWpY2E0JAnNg%2F640%3Fwx_fmt%3Dpng%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></span></p><p style="outline: 0px;text-align: center;"><span style="outline: 0px;"><span leaf=""><a class="weapp_text_link js_weapp_entry" style="padding-right: 0px;padding-left: 0px;outline: 0px;color: var(--weui-LINK);cursor: pointer;font-size: 14px;" data-miniprogram-type="text" data-miniprogram-appid="wx0c720b24e005e633" data-miniprogram-path="p?p=400-030-1051" data-miniprogram-nickname="电话码" data-miniprogram-servicetype="" data-miniprogram-applink="">点此电话咨询</a></span></span></p></div></div><div powered-by="xiumi.us" style="margin-top: 10px;outline: 0px;justify-content: flex-start;display: flex;flex-flow: row;"><div style="outline: 0px;display: inline-block;width: 645px;vertical-align: top;border-left: 3px solid rgb(232, 57, 57);border-bottom-left-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: -5px;margin-bottom: -5px;outline: 0px;"><div style="padding-right: 6px;padding-left: 6px;outline: 0px;font-size: 24px;color: rgb(233, 38, 52);line-height: 0.75;letter-spacing: 0px;text-align: justify;"><p style="outline: 0px;text-wrap: wrap;"><span style="outline: 0px;color: rgb(219, 0, 0);"><strong style="outline: 0px;"><span style="outline: 0px;font-size: 16px;"><span leaf="">X漏洞奖励计划</span></span></strong></span></p></div></div></div></div><div powered-by="xiumi.us" style="outline: 0px;text-align: justify;"><p style="margin-bottom: 16px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);"><span style="outline: 0px;color: rgb(84, 84, 84);"><span style="outline: 0px;font-size: 14px;"><span leaf="">“X漏洞奖励计划”是微步X情报社区推出的一款</span></span><span style="outline: 0px;font-size: 14px;letter-spacing: 0.578px;text-decoration: initial;text-decoration-color: rgba(0, 0, 0, 0.9);"><span leaf="">针对未公开</span></span><span style="outline: 0px;font-size: 14px;"><span leaf="">漏洞的奖励计划，我们鼓励白帽子提交挖掘到的0day漏洞，并给予白帽子可观的奖励。我们期望通过该计划与白帽子共同努力，提升0day防御能力，守护数字世界安全。</span></span></span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);"><span style="outline: 0px;color: rgb(84, 84, 84);"><span style="outline: 0px;font-size: 14px;"><span leaf="">活动详情：</span></span><span style="outline: 0px;font-size: 14px;letter-spacing: 0.578px;text-decoration: initial;text-decoration-color: rgba(0, 0, 0, 0.9);"><span leaf=""><a href="https://x.threatbook.com/v5/vulReward" target="_blank">https://x.threatbook.com/v5/vulReward</a></span></span></span></p></div></div></div></div><p class="mp_profile_iframe_wrp" style="margin-bottom: 0px;outline: 0px;"><span leaf=""><mp-common-profile class="custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-nickname="微步在线研究响应中心" data-index="0" data-from="2" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/fFyp1gWjicML0NlKR16SxQGjNPSYVoUxGgXhXvI4Z8ia5h8C9TGibEic1ABv6fniame8h0dh6zGX8ndXT8icjQocVh8A/300?wx_fmt=png&amp;wxfrom=19" data-signature="微步情报局最新威胁事件分析、漏洞分析、安全研究成果共享，探究网络攻击的真相" data-id="Mzg5MTc3ODY4Mw==" data-origin_num="354" data-biz_account_status="0"></mp-common-profile></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=7047d52f&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5MTc3ODY4Mw%3D%3D%26mid%3D2247508630%26idx%3D1%26sn%3D543bb7f3dbe8c36f4b62d8fdd61c0931">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 16 Apr 2026 17:19:00 +0800</pubDate>
    </item>
    <item>
      <title>Apache Tomcat 远程代码执行漏洞，附漏洞自查方案</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&amp;mid=2247508620&amp;idx=1&amp;sn=c31f1cadfa7661cddf43b3388c7ead33</link>
      <description>立即查看详情 →</description>
      <content:encoded><![CDATA[<p>原创 <span>微步情报局</span> <span>2026-04-15 15:55</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d610ba96&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FfFyp1gWjicMKRfkOibMss786PqPwUGjHu4siboRiaqI4mguqRmR09PN8XVEaw2KnV8ORyrCRF8ZQz35agEmw3yebIQ%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>立即查看详情 →</p>
  <p style="outline: 0px;text-align: center;visibility: visible;margin-bottom: 0px;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-cropselx1="0" data-cropselx2="432" data-cropsely1="0" data-cropsely2="184" data-imgfileid="100021107" data-ratio="0.42592592592592593" data-s="300,640" style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);width: 480px !important;visibility: visible !important;height: auto !important;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=e78774c2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FfFyp1gWjicMKNkm4Pg1Ed6nv0proxQLEKJ2CUCIficfAwKfClJ84puialc9eER0oaibMn1FDUpibeK1t1YvgZcLYl3A%2F640%3Fwx_fmt%3Dpng%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></span></p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><div style="font-size: 15px;" segoe="" pingfang="" data-pm-slice="0 0 []"><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 0 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞概况</span></span></p></div></div><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">Apache Tomcat是一款开源的Java Servlet容器和Web服务器，广泛用于部署和运行Java Web应用。</span></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">近日，Apache Tomcat官方发布通告，修复了Apache Tomcat 远程代码执行漏洞（CVE-2026-34486）。</span><span style="color: #d93025;font-weight: bold;"><span leaf="">微步情报局已成功复现。</span></span><span leaf="">经分析，该漏洞源于针对CVE-2026-29146的修复引入了回归缺陷。在消息解密失败后，未能正确终止消息处理流程，而是继续调用 super.messageReceived(msg)，导致攻击者构造的未加密或加密错误的恶意消息能够绕过加密保护，直接进入 Tribes 集群的反序列化流程，</span><span style="color: #d93025;font-weight: bold;"><span leaf="">若服务器类路径中存在可利用的反序列化链，则可实现远程代码执行。</span></span><span leaf="">（完整漏洞情报请查阅<a href="https://x.threatbook.com/v5/vul/XVE-2026-12886）" target="_blank">https://x.threatbook.com/v5/vul/XVE-2026-12886）</a></span></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">此漏洞利用条件<span textstyle="" style="color: rgb(219, 0, 0);font-weight: bold;">较为苛刻</span>，建议用户通过如下方案自查：</span><span leaf=""><br/></span><span leaf="">1. 优先排查Tomcat版本</span><span leaf=""><br/></span><span leaf="">2. 集群状态和EncryptIntercepto排查：</span><span style="font-size:10.5pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-ascii-theme-font:minor-fareast;mso-fareast-theme-font:minor-fareast;mso-hansi-theme-font:minor-fareast;mso-bidi-font-family:宋体;mso-ansi-language:
EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:AR-SA;" data-pm-slice="0 0 []"><span leaf="">检查是否启用了</span><span lang="EN-US"><span leaf=""> Tribes </span></span><span leaf="">集群并开启</span><span lang="EN-US"><span leaf="">EncryptInterceptor</span></span><span leaf="">，此组件默认不开启，可自查配置文件</span><span lang="EN-US"><span leaf="">(</span></span><span leaf="">默认路径</span><span lang="EN-US"><span leaf="">$CATALINA_HOME/conf/server.xml)</span></span><span leaf="">中是否存在集群配置关键字(如：&#34;</span><span leaf="">SimpleTcpCluster</span><span leaf="">&#34;)和EncryptInterceptor关键字(如：<span textstyle="" style="color: rgb(0, 0, 0);font-weight: normal;">&#34;</span></span><b><span lang="EN-US" style="color:#D93025;"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);font-weight: normal;">encryptionKey=&#34;)</span></span></span></b></span></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="font-size:10.5pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-ascii-theme-font:minor-fareast;mso-fareast-theme-font:minor-fareast;mso-hansi-theme-font:minor-fareast;mso-bidi-font-family:宋体;mso-ansi-language:
EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:AR-SA;" data-pm-slice="0 0 []"><span leaf="">3. 检查集群端口（Tribes Receiver 端口）开放情况</span></span></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">建议受此漏洞影响用户</span><span style="color: #d93025;font-weight: bold;"><span leaf="">尽快修复。</span></span></p><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞处置优先级(VPT)</span></span></p></div></div><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><strong style="font-size: 17px;letter-spacing: 0.034em;outline: 0px;"><span leaf="">综合处置优先级：</span></strong><span style="color: #d93025;font-weight: bold;font-size: 15px;"><span leaf="">中风险</span></span></p><table style="width: 100%;border-collapse: collapse;margin: 20px 0;font-size: 14px;table-layout: fixed;"><tbody><tr><td rowspan="3" style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">基本信息</span></p></td><td style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;"><p><span leaf="">微步编号</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">XVE-2026-12886</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">CVE编号</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">CVE-2026-34486</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">漏洞类型</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">远程命令执行</span></p></td></tr><tr><td rowspan="5" style="border: 1px solid #ddd;padding: 12px;vertical-align: top;font-weight: bold;background-color: #f8f9fa;"><p><span leaf="">利用条件评估</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">利用漏洞的网络条件</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">远程</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">是否需要绕过安全机制</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">否</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">对被攻击系统的要求</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf=""><span textstyle="" style="font-size: 12px;">1.启用Tribes集群功能</span></span><span leaf=""><br/></span><span leaf=""><span textstyle="" style="font-size: 12px;">2.攻击者能够访问集群端口(默认于4000开放)</span></span><span leaf=""><br/></span><span leaf=""><span textstyle="" style="font-size: 12px;">3.集群通信配置EncryptInterceptor 拦截器</span></span><span leaf=""><br/></span><span leaf=""><span textstyle="" style="font-size: 12px;">4.目标服务器的Java类路径中存在可利用的反序列化链</span></span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">利用漏洞的权限要求</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">无须用户权限</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">是否需要受害者配合</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">否</span></p></td></tr><tr><td rowspan="2" style="border: 1px solid #ddd;padding: 12px;vertical-align: top;font-weight: bold;background-color: #f8f9fa;"><p><span leaf="">利用情报</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">POC是否公开</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">否</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">已知利用行为</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">暂无</span></p></td></tr></tbody></table><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞影响范围</span></span></p></div></div><table style="width: 100%;border-collapse: collapse;margin: 20px 0;font-size: 14px;table-layout: fixed;"><tbody><tr><td style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">产品名称</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">Apache Tomcat</span></p></td></tr><tr><td style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">受影响版本</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">9.0.116</span></p><p><span leaf="">10.1.53</span></p><p><span leaf="">11.0.20</span></p></td></tr><tr><td style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">有无修复补丁</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">有</span></p></td></tr></tbody></table><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞复现</span></span></p></div></div><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;" nodeleaf=""><img alt="image.png" class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024971" data-ratio="0.6894409937888198" data-w="483" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=617b65dd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEOaV0NwKH9UYDqiakLtyDKdJjoctOQSxg0Acc5Z5saOONQPicnN46n7P165rjgOg1ZicZJWB1wncIVCMjeb4iaNevoMlwLqS9VdJKM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">修复方案</span></span></p></div></div><h3 style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;pointer-events: initial;"><span leaf="">官方修复方案</span></h3><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">官方已发布修复方案，请访问链接下载：</span><span leaf=""><br/></span><span leaf=""><a href="https://tomcat.apache.org/download-90.cgi" target="_blank">https://tomcat.apache.org/download-90.cgi</a></span><span leaf=""><br/></span><span leaf=""><a href="https://tomcat.apache.org/download-101.cgi" target="_blank">https://tomcat.apache.org/download-101.cgi</a></span><span leaf=""><br/></span><span leaf=""><a href="https://tomcat.apache.org/download-110.cgi" target="_blank">https://tomcat.apache.org/download-110.cgi</a></span></p><h3 style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;pointer-events: initial;"><span leaf="">临时缓解措施</span></h3><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">网络层面严格限制Tomcat集群通信端口的访问来源。</span></p><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">微步产品支撑</span></span></p></div></div><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">微步漏洞情报于</span><span style="color: #d93025;font-weight: bold;"><span leaf="">2026-04-10</span></span><span leaf="">收录该漏洞。</span></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">微步下一代威胁情报平台NGTIP及X情报社区已于漏洞收录时向漏洞订阅用户推送该漏洞情报，并将持续推送后续更新；对于已经录入资产的用户，支持实时自动化排查受影响资产。</span></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;margin: 0;"><span leaf="">微步威胁感知平台TDP、<span textstyle="" style="font-style: normal;">微步威胁防御系统OneSIG</span></span><span leaf=""> Java反序列化攻击的通用规则默认可检出。</span></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;" nodeleaf=""><img alt="image.png" class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024970" data-ratio="0.47314814814814815" data-w="1080" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=976b54df&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEP5Ph6XbJXKtO3iaEsWrOian4mOjUYLuyeRzIx7TukgnFWh57icXd9KRmcZnsQ0gRVUpztCSL0E1DWMEM4eW9njneGXT5lGxPapkA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></figure><div style="text-align: center;margin-top: 24px;margin-bottom: 24px;"><span leaf="">- END -</span><div powered-by="xiumi.us" style="margin-bottom: 10px;outline: 0px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;"><div style="padding: 20px 15px;outline: 0px;display: inline-block;width: 677px;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: solid;border-width: 1px;border-color: rgba(189, 16, 16, 0.22);box-shadow: rgba(189, 16, 16, 0.22) 4px 4px 0px;"><div powered-by="xiumi.us" style="margin-top: 10px;outline: 0px;justify-content: flex-start;display: flex;flex-flow: row;"><div style="outline: 0px;display: inline-block;width: 645px;vertical-align: top;border-left: 3px solid rgb(232, 57, 57);border-bottom-left-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: -5px;margin-bottom: -5px;outline: 0px;"><div style="padding-right: 6px;padding-left: 6px;outline: 0px;font-size: 24px;color: rgb(233, 38, 52);line-height: 0.75;letter-spacing: 0px;text-align: justify;"><p style="outline: 0px;text-wrap: wrap;"><span style="outline: 0px;color: rgb(219, 0, 0);"><strong style="outline: 0px;"><span style="outline: 0px;font-size: 16px;"><span leaf="">微步漏洞情报订阅服务</span></span></strong></span></p></div></div></div></div><div powered-by="xiumi.us" style="outline: 0px;text-align: justify;color: rgb(131, 131, 131);"><p style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);line-height: 1.6em;"><span style="outline: 0px;font-family: 微软雅黑;letter-spacing: 0.578px;text-decoration: initial;text-decoration-color: rgba(0, 0, 0, 0.9);font-size: 14px;color: rgb(84, 84, 84);"><span leaf="">微步提供漏洞情报订阅服务，精准、高效助力企业漏洞运营：</span></span></p><ul style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);list-style-type: square;" class="list-paddingleft-1"><li style="outline: 0px;color: rgb(84, 84, 84);"><p style="margin-bottom: 8px;outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">提供高价值漏洞情报，具备及时、准确、全面和可操作性，帮助企业高效应对漏洞应急与日常运营难题；</span></span></p></li><li style="outline: 0px;color: rgb(84, 84, 84);"><p style="margin-bottom: 8px;outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">可实现对高威胁漏洞提前掌握，以最快的效率解决信息差问题，缩短漏洞运营MTTR；</span></span></p></li><li style="outline: 0px;color: rgb(84, 84, 84);"><p style="margin-bottom: 8px;outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">提供漏洞完整的技术细节，更贴近用户漏洞处置的落地；</span></span></p></li><li style="outline: 0px;color: rgb(84, 84, 84);"><p style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">将漏洞与威胁事件库、APT组织和黑产团伙攻击大数据、网络空间测绘等结合，对漏洞的实际风险进行持续动态更新</span></span><span leaf="">。</span></span></p></li></ul><p style="margin-right: 16px;margin-left: 16px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-wrap: wrap;background-color: rgb(255, 255, 255);letter-spacing: 0.578px;text-align: center;"><span style="outline: 0px;font-size: 14px;letter-spacing: 0.578px;"><span leaf="">扫码在线沟通</span></span></p><div style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);line-height: 1.8;visibility: visible;"><p style="margin: 0pt 16px 8px;outline: 0px;letter-spacing: 0.544px;text-align: center;line-height: 1.75em;"><span style="outline: 0px;color: rgb(63, 63, 63);font-size: 14px;letter-spacing: 1px;"><span leaf="">↓</span><span style="outline: 0px;"><span leaf="">↓↓</span></span></span></p><p style="margin-bottom: 16px;outline: 0px;letter-spacing: 0.544px;text-align: center;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="350" style="outline: 0px;display: initial;visibility: visible !important;width: 96px !important;height: auto !important;" width="96px" data-cropselx1="0" data-cropselx2="96" data-cropsely1="0" data-cropsely2="96" data-imgfileid="100021104" src="https://wechat2rss.xlab.app/img-proxy/?k=68b2dbe3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYv6ic9zgr5hQl5bZ5Mx6PTAQg6tGLiciarvXajTdDnQiacxmwJFZ0D3ictBOmuYyRk99bibwZV49wbap77LibGQHdQPtA%2F640%3Fwx_fmt%3Dpng%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></span></p><p style="margin-top: 0.5em;margin-bottom: 8px;outline: 0px;letter-spacing: 0.544px;text-align: center;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="200" style="outline: 0px;letter-spacing: 0.544px;display: initial;visibility: visible !important;width: 24px !important;height: auto !important;" width="24px" data-imgfileid="100021109" src="https://wechat2rss.xlab.app/img-proxy/?k=ffe38040&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYv6ic9zgr5hTIdM9koHZFkrtYe5WU5rHxSDicbiaNFjEBAs1rojKGviaJGjOGd9KwKzN4aSpnNZDA5UWpY2E0JAnNg%2F640%3Fwx_fmt%3Dpng%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></span></p><p style="outline: 0px;text-align: center;"><span style="outline: 0px;"><span leaf=""><a class="weapp_text_link js_weapp_entry" style="padding-right: 0px;padding-left: 0px;outline: 0px;color: var(--weui-LINK);cursor: pointer;font-size: 14px;" data-miniprogram-type="text" data-miniprogram-appid="wx0c720b24e005e633" data-miniprogram-path="p?p=400-030-1051" data-miniprogram-nickname="电话码" data-miniprogram-servicetype="" data-miniprogram-applink="">点此电话咨询</a></span></span></p></div></div><div powered-by="xiumi.us" style="margin-top: 10px;outline: 0px;justify-content: flex-start;display: flex;flex-flow: row;"><div style="outline: 0px;display: inline-block;width: 645px;vertical-align: top;border-left: 3px solid rgb(232, 57, 57);border-bottom-left-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: -5px;margin-bottom: -5px;outline: 0px;"><div style="padding-right: 6px;padding-left: 6px;outline: 0px;font-size: 24px;color: rgb(233, 38, 52);line-height: 0.75;letter-spacing: 0px;text-align: justify;"><p style="outline: 0px;text-wrap: wrap;"><span style="outline: 0px;color: rgb(219, 0, 0);"><strong style="outline: 0px;"><span style="outline: 0px;font-size: 16px;"><span leaf="">X漏洞奖励计划</span></span></strong></span></p></div></div></div></div><div powered-by="xiumi.us" style="outline: 0px;text-align: justify;"><p style="margin-bottom: 16px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);"><span style="outline: 0px;color: rgb(84, 84, 84);"><span style="outline: 0px;font-size: 14px;"><span leaf="">“X漏洞奖励计划”是微步X情报社区推出的一款</span></span><span style="outline: 0px;font-size: 14px;letter-spacing: 0.578px;text-decoration: initial;text-decoration-color: rgba(0, 0, 0, 0.9);"><span leaf="">针对未公开</span></span><span style="outline: 0px;font-size: 14px;"><span leaf="">漏洞的奖励计划，我们鼓励白帽子提交挖掘到的0day漏洞，并给予白帽子可观的奖励。我们期望通过该计划与白帽子共同努力，提升0day防御能力，守护数字世界安全。</span></span></span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);"><span style="outline: 0px;color: rgb(84, 84, 84);"><span style="outline: 0px;font-size: 14px;"><span leaf="">活动详情：</span></span><span style="outline: 0px;font-size: 14px;letter-spacing: 0.578px;text-decoration: initial;text-decoration-color: rgba(0, 0, 0, 0.9);"><span leaf=""><a href="https://x.threatbook.com/v5/vulReward" target="_blank">https://x.threatbook.com/v5/vulReward</a></span></span></span></p></div></div></div></div><p class="mp_profile_iframe_wrp" style="margin-bottom: 0px;outline: 0px;"><span leaf=""><mp-common-profile class="custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-nickname="微步在线研究响应中心" data-index="0" data-from="2" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/fFyp1gWjicML0NlKR16SxQGjNPSYVoUxGgXhXvI4Z8ia5h8C9TGibEic1ABv6fniame8h0dh6zGX8ndXT8icjQocVh8A/300?wx_fmt=png&amp;wxfrom=19" data-signature="微步情报局最新威胁事件分析、漏洞分析、安全研究成果共享，探究网络攻击的真相" data-id="Mzg5MTc3ODY4Mw==" data-origin_num="354" data-biz_account_status="0"></mp-common-profile></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=84ba5239&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5MTc3ODY4Mw%3D%3D%26mid%3D2247508620%26idx%3D1%26sn%3Dc31f1cadfa7661cddf43b3388c7ead33">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 15 Apr 2026 15:55:00 +0800</pubDate>
    </item>
    <item>
      <title>Axios爆SSRF漏洞，特定条件下可导致RCE</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&amp;mid=2247508614&amp;idx=1&amp;sn=b0d4f042ae9147e26d0eb657c7bcb744</link>
      <description>立即查看详情 →</description>
      <content:encoded><![CDATA[<p>原创 <span>微步情报局</span> <span>2026-04-14 15:06</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d610ba96&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FfFyp1gWjicMKRfkOibMss786PqPwUGjHu4siboRiaqI4mguqRmR09PN8XVEaw2KnV8ORyrCRF8ZQz35agEmw3yebIQ%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>立即查看详情 →</p>
  <p style="outline: 0px;text-align: center;visibility: visible;margin-bottom: 0px;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.42592592592592593" data-s="300,640" data-type="jpeg" data-w="1080" style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);width: 480px !important;visibility: visible !important;height: auto !important;" data-cropselx1="0" data-cropselx2="432" data-cropsely1="0" data-cropsely2="184" data-imgfileid="100021107" src="https://wechat2rss.xlab.app/img-proxy/?k=e78774c2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FfFyp1gWjicMKNkm4Pg1Ed6nv0proxQLEKJ2CUCIficfAwKfClJ84puialc9eER0oaibMn1FDUpibeK1t1YvgZcLYl3A%2F640%3Fwx_fmt%3Dpng%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></span></p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: flex;flex-direction: column;justify-content: center;align-items: center;"></figure><div style="font-size: 15px;" segoe="" pingfang="" data-pm-slice="0 0 []"><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 0 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞概况</span></span></p></div></div><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">Axios是一个基于Promise的HTTP客户端，广泛应用于浏览器和Node.js环境。</span></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">近日，Axios官方发布安全通告，修复了一个SSRF漏洞（CVE-2026-40175）。</span><span style="color: #d93025;font-weight: bold;"><span leaf="">微步情报局已成功复现该漏洞。</span></span><span leaf="">经分析，该漏洞</span><span style="color: #d93025;font-weight: bold;"><span leaf="">无需用户权限</span></span><span leaf="">即可利用。攻击者可通过传入相对URL或绝对URL的方式，控制请求发送至非预期目标，从而对内网服务发起探测与访问，</span><span style="color: #d93025;font-weight: bold;"><span leaf="">导致敏感信息泄露或内网资产被攻击。</span></span></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">值得注意的是，在特定场景下，若结合不安全的运行环境配置或业务代码，</span><span style="color: #d93025;font-weight: bold;"><span leaf="">影响会进一步扩大，导致远程代码执行</span></span><span leaf="">。建议受影响用户</span><span style="color: #d93025;font-weight: bold;"><span leaf="">尽快升级修复</span></span><span leaf="">。（完整漏洞情报请查阅 <a href="https://x.threatbook.com/v5/vul/XVE-2026-13154）" target="_blank">https://x.threatbook.com/v5/vul/XVE-2026-13154）</a></span></p><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞处置优先级(VPT)</span></span></p></div></div><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><strong style="font-size: 17px;letter-spacing: 0.034em;outline: 0px;"><span leaf="">综合处置优先级：</span></strong><span style="color: #d93025;font-weight: bold;font-size: 15px;"><span leaf="">中风险</span></span></p><table style="width: 100%;border-collapse: collapse;margin: 20px 0;font-size: 14px;table-layout: fixed;"><tbody><tr><td rowspan="3" style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">基本信息</span></p></td><td style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;"><p><span leaf="">微步编号</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">XVE-2026-13154</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">CVE编号</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">CVE-2026-40175</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">漏洞类型</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">SSRF</span></p></td></tr><tr><td rowspan="5" style="border: 1px solid #ddd;padding: 12px;vertical-align: top;font-weight: bold;background-color: #f8f9fa;"><p><span leaf="">利用条件评估</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">利用漏洞的网络条件</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">远程</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">是否需要绕过安全机制</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">否</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">对被攻击系统的要求</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">无特殊要求</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">利用漏洞的权限要求</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">无须用户权限</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">是否需要受害者配合</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">否</span></p></td></tr><tr><td rowspan="2" style="border: 1px solid #ddd;padding: 12px;vertical-align: top;font-weight: bold;background-color: #f8f9fa;"><p><span leaf="">利用情报</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">POC是否公开</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><span style="color: #d93025;font-weight: bold;"><span leaf="">是</span></span></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">已知利用行为</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">暂无</span></p></td></tr></tbody></table><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞影响范围</span></span></p></div></div><table style="width: 100%;border-collapse: collapse;margin: 20px 0;font-size: 14px;table-layout: fixed;"><tbody><tr><td style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">产品名称</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">Axios</span></p></td></tr><tr><td style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">受影响版本</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">&lt; 1.15.0</span></p></td></tr><tr><td style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">有无修复补丁</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">有</span></p></td></tr></tbody></table><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞复现</span></span></p></div></div><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">SSRF:</span></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;" nodeleaf=""><img data-aistatus="1" alt="image.png" class="rich_pages wxw-img" data-ratio="0.38742138364779877" data-type="png" data-w="795" data-imgfileid="100024964" src="https://wechat2rss.xlab.app/img-proxy/?k=032ee822&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEOWOF2FLM2CZYetvVqWyVVr80kCiciaaELBZU8mje80zs0wtyoc5AjZaIfBVicY7HtLaAMn94ZoTALDCA3zUJ80eMuGeWea5mo9ibo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">RCE:</span></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;" nodeleaf=""><img data-aistatus="1" alt="image.png" class="rich_pages wxw-img" data-ratio="0.9616228070175439" data-type="png" data-w="912" data-imgfileid="100024963" src="https://wechat2rss.xlab.app/img-proxy/?k=c2d82c3f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdENOVLI2BQMNUAu1uzfotaQMRfEAJjf8kqbc8qTicH3S7kn4otFwWwrbrASVBunA9qV5FZoibyjfQMjSYT0J2282sA7J4bFfWUFk0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">修复方案</span></span></p></div></div><h3 style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;pointer-events: initial;"><span leaf="">官方修复方案</span></h3><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">官方已发布修复方案，请访问链接下载：</span><span leaf=""><br/></span><span leaf=""><a href="https://github.com/axios/axios/releases/tag/v1.15.0" target="_blank">https://github.com/axios/axios/releases/tag/v1.15.0</a></span></p><h3 style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;pointer-events: initial;"><span leaf="">临时缓解措施</span></h3><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">配置层：对 Host 头进行严格校验，仅允许业务使用的合法域名，避免攻击者通过伪造或覆盖 Host 头访问非预期的内部服务；同时避免直接信任 X-Forwarded-Host、X-Host、X-Original-Host 等非标准头。</span></p><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">微步产品支撑</span></span></p></div></div><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">微步漏洞情报于</span><span style="color: #d93025;font-weight: bold;"><span leaf="">2026-04-11</span></span><span leaf="">收录该漏洞。</span></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">微步下一代威胁情报平台NGTIP及X情报社区已于漏洞收录时向漏洞订阅用户推送该漏洞情报，并将持续推送后续更新；对于已经录入资产的用户，支持实时自动化排查受影响资产。</span></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;margin: 0;"><span leaf="">微步威胁感知平台TDP已于</span><span style="color: #d93025;font-weight: bold;"><span leaf="">20260414</span></span><span leaf="">支持检测，检测ID：</span><span style="color: #d93025;font-weight: bold;"><span leaf="">S3100174564，</span></span><span leaf="">模型/规则高于：</span><span style="color: #d93025;font-weight: bold;"><span leaf="">20260414000000</span></span><span leaf="">可检出。</span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.387037037037037" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100024965" src="https://wechat2rss.xlab.app/img-proxy/?k=5130a906&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEP6FiaxPJFz6ghhzYSXb7Tf6wJucTibgibFQaWW4fdWJG7co93IMib5hk1fkH4zuiczQn4hmkZS08akoYcv9zWPl9fg2KBQLpu4D7BA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: center;margin-top: 24px;margin-bottom: 24px;"><span leaf="">- END -</span><div powered-by="xiumi.us" style="margin-bottom: 10px;outline: 0px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;"><div style="padding: 20px 15px;outline: 0px;display: inline-block;width: 677px;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: solid;border-width: 1px;border-color: rgba(189, 16, 16, 0.22);box-shadow: rgba(189, 16, 16, 0.22) 4px 4px 0px;"><div powered-by="xiumi.us" style="margin-top: 10px;outline: 0px;justify-content: flex-start;display: flex;flex-flow: row;"><div style="outline: 0px;display: inline-block;width: 645px;vertical-align: top;border-left: 3px solid rgb(232, 57, 57);border-bottom-left-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: -5px;margin-bottom: -5px;outline: 0px;"><div style="padding-right: 6px;padding-left: 6px;outline: 0px;font-size: 24px;color: rgb(233, 38, 52);line-height: 0.75;letter-spacing: 0px;text-align: justify;"><p style="outline: 0px;text-wrap: wrap;"><span style="outline: 0px;color: rgb(219, 0, 0);"><strong style="outline: 0px;"><span style="outline: 0px;font-size: 16px;"><span leaf="">微步漏洞情报订阅服务</span></span></strong></span></p></div></div></div></div><div powered-by="xiumi.us" style="outline: 0px;text-align: justify;color: rgb(131, 131, 131);"><p style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);line-height: 1.6em;"><span style="outline: 0px;font-family: 微软雅黑;letter-spacing: 0.578px;text-decoration: initial;text-decoration-color: rgba(0, 0, 0, 0.9);font-size: 14px;color: rgb(84, 84, 84);"><span leaf="">微步提供漏洞情报订阅服务，精准、高效助力企业漏洞运营：</span></span></p><ul style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);list-style-type: square;" class="list-paddingleft-1"><li style="outline: 0px;color: rgb(84, 84, 84);"><p style="margin-bottom: 8px;outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">提供高价值漏洞情报，具备及时、准确、全面和可操作性，帮助企业高效应对漏洞应急与日常运营难题；</span></span></p></li><li style="outline: 0px;color: rgb(84, 84, 84);"><p style="margin-bottom: 8px;outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">可实现对高威胁漏洞提前掌握，以最快的效率解决信息差问题，缩短漏洞运营MTTR；</span></span></p></li><li style="outline: 0px;color: rgb(84, 84, 84);"><p style="margin-bottom: 8px;outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">提供漏洞完整的技术细节，更贴近用户漏洞处置的落地；</span></span></p></li><li style="outline: 0px;color: rgb(84, 84, 84);"><p style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">将漏洞与威胁事件库、APT组织和黑产团伙攻击大数据、网络空间测绘等结合，对漏洞的实际风险进行持续动态更新</span></span><span leaf="">。</span></span></p></li></ul><p style="margin-right: 16px;margin-left: 16px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-wrap: wrap;background-color: rgb(255, 255, 255);letter-spacing: 0.578px;text-align: center;"><span style="outline: 0px;font-size: 14px;letter-spacing: 0.578px;"><span leaf="">扫码在线沟通</span></span></p><div style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);line-height: 1.8;visibility: visible;"><p style="margin: 0pt 16px 8px;outline: 0px;letter-spacing: 0.544px;text-align: center;line-height: 1.75em;"><span style="outline: 0px;color: rgb(63, 63, 63);font-size: 14px;letter-spacing: 1px;"><span leaf="">↓</span><span style="outline: 0px;"><span leaf="">↓↓</span></span></span></p><p style="margin-bottom: 16px;outline: 0px;letter-spacing: 0.544px;text-align: center;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="350" style="outline: 0px;display: initial;visibility: visible !important;width: 96px !important;height: auto !important;" width="96px" data-cropselx1="0" data-cropselx2="96" data-cropsely1="0" data-cropsely2="96" data-imgfileid="100021104" src="https://wechat2rss.xlab.app/img-proxy/?k=68b2dbe3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYv6ic9zgr5hQl5bZ5Mx6PTAQg6tGLiciarvXajTdDnQiacxmwJFZ0D3ictBOmuYyRk99bibwZV49wbap77LibGQHdQPtA%2F640%3Fwx_fmt%3Dpng%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></span></p><p style="margin-top: 0.5em;margin-bottom: 8px;outline: 0px;letter-spacing: 0.544px;text-align: center;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="200" style="outline: 0px;letter-spacing: 0.544px;display: initial;visibility: visible !important;width: 24px !important;height: auto !important;" width="24px" data-imgfileid="100021109" src="https://wechat2rss.xlab.app/img-proxy/?k=ffe38040&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYv6ic9zgr5hTIdM9koHZFkrtYe5WU5rHxSDicbiaNFjEBAs1rojKGviaJGjOGd9KwKzN4aSpnNZDA5UWpY2E0JAnNg%2F640%3Fwx_fmt%3Dpng%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></span></p><p style="outline: 0px;text-align: center;"><span style="outline: 0px;"><span leaf=""><a class="weapp_text_link js_weapp_entry" style="padding-right: 0px;padding-left: 0px;outline: 0px;color: var(--weui-LINK);cursor: pointer;font-size: 14px;" data-miniprogram-type="text" data-miniprogram-appid="wx0c720b24e005e633" data-miniprogram-path="p?p=400-030-1051" data-miniprogram-nickname="电话码" data-miniprogram-servicetype="" data-miniprogram-applink="">点此电话咨询</a></span></span></p></div></div><div powered-by="xiumi.us" style="margin-top: 10px;outline: 0px;justify-content: flex-start;display: flex;flex-flow: row;"><div style="outline: 0px;display: inline-block;width: 645px;vertical-align: top;border-left: 3px solid rgb(232, 57, 57);border-bottom-left-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: -5px;margin-bottom: -5px;outline: 0px;"><div style="padding-right: 6px;padding-left: 6px;outline: 0px;font-size: 24px;color: rgb(233, 38, 52);line-height: 0.75;letter-spacing: 0px;text-align: justify;"><p style="outline: 0px;text-wrap: wrap;"><span style="outline: 0px;color: rgb(219, 0, 0);"><strong style="outline: 0px;"><span style="outline: 0px;font-size: 16px;"><span leaf="">X漏洞奖励计划</span></span></strong></span></p></div></div></div></div><div powered-by="xiumi.us" style="outline: 0px;text-align: justify;"><p style="margin-bottom: 16px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);"><span style="outline: 0px;color: rgb(84, 84, 84);"><span style="outline: 0px;font-size: 14px;"><span leaf="">“X漏洞奖励计划”是微步X情报社区推出的一款</span></span><span style="outline: 0px;font-size: 14px;letter-spacing: 0.578px;text-decoration: initial;text-decoration-color: rgba(0, 0, 0, 0.9);"><span leaf="">针对未公开</span></span><span style="outline: 0px;font-size: 14px;"><span leaf="">漏洞的奖励计划，我们鼓励白帽子提交挖掘到的0day漏洞，并给予白帽子可观的奖励。我们期望通过该计划与白帽子共同努力，提升0day防御能力，守护数字世界安全。</span></span></span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);"><span style="outline: 0px;color: rgb(84, 84, 84);"><span style="outline: 0px;font-size: 14px;"><span leaf="">活动详情：</span></span><span style="outline: 0px;font-size: 14px;letter-spacing: 0.578px;text-decoration: initial;text-decoration-color: rgba(0, 0, 0, 0.9);"><span leaf=""><a href="https://x.threatbook.com/v5/vulReward" target="_blank">https://x.threatbook.com/v5/vulReward</a></span></span></span></p></div></div></div></div><p class="mp_profile_iframe_wrp" style="margin-bottom: 0px;outline: 0px;"><span leaf=""><mp-common-profile class="custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-nickname="微步在线研究响应中心" data-index="0" data-from="2" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/fFyp1gWjicML0NlKR16SxQGjNPSYVoUxGgXhXvI4Z8ia5h8C9TGibEic1ABv6fniame8h0dh6zGX8ndXT8icjQocVh8A/300?wx_fmt=png&amp;wxfrom=19" data-signature="微步情报局最新威胁事件分析、漏洞分析、安全研究成果共享，探究网络攻击的真相" data-id="Mzg5MTc3ODY4Mw==" data-origin_num="354" data-biz_account_status="0"></mp-common-profile></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=8cd8d923&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5MTc3ODY4Mw%3D%3D%26mid%3D2247508614%26idx%3D1%26sn%3Db0d4f042ae9147e26d0eb657c7bcb744">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 14 Apr 2026 15:06:00 +0800</pubDate>
    </item>
    <item>
      <title>Nginx曝新漏洞，特定配置下可实现任意文件读写</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&amp;mid=2247508609&amp;idx=1&amp;sn=e96453088406b1327576791d35a60bde</link>
      <description>立即查看详情 →</description>
      <content:encoded><![CDATA[<p>原创 <span>微步情报局</span> <span>2026-04-11 16:45</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d610ba96&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FfFyp1gWjicMKRfkOibMss786PqPwUGjHu4siboRiaqI4mguqRmR09PN8XVEaw2KnV8ORyrCRF8ZQz35agEmw3yebIQ%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>立即查看详情 →</p>
  <p style="outline: 0px;text-align: center;visibility: visible;margin-bottom: 0px;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-cropselx1="0" data-cropselx2="432" data-cropsely1="0" data-cropsely2="184" data-imgfileid="100021107" data-ratio="0.42592592592592593" data-s="300,640" style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);width: 480px !important;visibility: visible !important;height: auto !important;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=e78774c2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FfFyp1gWjicMKNkm4Pg1Ed6nv0proxQLEKJ2CUCIficfAwKfClJ84puialc9eER0oaibMn1FDUpibeK1t1YvgZcLYl3A%2F640%3Fwx_fmt%3Dpng%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></span></p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: flex;flex-direction: column;justify-content: center;align-items: center;"></figure><div style="font-size: 15px;" segoe="" pingfang="" data-pm-slice="0 0 []"><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 0 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞概况</span></span></p></div></div><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">Nginx是一款轻量级的高性能Web服务器和反向代理服务器。ngx_http_dav_module 是 Nginx 的一个内置 HTTP WebDAV 模块，用来让客户端通过 HTTP 方法直接操作服务器上的文件和目录。</span></p><p><span leaf="">微步情报局于今日监控到Ngnix ngx_http_dav_module模块缓冲区溢出漏洞（CVE-2026-27654）。微步情报局已成功复现。当Nginx配置同时满足以下条件时，攻击者可以通过特制请求触发缓冲区溢出：</span><span leaf=""><br/></span><span leaf="">1. location 是普通前缀块</span><span leaf=""><br/></span><span leaf="">2. 开启 dav_methods COPY/MOVE </span><span leaf=""><br/></span><span leaf="">3. 使用alias指令来映射本地目录</span></p><p><span leaf="">经分析，</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 15px;&#34;,&#34;segoe&#34;:&#34;&#34;,&#34;pingfang&#34;:&#34;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="font-size: 15px;color: rgb(217, 48, 37);font-weight: bold;">ngx_http_dav_module模块非默认安装，且漏洞</span><span leaf="" style="font-size: 15px;color: rgb(217, 48, 37);font-weight: bold;">依赖特殊配置，可能实际影响资产数量较为有限。但由于该漏洞aarch64架构上的利用脚本已公开，且能造成任意文件读写，建议用户自查当前Nginx配置是否满足上述利用条件，如果确认受影响请尽快修复。</span></p><p><span leaf="">（完整自查方案请查阅微步漏洞情报：<a href="https://x.threatbook.com/v5/vul/XVE-2026-9305）" target="_blank">https://x.threatbook.com/v5/vul/XVE-2026-9305）</a></span></p><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞处置优先级(VPT)</span></span></p></div></div><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><strong style="font-size: 17px;letter-spacing: 0.034em;outline: 0px;"><span leaf="">综合处置优先级：</span><span leaf="" style="line-height: 1.6em;color: rgb(217, 48, 37);font-weight: bold;font-size: 15px;">中</span></strong><span style="color: #d93025;font-weight: bold;font-size: 15px;"><span leaf="">风险</span></span></p><table style="width: 100%;border-collapse: collapse;margin: 20px 0;font-size: 14px;table-layout: fixed;"><tbody><tr><td rowspan="3" style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">基本信息</span></p></td><td style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;"><p><span leaf="">微步编号</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">XVE-2026-9305</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">CVE编号</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">CVE-2026-27654</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">漏洞类型</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">缓冲区溢出</span></p></td></tr><tr><td rowspan="5" style="border: 1px solid #ddd;padding: 12px;vertical-align: top;font-weight: bold;background-color: #f8f9fa;"><p><span leaf="">利用条件评估</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">利用漏洞的网络条件</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">远程</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">是否需要绕过安全机制</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">否</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">对被攻击系统的要求</span></p></td><td><p><span leaf="" style="color: rgb(217, 48, 37);font-weight: bold;">1.需要使用ngx_http_dav_module模块</span><span leaf="" style="color: rgb(217, 48, 37);font-weight: bold;"><br/></span><span leaf="" style="color: rgb(217, 48, 37);font-weight: bold;">2. 必须允许COPY或MOVE方法</span><span leaf="" style="color: rgb(217, 48, 37);font-weight: bold;"><br/></span><span leaf="" style="color: rgb(217, 48, 37);font-weight: bold;">3. 必须使用alias指令来映射本地目录</span><span leaf="" style="color: rgb(217, 48, 37);font-weight: bold;"><br/></span><span leaf="" style="color: rgb(217, 48, 37);font-weight: bold;">4. location配置中必须存在一个普通的、非正则表达式的URI前缀匹配块</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">利用漏洞的权限要求</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">无需用户权限</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">是否需要受害者配合</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">否</span></p></td></tr><tr><td rowspan="2" style="border: 1px solid #ddd;padding: 12px;vertical-align: top;font-weight: bold;background-color: #f8f9fa;"><p><span leaf="">利用情报</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">POC是否公开</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><span style="color: #d93025;font-weight: bold;"><span leaf="">是</span></span></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">已知利用行为</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">暂无</span></p></td></tr></tbody></table><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞影响范围</span></span></p></div></div><table style="width: 100%;border-collapse: collapse;margin: 20px 0;font-size: 14px;table-layout: fixed;"><tbody><tr><td style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">产品名称</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">F5 | NGINX</span></p></td></tr><tr><td style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">受影响版本</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><div><span leaf="">开源版</span><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">0.5.13 &lt;= version &lt;= 0.9.7</span><span leaf=""><br/></span><span leaf="">1.0.0 &lt;= version &lt; 1.28.3</span><span leaf=""><br/></span><span leaf="">1.29.0 &lt;= version &lt; 1.29.7</span></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">商业版</span></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">R36 分支：R36 &lt;= version &lt; R36 P3</span><span leaf=""><br/></span><span leaf="">R35 分支：R35 &lt;= version &lt; R35 P2</span><span leaf=""><br/></span><span leaf="">R34 分支：所有版本</span><span leaf=""><br/></span><span leaf="">R33 分支：所有版本</span><span leaf=""><br/></span><span leaf="">R32 分支：R32 &lt;= version &lt; R32 P5</span></p></div></td></tr><tr><td style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">有无修复补丁</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">有</span></p></td></tr></tbody></table><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞复现</span></span></p></div></div><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;" nodeleaf=""><img alt="image.png" class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024959" data-ratio="0.43148148148148147" data-w="1080" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=a50db1bd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEMu32CWIFc0Zw2leDsibAtQiaQs0GyjduclCL2OiaVgZ3f7SV9J7qYbWtgDVZreVh0sKONAejOCg7EIAxBYwFdVhGUZFFN0cibEDfs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">由上图可见成功读取/etc/passwd文件</span></p><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">修复方案</span></span></p></div></div><h3 style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;pointer-events: initial;"><span leaf="">官方修复方案</span></h3><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">官方已发布修复方案，请访问链接下载：</span><span leaf=""><br/></span><span leaf=""><a href="https://my.f5.com/manage/s/article/K000160382" target="_blank">https://my.f5.com/manage/s/article/K000160382</a></span></p><h3 style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;pointer-events: initial;"><span leaf="">临时缓解措施</span></h3><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">修改nginx.conf中对应的location块，在dav_methods中禁用COPY和MOVE方法，配置方式如下所示：</span><span leaf=""><br/></span><span leaf="">1. 将nginx.conf中dav_methods COPY; 修改为 dav_methods PUT DELETE MKCOL;</span><span leaf=""><br/></span><span leaf="">2. 检查Nginx配置：nginx -t -c /tmp/lab/nginx.conf -p /tmp/lab/</span><span leaf=""><br/></span><span leaf="">3. 重启 Nginx：nginx -s reload</span></p><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">微步产品支撑</span></span></p></div></div><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">微步漏洞情报于</span><span style="color: #d93025;font-weight: bold;"><span leaf="">2026-03-24</span></span><span leaf="">收录该漏洞。</span></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span leaf="">微步下一代威胁情报平台NGTIP及X情报社区已于漏洞收录时向漏洞订阅用户推送该漏洞情报，并将持续推送后续更新；对于已经录入资产的用户，支持实时自动化排查受影响资产。</span></p><p style="margin-left: 0;padding: 0;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;margin: 0;"><span leaf="">微步威胁感知平台TDP通用规则默认可检出。</span></p></div><div style="text-align: center;margin-top: 24px;margin-bottom: 24px;"><span leaf="">- END -</span><div powered-by="xiumi.us" style="margin-bottom: 10px;outline: 0px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;"><div style="padding: 20px 15px;outline: 0px;display: inline-block;width: 677px;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: solid;border-width: 1px;border-color: rgba(189, 16, 16, 0.22);box-shadow: rgba(189, 16, 16, 0.22) 4px 4px 0px;"><div powered-by="xiumi.us" style="margin-top: 10px;outline: 0px;justify-content: flex-start;display: flex;flex-flow: row;"><div style="outline: 0px;display: inline-block;width: 645px;vertical-align: top;border-left: 3px solid rgb(232, 57, 57);border-bottom-left-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: -5px;margin-bottom: -5px;outline: 0px;"><div style="padding-right: 6px;padding-left: 6px;outline: 0px;font-size: 24px;color: rgb(233, 38, 52);line-height: 0.75;letter-spacing: 0px;text-align: justify;"><p style="outline: 0px;text-wrap: wrap;"><span style="outline: 0px;color: rgb(219, 0, 0);"><strong style="outline: 0px;"><span style="outline: 0px;font-size: 16px;"><span leaf="">微步漏洞情报订阅服务</span></span></strong></span></p></div></div></div></div><div powered-by="xiumi.us" style="outline: 0px;text-align: justify;color: rgb(131, 131, 131);"><p style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);line-height: 1.6em;"><span style="outline: 0px;font-family: 微软雅黑;letter-spacing: 0.578px;text-decoration: initial;text-decoration-color: rgba(0, 0, 0, 0.9);font-size: 14px;color: rgb(84, 84, 84);"><span leaf="">微步提供漏洞情报订阅服务，精准、高效助力企业漏洞运营：</span></span></p><ul style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);list-style-type: square;" class="list-paddingleft-1"><li style="outline: 0px;color: rgb(84, 84, 84);"><p style="margin-bottom: 8px;outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">提供高价值漏洞情报，具备及时、准确、全面和可操作性，帮助企业高效应对漏洞应急与日常运营难题；</span></span></p></li><li style="outline: 0px;color: rgb(84, 84, 84);"><p style="margin-bottom: 8px;outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">可实现对高威胁漏洞提前掌握，以最快的效率解决信息差问题，缩短漏洞运营MTTR；</span></span></p></li><li style="outline: 0px;color: rgb(84, 84, 84);"><p style="margin-bottom: 8px;outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">提供漏洞完整的技术细节，更贴近用户漏洞处置的落地；</span></span></p></li><li style="outline: 0px;color: rgb(84, 84, 84);"><p style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">将漏洞与威胁事件库、APT组织和黑产团伙攻击大数据、网络空间测绘等结合，对漏洞的实际风险进行持续动态更新</span></span><span leaf="">。</span></span></p></li></ul><p style="margin-right: 16px;margin-left: 16px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-wrap: wrap;background-color: rgb(255, 255, 255);letter-spacing: 0.578px;text-align: center;"><span style="outline: 0px;font-size: 14px;letter-spacing: 0.578px;"><span leaf="">扫码在线沟通</span></span></p><div style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);line-height: 1.8;visibility: visible;"><p style="margin: 0pt 16px 8px;outline: 0px;letter-spacing: 0.544px;text-align: center;line-height: 1.75em;"><span style="outline: 0px;color: rgb(63, 63, 63);font-size: 14px;letter-spacing: 1px;"><span leaf="">↓</span><span style="outline: 0px;"><span leaf="">↓↓</span></span></span></p><p style="margin-bottom: 16px;outline: 0px;letter-spacing: 0.544px;text-align: center;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-cropselx1="0" data-cropselx2="96" data-cropsely1="0" data-cropsely2="96" data-imgfileid="100021104" data-ratio="1" data-s="300,640" width="96px" data-type="png" data-w="350" style="outline: 0px;display: initial;visibility: visible !important;width: 96px !important;height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=68b2dbe3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYv6ic9zgr5hQl5bZ5Mx6PTAQg6tGLiciarvXajTdDnQiacxmwJFZ0D3ictBOmuYyRk99bibwZV49wbap77LibGQHdQPtA%2F640%3Fwx_fmt%3Dpng%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></span></p><p style="margin-top: 0.5em;margin-bottom: 8px;outline: 0px;letter-spacing: 0.544px;text-align: center;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="200" style="outline: 0px;letter-spacing: 0.544px;display: initial;visibility: visible !important;width: 24px !important;height: auto !important;" width="24px" data-imgfileid="100021109" src="https://wechat2rss.xlab.app/img-proxy/?k=ffe38040&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYv6ic9zgr5hTIdM9koHZFkrtYe5WU5rHxSDicbiaNFjEBAs1rojKGviaJGjOGd9KwKzN4aSpnNZDA5UWpY2E0JAnNg%2F640%3Fwx_fmt%3Dpng%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></span></p><p style="outline: 0px;text-align: center;"><span style="outline: 0px;"><span leaf=""><a class="weapp_text_link js_weapp_entry" style="padding-right: 0px;padding-left: 0px;outline: 0px;color: var(--weui-LINK);cursor: pointer;font-size: 14px;" data-miniprogram-type="text" data-miniprogram-appid="wx0c720b24e005e633" data-miniprogram-path="p?p=400-030-1051" data-miniprogram-nickname="电话码" data-miniprogram-servicetype="" data-miniprogram-applink="">点此电话咨询</a></span></span></p></div></div><div powered-by="xiumi.us" style="margin-top: 10px;outline: 0px;justify-content: flex-start;display: flex;flex-flow: row;"><div style="outline: 0px;display: inline-block;width: 645px;vertical-align: top;border-left: 3px solid rgb(232, 57, 57);border-bottom-left-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: -5px;margin-bottom: -5px;outline: 0px;"><div style="padding-right: 6px;padding-left: 6px;outline: 0px;font-size: 24px;color: rgb(233, 38, 52);line-height: 0.75;letter-spacing: 0px;text-align: justify;"><p style="outline: 0px;text-wrap: wrap;"><span style="outline: 0px;color: rgb(219, 0, 0);"><strong style="outline: 0px;"><span style="outline: 0px;font-size: 16px;"><span leaf="">X漏洞奖励计划</span></span></strong></span></p></div></div></div></div><div powered-by="xiumi.us" style="outline: 0px;text-align: justify;"><p style="margin-bottom: 16px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);"><span style="outline: 0px;color: rgb(84, 84, 84);"><span style="outline: 0px;font-size: 14px;"><span leaf="">“X漏洞奖励计划”是微步X情报社区推出的一款</span></span><span style="outline: 0px;font-size: 14px;letter-spacing: 0.578px;text-decoration: initial;text-decoration-color: rgba(0, 0, 0, 0.9);"><span leaf="">针对未公开</span></span><span style="outline: 0px;font-size: 14px;"><span leaf="">漏洞的奖励计划，我们鼓励白帽子提交挖掘到的0day漏洞，并给予白帽子可观的奖励。我们期望通过该计划与白帽子共同努力，提升0day防御能力，守护数字世界安全。</span></span></span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);"><span style="outline: 0px;color: rgb(84, 84, 84);"><span style="outline: 0px;font-size: 14px;"><span leaf="">活动详情：</span></span><span style="outline: 0px;font-size: 14px;letter-spacing: 0.578px;text-decoration: initial;text-decoration-color: rgba(0, 0, 0, 0.9);"><span leaf=""><a href="https://x.threatbook.com/v5/vulReward" target="_blank">https://x.threatbook.com/v5/vulReward</a></span></span></span></p></div></div></div></div><p class="mp_profile_iframe_wrp" style="margin-bottom: 0px;outline: 0px;"><span leaf=""><mp-common-profile class="custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-nickname="微步在线研究响应中心" data-index="0" data-from="2" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/fFyp1gWjicML0NlKR16SxQGjNPSYVoUxGgXhXvI4Z8ia5h8C9TGibEic1ABv6fniame8h0dh6zGX8ndXT8icjQocVh8A/300?wx_fmt=png&amp;wxfrom=19" data-signature="微步情报局最新威胁事件分析、漏洞分析、安全研究成果共享，探究网络攻击的真相" data-id="Mzg5MTc3ODY4Mw==" data-origin_num="354" data-biz_account_status="0"></mp-common-profile></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=7ad1311e&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5MTc3ODY4Mw%3D%3D%26mid%3D2247508609%26idx%3D1%26sn%3De96453088406b1327576791d35a60bde">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sat, 11 Apr 2026 16:45:00 +0800</pubDate>
    </item>
    <item>
      <title>漏洞通告 | ActiveMQ远程代码执行漏洞</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&amp;mid=2247508577&amp;idx=1&amp;sn=9b54d7cab51cf308ac60ce38eaeeba12</link>
      <description>立即查看详情 →</description>
      <content:encoded><![CDATA[<p>原创 <span>微步情报局</span> <span>2026-04-09 08:31</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d610ba96&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FfFyp1gWjicMKRfkOibMss786PqPwUGjHu4siboRiaqI4mguqRmR09PN8XVEaw2KnV8ORyrCRF8ZQz35agEmw3yebIQ%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>立即查看详情 →</p>
  <p style="outline: 0px;text-align: center;visibility: visible;margin-bottom: 0px;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-cropselx1="0" data-cropselx2="432" data-cropsely1="0" data-cropsely2="184" data-imgfileid="100021107" data-ratio="0.42592592592592593" data-s="300,640" style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);width: 480px !important;visibility: visible !important;height: auto !important;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=e78774c2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FfFyp1gWjicMKNkm4Pg1Ed6nv0proxQLEKJ2CUCIficfAwKfClJ84puialc9eER0oaibMn1FDUpibeK1t1YvgZcLYl3A%2F640%3Fwx_fmt%3Dpng%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></span></p><div data-tool="mdnice编辑器" data-website="https://www.mdnice.com" style="margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 10px;padding-right: 10px;background-attachment: scroll;background-clip: border-box;background-color: rgba(0, 0, 0, 0);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;font-family: Optima, &#39;Microsoft YaHei&#39;, PingFangSC-regular, serif;font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;word-spacing: 0em;letter-spacing: 0em;word-break: break-word;overflow-wrap: break-word;text-align: left;" data-pm-slice="0 0 []"><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 0 0 12px 0;" data-tool="mdnice编辑器"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞概况</span></span></p></div></div><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">Apache ActiveMQ是一款开源的、实现了JMS规范的消息中间件，提供高性能的消息传递服务。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">近日，Apache ActiveMQ官方发布通告，修复了Apache ActiveMQ Jolokia接口代码注入漏洞（CVE-2026-34197）。</span><span style="color: #d93025;font-weight: bold;"><span leaf="">微步情报局已成功复现。</span></span><span leaf="">经分析，该漏洞利用需要具备普通用户权限，攻击者具备该权限后可构造特定请求使Broker配置远程加载恶意配置，进而实现代码执行。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span style="color: #d93025;font-weight: bold;"><span leaf="">值得注意的是，在ActiveMQ 6.x版本中，攻击者能够通过在CVE-2024-32114绕过鉴权，调用任意管理API，所以可结合本漏洞形成组合利用链，最终实现无条件远程代码执行。</span></span></p><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;" data-tool="mdnice编辑器"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞处置优先级(VPT)</span></span></p></div></div><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><strong style="color: rgb(0, 0, 0);font-weight: bold;background-attachment: scroll;background-clip: border-box;background-color: rgba(0, 0, 0, 0);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;font-size: 17px;letter-spacing: 0.034em;outline: 0px;"><span leaf="">综合处置优先级：</span></strong><span style="color: #d93025;font-weight: bold;font-size: 15px;"><span leaf="">中风险</span></span></p><table style="width: 100%;border-collapse: collapse;margin: 20px 0;font-size: 14px;table-layout: fixed;"><tbody><tr><td rowspan="3" style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">基本信息</span></p></td><td style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;"><p><span leaf="">微步编号</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">XVE-2026-11858</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">CVE编号</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">CVE-2026-34197</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">漏洞类型</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">代码注入</span></p></td></tr><tr><td rowspan="5" style="border: 1px solid #ddd;padding: 12px;vertical-align: top;font-weight: bold;background-color: #f8f9fa;"><p><span leaf="">利用条件评估</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">利用漏洞的网络条件</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">远程</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">是否需要绕过安全机制</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">否</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">对被攻击系统的要求</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">无特殊要求</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">利用漏洞的权限要求</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">需要普通用户权限</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">是否需要受害者配合</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">否</span></p></td></tr><tr><td rowspan="2" style="border: 1px solid #ddd;padding: 12px;vertical-align: top;font-weight: bold;background-color: #f8f9fa;"><p><span leaf="">利用情报</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">POC是否公开</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><span style="color: #d93025;font-weight: bold;"><span leaf="">是</span></span></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">已知利用行为</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">暂无</span></p></td></tr></tbody></table><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;" data-tool="mdnice编辑器"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞影响范围</span></span></p></div></div><table style="width: 100%;border-collapse: collapse;margin: 20px 0;font-size: 14px;table-layout: fixed;"><tbody><tr><td style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">产品名称</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">Apache ActiveMQ</span></p></td></tr><tr><td style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">受影响版本</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">version &lt;= 5.19.3, 6.0.0 &lt;= version &lt;= 6.2.2</span></p></td></tr><tr><td style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">有无修复补丁</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">有</span></p></td></tr></tbody></table><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;" data-tool="mdnice编辑器"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞复现</span></span></p></div></div><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024918" data-ratio="0.6785109983079526" style="display: block;margin-top: 0px;margin-right: auto;margin-bottom: 0px;margin-left: auto;max-width: 100%;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;object-fit: fill;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;" data-type="png" data-w="591" src="https://wechat2rss.xlab.app/img-proxy/?k=2fdb27f9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEP4ZukR7UlKHahYK5Tdhtm4WHaYaGQwXUOVUT5WudflYa5XTJqxrCkEJmdibtjviaRAd92VAEoWszCGcXiavbSgsUBNBa4NhJfB4Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">加载上述恶意XML文件：</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024919" data-ratio="0.55" style="display: block;margin-top: 0px;margin-right: auto;margin-bottom: 0px;margin-left: auto;max-width: 100%;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=b5643dd1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdENDHPPCFeG6eMpSAQ2qCx4FqXZqfNwmjDibP61u12PBib16UnkMoQS2xb3AftEzaibuXutIlfrnspdmK9YCkbyLdb6r5ZuzPdVYfA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/>可见文件成功创建。</span></p><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;" data-tool="mdnice编辑器"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">修复方案</span></span></p></div></div><h3 style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;pointer-events: initial;" data-tool="mdnice编辑器"><span leaf="">官方修复方案</span></h3><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">官方已发布修复方案，请访问链接下载：</span><span leaf=""><br/></span><span leaf=""><a href="https://activemq.apache.org/security-advisories.data/CVE-2026-34197-announcement.txt" target="_blank">https://activemq.apache.org/security-advisories.data/CVE-2026-34197-announcement.txt</a></span></p><h3 style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;pointer-events: initial;" data-tool="mdnice编辑器"><span leaf="">临时缓解措施</span></h3><p><span leaf="">1、网络层：程序默认只对本地127.0.0.1开放，若改为0.0.0.0请将程序收敛至内网，或设置白名单仅允许可信IP访问/api/jolokia</span></p><p><span leaf="">2、配置层：此漏洞利用需要普通用户权限，加强密码策略也可一定程度上限制此漏洞</span></p><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;" data-tool="mdnice编辑器"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">微步产品支撑</span></span></p></div></div><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">微步漏洞情报于</span><span style="color: #d93025;font-weight: bold;"><span leaf="">2026-04-06</span></span><span leaf="">收录该漏洞。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">微步下一代威胁情报平台NGTIP及X情报社区已于漏洞收录时向漏洞订阅用户推送该漏洞情报，并将持续推送后续更新；对于已经录入资产的用户，支持实时自动化排查受影响资产。</span></p><p style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;margin: 0;" data-tool="mdnice编辑器"><span leaf="">微步威胁感知平台TDP已于<span textstyle="" style="color: rgb(219, 0, 0);font-weight: bold;text-decoration: none;">20260408</span>支持检测，检测ID：</span><span style="color: #d93025;font-weight: bold;"><span leaf="">S3100174472，</span></span><span leaf="">模型/规则高于：</span><span style="color: #d93025;font-weight: bold;"><span leaf="">20260408000000</span></span></p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024917" data-ratio="0.3314814814814815" style="display: block;margin-top: 0px;margin-right: auto;margin-bottom: 0px;margin-left: auto;max-width: 100%;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;object-fit: fill;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=4ada6be5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEMiaFIiaeAJOsbpazxiaR3micvwnl71Q1ZWn2XpAKy1HDhRLzh9GpRicl1vCWYibLhd49ltDtUdCeEAaekof58Nw1I5an2IEHrx2LB7Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure></div><div style="text-align: center;margin-top: 24px;margin-bottom: 24px;"><span leaf="">- END -</span><div powered-by="xiumi.us" style="margin-bottom: 10px;outline: 0px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;"><div style="padding: 20px 15px;outline: 0px;display: inline-block;width: 677px;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: solid;border-width: 1px;border-color: rgba(189, 16, 16, 0.22);box-shadow: rgba(189, 16, 16, 0.22) 4px 4px 0px;"><div powered-by="xiumi.us" style="margin-top: 10px;outline: 0px;justify-content: flex-start;display: flex;flex-flow: row;"><div style="outline: 0px;display: inline-block;width: 645px;vertical-align: top;border-left: 3px solid rgb(232, 57, 57);border-bottom-left-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: -5px;margin-bottom: -5px;outline: 0px;"><div style="padding-right: 6px;padding-left: 6px;outline: 0px;font-size: 24px;color: rgb(233, 38, 52);line-height: 0.75;letter-spacing: 0px;text-align: justify;"><p style="outline: 0px;text-wrap: wrap;"><span style="outline: 0px;color: rgb(219, 0, 0);"><strong style="outline: 0px;"><span style="outline: 0px;font-size: 16px;"><span leaf="">微步漏洞情报订阅服务</span></span></strong></span></p></div></div></div></div><div powered-by="xiumi.us" style="outline: 0px;text-align: justify;color: rgb(131, 131, 131);"><p style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);line-height: 1.6em;"><span style="outline: 0px;font-family: 微软雅黑;letter-spacing: 0.578px;text-decoration: initial;text-decoration-color: rgba(0, 0, 0, 0.9);font-size: 14px;color: rgb(84, 84, 84);"><span leaf="">微步提供漏洞情报订阅服务，精准、高效助力企业漏洞运营：</span></span></p><ul style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);list-style-type: square;" class="list-paddingleft-1"><li style="outline: 0px;color: rgb(84, 84, 84);"><p style="margin-bottom: 8px;outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">提供高价值漏洞情报，具备及时、准确、全面和可操作性，帮助企业高效应对漏洞应急与日常运营难题；</span></span></p></li><li style="outline: 0px;color: rgb(84, 84, 84);"><p style="margin-bottom: 8px;outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">可实现对高威胁漏洞提前掌握，以最快的效率解决信息差问题，缩短漏洞运营MTTR；</span></span></p></li><li style="outline: 0px;color: rgb(84, 84, 84);"><p style="margin-bottom: 8px;outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">提供漏洞完整的技术细节，更贴近用户漏洞处置的落地；</span></span></p></li><li style="outline: 0px;color: rgb(84, 84, 84);"><p style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">将漏洞与威胁事件库、APT组织和黑产团伙攻击大数据、网络空间测绘等结合，对漏洞的实际风险进行持续动态更新</span></span><span leaf="">。</span></span></p></li></ul><p style="margin-right: 16px;margin-left: 16px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-wrap: wrap;background-color: rgb(255, 255, 255);letter-spacing: 0.578px;text-align: center;"><span style="outline: 0px;font-size: 14px;letter-spacing: 0.578px;"><span leaf="">扫码在线沟通</span></span></p><div style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);line-height: 1.8;visibility: visible;"><p style="margin: 0pt 16px 8px;outline: 0px;letter-spacing: 0.544px;text-align: center;line-height: 1.75em;"><span style="outline: 0px;color: rgb(63, 63, 63);font-size: 14px;letter-spacing: 1px;"><span leaf="">↓</span><span style="outline: 0px;"><span leaf="">↓↓</span></span></span></p><p style="margin-bottom: 16px;outline: 0px;letter-spacing: 0.544px;text-align: center;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="350" style="outline: 0px;display: initial;visibility: visible !important;width: 96px !important;height: auto !important;" width="96px" data-cropselx1="0" data-cropselx2="96" data-cropsely1="0" data-cropsely2="96" data-imgfileid="100021104" src="https://wechat2rss.xlab.app/img-proxy/?k=68b2dbe3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYv6ic9zgr5hQl5bZ5Mx6PTAQg6tGLiciarvXajTdDnQiacxmwJFZ0D3ictBOmuYyRk99bibwZV49wbap77LibGQHdQPtA%2F640%3Fwx_fmt%3Dpng%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></span></p><p style="margin-top: 0.5em;margin-bottom: 8px;outline: 0px;letter-spacing: 0.544px;text-align: center;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="200" style="outline: 0px;letter-spacing: 0.544px;display: initial;visibility: visible !important;width: 24px !important;height: auto !important;" width="24px" data-imgfileid="100021109" src="https://wechat2rss.xlab.app/img-proxy/?k=ffe38040&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYv6ic9zgr5hTIdM9koHZFkrtYe5WU5rHxSDicbiaNFjEBAs1rojKGviaJGjOGd9KwKzN4aSpnNZDA5UWpY2E0JAnNg%2F640%3Fwx_fmt%3Dpng%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></span></p><p style="outline: 0px;text-align: center;"><span style="outline: 0px;"><span leaf=""><a class="weapp_text_link js_weapp_entry" style="padding-right: 0px;padding-left: 0px;outline: 0px;color: var(--weui-LINK);cursor: pointer;font-size: 14px;" data-miniprogram-type="text" data-miniprogram-appid="wx0c720b24e005e633" data-miniprogram-path="p?p=400-030-1051" data-miniprogram-nickname="电话码" data-miniprogram-servicetype="" data-miniprogram-applink="">点此电话咨询</a></span></span></p></div></div><div powered-by="xiumi.us" style="margin-top: 10px;outline: 0px;justify-content: flex-start;display: flex;flex-flow: row;"><div style="outline: 0px;display: inline-block;width: 645px;vertical-align: top;border-left: 3px solid rgb(232, 57, 57);border-bottom-left-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: -5px;margin-bottom: -5px;outline: 0px;"><div style="padding-right: 6px;padding-left: 6px;outline: 0px;font-size: 24px;color: rgb(233, 38, 52);line-height: 0.75;letter-spacing: 0px;text-align: justify;"><p style="outline: 0px;text-wrap: wrap;"><span style="outline: 0px;color: rgb(219, 0, 0);"><strong style="outline: 0px;"><span style="outline: 0px;font-size: 16px;"><span leaf="">X漏洞奖励计划</span></span></strong></span></p></div></div></div></div><div powered-by="xiumi.us" style="outline: 0px;text-align: justify;"><p style="margin-bottom: 16px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);"><span style="outline: 0px;color: rgb(84, 84, 84);"><span style="outline: 0px;font-size: 14px;"><span leaf="">“X漏洞奖励计划”是微步X情报社区推出的一款</span></span><span style="outline: 0px;font-size: 14px;letter-spacing: 0.578px;text-decoration: initial;text-decoration-color: rgba(0, 0, 0, 0.9);"><span leaf="">针对未公开</span></span><span style="outline: 0px;font-size: 14px;"><span leaf="">漏洞的奖励计划，我们鼓励白帽子提交挖掘到的0day漏洞，并给予白帽子可观的奖励。我们期望通过该计划与白帽子共同努力，提升0day防御能力，守护数字世界安全。</span></span></span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);"><span style="outline: 0px;color: rgb(84, 84, 84);"><span style="outline: 0px;font-size: 14px;"><span leaf="">活动详情：</span></span><span style="outline: 0px;font-size: 14px;letter-spacing: 0.578px;text-decoration: initial;text-decoration-color: rgba(0, 0, 0, 0.9);"><span leaf=""><a href="https://x.threatbook.com/v5/vulReward" target="_blank">https://x.threatbook.com/v5/vulReward</a></span></span></span></p></div></div></div></div><p class="mp_profile_iframe_wrp" style="margin-bottom: 0px;outline: 0px;"><span leaf=""><mp-common-profile class="custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-nickname="微步在线研究响应中心" data-index="0" data-from="2" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/fFyp1gWjicML0NlKR16SxQGjNPSYVoUxGgXhXvI4Z8ia5h8C9TGibEic1ABv6fniame8h0dh6zGX8ndXT8icjQocVh8A/300?wx_fmt=png&amp;wxfrom=19" data-signature="微步情报局最新威胁事件分析、漏洞分析、安全研究成果共享，探究网络攻击的真相" data-id="Mzg5MTc3ODY4Mw==" data-origin_num="354" data-biz_account_status="0"></mp-common-profile></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=3f676d96&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5MTc3ODY4Mw%3D%3D%26mid%3D2247508577%26idx%3D1%26sn%3D9b54d7cab51cf308ac60ce38eaeeba12">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 09 Apr 2026 08:31:00 +0800</pubDate>
    </item>
    <item>
      <title>辟谣！Everything没被银狐投毒！</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&amp;mid=2247508574&amp;idx=1&amp;sn=4ba2ab35cad465087948d2cc96c03e72</link>
      <description>可以放心了</description>
      <content:encoded><![CDATA[<p><span>微步在线研究响应中心</span> <span>2026-04-08 17:54</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=00a7522f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FT4OSm0sXdEN1xYBic9ngcddpLDft1VsEc4iaI6uF5PAGJWEvIgiaKKRJibQQs3yXCL6xRSQ4HgHmU6SxrGDv6oj7UMTUNg4eoibiaQmv6tFG8OWaE%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>可以放心了</p>
  <p style="text-align: left;margin: 3pt 0pt;line-height: 1.75em;" data-pm-slice="0 0 []"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">2026年4月8日下午，微步</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">情报局</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">观察</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">到有传言</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">称</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">everything</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">工具</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">某</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">历史版本</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">被“银狐”投毒</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">，</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">经过</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">快速分析</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">，</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">我们</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">初步确认：</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">该</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">版本</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">的</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">everything</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">工具</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">被</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">“银狐</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">”</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">投毒</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">传言</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">为假</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">，</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">用户可</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">正常</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">使用</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">。</span></span></span></p><p style="text-align: left;margin: 3pt 0pt;line-height: 1.75em;"><span style="font-size: 12pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 18px;color: rgb(219, 0, 0);">事件起因与最终结论</span></span></span></p><p style="text-align: left;margin: 3pt 0pt;line-height: 1.75em;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">今天</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">下午</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">我们发现</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">有一个</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">名为</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">《</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">关于</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">everything</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">工具</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">1</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">.</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">4</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">.</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">1</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">.</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">1</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">0</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">2</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">2</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">版本</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">存在</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">可疑</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">木马</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">活动</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">的</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">排查情况</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">》</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">的</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">pdf</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">文件</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">正在</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">流传</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">，</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">我们</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">初步</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">分析</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">结论</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">如下</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">：</span></span></span></p><p style="text-align: left;margin: 3pt 0pt 3pt 16.8pt;text-indent: -16.8pt;line-height: 1.75em;" data-pm-slice="0 0 []"><span style=""><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;"><span leaf=""><span textstyle="" style="font-size: 15px;">1. </span></span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">文件中提及可疑</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">美国</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">IP</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">：</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">13.107.246.50</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">为</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(219, 0, 0);font-weight: bold;">C</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(219, 0, 0);font-weight: bold;">DN </span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(219, 0, 0);font-weight: bold;">IP</span></span></span></p><p style="text-align: left;margin: 3pt 0pt 3pt 16.8pt;text-indent: -16.8pt;line-height: 1.75em;"><span style=""><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;"><span leaf=""><span textstyle="" style="font-size: 15px;">2. </span></span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">文件中</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">提及</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">可疑</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">的</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">Everything-1.4.1.1022.x64-Setup.exe</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">文件</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">为</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">白文件</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">，</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(219, 0, 0);font-weight: bold;">已</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(219, 0, 0);font-weight: bold;">存在</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(219, 0, 0);font-weight: bold;">超过</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(219, 0, 0);font-weight: bold;">4</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(219, 0, 0);font-weight: bold;">年</span></span></span></p><p style="text-align: left;margin: 3pt 0pt 3pt 16.8pt;text-indent: -16.8pt;line-height: 1.75em;"><span style=""><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;"><span leaf=""><span textstyle="" style="font-size: 15px;">3. </span></span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">基于</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">现有</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">证据</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">无法</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">将</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">工具</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">安装包</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">关联</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">到</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">“</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">银狐</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">”</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">木马</span></span></span></p><p style="text-align: left;margin: 3pt 0pt 3pt 16.8pt;text-indent: -16.8pt;line-height: 1.75em;"><span style=""><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;"><span leaf=""><span textstyle="" style="font-size: 15px;">4. </span></span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">该</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">白文件</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">疑</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">为</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">银狐木马</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">运行</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">所</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">使用</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">的</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(219, 0, 0);font-weight: bold;">“白加黑</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(219, 0, 0);font-weight: bold;">”</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(219, 0, 0);font-weight: bold;">技术</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(219, 0, 0);font-weight: bold;">中</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(219, 0, 0);font-weight: bold;">的</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(219, 0, 0);font-weight: bold;">白文件</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">，用于加载</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">银狐黑</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">DLL</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">文件</span></span></span></p><p style="text-align: left;margin: 3pt 0pt;line-height: 1.75em;"><span style="display: inline-block;overflow: hidden;transform: rotate(0deg);width: 604.733px;height: 526.929px;text-indent: 0px;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.8712962962962963" data-type="png" data-w="1080" height="526.929" style="margin-left: 0px;margin-top: 0px;width: 604.733px;height: 526.929px;" width="604.733" data-imgfileid="100024912" src="https://wechat2rss.xlab.app/img-proxy/?k=9a9311be&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEMSiaNKfdMg0APNqC8b8sxxiahaUC0DWazp3TDG3nvZia8HYBUKWHRXRYmn8l2FyF6n6vHq4e3lASyc4ARbU5BzZlicaHyvKlW2Jn0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;margin: 3pt 0pt;line-height: 1.75em;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">pdf文档</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">首屏</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">截图</span></span></span></p><p style="text-align:left;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;" data-pm-slice="0 0 []"><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 18px;color: rgb(219, 0, 0);">详细分析</span></span></span></p><p style="text-align: left;margin: 3pt 0pt;line-height: 1.75em;" data-pm-slice="0 0 []"><span style="font-size: 12pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: normal;">针对</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">该文档</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">内</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">对应</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">的</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">官网</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">下载</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">地址</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">：</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;"><a href="https://www.voidtools.com/Everything-1.4.1.1022.x64-Setup.exe" target="_blank">https://www.voidtools.com/Everything-1.4.1.1022.x64-Setup.exe</a></span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">，</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">下载</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">样本</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">为</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">：</span></span></span></p><p style="text-align: left;margin: 3pt 0pt;line-height: 1.75em;" data-pm-slice="0 0 []"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">488d285760eb1aeb148e2aec18a2f063571a6630acb26a02b6751c56ca4a95be</span></span></span></p><p style="text-align: left;margin: 3pt 0pt;line-height: 1.75em;" data-pm-slice="0 0 []"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">该样本</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">至少存在</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">4</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">年</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">以上</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">，</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">于</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">2022</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">年</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">10</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">月</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">10</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">日</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">被</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">用户</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">上传至</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">微步</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">S</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">云</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">沙箱</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">，</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">经过</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">S</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">沙箱</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">分析</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">，</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">该</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">样本</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">为</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">正常</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">文件</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">：</span></span></span></p><p style="text-align: left;margin: 3pt 0pt;line-height: 1.75em;"><span style="display: inline-block;overflow: hidden;transform: rotate(0deg);width: 604.733px;height: 282.104px;text-indent: 0px;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024920" data-ratio="0.4666666666666667" width="604.733" data-type="png" data-w="1080" height="282.104" style="margin-left: 0px;margin-top: 0px;width: 604.733px;height: 282.104px;" src="https://wechat2rss.xlab.app/img-proxy/?k=02464c0e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEPnzsJSaFw0icQTHl9W8NxgEnmg0yKwlsNd5QTWYkwfD7lH3TtHNnr4floOxUDQQ3XXKOmicoUTpmMZTGd2OjcsbK97icXyd0VG0w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: left;margin: 3pt 0pt;line-height: 1.75em;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">针对</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">该</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">文档</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">中</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">恶意</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">IOC</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">：</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">hc15.ime.hk</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;"> /</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">bb.kgdhjc.com</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">为</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">银狐</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">远控</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">使用</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">IOC</span></span></span></p><p style="text-align:left;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;" data-pm-slice="0 0 []"><span style="display: inline-block;overflow: hidden;transform:rotate(0deg);width: 604.7333333333333px;height: 348.422467191601px;text-indent: 0;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024921" data-ratio="0.575925925925926" width="604.733" data-type="png" data-w="1080" height="348.422" style="margin-left: 0px;margin-top: 0px;width: 604.733px;height: 348.422px;" src="https://wechat2rss.xlab.app/img-proxy/?k=91cc6b75&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEOut6tdMy0AVNsu7gQwdpdfWGE9HjFmamcG9pjDZguNKf1X6HQHxVwKzmosNm0DrGibbRzSX244XgBl7k1GhBsMpJ9jLXdiau8pg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-size: 15px;">但银狐木马善于使用进程注入以及白加黑技术来进行免杀，所以发起远控请求的进程不一定是恶意程序，也可能包含白文件进程或者系统进程。</span></span></p><p style="line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-size: 15px;">因此社区用户会被误导分享该IP为银狐IOC，但实际为白文件所请求的CDN IP：</span></span></p><p style="text-align:left;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;" data-pm-slice="0 0 []"><span style="display: inline-block;overflow: hidden;transform:rotate(0deg);width: 604.7333333333333px;height: 499.5238845144357px;text-indent: 0;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.8260233918128655" data-type="png" data-w="684" height="499.524" style="margin-left: 0px;margin-top: 0px;width: 604.733px;height: 499.524px;" width="604.733" data-imgfileid="100024922" src="https://wechat2rss.xlab.app/img-proxy/?k=7a739b3e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdENaTgGPYEvFZ8zNb2pQhdkrhZj45WS1deeopDbRcF94KskaJTBN7dDmuic8r1JfvIhNc3rXib7Nm9wwR7u2dWeW3WuE7ibct3MUlc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="line-height: 1.75em;"><span leaf="" style=""><span textstyle="" style="font-size: 15px;">该银狐IOC关联的相关样本均为一些仿冒软件安装包程序，诱饵文件中包含：Chrome，搜狗输入法，汽水音乐，Xshell等常见软件。</span></span></p><p style="text-align:left;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;" data-pm-slice="0 0 []"><span style="display: inline-block;overflow: hidden;transform:rotate(0deg);width: 604.7333333333333px;height: 375.4879790026246px;text-indent: 0;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6212962962962963" data-type="png" data-w="1080" height="375.488" style="margin-left: 0px;margin-top: 0px;width: 604.733px;height: 375.488px;" width="604.733" data-imgfileid="100024923" src="https://wechat2rss.xlab.app/img-proxy/?k=a893f26d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdENCibPZFayGnJokQV3iaB4uzKZR9bDsXIHaibuhFECZKibBPFe3fjoUT3VHaDOyGFdeGP8TJHW710jUKvmJNfJHPibQE5boDibdXc9gU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;">这是银狐木马常见的仿冒钓鱼网站并投递银狐木马的攻击手法，微步情报局建议用户在尝试下载软件时，在x社区查询下载网站是否为钓鱼网站：</span></span></p><p style="text-align:left;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;" data-pm-slice="0 0 []"><span style="display: inline-block;overflow: hidden;transform:rotate(0deg);width: 604.7333333333333px;height: 241.89333333333335px;text-indent: 0;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4" data-type="png" data-w="1080" height="241.893" style="margin-left: 0px;margin-top: 0px;width: 604.733px;height: 241.893px;" width="604.733" data-imgfileid="100024924" src="https://wechat2rss.xlab.app/img-proxy/?k=f98e0f08&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEOoTzVaNvteTPxDfBkKIrxiaS9XCz2nGx9HHUWGbY48mXY7H43tK9PJd3lSLFVcsT2pGyTmqN8xFu1vuEYTR8cprKpHOic5AibcMQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-size: 15px;">同时在使用软件时，如对文件安全性存疑，推荐使用微步云沙箱进行检查后使用:</span></span></p><p style="line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-size: 15px;"><a href="http://s.threatbook.com" target="_blank">http://s.threatbook.com</a></span></span></p><p style="text-align:left;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;" data-pm-slice="0 0 []"><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 18px;color: rgb(219, 0, 0);">相关</span></span></span><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 18px;color: rgb(219, 0, 0);">恶意</span></span></span><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 18px;color: rgb(219, 0, 0);">IOC</span></span></span></p><p style="text-align:left;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">hc15.ime.hk</span></span></p><p style="text-align:left;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">bb.kgdhjc.com</span></span></p><p class="mp_profile_iframe_wrp" nodeleaf=""><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-nickname="微步在线研究响应中心" data-from="0" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/fFyp1gWjicML0NlKR16SxQGjNPSYVoUxGgXhXvI4Z8ia5h8C9TGibEic1ABv6fniame8h0dh6zGX8ndXT8icjQocVh8A/0?wx_fmt=png" data-signature="微步情报局最新威胁事件分析、漏洞分析、安全研究成果共享，探究网络攻击的真相" data-id="Mzg5MTc3ODY4Mw==" data-is_biz_ban="0" data-service_type="1" data-verify_status="2"></mp-common-profile></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.887890625" data-s="300,640" data-type="png" data-w="2560" type="block" data-imgfileid="100024925" src="https://wechat2rss.xlab.app/img-proxy/?k=a44348ad&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEOzRePK76EWxGV43BPZfRzmdOpakc8ibYnicF68iccD11wKzkrXxtbOu0H3VDYUibUn73UNcCHiaxzxiaTvTFKXXpDMEBSbMMGY40qEQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=7aa0894e&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5MTc3ODY4Mw%3D%3D%26mid%3D2247508574%26idx%3D1%26sn%3D4ba2ab35cad465087948d2cc96c03e72">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 08 Apr 2026 17:54:00 +0800</pubDate>
    </item>
    <item>
      <title>AI一句话挖出Vim RCE？还缺亿点点细节</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&amp;mid=2247508518&amp;idx=1&amp;sn=f6a96ec06480962b7fd83fa0c8baf4fc</link>
      <description>立即查看详情 →</description>
      <content:encoded><![CDATA[<p>原创 <span>微步情报局</span> <span>2026-04-01 08:05</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d610ba96&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FfFyp1gWjicMKRfkOibMss786PqPwUGjHu4siboRiaqI4mguqRmR09PN8XVEaw2KnV8ORyrCRF8ZQz35agEmw3yebIQ%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>立即查看详情 →</p>
  <p style="outline: 0px;text-align: center;visibility: visible;margin-bottom: 0px;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-cropselx1="0" data-cropselx2="432" data-cropsely1="0" data-cropsely2="184" data-imgfileid="100021107" data-ratio="0.42592592592592593" data-s="300,640" style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);width: 480px !important;visibility: visible !important;height: auto !important;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=e78774c2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FfFyp1gWjicMKNkm4Pg1Ed6nv0proxQLEKJ2CUCIficfAwKfClJ84puialc9eER0oaibMn1FDUpibeK1t1YvgZcLYl3A%2F640%3Fwx_fmt%3Dpng%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></span></p><div data-tool="mdnice编辑器" data-website="https://www.mdnice.com" style="margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 10px;padding-right: 10px;background-attachment: scroll;background-clip: border-box;background-color: rgba(0, 0, 0, 0);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;font-family: Optima, &#39;Microsoft YaHei&#39;, PingFangSC-regular, serif;font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;word-spacing: 0em;letter-spacing: 0em;word-break: break-word;overflow-wrap: break-word;text-align: left;" data-pm-slice="0 0 []"><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 0 0 12px 0;" data-tool="mdnice编辑器"><div style="outline: 0px;visibility: visible;"><div data-tool="mdnice编辑器" data-website="https://www.mdnice.com" style="margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 10px;padding-right: 10px;background-attachment: scroll;background-clip: border-box;background-color: rgba(0, 0, 0, 0);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;font-family: Optima, &#39;Microsoft YaHei&#39;, PingFangSC-regular, serif;font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;word-spacing: 0em;letter-spacing: 0em;word-break: break-word;overflow-wrap: break-word;text-align: left;" data-pm-slice="0 0 []"><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 0 0 12px 0;" data-tool="mdnice编辑器"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞概况</span></span></p></div></div><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">Vim是一款跨平台文本编辑器，其modeline功能允许在文件首尾行设置编辑器选项。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">近日，Vim官方发布通告，修复了Vim 远程代码执行漏洞（CVE-2026-34714）。</span><span style="color: #d93025;font-weight: bold;"><span leaf="">微步情报局已成功复现。</span></span><span leaf="">经分析，该漏洞源于Vim处理tabpanel选项时存在两处安全缺陷：tabpanel选项可通过modeline设置表达式而无需验证；autocmd_add()函数缺少安全检查，可在沙箱内注册沙箱外执行的自动命令。（完整漏洞情报请查阅<a href="https://x.threatbook.com/v5/vul/XVE-2026-10680）" target="_blank">https://x.threatbook.com/v5/vul/XVE-2026-10680）</a></span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">此漏洞</span><span style="color: #d93025;font-weight: bold;"><span leaf="">无须用户权限</span></span><span leaf="">，攻击者通过诱使受害者使用Vim打开恶意文件，</span><span style="color: #d93025;font-weight: bold;"><span leaf="">便可以受害者权限执行任意命令。</span></span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">需要注意的是，虽然此漏洞是安全研究员通过 Claude Code + Opus 4.6 使用一句Prompt便完成的漏洞挖掘，但目前<span textstyle="" style="color: rgb(219, 0, 0);font-weight: bold;">来看 AI 产出的漏洞缺失一些关键的细节，以至于还不能直接用到漏洞管控。</span></span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">以本漏洞为例，微步情报局在分析研究此漏洞的过程中发现：</span></p><ol style="list-style-type: decimal;margin-top: 8px;margin-bottom: 8px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 25px;padding-right: 0px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><p style="margin-top: 5px;margin-bottom: 5px;color: rgb(1, 1, 1);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;font-weight: normal;"><span leaf="">Vim有不同的编译版本，通过--with-features参数控制，当编译参数为normal和tiny时，Vim不受该漏洞影响。</span><span style="color: #d93025;font-weight: bold;"><span leaf="">例如，MacOS内置的Vim默认使用normal模式进行编译，不受此漏洞影响</span></span></p></li><li><p style="margin-top: 5px;margin-bottom: 5px;color: rgb(1, 1, 1);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;font-weight: normal;"><span leaf="">不同权限的用户对modeline的处理方式不同，</span><span style="color: #d93025;font-weight: bold;"><span leaf="">例如使用ROOT权限使用Vim时，需要在Vim配置文件中显示配置set modeline，所以以ROOT权限使用Vim默认不受影响</span></span></p></li><li><p style="margin-top: 5px;margin-bottom: 5px;color: rgb(1, 1, 1);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;font-weight: normal;"><span leaf="">当前Vim通告（AI提交）声称影响版本为 &lt; 9.2.0272。但结合代码与实测，</span><span style="color: #d93025;font-weight: bold;"><span leaf="">正确范围应为：9.1.1391（tabpanel 是从 v9.1.1391 才引入） &lt;= version &lt; 9.2.0272</span></span></p></li></ol><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span style="color: #d93025;font-weight: bold;"><span leaf=""> AI挖洞已成现实，但企业日常面临的漏洞“可管控、可修复”的是一个慎重且严谨的场景，还无法完全依赖AI自动化落地，仍然依赖高质量漏洞情报来保证漏洞治理效果。</span></span></p><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;" data-tool="mdnice编辑器"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞处置优先级(VPT)</span></span></p></div></div><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><strong style="color: rgb(0, 0, 0);font-weight: bold;background-attachment: scroll;background-clip: border-box;background-color: rgba(0, 0, 0, 0);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;font-size: 17px;letter-spacing: 0.034em;outline: 0px;"><span leaf="">综合处置优先级：</span></strong><span style="color: #d93025;font-weight: bold;font-size: 15px;"><span leaf="">中风险</span></span></p><table style="width: 100%;border-collapse: collapse;margin: 20px 0;font-size: 14px;table-layout: fixed;"><tbody><tr><td rowspan="3" style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">基本信息</span></p></td><td style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;"><p><span leaf="">微步编号</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">XVE-2026-10680</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">CVE编号</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">CVE-2026-34714</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">漏洞类型</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">RCE</span></p></td></tr><tr><td rowspan="5" style="border: 1px solid #ddd;padding: 12px;vertical-align: top;font-weight: bold;background-color: #f8f9fa;"><p><span leaf="">利用条件评估</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">利用漏洞的网络条件</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">远程</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">是否需要绕过安全机制</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">否</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">对被攻击系统的要求</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><span style="color: #d93025;font-weight: bold;"><span leaf="">确认启用tabpanel插件</span></span></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">利用漏洞的权限要求</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">无须用户权限</span></p></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">是否需要受害者配合</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf=""><span textstyle="" style="color: rgb(219, 0, 0);">是</span></span></p></td></tr><tr><td rowspan="2" style="border: 1px solid #ddd;padding: 12px;vertical-align: top;font-weight: bold;background-color: #f8f9fa;"><p><span leaf="">利用情报</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">POC是否公开</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><span style="color: #d93025;font-weight: bold;"><span leaf="">是</span></span></td></tr><tr><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">已知利用行为</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">否</span></p></td></tr></tbody></table><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;" data-tool="mdnice编辑器"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞影响范围</span></span></p></div></div><table style="width: 100%;border-collapse: collapse;margin: 20px 0;font-size: 14px;table-layout: fixed;"><tbody><tr><td style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">产品名称</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">Vim | Vim</span></p></td></tr><tr><td style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">受影响版本</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">v9.1.1391 &lt;= version &lt; v9.2.0272</span></p></td></tr><tr><td style="border: 1px solid rgb(221, 221, 221);padding: 12px;vertical-align: top;font-weight: bold;background-color: rgb(248, 249, 250);"><p><span leaf="">有无修复补丁</span></p></td><td style="border: 1px solid #ddd;padding: 12px;vertical-align: top;"><p><span leaf="">有</span></p></td></tr></tbody></table><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;" data-tool="mdnice编辑器"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">漏洞复现</span></span></p></div></div><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">1. 复现版本</span></p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024867" data-ratio="0.6284722222222222" style="display: block;margin-top: 0px;margin-right: auto;margin-bottom: 0px;margin-left: auto;max-width: 100%;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;object-fit: fill;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;" data-type="png" data-w="576" src="https://wechat2rss.xlab.app/img-proxy/?k=022ab43a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEONyHU9cXSxFWxQJRXIHDbjeXFzm9EjO2PpiahMuLHeYwW9PEmDBco39ic1YHrKIuxV6lJTRmP7SOpNfXub2O08KAgNxCRsEHG0A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure><ol style="list-style-type: decimal;margin-top: 8px;margin-bottom: 8px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 25px;padding-right: 0px;color: rgb(0, 0, 0);" class="list-paddingleft-1" start="2"><li><p style="margin-top: 5px;margin-bottom: 5px;color: rgb(1, 1, 1);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;font-weight: normal;"><span leaf="">触发</span></p></li></ol><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;"><span leaf="">vim poc.md</span></code></pre><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">打开后会看到 :!id&gt;/tmp/success 被执行提示，按回车，再输入 :q! 退出。</span></p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024866" data-ratio="0.2682186234817814" style="display: block;margin-top: 0px;margin-right: auto;margin-bottom: 0px;margin-left: auto;max-width: 100%;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;object-fit: fill;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;" data-type="png" data-w="988" src="https://wechat2rss.xlab.app/img-proxy/?k=6692a186&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEMk6ObALIGNsXBiaHibB6sQ5EeLXHWevktHxsASVNRjnZW3xhB9GIt6srQ1jdoPyAgHtGfuYeuUxTt59oHzqvve04QLFtA70UrjY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;" data-tool="mdnice编辑器"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">修复方案</span></span></p></div></div><h3 style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;pointer-events: initial;" data-tool="mdnice编辑器"><span leaf="">官方修复方案</span></h3><p data-pm-slice="0 0 []"><span leaf="">官方已发布漏洞通告，建议受影响的用户依据官方通告进行修复。</span></p><p><span leaf=""><a href="https://github.com/vim/vim/security/advisories/GHSA-2gmj-rpqf-pxvh" target="_blank">https://github.com/vim/vim/security/advisories/GHSA-2gmj-rpqf-pxvh</a></span></p><h3 style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;pointer-events: initial;" data-tool="mdnice编辑器"><span leaf="">临时缓解措施</span></h3><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">以下两种配置方式中任选一个即可：</span></p><ul style="list-style-type: disc;margin-top: 8px;margin-bottom: 8px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 25px;padding-right: 0px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><p style="margin-top: 5px;margin-bottom: 5px;color: rgb(1, 1, 1);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;font-weight: normal;"><span leaf="">禁用Modeline：在~/.vimrc中添加: </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">set nomodeline</span></code></p></li><li><p style="margin-top: 5px;margin-bottom: 5px;color: rgb(1, 1, 1);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;font-weight: normal;"><span leaf="">禁用Modeline表达式：在~/.vimrc中添加: </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">set modelineexpr=0</span></code></p></li></ul><div style="outline: 0px;display: flex;justify-content: flex-start;visibility: visible;margin: 24px 0 12px 0;" data-tool="mdnice编辑器"><div style="outline: 0px;visibility: visible;"><p data-brushtype="text" style="padding: 4px 3px;outline: 0px;font-size: 16px;letter-spacing: 1.5px;color: rgb(0, 0, 0);visibility: visible;"><span style="font-size: 18px;font-weight: bold;color: #d93025;border-left: 4px solid #d93025;padding-left: 15px;"><span leaf="">微步产品支撑</span></span></p></div></div><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">微步漏洞情报于</span><span style="color: #d93025;font-weight: bold;"><span leaf="">2026-03-30</span></span><span leaf="">收录该漏洞。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">微步下一代威胁情报平台NGTIP及X情报社区已于漏洞收录时向漏洞订阅用户推送该漏洞情报，并将持续推送后续更新；对于已经录入资产的用户，支持实时自动化排查受影响资产。</span></p><p style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;margin: 0;" data-tool="mdnice编辑器"><span leaf="">微步终端安全管理平台OneSEC已于</span><span style="color: #d93025;font-weight: bold;"><span leaf="">2026-03-31</span></span><span leaf="">支持检测，</span><span leaf="">以下为信创操作系统平台的检出截图。</span><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024865" data-ratio="0.31851851851851853" style="display: block;margin-top: 0px;margin-right: auto;margin-bottom: 0px;margin-left: auto;max-width: 100%;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;object-fit: fill;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=a0f4a9e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEOnewEyRx2LyaSqUM8J9qWUPH8kX1e335bzXdic0AziaxJZg2Dlibic6x6ITibqrfWPiabjH97hRL9iaZTicKibyMFJ49jBLbejPpqibJhKo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024864" data-ratio="0.1984511132623427" style="display: block;margin-top: 0px;margin-right: auto;margin-bottom: 0px;margin-left: auto;max-width: 100%;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;object-fit: fill;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px 0px;" data-type="png" data-w="1033" src="https://wechat2rss.xlab.app/img-proxy/?k=4d397f24&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEP92COT89A9scE6C4o5WnuGM3A3tyGGA2o7R3ibzeoSHqbicc6xdYShFukib3ZWKQLOUhHoWjXjG7ShGNMBNKFNENYIicxDnmqJp5I%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure></div></div></div></div><div style="text-align: center;margin-top: 24px;margin-bottom: 24px;"><span leaf="">- END -</span><div powered-by="xiumi.us" style="margin-bottom: 10px;outline: 0px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;"><div style="padding: 20px 15px;outline: 0px;display: inline-block;width: 677px;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: solid;border-width: 1px;border-color: rgba(189, 16, 16, 0.22);box-shadow: rgba(189, 16, 16, 0.22) 4px 4px 0px;"><div powered-by="xiumi.us" style="margin-top: 10px;outline: 0px;justify-content: flex-start;display: flex;flex-flow: row;"><div style="outline: 0px;display: inline-block;width: 645px;vertical-align: top;border-left: 3px solid rgb(232, 57, 57);border-bottom-left-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: -5px;margin-bottom: -5px;outline: 0px;"><div style="padding-right: 6px;padding-left: 6px;outline: 0px;font-size: 24px;color: rgb(233, 38, 52);line-height: 0.75;letter-spacing: 0px;text-align: justify;"><p style="outline: 0px;text-wrap: wrap;"><span style="outline: 0px;color: rgb(219, 0, 0);"><strong style="outline: 0px;"><span style="outline: 0px;font-size: 16px;"><span leaf="">微步漏洞情报订阅服务</span></span></strong></span></p></div></div></div></div><div powered-by="xiumi.us" style="outline: 0px;text-align: justify;color: rgb(131, 131, 131);"><p style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);line-height: 1.6em;"><span style="outline: 0px;font-family: 微软雅黑;letter-spacing: 0.578px;text-decoration: initial;text-decoration-color: rgba(0, 0, 0, 0.9);font-size: 14px;color: rgb(84, 84, 84);"><span leaf="">微步提供漏洞情报订阅服务，精准、高效助力企业漏洞运营：</span></span></p><ul style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);list-style-type: square;" class="list-paddingleft-1"><li style="outline: 0px;color: rgb(84, 84, 84);"><p style="margin-bottom: 8px;outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">提供高价值漏洞情报，具备及时、准确、全面和可操作性，帮助企业高效应对漏洞应急与日常运营难题；</span></span></p></li><li style="outline: 0px;color: rgb(84, 84, 84);"><p style="margin-bottom: 8px;outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">可实现对高威胁漏洞提前掌握，以最快的效率解决信息差问题，缩短漏洞运营MTTR；</span></span></p></li><li style="outline: 0px;color: rgb(84, 84, 84);"><p style="margin-bottom: 8px;outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">提供漏洞完整的技术细节，更贴近用户漏洞处置的落地；</span></span></p></li><li style="outline: 0px;color: rgb(84, 84, 84);"><p style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">将漏洞与威胁事件库、APT组织和黑产团伙攻击大数据、网络空间测绘等结合，对漏洞的实际风险进行持续动态更新</span></span><span leaf="">。</span></span></p></li></ul><p style="margin-right: 16px;margin-left: 16px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-wrap: wrap;background-color: rgb(255, 255, 255);letter-spacing: 0.578px;text-align: center;"><span style="outline: 0px;font-size: 14px;letter-spacing: 0.578px;"><span leaf="">扫码在线沟通</span></span></p><div style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);line-height: 1.8;visibility: visible;"><p style="margin: 0pt 16px 8px;outline: 0px;letter-spacing: 0.544px;text-align: center;line-height: 1.75em;"><span style="outline: 0px;color: rgb(63, 63, 63);font-size: 14px;letter-spacing: 1px;"><span leaf="">↓</span><span style="outline: 0px;"><span leaf="">↓↓</span></span></span></p><p style="margin-bottom: 16px;outline: 0px;letter-spacing: 0.544px;text-align: center;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="350" style="outline: 0px;display: initial;visibility: visible !important;width: 96px !important;height: auto !important;" width="96px" data-cropselx1="0" data-cropselx2="96" data-cropsely1="0" data-cropsely2="96" data-imgfileid="100021104" src="https://wechat2rss.xlab.app/img-proxy/?k=68b2dbe3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYv6ic9zgr5hQl5bZ5Mx6PTAQg6tGLiciarvXajTdDnQiacxmwJFZ0D3ictBOmuYyRk99bibwZV49wbap77LibGQHdQPtA%2F640%3Fwx_fmt%3Dpng%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></span></p><p style="margin-top: 0.5em;margin-bottom: 8px;outline: 0px;letter-spacing: 0.544px;text-align: center;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="200" style="outline: 0px;letter-spacing: 0.544px;display: initial;visibility: visible !important;width: 24px !important;height: auto !important;" width="24px" data-imgfileid="100021109" src="https://wechat2rss.xlab.app/img-proxy/?k=ffe38040&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYv6ic9zgr5hTIdM9koHZFkrtYe5WU5rHxSDicbiaNFjEBAs1rojKGviaJGjOGd9KwKzN4aSpnNZDA5UWpY2E0JAnNg%2F640%3Fwx_fmt%3Dpng%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></span></p><p style="outline: 0px;text-align: center;"><span style="outline: 0px;"><span leaf=""><a class="weapp_text_link js_weapp_entry" style="padding-right: 0px;padding-left: 0px;outline: 0px;color: var(--weui-LINK);cursor: pointer;font-size: 14px;" data-miniprogram-type="text" data-miniprogram-appid="wx0c720b24e005e633" data-miniprogram-path="p?p=400-030-1051" data-miniprogram-nickname="电话码" data-miniprogram-servicetype="" data-miniprogram-applink="">点此电话咨询</a></span></span></p></div></div><div powered-by="xiumi.us" style="margin-top: 10px;outline: 0px;justify-content: flex-start;display: flex;flex-flow: row;"><div style="outline: 0px;display: inline-block;width: 645px;vertical-align: top;border-left: 3px solid rgb(232, 57, 57);border-bottom-left-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: -5px;margin-bottom: -5px;outline: 0px;"><div style="padding-right: 6px;padding-left: 6px;outline: 0px;font-size: 24px;color: rgb(233, 38, 52);line-height: 0.75;letter-spacing: 0px;text-align: justify;"><p style="outline: 0px;text-wrap: wrap;"><span style="outline: 0px;color: rgb(219, 0, 0);"><strong style="outline: 0px;"><span style="outline: 0px;font-size: 16px;"><span leaf="">X漏洞奖励计划</span></span></strong></span></p></div></div></div></div><div powered-by="xiumi.us" style="outline: 0px;text-align: justify;"><p style="margin-bottom: 16px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);"><span style="outline: 0px;color: rgb(84, 84, 84);"><span style="outline: 0px;font-size: 14px;"><span leaf="">“X漏洞奖励计划”是微步X情报社区推出的一款</span></span><span style="outline: 0px;font-size: 14px;letter-spacing: 0.578px;text-decoration: initial;text-decoration-color: rgba(0, 0, 0, 0.9);"><span leaf="">针对未公开</span></span><span style="outline: 0px;font-size: 14px;"><span leaf="">漏洞的奖励计划，我们鼓励白帽子提交挖掘到的0day漏洞，并给予白帽子可观的奖励。我们期望通过该计划与白帽子共同努力，提升0day防御能力，守护数字世界安全。</span></span></span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);"><span style="outline: 0px;color: rgb(84, 84, 84);"><span style="outline: 0px;font-size: 14px;"><span leaf="">活动详情：</span></span><span style="outline: 0px;font-size: 14px;letter-spacing: 0.578px;text-decoration: initial;text-decoration-color: rgba(0, 0, 0, 0.9);"><span leaf=""><a href="https://x.threatbook.com/v5/vulReward" target="_blank">https://x.threatbook.com/v5/vulReward</a></span></span></span></p></div></div></div></div><p class="mp_profile_iframe_wrp" style="margin-bottom: 0px;outline: 0px;"><span leaf=""><mp-common-profile class="custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-nickname="微步在线研究响应中心" data-index="0" data-from="2" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/fFyp1gWjicML0NlKR16SxQGjNPSYVoUxGgXhXvI4Z8ia5h8C9TGibEic1ABv6fniame8h0dh6zGX8ndXT8icjQocVh8A/300?wx_fmt=png&amp;wxfrom=19" data-signature="微步情报局最新威胁事件分析、漏洞分析、安全研究成果共享，探究网络攻击的真相" data-id="Mzg5MTc3ODY4Mw==" data-origin_num="354" data-biz_account_status="0"></mp-common-profile></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=abc13be6&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5MTc3ODY4Mw%3D%3D%26mid%3D2247508518%26idx%3D1%26sn%3Df6a96ec06480962b7fd83fa0c8baf4fc">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 01 Apr 2026 08:05:00 +0800</pubDate>
    </item>
    <item>
      <title>OpenClaw又又又危！Axios npm被投毒，植入全平台木马</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&amp;mid=2247508505&amp;idx=1&amp;sn=906fb32ff9f5b00c2600c6eb37da2400</link>
      <description>今日，Axios这个年下载量超36亿、JavaScript 生态最核心的依赖之一，在 npm 仓库遭遇供应链投</description>
      <content:encoded><![CDATA[<p><span>微步情报局</span> <span>2026-03-31 13:40</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d641ccd3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FT4OSm0sXdENj8tdrGxgI95neZ2p1cL5d0HTQPEvCQYOjzEZUNQUC3OVPNcuMm8xXvR1EvEoBZe7bP6TaD1MEiaprcibaTCtfWGREzmVia7Oo3c%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 16px;" data-pm-slice="0 0 []"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">今日</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">，</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">Axios</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">这个</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">年</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">下载量</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">超</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">3</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">6</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">亿、</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">JavaScript 生态最核心</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">的</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">依赖</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">之一</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">，</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">在 npm 仓库遭遇供应链投毒。相关风险已传导至OpenClaw，</span><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(0, 0, 0);font-weight: normal;">在北京时间3月31日8:00-12:00期间正常安装使用OpenClaw时，会因上游依赖被污染而被动接触并</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(0, 0, 0);font-weight: normal;">感染</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(0, 0, 0);font-weight: normal;">恶意</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(0, 0, 0);font-weight: normal;">代码</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(0, 0, 0);font-weight: normal;">。</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 16px;" data-pm-slice="0 0 []"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(219, 0, 0);font-weight: bold;">恶意版本1.14.1与0.30.4会自动下载并运行远控木马，影响操作系统包括Windows、Linux及macOS。建议大家立即排查sfrclak.com反连情况（反连即失陷），处置方案详见后文。</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 16px;" data-pm-slice="0 0 []"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(0, 0, 0);font-weight: normal;">微步OneSEC EDR已经在安装OpenClaw的机器上，检测到恶意代码：</span></span></span></p><p style="text-align: center;margin-bottom: 0px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.19722222222222222" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100024847" src="https://wechat2rss.xlab.app/img-proxy/?k=1c2b3c03&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEObqDDwz0X6cu1ZY2s9uA5UdVwCLYPM0WTFxtQmHGwVYaEBqBOdQy1icVxtCEMNMh8wbGTaPTyY2hzmibvNrkriarQQNevKtic3oIY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;margin-top: 0px;"><span leaf=""><span textstyle="" style="font-size: 12px;">Windows检测结果</span></span></p><p style="text-align: center;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3584788029925187" data-s="300,640" data-type="png" data-w="1604" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/T4OSm0sXdEMYBQoTfLyB5FdpILWzWAicUbyC2icnvuRoVKeH8pCXkXr47dTWiauVgOwqFAfv0My53NBuItT6Mkd3kQ4g6BPh2KibJTqd1VWGQ4c/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="578" data-cropsely2="206" data-imgfileid="100024850" src="https://wechat2rss.xlab.app/img-proxy/?k=e67db44b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEMYBQoTfLyB5FdpILWzWAicUbyC2icnvuRoVKeH8pCXkXr47dTWiauVgOwqFAfv0My53NBuItT6Mkd3kQ4g6BPh2KibJTqd1VWGQ4c%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><span textstyle="" style="font-size: 12px;">macOS检测结果</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">微步</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">情报局</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">研判</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">认为</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">，</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">这次</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">投毒</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">的</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">潜在</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">影响面</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">几乎</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">包括</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">所有</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">HTTP 请求的Node.js和浏览器应用——从 React 前端到 CI/CD 工具，再到服务器端 API</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">。</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">目前</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">，</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">恶意</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">软件包</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">已被</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">官方</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">移除</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">。</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">大致</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">时间线（UTC）</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">如下</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">：</span></span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">3月30日23:59:12</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">：攻击者发布恶意依赖包plain-crypto-js@4.2.1</span></span></span></p></li><li><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">3月31日00:00左右</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">：攻击者利用被盗的 Axios 维护者 npm 账号，绕过 GitHub Actions CI/CD，手动发布axios@1.14.1与axios@0.30.4</span></span></span></p></li><li><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">3月31日00:05:41</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">：Socket.dev 自动化检测发现异常包plain-crypto-js</span></span></span></p></li><li><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 16px;"><span leaf="" style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;font-weight: bold;">3月31日04:00:00：</span><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">npm官方下架恶意npm包plain-crypto-js，axios@1.14.1与axios@0.30.4</span></span></p></li></ul><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 16px;" data-pm-slice="0 0 []"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 18px;letter-spacing: 1px;color: rgb(219, 0, 0);font-weight: bold;">事件分析</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 16px 0pt;" data-pm-slice="0 0 []"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">攻击者</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">在</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">3</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">月</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">3</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">0</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">日</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">注册</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">了</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">恶意</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">域名</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">：</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">sfrclak.com</span></span></span><span style="display: inline-block;overflow: hidden;transform: rotate(0deg);width: 604.733px;height: 137.328px;text-indent: 0px;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/T4OSm0sXdEPZlMmicICJgWr0jicvo3e0ibbOIibMTs1NGicZm4sulf6wibXrxhaOT4MbZvryk4OeuFF6hvPv4aVkshvCxqicuYODeMBEAcWKDiaE6wU/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="578" data-cropsely2="142" data-imgfileid="100024851" data-ratio="0.23284313725490197" data-s="300,640" style="margin-left: 0px;width: 604.733px;height: 137.328px;" data-type="png" data-w="1224" src="https://wechat2rss.xlab.app/img-proxy/?k=3c6266c6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEPZlMmicICJgWr0jicvo3e0ibbOIibMTs1NGicZm4sulf6wibXrxhaOT4MbZvryk4OeuFF6hvPv4aVkshvCxqicuYODeMBEAcWKDiaE6wU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">在</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">3</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">0</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">日</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">晚</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">发布</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">了</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">恶意</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">的</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">npm</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">包</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">plain-crypto-js@4.2.1</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">，</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">并</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">使用</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">盗取</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">的</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">Axios 维护者 npm 账号</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">更新</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">了</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">Axios</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">1</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">.</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">1</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">4</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">.</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">1</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">和</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">0.30.4</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">这两个</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">版本</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">，</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">并</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">在</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">这俩个</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">版本的</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">package.json</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">中</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">引入</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">了</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">恶意</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">的</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">npm</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">包</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">。</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">在</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">恶意</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">的</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">npm</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">包</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">plain-crypto-js@4.2.1</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">中</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">，</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">通过</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">package.json</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">引入</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">了</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">postinstall</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">触发</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">命令</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">：</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 16px;"><span style="display: inline-block;overflow: hidden;transform: rotate(0deg);width: 604.733px;height: 92.5004px;text-indent: 0px;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024839" data-ratio="0.15296052631578946" width="604.733" data-type="png" data-w="608" height="92.5004" style="margin-left: 0px;margin-top: 0px;width: 604.733px;height: 92.5004px;" src="https://wechat2rss.xlab.app/img-proxy/?k=e2b8572a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEOrdXrOEMqMBZtjo6ksZtQQshaEbz9rMEYoFhaXv3ia3HYwalnH5g6B6FLPCyAicYvuVIKwgWiceVJwNkYptoHYhHuxJicJt9ZkQbg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">运行</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">的</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">set</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">up</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">.</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">j</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">s</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">是</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">一个</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">混淆</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">的</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">js</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">代码</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">：</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 16px;"><span style="display: inline-block;overflow: hidden;transform: rotate(0deg);width: 604.733px;height: 131.12px;text-indent: 0px;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024842" data-ratio="0.21666666666666667" width="604.733" data-type="png" data-w="1080" height="131.12" style="margin-left: 0px;margin-top: 0px;width: 604.733px;height: 131.12px;" src="https://wechat2rss.xlab.app/img-proxy/?k=f90c7ab5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdENOqleN5WSzLxXiaEYn57jZpv13C8JnEicKtcd2WYuKfHiaTZFiaeG50ymFD3ppRODfZvA5XLbqbcqedWXu9EvucibibxSiaIrFbtXPq8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">该</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">js</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">文件</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">的</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">作用</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">是</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">检测</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">运行</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">的</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">主机</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">的</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">平台</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">，</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">并</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">根据</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">运行</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">平台</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">从</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">攻击者</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">服务</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">通过</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">下载</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">不同</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">的</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">后续</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">载荷</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">：</span></span></span></p><p style="margin-top: 16px;"><span leaf="" style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">攻击者服务器URL地址：<a href="http://sfrclak.com:8000/6202033" target="_blank">http://sfrclak.com:8000/6202033</a></span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024855" data-ratio="0.25277777777777777" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=963ffd8f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEMz7aEI5O10fbPdy76asz7OIMW6zlVaaHDY1GfC75tdoafia9Hz2E5EGla6p4q5lecm3b141qCbrdY4ayI6YW9JnslxLRZhbIl4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 16px;" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">云沙箱S、沙箱分析平台OneSandbox检测结果如下</span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 16px;" data-pm-slice="0 0 []"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.6497056349873843" data-s="300,640" data-type="png" data-w="2378" type="block" data-imgfileid="100024852" src="https://wechat2rss.xlab.app/img-proxy/?k=13a3c9a5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEO1ptTIZqp3hTtmSGwWiblIHVFXrgNNjaZxq1xRVjMuVADR1dDzMDccPOzyHHIIe9T94pnLxy7iajvgKWX9j6WXC1BM7FPqeiaFBs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 16px;" data-pm-slice="0 0 []"><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">目前</span></span></span><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">后续</span></span></span><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">载荷</span></span></span><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">无法</span></span></span><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">下载</span></span></span><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">分析</span></span></span><span data-font-family="default"><span leaf="" style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">。</span></span></span></p><p style="margin-bottom: 16px;line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 18px;letter-spacing: 1px;color: rgb(219, 0, 0);font-weight: bold;">排查方案</span></span></p><p style="margin-bottom: 16px;line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">排查恶意域名</span><span textstyle="" style="font-size: 15px;letter-spacing: 1px;font-weight: bold;">sfrclak.com</span><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">反连情况</span></span></p><p style="margin-bottom: 16px;line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">检查项目中是否有恶意的 Axios 版本：</span></span></p><p style="margin-bottom: 16px;line-height: 1.6em;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.10336538461538461" data-s="300,640" data-type="png" data-w="1248" type="block" data-imgfileid="100024844" src="https://wechat2rss.xlab.app/img-proxy/?k=f25e6062&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEPughQ8VWV72rZ6tNWqPLKic2I6J1qcbhYw6DNA2jEcZ77ebg6vb55eQgicJhKBqSfdDU5gdA3QB8F3HEuOgdia481N3J7U81FL1k%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="margin-bottom: 16px;line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">检查node_modules中的恶意npm包：</span></span></p><p style="margin-bottom: 16px;line-height: 1.6em;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.06954436450839328" data-s="300,640" data-type="png" data-w="1251" type="block" data-imgfileid="100024845" src="https://wechat2rss.xlab.app/img-proxy/?k=b0ac11ef&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdENSbAgrkLb38X6lBppE8yldo11ibiaScKJmzf96qia2IDEH02CH7KZdaiaYkP6emBthCibJoSyjnWYzDGfpqEqLq6X7hQroFKgVLl7k%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="margin-bottom: 16px;line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">如果已经运行，该目录内的存根将被替换为干净的存根。目录的存在足以证明加载器已执行。setup.jspackage.json检查受影响系统上的RAT伪影：</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3333333333333333" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100024846" src="https://wechat2rss.xlab.app/img-proxy/?k=02e94477&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEN1rqMroFghrk7wlYFcxpt8KzYrbucuNehtZ1dUdcP5740gWX4bk3A5jnWjFhcgA7m6xNgTUs2y49SEicP1rPXV1J3KskfjUO4I%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-bottom: 16px;line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">‍</span></span></p><p style="margin-bottom: 16px;line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 18px;letter-spacing: 1px;color: rgb(219, 0, 0);font-weight: bold;">临时处置建议</span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 16px;" data-pm-slice="0 0 []"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;font-weight: bold;">封禁</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;font-weight: bold;">域名</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;font-weight: bold;">：</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">sfrclak.com</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">/</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">callnrwise.com</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 16px;" data-pm-slice="0 0 []"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;font-weight: bold;">排查</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;font-weight: bold;">自身</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;font-weight: bold;">环境</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;font-weight: bold;">：</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">Axios</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">的</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">版本</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">是否</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">为</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">受影响</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">的</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">版本</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">1</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">.</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">1</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">4</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">.</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">1</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">或</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">0.30.4</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;font-weight: bold;">排查</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;font-weight: bold;">服务</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;font-weight: bold;">依赖</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">中</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">是否</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">存在</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">恶意</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">npm</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">包</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">：</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">plain-crypto-js@4.2.1</span></span></span></p><p style="text-align: left;line-height: 1.3;margin: 3pt 0pt 16px;"><span style="font-size: 11pt;font-weight: bold;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 18px;color: rgb(219, 0, 0);">附录</span></span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.55" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100024856" src="https://wechat2rss.xlab.app/img-proxy/?k=3b845546&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdENJTISCQNZ5Tiar4DoaZbibBF4gjZ7nib1MC6oLxCtG4mqF09gIRuubg8lISOpBJBQby1qJQh3OOvDTNiaSRlDf77P78OPaiaTExChg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: left;line-height: 1.6em;margin: 16px 0pt;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">另</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">外</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">，</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">微步</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">情报局</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">在</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">拓线</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">分析</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">过程</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">中</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">，</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">发</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">现</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">以下</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">I</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">O</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">C</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">高</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">度</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">疑似</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">攻击</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">者</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">持有</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">资产</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">，</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">用户</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">可</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">根据</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">业务</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">情况</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">提前</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">进</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">行</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">封禁</span></span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">。</span></span></span></p><p style="text-align: left;margin: 16px 0pt;line-height: 1.6em;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">142.11.196.73</span></span></span></p><p style="text-align: left;line-height: 1.6em;margin: 16px 0pt;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">142.11.199.73</span></span></span></p><p style="margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;letter-spacing: 1px;">-END-</span></span></p><p class="mp_profile_iframe_wrp" nodeleaf=""><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-nickname="微步在线研究响应中心" data-from="0" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/fFyp1gWjicML0NlKR16SxQGjNPSYVoUxGgXhXvI4Z8ia5h8C9TGibEic1ABv6fniame8h0dh6zGX8ndXT8icjQocVh8A/0?wx_fmt=png" data-signature="微步情报局最新威胁事件分析、漏洞分析、安全研究成果共享，探究网络攻击的真相" data-id="Mzg5MTc3ODY4Mw==" data-is_biz_ban="0" data-service_type="1" data-verify_status="2"></mp-common-profile></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=7044a9f3&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5MTc3ODY4Mw%3D%3D%26mid%3D2247508505%26idx%3D1%26sn%3D906fb32ff9f5b00c2600c6eb37da2400">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 31 Mar 2026 13:40:00 +0800</pubDate>
    </item>
    <item>
      <title>大规模失陷！Apifox遭投毒，请立即排查</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&amp;mid=2247508474&amp;idx=1&amp;sn=0c54bef0fb110b738a49459efda40b59</link>
      <description>立即排查apifox.it.com的所有访问请求</description>
      <content:encoded><![CDATA[<p><span>微步情报局</span> <span>2026-03-26 12:20</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=e8b6a237&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FT4OSm0sXdEODGzC7I9C1L6b1V4ibsMiaXYv7VXicbPBGfDcvto0T3iclV0fSgmVtWySAibLbUj6XpicJuk2PbT5u6KqAiaHLz6wq4I0OHIyw5jXjDo%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>立即排查apifox.it.com的所有访问请求</p>
  <p style="margin-bottom: 16px;line-height: 1.6em;"><span leaf="" style=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">近日国内流行的API协作平台Apifox发布公告，称遭遇供应链投毒。</span><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(219, 0, 0);font-weight: bold;">微步情报局研判发现，3月4日后，一旦请求域名apifox.it.com即已失陷，建议用户立即排查和做好应急处置，同时升级至最新版本，Windows、Linux以及macOS均受影响。（排查方法和处置建议详见后文）</span></span></p><p style="margin-bottom: 16px;line-height: 1.6em;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4203338391502276" data-type="png" data-w="1318" height="254.19" style="margin-left:0px;margin-top:0px;width:100%;" width="604.733" data-backw="578" data-backh="243" data-imgfileid="100024798" src="https://wechat2rss.xlab.app/img-proxy/?k=e8abc7ec&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEPeBtgoMpVtIyIbEWOu6RbjBjydibGGzxHvxY1EP8p7g7IIWF6j42TPeI7BfZSbjLfsiblcU5CxudMHzVgk7TmauSS3NzbuJAKmA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style=""><span textstyle="" style="font-size: 12px;letter-spacing: 1px;">图：Apifox官方公告</span></span></p><p style="margin-bottom: 16px;line-height: 1.6em;"><span leaf="" style=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">公告显示，Apifox CDN服务所托管的前端脚本文件被植入恶意代码，3月4日后启动应用有概率触发，收集主机敏感信息并下载、执行后续载荷。</span><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(219, 0, 0);font-weight: bold;">目前，apifox.it.com已无法访问，共持续18天。</span></span></p><div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="margin: 10px 0% 0px;display: inline-block;width: 100%;border-width: 0px 0px 0px 10px;border-style: solid;border-left-color: rgb(219, 0, 0);border-right-color: rgb(219, 0, 0);padding: 0px 0px 0px 5px;box-sizing: border-box;"><div style="font-size: 18px;width: 100%;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">事件分析</span></span></p></div></div></div><p style="margin-bottom: 16px;line-height: 1.6em;margin-top: 16px;"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">2026年3月25日8点36分，在2libra论坛上有用户爆出知名API协作研发平台Apifox存在投毒攻击：</span></span></p><div style="margin-bottom: 16px;line-height: 1.6em;margin-top: 16px;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.687715269804822" data-type="png" data-w="871" height="415.8843044619423" style="margin-left:0px;width:100%;" width="604.7333333333333" data-backw="578" data-backh="397" data-imgfileid="100024817" src="https://wechat2rss.xlab.app/img-proxy/?k=500ce11b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEMz5icNOokU8B4vL4NGlGYSpT0wfIw2mwLcGwI6raUFJ2Ghxkq9c6fmGGpHBubW6yxqILvGenGoNjkC9nn03UzTHCv9Mn4YIWSM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span leaf="" style=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">微步情报局分析投毒js文件可以看到远控IOC：apifox.it.com，其余四个IOC尚未在攻击者代码中看到，但建议封禁。</span></span></p><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span leaf="" style=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">Apifox基于Electron框架开发，如果在不开始沙盒（Sandbox）且通过网络加载JavaScript资源，一旦发生劫持或投毒，攻击者的恶意脚本可直接在主机环境下运行，执行命令，窃取本地文件。</span></span></p><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span leaf="" style=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">旧版（SaaS版2.8.19以前）Apifox应用启动后会从官方地址获取js资源（目前请求资源正常）：</span></span></p><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.516213389121339" data-type="png" data-w="1912" height="312.1714435695538" style="margin-left:0px;width:100%;" width="604.7333333333333" data-backw="578" data-backh="298" data-imgfileid="100024824" src="https://wechat2rss.xlab.app/img-proxy/?k=b107d4fc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEPChYiaB8XoR1AuH2ObtZer29plCw6NQibibWnctxYveWgrGbRLE97Nc0oVuIOWUKJG4ibZ7GcawnMPQmSwKUV6T3Pnmaesdw3I1rE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span leaf="" style=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">通过Wayback Machine可以搜索到该js资源在3月5号的存档：</span></span></p><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.49581589958158995" data-type="png" data-w="1912" height="299.8364304461942" style="margin-left:0px;width:100%;" width="604.7333333333333" data-backw="578" data-backh="287" data-imgfileid="100024816" src="https://wechat2rss.xlab.app/img-proxy/?k=c1d7d036&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdENP59s5cJ04iaO2knicXKQO7nX4d4uyaxwjul67icNPia6SyhWQ0rJHPb49ZHl6FOKjp96w0iaBYwm2W3pqDYfnmS3iaXDXIVPiakNOkU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span leaf="" style=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">从该存档文件可以看到，攻击者在原本js文件末尾增加了一段高度混淆的代码：</span></span></p><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.49581589958158995" data-type="png" data-w="1912" height="299.8364304461942" style="margin-left:0px;width:100%;" width="604.7333333333333" data-backw="578" data-backh="287" data-imgfileid="100024823" src="https://wechat2rss.xlab.app/img-proxy/?k=80d878f9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEM82MIGMYJSvpnsuElCib75t9NZNz2otd0q8g8MTEyobMxibiaClZ5rRwbZrPGNy4KicvIG7icDhP9nGe4lYnPZ3JYjUwq0I9Y9VXOY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span leaf="" style=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">而该恶意代码首先会加载node.js的crypto，os模块</span></span></p><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4465174129353234" data-type="png" data-w="804" height="270.024" style="margin-left:0px;width:100%;" width="604.733" data-backw="578" data-backh="258" data-imgfileid="100024815" src="https://wechat2rss.xlab.app/img-proxy/?k=882751c2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdENHp87Rr80xmtOARsrkS4BFWQUvrxS4BrPH5Vzm1ZIjPiaeqfiaGsoVlNjbciaNVWAic8pplD0xIa0gU8JJb4fugVqBo0enkjZb4mE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span leaf="" style=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">通过该模块读取设备信息：网络接口/MAC、CPU、平台、主机名、用户名等。然后尝试读取本地的common.currentUserId获取使用用户的信息，如果不存在则通过读取common.accessToken 调Apifox的官方接口补充身份信息，攻击者使用该信息作为上传窃密信息的用户标记字段af_apifox_user，af_apifox_name：</span></span></p><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7367119901112484" data-type="png" data-w="809" height="445.514" style="margin-left:0px;width:100%;" width="604.733" data-backw="578" data-backh="426" data-imgfileid="100024822" src="https://wechat2rss.xlab.app/img-proxy/?k=d3bf42e1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdENeUuqE6oB9jC8WUIrfPan6TwzgicgqCliabxeLwwAG0oabc7OoK6V87UUIOJOOqm3ClYPHk5YMSViaD9UheTuFNcIV9WIb285mWE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span leaf="" style=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">收集完成信息后，恶意脚本会调用本地硬编码的PEM 私钥对信息加密上传：</span></span></p><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5106918238993711" data-type="png" data-w="795" height="308.832" style="margin-left:0px;width:100%;" width="604.733" data-backw="578" data-backh="295" data-imgfileid="100024821" src="https://wechat2rss.xlab.app/img-proxy/?k=f7c9e4de&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEMrSPs6n4V2uX88BcUpx74U2l96Kebl0ZZUvAE46qDkEtXa0JBwYO3PELLWyGxy0nU0CpQsIcVH8nB1GZMdSmIF9ahmzYSvcCU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span leaf="" style=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">上传地址被混淆加密：</span></span></p><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5552825552825553" data-type="png" data-w="814" height="335.798" style="margin-left:0px;width:100%;" width="604.733" data-backw="578" data-backh="321" data-imgfileid="100024820" src="https://wechat2rss.xlab.app/img-proxy/?k=5b297b44&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEPLiaj7FfAWnWGBMmhCaRtRhwycq2UnDc7Nh8d0jic2Y50WgI9QA50A3rSt8eR1qlWibIDbakuRhqdh5PO17lqeotibSJnspiaFDDZE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span leaf="" style=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">解密后地址为：<a href="https://apifox.it.com/public/apifox-event.js，并对请求响应使用硬编码的PEM私钥解密执行：" target="_blank">https://apifox.it.com/public/apifox-event.js，并对请求响应使用硬编码的PEM私钥解密执行：</a></span></span></p><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.2961104140526976" data-type="png" data-w="797" height="179.068" style="margin-left:0px;width:100%;" width="604.733" data-backw="578" data-backh="171" data-imgfileid="100024819" src="https://wechat2rss.xlab.app/img-proxy/?k=12001792&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdENMQ9HyKUffdcxvZYRGE09icBM2dr45TgiaHFEdAu8FIeMVV9VntohsvKdeNkPMHqeB28Ay60Hhcv2yrLtbUNzt4QQxx7k6zZRs0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span leaf="" style=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">整个过程会通过scheduleNext在30分钟到3个小时之间随机间隔不断触发：</span></span></p><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.24812030075187969" data-type="png" data-w="798" height="150.047" style="margin-left:0px;width:100%;" width="604.733" data-backw="578" data-backh="143" data-imgfileid="100024818" src="https://wechat2rss.xlab.app/img-proxy/?k=3bfdf0db&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdENL68Wt2tSEncaK9JPhk4jUQzKiaKxfw5bKoA3SEicqoQmTHt9E9miaycJA4oWwahiaUib698cWQLzpRFiaLiaJZ8JCVnO7fuUr2j8gDw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span leaf="" style=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">解密加载的第二阶段载荷会进一步收集窃密主机信息：</span></span></p><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9855769230769231" data-type="png" data-w="624" height="596.011" style="margin-left:0px;width:100%;" width="604.733" data-backw="578" data-backh="570" data-imgfileid="100024825" src="https://wechat2rss.xlab.app/img-proxy/?k=d42570bd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEM1cWuribACohpDHHdta5dEJmr8miaVuiaQp2Xp5Cib5sLTT2DRtDarsPria2c1Vf4WQWQsWavpXOmTkWQCAefncN4OfVlORq6O2An0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span leaf="" style=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">包括不限于：history文件，ssh私钥，known_hosts文件</span></span></p></div><div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="6 2 []"><div style="margin: 10px 0% 0px;display: inline-block;width: 100%;border-width: 0px 0px 0px 10px;border-style: solid;border-left-color: rgb(219, 0, 0);border-right-color: rgb(219, 0, 0);padding: 0px 0px 0px 5px;box-sizing: border-box;"><div style="font-size: 18px;width: 100%;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">受影响排查</span></strong></p></div></div></div><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span leaf="" style=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">Apifox官方指出在2.8.19以及更高版本，本地客户端不再通过在线加载js资源，而内置打包：</span></span></p><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3620488940628638" data-type="png" data-w="859" height="218.943" style="margin-left:0px;width:100%;" width="604.733" data-backw="578" data-backh="209" data-imgfileid="100024787" src="https://wechat2rss.xlab.app/img-proxy/?k=910d8fe8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdENibe8uorGUibpPoq6RBdYguXnjjTYibsASLVCibeS6kbpcy3PVqykflFHxPBlleLicSwWeX5c8TpN9XprN87NTQ3OuS87QOPCQcibOQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">OneSEC用户可查询历史日志中是否存在IOC域名反连来确定失陷范围：</span></span></p><p nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.29893778452200304" data-type="png" data-w="1977" height="180.778" style="margin-left:0px;margin-top:0px;width:100%;" width="604.733" data-backw="578" data-backh="173" data-imgfileid="100024794" src="https://wechat2rss.xlab.app/img-proxy/?k=90c4d956&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEMGPiaBPy01QpkXxicscUjY9NsOYPl7n4Kv1BXYWcib94mUibBN3MjjppE4sdHNIO5K7Uiat2JGTAyTxRgqlFxpJuVLCSlVRLo1G6E0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span leaf="" style=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">建议同时根据安装Apifox的版本来确定要升级范围，对于低于2.8.19版本的机器进行及时升级。这些低版本机器未出现ioc反连，也建议做各类密码、token和key的轮换或者重置：</span></span></p><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5246091488129705" data-type="png" data-w="1727" height="317.249" style="margin-left:0px;width:100%;" width="604.733" data-backw="578" data-backh="303" data-imgfileid="100024796" src="https://wechat2rss.xlab.app/img-proxy/?k=29b21a23&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEOibKwCZPn3J8bOp19dVibicfibicXRPInzrxXLvott59W7yZjaTWjeHrLiaY3R90f28RvVXwB97A3EseQLiaodurds6pGUpgvx6ZLLII%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span leaf="" style=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">用户也可以通过禁止对apifox.it.com的访问进行临时阻断。</span></span></p><div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="margin: 10px 0% 0px;display: inline-block;width: 100%;border-width: 0px 0px 0px 10px;border-style: solid;border-left-color: rgb(219, 0, 0);border-right-color: rgb(219, 0, 0);padding: 0px 0px 0px 5px;box-sizing: border-box;"><div style="font-size: 18px;width: 100%;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">处置建议</span></b></p></div></div></div><p style="margin-top: 16px;margin-bottom: 0px;line-height: 1.6em;"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">根据</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">Api</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">fox</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">官方</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">对</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">该</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">投毒</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">事件</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">的</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">公告</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">：</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">关于 Apifox 外部 JS 文件受篡改的风险提示与升级公告 - Apifox 帮助文档。</span></span></span></p><p style="margin-top: 16px;margin-bottom: 0px;line-height: 1.6em;"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">链接：<a href="https://docs.apifox.com/8392582m0" target="_blank">https://docs.apifox.com/8392582m0</a></span></span></span></p><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-backh="286" data-backw="578" data-imgfileid="100024789" data-ratio="0.49581589958158995" width="604.733" data-type="png" data-w="1912" height="299.836" style="margin-left:0px;width:100%;" src="https://wechat2rss.xlab.app/img-proxy/?k=c2dfa829&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEPG93lc8QvZ2Wokkmn7ymFasbeMsbZs6ialVmHehklIYZ3SRibibvr1nqZibtgt2N4xRRT7yMeQNecjs0iaAfgPSrcoFFnIv7oQSp4M%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;class&#34;:&#34;paragraph text-align-type-left&#34;,&#34;style&#34;:&#34;margin-top: 16px; margin-bottom: 16px; line-height: 1.6em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;class&#34;:&#34;image-wrapper&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">微步情报局强烈建议，用户立即升级Apifox到2.8.19版本及以上，同时更换SSH密钥，GitHub、GitLab密码/Token，修改命令行历史中暴露的所有密码、Token 和 API Key，审查服务器登录日志，检查是否有异常 SSH 。</span></span></p><div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="margin: 10px 0% 0px;display: inline-block;width: 100%;border-width: 0px 0px 0px 10px;border-style: solid;border-left-color: rgb(219, 0, 0);border-right-color: rgb(219, 0, 0);padding: 0px 0px 0px 5px;box-sizing: border-box;"><div style="font-size: 18px;width: 100%;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">IOC</span></b></p></div></div></div><p style="text-align: left;line-height: 1em;margin: 16px 0pt;" data-pm-slice="0 0 []"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="letter-spacing: 1px;">apifox.it.com</span></span></span></p><p style="text-align: left;margin: 16px 0pt;line-height: 1.6em;" data-pm-slice="0 0 []"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;font-weight: bold;">以下IOC暂未标记情报，由事件预警者Path@2Libra提供。尚未在攻击代码中找到相关域名，域名高度可疑，严谨起见可以封禁</span></span></span></p><p style="text-align: left;margin: 16px 0pt;line-height: 1em;" data-pm-slice="0 0 []"><span style="font-size: 11pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-monospace"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">cdn.openroute.dev</span></span></span></p><p style="text-align: left;margin: 16px 0pt;line-height: 1em;"><span style="font-size: 11pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-monospace"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">upgrade</span></span></span><span style="font-size: 11pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-monospace"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">.</span></span></span><span style="font-size: 11pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-monospace"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">feishu.it.com</span></span></span></p><p style="text-align: left;margin: 16px 0pt;line-height: 1em;"><span style="font-size: 11pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-monospace"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">system.toshinkyo.or.jp</span></span></span></p><p style="text-align: left;line-height: 1em;margin: 16px 0pt;"><span style="font-size: 11pt;font-family: 微软雅黑;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="ui-monospace"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">ns.feishu.it.com</span></span></span></p><div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="margin: 10px 0% 0px;display: inline-block;width: 100%;border-width: 0px 0px 0px 10px;border-style: solid;border-left-color: rgb(219, 0, 0);border-right-color: rgb(219, 0, 0);padding: 0px 0px 0px 5px;box-sizing: border-box;"><div style="font-size: 18px;width: 100%;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Reference</span></strong></p></div></div></div><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">【漏洞预警】关于 apifox 被投毒的风险提示 - 2Libra</span></span></p><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;"><a href="https://2libra.com/post/network-security/8HvXoR_" target="_blank">https://2libra.com/post/network-security/8HvXoR_</a></span></span></p><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">关于 Apifox 外部 JS 文件受篡改的风险提示与升级公告 - Apifox 帮助文档</span></span></p><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;"><a href="https://docs.apifox.com/8392582m0" target="_blank">https://docs.apifox.com/8392582m0</a></span></span></p><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">Apifox 供应链投毒攻击 — 完整技术分析 - 白帽酱の博客</span></span></p><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;"><a href="https://rce.moe/2026/03/25/apifox-supply-chain-attack-analysis/" target="_blank">https://rce.moe/2026/03/25/apifox-supply-chain-attack-analysis/</a></span></span></p><p style="margin-top: 24px;margin-bottom: 16px;text-align: center;"><span leaf="" style=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">-END-</span></span></p><p class="mp_profile_iframe_wrp" nodeleaf=""><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-nickname="微步在线研究响应中心" data-from="0" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/fFyp1gWjicML0NlKR16SxQGjNPSYVoUxGgXhXvI4Z8ia5h8C9TGibEic1ABv6fniame8h0dh6zGX8ndXT8icjQocVh8A/0?wx_fmt=png" data-signature="微步情报局最新威胁事件分析、漏洞分析、安全研究成果共享，探究网络攻击的真相" data-id="Mzg5MTc3ODY4Mw==" data-is_biz_ban="0" data-service_type="1" data-verify_status="2"></mp-common-profile></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=faa0d791&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5MTc3ODY4Mw%3D%3D%26mid%3D2247508474%26idx%3D1%26sn%3D0c54bef0fb110b738a49459efda40b59">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 26 Mar 2026 12:20:00 +0800</pubDate>
    </item>
    <item>
      <title>安全工具被入侵，引发大规模AI供应链投毒</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&amp;mid=2247508412&amp;idx=1&amp;sn=9fd2677b5c2040dce82c96551d46f44f</link>
      <description>数千个AI项目、数十万台设备受影响</description>
      <content:encoded><![CDATA[<p><span>微步情报局</span> <span>2026-03-25 15:04</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=c790855b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FT4OSm0sXdEPtiaxmMJd5It1rHh7ibdZAGaQxdpDGXicUpvQoZPBHJU5ljYicBoCnnRd4oZt4WpLX16D4V2Tv3eGhWXibTx3TQqsiaC1facS8p0Mj0%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>数千个AI项目、数十万台设备受影响</p>
  <p style="margin-bottom: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">3月24日，微步情报局监测到</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">AI核心组件LiteLLM</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">遭遇大规模供应链投毒，</span><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(219, 0, 0);font-weight: bold;">PyPI仓库1.82.7和1.82.8两个版本包含攻击者植入的后门。</span></span></p><p style="margin-bottom: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(0, 0, 0);font-weight: normal;">尽管46分钟恶意版本就被移除，</span><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(219, 0, 0);font-weight: bold;">但鉴于其单日300万+次、单月近亿次的下载量，仍对下游数千个AI项目造成极大影响。</span><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">公开报道显示，攻击者TeamPCP声称已窃取</span><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(219, 0, 0);font-weight: bold;">数十万台</span><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">设备的数据。此次事件基本脉络如下（UTC时间）：</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="font-size:15px;letter-spacing:1px;"><p style="margin-bottom: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;font-weight: bold;">2月底</span><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">——攻击者入侵开源漏扫工具Trivy，植入恶意代码</span></span></p></li><li style="font-size:15px;letter-spacing:1px;"><p style="margin-bottom: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;font-weight: bold;">3月中上旬</span><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">——LiteLLM CI/CD流水线使用恶意Trivy版本，致使PyPI凭证失窃</span></span></p></li><li style="font-size:15px;letter-spacing:1px;"><p style="margin-bottom: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;font-weight: bold;">3月24日10:39</span><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">——攻击者利用PyPI凭证，上传完成两个包含后门的LiteLLM版本</span></span></p></li><li style="font-size:15px;letter-spacing:1px;"><p style="margin-bottom: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;font-weight: bold;">3月24日11:25</span><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">——恶意版本1.82.7和1.82.8被官方移除，存活46分钟</span></span></p></li></ul><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;font-weight: bold;">经过进一步研判，恶意代码主要在Linux平台运行，Windows几乎不受影响。</span></span></p><div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="margin: 10px 0% 0px;display: inline-block;width: 100%;border-width: 0px 0px 0px 10px;border-style: solid;border-left-color: rgb(219, 0, 0);border-right-color: rgb(219, 0, 0);padding: 0px 0px 0px 5px;box-sizing: border-box;"><div style="font-size: 18px;width: 100%;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">一、概述</span></strong></p></div></div></div><table><tbody><tr><td data-colwidth="99" width="99" valign="middle"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 14px;">事件概述</span></span></p></td><td data-colwidth="359" width="359" valign="middle"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 14px;">LiteLLM供应链投毒，窃取凭证等高价值数据</span></span></p></td></tr><tr><td data-colwidth="99" width="99" valign="middle"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 14px;">涉及产品</span></span></p></td><td data-colwidth="359" width="359" valign="middle"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 14px;">LiteLLM（月下载量约9700万次）</span></span></p></td></tr><tr><td data-colwidth="99" width="99" valign="middle"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 14px;">影响版本</span></span></p></td><td data-colwidth="359" width="359" valign="middle"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 14px;">1.82.7 和 1.82.8，已被移除，安全版本为 1.82.6</span></span></p></td></tr><tr><td data-colwidth="99" width="99" valign="middle"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 14px;">发现时间</span></span></p></td><td data-colwidth="359" width="359" valign="middle"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 14px;">2026年3月24日（UTC时间10:39 - 11:25）</span></span></p></td></tr><tr><td data-colwidth="99" width="99" valign="middle"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 14px;">攻击者</span></span></p></td><td data-colwidth="359" width="359" valign="middle"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 14px;">黑客组织 TeamPCP</span></span></p></td></tr><tr><td data-colwidth="99" width="99" valign="middle"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 14px;">事件根因</span></span></p></td><td data-colwidth="359" width="359" valign="middle"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 14px;">LiteLLM的CI/CD流水线使用了已被入侵的Trivy工具，导致发布权限泄露</span></span></p></td></tr><tr><td data-colwidth="99" width="99" valign="middle"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 14px;">事件危害</span></span><o:page></o:page></p></td><td data-colwidth="359" width="359" valign="middle"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 14px;">SSH密钥、云服务凭据（AWS/GCP/Azure）、Kubernetes机密、CI/CD令牌、加密钱包等被窃取</span></span></p></td></tr></tbody></table><div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="margin: 10px 0% 0px;display: inline-block;width: 100%;border-width: 0px 0px 0px 10px;border-style: solid;border-left-color: rgb(219, 0, 0);border-right-color: rgb(219, 0, 0);padding: 0px 0px 0px 5px;box-sizing: border-box;"><div style="font-size: 18px;width: 100%;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">二、供应链分析</span></strong></p></div></div></div><h1><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">litellm供应链投毒主要影响1.82.7和1.82.8两个版本。</span></span></h1><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.18952234206471494" data-w="649" style="width: 604.74px;height: 114.61px;" src="https://wechat2rss.xlab.app/img-proxy/?k=b18b896a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEPKuKXou9y3XjFVheFuGodwSNoGovIzaHVxqM416JnrL7Zm4ncaRiabE5qqQhmJBQd9lYmcuv0icsqqibG5x9gQhFXOqL3ibC7QdsA%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">在1.82.7版本中，恶意攻击者将一段base64编码后的恶意代码加入到proxy\</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">proxy_server.py文件中，一旦导入litellm项目中的proxy库，便启动执行该恶意代码。</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">在proxy_server.py文件中存在三个版本，后面两个被注释的恶意编码经过分析后，与非注释恶意编码功能及通信完全相同，只是在加密方式上略有差异。</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.18" data-s="300,640" data-type="png" data-w="650" type="block" data-imgfileid="100024762" src="https://wechat2rss.xlab.app/img-proxy/?k=7aa46587&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEPaWicz2fC4e64OMQeOhX9piavPAibytm0vlL5BbfxzN4uRqZ0RHia2CdicQZpxcvDsG2iaPy6to6LvEibTsJNicXpCCHS4JQzlxgllZ2M%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">在1.82.8版本中，不但包含这种恶意代码注入，还增加了恶意的litellm_init.pth，利用 .pth文件在python运行时启动的特性进行隐匿执行。</span></span></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4714946070878274" data-w="649" style="width: 604.74px;height: 285.13px;" src="https://wechat2rss.xlab.app/img-proxy/?k=0c79f419&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdENuictqlpusctTlRJhgsSTdKv8kpCH7u1MLT4icVrsGhCGiabRBpNYIgvRl6cmtG5J2cg0ZfjIkicUPsyuZhUZibCbtxmLSnh2pE1Q0%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">经过代码对比，.pth文件中的恶意编码与</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">proxy_server.py文件的非注释的恶意编码完全一致，因此主要分析以.</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">pth文件中的恶意编码为主。</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3081664098613251" data-s="300,640" data-type="png" data-w="649" type="block" data-imgfileid="100024763" src="https://wechat2rss.xlab.app/img-proxy/?k=4c4b8da3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEN4SFG0uzwYT5ibTa4z3LE0dnFVbI8WyD2fxbEl0DnibNdZ3gcLsT0HQE8YkZwAicXZBovyQMufia8u4oaEoPKssssWdFysjCEgSpE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">恶意编码比较简单，首先会从失陷主机窃取大量敏感数据信息，然后下载持久化脚本维持持久化，然后上传打包的敏感信息。</span></span></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6756329113924051" data-w="632" style="width: 604.74px;height: 408.58px;" src="https://wechat2rss.xlab.app/img-proxy/?k=c9a5880a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEOwC6G78YFujRkkfqULyl7u6N7yMyLvy8py6xiaarWc0KqO5iaXk85hKee83TNYOshfOKt79j1Ql3Kvq538ohZiat5YxOia7l3N3qQ%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">值得注意的是，恶意攻击者将路径设置为Linux常用目录，并未针对Windows。</span></span></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.08279220779220779" data-w="616" style="width: 604.74px;height: 50.07px;" src="https://wechat2rss.xlab.app/img-proxy/?k=0062d643&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEMojfuzMa4z5vnLpiaNGkWpWlfDr8AfiaVEPkGl3gvDicA6BmhyXEFBhmHzPbrqjTDkJ3oNNRG5yWrWVnZia3bqyoNrXwOKicC16wFs%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">获取系统信息、printenv环境变量、SSH密钥、Git凭证。</span></span></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.2169230769230769" data-w="650" style="width: 604.74px;height: 131.18px;" src="https://wechat2rss.xlab.app/img-proxy/?k=7e497ada&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEMHIGYldBFwiatRoQZxc59ofGhiaT9zibDEjqB8Gwe1T75Mokia6m38xNaoy9JibTibvmqUibzLXHQUpiaKbngd2weYO3Bcl0hZG0qgFaI%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">获取AWS凭证、GCP凭证、Azure凭据、Kubernetes密钥、GCP凭证、Azure凭据。</span></span><o:page></o:page></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6692307692307692" data-w="650" style="width: 604.74px;height: 404.71px;" src="https://wechat2rss.xlab.app/img-proxy/?k=5a256ab5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEMZwicMHJZ4jDXNXIcv06v0PibJ7n7dQRxf25ic21qV51wZ4afDTUWjtScjmXP2z1tHkjqjbZfdwd2AiaQ4GT57QP12tuibQlT12LH0%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">获取Docker配置信息、常见包管理、WireGuard key、CI/CD 密钥、数据库凭证。</span></span></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7415384615384616" data-w="650" style="width: 604.74px;height: 448.44px;" src="https://wechat2rss.xlab.app/img-proxy/?k=dd1b840b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEOlQibAJl5VwWu2UXPlOJMiaegAIdM7domldUbHfOTsT1YZEQC3LhqHCKHRKU2xWYiaBIazM3gn6HVqDjBPZHNOfibXMfhDajPiaxCI%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">获取Shell历史记录、加密钱包、CI/CD 密钥和Webhook信息。</span></span><o:page></o:page></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4745762711864407" data-w="649" style="width: 604.74px;height: 287px;" src="https://wechat2rss.xlab.app/img-proxy/?k=565ddff9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEMOvcB4sia7CfhXZPBTbptQL6QjKhibiczkwyVb2DauUNnWzVPpRs3Qhx26iaXDjoWaSkGpq7q9qic12libXD2fl4nlDkRw73eDOtn98%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">通过通信获取AWS凭证等。</span></span></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5015384615384615" data-w="650" style="width: 604.74px;height: 303.3px;" src="https://wechat2rss.xlab.app/img-proxy/?k=bdd4f2ca&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEPfuic6S4Rz3eb1n48UrTzgiaiahLzzicrCECWSV7mG92Bnv0Qka5ib7dk8WxOfarX6gnDsCHE6ueHm8lYkyZK6bKMdYlF7Fic90tS1U%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">使用kubernetes节点下载恶意脚本保存为sysmon.py。</span></span></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.2696456086286595" data-w="649" style="width: 604.74px;height: 163.07px;" src="https://wechat2rss.xlab.app/img-proxy/?k=04f8f34f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEPS7OggxbUv0DR8yk194ibBaGJ95nhrGl6rq07pqxYTkQ6ibd6nqsKmcCJaIP1kJX0HPdyV0WDAlPhrAuaZNgu4seEMCpL0ACM2Q%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">恶意脚本解码如下，主要访问checkmarx.zone/raw下载文件，读取其中的链接来执行二阶段脚本下载</span></span><o:page></o:page></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7026194144838213" data-w="649" style="width: 604.74px;height: 424.9px;" src="https://wechat2rss.xlab.app/img-proxy/?k=24eb6ae3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEM1ibaLD2ftu57lVwqe1rHJRmZbyRaNhrhhspUaRes0icpd0OibYL7LYxY8zHx1iaRFJvLej523vFO1O3LkCAK7X9BRsAa1bn81azY%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">但是当前链接已被恶意攻击者导向非恶意网站，无法继续执行下载。</span></span><o:page></o:page></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.8338461538461538" data-w="650" style="width: 604.74px;height: 504.26px;" src="https://wechat2rss.xlab.app/img-proxy/?k=ab001414&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEPfLkL7q88lc5oXwUMLV9UFK85uYdY6sVWiaoJhVFMWuOibuaB82vAFM0cagCIVrmPTVicLgyFicWDnIDoBUsVFicLwVu14qcy6w2Lo%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">后续会设置增加</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">sysmon.service来持久化运行下载到的脚本，该脚本保存为</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">/host/root/.config/sysmon/sysmon.py</span></span></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.2673484295105917" data-w="1369" style="width: 604.74px;height: 161.68px;" src="https://wechat2rss.xlab.app/img-proxy/?k=f11f4cbe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEMH5DDmlxOzAaBMcEEoazFQATmK5IIPEbPkwQwMBL02wJ7F6zklSe055jgpwJ6lXRrFruownUMUNgiciaSythl6X4FenuhpTnLnQ%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">在收集大量敏感信息后写入临时文件后，加密打包生成tpcp.tar.gz文件，然后上传到models.litellm.cloud，官方网站为litellm.ai。可以看出攻击者特地申请相似域名来进行指向性投毒，这种相似域名避免引起流量关注。</span></span><o:page></o:page></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3523076923076923" data-w="650" style="width: 604.74px;height: 213.06px;" src="https://wechat2rss.xlab.app/img-proxy/?k=f5a90c91&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdENVD1aTxHULEAvfNpmNmiczg5KsJc3g95FXoia7mnph8tY4OP8YqVP3YCtUsMnqFicsoZWNePoOtTFCctHofID56BLyHNPEUlvIfc%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">其中对数据进行加密的公钥在三个版本一直没有改变。</span></span></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5100917431192661" data-w="545" style="width: 545.01px;height: 278px;" src="https://wechat2rss.xlab.app/img-proxy/?k=a349d235&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdENyu2I76D5sEVOwKLEXwc3wwaGXNicEj3iazicgJk3U5LNxDDnxicrUOVGYVbdicDIbhs0iaHewdEIzqIbykaWP0805jtt04Siano3Xj8%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">另外在前两个版本中使用了RC4来加密执行脚本，其中的密钥内容为nigger，说明攻击者带有一定的黑人歧视倾向，可能与种族主义有关。</span></span></p><p style="margin-top: 16px;line-height: 1.6em;margin-bottom: 24px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4323076923076923" data-w="650" style="width: 604.74px;height: 261.43px;" src="https://wechat2rss.xlab.app/img-proxy/?k=9a1b1360&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEPddX3D41TuSgrrk1NWfQkOywQ6q3mbFxdVRGEJNzczrJpDLxoa7Jiblkmf8Cz8TC2EebnEpibY049cfeZks6SsyrdGtP0icDFRhM%2F640%3Fwx_fmt%3Dpng"/></span></p><div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="margin: 10px 0% 0px;display: inline-block;width: 100%;border-width: 0px 0px 0px 10px;border-style: solid;border-left-color: rgb(219, 0, 0);border-right-color: rgb(219, 0, 0);padding: 0px 0px 0px 5px;box-sizing: border-box;"><div style="font-size: 18px;width: 100%;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">三、排查方式</span></strong></p></div></div></div><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">1.</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">重点在linux环境下通过python命令(pip show litellm)，排查是否安装litellm的1.82.7/1.82.投毒版本,若显示版本为这两种，立即停止该服务并卸载以及对失陷机器进行断网处理。</span></span><o:page></o:page></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">2.</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">针对网络通信部分，拦截</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">models.litellm.cloud以及checkmarx.zone的域名通信。</span></span></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">3.</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">排查是否存在</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">/tmp/pglog或者/tmp/.pg_state以及/host/root/.config/sysmon/sysmon.py和tpcp.tar.gz文件以及其他python库中与litellm_init.pth的sha256一致的pth文件，如果存在，则删除该文件。另外排查是否新增非工作相关的sysmon.service，如果有，则删除该服务。</span></span></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">4.</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">建议交给专业人员进行分析失陷机器是否存在其他未知风险。</span></span></p><div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="margin: 10px 0% 0px;display: inline-block;width: 100%;border-width: 0px 0px 0px 10px;border-style: solid;border-left-color: rgb(219, 0, 0);border-right-color: rgb(219, 0, 0);padding: 0px 0px 0px 5px;box-sizing: border-box;"><div style="font-size: 18px;width: 100%;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">四、检测方案</span></strong></p></div></div></div><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">微步终端安全管理平台OneSEC已支持对恶意代码的精确检测，建议受影响用户及时关注</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">数据外传和敏感文件访问等终端日志。</span></span></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.26107072042300067" data-w="1513" style="width: 604.74px;height: 157.88px;" src="https://wechat2rss.xlab.app/img-proxy/?k=5ea567a2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEOxJbxUmc8pmp0Tn9WagJXdIKdd4E8zVP7MibxYTMBB6CagpUvwSBMwU0RKiadfdvAeaLK63pvwzwY34ydEMAN5ibu2V1yMqUHpbw%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">此外，</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">微威胁感知平台TDP、威胁防御系统OneSIG、互联网安全接入平台OneDNS、云沙箱S、沙箱分析平台OneSandbox等，均支持对相关IOC的检测与拦截。</span></span></p><div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="margin: 10px 0% 0px;display: inline-block;width: 100%;border-width: 0px 0px 0px 10px;border-style: solid;border-left-color: rgb(219, 0, 0);border-right-color: rgb(219, 0, 0);padding: 0px 0px 0px 5px;box-sizing: border-box;"><div style="font-size: 18px;width: 100%;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">五、IOC</span></strong></p></div></div></div><table style="width:446px;"><tbody><tr><td data-colwidth="301" width="301" valign="middle"><p style="text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">IOC</span></span></p></td><td data-colwidth="145" width="145" valign="middle"><p style="text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">说明</span></span></p></td></tr><tr><td data-colwidth="301" width="301" valign="middle"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">d2a0d5f564628773b6af7b9c11f6b86531a875bd2d186d7081ab62748a800ebb</span></span></p></td><td data-colwidth="145" width="145" valign="middle"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">litellm-1.82.8.whl</span></span></p></td></tr><tr><td data-colwidth="301" width="301" valign="middle"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">71e35aef03099cd1f2d6446734273025a163597de93912df321ef118bf135238</span></span></p></td><td data-colwidth="145" width="145" valign="middle"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">litellm_init.pth</span></span></p></td></tr><tr><td data-colwidth="301" width="301" valign="middle"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">a0d229be8efcb2f9135e2ad55ba275b76ddcfeb55fa4370e0a522a5bdee0120b</span></span></p></td><td data-colwidth="145" width="145" valign="middle"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">proxy_server.py</span></span></p></td></tr><tr><td data-colwidth="301" width="301" valign="middle"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">8395c3268d5c5dbae1c7c6d4bb3c318c752ba4608cfcd90eb97ffb94a910eac2</span></span></p></td><td data-colwidth="145" width="145" valign="middle"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">litellm-1.82.7.whl</span></span></p></td></tr><tr><td data-colwidth="301" width="301" valign="middle"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">models.litellm.cloud</span></span></p></td><td data-colwidth="145" width="145" valign="middle"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">敏感信息上传</span></span></p></td></tr><tr><td data-colwidth="301" width="301" valign="middle"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">checkmarx.zone</span></span></p></td><td data-colwidth="145" width="145" valign="middle"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 14px;letter-spacing: normal;">下载持久化脚本</span></span></p></td></tr></tbody></table><p style="margin-top: 24px;text-align: center;"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;">-END-</span></span></p><p nodeleaf=""><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-nickname="微步在线研究响应中心" data-from="2" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/fFyp1gWjicML0NlKR16SxQGjNPSYVoUxGgXhXvI4Z8ia5h8C9TGibEic1ABv6fniame8h0dh6zGX8ndXT8icjQocVh8A/0?wx_fmt=png" data-signature="微步情报局最新威胁事件分析、漏洞分析、安全研究成果共享，探究网络攻击的真相" data-id="Mzg5MTc3ODY4Mw==" data-is_biz_ban="0" data-service_type="1" data-verify_status="2"></mp-common-profile></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=1fa97954&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5MTc3ODY4Mw%3D%3D%26mid%3D2247508412%26idx%3D1%26sn%3D9fd2677b5c2040dce82c96551d46f44f">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 25 Mar 2026 15:04:00 +0800</pubDate>
    </item>
    <item>
      <title>AI Coding Agent最新攻击总结：7大漏洞利用手法</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&amp;mid=2247508389&amp;idx=1&amp;sn=a3afdb49432f816d071a103ec98add35</link>
      <description>附漏洞清单</description>
      <content:encoded><![CDATA[<p>原创 <span>微步情报局</span> <span>2026-03-24 16:32</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=ba1c93e1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FT4OSm0sXdEPtszp5iaol2GMlaDYF5TneuEtGAcXhhP8jWxjRbp8QJXMCU8QE7CvaKr3BjDKzFwaZDbliaPOvoP2icegau5zn6xmjS4LYKnHfB8%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>附漏洞清单</p>
  <p style="line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(63, 63, 63);">与OpenClaw这类通用AI智能体不同，Claude Code、Cursor等</span><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(63, 63, 63);font-weight: normal;">AI Coding Agent（AI编程智能体）在企业内使用频次更高、停留时间更长，且深度嵌入开发流程、持有最高权限</span><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(63, 63, 63);">——一旦沦陷，源代码、API密钥乃至整个基础设施都将可能被全面接管，潜在风险更大。</span></span></p><p style="line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(63, 63, 63);">本文</span><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(63, 63, 63);font-weight: normal;">基于微步情报局捕获的大量真实漏洞与攻击案例，</span><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(63, 63, 63);font-weight: bold;">系统梳理了AI Coding Agent的主要攻击向量、典型漏洞利用手法及主流安全产品现状</span><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(63, 63, 63);">，希望能为研发与安全团队提供一份有价值的风险预防指引。</span></span></p><div style="font-size: 15px;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="margin: 10px 0% 0px;display: inline-block;width: 100%;border-width: 0px 0px 0px 10px;border-style: solid;border-left-color: rgb(219, 0, 0);border-right-color: rgb(219, 0, 0);padding: 0px 0px 0px 5px;box-sizing: border-box;"><div style="font-size: 17px;width: 100%;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">AI Coding Agent风险本质</span></strong></p></div></div></div><p style="line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(63, 63, 63);">Claude Code、Cursor等这类典型</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.6em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(63, 63, 63);font-weight: normal;">AI Coding Agent</span></span><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(63, 63, 63);">的数据流，大致如下：</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.298046875" data-s="300,640" data-type="png" data-w="2560" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/T4OSm0sXdEOSBNKaG4pErHwfqaX7x1CryZJ22HAFbgBMXPnsKOg5PIed1iaiagt1omviakjk6YdbiaztmsvHHbxQYxUaGHUX01gLC7jFnVZypn4/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="578" data-cropsely2="149" data-imgfileid="100024733" src="https://wechat2rss.xlab.app/img-proxy/?k=0c0bc613&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEOSBNKaG4pErHwfqaX7x1CryZJ22HAFbgBMXPnsKOg5PIed1iaiagt1omviakjk6YdbiaztmsvHHbxQYxUaGHUX01gLC7jFnVZypn4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.6em;margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(63, 63, 63);font-weight: bold;">其关键风险点在于：</span></span></p><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="line-height: 1.6em;margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(63, 63, 63);">权限过大。Agent通常以用户身份运行，拥有几乎完整的本地文件系统与命令执行权限。</span></span></p></li><li><p style="line-height: 1.6em;margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(63, 63, 63);">指令来源复杂。除用户直接输入外，还包括README、代码注释、npm/yarn包描述、.git/config、插件配置、MCP服务器返回等多个不可信来源。</span></span></p></li><li><p style="line-height: 1.6em;margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(63, 63, 63);">语义难以区隔。LLM很难可靠区分“用户真实意图”与“恶意注入指令”，导致间接Prompt Injection成为最普遍、最难防御的攻击手段。</span></span></p></li></ul><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">而攻击者只需在项目中植入少量恶意内容（如隐藏在注释中的指令），即可诱导智能体执行任意操作</span><span textstyle="" style="font-size: 15px;color: rgb(219, 0, 0);">（比如，可能让智能体心甘情愿地把你的SSH密钥发到外部服务器），而智能体全程都认为自己在&#34;帮用户完成任务&#34;</span><span textstyle="" style="font-size: 15px;">。</span></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">需要明确的是，AI Coding Agent已不再是辅助工具，而是开发者环境中权限最高的“内部进程”。其安全风险根源在于过度授权与指令边界模糊。因此，</span><span textstyle="" style="font-size: 15px;font-weight: bold;">防护焦点必须从单一工具前移至AI Coding Agent的全生命周期治理</span><span textstyle="" style="font-size: 15px;">。</span></span></p><div style="font-size: 15px;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="margin: 10px 0% 0px;display: inline-block;width: 100%;border-width: 0px 0px 0px 10px;border-style: solid;border-left-color: rgb(219, 0, 0);border-right-color: rgb(219, 0, 0);padding: 0px 0px 0px 5px;box-sizing: border-box;"><div style="font-size: 17px;width: 100%;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">AI Coding Agent漏洞利用手法</span></strong></p></div></div></div><p style="line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(63, 63, 63);">经过深入分析漏洞情报及攻击事件，微步情报局将AI Coding Agent攻击手法归纳为以下七类：</span></span></p><div style="font-size: 15px;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: left;margin: 10px 0%;justify-content: flex-start;display: flex;flex-flow: row;opacity: 1;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 0 0 auto;min-width: 10%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="text-align: right;justify-content: flex-end;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-bottom: 4px solid rgb(224, 26, 26);border-bottom-right-radius: 0px;padding: 0px 10px 0px 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 20px;color: rgb(224, 26, 26);text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><em style="box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 18px;">01</span></span></strong></em></p></div></div></div></div><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 100 100 0%;height: auto;border-bottom: 4px solid rgb(224, 26, 26);padding: 5px 10px 5px 0px;box-sizing: border-box;"><div style="color: rgba(0, 0, 0, 0.85);font-size: 16px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">Prompt Injection攻击</span></span></strong></p></div></div></div></div></div></div><p style="text-indent: 0px;line-height: 1.6em;margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(63, 63, 63);">攻击者通过README、代码注释、@Docs引用、Terminal输入通道等位置植入精心构造的恶意指令，诱导智能体执行未经授权的系统命令或文件操作。</span></span></p><p style="text-align: center;margin-bottom: 0px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.43984375" data-s="300,640" data-type="png" data-w="2560" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/T4OSm0sXdEObvxHWicEJ7l0bPobnjMHFr0RHhicDB3smRl1QR5t5ws4PBydW3FKuKkZ7N30BOBb49w9eQAv21ibE7TW4tYCibRJc8ic8ElJCOByo/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="578" data-cropsely2="172" data-imgfileid="100024734" src="https://wechat2rss.xlab.app/img-proxy/?k=16dfef8c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEObvxHWicEJ7l0bPobnjMHFr0RHhicDB3smRl1QR5t5ws4PBydW3FKuKkZ7N30BOBb49w9eQAv21ibE7TW4tYCibRJc8ic8ElJCOByo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-top: 0px;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(63, 63, 63);">典型案例：</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.41854636591478694" data-s="300,640" data-type="png" data-w="798" style="width:548px;height:229px;" type="block" data-imgfileid="100024725" src="https://wechat2rss.xlab.app/img-proxy/?k=fd0b8e97&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdENRVOWaYIzXrYxGsbqhFVQqfsiaHD5AtNiaCVicSNv8bpY3uNr6cgoX5l7ehBm8SHPnkQ2Tm76jPUbS6MX4V4EiaVRcLCVsTQXO8HI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="font-size: 15px;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: left;margin: 10px 0%;justify-content: flex-start;display: flex;flex-flow: row;opacity: 1;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 0 0 auto;min-width: 10%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="text-align: right;justify-content: flex-end;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-bottom: 4px solid rgb(224, 26, 26);border-bottom-right-radius: 0px;padding: 0px 10px 0px 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 20px;color: rgb(224, 26, 26);text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><em style="box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 18px;">02</span></span></strong></em></p></div></div></div></div><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 100 100 0%;height: auto;border-bottom: 4px solid rgb(224, 26, 26);padding: 5px 10px 5px 0px;box-sizing: border-box;"><div style="color: rgba(0, 0, 0, 0.85);font-size: 16px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">自动加载与信任前执行攻击</span></span></strong></p></div></div></div></div></div></div><p style="line-height: 1.6em;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(63, 63, 63);">攻击者利用项目初始化或依赖安装过程中自动加载的配置文件（如 .yarnrc.yml、.cursor/mcp.json、git配置模板等），在用户尚未明确确认或知情的情况下触发远程代码执行。</span></span></p><p style="text-align: center;margin-bottom: 0px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.30859375" data-s="300,640" data-type="png" data-w="2560" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/T4OSm0sXdEOZeZ2Ch2neZqe6GHIbLOv63hfrm9kBAAEGR6OCg6gNVESTQxAVicWicMqO0ibzSiawKDq9CibvPcQZReRLEb6NB8kFBv6mRiaEC1KW8/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="578" data-cropsely2="218" data-imgfileid="100024735" src="https://wechat2rss.xlab.app/img-proxy/?k=8ebfdba2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEOZeZ2Ch2neZqe6GHIbLOv63hfrm9kBAAEGR6OCg6gNVESTQxAVicWicMqO0ibzSiawKDq9CibvPcQZReRLEb6NB8kFBv6mRiaEC1KW8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-bottom: 0px;margin-top: 0px;"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(63, 63, 63);">典型案例：</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.571072319201995" data-s="300,640" data-type="png" data-w="802" style="width:534px;height:305px;" type="block" data-imgfileid="100024726" src="https://wechat2rss.xlab.app/img-proxy/?k=748ce8dc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEMt2ztib6xKWib8eZltJKxsXxV9qJzd3uIgV6ozhpnibkV7SEIW883AAppQiaWchVicezDNk7CRmUY6yibxUDIlNCf3ASPL9QG5WkeUM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="font-size: 15px;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: left;margin: 10px 0%;justify-content: flex-start;display: flex;flex-flow: row;opacity: 1;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 0 0 auto;min-width: 10%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="text-align: right;justify-content: flex-end;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-bottom: 4px solid rgb(224, 26, 26);border-bottom-right-radius: 0px;padding: 0px 10px 0px 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 20px;color: rgb(224, 26, 26);text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><em style="box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 18px;">03</span></span></strong></em></p></div></div></div></div><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 100 100 0%;height: auto;border-bottom: 4px solid rgb(224, 26, 26);padding: 5px 10px 5px 0px;box-sizing: border-box;"><div style="color: rgba(0, 0, 0, 0.85);font-size: 16px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">文件系统边界绕过攻击</span></span></strong></p></div></div></div></div></div></div><p style="line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(63, 63, 63);">通过符号链接（symlink）、Windows路径解析特性（反斜杠、NTFS备用数据流）、工作目录切换等技术手段，绕过智能体内置的路径限制规则，实现对项目目录以外敏感文件或系统的读取、修改。</span></span></p><p style="text-align: center;margin-bottom: 0px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.292578125" data-s="300,640" data-type="png" data-w="2560" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/T4OSm0sXdEO6Ow95H6lGOHdrsGkCtzQxXhACA0ibz4gSoNPQDrTPFUZTp1Hfgibxicr7IJXvGyWlHXibXlTuoZgrdhBTY1J6HeoicicYVHGoTvJ5Q/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="578" data-cropsely2="174" data-imgfileid="100024736" src="https://wechat2rss.xlab.app/img-proxy/?k=b6c15bfd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEO6Ow95H6lGOHdrsGkCtzQxXhACA0ibz4gSoNPQDrTPFUZTp1Hfgibxicr7IJXvGyWlHXibXlTuoZgrdhBTY1J6HeoicicYVHGoTvJ5Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(63, 63, 63);">典型案例：</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7384806973848069" data-s="300,640" data-type="png" data-w="803" style="width:536px;height:396px;" type="block" data-imgfileid="100024727" src="https://wechat2rss.xlab.app/img-proxy/?k=4776a089&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEMqrgA4Z7FSDeB4lwIITflTLUQXNA0icpDSJKB9LibQo6mRgia5ByXareujye9zCwoWX0Yjq3rTfKvmVYDMnZmYiaOkVaBic8MLsXaU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="font-size: 15px;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: left;margin: 10px 0%;justify-content: flex-start;display: flex;flex-flow: row;opacity: 1;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 0 0 auto;min-width: 10%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="text-align: right;justify-content: flex-end;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-bottom: 4px solid rgb(224, 26, 26);border-bottom-right-radius: 0px;padding: 0px 10px 0px 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 20px;color: rgb(224, 26, 26);text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><em style="box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 18px;">04</span></span></strong></em></p></div></div></div></div><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 100 100 0%;height: auto;border-bottom: 4px solid rgb(224, 26, 26);padding: 5px 10px 5px 0px;box-sizing: border-box;"><div style="color: rgba(0, 0, 0, 0.85);font-size: 16px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">命令解析与校验逻辑绕过攻击</span></span></strong></p></div></div></div></div></div></div><p style="margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(63, 63, 63);">利用shell解析规则与智能体命令白名单/审批逻辑之间的语义差异（如$IFS分割、ZSH特有重定向语法、命令替换、环境变量污染等），绕过预设的安全检查机制执行高危命令。</span></span></p><p style="text-align: center;margin-bottom: 0px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.358203125" data-s="300,640" data-type="png" data-w="2560" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/T4OSm0sXdENU9MC0TVlnCVrDWEsu2NFt3ELicYhMFQ0kbFibDE4o2d2eOWX6EsXjydYs7GyILm2n5Is1VAjm7sGCiaLub7uHXCicVnaG914GYUM/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="578" data-cropsely2="171" data-imgfileid="100024737" src="https://wechat2rss.xlab.app/img-proxy/?k=e51a022c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdENU9MC0TVlnCVrDWEsu2NFt3ELicYhMFQ0kbFibDE4o2d2eOWX6EsXjydYs7GyILm2n5Is1VAjm7sGCiaLub7uHXCicVnaG914GYUM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(63, 63, 63);">典型案例：</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.46261089987325726" data-s="300,640" data-type="png" data-w="789" type="block" data-imgfileid="100024730" src="https://wechat2rss.xlab.app/img-proxy/?k=558d47ea&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEOb2tiaz5AoX89Z9KYpJJOEn5RfDSbHZEpvrHqzcQATDKB9uL4icknygfxSh0hOzGP92soB2CXHJJS8YdCMAkbPY1sj9RoAYkf7s%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="font-size: 15px;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: left;margin: 10px 0%;justify-content: flex-start;display: flex;flex-flow: row;opacity: 1;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 0 0 auto;min-width: 10%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="text-align: right;justify-content: flex-end;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-bottom: 4px solid rgb(224, 26, 26);border-bottom-right-radius: 0px;padding: 0px 10px 0px 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 16px;color: rgb(224, 26, 26);text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><em style="box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 18px;">05</span></span></strong></em></p></div></div></div></div><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 100 100 0%;height: auto;border-bottom: 4px solid rgb(224, 26, 26);padding: 5px 10px 5px 0px;box-sizing: border-box;"><div style="color: rgba(0, 0, 0, 0.85);font-size: 16px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">扩展机制与第三方控制通道攻击</span></span></strong></p></div></div></div></div></div></div><p style="margin-bottom: 8px;line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(63, 63, 63);">针对 MCP（Model Control Protocol）、插件系统、deep-link、本地服务接口等扩展机制进行配置篡改、OAuth滥用或域名欺骗，实现持久化控制或权限提升。</span></span></p><p style="text-align: center;margin-bottom: 0px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.31953125" data-s="300,640" data-type="png" data-w="2560" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/T4OSm0sXdEPC3nKaaUA7sBGwibcckYeLuuW4WrECRHiacym0R5j3sBfZWNoJEkfUlMEibXKHKjCdmMheiapcUWEQkUmDIChTEqO9hbC3OibXaRoI/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="578" data-cropsely2="191" data-imgfileid="100024738" src="https://wechat2rss.xlab.app/img-proxy/?k=76657bfe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEPC3nKaaUA7sBGwibcckYeLuuW4WrECRHiacym0R5j3sBfZWNoJEkfUlMEibXKHKjCdmMheiapcUWEQkUmDIChTEqO9hbC3OibXaRoI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-bottom: 0px;line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(63, 63, 63);">典型案例：</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.41635220125786165" data-s="300,640" data-type="png" data-w="795" style="width:547px;height:228px;" type="block" data-imgfileid="100024731" src="https://wechat2rss.xlab.app/img-proxy/?k=d0517349&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEPVxtiaH5QCRAluWSHh9yya1Wd1oRzdIXaiclSkqTkPria07L1bPma8fRH141WPnqXrhib7JxQouLjbLo9RvAKPGD49czFfUyPs3XQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="font-size: 15px;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: left;margin: 10px 0%;justify-content: flex-start;display: flex;flex-flow: row;opacity: 1;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 0 0 auto;min-width: 10%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="text-align: right;justify-content: flex-end;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-bottom: 4px solid rgb(224, 26, 26);border-bottom-right-radius: 0px;padding: 0px 10px 0px 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 18px;color: rgb(224, 26, 26);text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><em style="box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">06</span></strong></em></p></div></div></div></div><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 100 100 0%;height: auto;border-bottom: 4px solid rgb(224, 26, 26);padding: 5px 10px 5px 0px;box-sizing: border-box;"><div style="color: rgba(0, 0, 0, 0.85);font-size: 16px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">本地接口暴露与跨域攻击</span></span></strong></p></div></div></div></div></div></div><p style="margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(63, 63, 63);">智能体或IDE扩展暴露的WebSocket、HTTP接口缺乏足够的源验证或CORS保护，导致恶意网站通过XSS、SSRF、CSRF等方式直接调用本地API，执行命令或窃取文件。</span></span></p><p style="text-align: center;margin-bottom: 0px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3640625" data-s="300,640" data-type="png" data-w="2560" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/T4OSm0sXdEMXnsNhwGZOBb9BEx0b8dMiaWFcb83NMh5Qzib4wFQ6DZIuRqsegiaPhhtc44958ug8u7VxyBdafVguFkkal8s51WFvLvFswHgaRs/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="578" data-cropsely2="127" data-imgfileid="100024739" src="https://wechat2rss.xlab.app/img-proxy/?k=b1ac0580&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdEMXnsNhwGZOBb9BEx0b8dMiaWFcb83NMh5Qzib4wFQ6DZIuRqsegiaPhhtc44958ug8u7VxyBdafVguFkkal8s51WFvLvFswHgaRs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-bottom: 0px;line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(63, 63, 63);">典型案例：</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5747126436781609" data-s="300,640" data-type="png" data-w="783" style="width:558px;height:321px;" type="block" data-imgfileid="100024732" src="https://wechat2rss.xlab.app/img-proxy/?k=2df6f4f9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdENIUWc9VC6JY1u1PLVOSLYib9LXtGicQhqyU0AASR1cEBPQlENQKdicUr6Ja3PyDZmllhucJRdibIEcg3rTdRZgOQOH1ChK9b4FMMo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="font-size: 15px;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: left;margin: 10px 0%;justify-content: flex-start;display: flex;flex-flow: row;opacity: 1;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><div style="display: flex;flex-flow: row;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 0 0 auto;min-width: 10%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="text-align: right;justify-content: flex-end;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-bottom: 4px solid rgb(224, 26, 26);border-bottom-right-radius: 0px;padding: 0px 10px 0px 0px;align-self: flex-start;box-sizing: border-box;"><div style="font-size: 18px;color: rgb(224, 26, 26);text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><em style="box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">07</span></strong></em></p></div></div></div></div><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 100 100 0%;height: auto;border-bottom: 4px solid rgb(224, 26, 26);padding: 5px 10px 5px 0px;box-sizing: border-box;"><div style="color: rgba(0, 0, 0, 0.85);font-size: 16px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">关键配置文件投毒与持久化控制</span></span></strong></p></div></div></div></div></div></div><p style="line-height: 1.6em;text-align: justify;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(63, 63, 63);">通过修改或注入settings.json、.git/hooks/、.yarnrc.yml、.cursorignore、</span></span></p><p style="line-height: 1.6em;text-align: justify;margin-top: 0px;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(63, 63, 63);">.code-workspace 等关键配置文件，实现智能体行为篡改、沙箱逃逸或持久化控制。</span></span></p><p style="text-align: center;margin-bottom: 0px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3359375" data-s="300,640" data-type="png" data-w="2560" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/T4OSm0sXdENkj5TM3IUJtHktHh4N9vzjnHEEicc0pem47exXERFyMbUAsMsAqGo0vCwMSGGsUjQeBjnd06WvmgwLW6h7qLw0seNSwJTBWErY/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="578" data-cropsely2="204" data-imgfileid="100024740" src="https://wechat2rss.xlab.app/img-proxy/?k=db1785f3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FT4OSm0sXdENkj5TM3IUJtHktHh4N9vzjnHEEicc0pem47exXERFyMbUAsMsAqGo0vCwMSGGsUjQeBjnd06WvmgwLW6h7qLw0seNSwJTBWErY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.6em;text-align: justify;margin-top: 0px;margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(63, 63, 63);">典型案例：</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9155844155844156" data-s="300,640" data-type="png" data-w="770" style="width:530px;height:485px;" type="block" data-imgfileid="100024729" src="https://wechat2rss.xlab.app/img-proxy/?k=46aa4717&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FT4OSm0sXdEOIUazMyFGw7sXbYjKzSojwppibmibakU9AXm4BIFthwSmZeJa8kpepdSYtPF5IkvpFsxwiawMaibnZD8SnUKgG3ZhItbL5HtwQE3U%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="font-size: 15px;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="margin: 10px 0% 0px;display: inline-block;width: 100%;border-width: 0px 0px 0px 10px;border-style: solid;border-left-color: rgb(219, 0, 0);border-right-color: rgb(219, 0, 0);padding: 0px 0px 0px 5px;box-sizing: border-box;"><div style="font-size: 17px;width: 100%;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">AI Coding Agent防护</span></strong></p></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(63, 63, 63);">目前企业仍处于功能优先、安全补救的阶段，多数产品对Prompt Injection、配置投毒、边界绕过的防御仍不充分。</span><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(63, 63, 63);font-weight: bold;">建议将AI编程智能体安全纳入企业供应链安全管理体系，与依赖扫描、容器化、访问控制等措施统筹推进</span><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(63, 63, 63);">。</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(63, 63, 63);">从漏洞利用手法来看，短期内严格的流程管控与最小权限原则仍是最高效的现实防护手段，可采取的措施有：</span></span></p></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li style="font-size:15px;"><p style="margin-bottom: 8px;text-indent: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">强制使用最新版本，关闭Auto-Run 与Auto-Apply功能。</span></span></p></li><li style="font-size:15px;"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">以容器或低权限账户隔离运行，限制对主系统访问。</span></span></p></li><li style="font-size:15px;"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">克隆外部仓库前强制人工审查，禁用 .yarnrc.yml、.cursor/ 目录、git hooks 等自动加载。</span></span></p></li><li style="font-size:15px;"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">MCP与插件仅限白名单，定期审计已批准配置。</span></span></p></li><li style="font-size:15px;"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">监控对私钥、token、settings.json 等敏感文件的写操作。</span></span></p></li><li style="font-size:15px;"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">所有shell执行必须人工确认，启用最严格白名单。</span></span></p></li><li style="font-size:15px;"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">网络层面仅允许官方 API 域名访问。</span></span></p></li><li style="font-size:15px;"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 15px;">建立“不可信项目隔离使用”流程，并对团队进行针对性培训。</span></span></p></li></ul><div style="font-size: 15px;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="margin: 10px 0% 0px;display: inline-block;width: 100%;border-width: 0px 0px 0px 10px;border-style: solid;border-left-color: rgb(219, 0, 0);border-right-color: rgb(219, 0, 0);padding: 0px 0px 0px 5px;box-sizing: border-box;"><div style="font-size: 17px;width: 100%;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">附：部分AI Coding Agent漏洞清单</span></strong></p></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(63, 63, 63);font-weight: bold;">Claude Code</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(63, 63, 63);font-weight: normal;">共21个漏洞，其中20个有CVE编号，1个仅有GHSA编号。</span></span></p></div><div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="will-change: transform;box-sizing: border-box;"><p style="font-size: 10px;box-sizing: border-box;margin-bottom: -10px;"><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;width:523px;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:45.3pt;"><td data-colwidth="44" width="44" style="border-width: 1pt;border-style: solid;border-color: rgb(223, 226, 229) rgb(223, 226, 229) rgb(203, 205, 209);border-image: initial;padding: 3.6pt 7.8pt;height: 45.3pt;"><p><span leaf=""><span textstyle="" style="font-size: 10px;font-weight: bold;">序号</span></span></p></td><td data-colwidth="63" width="63" style="border-top: 1pt solid rgb(223, 226, 229);border-left: none;border-bottom: 1pt solid rgb(203, 205, 209);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 45.3pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;font-weight: bold;">GHSA</span></span></span></p></td><td data-colwidth="63" width="63" style="border-top: 1pt solid rgb(223, 226, 229);border-left: none;border-bottom: 1pt solid rgb(203, 205, 209);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 45.3pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;font-weight: bold;">CVE</span></span></span></p></td><td data-colwidth="64" width="57" style="border-top: 1pt solid rgb(223, 226, 229);border-left: none;border-bottom: 1pt solid rgb(203, 205, 209);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 45.3pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;font-weight: bold;">XVE</span></span></span></p></td><td data-colwidth="58" width="66" style="border-top: 1pt solid rgb(223, 226, 229);border-left: none;border-bottom: 1pt solid rgb(203, 205, 209);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 45.3pt;"><p><span leaf=""><span textstyle="" style="font-size: 10px;font-weight: bold;">公告</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 10px;font-weight: bold;">时间</span></span></p></td><td data-colwidth="106" width="57" style="border-top: 1pt solid rgb(223, 226, 229);border-left: none;border-bottom: 1pt solid rgb(203, 205, 209);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 45.3pt;"><p><span leaf=""><span textstyle="" style="font-size: 10px;font-weight: bold;">官方</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 10px;font-weight: bold;">定级</span></span></p></td><td data-colwidth="59" width="85" style="border-top: 1pt solid rgb(223, 226, 229);border-left: none;border-bottom: 1pt solid rgb(203, 205, 209);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 45.3pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;font-weight: bold;">GitHub</span></span></span><span leaf=""><span textstyle="" style="font-size: 10px;font-weight: bold;">影响版本</span></span></p></td><td data-colwidth="66" width="66" style="border-top: 1pt solid rgb(223, 226, 229);border-left: none;border-bottom: 1pt solid rgb(203, 205, 209);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 45.3pt;"><p><span leaf=""><span textstyle="" style="font-size: 10px;font-weight: bold;">修复版本</span></span></p></td></tr><tr style="mso-yfti-irow:1;height:20.25pt;"><td data-colwidth="44" width="44" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">1</span></span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-66q4-vfjg-2qhh</span></span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2026-25722</span></span></span></p></td><td data-colwidth="64" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2026-2727</span></span></span></p></td><td data-colwidth="58" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">2026-02-06</span></span></span></p></td><td data-colwidth="106" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p style="text-align: center;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">High</span></span></span></p></td><td data-colwidth="59" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt; v2.0.57</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">v2.0.57</span></span></span></p></td></tr><tr style="mso-yfti-irow:2;height:20.25pt;"><td data-colwidth="44" width="44" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">2</span></span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-mhg7-666j-cqg4</span></span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2026-25723</span></span></span></p></td><td data-colwidth="64" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2026-2728</span></span></span></p></td><td data-colwidth="58" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">2026-02-06</span></span></span></p></td><td data-colwidth="106" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">High</span></span></span></p></td><td data-colwidth="59" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt;   v2.0.55</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">v2.0.55</span></span></span></p></td></tr><tr style="mso-yfti-irow:3;height:20.25pt;"><td data-colwidth="44" width="44" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">3</span></span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-ff64-7w26-62rf</span></span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2026-25725</span></span></span></p></td><td data-colwidth="64" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2026-2730</span></span></span></p></td><td data-colwidth="58" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">2026-02-06</span></span></span></p></td><td data-colwidth="106" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">High</span></span></span></p></td><td data-colwidth="59" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt; v2.1.2</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">v2.1.2</span></span></span></p></td></tr><tr style="mso-yfti-irow:4;height:20.25pt;"><td data-colwidth="44" width="44" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">4</span></span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-4q92-rfm6-2cqx</span></span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2026-25724</span></span></span></p></td><td data-colwidth="64" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2026-2729</span></span></span></p></td><td data-colwidth="58" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">2026-02-06</span></span></span></p></td><td data-colwidth="106" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">Low</span></span></span></p></td><td data-colwidth="59" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt;   v2.1.7</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">v2.1.7</span></span></span></p></td></tr><tr style="mso-yfti-irow:5;height:20.25pt;"><td data-colwidth="44" width="44" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">5</span></span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-qgqw-h4xq-7w8w</span></span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2026-24887</span></span></span></p></td><td data-colwidth="64" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2026-2325</span></span></span></p></td><td data-colwidth="58" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">2026-02-03</span></span></span></p></td><td data-colwidth="106" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">High</span></span></span></p></td><td data-colwidth="59" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt; v2.0.72</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">v2.0.72</span></span></span></p></td></tr><tr style="mso-yfti-irow:6;height:20.25pt;"><td data-colwidth="44" width="44" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">6</span></span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-q728-gf8j-w49r</span></span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2026-24053</span></span></span></p></td><td data-colwidth="64" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2026-2340</span></span></span></p></td><td data-colwidth="58" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">2026-02-03</span></span></span></p></td><td data-colwidth="106" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">High</span></span></span></p></td><td data-colwidth="59" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt;   v2.0.74</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">v2.0.74</span></span></span></p></td></tr><tr style="mso-yfti-irow:7;height:20.25pt;"><td data-colwidth="44" width="44" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">7</span></span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-vhw5-3g5m-8ggf</span></span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2026-24052</span></span></span></p></td><td data-colwidth="64" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2026-2341</span></span></span></p></td><td data-colwidth="58" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">2026-02-03</span></span></span></p></td><td data-colwidth="106" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">High</span></span></span></p></td><td data-colwidth="59" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt; v1.0.111</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">v1.0.111</span></span></span></p></td></tr><tr style="mso-yfti-irow:8;height:20.25pt;"><td data-colwidth="44" width="44" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">8</span></span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-jh7p-qr78-84p7</span></span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2026-21852</span></span></span></p></td><td data-colwidth="64" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2026-1180</span></span></span></p></td><td data-colwidth="58" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">2026-01-20</span></span></span></p></td><td data-colwidth="106" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">Medium</span></span></span></p></td><td data-colwidth="59" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt;   v2.0.65</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">v2.0.65</span></span></span></p></td></tr><tr style="mso-yfti-irow:9;height:20.25pt;"><td data-colwidth="44" width="44" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">9</span></span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-xq4m-mc3c-vvg3</span></span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2025-66032</span></span></span></p></td><td data-colwidth="64" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2025-42681</span></span></span></p></td><td data-colwidth="58" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">2025-12-03</span></span></span></p></td><td data-colwidth="106" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">High</span></span></span></p></td><td data-colwidth="59" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt;v1.0.93</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">v1.0.93</span></span></span></p></td></tr><tr style="mso-yfti-irow:10;height:20.25pt;"><td data-colwidth="44" width="44" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">10</span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">GHSA-5hhx-v7f6-x7gv</span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">CVE-2025-65099</span></span></p></td><td data-colwidth="64" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">XVE-2025-41441</span></span></p></td><td data-colwidth="58" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">2025-11-19</span></span></p></td><td data-colwidth="106" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">High</span></span></p></td><td data-colwidth="59" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">&lt;v1.0.39</span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p style="text-align: right;"><span lang="EN-US" style="color: black;"><span leaf="">v1.0.39</span></span></p></td></tr><tr style="mso-yfti-irow:11;height:20.25pt;"><td data-colwidth="44" width="44" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">11</span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">GHSA-7mv8-j34q-vp7q</span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">CVE-2025-64755</span></span></p></td><td data-colwidth="64" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">XVE-2025-41631</span></span></p></td><td data-colwidth="58" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">2025-11-20</span></span></p></td><td data-colwidth="106" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">High</span></span></p></td><td data-colwidth="59" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">&lt;v2.0.31</span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">v2.0.31</span></span></p></td></tr><tr style="mso-yfti-irow:12;height:20.25pt;"><td data-colwidth="44" width="44" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">12</span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">GHSA-66m2-gx93-v996</span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">CVE-2025-59829</span></span></p></td><td data-colwidth="64" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">XVE-2025-36102</span></span></p></td><td data-colwidth="58" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">2025-10-03</span></span></p></td><td data-colwidth="106" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">Low</span></span></p></td><td data-colwidth="59" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">&lt;   v1.0.120</span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">v1.0.120</span></span></p></td></tr><tr style="mso-yfti-irow:13;height:20.25pt;"><td data-colwidth="44" width="44" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">13</span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">GHSA-2jjv-qf24-vfm4</span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">CVE-2025-59828</span></span></p></td><td data-colwidth="64" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">XVE-2025-35128</span></span></p></td><td data-colwidth="58" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">2025-09-24</span></span></p></td><td data-colwidth="106" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">High</span></span></p></td><td data-colwidth="59" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">&lt; v1.0.39</span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">v1.0.39</span></span></p></td></tr><tr style="mso-yfti-irow:14;height:20.25pt;"><td data-colwidth="44" width="44" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">14</span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">GHSA-4fgq-fpq9-mr3g</span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">CVE-2025-59536</span></span></p></td><td data-colwidth="64" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">XVE-2025-36082</span></span></p></td><td data-colwidth="58" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">2025-10-03</span></span></p></td><td data-colwidth="106" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">High</span></span></p></td><td data-colwidth="59" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">&lt;   v1.0.111</span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">v1.0.111</span></span></p></td></tr><tr style="mso-yfti-irow:15;height:20.25pt;"><td data-colwidth="44" width="44" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">15</span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">GHSA-j4h9-wv2m-wrf7</span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">CVE-2025-59041</span></span></p></td><td data-colwidth="64" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">XVE-2025-33444</span></span></p></td><td data-colwidth="58" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">2025-09-09</span></span></p></td><td data-colwidth="106" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">High</span></span></p></td><td data-colwidth="59" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">&lt;1.0.105</span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">1.0.105</span></span></p></td></tr><tr style="mso-yfti-irow:16;height:20.25pt;"><td data-colwidth="44" width="44" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">16</span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">GHSA-qxfv-fcpc-w36x</span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">CVE-2025-58764</span></span></p></td><td data-colwidth="64" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">XVE-2025-33443</span></span></p></td><td data-colwidth="58" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">2025-09-09</span></span></p></td><td data-colwidth="106" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">High</span></span></p></td><td data-colwidth="59" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">&lt;1.0.105</span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">1.0.105</span></span></p></td></tr><tr style="mso-yfti-irow:17;height:20.25pt;"><td data-colwidth="44" width="44" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">17</span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">GHSA-ph6w-f82w-28w6</span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">N/A</span></span></p></td><td data-colwidth="64" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">XVE-2025-32752</span></span></p></td><td data-colwidth="58" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">2025-09-02</span></span></p></td><td data-colwidth="106" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">High</span></span></p></td><td data-colwidth="59" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">&lt; v1.0.87</span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">v1.0.87</span></span></p></td></tr><tr style="mso-yfti-irow:18;height:20.25pt;"><td data-colwidth="44" width="44" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">18</span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">GHSA-x5gv-jw7f-j6xj</span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">CVE-2025-55284</span></span></p></td><td data-colwidth="64" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">XVE-2025-30835</span></span></p></td><td data-colwidth="58" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">2025-08-15</span></span></p></td><td data-colwidth="106" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">High</span></span></p></td><td data-colwidth="59" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">&lt;   v1.0.4</span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">v1.0.4</span></span></p></td></tr><tr style="mso-yfti-irow:19;height:20.25pt;"><td data-colwidth="44" width="44" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">19</span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">GHSA-x56v-x2h6-7j34</span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">CVE-2025-54795</span></span></p></td><td data-colwidth="64" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">XVE-2025-29459</span></span></p></td><td data-colwidth="58" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">2025-08-01</span></span></p></td><td data-colwidth="106" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">High</span></span></p></td><td data-colwidth="59" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">&lt; v1.0.20</span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">v1.0.20</span></span></p></td></tr><tr style="mso-yfti-irow:20;height:20.25pt;"><td data-colwidth="44" width="44" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">20</span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">GHSA-pmw4-pwvc-3hx2</span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">CVE-2025-54794</span></span></p></td><td data-colwidth="64" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">XVE-2025-29460</span></span></p></td><td data-colwidth="58" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">2025-08-01</span></span></p></td><td data-colwidth="106" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">High</span></span></p></td><td data-colwidth="59" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">&lt;   v0.2.111</span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf="">v0.2.111</span></span></p></td></tr><tr style="mso-yfti-irow:21;mso-yfti-lastrow:yes;height:20.25pt;"><td data-colwidth="44" width="44" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">21</span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">GHSA-9f65-56v6-gxw7</span></span></p></td><td data-colwidth="63" width="63" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">CVE-2025-52882</span></span></p></td><td data-colwidth="64" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">XVE-2025-24962</span></span></p></td><td data-colwidth="58" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">2025-06-23</span></span></p></td><td data-colwidth="106" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">High</span></span></p></td><td data-colwidth="59" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">&gt; 0.2.116 &lt; 1.0.24</span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf="">1.0.24+</span></span></p></td></tr></tbody></table></p></div></div><table style="border-collapse:collapse;border:none;table-layout:fixed;mso-table-layout-alt:fixed;width:508px;"><tbody><tr style="height:27px;"></tr></tbody></table><div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="will-change: transform;box-sizing: border-box;"><div style="font-size: 10px;box-sizing: border-box;margin-bottom: -10px;"><div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="will-change: transform;box-sizing: border-box;"><div style="font-size: 10px;box-sizing: border-box;margin-bottom: -10px;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">Cursor</span></span></p></div></div></div></div></div></div><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">共 <span textstyle="" style="font-weight: bold;">28 个</span>漏洞，其中25个有CVE编号，3个仅有GHSA编号。</span></span></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:
 1184;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:20.25pt;"><td data-colwidth="85" width="85" style="border-width: 1pt;border-style: solid;border-color: rgb(223, 226, 229) rgb(223, 226, 229) rgb(203, 205, 209);border-image: initial;padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;font-weight: bold;">GHSA</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: 1pt solid rgb(223, 226, 229);border-left: none;border-bottom: 1pt solid rgb(203, 205, 209);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;font-weight: bold;">CVE</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: 1pt solid rgb(223, 226, 229);border-left: none;border-bottom: 1pt solid rgb(203, 205, 209);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;font-weight: bold;">XVE</span></span></span></p></td><td data-colwidth="85" width="85" style="border-top: 1pt solid rgb(223, 226, 229);border-left: none;border-bottom: 1pt solid rgb(203, 205, 209);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span leaf=""><span textstyle="" style="font-size: 10px;font-weight: bold;">产品（为空的是</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;font-weight: bold;">cursor</span></span></span><span leaf=""><span textstyle="" style="font-size: 10px;font-weight: bold;">）</span></span></p></td><td data-colwidth="66" width="66" style="border-top: 1pt solid rgb(223, 226, 229);border-left: none;border-bottom: 1pt solid rgb(203, 205, 209);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span leaf=""><span textstyle="" style="font-size: 10px;font-weight: bold;">公告时间</span></span></p></td><td data-colwidth="57" width="57" style="border-top: 1pt solid rgb(223, 226, 229);border-left: none;border-bottom: 1pt solid rgb(203, 205, 209);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span leaf=""><span textstyle="" style="font-size: 10px;font-weight: bold;">官方定级</span></span></p></td><td data-colwidth="66" width="66" style="border-top: 1pt solid rgb(223, 226, 229);border-left: none;border-bottom: 1pt solid rgb(203, 205, 209);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;font-weight: bold;">GitHub</span></span></span><span leaf=""><span textstyle="" style="font-size: 10px;font-weight: bold;">影响版本</span></span></p></td><td data-colwidth="57" width="57" style="border-top: 1pt solid rgb(223, 226, 229);border-left: none;border-bottom: 1pt solid rgb(203, 205, 209);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span leaf=""><span textstyle="" style="font-size: 10px;font-weight: bold;">修复</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 10px;font-weight: bold;">版本</span></span></p></td></tr><tr style="mso-yfti-irow:1;height:20.25pt;"><td data-colwidth="85" width="85" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-8pcm-8jpx-hv8r</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2026-26268</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2026-3480</span></span></span></p></td><td data-colwidth="85" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">Cursor</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">2026-02-13</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">High</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt;2.5</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">2.5</span></span></span></p></td></tr><tr style="mso-yfti-irow:2;height:20.25pt;"><td data-colwidth="85" width="85" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-2jr2-8wf5-v6pf</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2025-64107</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2025-39894</span></span></span></p></td><td data-colwidth="85" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">Cursor</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">2025-11-03</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">High</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">1.7.52</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">2.0</span></span></span></p></td></tr><tr style="mso-yfti-irow:3;height:20.25pt;"><td data-colwidth="85" width="85" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-4575-fh42-7848</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2025-64106</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2025-39893</span></span></span></p></td><td data-colwidth="85" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">Cursor</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">2025-11-03</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">High</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">1.7.28</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">2.0</span></span></span></p></td></tr><tr style="mso-yfti-irow:4;height:20.25pt;"><td data-colwidth="85" width="85" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-6r98-6qcw-rxrw</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2025-64108</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2025-39890</span></span></span></p></td><td data-colwidth="85" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">Cursor</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">2025-11-03</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">High</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">1.7.44</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">2.0</span></span></span></p></td></tr><tr style="mso-yfti-irow:5;height:20.25pt;"><td data-colwidth="85" width="85" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-vhc2-fjv4-wqch</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2025-64110</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2025-39888</span></span></span></p></td><td data-colwidth="85" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">Cursor</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">2025-11-03</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">High</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">1.7.23</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">2.0</span></span></span></p></td></tr><tr style="mso-yfti-irow:6;height:20.25pt;"><td data-colwidth="85" width="85" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-x2vq-h6v6-jhc6</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2025-61593</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2025-36148</span></span></span></p></td><td data-colwidth="85" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">Cursor   CLI</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">2025-10-02</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">High</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt;   2025.09.12-4852336</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">2025.09.17-25b418f</span></span></span></p></td></tr><tr style="mso-yfti-irow:7;height:20.25pt;"><td data-colwidth="85" width="85" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-xcwh-rrwj-gxc7</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2025-59944</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2025-36161</span></span></span></p></td><td data-colwidth="85" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">Cursor</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">2025-10-02</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">High</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt; 1.6.23</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">1.7</span></span></span></p></td></tr><tr style="mso-yfti-irow:8;height:20.25pt;"><td data-colwidth="85" width="85" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-wj33-264c-j9cq</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2025-61591</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2025-36117</span></span></span></p></td><td data-colwidth="85" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">Cursor   CLI</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">2025-10-02</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">High</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt;   2025.09.17-25b418f</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">2025.09.17-25b418f</span></span></span></p></td></tr><tr style="mso-yfti-irow:9;height:20.25pt;"><td data-colwidth="85" width="85" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-hf2x-r83r-qw5q</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2026-31854</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2026-7126</span></span></span></p></td><td data-colwidth="85" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">Cursor</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">2026-03-09</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">High</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt;2.0</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">2.0</span></span></span></p></td></tr><tr style="mso-yfti-irow:10;height:20.25pt;"><td data-colwidth="85" width="85" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-v64q-396f-7m79</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2025-61592</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2025-36115</span></span></span></p></td><td data-colwidth="85" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">Cursor   CLI</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">2025-10-02</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">High</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt;   2025.09.17-25b418f</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">2025.09.17-25b418f</span></span></span></p></td></tr><tr style="mso-yfti-irow:11;height:20.25pt;"><td data-colwidth="85" width="85" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-4hwr-97q3-37w2</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2025-64109</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2025-39889</span></span></span></p></td><td data-colwidth="85" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">Cursor CLI</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">2025-11-03</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">High</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt; 2025.09.17-25b418f</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">2025.09.17-25b418f</span></span></span></p></td></tr><tr style="mso-yfti-irow:12;height:20.25pt;"><td data-colwidth="85" width="85" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-82wg-qcm4-fp2w</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2026-22708</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2026-0670</span></span></span></p></td><td data-colwidth="85" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">Cursor</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">2026-01-14</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">High</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt;=   2.2</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">2.3</span></span></span></p></td></tr><tr style="mso-yfti-irow:13;height:20.25pt;"><td data-colwidth="85" width="85" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-xg6w-rmh5-r77r</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2025-61590</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2025-36118</span></span></span></p></td><td data-colwidth="85" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">Cursor</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">2025-10-02</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">High</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt; 1.7</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">1.7</span></span></span></p></td></tr><tr style="mso-yfti-irow:14;height:20.25pt;"><td data-colwidth="85" width="85" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-xw2x-252g-97w2</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2025-61589</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2025-36081</span></span></span></p></td><td data-colwidth="85" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">Cursor</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">2025-10-02</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">Medium</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt;=1.6</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">1.7</span></span></span></p></td></tr><tr style="mso-yfti-irow:15;height:20.25pt;"><td data-colwidth="85" width="85" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-24mc-g4xr-4395</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2025-54136</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2025-29347</span></span></span></p></td><td data-colwidth="85" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">Cursor</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">2025-08-01</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">High</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt; 1.2.4</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">1.3</span></span></span></p></td></tr><tr style="mso-yfti-irow:16;height:20.25pt;"><td data-colwidth="85" width="85" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-4cxx-hrm3-49rm</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2025-54135</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2025-29425</span></span></span></p></td><td data-colwidth="85" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">Cursor</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">2025-08-02</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">High</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt;=   1.2.1</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">1.3.9</span></span></span></p></td></tr><tr style="mso-yfti-irow:17;height:20.25pt;"><td data-colwidth="85" width="85" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-r22h-5wp2-2wfv</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2025-54133</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2025-29346</span></span></span></p></td><td data-colwidth="85" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">Cursor</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">2025-08-01</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">Medium</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">1.17</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">1.3</span></span></span></p></td></tr><tr style="mso-yfti-irow:18;height:20.25pt;"><td data-colwidth="85" width="85" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-43wj-mwcc-x93p</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2025-54132</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2025-29349</span></span></span></p></td><td data-colwidth="85" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">Cursor</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">2025-08-01</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">Medium</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt;1.3</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">1.3</span></span></span></p></td></tr><tr style="mso-yfti-irow:19;height:20.25pt;"><td data-colwidth="85" width="85" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-534m-3w6r-8pqr</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2025-54131</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2025-29348</span></span></span></p></td><td data-colwidth="85" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">Cursor</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">2025-08-01</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">Medium</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt;1.3</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">1.3</span></span></span></p></td></tr><tr style="mso-yfti-irow:20;height:20.25pt;"><td data-colwidth="85" width="85" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-c43p-6fv2-6gr2</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">N/A</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2025-29506</span></span></span></p></td><td data-colwidth="85" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">Cursor   API</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">2025-06-19</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">Medium</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt;   2025-06-17</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">2025-06-17</span></span></span></p></td></tr><tr style="mso-yfti-irow:21;height:20.25pt;"><td data-colwidth="85" width="85" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-rjmc-526x-8653</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">N/A</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2025-29505</span></span></span></p></td><td data-colwidth="85" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">Cursor API</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">2025-06-19</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">Medium</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt; 2025-06-17</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">2025-06-17</span></span></span></p></td></tr><tr style="mso-yfti-irow:22;height:20.25pt;"><td data-colwidth="85" width="85" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-9h3v-h59j-v6rj</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2025-49150</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2025-23218</span></span></span></p></td><td data-colwidth="85" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">Cursor</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">2025-06-11</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">Medium</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt;0.51.0</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">0.51.0</span></span></span></p></td></tr><tr style="mso-yfti-irow:23;height:20.25pt;"><td data-colwidth="85" width="85" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-vqv7-vq92-x87f</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2025-54130</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2025-29500</span></span></span></p></td><td data-colwidth="85" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">Cursor</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">2025-08-02</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">High</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt;1.3</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">1.3.9</span></span></span></p></td></tr><tr style="mso-yfti-irow:24;height:20.25pt;"><td data-colwidth="85" width="85" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-qjh8-mh96-fc86</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2025-32018</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2025-12996</span></span></span></p></td><td data-colwidth="85" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">Cursor</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">2025-04-07</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">High</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">0.45.0-0.48.6</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">0.48.7+</span></span></span></p></td></tr><tr style="mso-yfti-irow:25;height:20.25pt;"><td data-colwidth="85" width="85" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-g4ff-54cv-h6f9</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">N/A</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2024-42959</span></span></span></p></td><td data-colwidth="85" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">Cursor API</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">2024-11-27</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">Low</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt; 2025-11-27</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">Nov 27+</span></span></span></p></td></tr><tr style="mso-yfti-irow:26;height:20.25pt;"><td data-colwidth="85" width="85" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-rmj9-23rg-gr67</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2024-48919</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2024-30588</span></span></span></p></td><td data-colwidth="85" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">Cursor</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">2024-10-22</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">High</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt;=   0.41.0</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">0.42</span></span></span></p></td></tr><tr style="mso-yfti-irow:27;mso-yfti-lastrow:yes;height:20.25pt;"><td data-colwidth="85" width="85" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-x352-xv29-r74m</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2024-45599</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2024-28100</span></span></span></p></td><td data-colwidth="85" width="85" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">Cursor</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">2024-09-24</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">Low</span></span></span></p></td><td data-colwidth="66" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt; 0.41.0</span></span></span></p></td><td data-colwidth="57" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">0.41.0</span></span></span></p></td></tr></tbody></table><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;" data-pm-slice="0 0 []"><span style="font-size:11pt;font-weight:bold;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;">OpenCode</span></span></span></p><table style="border-collapse:collapse;border:none;table-layout:fixed;mso-table-layout-alt:fixed;"><tbody><tr style="height:27px;"><td data-colwidth="96" width="96" style="box-sizing: border-box;vertical-align: middle;padding: 4.8px 10.4px;border-width: 1px;border-style: solid;border-color: rgb(223, 226, 229) rgb(223, 226, 229) rgb(203, 205, 209);"><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 12px;font-weight: bold;">GHSA</span></span></span></p></td><td data-colwidth="72" width="72" style="box-sizing: border-box;vertical-align: middle;padding: 4.8px 10.4px;border-width: 1px 1px 1px 0px;border-style: solid;border-color: rgb(223, 226, 229) rgb(223, 226, 229) rgb(203, 205, 209);"><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 12px;font-weight: bold;">CVE</span></span></span></p></td><td data-colwidth="68" width="68" style="box-sizing: border-box;vertical-align: middle;padding: 4.8px 10.4px;border-width: 1px 1px 1px 0px;border-style: solid;border-color: rgb(223, 226, 229) rgb(223, 226, 229) rgb(203, 205, 209);"><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 12px;font-weight: bold;">XVE</span></span></span></p></td><td data-colwidth="52" width="52" style="box-sizing: border-box;vertical-align: middle;padding: 4.8px 10.4px;border-width: 1px 1px 1px 0px;border-style: solid;border-color: rgb(223, 226, 229) rgb(223, 226, 229) rgb(203, 205, 209);"><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 12px;font-weight: bold;">产品</span></span></span></p></td><td data-colwidth="58" width="58" style="box-sizing: border-box;vertical-align: middle;padding: 4.8px 10.4px;border-width: 1px 1px 1px 0px;border-style: solid;border-color: rgb(223, 226, 229) rgb(223, 226, 229) rgb(203, 205, 209);"><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 12px;font-weight: bold;">公告</span></span></span></p><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 12px;font-weight: bold;">时间</span></span></span></p></td><td data-colwidth="74" width="74" style="box-sizing: border-box;vertical-align: middle;padding: 4.8px 10.4px;border-width: 1px 1px 1px 0px;border-style: solid;border-color: rgb(223, 226, 229) rgb(223, 226, 229) rgb(203, 205, 209);"><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 12px;font-weight: bold;">官方</span></span></span></p><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 12px;font-weight: bold;">定级</span></span></span></p></td><td data-colwidth="72" width="72" style="box-sizing: border-box;vertical-align: middle;padding: 4.8px 10.4px;border-width: 1px 1px 1px 0px;border-style: solid;border-color: rgb(223, 226, 229) rgb(223, 226, 229) rgb(203, 205, 209);"><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 12px;font-weight: bold;">影响</span></span></span></p><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 12px;font-weight: bold;">版本</span></span></span></p></td><td data-colwidth="73" width="73" style="box-sizing: border-box;vertical-align: middle;padding: 4.8px 10.4px;border-width: 1px 1px 1px 0px;border-style: solid;border-color: rgb(223, 226, 229) rgb(223, 226, 229) rgb(203, 205, 209);"><p style="text-align: center;line-height: 1.3;margin: 3pt 0pt;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 12px;font-weight: bold;">修复</span></span></span></p><p style="text-align: center;line-height: 1.3;margin: 3pt 0pt;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 12px;font-weight: bold;">版本</span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="96" width="96" style="box-sizing: border-box;vertical-align: middle;padding: 4.8px 10.4px;border-width: 1px;border-style: solid;border-color: rgb(203, 205, 209) rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-c83v-7274-4vgp</span></span></span></p></td><td data-colwidth="72" width="72" style="box-sizing: border-box;vertical-align: middle;padding: 4.8px 10.4px;border-width: 1px 1px 1px 0px;border-style: solid;border-color: rgb(203, 205, 209) rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2026-22813</span></span></span></p></td><td data-colwidth="68" width="68" style="box-sizing: border-box;vertical-align: middle;padding: 4.8px 10.4px;border-width: 1px 1px 1px 0px;border-style: solid;border-color: rgb(203, 205, 209) rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2026-0429</span></span></span></p></td><td data-colwidth="52" width="52" style="box-sizing: border-box;vertical-align: middle;padding: 4.8px 10.4px;border-width: 1px 1px 1px 0px;border-style: solid;border-color: rgb(203, 205, 209) rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 10px;">Opencode</span></span></span></p></td><td data-colwidth="58" width="58" style="box-sizing: border-box;vertical-align: middle;padding: 4.8px 10.4px;border-width: 1px 1px 1px 0px;border-style: solid;border-color: rgb(203, 205, 209) rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 10px;">2026-01-12</span></span></span></p></td><td data-colwidth="74" width="74" style="box-sizing: border-box;vertical-align: middle;padding: 4.8px 10.4px;border-width: 1px 1px 1px 0px;border-style: solid;border-color: rgb(203, 205, 209) rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 10px;">Critical</span></span></span></p></td><td data-colwidth="72" width="72" style="box-sizing: border-box;vertical-align: middle;padding: 4.8px 10.4px;border-width: 1px 1px 1px 0px;border-style: solid;border-color: rgb(203, 205, 209) rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt;1.1.10</span></span></span></p></td><td data-colwidth="73" width="73" style="box-sizing: border-box;vertical-align: middle;padding: 4.8px 10.4px;border-width: 1px 1px 1px 0px;border-style: solid;border-color: rgb(203, 205, 209) rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 10px;">1.1.10</span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="96" width="96" style="box-sizing: border-box;background: rgb(248, 248, 248);vertical-align: middle;padding: 4.8px 10.4px;border-width: 0px 1px 1px;border-style: solid;border-color: rgb(223, 226, 229);"><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-vxw4-wv6m-9hhh</span></span></span></p></td><td data-colwidth="72" width="72" style="box-sizing: border-box;background: rgb(248, 248, 248);vertical-align: middle;padding: 4.8px 10.4px;border-width: 0px 1px 1px 0px;border-style: solid;border-color: rgb(223, 226, 229);"><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2026-22812</span></span></span></p></td><td data-colwidth="68" width="68" style="box-sizing: border-box;background: rgb(248, 248, 248);vertical-align: middle;padding: 4.8px 10.4px;border-width: 0px 1px 1px 0px;border-style: solid;border-color: rgb(223, 226, 229);"><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2026-0428</span></span></span></p></td><td data-colwidth="52" width="52" style="box-sizing: border-box;background: rgb(248, 248, 248);vertical-align: middle;padding: 4.8px 10.4px;border-width: 0px 1px 1px 0px;border-style: solid;border-color: rgb(223, 226, 229);"><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 10px;">Opencode</span></span></span></p></td><td data-colwidth="58" width="58" style="box-sizing: border-box;background: rgb(248, 248, 248);vertical-align: middle;padding: 4.8px 10.4px;border-width: 0px 1px 1px 0px;border-style: solid;border-color: rgb(223, 226, 229);"><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 10px;">2026-01-12</span></span></span></p></td><td data-colwidth="74" width="74" style="box-sizing: border-box;background: rgb(248, 248, 248);vertical-align: middle;padding: 4.8px 10.4px;border-width: 0px 1px 1px 0px;border-style: solid;border-color: rgb(223, 226, 229);"><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 10px;">High</span></span></span></p></td><td data-colwidth="72" width="72" style="box-sizing: border-box;background: rgb(248, 248, 248);vertical-align: middle;padding: 4.8px 10.4px;border-width: 0px 1px 1px 0px;border-style: solid;border-color: rgb(223, 226, 229);"><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt; 1.0.216</span></span></span></p></td><td data-colwidth="73" width="73" style="box-sizing: border-box;background: rgb(248, 248, 248);vertical-align: middle;padding: 4.8px 10.4px;border-width: 0px 1px 1px 0px;border-style: solid;border-color: rgb(223, 226, 229);"><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 10px;">1.0.216</span></span></span></p></td></tr></tbody></table><p style="margin-top: 16px;margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">Codex CLI</span></span></p><table style="border-collapse:collapse;mso-table-layout-alt:fixed;mso-yfti-tbllook:1184;width:543px;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:20.25pt;"><td data-colwidth="72" width="66" style="border-width: 1pt;border-style: solid;border-color: rgb(223, 226, 229) rgb(223, 226, 229) rgb(203, 205, 209);border-image: initial;padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;font-weight: bold;">GHSA</span></span></span></p></td><td data-colwidth="72" width="66" style="border-top: 1pt solid rgb(223, 226, 229);border-left: none;border-bottom: 1pt solid rgb(203, 205, 209);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;font-weight: bold;">CVE</span></span></span></p></td><td data-colwidth="69" width="66" style="border-top: 1pt solid rgb(223, 226, 229);border-left: none;border-bottom: 1pt solid rgb(203, 205, 209);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;font-weight: bold;">XVE</span></span></span></p></td><td data-colwidth="57" width="76" style="border-top: 1pt solid rgb(223, 226, 229);border-left: none;border-bottom: 1pt solid rgb(203, 205, 209);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span leaf=""><span textstyle="" style="font-size: 10px;font-weight: bold;">产品</span></span></p></td><td data-colwidth="70" width="76" style="border-top: 1pt solid rgb(223, 226, 229);border-left: none;border-bottom: 1pt solid rgb(203, 205, 209);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p style="text-align: justify;"><span leaf=""><span textstyle="" style="font-size: 10px;font-weight: bold;">公告时间</span></span></p></td><td data-colwidth="68" width="66" style="border-top: 1pt solid rgb(223, 226, 229);border-left: none;border-bottom: 1pt solid rgb(203, 205, 209);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span leaf=""><span textstyle="" style="font-size: 10px;letter-spacing: normal;font-weight: bold;">官方定级</span></span></p></td><td data-colwidth="67" width="57" style="border-top: 1pt solid rgb(223, 226, 229);border-left: none;border-bottom: 1pt solid rgb(203, 205, 209);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span leaf=""><span textstyle="" style="font-size: 10px;letter-spacing: normal;font-weight: bold;">影响版本</span></span></p></td><td data-colwidth="68" width="57" style="border-top: 1pt solid rgb(223, 226, 229);border-left: none;border-bottom: 1pt solid rgb(203, 205, 209);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span leaf=""><span textstyle="" style="font-size: 10px;letter-spacing: normal;font-weight: bold;">修复版本</span></span></p></td></tr><tr style="mso-yfti-irow:1;height:20.25pt;"><td data-colwidth="72" width="66" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">N/A</span></span></span></p></td><td data-colwidth="72" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2025-55345</span></span></span></p></td><td data-colwidth="69" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2025-30413</span></span></span></p></td><td data-colwidth="57" width="76" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">Codex CLI</span></span></span></p></td><td data-colwidth="70" width="76" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">2025-08-13</span></span></span></p></td><td data-colwidth="68" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">Medium</span></span></span></p></td><td data-colwidth="67" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt;0.12.0</span></span></span></p></td><td data-colwidth="68" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">0.12.0</span></span></span></p></td></tr><tr style="mso-yfti-irow:2;height:20.25pt;"><td data-colwidth="72" width="66" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">GHSA-w5fx-fh39-j5rw</span></span></span></p></td><td data-colwidth="72" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2025-59532</span></span></span></p></td><td data-colwidth="69" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2025-34922</span></span></span></p></td><td data-colwidth="57" width="76" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">Codex   CLI</span></span></span></p></td><td data-colwidth="70" width="76" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">2025-07-24</span></span></span></p></td><td data-colwidth="68" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">High</span></span></span></p></td><td data-colwidth="67" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">0.2.0-0.38.0</span></span></span></p></td><td data-colwidth="68" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US" style="color:black;mso-color-alt:windowtext;"><span leaf=""><span textstyle="" style="font-size: 10px;">0.39.0</span></span></span></p></td></tr><tr style="mso-yfti-irow:3;mso-yfti-lastrow:yes;height:20.25pt;"><td data-colwidth="72" width="66" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-image: initial;border-top: none;padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">N/A</span></span></span></p></td><td data-colwidth="72" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">CVE-2025-54558</span></span></span></p></td><td data-colwidth="69" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">XVE-2025-28425</span></span></span></p></td><td data-colwidth="57" width="76" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">Codex CLI</span></span></span></p></td><td data-colwidth="70" width="76" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">2026-01-12</span></span></span></p></td><td data-colwidth="68" width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">Low</span></span></span></p></td><td data-colwidth="67" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">&lt;0.9.0</span></span></span></p></td><td data-colwidth="68" width="57" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 3.6pt 7.8pt;height: 20.25pt;"><p><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 10px;">0.9.0</span></span></span></p></td></tr></tbody></table><p style="text-align: left;line-height: 1.6em;margin: 3pt 0pt;" data-pm-slice="0 0 []"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 15px;letter-spacing: 1px;color: rgb(63, 63, 63);">以上漏洞完整内容均可通过微步漏洞情报查询。</span></span></span></p><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 0px 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(51, 51, 51);text-align: center;background-color: rgb(255, 255, 255);line-height: 1.6;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 17px;line-height: 1.6;"><span textstyle="" style="font-size: 14px;">欢迎扫码联系</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 0px 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(51, 51, 51);text-align: center;background-color: rgb(255, 255, 255);line-height: 1.6;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 17px;line-height: 1.6;"><span textstyle="" style="font-size: 14px;">↓↓↓</span></span></p><p style="text-align: center;line-height: 1.6em;margin: 3pt 0pt;" data-pm-slice="0 0 []"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1" data-w="350" style="width:204px;height:204px;" src="https://wechat2rss.xlab.app/img-proxy/?k=02672132&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FYv6ic9zgr5hQl5bZ5Mx6PTAQg6tGLiciarvXajTdDnQiacxmwJFZ0D3ictBOmuYyRk99bibwZV49wbap77LibGQHdQPtA%2F640%3Fwx_fmt%3Dpng%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1%26tp%3Dwebp%23imgIndex%3D7"/></span></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=7962986e&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg5MTc3ODY4Mw%3D%3D%26mid%3D2247508389%26idx%3D1%26sn%3Da3afdb49432f816d071a103ec98add35">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 24 Mar 2026 16:32:00 +0800</pubDate>
    </item>
  </channel>
</rss>