This commit is contained in:
ubuntu-master 2025-10-02 00:00:02 +08:00
parent de351e2fd1
commit 0343b4ff4e

View File

@ -3,7 +3,7 @@
> 本文由AI自动生成基于对安全相关仓库、CVE和最新安全研究成果的自动化分析。
>
> 更新时间2025-10-01 19:05:35
> 更新时间2025-10-01 23:57:38
<!-- more -->
@ -25,6 +25,12 @@
* [KerberosII-如何攻击Kerberos](https://mp.weixin.qq.com/s?__biz=MzI5NDg0ODkwMQ==&mid=2247486675&idx=1&sn=1959685750074d82b3efc465839abe54)
* [任意文件读取&下载漏洞的全面解析及利用](https://mp.weixin.qq.com/s?__biz=Mzk1NzgzMjkxOQ==&mid=2247485370&idx=1&sn=a703e4d803fa36d58fb22449009117da)
* [盘点Web常见漏洞覆盖80%的渗透场景附PDF](https://mp.weixin.qq.com/s?__biz=MzkxMzMyNzMyMA==&mid=2247575111&idx=2&sn=13003c5c8186ed6e3eb9affc8301b266)
* [CVE-2025-41243Spring Cloud Gateway SpEL表达式注入漏洞POC](https://mp.weixin.qq.com/s?__biz=Mzg2ODcxMjYzMA==&mid=2247486199&idx=1&sn=e6c0fe2687ace7c1360dc26da090a58b)
* [CVE-2025-56383Notepad++ DLL劫持漏洞POC](https://mp.weixin.qq.com/s?__biz=Mzg2ODcxMjYzMA==&mid=2247486199&idx=2&sn=4866cfe9c76924093aabeaac24a93cd3)
* [安全圈新型 Android 银行木马 \"Klopatra\" 利用隐藏的 VNC 控制感染的智能手机](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652071990&idx=3&sn=d6e91ead209debcf30202f32087ecb77)
* [内网安全漏洞有多可怕?一人失误,全公司沦陷](https://mp.weixin.qq.com/s?__biz=Mzg4NDc0Njk1MQ==&mid=2247487600&idx=1&sn=a8a1deae35d37912fdedaba588ed1d35)
* [特斯拉车载通信单元漏洞使攻击者可获取Root权限](https://mp.weixin.qq.com/s?__biz=MjM5NjA0NjgyMA==&mid=2651328330&idx=1&sn=690643e23ada06629662057fec498777)
* [Linux内核6.17正式发布修复高危UAF漏洞](https://mp.weixin.qq.com/s?__biz=MjM5NjA0NjgyMA==&mid=2651328330&idx=3&sn=e83dc08ed6f79d4042f634d8d1041c12)
### 🔬 安全研究
@ -32,6 +38,8 @@
* [CycloneDX全栈软件供应链安全标准与优势分析](https://mp.weixin.qq.com/s?__biz=MzkyMTYyOTQ5NA==&mid=2247487512&idx=1&sn=3ab4a889b0642bfceca4e553e81a31c3)
* [10张动图秒懂经典通信协议原理](https://mp.weixin.qq.com/s?__biz=MzIzOTc2OTAxMg==&mid=2247560472&idx=1&sn=60a5f3d7719c63e8096c5ad620768912)
* [基于OTA场景的电控信息安全研究](https://mp.weixin.qq.com/s?__biz=MzU2MDk1Nzg2MQ==&mid=2247627677&idx=2&sn=f0c72c4ce1173e2b2916712d1a6e44a1)
* [MaldevAcademyLdr.2:采用多种规避技术的 RunPE 实现](https://mp.weixin.qq.com/s?__biz=MzAxMjYyMzkwOA==&mid=2247532950&idx=2&sn=d408a00bc6a9dcac185e793698224368)
* [FlipSwitchLiunx下一种新颖的系统调用Hooking技术](https://mp.weixin.qq.com/s?__biz=MzI2Mjk4NjgxMg==&mid=2247483745&idx=1&sn=b9f83b2bdbea44d100044e8a1937bfdb)
### 🎯 威胁情报
@ -40,6 +48,10 @@
* [白象APT现形记伪装成简历的“核按钮”一旦点开内网瞬间被踩穿三步溯源看幕后巨象如何轰然倒地](https://mp.weixin.qq.com/s?__biz=MzkxNzY5MTg1Ng==&mid=2247492746&idx=1&sn=5299f5f51fdcac40b1b4392bf65ef8fb)
* [探索Ollama 桌面版驱动式攻击](https://mp.weixin.qq.com/s?__biz=MzI4NTcxMjQ1MA==&mid=2247617239&idx=1&sn=83c5fbd654bb41a9394c3172ae8c904b)
* [黑客的“退休邀请函”BBC记者面临诱惑](https://mp.weixin.qq.com/s?__biz=MzkzOTQ5MzY3OQ==&mid=2247484467&idx=1&sn=0c8b34b87cf33a7458774625939d6fa5)
* [某最新高级免杀木马样本分析](https://mp.weixin.qq.com/s?__biz=MzA4ODEyODA3MQ==&mid=2247493502&idx=1&sn=b02a0941d97e79b1f3c8f99f98b53f0b)
* [安全圈黑客伪装成 Google 招聘人员窃取 Gmail 登录信息](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652071990&idx=1&sn=51765583e7718b2788ebdd80a1a77b73)
* [捷豹路虎与朝日啤酒遭遇网络攻击](https://mp.weixin.qq.com/s?__biz=MjM5NjA0NjgyMA==&mid=2651328330&idx=2&sn=78850a6db9b0471646d292a9c49c15ef)
* [NIST发布保护工控系统免受便携式xa0USB设备威胁指南](https://mp.weixin.qq.com/s?__biz=MzI3NzM5NDA0NA==&mid=2247492071&idx=1&sn=86bfc359d119281a8de7cc5d1698d98f)
### 🛠️ 安全工具
@ -65,6 +77,8 @@
* [安全月报| 9 月加密货币安全事件造成 1.16 亿美元损失](https://mp.weixin.qq.com/s?__biz=MzU1OTc2MzE2Mg==&mid=2247489905&idx=1&sn=88b3f47d2580c358868b6ba65f9557da)
* [论坛资讯 | 张谧教授在外滩大会以“大模型安全治理-JADE助力负责任AI”为题展开分享](https://mp.weixin.qq.com/s?__biz=MzU4NzUxOTI0OQ==&mid=2247496049&idx=1&sn=07f7bcc328237f81a929b02ac79941b1)
* [今日政务数据安全处理要求国标实施](https://mp.weixin.qq.com/s?__biz=Mzg2NjY2MTI3Mg==&mid=2247501885&idx=1&sn=66d7bb5071908b61e2883983efcf05e7)
* [安全圈RemoteCOM 被黑:泄露近 14,000名受法院监管人员数据](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652071990&idx=2&sn=e5cce86c3a4ef4f2fdb1c09d775b7ef2)
* [安全圈美国保险平台 ClaimPix 泄露 10.7TB 数据,客户个人信息暴露](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652071990&idx=4&sn=4464ac9c454134213302ab0a4dc44c44)
### 📌 其他
@ -237,6 +251,22 @@
* [橘子洲头感悟初心 砥砺奋进迎国庆](https://mp.weixin.qq.com/s?__biz=MzI0NTkwMDY1MA==&mid=2247484801&idx=1&sn=5ae31efb104889331c675c0c890187b9)
* [基于网络信任实现车联网OTA升级的安全合规策略](https://mp.weixin.qq.com/s?__biz=MzU2MDk1Nzg2MQ==&mid=2247627677&idx=1&sn=1adfcd3f585273ff7d959505d3ec5598)
* [中央计算平台集成与OTA合规实战培训课程 2025](https://mp.weixin.qq.com/s?__biz=MzU2MDk1Nzg2MQ==&mid=2247627677&idx=3&sn=80ffa4519fa69159546cd7c88a237a93)
* [干货许多人都忽略的10大Web安全盲区](https://mp.weixin.qq.com/s?__biz=MzkxMDU5MzY0NQ==&mid=2247485428&idx=1&sn=aae4696785d44cc59d1de728b882b6fa)
* [庆祝祖国76周年](https://mp.weixin.qq.com/s?__biz=MzkyMDcyODYwNw==&mid=2247487431&idx=1&sn=10fe8d74b4a458dee5987ece39137807)
* [身份证最后一位的小心机揭秘Checksum校验的秘密](https://mp.weixin.qq.com/s?__biz=MzI5MjY4MTMyMQ==&mid=2247492502&idx=1&sn=42017a51f1d5e0c0fac6361e6bab9c90)
* [今天起,一批网络安全相关新规开始施行!](https://mp.weixin.qq.com/s?__biz=Mzg4NzQ4MzA4Ng==&mid=2247486131&idx=1&sn=514ab5f649ee957bc48e7be4a43daf16)
* [扇贝打卡3333天](https://mp.weixin.qq.com/s?__biz=MzUzMjQyMDE3Ng==&mid=2247488660&idx=1&sn=747ea1201fb5a1fcc07b373836c161b4)
* [DCOM 横向移动信标对象文件 BOF](https://mp.weixin.qq.com/s?__biz=MzAxMjYyMzkwOA==&mid=2247532950&idx=1&sn=7cc75110396170cb6b033c7c2d1b61f6)
* [一文带你直击路由的核心:静态路由和动态路由的那些事儿](https://mp.weixin.qq.com/s?__biz=MzUyNTExOTY1Nw==&mid=2247531873&idx=1&sn=42a71cc9eb88ec4beac1969f583752fd)
* [了解网络安全知识,这组海报值得收藏](https://mp.weixin.qq.com/s?__biz=MjM5OTk4MDE2MA==&mid=2655292582&idx=1&sn=812385e36539e069b14c3ee16f1d16b2)
* [PPT 大模型安全解决方案](https://mp.weixin.qq.com/s?__biz=MjM5OTk4MDE2MA==&mid=2655292582&idx=2&sn=411090e7cb617e17901811bb680ab525)
* [为什么不在机场帮人带行李](https://mp.weixin.qq.com/s?__biz=MzA5MTYyMDQ0OQ==&mid=2247494111&idx=1&sn=d79b2f758b862ac393eb1efecbab1888)
* [网络通信里的“说话方式”:单工、半双工和全双工到底有啥区别?](https://mp.weixin.qq.com/s?__biz=MzIyMzIwNzAxMQ==&mid=2649470999&idx=1&sn=a06b57a8a3ada37d5cd377869e147d4b)
* [反向代理是什么ZeroNews 如何帮你实现安全内网穿透](https://mp.weixin.qq.com/s?__biz=Mzg2NTkwODU3Ng==&mid=2247515434&idx=1&sn=453d23a255ee52fa84125faf248e5002)
* [由敏感参数到反序列化命令执行的src挖掘记录](https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&mid=2247498341&idx=1&sn=7f56c5286e8f4ec43df3c9e797a279b5)
* [通过直接刷题逆向学习pwnciscn_2019_n_1 - 浮点数溢出与IEEE 754编码实战](https://mp.weixin.qq.com/s?__biz=MzE5MTEzNzcwNg==&mid=2247483868&idx=1&sn=7c39babb5fca091a7a675c8133c554df)
* [揭秘可靠的赚钱游戏:是馅饼还是陷阱?](https://mp.weixin.qq.com/s?__biz=MzIzMzI1Njg3Mw==&mid=2651930174&idx=1&sn=eb93809050ba10330eb48a9dcc281823)
* [Sora2 震撼首秀AI安全工坊献上国庆赛博朋克网络安全视觉献礼](https://mp.weixin.qq.com/s?__biz=Mzg5MDQyMzg3NQ==&mid=2247485047&idx=1&sn=08e0aed309bea64ba93be3ffd0e1b6dc)
## 安全分析
(2025-10-01)