From 11ccc7dec7c14e2a183ae842f4196edc04da430c Mon Sep 17 00:00:00 2001 From: ubuntu-master <204118693@qq.com> Date: Sun, 28 Sep 2025 00:00:02 +0800 Subject: [PATCH] =?UTF-8?q?=E6=9B=B4=E6=96=B0?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- results/2025-09-27.md | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/results/2025-09-27.md b/results/2025-09-27.md index cb9ef45..4aec52d 100644 --- a/results/2025-09-27.md +++ b/results/2025-09-27.md @@ -3,7 +3,7 @@ > 本文由AI自动生成,基于对安全相关仓库、CVE和最新安全研究成果的自动化分析。 > -> 更新时间:2025-09-27 20:32:38 +> 更新时间:2025-09-27 22:54:14 @@ -26,6 +26,7 @@ * [用友NC changeEvent sql注入漏洞](https://mp.weixin.qq.com/s?__biz=MzkzMTcwMTg1Mg==&mid=2247492874&idx=1&sn=09837b8a01d357546c39558ccccf7352) * [安全圈曝一加氧 OS 12 - 15 系统存严重漏洞,10 月中旬修复](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652071914&idx=2&sn=86d304cc99574054f117c3198c848b5d) * [绕过WAF:追踪源站IP与SQL注入的艺术](https://mp.weixin.qq.com/s?__biz=MzIzMTIzNTM0MA==&mid=2247498320&idx=1&sn=aaac6c6ee63bcbdb412334398f8ded90) +* [java 代码审计 - SpEL 表达式注入](https://mp.weixin.qq.com/s?__biz=MzU5NjYwNDIyOQ==&mid=2247485633&idx=1&sn=8a17503ee380163fdf321dd75f8fc609) ### 🔬 安全研究 @@ -54,6 +55,8 @@ * [WSUS 就是 SUS:NTLM 中继攻击显而易见](https://mp.weixin.qq.com/s?__biz=MzAxMjYyMzkwOA==&mid=2247532907&idx=1&sn=b5663b7500727fc8fcbdfad7a3fc8729) * [安全圈22 岁主谋落网!00 后黑客组建的 DDoS 僵尸网络帝国 RapperBot 被彻底取缔](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652071914&idx=3&sn=d4225f84fddd6c697df15393310f4425) * [iframe安全盲区:支付信息窃取攻击的新温床](https://mp.weixin.qq.com/s?__biz=MzU2NDY2OTU4Nw==&mid=2247524011&idx=1&sn=427809fea64c780ef256c7722d09ee5b) +* [黑客必须熟练的系统操作?!看完小白直升大佬 Linux篇](https://mp.weixin.qq.com/s?__biz=MzYyNDYwOTIwMA==&mid=2247483712&idx=1&sn=543ea2c1f447f6e11185560faa0f92e2) +* [英国逮捕了参与网络攻击伦敦交通局的青少年黑客](https://mp.weixin.qq.com/s?__biz=Mzg3ODY0NTczMA==&mid=2247493622&idx=1&sn=95ec50421bbd886d89a58b45eca395a5) ### 🛠️ 安全工具 @@ -189,6 +192,9 @@ * [中央计算平台集成与OTA合规实战培训课程 2025](https://mp.weixin.qq.com/s?__biz=MzU2MDk1Nzg2MQ==&mid=2247627607&idx=2&sn=aa2082ae1bac92125ad629e687613cf6) * [安全圈XCSSET 新变种:专攻苹果 Mac 开发者,窃取加密货币钱包!](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652071914&idx=1&sn=d353548f324e5cf7a32afe5fc67542eb) * [定!好!闹!钟!](https://mp.weixin.qq.com/s?__biz=MzkzNzY3ODk4MQ==&mid=2247484443&idx=1&sn=10b2afa5025bfc3ecd18b4319f2fb230) +* [CTF简介](https://mp.weixin.qq.com/s?__biz=MzAwNTUzNjE3OQ==&mid=2649559874&idx=1&sn=7a5f579a088ec02e4e027de008da3ce5) +* [C++、Python、Java,第一次入门编程选择哪个更好?](https://mp.weixin.qq.com/s?__biz=MzkwODM4NDM5OA==&mid=2247520211&idx=1&sn=960fca44a91d0564b06a8594b18bdb81) +* [备赛17届蓝桥杯历年真题及题解 - 交互](https://mp.weixin.qq.com/s?__biz=MzkwODM4NDM5OA==&mid=2247520211&idx=2&sn=8b000f84261f6454117c34fa1965281b) ## 安全分析 (2025-09-27)