diff --git a/results/2025-09-07.md b/results/2025-09-07.md index f09c401..ffeda63 100644 --- a/results/2025-09-07.md +++ b/results/2025-09-07.md @@ -3,7 +3,7 @@ > 本文由AI自动生成,基于对安全相关仓库、CVE和最新安全研究成果的自动化分析。 > -> 更新时间:2025-09-07 07:12:48 +> 更新时间:2025-09-07 11:40:01 @@ -12,14 +12,43 @@ ### 🔍 漏洞分析 * [突发!TP-Link路由器曝高危漏洞,多型号受影响](https://mp.weixin.qq.com/s?__biz=MzU2MjU2MzI3MA==&mid=2247484864&idx=1&sn=f93f29746fdbc3b84f15845dc55a5233) +* [已复现百度网盘Windows客户端存在远程命令执行漏洞](https://mp.weixin.qq.com/s?__biz=MzkwMTQyODI4Ng==&mid=2247497403&idx=3&sn=f59c47882972ca85f7c5a284784303e1) +* [Facebook 服务器上的远程代码执行](https://mp.weixin.qq.com/s?__biz=Mzg4NjY3OTQ3NA==&mid=2247487101&idx=1&sn=eee3fcb277c3acf137f88490aa62bfee) +* [Java安全保姆级shiro+spring环境分析并复现spring内存马注入](https://mp.weixin.qq.com/s?__biz=MzI5NDg0ODkwMQ==&mid=2247486560&idx=1&sn=6e82030682f9901d5c4e1ba6f768d4c1) +* [80个反序列化漏洞全景合集 3 | 介绍一个 ViewState 反序列化不常见的知识点](https://mp.weixin.qq.com/s?__biz=MzUyOTc3NTQ5MA==&mid=2247500532&idx=3&sn=a0a2ce8105d376db27a6dd3efd2953e9) +* [高危漏洞预警百度网盘Windows客户端远程命令执行漏洞](https://mp.weixin.qq.com/s?__biz=MzAxMjE3ODU3MQ==&mid=2650612194&idx=4&sn=e50df095af129b8762275e0d0b95ba34) +* [通过分析前端js引发的SQL注入fuzz绕过代码层面和waf层面的双重防御](https://mp.weixin.qq.com/s?__biz=Mzk0Mzc1MTI2Nw==&mid=2247496491&idx=1&sn=c20bd5f9702629102e64a8921529befc) + +### 🔬 安全研究 + +* [cobalt strike流量分析进阶](https://mp.weixin.qq.com/s?__biz=Mzg3NTU3NTY0Nw==&mid=2247490090&idx=1&sn=297840d0cdb84cc8d56ce85edb6c8134) +* [AI 技术应用中的违法犯罪风险及防范指南(第二期)](https://mp.weixin.qq.com/s?__biz=MzkzNjkxOTEzNw==&mid=2247485079&idx=1&sn=4a1e42a6e3e661a31abf2b93e6ed1236) +* [基于AI生命周期的个人信息保护风险研究综述](https://mp.weixin.qq.com/s?__biz=MzIxODM0NDU4MQ==&mid=2247507585&idx=1&sn=a0ca6a2b9c01457d215dfb8d8a9a1372) +* [美国技术壁垒战略对我国科技发展的影响与对策](https://mp.weixin.qq.com/s?__biz=MzkxNjU2NjY5MQ==&mid=2247516432&idx=1&sn=30fa22fdf3a827ffc3b3939c0482eea7) ### 🎯 威胁情报 * [APT攻击演进新态势:从隐蔽渗透到持久化驻留的完整防御体系](https://mp.weixin.qq.com/s?__biz=Mzg4NDc0Njk1MQ==&mid=2247487467&idx=1&sn=c57d85cce61391caa4035c249af23258) +* [前14篇免费ISO/IEC 27701: 2019 标准详解与实施(93)6.9.2.1 恶意软件的控制](https://mp.weixin.qq.com/s?__biz=MzA5OTEyNzc1Nw==&mid=2247486710&idx=2&sn=359259daa131d42f6ab7510695f910ac) +* [网络安全进入“AI攻防时代”:FireCompass融资2000万美元,能像黑客一样思考](https://mp.weixin.qq.com/s?__biz=MzI3NzM5NDA0NA==&mid=2247491971&idx=1&sn=656fe2f1c71b20cf93d7c5c03269d9b7) + +### 🛠️ 安全工具 + +* [前14篇免费ISO/IEC 27701: 2019 标准详解与实施(92)6.9.1.4 开发、测试和运行环境的分离](https://mp.weixin.qq.com/s?__biz=MzA5OTEyNzc1Nw==&mid=2247486710&idx=3&sn=e00c6ed98b4a500ba23f6576bc92d7fd) +* [多线程端口扫描工具PortScanner](https://mp.weixin.qq.com/s?__biz=MzIxOTM2MDYwNg==&mid=2247518109&idx=1&sn=4103abd33057400d35c0f427b6b49292) +* [.NET 2025 年第 88 期实战工具库和资源汇总](https://mp.weixin.qq.com/s?__biz=MzUyOTc3NTQ5MA==&mid=2247500532&idx=1&sn=2cd992b969ce1d9f3f4632d1fc587794) +* [Windows权威工具集-sysinternals suite部署](https://mp.weixin.qq.com/s?__biz=MzAxMjE3ODU3MQ==&mid=2650612194&idx=3&sn=12f206cb14268959ae8e902007e85f21) ### 📚 最佳实践 * [OSEP 考试复习与准备指南 2025](https://mp.weixin.qq.com/s?__biz=MzU4MjUxNjQ1Ng==&mid=2247524944&idx=1&sn=70f1385083c2819415fde7c7ab5b6397) +* [百元企业AP秒变千兆路由!手撕Web配置,解锁PPPoE/NAT隐藏技能](https://mp.weixin.qq.com/s?__biz=MzI4NjAzMTk3MA==&mid=2458861371&idx=1&sn=f36e55df9d3d59da4755c14ee8d50ba3) + +### 🍉 吃瓜新闻 + +* [行业资讯:安博通股东和实际控制人钟竹先生转让公司5.60%给一三一白龙马3号私募证券投资基金,转让价格为3.0988亿](https://mp.weixin.qq.com/s?__biz=MzUzNjkxODE5MA==&mid=2247493661&idx=1&sn=9e2c4db62690cc8f38649462c40f7c1e) +* [全球三大网络安全巨头同时被黑](https://mp.weixin.qq.com/s?__biz=MzkwMTQyODI4Ng==&mid=2247497403&idx=2&sn=0d112006b8190c29e251f92e693be249) +* [中小企业的网络安全正接近崩溃临界点](https://mp.weixin.qq.com/s?__biz=MzAxMjE3ODU3MQ==&mid=2650612194&idx=2&sn=7420e3a5fc79bece6b55f01bed929b7d) ### 📌 其他 @@ -27,6 +56,36 @@ * [牟林:东风浩荡,威震寰宇、覆盖全球、以武止戈](https://mp.weixin.qq.com/s?__biz=MzA5MDg1MDUyMA==&mid=2650481224&idx=2&sn=27e2b083b8339fdbc2802e4f7a9bfd72) * [凭什么大厂都在抢夺数字身份控制权?真相让人愤怒](https://mp.weixin.qq.com/s?__biz=MzI1NjQxMzIzMw==&mid=2247498079&idx=1&sn=22104e3bbef512f5fec463833e07505c) * [美陆军无人装备体系大揭秘:无人作战的战略转型与挑战(3.2万字干货)](https://mp.weixin.qq.com/s?__biz=MzkyMjY1MTg1MQ==&mid=2247495859&idx=1&sn=943a2e202947f28eda17a15ef91224dd) +* [每周网安态势概览20250907034期](https://mp.weixin.qq.com/s?__biz=MzkyMjQ5ODk5OA==&mid=2247513615&idx=1&sn=0f44eb1a503b8cc4d3171cb04ffbc885) +* [暗网对决:XSS论坛与DamageLib论坛的前世今生](https://mp.weixin.qq.com/s?__biz=MzkyMjQ5ODk5OA==&mid=2247513615&idx=2&sn=7956cc716b95a0444b997e803df9fa64) +* [你的服务器,可能正在背地里为“博彩网站”打工!一个新型IIS恶意模块的“骚操作”大赏。](https://mp.weixin.qq.com/s?__biz=MzA4NTY4MjAyMQ==&mid=2447901304&idx=1&sn=17153b5f376b71145e68b88fdb56242a) +* [白露 | 白露至 秋意浓](https://mp.weixin.qq.com/s?__biz=MjM5NzE0NTIxMg==&mid=2651136190&idx=1&sn=9f747e6d5fe14f4cc08ec8686b22104a) +* [涉案上亿元!抓获72人!东营公安揭开特大电诈洗钱案的隐秘面纱](https://mp.weixin.qq.com/s?__biz=MzIxOTM2MDYwNg==&mid=2247517886&idx=1&sn=72100feb7070dba1e0ca0ffe6690dfc9) +* [重庆三峡学院85万元采购设备网购仅299元,官方通报:分管副院长等多人被立案调查,中标单位被顶格罚款](https://mp.weixin.qq.com/s?__biz=Mzk0ODY1NzEwMA==&mid=2247492816&idx=1&sn=a7d33df3882eadfab5977bcb6fde3371) +* [月薪2万+的网络工程师,到底藏着哪些“绝活”?](https://mp.weixin.qq.com/s?__biz=MzUyNTExOTY1Nw==&mid=2247531677&idx=1&sn=a4b674eeaf06f78c293383031f0f7f7b) +* [2026合作伙伴巡礼奇安盘古-奇安信旗下业务安全领域解决方案领航者](https://mp.weixin.qq.com/s?__biz=MzAwMTMzMDUwNg==&mid=2650889720&idx=1&sn=5962c3252786e4d567650fcb5a3af648) +* [154W!真心建议师傅们冲一冲工资高、前景好的新方向!](https://mp.weixin.qq.com/s?__biz=MzAwMjA5OTY5Ng==&mid=2247527192&idx=1&sn=36d9f91f0ad825369a2213c12da08432) +* [今日白露|露从今夜白,秋意渐盈怀](https://mp.weixin.qq.com/s?__biz=MzAxMDE4MTAzMQ==&mid=2661302611&idx=1&sn=c078988f8ad973a044f77783290a359e) +* [收藏!12个政府采购违规典型案例(附解析)](https://mp.weixin.qq.com/s?__biz=MzkzNjkxOTEzNw==&mid=2247485093&idx=1&sn=8f9ebf1a309719ddb4cd7963aff157b6) +* [前14篇免费ISO/IEC 27701: 2019 标准详解与实施(94)6.9.3.1 信息备份](https://mp.weixin.qq.com/s?__biz=MzA5OTEyNzc1Nw==&mid=2247486710&idx=1&sn=9d309350f10e843dca0a8aa6b0b83e0b) +* [数字战场,网络长城 | 两支部队首次亮相阅兵场,引领国家网络安全人才培养新高度](https://mp.weixin.qq.com/s?__biz=MzkwMTQyODI4Ng==&mid=2247497403&idx=1&sn=86269b31c16e3ee64fda340ee3771ed3) +* [网络工程师们,你们是怎么走上这条路的?误打误撞吗?](https://mp.weixin.qq.com/s?__biz=MzUyNTExOTY1Nw==&mid=2247531671&idx=1&sn=d1098fa8d1026e8c02977fc59a11c489) +* [安全行业的同学要不要学编程?](https://mp.weixin.qq.com/s?__biz=MzU5NzQ3NzIwMA==&mid=2247487047&idx=1&sn=e84802952aadc0b004591ba0059c9253) +* [NSMP SIEM SOAR SAS 傻傻分不清](https://mp.weixin.qq.com/s?__biz=MzI4NzA1Nzg5OA==&mid=2247486089&idx=1&sn=0a2aa123128d601e71976093402f8d37) +* [低空标准大全558项国家、 行业、 团体相关重点标准汇总](https://mp.weixin.qq.com/s?__biz=Mzg4MDU0NTQ4Mw==&mid=2247533345&idx=1&sn=25b277f095fdf192dede8e95644efa24) +* [网安原创文章推荐2025/9/6](https://mp.weixin.qq.com/s?__biz=MzAxNzg3NzMyNQ==&mid=2247490384&idx=1&sn=602b50b37c90b33b3f77666853b4d35f) +* [EPP应对免杀后的CS后门](https://mp.weixin.qq.com/s?__biz=MzIzMTMxMTcxOA==&mid=2247485016&idx=1&sn=1ac8ea5cdab4c33d916f98e8a4b5818a) +* [记一次安服薅洞实战](https://mp.weixin.qq.com/s?__biz=MzIwMzIyMjYzNA==&mid=2247519522&idx=1&sn=5da012ee4494c7e46a0fa65138fa6c35) +* [大学生网络安全必看导论](https://mp.weixin.qq.com/s?__biz=Mzg4MDg5NzAxMQ==&mid=2247486088&idx=1&sn=89486813a3a6802acb6435ce7368cbda) +* [手术中,请假一周](https://mp.weixin.qq.com/s?__biz=MzkyNzM2MjM0OQ==&mid=2247498631&idx=1&sn=6809425d4351b5990a652f545596de9a) +* [白露|草木凝霜 秋意渐浓](https://mp.weixin.qq.com/s?__biz=MzIxNDIzNTcxMg==&mid=2247509080&idx=1&sn=23391acc85956211974dd4f82ccb450e) +* [实战从SSRF到任意文件下载再到远程文件下载](https://mp.weixin.qq.com/s?__biz=MzU0MTc2NTExNg==&mid=2247492864&idx=1&sn=62a226c7ba682172f8a830fa4fe48df6) +* [二十四节气:今日白露](https://mp.weixin.qq.com/s?__biz=MzA4MTE0MTEwNQ==&mid=2668670661&idx=1&sn=21fec416f28dfa8a3e039ec972394215) +* [.NET 内网攻防实战电子报刊](https://mp.weixin.qq.com/s?__biz=MzUyOTc3NTQ5MA==&mid=2247500532&idx=2&sn=a2b464fd42a6d812089636eb7f91de29) +* [信创笔记本电脑使用初体验](https://mp.weixin.qq.com/s?__biz=MzU3MDEwMjk2MQ==&mid=2247485219&idx=1&sn=835183bf18e7319ea6071c9e659f10dc) +* [打官司拿不到钱?教你快速锁定老赖财产,人肉搜索:挖出藏匿的、房、车、钱、人在那、及所有的信息](https://mp.weixin.qq.com/s?__biz=MzIxOTM2MDYwNg==&mid=2247517887&idx=1&sn=bc5cfd36c2525b13c4f82b2702503339) +* [清秋满白露 美好意蕴长](https://mp.weixin.qq.com/s?__biz=MzUyMjI2MzkzMQ==&mid=2247488097&idx=1&sn=04a647639f320ce0a2340536702c1598) +* [实战派分享|AI安全第六期 9月11日 大模型安全治理与个人隐私保护](https://mp.weixin.qq.com/s?__biz=MzkxNjU2NjY5MQ==&mid=2247516432&idx=2&sn=41ac5b8606f08caf45a613b6701fd426) ## 安全分析 (2025-09-07)