This commit is contained in:
ubuntu-master 2025-10-30 00:00:03 +08:00
parent 88d996ccf5
commit d4e82ad31c

View File

@ -3,7 +3,7 @@
> 本文由AI自动生成基于对安全相关仓库、CVE和最新安全研究成果的自动化分析。
>
> 更新时间2025-10-29 20:10:14
> 更新时间2025-10-29 22:35:43
<!-- more -->
@ -62,6 +62,9 @@
* [新型零点击攻击通过主流AI Agent利用MCP静默窃取数据](https://mp.weixin.qq.com/s?__biz=MjM5NjA0NjgyMA==&mid=2651329485&idx=4&sn=c68a73ca73921e25841452d06dd19084)
* [CNNVD | 关于Apache Tomcat安全漏洞的通报](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664252075&idx=2&sn=285e1a4e4530f91da43311cc324d4f96)
* [漏洞通告 | Apachexa0Tomcatxa0目录遍历漏洞](https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&mid=2247507949&idx=1&sn=1dcdbdc965a48087e4c44fb75d17da35)
* [案例Google Cloud SSRF 漏洞](https://mp.weixin.qq.com/s?__biz=Mzg2Mzg2NDM0NA==&mid=2247485495&idx=1&sn=14c17432a1a9e269c519a08b8cda0562)
* [想靠挖SRC漏洞赚钱先想清楚这几个问题](https://mp.weixin.qq.com/s?__biz=MzkxNTY3MTE5MA==&mid=2247485578&idx=1&sn=32db29e4c455e418527ae0b88f84a8e8)
* [CVE-2025-62725 Docker Compose OCI 工件路径遍历](https://mp.weixin.qq.com/s?__biz=MzAxMjYyMzkwOA==&mid=2247533334&idx=1&sn=4e5683ce6127d0e21411e716c85de9ca)
### 🔬 安全研究
@ -75,6 +78,7 @@
* [专题·网络靶场 | 美国网络靶场发展演进过程和趋势特点分析](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664252075&idx=1&sn=de62763587bac8b712278231d8998199)
* [AI辅助逆向APP白盒AES分析](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458602868&idx=1&sn=8a9a6507a73d998e0ebb6f0a5f787fa0)
* [数据安全丨92%的AI数据安全和隐私研究搞错方向](https://mp.weixin.qq.com/s?__biz=MzI2MDk2NDA0OA==&mid=2247535401&idx=2&sn=cefc4821e2f57cba57bbb162c3288b1f)
* [Gartner预测将重塑2026年的关键技术趋势](https://mp.weixin.qq.com/s?__biz=Mzk4ODI4MDEzNQ==&mid=2247483971&idx=1&sn=f3f4be0766b6de8e4ab3c70fc5a89dbc)
### 🎯 威胁情报
@ -106,6 +110,7 @@
* [安全圈新型Android银行木马“GhostGrab”静默窃取登录凭证并拦截短信OTP](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652072467&idx=3&sn=562c565cac54ccdbfe72f4cd788093ff)
* [公司为什么能监控你的HTTPS上网内容白帽黑客带你拆解背后的技术逻辑](https://mp.weixin.qq.com/s?__biz=MzkwMjc0NDk0NQ==&mid=2247487571&idx=1&sn=45a1ea877636231d14c88f4081e99cd4)
* [不懂英语能不能学会黑客技术?十年白帽经验告诉你答案!](https://mp.weixin.qq.com/s?__biz=MzkwMjc0NDk0NQ==&mid=2247487571&idx=2&sn=fe6cae9cd83b6a632d76d912184dd2c2)
* [威胁情报异地登录账号的可疑IP](https://mp.weixin.qq.com/s?__biz=Mzg2MjgwMzIxMA==&mid=2247485747&idx=1&sn=41a0a77b2b01534f8d508ea6fa8cda8d)
### 🛠️ 安全工具
@ -124,6 +129,7 @@
* [珍藏版渗透测试手册,简直太赞了!](https://mp.weixin.qq.com/s?__biz=MzkxMzMyNzMyMA==&mid=2247575458&idx=2&sn=8fdd4397d24a8344fc15211065facb92)
* [京东实战案例LLM 如何重塑安全运营与渗透测试CAIDCP 带你看 AI 驱动安全新范式](https://mp.weixin.qq.com/s?__biz=MzkwMTM5MDUxMA==&mid=2247508179&idx=1&sn=06235158d71b57c68965a61a257f5f88)
* [Palo Alto推出首个安全代理平台押注Agentic AI赋能安全自动化](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247515141&idx=1&sn=4813ff990fcdf0efc6af1c1288be2e2b)
* [MS08067顺利交付中国人民解放军某部队C#代码审计培训课程高质量精品实战版](https://mp.weixin.qq.com/s?__biz=MzU1NjgzOTAyMg==&mid=2247524827&idx=1&sn=00b6ce95057e5ab4502092ddffd5e6f1)
### 📚 最佳实践
@ -179,6 +185,11 @@
* [Everest勒索团伙发起连环攻击泄露AT&T数据并索要巨额赎金](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458602868&idx=3&sn=b7122d5054548a62a1c00bf94653eb8d)
* [渊亭科技入选“2025政务大数据企业TOP30”](https://mp.weixin.qq.com/s?__biz=MzIzNjE1ODE2OA==&mid=2660192732&idx=1&sn=ad88e9de60ce45aecfff4cba9bd5559f)
* [金融业数据分级实操:从央行检查案例反推标准](https://mp.weixin.qq.com/s?__biz=MzI0NjAyMjU4MA==&mid=2649597698&idx=1&sn=c6d8bdf79a072f611fb646cf075837da)
* [企业首获“碳中和”认证北京朝阳奖励5万元 ,赛迪认证提供专业服务助企业达标](https://mp.weixin.qq.com/s?__biz=MjM5NzYwNDU0Mg==&mid=2649255596&idx=1&sn=4249001f5d817744cfa47fe4777b9b95)
* [数字政府优秀案例联播长沙市:公共数据授权运营平台助力数字经济高质量发展](https://mp.weixin.qq.com/s?__biz=MjM5NzYwNDU0Mg==&mid=2649255596&idx=2&sn=08a43b37916d4e36c56d9e825bc49eae)
* [关于开展优质数据源征集活动的通知](https://mp.weixin.qq.com/s?__biz=MjM5NzYwNDU0Mg==&mid=2649255596&idx=3&sn=628f3f4c6cc33c3f416854820bd3ef23)
* [圆满落幕∣一汽奔腾-汽车网络数据安全日在长春成功举办](https://mp.weixin.qq.com/s?__biz=MzIzOTc2OTAxMg==&mid=2247561775&idx=1&sn=948a9e7f8d4fbed363c6a6a5479cd39e)
* [少年,给个机会,了解下电子数据取证,合法又有趣(不喜欢的话明天我再来推荐别的)](https://mp.weixin.qq.com/s?__biz=MzE5ODQ0ODQ3NA==&mid=2247483916&idx=1&sn=35bda4566fe2dd908f86425f2e77c309)
### 📌 其他
@ -382,6 +393,20 @@
* [新《网络安全法》表决通过 | 2025版与2016版修订对照全文](https://mp.weixin.qq.com/s?__biz=MjM5NjA2NzY3NA==&mid=2448690931&idx=1&sn=f8b0e4fd2965965062745e6b54d27d05)
* [网安法 2025 深度解读](https://mp.weixin.qq.com/s?__biz=Mzk2NDAzNzI5NQ==&mid=2247484170&idx=1&sn=2ab8c82fe6638489827ef950fb5b7e82)
* [Kali火到娱乐圈了](https://mp.weixin.qq.com/s?__biz=MzkxNTIwNTkyNg==&mid=2247556637&idx=1&sn=00d0f10cd30f882a4c0b6f4c78b88ac4)
* [重磅《网络安全法》八年来首次大修AI正式入法罚则全面升级](https://mp.weixin.qq.com/s?__biz=MzI5NTM4OTQ5Mg==&mid=2247637824&idx=1&sn=ea0d6f16fa24e94a549b632995ff00a4)
* [某集团子域安全缺陷引发的全域沦陷](https://mp.weixin.qq.com/s?__biz=MzU0MTc2NTExNg==&mid=2247493014&idx=1&sn=f988924e18edaca60d775264d9435f53)
* [Azure AD 渗透学习](https://mp.weixin.qq.com/s?__biz=MzA3NTc0MTA1Mg==&mid=2664712587&idx=1&sn=9e76c05b06283dec35bff152d28d782e)
* [Tr0ll2:一张“图骗”shellshck撬开SSH268个A引爆缓冲区溢出风暴](https://mp.weixin.qq.com/s?__biz=Mzk3NTEyMzQzOA==&mid=2247488167&idx=1&sn=24ceff9a29b1a3f6b0d7278ad6097c8e)
* [盘点以虚拟货币为手段的犯罪](https://mp.weixin.qq.com/s?__biz=MzA3Mjc1MTkwOA==&mid=2650562751&idx=1&sn=dca8271eb6d8bde3a20c3d1a4d7d5a7d)
* [女科学家的平凡瞬间](https://mp.weixin.qq.com/s?__biz=MzUzMjQyMDE3Ng==&mid=2247488737&idx=1&sn=fedda3f57c3e4411f085cbd984c0e3cc)
* [别笑“抓包”老土,它是每个安全人最后的底线!](https://mp.weixin.qq.com/s?__biz=MzI5MjY4MTMyMQ==&mid=2247492681&idx=1&sn=df700a2ca6b869c2b5bbcc6528684147)
* [WPNewStar CTF 2025 Week4 之 WEB方向题解](https://mp.weixin.qq.com/s?__biz=Mzk0NDYwOTcxNg==&mid=2247486387&idx=1&sn=07771fc475f8b1ef2a66c2f72e44e774)
* [10 月特惠即将结束!从未折扣过产品、两大系列软件不容错过](https://mp.weixin.qq.com/s?__biz=MzI2MjcwMTgwOQ==&mid=2247492736&idx=1&sn=97eba71886d2ac2ce7d491fd24d07172)
* [\"Evtx Web Analysiser\"实战案例(三)](https://mp.weixin.qq.com/s?__biz=MjM5NDcxMDQzNA==&mid=2247490059&idx=1&sn=3e33163a4e1116b95c26829cd7bc5413)
* [《网络空间安全科学学报》第二届青年编委招募](https://mp.weixin.qq.com/s?__biz=MzI0NjU2NDMwNQ==&mid=2247506035&idx=1&sn=3b9fc774be2825a4e65b225b9f3b3e7c)
* [网络安全法通过!一图读懂,网络安全法到底修改了什么?](https://mp.weixin.qq.com/s?__biz=MzU2NDY2OTU4Nw==&mid=2247524642&idx=1&sn=ac25faf3b04398914c4d3f49eeee72fb)
* [关于重庆第二师范学院2025年网络安全大赛决赛的一则通知](https://mp.weixin.qq.com/s?__biz=MzkxNjcyMTc0NQ==&mid=2247484640&idx=1&sn=9770f9bdc34cd2d893b17e85a02f3c29)
* [cyberstrikelabPT-2](https://mp.weixin.qq.com/s?__biz=MzkzNzg4MTI0NQ==&mid=2247488321&idx=1&sn=e4818595883fd275d98a6c4bb0b43537)
## 安全分析
(2025-10-29)