Category

資安雷達

CVE、Supply Chain、重大資安事件

資安雷達

2026-08-10 — Apache Ranger 同批爆三起 RCE、dcrypt 密碼庫 GCM nonce 與 Ed25519 偽造弱點、Perl 正規表示式越界讀寫

primary=https://www.openwall.com/lists/oss-security/2026/08/09/7 primary=https://www.openwall.com/lists/oss-security/2026/08/09/6 primary=https://www.openwall.com/lists/oss-security/2026/08/09/5 primary=https://www.openwall.com/lists/oss-security/2026/08/09/2 primary=https://www.openwall.com/lists/oss-security/2026/08/09/3 primary=https://www.openwall.com/lists/oss-security/2026/08/09/4 primary=https://www.openwall.com/lists/oss-security/2026/08/09/8 primary=https://www.openwall.com/lists/oss-security/2026/08/09/9 primary=https://www.openwall.com/lists/oss-security/2026/08/09/10 primary=https://www.openwall.com/lists/oss-security/2026/08/09/11 primary=https://rustsec.org/advisories/RUSTSEC-2026-0238.html primary=https://rustsec.org/advisories/RUSTSEC-2026-0240.html primary=https://rustsec.org/advisories/RUSTSEC-2026-0239.html primary=https://rustsec.org/advisories/RUSTSEC-2026-0242.html primary=https://rustsec.org/advisories/RUSTSEC-2026-0237.html primary=https://rustsec.org/advisories/RUSTSEC-2026-0241.html primary=https://rustsec.org/advisories/RUSTSEC-2026-0243.html primary=https://rustsec.org/advisories/RUSTSEC-2026-0244.html primary=https://www.openwall.com/lists/oss-security/2026/08/09/12

2 min Read →
資安雷達

2026-08-08 — GitPython 六洞齊發、Apache Fory 三記憶體安全漏洞、CodeIgniter4 Query Builder SQL 注入等協同揭露解析

primary=https://github.com/advisories/GHSA-jm78-9fvv-mhgr primary=https://github.com/advisories/GHSA-wvpp-8hx9-p66j primary=https://github.com/advisories/GHSA-hmq2-w58f-27jc primary=https://github.com/advisories/GHSA-4gmw-gg2m-w46p primary=https://github.com/advisories/GHSA-9rj7-rf2p-w77r primary=https://github.com/advisories/GHSA-hh9p-6wh2-4mfc primary=https://www.openwall.com/lists/oss-security/2026/08/07/3 primary=https://www.openwall.com/lists/oss-security/2026/08/07/4 primary=https://www.openwall.com/lists/oss-security/2026/08/07/5 primary=https://github.com/advisories/GHSA-c9w5-rwh3-7pm9 primary=https://github.com/advisories/GHSA-mmj4-63m4-r6h5 primary=https://github.com/advisories/GHSA-hhmc-q9hp-r662 primary=https://github.com/advisories/GHSA-7wmf-pw8j-mc78

3 min Read →
資安雷達

2026-08-06 — rclone 一次揭露 14 個漏洞、Nuxt 修補 7 項含兩起 RCE、Atlassian Rovo 被爆料可遭提示注入外洩資料

primary=https://github.com/advisories/GHSA-2m8m-jhrm-w6j2 primary=https://github.com/advisories/GHSA-fqj9-69pf-6pjg primary=https://github.com/advisories/GHSA-7p4m-qxvv-g567 primary=https://github.com/advisories/GHSA-4vr5-p2gc-h23p primary=https://github.com/advisories/GHSA-gx4c-2hqx-cw2r primary=https://github.com/advisories/GHSA-279x-mwfv-vcqv primary=https://github.com/advisories/GHSA-9473-5f9j-94wq primary=https://github.com/advisories/GHSA-9pgf-384g-p7mv primary=https://github.com/advisories/GHSA-wm8w-6qjm-cv43 primary=https://github.com/advisories/GHSA-hxvh-4h3w-prp9 primary=https://github.com/advisories/GHSA-48hr-524c-v5w3 primary=https://github.com/advisories/GHSA-hxcr-hm88-mpq6 primary=https://www.promptarmor.com/resources/atlassian-rovo-exfiltrates-data

1 min Read →
資安雷達

2026-08-05 — LLM代理試圖入侵GitHub專案、Open WebUI單日11個漏洞公告、Bouncy Castle一次修32個CVE

primary=https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing primary=https://lwn.net/Articles/1087162/ primary=https://github.com/advisories/GHSA-8x5v-cpv7-8jjp primary=https://github.com/advisories/GHSA-3xpf-xq7r-v8c5 primary=https://github.com/advisories/GHSA-jxc9-xmc4-gr23 primary=https://oss-security.openwall.org/2026/08/04/2 primary=https://www.bouncycastle.org/resources/new-release-bouncy-castle-java-1-85/

1 min Read →
資安雷達

2026-08-04 — python-cryptography 的 Bleichenbacher oracle、Apache NiFi 四則 Parameter Context 授權破口、undici 重試攔截器回應失步同日齊發

primary=https://github.com/advisories/GHSA-m2h6-j472-rp4c primary=https://github.com/advisories/GHSA-jwv3-5hgf-82ww primary=https://github.com/advisories/GHSA-g6cj-pr64-35w5 primary=https://www.openwall.com/lists/oss-security/2026/08/03/13 primary=https://www.openwall.com/lists/oss-security/2026/08/03/12 primary=https://www.openwall.com/lists/oss-security/2026/08/03/11 primary=https://www.openwall.com/lists/oss-security/2026/08/03/10 primary=https://github.com/advisories/GHSA-m8rv-5g2x-5cg5 primary=https://github.com/advisories/GHSA-jr45-8vmc-qm54 primary=https://github.com/advisories/GHSA-v3r7-h72x-cjcm primary=https://github.com/advisories/GHSA-8xcm-r25x-g524 primary=https://github.com/advisories/GHSA-4cwx-7wf7-3272

3 min Read →
資安雷達

2026-08-03 — Nostr 生態系一日 8 份 RustSec 公告、iwd 802.11k 堆疊溢位待修、GNOME 揭露期砍到 30 天

primary=https://rustsec.org/advisories/RUSTSEC-2026-0225.html primary=https://rustsec.org/advisories/RUSTSEC-2026-0226.html primary=https://rustsec.org/advisories/RUSTSEC-2026-0227.html primary=https://rustsec.org/advisories/RUSTSEC-2026-0228.html primary=https://rustsec.org/advisories/RUSTSEC-2026-0229.html primary=https://rustsec.org/advisories/RUSTSEC-2026-0230.html primary=https://rustsec.org/advisories/RUSTSEC-2026-0231.html primary=https://rustsec.org/advisories/RUSTSEC-2026-0232.html primary=https://www.openwall.com/lists/oss-security/2026/08/02/2 primary=https://www.openwall.com/lists/oss-security/2026/08/02/3

2 min Read →
資安雷達

2026-08-02 — Rails Active Storage 現 9.5 分嚴重漏洞 CVE-2026-66066、蘋果螢幕分享驗證判斷寫反可預先認證入侵、TruffleHog 掃 7.6PB 訓練資料揪出 22 萬組活躍憑證

primary=https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm primary=https://oss-security.openwall.org/mailing-lists/oss-security/2026/08/01/6 primary=https://warez.sl0p.foo/apple-screensharing-rce/ primary=https://support.apple.com/en-us/128067 primary=https://trufflesecurity.com/blog/scanning-7-6-petabytes-of-ai-training-data-for-secrets

1 min Read →