Category

資安雷達

CVE、Supply Chain、重大資安事件

資安雷達

2026-08-26 — MCP 工具鏈同日爆七起資安公告、gRPC Erlang 修四包含危急 RCE、AshAuthentication OAuth 帳戶接管

primary=https://github.com/advisories/GHSA-hvfh-5mj3-5f3j primary=https://github.com/advisories/GHSA-w3fx-mc44-mf6j primary=https://github.com/advisories/GHSA-72f3-6w86-7rv3 primary=https://github.com/advisories/GHSA-fh3r-g96v-f578 primary=https://github.com/advisories/GHSA-xc9g-j69q-37xw primary=https://github.com/advisories/GHSA-cmwv-wf9p-p8wx primary=https://github.com/advisories/GHSA-vwf3-4xxj-qg6h primary=https://github.com/advisories/GHSA-6ccx-9c9f-327w primary=https://github.com/advisories/GHSA-q8gf-9rvj-gmgj primary=https://github.com/advisories/GHSA-mwr4-5g34-j5cq primary=https://github.com/advisories/GHSA-grp7-v8xh-rj7h primary=https://github.com/advisories/GHSA-777c-2fxx-qr28

2 min Read →
資安雷達

2026-08-25 — Apache Camel 七連發 CVE、rust-postgres 生態圈 panic DoS、LLM 推論引擎主機控制風險三則資安動態

primary=https://www.openwall.com/lists/oss-security/2026/08/24/9 primary=https://www.openwall.com/lists/oss-security/2026/08/24/14 primary=https://www.openwall.com/lists/oss-security/2026/08/24/13 primary=https://www.openwall.com/lists/oss-security/2026/08/24/12 primary=https://www.openwall.com/lists/oss-security/2026/08/24/11 primary=https://www.openwall.com/lists/oss-security/2026/08/24/10 primary=https://www.openwall.com/lists/oss-security/2026/08/24/8 primary=https://github.com/advisories/GHSA-3gjw-f78c-vvpw primary=https://github.com/advisories/GHSA-rgqc-3x5p-6gwg primary=https://github.com/advisories/GHSA-5x78-73v4-xg6w primary=https://boydkane.com/essays/llms-could-control-their-host-machines-by-exploiting-inference-engines primary=https://news.ycombinator.com/item?id=49424387 primary=https://github.com/vllm-project/vllm/security/advisories/GHSA-79j6-g2m3-jgfw

2 min Read →
資安雷達

2026-08-24 — gzip 全域陣列溢位、Kata Containers 主機端提權、DBD::Pg 堆積溢位三則 CVE 解析

primary=https://github.com/advisories/GHSA-qxh4-rprf-2mmj primary=https://github.com/kata-containers/kata-containers/security/advisories/GHSA-mp2j-xm59-qfgw primary=https://nvd.nist.gov/vuln/detail/CVE-2026-50540 primary=https://github.com/kata-containers/kata-containers/commit/03cc670076099530f4e1e9cb22849afdafb20f65 primary=https://github.com/bucardo/dbdpg/commit/6d6f47ed2403cda55c82b1bad56e388ba7390065 primary=https://metacpan.org/release/TURNSTEP/DBD-Pg-3.21.1/source/Changes

2 min Read →
資安雷達

2026-08-20 — SearXNG MCP、Moby BuildKit 與 Ceph 同日修補多起高風險漏洞

primary=https://github.com/advisories/GHSA-q87f-qc2r-2gw4 primary=https://github.com/advisories/GHSA-wppf-h75h-6pm6 primary=https://github.com/advisories/GHSA-hjwh-xvfw-qrwj primary=https://github.com/advisories/GHSA-72x6-4j93-7w86 primary=https://github.com/advisories/GHSA-7236-3392-c5c6 primary=https://www.openwall.com/lists/oss-security/2026/08/19/4 primary=https://github.com/ceph/ceph/releases/tag/v20.2.4 primary=https://github.com/ceph/ceph/releases/tag/v19.2.6

2 min Read →
資安雷達

2026-08-19 — CPython urllib 認證外洩、Lemur SSRF 連環公告與 moby/go-archive 解壓縮路徑穿越三則資安修補

primary=https://www.openwall.com/lists/oss-security/2026/08/18/3 primary=https://github.com/python/cpython/pull/155696 primary=https://github.com/advisories/GHSA-xpmj-wjcp-6pww primary=https://github.com/advisories/GHSA-f3qq-49m6-rw8f primary=https://github.com/advisories/GHSA-v5rc-cpwc-cfpr primary=https://github.com/advisories/GHSA-hfg8-hc9c-6c3h

2 min Read →
資安雷達

2026-08-18 — vm2 沙箱四洞齊爆、AI Autofix 引入注入漏洞攻陷 Snowflake Jira、MLflow 授權與 SSRF 三連環洞同日修補

primary=https://github.com/advisories/GHSA-m283-3h24-438v primary=https://github.com/advisories/GHSA-cfcw-xp6x-25gj primary=https://github.com/advisories/GHSA-m5w8-4gq2-6f8x primary=https://github.com/advisories/GHSA-v836-6xw4-9cx3 primary=https://www.wiz.io/blog/red-agent-snowflake-copilot-cicd-bug primary=https://github.com/advisories/GHSA-gqch-g4w5-7qcw primary=https://github.com/advisories/GHSA-3p64-6gvh-82v5 primary=https://github.com/advisories/GHSA-7gwp-5pfp-969j

3 min Read →