Category

資安雷達

CVE、Supply Chain、重大資安事件

資安雷達

2026-06-26 — libexpat 2.8.2 修補 13 漏洞、PowerDNS Recursor 8 個 CVE、Go SSH 套件驗證繞過 CVSS 9.1

primary=https://github.com/libexpat/libexpat/releases/tag/R_2_8_2 primary=https://github.com/libexpat/libexpat/blob/R_2_8_2/expat/Changes primary=https://blog.powerdns.com/2026/06/25/powerdns-security-advisory-2026-08-for-powerdns-recursor primary=https://docs.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-07.html primary=https://github.com/advisories/GHSA-5cgq-3rg8-m6cv primary=https://pkg.go.dev/vuln/GO-2026-5021

2 min Read →
資安雷達

2026-06-25 — Hoppscotch CVSS 10.0 JWT 金鑰竄改、curl 一次修補 18 個漏洞、美國行政命令 2030 後量子遷移期限

primary=https://github.com/hoppscotch/hoppscotch/security/advisories/GHSA-j542-4rch-8hwf primary=https://curl.se/docs/CVE-2026-8925.html primary=https://curl.se/docs/CVE-2026-9079.html primary=https://curl.se/docs/CVE-2026-11856.html primary=https://blog.cloudflare.com/post-quantum-eo-2026/ primary=https://www.whitehouse.gov/presidential-actions/2026/06/securing-the-nation-against-advanced-cryptographic-attacks/ primary=https://csrc.nist.gov/projects/post-quantum-cryptography

1 min Read →
資安雷達

2026-06-20 — Apache APISIX 驗證繞過、SurrealDB JWKS SSRF、LangSmith 任意檔案讀取

primary=https://www.openwall.com/lists/oss-security/2026/06/19/12 primary=https://www.cve.org/CVERecord?id=CVE-2026-49230 primary=https://github.com/advisories/GHSA-h5rg-8p7f-47g2 primary=https://github.com/surrealdb/surrealdb/security/advisories/GHSA-h5rg-8p7f-47g2 primary=https://github.com/advisories/GHSA-f4xh-w4cj-qxq8 primary=https://github.com/langchain-ai/langsmith-sdk/security/advisories/GHSA-f4xh-w4cj-qxq8

2 min Read →