Category

資安雷達

CVE、Supply Chain、重大資安事件

資安雷達

2026-08-16 — Dancer2 認證外掛密碼重設連結遭 Host 標頭挾持,Perl DBI 模組兩起獨立堆積溢位漏洞同步在 1.652 版修補

primary=https://www.openwall.com/lists/oss-security/2026/08/15/4 primary=https://github.com/PerlDancer/Dancer2-Plugin-Auth-Extensible primary=https://github.com/perl5-dbi/dbi/security/advisories/GHSA-623j-hfpc-mrc4 primary=https://github.com/perl5-dbi/dbi/commit/29b72ae7d2a8114a734a55840bf1c45b89207809.patch primary=https://github.com/perl5-dbi/dbi/security/advisories/GHSA-wj3v-c3hh-mhqr primary=https://github.com/perl5-dbi/dbi/commit/c751ae5a5a6f56c2f8284f37c1f4d43500352ef1.patch

1 min Read →
資安雷達

2026-08-15 s2n-quic 的 CRYPTO 幀重組緩衝區未設上限導致記憶體耗盡攻擊,Token Optimizer MCP 則同時修補 dashboard API 路徑穿越與 smart_user 指令注入

primary=https://github.com/advisories/GHSA-9q54-f358-3fqf primary=https://github.com/aws/s2n-quic/compare/v1.81.0...v1.82.0 primary=https://github.com/advisories/GHSA-76pc-mqxp-3rq5 primary=https://github.com/advisories/GHSA-49mq-fc6q-3h46 primary=https://github.com/ooples/token-optimizer-mcp/commit/b4ee96dac799cbfba0a9f9c17844ce9d613cbcc7

2 min Read →
資安雷達

2026-08-14 — vLLM completions 端點缺少 prompt 陣列上限導致資源耗盡,Apache HttpComponents 非同步傳輸主機名驗證靜默失效使 TLS 遭中間人繞過,已退役的 Apache Shindig 因 XStream 反序列化可被觸發任意程式碼執行

primary=https://github.com/advisories/GHSA-87x5-vmc3-756j primary=https://github.com/vllm-project/vllm/commit/675f4295cdfe0d870471c2b51bfeca3a68a9569e primary=https://www.openwall.com/lists/oss-security/2026/08/13/6 primary=https://www.openwall.com/lists/oss-security/2026/08/13/7

1 min Read →
資安雷達

2026-08-10 — Apache Ranger 同批爆三起 RCE、dcrypt 密碼庫 GCM nonce 與 Ed25519 偽造弱點、Perl 正規表示式越界讀寫

primary=https://www.openwall.com/lists/oss-security/2026/08/09/7 primary=https://www.openwall.com/lists/oss-security/2026/08/09/6 primary=https://www.openwall.com/lists/oss-security/2026/08/09/5 primary=https://www.openwall.com/lists/oss-security/2026/08/09/2 primary=https://www.openwall.com/lists/oss-security/2026/08/09/3 primary=https://www.openwall.com/lists/oss-security/2026/08/09/4 primary=https://www.openwall.com/lists/oss-security/2026/08/09/8 primary=https://www.openwall.com/lists/oss-security/2026/08/09/9 primary=https://www.openwall.com/lists/oss-security/2026/08/09/10 primary=https://www.openwall.com/lists/oss-security/2026/08/09/11 primary=https://rustsec.org/advisories/RUSTSEC-2026-0238.html primary=https://rustsec.org/advisories/RUSTSEC-2026-0240.html primary=https://rustsec.org/advisories/RUSTSEC-2026-0239.html primary=https://rustsec.org/advisories/RUSTSEC-2026-0242.html primary=https://rustsec.org/advisories/RUSTSEC-2026-0237.html primary=https://rustsec.org/advisories/RUSTSEC-2026-0241.html primary=https://rustsec.org/advisories/RUSTSEC-2026-0243.html primary=https://rustsec.org/advisories/RUSTSEC-2026-0244.html primary=https://www.openwall.com/lists/oss-security/2026/08/09/12

2 min Read →
資安雷達

2026-08-08 — GitPython 六洞齊發、Apache Fory 三記憶體安全漏洞、CodeIgniter4 Query Builder SQL 注入等協同揭露解析

primary=https://github.com/advisories/GHSA-jm78-9fvv-mhgr primary=https://github.com/advisories/GHSA-wvpp-8hx9-p66j primary=https://github.com/advisories/GHSA-hmq2-w58f-27jc primary=https://github.com/advisories/GHSA-4gmw-gg2m-w46p primary=https://github.com/advisories/GHSA-9rj7-rf2p-w77r primary=https://github.com/advisories/GHSA-hh9p-6wh2-4mfc primary=https://www.openwall.com/lists/oss-security/2026/08/07/3 primary=https://www.openwall.com/lists/oss-security/2026/08/07/4 primary=https://www.openwall.com/lists/oss-security/2026/08/07/5 primary=https://github.com/advisories/GHSA-c9w5-rwh3-7pm9 primary=https://github.com/advisories/GHSA-mmj4-63m4-r6h5 primary=https://github.com/advisories/GHSA-hhmc-q9hp-r662 primary=https://github.com/advisories/GHSA-7wmf-pw8j-mc78

3 min Read →
資安雷達

2026-08-06 — rclone 一次揭露 14 個漏洞、Nuxt 修補 7 項含兩起 RCE、Atlassian Rovo 被爆料可遭提示注入外洩資料

primary=https://github.com/advisories/GHSA-2m8m-jhrm-w6j2 primary=https://github.com/advisories/GHSA-fqj9-69pf-6pjg primary=https://github.com/advisories/GHSA-7p4m-qxvv-g567 primary=https://github.com/advisories/GHSA-4vr5-p2gc-h23p primary=https://github.com/advisories/GHSA-gx4c-2hqx-cw2r primary=https://github.com/advisories/GHSA-279x-mwfv-vcqv primary=https://github.com/advisories/GHSA-9473-5f9j-94wq primary=https://github.com/advisories/GHSA-9pgf-384g-p7mv primary=https://github.com/advisories/GHSA-wm8w-6qjm-cv43 primary=https://github.com/advisories/GHSA-hxvh-4h3w-prp9 primary=https://github.com/advisories/GHSA-48hr-524c-v5w3 primary=https://github.com/advisories/GHSA-hxcr-hm88-mpq6 primary=https://www.promptarmor.com/resources/atlassian-rovo-exfiltrates-data

1 min Read →
資安雷達

2026-08-05 — LLM代理試圖入侵GitHub專案、Open WebUI單日11個漏洞公告、Bouncy Castle一次修32個CVE

primary=https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing primary=https://lwn.net/Articles/1087162/ primary=https://github.com/advisories/GHSA-8x5v-cpv7-8jjp primary=https://github.com/advisories/GHSA-3xpf-xq7r-v8c5 primary=https://github.com/advisories/GHSA-jxc9-xmc4-gr23 primary=https://oss-security.openwall.org/2026/08/04/2 primary=https://www.bouncycastle.org/resources/new-release-bouncy-castle-java-1-85/

1 min Read →