<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Doonsec's feed</title><link>http://wechat.doonsec.com/Mzk0Mjc2MzQ0Ng.xml</link><description>The latest security articles about WeChat official account</description><language>zh-CN</language><lastBuildDate>Tue, 04 Nov 2025 17:50:28 GMT</lastBuildDate><generator>PyRSS2Gen-1.1.0</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><image><url>http://wechat.doonsec.com/</url><title>Doonsec</title><link>http://wechat.doonsec.com/static/front/img/doonsec_bak3.png</link></image><item><title>关于账号进行迁移的说明</title><link>https://mp.weixin.qq.com/s?__biz=Mzk0Mjc2MzQ0Ng==&amp;mid=2247484562&amp;idx=1&amp;sn=347c34503f091b28d3395af8cfc81303</link><description>关于账号进行迁移的说明</description><author>棉花糖网安情报站</author><category>棉花糖网安情报站</category><pubDate>2025-11-04T15:35:11</pubDate></item><item><title>疑似启明星辰文档数据泄露至暗网论坛 darkforums</title><link>https://mp.weixin.qq.com/s?__biz=Mzk0Mjc2MzQ0Ng==&amp;mid=2247484561&amp;idx=1&amp;sn=bea3525a6933074f4c5bbe153d51eaca</link><description></description><author>棉花糖网安情报站</author><category>棉花糖网安情报站</category><pubDate>2025-05-18T14:10:20</pubDate></item><item><title>F5 BIG-IP rce漏洞 CVE-2025-31644</title><link>https://mp.weixin.qq.com/s?__biz=Mzk0Mjc2MzQ0Ng==&amp;mid=2247484553&amp;idx=1&amp;sn=76ac840bd43c005468a6a364354f7bc0</link><description></description><author>棉花糖网安情报站</author><category>棉花糖网安情报站</category><pubDate>2025-05-15T16:22:34</pubDate></item><item><title>【密码喷洒攻防实战】Microsoft Entra SSO功能的滥用与防御</title><link>https://mp.weixin.qq.com/s?__biz=Mzk0Mjc2MzQ0Ng==&amp;mid=2247484536&amp;idx=1&amp;sn=9863cac1f505ed9f26b43dfab9a55ae6</link><description>Microsoft Entra 无缝单一登录（Seamless Single Sign-On）是微软推出的一种</description><author>棉花糖网安情报站</author><category>棉花糖网安情报站</category><pubDate>2025-04-18T11:23:07</pubDate></item><item><title>《.NET安全攻防指南》上下册重磅来袭！</title><link>https://mp.weixin.qq.com/s?__biz=Mzk0Mjc2MzQ0Ng==&amp;mid=2247484532&amp;idx=1&amp;sn=7728514fddc9d858b020610ec94d4045</link><description>每个时代的安全议题皆与当时社会的核心价值紧密相连。</description><author>棉花糖网安情报站</author><category>棉花糖网安情报站</category><pubDate>2025-04-16T10:00:27</pubDate></item><item><title>【免费下载】美国国际开发署全球联系人全部资料（具体电话、地址、邮箱）</title><link>https://mp.weixin.qq.com/s?__biz=Mzk0Mjc2MzQ0Ng==&amp;mid=2247484528&amp;idx=1&amp;sn=265da341ec28b8cc34175db579bbae89</link><description></description><author>棉花糖网安情报站</author><category>棉花糖网安情报站</category><pubDate>2025-02-17T09:13:41</pubDate></item><item><title>7-Zip高危漏洞CVE-2025-0411 poc 攻击者可绕过安全机制远程执行代码</title><link>https://mp.weixin.qq.com/s?__biz=Mzk0Mjc2MzQ0Ng==&amp;mid=2247484515&amp;idx=1&amp;sn=7626bbc733c1de7e73a860df756a9589</link><description>7z高危cve漏洞公开</description><author>棉花糖网安情报站</author><category>棉花糖网安情报站</category><pubDate>2025-01-23T09:39:51</pubDate></item><item><title>macos高危漏洞CVE-2024-54498 解析+复现</title><link>https://mp.weixin.qq.com/s?__biz=Mzk0Mjc2MzQ0Ng==&amp;mid=2247484513&amp;idx=1&amp;sn=ce8323e3947ba30d7a9cf7463b3233db</link><description>绕过mac沙盒机制</description><author>棉花糖网安情报站</author><category>棉花糖网安情报站</category><pubDate>2025-01-14T03:27:06</pubDate></item><item><title>外网露出：新版 CobaltStrike 顶级免杀套件Arsenal kit</title><link>https://mp.weixin.qq.com/s?__biz=Mzk0Mjc2MzQ0Ng==&amp;mid=2247484511&amp;idx=1&amp;sn=9f17ce402cd178335216998b2a486d22</link><description>cs插件</description><author>棉花糖网安情报站</author><category>棉花糖网安情报站</category><pubDate>2025-01-08T12:24:20</pubDate></item><item><title>CVE-2024-50603  Aviatrix Controller RCE 发布 poc</title><link>https://mp.weixin.qq.com/s?__biz=Mzk0Mjc2MzQ0Ng==&amp;mid=2247484511&amp;idx=2&amp;sn=efa9830c743cb37581a1d0a71cc13391</link><description>CVE-2024-50603</description><author>棉花糖网安情报站</author><category>棉花糖网安情报站</category><pubDate>2025-01-08T12:24:20</pubDate></item><item><title>CVE-2024-43452 Windows 提权漏洞发布 PoC</title><link>https://mp.weixin.qq.com/s?__biz=Mzk0Mjc2MzQ0Ng==&amp;mid=2247484497&amp;idx=1&amp;sn=3bd62112070f1ccf62c11527c5dcdf91</link><description>CVE-2024-43452</description><author>棉花糖网安情报站</author><category>棉花糖网安情报站</category><pubDate>2025-01-06T20:29:17</pubDate></item><item><title>CVE-2024-43405：Nuclei 漏洞允许攻击者执行未经授权的远程代码</title><link>https://mp.weixin.qq.com/s?__biz=Mzk0Mjc2MzQ0Ng==&amp;mid=2247484492&amp;idx=1&amp;sn=77916e199717b041fc5904d60cbd15d9</link><description>CVE-2024-43405</description><author>棉花糖网安情报站</author><category>棉花糖网安情报站</category><pubDate>2025-01-05T20:01:52</pubDate></item><item><title>威胁者发布更多数据后，思科确认未发生泄密事件</title><link>https://mp.weixin.qq.com/s?__biz=Mzk0Mjc2MzQ0Ng==&amp;mid=2247484492&amp;idx=2&amp;sn=d1a6c296356c6b8cd0d6c9ff78968a64</link><description>cve-2024-53376</description><author>棉花糖网安情报站</author><category>棉花糖网安情报站</category><pubDate>2025-01-05T20:01:52</pubDate></item><item><title>自定义kali：增加60+常用渗透工具，哥斯拉特战版，cs魔改应有尽有，菜单栏启动</title><link>https://mp.weixin.qq.com/s?__biz=Mzk0Mjc2MzQ0Ng==&amp;mid=2247484474&amp;idx=1&amp;sn=0c1f0aeb3dd9019abe8549a91dd8078c</link><description>kali修改版，哥斯拉特战版，cs魔改，vshell应有尽有</description><author>棉花糖网安情报站</author><category>棉花糖网安情报站</category><pubDate>2024-12-27T13:29:38</pubDate></item><item><title>全网最全之数证杯团体决赛wp</title><link>https://mp.weixin.qq.com/s?__biz=Mzk0Mjc2MzQ0Ng==&amp;mid=2247484441&amp;idx=1&amp;sn=4850179ef951cd26970ff7ae3cc9d8a0</link><description>数证杯wp</description><author>棉花糖网安情报站</author><category>棉花糖网安情报站</category><pubDate>2024-12-18T09:03:27</pubDate></item><item><title>Apache Struts RCE  (CVE-2024-53677)  POC公开</title><link>https://mp.weixin.qq.com/s?__biz=Mzk0Mjc2MzQ0Ng==&amp;mid=2247483865&amp;idx=1&amp;sn=c06e08bfe1fc6745535e7aa7b4964319</link><description>CVE-2024-53677</description><author>棉花糖网安情报站</author><category>棉花糖网安情报站</category><pubDate>2024-12-17T11:16:37</pubDate></item><item><title>Fortify 24.2.0 win/mac/linux 下载</title><link>https://mp.weixin.qq.com/s?__biz=Mzk0Mjc2MzQ0Ng==&amp;mid=2247483857&amp;idx=1&amp;sn=cc68e02400a25d163eec31681ef28ae1</link><description>Fortify 24.2.0</description><author>棉花糖网安情报站</author><category>棉花糖网安情报站</category><pubDate>2024-12-16T11:26:12</pubDate></item><item><title>Cleo 0day漏洞  CVE-2024-50623 poc 公开</title><link>https://mp.weixin.qq.com/s?__biz=Mzk0Mjc2MzQ0Ng==&amp;mid=2247483849&amp;idx=1&amp;sn=8cc1ca7c88267e641c37046706506242</link><description>CVE-2024-50623 的 PoC 发布</description><author>棉花糖网安情报站</author><category>棉花糖网安情报站</category><pubDate>2024-12-12T11:41:29</pubDate></item><item><title>啊？学姐，你这个工具还有更多玩法？</title><link>https://mp.weixin.qq.com/s?__biz=Mzk0Mjc2MzQ0Ng==&amp;mid=2247483843&amp;idx=1&amp;sn=2632583df0132e2a7de605bcd31de4d2</link><description>和学姐探讨工具的使用</description><author>棉花糖网安情报站</author><category>棉花糖网安情报站</category><pubDate>2024-12-07T18:48:48</pubDate></item><item><title>Zabbix SQL 注入 CVE-2024-42327 POC已公开</title><link>https://mp.weixin.qq.com/s?__biz=Mzk0Mjc2MzQ0Ng==&amp;mid=2247483805&amp;idx=1&amp;sn=301f996bf5a4d7d342bbd808683d2ed1</link><description>CVE-2024-42327 的 PoC 发布</description><author>棉花糖网安情报站</author><category>棉花糖网安情报站</category><pubDate>2024-12-04T12:55:27</pubDate></item><item><title>揭示台湾攻击活动中SmokeLoader的高级手法</title><link>https://mp.weixin.qq.com/s?__biz=Mzk0Mjc2MzQ0Ng==&amp;mid=2247483795&amp;idx=1&amp;sn=e17d680f465cb59907286aabecbec082</link><description>FortiGuard Labs最近的一份报告揭示了一次涉及臭名昭著的SmokeLoader恶意软件的定向网络攻击。这次攻击活动于2024年9月在台湾多个行业（包括制造业、医疗保健和IT）中被观察到。</description><author>棉花糖网安情报站</author><category>棉花糖网安情报站</category><pubDate>2024-12-03T12:27:27</pubDate></item><item><title>开源文件共享软件存在严重漏洞CVE-2024-11680，已有公开的PoC</title><link>https://mp.weixin.qq.com/s?__biz=Mzk0Mjc2MzQ0Ng==&amp;mid=2247483780&amp;idx=1&amp;sn=5b3b72191864bf73dedd0708130f587b</link><description>根据VulnCheck的报告，开源文件共享应用程序ProjectSend中的一个严重漏洞，标识为CVE-2024-11680,尽管自2023年5月起已发布补丁，但是99%的ProjectSend公网机器仍未修复依然面临被攻击的风险</description><author>棉花糖网安情报站</author><category>棉花糖网安情报站</category><pubDate>2024-11-28T16:44:05</pubDate></item><item><title>著名压缩工具7-Zip 存在远程代码执行漏洞——CVE-2024-11477</title><link>https://mp.weixin.qq.com/s?__biz=Mzk0Mjc2MzQ0Ng==&amp;mid=2247483769&amp;idx=1&amp;sn=61e608296fdac4830a429201ab51d65a</link><description>在流行的文件压缩工具7-Zip中发现了一个高危漏洞（CVE-2024-11477），可能允许攻击者在易受攻击的系统上执行恶意代码。</description><author>棉花糖网安情报站</author><category>棉花糖网安情报站</category><pubDate>2024-11-26T09:15:19</pubDate></item><item><title>一键梭哈工具！3697个xss payload助力h1赚美刀</title><link>https://mp.weixin.qq.com/s?__biz=Mzk0Mjc2MzQ0Ng==&amp;mid=2247483764&amp;idx=1&amp;sn=caac6964d972afe733be966c757e5cc1</link><description>3697个xss payload</description><author>棉花糖网安情报站</author><category>棉花糖网安情报站</category><pubDate>2024-11-25T19:37:38</pubDate></item><item><title>2024年wordpress、d-link等相关的多个cve漏洞poc</title><link>https://mp.weixin.qq.com/s?__biz=Mzk0Mjc2MzQ0Ng==&amp;mid=2247483735&amp;idx=1&amp;sn=e9d3836aafa30ce2dc27226288315747</link><description>2024年cve相关</description><author>棉花糖网安情报站</author><category>棉花糖网安情报站</category><pubDate>2024-11-24T20:09:45</pubDate></item><item><title>黑客出售CVE-2024-23113获取的设备权限</title><link>https://mp.weixin.qq.com/s?__biz=Mzk0Mjc2MzQ0Ng==&amp;mid=2247483702&amp;idx=1&amp;sn=22f3ee684c9c6a9c25e06609e1f6579c</link><description>Fortinet CVE-2024-23113是一个高危的格式字符串漏洞，存在于Fortinet的FortiOS、FortiProxy、FortiPAM和FortiWeb等产品中</description><author>棉花糖网安情报站</author><category>棉花糖网安情报站</category><pubDate>2024-11-16T18:01:12</pubDate></item><item><title>(免费)信息安全技术IT安全运维管理指南</title><link>https://mp.weixin.qq.com/s?__biz=Mzk0Mjc2MzQ0Ng==&amp;mid=2247483697&amp;idx=1&amp;sn=836598d7ee483353a609d0bde5977f64</link><description>棉花糖旗下永久更新免费资料公众号</description><author>棉花糖网安情报站</author><category>棉花糖网安情报站</category><pubDate>2024-10-06T16:48:34</pubDate></item><item><title>(免费)零信任网络安全应用要求</title><link>https://mp.weixin.qq.com/s?__biz=Mzk0Mjc2MzQ0Ng==&amp;mid=2247483692&amp;idx=1&amp;sn=63991d806e2adf062b2f3387330a503e</link><description>(免费)零信任网络安全应用要求</description><author>棉花糖网安情报站</author><category>棉花糖网安情报站</category><pubDate>2024-10-05T16:21:54</pubDate></item><item><title>(免费)YDT 2387-2023 网络安全监测系统技术要求</title><link>https://mp.weixin.qq.com/s?__biz=Mzk0Mjc2MzQ0Ng==&amp;mid=2247483686&amp;idx=1&amp;sn=fd99b7099ca9e138531cd8836b822d72</link><description>(免费)YDT 2387-2023 网络安全监测系统技术要求</description><author>棉花糖网安情报站</author><category>棉花糖网安情报站</category><pubDate>2024-10-04T16:30:00</pubDate></item><item><title>(免费)2024网络犯罪报告.pdf</title><link>https://mp.weixin.qq.com/s?__biz=Mzk0Mjc2MzQ0Ng==&amp;mid=2247483678&amp;idx=1&amp;sn=24750b0b5593e5240a27c82884713602</link><description>(免费)2024网络犯罪报告.pdf</description><author>棉花糖网安情报站</author><category>棉花糖网安情报站</category><pubDate>2024-09-30T18:09:23</pubDate></item><item><title>(免费)2024上半年网络安全漏洞态势报告</title><link>https://mp.weixin.qq.com/s?__biz=Mzk0Mjc2MzQ0Ng==&amp;mid=2247483672&amp;idx=1&amp;sn=0f7e348f8561ea285bb0a392132fa699</link><description>(免费)2024上半年网络安全漏洞态势报告</description><author>棉花糖网安情报站</author><category>棉花糖网安情报站</category><pubDate>2024-09-29T18:47:00</pubDate></item></channel></rss>