<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Doonsec's feed</title><link>http://wechat.doonsec.com/MzkyMjcxNzE2MQ.xml</link><description>The latest security articles about WeChat official account</description><language>zh-CN</language><lastBuildDate>Tue, 09 Dec 2025 07:33:17 GMT</lastBuildDate><generator>PyRSS2Gen-1.1.0</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><image><url>http://wechat.doonsec.com/</url><title>Doonsec</title><link>http://wechat.doonsec.com/static/front/img/doonsec_bak3.png</link></image><item><title>分享的图片、视频、链接</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484713&amp;idx=1&amp;sn=8ff6f682f568d9f0d3e494f2f5420ff0</link><description></description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2025-12-08T19:58:30</pubDate></item><item><title>Chrome 紧急修复 V8 引擎类型混淆漏洞（CVE-2025-10585）</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484704&amp;idx=1&amp;sn=866355da2312e9272a6e8be013b46899</link><description>Chrome 紧急修复 V8 引擎类型混淆漏洞（CVE-2025-10585）</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2025-09-20T15:08:59</pubDate></item><item><title>在企业和政府网络中发现新型 Buterat 后门木马软件</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484697&amp;idx=1&amp;sn=8ef4e33af67feca905203949104bfe6b</link><description>在企业和政府网络中发现新型 Buterat 后门木马软件</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2025-09-19T18:00:00</pubDate></item><item><title>超160万健身会员录音曝光,Hello Gym陷数据安全风波</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484691&amp;idx=1&amp;sn=66ab5062cb1f744cc0b6544bb0f9e0b7</link><description>超160万健身会员录音曝光,Hello Gym陷数据安全风波</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2025-09-19T08:00:20</pubDate></item><item><title>VoidProxy网络钓鱼窃取 Microsoft 与 Google 登录凭据</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484683&amp;idx=1&amp;sn=14df957ecd2ac29993bc45009ba6ec74</link><description>VoidProxy网络钓鱼窃取 Microsoft 与 Google 登录凭据</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2025-09-17T18:00:00</pubDate></item><item><title>新型勒索软件 Yurei 利用开源工具作案</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484671&amp;idx=1&amp;sn=16ab66638ccc3295ab8d353822dfd089</link><description>新型勒索软件 Yurei 利用开源工具作案</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2025-09-17T08:00:15</pubDate></item><item><title>DELMIA Apriso CVE-2025-5086 反序列化远程代码执行漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484666&amp;idx=1&amp;sn=131e075be20e59b4368f32ba2db6892f</link><description></description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2025-09-16T19:04:47</pubDate></item><item><title>黑客利用 X(Twitter) 的 Grok AI 通过广告推送恶意链接</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484662&amp;idx=1&amp;sn=01c04cbffba78c3f7cda2024f5cdb2cf</link><description>黑客利用 X(Twitter) 的 Grok AI 通过广告推送恶意链接</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2025-09-16T08:01:56</pubDate></item><item><title>越南央行旗下机构被黑！全国信用数据或遭泄露</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484656&amp;idx=1&amp;sn=1203f97873317c5ed4ae61e556a5a944</link><description></description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2025-09-15T19:06:04</pubDate></item><item><title>新型银行木马PhantomCall来袭！伪装Chrome应用！</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484652&amp;idx=1&amp;sn=53a48778251de07d6c52ca6913ae852c</link><description>新型银行木马PhantomCall来袭！伪装Chrome应用！</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2025-09-15T08:02:55</pubDate></item><item><title>微软已紧急修补！新型HybridPetya勒索软件可绕过UEFI安全启动机制</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484633&amp;idx=1&amp;sn=5f6236a6b8d7ee6883b1da41f2ddcb95</link><description>微软已紧急修补！新型HybridPetya勒索软件可绕过UEFI安全启动机制</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2025-09-14T18:00:00</pubDate></item><item><title>你的U盘可能正在自动复制间谍软件！X-Force披露最新SnakeDiskUSB蠕虫</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484626&amp;idx=1&amp;sn=0ae42a20d536f69b7bb5aacb6c6b3c89</link><description>你的U盘可能正在自动复制间谍软件！X-Force披露最新SnakeDiskUSB蠕虫</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2025-09-14T08:00:17</pubDate></item><item><title>WhatsApp曝零日漏洞，苹果用户遭精准攻击！</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484612&amp;idx=1&amp;sn=a7d2086b2f1deee92d66c71280b00d1e</link><description>WhatsApp曝零日漏洞，苹果用户遭精准攻击！</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2025-09-12T08:01:42</pubDate></item><item><title>漏洞正被活跃利用，数百万TP-Link路由器面临远程控制风险u200b</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484607&amp;idx=1&amp;sn=b184891d3e6db9bb31134ec3737c7532</link><description>漏洞正被活跃利用，数百万TP-Link路由器面临远程控制风险u200b</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2025-09-11T08:05:36</pubDate></item><item><title>DeepSeek被曝严重数据泄露：百万条日志、聊天记录与密钥全网公开u200b</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484602&amp;idx=1&amp;sn=a5e23e5d273bccb6f71fe745ee029574</link><description>DeepSeek被曝严重数据泄露：百万条日志、聊天记录与密钥全网公开u200b</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2025-09-10T08:00:50</pubDate></item><item><title>防火墙能防住黑客，但防得住HR招进来的“自己人”吗？u200b</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484597&amp;idx=1&amp;sn=7ee47521f261b6bae9486ed3369cf6ef</link><description>防火墙能防住黑客，但防得住HR招进来的“自己人”吗？u200b</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2025-09-09T08:20:50</pubDate></item><item><title>补丁永远打不完？揭示IT自动化的真正挑战与未来u200b</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484591&amp;idx=1&amp;sn=22735785271d8362bbfbaee8d7b46b8e</link><description>补丁永远打不完？揭示IT自动化的真正挑战与未来u200b</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2025-09-08T08:05:37</pubDate></item><item><title>网络犯罪分子正在出售中国监控摄像头的访问权限</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484585&amp;idx=1&amp;sn=a8c960b1db2774826cf5b567b33f3615</link><description>网络犯罪分子正在出售中国监控摄像头的访问权限</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2025-09-07T12:19:32</pubDate></item><item><title>黑客入侵麦当劳系统获取免费鸡块，发现漏洞价值数百万美元</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484576&amp;idx=1&amp;sn=f6b4e173cffb2510bf717b891dbdd00b</link><description>黑客入侵麦当劳系统获取免费鸡块，发现漏洞价值数百万美元</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2025-09-06T17:00:43</pubDate></item><item><title>深入分析与防范网络钓鱼邮件攻击</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484571&amp;idx=1&amp;sn=46da340820f589a26ee195c3b4aba407</link><description>深入分析与防范网络钓鱼邮件攻击</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2025-01-17T09:03:30</pubDate></item><item><title>自从进了这个京东捡漏福利群，拿了很多0元商品，还有很多秒杀呢！</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484570&amp;idx=1&amp;sn=11f94851680e7d129f929090b5f9e9f5</link><description>很遗憾地说，这不是一篇告诉你京东plus怎么充值，哪款电商平台适合购物，这篇文章仅推荐优惠群。</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2025-01-16T09:07:51</pubDate></item><item><title>日志分析----RDP暴力破解</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484556&amp;idx=1&amp;sn=b20c672f9f98a6420b752a7bfac62b35</link><description>日志分析----RDP暴力破解</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2025-01-14T09:05:18</pubDate></item><item><title>【漏洞复现】急诊急救快速联动平台ServicePage.aspx任意文件读取漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484549&amp;idx=1&amp;sn=a88bf7fad8fe67e1040afaefb128bffe</link><description>【漏洞复现】急诊急救快速联动平台ServicePage.aspx任意文件读取漏洞</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2025-01-07T09:05:19</pubDate></item><item><title>浏览器取证——Cryptominer(加密货币挖矿)</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484541&amp;idx=1&amp;sn=27a0183ead10bbc5064b6af4be2d5d4d</link><description>浏览器取证——Cryptominer(加密货币挖矿)</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2025-01-03T09:51:51</pubDate></item><item><title>日志分析——被入侵的 WordPress</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484530&amp;idx=1&amp;sn=a72d1b6359f2f7027e778942fe23eae2</link><description>日志分析——被入侵的 WordPress</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-12-31T09:06:01</pubDate></item><item><title>【漏洞复现】高校人力资源管理服务平台系统ReportServer存在敏感信息泄露漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484514&amp;idx=1&amp;sn=d4b86b9f70beb745e30ac3f215a67872</link><description>【漏洞复现】高校人力资源管理服务平台系统ReportServer存在敏感信息泄露漏洞</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-12-27T09:03:26</pubDate></item><item><title>Oracle WebLogic Server反序列化漏洞(CVE-2024-21216)</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484506&amp;idx=1&amp;sn=4e8642ae5fb5ac56155c85575660f234</link><description>Oracle WebLogic Server反序列化漏洞（CVE-2024-21216）</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-12-25T14:01:17</pubDate></item><item><title>CVE-2024-11477：7-Zip 中的严重缺陷可让黑客控制</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484499&amp;idx=1&amp;sn=5e4e9c892b49d69df1a5ebc34b3ee227</link><description>CVE-2024-11477：7-Zip 中的严重缺陷可让黑客控制</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-12-20T10:36:02</pubDate></item><item><title>【漏洞复现】网动统一通信平台ActiveUC存在信息泄露漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484494&amp;idx=1&amp;sn=3e4bad9e318e8af71c4733ed839c2aec</link><description>【漏洞复现】网动统一通信平台ActiveUC存在信息泄露漏洞</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-12-10T09:07:22</pubDate></item><item><title>【漏洞复现】Palo Alto PAN-OS身份认证绕过CVE-2024-0012及命令执行漏洞CVE-2024-9474</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484485&amp;idx=1&amp;sn=0f5b3d6588ad00afd34fe51811a012a4</link><description>【漏洞复现】Palo Alto Networks PAN-OS身份认证绕过CVE-2024-0012及命令执行漏洞CVE-2024-9474</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-12-09T09:34:02</pubDate></item><item><title>【漏洞复现】赛普EAP企业适配管理平台Upload任意文件上传漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484475&amp;idx=1&amp;sn=abb1e90b0a7bf06630254cbceb7a4db6</link><description>【漏洞复现】赛普EAP企业适配管理平台Upload任意文件上传漏洞</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-12-06T09:09:19</pubDate></item><item><title>【漏洞复现】金华迪加现场大屏系统存在任意文件上传getshell漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484468&amp;idx=1&amp;sn=034d450a0362a5ea3ced5e18dd1f68eb</link><description>【漏洞复现】金华迪加现场大屏系统存在任意文件上传getshell漏洞</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-12-05T09:07:25</pubDate></item><item><title>【漏洞复现】Bazaar 任意文件读取漏洞(CVE-2024-40348)</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484450&amp;idx=1&amp;sn=18f5fca3583408b95ab16f7b37e5ebba</link><description>【漏洞复现】Bazaar 任意文件读取漏洞(CVE-2024-40348)</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-12-03T09:04:59</pubDate></item><item><title>【漏洞复现】OfficeWeb365 SaveDraw 任意文件上传getshell漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484430&amp;idx=1&amp;sn=ce83f5232dd760583f858e6ddccf7aa7</link><description>【漏洞复现】OfficeWeb365 SaveDraw 任意文件上传getshell漏洞</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-12-02T09:10:26</pubDate></item><item><title>【漏洞复现】同享TXEHR V15人力管理管理平台信息泄露漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484429&amp;idx=1&amp;sn=68a1517617279baad8d107745f42fc21</link><description>【漏洞复现】同享TXEHR V15人力管理管理平台信息泄露漏洞</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-11-29T09:13:52</pubDate></item><item><title>【漏洞复现】ArcGIS地理空间平台manager任意文件读取漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484389&amp;idx=1&amp;sn=e3cac6c2d8f4b76f14984ceda7aba4a9</link><description>【漏洞复现】ArcGIS地理空间平台manager任意文件读取漏洞</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-11-26T09:07:06</pubDate></item><item><title>【漏洞复现】明源云ERP报表 GetErpConfig.aspx存在信息泄露漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484388&amp;idx=1&amp;sn=ef6fed2e7d12fc7b14b6f661f7a3390e</link><description>【漏洞复现】明源云ERP报表 GetErpConfig.aspx存在信息泄露漏洞</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-11-25T09:14:56</pubDate></item><item><title>【漏洞复现】九思OA dl任意文件读取漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484387&amp;idx=1&amp;sn=f887c236bdc1cfcc3e1bc2e90e4ff8e8</link><description>【漏洞复现】九思OA dl任意文件读取漏洞</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-11-22T09:07:37</pubDate></item><item><title>【漏洞复现】数字通云平台智慧政务cookie登录绕过漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484368&amp;idx=1&amp;sn=49f5c63e530ff4a5360f1bde3b2f324f</link><description>【漏洞复现】数字通云平台智慧政务cookie登录绕过漏洞</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-11-21T09:22:56</pubDate></item><item><title>【漏洞复现】D-Link  NAS 远程命令执行漏洞(CVE-2024-3273)</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484334&amp;idx=1&amp;sn=bfd4f94e969ee9f8e7ec653c0feae32a</link><description>【漏洞复现】D-Link  NAS 远程命令执行漏洞(CVE-2024-3273)</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-11-19T17:52:20</pubDate></item><item><title>【漏洞复现】英飞达医学影像存档与通信系统webservices接口存在信息泄露漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484315&amp;idx=1&amp;sn=f4aa02a7e95ecbc0b1052e97591654d0</link><description>【漏洞复现】英飞达医学影像存档与通信系统webservices接口存在信息泄露漏洞</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-11-18T09:20:10</pubDate></item><item><title>【漏洞复现】D-Link account_mgr.cgi接口命令注入漏洞(CVE-2024-10914)</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484299&amp;idx=1&amp;sn=dee6ee969b78942a5ed69cc3902c278e</link><description>D-Link account_mgr.cgi接口命令注入漏洞(CVE-2024-10914)</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-11-15T09:28:31</pubDate></item><item><title>APP渗透测试-drozer</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484253&amp;idx=1&amp;sn=c301d6e1a37329455b1908072f1379c3</link><description>APP渗透测试-drozer</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-11-11T10:35:14</pubDate></item><item><title>【漏洞复现】同望OA系统tooneAssistantAttachement.jsp接口处存在任意文件读取漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484202&amp;idx=1&amp;sn=853b3e38f6be3f100a2ec767dc95dfa1</link><description>【漏洞复现】同望OA系统tooneAssistantAttachement.jsp接口处存在任意文件读取漏洞</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-11-08T16:34:05</pubDate></item><item><title>【漏洞复现】天融信运维安全审计系统download接口处存在任意文件读取漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484187&amp;idx=1&amp;sn=f55b74afb22c8acada36107beebd6faf</link><description>【漏洞复现】天融信运维安全审计系统download接口处存在任意文件读取漏洞</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-11-04T09:45:12</pubDate></item><item><title>【漏洞复现】CyberPanel远程命令执行漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484172&amp;idx=1&amp;sn=1ab0fb82881444a83e5ba7ec9ebf4ced</link><description>【漏洞复现】CyberPanel远程命令执行漏洞</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-11-01T09:08:14</pubDate></item><item><title>【漏洞复现】微信公众号小说漫画系统 fileupload.php 任意文件上传漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484155&amp;idx=1&amp;sn=df204c5f091d5ce2276b5e14d4ce5ede</link><description>【漏洞复现】微信公众号小说漫画系统 fileupload.php 任意文件上传漏洞</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-10-31T09:28:23</pubDate></item><item><title>【漏洞复现】NUUO摄像头远程命令执行漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484140&amp;idx=1&amp;sn=38aec95c9f06ff775512f193be2ad0f3</link><description></description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-10-30T09:12:49</pubDate></item><item><title>【漏洞复现】时空智友ERP系统uploadStudioFile任意文件上传漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484123&amp;idx=1&amp;sn=c311ed1740c168505a5904bcea9d9861</link><description>【漏洞复现】时空智友ERP系统uploadStudioFile任意文件上传漏洞</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-10-29T09:13:37</pubDate></item><item><title>Tenda路由器账号密码信息泄露漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484100&amp;idx=1&amp;sn=f6113950f7b771d1e02b7abbb6d01483</link><description>Tenda路由器账号密码信息泄露漏洞</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-10-28T10:14:50</pubDate></item><item><title>【漏洞复现】方正全媒体新闻采编系统存在XXE漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484084&amp;idx=1&amp;sn=56fa88b132dee5a5258f37aac0a8de49</link><description>【漏洞复现】方正全媒体新闻采编系统存在XXE漏洞</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-10-18T08:52:42</pubDate></item><item><title>【漏洞复现】孚盟云系统/Ajax/AjaxSendDingdingMessage接口处存在sql注入漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484069&amp;idx=1&amp;sn=76bb22a1092e679d59e4f72a79140231</link><description>【漏洞复现】孚盟云系统/Ajax/AjaxSendDingdingMessage接口处存在sql注入漏洞</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-10-11T23:00:14</pubDate></item><item><title>全球网络安全搜索引擎十大排行与分析</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484052&amp;idx=1&amp;sn=4ace66548d937d470b5f084214cc7078</link><description>全球网络安全搜索引擎十大排行与分析</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-10-10T11:55:54</pubDate></item><item><title>【漏洞复现】DataEase 数据库配置信息泄露漏洞（CVE-2024-30269）</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484035&amp;idx=1&amp;sn=a1e5fec01d77476d0dbfab488e8253ba</link><description>【漏洞复现】DataEase 数据库配置信息泄露漏洞（CVE-2024-30269）</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-10-09T15:47:31</pubDate></item><item><title>【漏洞复现】致远OA rest/m3接口处敏感信息泄露</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247484014&amp;idx=1&amp;sn=b482e5da9b23d9c078faeac84034c4e4</link><description>【漏洞复现】致远OA rest/m3接口处敏感信息泄露</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-09-29T10:51:21</pubDate></item><item><title>云安全研究（一）</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247483999&amp;idx=1&amp;sn=8e24ee0525b8ebb966de5e36e3f3693f</link><description>云安全研究（一）</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-09-27T09:25:29</pubDate></item><item><title>浅谈挖掘UAC白名单以及利用</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247483988&amp;idx=1&amp;sn=4b2c367d8011f31dfed36e205c2edcc2</link><description>浅谈挖掘UAC白名单以及利用</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-09-23T10:14:15</pubDate></item><item><title>APP抓包--httpcanary教程</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247483968&amp;idx=1&amp;sn=88acbd9d8ef8484df633bad0fa33d4aa</link><description>APP抓包--httpcanary教程</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-09-20T09:42:30</pubDate></item><item><title>【漏洞复现】Windows 远程桌面授权服务远程代码执行漏洞（CVE-2024-38077）</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247483949&amp;idx=1&amp;sn=7d5c7979195c24d211238656a47c0335</link><description>Windows 远程桌面授权服务远程代码执行漏洞（CVE-2024-38077）</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-09-13T11:50:34</pubDate></item><item><title>【漏洞复现】Windows TCP/IP远程执行代码蓝屏漏洞(CVE-2024-38063)</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247483932&amp;idx=1&amp;sn=b0526beaa3d429a2442b65c573d3560a</link><description>【漏洞复现】Windows TCP/IP远程执行代码蓝屏漏洞(CVE-2024-38063)</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-09-12T10:10:26</pubDate></item><item><title>小程序抓包--Proxifier的安装及使用教程</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247483918&amp;idx=1&amp;sn=c1be2dfcad09f09f252e4cdce8d894c8</link><description>小程序抓包--Proxifier的安装及使用教程</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-09-10T17:31:55</pubDate></item><item><title>【漏洞复现】华天动力OA任意文件读取漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247483896&amp;idx=1&amp;sn=0038a9fe6ac482957dc7129a85d5eb20</link><description>【漏洞复现】华天动力OA任意文件读取漏洞</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-09-09T15:07:27</pubDate></item><item><title>【漏洞复现】用友NC /content 接口SQL注入漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247483886&amp;idx=1&amp;sn=4f525b41f75c3863fbe1c8e816018ac2</link><description>【漏洞复现】用友NC /content 接口SQL注入漏洞</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-09-06T15:21:50</pubDate></item><item><title>【漏洞复现】泛微 e-cology v10 远程代码执行漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247483875&amp;idx=1&amp;sn=6077e2c0c52d04a75b4bf1505cb5b987</link><description>【漏洞复现】泛微 e-cology v10 远程代码执行漏洞</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-08-21T15:28:34</pubDate></item><item><title>【漏洞复现】康达vpn-list_base_config.php存在命令执行漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247483862&amp;idx=1&amp;sn=c7a1305e743abeceaf24f9d66affcbc8</link><description>【漏洞复现】康达vpn-list_base_config.php存在命令执行漏洞</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-08-19T10:18:59</pubDate></item><item><title>【2024HW情报】0729-0801漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247483849&amp;idx=1&amp;sn=8db15c2180096a51201748a35740561f</link><description>【2024HW情报】0729-0801漏洞</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-08-02T15:55:06</pubDate></item><item><title>【2024HW情报】0722-0726漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247483844&amp;idx=1&amp;sn=8685b0090897f36692db5ebd5c7aea8b</link><description>【2024HW情报】0722-0726漏洞</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-07-26T18:23:24</pubDate></item><item><title>【2024HW情报】【漏洞复现】致远OA fileUpload.do 前台文件上传绕过漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247483839&amp;idx=1&amp;sn=a38944c2de17264127af38281a70e9c6</link><description>【2024HW情报】【漏洞复现】致远OA fileUpload.do 前台文件上传绕过漏洞</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-07-23T11:07:46</pubDate></item><item><title>【漏洞复现】海康威视安防管理平台/v1/keepAlive 接口处存在远程命令执行漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247483828&amp;idx=1&amp;sn=0c995e18603edd1be0c29abff880faad</link><description>【漏洞复现】海康威视安防管理平台/v1/keepAlive 接口处存在远程命令执行漏洞</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-07-18T16:03:53</pubDate></item><item><title>【漏洞复现】通达OA moare接口反序列化漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247483806&amp;idx=1&amp;sn=1e88b314988ef2101e085e860db2f3bf</link><description>【漏洞复现】通达OA moare接口反序列化漏洞</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-07-17T17:52:26</pubDate></item><item><title>【漏洞复现】鲸发卡系统任意文件读取漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247483794&amp;idx=1&amp;sn=096197741325dcc44f17b7ab293e003b</link><description>【漏洞复现】鲸发卡系统任意文件读取漏洞</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-07-11T11:22:16</pubDate></item><item><title>【漏洞复现】迈普多业务融合网关远程命令执行漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247483782&amp;idx=1&amp;sn=d18aa4390cb073ab5b71675f4ecd7f86</link><description>【漏洞复现】迈普多业务融合网关远程命令执行漏洞</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-06-27T09:51:36</pubDate></item><item><title>【漏洞复现】极企智能办公路由接口jumper.php存在RCE漏洞</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247483770&amp;idx=1&amp;sn=965564f2d9be13e438ec5de5de4d73e1</link><description>【漏洞复现】极企智能办公路由接口jumper.php存在RCE漏洞</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-06-26T16:03:05</pubDate></item><item><title>【漏洞复现】PHP CGI Windows平台远程代码执行漏洞(CVE-2024-4577)</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247483756&amp;idx=1&amp;sn=cd26b06369fe1ef12e205b18a05193c6</link><description>【漏洞复现】PHP CGI Windows平台远程代码执行漏洞(CVE-2024-4577)</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-06-24T10:02:13</pubDate></item><item><title>【漏洞复现】学分制系统 GetCalendarContentById SQL注入漏洞getshell</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247483744&amp;idx=1&amp;sn=7ba0121b6bb6f5b8d8a6be7516d5101c</link><description>【漏洞复现】学分制系统 GetCalendarContentById SQL注入漏洞getshell</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-06-23T08:02:09</pubDate></item><item><title>【漏洞复现】XWiki远程代码执⾏漏洞(CVE-2024-31982)</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247483730&amp;idx=1&amp;sn=ce18dc8c8dea67e51ffba640c29b15d8</link><description>【漏洞复现】XWiki远程代码执⾏漏洞(CVE-2024-31982)</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-06-22T17:56:14</pubDate></item><item><title>攻防世界web-(unsepin)wp</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247483707&amp;idx=1&amp;sn=c9fb99060d200d5ada386fe976116a01</link><description>攻防世界web-(unsepin)wp</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-06-21T08:00:07</pubDate></item><item><title>【漏洞复现】Jenkins CLI 任意文件读取漏洞CVE-2024-23897</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247483692&amp;idx=1&amp;sn=1aa6393995bb9a779b3c26ef98f46c17</link><description>【漏洞复现】Jenkins CLI 任意文件读取漏洞CVE-2024-23897</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-06-19T17:59:29</pubDate></item><item><title>必火CTF--中级赛wp</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247483680&amp;idx=1&amp;sn=07551968b3367c9305ebcb7e2fda362e</link><description>必火CTF--中级赛wp</description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-06-18T18:11:01</pubDate></item><item><title>必火CTF--初级赛wp</title><link>https://mp.weixin.qq.com/s?__biz=MzkyMjcxNzE2MQ==&amp;mid=2247483663&amp;idx=1&amp;sn=db8b4807bda1bde5bfd1880ab889a690</link><description></description><author>白帽攻防</author><category>白帽攻防</category><pubDate>2024-06-17T17:33:30</pubDate></item></channel></rss>