威胁情报
针对攻击活动、样本与IOC的持续情报更新。
-
Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability
Mirasvit | Mirasvit Full Page Cache Warmer | https://mirasvit.com/package/changelog/?package=mirasvit/module-cache-warmer ; https://nvd.nist.gov/vuln/detail/CVE-2026-45247
Mirasvit | Mirasvit Full Page Cache Warmer | https://mirasvit.com/package/changelog/?package=mirasvit/module-cache-warmer ; https://nvd.nist.gov/vuln/detail/CVE-2026-45247Mirasvit | Mirasvit Full Page Cache Warmer | https://mirasvit.com/package/changelog/?package=mirasvit/module-cache-warmer ; https://nvd.nist.gov/vuln/detail/CVE-2026-45247扩展字段
{ "cve_id": "CVE-2026-45247", "due_date": "2026-06-06T00:00:00+00:00", "known_ransomware_campaign_use": "Unknown", "product": "Mirasvit Full Page Cache Warmer", "raw_date_added": "2026-06-03", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.", "vendor_project": "Mirasvit" } -
Android Framework Integer Overflow Vulnerability
Android | Framework | https://source.android.com/docs/security/bulletin/2026/2026-06-01 ; https://nvd.nist.gov/vuln/detail/CVE-2025-48595
Android | Framework | https://source.android.com/docs/security/bulletin/2026/2026-06-01 ; https://nvd.nist.gov/vuln/detail/CVE-2025-48595Android | Framework | https://source.android.com/docs/security/bulletin/2026/2026-06-01 ; https://nvd.nist.gov/vuln/detail/CVE-2025-48595扩展字段
{ "cve_id": "CVE-2025-48595", "due_date": "2026-06-05T00:00:00+00:00", "known_ransomware_campaign_use": "Unknown", "product": "Framework", "raw_date_added": "2026-06-02", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.", "vendor_project": "Android" } -
Linux Kernel Improper Authentication Vulnerability
Linux | Kernel | This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=24f6008564183aa120d07c03d9289519c2fe02…
Linux | Kernel | This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=24f6008564183aa120d07c03d9289519c2fe02Linux | Kernel | This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=24f6008564183aa120d07c03d9289519c2fe02af ; https://www.kernel.org/ ; https://nvd.nist.gov/vuln/detail/CVE-2022-0492扩展字段
{ "cve_id": "CVE-2022-0492", "due_date": "2026-06-05T00:00:00+00:00", "known_ransomware_campaign_use": "Unknown", "product": "Kernel", "raw_date_added": "2026-06-02", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.", "vendor_project": "Linux" } -
Oracle WebLogic Server Unspecified Vulnerability
Oracle | WebLogic Server | https://www.oracle.com/security-alerts/cpujul2024.html ; https://nvd.nist.gov/vuln/detail/CVE-2024-21182
Oracle | WebLogic Server | https://www.oracle.com/security-alerts/cpujul2024.html ; https://nvd.nist.gov/vuln/detail/CVE-2024-21182Oracle | WebLogic Server | https://www.oracle.com/security-alerts/cpujul2024.html ; https://nvd.nist.gov/vuln/detail/CVE-2024-21182扩展字段
{ "cve_id": "CVE-2024-21182", "due_date": "2026-06-04T00:00:00+00:00", "known_ransomware_campaign_use": "Unknown", "product": "WebLogic Server", "raw_date_added": "2026-06-01", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.", "vendor_project": "Oracle" } -
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
Palo Alto Networks | PAN-OS | https://security.paloaltonetworks.com/CVE-2026-0257 ; https://nvd.nist.gov/vuln/detail/CVE-2026-0257
Palo Alto Networks | PAN-OS | https://security.paloaltonetworks.com/CVE-2026-0257 ; https://nvd.nist.gov/vuln/detail/CVE-2026-0257Palo Alto Networks | PAN-OS | https://security.paloaltonetworks.com/CVE-2026-0257 ; https://nvd.nist.gov/vuln/detail/CVE-2026-0257扩展字段
{ "cve_id": "CVE-2026-0257", "due_date": "2026-06-01T00:00:00+00:00", "known_ransomware_campaign_use": "Unknown", "product": "PAN-OS", "raw_date_added": "2026-05-29", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.", "vendor_project": "Palo Alto Networks" } -
Daemon Tools Lite Embedded Malicious Code Vulnerability
Daemon | Daemon Tools Lite | https://blog.daemon-tools.cc/post/security-incident ; https://nvd.nist.gov/vuln/detail/CVE-2026-8398
Daemon | Daemon Tools Lite | https://blog.daemon-tools.cc/post/security-incident ; https://nvd.nist.gov/vuln/detail/CVE-2026-8398Daemon | Daemon Tools Lite | https://blog.daemon-tools.cc/post/security-incident ; https://nvd.nist.gov/vuln/detail/CVE-2026-8398扩展字段
{ "cve_id": "CVE-2026-8398", "due_date": "2026-05-30T00:00:00+00:00", "known_ransomware_campaign_use": "Unknown", "product": "Daemon Tools Lite", "raw_date_added": "2026-05-27", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.", "vendor_project": "Daemon" } -
TanStack Unspecified Vulnerability
TanStack | TanStack | This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/TanStack/router/security/advisories/GHSA-g7cv-rxg3-hmpx ; https://nvd.nist.gov/vuln/detail/CVE-2026-45321
TanStack | TanStack | This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/TanStack/router/security/advisories/GHSA-g7cv-rxg3-hmpx ; https://nvd.nist.gov/vuln/detail/CVE-2026-45321TanStack | TanStack | This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/TanStack/router/security/advisories/GHSA-g7cv-rxg3-hmpx ; https://nvd.nist.gov/vuln/detail/CVE-2026-45321扩展字段
{ "cve_id": "CVE-2026-45321", "due_date": "2026-06-10T00:00:00+00:00", "known_ransomware_campaign_use": "Known", "product": "TanStack", "raw_date_added": "2026-05-27", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.", "vendor_project": "TanStack" } -
Nx Console Embedded Malicious Code Vulnerability
Nx | Nx Console | This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w ; https://nvd.nist.gov/vuln/detail/CVE-2026-48027
Nx | Nx Console | This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w ; https://nvd.nist.gov/vuln/detail/CVE-2026-48027Nx | Nx Console | This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w ; https://nvd.nist.gov/vuln/detail/CVE-2026-48027扩展字段
{ "cve_id": "CVE-2026-48027", "due_date": "2026-06-10T00:00:00+00:00", "known_ransomware_campaign_use": "Known", "product": "Nx Console", "raw_date_added": "2026-05-27", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.", "vendor_project": "Nx" }