<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet href="/rss.xsl" type="text/xsl"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>安全 | 笨蛋三月七的日常</title><description>互联网搬💩集散地BGP 分频: @bakanetwork内频：https://t.me/+KeNZttiOmFtlZjE1「愿你在未来与我的既往重逢」</description><link>https://broadcastchannel-95o.pages.dev</link><item><title>#安全预警 NPM包 node-ipc 出现供应链攻击，请暂停安装</title><link>https://broadcastchannel-95o.pages.dev/posts/2239</link><guid isPermaLink="true">https://broadcastchannel-95o.pages.dev/posts/2239</guid><pubDate>Thu, 14 May 2026 18:05:13 GMT</pubDate><content:encoded>&lt;a href=&quot;/search/%23%E5%AE%89%E5%85%A8%E9%A2%84%E8%AD%A6&quot;&gt;#安全预警&lt;/a&gt; NPM包 node-ipc 出现供应链攻击，请暂停安装。&lt;br /&gt;&lt;br /&gt;发生时间:5月14日23:30左右</content:encoded></item><item><title>#碎碎念 #前端 #安全 #新动态看乐了，还好我已经远离 Next.js 了CVE-2026-44578 CVE-2026-44578 ⚠️ Next.js – WebSocket Upgrade SSRF (CVSS 8.6) A server-side request forgery vulnerability in Next.js allows unauthenticated attackers to force self-hosted instances to make internal HTTP requests via the WebSocket upgrade handler. By sending a crafted absolute-form HTTP request with Upgrade: websocket headers, attackers can access internal services, cloud metadata endpoints, admin panels, and internal APIs reachable from the Next.js server on port 80. Successful exploitation may expose cloud credentials, API keys, secrets, and configuration data. Affected: Next.js 13.4.13+, 14.x, 15.x &lt;15.5.16, 16.0.0–16.2.4 Mitigation: Upgrade immediately to 15.5.16 or 16.2.5.  Modat Magnify Query: technology=&quot;Next.js&quot; The platform: </title><link>https://broadcastchannel-95o.pages.dev/posts/2230</link><guid isPermaLink="true">https://broadcastchannel-95o.pages.dev/posts/2230</guid><pubDate>Thu, 14 May 2026 14:24:37 GMT</pubDate><content:encoded>&lt;div&gt;
      
        &lt;img src=&quot;https://cdn5.telesco.pe/file/J5wyT94ea9YyWIE2AjvteHEDK8p2CY7X6jJGj1TlpZvStmMR0EYYIfLlU6ouv8ThbAtE2T4Q5TvLdB1ZXG_2qG9Pm709aF4A5l5Ag-lx7TBUOjz4as8FVXPlNA5Ep4RUoUIoXKuII3yiQwVCeZJom9ihDUHC17px51a2Atn2lsYMC83uhayBvLn6iLUI0dUAT30t62eTW9otYt1zOkJLq02Rkv1BLrXmZYxeApWncMB0SfqRlGtnI8iE_lM26pZJxVqTvlxodJVxrBjsn_Pnf62w9y8I48VOqr-ReAPFwanAkK6ObuplHGhWpg_WUOkKw4vKTQnN07zu-JbfI2xdBg.jpg&quot; alt=&quot;#碎碎念 #前端 #安全 #新动态看乐了，还好我已经远离 Next.js 了CVE-2026-44578 CVE-2026-44578 ⚠️ Next.js – WebSocket Upgrade SSRF (CVSS 8.6) A server-side request forgery vulnerability in Next.js allows unauthenticated attackers to force self-hosted instances to make internal HTTP requests via the WebSocket upgrade handler. By sending a crafted absolute-form HTTP request with Upgrade: websocket headers, attackers can access internal services, cloud metadata endpoints, admin panels, and internal APIs reachable from the Next.js server on port 80. Successful exploitation may expose cloud credentials, API keys, secrets, and configuration data. Affected: Next.js 13.4.13+, 14.x, 15.x &amp;lt;15.5.16, 16.0.0–16.2.4 Mitigation: Upgrade immediately to 15.5.16 or 16.2.5.  Modat Magnify Query: technology=&quot; loading=&quot;lazy&quot; /&gt;
      
      
        
      
    &lt;/div&gt;&lt;a href=&quot;/search/%23%E7%A2%8E%E7%A2%8E%E5%BF%B5&quot;&gt;#碎碎念&lt;/a&gt; &lt;a href=&quot;/search/%23%E5%89%8D%E7%AB%AF&quot;&gt;#前端&lt;/a&gt; &lt;a href=&quot;/search/%23%E5%AE%89%E5%85%A8&quot;&gt;#安全&lt;/a&gt; &lt;a href=&quot;/search/%23%E6%96%B0%E5%8A%A8%E6%80%81&quot;&gt;#新动态&lt;/a&gt;&lt;br /&gt;看乐了，还好我已经远离 Next.js 了&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;https://x.com/modat_magnify/status/2054848379339837850&quot; target=&quot;_blank&quot;&gt;CVE-2026-44578 &lt;/a&gt;&lt;br /&gt;&lt;blockquote&gt;CVE-2026-44578 &lt;br /&gt;&lt;i&gt;&lt;b&gt;⚠️&lt;/b&gt;&lt;/i&gt; Next.js – WebSocket Upgrade SSRF (CVSS 8.6) &lt;br /&gt;&lt;br /&gt;A server-side request forgery vulnerability in Next.js allows unauthenticated attackers to force self-hosted instances to make internal HTTP requests via the WebSocket upgrade handler. &lt;br /&gt;By sending a crafted absolute-form HTTP request with Upgrade: websocket headers, attackers can access internal services, cloud metadata endpoints, admin panels, and internal APIs reachable from the Next.js server on port 80. Successful exploitation may expose cloud credentials, API keys, secrets, and configuration data. &lt;br /&gt;&lt;br /&gt;Affected: Next.js 13.4.13+, 14.x, 15.x &amp;lt;15.5.16, 16.0.0–16.2.4 &lt;br /&gt;&lt;br /&gt;Mitigation: Upgrade immediately to 15.5.16 or 16.2.5.  &lt;br /&gt;&lt;br /&gt;Modat Magnify Query: &lt;br /&gt;technology=&quot;Next.js&quot; &lt;br /&gt;&lt;br /&gt;The platform: &lt;br /&gt;&lt;a href=&quot;https://magnify.modat.io/&quot; target=&quot;_blank&quot;&gt;https://magnify.modat.io/&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;/search/%23threatintel&quot;&gt;#threatintel&lt;/a&gt; &lt;a href=&quot;/search/%23vulnerability&quot;&gt;#vulnerability&lt;/a&gt; &lt;a href=&quot;/search/%23CVE202644578&quot;&gt;#CVE202644578&lt;/a&gt; &lt;a href=&quot;/search/%23Nextjs&quot;&gt;#Nextjs&lt;/a&gt; &lt;a href=&quot;/search/%23SSRF&quot;&gt;#SSRF&lt;/a&gt; &lt;a href=&quot;/search/%23WebSocket&quot;&gt;#WebSocket&lt;/a&gt; &lt;a href=&quot;/search/%23CloudSecurity&quot;&gt;#CloudSecurity&lt;/a&gt; &lt;a href=&quot;/search/%23infosec&quot;&gt;#infosec&lt;/a&gt; &lt;a href=&quot;/search/%23Critical&quot;&gt;#Critical&lt;/a&gt; &lt;a href=&quot;/search/%23ModatMagnify&quot;&gt;#ModatMagnify&lt;/a&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;最近 CVE 好 热 闹 啊</content:encoded></item><item><title>#安全资讯 病毒开源也是开源？致力于供应链攻击的 TeamPCP 团队在 GitHub 开源蠕虫病毒 Shai-Hulud，随后还有好心人贡献代码让蠕虫支持 FreeBSD (用户：我可谢谢你)</title><link>https://broadcastchannel-95o.pages.dev/posts/2193</link><guid isPermaLink="true">https://broadcastchannel-95o.pages.dev/posts/2193</guid><pubDate>Wed, 13 May 2026 07:58:17 GMT</pubDate><content:encoded>&lt;div&gt;
      
        &lt;img src=&quot;https://cdn5.telesco.pe/file/Xc-tHruVlfqbIuPMVs7o-SX-bukcExq6m7tbojEcVMFYuJ6ckweEnffaFKHgHhY0qDnCtfRKBsTyyVtSDKjwgk5E9K4C4BVkWlXXsuvGrfqUHtGa6Lg7fvgHAGIyItAFl2xadQISsW0pi38lhSeqFRIymwCJfCu1aCegglDQBCCgRCA-V51Lc_OoTqL9EbcpzCck2yVVPXLdO1Fl2Qh5hv3W1eTTE1is54lzEIgFYKrxIuQhDtZeuaRkk7PAlXnscuHLbrmlPg-YWdbPOsK50A9FSLfyCsfGC3Gux2ogqQVdJRJnY_wXmn0HfV0y6r3e97ZC5rhY7OsyKRKNZHOWOQ.jpg&quot; alt=&quot;#安全资讯 病毒开源也是开源？致力于供应链攻击的 TeamPCP 团队在 GitHub 开源蠕虫病毒 Shai-Hulud，随后还有好心人贡献代码让蠕虫支持 FreeBSD (用户：我可谢谢你)&quot; loading=&quot;lazy&quot; /&gt;
      
      
        
      
    
      
        &lt;img src=&quot;https://cdn5.telesco.pe/file/r4FY6ssnHFbMYXpDwFDSFSwh-tYgBczQICmUuBA1P6ekvQJ_Af37phcFPAb-kR8ra_xQKoc_uPb6aHjbM3cPbrpkDkx1xGtoCyfu_UMcGGMuMb-b9pikwvRV3ZUNww9FDEeYCAzlunns3sB1D2Q18TF7LwGkKO4j1c39bgSIeiJ_LIuHYb726qpYdqEZwIKPIg6R19UjctkdibvwhzrUFpnxeowQgPOUSAQ0XE1KMuPZku9Qs8kcHEpXuIy1SdwFeGZ4HXkBgYIT9xGISfiqbV4kWUVlZ0Ypueqf5qVLGL4rm7YKUKy0WHP0_9nVxnS01SJs_iHzS3DTS5BCSzjRdw.jpg&quot; alt=&quot;#安全资讯 病毒开源也是开源？致力于供应链攻击的 TeamPCP 团队在 GitHub 开源蠕虫病毒 Shai-Hulud，随后还有好心人贡献代码让蠕虫支持 FreeBSD (用户：我可谢谢你)&quot; loading=&quot;lazy&quot; /&gt;
      
      
        
      
    &lt;/div&gt;&lt;a href=&quot;/search/%23%E5%AE%89%E5%85%A8%E8%B5%84%E8%AE%AF&quot;&gt;#安全资讯&lt;/a&gt; &lt;b&gt;病毒开源也是开源？致力于供应链攻击的 TeamPCP 团队在 GitHub 开源蠕虫病毒 Shai-Hulud，随后还有好心人贡献代码让蠕虫支持 FreeBSD (用户：我可谢谢你)。&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;这个蠕虫病毒只需要简单修改即可部署使用，OX 分析师也确认代码是有效的，与黑客此前发起攻击使用的代码相同。&lt;br /&gt;&lt;br /&gt;查看详情：&lt;a href=&quot;https://ourl.co/112919&quot; target=&quot;_blank&quot;&gt;https://ourl.co/112919&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;&lt;b&gt;🤪&lt;/b&gt;&lt;/i&gt;&lt;a href=&quot;https://t.me/landiansub&quot; target=&quot;_blank&quot;&gt;订阅&lt;/a&gt; &lt;i&gt;&lt;b&gt;❓&lt;/b&gt;&lt;/i&gt;&lt;a href=&quot;https://t.me/id7371&quot; target=&quot;_blank&quot;&gt;解封&lt;/a&gt; &lt;i&gt;&lt;b&gt;😁&lt;/b&gt;&lt;/i&gt;&lt;a href=&quot;https://x.com/intent/follow?screen_name=landiantech&quot; target=&quot;_blank&quot;&gt;推特&lt;/a&gt; &lt;i&gt;&lt;b&gt;👍&lt;/b&gt;&lt;/i&gt;&lt;a href=&quot;https://t.me/landiansub/12423&quot; target=&quot;_blank&quot;&gt;CN2VPS&lt;/a&gt;</content:encoded></item></channel></rss>