Posts of last 24 hours
资产测绘实战踩坑:580 个子域名结果 85% 是假阳性,从 grep -qv '^$' 空应答误判、泛解析、UDP 53 被墙到裸域漏验,逐个排坑后沉淀出"预筛 + 多轮枚举"两阶段方案,误报率降至 0。代码已开源。
https://xz.aliyun.com/news/92673
本文以一款会员时长类应用作为研究样本,完整拆解因账号注销物理删库带来的权限校验缺陷,复现 “注销 - 重注册” 无限领取新人权益的攻击链路,同时搭配抽象伪代码定位底层代码问题,给出通用化修复与审计思路。
https://xz.aliyun.com/news/92682
米国CISAがCISA ICS Advisory / ICS Medical Advisoryを公表しました。
https://jvn.jp/vu/JVNVU97889580/
A vulnerability identified as critical has been detected in IBM AIX and PowerVM VIOS 7.2/7.3/4.1. This affects an unknown part. Performing a manipulation results in out-of-bounds write.
This vulnerability is identified as CVE-2026-16958. The attack can be initiated remotely. There is not any exploit available.
https://vuldb.com/vuln/394012
A vulnerability categorized as critical has been discovered in Microsoft Entra. Affected by this issue is some unknown functionality. Such manipulation leads to server-side request forgery.
This vulnerability is referenced as CVE-2026-69851. It is possible to launch the attack remotely. No exploit is available.
This product operates as a managed service, which prevents users from maintaining vulnerability countermeasures themselves.
https://vuldb.com/vuln/394011
A vulnerability was found in Microsoft Azure Virtual Machines. It has been rated as critical. Affected by this vulnerability is an unknown functionality. This manipulation causes server-side request forgery.
The identification of this vulnerability is CVE-2026-69543. It is possible to initiate the attack remotely. There is no exploit available.
This product is a managed service, so users are unable to manage vulnerability countermeasures on their own.
https://vuldb.com/vuln/394010
A vulnerability was found in Microsoft Azure Data Factory. It has been declared as problematic. Affected is an unknown function. The manipulation results in server-side request forgery.
This vulnerability was named CVE-2026-66800. The attack may be performed from remote. There is no available exploit.
This product is a managed service. This means that users cannot maintain vulnerability countermeasures themselves.
https://vuldb.com/vuln/394009
A vulnerability was found in Microsoft Azure Arc. It has been classified as critical. This impacts an unknown function. The manipulation leads to improper authorization.
This vulnerability is uniquely identified as CVE-2026-69555. The attack is possible to be carried out remotely. No exploit exists.
This product is a managed service. It is not possible for users to maintain vulnerability countermeasures themselves.
https://vuldb.com/vuln/394008
A vulnerability was found in Microsoft Azure Data Manager for Energy and classified as critical. This affects an unknown function. Executing a manipulation can lead to integer overflow.
This vulnerability is handled as CVE-2026-69419. The attack can be executed remotely. There is not any exploit available.
This product is available as a managed service. Users are not able to maintain vulnerability countermeasures themselves.
https://vuldb.com/vuln/394007