每月主流操作系统、浏览器和服务器运行时都会披露数十个 CVE 漏洞。我们过滤无关噪音,重点筛选出已被在野利用的 0-Day 漏洞,并直接关联逐行高层源码深度剖析。
月度安全累积更新、内核本地提权漏洞以及关键系统底层服务修复通报。
Triage of 79 CVEs including CVE-2024-30051 DWM zero-day exploited in the wild by ransomware.
Triage of Ubuntu's September 2026 kernel rollups addressing critical io_uring memory corruption, eBPF verifier...
Technical triage of Canonical's August 2026 kernel update patching critical Netfilter nf_tables double-free an...
Triage of Ubuntu's July 2026 kernel updates fixing critical OverlayFS file capability bypasses and container s...
Technical triage of Ubuntu's core system library updates resolving the Glibc __vsyslog_internal buffer overflo...
Triage of Ubuntu's May 2026 kernel advisory addressing Kernel TLS zero-copy use-after-free and cryptographic s...
Technical triage of Ubuntu's April 2026 update fixing AppArmor socket mediation bypasses and packet filter san...
Handset security bulletins, baseband/kernel hardware zero-days, and browser sandbox exploits.
Analysis of CVE-2024-23222 WebKit JIT type confusion targeted by commercial spyware.
Triage of Google's September 2026 Android bulletin resolving actively exploited zero-days in the Binder IPC dr...
Technical triage of Android's August 2026 release addressing critical Qualcomm Adreno GPU kernel memory corrup...
Triage of Android's July 2026 security release addressing remote code execution via malformed H.264/H.265 vide...
Technical triage of Google's June 2026 Pixel advisory resolving actively exploited zero-days in the Arm Mali G...
Triage of Android's May 2026 security updates resolving framework intent redirection flaws and mutable Pending...
Technical triage of Android's April 2026 release addressing zero-click Bluetooth HCI fragmentation heap buffer...
V8 engine type confusions, HTTP request smuggling in llhttp, and runtime permission sandbox escapes.
Emergency stable channel patch for CVE-2024-4947 V8 Turbofan compiler type confusion.
Triage of the coordinated September 2026 Node.js release patching critical HTTP request smuggling in llhttp ac...
Technical triage of Node.js July 2026 security release fixing filesystem sandbox escapes in the experimental p...
Triage of Node.js May 2026 release fixing CRLF header injection and SSRF protections in the built-in global fe...
Technical triage of Node.js April 2026 emergency update fixing critical command argument injection on Windows ...
Control plane authorization bypasses, runc container breakouts, and Ingress annotation code injection.
Triage of the Kubernetes September 2026 release addressing authorization bypasses in aggregated API servers an...
Technical triage of the July 2026 ingress-nginx security advisory resolving custom annotation code injection a...
Triage of the May 2026 Kubernetes release addressing named pipe impersonation and container host breakout on W...
Technical triage of the landmark Leaky Vessels runc container breakout (CVE-2024-21626) affecting Docker, Kube...