<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>安全研究 on Lynx 的技术博客</title><link>https://blog.lynxflow.co/categories/%E5%AE%89%E5%85%A8%E7%A0%94%E7%A9%B6/</link><description>Recent content in 安全研究 on Lynx 的技术博客</description><generator>Hugo -- gohugo.io</generator><language>zh-cn</language><lastBuildDate>Wed, 02 Sep 2026 01:00:00 +0800</lastBuildDate><atom:link href="https://blog.lynxflow.co/categories/%E5%AE%89%E5%85%A8%E7%A0%94%E7%A9%B6/index.xml" rel="self" type="application/rss+xml"/><item><title>一只探针是怎样变成「总钥匙」的：哪吒探针失陷事件全复盘，附各领域重大漏洞分类表</title><link>https://blog.lynxflow.co/posts/nezha-probe-panel-takeover-vuln-history/</link><pubDate>Wed, 02 Sep 2026 01:00:00 +0800</pubDate><guid>https://blog.lynxflow.co/posts/nezha-probe-panel-takeover-vuln-history/</guid><description>&lt;img src="https://blog.lynxflow.co/images/nezha-probe-panel-takeover-vuln-history.png?v=090818" alt="Featured image of post 一只探针是怎样变成「总钥匙」的：哪吒探针失陷事件全复盘，附各领域重大漏洞分类表" /&gt;引言：一份没有它的官方名单 2021 年 11 月，美国政府开列了一份特殊目录：凡是&amp;quot;已被证实出现在真实攻击中&amp;quot;的漏洞，全部录入，强制联邦机构限期修复。这份目录叫 CISA KEV(已知被利用漏洞目录，关于 CVE/KEV 等术语的由来与口径，见本站另一篇《漏洞世界的「暗语」》)。截至 2026 年 8 月 31 日发布版，KEV 共收录 1,687 条漏洞，其中 352 条被标注为&amp;quot;曾被勒索软件团伙利用&amp;quot;。</description></item><item><title>从「被驳回」到「published」：我的第一个安全公告</title><link>https://blog.lynxflow.co/posts/first-accepted-security-advisory-qwed-mcp-rce/</link><pubDate>Fri, 28 Aug 2026 00:00:00 +0800</pubDate><guid>https://blog.lynxflow.co/posts/first-accepted-security-advisory-qwed-mcp-rce/</guid><description>2026 年 8 月 27 日的下午，我刷新那条私有公告页面的时候，状态从 triage 变成了 published。
那一刻是真的开心。
一条四个半小时的公告 公告编号 GHSA-2p69-jpm6-jrxh，严重度 Critical，CVSS 9.8，标题写着：</description></item></channel></rss>