1. 崩溃而非Shell:SolarWinds Serv-U CVE-2026-28318分析 漏洞 | 高危 | 已在野利用 | 2026-06-16 00:00 | CVE-2026-28318 | bishopfox.com | 原文 ↗ | #active-exploitation | #rce | #vulnerability-research
2. 不给糖就捣蛋:5 个可怕的网络钓鱼故事 博客 | 2025-10-30 12:00 | bugcrowd.com | 原文 ↗ | #supply-chain | #phishing | #bugcrowd
3. SolarWinds部分缓刑、CrowdStrike教训、LLM氪星石——CISO安全简报 博客 | 2024-10-16 15:00 | yeswehack.com | 原文 ↗ | #ai-security | #bug-bounty | #supply-chain
4. 政府针对安全研究人员案件被驳回的启示 博客 | 2024-08-15 21:50 | hackerone.com | 原文 ↗ | #regulation | #solarwinds | #legal
5. 美国 SEC 网络规则与 SolarWinds CISO 遭起诉:统一 OffSec 战略如何优化你的 SEC 披露 博客 | 2024-02-08 09:14 | yeswehack.com | 原文 ↗ | #compliance | #offsec | #regulation
6. 借助 HackerOne 强化资产以符合 SEC 要求 博客 | 2023-11-16 17:08 | hackerone.com | 原文 ↗ | #bug-bounty | #vulnerability-management | #compliance
7. EMA 报告:未知漏洞成为首要 Active Directory 安全关切 博客 | 2022-01-26 00:25 | semperis.com | 原文 ↗ | #vulnerability-management | #active-directory | #solarwinds
8. 制作利用:SolarWinds 漏洞 CVE-2021-35211 漏洞 | 2022-01-13 00:00 | CVE-2021-35211 | bishopfox.com | 原文 ↗ | #vulnerability | #solarwinds | #rop
9. 与道德黑客合作保障供应链安全 博客 | 2021-11-30 17:50 | hackerone.com | 原文 ↗ | #bug-bounty | #supply-chain | #open-source
10. 现在是重新思考 Active Directory 安全的时候了 博客 | 2021-08-04 16:13 | semperis.com | 原文 ↗ | #active-directory | #identity-security | #security-strategy
11. 是时候放弃在混合环境中使用 ADFS 进行身份验证了吗? 博客 | 2021-07-08 19:28 | semperis.com | 原文 ↗ | #cloud | #active-directory | #authentication
12. 与 Alex Stamos 和 Charles Carmakal 对话:关于供应链和勒索软件攻击的新见解 事件 | 2021-06-10 00:00 | bishopfox.com | 原文 ↗ | #supply-chain | #incident-response | #threat-intelligence
13. 微软称:俄罗斯 SolarWinds 黑客再次攻击美国政府机构 博客 | 2021-06-02 15:44 | hackerone.com | 原文 ↗ | #supply-chain | #phishing | #apt
14. 身份攻击观察:2021 年 5 月 博客 | 2021-05-28 15:53 | semperis.com | 原文 ↗ | #active-directory | #solarwinds | #news-roundup
15. 身份攻击观察:2021 年 3 月 博客 | 2021-03-26 18:58 | semperis.com | 原文 ↗ | #active-directory | #ransomware | #solarwinds
16. 配置错误与供应链漏洞的兴起 漏洞 | 2021-02-26 04:51 | hackerone.com | 原文 ↗ | #supply-chain | #cloud-security | #solarwinds
17. Semperis 身份攻击观察:2021 年 2 月 博客 | 2021-02-26 18:28 | semperis.com | 原文 ↗ | #active-directory | #ransomware | #solarwinds
18. Semperis 专家:SolarWinds 攻击凸显保护 AD 的必要性 事件 | 2021-02-02 16:02 | semperis.com | 原文 ↗ | #cloud | #supply-chain | #active-directory
19. 与 OP Financial Group CISO 和 @mrtuxracer 对话的 5 点收获 博客 | 2021-01-27 18:59 | hackerone.com | 原文 ↗ | #phishing | #webinar | #ciso
20. 关于 SolarWinds Orion 攻击事件,我们目前知道(和不知道)的 博客 | 2020-12-15 00:00 | bishopfox.com | 原文 ↗ | #supply-chain | #nation-state | #solarwinds
21. NotPetya 回响:最新供应链攻击使 Active Directory 面临被入侵风险 博客 | 2020-12-15 14:33 | semperis.com | 原文 ↗ | #supply-chain | #active-directory | #solarwinds
22. SolarWinds Serv-U Managed File Transfer——会话 ID 熵不足 公告 | 2018-05-14 00:00 | CVE-2018-10240 | bishopfox.com | 原文 ↗ | #brute-force | #solarwinds | #session-hijacking
23. SolarWinds Serv-U Managed File Transfer——拒绝服务 公告 | 2018-05-11 00:00 | CVE-2018-10241 | bishopfox.com | 原文 ↗ | #denial-of-service | #solarwinds | #serv-u
24. SolarWinds Log & Event Manager——不当访问控制 漏洞 | 2017-05-12 00:00 | CVE-2017-7646 | bishopfox.com | 原文 ↗ | #access-control | #advisory | #solarwinds
25. SolarWinds Log & Event Manager——任意命令注入 漏洞 | 2017-05-12 00:00 | CVE-2017-7647 | bishopfox.com | 原文 ↗ | #advisory | #solarwinds | #command-injection