Signal 安全 Origin 7-Zip 高危漏洞提醒:别把解压工具当成无害小组件 Sato 2026年7月23日 06:38 Hot: 82 ℃ Abstract: 7-Zip 被曝远程代码执行漏洞,恶意 XZ 压缩数据可能在打开或解压时触发问题。比起只看漏洞编号,更该盘点哪些服务、脚本和开发机在处理不可信压缩包,并把解压流程放到低权限、可回滚、可观测的位置。 安全 开源 基础设施 7-Zip 漏洞 运维 阅读全文
Signal 安全 Origin 7-Zip 的 XZ 解码漏洞,真正该紧张的是自动解压链路 Sato 2026年7月22日 06:38 Hot: 66 ℃ Abstract: 7-Zip 被披露一个与 XZ 解码相关的堆缓冲区溢出漏洞,摘要称可能被用于远程执行代码。比起单机用户手动解压,我更关心服务端、CI、网关和文件处理任务里的自动解压流程:哪里会接收外部压缩包,哪里缺少隔离,哪里没有快速回滚。 安全 开源 基础设施 7-Zip 漏洞 运维 阅读全文
Signal 安全 Origin XZ 后门这件事,最该记住的不是 0.5 秒 Sato 2026年7月21日 06:38 Hot: 85 ℃ Abstract: XZ Utils 后门再次提醒我们,供应链安全不只是一套扫描工具能解决的问题。真正容易被忽略的,是维护者压力、构建链路、发布包和线上异常之间那些不起眼的缝。 开源 供应链安全 Linux 运维 技术观察 阅读全文
Signal 安全 via Building a Production Grade Authentication System with NestJS Sato 2026年6月29日 06:11 Hot: 111 ℃ Abstract: Building a Production Grade Authentication System with NestJS Security is not a feature you bolt on after the fact. It is an architectural decision that shapes every layer of a system, from how requests are received to how identities are verified and how access is enforced. NestJS, with its opinionated structure and enterprise level design philosophy, makes it possible to build authentication systems that are not jus... Forum RSS 阅读全文