23:07 · 2026年5月20日 · 周三 菜板tv🙈🙊🙉 已经快进到 ai萝卜蹲了哈哈哈哈哈哈,你被日完我被日。不过这一次GitHub action被一锅端,zerotrust都防不住,着实难搞 https://tanstack.com/blog/npm-supply-chain-compromise-postmortem https://twitter.com/nebusecurity/status/2057071579876753643上次圈子里这么热闹,还是16年我刚入行安全的时候哈哈哈哈哈 X (formerly Twitter) Nebula Security (@nebusecurity) on X Introducing nginx-poolslip, a fresh RCE for the the latest nginx release 1.31.0. nginx-rift has been patched, but our security agent Vega has found a new 0 day. We will release the full technical writeup with ASLR bypass 30 days after the patch on ht…