东方财富东方财富华尔街见闻华尔街见闻同花顺同花顺微信读书微信读书LichessLichessV2EXV2EX微博微博今日头条今日头条百度百度快手快手哔哩哔哩哔哩哔哩知乎知乎腾讯新闻腾讯新闻网易新闻网易新闻澎湃新闻澎湃新闻新浪新闻新浪新闻新浪网新浪网豆瓣电影豆瓣电影GitHubGitHubCSDNCSDNIT之家IT之家36氪36氪宝庆银楼宝庆银楼中国黄金中国黄金周生生周生生英皇珠宝英皇珠宝老凤祥(广东)老凤祥(广东)六福珠宝六福珠宝周大福周大福周六福周六福Adafruit BlogAdafruit BlogAIbaseAIbaseAnt Bailing Developer BlogAnt Bailing Developer BlogAnthropicAnthropic小众软件小众软件AppleAppleApple PodcastsApple PodcastsAppleInsiderAppleInsiderArs TechnicaArs TechnicaarXivarXivAxiosAxiosBerkeley AI ResearchBerkeley AI ResearchBarchartBarchartBBC NewsBBC NewsBD Tech TalksBD Tech TalksBerkeley RDIBerkeley RDIBig ThinkBig Think哔哩哔哩热搜哔哩哔哩热搜哔哩哔哩热门视频哔哩哔哩热门视频BinanceBinanceBloombergBloombergBlueskyBlueskyBoston Dynamics BlogBoston Dynamics BlogBusiness InsiderBusiness InsiderByteDance Seed ResearchByteDance Seed Research参考消息参考消息虫部落虫部落Claude BlogClaude BlogClaude Code ReleasesClaude Code ReleasesCloudflare BlogCloudflare BlogCMU Machine Learning BlogCMU Machine Learning BlogCoinGeckoCoinGeckoCointelegraphCointelegraphcrates.iocrates.ioCrowd SupplyCrowd SupplyCSS-TricksCSS-Tricks51CTO51CTOCult of MacCult of MacCursor BlogCursor Blogdaily.dev · Populardaily.dev · PopularDaring FireballDaring FireballDario AmodeiDario AmodeiDeepLearning.AI · The BatchDeepLearning.AI · The BatchGoogle DeepMind BlogGoogle DeepMind BlogDeepSeek GitHubDeepSeek GitHubDefiLlamaDefiLlamaDescript BlogDescript BlogDEV.toDEV.to数字尾巴数字尾巴Docker HubDocker Hub豆瓣读书豆瓣读书豆瓣讨论豆瓣讨论Dwarkesh PatelDwarkesh PatelThe EconomistThe EconomistEleutherAI BlogEleutherAI BlogEngadgetEngadgetFinancial TimesFinancial TimesFlathubFlathubfreeCodeCampfreeCodeCampFrontiersFrontiersGary MarcusGary Marcus极客公园极客公园原神原神果核剥壳果核剥壳GoogleGoogleGoogle TrendsGoogle Trends果壳果壳HackadayHackadayHacker NewsHacker NewsHelloGitHubHelloGitHub历史上的今天历史上的今天HomebrewHomebrew崩坏3崩坏3Hugging FaceHugging Face活动行活动行虎扑虎扑虎嗅虎嗅IEEE SpectrumIEEE Spectrum爱范儿爱范儿凤凰网 · 热点资讯凤凰网 · 热点资讯inclusionAIinclusionAIIndie HackersIndie HackersInfoQInfoQInterconnectsInterconnects爱奇艺热播榜爱奇艺热播榜IT之家「喜加一」IT之家「喜加一」简书简书稀土掘金稀土掘金Andrej KarpathyAndrej KarpathyMoonshot AI KimiMoonshot AI KimiLatent SpaceLatent SpaceLessWrongLessWrongLil'Log (Lilian Weng)Lil'Log (Lilian Weng)Linux.doLinux.doLMSYS BlogLMSYS BlogLobstersLobsters英雄联盟英雄联盟LWN.netLWN.netMacRumorsMacRumorsMake: MagazineMake: MagazineMaven CentralMaven CentralMediumMediumMeituan LongCatMeituan LongCatMeta AI BlogMeta AI BlogMeta EngineeringMeta EngineeringMidjourney UpdatesMidjourney UpdatesMiniMaxMiniMaxMIT News · RoboticsMIT News · RoboticsMIT Technology ReviewMIT Technology Review米游社米游社Mozilla.ai BlogMozilla.ai BlogNatureNatureNeuroscience NewsNeuroscience NewsNew Atlas · RoboticsNew Atlas · RoboticsThe New YorkerThe New Yorker水木社区水木社区NGANGA9to5Mac9to5MacNodeSeekNodeSeek牛客牛客NuGetNuGetNVIDIANVIDIA纽约时报纽约时报OEISOEISOne Useful ThingOne Useful ThingOpen Robotics BlogOpen Robotics BlogOpenAIOpenAIOpenAlexOpenAlexOpenReviewOpenReviewOpenRouterOpenRouterPackagistPackagist远景论坛远景论坛PhoronixPhoronixPhys.orgPhys.orgPixivPixivPlanet ROSPlanet ROS吾爱破解吾爱破解PoliticoPolitico中国电建阳光采购网中国电建阳光采购网Product HuntProduct HuntPubMedPubMedPyPIPyPIQoderQoder腾讯视频热搜榜腾讯视频热搜榜Quanta MagazineQuanta MagazineQwenQwenReutersReutersRFC EditorRFC EditorRobohubRobohubRobotics & Automation NewsRobotics & Automation NewsRobotics TomorrowRobotics TomorrowROS DiscourseROS Discourse阮一峰的网络日志阮一峰的网络日志RubyGemsRubyGemsRunwayRunwaySam AltmanSam AltmanScienceAlertScienceAlertAhead of AIAhead of AISecurityOnlineSecurityOnlineServeTheHomeServeTheHomeServiceNow AIServiceNow AISimon WillisonSimon WillisonSingularity HubSingularity HubSky NewsSky NewsSlashdotSlashdotSmashing MagazineSmashing Magazine什么值得买什么值得买SolidotSolidotSpotifySpotify俄罗斯卫星通讯社俄罗斯卫星通讯社少数派少数派Stack OverflowStack OverflowStack Overflow BlogStack Overflow Blog崩坏:星穹铁道崩坏:星穹铁道SteamSteamSubstackSubstackSunoSunoSuno BlogSuno BlogSynced ReviewSynced Review淘宝逛一逛淘宝逛一逛TechCrunchTechCrunchTech Xplore · RoboticsTech Xplore · Robotics腾讯热点腾讯热点The AtlanticThe AtlanticThe DecoderThe DecoderThe GradientThe GradientThe GuardianThe GuardianThe RegisterThe RegisterThe VergeThe Verge百度贴吧百度贴吧TikTokTikTokTindie BlogTindie BlogTomer TunguzTomer TunguzTom's HardwareTom's HardwareTransformer CircuitsTransformer CircuitsTVmazeTVmaze优设网优设网UiverseUiverseVentureBeat · AIVentureBeat · AI万方数据万方数据中央气象台中央气象台WikidataWikidataWikipediaWikipediaWiredWiredThe Wall Street JournalThe Wall Street JournalxAI NewsxAI News小鹅通小鹅通YahooYahooYahoo FinanceYahoo FinanceYollomiYollomi有道精品课有道精品课YouTubeYouTube游研社游研社知乎日报知乎日报Zhipu AI ResearchZhipu AI Research财新数据通财新数据通央视新闻联播央视新闻联播CelesTrakCelesTrakCISA KEVCISA KEV财联社财联社CoinDeskCoinDesk法布财经法布财经富途牛牛富途牛牛格隆汇格隆汇HDXHDX和讯网和讯网Investing.comInvesting.com界面新闻界面新闻金十数据金十数据21财经21财经金融界金融界Launch Library 2Launch Library 2MKTNews · 快讯MKTNews · 快讯NASA EONETNASA EONETNOAA/NWSNOAA/NWSNVDNVDopenFDAopenFDAOSV.devOSV.dev量子位 · 具身智能量子位 · 具身智能新浪财经新浪财经Spaceflight NewsSpaceflight NewsTelegram OSINTTelegram OSINT腾讯混元研究腾讯混元研究USAspendingUSAspendingUSGS EarthquakesUSGS EarthquakesWHO 疫情通报WHO 疫情通报选股宝选股宝第一财经第一财经

实时热搜

  • 01803.1万
    Dai Dai
    4:01 · 榜期 2026-10-03 · 上期第 1 名 · 变化 +14.8% · 在榜 134 期Shakira / Burna Boy
  • 02533.9万
    Xamdam Sobirov - Peshta / Хамдам Собиров - Пешта / Video Klip
    3:01 · 榜期 2026-10-03 · 上期第 4 名 · 变化 +18.0% · 在榜 49 期Xamdam Sobirov
  • 03494.9万
    Casa Tupka Anthemo
    3:06 · 榜期 2026-10-03 · 上期第 2 名 · 变化 -12.0% · 在榜 15 期Yo Yo Honey Singh
  • 04390.2万
    Yeshanagula | The Paradise | Nani | Keerthy Suresh | Anirudh Ravichander | Srikanth Odela
    3:12 · 榜期 2026-10-03 · 上期第 3 名 · 变化 -20.8% · 在榜 36 期Saregama Telugu
  • 05353.7万
    KALYANI (Remix)
    4:48 · 榜期 2026-10-03 · 上期第 6 名 · 变化 -10.4% · 在榜 75 期ARJN / KDS / FIFTY4 / Shreya Ghoshal
  • 06350.3万
    Parvati
    4:46 · 榜期 2026-10-03 · 上期第 5 名 · 变化 -15.1% · 在榜 37 期Sadhu Tiwari
  • 07283.6万
    Barsaat
    3:06 · 榜期 2026-10-03 · 上期第 8 名 · 变化 -8.8% · 在榜 62 期Banjaare / Roni
  • 08262.5万
    Basinga Balaalu
    4:22 · 榜期 2026-10-03 · 上期第 7 名 · 变化 -18.6% · 在榜 80 期Srinidhi Nerella / Kalyan Keys / Swamy Naresh
  • 09221.5万
    Shararat
    3:49 · 榜期 2026-10-03 · 上期第 9 名 · 变化 -11.7% · 在榜 299 期Madhubanti Bagchi / Jasmine Sandlas / Shashwat Sachdev
  • 10213.9万
    Todo Lo Fue
    3:10 · 榜期 2026-10-03 · 上期第 22 名 · 变化 +29.1% · 在榜 245 期Lenin Ramirez
  • 11211.2万
    BbY WOW
    3:46 · 榜期 2026-10-03 · 上期第 11 名 · 变化 -1.9% · 在榜 42 期Judeline / rusowsky
  • 12207.7万
    Training Season (Live)
    3:34 · 榜期 2026-10-03 · 上期第 14 名 · 变化 +3.7% · 在榜 45 期Dua Lipa
  • 13200.1万
    Dame Tu Cosita
    2:33 · 榜期 2026-10-03 · 本期上榜 · 变化 +8.7% · 在榜 80 期Dancing Green Alien / El Chombo
  • 14187.8万
    KALYANI (Remix)
    4:09 · 榜期 2026-10-03 · 上期第 12 名 · 变化 -6.8% · 在榜 49 期Shreya Ghoshal / ARJN / FIFTY4 / KDS
  • 15186.9万
    Radhimaa [From "Think Indie"]
    5:48 · 榜期 2026-10-03 · 上期第 13 名 · 变化 -7.2% · 在榜 41 期Asma Teji / Sai Abhyankkar / Vivek / Nargis Teji
  • 16180.1万
    SaWaDiKa (Official Music Video)
    3:07 · 榜期 2026-10-03 · 上期第 16 名 · 变化 -3.7% · 在榜 29 期LISA
  • 17174.4万
    Si Antes Te Hubiera Conocido
    3:16 · 榜期 2026-10-03 · 本期上榜 · 变化 +12.7% · 在榜 379 期KAROL G
  • 18172.2万
    Aaya Sher
    4:57 · 榜期 2026-10-03 · 上期第 10 名 · 变化 -24.9% · 在榜 167 期Jangi Reddy / Arjun Chandy / Anirudh Ravichander / Kasarla Shyam
  • 19171.2万
    Teh Hijau
    3:31 · 榜期 2026-10-03 · 上期第 28 名 · 变化 +14.0% · 在榜 90 期Tulus
  • 20167.8万
    Garee2a Awy - A COLORS SHOW
    2:37 · 榜期 2026-10-03 · 上期第 21 名 · 变化 -0.4% · 在榜 65 期TUL8TE
  • 01
    CREW DRAGON 13
    International designator: 2026-226A NORAD catalog ID: 100882 Classification: Unclassified Element epoch: 2026-10-04T12:43:41.827008 Inclination: 51.6316° Eccentricity: 0.00068807 Mean motion: 15.4873 rev/day
  • 02
    STARLINK-40076
    International designator: 2026-225Z NORAD catalog ID: 100878 Classification: Unclassified Element epoch: 2026-10-04T14:00:01.999872 Inclination: 30.486° Eccentricity: 2.025e-05 Mean motion: 15.9224 rev/day
  • 03
    STARLINK-40082
    International designator: 2026-225Y NORAD catalog ID: 100877 Classification: Unclassified Element epoch: 2026-10-04T14:00:01.999872 Inclination: 30.4862° Eccentricity: 5.498e-05 Mean motion: 15.9221 rev/day
  • 04
    STARLINK-40101
    International designator: 2026-225X NORAD catalog ID: 100876 Classification: Unclassified Element epoch: 2026-10-04T14:00:01.999872 Inclination: 30.4873° Eccentricity: 1.987e-05 Mean motion: 15.9221 rev/day
  • 05
    STARLINK-40103
    International designator: 2026-225W NORAD catalog ID: 100875 Classification: Unclassified Element epoch: 2026-10-04T14:00:01.999872 Inclination: 30.4869° Eccentricity: 3.594e-05 Mean motion: 15.9221 rev/day
  • 06
    STARLINK-40078
    International designator: 2026-225V NORAD catalog ID: 100874 Classification: Unclassified Element epoch: 2026-10-04T14:00:01.999872 Inclination: 30.489° Eccentricity: 4.756e-05 Mean motion: 15.926 rev/day
  • 07
    STARLINK-40088
    International designator: 2026-225U NORAD catalog ID: 100873 Classification: Unclassified Element epoch: 2026-10-04T14:00:01.999872 Inclination: 30.4898° Eccentricity: 3.277e-05 Mean motion: 15.9313 rev/day
  • 08
    STARLINK-40081
    International designator: 2026-225T NORAD catalog ID: 100872 Classification: Unclassified Element epoch: 2026-10-04T14:00:01.999872 Inclination: 30.4902° Eccentricity: 3.407e-05 Mean motion: 15.9363 rev/day
  • 09
    STARLINK-40079
    International designator: 2026-225S NORAD catalog ID: 100871 Classification: Unclassified Element epoch: 2026-10-04T14:00:01.999872 Inclination: 30.4907° Eccentricity: 2.086e-05 Mean motion: 15.9414 rev/day
  • 10
    STARLINK-40080
    International designator: 2026-225R NORAD catalog ID: 100870 Classification: Unclassified Element epoch: 2026-10-04T14:00:01.999872 Inclination: 30.491° Eccentricity: 1.593e-05 Mean motion: 15.9709 rev/day
  • 11
    STARLINK-40077
    International designator: 2026-225Q NORAD catalog ID: 100869 Classification: Unclassified Element epoch: 2026-10-04T14:00:01.999872 Inclination: 30.4911° Eccentricity: 2.225e-05 Mean motion: 15.9677 rev/day
  • 12
    STARLINK-40092
    International designator: 2026-225P NORAD catalog ID: 100868 Classification: Unclassified Element epoch: 2026-10-04T14:00:01.999872 Inclination: 30.4863° Eccentricity: 7.5e-06 Mean motion: 15.9223 rev/day
  • 13
    STARLINK-40087
    International designator: 2026-225N NORAD catalog ID: 100867 Classification: Unclassified Element epoch: 2026-10-04T14:00:01.999872 Inclination: 30.491° Eccentricity: 2.406e-05 Mean motion: 15.9689 rev/day
  • 14
    STARLINK-40091
    International designator: 2026-225M NORAD catalog ID: 100866 Classification: Unclassified Element epoch: 2026-10-04T14:00:01.999872 Inclination: 30.4864° Eccentricity: 1.008e-05 Mean motion: 15.9224 rev/day
  • 15
    STARLINK-40090
    International designator: 2026-225L NORAD catalog ID: 100865 Classification: Unclassified Element epoch: 2026-10-04T14:00:01.999872 Inclination: 30.4873° Eccentricity: 3.154e-05 Mean motion: 15.9225 rev/day
  • 16
    STARLINK-40086
    International designator: 2026-225K NORAD catalog ID: 100864 Classification: Unclassified Element epoch: 2026-10-04T14:00:01.999872 Inclination: 30.4876° Eccentricity: 1.413e-05 Mean motion: 15.9226 rev/day
  • 17
    STARLINK-40085
    International designator: 2026-225J NORAD catalog ID: 100863 Classification: Unclassified Element epoch: 2026-10-04T14:00:01.999872 Inclination: 30.4883° Eccentricity: 1.372e-05 Mean motion: 15.9223 rev/day
  • 18
    STARLINK-40075
    International designator: 2026-225H NORAD catalog ID: 100862 Classification: Unclassified Element epoch: 2026-10-04T14:00:01.999872 Inclination: 30.4889° Eccentricity: 3.557e-05 Mean motion: 15.9241 rev/day
  • 19
    STARLINK-40100
    International designator: 2026-225G NORAD catalog ID: 100861 Classification: Unclassified Element epoch: 2026-10-04T14:00:01.999872 Inclination: 30.4894° Eccentricity: 4.239e-05 Mean motion: 15.9288 rev/day
  • 20
    STARLINK-40098
    International designator: 2026-225F NORAD catalog ID: 100860 Classification: Unclassified Element epoch: 2026-10-04T14:00:01.999872 Inclination: 30.4895° Eccentricity: 3.68e-05 Mean motion: 15.934 rev/day
3小时前更新
  • 01
    CVE-2026-88779 · Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
    Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 02
    CVE-2026-102490 · Zammad GmbH Zammad Improper Privilege Management Vulnerability
    Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 03
    CVE-2026-102489 · Zammad GmbH Zammad Session Fixation Vulnerability
    Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 04
    CVE-2026-104286 · Fortinet FortiMail Path Traversal Vulnerability
    Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 05
    CVE-2026-76504 · Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability
    Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 06
    CVE-2026-86950 · Apple Multiple Products Out-of-Bounds Write Vulnerability
    Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 07
    CVE-2026-88772 · Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
    Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 08
    CVE-2026-88771 · Citrix NetScaler Improper Input Validation Vulnerability
    Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 09
    CVE-2026-87902 · WordPress Core Remote File Inclusion Vulnerability
    WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 10
    CVE-2026-67279 · Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
    Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 11
    CVE-2026-65660 · Microsoft SharePoint Code Injection Vulnerability
    Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 12
    CVE-2026-71362 · Adobe Commerce and Magento Incorrect Authorization Vulnerability
    Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 13
    CVE-2026-5430 · WSO2 Multiple Products Path Traversal Vulnerability
    WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 14
    CVE-2026-94127 · F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
    F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 15
    CVE-2026-93952 · Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
    Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 16
    CVE-2026-93616 · Check Point Multiple Products Path Traversal Vulnerability
    Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 17
    CVE-2026-85102 · Check Point Multiple Products Improper Certificate Validation Vulnerability
    Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 18
    CVE-2026-7273 · Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
    Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 19
    CVE-2026-53266 · Linux Kernel Out-of-Bounds Write Vulnerability
    Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 20
    CVE-2025-39964 · Linux Kernel Race Condition Vulnerability
    Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 智谱股价涨超5% GLM-5.3海外走红
    【智谱股价涨超5% GLM-5.3海外走红】财联社10月5日电,智谱(02513.HK)港股涨幅扩大至超5%。消息面上,智谱旗下GLM系列模型近期接连获得海外认可,近日,AI编程工具Cursor宣布上线GLM-5.3及GLM-5.3-Flash,并表示,GLM-5.3在Max推理设置下,取得其自有编程评测CursorBench 4.0中开放权重模型的最高分。官方榜单显示,该模型得分为42.6%。此外,德国主权AI Aleph Alpha发布的新模型Kolibri,也披露了对GLM的使用。
  • 澳大利亚调查迪拜航空副驾驶与澳关联
    【澳大利亚调查迪拜航空副驾驶与澳关联】财联社10月5日电,澳大利亚警方发言人4日说,该国一个由多机构人员组成的反恐小组正调查迪拜航空FZ1073航班副驾驶与澳大利亚的关联。这名副驾驶日前在该航班驾驶舱内袭击机长,有消息称他曾在澳大利亚留学。这名警方发言人表示,这个联合反恐小组成员来自澳联邦警方、维多利亚州警方和澳大利亚安全情报局。
  • 美“艾森豪威尔”号航母将返美接受事故调查
    【美“艾森豪威尔”号航母将返美接受事故调查】财联社10月5日电,美国大西洋舰队海军航空部队当地时间10月2日发表声明说,因9月28日发生事故,美“艾森豪威尔”号航母将返回位于美国东海岸的弗吉尼亚州诺福克海军基地,对该舰的飞机起降设备进行检查和全面评估。声明说,事故原因仍在调查中,海军技术专家将在恢复飞行作业前完成必要的维护工作。据美国海军9月28日通报,在美国弗吉尼亚州海岸附近的“艾森豪威尔”号航母当天发生舰载机着舰事故,两名飞行员弹射逃生,另有4名舰上人员受伤。两名飞行员被搜救人员救起后安全返回舰上。
  • 德国宣布向乌克兰提供10亿欧元军事援助
    【德国宣布向乌克兰提供10亿欧元军事援助】财联社10月5日电,当地时间10月4日,德国总理默茨突访乌克兰首都基辅。在俄乌冲突即将迎来爆发后第五个冬天的关键时刻,默茨重申了德国对乌克兰“坚定不移”的支持。
  • 横琴口岸单日客流突破15万人次 创口岸启用以来新高
    【横琴口岸单日客流突破15万人次 创口岸启用以来新高】财联社10月5日电,从珠海边检总站横琴边检站了解到,10月4日,横琴口岸迎来国庆假期出入境客流峰值。据横琴边检站统计,当日口岸出入境客流突破15万人次,超越今年5月2日14.79万人次的单日最高纪录,较去年同期增长20%,刷新口岸启用以来单日客流历史新高,这也是口岸首次突破15万人次大关。今年以来,口岸单日客流已多次超14万人次,琴澳往来热度持续攀升。
  • 东盟与中日韩宏观经济研究办公室:区域整体仍表现稳健
    【东盟与中日韩宏观经济研究办公室:区域整体仍表现稳健】财联社10月5日电,东盟与中日韩宏观经济研究办公室当地时间5日正式发布《东盟与中日韩区域金融稳定报告(2026)》和《2026年东盟与中日韩区域经济展望》10月更新版。报告指出,尽管受到中东能源冲击的影响,区域整体表现仍然稳健。东盟与中日韩宏观经济研究办公室预计,2026年和2027年区域经济增长率均为4.1%,通胀率分别为1.6%和1.7%。人工智能相关出口和投资走强,为经济增长提供支撑,而能源价格上涨以及厄尔尼诺现象带来的食品价格压力可能推高通胀。此外,霍尔木兹海峡航运受阻推高了能源价格,并再度引发市场对全球通胀的担忧。报告指出,尽管面
  • 长三角铁路返程客流增多 今日预计发送旅客超380万人次
    【长三角铁路返程客流增多 今日预计发送旅客超380万人次】财联社10月5日电,从中国铁路上海局集团有限公司获悉,10月5日国庆假期第5天,长三角铁路返程客流增多,出行客流维持高位,当天预计发送旅客超380万人次。10月4日,上铁集团发送旅客375.5万人次。自9月23日中秋国庆假期运输启动以来,截至10月4日,长三角铁路累计发送旅客4098.9万人次,日均发送约341.6万人次,假期客流持续处于高位运行。
  • 天赐材料香港上市料筹资不超过5亿美元
    【天赐材料香港上市料筹资不超过5亿美元】财联社10月5日电,据报道,天赐材料已开始香港上市预推介,预计筹资约4亿至5亿美元。
  • 港股PCB股走强 建滔积层板涨超7%
    【港股PCB股走强 建滔积层板涨超7%】财联社10月5日电,截至发稿,建滔积层板(01888.HK)涨7.49%,建滔集团(00148.HK)涨7.04%,广合科技(01989.HK)涨5.68%。
  • 一汽丰田:“一汽丰田或将彻底退出历史舞台”等均为不实言论
    【一汽丰田:“一汽丰田或将彻底退出历史舞台”等均为不实言论】财联社10月5日电,一汽丰田汽车销售有限公司发布针对近期网络上出现的有关一汽丰田不实言论的声明称,近期,中国第一汽车集团有限公司与广州汽车工业集团有限公司签署战略合作框架协议,引发行业及消费者广泛关注。一汽丰田深耕国内市场23年,拥有成熟的产品矩阵、完备的产销售后体系和千万用户保有规模。目前全系车型产销、迭代规划均按计划有序推进,后续将依托集团合作的更大资源优势,持续创新,回馈广大用户信任。针对部分网络账号散布的“一汽丰田或将彻底退出历史舞台”“丰田大降价”等不实言论,我司保留法律追责权利。
  • 也门政府军宣布反攻胡塞武装
    【也门政府军宣布反攻胡塞武装】财联社10月5日电,也门政府军发言人马吉德·努扎伊利当地时间10月4日发表视频声明,宣布启动军事行动,以“收复国家全部领土、确立完整的国家主权”。努扎伊利还呼吁胡塞武装人员放下武器、停止战斗,称将对其予以赦免。当天稍早时候,也门行使总统职权的总统领导委员会主席拉沙德·阿里米在沙特阿拉伯首都利雅得宣布启动军事行动,以收复胡塞武装近期控制的地区。
  • 我国沙漠油田超深油气产量突破2600万吨
    【我国沙漠油田超深油气产量突破2600万吨】财联社10月5日电,今天从中国石油获悉,我国沙漠最大油田,哈得-富满油田已从6000米之下采出油气突破2600万吨。日前,位于塔克拉玛干沙漠北缘的震探1井,成功取出地下8080米深处的岩芯,这些岩芯已在地下沉睡约5亿年。这是我国首次在塔里木盆地西北缘8000米以深取出岩芯。
  • 财联社10月5日电,WTI原油期货从日内低点反弹至90美元/桶,最新报90.042美元/桶,日内下跌1.17%。
    WTI原油期货从日内低点反弹至90美元/桶,最新报90.042美元/桶,日内下跌1.17%。
  • 9月中国大宗商品价格指数环比上涨4.1%
    【9月中国大宗商品价格指数环比上涨4.1%】财联社10月5日电,中国物流与采购联合会今天(5日)公布9月份中国大宗商品价格指数。从指数运行情况看,随着传统生产建设旺季到来,重大项目加快落地,以及制造业生产和市场需求持续改善,大宗商品市场景气水平进一步提升,为四季度经济平稳运行奠定良好基础。9月份中国大宗商品价格指数为137.6点,环比上涨4.1%,同比上涨22.9%。在中国物流与采购联合会重点监测的50种大宗商品中,9月份价格环比上涨的大宗商品有38种。其中,甲醇、乙二醇和焦炭涨幅居前,环比分别上涨39.5%、24.8%和20.4%。
  • 港股光通信股走强 京信通信涨超7%
    【港股光通信股走强 京信通信涨超7%】财联社10月5日电,截至发稿,京信通信(02342.HK)涨7.53%,剑桥科技(06166.HK)涨3.37%,海光芯正(01191.HK)涨2.57%,俊知集团(01300.HK)涨2.10%。
  • 港股人工智能相关个股走强 深演智能涨近6%
    【港股人工智能相关个股走强 深演智能涨近6%】财联社10月5日电,截至发稿,深演智能(02723.HK)涨5.96%,智谱(02513.HK)涨3.67%,英矽智能(03696.HK)涨1.22%。
刚刚更新