<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>威胁情报 on 思安录 | Thinking&#39;s Security Notes</title>
    <link>https://blog.1sec.day/tags/%E5%A8%81%E8%83%81%E6%83%85%E6%8A%A5/</link>
    <description>Recent content in 威胁情报 on 思安录 | Thinking&#39;s Security Notes</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>zh-cn</language>
    <managingEditor>Thinking</managingEditor>
    <webMaster>Thinking</webMaster>
    <lastBuildDate>Wed, 15 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.1sec.day/tags/%E5%A8%81%E8%83%81%E6%83%85%E6%8A%A5/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Telegram 桌面端本地会话复用</title>
      <link>https://blog.1sec.day/posts/2026-07-15-telegram-desktop-local-session-reuse/</link>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/posts/2026-07-15-telegram-desktop-local-session-reuse/</guid>
      
      <description>&lt;blockquote&gt;
&lt;p&gt;导读：这个复现结果超出了我原本的认知。Telegram 的设备认证机制——手机号验证、短信验证码、二次验证密码——在我的理解里是设计完备的。但当 tdata 被复制到另一台 Mac 后启动客户端，登录界面没有出现。这不是 2FA 被破解了，而是整个复用过程根本没有触发需要验证的环节。&lt;/p&gt;
&lt;/blockquote&gt;</description>
      
    </item>
    
    <item>
      <title>伪装成热门项目的加密货币剪贴板劫持器：跨平台 Ghost Network 生态分析</title>
      <link>https://blog.1sec.day/posts/2026-07-16-fake-reputation-crypto-clipboard-hijacker/</link>
      <pubDate>Fri, 20 Jun 2025 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/posts/2026-07-16-fake-reputation-crypto-clipboard-hijacker/</guid>
      
      <description>&lt;blockquote&gt;
&lt;p&gt;导读：当 GitHub 的 Star、SourceForge 的下载量、YouTube 的播放量、VirusTotal 的&amp;quot;安全&amp;quot;投票全部可被伪造，&amp;ldquo;社会证明&amp;quot;这套信任机制本身就成了攻击面。Check Point 这份研究揭示了一个把恶意软件伪装成热门项目玩出花样的 Rust 剪贴板劫持器 campaign，值得每一位安全从业者关注。&lt;/p&gt;
&lt;/blockquote&gt;</description>
      
    </item>
    
    <item>
      <title>Lazarus Group 针对加密货币交易所的 APT 攻击：IOC 与 TTP 披露</title>
      <link>https://blog.1sec.day/posts/2025-02-23-lazarus-apt-attack/</link>
      <pubDate>Sun, 23 Feb 2025 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/posts/2025-02-23-lazarus-apt-attack/</guid>
      
      <description>&lt;blockquote&gt;
&lt;p&gt;网络安全对抗是一场持久战。本文由我（Thinking）与山哥（23pds）联合撰写。&lt;/p&gt;
&lt;/blockquote&gt;</description>
      
    </item>
    
    <item>
      <title>虚假 Aggr Chrome 扩展盗币分析：Cookie 窃取与对敲攻击</title>
      <link>https://blog.1sec.day/posts/2024-05-31-aggr-malicious-chrome-extension/</link>
      <pubDate>Fri, 31 May 2024 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/posts/2024-05-31-aggr-malicious-chrome-extension/</guid>
      
      <description></description>
      
    </item>
    
    <item>
      <title>Celer Network cBridge 跨链桥事故分析：BGP 劫持攻击</title>
      <link>https://blog.1sec.day/posts/2022-08-20-celer-network-bgp-hijacking/</link>
      <pubDate>Sat, 20 Aug 2022 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/posts/2022-08-20-celer-network-bgp-hijacking/</guid>
      
      <description></description>
      
    </item>
    
    <item>
      <title>Solana 公链大规模盗币事件分析：Slope Wallet Sentry 泄露助记词</title>
      <link>https://blog.1sec.day/posts/2022-08-04-solana-massive-theft/</link>
      <pubDate>Thu, 04 Aug 2022 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/posts/2022-08-04-solana-massive-theft/</guid>
      
      <description></description>
      
    </item>
    
    <item>
      <title>Discord 私信钓鱼手法分析</title>
      <link>https://blog.1sec.day/posts/2022-05-17-discord-phishing-analysis/</link>
      <pubDate>Tue, 17 May 2022 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/posts/2022-05-17-discord-phishing-analysis/</guid>
      
      <description></description>
      
    </item>
    
  </channel>
</rss>
