<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>风险预警 | 今天abc看了啥🤔</title><description>现在我也不知道这频道发了啥了，各位慢慢吃瓜，将就着看联系我请去 @abc1763613206友链儿@cyberElaina@rvalue_daily@billchenla</description><link>https://channel.0w0.best</link><item><title>#风险预警本频道从多信源整理, PVE WebUI 近期极有可能已出现严重 RCE 0day 安全漏洞 (并已出现在野利用报告)，从 PVE7 (已 EOL, 建议立即更新) 到 PVE8 (已知报告版本: 8.0.3 / 8.2 / 8.4) 全系列均已被攻破，可绕过身份验证</title><link>https://channel.0w0.best/posts/7693</link><guid isPermaLink="true">https://channel.0w0.best/posts/7693</guid><pubDate>Tue, 01 Sep 2026 00:15:12 GMT</pubDate><content:encoded>&lt;div class=&quot;tgme_widget_message_forwarded_from accent_color&quot;&gt;Forwarded from &lt;a class=&quot;tgme_widget_message_forwarded_from_name&quot; href=&quot;https://t.me/hatschannel/6148&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;&lt;span&gt;HAT&apos;s Public Channel | &lt;i class=&quot;emoji&quot; style=&quot;background-image:url(&apos;//telegram.org/img/emoji/40/F09FABAA.png&apos;)&quot;&gt;&lt;b&gt;🫪&lt;/b&gt;&lt;/i&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;a href=&quot;/search/result?q=%23%E9%A3%8E%E9%99%A9%E9%A2%84%E8%AD%A6&quot; title=&quot;#风险预警&quot;&gt;#风险预警&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;本频道从多信源整理, PVE WebUI 近期极有可能已出现严重 RCE 0day 安全漏洞 (并已出现在野利用报告)，从 PVE7 (已 EOL, 建议立即更新) 到 PVE8 (已知报告版本: 8.0.3 / 8.2 / 8.4) 全系列均已被攻破，可绕过身份验证。&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;操作建议:&lt;br /&gt;&lt;br /&gt;1) 立即停止将任何 PVE WebUI / WebAPI (8006) / SSH 直接暴露公网；&lt;br /&gt;2) 如一定需要暴露公网，也尽可能利用 VPN (e.g. Tailscale)  / SD-WAN / Cloudflare Zero-Trust (One) 为 PVE WebUI 增加二层防护 (或者最简单的: 加个 basic auth)；在 sshd config 中也禁止使用密码登录；&lt;br /&gt;3) 哪怕 PVE 仅部署在内网，也请配置好 IP-ACL Rule；&lt;br /&gt;4) PVE &amp;lt;=8 已正式 EOL，无论如何都请更新到 PVE 9；&lt;br /&gt;5) 非常建议 PVE9 也采取以上安全措施建议；&lt;br /&gt;6) 近期在运维时需要投入更多精力关注 PVE 相关补丁更新。&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;refs: &lt;a href=&quot;https://forum.proxmox.com/threads/proxmox-ve-7-is-vulnerable-to-some-type-of-0day-rce-non-auth.186078/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; title=&quot;PVE7 report&quot;&gt;PVE7 report&lt;/a&gt; | &lt;a href=&quot;https://forum.proxmox.com/threads/proxmox-ve-7-is-vulnerable-to-some-type-of-0day-rce-non-auth.186078/#post-867820&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; title=&quot;PVE 8.0.3/8.2/8.4 report&quot;&gt;PVE 8.0.3/8.2/8.4 report&lt;/a&gt;&lt;a class=&quot;tgme_widget_message_link_preview&quot; href=&quot;https://forum.proxmox.com/threads/proxmox-ve-7-is-vulnerable-to-some-type-of-0day-rce-non-auth.186078&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; title=&quot;Two days ago, my Proxmox VE 7 installation, which was over four years old with the latest updates available up to EOL and only one user (root), was encrypted, and a ransom was demanded for...&quot;&gt;
  &lt;i class=&quot;link_preview_right_image&quot; style=&quot;background-image:url(&apos;https://cdn4.telesco.pe/file/L0JMLAAIb2BP4a91nqnpW7iOa3Z6Ftm16QfEpApDdbZyavv51fVEc4tuGhflxBFOPKKVyPYz30xjp7rTqQW4oZ2L9tHPIMHVxqwa2JZX2LnVUzVaiuD-8TojL3_iu5AYF7HPW_IDSJkdfXvYY80yXG5LjDRVK_BnStxPVyCs5op6mmzWWyOXfI5AdQtTLUNEnv2B6RRTWkSgvY8tiParEXxhqRjctV2gK7lCOoRv_HdVpppho6FTuEFAdPvyzkSyp9-Phk52pqLRKvqSh7gu7n-XhH95uytNF21_xozgQ3UIWz3g3dr198Fr5wjE6M0WHQ5xxFFEvV3MPVtaSvutjw.jpg&apos;)&quot;&gt;&lt;/i&gt;
  &lt;div class=&quot;link_preview_site_name accent_color&quot;&gt;Proxmox Support Forum&lt;/div&gt;
  
  &lt;div class=&quot;link_preview_title&quot;&gt;Proxmox VE 7 is vulnerable to some type of 0day/RCE non auth&lt;/div&gt;
  &lt;div class=&quot;link_preview_description&quot;&gt;Two days ago, my Proxmox VE 7 installation, which was over four years old with the latest updates available up to EOL and only one user (root), was encrypted, and a ransom was demanded for...&lt;/div&gt;
&lt;/a&gt;</content:encoded></item><item><link>https://channel.0w0.best/posts/5532</link><guid isPermaLink="true">https://channel.0w0.best/posts/5532</guid><pubDate>Sat, 14 Sep 2024 12:57:25 GMT</pubDate><content:encoded>&lt;a href=&quot;https://fixupx.com/0xcf1/status/1834915727662288975&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; title=&quot;https://fixupx.com/0xcf1/status/1834915727662288975&quot;&gt;https://fixupx.com/0xcf1/status/1834915727662288975&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;https://t.me/illusory_world/5252&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; title=&quot;https://t.me/illusory_world/5252&quot;&gt;https://t.me/illusory_world/5252&lt;/a&gt;&lt;a class=&quot;tgme_widget_message_link_preview&quot; href=&quot;https://fixupx.com/0xcf1/status/1834915727662288975&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; title=&quot;Sorry, that post doesn&apos;t exist :(&quot;&gt;
  
  &lt;div class=&quot;link_preview_site_name accent_color&quot;&gt;Fixupx&lt;/div&gt;
  
  &lt;div class=&quot;link_preview_title&quot;&gt;FxTwitter / FixupX&lt;/div&gt;
  &lt;div class=&quot;link_preview_description&quot;&gt;Sorry, that post doesn&apos;t exist :(&lt;/div&gt;
&lt;/a&gt;</content:encoded></item></channel></rss>