<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	 xmlns:media="http://search.yahoo.com/mrss/" >

<channel>
	<title>开源 &#8211; PSA.NGO</title>
	<atom:link href="https://psa.ngo/news/category/open-source/feed/" rel="self" type="application/rss+xml" />
	<link>https://psa.ngo</link>
	<description>关注数字隐私、信息安全、知识可及性</description>
	<lastBuildDate>Fri, 12 Jun 2026 19:11:25 +0000</lastBuildDate>
	<language>zh-Hans</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://psa.ngo/wp-content/uploads/2024/07/PSA-icon-150x150.png</url>
	<title>开源 &#8211; PSA.NGO</title>
	<link>https://psa.ngo</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>GitHub公布npm安全调整，瞄准软件供应链风险</title>
		<link>https://psa.ngo/news/github-npm-security-changes-supply-chain-attacks/</link>
		
		<dc:creator><![CDATA[psa]]></dc:creator>
		<pubDate>Fri, 12 Jun 2026 19:11:25 +0000</pubDate>
				<category><![CDATA[信息安全]]></category>
		<category><![CDATA[开源]]></category>
		<category><![CDATA[科技公司]]></category>
		<guid isPermaLink="false">https://psa.ngo/news/github-npm-security-changes-supply-chain-attacks/</guid>

					<description><![CDATA[据安全媒体报道，GitHub宣布将对npm实施一系列安全调整，以应对不断增加的供应链攻击风险，强化JavaSc [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>据安全媒体报道，<a href="https://www.bleepingcomputer.com/news/security/github-announces-npm-security-changes-to-tackle-supply-chain-attacks/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">GitHub宣布将对npm实施一系列安全调整<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a>，以应对不断增加的供应链攻击风险，强化JavaScript生态的包管理与发布流程安全。</p>
<p>报道指出，此举旨在降低依赖被投毒、账号被盗用等带来的传播风险；更多实施细节与时间表尚待进一步披露，相关变更预计将影响开发者的发布与依赖管理实践。</p>
<p><a href="https://www.bleepingcomputer.com/news/security/github-announces-npm-security-changes-to-tackle-supply-chain-attacks/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">来源<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>macOS 27测试版调整引导检测：Asahi Linux在Apple Silicon上暂被“隐身”</title>
		<link>https://psa.ngo/news/macos-27-beta-hides-asahi-linux-on-apple-silicon/</link>
		
		<dc:creator><![CDATA[psa]]></dc:creator>
		<pubDate>Fri, 12 Jun 2026 19:11:25 +0000</pubDate>
				<category><![CDATA[开源]]></category>
		<category><![CDATA[科技公司]]></category>
		<guid isPermaLink="false">https://psa.ngo/news/macos-27-beta-hides-asahi-linux-on-apple-silicon/</guid>

					<description><![CDATA[Apple于本周WWDC发布的macOS 27测试版，因更改了启动管理器和“启动磁盘”对可引导系统卷的识别方式 [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Apple于本周WWDC发布的macOS 27测试版，因更改了启动管理器和“启动磁盘”对可引导系统卷的识别方式，导致Asahi Linux分区在Apple Silicon设备上不再显示，用户暂时无法从该分区引导Linux。相关变化由Asahi Linux团队披露，并提醒用户留意影响<a href="https://www.theregister.com/os-platforms/2026/06/10/macos-27-beta-boots-asahi-linux-off-apple-silicon/5253587" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">细节与风险<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a>。</p>
<p>团队建议Asahi Linux用户暂勿升级至macOS 27测试版；若必须尝鲜，应先在次要卷安装一份macOS 26，或将macOS 27安装到次要卷，以保留可回退的稳定系统。Asahi Linux安装器已临时阻止在macOS 27上执行安装；对于未保留稳定版macOS便直接安装测试版的用户，团队表示将不提供支持。</p>
<p>Asahi Linux称已向Apple提交错误报告，并判断此问题更可能是测试版阶段的意外变动而非刻意封堵。已升级测试版且发现Asahi分区“消失”的用户无需恐慌——分区仍在，数据未丢失。尽管项目今年经历人事波动，Asahi Linux仍持续推进对Apple Silicon的适配，4月发布了Fedora Asahi Remix 44，此次状况被形容为“路上的小坎”，并非终点。</p>
<p><a href="https://www.theregister.com/os-platforms/2026/06/10/macos-27-beta-boots-asahi-linux-off-apple-silicon/5253587" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">来源<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Linux曝“CIFSwitch”漏洞：多发行版或遭本地提权至root</title>
		<link>https://psa.ngo/news/cifswitch-linux-flaw-root-multiple-distributions/</link>
		
		<dc:creator><![CDATA[psa]]></dc:creator>
		<pubDate>Sun, 31 May 2026 16:11:18 +0000</pubDate>
				<category><![CDATA[信息安全]]></category>
		<category><![CDATA[开源]]></category>
		<guid isPermaLink="false">https://psa.ngo/news/cifswitch-linux-flaw-root-multiple-distributions/</guid>

					<description><![CDATA[据BleepingComputer报道，安全研究人员披露名为“CIFSwitch”的Linux安全缺陷，攻击者 [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>据<a href="https://www.bleepingcomputer.com/news/security/new-cifswitch-linux-flaw-gives-root-on-multiple-distributions/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">BleepingComputer<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a>报道，安全研究人员披露名为“CIFSwitch”的Linux安全缺陷，攻击者可在多款发行版上将权限提升至root。本次披露称其影响范围跨发行版，但目前公开材料未提供进一步技术细节。</p>
<p>截至发稿，尚无明确的CVE编号、受影响版本清单或官方修复时间表。业内建议在更多信息发布前，关注各发行版安全公告，及时应用更新，并限制不受信任的本地访问与代码执行，作为通用的风险缓解措施。</p>
<p><a href="https://www.bleepingcomputer.com/news/security/new-cifswitch-linux-flaw-gives-root-on-multiple-distributions/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">来源<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Apache ActiveMQ曝在野漏洞 约6,400台服务器受波及</title>
		<link>https://psa.ngo/news/apache-activemq-flaw-actively-exploited-impacts-6400-servers/</link>
		
		<dc:creator><![CDATA[psa]]></dc:creator>
		<pubDate>Wed, 22 Apr 2026 16:12:00 +0000</pubDate>
				<category><![CDATA[信息安全]]></category>
		<category><![CDATA[开源]]></category>
		<guid isPermaLink="false">https://psa.ngo/news/apache-activemq-flaw-actively-exploited-impacts-6400-servers/</guid>

					<description><![CDATA[据BleepingComputer报道称，Apache ActiveMQ被披露存在一处正遭到攻击者利用的安全漏 [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>据<a href="https://www.bleepingcomputer.com/news/security/actively-exploited-apache-activemq-flaw-impacts-6-400-servers/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">BleepingComputer报道称<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a>，Apache ActiveMQ被披露存在一处正遭到攻击者利用的安全漏洞，互联网测量显示约有6,400台对外可见的服务器可能受影响。报道提示相关风险正在进行中。</p>
<p>业界建议使用ActiveMQ的组织尽快评估资产暴露面，关注官方通报与更新，及时修补；在无法立即升级的情况下，临时收紧对外访问、仅开放必要服务，并加强异常流量与进程行为监测，以降低被入侵风险。</p>
<p><a href="https://www.bleepingcomputer.com/news/security/actively-exploited-apache-activemq-flaw-impacts-6-400-servers/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">来源<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Betterleaks亮相：开源密钥扫描工具瞄准Gitleaks替代位</title>
		<link>https://psa.ngo/news/betterleaks-open-source-secrets-scanner-aims-to-replace-gitleaks/</link>
		
		<dc:creator><![CDATA[psa]]></dc:creator>
		<pubDate>Wed, 18 Mar 2026 01:11:25 +0000</pubDate>
				<category><![CDATA[信息安全]]></category>
		<category><![CDATA[开源]]></category>
		<guid isPermaLink="false">https://psa.ngo/news/betterleaks-open-source-secrets-scanner-aims-to-replace-gitleaks/</guid>

					<description><![CDATA[据BleepingComputer报道，开源“secrets scanner”工具Betterleaks近期发 [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>据<a href="https://www.bleepingcomputer.com/news/security/betterleaks-a-new-open-source-secrets-scanner-to-replace-gitleaks/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">BleepingComputer<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a>报道，开源“secrets scanner”工具Betterleaks近期发布，定位为Gitleaks的替代方案。该项目聚焦在代码与版本库场景下发现潜在敏感信息泄露风险。 </p>
<p>目前公开报道对Betterleaks的技术细节、维护方与发布时间等关键信息披露有限，工具规则覆盖范围、集成方式及成熟度仍有待进一步验证。业内人士提醒，在将此类扫描器纳入流程前，应结合自身合规与CI/CD需求进行评估。</p>
<p><a href="https://www.bleepingcomputer.com/news/security/betterleaks-a-new-open-source-secrets-scanner-to-replace-gitleaks/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">来源<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Bing AI被指引流至伪冒OpenClaw仓库 诱导下载信息窃取恶意软件</title>
		<link>https://psa.ngo/news/bing-ai-promotes-fake-openclaw-github-repo-malware/</link>
		
		<dc:creator><![CDATA[psa]]></dc:creator>
		<pubDate>Sat, 07 Mar 2026 14:11:37 +0000</pubDate>
				<category><![CDATA[信息安全]]></category>
		<category><![CDATA[开源]]></category>
		<category><![CDATA[科技公司]]></category>
		<guid isPermaLink="false">https://psa.ngo/news/bing-ai-promotes-fake-openclaw-github-repo-malware/</guid>

					<description><![CDATA[据BleepingComputer报道，Bing AI在推荐结果中推广了一个伪造的GitHub仓库，该仓库冒充 [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>据<a href="https://www.bleepingcomputer.com/news/security/bing-ai-promoted-fake-openclaw-github-repo-pushing-info-stealing-malware/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">BleepingComputer报道<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a>，Bing AI在推荐结果中推广了一个伪造的GitHub仓库，该仓库冒充“OpenClaw”，实际则分发信息窃取型恶意软件，存在诱导用户下载执行的安全风险。</p>
<p>这一事件再次暴露出AI生成与聚合推荐在安全上的薄弱环节：攻击者通过仿冒热门开源项目来获取信任与流量。安全人士建议用户核验仓库归属、审查提交与发布历史，并避免未经验证地运行安装脚本或二进制文件。</p>
<p>目前公开报道对技术细节与处置进展披露有限，相关平台的响应与后续整治情况仍有待进一步确认。</p>
<p><a href="https://www.bleepingcomputer.com/news/security/bing-ai-promoted-fake-openclaw-github-repo-pushing-info-stealing-malware/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">来源<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>安装量近90万的WordPress插件曝出严重RCE风险</title>
		<link>https://psa.ngo/news/wordpress-plugin-900k-installs-critical-rce-risk/</link>
		
		<dc:creator><![CDATA[psa]]></dc:creator>
		<pubDate>Fri, 13 Feb 2026 07:11:45 +0000</pubDate>
				<category><![CDATA[信息安全]]></category>
		<category><![CDATA[开源]]></category>
		<guid isPermaLink="false">https://psa.ngo/news/wordpress-plugin-900k-installs-critical-rce-risk/</guid>

					<description><![CDATA[据安全媒体报道，一款安装量约90万的WordPress插件被披露存在严重远程代码执行（RCE）漏洞，攻击者可能 [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>据<a href="https://www.bleepingcomputer.com/news/security/wordpress-plugin-with-900k-installs-vulnerable-to-critical-rce-flaw/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">安全媒体报道<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a>，一款安装量约90万的WordPress插件被披露存在严重远程代码执行（RCE）漏洞，攻击者可能在未授权情况下在受影响站点上执行任意代码，带来网站被接管、数据泄露与植入恶意程序等高风险。</p>
<p>目前外界可获信息有限，报道节选中未披露涉及的具体插件名称、受影响版本区间与修复状态。为降低潜在风险，网站管理员应密切关注插件开发者与WordPress插件目录的公告，尽快获取补丁；在无法立即修复时，可评估临时停用相关插件、收紧后台账户权限并启用WAF/入侵检测以降低攻击面。</p>
<p><a href="https://www.bleepingcomputer.com/news/security/wordpress-plugin-with-900k-installs-vulnerable-to-critical-rce-flaw/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">来源<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>n8n曝新型沙箱逃逸漏洞 公开实例恐遭远程代码执行</title>
		<link>https://psa.ngo/news/n8n-sandbox-escape-rce/</link>
		
		<dc:creator><![CDATA[psa]]></dc:creator>
		<pubDate>Thu, 29 Jan 2026 11:11:34 +0000</pubDate>
				<category><![CDATA[信息安全]]></category>
		<category><![CDATA[开源]]></category>
		<guid isPermaLink="false">https://psa.ngo/news/n8n-sandbox-escape-rce/</guid>

					<description><![CDATA[据BleepingComputer报道，安全研究披露一项影响 n8n 的新型沙箱逃逸漏洞，可能使暴露在互联网上 [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>据<a href="https://www.bleepingcomputer.com/news/security/new-sandbox-escape-flaw-exposes-n8n-instances-to-rce-attacks/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">BleepingComputer<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a>报道，安全研究披露一项影响 n8n 的新型沙箱逃逸漏洞，可能使暴露在互联网上的实例遭受远程代码执行（RCE）攻击。攻击者一旦得手，或可在受影响服务器上执行任意指令，进而危及业务流程与数据安全。</p>
<p>n8n是广泛用于自动化编排与集成的开源工具，常以自托管方式部署。报道提醒，未经良好访问控制的公开实例风险尤甚，运营方应尽快评估暴露面与潜在影响。</p>
<p>安全专家建议，及时关注官方修复与公告，更新至可用的安全版本；同时收紧网络暴露面和鉴权策略（如启用强身份验证、限制来源IP、隔离高风险节点），并审计执行日志以发现可疑行为。</p>
<p><a href="https://www.bleepingcomputer.com/news/security/new-sandbox-escape-flaw-exposes-n8n-instances-to-rce-attacks/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">来源<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Chainlit框架曝安全缺陷 或被利用渗透云环境</title>
		<link>https://psa.ngo/news/chainlit-ai-framework-vulns-cloud-breach/</link>
		
		<dc:creator><![CDATA[psa]]></dc:creator>
		<pubDate>Thu, 22 Jan 2026 16:11:10 +0000</pubDate>
				<category><![CDATA[信息安全]]></category>
		<category><![CDATA[开源]]></category>
		<guid isPermaLink="false">https://psa.ngo/news/chainlit-ai-framework-vulns-cloud-breach/</guid>

					<description><![CDATA[据BleepingComputer的报道，用于构建AI应用的Chainlit框架被曝存在多处缺陷，攻击者可能借 [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>据<a href="https://www.bleepingcomputer.com/news/security/chainlit-ai-framework-bugs-let-hackers-breach-cloud-environments/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">BleepingComputer的报道<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a>，用于构建AI应用的Chainlit框架被曝存在多处缺陷，攻击者可能借此突破防线并获取云环境访问权限。报道指向的问题聚焦于框架在特定条件下的安全暴露，可能为入侵云资源打开通道。</p>
<p>目前公开信息未披露漏洞技术细节、影响版本与修复进展。安全专家建议相关使用方密切关注项目与云服务商公告，审查云访问密钥与权限配置，并在不影响业务的前提下实施最小权限与日志审计等加固措施。</p>
<p><a href="https://www.bleepingcomputer.com/news/security/chainlit-ai-framework-bugs-let-hackers-breach-cloud-environments/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">来源<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>GitLab警示高危2FA绕过与拒绝服务漏洞，呼吁尽快修补</title>
		<link>https://psa.ngo/news/gitlab-high-severity-2fa-bypass-dos-flaws-warning/</link>
		
		<dc:creator><![CDATA[psa]]></dc:creator>
		<pubDate>Thu, 22 Jan 2026 05:11:18 +0000</pubDate>
				<category><![CDATA[信息安全]]></category>
		<category><![CDATA[开源]]></category>
		<category><![CDATA[科技公司]]></category>
		<guid isPermaLink="false">https://psa.ngo/news/gitlab-high-severity-2fa-bypass-dos-flaws-warning/</guid>

					<description><![CDATA[安全媒体报道称，GitLab发布安全警告，披露高严重度问题，涉及双重身份验证（2FA）可被绕过以及可能导致服务 [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>安全媒体<a href="https://www.bleepingcomputer.com/news/security/gitlab-warns-of-high-severity-2fa-bypass-denial-of-service-flaws/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">报道称<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a>，GitLab发布安全警告，披露高严重度问题，涉及双重身份验证（2FA）可被绕过以及可能导致服务中断的拒绝服务（DoS）缺陷。报道称，这些漏洞风险较高，可能影响账户防护与服务可用性。</p>
<p>GitLab建议用户和管理员尽快升级至受支持的最新版本，并依据官方指南实施缓解与修补措施，以降低被攻击面与潜在业务中断风险。相关技术细节、受影响范围与补丁信息以官方发布与后续通告为准。</p>
<p><a href="https://www.bleepingcomputer.com/news/security/gitlab-warns-of-high-severity-2fa-bypass-denial-of-service-flaws/" rel="noopener nofollow external noreferrer" target="_blank" data-wpel-link="external" class="wpel-icon-right">来源<i class="wpel-icon dashicons-before dashicons-external" aria-hidden="true"></i></a></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
