{
  "version": "https://jsonfeed.org/version/1.1",
  "title": ".安全 · tldlog",
  "home_page_url": "https://tldlog.com/zh/s/anquan/",
  "feed_url": "https://tldlog.com/zh/s/anquan/feed.json",
  "description": "域名和DNS面临的安全威胁：漏洞、DNSSEC、DNS滥用、网络钓鱼、域名劫持，以及注册管理机构和注册服务机构的安全事件。",
  "language": "zh-Hans",
  "items": [
    {
      "id": "https://tldlog.com/zh/l/rare-cyrillic-latin-letters-let-attackers-spoof-urls/",
      "url": "https://tldlog.com/zh/l/rare-cyrillic-latin-letters-let-attackers-spoof-urls/",
      "external_url": "https://www.theregister.com/security/2026/10/10/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers/5302383?utm_source=tldlog.com&utm_medium=referral",
      "title": "罕见西里尔和拉丁字母可在Chromium浏览器中伪造网址",
      "content_html": "<p>Have I Been Squatted公司的研究人员Ian Muscat和Leanne Briffa发现，两个罕见字符——西里尔字母带杠o和带钩拉丁字母K——可绕过Chromium的反仿冒检测，使仿冒域名显示为可信品牌名称。</p><p>来源： <a href=\"https://www.theregister.com/security/2026/10/10/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers/5302383?utm_source=tldlog.com&amp;utm_medium=referral\">theregister.com</a></p>",
      "summary": "Have I Been Squatted公司的研究人员Ian Muscat和Leanne Briffa发现，两个罕见字符——西里尔字母带杠o和带钩拉丁字母K——可绕过Chromium的反仿冒检测，使仿冒域名显示为可信品牌名称。",
      "date_published": "2026-10-11T14:01:28Z",
      "date_modified": "2026-10-11T14:01:28Z",
      "tags": [
        ".安全"
      ],
      "language": "zh-Hans"
    },
    {
      "id": "https://tldlog.com/zh/l/icann-dnssec-genyaoshi-lunzhuan/",
      "url": "https://tldlog.com/zh/l/icann-dnssec-genyaoshi-lunzhuan/",
      "external_url": "https://www.icann.org/resources/pages/ksk-rollover-en?utm_source=tldlog.com&utm_medium=referral",
      "title": "ICANN提醒解析器运营商在密钥轮转前检查新DNSSEC根密钥",
      "content_html": "<p>ICANN已敦促DNSSEC验证解析器的运营商在2026年10月11日的根区密钥轮转之前，确认其信任锚配置中已包含Key Tag为38696的KSK-2024。</p><p>来源： <a href=\"https://www.icann.org/resources/pages/ksk-rollover-en?utm_source=tldlog.com&amp;utm_medium=referral\">icann.org</a></p>",
      "summary": "ICANN已敦促DNSSEC验证解析器的运营商在2026年10月11日的根区密钥轮转之前，确认其信任锚配置中已包含Key Tag为38696的KSK-2024。",
      "date_published": "2026-10-11T07:26:48Z",
      "date_modified": "2026-10-11T15:35:47Z",
      "tags": [
        ".安全"
      ],
      "language": "zh-Hans"
    },
    {
      "id": "https://tldlog.com/zh/l/gobalance-loudong-onion-xianzhi/",
      "url": "https://tldlog.com/zh/l/gobalance-loudong-onion-xianzhi/",
      "external_url": "https://thehackernews.com/2026/10/gobalance-flaw-lets-attackers-hijack.html?m=1&utm_source=tldlog.com&utm_medium=referral",
      "title": "GoBalance漏洞致Tor .onion地址被劫持",
      "content_html": "<p>Searchlight Cyber披露暗网站点常用负载均衡工具GoBalance存在缺陷，攻击者可借公开数据还原站点私钥并劫持其.onion地址，Dread论坛即因此遭劫持。</p><p>来源： <a href=\"https://thehackernews.com/2026/10/gobalance-flaw-lets-attackers-hijack.html?m=1&amp;utm_source=tldlog.com&amp;utm_medium=referral\">thehackernews.com</a></p>",
      "summary": "Searchlight Cyber披露暗网站点常用负载均衡工具GoBalance存在缺陷，攻击者可借公开数据还原站点私钥并劫持其.onion地址，Dread论坛即因此遭劫持。",
      "date_published": "2026-10-10T22:55:43Z",
      "date_modified": "2026-10-10T22:55:43Z",
      "tags": [
        ".安全"
      ],
      "language": "zh-Hans"
    }
  ]
}
