Aggregator
书生大模型实战营闯关 第二关:Python 基础知识
2 months 2 weeks ago
'CrossBarking' Attack Targeted Secret APIs, Exposing Opera Browser Users
2 months 2 weeks ago
Using a malicious Chrome extension, researchers showed how an attacker could use a now-fixed bug to inject custom code into a victim's Opera browser to exploit special and powerful APIs, used by developers and typically saved for only the most trusted sites.
Nate Nelson, Contributing Writer
Взломай и заработай: «Афиша» превращает хакеров в союзников
2 months 2 weeks ago
Компания запускает программу Bug Bounty для поиска уязвимостей.
CVE-2017-2473 | Apple macOS up to 10.12.3 Kernel memory corruption (HT207615 / EDB-41792)
2 months 2 weeks ago
A vulnerability classified as critical has been found in Apple macOS up to 10.12.3. This affects an unknown part of the component Kernel. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2017-2473. It is possible to launch the attack on the local host. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Opera Browser Fixes Big Security Hole That Could Have Exposed Your Information
2 months 2 weeks ago
A now-patched security flaw in the Opera web browser could have enabled a malicious extension to gain unauthorized, full access to private APIs.
The attack, codenamed CrossBarking, could have made it possible to conduct actions such as capturing screenshots, modifying browser settings, and account hijacking, Guardio Labs said.
To demonstrate the issue, the company said it managed to publish a
The Hacker News
Product showcase: Shift API security left with StackHawk
2 months 2 weeks ago
With the proliferation of APIs, and the speed at which AI functionality is helping fuel innovation, a strategic approach for securing APIs is no longer a nice to have, it’s a criticality. Without a proactive approach, your APIs could become easy targets for attackers. StackHawk is here to flip the script by offering a proactive, Shift-left API security solution that helps organizations secure their APIs from the start, not after it’s too late. StackHawk’s platform … More →
The post Product showcase: Shift API security left with StackHawk appeared first on Help Net Security.
Help Net Security
malloc_init_state_attack
2 months 2 weeks ago
malloc_init_state_attack
jndi +反序列化攻击绕过 jdk 限制技术学习
2 months 2 weeks ago
jndi +反序列化攻击绕过 jdk 限制技术学习
0xGame-week3-pwn解析
2 months 2 weeks ago
0xGame-week3-pwn解析
2024源鲁杯 [Final] WEB
2 months 2 weeks ago
2024源鲁杯 [Final] WEB
DASCTF 2024 十月挑战赛
2 months 2 weeks ago
DASCTF 2024 十月挑战赛
2024BuildCTF week2 WEB
2 months 2 weeks ago
2024BuildCTF week2 WEB
2024BuildCTF公开赛-Misc&Crypto方向WriteUp详解
2 months 2 weeks ago
2024BuildCTF公开赛-Misc&Crypto方向WriteUp详解
2024BuildCTF-WEB全解
2 months 2 weeks ago
2024BuildCTF-WEB全解
2024BuildCTF-MISC全解
2 months 2 weeks ago
2024BuildCTF-MISC全解
2024BulidCTF-逆向部分题解
2 months 2 weeks ago
2024BulidCTF-逆向部分题解
Jinja2-SSTI 新回显方式技术学习
2 months 2 weeks ago
Jinja2-SSTI 新回显方式技术学习
2024年NSSCTF秋季招新赛(校外赛道) Crypto
2 months 2 weeks ago
2024年NSSCTF秋季招新赛(校外赛道) Crypto
Over Half of US County Websites “Could Be Spoofed”
2 months 2 weeks ago
Comparitech warns that voters could be misled as most local government sites are failing on basic security