Aggregator
STRIDE GPT:AI 驱动的威胁建模,筑牢应用安全防线
1 year ago
安全客
IBM security advisory (AV25-209)
1 year ago
Canadian Centre for Cyber Security
Linux Terminal Shortcuts
1 year ago
Linux Terminal Shortcuts
Dark Web Informer - Cyber Threat Intelligence
Dell security advisory (AV25-208)
1 year ago
Canadian Centre for Cyber Security
ResolverRAT Campaign Targets Healthcare, Pharma via Phishing and DLL Side-Loading
1 year ago
Cybersecurity researchers have discovered a new, sophisticated remote access trojan called ResolverRAT that has been observed in attacks targeting healthcare and pharmaceutical sectors.
"The threat actor leverages fear-based lures delivered via phishing emails, designed to pressure recipients into clicking a malicious link," Morphisec Labs researcher Nadav Lorber said in a report shared with The
The Hacker News
警惕!TROX Stealer 利用社会工程学实施数据盗窃
1 year ago
安全客
Akira
1 year ago
cohenido
Waiting Thread Hijacking: A Stealthier Version of Thread Execution Hijacking
1 year ago
Research by: hasherezade Key Points Introduction Process injection is one of the important techniques used by attackers. We can find its variants implemented in almost every malware. It serves purposes such as: In our previous blog on process injections we explained the foundations of this topic and basic ideas behind detection and prevention. We also proposed a new technique dubbed Thread […]
The post Waiting Thread Hijacking: A Stealthier Version of Thread Execution Hijacking appeared first on Check Point Research.
SecWiki News 2025-04-14 Review
1 year ago
SecWiki周刊(第580期) by ourren
OneEval:大模型知识增强综合能力评测榜单 by ourren
Awesome-NTA: awesome papers, datasets and tools about network traffic analysis by ourren
更多最新文章,请访问SecWiki
OneEval:大模型知识增强综合能力评测榜单 by ourren
Awesome-NTA: awesome papers, datasets and tools about network traffic analysis by ourren
更多最新文章,请访问SecWiki
[Control systems] CISA ICS security advisories (AV25–207)
1 year ago
Canadian Centre for Cyber Security
Ubuntu security advisory (AV25-206)
1 year ago
Canadian Centre for Cyber Security
Tycoon 2FA 网络钓鱼工具包升级,终端防护面临挑战
1 year ago
安全客
辟谣!
1 year ago
正文昨天在开bp测试的时候,突然看到一个令人吃惊的消息:GitHub 疑似屏蔽了所有中国 IP 的访问。
HelloKitty 勒索软件重现,Windows、Linux 和 ESXi 环境安全告急
1 year ago
安全客
Meta to resume AI training on content shared by Europeans
1 year ago
Meta announced today that it will soon start training its artificial intelligence models using content shared by European adult users on its Facebook and Instagram social media platforms. [...]
Sergiu Gatlan
21% of security teams train just once a year—here’s how to fix that
1 year ago
In this blog, we'll explore the main reasons why security teams fall behind, what you can do to fix it, and how to build a culture of continuous learning.
The 'paste and run' phenomenon & OCSF standardization
1 year ago
Red Canary
微软警告 Windows 11 用户不要删除神秘的空文件夹
1 year ago
Windows 11 24H2 用户在安装最新安全更新之后可能会对设备上出现一个神秘的空文件夹 inetpub 而感到困惑,鉴于它是空文件夹,一部分人可能觉得删除它不会发生什么大事。微软发表声明,警告不要删除,称该文件夹是修复 Windows Process Activation 提权漏洞 CVE-2025-21204 的一部分,IT 管理员和用户不要对此采取任何行动。如果你已经删除了怎么办?微软提供了修复方法:控制面板 > 程序 > 程序和功能 > 启用或关闭 Windows 功能,点击之后寻找到 Internet Information Services 然后勾选框,点击确定按钮,inetpub 文件夹将会重新创建。
Android 安全告急:黑客伪造 Google Chrome 安装页,植入 SpyNote 恶意软件
1 year ago
安全客