Aggregator
Aeternum Botnet Shifts Command Control to Polygon Blockchain
NDSS 2025 – Translating C To Rust: Lessons From A User Study
Session 13D: Software Security: Code and Compiler
Authors, Creators & Presenters: Ruishi Li (National University of Singapore), Bo Wang (National University of Singapore), Tianyu Li (National University of Singapore), Prateek Saxena (National University of Singapore), Ashish Kundu (Cisco Research)
PAPER
Translating C To Rust: Lessons From A User Study
Rust aims to offer full memory safety for programs, a guarantee that untamed C programs do not enjoy. How difficult is it to translate existing C code to Rust? To get a complementary view from that of automatic C to Rust translators, we report on a user study asking humans to translate real-world C programs to Rust. Our participants are able to produce safe Rust translations, whereas state-of-the-art automatic tools are not able to do so. Our analysis highlights that the high-level strategy taken by users departs significantly from those of automatic tools we study. We also find that users often choose zero-cost (static) abstractions for temporal safety, which addresses a predominant component of runtime costs in other full memory safety defenses. User-provided translations showcase a rich landscape of specialized strategies to translate the same C program in different ways to safe Rust, which future automatic translators can consider.
ABOUT NDSS
The Network and Distributed System Security Symposium (NDSS) fosters information exchange among researchers and practitioners of network and distributed system security. The target audience includes those interested in practical aspects of network and distributed system security, with a focus on actual system design and implementation. A major goal is to encourage and enable the Internet community to apply, deploy, and advance the state of available security technologies.
Our thanks to the Network and Distributed System Security (NDSS) Symposium for publishing their Creators, Authors and Presenter’s superb NDSS Symposium 2025 Conference content on the Organizations' YouTube Channel.
The post NDSS 2025 – Translating C To Rust: Lessons From A User Study appeared first on Security Boulevard.
SecWiki News 2026-02-26 Review
更多最新文章,请访问SecWiki
AI时代的EICAR病毒:用魔术字符串瘫痪Claude的攻防实验
Ваш телефон внезапно начал обновляться? Это может быть вирус Oblivion, захватывающий контроль над системой
ResidentBat Android Malware Provides Belarusian KGB with Persistent Access to Mobile Devices
A newly documented Android spyware called ResidentBat has been linked to the Belarusian KGB, giving state operators deep and persistent access to the mobile devices of journalists and civil society members. First publicly reported in December 2025 through a joint investigation by Reporters Without Borders (RSF) and RESIDENT.NGO, the malware’s code history suggests it was quietly developed […]
The post ResidentBat Android Malware Provides Belarusian KGB with Persistent Access to Mobile Devices appeared first on Cyber Security News.
MindsDB BYOM 远程代码执行漏洞挖掘
Insomnia
You must login to view this content
CVE-2026-3275 | Tenda F453 1.0.0.3 httpd /goform/addressNat fromAddressNat entrys buffer overflow
CVE-2026-3274 | Tenda F453 1.0.0.3 httpd /goform/L7Prot frmL7ProtForm page buffer overflow
CVE-2026-3273 | Tenda F453 1.0.0.3 httpd /goform/AdvSetWrlsafeset formWrlsafeset mit_ssid_index buffer overflow
CVE-2026-3272 | Tenda F453 1.0.0.3 httpd /goform/DhcpListClient fromDhcpListClient page buffer overflow
CVE-2026-3271 | Tenda F453 1.0.0.3 httpd /goform/P2pListFilterof fromP2pListFilter page buffer overflow
CVE-2026-3270 | psi-probe PSI Probe up to 5.3.0 Whois Whois.java lookup server-side request forgery
CVE-2026-3269 | psi-probe PSI Probe up to 5.3.0 Session ExpireSessionsController.java handleRequestInternal denial of service
CVE-2026-3268 | psi-probe PSI Probe up to 5.3.0 Session Attribute RemoveSessAttributeController.java access control (EUVD-2026-8926)
How Hackers Used Anthropic’s Claude to Breach the Mexican Government
Between December 2025 and early January 2026, an unidentified solo operator carried out one of the most technically significant cyberattacks […]
The post How Hackers Used Anthropic’s Claude to Breach the Mexican Government appeared first on HawkEye.