Aggregator
Submit #736637: PHPGurukul News Portal v1.0 Cross Site Scripting [Accepted]
CVE-2026-1423 | code-projects Online Examination System 1.0 /admin_pic.php unrestricted upload
CVE-2026-1422 | code-projects Online Examination System 1.0 Login Page /index.php User sql injection
CVE-2026-1421 | code-projects Online Examination System 1.0 Add Pages cross site scripting
CVE-2026-1420 | Tenda AC23 16.03.07.52 /goform/WifiExtraSet wpapsk_crypto buffer overflow
Submit #736607: code-projects Online Examination System 1 Unrestricted Upload [Accepted]
Submit #736606: code-projects Online Examination System 1 SQL Injection [Accepted]
Submit #736605: code-projects Online Examination System 1 Cross Site Scripting [Accepted]
Кожаные мешки больше не нужны: Amazon меняет 30 000 клерков на один мощный алгоритм
Submit #736559: Tenda AC23 V16.03.07.52 Buffer Overflow [Accepted]
Физики врали (не специально): Большой взрыв был жидким, а Вселенная — это суп
0xL4ugh CTF v5
Date: Jan. 23, 2026, 1 p.m. — 25 Jan. 2026, 13:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://ctf.0xL4ugh.com/
Rating weight: 29.19
Event organizers: 0xL4ugh
VSL CTF 2026
Date: Jan. 24, 2026, 8 a.m. — 25 Jan. 2026, 08:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://vsl-ctf.com/
Rating weight: 23.60
Event organizers: VSL
Fluid Attacks' CTF 2026-1
Date: Jan. 24, 2026, 1 p.m. — 25 Jan. 2026, 13:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://fluidattacks.com/ctf
Rating weight: 0
Event organizers: Fluid Attacks
NDSS 2025 – RContainer
Session 10A: Confidential Computing 2
Authors, Creators & Presenters: Qihang Zhou (Institute of Information Engineering, Chinese Academy of Sciences), Wenzhuo Cao (Institute of Information Engineering, Chinese Academy of Sciences; School of Cyberspace Security, University of Chinese Academy of Sciences), Xiaoqi Jia (Institute of Information Engineering, Chinese Academy of Sciences), Peng Liu (The Pennsylvania State University, USA), Shengzhi Zhang (Department of Computer Science, Metropolitan College, Boston University, USA), Jiayun Chen (Institute of Information Engineering, Chinese Academy of Sciences; School of Cyberspace Security, University of Chinese Academy of Sciences), Shaowen Xu (Institute of Information Engineering, Chinese Academy of Sciences; School of Cyberspace Security, University of Chinese Academy of Sciences), Zhenyu Song (Institute of Information Engineering, Chinese Academy of Science)
PAPER
RContainer: A Secure Container Architecture through Extending ARM CCA Hardware Primitives
Containers have become widely adopted in cloud platforms due to their efficient deployment and high resource utilization. However, their weak isolation has always posed a significant security concern. In this paper, we propose RContainer, a novel secure container architecture that protects containers from untrusted operating systems and enforces strong isolation among containers by extending ARM Confidential Computing Architecture (CCA) hardware primitives. RContainer introduces a small, trusted mini-OS that runs alongside the deprivileged OS, responsible for monitoring the control flow between the operating system and containers. Additionally, RContainer uses shim-style isolation, creating an isolated physical address space called con-shim for each container at the kernel layer through the Granule Protection Check mechanism. We have implemented RContainer on ARMv9-A Fixed Virtual Platform and ARMv8 hardware SoC for security analysis and performance evaluation. Experimental results demonstrate that RContainer can significantly enhance container security with a modest performance overhead and a minimal Trusted Computing Base (TCB).
ABOUT NDSS
The Network and Distributed System Security Symposium (NDSS) fosters information exchange among researchers and practitioners of network and distributed system security. The target audience includes those interested in practical aspects of network and distributed system security, with a focus on actual system design and implementation. A major goal is to encourage and enable the Internet community to apply, deploy, and advance the state of available security technologies.
Our thanks to the Network and Distributed System Security (NDSS) Symposium for publishing their Creators, Authors and Presenter’s superb NDSS Symposium 2025 Conference content on the Organizations' YouTube Channel.
The post NDSS 2025 – RContainer appeared first on Security Boulevard.
SecWiki News 2026-01-25 Review
Tesla LTE 安全分析 by 路人甲
Jar-analyzer + Claude Skills审计探索 by ourren
Jar Analyzer - 一个 JAR 包 GUI 分析工具 by ourren
自动化漏洞挖掘:过去、现在与未来——AI 的上限在哪里? by ourren
更多最新文章,请访问SecWiki
The Hackers Labs-Despromptado
Qilin
You must login to view this content
Orion RaaS Recruitment Drive Promises Luxury Rewards
You must login to view this content