Aggregator
Xcheck Java引擎漏洞挖掘&防护识别
3 years 6 months ago
0x00 漏洞挖掘新增两个CNVD近期,使用了Xcheck Java引擎对一些开源网站系统进行检查,最终发现
Cybersecurity Compliance Failures in Financial Services
3 years 6 months ago
Examining three breach and compliance failure cases under the New York Department of Financial Services’ 23 NYCRR Part 500 cybersecurity regulation.
汽车总线知识扫盲 - 序
3 years 6 months ago
前言
汽车行业非常严谨,许多产品都要按照规范设计,首先要搞清楚ISO与SAE的关系。
Gorgias
SMB Worm Indexsinas
3 years 6 months ago
New details in the Indexsinas SMB worm, also dubbed NSABuffMiner.
Liad Mordekoviz & Ophir Harpaz
一次 Shiro 到内网漫游横向渗透
3 years 6 months ago
一次 Shiro 到内网漫游横向渗透
Merlin Labs 遭攻击 会是一起内部作案吗?
3 years 6 months ago
6 月 28 日,收益聚合器 Merlin Lab 遭到黑客攻击。
安全服务的发展
3 years 6 months ago
最近几年,安全服务发生了一些显著变化。本文重点介绍MSS服务和MDR服务以及国内安全服务现状。
某知笔记服务端docker镜像授权分析
3 years 6 months ago
半块西瓜皮
The Threat That Never Went Away Is Back (with a Vengeance)
3 years 6 months ago
What is your recollection of May 2017? Emmanuel Macron won the French election. The Ringling Bros. and Barnum & Bailey Circus gave its final performance after a 146-year run. The U.S. FCC voted to overturn net neutrality rules. And the National Health Service in the United Kingdom was crippled by a massive ransomware attack that ended up costing over $120 million.
Jim Black
JVMTI加密保护绕过
3 years 6 months ago
研究过程
最近研究某汽车,遇到一个Win下的软件,用于连接经销商内网。
安装完成,目录有jar文件又有exe文件。
执行start.exe之后
Gorgias
数据众包平台Premise持续向美军提供情报数据
3 years 6 months ago
美国一家名为Premise Data Corp.的数据公司,通过三百万名兼职人员,以拍照、数据记录、填写问卷
宝,我今天发财了!发的什么财?诚聘英才!
3 years 6 months ago
宝,我今天发财了!发的什么财?诚聘英才!
Airtag hacks - scanning via browser, removing speaker and data exfiltration
3 years 6 months ago
Until the Apple Airtag came out a few months ago I hadn’t really looked into the tag tracking market. Turns out there were already quite a lot of offerings available before Apple joined the market, most notably Tile.
However, I wanted to try out the Airtag and ended up ordering a few.
This post will explore three things:
Removing the speaker of my Airtag Using Browser APIs to scan for Airtags (if you don’t have an iPhone but someone tries to stalk you this might be handy) Explore data exfiltration via Airtags and Apple’s “Find My” network By the way, when you order your Airtags online you can customize them.
精选|QEMU仿真方式总结
3 years 6 months ago
QEMU仿真方式总结
算法稳定币 SafeDollar 归零,Polygon 生态遭黑客盯上?
3 years 6 months ago
6 月 28 日,Polygon 生态中的算法稳定币项目 SafeDollar 遭到黑客攻击,该项目所发行的稳定币 SDO 从 1.07 美元趋于归零,攻击者拿走了价值 25 万美元的 USDC 和 USDT。
【文末福利】银针安全沙龙上海站嘉宾招募,这个盛夏与你在上海不期而遇~
3 years 6 months ago
银针安全沙龙上海站开启报名!转发赢银针安全沙龙定制T恤~
AntSword新类型 CmdLinux 预览
3 years 6 months ago
新类型 cmdlinux,直连命令执行WebShell
AWD中二进制补丁的常见手工打法
3 years 6 months ago
银针
是什么让我不与众人同:西安交大钱学森学院分享
3 years 6 months ago
前些时回母校做了个分享,回来修改速记稿修改了整整两周。以下是分享全文。答疑部分日后再发。