Aggregator
让 Deepseek 帮我写 POC,又快又准确!
5 months 1 week ago
让 Deepseek 帮我写 POC,又快又准确!
5 months 1 week ago
GreenSpot APT针对163.com用户发起钓鱼攻击
5 months 1 week ago
近日,一起大规模的数据泄露事件震动了网络安全界。名为“HikkI-Chan”的黑客在臭名昭著的Breach Forums上泄露了超过3.9亿VK用户的个人信息。
GreenSpot APT针对163.com用户发起钓鱼攻击
5 months 1 week ago
近日,一起大规模的数据泄露事件震动了网络安全界。名为“HikkI-Chan”的黑客在臭名昭著的Breach Forums上泄露了超过3.9亿VK用户的个人信息。
FINALDRAFT Malware Exploits Microsoft Graph API for Espionage on Windows and Linux
5 months 1 week ago
Threat hunters have shed light on a new campaign targeting the foreign ministry of an unnamed South American nation with bespoke malware capable of granting remote access to infected hosts.
The activity, detected in November 2024, has been attributed by Elastic Security Labs to a threat cluster it tracks as REF7707. Some of the other targets include a telecommunications entity and a university,
The Hacker News
记一次恶意文件上传应急响应
5 months 1 week ago
一次恶意链接应急响应过程~
CVE-2024-3303 | GitLab Enterprise Edition up to 17.6.4/17.7.3/17.8.1 information disclosure
5 months 1 week ago
A vulnerability was found in GitLab Enterprise Edition up to 17.6.4/17.7.3/17.8.1. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to information disclosure.
The identification of this vulnerability is CVE-2024-3303. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-13639 | edmonparker Read More & Accordion Plugin up to 3.4.2 on WordPress expmDeleteData authorization
5 months 1 week ago
A vulnerability was found in edmonparker Read More & Accordion Plugin up to 3.4.2 on WordPress. It has been declared as problematic. This vulnerability affects the function expmDeleteData. The manipulation leads to missing authorization.
This vulnerability was named CVE-2024-13639. The attack can be initiated remotely. There is no exploit available.
vuldb.com
成果分享 | 频域视角下的时间序列分类模型后门攻击研究
5 months 1 week ago
我实验室白泽智能的近期研究成果基于频域的增强型攻击,在多种下游任务和模型上均取得优于现有SOTA攻击方法的表现。目前该工作已被交叉综合领域顶级会议WWW2025录用。
成果分享 | 频域视角下的时间序列分类模型后门攻击研究
5 months 1 week ago
我实验室白泽智能的近期研究成果基于频域的增强型攻击,在多种下游任务和模型上均取得优于现有SOTA攻击方法的表现。目前该工作已被交叉综合领域顶级会议WWW2025录用。
微软2025年2月补丁日重点漏洞安全预警
5 months 1 week ago
2025 年 2 月 11 日,微软官方发布了 2 月安全更新,针对共 63 个 CVE 进行修复,涉及多个 Windows 主流版本及多款主流产品和组件,请及时安装补丁修复。
微软2025年2月补丁日重点漏洞安全预警
5 months 1 week ago
2025 年 2 月 11 日,微软官方发布了 2 月安全更新,针对共 63 个 CVE 进行修复,涉及多个 Windows 主流版本及多款主流产品和组件,请及时安装补丁修复。
Орёл или решка: как мелочи заставляют нас доверять незнакомцам
5 months 1 week ago
Исследователи утверждают: мы всегда ищем «своих» в толпе.
攻击DeepSeek的僵尸网络HailBot的三个变种分析
5 months 1 week ago
1 概述安天CERT在2月5日发布了《攻击DeepSeek的相关僵尸网络样本分析》报告,分析了攻击中活跃的两个僵尸网络体系RapperBot和HailBot和其典型样本,分析了其与Mirai僵尸木马源代码泄漏的衍生关系。安天工程师依托特征工程机制,进一步对HailBot僵尸网络样本集合进行了更细粒度差异比对,在将样本向控制台输出的字符串作为分类标识条件的比对中,发现部分样本修改了
内网渗透 | 内网信息收集总结
5 months 1 week ago
已经获取的一台内网的主机权限,如何在内网中寻找我们需要的目标资产,就需要我们根据收集当前主机同网段的其他机器,查看网络链接,看能否发现新网段,为后续内网横移做准备。
Zilveren medaille voor Nederland op Invictus Games
5 months 1 week ago
Sergeant-majoor Ingrid van Meel heeft op de Invictus Games in Canada de eerste medaille behaald voor de Nederlandse ploeg. Ze won zilver op het onderdeel skeleton. “Dat ik het hierom helemaal niet deed, maakt het des te leuker.”
Fog
5 months 1 week ago
cohenido
Lynx
5 months 1 week ago
cohenido
Qilin
5 months 1 week ago
cohenido