Aggregator
3.62 万亿美元,苹果重回世界第一;腾讯「王者」衍生大作被曝已停摆;马斯克讨薪失败,天价薪酬被驳回|极客早知道
1 year 4 months ago
极氪与领克合并后,新公司简称为「极氪科技集团」;
美国升级对华半导体管制:140 家企业被列入「实体清单」限制设备商和 HBM;
腾讯混元大模型上线并开源文生视频能力:支持中英文双语输入,参数量 130 亿
LABScon24 Replay | PKfail: Supply-Chain Failures in Secure Boot Key Management
1 year 4 months ago
LABScon24 Replay | PKfail: Supply-Chain Failures in Secure Boot Key Management
FTC bans data brokers from selling Americans’ sensitive location data
1 year 4 months ago
FTC bans data brokers from selling Americans’ sensitive location data
A step-by-step intro to Client Side Path-Traversal with Eval Villain
1 year 4 months ago
A step-by-step intro to Client Side Path-Traversal with Eval Villain
老白帽创业三年:向死而生
1 year 4 months ago
做最坏的打算,拿最好的结果
The HackerNoon Newsletter: Code Smell 282 - Bad Defaults and How to Fix Them (12/3/2024)
1 year 4 months ago
The HackerNoon Newsletter: Code Smell 282 - Bad Defaults and How to Fix Them (12/3/2024)
Weekly Report: JPCERT/CCが「正規サービスを悪用した攻撃グループAPT-C-60による攻撃」を公開
1 year 4 months ago
JPCERT/CCは、「正規サービスを悪用した攻撃グループAPT-C-60による攻撃」を公開しました。JPCERT/CCでは、2024年8月ごろに攻撃グループAPT-C-60によるものとみられる国内の組織に対する攻撃を確認しています。本記事では、マルウェア感染までの流れ、ダウンローダーの分析、バックドアの分析、同種のマルウェアを使用した攻撃キャンペーンの4項目に分けて攻撃手法を解説しています。
威努特四件套轻装上阵,卷烟厂安全威胁绕道走
1 year 4 months ago
为卷烟厂企业数字化转型道路提供安全座驾。
Startups of The Year: Meet the Engineering Industry
1 year 4 months ago
Startups of The Year: Meet the Engineering Industry
The Road to Agentic AI: Exposed Foundations
1 year 4 months ago
Our research into Retrieval Augmented Generation (RAG) systems uncovered at least 80 unprotected servers. We highlight this problem, which can lead to potential data loss and unauthorized access.
Morton Swimmer
【揭秘】打印机痕迹取证
1 year 4 months ago
【揭秘】打印机痕迹取证
【刑事电子数据的最佳证据规则】
1 year 4 months ago
【刑事电子数据的最佳证据规则】
SecWiki News 2024-12-03 Review
1 year 4 months ago
SecWiki News 2024-12-03 Review
Uncovering a Subtle Bug in EVM Arithmetic: The Case of Negating Zero
1 year 4 months ago
Uncovering a Subtle Bug in EVM Arithmetic: The Case of Negating Zero
Daily Dose of Dark Web Informer - December 3rd, 2024
1 year 4 months ago
This daily article is intended to make it easier for those who want to stay updated with my regular Dark Web Informer and X/Twitter posts.
Dark Web Informer - Cyber Threat Intelligence
CVE-2024-45801 | cure53 DOMPurify up to 2.5.3/3.1.2 Nesting redos (GHSA-mmhx-hmjr-r674 / Nessus ID 212033)
1 year 4 months ago
A vulnerability was found in cure53 DOMPurify up to 2.5.3/3.1.2. It has been declared as critical. This vulnerability affects unknown code of the component Nesting Handler. The manipulation leads to inefficient regular expression complexity.
This vulnerability was named CVE-2024-45801. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
The AI Fix #27: Why is AI full of real-life Bond villains?
1 year 4 months ago
The AI Fix #27: Why is AI full of real-life Bond villains?
DMM Bitcoin halts operations six months after a $300 million cyber heist
1 year 4 months ago
DMM Bitcoin halts operations six months after a $300 million cyber heist
CSPT the Eval Villain Way!
1 year 4 months ago
CSPT the Eval Villain Way!