Aggregator
Alleged Boss of ‘Scattered Spider’ Hacking Group Arrested
1 year 9 months ago
A 22-year-old man from the United Kingdom arrested this week in Spain is allegedly the ringleader of Scattered Spider, a cybercrime group suspected of hacking into Twilio, LastPass, DoorDash, Mailchimp, and nearly 130 other organizations over the past two years.
BrianKrebs
CVE-2024-28995 Exploit PoC: SolarWinds Serv-U Directory Traversal Vulnerability > 15.4
1 year 9 months ago
SolarWinds patched a High severity vulnerability in Serv-U File Transfer Solution that affects multiple Serv-U products in FTP Server, Gateway and MFT Server versions 15.4. This vulnerability has been assigned with CVE-2024-28995 and severity as 8.6 (High).
Hacker Hunter
一款开源Linux应急响应脚本,快速发现主机异常
1 year 9 months ago
一套完善的Linux通用应急响应脚本,其实对防御方是非常重要的,可以快速检测主机的一些异常信息。脚本地址,请看文末。
一款开源Linux应急响应脚本,快速发现主机异常
1 year 9 months ago
一套完善的Linux通用应急响应脚本,其实对防御方是非常重要的,可以快速检测主机的一些异常信息。脚本地址,请看文末。
一款开源Linux应急响应脚本,快速发现主机异常
1 year 9 months ago
一套完善的Linux通用应急响应脚本,其实对防御方是非常重要的,可以快速检测主机的一些异常信息。脚本地址,请看文末。
一款开源Linux应急响应脚本,快速发现主机异常
1 year 9 months ago
一套完善的Linux通用应急响应脚本,其实对防御方是非常重要的,可以快速检测主机的一些异常信息。脚本地址,请看文末。
一款开源Linux应急响应脚本,快速发现主机异常
1 year 9 months ago
一套完善的Linux通用应急响应脚本,其实对防御方是非常重要的,可以快速检测主机的一些异常信息。脚本地址,请看文末。
GitHub Copilot Chat: From Prompt Injection to Data Exfiltration
1 year 9 months ago
This post highlights how the GitHub Copilot Chat VS Code Extension was vulnerable to data exfiltration via prompt injection when analyzing untrusted source code.
GitHub Copilot ChatGitHub Copilot Chat is a VS Code Extension that allows a user to chat with source code, refactor code, get info about terminal output, or general help about VS Code, and things along those lines.
It does so by sending source code, along with the user’s questions to a large language model (LLM). A bit of a segue, but if you are curious, here are its system instructions, highlighting some interesting prompting strategies and that it is powered by GPT-4:
第96篇:蓝队分析研判工具箱1.08版本(溯源辅助|解密攻击流量|冰蝎、哥斯拉、天蝎解密|资产测绘搜索)
1 year 9 months ago
Time to challenge yourself in the 2024 Google CTF
1 year 9 months ago
Kimberly Samra
北京交通大学 | 图提示学习中跨上下文后门攻击
1 year 9 months ago
探讨了跨上下文场景中图提示学习(Graph Prompt Learning)面临的后门威胁。
Akamai’s Perspective on June’s Patch Tuesday 2024
1 year 9 months ago
Akamai Security Intelligence Group
How Healthcare Providers Should Think About Balancing Innovation Efforts with Cybersecurity Goals
1 year 9 months ago
Steve Winterfeld
How Healthcare Providers Should Think About Balancing Innovation Efforts with Cybersecurity Goals
1 year 9 months ago
Steve Winterfeld
How Arid Viper spies on Android users in the Middle East – Week in security with Tony Anscombe
1 year 9 months ago
The spyware, called AridSpy by ESET, is distributed through websites that pose as various messaging apps, a job search app, and a Palestinian Civil Registry app
CSO的“最佳拍档” ,长亭科技再获认可!
1 year 9 months ago
让我康康
公示!长亭问津安全大模型通过国家网信办算法备案
1 year 9 months ago
👍 👍 👍
【火绒安全周报】黑客假冒政府人员进行诈骗/N站遭遇网络攻击
1 year 9 months ago
第八届XCTF国际联赛总决赛 |倒计时7天!
1 year 9 months ago
迎风破浪 淬炼锋芒