Aggregator
萤火V2.13功能更新快报
2 years 3 months ago
星阑科技上榜《CCSIP 2023中国网络安全行业全景册》多个细分领域
2 years 3 months ago
萤火V2.13功能更新快报
2 years 3 months ago
Google Gemini: Planting Instructions For Delayed Automatic Tool Invocation
2 years 3 months ago
Last November, while testing Google Bard (now called Gemini) for vulnerabilities, I had a couple of interesting observations when it comes to automatic tool invocation.
Confused Deputy - Automatic Tool InvocationFirst, what do I mean by this… “automatic tool invocation”…
Consider the following scenario: An attacker sends a malicious email to a user containing instructions to call an external tool. Google named these tools Extensions.
When the user analyzes the email with an LLM, it interprets the instructions and calls the external tool, leading to a kind of request forgery or maybe better called automatic tool invocation.
Millions of Undetectable Malicious URLs Generated Via the Abuse of Public Cloud and Web 3.0 Services
2 years 3 months ago
长亭珂兰寺招生简章
2 years 3 months ago
一篇文章了解珂兰寺
Major Cellular Outage in the U.S.
2 years 3 months ago
Summary
At approximately 0330 eastern time in the United States, over 70 thousand AT&T users reported interruptions in their mobile, internet, and home phone services. There outage is not currently being attributed any any cyber attacks.
Threat Type
Critical Infrastructure Outage
Overview
AT&T is currently investigating a network outage affecting over 70 thousand of their customers. The outage reportedly began at about 0330 eastern time. Initial reports claimed that this outage also affected T-Mobile and
长亭珂兰寺招生简章
2 years 3 months ago
一篇文章了解珂兰寺
Everything you need to know about IP grabbers
2 years 3 months ago
Unsuspecting users beware, IP grabbers do not ask for your permission.
Workloads on Any Cloud: Designing a Cloud Portability Strategy
2 years 3 months ago
Billy Thompson
【工具分享】一款针对Spring Boot的开源渗透框架(持续更新中)
2 years 3 months ago
Spring Boot的开源渗透框架,主要用作扫描Spring Boot的敏感信息泄露端点,并可以直接测试Spring的相关高危漏洞。
用mshta让bat以管理员身份运行
2 years 3 months ago
这种技巧我这辈子都用不上,是不是在一些不太合法的需求中用得着啊
CSS实现表格对角线
2 years 3 months ago
杨龙
《少年黑客》第六季,久违的少年黑客团,继续闪耀!
2 years 3 months ago
「深蓝洞察」2023 年度最多面的漏洞
2 years 3 months ago
深蓝洞察年度安全报告第三篇
APT-C-24(SideWinder)组织新威胁:基于Nim的载荷浮出水面
2 years 3 months ago
近期,我们捕获到了SideWinder针对不丹、缅甸、尼泊尔的攻击样本,这类样本主要是通过宏文档释放Nim语言编译的攻击载荷,这类载荷在响尾蛇历史攻击者中很少见。鉴于此情况,本文重点披露响尾蛇组织使用的这类组件。
给互联网人的反侦查手册 2.0
2 years 3 months ago
屏幕另一端的人严肃地提出了第一个问题:“2022 年 x 月 x 日,你在 x 点 x 分 x 秒你打开了 xx 文档,你先是快速滑动页面,之后在 xx 位置停 […]
root
Exploitation Observed: Ivanti Connect Secure — CVE-2023-46805 and CVE-2024-21887
2 years 3 months ago
Noam Atias & Sam Tinklenberg
Data Matters — Empowering Threat Hunters to Reduce API Risk
2 years 3 months ago
Abigail Ojeda