Aggregator
新的 Skuld 信息窃取活动在 npm 生态系统中亮相
8 months 1 week ago
安全客
CVE-2004-0771 | F-Secure Anti-Virus ZIP Archive privileges management (EDB-24120 / Nessus ID 14813)
8 months 1 week ago
A vulnerability has been found in F-Secure Anti-Virus and classified as critical. Affected by this vulnerability is an unknown functionality of the component ZIP Archive Handler. The manipulation leads to improper privilege management.
This vulnerability is known as CVE-2004-0771. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
Lazarus Group 不断发展的武器库:揭开新的恶意软件和感染链的面纱
8 months 1 week ago
安全客
Regex 101: Practical Tips for Mastering Regular Expressions
8 months 1 week ago
Ever wished you could instantly extract all email addresses from a document or clean up messy data w
CVE-2006-4444 | Cybozu Garoon iid sql injection (EDB-2267 / XFDB-28594)
8 months 1 week ago
A vulnerability, which was classified as critical, was found in Cybozu Garoon. Affected is an unknown function. The manipulation of the argument iid leads to sql injection.
This vulnerability is traded as CVE-2006-4444. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
美国CISA发布强制性指令,要求联邦机构落实SaaS安全配置基线
8 months 1 week ago
知名AI公司云泄漏超1.29TB内部敏感数据
8 months 1 week ago
因云存储配置不当
知名AI公司云泄漏超1.29TB内部敏感数据
8 months 1 week ago
关注我们带你读懂网络安全据悉,暴露的数据库包含个人敏感数据和公司运营数据,事件归因为云存储配置不当。前情回顾·全球数据泄漏态势背调公司发生超大规模数据泄漏,一亿美国人隐私信息暴露国内某上市公司疑遭勒索
美国CISA发布强制性指令,要求联邦机构落实SaaS安全配置基线
8 months 1 week ago
关注我们带你读懂网络安全美国政府发布了关于云服务安全实践实施的指导意见。2024年12月17日,美国网络安全与基础设施安全局(Cybersecurity and Infrastructure Secu
NDSS 2025|Prompt泄露风险:抖音集团安全研究团队揭露多租户KV缓存共享漏洞
8 months 1 week ago
再次入选NDSS 2025!
NDSS 2025|Prompt泄露风险:抖音集团安全研究团队揭露多租户KV缓存共享漏洞
8 months 1 week ago
再次入选NDSS 2025!
NDSS 2025|Prompt泄露风险:抖音集团安全研究团队揭露多租户KV缓存共享漏洞
8 months 1 week ago
再次入选NDSS 2025!
Interpol Identifies Over 140 Human Traffickers in New Initiative
8 months 1 week ago
A new digital operation has enabled Interpol to identify scores of human traffickers operating between South America and Europe
Top Open Source API Security Tools
8 months 1 week ago
The modern world relies on Application Programming Interfaces (APIs). They allow applications
派评 | 近期值得关注的 App
8 months 1 week ago
欢迎收看本期《派评》。你可以通过文章目录快速跳转到你感兴趣的内容。如果发现了其它感兴趣的 App 或者关注的话题,也欢迎在评论区和我们讨论。不容错过的 App 更新除了「新鲜」App,App St
NDSS 2025|Prompt泄露风险:抖音集团安全研究团队揭露多租户KV缓存共享漏洞
8 months 1 week ago
再次入选NDSS 2025!
NDSS 2025|Prompt泄露风险:抖音集团安全研究团队揭露多租户KV缓存共享漏洞
8 months 1 week ago
抖音集团安全研究团队和南方科技大学可信系统安全实验室合作的研究论文揭示了大语言模型安全领域服务框架的侧信道漏洞,利用多租户场景下的KV缓存共享机制精确恢复了用户提示词。本工作成果《I Know Wha
Cloud Atlas seen using a new tool in its attacks
8 months 1 week ago
IntroductionKnown since 2014, Cloud Atlas targets Eastern Europe and Central Asia. We
Chris Hadfield: The sky is falling – what to do about space junk? | Starmus highlights
8 months 1 week ago
The first Canadian to walk in space dives deep into the origins of space debris, how it’s become a growing problem, and how we can clean up the orbital mess