Aggregator
Name That Toon Contest
3 weeks 6 days hence
[Virtual Event] Anatomy of a Data Breach: What to Do if it Happens to You
2 weeks 5 days hence
[An RX Global Event] Infosecurity Europe
3 days 15 hours hence
Name That Toon: Mark of (Cybersecurity) Progress
2 hours 2 minutes ago
As part of Dark Reading's 20th anniversary package, we asked readers for a cybersecurity-related caption that captures their thoughts about the industry's last two decades.
John Klossner
Cryptographic algorithms for UNCLASSIFIED, PROTECTED A, and PROTECTED B information - ITSP.40.111
3 hours 38 minutes ago
Canadian Centre for Cyber Security
ChatGPT share links abused to host fake outage pages to deliver malware
4 hours 3 minutes ago
Threat actors are abusing ChatGPT's content-sharing feature to display fake OpenAI outage pages that direct users to download malware disguised as the ChatGPT desktop application. [...]
Lawrence Abrams
California AG sues 23andMe over 2023 breach exposing health data
4 hours 16 minutes ago
California Attorney General Rob Bonta filed a lawsuit against 23andMe, now Chrome Holding Co., over the company's failure to protect sensitive customer genetic and personal information. [...]
Bill Toulas
ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface
4 hours 17 minutes ago
Cybersecurity researchers have disclosed details of a vulnerability in OpenAI ChatGPT that leverages the artificial intelligence (AI) assistant's implicit trust in Markdown links and images to trigger prompt injections and open the door to phishing attacks.
The technique has been codenamed ChatGPhish by Permiso Security.
"The chatgpt.com response renderer trusts Markdown links and Markdown
The Hacker News
Top 10 artificial intelligence security actions: A primer - ITSAP.10.049
4 hours 18 minutes ago
Our top AI security actions are designed to help organizations of all sizes and sectors strengthen their cyber resilience.
Canadian Centre for Cyber Security
复现 ICLR 2026 在审《TrojanPraise》:从 12% 到 42% 的 LoRA 越狱调参实战
5 hours 25 minutes ago
一个越狱调参实验
泛微e9分析思路
5 hours 25 minutes ago
本文基于泛微e9(9.00.210804版本),系统阐述OA系统的安全审计方法。文章涵盖环境搭建、六大类路由(/weaver/、/api/、/services/*、/dwr/*等)的分析,详细剖析SecurityMain安全过滤机制、XssRequestWeblogic参数过滤、登录绕过等技术要点。通过FileDownloadLocation文件读取、browser.jsp SQL注入等实战案例,
记攻防中的钓鱼样本分析
5 hours 30 minutes ago
一次攻防下钓鱼GO木马的详细分析,拿下CS shellcode
PHP WebShell 免杀之字符串运算 + 动态调用
5 hours 33 minutes ago
WebShell 免杀
关于某池WAF SQL 注入绕过可行性探究
5 hours 33 minutes ago
某池WAF SQL注入Bypass
Coze空间cs流量转发
5 hours 34 minutes ago
讲述如何在Coze空间部署cs流量转发
基于AI生成的WinRAR钓鱼网站攻防分析
5 hours 36 minutes ago
钓鱼网站利用AI生成逼真页面、仿冒官方域名排名,诱导用户下载携带恶意载荷的“WinRAR安装包”。
伪装成10086官网流量的Cobalt Strike木马深度分析
5 hours 37 minutes ago
海量IP地址字符串转码生成shellcode、Beacon木马伪造Referer请求头为10086官网
一款伪装成豆包Claw的恶意项目
5 hours 39 minutes ago
一款伪装成豆包Claw的恶意项目仍在活跃
Agentic / Context
5 hours 42 minutes ago
Agentic / Context