Aggregator
The Threat That Never Went Away Is Back (with a Vengeance)
3 years 6 months ago
What is your recollection of May 2017? Emmanuel Macron won the French election. The Ringling Bros. and Barnum & Bailey Circus gave its final performance after a 146-year run. The U.S. FCC voted to overturn net neutrality rules. And the National Health Service in the United Kingdom was crippled by a massive ransomware attack that ended up costing over $120 million.
Jim Black
JVMTI加密保护绕过
3 years 6 months ago
研究过程
最近研究某汽车,遇到一个Win下的软件,用于连接经销商内网。
安装完成,目录有jar文件又有exe文件。
执行start.exe之后
Gorgias
数据众包平台Premise持续向美军提供情报数据
3 years 6 months ago
美国一家名为Premise Data Corp.的数据公司,通过三百万名兼职人员,以拍照、数据记录、填写问卷
宝,我今天发财了!发的什么财?诚聘英才!
3 years 6 months ago
宝,我今天发财了!发的什么财?诚聘英才!
Airtag hacks - scanning via browser, removing speaker and data exfiltration
3 years 6 months ago
Until the Apple Airtag came out a few months ago I hadn’t really looked into the tag tracking market. Turns out there were already quite a lot of offerings available before Apple joined the market, most notably Tile.
However, I wanted to try out the Airtag and ended up ordering a few.
This post will explore three things:
Removing the speaker of my Airtag Using Browser APIs to scan for Airtags (if you don’t have an iPhone but someone tries to stalk you this might be handy) Explore data exfiltration via Airtags and Apple’s “Find My” network By the way, when you order your Airtags online you can customize them.
精选|QEMU仿真方式总结
3 years 6 months ago
QEMU仿真方式总结
算法稳定币 SafeDollar 归零,Polygon 生态遭黑客盯上?
3 years 6 months ago
6 月 28 日,Polygon 生态中的算法稳定币项目 SafeDollar 遭到黑客攻击,该项目所发行的稳定币 SDO 从 1.07 美元趋于归零,攻击者拿走了价值 25 万美元的 USDC 和 USDT。
【文末福利】银针安全沙龙上海站嘉宾招募,这个盛夏与你在上海不期而遇~
3 years 6 months ago
银针安全沙龙上海站开启报名!转发赢银针安全沙龙定制T恤~
AntSword新类型 CmdLinux 预览
3 years 6 months ago
新类型 cmdlinux,直连命令执行WebShell
AWD中二进制补丁的常见手工打法
3 years 6 months ago
银针
是什么让我不与众人同:西安交大钱学森学院分享
3 years 6 months ago
前些时回母校做了个分享,回来修改速记稿修改了整整两周。以下是分享全文。答疑部分日后再发。
Windows11要求硬件必须有TPM2.0,以后Windows很可能也会和Android、iOS、macOS一样全盘加密。对普通用户来说,系统更安全了,对取证工作者来说,却喜忧参半。
3 years 6 months ago
What We Can Learn From Ransomware Actor "Security Reports"
3 years 6 months ago
Ransomware Actors Explain in their Own Words How to Become an Expensive
Target through security reports written to victims.
Bill Siegel
未来的网络就像一个生命体
3 years 6 months ago
对网络的认知需要升级了!
XMLDecoder反序列化与CVE-2017-10271
3 years 6 months ago
XMLEncoder与 XMLDecoder使用XMLEncoder来生成表示JavaBeans组件(bea
迈克菲杀毒软件创始人在监狱死亡
3 years 6 months ago
2021 Application Protection Report Supplement: Sectors and Vectors
3 years 6 months ago
A detailed examination of application risk and cybersecurity attack chains, broken down by sector.
How to Perform a Zero Trust AWS Assessment with Infection Monkey and ScoutSuite
3 years 6 months ago
Take action on issues highlighted in the report to ensure your AWS cloud defenses are protected in a data breach, minimizing impact and data loss.
Mike Salvatore
复现|路由器命令执行
3 years 6 months ago
快来跟我们一起复现漏洞吧~