宜禾
@qrzsec
10
subscribers
4
photos
1
file
1.67K
links
个人感兴趣的安全文章推送与
@qrzbing
的博客评论区
Download Telegram
Join
宜禾
10 subscribers
宜禾
直观解读 JuiceFS 的数据和元数据设计(三):看山还是山(2024)
宜禾
1.32.3
GitHub
Release 1.32.3 · dani-garcia/vaultwarden
Notable changes
Email template for org invites was updated again. The URL got HTML Encoded which resulted in a sometimes non-working URL (#5100)
Fixed SMTP issues with some providers which send er...
宜禾
Version 1.14.0
GitHub
Release Version 1.14.0 · umputun/remark42
What's Changed
Add Content-Security-Policy and Permissions-Policy headers by @paskal in #1805
add RTL support by @adueck in #1799
fix: Apple login integration by @tomy0000000 in #1806
Fix prob...
宜禾
Chemistry - HackTheBox
喵喵喵喵
Chemistry - HackTheBox
有东西被加密了, 请输入密码查看.
宜禾
Exploiting File Writes in Hardened Node.js Environments
Swing'Blog 浮生若梦
Exploiting File Writes in Hardened Node.js Environments
宜禾
每日安全动态推送(24/10/28)
Weixin Official Accounts Platform
每日安全动态推送(24/10/28)
降级Windows以利用已修补的漏洞;FortiManager 零日漏洞;secp256k1-node中ECDH私钥提取漏洞分析
宜禾
G.O.S.S.I.P 阅读推荐 2024-10-28 Query Provenance Analysis
Weixin Official Accounts Platform
G.O.S.S.I.P 阅读推荐 2024-10-28 Query Provenance Analysis
宜禾
每日安全动态推送(24/10/29)
Weixin Official Accounts Platform
每日安全动态推送(24/10/29)
思科ASA与FTD软件中远程访问VPN服务的重大漏洞;对可信平台模块的SPI接口进行嗅探攻击,以低成本提取BitLocker密钥;NUUO网络视频录像机任意文件上传
宜禾
Lumma/Amadey: fake CAPTCHAs want to know if you’re human
Securelist
Malicious CAPTCHA delivers Lumma and Amadey Trojans
Malicious CAPTCHA distributed through ad networks delivers the Amadey Trojan or the Lumma stealer, which pilfers data from browsers, password managers, and crypto wallets.
宜禾
Risk reduction redefined: How compromise assessment helps strengthen cyberdefenses
Securelist
Compromise assessment in cybersecurity: real-world cases
Kaspersky experts analyze cyberdefense weak points, including patch management, policy violations and MSSP issues, and real-world cases where compromise assessment helped detect and mitigate incidents.
宜禾
Bloch sphere
宜禾
每日安全动态推送(24/10/30)
Weixin Official Accounts Platform
每日安全动态推送(24/10/30)
Linux内核TCP合成接收套接字关闭时的除零错误;CyberPanel 控制面板远程命令执行;Rust的安全幻影:语言层面的约束及其局限性
宜禾
The Karma connection in Chrome Web Store
Almost Secure
The Karma connection in Chrome Web Store
A bunch of malicious extensions in Chrome Web Store have hidden affiliate fraud functionality, collect users’ browsing profiles, or both. These extensions appear to be connected to the Karma shopping assistant, developed by Karma Shopping Ltd. which is not…
宜禾
G.O.S.S.I.P 阅读推荐 2024-10-30 SmartAxe
宜禾
以子之矛陷子之盾 · 用AI对AI漏洞的利用探索
DARKNAVY
以子之矛陷子之盾 · 用AI对AI漏洞的利用探索
2024年9月24日,OpenAI的CEO Sam Altman发表文章《The Intelligence Age》,大胆地宣告了AI时代的到来。
给予文章强有力支撑的是ChatGPT-o1的发布,这是一次里程碑式的事件,在深度学习的加成下,大模型如虎添翼,表现强劲。
身处时代浪潮之中,DARKNAVY也积极拥抱AI,探索AI和安全的关系。AI能否在发现和利用漏洞时,再现人类的方法论?AI会不会带来新的安全问题?
楚人有鬻盾与矛者,誉之曰:“吾盾之坚,物莫能陷之。”以誉其矛曰:“吾矛之利,于物无不陷…
宜禾
Loose-lipped neural networks and lazy scammers
Securelist
How phishing pages admit to being LLM-made
Scammers use large language models (LLMs) to create phishing pages and leave artifacts in texts and tags, like the phrase "As an AI language model…".
宜禾
每日安全动态推送(24/10/31)
Weixin Official Accounts Platform
每日安全动态推送(24/10/31)
APT29利用RDP渗透乌克兰;Windows TCP/IP 远程代码执行漏洞;WebKitGTK与WPE WebKit安全公告
宜禾
每日安全动态推送(24/11/1)
Weixin Official Accounts Platform
每日安全动态推送(24/11/1)
利用Magento和Adobe Commerce系统的两个漏洞实现远程代码执行;利用公开的.git文件夹进行漏洞挖掘;利用 0-Day Opera 漏洞进行跨浏览器扩展存储攻击
宜禾
G.O.S.S.I.P 阅读推荐 2024-11-01 交叉火线—对苹果设备跨异构计算单元内存的模糊测试
Weixin Official Accounts Platform
G.O.S.S.I.P 阅读推荐 2024-11-01 交叉火线—对苹果设备跨异构计算单元内存的模糊测试
宜禾
A Brief Look at FortiJump (FortiManager CVE-2024-47575)
Bishop Fox
A Deeper Look at FortiJump (FortiManager CVE-2024-47575)
The recent discovery of FortiJump (CVE-2024-47575) highlights a critical vulnerability exploited in the wild, prompting an urgent need to understand its…