Aggregator
2025古剑山CTF两道pwn
利用数据流“清洗”大模型漏洞检测:LLMSAN 技术解析
压缩文件 CRC32 碰撞原理解析以及制作解密脚本
PolarCTF2025 冬季个人赛 PWN 方向全解
AI agents break rules in unexpected ways
AI agents are starting to take on tasks that used to be handled by people. These systems plan steps, call tools, and carry out actions without a person approving every move. This shift is raising questions for security leaders. A new research paper offers one of the first attempts to measure how well these agents stay inside guardrails when users try to push them off course. The work comes from a group of researchers at … More →
The post AI agents break rules in unexpected ways appeared first on Help Net Security.
Fastjson2 RCE 深度剖析:从黑名单绕过到双代理链利用
Apache Causeway (CVE-2025-64408) 反序列化远程代码执行漏洞分析
Burp Suite’s Scanning Arsenal Powered With Detection for Critical React2Shell Vulnerabilities
PortSwigger has enhanced Burp Suite’s scanning arsenal with the latest update to its ActiveScan++ extension, introducing detection for the critical React2Shell vulnerabilities (CVE-2025-55182 and CVE-2025-66478). This server-side request forgery (SSRF) flaw in React applications allows attackers to execute arbitrary shell commands, potentially leading to full remote code execution (RCE) on affected servers. Security researchers and […]
The post Burp Suite’s Scanning Arsenal Powered With Detection for Critical React2Shell Vulnerabilities appeared first on Cyber Security News.