Aggregator
ZDI-CAN-24019: Arista
你是想当个网络安全“装机工”,还是想从源头重塑安全体系?
议题1- 投票| KCon大会议题评选 High-value Web Application Post-Exploitation
吃瓜群众且吃且珍惜
检测OpenSSH远程代码执行漏洞CVE-2024-6387(行为和流量)
漏洞通告 | GeoServer JXPath远程代码执行漏洞
【复现】Geoserver远程代码执行漏洞(CVE-2024-36401)的风险通告
多人吃饭,精细分账的小工具 EasySplit
智能化软件开发微访谈·第三十二期 Rust语言与系统及生态发展·活动预告
Vulnerabilities in PanelView Plus devices could lead to remote code execution
Microsoft discovered and responsibly disclosed two vulnerabilities in Rockwell’s PanelView Plus that could be remotely exploited by unauthenticated attackers, allowing them to perform remote code execution (RCE) and denial-of-service (DoS). PanelView Plus devices are graphic terminals, which are known as human machine interface (HMI) and are used in the industrial space.
The post Vulnerabilities in PanelView Plus devices could lead to remote code execution appeared first on Microsoft Security Blog.
Weaponizing API discovery metadata
Learn how to weaponize API discovery metadata to improve your recon of the APIs you are hacking or conducting security testing on.
The post Weaponizing API discovery metadata appeared first on Dana Epp's Blog.
Like Shooting Phish in a Barrel
Modern Cryptographic Attacks: A Guide for the Perplexed
Introduction Cryptographic attacks, even more advanced ones, are often made more difficult to understand than they need to be. Sometimes it’s because the explanation is “too much too soon” — it skips the simple general idea and goes straight to real world attacks with all their messy details. Other times it’s because of too much […]
The post Modern Cryptographic Attacks: A Guide for the Perplexed appeared first on Check Point Research.