Aggregator
Akamai?s Responsibility to Our Enterprise Customers
11 months ago
Adam Karon
Apache Struts2 文件上传漏洞分析(CVE-2023-50164)
11 months ago
攻击者可以操纵文件上传参数以启用路径遍历,在某些情况下,这可能导致上传可用于执行远程代码执行的恶意文件。
ChatAFL:LLM模型指导的协议模糊测试|技术进展
11 months ago
本文主要工作:
实现了一个LLM引导的协议模糊器。提出三种基于LLM的模糊器变异策略,每种策略解决了协议模糊测试的特定挑战。本文实现了灰盒模糊测试算法并命名为CHATAFL。目前该工具已在github开源。
Router4 -- 应用路由扫描基础知识及核心代码浅析
11 months ago
Github发现一个很棒的工具,通过JDI实现了Tomcat 各个版本 Jetty,Spring,Struts,Jersey等中间价框架的路由扫描
致谢信 | 感谢国防科技大学 Alioth 团队对小米安全的帮助与支持
11 months ago
感谢您对小米安全的帮助与支持!
Noname Security Platform Updates: 3.24 Release
11 months ago
Stas Neyman
如何使用 Google 的 Gemini
11 months ago
2023.12.07:Google推出了最新的人工智能模型 Gemini (双子座),看演示视频: https://www.youtube.com/watch? […]
root
猎影观察:在勒索的泥土里,如何阻止大模型开出恶之花?
11 months ago
技术无善恶,考验的是人心
HackTheBox Coder [Bloodhound AD Enumeration + ADCS CVE-2022-26923]
11 months ago
简述
本文是insane难度的HTB Coder机器的域渗透部分,其中Bloodhound AD Enumeration, ADCS CVE-2022-26923等域渗透提权细节是此box的特色,主要参考0xdf’s blog coder walkthrough和HTB的coder官方writeup paper记录这篇博客加深记忆和理解,及供后续做深入研究查阅,备忘。
253
The Do?s and Don?ts of Modern API Security
11 months ago
Abigail Ojeda
Women Can Make a Difference in the Field of Data Science
11 months ago
Tashema Nichols-Jones
网安创业的核心竞争力是成本控制
11 months ago
【学术沙龙】NISL 12月21日活动预告 - TO BE ON AIR
11 months ago
清华大学网络与信息安全实验室学术论文分享活动
OpenAI Begins Tackling ChatGPT Data Leak Vulnerability
11 months ago
OpenAI seems to have implemented some mitigation steps for a well-known data exfiltration vulnerability in ChatGPT. Attackers can use image markdown rendering during prompt injection attacks to send data to third party servers without the users' consent.
The fix is not perfect, but a step into the right direction. In this post I share what I figured out so far about the fix after looking at it briefly this morning.
一些BAT的XSS实例(九)番外篇
11 months 1 week ago
前言本来该系列只有八篇,这篇是由于之前设计题目的过程中,别人给出了多个我没想到的解法思路,所以就专门写了这个
Spike in Atlassian Exploitation Attempts: Patching is Crucial
11 months 1 week ago
In the blog we discuss the importance of securing your Atlassian products, provide valuable insights on various IP activities, and offer friendly advice on proactive measures to protect your organization.
Europol Makes New Ransomware Arrests. But Will It Make Any Difference?
11 months 1 week ago
In the relatively short history of ransomware crime, very few of the professional criminals behind these attacks have ever been brought to justice. So many crimes, so few arrests, and there’s no mystery as to why: Ransomware criminals typically operate from countries with weak or no laws against what they do, and sometimes (stand up, […]
The post Europol Makes New Ransomware Arrests. But Will It Make Any Difference? appeared first on Ransomware.org.
John E. Dunn
Novel Detection of Process Injection Using Network Anomalies
11 months 1 week ago
Ofir Shen
Insights from Survey of Financial Services Cyber Leaders in Asia-Pacific
11 months 1 week ago
Cheryl Chiodi