I Almost Bought a $239 Domain for $1 — A Ghost-Level Bug No One’s Watching
一位安全研究人员发现某域名平台价格字段未进行服务器端验证,可随意篡改价格。他将$239域名改为$1并成功下单,随后负责任披露漏洞但未获回复,漏洞至今未修复。该问题暴露企业对客户端信任的严重缺陷,强调所有关键逻辑必须服务器端验证。
Security researchers from zLabs have discovered a more advanced version of the Konfety Android malware, which uses complex ZIP-level changes to avoid detection and mimic genuine apps on the Google Play Store, marking a dramatic increase in mobile dangers. This malware employs an “evil-twin” strategy, where malicious versions distributed through third-party sources share identical package […]
The post Konfety Android Malware Exploits ZIP Tricks to Masquerade as Legit Apps on Google Play appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.