Aggregator
星阑科技上榜《CCSIP 2023中国网络安全行业全景册》多个细分领域
1 year 1 month ago
萤火V2.13功能更新快报
1 year 1 month ago
星阑科技上榜《CCSIP 2023中国网络安全行业全景册》多个细分领域
1 year 1 month ago
萤火V2.13功能更新快报
1 year 1 month ago
星阑科技上榜《CCSIP 2023中国网络安全行业全景册》多个细分领域
1 year 1 month ago
萤火V2.13功能更新快报
1 year 1 month ago
Google Gemini: Planting Instructions For Delayed Automatic Tool Invocation
1 year 1 month ago
Last November, while testing Google Bard (now called Gemini) for vulnerabilities, I had a couple of interesting observations when it comes to automatic tool invocation.
Confused Deputy - Automatic Tool Invocation First, what do I mean by this… “automatic tool invocation”…
Consider the following scenario: An attacker sends a malicious email to a user containing instructions to call an external tool. Google named these tools Extensions.
When the user analyzes the email with an LLM, it interprets the instructions and calls the external tool, leading to a kind of request forgery or maybe better called automatic tool invocation.
Millions of Undetectable Malicious URLs Generated Via the Abuse of Public Cloud and Web 3.0 Services
1 year 1 month ago
Major Cellular Outage in the U.S.
1 year 1 month ago
Summary
At approximately 0330 eastern time in the United States, over 70 thousand AT&T users reported interruptions in their mobile, internet, and home phone services. There outage is not currently being attributed any any cyber attacks.
Threat Type
Critical Infrastructure Outage
Overview
AT&T is currently investigating a network outage affecting over 70 thousand of their customers. The outage reportedly began at about 0330 eastern time. Initial reports claimed that this outage also affected T-Mobile and
长亭珂兰寺招生简章
1 year 1 month ago
一篇文章了解珂兰寺
Everything you need to know about IP grabbers
1 year 1 month ago
Unsuspecting users beware, IP grabbers do not ask for your permission.
【工具分享】一款针对Spring Boot的开源渗透框架(持续更新中)
1 year 1 month ago
Spring Boot的开源渗透框架,主要用作扫描Spring Boot的敏感信息泄露端点,并可以直接测试Spring的相关高危漏洞。
用mshta让bat以管理员身份运行
1 year 1 month ago
这种技巧我这辈子都用不上,是不是在一些不太合法的需求中用得着啊
CSS实现表格对角线
1 year 1 month ago
杨龙
《少年黑客》第六季,久违的少年黑客团,继续闪耀!
1 year 1 month ago
「深蓝洞察」2023 年度最多面的漏洞
1 year 1 month ago
深蓝洞察年度安全报告第三篇
APT-C-24(SideWinder)组织新威胁:基于Nim的载荷浮出水面
1 year 1 month ago
近期,我们捕获到了SideWinder针对不丹、缅甸、尼泊尔的攻击样本,这类样本主要是通过宏文档释放Nim语言编译的攻击载荷,这类载荷在响尾蛇历史攻击者中很少见。鉴于此情况,本文重点披露响尾蛇组织使用的这类组件。
给互联网人的反侦查手册 2.0
1 year 1 month ago
屏幕另一端的人严肃地提出了第一个问题:“2022 年 x 月 x 日,你在 x 点 x 分 x 秒你打开了 xx 文档,你先是快速滑动页面,之后在 xx 位置停 […]
root
Exploitation Observed: Ivanti Connect Secure ? CVE-2023-46805 and CVE-2024-21887
1 year 1 month ago
Noam Atias & Sam Tinklenberg