Aggregator
基于规则的流量加解密工具-CloudX
记一次完整的内网渗透过程总结
yonkies_keygenme_4 代码混淆
利用中间人做tls卸载实现C2检出
Submit #607209: Bludit 3.16.2 Unrestricted Upload [Duplicate]
Submit #607203: Bludit 3.16.2 Improper Neutralization of Alternate XSS Syntax [Duplicate]
Submit #603746: https://github.com/Done-0 https://github.com/Done-0/Jank 9b7b0cb Authorization Bypass [Accepted]
Submit #603726: https://github.com/mao888 https://github.com/mao888/bluebell-plus v2.3.0 Authorization Bypass [Accepted]
JNDI注入内存马并绕过Tomcat高版本
Mysql注入中锁机制的应用
Russia Jailed Hacker Who Worked for Ukrainian Intelligence to Launch Cyberattacks on Critical Infrastructure
Russian Federal Security Service (FSB) officers have detained two hackers in Siberia who conducted cyberattacks on critical infrastructure facilities under direct orders from Ukrainian intelligence services. The simultaneous arrests in the Kemerovo and Tomsk regions exposed a sophisticated cyber espionage network targeting Russia’s governmental, industrial, and financial information systems. The primary suspect, a 36-year-old resident […]
The post Russia Jailed Hacker Who Worked for Ukrainian Intelligence to Launch Cyberattacks on Critical Infrastructure appeared first on Cyber Security News.
Submit #603552: 07FLYCMS https://github.com/lingqifei/07fly-crm V1.3.9 CSRF [Accepted]
Submit #603132: 程序员二师兄 oasys master arbitrary file reading [Duplicate]
Submit #603012: LinBle LBT-T300-T310 v2.2.3.6 Buffer Overflow [Accepted]
某管家公章管理系统审计记录
Threat Actors Turning Job Offers Into Traps, Over $264 Million Lost in 2024 Alone
Cybercriminals are exploiting the economic uncertainty and remote work trends to orchestrate sophisticated employment fraud schemes, with victims losing over $264 million in 2024 alone according to FBI reports. These malicious campaigns, known as “task scams,” represent a rapidly evolving threat landscape where fraudsters weaponize legitimate job-seeking behavior to extract cryptocurrency payments from unsuspecting victims […]
The post Threat Actors Turning Job Offers Into Traps, Over $264 Million Lost in 2024 Alone appeared first on Cyber Security News.
Instagram Started Using 1-Week Validity TLS Certificates and Changes Them Daily
Instagram has adopted an unprecedented approach to web security by implementing daily rotation of TLS certificates that maintain validity periods of just one week, according to a recent technical analysis. This practice represents a significant departure from industry standards, where certificates typically remain valid for 90 days or longer, suggesting a strategic shift toward enhanced […]
The post Instagram Started Using 1-Week Validity TLS Certificates and Changes Them Daily appeared first on Cyber Security News.