Aggregator
针对某黑产组织钓鱼攻击样本分析
SDL 19/100问:如何选择静态代码扫描(SAST)工具?
CVE-2024-24576 Windows 下多语言命令注入漏洞分析
近期来自 Flatt Security Inc. 的 RyotaK 披露了 Windows 下多个编程语言的命令注入漏洞(漏洞被命名为 BatBadBut),其中 Rust 语言对应的漏洞编号为 CVE-2024-24576,因为 Rust 语言自带流量属性,国内安全/科技自媒体可能会使用一些怪异的标题来进行宣传。实际上,这个漏洞跟内存安全没有关系,是 Windows 下 cmd.exe 对命令行参数的特殊解析逻辑所导致的逻辑漏洞;此外,这个漏洞也不仅仅影响 Rust,像 PHP、Python 等语言均受影响。
钓鱼邮件如何确定office附件宏的打开者身份?| 总第241周
Delinea has cloud security incident in Thycotic Secret Server gaff
蹭 Wi-Fi 会不会导致银行密码被盗
HackSpaceCon 2024: Short Trip Report, Slides and Rocket Launch
This week was HackSpaceCon 2024. It was the first time I attended and it was fantastic.
The conference was at the Kennedy Space Center! Yes, right there and the swag and talks matched the world class location.
The keynote “Buckle up! Let’s make the world a safer place” was by Dave Kennedy, who provided great insights on attacker strategies of the past and present, the importance of active threat hunting and challenges ahead. A great specific example he gave was how simple modifications to off-the-shelf malware (still) go entirely under the radar.