Aggregator
回归基本功:关于skills,prompt engineering及其安全能力探索
2 months 2 weeks ago
本文是一篇探讨如何将AI(尤其是大语言模型)与Web3智能合约安全审计深度结合的技术实践与方法论文章。基于实际工作经验,提出在AI时代,真正高效的自动化代码审计不应依赖简单的指令或具体的漏洞案例,而应回归“提示词编写(Prompt Engineering)”的基本功。
微软高管表示Xbox Game Pass价格太贵了
2 months 2 weeks ago
嗯,用户让我帮忙总结一下这篇文章的内容,控制在一百个字以内,而且不需要用“文章内容总结”或者“这篇文章”这样的开头。直接写描述就行。首先,我得仔细阅读一下文章内容。
文章主要讲的是微软的新任Xbox负责人阿莎·夏尔马暗示Xbox Game Pass的定价即将变化。她提到Game Pass对玩家来说已经变得过于昂贵,微软需要一个更好的价值等式。此外,微软去年已经将Xbox Game Pass Ultimate的价格提高了50%,涨到了每月29.99美元。
好的,我需要把这些信息浓缩到100字以内。首先,提到负责人是谁,然后说明Game Pass定价要变,因为价格太高了,微软需要调整价值等式,并且提到去年已经涨价了。
可能的结构是:微软Xbox新负责人暗示Game Pass定价变化,因价格过高需调整价值等式,并提到去年已涨价50%。
这样应该能控制在100字以内,并且直接描述内容,没有多余的开头。
微软Xbox新负责人暗示Game Pass定价将变,因价格过高需调整价值等式,并提到去年已涨价50%。
帆软报表FineReport历史漏洞分析(一)
2 months 2 weeks ago
本文对帆软FineReport的项目结构,路由映射和历史漏洞进行详细分析,旨在为想要审计帆软报表的读者提供详尽的入门指南。
ARM64动态指令追踪工具使用与实现分析
2 months 2 weeks ago
ARM64动态指令追踪工具使用与实现分析
谷歌宣布将网站劫持后退按钮视为恶意做法 避免用户点击后退结果跳转到主页
2 months 2 weeks ago
嗯,用户让我总结这篇文章的内容,控制在一百个字以内,而且不需要特定的开头。首先,我得通读一下文章,抓住主要信息。
文章讲的是谷歌搜索开始打击网站劫持后退按钮的行为。劫持后退按钮是指用户点击浏览器的后退按钮时,不是返回到上一个页面,而是被跳转到网站首页或者广告页面。这种行为破坏了用户体验,谷歌因此决定采取措施。
接下来,文章提到截止日期是2026年6月15日,如果不改正,网站可能会被降权甚至清空索引。很多网站都用这种方法来提升流量,但影响用户体验。
所以,总结的时候要包括谷歌打击劫持后退按钮、截止日期以及可能的后果。控制在100字以内的话,需要简洁明了。
可能的表达:“谷歌宣布自2026年6月15日起打击网站劫持浏览器后退按钮行为。该行为迫使用户返回网站首页或广告页而非上一页面,严重破坏用户体验。未改正者将面临降权或清空索引风险。”
这样既涵盖了主要信息,又符合字数限制。
谷歌宣布自2026年6月15日起打击网站劫持浏览器后退按钮行为。该行为迫使用户返回网站首页或广告页而非上一页面,严重破坏用户体验。未改正者将面临降权或清空索引风险。
2026阿里白帽大会 - 破局与重构:多模态AI Agent的红蓝对抗效率革命
2 months 2 weeks ago
2026白帽大会 - 破局与重构:多模态AI Agent的红蓝对抗效率革命
CVE-2026-33119 | Microsoft Edge up to 146.0.3856.84 on Android clickjacking (EUVD-2026-21603 / Nessus ID 305979)
2 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in Microsoft Edge on Android. The impacted element is an unknown function. The manipulation results in clickjacking.
This vulnerability is identified as CVE-2026-33119. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2026-27135 | nghttp2 up to 1.68.0 HTTP/2 nghttp2_session_terminate_session assertion (GHSA-6933-cjhr-5qg6 / EUVD-2026-12919)
2 months 2 weeks ago
A vulnerability identified as problematic has been detected in nghttp2 up to 1.68.0. This impacts the function nghttp2_session_terminate_session of the component HTTP2 Handler. Performing a manipulation results in reachable assertion.
This vulnerability is identified as CVE-2026-27135. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2026-32647 | F5 NGINX Open Source/NGINX Plus ngx_http_mp4_module out-of-bounds (K000160366 / Nessus ID 305582)
2 months 2 weeks ago
A vulnerability labeled as problematic has been found in F5 NGINX Open Source and NGINX Plus. Affected by this issue is the function ngx_http_mp4_module. The manipulation results in out-of-bounds read.
This vulnerability is reported as CVE-2026-32647. The attack requires a local approach. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2026-27784 | F5 NGINX Open Source ngx_http_mp4_module integer overflow (K000160364 / Nessus ID 305646)
2 months 2 weeks ago
A vulnerability marked as critical has been reported in F5 NGINX Open Source. This affects the function ngx_http_mp4_module. This manipulation causes integer overflow.
This vulnerability appears as CVE-2026-27784. The attack requires local access. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CyberStrikeLab-Medal:从 0day 审计到域控权限的全链路渗透复盘
2 months 2 weeks ago
仿真内网、内网渗透、横向移动、权限维持、多层代理、evasion
Cybersecurity in an Age of Geopolitical Fracture
2 months 2 weeks ago
Why Cyber Risk Is Now Shaped as Much by Nations as by Hackers
Wars are becoming more frequent, and are no longer only kinetic. They are just as active in the cyber world, with impacts much larger than can be imagined. This also leads to state-sponsored hacktivists targeting the critical infrastructure of nations.
Wars are becoming more frequent, and are no longer only kinetic. They are just as active in the cyber world, with impacts much larger than can be imagined. This also leads to state-sponsored hacktivists targeting the critical infrastructure of nations.
Why Cloud Intrusions Still Evade Detection
2 months 2 weeks ago
In Open-Source Silicon We Trust: 'Bunnie' Huang's Baochip
2 months 2 weeks ago
Veteran Hardware Hacker's Chip Facilitates More Trustworthy and Secure Devices
How can we trust hardware to not betray us? Enter the Baochip-1x, a piece of largely open-source silicon created by Andrew "Bunnie" Huang, which he said is designed to give developers an affordable, security-focused and attestable chip, not least for building high-assurance, embedded devices.
How can we trust hardware to not betray us? Enter the Baochip-1x, a piece of largely open-source silicon created by Andrew "Bunnie" Huang, which he said is designed to give developers an affordable, security-focused and attestable chip, not least for building high-assurance, embedded devices.
France Tees Up Big Public Sector Move Away From US Tech
2 months 2 weeks ago
European Governments Grow Suspicious of Silicon Valley
French abandonment of American software for open-source alternatives continues apace, with all government ministries now facing a fall deadline for outlining plans to reduce their dependence on U.S. tech. France must "regain control of our digital destiny," said public action minister David Amiel.
French abandonment of American software for open-source alternatives continues apace, with all government ministries now facing a fall deadline for outlining plans to reduce their dependence on U.S. tech. France must "regain control of our digital destiny," said public action minister David Amiel.
Lawsuit: AI Illegally Recorded Doctor-Patient Encounters
2 months 2 weeks ago
Patients Allege Health Entities Did Not Get Consent to Record Conversations
Proposed federal class action litigation alleges that two California healthcare organizations violated patient privacy in their use of an AI-enabled ambient tool that records, transcribes, and processes sensitive conversations between clinicians and patients without individuals' consent.
Proposed federal class action litigation alleges that two California healthcare organizations violated patient privacy in their use of an AI-enabled ambient tool that records, transcribes, and processes sensitive conversations between clinicians and patients without individuals' consent.
Claude Mythos Could Flood Vendors With Fixes They Deferred
2 months 2 weeks ago
Ex-Microsoft CIO: Mythos Could Surface Known Flaws Faster Than Vendors Can Fix Them
Former Microsoft CIO Jim DuBois and IDC's Frank Dickson say Claude Mythos Preview could rapidly surface long-known but unfixed software flaws at scale, forcing vendors and enterprises to strengthen patch validation, orchestration and deployment before attackers exploit the backlog.
Former Microsoft CIO Jim DuBois and IDC's Frank Dickson say Claude Mythos Preview could rapidly surface long-known but unfixed software flaws at scale, forcing vendors and enterprises to strengthen patch validation, orchestration and deployment before attackers exploit the backlog.
Rockstar’s GTA Game Hacked – Attackers published 78.6 Million Records Online
2 months 2 weeks ago
Rockstar Games has confirmed a data breach after the notorious hacking group ShinyHunters exploited a third-party integration to access the company’s internal Snowflake data warehouse, ultimately leaking over 78.6 million records on April 14, 2026. The breach did not stem from a direct attack on Rockstar’s infrastructure. Instead, ShinyHunters leveraged Anodot, an AI-powered cloud cost […]
The post Rockstar’s GTA Game Hacked – Attackers published 78.6 Million Records Online appeared first on Cyber Security News.
Guru Baran
CVE-2026-24291-Windows权限提升漏洞“RegPwn”复现分析
2 months 2 weeks ago
前言这个漏洞是英国 MDSecLabs 的 Filip Dragovic 发现的,据作者讲述,这个漏洞由于很巧妙,它们在红队评估中从2025年1月就开始使用,直到2026年2月报告给微软后,才在3月的补丁星期二修复,这么看也用够本了,原文只是讲了漏洞的核心部分,本文会讲清楚这个漏洞涉及的概念、如何形成的,如何利用它原文地址:https://www.mdsec.co.uk/2026/03/rip-r