Aggregator
《CTF训练营-Web篇》更新:反序列化漏洞(四)Laravel反序列化链分析
找工作 投简历
Unicorn 获取魔改 ollvm 平坦化控制流
Устроиться айтишником мечты оказалось проще, чем кажется — особенно если мечтает о вас Ким Чен Ын
New TxTag Phishing Attack Leverages .gov Domain to Trick Employees
A sophisticated phishing campaign targeting employees with fake toll payment notices has been identified, combining government domain spoofing with social engineering tactics. The attackers craft messages claiming to be from TxTag, warning recipients that their accounts face suspension unless outstanding balances are paid immediately. This campaign leverages urgency and fear to compel victims into clicking […]
The post New TxTag Phishing Attack Leverages .gov Domain to Trick Employees appeared first on Cyber Security News.
Massive 7.3 Tbps DDoS Attack Delivers 37.4 TB in 45 Seconds, Targeting Hosting Provider
У разраба открыт GitHub — у них открыт доступ. Всё благодаря одному пробелу
Microsoft Introduces Enhanced Security Defaults for Windows 365 Cloud PCs
Microsoft has announced a significant update to the security posture of its Windows 365 Cloud PCs, introducing new secure-by-default capabilities designed to fortify virtual desktop environments against modern cyber threats. These changes, set to roll out in the second half of 2025, reflect Microsoft’s ongoing commitment to its Secure Future Initiative (SFI) and the evolving […]
The post Microsoft Introduces Enhanced Security Defaults for Windows 365 Cloud PCs appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
【附下载】一表看清 等保高风险判定 25版与20版变化
20与25版具体事项对比
新增的判例清单
删除的判例清单
20、25版原文
近期,公安部发布了《网络安全等级保护测评高风险判定实施指引(试行)》。与20版本对比后,本文梳理出判例变化项40+,删减项20+,新增项40+,其中安全通用要求新增5项、云计算安全扩展要求新增13项、移动互联安全扩展要求新增10项、物联网安全扩展要求新增4项、工业控制系统安全扩展要求新增9项。
版本
2025版本
2020版本
包含内容
标准要求
标准要求
适用范围
适用范围
问题描述
判例场景
可能的缓解措施
补偿因素
风险评价
特别说明:因时间有限,若有不足之处,请以原文为准
参考资料:
《网络安全等级保护测评高风险判定实施指引(试行)》(2025)
《网络安全等级保护测评高风险判定指引》(2020)
来源:重庆信通设计院天空实验室