Posts of last few hours
Please support the site operations by clicking ads.
CVE-2026-74610 是 Linux 内核 ktls 子系统新近披露的漏洞,因散射链表处理错误导致越界。本文主要分析该漏洞原理,并给出可用于验证漏洞的poc
https://xz.aliyun.com/news/92741
MI5 warns UK universities that over 100 academics may have unknowingly worked on research funded by a Chinese institute linked to the MSS. On September 30, MI5 published a formal warning naming the China General Technology Research Institute, CGTRI, also called CAGT in some translations, as an outfit with very strong ties to China’s Ministry […]
https://securityaffairs.com/200396/intelligence/mi5-raises-alarm-over-chinese-funding-of-uk-academic-research.html
Следствие получило редкий шанс заглянуть внутрь одной из самых закрытых киберпреступных сетей.
https://www.securitylab.ru/news/578281.php
记录一次真实众测中的攻击面扩展过程。文中资产信息均已脱敏,仅用于技术交流。
https://xz.aliyun.com/news/92800
用 CE + x32dbg 定位背包、仓库、周围怪物 NPC 三类成组数据的基址与偏移,重点讲回溯卡在全局变量上时的三条破解思路。
https://xz.aliyun.com/news/92844
本文是对 XSS(Cross-Site Scripting,跨站脚本攻击)的二次回顾与学习总结,主要围绕 XSS 的基本原理、反射型/存储型/DOM 型分类、常见危害以及漏洞探测展开。在此基础上,重点整理了 XSS 中常见的过滤绕过思路,包括双写、大小写、空格、闭合、注释、HTML 实体、事件处理器、伪协议、SVG 等技巧,并结合具体代码分析其产生原因与适用场景。文章最后以 XSS-labs 为主
https://xz.aliyun.com/news/92742
Dify 1.16.1 版本中,发现未授权SSRF漏洞,这与之前的CVE-2025-29720、CVE-2025-56520属于同地址的漏洞,但是我并未在公网上找到详细的分析报告,而且版本很靠前,为什么最新版本的还是会存在这个问题,那就一种可能修了没修好,不管怎么修该有问题下一个版本还是这里出问题。 第二个漏洞就是代码沙箱的网络访问,直接创建节点就可以进行ssrf+命令执行
https://xz.aliyun.com/news/92812
本文复现奶龙杯 CTF 中四道 Pwn 题目的解题过程,涵盖静态链接 ROP、栈对齐绕过、Seccomp 下自修改代码构造 ORW 链及格式化字符串泄露 Canary 结合栈溢出利用。
https://xz.aliyun.com/news/92716
Iranian hacker Amir Barati faces extradition to the US over an alleged Iranian campaign that stole 31TB of data from universities. Amir Barati spent June 25 getting arrested in Montenegro, and this week a Montenegrin court signed off on sending him to the United States. He’s a dual Turkish and Iranian citizen, 40 years old, […]
https://securityaffairs.com/200387/security/iranian-hacker-accused-of-draining-31tb-from-university-inboxes-extradited-to-the-us.html
自主进攻性网络作战已经到来。
https://mp.weixin.qq.com/s?__biz=MzU0MzgyMzM2Nw==&mid=2247487224&idx=1&sn=e65a318daa7175f9adcbc262add3a835
面向若依生态的专项漏洞扫描器实现解析:三态判定降低误报、AI 生成 POC 自验证回灌、nuclei 模板兼容,附靶场实战验证与真实 POC 代码。
https://xz.aliyun.com/news/92740
Базовые станции смогут временно замолкать во время специальных мероприятий.
https://www.securitylab.ru/news/578294.php
本文记录了多道 Web CTF 题目的分析与解题过程,涵盖 PHP 反序列化、客户端逻辑篡改、路径穿越、SSTI、CBC 字节翻转、参数与请求方法绕过、信息泄露以及 Shiro 反序列化等常见 Web 安全漏洞。文章通过分析题目源码、前端 JavaScript 和接口逻辑,结合实际请求与脚本利用,逐步还原漏洞成因及利用链路。其中包括利用 PHP 反序列化修改对象属性、篡改前端游戏状态并绕过服务端校
https://xz.aliyun.com/news/92786
Google has now suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded by AI-generated reports. [...]
https://www.bleepingcomputer.com/news/google/google-halts-open-source-bug-bounty-program-amid-ai-spam-surge/
2026polarctf秋季赛部分题解,接触agent之后第一次比较独立的比赛,简单题较多,难一点的依旧搓不出来
https://xz.aliyun.com/news/92787
Directus 默认 SSRF 黑名单只防了 AWS 那个 metadata 地址——国产云(腾讯云 169.254.0.23、阿里云 100.100.100.200)一个都没拦。链 A 用 editor 账号打 import 端点直接拉回实例指纹;链 B 用 Webhook Flow 零账号匿名触发。配套 import-ssrf-audit.py 加 --metadata-check 模式,3
https://xz.aliyun.com/news/92720
Latest Blog Posts
- 3 hours 9 minutes ago
- 3 hours 9 minutes ago
- 3 hours 9 minutes ago
- 3 hours 10 minutes ago
- 3 hours 10 minutes ago
- 3 hours 10 minutes ago
- 3 hours 10 minutes ago
- 3 hours 10 minutes ago
- 3 hours 10 minutes ago
- 3 hours 10 minutes ago