Posts of last few hours
Please support the site operations by clicking ads.
本文是对 XSS(Cross-Site Scripting,跨站脚本攻击)的二次回顾与学习总结,主要围绕 XSS 的基本原理、反射型/存储型/DOM 型分类、常见危害以及漏洞探测展开。在此基础上,重点整理了 XSS 中常见的过滤绕过思路,包括双写、大小写、空格、闭合、注释、HTML 实体、事件处理器、伪协议、SVG 等技巧,并结合具体代码分析其产生原因与适用场景。文章最后以 XSS-labs 为主
https://xz.aliyun.com/news/92742
Zygote 是 Android 系统中所有应用进程的"祖先",通过 fork() 机制派生新进程。向 Zygote 注入模块
后,后续所有由 Zygote 生成(fork)出的应用进程都会继承该模块,实现向派生模块注入的效果。
https://xz.aliyun.com/news/92747
把确定性留给系统,把不确定性交给模型。
https://xz.aliyun.com/news/92758
A forum actor posting as Quantique has released what they describe as a dataset scraped from ColisPort, a French parcel-shipping service.
https://darkwebinformer.com/colisport-api-scraped-dataset-claim-covers-19-741-records/
Ireland’s DPC fined Google €403 million over GDPR violations involving location data, transparency, retention and user control. Ireland’s Data Protection Commission (DPC) just fined Google €403 million, and the case behind it goes back six years, to a set of complaints that never really went away. The DPC launched the investigation in February 2020 after […]
https://securityaffairs.com/199494/laws-and-regulations/google-fined-e403-million-over-location-data-practices.html
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical. [...]
https://www.bleepingcomputer.com/news/security/cisa-alerts-of-active-exploitation-of-three-linux-kernel-flaws/
ShinyHunters defaced Clop's Dark Web site and claims to have stolen victim data, potentially exposing organizations that paid ransoms to renewed extortion attempts.
https://www.darkreading.com/cyberattacks-data-breaches/shinyhunters-hacked-clop-what-about-clops-victims
https://cyber.gc.ca/en/alerts-advisories/veeam-security-advisory-av26-513
Ireland’s Data Protection Commission will fine Google more than €403 million ($462 million) over the tech giant’s processing of location data, concluding an inquiry into the company that began in early 2020.
https://therecord.media/google-europe-location-data-fine
Victims have been identified in Africa, including in Kenya and Uganda.
https://www.darkreading.com/cyberattacks-data-breaches/cybercriminals-hiding-new-malware-torrents-popular-films
https://cyber.gc.ca/en/alerts-advisories/misp-security-advisory-av26-946
Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component. [...]
https://www.bleepingcomputer.com/news/security/wordpress-click2shell-flaw-lets-hackers-execute-php-on-the-server/
Hackers targeted two Colorado water utilities, changing OT settings and disabling alarms, but causing no impact on water services or safety. Foreign hackers targeted the operational technology (OT) systems of two small private water utilities in Colorado in late August, apparently trying to disrupt operations. Local authorities haven’t identified the affected utilities or the attackers. […]
https://securityaffairs.com/199480/ics-scada/foreign-hackers-target-two-colorado-water-utilities.html
A forum actor posting as Individual is selling what they claim is a full breach of the Federal Capital Territory Internal Revenue Service (FCT-IRS) in Nigeria.
https://darkwebinformer.com/fct-irs-full-breach-claim-includes-5m-records-and-121k-users/
Microsoft will retire the Calendar, People, and Files Microsoft 365 companion apps on December 16 and has asked admins to remove them from managed devices. [...]
https://www.bleepingcomputer.com/news/microsoft/microsoft-to-retire-microsoft-365-companion-apps-in-december/
A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17.
Microsoft's own hardware-compatibility program signs the driver, scored zero detections on VirusTotal when researchers
https://thehackernews.com/2026/09/fake-lastpass-authenticator-installer.html
https://cyber.gc.ca/en/alerts-advisories/mongodb-security-advisory
The North Korean threat actors behind the Contagious Interview campaign have compromised at least 30,000 devices located in more than 100 countries and siphoned funds or account credentials from over 7,000 cryptocurrency wallets, according to a new joint cybersecurity advisory.
The primary targets of the campaign are individual web designers, engineers, and specialists in cryptocurrency,
https://thehackernews.com/2026/09/contagious-interview-campaign.html
Google has been fined €403 million for breaking the EU's data protection law, the GDPR, in the way three of its features handled people's location data from May 2018 to February 2020.
Ireland's Data Protection Commission (DPC), Google's lead regulator in the EU, also ordered the company to make its processing comply with the law within 6 months. The DPC has not said publicly which
https://thehackernews.com/2026/09/google-fined-403-million-over-gdpr.html
Latest Blog Posts
- 4 weeks 2 days ago
- 3 months ago
- 3 months ago
- 3 months ago
- 3 months ago
- 7 months 3 weeks ago
- 1 year 1 month ago
- 1 year 1 month ago
- 1 year 2 months ago
- 1 year 6 months ago