password
icon
URL
type
date
summary
status
slug
tags
category
免责声明:本文章中的信息和观点仅代表引用网站或者原作者,本网站只是引用其观点、内容,不代表本网站、公众号、黑客驰本人的观点或立场。本文章论述内容仅作为教育参考使用,如有违法行为与本网站和黑客驰无关,国法无情,自行负责。
将我们的公众号内容加星获得隐藏内容。
↘️以下为目录,点击可跳转,右划点击标题跳转到原文
安全团队博客
来源
Tags
摘要
标题
发布时间
不安全
SatGus卫星由CrunchLabs所有,用于为客户提供太空自拍服务。该卫星通过屏幕和摄像头拍摄照片,并以400.2MHz和2,262.5MHz频率传输信号。技术爱好者尝试接收信号但因加密无法解码。
Mar 13, 2025
不安全
Windows
M. Khanfar发布了新的频谱可视化软件"Fosphor Spectrum Visualization Windows Version",基于GNU Radio和GPU加速的Fosphor引擎,支持RTL-SDR、Airspy和HackRF设备的实时频谱分析和频率扫描功能。该软件免费但不开源,并可能被 antivirus 软件误报为可疑程序。
Mar 13, 2025
不安全
勒索软件
数据泄露
医疗巨头的法律威胁引发斯特雷桑效应,Medusa勒索软件团伙改用邮票而非暗网。播客探讨数据泄露、学生被捕、安全公司失误等安全事件。
Mar 13, 2025
不安全
研究人员发现一个大规模加密货币投资诈骗活动,通过假冒知名品牌和事件吸引受害者,并承诺高回报进行诈骗。这些虚假平台利用标准化工具包生成,并通过特定域名注册和云服务隐藏真实位置。活动主要针对东非和亚洲用户,并利用社交媒体和Telegram推广。
Mar 13, 2025
不安全
Tails
作者想用Tailscale加密VPS连接但因WireGuard不适用转而使用V2ray协议,并寻求替代方案、类似协议及建议。
Mar 13, 2025
不安全
文章描述了通过Elastic Discover查询并导出CSV格式的数据,利用Power BI进行分析的过程。重点展示了如何对@timestamp字段进行拆分,并通过可视化揭示了特定IP的活动规律、文件上传行为及潜在威胁。
Mar 13, 2025
不安全
微软
微软修复OneDrive共享文件夹变快捷方式问题,因后端迁移不完整导致部分用户无法访问已持续近一年。未完成迁移的用户受影响严重,微软仅提供网页版作为临时解决方案。
Mar 13, 2025
不安全
谷歌
谷歌更新Play Protect功能,允许用户临时暂停扫描并在次日自动恢复。此功能旨在方便用户安装第三方APK文件,但建议用户除非必要否则不应禁用该选项以确保安全。
Mar 13, 2025
不安全
行为分析
安全事件响应
文章探讨了人工智能在网络安全攻防中的应用与挑战。提出六个最佳实践:自学习AI提升威胁检测能力、自动化钓鱼防御、加速安全事件响应、持续强化攻击面、利用行为分析和AI检测内部威胁以及人机协同的AI模式。强调企业需将AI与人类专业知识结合,在“AI VS. AI”的对抗中保持优势。
Mar 13, 2025
不安全
三星
暴力破解
文章描述了三星Galaxy设备在Auracast功能中存在广播代码安全漏洞。默认情况下,设备生成的4字符广播代码仅由2个随机字节组成,易被暴力破解。攻击者可利用此漏洞解密广播内容甚至劫持广播。三星已修复该问题,将默认代码长度增加至6字节,并生成更安全的随机密码。
Mar 13, 2025
不安全
长江存储推出多款固态硬盘新品,包括企业级PCIe 5.0 PE511(最高32TB)、消费级PCIe 5.0 PC550(TLC颗粒)及PCIe 4.0 PC450和PC42Q(QLC颗粒),满足不同需求。
Mar 13, 2025
不安全
文章介绍了错误代码521的原因及解决方法,指出该错误通常由服务器连接问题、ISP故障或配置错误引起,并建议检查网络连接、联系ISP或调整服务器设置以解决问题。
Mar 13, 2025
不安全
后门
Backdoor
数据泄露
近期发现基于Python的AnubisBackdoor后门程序频繁出现,由Savage Ladybug组织开发,与FIN7有关。该恶意软件可提供远程访问权限、执行命令并推动数据泄露,采用FUD技术躲避检测,在垃圾邮件攻击中被广泛使用。
Mar 13, 2025
不安全
黑客
用户怀疑其移动设备被黑客入侵,并描述了在使用Humanbenchmark等游戏时遇到的异常现象,包括侮辱性词汇频繁出现、Facebook账户被盗以及收到Discord上的威胁信息。此外,设备还出现照片替换和异常关机等问题。用户在r/IT社区未获有效回应后寻求进一步帮助。
Mar 13, 2025
不安全
微软
Windows
微软发布3月安全更新补丁,修复了Windows、Office等产品的57个漏洞,其中6个为关键级高危漏洞。多个漏洞已遭在野利用,建议用户尽快安装补丁以防范风险。
Mar 13, 2025
不安全
黑客
/r/netsec 是一个由社区管理的信息安全聚合平台,旨在为安全从业者、学生、研究人员和黑客提供高质量的技术内容。
Mar 13, 2025
不安全
Linux
Meta警告称FreeType库存在被积极利用的高危漏洞(CVE-2025-27363),影响版本2.13.0及以下。该漏洞可能导致任意代码执行。多个Linux发行版受影响,建议升级至FreeType 2.13.3修复。
Mar 13, 2025
不安全
APT攻击
钓鱼攻击
文章分析了2024年全球APT攻击的技术演进与防御策略,揭示了0day漏洞利用、供应链投毒及生成式AI在钓鱼攻击中的应用。同时指出地缘政治冲突加剧APT威胁,并提出基于AI的安全解决方案以提升威胁检测能力,构建主动防御体系应对未来网络攻防挑战。
Mar 13, 2025
不安全
Cloudflare
防火墙
文章介绍了错误代码521的原因及解决方法,指出该错误通常与Cloudflare服务相关,可能由服务器配置问题、防火墙设置不当或网络连接异常引起,并提供了检查服务器状态、验证防火墙设置和联系网络服务提供商等解决步骤。
Mar 13, 2025
不安全
西部数据
OpenAI发布新AI Agent工具和API;西部数据推出26TB NAS硬盘;Pocket Casts Web播放器免费;小红书禁止站外交易导流。
Mar 13, 2025
不安全
后门
Windows
Windows Server
微软
微软修复了自2023年3月起被利用的Windows NT内核子系统安全漏洞(CVE-2025-24983),该漏洞被PipeMagic后门用于权限提升和数据窃取。仅影响Windows 10 v1809、Windows Server 2019及更早版本,Windows 11不受影响。微软因漏洞利用复杂性拖延两年修复。
Mar 13, 2025
不安全
黑客
黑客组织Lazarus上传恶意软件包至npm平台;SolarWinds网络帮助台曝漏洞可解密敏感密码;其他安全威胁与漏洞亦被曝光。
Mar 13, 2025
不安全
SQL注入
数据泄露
远程代码执行
GLPI软件存在未认证SQL注入漏洞, 可通过构造XML请求触发, 造成数据库数据泄露及远程代码执行风险, 影响企业网络安全性.
Mar 13, 2025
山石网科安全技术研究院
虽然利用条件较多,但漏洞影响还是非常广泛的,建议使用相关版本的用户尽快升级安全更新。
Mar 11, 2025
代码审计星球
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
Mar 13, 2025
安全研究GoSSIP
New season! ATEC 2025 • AI & Robotics Real-World Challenges
Mar 9, 2025
看雪学院
GDA中含多个由作者独立研究的高速分析引擎,例如反编译引擎、漏洞检测引擎、恶意行为检测引擎、污点传播分析引擎、反混淆引擎、apk壳检测引擎等。
Mar 13, 2025
绿盟科技CERT
远程代码执行
近日,绿盟科技CERT监测到Apache发布安全公告,修复了Apache Tomcat远程代码执行漏洞(CVE-2025-24813),目前已成功复现,请相关用户尽快采取措施进行防护。
Mar 11, 2025
绿盟科技CERT
Microsoft
Windows
微软
远程代码执行
3月12日,绿盟科技CERT监测到微软发布3月安全更新补丁,修复了57个安全问题,涉及Windows、Microsoft Office、Azure等广泛使用的产品,其中包括权限提升、远程代码执行等高危漏洞类型。
Mar 12, 2025
天融信阿尔法实验室
远程代码执行
3月11日,天融信阿尔法实验室监测到Tomcat官方发布了一个安全公告,修复了一个特定条件的远程代码执行漏洞(CVE-2025-24813)。建议受影响用户尽快升级。
Mar 11, 2025
腾讯玄武实验室
远程代码执行
Kibana 原型污染漏洞致远程代码执行;Solr服务器上获得RCE的一种巧妙方法;改进的ChaCha密码分析:用位穿刺突破PNBs
Mar 12, 2025
Seebug Paper
作者:DARKNAVY
原文链接:https://mp.weixin.qq.com/s/lUA03YjBiCAatcJh-bUHEQ
近年来,漏洞攻防不断演进。从多年前仅需一个栈溢出就能攻破系统,到如今需要运用各种精妙的手法来突破系统的层层防御。“盾”与“矛”始终处于动态对抗:每当新的防御措施出现,新的攻击手段随之而来。防御机制的升级促使攻击者寻找新的突破口,而攻击方法的创新又推动着防御技术...
Mar 10, 2025
Seebug Paper
作者:DARKNAVY
原文链接:https://mp.weixin.qq.com/s/LaM5iz_EKbAK_lkaAcBshw
在攻防对抗日益激烈的2024年,安全软件一直被视为企业安全防线的重要基石。然而,这些安全软件本身也可能存在漏洞,甚至被攻击者利用作为入侵的跳板来对用户造成危害。多年来,因为安全软件而导致的事故不禁让人产生一个疑问——安全软件真的可信吗?
安全软件被滥用为攻击工...
Mar 11, 2025
Seebug Paper
作者:DARKNAVY
原文链接:https://mp.weixin.qq.com/s/Y8-wT88VnLeMUiD-HssPyw
在网络安全领域,漏洞披露一直被视为保护用户的重要环节,但在现实中,这一过程却充满了争议和矛盾。究竟什么才算得上“负责任的披露”?当厂商在信息公开和补丁发布上占据主导地位,而安全研究者则需要耗费大量精力进行沟通与博弈,这一模式是否还能真正实现保护用户安全的初衷?...
Mar 12, 2025
Seebug Paper
.katex img {
display: block;
position: absolute;
width: 100%;
height: inherit;
}
作者:0x7F@知道创宇404实验室
日期:2025年2月28日
1. 前言
在「机器学习的线性回归模型」文章中,我们学习了监督学习中如何使用线性回归模型拟合连...
Mar 13, 2025
绿盟科技技术博客
目录: ☆ 背景介绍 ☆ 基本思路 ☆ MergeFile.py ☆ Repomix ☆ gitseek.de<p class="more-link"><a class="themebutton" href="https://blog.nsfocus.net/ai-3/">Read More</a></p>
Mar 10, 2025
绿盟科技技术博客
数据泄露
摘要 :2025年初大模型数据泄露集中爆发,安全威胁直击核心数据与用户隐私,本文深度剖析五大事件,敲响AI安全<p class="more-link"><a class="themebutton" href="https://blog.nsfocus.net/ai-4/">Read More</a></p>
Mar 10, 2025
绿盟科技技术博客
本週热点概览 威胁通告 Ollama 配置不当未授权访问漏洞(CNVD-2025-04094)通告 VMwar<p class="more-link"><a class="themebutton" href="https://blog.nsfocus.net/2025-03-03-2025-03-09/">Read More</a></p>
Mar 10, 2025
绿盟科技技术博客
一、基础知识概述 近日,绿盟科技CERT监测到Apache发布安全公告,修复了Apache Tomcat远程代<p class="more-link"><a class="themebutton" href="https://blog.nsfocus.net/cve-2025-24813/">Read More</a></p>
Mar 11, 2025
SecWiki News(国内外安全资讯)
今日暂未更新资讯~<br />更多最新文章,请访问<a href="http://www.sec-wiki.com/">SecWiki</a>
Mar 9, 2025
SecWiki News(国内外安全资讯)
<a href="https://mp.weixin.qq.com/s/rILsn-iZOKdzeY6IinanTA" target="_blank">虚拟汽车的CAN总线攻防实战</a> by ourren<br /><br /><a href="https://mp.weixin.qq.com/s/Yu-Pyrng4CXCZk-SMureOg" target="_blank">Claude 3.7与DeepSeek R1软件开发能力评测</a> by ourren<br /><br /><a href="https://mp.weixin.qq.com/s/cWN8X06nRHL9Ya
Mar 10, 2025
SecWiki News(国内外安全资讯)
今日暂未更新资讯~<br />更多最新文章,请访问<a href="http://www.sec-wiki.com/">SecWiki</a>
Mar 11, 2025
SecWiki News(国内外安全资讯)
模糊测试
<a href="http://cjc.ict.ac.cn/online/onlinepaper/wqy-2024923151544.pdf" target="_blank">智能模糊测试综述:问题探索和方法分类</a> by ourren<br /><br />更多最新文章,请访问<a href="http://www.sec-wiki.com/">SecWiki</a>
Mar 12, 2025
FreeBuf互联网安全新媒体平台
马斯克回应其社交媒体平台 X 出现故障的问题,称其为一次针对 X 的大规模网络攻击。
Mar 11, 2025
FreeBuf互联网安全新媒体平台
零日漏洞
苹果
苹果紧急修复第三个在2025年被利用的零日漏洞CVE-2025-24201,攻击者通过恶意网页突破沙箱限制,影响多款设备。
Mar 11, 2025
FreeBuf互联网安全新媒体平台
勒索软件
零日漏洞
Windows
VMware
Windows与VMware零日漏洞正被勒索软件和APT组织利用,OpenSSH十年老漏洞重现,管理员需立即进行修复。
Mar 12, 2025
FreeBuf互联网安全新媒体平台
其根源在于可预测的加密密钥和 nonce 重用,使得即使没有直接系统访问权限,也能解密存储的秘密信息。
Mar 12, 2025
FreeBuf互联网安全新媒体平台
谷歌
谷歌紧急警告:别对Chromecast进行出厂重置。过期证书导致2000万台设备无法正常运行,用户陷入“变砖”困境。
Mar 12, 2025
FreeBuf互联网安全新媒体平台
GitHub
AI 辅助的虚假 GitHub 仓库窃取敏感数据,伪装合法项目分发 Lumma Stealer 恶意软件。
Mar 12, 2025
FreeBuf互联网安全新媒体平台
macOS
新型XCSSET恶意软件利用增强混淆技术攻击macOS用户,感染Xcode项目,窃取敏感信息,采用复杂持久化机制,威胁开发者安全。
Mar 12, 2025
FreeBuf互联网安全新媒体平台
黑客
API攻击威胁加剧:59%的组织开放API“写入”权限,黑客可未经授权访问,导致数据窃取、账户接管等重大风险。
Mar 12, 2025
FreeBuf互联网安全新媒体平台
零日漏洞
VMware
微软
微软与VMware零日漏洞紧急修复指南;TP-Link漏洞感染超6000台设备
Mar 12, 2025
FreeBuf互联网安全新媒体平台
至少400个IP地址被发现同时利用多个SSRF漏洞,攻击尝试之间表现出显著的重叠。
Mar 12, 2025
嘶吼
邮件安全
<p>3月13日(周四)15:00直播,立即扫码预约,一键占座!</p><p><br />直播亮点抢先看:<br />✔前沿洞察:大模型在邮件安全领域的破局之路<br />✔新品发布:CACTER大模型邮件安全网关首秀<br />✔跨界论道:清华学者&技术大拿共话AI防御演进<br /><br />CACTER大模型邮件安全网关重磅登场!大模型赋能邮件安全,精准智御新型恶意威胁,守护邮件安全防线,超多功能等你揭秘~</p><p style="text-align: center;"><img alt="直播海报.png" src="https://img.4hou.com/upload
Mar 11, 2025
嘶吼
<p style="text-align: center;"><img alt="[email protected]" src="https://img.4hou.com/uploads/ueditor/php/upload/image/20250311/1741661442120605.png" title="1741661442120605.png" /></p><p>在 Python JSON Logger 包(python-json-logger)中,发现了一个严重影响版本 3.2.0 和 3.2.1 的重大漏洞,编号为 CVE-2025-27607。该漏洞因对缺失依赖项
Mar 11, 2025
嘶吼
<p>来自新疆的全国政协委员拟为治理“AI生成不实信息”提出建言。</p><p>2025年全国两会即将召开,全国政协委员、新疆新的社会阶层人士联谊会副会长海尼扎提·托呼提拟向大会提交“关于加强AI生成不实信息治理”等提案,建议社交媒体平台等互联网平台加强内容审核机制,建立专门的AI生成内容审核团队,对平台内容执行严格监管。</p><p>随着人工智能技术的迅猛发展,AI生成不实信息的问题愈发严重,成为信息传播领域面临的一大新挑战。“这些不实信息通常具有迷惑性强、刺激度高、传播力广等特点,不仅侵蚀了信息的真实性,还扰乱了社会秩序与公众认知。”前述提案举例说,在甘肃首例AI虚假信息案中,洪某弟利用C
Mar 11, 2025
嘶吼
中国
<p>近日,中国计算机学会(CCF)计算机安全专委会和上海市计算机学会网络专委会联合发起2025年网络安全十大趋势预测活动。来自国家网络安全主管部门、高校、科研院所、国有企业及民营企业界的专家学者,投票评选出了2025年网络安全十大发展趋势。</p><p><strong>趋势1:人工智能广泛赋能网络安全</strong></p><p>随着人工智能(AI)技术的飞速发展,其已逐渐渗透到网络安全的各个层面。AI在网络安全中的应用,如通过机器学习算法自动检测异常行为、预测潜在威胁,以及利用自然语言处理技术分析安全日志,能显著提升安全检测的效率与准确性。例如,AI可以实时分析海量网络数据,快速识别出恶
Mar 11, 2025
嘶吼
<p>近年来,中央网信办持续部署开展“清朗”系列专项行动,集中时间、集中力量打击网上各类乱象问题,从严处置违规平台和账号,取得积极成效,形成有力震慑。2025年,“清朗”系列专项行动将进一步巩固提升治理成效,聚焦人民群众反映强烈的突出问题,在破解难点瓶颈方面下功夫,强化源头管理和基础管理;在治理创新方面下功夫,针对性细化每个专项打法举措;在维护网民权益方面下功夫,严厉打击各类侵权违法行为,营造更加清朗有序的网络环境。</p><p>重点整治任务主要包括:一是整治春节网络环境,集中打击挑起极端对立、炮制不实信息、宣扬低俗恶俗、鼓吹不良文化、违法活动引流等问题。二是整治“自媒体”发布不实信息,包括发
Mar 11, 2025
嘶吼
<p>“315”已经成为保护消费者权益的符号和标志,对市场规范起到示范作用。微热点研究院基于2023年、2024年同期315晚会传播数据分析及近期舆论传播态势,结合近期消费及投诉热点,分析315期间维权领域热点,以供参考。</p><p><span style="font-size: 20px;"><strong>315晚会影响力逐年提高</strong></span></p><p>历史同期数据显示,315晚会影响力呈明显增长态势,全网信息量、媒体报道量均有较大增长。统计时段内,315晚会的全网信息量由2023年的13.64万条增至2024年的33.16万条,增幅达143.1%,侧面说明315晚
Mar 11, 2025
嘶吼
远程代码执行
<p style="text-align: center;"><img alt="image.png" src="https://img.4hou.com/uploads/ueditor/php/upload/image/20250312/1741746800389310.png" title="1741746651615498.png" /></p><p>Apache Camel 中近期披露的一个安全漏洞(编号为 CVE - 2025 - 27636),已引发整个网络安全社区的高度警惕。该漏洞允许攻击者向 Camel Exec 组件配置注入任意标头,进而有可能实现远程代码执行(RCE)。</
Mar 12, 2025
嘶吼
<p>近日,丈八网安凭借其技术领先性和全面务实的网络安全人才培养解决方案,以及丰富的校企合作项目经验,入选教育部产学合作协同育人项目企业名单。未来,丈八网安将定向投入丰富的技术、内容、服务资源,用于合作高校的教学体系、师资培训体系和实践基地建设工作。</p><p>产学合作协同育人项目是教育部为贯彻《国务院办公厅关于深化高等学校创新创业教育改革的实施意见》和《国务院办公厅关于深化产教融合的若干意见》精神,深化产教融合、推动高等教育改革而推出的重要举措。通过项目实施,能够实现人才培养与企业需求的无缝对接,促进教育与产业的深度融合和高质量发展。在此背景下,丈八网安在长期校企合作实践中不断摸索,通过对
Mar 12, 2025
深信服千里目安全实验室
2025年3月11日,深瞳漏洞实验室监测到一则Apache-Tomcat组件存在代码执行漏洞的信息,漏洞编号:CVE-2025-24813,漏洞威胁等级:高危。
Mar 11, 2025
深信服千里目安全实验室
Fortinet
2025年3月12日,深瞳漏洞实验室监测到一则Fortinet多产品存在代码执行漏洞的信息,漏洞编号:CVE-2024-45324,漏洞威胁等级:高危。
Mar 12, 2025
深信服千里目安全实验室
微软
2025年3月12日(北京时间),微软发布了2025 年 23月安全更新,共发布了58个CVE的补丁程序,同比上月减少了9个。
Mar 12, 2025
锦行信息安全
2025年3月7日,由广西职业技术学院主办,广西职业技术学院大数据学院及广州锦行网络科技有限公司承办的“智能网联汽车数据安全专家研讨会暨人工智能网联汽车数据安全创新实验室揭牌仪式”在广西职业技术学院隆重举行。
Mar 10, 2025
极客公园
索尼
华为
零跑 B10 试驾车到店:15 万内激光雷达城区智驾 SUV,3 月 10 日预售;索尼宣布高层人事调整,陶琳被任命为集团首位女性 CFO;消息称华为组建医疗卫生军团,推动医疗大模型临床应用
Mar 9, 2025
极客公园
特斯拉
特斯拉无人出租车亮相得州工厂;健康专家警示:AI 伴侣可补充但不能替代现实社交关系;黑鲨发布「支持手势刷短视频」的魔戒 2 智能戒指。
Mar 10, 2025
极客公园
美股市场遭遇“黑色星期一”,纳斯达克指数盘中重挫逾3%;零跑旗下全新车型 B10 今日正式启动预售,价格为 10.98 万-13.98 万元。;二手平台发布号称“3D 打印SU7 Ultra车标商品”,售价在 9.9 元至 168 元不等
Mar 11, 2025
极客公园
DeepSeek 官方辟谣:R2 发布为假消息
Mar 12, 2025
极客公园
美国
谷歌
特斯拉
苹果
苹果确认 Siri 新功能延期;马斯克:承诺两年内将特斯拉在美国的汽车产量翻倍;谷歌联合创始人秘密研究AI 3D 打印飞机。
Mar 13, 2025
丁爸情报分析师的工具箱
美国
美国陆军的绝密、绝精锐第 1 能力整合大队(空降),或称第 1 CIG,于 1981 年正式成立,后被称为情报支援部队 (INTELLIGENCE SUPPORT ACTIVITY (ISA) )。
Mar 9, 2025
丁爸情报分析师的工具箱
美国
美国自二战后逐步建立起庞大的海外军事基地网络,目前国防部(DOD)在至少51个国家管理或使用128个海外基地。
Mar 10, 2025
安全引擎
Google
Google 在 2019 年提出了 V3 版本的Chrome扩展程序标准。V3 标准在性能和安全性上都有不少提升,但是由于兼容性问题和开发者强烈反对,一再推迟,直到最近 V2 大限终至。
近期打开 Chrome 之后发现多个扩展插件开始罢工,包括居家必备的扩展程序 Proxy SwitchyOmega。
其实这个插件已经有 V3 版本,但是考虑到今年初有一大批 Chrome 扩展被钓鱼投毒,主要受害者就包括 Proxy SwitchyOmega V3 在内。
于是决定尝试从零写一个自用的代理切换工具,用 Cursor 半小时搞定,功能简单,够用。
代码已开源,自取,没做详尽测试,欢迎
Mar 11, 2025
喜马拉雅安全响应平台
春归万物生,漏洞无处藏!值此安全焕新季,SRC平台开启「春日双倍活动」,诚邀白帽子聚焦服务器、数据泄漏高危漏洞,提交有效漏洞即可享双倍奖励!用技术唤醒安全生机,让挖洞更有“春意”!
Mar 10, 2025
数世咨询
黑客
谷歌
谷歌 2024 年漏洞赏金计划,1200 万美元奖励安全研究人员,诚邀白帽黑客找bug
Mar 12, 2025
白泽安全实验室
黑客
数据泄露
近日,一起大规模的数据泄露事件震动了网络安全界。名为“HikkI-Chan”的黑客在臭名昭著的Breach Forums上泄露了超过3.9亿VK用户的个人信息。
Mar 10, 2025
90Sec - 专注于网络空间安全
行为分析
<p>杀毒软件的检测方式,主要还是靠特征匹配,虽然现在有很多<strong>行为分析</strong>的杀软,但归根结底,它们还是在监控<strong>API 调用模式</strong>。问题是,合法软件和恶意软件调用的 API 大部分是一样的,所以行为检测很容易误判。而且,只要换个编译器、改改代码,很多恶意软件就能成功绕过查杀。</p>
<p>为了更稳妥地避开杀毒软件,我们可以采用远程分离免杀(Remote Loader)的方法——本地只运行一个下载器(Loader),shellcode放在远程服务器上,运行时再下载并执行,本地并无实际文件落地;这样杀软在扫描本地文件时什么都抓不到。</p>
Mar 12, 2025
CNVD漏洞平台
国家信息安全漏洞共享平台(以下简称CNVD)本周共收集、整理信息安全漏洞291个,其中高危漏洞120个、中危漏洞163个、低危漏洞8个。
Mar 10, 2025
青衣十三楼飞花堂
黑客
Phrack的纯文本还将传承那份探索与自由的黑客精神。正如第31期所言:“无论名为何物,Phrack承载的是我们的黑客历史和初心。”这盏灯塔的光芒,将永远照亮技术世界的每一个角落。
Mar 10, 2025
雷神众测
雷神众测拥有该文章的修改和解释权。如欲转载或传播此文章,必须保证此文章的副本,包括版权声明等全部内容。声明雷神众测允许,不得任意修改或增减此文章内容,不得以任何方式将其用于商业目的。
Mar 10, 2025
吾爱破解论坛
内有福利,再送40个账号注册码或300论坛币,吾爱破解论坛开放注册时间:2025年3月13日 12:00 -- 14:00 和 20:00 -- 22:00,赶紧上好闹钟顺便告诉小伙伴吧。
Mar 10, 2025
CNNVD安全动态
近日,国家信息安全漏洞库(CNNVD)收到关于Apache Tomcat安全漏洞(CNNVD-202503-1068、CVE-2025-24813)情况的报送。
Mar 11, 2025
中国信息安全
数据经纪人模式旨在围绕创新数据开发应用场景,构建包括了解用户需求、挖掘数据产品、构建数据模型、匹配市场需求等在内的全链路支撑体系。随着大数据技术的发展和数字经济的兴起,数据经纪人的业务范围逐渐拓展。
Mar 10, 2025
中国信息安全
大力提升乡村数字治理能力,要强化问题意识,采取有效措施,促进数字技术与乡村治理深度融合,提升乡村治理效能,使数字技术真正赋能乡村治理。
Mar 10, 2025
中国信息安全
中国
中国代表团团长、外交部网络和数字事务协调员王磊在联合国信息安全开放式工作组第十期会上的发言
Mar 10, 2025
中国信息安全
当前,随着以Deepseek为代表的高效推理大模型快速发展和广泛部署,数据汇聚产量低、供给质量低、利用效率低的矛盾愈发突出,高质量数据集建设的重要性日益显现。应从供给、标准、安全、价值多向发力,做好高质量数据集建设工作,赋能行业高质量发展。
Mar 10, 2025
中国信息安全
当前,电信网络诈骗犯罪形势依然严峻复杂,电诈手段不断演变升级,呈现出犯罪组织集团化、犯罪链条专门化、犯罪类型复杂化等特点。尤其是许多犯罪分子将诈骗活动的触角延伸至境外,通过跨境作案逃避法律制裁,给司法办案带来新挑战。
Mar 11, 2025
中国信息安全
近日,国家信息安全漏洞库收到关于Apache Tomcat安全漏洞(CNNVD-202503-1068、CVE-2025-24813)情况的报送。
Mar 11, 2025
中国信息安全
现代
当今世界,信息化高度发达,无形的电磁身影无处不在,从手机信号到电视广播,从Wi-Fi到蓝牙……电磁信号已成为现代人类生产、生活中如影随形的信息传输媒介,在带给我们便利生活的同时,也暗藏着敏感信息泄露的风险。
Mar 11, 2025
中国信息安全
我国正处于大力发展数据事业的关键时期,近年来党中央国务院高度重视数据要素市场培育及公共数据资源开发利用。全国一体化公共数据资源登记平台于2025年3月1日正式上线,标志着数据要素市场化配置改革迈出重要一步。
Mar 11, 2025
中国信息安全
黑客
病毒
海量的数据是宝贵的生产资料,但对数据的挖掘利用也带来新的问题——信息泄露、黑客攻击、病毒传播等问题频发,以及数据资源的合理利用、合规监管等都成为政府机构、企事业单位数据整合、共享和协同计算的障碍。
Mar 11, 2025
安全学术圈
谷歌
利用静态程序分析技术,对谷歌商店上的2.2M个应用程序如何访问剪贴板数据,如何处理剪贴板数据,以及这些行为在多大程度上暴露了严重的安全和隐私风险进行了分析。
Mar 10, 2025
安全学术圈
本文主要研究WebRTC中DTLS握手过程的流量识别方法,在Docker环境中采集流量,采用基于流量统计特征的提取方法,最终利用多层感知器(MLP)模型判断流量是否为Snowflake流量。
Mar 11, 2025
奇安信威胁情报中心
黑客
威胁情报
Google
奇安信威胁情报中心发现了一个规模巨大且能够劫持受害者Google搜索内容和电商链接等的黑客团伙,基于 PDNS 数据发现该团伙从 2021 年开始活跃,并且恶意域名在 OPENDNS 的 top 1m 列表中,全球受影响的终端至少百万级别。
Mar 11, 2025
Zgao's blog
通常在docker run 时可能会忘记添加必要的端口映射,但是在运行成功后,想要添加新的端口映射。网上给出的</div><div class="blog-btn"><a class="home-blog-btn" href="https://zgao.top/%e4%b8%ba%e6%ad%a3%e5%9c%a8%e8%bf%90%e8%a1%8c%e4%b8%addocker%e5%ae%b9%e5%99%a8%e5%8a%a8%e6%80%81%e6%b7%bb%e5%8a%a0%e7%ab%af%e5%8f%a3%e6%98%a0%e5%b0%84/">阅读更多</a>
Mar 10, 2025
安全牛
牛览网络安全全球资讯,洞察行业发展前沿态势!
Mar 11, 2025
不安全
数据泄露
文章介绍了通过Unicode标签和变体选择符实现文本隐藏的技术,并提出了Sneaky Bits工具,利用两个不可见的Unicode字符编码任何Unicode字符。该技术可用于数据隐藏、注入攻击及数据泄露,并探讨了潜在风险及缓解措施。
Mar 13, 2025
FreeBuf互联网安全新媒体平台
研究团队最近发现了一种复杂的浏览器攻击技术,该技术允许恶意扩展程序冒充受害者浏览器上安装的任何扩展程序。
Mar 10, 2025
FreeBuf互联网安全新媒体平台
该组织自至少2012年以来一直活跃,主要目标是中亚国家的警察、军队、海事和海军部队。
Mar 11, 2025
FreeBuf互联网安全新媒体平台
后门
黑客
供应链攻击
朝鲜 Lazarus 黑客通过 npm 包发起供应链攻击,窃取凭证、部署后门并提取加密货币信息。
Mar 11, 2025
FreeBuf互联网安全新媒体平台
谷歌
谷歌2024年向漏洞猎人们支付了1800万美元,累计奖金超6500万,安卓和云漏洞奖励达新高,展现其持续强化安全防护的紧迫决心。
Mar 11, 2025
FreeBuf互联网安全新媒体平台
瑞士
瑞士NCSC要求关键基础设施组织在遭受网络攻击后24小时内报告,否则将面临高额罚款。
Mar 11, 2025
FreeBuf互联网安全新媒体平台
数据泄露
处置旧设备时,数据未彻底删除可能被恢复,导致身份盗窃、金融欺诈或企业数据泄露。立即采取安全擦除或物理销毁措施,避免敏感信息落入不法分子之手。
Mar 10, 2025
FreeBuf互联网安全新媒体平台
4300万Python安装面临RCE攻击!未注册依赖项漏洞(GHSA-wmxh-pxcx-9w24)威胁严重。
Mar 10, 2025
FreeBuf互联网安全新媒体平台
勒索软件
Black Basta 勒索软件组织泄露大量内部聊天记录,揭示其全球攻击策略与工具库,对 500 多家实体造成严重威胁,尤其是医疗行业,双重勒索手段使其成为网络安全领域的重大挑战。
Mar 10, 2025
FreeBuf互联网安全新媒体平台
身份认证
资产搜索时发现某学校的统一身份认证处的找回密码功能,发现需要对应手机号,前期信息收集中并未找到某个学生的手机号,但是其系统存在找回手机号功能,需要对应学生的学号和身份证号,所以我们接下来需要去找到某一
Mar 10, 2025
FreeBuf互联网安全新媒体平台
攻击者可以利用反射型XSS漏洞,通过在目标网站中注入恶意iframe代码,加载攻击者的网站,并修改window.name来执行跳转和弹出窗口攻击。具体步骤如下:攻击者在目标网站的输入框或URL参数中注
Mar 11, 2025
代码审计星球
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
Mar 11, 2025
FreeBuf互联网安全新媒体平台
勒索软件
EDR
本期《Security Affairs》周报揭露了多起重大网络攻击事件,包括勒索软件绕过EDR检测、国际执法行动查封非法交易所,以及多个关键漏洞被利用,凸显网络安全形势的严峻性。
Mar 9, 2025
FreeBuf互联网安全新媒体平台
#gogs #Craft-API #py-eval #vault-toke-SSH权限提升
Mar 9, 2025
不安全
Slack
文章指出敏感信息泄露不仅存在于代码仓库中,还可能通过开发者使用的协作工具(如Slack、Teams、Jira)暴露。Cycode通过实时扫描这些平台检测敏感数据,并提供自动修复功能以减少安全风险。
Mar 11, 2025
不安全
Google
Google Chrome逐步淘汰Manifest V2扩展,导致uBlock Origin被禁用,用户受影响。Chrome商店停止提供下载,Firefox仍支持该扩展。
Mar 11, 2025
不安全
Google
澳大利亚
Google为已停更的Pixel 4a发布更新以提升电池稳定性。澳大利亚监管机构指出该机型部分电池存在过热起火风险,建议更新固件或更换电池。
Mar 11, 2025
不安全
Google
浏览器安全
Google发布Chrome浏览器安全更新134.0.6998.88/89,修复五个高风险漏洞,其中三个为严重级别。这些漏洞涉及V8 JavaScript引擎和GPU组件的类型混淆、越界写入等问题,可能导致任意代码执行或沙盒逃逸。建议用户立即更新以防范潜在威胁。
Mar 11, 2025
不安全
远程代码执行
防火墙
SQL注入
勒索软件
Cyble蜜罐传感器检测到针对WordPress插件、网络设备及防火墙等的漏洞攻击,包括远程代码执行、SQL注入等高危漏洞。威胁行为者利用这些漏洞进行勒索软件攻击或加入僵尸网络,并持续扫描易受攻击的设备。建议组织立即修补漏洞、阻止恶意IP及加强密码策略以应对持续威胁。
Mar 11, 2025
不安全
GDPR
GDPR保障个人数据隐私,NIS 2保护关键基础设施安全。两者通过风险管理、技术措施和组织流程相互补充,共同构建安全、可靠且有弹性的数字环境。
Mar 11, 2025
不安全
ICS Security / VulnerabilityTaiwanese company Moxa has released a security update to address a cr
Mar 11, 2025
不安全
Cyber Espionage
Cyber Espionage / Maritime SecurityMaritime and logistics companies in South and Southeast Asia, t
Mar 11, 2025
不安全
本文探讨了本地大模型的推理框架与应用工具,介绍了llama.cpp项目及其支持的硬件与量化策略,并展示了通过Ollama和Open WebUI等工具轻松部署与使用大模型的方法。此外,还讨论了大模型在对话机器人、编程辅助、笔记软件及自动化流程等场景中的实际应用。
Mar 11, 2025
不安全
Cybersecurity Challenges in Cross-Border Data Transfers and Regulatory Compliance Str
Mar 11, 2025
不安全
#加密货币 微策略 (MSTR) 趁着比特币价格下跌再次增发 210 亿美元优先股 STRK 用于收购比特币,微策略的说明很清楚,就是为了筹集资金增持比特币。目前微策略持有 49.9
Mar 11, 2025
不安全
开曼群岛发布新法规要求加密货币托管和交易公司必须申报并获得许可才能开展业务。新条例于 4 月 1 日实施,相关公司要在 6 月 29 日前提交申报,披露托管的加密货币类型和数量、安全存储等方面的工作。
Mar 11, 2025
不安全
博通
VMware
博通收购VMware后通过改革许可证模式和捆绑销售策略大幅提升营收。其软件业务季度营收增长10亿美元,前万名客户中70%转向高价VCF订阅套餐。尽管价格上涨引发不满和部分客户转向开源方案,但多数企业仍依赖VMware技术。
Mar 11, 2025
不安全
iOS
微软
Windows
微软将于5月27日从商店中删除微软远程桌面(红色图标),用户需转用新的Windows App(蓝色图标)。PC版仅支持工作和学校账户登录使用;iOS版则无需登录即可使用。
Mar 11, 2025
不安全
微软
Windows
微软收购动视暴雪后,玩家对Xbox兴趣增加但销量下滑。微软计划推出Xbox品牌掌机Keenan,并于2027年推出下一代主机。新掌机运行Windows系统并突出PC Game Pass;下一代主机将更接近Windows生态并支持第三方应用商店。
Mar 11, 2025
不安全
谷歌
前谷歌CEO埃里克·施密特收购并领导Relativity Space,该公司转型开发大型火箭Terran R,不再使用3D打印技术。计划今年完成测试火箭制造,并于明年试射,目标是每年发射50至100枚火箭。
Mar 11, 2025
不安全
r/netsecstudents是一个网络安全性学习社区,提供资源分享、问题解答和互助学习环境。用户询问是否有成员尝试过Black Hills InfoSec的Wifi-Forge工具用于Wi-Fi破解,并提到该工具的Docker镜像较大。
Mar 11, 2025
不安全
微软
Windows
微软修复了Windows 11 24H2与AutoCAD 2022的兼容性问题,用户需将AutoCAD更新至2022.1.4或更高版本后方可升级系统。其他版本如AutoCAD 2023至2025不受影响。
Mar 11, 2025
不安全
微软
微软开始处理Xbox跨区低价购买游戏的行为,部分用户被临时封禁后解封。微软称使用VPN跨区订阅属欺诈性获取内容,并未实施永久封号策略。科技公司通常根据不同地区的购买力和价格进行差异化定价,导致用户寻求低价区购买。尽管如此,完全禁止跨区订阅仍有难度。
Mar 11, 2025
不安全
Cloudflare
文章描述了一个网络错误代码521的情况,通常与Cloudflare服务相关,表示服务器未能响应请求或连接超时。
Mar 11, 2025
不安全
美国
特朗普签署命令利用美国扣押的比特币建立战略储备,并未计划自行购买。此举被视为象征性举措,可能影响加密货币市场。
Mar 11, 2025
不安全
This is the first part of a series of blog posts about techniques to bypass web filters, lo
Mar 11, 2025
不安全
Ivanti
CISA
美国
美国网络安全机构CISA将Advantive VeraCore和Ivanti EPM的多个高危漏洞加入已知被利用目录,指出越南威胁团伙XE集团正利用VeraCore漏洞进行攻击,而Ivanti EPM漏洞虽未公开被利用但已有PoC代码。机构需在2025年3月前修复以防范风险。
U.S. CISA adds Advantive VeraCore and Ivanti EPM flaws to its Known Exploited Vulnerabilities catalog
Mar 11, 2025
不安全
文章指出AI公司通过免费提供产品培养用户习惯,改变期望,迫使企业采用其技术以满足用户需求,从而实现盈利。
Mar 11, 2025
不安全
GRC工程将治理、风险和合规融入日常运营,通过自动化和实时监控提升效率与安全性。与传统繁琐的手动流程不同,它整合技术与团队协作,减少审计压力并增强业务优势。
Mar 11, 2025
不安全
联想
微软
Windows
微软计划推出Xbox品牌的贴牌游戏掌机,由华硕、联想等厂商生产。该设备将搭载完整Windows 11系统,并优化游戏兼容性和用户体验。预计于今年晚些时候发布,并可能在2027年推出下一代Xbox主机。
Mar 11, 2025
不安全
DoS攻击
黑客
DDoS攻击
X/Twitter昨晚遭DDoS攻击致多次中断,埃隆·马斯克称攻击源为乌克兰。黑客组织暗黑风暴发布声明称对此负责,并与乌克兰无关。该组织通过Telegram直播攻击过程,并对马斯克的指控表示不满。未来可能继续针对X/Twitter发起攻击。
Mar 11, 2025
不安全
Cloudflare
文章介绍了错误代码521的原因及其解决方法。该错误通常由服务器超时引起,常见于Cloudflare服务中。用户可检查服务器状态、优化网络配置或联系主机提供商以解决问题。
Mar 11, 2025
不安全
苹果
macOS
Apple
iOS
苹果计划在2025年重新设计iOS 19和macOS 16系统,摒弃自iOS7以来的设计风格,灵感或来自Apple visionOS的浮动式、半透明和圆形图标设计,以提升用户体验。
Mar 11, 2025
不安全
微软
Windows
微软发布 Copilot for Windows 11 测试版,新增语音对话功能,支持通过快捷键 Alt + 空格键启动对话,并可通过 ESC 结束对话。
Mar 11, 2025
不安全
iOS
开源邮件客户端 Thunderbird 计划于今年晚些时候推出 iOS 版本,并在今年底发布 Alpha 测试版本,提供基本的邮件显示和发送功能。该客户端目前支持桌面和安卓平台,iOS 版本正在开发中。
Mar 11, 2025
不安全
苹果
欧盟拟对苹果和Meta小额罚款以警告其违反数字市场法案,苹果开放功能但仍有诸多限制,Meta也面临类似处罚。特朗普曾威胁干预,此次温和处罚或避免冲突。
Mar 11, 2025
不安全
GitHub
Intel
IntelliJ IDEA 2023.2版後不再支援Resin Plugin,改用JSR 45替代略顯不便。開發者在GitHub發現resin_idea插件,手動安裝後可恢復Resin功能,提升class和JSP的除錯效率。此插件適用於2024.2.0.2版本。
Mar 11, 2025
不安全
在一个糟糕的大学课程中,学生尝试破解基于用户名的加密算法以生成特定用户的解决方案。尽管花费了两个小时,仍未成功解决挑战。
Mar 11, 2025
不安全
黑客
该页面介绍了一个黑客社区,旨在帮助新手成长为老手,提供问答和学习平台,并邀请用户加入Discord进行交流。
Mar 11, 2025
不安全
这是一个网络安全部门的学生交流社区,在Reddit上提供资源分享、问题解答和互助学习的机会。
What to expect from Junior Network Security Engineer ? , Like what he must know to land Job in this tough market
Mar 11, 2025
不安全
闪迪宣布涨价超10%,归因于供需失衡与关税压力;HTC推出93美元入门机型Wildfire E5 Plus;鸿海发布企业级大模型FoxBrain;马斯克称X遭网络攻击;一加确认砍掉经典三段式开关设计。
Mar 11, 2025
不安全
ISC Stormcast播客于2025年3月11日发布,值班处理员为Xavier Mertens,当前威胁级别为绿色。用户计划参加4月13日至18日在奥兰多举办的“应用安全:保护Web应用、API和微服务”课程。
ISC Stormcast For Tuesday, March 11th, 2025 https://isc.sans.edu/podcastdetail/9358, (Tue, Mar 11th)
Mar 11, 2025
不安全
黑客
这是一个黑客社区,旨在帮助新手成长为专家。用户可以提问、回答和学习地下技能,并通过Discord进行交流。
Hey guys i hope you all are doing good in your life. Am quiet curious about how much hackers earn from bug bounty on monthly basis and yearly basis. Am not into tech background but i love what you guys do and it makes me really happy too see such cool peoples. And is there any other way to earn?
Mar 11, 2025
不安全
David Cowen宣布将于2025年3月26日主持关于法律网络安全问题的小组讨论,参与者包括同事、法律顾问及法官Ada Brown,读者可点击链接注册。
Mar 11, 2025
不安全
作者分享了自己尝试制作少数派周边产品的经历,介绍了串珠技法(如Peyote、Brick等)、珠子选择及设计软件,并表达了希望与社区共同设计的愿望。
Mar 11, 2025
不安全
NTT
日本
特朗普将封禁DeepSeek?外交部回应;日本电信巨头 NTT系统遭入侵,1.8 万企业客户信息恐遭窃取 | 牛览 日期:2025年03月11日
Mar 11, 2025
不安全
Ivanti
CISA
HP
德国
中国
CISA将五个影响Advantive VeraCore和Ivanti EPM的安全漏洞加入已知被利用目录。VeraCore的漏洞被越南威胁组织XE Group利用,而EPM的三个漏洞尚未有公开利用报告。同时,PHP-CGI的关键漏洞CVE-2024-4577正被大规模攻击,主要来自德国和中国。
Mar 11, 2025
不安全
HP
惠普
惠普打印机固件更新致原装墨盒无法使用,出现错误代码11。受影响型号为HP LaserJet M232-M237系列,惠普正在调查并建议用户联系支持团队解决问题。
Mar 11, 2025
不安全
XML External Entity (XXE) vulnerabilities are one of the most overlooked yet impactful vulnerabiliti
Mar 11, 2025
不安全
DoS攻击
Cloudflare
黑客
DDoS攻击
亲巴勒斯坦黑客组织暗黑风暴对X/Twitter发起大规模DDoS攻击,导致平台多次中断。最终通过Cloudflare拦截恶意流量恢复服务。该组织未透露攻击细节但直播进度,预计后续可能继续攻击。
Mar 11, 2025
不安全
VMware
黑客
上周安全动态涵盖Bybit黑客事件、VMware漏洞修复及Kerberos更新等新闻,同时介绍了Detection Studio和ZeroProbe等新工具与技术。
Mar 11, 2025
网安新闻
来源
Tags
摘要
标题
发布时间
安全牛
在软件供应链安全的世界里,安全与效率的平衡始终是企业面临的核心挑战。传统安全管理工具往往陷入两难境地:要么为了 […]
Mar 10, 2025
安全牛
摘要: 2024年3月5日,十四届全国人大二次会议在北京召开,“新质生产力”首次被写入政府工作报告,并在报告中 […]
Mar 10, 2025
安全牛
DeepSeek-R1上线后即遭遇持续恶意攻击,开源软件漏洞引爆全球供应链危机,暗网“勒索即服务(RaaS)” […]
Mar 10, 2025
安全牛
黑客
数据泄露
在黑客攻击日益复杂、数据泄露事件频频登上新闻头条的背景下, CISO肩负着保护企业数字资产、维护声誉和确保合规 […]
Mar 11, 2025
安全牛
新闻速览 •特朗普将封禁DeepSeek?外交部回应 •工信部CSTIS提醒:防范网站被攻击网页被篡改的风险 […]
Mar 11, 2025
安全牛
瑞士
新闻速览 •瑞士出台新规,关键基础设施运营商要在24小时内报告网络攻击 •马斯克X平台被连续击垮,Dark S […]
Mar 12, 2025
安全牛
新闻速览 •数据保护不力致20万驾照信息泄露,Allstat子公司National  General […]
Mar 13, 2025
安全牛
人工智能技术的发展正在深刻影响着网络安全领域。一方面,AI赋能了网络攻击手段的自动化和智能化,使得攻击者能够更 […]
Mar 13, 2025
安全牛
2024年,全球APT组织通过技术跃迁、组织升级等不断演化和扩张,已将攻击的魔爪伸向影响更广泛、更具破坏性的领 […]
Mar 13, 2025
SecWiki News
今日暂未更新资讯~<br />更多最新文章,请访问<a href="http://www.sec-wiki.com/">SecWiki</a>
Mar 9, 2025
SecWiki News
<a href="https://mp.weixin.qq.com/s/rILsn-iZOKdzeY6IinanTA" target="_blank">虚拟汽车的CAN总线攻防实战</a> by ourren<br /><br /><a href="https://mp.weixin.qq.com/s/Yu-Pyrng4CXCZk-SMureOg" target="_blank">Claude 3.7与DeepSeek R1软件开发能力评测</a> by ourren<br /><br /><a href="https://mp.weixin.qq.com/s/cWN8X06nRHL9Ya
Mar 10, 2025
SecWiki News
今日暂未更新资讯~<br />更多最新文章,请访问<a href="http://www.sec-wiki.com/">SecWiki</a>
Mar 11, 2025
SecWiki News
模糊测试
<a href="http://cjc.ict.ac.cn/online/onlinepaper/wqy-2024923151544.pdf" target="_blank">智能模糊测试综述:问题探索和方法分类</a> by ourren<br /><br />更多最新文章,请访问<a href="http://www.sec-wiki.com/">SecWiki</a>
Mar 12, 2025
FreeBuf
马斯克回应其社交媒体平台 X 出现故障的问题,称其为一次针对 X 的大规模网络攻击。
Mar 11, 2025
FreeBuf
零日漏洞
苹果
苹果紧急修复第三个在2025年被利用的零日漏洞CVE-2025-24201,攻击者通过恶意网页突破沙箱限制,影响多款设备。
Mar 11, 2025
FreeBuf
勒索软件
零日漏洞
Windows
VMware
Windows与VMware零日漏洞正被勒索软件和APT组织利用,OpenSSH十年老漏洞重现,管理员需立即进行修复。
Mar 12, 2025
FreeBuf
其根源在于可预测的加密密钥和 nonce 重用,使得即使没有直接系统访问权限,也能解密存储的秘密信息。
Mar 12, 2025
FreeBuf
谷歌
谷歌紧急警告:别对Chromecast进行出厂重置。过期证书导致2000万台设备无法正常运行,用户陷入“变砖”困境。
Mar 12, 2025
FreeBuf
GitHub
AI 辅助的虚假 GitHub 仓库窃取敏感数据,伪装合法项目分发 Lumma Stealer 恶意软件。
Mar 12, 2025
FreeBuf
macOS
新型XCSSET恶意软件利用增强混淆技术攻击macOS用户,感染Xcode项目,窃取敏感信息,采用复杂持久化机制,威胁开发者安全。
Mar 12, 2025
FreeBuf
黑客
API攻击威胁加剧:59%的组织开放API“写入”权限,黑客可未经授权访问,导致数据窃取、账户接管等重大风险。
Mar 12, 2025
FreeBuf
零日漏洞
VMware
微软
微软与VMware零日漏洞紧急修复指南;TP-Link漏洞感染超6000台设备
Mar 12, 2025
安全文摘
作者:DARKNAVY
原文链接:https://mp.weixin.qq.com/s/lUA03YjBiCAatcJh-bUHEQ
近年来,漏洞攻防不断演进。从多年前仅需一个栈溢出就能攻破系统,到如今需要运用各种精妙的手法来突破系统的层层防御。“盾”与“矛”始终处于动态对抗:每当新的防御措施出现,新的攻击手段随之而来。防御机制的升级促使攻击者寻找新的突破口,而攻击方法的创新又推动着防御技术...
Mar 10, 2025
安全文摘
作者:DARKNAVY
原文链接:https://mp.weixin.qq.com/s/LaM5iz_EKbAK_lkaAcBshw
在攻防对抗日益激烈的2024年,安全软件一直被视为企业安全防线的重要基石。然而,这些安全软件本身也可能存在漏洞,甚至被攻击者利用作为入侵的跳板来对用户造成危害。多年来,因为安全软件而导致的事故不禁让人产生一个疑问——安全软件真的可信吗?
安全软件被滥用为攻击工...
Mar 11, 2025
安全文摘
作者:DARKNAVY
原文链接:https://mp.weixin.qq.com/s/Y8-wT88VnLeMUiD-HssPyw
在网络安全领域,漏洞披露一直被视为保护用户的重要环节,但在现实中,这一过程却充满了争议和矛盾。究竟什么才算得上“负责任的披露”?当厂商在信息公开和补丁发布上占据主导地位,而安全研究者则需要耗费大量精力进行沟通与博弈,这一模式是否还能真正实现保护用户安全的初衷?...
Mar 12, 2025
安全文摘
.katex img {
display: block;
position: absolute;
width: 100%;
height: inherit;
}
作者:0x7F@知道创宇404实验室
日期:2025年2月28日
1. 前言
在「机器学习的线性回归模型」文章中,我们学习了监督学习中如何使用线性回归模型拟合连...
Mar 13, 2025
FreeBuf
研究团队最近发现了一种复杂的浏览器攻击技术,该技术允许恶意扩展程序冒充受害者浏览器上安装的任何扩展程序。
Mar 10, 2025
FreeBuf
后门
黑客
供应链攻击
朝鲜 Lazarus 黑客通过 npm 包发起供应链攻击,窃取凭证、部署后门并提取加密货币信息。
Mar 11, 2025
FreeBuf
谷歌
谷歌2024年向漏洞猎人们支付了1800万美元,累计奖金超6500万,安卓和云漏洞奖励达新高,展现其持续强化安全防护的紧迫决心。
Mar 11, 2025
FreeBuf
数据泄露
处置旧设备时,数据未彻底删除可能被恢复,导致身份盗窃、金融欺诈或企业数据泄露。立即采取安全擦除或物理销毁措施,避免敏感信息落入不法分子之手。
Mar 10, 2025
FreeBuf
4300万Python安装面临RCE攻击!未注册依赖项漏洞(GHSA-wmxh-pxcx-9w24)威胁严重。
Mar 10, 2025
FreeBuf
勒索软件
Black Basta 勒索软件组织泄露大量内部聊天记录,揭示其全球攻击策略与工具库,对 500 多家实体造成严重威胁,尤其是医疗行业,双重勒索手段使其成为网络安全领域的重大挑战。
Mar 10, 2025
FreeBuf
身份认证
资产搜索时发现某学校的统一身份认证处的找回密码功能,发现需要对应手机号,前期信息收集中并未找到某个学生的手机号,但是其系统存在找回手机号功能,需要对应学生的学号和身份证号,所以我们接下来需要去找到某一
Mar 10, 2025
FreeBuf
攻击者可以利用反射型XSS漏洞,通过在目标网站中注入恶意iframe代码,加载攻击者的网站,并修改window.name来执行跳转和弹出窗口攻击。具体步骤如下:攻击者在目标网站的输入框或URL参数中注
Mar 11, 2025
FreeBuf
勒索软件
EDR
本期《Security Affairs》周报揭露了多起重大网络攻击事件,包括勒索软件绕过EDR检测、国际执法行动查封非法交易所,以及多个关键漏洞被利用,凸显网络安全形势的严峻性。
Mar 9, 2025
威胁情报
来源
Tags
摘要
标题
发布时间
Dark Reading
Microsoft
Microsoft has identified a complex, malvertising-based attack chain that delivered Lumma and other infostealers to enterprise and consumer PC users; the campaign is unlikely the last of its kind.
Mar 10, 2025
Dark Reading
In the battle against two-minute micro-attacks that can knock out critical communication services, the difference between success and failure can literally come down to seconds.
Mar 10, 2025
Dark Reading
Windows
Clandestine kill switch was designed to lock out other users if the developer's account in the company's Windows Active Directory was ever disabled.
Mar 10, 2025
Dark Reading
Check Point
The South American-based advanced persistent threat group is using an exploit with a "high infection rate," according to research from Check Point.
Mar 10, 2025
Dark Reading
The program underwent a series of changes in the past year, including richer maximum rewards in a variety of bug categories.
Mar 10, 2025
Dark Reading
India
The likely India-based threat group is also targeting logistics companies in a continued expansion of its activities.
Mar 10, 2025
Dark Reading
RAT
An email campaign luring users with offers of free President Trump meme coins can lead to computer takeover via the ConnectWise RAT, in less than 2 minutes.
Mar 11, 2025
Dark Reading
Analysts weigh in on how democratizing cybersecurity could benefit organizations, particularly SMBs, as threats increase across the landscape.
Mar 11, 2025
Dark Reading
While deregulation may open opportunities for growth and innovation, it also creates new risks that demand a proactive, accountable approach to security.
Mar 11, 2025
Dark Reading
RAT
A Libya-linked threat actor has resurfaced attacking the Middle East and North Africa, using the same old political phishing tricks to deliver AsyncRAT that have worked for years.
Mar 11, 2025
Dark Reading
Plankey has served in numerous cybersecurity positions in the past, including during the first Trump presidency from 2018-2020.
Mar 11, 2025
Dark Reading
Microsoft
The number of zero-day vulnerabilities getting patched in Microsoft's March update is the company's second-largest ever.
Mar 11, 2025
Dark Reading
To truly become indispensable in the boardroom, CISOs need to meet the dual demands of defending against sophisticated adversaries while leading resilience strategies.
Mar 12, 2025
Dark Reading
In the past, the vulnerability was exploited to drop Mirai botnet malware. Today, it's being used once more for another botnet campaign with its own malware.
Mar 12, 2025
Dark Reading
The prolonged attack, which lasted 300+ days, is the first known compromise of the US electric grid by the Voltzite subgroup of the Chinese APT; during it, the APT attempted to exfiltrate critical OT infrastructure data.
Mar 12, 2025
Dark Reading
iOS
A threat actor leveraged the vulnerability in an "extremely sophisticated" attack on targeted iOS users, the company says.
Mar 12, 2025
Dark Reading
The National Institute of Standards and Technology (NIST) has released updated differential privacy guidelines for organizations to follow to protect personally identifiable information when sharing data.
Mar 12, 2025
Dark Reading
Shell
Mandiant researchers found the routers of several unnamed organizations (likely telcos and ISPs) were hacked by UNC3886, and contained a custom backdoor called "TinyShell."
Mar 12, 2025
Dark Reading
United Arab Emirates
Following increasing attacks on healthcare organizations, the United Arab Emirates has refined its regulatory strategy for improving cybersecurity in healthcare.
Mar 13, 2025
Dark Reading
Symantec
Researchers from Symantec showed how OpenAI's Operator agent, currently in research preview, can be used to construct a basic phishing attack from start to finish.
Mar 13, 2025
Malwarebytes Labs
Malwarebytes Premium Security has once again been awarded “Product of the Year” after successfully blocking 100% of “in-the-wild” malware samples.
Mar 10, 2025
Malwarebytes Labs
A list of topics we covered in the week of March 3 to March 9 of 2025
Mar 10, 2025
Malwarebytes Labs
An increasing number of websites use a clipboard hijacker and instruct victims on how to infect their own machine.
Mar 10, 2025
Malwarebytes Labs
This week on the Lock and Code podcast, we speak with Tim Shott about his attempt to find his location data following a major data breach.
How ads weirdly know your screen brightness, headphone jack use, and location, with Tim Shott (Lock and Code S06E05)
Mar 10, 2025
Malwarebytes Labs
In the early morning hours of March 10, thousands of users on X (formerly Twitter) began having trouble logging into the...
Mar 10, 2025
Malwarebytes Labs
Android
Google
Google spies on Android device users, starting from even before they have logged in to their Google account.
Mar 12, 2025
Malwarebytes Labs
Sports betting is a multi-billion-dollar industry, but behind the flashing lights and promises of easy money lies a hidden underworld of deception.
Mar 12, 2025
Malwarebytes Labs
Apple
iPadOS
iOS
Apple has patched a vulnerability in iOS and iPadOS that was under active exploitation in extremely sophisticated attacks.
Mar 12, 2025
Unit 42 by Palo Alto Networks
<p>We identified a campaign spreading thousands of sca crypto investment platforms through websites and mobile apps, possibly through a standardized toolkit.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/fraud-crypto-platforms-campaign/">Investigating Scam Crypto Investment Platforms
Mar 13, 2025
渗透测试
来源
Tags
摘要
标题
发布时间
PortSwigger Security Blog
Why now? Artificial intelligence is rapidly transforming industries, and security testing is no exception. At PortSwigger, we’ve always been driven by innovation, but we don’t chase trends for the sak
Mar 12, 2025
PortSwigger Security Blog
Security is a team sport. Whether you're a pentester, bug bounty hunter, student, or just love breaking (and fixing) things, our field thrives on shared knowledge, collaboration, and support. We want
Mar 13, 2025
Paper安全渗透
作者:DARKNAVY
原文链接:https://mp.weixin.qq.com/s/lUA03YjBiCAatcJh-bUHEQ
近年来,漏洞攻防不断演进。从多年前仅需一个栈溢出就能攻破系统,到如今需要运用各种精妙的手法来突破系统的层层防御。“盾”与“矛”始终处于动态对抗:每当新的防御措施出现,新的攻击手段随之而来。防御机制的升级促使攻击者寻找新的突破口,而攻击方法的创新又推动着防御技术...
Mar 10, 2025
Paper安全渗透
作者:DARKNAVY
原文链接:https://mp.weixin.qq.com/s/LaM5iz_EKbAK_lkaAcBshw
在攻防对抗日益激烈的2024年,安全软件一直被视为企业安全防线的重要基石。然而,这些安全软件本身也可能存在漏洞,甚至被攻击者利用作为入侵的跳板来对用户造成危害。多年来,因为安全软件而导致的事故不禁让人产生一个疑问——安全软件真的可信吗?
安全软件被滥用为攻击工...
Mar 11, 2025
Paper安全渗透
作者:DARKNAVY
原文链接:https://mp.weixin.qq.com/s/Y8-wT88VnLeMUiD-HssPyw
在网络安全领域,漏洞披露一直被视为保护用户的重要环节,但在现实中,这一过程却充满了争议和矛盾。究竟什么才算得上“负责任的披露”?当厂商在信息公开和补丁发布上占据主导地位,而安全研究者则需要耗费大量精力进行沟通与博弈,这一模式是否还能真正实现保护用户安全的初衷?...
Mar 12, 2025
Paper安全渗透
.katex img {
display: block;
position: absolute;
width: 100%;
height: inherit;
}
作者:0x7F@知道创宇404实验室
日期:2025年2月28日
1. 前言
在「机器学习的线性回归模型」文章中,我们学习了监督学习中如何使用线性回归模型拟合连...
Mar 13, 2025
恶意软件分析
来源
Tags
摘要
标题
发布时间
漏洞分析
来源
Tags
摘要
标题
发布时间
Kaspersky Securelist
TTPs
In this article, we discuss the tools and TTPs used in the SideWinder APT's attacks in H2 2024, as well as shifts in its targets, such as an increase in attacks against the maritime and logistics sectors.
Mar 10, 2025
Kaspersky Securelist
Kaspersky
Kaspersky experts describe a new wave of attacks distributing the DCRat backdoor through YouTube under the guise of game cheats.
Mar 11, 2025
Kaspersky Securelist
Kaspersky
Kaspersky provides incident response statistics for 2024, as well real incidents analysis. The report also shares IR trends and cybersecurity recommendations.
Mar 12, 2025
Kaspersky Securelist
Russia
We analyze the activities of the Head Mare hacktivist group, which has been attacking Russian companies jointly with Twelve.
Mar 13, 2025
Full Disclosure
<p>Posted by areca-palm via Fulldisclosure on Mar 11</p>[CVE pending]<br />
<br />
Sandboxing Python is notoriously difficult, the Python module "asteval" is no exception. Add to this the fact that a <br />
large set of numpy functions are exposed within the sandbox by default.<br />
Versi
Mar 11, 2025
Hacker News Exploits
Russia
Kaspersky
A new mass malware campaign is infecting users with a cryptocurrency miner named SilentCryptoMiner by masquerading it as a tool designed to circumvent internet blocks and restrictions around online services.
Russian cybersecurity company Kaspersky said the activity is part of a larger trend where cy
Mar 10, 2025
Hacker News Exploits
Cyber threats today don't just evolve—they mutate rapidly, testing the resilience of everything from global financial systems to critical infrastructure. As cybersecurity confronts new battlegrounds—ranging from nation-state espionage and ransomware to manipulated AI chatbots—the landscape becomes i
Mar 10, 2025
Hacker News Exploits
Google
The Need For Unified Security
Google Workspace is where teams collaborate, share ideas, and get work done. But while it makes work easier, it also creates new security challenges. Cybercriminals are constantly evolving, finding ways to exploit misconfigurations, steal sensitive data, and hijack user
Mar 10, 2025
Hacker News Exploits
RAT
The Middle East and North Africa have become the target of a new campaign that delivers a modified version of a known malware called AsyncRAT since September 2024.
"The campaign, which leverages social media to distribute malware, is tied to the region's current geopolitical climate," Positive Techn
Mar 10, 2025
Hacker News Exploits
Cybersecurity researchers have demonstrated a novel technique that allows a malicious web browser extension to impersonate any installed add-on.
"The polymorphic extensions create a pixel perfect replica of the target's icon, HTML popup, workflows and even temporarily disables the legitimate extensi
Mar 10, 2025
Hacker News Exploits
Ivanti
CISA
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added five security flaws impacting Advantive VeraCore and Ivanti Endpoint Manager (EPM) to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation in the wild.
The list of vulnerabilities
Mar 11, 2025
Hacker News Exploits
Taiwanese company Moxa has released a security update to address a critical security flaw impacting its PT switches that could permit an attacker to bypass authentication guarantees.
The vulnerability, tracked as CVE-2024-12297, has been assigned a CVSS v4 score of 9.2 out of a maximum of 10.0.
"Mul
Mar 11, 2025
Hacker News Exploits
Kaspersky
United Arab Emirates
Maritime and logistics companies in South and Southeast Asia, the Middle East, and Africa have become the target of an advanced persistent threat (APT) group dubbed SideWinder.
The attacks, observed by Kaspersky in 2024, spread across Bangladesh, Cambodia, Djibouti, Egypt, the United Arab Emirates,
Mar 11, 2025
Hacker News Exploits
Inside the most innocent-looking image, a breathtaking landscape, or a funny meme, something dangerous could be hiding, waiting for its moment to strike.
No strange file names. No antivirus warnings. Just a harmless picture, secretly concealing a payload that can steal data, execute malware, and tak
Mar 11, 2025
Hacker News Exploits
In cybersecurity, confidence is a double-edged sword. Organizations often operate under a false sense of security, believing that patched vulnerabilities, up-to-date tools, polished dashboards, and glowing risk scores guarantee safety. The reality is a bit of a different story. In the real world, ch
Mar 11, 2025
Hacker News Exploits
Unpatched TP-Link Archer routers have become the target of a new botnet campaign dubbed Ballista, according to new findings from the Cato CTRL team.
"The botnet exploits a remote code execution (RCE) vulnerability in TP-Link Archer routers (CVE-2023-1389) to spread itself automatically over the Inte
Mar 11, 2025
Hacker News Exploits
The threat actor known as Blind Eagle has been linked to a series of ongoing campaigns targeting Colombian institutions and government entities since November 2024.
"The monitored campaigns targeted Colombian judicial institutions and other government or private organizations, with high infection ra
Mar 11, 2025
Hacker News Exploits
Apple
Apple on Tuesday released a security update to address a zero-day flaw that it said has been exploited in "extremely sophisticated" attacks.
The vulnerability has been assigned the CVE identifier CVE-2025-24201 and is rooted in the WebKit web browser engine component.
It has been described as an out
Mar 12, 2025
Hacker News Exploits
Microsoft
Microsoft on Tuesday released security updates to address 57 security vulnerabilities in its software, including a whopping six zero-days that it said have been actively exploited in the wild.
Of the 56 flaws, six are rated Critical, 50 are rated Important, and one is rated Low in severity. Twenty-t
Mar 12, 2025
Hacker News Exploits
We’ve been hearing the same story for years: AI is coming for your job. In fact, in 2017, McKinsey printed a report, Jobs Lost, Jobs Gained: Workforce Transitions in a Time of Automation, predicting that by 2030, 375 million workers would need to find new jobs or risk being displaced by AI and autom
Mar 12, 2025
Hacker News Exploits
GreyNoise
Threat intelligence firm GreyNoise is warning of a "coordinated surge" in the exploitation of Server-Side Request Forgery (SSRF) vulnerabilities spanning multiple platforms.
"At least 400 IPs have been seen actively exploiting multiple SSRF CVEs simultaneously, with notable overlap between attack at
Mar 12, 2025
Hacker News Exploits
China
The China-nexus cyber espionage group tracked as UNC3886 has been observed targeting end-of-life MX routers from Juniper Networks as part of a campaign designed to deploy custom backdoors, highlighting their ability to focus on internal networking infrastructure.
"The backdoors had varying custom ca
Mar 12, 2025
Hacker News Exploits
Browser maker Mozilla is urging users to update their Firefox instances to the latest version to avoid facing issues with using add-ons due to the impending expiration of a root certificate.
"On March 14, 2025, a root certificate used to verify signed content and add-ons for various Mozilla projects
Mar 13, 2025
Hacker News Exploits
Meta has warned that a security vulnerability impacting the FreeType open-source font rendering library may have been exploited in the wild.
The vulnerability has been assigned the CVE identifier CVE-2025-27363, and carries a CVSS score of 8.1, indicating high severity. Described as an out-of-bounds
Mar 13, 2025
SANS Internet Storm Center
Looking over some weblogs on my way back from class in Baltimore, I feel a reminder is appropriate that (a) weblogs are still a thing and (b) what some of the common webshells are that attackers are looking for.
Mar 9, 2025
SANS Internet Storm Center
暂无内容
Mar 10, 2025
SANS Internet Storm Center
Microsoft
Windows
I returned from another FOR610[1] class last week in London. One key tip I give to my students is to keep an eye on "strange" API calls. In the Windows ecosystem, Microsoft offers tons of API calls to developers. The fact that an API is used in a program does not always mean we are facing
Mar 10, 2025
SANS Internet Storm Center
暂无内容
ISC Stormcast For Tuesday, March 11th, 2025 https://isc.sans.edu/podcastdetail/9358, (Tue, Mar 11th)
Mar 11, 2025
SANS Internet Storm Center
The March patch Tuesday looks like a fairly light affair, with only 51 vulnerabilities total and only six rated as critical. However, this patch Tuesday also includes six patches for already exploited, aka "0-Day" vulnerabilities. None of the already exploited vulnerabilities are rated as critical.
Mar 11, 2025
SANS Internet Storm Center
暂无内容
ISC Stormcast For Wednesday, March 12th, 2025 https://isc.sans.edu/podcastdetail/9360, (Wed, Mar 12th)
Mar 12, 2025
SANS Internet Storm Center
Today, I noticed increased scans for the VMWare Hyprid Cloud Extension (HCX) "sessions" endpoint. These endpoints are sometimes associated with exploit attempts for various VMWare vulnerabilities to determine if the system is running the extensions or to gather additional information to aid exploita
Mar 12, 2025
SANS Internet Storm Center
I previously used Power BI [2] to analyze DShield sensor data and this time I wanted to show how it could be used by selecting certain type of data as a large dataset and export it for analysis. This time, I ran a query in Elastic Discover and exported that data to analyze it in PowerBI in
Mar 13, 2025
SANS Internet Storm Center
暂无内容
ISC Stormcast For Thursday, March 13th, 2025 https://isc.sans.edu/podcastdetail/9362, (Thu, Mar 13th)
Mar 13, 2025
Hacker News Exploits
Unpatched TP-Link Archer routers have become the target of a new botnet campaign dubbed Ballista, according to new findings from the Cato CTRL team.
"The botnet exploits a remote code execution (RCE) vulnerability in TP-Link Archer routers (CVE-2023-1389) to spread itself automatically over the Inte
Mar 11, 2025
安全研究
来源
Tags
摘要
标题
发布时间
Palo Alto Networks Research
<p>We identified a campaign spreading thousands of sca crypto investment platforms through websites and mobile apps, possibly through a standardized toolkit.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/fraud-crypto-platforms-campaign/">Investigating Scam Crypto Investment Platforms
Mar 13, 2025
安全前沿
邮件安全
<p>3月13日(周四)15:00直播,立即扫码预约,一键占座!</p><p><br />直播亮点抢先看:<br />✔前沿洞察:大模型在邮件安全领域的破局之路<br />✔新品发布:CACTER大模型邮件安全网关首秀<br />✔跨界论道:清华学者&技术大拿共话AI防御演进<br /><br />CACTER大模型邮件安全网关重磅登场!大模型赋能邮件安全,精准智御新型恶意威胁,守护邮件安全防线,超多功能等你揭秘~</p><p style="text-align: center;"><img alt="直播海报.png" src="https://img.4hou.com/upload
Mar 11, 2025
安全前沿
<p style="text-align: center;"><img alt="[email protected]" src="https://img.4hou.com/uploads/ueditor/php/upload/image/20250311/1741661442120605.png" title="1741661442120605.png" /></p><p>在 Python JSON Logger 包(python-json-logger)中,发现了一个严重影响版本 3.2.0 和 3.2.1 的重大漏洞,编号为 CVE-2025-27607。该漏洞因对缺失依赖项
Mar 11, 2025
安全前沿
<p>来自新疆的全国政协委员拟为治理“AI生成不实信息”提出建言。</p><p>2025年全国两会即将召开,全国政协委员、新疆新的社会阶层人士联谊会副会长海尼扎提·托呼提拟向大会提交“关于加强AI生成不实信息治理”等提案,建议社交媒体平台等互联网平台加强内容审核机制,建立专门的AI生成内容审核团队,对平台内容执行严格监管。</p><p>随着人工智能技术的迅猛发展,AI生成不实信息的问题愈发严重,成为信息传播领域面临的一大新挑战。“这些不实信息通常具有迷惑性强、刺激度高、传播力广等特点,不仅侵蚀了信息的真实性,还扰乱了社会秩序与公众认知。”前述提案举例说,在甘肃首例AI虚假信息案中,洪某弟利用C
Mar 11, 2025
安全前沿
中国
<p>近日,中国计算机学会(CCF)计算机安全专委会和上海市计算机学会网络专委会联合发起2025年网络安全十大趋势预测活动。来自国家网络安全主管部门、高校、科研院所、国有企业及民营企业界的专家学者,投票评选出了2025年网络安全十大发展趋势。</p><p><strong>趋势1:人工智能广泛赋能网络安全</strong></p><p>随着人工智能(AI)技术的飞速发展,其已逐渐渗透到网络安全的各个层面。AI在网络安全中的应用,如通过机器学习算法自动检测异常行为、预测潜在威胁,以及利用自然语言处理技术分析安全日志,能显著提升安全检测的效率与准确性。例如,AI可以实时分析海量网络数据,快速识别出恶
Mar 11, 2025
安全前沿
<p>近年来,中央网信办持续部署开展“清朗”系列专项行动,集中时间、集中力量打击网上各类乱象问题,从严处置违规平台和账号,取得积极成效,形成有力震慑。2025年,“清朗”系列专项行动将进一步巩固提升治理成效,聚焦人民群众反映强烈的突出问题,在破解难点瓶颈方面下功夫,强化源头管理和基础管理;在治理创新方面下功夫,针对性细化每个专项打法举措;在维护网民权益方面下功夫,严厉打击各类侵权违法行为,营造更加清朗有序的网络环境。</p><p>重点整治任务主要包括:一是整治春节网络环境,集中打击挑起极端对立、炮制不实信息、宣扬低俗恶俗、鼓吹不良文化、违法活动引流等问题。二是整治“自媒体”发布不实信息,包括发
Mar 11, 2025
安全前沿
<p>“315”已经成为保护消费者权益的符号和标志,对市场规范起到示范作用。微热点研究院基于2023年、2024年同期315晚会传播数据分析及近期舆论传播态势,结合近期消费及投诉热点,分析315期间维权领域热点,以供参考。</p><p><span style="font-size: 20px;"><strong>315晚会影响力逐年提高</strong></span></p><p>历史同期数据显示,315晚会影响力呈明显增长态势,全网信息量、媒体报道量均有较大增长。统计时段内,315晚会的全网信息量由2023年的13.64万条增至2024年的33.16万条,增幅达143.1%,侧面说明315晚
Mar 11, 2025
安全前沿
远程代码执行
<p style="text-align: center;"><img alt="image.png" src="https://img.4hou.com/uploads/ueditor/php/upload/image/20250312/1741746800389310.png" title="1741746651615498.png" /></p><p>Apache Camel 中近期披露的一个安全漏洞(编号为 CVE - 2025 - 27636),已引发整个网络安全社区的高度警惕。该漏洞允许攻击者向 Camel Exec 组件配置注入任意标头,进而有可能实现远程代码执行(RCE)。</
Mar 12, 2025
安全前沿
<p>近日,丈八网安凭借其技术领先性和全面务实的网络安全人才培养解决方案,以及丰富的校企合作项目经验,入选教育部产学合作协同育人项目企业名单。未来,丈八网安将定向投入丰富的技术、内容、服务资源,用于合作高校的教学体系、师资培训体系和实践基地建设工作。</p><p>产学合作协同育人项目是教育部为贯彻《国务院办公厅关于深化高等学校创新创业教育改革的实施意见》和《国务院办公厅关于深化产教融合的若干意见》精神,深化产教融合、推动高等教育改革而推出的重要举措。通过项目实施,能够实现人才培养与企业需求的无缝对接,促进教育与产业的深度融合和高质量发展。在此背景下,丈八网安在长期校企合作实践中不断摸索,通过对
Mar 12, 2025
安全前沿
后门
Backdoor
数据泄露
病毒
<p>近期, AnubisBackdoor 频繁出现。这是一个基于 Python 的后门程序,其幕后黑手是 Savage Ladybug 组织。据报道,该组织与臭名昭著的 FIN7 网络犯罪团伙存在关联。</p><p>此恶意软件的目的在于提供远程访问权限、执行命令以及推动数据泄露,与此同时,还能躲避大多数防病毒解决方案的检测。</p><p style="text-align: center;"><img alt="image.png" src="https://img.4hou.com/uploads/ueditor/php/upload/image/20250313/174183260179
Mar 13, 2025
法律与合规
来源
Tags
摘要
标题
发布时间
Krebs on Security
India
Authorities in India today arrested the alleged co-founder of Garantex, a cryptocurrency exchange sanctioned by the U.S. government in 2022 for facilitating tens of billions of dollars in money laundering by transnational criminal and cybercriminal organizations. Sources close to the investigation t
Mar 11, 2025
Krebs on Security
Microsoft
Windows
Microsoft today issued more than 50 security updates for its various Windows operating systems, including fixes for a whopping six zero-day vulnerabilities that are already seeing active exploitation.
Mar 11, 2025
Electronic Frontier Foundation
<div class="field field--name-body field--type-text-with-summary field--label-hidden"><div class="field__items"><div class="field__item even"><p><span>Last month saw digital rights organizations and social justice groups head to Taiwan for this year's </span><a href="https://www.eff.org/deeplinks/20
Mar 10, 2025
Electronic Frontier Foundation
<div class="field field--name-body field--type-text-with-summary field--label-hidden"><div class="field__items"><div class="field__item even"><p><span>On Monday, March 10, EFF sent a <a href="https://www.eff.org/document/eff-letter-senate-committee-judiciary-regarding-stop-csam-act">letter</a> to th
Mar 11, 2025
Electronic Frontier Foundation
<div class="field field--name-body field--type-text-with-summary field--label-hidden"><div class="field__items"><div class="field__item even"><p><span class="TextRun SCXW156673703 BCX4" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW156673703 BCX4">Good old-fashioned grassroots advocac
Mar 11, 2025
Electronic Frontier Foundation
<div class="field field--name-body field--type-text-with-summary field--label-hidden"><div class="field__items"><div class="field__item even"><h2><span>A look back at the games governments played to avoid transparency<br /></span></h2>
<p><span>In the year 2015, we witnessed the launch of OpenAI, a
Mar 11, 2025
Electronic Frontier Foundation
<div class="field field--name-body field--type-text-with-summary field--label-hidden"><div class="field__items"><div class="field__item even"><p><span>In a bold push for medical privacy, Hawaii's House of Representatives has introduced </span><a href="https://www.capitol.hawaii.gov/sessions/session2
Hawaii Takes a Stand for Privacy: HCR 144/HR 138 Calls for Investigation of Crisis Pregnancy Centers
Mar 11, 2025
Electronic Frontier Foundation
<div class="field field--name-body field--type-text-with-summary field--label-hidden"><div class="field__items"><div class="field__item even"><p><span>The Anchorage Police Department (APD) has concluded its three-month trial of Axon’s Draft One, an AI system that uses audio from body-worn cameras to
Mar 12, 2025
Electronic Frontier Foundation
<div class="field field--name-body field--type-text-with-summary field--label-hidden"><div class="field__items"><div class="field__item even"><p><span>As a legal organization that has fought in court to defend the rights of technology users for almost 35 years, including numerous legal challenges to
Mar 12, 2025
Electronic Frontier Foundation
<div class="field field--name-body field--type-text-with-summary field--label-hidden"><div class="field__items"><div class="field__item even"><p>EFF is deeply saddened to learn of the passing of Mark Klein, a bona fide hero who risked civil liability and criminal prosecution to help expose a massive
Mar 12, 2025
工业控制系统安全
来源
Tags
摘要
标题
发布时间
Dragos Security Blog
<p>Are you an asset owner or operator in the industrial sector, working to fortify your OT cybersecurity posture against ever-evolving...</p>
The post <a href="https://www.dragos.com/blog/network-learn-defend-dragos-forum-helps-to-empower-ot-security-professionals/">Network, Learn, Defend: the Drago
Mar 10, 2025
国家安全
来源
Tags
摘要
标题
发布时间
物联网安全
来源
Tags
摘要
标题
发布时间
IoT Security Foundation
<p>The Cyber Resilience Act (CRA) is a crucial piece of legislation that aims to strengthen cybersecurity across the European Union. It’s designed to ensure that products with digital elements meet specific security standards, ultimately protecting consumers and businesses alike.</p>
<p>The post <a
Mar 12, 2025
IoT Security Foundation
<p>The Cyber Resilience Act (CRA) is a crucial piece of legislation that aims to strengthen cybersecurity across the European Union. It’s designed to ensure that products with digital elements meet specific security standards, ultimately protecting consumers and businesses alike.</p>
<p>The post <a
Mar 12, 2025
数据隐私
来源
Tags
摘要
标题
发布时间
International Association of Privacy Professionals (IAPP)
<p>Social platform Bluesky CEO Jay Graber said the company is exploring consumer opt outs from data sharing for AI training purposes, TechCrunch reports. Graber said the proposed framework will give users more control over their data and would work similarly to how "websites specify whether they wan
Mar 11, 2025
International Association of Privacy Professionals (IAPP)
<p>A study by marketing research group YouGov found 54% of U.S. consumers consider targeted advertisements to be invasive, while 27% believe personalized ads are helpful when purchasing products online, MediaPost reports. The study also found consumers would be more comfortable with personalized ads
Mar 11, 2025
International Association of Privacy Professionals (IAPP)
<p>The American Psychological Association's Council of Representatives approved new policies to protect individuals' psychological and neural data collected by consumer devices. The safeguards aim to address "the need for ethical collection, storage and use of data gathered from direct-to-consumer s
Mar 11, 2025
International Association of Privacy Professionals (IAPP)
<p>The U.S. Federal Trade Commission reported consumers lost USD12.5 billion to fraud in 2024, a 25% increase compared to 2023. The agency said imposter scams, online shopping issues, and business and job opportunities were the top three categories of fraud.<br /><a href="https://www.ftc.gov/news-ev
Mar 11, 2025
International Association of Privacy Professionals (IAPP)
Belgium
<p>Belgium's Data Protection Authority is seeking feedback on its <a class="mktNoTok" href="https://www.autoriteprotectiondonnees.be/publications/recommandation-01-2025-relative-aux-traitements-de-donnees-a-caractere-personnel-dans-le-cadre-du-marketing-direct.pdf">updated guidance</a> on direct mar
Mar 11, 2025
International Association of Privacy Professionals (IAPP)
<p>New York Attorney General Letitia James filed a lawsuit against National General and Allstate, claiming the insurance companies had insufficient data protection practices when they sustained two data breaches affecting customers' personal data. James' office alleged the companies failed to notify
Mar 11, 2025
International Association of Privacy Professionals (IAPP)
<p>California Attorney General Rob Bonta issued California Consumer Privacy Act compliance letters concerning geolocation data sales. Bonta said the letters, sent to covered entities across various industries, requested additional information related to recipients' business activities while notifyin
Mar 11, 2025
International Association of Privacy Professionals (IAPP)
<p>The Network Advertising Initiative announced the launch of its Self-Regulatory Framework, which is intended to serve as a model for digital advertisers to self-regulate and comply with U.S. state and federal privacy regulations. To comply with the framework, NAI member companies must agree to pri
Mar 11, 2025
International Association of Privacy Professionals (IAPP)
Mexico
<p>Two recent legal reforms in Mexico may have a significant impact on the country's data protection enforcement regime, Basham, Ringe y Correa, S.C.'s Data Protection and IT Associate Renata Denisse Bueron Valenzuela and Data Protection Associate Ivan Garcia Argueta write. Bueron and Garcia explore
Mar 11, 2025
International Association of Privacy Professionals (IAPP)
<p>The European Commission released the third draft of the general-purpose AI Code of Practice with 16 additional safety and security commitments related to AI models with systemic risks. The final draft is expected to be ready in May after the working group receives another round of feedback.<br />
Mar 11, 2025
International Association of Privacy Professionals (IAPP)
<p>The fields of privacy, AI governance and digital responsibility have undergone substantial transformation in recent years. To understand the current salary landscape for professionals across each industry, the IAPP is running its Salary Survey for the first time since 2022. At the survey's conclu
Mar 11, 2025
International Association of Privacy Professionals (IAPP)
<p>Hong Kong's Office of the Privacy Commissioner for Personal Data found more than 109,000 individuals were affected by a data breach that allegedly occurred because of a fault within the Integrated Companies Registry Information System's e-service system. The breach affected individuals' sensitive
Mar 12, 2025
International Association of Privacy Professionals (IAPP)
<p>Luxembourg's National Commission for Data Protection issued a reminder about the importance of user consent when used as a legal basis for processing under the EU General Data Protection Regulation. The CNPD's updated information specifies "under what conditions consent can be considered valid" u
Mar 12, 2025
International Association of Privacy Professionals (IAPP)
Canada
<p>The European Parliament approved an agreement to allow secure passenger name record data, including individuals' travel and contact information, to be shared between the EU and Canada. The agreement aims to protect consumer information and prevent sensitive data from being processed while allowin
Mar 12, 2025
International Association of Privacy Professionals (IAPP)
India
<p>Indiana University's Center for Applied Cybersecurity Research Executive Director Scott Shackelford writes about a gradual shift toward workers having more privacy in the workplace thanks to U.S. state-level laws. "Across the board, employers need to ensure appropriate notice and consent, and pay
Mar 12, 2025
International Association of Privacy Professionals (IAPP)
Honda
<p>The California Privacy Protection Agency announced a USD632,500 settlement with American Honda Motor over alleged California Consumer Privacy Act violations. The settlement resolves claims around various aspects of Honda's privacy practices, including insufficient necessity and proportionality co
Mar 12, 2025
International Association of Privacy Professionals (IAPP)
<p>Axios reports the U.S. Senate Committee on Commerce, Science and Transportation advanced Federal Trade Commissioner nominee Mark Meador and Office of Science and Technology Policy Director nominee Michael Kratsios to full Senate confirmation votes. Meanwhile, the full Senate confirmed Gail Slater
Mar 12, 2025
International Association of Privacy Professionals (IAPP)
Canada
<p>Innovation, Science and Economic Development Canada is seeking stakeholder feedback on how it should implement certifications for trusted data flows under the Global Cross-Border Privacy Rules Forum. The ISED explained the certifications would make it easier to conduct cross-border data transfers
Mar 12, 2025
International Association of Privacy Professionals (IAPP)
Spain
<p>Spain's Ministry for Digital Transformation and Public Service will draft a law codifying the provisions of the EU AI Act into domestic law. The bill, which will cover prohibited AI practices and high-risk AI development, will enter several procedures before returning to the Council of Ministers
Mar 12, 2025
International Association of Privacy Professionals (IAPP)
<p>U.K. Minister of State for Data Protection and Telecoms Chris Bryant told attendees at the IAPP Data Protection Intensive: UK 2025 the proposed U.K. data reforms contained in the Data Use and Access Bill could pass by late April. Bryant expressed optimism regarding the bill, which still has steps
Mar 12, 2025
Future of Privacy Forum
Singapore
March 10, 2025 — Singapore Management University (SMU) and the Future of Privacy Forum (FPF) have signed a Memorandum of Understanding (MOU) to strengthen collaboration in data governance, privacy, and emerging technology regulation across the Asia-Pacific region. By combining SMU’s expertise
Singapore Management University and Future of Privacy Forum Form Partnership to Advance Expertise in Digital Law and Data Governance in Asia-Pacific
Mar 10, 2025
Future of Privacy Forum
The Future of Privacy Forum (FPF) released a landscape analysis of the adoption of Privacy Enhancing Technologies (PETs) by State Education Agencies (SEAs). As agencies face increasing pressure to leverage sensitive student and institutional data for analysis and research, PETs offer a unique potent
Mar 13, 2025
Electronic Frontier Foundation
<div class="field field--name-body field--type-text-with-summary field--label-hidden"><div class="field__items"><div class="field__item even"><p><span>Last month saw digital rights organizations and social justice groups head to Taiwan for this year's </span><a href="https://www.eff.org/deeplinks/20
Mar 10, 2025
Electronic Frontier Foundation
<div class="field field--name-body field--type-text-with-summary field--label-hidden"><div class="field__items"><div class="field__item even"><p><span>On Monday, March 10, EFF sent a <a href="https://www.eff.org/document/eff-letter-senate-committee-judiciary-regarding-stop-csam-act">letter</a> to th
Mar 11, 2025
Electronic Frontier Foundation
<div class="field field--name-body field--type-text-with-summary field--label-hidden"><div class="field__items"><div class="field__item even"><p><span class="TextRun SCXW156673703 BCX4" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW156673703 BCX4">Good old-fashioned grassroots advocac
Mar 11, 2025
Electronic Frontier Foundation
<div class="field field--name-body field--type-text-with-summary field--label-hidden"><div class="field__items"><div class="field__item even"><h2><span>A look back at the games governments played to avoid transparency<br /></span></h2>
<p><span>In the year 2015, we witnessed the launch of OpenAI, a
Mar 11, 2025
Electronic Frontier Foundation
<div class="field field--name-body field--type-text-with-summary field--label-hidden"><div class="field__items"><div class="field__item even"><p><span>In a bold push for medical privacy, Hawaii's House of Representatives has introduced </span><a href="https://www.capitol.hawaii.gov/sessions/session2
Hawaii Takes a Stand for Privacy: HCR 144/HR 138 Calls for Investigation of Crisis Pregnancy Centers
Mar 11, 2025
Electronic Frontier Foundation
<div class="field field--name-body field--type-text-with-summary field--label-hidden"><div class="field__items"><div class="field__item even"><p><span>The Anchorage Police Department (APD) has concluded its three-month trial of Axon’s Draft One, an AI system that uses audio from body-worn cameras to
Mar 12, 2025
Electronic Frontier Foundation
<div class="field field--name-body field--type-text-with-summary field--label-hidden"><div class="field__items"><div class="field__item even"><p><span>As a legal organization that has fought in court to defend the rights of technology users for almost 35 years, including numerous legal challenges to
Mar 12, 2025
Electronic Frontier Foundation
<div class="field field--name-body field--type-text-with-summary field--label-hidden"><div class="field__items"><div class="field__item even"><p>EFF is deeply saddened to learn of the passing of Mark Klein, a bona fide hero who risked civil liability and criminal prosecution to help expose a massive
Mar 12, 2025
International Association of Privacy Professionals (IAPP)
<p>U.S. Rep. Tim Walberg, R-Mich., spoke with Punchbowl News regarding the past and future work on the Children and Teen's Online Privacy Protection Act, also known as COPPA 2.0. Walberg indicated the bipartisan proposal's <a href="https://iapp.org/news/a/questions-linger-as-us-house-committee-appro
Mar 10, 2025
International Association of Privacy Professionals (IAPP)
<p>The California Privacy Protection Agency Board voted 7 March to begin a formal rulemaking procedure on drafting data broker regulations under the Delete Act, Bloomberg Law reports. Notably, the draft rules will establish specifics around the creation and application of a data deletion tool recogn
Mar 10, 2025
International Association of Privacy Professionals (IAPP)
India
<p>India's Ministry for Electronics and Information Technology released a report on its AI strategy, including efforts to promote innovation and align with its Viksit Bharat initiative that aims to ensure India is a leader in the AI landscape by 2047. The report said India's approach to AI will focu
Mar 10, 2025
International Association of Privacy Professionals (IAPP)
<p>Signal President Meredith Whittaker raised concerns about the potential privacy implications of agentic AI, TechCrunch reports. Whittaker said agentic AI's alleged ability to do a variety of tasks for consumers would mean granting the technology access to large amounts of data "with something tha
Mar 10, 2025
International Association of Privacy Professionals (IAPP)
<p>The European Data Protection Board will discuss a procedure for how to approve binding corporate rules for controllers and processors under the EU General Data Protection Regulation during its 13 March meeting. The group will also discuss a statement on implementing the Passenger Name Record Dire
Mar 10, 2025
International Association of Privacy Professionals (IAPP)
<p>Consumer Reports published an <a href="https://innovation.consumerreports.org/AI-Voice-Cloning-Report-.pdf">analysis</a> highlighting potential privacy issues at six voice cloning companies. Consumer Reports Policy Analyst Grace Gedye said the assessment showed "there are basic steps companies ca
Mar 10, 2025
International Association of Privacy Professionals (IAPP)
<p>New York Attorney General Letitia James announced a USD650,000 settlement with app developer Saturn Technologies after the company allegedly did not confirm users' school email addresses and age on its calendar platform for high school students. James said Saturn "will have to update its practice
Mar 10, 2025
International Association of Privacy Professionals (IAPP)
<p>Oregon Attorney General Dan Rayfield released a <a class="mktNoTok" href="https://www.doj.state.or.us/wp-content/uploads/2025/03/OCPA-Six-Month-Enforcement-Report.pdf">report</a> detailing the enforcement actions and complaints received since the Oregon Consumer Privacy Act took effect 1 July 202
Mar 10, 2025
International Association of Privacy Professionals (IAPP)
CIPP
<p>Privacy litigation is growing more prevalent in the U.S., with individuals finding success in arguing their claims or securing favorable settlements to avoid proceedings. In the first of a six-part IAPP series on litigation trends, IAPP Research and Insights Analyst Cheryl Saniuk-Heinig, CIPP/E,
Mar 10, 2025
International Association of Privacy Professionals (IAPP)
<p>The European Parliamentary Research Service published a memo explaining the situation around the EU-U.K. adequacy decision, which needs to be reaffirmed by the European Commission by 27 June. The memo details how the potential passage of the proposed Data Use and Access Bill and provisions of the
Mar 10, 2025
International Association of Privacy Professionals (IAPP)
<p>The European Data Protection Supervisor released its 2020-24 mandate review detailing the authority's enforcement actions and its strategy for protecting individuals' privacy. The EDPS will continue its enforcement efforts aiming to bolster organizations' compliance with privacy regulations while
Mar 10, 2025
企业安全
来源
Tags
摘要
标题
发布时间
Cisco Security Blog
Cisco Secure
Cisco
See how Cisco Secure Firewall excelled in the SE Labs test, blocking advanced attacks with innovative threat intelligence and encryption capabilities.
Mar 11, 2025
Cisco Security Blog
Demystify the potential threat that quantum computing poses to encryption and the security of the network.
Mar 12, 2025
安全牛
在软件供应链安全的世界里,安全与效率的平衡始终是企业面临的核心挑战。传统安全管理工具往往陷入两难境地:要么为了 […]
Mar 10, 2025
安全牛
摘要: 2024年3月5日,十四届全国人大二次会议在北京召开,“新质生产力”首次被写入政府工作报告,并在报告中 […]
Mar 10, 2025
安全牛
DeepSeek-R1上线后即遭遇持续恶意攻击,开源软件漏洞引爆全球供应链危机,暗网“勒索即服务(RaaS)” […]
Mar 10, 2025
安全牛
黑客
数据泄露
在黑客攻击日益复杂、数据泄露事件频频登上新闻头条的背景下, CISO肩负着保护企业数字资产、维护声誉和确保合规 […]
Mar 11, 2025
安全牛
新闻速览 •特朗普将封禁DeepSeek?外交部回应 •工信部CSTIS提醒:防范网站被攻击网页被篡改的风险 […]
Mar 11, 2025
安全牛
瑞士
新闻速览 •瑞士出台新规,关键基础设施运营商要在24小时内报告网络攻击 •马斯克X平台被连续击垮,Dark S […]
Mar 12, 2025
安全牛
新闻速览 •数据保护不力致20万驾照信息泄露,Allstat子公司National  General […]
Mar 13, 2025
安全牛
人工智能技术的发展正在深刻影响着网络安全领域。一方面,AI赋能了网络攻击手段的自动化和智能化,使得攻击者能够更 […]
Mar 13, 2025
安全牛
2024年,全球APT组织通过技术跃迁、组织升级等不断演化和扩张,已将攻击的魔爪伸向影响更广泛、更具破坏性的领 […]
Mar 13, 2025
Tenable Blog
<ol class="blog-severity-badges"><li class="blog-severity-badges critical"><span class="number">6</span>Critical</li><li class="blog-severity-badges important"><span class="number">50</span>Important</li><li class="blog-severity-badges moderate"><span class="number">0</span>Moderate</li><li class="b
Microsoft’s March 2025 Patch Tuesday Addresses 56 CVEs (CVE-2025-26633, CVE-2025-24983, CVE-2025-24993)
Mar 11, 2025
Tenable Blog
Tenable
<p><strong>Tenable Research examines DeepSeek R1 and its capability to develop malware, such as a keylogger and ransomware. We found it provides a useful starting point, but requires additional prompting and debugging.</strong></p><h2>Background</h2><p>As generative artificial intelligence (GenAI) h
Mar 13, 2025
移动安全
来源
Tags
摘要
标题
发布时间
云安全
来源
Tags
摘要
标题
发布时间
- 作者:黑客驰
- 链接:https://hackerchi.top/article/HackerNews
- 声明:本文采用 CC BY-NC-SA 4.0 许可协议,转载请注明出处。
相关文章