Back to .md Directory
每日安全资讯(2023-08-05)
- Sploitus.com Exploits RSS Feed
- PHPJabbers Shuttle Booking Software 1.0 - Reflected XSS exploit
- Shelly PRO 4PM v0.11.0 - Authentication Bypass exploit
- Adiscon LogAnalyzer 4.1.13 Cross Site Scripting exploit
- Web Portal People CMS 2.8 Open Redirection exploit
- Adiscon LogAnalyzer v.4.1.13 - Cross Site Scripting exploit
- Voodoo Chat 1.0RC1b Information Disclosure exploit
- VOC++ Business Special Edition Creatiff Original 1.3 Information Disclosure exploit
- WordPress EventON Calendar 4.4 Insecure Direct Object Reference exploit
- Joomla JLex Review 6.0.1 - Reflected XSS exploit
- WordPress Plugin Ninja Forms 3.6.25 - Reflected XSS exploit
- Virtual Snipers DMS 1.0 SQL Injection exploit
- Xlight FTP Server 3.9.3.6 - 'Stack Buffer Overflow' (DOS) exploit
- Webedition CMS v2.9.8.8 - Stored XSS exploit
- Campcodes Online Matrimonial Website System v3.3 - Code Execution via malicious SVG file upload exploit
- Academy LMS 6.0 - Reflected XSS exploit
- Canon PIXMA TR4550 1.020 / 1.080 Unencrypted Secret Storage exploit
- VideoPRO CMS 2.0 Insecure Settings exploit
- Coupons CMS 5.00 Open Redirect exploit
- Webutler 3.2 Shell Upload exploit
- Kolibri 2.0 Buffer Overflow exploit
- Videoplay 1.3.0 Insecure Settings exploit
- Diebold Nixdorf Vynamic View Console 5.3.1 DLL Hijacking exploit
- Shelly PRO 4PM 0.11.0 Authentication Bypass exploit
- Exploit for Race Condition in Linux Linux Kernel exploit
- Exploit for Improper Authentication in Ivanti Endpoint Manager Mobile exploit
- Exploit for Improper Access Control in Papercut Papercut Ng exploit
- Exploit for Cross-site Scripting in Ninjaforms Ninja Forms exploit
- Exploit for CVE-2023-38497 exploit
- Exploit for Cross-site Scripting in Cpanel exploit
- SecWiki News
- Trustwave Blog
- HackerOne Hacker Activity
- Files ≈ Packet Storm
- Debian Security Advisory 5466-1
- Canon PIXMA TR4550 1.020 / 1.080 Unencrypted Secret Storage
- Ubuntu Security Notice USN-6274-1
- Intelliants Subrion CMS 4.2.1 Remote Code Execution
- Citrix ADC (NetScaler) Remote Code Execution
- GNU Transport Layer Security Library 3.7.10
- Debian Security Advisory 5464-1
- WordPress Adivaha Travel 2.3 Cross Site Scripting
- Red Hat Security Advisory 2023-4475-01
- Ubuntu Security Notice USN-6273-1
- Debian Security Advisory 5465-1
- Red Hat Security Advisory 2023-4471-01
- Xlight FTP Server 3.9.3.6 Stack Buffer Overflow
- Red Hat Security Advisory 2023-4472-01
- Ubuntu Security Notice USN-5064-3
- WordPress EventON Calendar 4.4 Insecure Direct Object Reference
- WordPress Ninja Forms 3.6.25 Cross Site Scripting
- Ubuntu Security Notice USN-6275-1
- COURIER DEPRIXA 2.5 Cross Site Request Forgery
- Webedition CMS 2.9.8.8 Cross Site Scripting
- Webedition CMS 2.9.8.8 Remote Code Execution
- Webutler 3.2 Shell Upload
- Red Hat Security Advisory 2023-4461-01
- Ubuntu Security Notice USN-6272-1
- Videoplay 1.3.0 Insecure Settings
- unSafe.sh - 不安全
- The 2023 MES Midmarket 100
- 黑客解锁了特斯拉需要额外付费的软件功能
- Kilimanjaro – Journal
- 用RSSHub替代Feed43
- 海表面温度创下了 20.96C 的新纪录
- The end looms for Meta's behavioural advertising in Europe
- Microsoft Teams used in phishing campaign to bypass multi-factor authentication
- Decompile C++ using NSA Ghidra
- CVE-2023-39143: PaperCut Path Traversal/File Upload RCE Vulnerability
- The Good, the Bad and the Ugly in Cybersecurity – Week 31
- IMDShift - Automates Migration Process Of Workloads To IMDSv2 To Avoid SSRF Attacks
- 研究证实很多人感觉他们的工作毫无意义
- Twitter @Nicolas Krassas
- chromecookiestealer: Steal/Inject Chrome cookies over the DevTools protocol https://securityonline.info/chromecookiestealer-steal-inject-chrome-cookie...
- Researchers Jailbreak Tesla Vehicles, Gain Control Over Paid Features https://www.hackread.com/jailbreak-tesla-vehicles-access-paid-features/
- Fake VMware vConnector package on PyPI targets IT pros https://www.bleepingcomputer.com/news/security/fake-vmware-vconnector-package-on-pypi-targets-i...
- IMDShift - Automates Migration Process Of Workloads To IMDSv2 To Avoid SSRF Attacks http://www.kitploit.com/2023/08/imdshift-automates-migration-proce...
- Malicious npm Packages Found Exfiltrating Sensitive Data from Developers https://thehackernews.com/2023/08/malicious-npm-packages-found.html
- Political Milestones for AI https://www.schneier.com/blog/archives/2023/08/political-milestones-for-ai.html
- Attackers use dynamic code loading to bypass Google Play store’s malware detections https://securityaffairs.com/149150/hacking/google-play-malware-ve...
- Leaked Secrets and Unlimited Miles: Hacking the Largest Airline and Hotel Rewards Platform https://samcurry.net/points-com/
- Targeted npm Malware Attempts to Steal Company Source Code https://www.reddit.com/r/netsec/comments/15hd257/targeted_npm_malware_attempts_to_steal_com...
- Russia's Cozy Bear is back and hitting Microsoft Teams to phish top targets https://go.theregister.com/feed/www.theregister.com/2023/08/03/microsoft_t...
- Nuked-MD-FPGA -- cycle-accurate Sega Genesis/MD hardware implementation based on reverse-engineering console's chips https://www.reddit.com/r/ReverseE...
- Film companies lose battle to unmask Reddit users https://www.malwarebytes.com/blog/news/2023/08/old-reddit-posts-come-back-to-haunt-users-in-piracy-c...
- Couple admit they laundered $4B in stolen Bitcoins after Bitfinex super-heist https://go.theregister.com/feed/www.theregister.com/2023/08/04/couple_bi...
- New Microsoft Azure AD CTS feature can be abused for lateral movement https://www.bleepingcomputer.com/news/security/new-microsoft-azure-ad-cts-featur...
- Recent Commits to cve:main
- Security Boulevard
- BSides Leeds 2023 – Dan Houghton – Web Browser Automation: How To Be More Robot, Easily!
- Smart-Advertising Company Gains Visibility into Cloud Data
- What is a SOC 2 Report? With Examples + Template
- Threat Intelligence Sharing: 5 Best Practices
- CISA Issues a Call to Action for Improved UEFI Security
- Actionable Threat Intelligence: Generating Risk Reduction from CTI
- Daniel Stori’s and Michael Tharrington’s – ‘First Day On The Job’
- Google Report Reveals Most Widely Used Cloud Attack Vectors
- Cybersecurity Insights with Contrast CISO David Lindner | 8/4
- Five Key Reasons to Modernize Your PKI
- 安全脉搏
- 安全客-有思想的安全新媒体
- Google Online Security Blog
- paper - Last paper
- 嘶吼 RoarTalk – 网络安全行业综合服务平台,4hou.com
- Tenable Blog
- Horizon3.ai
- CCC Event Blog
- SAP Blogs
- Navigating the Next Steps in your SAP SuccessFactors Onboarding Journey: The Value of Transformation
- Make your voice heard – take our survey on SAP’s Product Compliance Solutions!
- Calling all Developers: Help Us Shape the Future of BTP with AI
- Energizing Cloud ALM Transformation- Crave InfoTech Excels at SAP Cloud ALM Summit APJ 2023
- India’s Innovation Puzzle – R&D Budget a ‘Cost or Investment’?
- Currency Conversion and Optimization for SAP BTP applications
- XSA Blog Series – HDI Container, Persistence and CAP
- RFQ process Coll. no. automation.
- SAP Commerce Cloud – Unleashing the power of Ehcache
- SAP Business Connector Migration 1: ELSTER/ERiC Scenarios
- Twitter @bytehx
- Malware-Traffic-Analysis.net - Blog Entries
- Exodus Intelligence
- Reverse Engineering
- Hex Rays
- Microsoft Security Response Center
- Exploit-DB.com RSS Feed
- [dos] Xlight FTP Server 3.9.3.6 - 'Stack Buffer Overflow' (DOS)
- [webapps] WordPress Plugin Forminator 1.24.6 - Unauthenticated Remote Command Execution
- [webapps] WordPress adivaha Travel Plugin 2.3 - Reflected XSS
- [webapps] Webedition CMS v2.9.8.8 - Stored XSS
- [webapps] Webedition CMS v2.9.8.8 - Remote Code Execution (RCE)
- [webapps] Webutler v3.2 - Remote Code Execution (RCE)
- [webapps] Wordpress Plugin EventON Calendar 4.4 - Unauthenticated Post Access via IDOR
- [webapps] Wordpress Plugin EventON Calendar 4.4 - Unauthenticated Event Access
- [remote] Shelly PRO 4PM v0.11.0 - Authentication Bypass
- [webapps] Campcodes Online Matrimonial Website System v3.3 - Code Execution via malicious SVG file upload
- [webapps] WordPress adivaha Travel Plugin 2.3 - SQL Injection
- [webapps] Academy LMS 6.0 - Reflected XSS
- [webapps] PHPJabbers Rental Property Booking 2.0 - Reflected XSS
- [webapps] PHPJabbers Taxi Booking 2.0 - Reflected XSS
- [webapps] PHPJabbers Cleaning Business 1.0 - Reflected XSS
- [webapps] PHPJabbers Night Club Booking 1.0 - Reflected XSS
- [webapps] PHPJabbers Service Booking Script 1.0 - Reflected XSS
- [webapps] PHPJabbers Shuttle Booking Software 1.0 - Reflected XSS
- [webapps] JLex GuestBook 1.6.4 - Reflected XSS
- [webapps] Ozeki SMS Gateway 10.3.208 - Arbitrary File Read (Unauthenticated)
- [webapps] Joomla JLex Review 6.0.1 - Reflected XSS
- [webapps] WordPress Plugin Ninja Forms 3.6.25 - Reflected XSS
- [webapps] Adiscon LogAnalyzer v.4.1.13 - Cross Site Scripting
- [remote] ReyeeOS 1.204.1614 - MITM Remote Code Execution (RCE)
- SentinelOne
- 明天的乌云
- USENIX
- Improving Logging to Reduce Permission Over-Granting Mistakes
- V-Cloak: Intelligibility-, Naturalness- & Timbre-Preserving Real-Time Voice Anonymization
- PatchVerif: Discovering Faulty Patches in Robotic Vehicles
- DISTDET: A Cost-Effective Distributed Cyber Threat Detection System
- The Impostor Among US(B): Off-Path Injection Attacks on USB Communications
- Fuzztruction: Using Fault Injection-based Fuzzing to Leverage Implicit Domain Knowledge
- NVLeak: Off-Chip Side-Channel Attacks via Non-Volatile Memory Systems
- A Research Framework and Initial Study of Browser Security for the Visually Impaired
- PUMM: Preventing Use-After-Free Using Execution Unit Partitioning
- POLICYCOMP: Counterpart Comparison of Privacy Policies Uncovers Overbroad Personal Data Collection Practices
- The Maginot Line: Attacking the Boundary of DNS Caching Protection
- One Server for the Price of Two: Simple and Fast Single-Server Private Information Retrieval
- Exploring User Reactions and Mental Models Towards Perceptual Manipulation Attacks in Mixed Reality
- Eavesdropping Mobile App Activity via Radio-Frequency Energy Harvesting
- Side-Channel Attacks on Optane Persistent Memory
- A Study of Multi-Factor and Risk-Based Authentication Availability
- Person Re-identification in 3D Space: A WiFi Vision-based Approach
- Fourteen Years in the Life: A Root Server’s Perspective on DNS Resolver Security
- ClepsydraCache -- Preventing Cache Attacks with Time-Based Evictions
- Guarding Serverless Applications with Kalium
- DynSQL: Stateful Fuzzing for Database Management Systems with Complex and Valid SQL Query Generation
- Automated Security Analysis of Exposure Notification Systems
- xNIDS: Explaining Deep Learning-based Network Intrusion Detection Systems for Active Intrusion Responses
- Pspray: Timing Side-Channel based Linux Kernel Heap Exploitation Technique
- Strategies and Vulnerabilities of Participants in Venezuelan Influence Operations
- Investigating Verification Behavior and Perceptions of Visual Digital Certificates
- Remote Attacks on Speech Recognition Systems Using Sound from Power Supply
- HOMESPY: The Invisible Sniffer of Infrared Remote Control of Smart TVs
- FuzzJIT: Oracle-Enhanced Fuzzing for JavaScript Engine JIT Compiler
- TPatch: A Triggered Physical Adversarial Patch
- TAP: Transparent and Privacy-Preserving Data Services
- UnGANable: Defending Against GAN-based Face Manipulation
- Back to School: On the (In)Security of Academic VPNs
- Squint Hard Enough: Attacking Perceptual Hashing with Adversarial Machine Learning
- "All of them claim to be the best": Multi-perspective study of VPN users and VPN providers
- GlitchHiker: Uncovering Vulnerabilities of Image Signal Transmission with IEMI
- Device Tracking via Linux’s New TCP Source Port Selection Algorithm
- The Writing on the Wall and 3D Digital Twins: Personal Information in (not so) Private Real Estate
- PrivTrace: Differentially Private Trajectory Synthesis by Adaptive Markov Models
- Egg Hunt in Tesla Infotainment: A First Look at Reverse Engineering of Qt Binaries
- Learning Normality is Enough: A Software-based Mitigation against Inaudible Voice Attacks
- FirmSolo: Enabling dynamic analysis of binary Linux-based IoT kernel modules
- CacheQL: Quantifying and Localizing Cache Side-Channel Vulnerabilities in Production Software
- “If sighted people know, I should be able to know:” Privacy Perceptions of Bystanders with Visual Impairments around Camera-based Technology
- Access Denied: Assessing Physical Risks to Internet Access Networks
- Security and Privacy Failures in Popular 2FA Apps
- A comprehensive, formal and automated analysis of the EDHOC protocol
- Hash Gone Bad: Automated discovery of protocol attacks that exploit hash function weaknesses
- (M)WAIT for It: Bridging the Gap between Microarchitectural and Architectural Side Channels
- Content-Type: multipart/oracle - Tapping into Format Oracles in Email End-to-End Encryption
- Glowing in the Dark: Uncovering IPv6 Address Discovery and Scanning Strategies in the Wild
- Every Signature is Broken: On the Insecurity of Microsoft Office’s OOXML Signatures
- Humans vs. Machines in Malware Classification
- How fast do you heal? A taxonomy for post-compromise security in secure-channel establishment
- Assessing Anonymity Techniques Employed in German Court Decisions: A De-Anonymization Experiment
- GLeeFuzz: Fuzzing WebGL Through Error Message Guided Mutation
- Are You Spying on Me? Large-Scale Analysis on IoT Data Exposure through Companion Apps
- The Space of Adversarial Strategies
- Credit Karma: Understanding Security Implications of Exposed Cloud Services through Automated Capability Inference
- That Person Moves Like A Car: Misclassification Attack Detection for Autonomous Systems Using Spatiotemporal Consistency
- CipherH: Automated Detection of Ciphertext Side-channel Vulnerabilities in Cryptographic Implementations
- "My Privacy for their Security": Employees' Privacy Perspectives and Expectations when using Enterprise Security Software
- Combating Robocalls with Phone Virtual Assistant Mediated Interaction
- On the Feasibility of Malware Unpacking via Hardware-assisted Loop Profiling
- Distance-Aware Private Set Intersection
- NeuroPots: Realtime Proactive Defense against Bit-Flip Attacks in Neural Networks
- Towards a General Video-based Keystroke Inference Attack
- URET: Universal Robustness Evaluation Toolkit (for Evasion)
- You Can't See Me: Physical Removal Attacks on LiDAR-based Autonomous Vehicles Driving Frameworks
- Framing Frames: Bypassing Wi-Fi Encryption by Manipulating Transmit Queues
- SMACK: Semantically Meaningful Adversarial Audio Attack
- Gradient Obfuscation Gives a False Sense of Security in Federated Learning
- Automata-Guided Control-Flow-Sensitive Fuzz Driver Generation
- Are Consumers Willing to Pay for Security and Privacy of IoT Devices?
- PhyAuth: Physical-Layer Message Authentication for ZigBee Networks
- Fairness Properties of Face Recognition and Obfuscation Systems
- Beyond The Gates: An Empirical Analysis of HTTP-Managed Password Stealers and Operators
- Decompiling x86 Deep Neural Network Executables
- PolyFuzz: Holistic Greybox Fuzzing of Multi-Language Systems
- Linear Private Set Union from Multi-Query Reverse Private Membership Test
- An Efficient Design of Intelligent Network Data Plane
- AIFORE: Smart Fuzzing Based on Automatic Input Format Reverse Engineering
- Inducing Authentication Failures to Bypass Credit Card PINs
- Silent Spring: Prototype Pollution Leads to Remote Code Execution in Node.js
- Reassembly is Hard: A Reflection on Challenges and Strategies
- PCAT: Functionality and Data Stealing from Split Learning by Pseudo-Client Attack
- VulChecker: Graph-based Vulnerability Localization in Source Code
- Examining Consumer Reviews to Understand Security and Privacy Issues in the Market of Smart Home Devices
- Timeless Timing Attacks and Preload Defenses in Tor's DNS Cache
- Isolated and Exhausted: Attacking Operating Systems via Site Isolation in the Browser
- Internet Service Providers' and Individuals' Attitudes, Barriers, and Incentives to Secure IoT
- FreeBuf网络安全行业门户
- text/plain
- Black Hills Information Security
- bishopfox.com
- Light Cube
- rtl-sdr.com
- 奇客Solidot–传递最新科技情报
- 安全牛
- SecPulse安全脉搏
- KitPloit - PenTest & Hacking Tools
- 腾讯玄武实验室
- 虎符智库
- 绿盟科技研究通讯
- 代码卫士
- 安全内参
- 软件安全与逆向分析
- 暗影安全
- 奇安信威胁情报中心
- 安全研究GoSSIP
- 数世咨询
- 奇安信病毒响应中心
- Seebug漏洞平台
- HackerNews
- 网安杂谈
- 安全牛
- 极客公园
- 安全圈
- 三六零CERT
- 看雪学苑
- 我的安全视界观
- Malwarebytes Labs
- 陌陌安全
- CNCERT国家工程研究中心
- 长亭科技
- KCon 黑客大会
- 慢雾科技
- 中国信息安全
- M01N Team
- 迪哥讲事
- 字节跳动技术团队
- 火绒安全
- Numen Cyber Labs
- 国家互联网应急中心CNCERT
- 关键基础设施安全应急响应中心
- Over Security - Cybersecurity news aggregator
- Microsoft fixes flaw after being called irresponsible by Tenable CEO
- Microsoft resolves vulnerability following criticism from Tenable CEO
- Lawsuit accuses hospital of sharing patient health data with Facebook
- New PaperCut critical bug exposes unpatched servers to RCE attacks
- FBI investigating ransomware attack crippling hospitals across 4 states
- FBI warns of scammers posing as NFT devs to steal your crypto
- Discarded medical devices found to have troves of information on healthcare facilities
- Microsoft kills Cortana in Windows 11 preview, long live AI!
- Google explains how Android malware slips onto Google Play Store
- “Crocodile of Wall Street” and her husband plead guilty to giant-sized cryptocrimes
- Extended warranty robocallers fined $300 million after 5 billion scam calls
- US ‘lagging behind’ on Border Gateway Protocol security practices, CISA and FCC chiefs say
- Teach a Man to Phish and He’s Set for Life
- Spotify down: music searches, pages, account signups not working
- Dopo WormGPT arriva FraudGPT: il cybercrimine punta sui chatbot malevoli
- Fake VMware vConnector package on PyPI targets IT pros
- Violate e-mail di funzionari USA e UE, sale la tensione con la Cina: nuovi scenari di cyberwar
- Emotet e Lokibot non mollano, e nascono nuove minacce: il report di Kaspersky
- La cyber security per proteggere i sistemi di calcolo quantistico: minacce e soluzioni tecnologiche
- Risky Biz News: Microsoft accused of negligence in dealing with security flaw, again
- Yak Project
- 信安杂记
- 网安寻路人
- /dev/random
- 嘶吼专业版
- Securityinfo.it
- 360数字安全
- Schneier on Security
- 补天平台
- 深信服千里目安全技术中心
- SANS Internet Storm Center, InfoCON: green
- bellingcat
- Full Disclosure
- Krebs on Security
- Security Affairs
- A cyberattack impacted operations of multiple hospitals in several US states
- Married couple pleaded guilty to laundering billions in cryptocurrency stolen from Bitfinex in 2016
- Malicious packages in the NPM designed for highly-targeted attacks
- Attackers use dynamic code loading to bypass Google Play store’s malware detections
- CISA, FBI, and NSA published the list of 12 most exploited vulnerabilities of 2022
- Graham Cluley
- Blackhat Library: Hacking techniques and research
- Deeplinks
- Your Hacking Tutorial by Zempirians
- I don't know if this is the right place. Please tell me if it isn't. I'm a writer working on a series of short stories about a pentester work works with company to test physical and digital security of locations. (Think like a hacker MacGyver).
- Modify EXE without source code?
- Integer Overflow Detected in Keyspace of Mask
- Technical Information Security Content & Discussion
- Pentestmag
- Google Online Security Blog
- Information Security
- Social Engineering
- The Hacker News
- NYC Couple Pleads Guilty to Money Laundering in $3.6 Billion Bitfinex Hack
- Webinar - Making PAM Great Again: Solving the Top 5 Identity Team PAM Challenges
- Malicious npm Packages Found Exfiltrating Sensitive Data from Developers
- Major Cybersecurity Agencies Collaborate to Unveil 2022's Most Exploited Vulnerabilities
- KitPloit - PenTest Tools!
- Computer Forensics
- Security Weekly Podcast Network (Audio)
- Dark Space Blogspot
Related Documents
MEMORY.md
Zig 0.16.0 Context Document for LLMs
**Purpose:** This document updates LLM knowledge from Zig 0.13/0.14 to modern Zig (0.15.x/0.16.0). Paste this into any LLM conversation when working with current Zig code.
aillmrag
0
14
mattneelMEMORY.md
TreeDex — Comprehensive Documentation
> Tree-based, vectorless document RAG framework.
aiagentllm
0
2
mithun50MEMORY.md
所有收集类项目
- 跟驻留/持久化有关的工具和文章,多平台。包括80个工具和350左右文章。
ai
0
2
alphaSeclabMEMORY.md
Attaching virtual persistent memory in a {{site.data.keyword.powerSys_notm}} instance
lastupdated: "2026-03-25"
ai
0
1
ibm-cloud-docs