向Typora学习electron安全攻防
本文为看雪论坛优秀文章看雪论坛作者ID:钞能力大叔目标应用: aHR0cHM6Ly90eXBvcmEuaW8v 越来越多的应用开始使用 electron 来构建跨平台桌面应用。...
透过数据安全法看API安全该如何防护
摘要近年来,在面对数据安全威胁日益严峻的态势,我国逐步颁布了系列数据安全相关的法律法规,着力解决数据安全领域的突出问题。而API作为连接数据与应用的重...
QEMU虚拟化安全的攻击面探索与思考
QEMU和KVM作为虚拟化技术的典型代表,被广泛的应用在各家厂商的云计算系统中。作为一款有着十多年历史的软件,QEMU一直遭受着安全问题的困扰。随着以QEMU/KVM...
APT ToddyCat
Unveiling an unknown APT actor attacking high-profile entities in Europe and Asia ToddyCat is a relatively new APT actor that we have not been ab...
Hacking into the worldwide Jacuzzi SmartTub network
Background Jacuzzi Brands is a widely recognized hot tub and spa manufacturer. There are several brands under their umbrella: Jacuzzi Hot Tubs ...
Demystifying Tesla’s Bluetooth Passive Entry System
原文始发于trifinite.org:Demystifying Tesla’s Bluetooth Passive Entry System
Technical Analysis of PureCrypter: A Fully-Functional Loader Distributing Remote Access Trojans and Information Stealers
Key points PureCrypter is a fully-featured loader being sold since at least March 2021 The malware has been observed distributing a variety of...
每日安全动态推送(06-22)
Tencent Security Xuanwu Lab Daily News• Intercepting MS Teams Communication:https://blacklabsdev.medium.com/intercepting-ms-team-communication...
CVE-2022-31289 Nexus Repository Manager 的一个伪认证绕过 “漏洞”
★且听安全★-点关注,不迷路!★漏洞空间站★-优质漏洞资源和小伙伴聚集地!漏洞信息最近在网上看到 Nexus Repository Manager 爆出存在所谓的认证绕过漏洞 CVE-...
Follina 补了?IE 凉了?花几分钟再弹个计算器
由于没有漂亮的小姐姐可以拍旅游 vlog,继续写穷酸的技术文。虽然本文不涉及任何漏洞,但考虑到一些因素,还是隐去一些关键的字符串信息。具有分析能力的读者...