Sec-News 安全文摘
-
1
WeWorm | The first zero-click worm to spread through WeChat calls across iOS and Android.
-
2
From Code to Chain: Why WP2Shell Stayed Out of Reach
-
3
Going depthfirst: Achieving GitLab RCE via Two Ruby Memory Corruption Vulnerabilities
-
4
契约锁远程代码执行漏洞分析(新)
-
5
GitHub RCE Vulnerability: CVE-2026-3854 Breakdown
-
6
Fastjson 1.2.83 “Gadget-Free” 漏洞(0day)深度分析与防御指南
-
7
fastjson 1.2.83 JSONType RCE详解
-
8
15-Year-Old Pre-Auth nginx RCE Across 13 Call Sites: Two-Pass Capture Clobbering CVE-2026-42533
-
9
WordPress 7.0.2: Two Core Bugs to Pre-Auth RCE
-
10
免费代理背后的攻击者行为分析
宝玉的分享
-
1
高效电商 AI 智能体解剖指南 | 选自 Anthropic 的 Claude 博客
-
2
AI 原生思维——像训练大模型一样训练自己
-
3
Warp 如何让 Agent 自我进化
-
4
我的 AI 原生开发流程:一个真实案例的完整复盘
-
5
从 TL 到 EM:我终于不再盯着 AI 写代码了
-
6
关于 Agent 的几个判断
-
7
“母病速归”式 AI:号称省 65% Token,实测只有 8.5%
-
8
一文看懂ChatGPT、Codex、Work 的差别
-
9
从零开始玩转循环 (Getting started with loops)
-
10
从写代码到管 Agent:斯坦福首门 AI 软件开发课的讲师说,大多数工程师还没准备好
(IN)SECURE Magazine Notification
-
1
(IN)SECURE Magazine Issue 1
-
2
(IN)SECURE Magazine Issue 9
-
3
(IN)SECURE Magazine Issue 14
-
4
(IN)SECURE Magazine Issue 49
-
5
(IN)SECURE Magazine Issue 50
-
6
(IN)SECURE Magazine Issue 52
-
7
(IN)SECURE Magazine Issue 53
-
8
(IN)SECURE Magazine Issue 54
-
9
(IN)SECURE Magazine Issue 55
-
10
(IN)SECURE Magazine Issue 57
Azeria Labs
-
1
ARM Instruction set (Part 3)
-
2
Memory Instructions: Load and Store (Part 4)
-
3
Load and Store Multiple (Part 5)
-
4
Conditional Execution and Branching (Part 6)
-
5
Functions and the Stack (Part 7)
-
6
Writing ARM Shellcode
-
7
Process Memory and Memory Corruption
-
8
Assembly Basics Cheatsheet
-
9
ARM Lab (VM)
-
10
Heap Exploitation Part 1: Understanding the Glibc Heap Implementation
Bits, Please!
-
1
__attribute__((constructor))
-
2
Getting arbitrary code execution in TrustZone's kernel from any context
-
3
Exploring Qualcomm's TrustZone implementation
-
4
Full TrustZone exploit for MSM8974
-
5
Android linux kernel privilege escalation vulnerability and exploit (CVE-2014-4322)
-
6
Effectively bypassing kptr_restrict on Android
-
7
Android linux kernel privilege escalation (CVE-2014-4323)
-
8
Android privilege escalation to mediaserver from zero permissions (CVE-2014-7920 + CVE-2014-7921)
-
9
Unlocking the Motorola Bootloader
-
10
Exploring Qualcomm's Secure Execution Environment
sgros-students
-
1
Autonomic computing similar work, tools and target service selection
-
2
Android application obfuscation and deobfuscation
-
3
Android obfuscation tools - ProGuard
-
4
Comparing C/C++ decompilers
-
5
Cryptographic lint tools
-
6
Java bytecode decompilers
-
7
Finding suitable problems with MySQL / MariaDB to focus on
-
8
Obfuscation techniques
-
9
Amandroid - Argus static analysis framework
-
10
Detecting cryptographic misuse with Argus static analysis framework
猜你喜欢
-
1
Grabbing data from Inputs and Textareas (Edge/IE)
-
2
CSS History Leak or “I know where you’ve been” (Edge)
-
3
Referer spoofing and defeating the XSS filter (Edge/IE)
-
4
Detecting analysts before installing the malware (IE)
-
5
Workers SOP Bypass importScripts and baseHref (Edge/IE)
-
6
On Patching Security Bugs
-
7
Detecting Local Files to Evade Analysts (IE)
-
8
Bypassing Mixed Content Warnings – Loading Insecure Content in Secure Pages (Edge/IE)
-
9
Abusing of Protocols to Load Local Files, bypass the HTML5 Sandbox and Open Popups (Edge)
-
10
Spoofing the address bar and the SmartScreen/Malware Warning (Edge)
cawan’s blog
-
1
What is Controlled Impedance Trace ? A Simple Guide To PCB Design For Embedded System
-
2
Design and Implementation of Token Stealing Kernel Shellcode for Windows 8
-
3
Memory Management Unit (MMU) Demystified For Embedded System
-
4
How To Cross Compile GDB and Run in Embedded System
-
5
What is Non-MMU or MMU-less Linux ?
-
6
Linux in Softcore Processor
-
7
How To Create A Ramdisk File and Make Use in Embedded System ?
-
8
Understanding Disk Partition in Flash For Embedded Linux System
-
9
A Simple Lab Guide of Using GDB in Embedded Linux System
-
10
The Essential Of Hacking Methodology From The Perspective Of Embedded Hacker