
腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ APT ] APT_CyberCriminal_Campagin_Collections - 2006 年至今的几乎所有公开的 APT 攻击分析报告收集: https://github.com/CyberMonitor/APT_CyberCriminal_Campagin_Collections
-
[ Compiler ] 来自 Hex-Rays 的 Ilfak Guilfanov 对 IDA Pro 新加入的 CPU 微码反编译器架构的介绍: https://recon.cx/2018/brussels/resources/slides/RECON-BRX-2018-Decompiler-internals-microcode.pdf
-
[ MalwareAnalysis ] McAfee 对 Honeybee 行动的调查报告,该行动针对人道主义援助组织散发恶意文档: https://securingtomorrow.mcafee.com/mcafee-labs/mcafee-uncovers-operation-honeybee-malicious-document-campaign-targeting-humanitarian-aid-groups/
-
[ Popular Software ] 绕过 Flash Player 中 ByteArray 的 length 属性检查实现代码执行(CVE-2018-4878) : https://securingtomorrow.mcafee.com/mcafee-labs/hackers-bypassed-adobe-flash-protection-mechanism/
-
[ Tools ] OpticSpy - 用于解码光学隐蔽信道传输的数据的工具: https://www.crowdsupply.com/grand-idea-studio/opticspy
-
[ Tools ] peanalyzer - 便携式可执行文件分析和反汇编工具: https://github.com/blacknbunny/peanalyzer
-
[ Tools ] Seth - 对 RDP 服务实施中间人攻击的工具,可从 RDP 连接中提取明文密码: https://github.com/SySS-Research/Seth