腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Android ] Something my team's been working on (scanning for security and privacy bugs in apps on Google Play): http://android-developers.blogspot.com/2016/04/enhancing-app-security-on-google-play.html
" 增强 Google Play 市场中应用的安全性, 来自 Android-Developers 官方 Blog ︰ https://t.co/Extqpdryy7"
-
[ Attack ] Which countries in EMEA are most targeted with advanced attacks? Find out more: http://bddy.me/21vVc41 #infosec https://t.co/j8cscmPLCi
"来自 FireEye 的区域性高级威胁报告: 欧洲、中东和非洲 ︰ https://t.co/sfGKtaoo6m https://t.co/j8cscmPLCi"
-
[ Attack ] JAKU - Analysis of Botnet Campaign : https://www.forcepoint.com/sites/default/files/resources/files/report_jaku_analysis_of_botnet_campaign_en_0.pdf (pdf/wp)
"JAKU Botnet 攻击行动分析报告, 来自 ForcePoint: https://t.co/JcbiFydGPx "
-
[ Attack ] How to Fall Victim to Advanced Persistent Threats > my newest article, thx to all involved https://www.bsk-consulting.de/2016/05/04/how-to-fall-victim-to-apt/ https://t.co/uAYLX2jicP
" 哪些行为可以 '帮助' 攻击者实施一次成功的 APT: https://t.co/7WsbZd3y3p https://t.co/uAYLX2jicP"
-
[ Industry News ] Author of the Gozi Banking Trojan ordered to pay $7 Million http://securityaffairs.co/wordpress/46961/cyber-crime/gozi-banking-trojan-author-sentence.html
"28 岁的俄罗斯籍的 Gozi 银行木马的作者被判赔 700 万弥补银行损失: https://t.co/5qL2JHVw7B"
-
[ IoTDevice ] The IoT can unlock homes, new Bitdefender report shows – HOTforSecurity http://www.hotforsecurity.com/blog/privacy-takes-the-back-seat-in-iot-products-new-report-confirms-13705.html
" IoT 设备极大的方便了生活,但当前 IoT 带来的隐私和安全隐患也不容忽视,来自 Bitdefender 的分析报告: https://t.co/zx2PQYcDzG"
-
[ Linux ] Linux kernel BPF UAF exploit https://bugs.chromium.org/p/project-zero/issues/detail?id=808
"Linux 内核 BPF double-fdput() UAF 漏洞, Project Zero Issue 808: https://t.co/lY9ZPAzFkh"
-
[ Mac OS X ] Apple updated its #Xcode development environment, patching two vulns - http://ow.ly/4nqISh
"Apple 更新 Xcode 7.3.1, 修复了 Git 组件相关的两个漏洞: https://t.co/NQvfdj1evN"
-
[ Malware ] TrueCrypter #ransomware is 1st ransomware to accept #Amazon gift cards: http://bit.ly/1SYsXL7
"TrueCrypter 是第一个接受 Amazon 礼品卡的勒索软件 ︰ https://t.co/1AKnrHZeAi"
-
[ MalwareAnalysis ] MultiScanner - A file analysis framework for malware analysis : https://github.com/MITRECND/multiscanner/
"MultiScanner - 一个模块化的恶意软件文件分析框架︰ https://t.co/6tha1Pl4rx"
-
[ OpenSourceProject ] Full analysis of the OpenSSL CBC padding oracle (CVE-2016-2107) : https://blog.cloudflare.com/yet-another-padding-oracle-in-openssl-cbc-ciphersuites/ cc: @ FiloSottile https://t.co/8rVPEBBTH0
"CloudFlare 对 OpenSSL 最新 CBC Padding Oracle 漏洞(CVE-2016-2107) 的分析 ︰ https://t.co/xZxAnzkBnV 附 PoC: https://github.com/FiloSottile/CVE-2016-2107 https://t.co/8rVPEBBTH0"
-
[ OpenSourceProject ] LIBARCHIVE ZIP ZIP_READ_MAC_METADATA CODE EXECUTION VULNERABILITY http://www.talosintel.com/reports/TALOS-2016-0155/ .Having collision on it with @ ada95ftw, congrats
"libarchive 在处理 ZIP 解压缩时存在堆溢出漏洞(CVE-2016-1541), 来自 Talos 的公告: https://t.co/6UEVztN9Rd "
-
[ Others ] ImageMagick exploit code has just been released and it's already actively being exploited in the wild. Patch! Patch! http://pastebin.com/aE4sKnCg
" Pastebin 网站有人贴出了 ImageMagick 的漏洞利用代码: https://t.co/VO0w5hbZXl"
-
[ Others ] API bug exposes #Telepresence hardware https://threatpost.com/cisco-patches-critical-telepresence-vulnerability/117866/ via @ threatpost
"Cisco 刚刚修复了 Telepresence 设备的一个严重漏洞,由于 API 的 Bug,允许未认证的用户获取系统访问权限, Telepresence 设备用于为用户提供一种比普通视频会议更高级的体验: https://t.co/VKh5zkasPh"
-
[ Others ] Kernel exploit for Wiiu 5.5 : https://gbatemp.net/threads/tutorial-running-kexploit-5-5-x-w-haxserver-loadiine-homebrew-launcher-etc.424948/
"WiiU 5.5 任天堂游戏机内核 Exploit ︰ https://t.co/CuGZACLvNp"
-
[ Tools ] Have added CANSocket support, detection of ISO-TP/UDS with padding and new DIFF/search features. Real examples here https://asintsov.blogspot.de/2016/05/cantoolz-iso-tp-and-diff-updates.html
"CanToolz 工具更新,兼容 Python 3.x, 支持 CANSocket: https://t.co/0kDhEFWYcn"
-
[ Tools ] SLAyer - formal verification tool that uses separation logic to verify memory safety of C programs https://github.com/Microsoft/SLAyer #microsoft
"SLAyer - 微软开源的一个形式验证工具,用分离逻辑验证 C 程序的内存安全: https://t.co/VlWFCPJjHk "
-
[ Windows ] My first Windows driver : Creating the Pink Screen Of Death : https://www.whitehatters.academy/my-first-windows-driver-creating-the-pink-screen-of-death/ #PSOD cc @ _samdb_ https://t.co/UOApIAD7KT
" 平时只见过 Windows 蓝屏崩溃,而作者写了一个驱动,可以触发粉色的 Screen of Death︰ https://t.co/wshhBs3kLV https://t.co/UOApIAD7KT"