
腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Android ] Sex Sells: Looking at Android Adult Adware Apps https://blogs.mcafee.com/mcafee-labs/sex-sells-looking-at-android-adult-adware-apps/
"Android 成人广告 APP 通过社交网络传播: https://t.co/ZjSa39gBun"
-
[ Attack ] .@ _jsoo_ In case most ppl don't understand Italian, slides are here http://www.hackinbo.it/programma-2/ @ embyte 's slide is here http://www.hackinbo.it/wp-content/uploads/2016/05/Marco-Balduzzi-HackInBo.pdf
" 暗网中的网络犯罪调查报告,来自 TrendMicro 研究员在 HackInBo 会议的演讲: https://t.co/uYsS3sC4qN"
-
[ Browser ] Google to kill Flash in Chrome by introducing click-to-play by default: https://groups.google.com/a/chromium.org/forum/#!searchin/chromium-dev/HTML5$20by$20default/chromium-dev/0wWoRRhTA_E/__E3jf40OAAJ & https://docs.google.com/presentation/d/106_KLNJfwb9L-1hVVa4i29aw1YXUy9qFX-Ye4kvJj-4/edit?pref=2&pli=1#slide=id.g1270f83468_0_5 #Flash #Bounties
" Chrome 浏览器开发者论坛上对 Flash 'click-to-play' 问题的讨论,第一次访问网站时会弹框确认是否允许加载 Flash,点击同意后,以后的访问就会自动加载了︰ https://t.co/UGabd8yzZ1 https://t.co/6YWoKbU5hR "
-
[ Detect ] Here are the "Hunting: Discovering Hidden Threats" slides from today https://docs.google.com/presentation/d/13Pnnn9yrKF5aZjTdRVVcGOUV7JMc1Yj3x1eHG1y-sL8/edit?usp=sharing
" 挖掘、捕获隐藏的威胁,来自 FireEye 的首席顾问谈威胁检测的问题: https://t.co/9CGVRWgnd3 "
-
[ iOS ] Looks like the original app is open source https://github.com/Asido/SystemMonitor
"iOS System Monitor: https://t.co/Ajdd0mLXQt"
-
[ IoTDevice ] Nest releases a open source ver "Thread" that makes possible for devices to simply, securely and reliably connect http://www.theinquirer.net/2457743
" Google 旗下 Nest 恒温器开源了自己的网络连接协议,协议的名称为'Thread',该协议让设备互联更加方便: https://t.co/qfC6TVIHv8 GitHub Repo: https://github.com/openthread/openthread "
-
[ Malware ] These are the slides from @ evan_pena2003 and my talk on Higher Level Malware! - http://www.slideshare.net/CTruncer/higher-level-malware
" 用高级语言编写恶意软件(Python/C#): https://t.co/mfexzt09AM"
-
[ Others ] Whitespace steganography : http://darkside.com.au/snow/ ,Details of Encoding scheme : http://darkside.com.au/snow/description.html
"SNOW - 空白字符隐写术︰ https://t.co/IIETQgN0Ee 编码方案介绍︰ https://t.co/95LeFwVV9E"
-
[ Pentest ] Run Metasploit Framework as a Docker Container Without Installation Pains : https://zeltser.com/metasploit-framework-docker-container/
"以 Docker 容器的方式运行 Metasploit 框架︰ https://t.co/XO0WXbsY0T"
-
[ Popular Software ] CVE-2016-4117: Flash Zero-Day Exploited in the Wild http://www.fireeye.com/blog/threat-research/2016/05/cve-2016-4117-flash-zero-day.html
"CVE-2016-4117 - 野外传播的 Flash 0Day: https://t.co/E668mMxjGx"
-
[ Windows ] Amazingly deep (700+ pages!) dive into Windows Security Auditing and Monitoring events - https://www.microsoft.com/en-us/download/details.aspx?id=52630
"Windows 10 安全审计与事件监控手册,来自微软官方: https://t.co/vkJOpxOsMj"