unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
We checked 1,237 fixes. One in four was not fixed.
Between October 2021 and August 2026 our clients sent 1,237 fixes back to us and asked us t...
2026-8-4 11:0:0 | 阅读: 11 |
收藏
|
Comments on: - appsec-labs.com
retest
verdict
mitigated
engagement
client
What 890 security engagements actually find
We have recorded 6,643 findings across 890 engagements since our platform went live. This i...
2026-8-4 09:0:0 | 阅读: 11 |
收藏
|
Comments on: - appsec-labs.com
bypass
client
engagements
median
Somebody Wired the Darknet Into Your AI. What Could Go Wrong?
Somebody has wired...
2026-7-24 05:0:48 | 阅读: 1 |
收藏
|
Comments on: - appsec-labs.com
darknet
somebody
mcp
genuinely
erez
Configured Is Not Enforced
This piece is my read on research published by TrustOnCloud. The findings are theirs; the a...
2026-7-21 13:9:32 | 阅读: 1 |
收藏
|
Comments on: - appsec-labs.com
security
assumed
enforced
lesson
Every Week Someone Asks Me When AI Will Replace Pentesters
This piece is my re...
2026-7-18 09:1:30 | 阅读: 1 |
收藏
|
Comments on: - appsec-labs.com
datadog
perfectly
security
scanners
formed
The Most Expensive Vulnerability Is a Token Nobody Rotated
Ozempic – the injec...
2026-7-8 09:1:11 | 阅读: 1 |
收藏
|
Comments on: - appsec-labs.com
forgot
somebody
security
rotate
billions
Cloud Ransomware: Soft-Delete and Versioning Are the Whole Story
You thought the cloud was looking after you?There is a way to encrypt all of your storage,...
2026-7-7 05:1:14 | 阅读: 1 |
收藏
|
Comments on: - appsec-labs.com
cloud
attacker
versioning
soft
Learn Mode and Enforce Mode Are Sold in the Same Breath. They Are Not the Same Thing.
AWS is now promising you security at machine speed. The agent will find the vulnerability b...
2026-7-6 05:2:55 | 阅读: 1 |
收藏
|
Comments on: - appsec-labs.com
security
machine
sold
stays
enforce
One Click, and Every Private Repo You Can Reach Is Theirs
One click. One sing...
2026-6-26 09:1:20 | 阅读: 1 |
收藏
|
Comments on: - appsec-labs.com
github
attackers
attacker
keystrokes
malicious
Attackers Are Running Their C2 on Your Cloud, and You Are Paying for It
Attackers are running their command-and-control server on your cloud. And you are paying fo...
2026-6-26 05:0:30 | 阅读: 1 |
收藏
|
Comments on: - appsec-labs.com
cloud
paying
somebody
attacker
victim
A Quarter of Azure Identities Trusting GitHub Actions Are Takeable. Right Now.
Almost a quarter of the identities in Azure that trust GitHub Actions are vulnerable to tak...
2026-6-25 09:1:49 | 阅读: 1 |
收藏
|
Comments on: - appsec-labs.com
cloud
identities
oidc
github
gitlab
Your AI Coding Tool Walks Straight Past Your Defences
The AI tools you trust to write your code? They walk past your defences. Not by accident. N...
2026-6-23 09:1:33 | 阅读: 1 |
收藏
|
Comments on: - appsec-labs.com
injection
security
recommends
attacker
2026
An Hour Into the Assessment We’re Cloud Admin – and It’s Never a Zero-Day
This piece is my read on research published by Pathfinding Labs. The findings are theirs; t...
2026-6-10 05:3:54 | 阅读: 1 |
收藏
|
Comments on: - appsec-labs.com
cloud
security
somebody
hop
pathfinding
The Docker Instruction That Runs on Your Machine, Not Theirs
There is a Docker instruction that runs automatically during your build. You do not know it...
2026-6-9 09:1:23 | 阅读: 1 |
收藏
|
Comments on: - appsec-labs.com
onbuild
somebody
github
lawyers
constantly
The AI Skill That Steals Your GitHub Token
Are your developers installing skills for their AI tools? Some of those skills steal their...
2026-6-6 05:1:17 | 阅读: 1 |
收藏
|
Comments on: - appsec-labs.com
developer
skill
github
claude
developers
One Cyrillic Letter, and the Identity Provider Was Theirs
This piece is my read on research published by Doyensec. The findings are theirs; the argum...
2026-5-21 09:1:14 | 阅读: 1 |
收藏
|
Comments on: - appsec-labs.com
letter
somebody
cyrillic
cloud
Attackers Don’t Break Into Your Cloud. They Log In.
Attackers are not breaking into your cloud. They are logging in.No exploit, no zero-day, n...
2026-5-16 05:2:34 | 阅读: 1 |
收藏
|
Comments on: - appsec-labs.com
attacker
gap
attackers
unusual
cloud
AI Wrote the Code. The CVE Is Still Yours.
This piece is my re...
2026-4-20 09:1:18 | 阅读: 2 |
收藏
|
Comments on: - appsec-labs.com
security
vibe
georgia
somebody
injection
Is Your AI Secure? The Dark Reality of LLM Vulnerabilities
嗯,用户让我用中文总结一篇文章,控制在一百个字以内,而且不需要特定的开头。首先,我需要通读这篇文章,理解它的主要内容。 文章主要讲的是针对大型语言模型(LLM)的应用程序的网络攻击越来越多,攻击手段也越来越复杂。文章提到了配置错误的聊天机器人、暴露的API以及与网络、云和移动系统的薄弱集成可能导致数据泄露、勒索软件事件或服务中断。为了防止这些问题,组织需要专注于理解AI行为及其被攻击者利用方式的网络安全服务。 接下来,文章详细介绍了安全渗透测试如何模拟针对LLM应用的真实攻击,揭示如提示注入、数据中毒、模型反转、访问控制失败和不安全网络集成等风险。还提到了结合网络、Web、云应用安全测试等形成端到端防御策略。最后,介绍了AppSec Labs提供的专门AI安全测试服务。 总结一下,文章强调了LLM应用面临的安全挑战,渗透测试的重要性以及如何实施有效的防御策略。现在需要将这些内容浓缩到100字以内。 首先确定关键点:LLM应用面临的安全威胁增加;渗透测试的重要性;涵盖的风险类型;结合多方面的安全测试形成防御策略;AppSec Labs的服务。 然后组织语言:大型语言模型应用面临日益增长的安全威胁,包括配置错误和API暴露等。渗透测试模拟真实攻击,识别提示注入、数据中毒等风险,并结合网络、云和移动安全测试构建全面防御。AppSec Labs提供专业AI安全测试服务。 检查字数是否在100字以内,并确保流畅自然。 </think> 大型语言模型应用面临日益增长的安全威胁,包括配置错误和API暴露等。渗透测试模拟真实攻击,识别提示注入、数据中毒等风险,并结合网络、云和移动安全测试构建全面防御。AppSec Labs提供专业AI安全测试服务。...
2026-2-22 22:0:0 | 阅读: 7 |
收藏
|
Comments on: - appsec-labs.com
security
llm
cloud
appsec
network
Medical Devices Penetration Testing
好的,我现在需要帮用户总结这篇文章的内容,控制在100字以内。首先,我得仔细阅读文章,抓住主要观点。 文章主要讲的是医疗设备面临网络安全威胁的问题。医疗设备现在连接到医院网络、云平台和移动应用,这使得它们成为网络攻击的目标。攻击可能导致敏感数据泄露、治疗中断以及监管处罚。 接下来,文章解释了为什么医疗设备渗透测试很重要。它提到了常见的漏洞,比如弱加密、过时的固件和不安全的默认设置。此外,还讨论了AI、云和Web接口带来的风险。 然后,文章详细介绍了渗透测试的过程,包括范围界定、侦察、漏洞发现、模拟攻击、影响评估和修复验证。还提到了选择可靠的测试合作伙伴的重要性,并比较了通用和专业的测试服务。 最后,结论部分强调了渗透测试在保护患者和临床操作中的核心作用,并提供了进一步资源的链接。 总结起来,我需要把这些关键点浓缩到100字以内。重点包括医疗设备的安全威胁、渗透测试的重要性、常见漏洞以及如何进行有效的测试。 </think> 医疗设备网络安全威胁日益严重,攻击可能导致数据泄露及治疗中断。渗透测试可发现设备漏洞并模拟攻击影响。常见问题包括弱加密、过时固件及网络配置不当。通过结构化测试流程与专业团队合作,医疗机构可提升安全水平并符合监管要求。...
2026-2-14 22:0:0 | 阅读: 11 |
收藏
|
Comments on: - appsec-labs.com
security
healthcare
clinical
cloud
Previous
-1
0
1
2
3
4
5
6
Next