unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
SequenceHash: multihashing for the rest of us
Multihashing is one of those cryptographic tasks that’s easy not to think about too much. This is un...
2026-10-2 11:0:0 | 阅读: 17 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
hasher
sequencemac
Don't let TEEs break your MPC
Threshold signature schemes, a form of multi-party computation (MPC) that lets a set of parties sign...
2026-9-25 11:0:0 | 阅读: 19 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
security
attestation
mpc
tees
SAML: A fractal of bad design
Born out of academia and raised in corporate IT departments, the Security Assertion Markup Language...
2026-9-21 11:0:0 | 阅读: 40 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
oidc
security
sso
Auditing in the age of (good enough) AI
Security firms have published numerous blog posts describing how they pointed their agent harness at...
2026-9-18 11:0:0 | 阅读: 30 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
masm
miden
analysis
library
lean
1Password's AI patching benchmark is misleading
1Password’s FLAWED report, published on August 6, 2026, gives defenders a misleading picture of AI p...
2026-9-15 11:0:0 | 阅读: 25 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
agents
security
planet
maintainers
A “proof” of Fermat’s Last Theorem that fits the margin
Fermat famously claimed to have a “truly marvelous proof” of his Last Theorem, but he never wrote it...
2026-9-9 11:0:0 | 阅读: 37 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
lean
fermat
theorem
proofs
flt
VMs won't contain cyber-capable agents
As part of Patch the Planet, we received preview access to GPT 5.6-Cyber with a simple task: evaluat...
2026-8-26 11:0:0 | 阅读: 41 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
machine
security
upstream
software
gpt
State divergence enables unauthorized access
We found and reported a bug in Provenance Blockchain, a public proof-of-stake chain built on Cosmos...
2026-8-25 11:0:0 | 阅读: 32 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
marker
markers
attacker
provenance
How Trail of Bits helps verify the integrity of your Signal chats
Every Signal chat starts the same way: the client asks the Signal server for the public key associat...
2026-8-11 17:30:0 | 阅读: 35 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
client
auditor
auditors
trail
A few notes on AWS Nitro Enclaves: KMS integration
Nitro Enclaves and Key ManagementService (KMS) feel like anatural fit: since the KMS can verify at...
2026-8-5 11:0:0 | 阅读: 49 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
kms
enclave
cmk
enclaves
attestation
Building secure Uniswap v4 hooks
Uniswap v4 hooks let developers add custom behavior to pools, including dynamic fees, custom account...
2026-7-30 11:0:0 | 阅读: 53 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
poolmanager
accounting
fee
pools
attacker
How we use /goal to find bugs in Patch the Planet
Codex’s /goal feature amplifies bug hunting, but getting good results requires the right prompt, the...
2026-7-28 11:0:0 | 阅读: 56 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
codex
outcome
client
security
remote
Rust-proof your code with our new Testing Handbook chapter
We’ve added a new chapter to our Testing Handbook: a comprehensive guide to security testing Rust pr...
2026-7-13 11:0:0 | 阅读: 40 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
security
chapter
memory
analysis
reviews
Mutation testing comes to DAML
In April we released Mewt, our open-source mutation-testing engine that finds the gaps in your test...
2026-7-8 11:0:0 | 阅读: 42 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
daml
mewt
buyer
seller
mutants
Field reports from Patch the Planet
We’re running Patch the Planet, an ongoing collaboration with OpenAI that pairs Trail of Bits engine...
2026-7-2 11:0:0 | 阅读: 49 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
gpt
harness
zlib
maintainers
bespoke
Shipping post-quantum cryptography to Python
Post-quantum cryptography is now one pip-install away for the entire Python ecosystem. With funding...
2026-6-30 11:0:0 | 阅读: 54 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
dsa
kem
primitives
pyca
python
Introducing Patch the Planet
What happens when you clear dozens of Trail of Bits engineers’ schedules, pair them with every open-...
2026-6-22 16:50:0 | 阅读: 62 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
patchy
security
planet
python
maintainers
Factoring "short-sleeve" RSA keys with polynomials
What happens when the bits of an RSA private key are heavily biased toward 0 instead of being random...
2026-6-12 11:0:0 | 阅读: 67 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
sleeve
completeftp
polynomial
dsa
The sorry state of skill distribution
Public skill marketplaces are being flooded with malicious skills that steal credentials, exfiltrate...
2026-6-3 11:0:0 | 阅读: 68 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
skill
malicious
llm
scanners
We hardened zizmor's GitHub Actions static analyzer
In March 2026, attackers exploited a pull_request_target misconfiguration inthe aquasecurity/trivy-...
2026-5-22 11:0:0 | 阅读: 51 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
zizmor
anchor
github
workflows
anchors
Previous
-1719
-1718
-1717
-1716
-1715
-1714
-1713
-1712
Next