unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
Signal in the noise: what hashtags reveal about hacktivism in 2025
研究分析了2025年网络激进主义活动的模式与趋势,发现其战术以高可见性和易执行性为主,而非技术复杂性。Telegram成为主要策划平台,标签广泛用于协调行动与宣传,DDoS攻击占比最高。尽管聚焦中东地区,但目标遍布全球,建议加强DDoS防护与开放渠道监测。...
2025-10-14 10:0:9 | 阅读: 98 |
收藏
|
Securelist - securelist.com
hacktivist
hashtags
monitoring
threats
political
The king is dead, long live the king! Windows 10 EOL and Windows 11 forensic artifacts
Windows 11引入了新的取证功能和变化,包括Recall截屏和AI分析、Notepad多标签支持及未保存内容存储、Windows Search从ESE转为SQLite数据库等。这些变化为取证分析提供了新工具和挑战。...
2025-10-14 08:0:57 | 阅读: 104 |
收藏
|
Securelist - securelist.com
windows
artifacts
recall
microsoft
uleb128
Detecting DLL hijacking with machine learning: real-world cases
Kaspersky SIEM集成了一种机器学习模型,用于检测DLL劫持攻击。该模型通过检查系统中加载的所有DLL库,并结合Kaspersky安全网络的全球知识库进行验证,以提高检测准确性并减少误报。模型支持两种运行模式:在correlator上处理已触发规则的事件,在collector上处理所有相关事件。在试点测试中,该模型成功识别了多个真实攻击案例,包括利用DLL侧载技术的恶意活动。...
2025-10-6 08:15:13 | 阅读: 14 |
收藏
|
Over Security - Cybersecurity news aggregator - securelist.com
library
malicious
hijacking
windows
How we trained an ML model to detect DLL hijacking
文章探讨了DLL劫持攻击的现状及其检测挑战,并介绍了卡巴斯基使用机器学习模型检测此类攻击的方法。通过三代模型的训练与优化,检测准确率显著提升,误报率降低。这些模型已应用于内部系统及商业产品中,有效识别并阻止 DLL 劫持攻击。...
2025-10-6 08:15:12 | 阅读: 14 |
收藏
|
Over Security - Cybersecurity news aggregator - securelist.com
hijacking
library
malicious
labeling
positives
Forensic journey: hunting evil within AmCache
文章探讨了Windows系统中AmCache文件的重要性。该文件记录了所有执行过的程序的元数据,包括路径、哈希值和时间戳等信息。通过分析这些数据,可以识别恶意软件、追踪攻击行为并生成威胁情报。...
2025-10-1 10:15:13 | 阅读: 14 |
收藏
|
Over Security - Cybersecurity news aggregator - securelist.com
amcache
windows
hve
Massive npm infection: the Shai-Hulud worm and patient zero
read file error: read notes: is a directory...
2025-9-25 10:15:13 | 阅读: 22 |
收藏
|
Over Security - Cybersecurity news aggregator - securelist.com
crowdstrike
shai
hulud
github
Threat landscape for industrial automation systems in Q2 2025
read file error: read notes: is a directory...
2025-9-19 10:45:13 | 阅读: 17 |
收藏
|
Over Security - Cybersecurity news aggregator - securelist.com
malicious
q2
pp
threats
decreased
RevengeHotels: a new wave of attacks leveraging LLMs and VenomRAT
文章描述了一个错误代码(1016),通常与网络连接问题相关,可能由代理服务器配置错误、网络连接中断或防火墙设置不当引起。解决方法包括检查代理设置、重启设备或联系网络管理员以排查具体原因。...
2025-9-16 10:15:14 | 阅读: 17 |
收藏
|
Over Security - Cybersecurity news aggregator - securelist.com
1016
Shiny tools, shallow checks: how the AI hype opens the door to malicious MCP servers
本文探讨了Model Context Protocol (MCP)作为AI助手与外部工具连接的标准如何被滥用为攻击手段。文章分析了协议级和供应链攻击路径,并通过恶意MCP服务器的概念验证展示了敏感数据泄露风险。建议采取审查安装、限制权限和监控异常行为等措施以防范威胁。...
2025-9-15 10:45:13 | 阅读: 14 |
收藏
|
Over Security - Cybersecurity news aggregator - securelist.com
mcp
malicious
analysis
github
ssh
Notes of cyber inspector: three clusters of threat in cyberspace
read file error: read notes: is a directory...
2025-9-10 14:30:17 | 阅读: 15 |
收藏
|
Over Security - Cybersecurity news aggregator - securelist.com
ttps
motivated
security
hacktivists
russia
IT threat evolution in Q2 2025. Non-mobile statistics
read file error: read notes: is a directory...
2025-9-5 09:15:14 | 阅读: 13 |
收藏
|
Over Security - Cybersecurity news aggregator - securelist.com
ransomware
quarter
trojan
territory
q2
IT threat evolution in Q2 2025. Mobile statistics
read file error: read notes: is a directory...
2025-9-5 09:15:12 | 阅读: 13 |
收藏
|
Over Security - Cybersecurity news aggregator - securelist.com
trojan
banker
mamont
q2
trojans
Cookies and how to bake them: what they are for, associated risks, and what session hijacking has to do with it
read file error: read notes: is a directory...
2025-9-2 10:15:12 | 阅读: 18 |
收藏
|
Over Security - Cybersecurity news aggregator - securelist.com
security
attacker
malicious
developers
fixation
How attackers adapt to built-in macOS protection
文章介绍了macOS的安全机制(如Keychain、TCC、SIP、File Quarantine、Gatekeeper和XProtect),分析了常见攻击方式及其绕过方法,并提供了检测和防御建议。...
2025-8-29 10:30:15 | 阅读: 20 |
收藏
|
Over Security - Cybersecurity news aggregator - securelist.com
security
keychain
library
spctl
keychains
Exploits and vulnerabilities in Q2 2025
read file error: read notes: is a directory...
2025-8-27 10:15:13 | 阅读: 20 |
收藏
|
Over Security - Cybersecurity news aggregator - securelist.com
q2
security
c2
exploited
Modern vehicle cybersecurity trends
现代汽车正向数字化发展,提供智能系统与便利功能,但也扩大了网络安全风险。车内网络复杂,不同车型安全架构差异大,未来可能面临更多威胁,尤其是针对车队和商用车辆的攻击风险增加。...
2025-8-22 09:15:14 | 阅读: 14 |
收藏
|
Over Security - Cybersecurity news aggregator - securelist.com
vehicles
vehicle
security
remote
GodRAT – New RAT targeting financial institutions
2024年9月发现针对金融行业的恶意攻击,通过Skype分发伪装成财务文件的恶意屏幕保护程序文件,部署名为GodRAT的远程访问木马(RAT),基于Gh0st RAT代码,并利用隐写术隐藏恶意代码。攻击者还使用AsyncRAT作为辅助植入程序以维持长期访问。该活动持续至2025年8月,主要针对香港和阿联酋等地。...
2025-8-19 11:15:13 | 阅读: 13 |
收藏
|
Over Security - Cybersecurity news aggregator - securelist.com
godrat
shellcode
scr
c2
injector
Evolution of the PipeMagic backdoor: from the RansomExx incident to CVE-2025-29824
read file error: read notes: is a directory...
2025-8-18 09:0:16 | 阅读: 43 |
收藏
|
Over Security - Cybersecurity news aggregator - securelist.com
pipemagic
attackers
payload
memory
loader
New trends in phishing and scams: how AI and social media are changing the game
read file error: read notes: is a directory...
2025-8-13 08:45:12 | 阅读: 20 |
收藏
|
Over Security - Cybersecurity news aggregator - securelist.com
phishing
victim
bots
attackers
translate
Scammers mass-mailing the Efimer Trojan to steal crypto
read file error: read notes: is a directory...
2025-8-8 09:15:11 | 阅读: 16 |
收藏
|
Over Security - Cybersecurity news aggregator - securelist.com
trojan
efimer
c2
phrases
ntdlg
Previous
2
3
4
5
6
7
8
9
Next