SecWiki周刊(第507期)
2023/11/13-2023/11/19
安全技术
Nemesis:蓝军攻击数据协同平台化实践
https://mp.weixin.qq.com/s/4D2slrxd7t1JnPpJY6CO7g
https://mp.weixin.qq.com/s/4D2slrxd7t1JnPpJY6CO7g
CodeQL分析XXL-JOB默认accessToken命令执行漏洞
https://mp.weixin.qq.com/s/AMqymFxASgKCUYZQAB8Nzw
https://mp.weixin.qq.com/s/AMqymFxASgKCUYZQAB8Nzw
多款Java模板引擎对比与模板注入的安全之旅
https://xz.aliyun.com/t/12969
https://xz.aliyun.com/t/12969
揭秘 VPN 背后的黑灰产组织
https://paper.seebug.org/3062/
https://paper.seebug.org/3062/
machine unlearning中的灾难遗忘问题的研究
https://mp.weixin.qq.com/s/fBYXwkg9Tm1uVc8ZmIViRQ
https://mp.weixin.qq.com/s/fBYXwkg9Tm1uVc8ZmIViRQ
"Operation Triangulation" 卡巴斯基被黑 - 续
https://mp.weixin.qq.com/s/ESi0bWF_jQ4nS1-CwjxlEQ
https://mp.weixin.qq.com/s/ESi0bWF_jQ4nS1-CwjxlEQ
美国推进网络空间安全发展的新举措
https://mp.weixin.qq.com/s/M6Ot2f9YW-58cbNXs10YbA
https://mp.weixin.qq.com/s/M6Ot2f9YW-58cbNXs10YbA
深度剖析GadgetInspector执行逻辑(上)
https://www.sec-in.com/article/2069
https://www.sec-in.com/article/2069
美国爱因斯坦计划跟踪与解读(2023版)
https://mp.weixin.qq.com/s/zvgOqgGqmdO4BvYsFzDTGw
https://mp.weixin.qq.com/s/zvgOqgGqmdO4BvYsFzDTGw
Defense Evasion(防御规避)
https://mp.weixin.qq.com/s/F0asRsaqOMvxHcu70kavZg
https://mp.weixin.qq.com/s/F0asRsaqOMvxHcu70kavZg
Your printer is not your printer ! - Hacking Printers at Pwn2Own Part II
https://devco.re/blog/2023/11/06/your-printer-is-not-your-printer-hacking-printers-pwn2own-part2/
https://devco.re/blog/2023/11/06/your-printer-is-not-your-printer-hacking-printers-pwn2own-part2/
Google WebP图像编解码库漏洞分析(CVE-2023-4863)
https://mp.weixin.qq.com/s/xy4SA9MDe5cPchoc8TJQ0w
https://mp.weixin.qq.com/s/xy4SA9MDe5cPchoc8TJQ0w
反击黑客团伙Hacking Team
https://feei.cn/hack-back-hacking-team/
https://feei.cn/hack-back-hacking-team/
PKU GeekGame 2023 - Writeup
https://imlonghao.com/61.html
https://imlonghao.com/61.html
基于大语言模型的零样本漏洞修复研究
https://mp.weixin.qq.com/s/Oc5WLqXBF_AvI6HAwZKPgA
https://mp.weixin.qq.com/s/Oc5WLqXBF_AvI6HAwZKPgA
Our audit of PyPI
https://blog.trailofbits.com/2023/11/14/our-audit-of-pypi/
https://blog.trailofbits.com/2023/11/14/our-audit-of-pypi/
SecWiki周刊(第506期)
https://www.sec-wiki.com/weekly/506
https://www.sec-wiki.com/weekly/506
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第507期)
