360-CERT每日安全简报
Daily Security Briefing
2020-11-02 星期一
<<Previous
Next>>
漏洞
Vulnerability
CVE-2020-17087 Windows Kernel cng.sys pool-based buffer overflow
https://bugs.chromium.org/p/project-zero/issues/detail?id=2104
CVE-2020-5980 NVIDIA SMI中的DLL劫持
https://www.pentestpartners.com/security-blog/dll-hijacking-in-nvidia-smi/
安全工具
Security Tools
红队用来收集windows信息的powershell工具
https://github.com/tobor88/PowerShell-Red-Team
CrossC2生成CobaltStrike的跨平台有效载荷工具
https://github.com/gloxec/CrossC2
安全报告
Security Report
In-depth analysis of Abaddon
https://github.com/MalPhobic/MalwareReports/blob/main/AbbadonRAT/Abbadon_RAT.pdf
安全事件
Security Incident
电商平台Lazada 110万账户信息被黑客入侵
https://www.cnbeta.com/articles/tech/1047381.htm
因未能确保客户个人数据安全问题,万豪国际被罚1840万英镑
https://finance.sina.com.cn/tech/2020-11-01/doc-iiznctkc8871028.shtml
安全研究
Security Research
构造一个 CodeDB 来探索全新的白盒静态扫描方案
https://paper.seebug.org/1387/
Fuzzing for eBPF JIT bugs in the Linux kernel(CVE-2020-27194)
https://scannell.me/fuzzing-for-ebpf-jit-bugs-in-the-linux-kernel/
CrowdStrike | 无文件攻击白皮书
https://mp.weixin.qq.com/s/0jMTOKsvV9q7_0Gz04veHg
.Net 反序列化之 ViewState 利用
https://paper.seebug.org/1386/
<<Previous
Next>>