Aggregator
结合代码分析OpenClaw远程代码执行漏洞(CVE-2026-28466)
CVE-2026-3672 Jeecgboot3.9.1/3.9.0 WAF绕过:正则缺陷导致SQL注入
AI-Skill 自动进化的智能爆破工具(从零开始简单开发你第一个skill)
ivanti CVE-2025-0282漏洞复现
提示词注入视角下的 AI Webshell 检测绕过技术研究
【CVE-2026-28451】OpenClaw存在的SSRF 漏洞代码层面原理分析
European-Chinese geopolitical issues drive renewed cyberespionage campaign
Proofpoint researchers say the group behind the surge, TA416, had turned away from Europe for a few years.
The post European-Chinese geopolitical issues drive renewed cyberespionage campaign appeared first on CyberScoop.
阿里CTF Java赛道Fury反序列化漏洞分析与利用链挖掘
North Korean hackers linked to Axios npm supply chain compromise
The software supply chain attack that resulted in the compromise of npm packages of Axios, an extremely popular HTTP client library, is believed to be the work of financially-motivated North Korean attackers. Links to UNC1069 On March 31, 2026, unknown attackers managed to publish two backdoored Axios npm packages after gaining access to a maintainer’s npm account. The malicious versions introduced a hidden dependency containing a post-install script, and this script executed automatically during installation … More →
The post North Korean hackers linked to Axios npm supply chain compromise appeared first on Help Net Security.