LiteLLM供应链攻击解析:三层架构,一个僵尸网络
注:本文翻译自de Março[1]的文章《Anatomia de um Infostealer Moderno: Três Camadas, Uma Botnet》[2],可点击文末“阅读原文”按
阅读全文注:本文翻译自de Março[1]的文章《Anatomia de um Infostealer Moderno: Três Camadas, Uma Botnet》[2],可点击文末“阅读原文”按
阅读全文注:本文翻译自 GMO Flatt Security 的文章《Remote Command Execution in Google Cloud with Single Directory Delet
阅读全文注:本文翻译自 Elastic Security Labs的文章《Linux & Cloud Detection Engineering - TeamPCP Container Attack Sce
阅读全文注:本文翻译自Apaksh[1]的文章《AWS Security Hardening: The Checklist Your Cloud Needs》[2],可点击文末“阅读原文”按钮查看英文原文。
阅读全文注:本文翻译自 Qualys 的文章《CrackArmor: Multiple vulnerabilities in AppArmor》[1],可点击文末“阅读原文”按钮查看英文原文。全文如下:摘要
阅读全文注:本文翻译自 Cymulate 的文章《CVE-2026-26117: Hijacking Azure Arc on Windows for Local Privilege Escalation
阅读全文注:本文翻译自 Innora 的文章《Anatomy of a Cloud Cryptojacking Campaign: XMRig via Hetzner Rescue Mode with Mu
阅读全文注:本文翻译自 Daze Security 的文章《Azure DevOps Privilege Escalation via OIDC Abuse》[1],可点击文末“阅读原文”按钮查看英文原文。
阅读全文注:本文翻译自 Calif[1] 的文章《A Race Within A Race: Exploiting CVE-2025-38617 in Linux Packet Sockets》[2],可点
阅读全文注:本文翻译自 Microsoft 的文章《OAuth redirection abuse enables phishing and malware delivery》[1],可点击文末“阅读原文”
阅读全文注:本文翻译自 StepSecurity 的文章《hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Mic
阅读全文开源工具地址:https://github.com/BishopFox/cloudfox注:本文翻译自Bishop Fox的文章《Introducing CloudFox GCP: Attack P
阅读全文注:本文翻译自 Riptides 的文章《Secretless Azure access with tokenex: Federated Identity via User-Assigned Man
阅读全文注:本文翻译自 Red Canary 的文章《ChatGPT in your inbox? Investigating Entra apps that request unexpected perm
阅读全文报名地址:https://app.brazenconnect.com/events/bJK18比赛开始时间:北京时间 2026年3月11日 22:00-23:00注:本文翻译自赛事官网《Captur
阅读全文注:本文翻译自 gitguardian - Tiexin Guo[1] 的文章《Responding to Exposed Secrets - An SRE's Incident Response
阅读全文注:本文翻译自 minimus 的文章《CVE-2026-22039: Kyverno Authorization Bypass - Minimus》[1],可点击文末“阅读原文”按钮查看英文原文。
阅读全文注:本文翻译自 Critical Thinking - Diyan Apostolov 的文章《Azure DevOps Agent Interception》[1],可点击文末“阅读原文”按钮查看
阅读全文注:本文翻译自 ORCA Security 的文章《Path Traversal in Rancher Local Path Provisioner Enables Host Filesystem
阅读全文注:本文翻译自 Omer Amiad[1] 的文章《GatewayToHeaven: Finding a Cross-Tenant Vulnerability in GCP's Apigee》[2]
阅读全文注:本文翻译自 Flare - Assaf Morag 的文章《Threat Alert: TeamPCP, An Emerging Force in the Cloud Native and Ra
阅读全文注:本文翻译自 NOMA Security 的文章《DockerDash: Two Attack Paths, One AI Supply Chain Crisis》[1],可点击文末“阅读原文”按
阅读全文注:本文翻译自Tenable的文章《LookOut: Discovering RCE and Internal Access on Looker (Google Cloud & On-Prem)》[
阅读全文注:本文翻译自Sysdig的文章《AI-assisted cloud intrusion achieves admin access in 8 minutes》[1],可点击文末“阅读原文”按钮查看
阅读全文注:本文翻译自 Kudelski Security - Nils Amiet 的文章《How We Exploited Qodo: From a PR Comment to RCE and an A
阅读全文注:本文翻译自 NVISO Lab - Stamatis Chatzimangou[1] 的文章《ConsentFix (a.k.a. AuthCodeFix): Detecting OAuth2
阅读全文注:本文翻译自 CNCF - Nick Haven, Fairwinds 的文章《Top 28 Kubernetes resources for 2026: Learn and stay up-to
阅读全文注:本文翻译自 Rapid7 的文章《Threat Actors Using AWS WorkMail in Phishing Campaigns》[1],可点击文末“阅读原文”按钮查看英文原文。全
阅读全文注:本文翻译自 GMO Cybersecurity 的文章《Revisiting GPUGate: Repo Squatting and OpenCL Deception to Deliver Hi
阅读全文