unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
SentinelOne + Claude: Integrations for AI Visibility, Governance, and Defense
Enterprise adoption of Claude across teams, workflows, and business functions is happening...
2026-6-2 19:59:49 | 阅读: 16 |
收藏
|
SentinelOne - www.sentinelone.com
security
frontier
claude
anthropic
singularity
LABScon25 Replay | Gamaredon x Turla: Unveiling a 2025 Espionage Alliance Targeting Ukraine
In this LABScon 25 presentation, ESET researchers Matthieu Faou and Zoltán Rusnák present...
2026-6-2 13:0:58 | 阅读: 21 |
收藏
|
SentinelLabs - www.sentinelone.com
labscon
turla
gamaredon
zoltán
matthieu
The Good, the Bad and the Ugly in Cybersecurity – Week 22
The Good | Authorities Dismantle Malicious Hosting Network & Sentence Oregon State Cyberat...
2026-5-29 14:38:21 | 阅读: 18 |
收藏
|
SentinelOne - www.sentinelone.com
trapdoor
attackers
malicious
security
oregon
The Good, the Bad and the Ugly in Cybersecurity – Week 21
The Good | Joint Operations Dismantle Cybercrime Infrastructure, Infostealers & Malicious...
2026-5-22 15:8:13 | 阅读: 22 |
收藏
|
SentinelOne - www.sentinelone.com
microsoft
defender
2026
security
exploited
Sentinels League 2026: Live Rankings for the Threat Hunting World Championship
The Threat Hunting World Championship is back — bigger, bolder, and with more on the line...
2026-5-20 13:0:44 | 阅读: 7 |
收藏
|
SentinelOne - www.sentinelone.com
league
sentinels
regional
standings
Sentinels League 2026: Live Rankings for the Threat Hunting World Championship
The Threat Hunting World Championship is back — bigger, bolding, and with more on the line...
2026-5-20 13:0:44 | 阅读: 29 |
收藏
|
SentinelOne - www.sentinelone.com
league
sentinels
regional
grand
Turn Blind Trust into Verified Control with Prompt Security for Agentic AI
Agentic AI is no longer theoretical. It’s already embedded across enterprises inside devel...
2026-5-19 13:43:37 | 阅读: 25 |
收藏
|
SentinelOne - www.sentinelone.com
agents
security
agentic
mcp
enforce
SHub Reaper | macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain
Infostealers targeting macOS have continued to proliferate over the last two years, with t...
2026-5-18 13:0:42 | 阅读: 33 |
收藏
|
SentinelOne - www.sentinelone.com
reaper
shub
applescript
c2
malicious
Breaking the Black Box: A Case Study in Red-Teaming a Government Education AI
The “black box” assessment represents the most authentic test of an AI system’s security....
2026-5-18 12:0:37 | 阅读: 28 |
收藏
|
SentinelOne - www.sentinelone.com
semantic
malicious
persona
developer
rude
Living Off the Pipeline: Defending Against CI/CD Subversion
The software supply chain has become one of the most attractive targets for modern adversa...
2026-5-15 13:0:53 | 阅读: 14 |
收藏
|
SentinelOne - www.sentinelone.com
attackers
malicious
runners
software
workflows
The Good, the Bad and the Ugly in Cybersecurity – Week 20
The Good | Authorities Dismantle Major Dark Web Marketplaces & Arrest Key AdminsEuropean...
2026-5-15 13:0:14 | 阅读: 24 |
收藏
|
SentinelOne - www.sentinelone.com
instructure
authorities
coordinated
german
LABScon25 Replay | Breach Alpha: Trading on Cyber Fallout
When a company suffers a cyber breach, its stock price often takes a hit, but the timing,...
2026-5-14 13:0:44 | 阅读: 29 |
收藏
|
SentinelLabs - www.sentinelone.com
labscon
security
speakers
mick
baccio
The Convergence of Cloud Secrets & AI Risk
In 2025, the enterprise risk landscape experienced a paradigm shift: the adoption of AI an...
2026-5-13 18:11:51 | 阅读: 35 |
收藏
|
SentinelOne - www.sentinelone.com
cloud
security
exposure
attackers
The Good, the Bad and the Ugly in Cybersecurity – Week 19
The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Faci...
2026-5-8 13:0:14 | 阅读: 46 |
收藏
|
SentinelOne - www.sentinelone.com
cloud
remote
zolotarjovs
karakurt
PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale
Executive SummarySentinelLABS has identified PCPJack, a credential theft framework that...
2026-5-7 10:0:17 | 阅读: 42 |
收藏
|
SentinelLabs - www.sentinelone.com
cloud
attacker
pcpjack
teampcp
lateral
LABScon25 Replay | Please Connect to the Foreign Entity to Enhance Your User Experience
In this LABScon 25 presentation, Joe FitzPatrick explores how networked devices manufactu...
2026-5-6 13:0:29 | 阅读: 33 |
收藏
|
SentinelLabs - www.sentinelone.com
labscon
hardware
joe
security
2026
The Good, the Bad and the Ugly in Cybersecurity – Week 18
The Good | Authorities Dismantle State-Backed Espionage & Cybercrime RingsThis week, auth...
2026-5-1 13:0:13 | 阅读: 34 |
收藏
|
SentinelOne - www.sentinelone.com
malicious
ftc
authorities
github
criminal
The Good, the Bad and the Ugly in Cybersecurity – Week 17
好,我现在需要帮用户总结这篇文章的内容,控制在100字以内。首先,我得仔细阅读文章,理解各个部分的主要内容。 文章分为三个部分:The Good, The Bad, 和The Ugly。在The Good部分,主要讲述了两个网络犯罪头目的审判情况。Tyler Robert Buchanan和Angelo Martino分别涉及诈骗、身份盗窃和勒索,他们被定罪并面临长期监禁。接着,在The Bad部分,英国的网络安全中心警告中国相关的威胁行为者正在扩大僵尸网络来隐藏网络攻击。他们利用劫持的消费设备来掩盖攻击来源,这让追踪变得困难。最后,在The Ugly部分,SentinelLABS发现了一个名为fast16的网络破坏框架,这个框架可以追溯到2005年,比Stuxnet还要早五年。它被用来干扰科学和工程计算,可能影响了多个领域的重要研究。 现在我要把这些内容浓缩到100字以内。首先,提到两个犯罪头目的审判和他们的罪行。然后简要说明中国相关的威胁行为者利用僵尸网络隐藏攻击。最后提到发现了一个早期的网络破坏框架及其影响。 确保语言简洁明了,不使用复杂的术语,并且直接描述文章内容。 </think> 文章报道了两名网络犯罪头目因诈骗、身份盗窃和勒索获刑;中国关联威胁行为者利用僵尸网络隐藏攻击;以及发现了一个早期的网络破坏框架fast16,其影响深远。...
2026-4-24 15:48:28 | 阅读: 41 |
收藏
|
SentinelOne - www.sentinelone.com
fast16
sabotage
buchanan
network
fast16 | Mystery ShadowBrokers Reference Reveals High-Precision Software Sabotage 5 Years Before Stuxnet
嗯,用户让我总结一下这篇文章的内容,控制在100个字以内,而且不需要用“文章内容总结”或者“这篇文章”这样的开头。直接写描述就行。 首先,我需要通读整篇文章,抓住主要信息。文章讲的是SentinelLABS发现了一个以前未被记录的网络破坏框架,叫做fast16。这个框架的核心组件可以追溯到2005年。它通过篡改高精度计算软件的结果来进行破坏活动。 接下来,fast16.sys这个驱动程序会拦截和修改从磁盘读取的可执行代码,特别是针对使用Intel编译器的软件。它的目标包括LS-DYNA、PKPM和MOHID这些高精度计算软件,这些软件常用于物理模拟、工程设计等领域。 文章还提到,fast16比Stuxnet早了至少五年,并且使用了定制的Lua虚拟机,这比Flame样本还要早三年。此外,fast16在ShadowBrokers泄露中被提及过。 最后,总结的时候需要涵盖fast16的功能、目标以及它的重要性。要确保在100字以内简洁明了地表达出来。 </think> SentinelLABS发现了一个2005年开发的网络破坏框架fast16.sys,该框架通过篡改高精度计算软件的结果进行破坏活动。它针对特定编译器生成的可执行文件,在内存中注入代码以改变计算结果,并传播至整个设施。该框架比Stuxnet早五年,并利用定制Lua虚拟机实现模块化功能。...
2026-4-23 22:0:45 | 阅读: 34 |
收藏
|
SentinelLabs - www.sentinelone.com
c6
software
fast16
8d
windows
LABScon25 Replay | Are Your Chinese Cameras Spying For You Or On You?
嗯,用户让我帮忙总结一下这篇文章的内容,控制在一百个字以内。首先,我需要通读文章,抓住主要信息。 文章主要讲的是两位研究人员Marc Rogers和Silas Cutler在LABScon 25上的演讲,他们探讨了超便宜的中国智能家庭设备的供应链问题。特别是视频门铃和安全摄像头,这些设备在主流电商平台以不同的品牌销售。 他们发现这些设备使用相同的硬件平台,由Allwinner半导体驱动,这家公司得到了中国政府的大量补贴。固件分析显示有硬编码的root密码,安全补丁其实只是注释掉易受攻击的服务,并没有真正移除它们。 此外,这些设备虽然看起来使用本地云服务,但数据经常被路由到香港和中国的服务器。研究人员还追踪到一系列空壳公司和虚构的人格,这些实体通过非响应的注册代理和PO箱来逃避法律服务,保护实际制造商不受监管。 硬件版本快速迭代且缺乏长期支持,这与恶意软件分发模式相似。虽然没有直接归咎于恶意行为,但研究人员认为这些设备形成了一个巨大的、易受攻击的物联网表面,可以通过海外配置控制。消费者被低价吸引,却不知道他们的数据最终受外国控制。 总结时要抓住关键点:供应链问题、安全漏洞、数据流向、空壳公司、快速迭代以及消费者风险。控制在100字以内,用简洁的语言表达出来。 </think> 两位研究人员揭示了中国超低价智能家庭设备(如视频门铃和摄像头)背后的复杂供应链问题。这些设备共享相同硬件平台,存在严重安全漏洞(如硬编码密码),数据常流向中国服务器。制造商通过空壳公司和虚构身份规避监管。快速迭代硬件版本与恶意软件分发模式相似。消费者因低价吸引而忽视数据安全风险。...
2026-4-22 22:0:15 | 阅读: 29 |
收藏
|
SentinelLabs - www.sentinelone.com
labscon
security
cutler
rogers
marc
Previous
-10
-9
-8
-7
-6
-5
-4
-3
Next