On Thursday August 6, Apple shipped an emergency macOS update. It fixed exactly one vulnerability, CVE-2026-65400, in a feature called Screen Sharing. Apple does not ship an update out of band unless ...
Two months ago, we demonstrated the first public bypass of Apple MIE on macOS 26.4.1. We withheld the technical details until Apple shipped fixes, which are now available in macOS 26.6. We'd like to t...
Calif 披露 Windows 11 本地提权漏洞 CVE-2026-50343。攻击者利用 InstallService 注册表键可写及 COM 组件 DLL 路径可控的逻辑缺陷,将恶意 DLL 注入 SYSTEM 进程,获取 NT AUTHORITY\SYSTEM 权限。该利用链无需管理员权限、UAC 同意或重启,且因不破坏内核内存而具有确定性。受影响版本包括 Windows 11 Build 10.0.26200.8457,微软已修复此高危漏洞。
Two weeks ago, we dropped an HTTP/2 bomb cooked up by Codex Cyber. This time, we sent Claude Mythos Preview spelunking through Squid’s guts, and it surfaced clutching a 29-year-old bug. Meet Squidblee...
文章详细披露了通过objdump -g命令执行任意代码的技术细节。作者发现FR30目标文件的重定位处理程序中存在缺失边界检查的漏洞,并构建了一个利用该堆溢出漏洞绕过ASLR、PIE和堆加固措施的完整利用链。该技术被称为“重定位导向编程”(ROP),通过操纵重定位条目实现堆外写入和指针修改,最终利用House of Apple 2技术实现代码执行。
一篇以 AI 第一人称口吻写的极短帖,说主人让它去"找找找漏洞的工具"的漏洞——即用逆向工具 IDA 去挖 IDA 本身的 bug。概念本身有递归趣味,对安全社区有一定吸引力。但正文只有两句话,没有任何实际漏洞信息、分析过程或发现结果,纯属开篇钩子,内容厚度几乎为零。适合作为社交动态看个乐子,不具备推荐阅读的信息价值。