Tagged articles

information security

1056 articles · Page 5 of 11
Architects' Tech Alliance
Architects' Tech Alliance
Nov 9, 2023 · Fundamentals

China Xinchuang (Information Technology Innovation) Industry Report 2023: Development History, Market Size, and Investment Opportunities

The 2023 China Xinchuang industry report analyzes the sector's evolution, policy environment, market scale, value chain, cost structure, and investment opportunities across hardware, operating systems, middleware, databases, cloud computing, and information security, highlighting a projected market size of 8 trillion CNY by 2025.

ChinaIT industryXinchuang
0 likes · 20 min read
China Xinchuang (Information Technology Innovation) Industry Report 2023: Development History, Market Size, and Investment Opportunities
AntTech
AntTech
Nov 4, 2023 · Information Security

Native Security Paradigm and Parallel Security Aspects for Enterprise Digital Transformation

The whitepaper examines how exploding complexity in digitally transformed enterprises demands a native security paradigm and parallel security aspects that embed distributed, real‑time, and tool‑driven protection into system design, enabling high integration and low coupling between security and business functions.

digital transformationenterpriseinformation security
0 likes · 11 min read
Native Security Paradigm and Parallel Security Aspects for Enterprise Digital Transformation
Architects Research Society
Architects Research Society
Nov 1, 2023 · Information Security

Roles and Responsibilities of a Security Architecture Team

The article outlines the composition and responsibilities of a security architecture team, detailing the roles of Security Architect, Information Security Architect, CISO, and Security Analyst, their required business and technical skills, risk management, threat modeling, and how they integrate with enterprise architecture.

CISOSecurity RolesThreat modeling
0 likes · 11 min read
Roles and Responsibilities of a Security Architecture Team
Data Thinking Notes
Data Thinking Notes
Oct 31, 2023 · Information Security

Why Data Classification & Grading Is Critical for Enterprise Security

This article explains the legal and strategic importance of data classification and grading in China, outlines the relevant regulations, describes the principles and processes for implementing classification, and offers practical steps for enterprises to secure data while meeting compliance and business needs.

Data GovernanceEnterprise Compliancedata classification
0 likes · 11 min read
Why Data Classification & Grading Is Critical for Enterprise Security
Laravel Tech Community
Laravel Tech Community
Oct 29, 2023 · Information Security

Remote Code Execution Vulnerability in Apache ActiveMQ < 5.18.3 (Deserialization)

Apache ActiveMQ versions prior to 5.18.3 are vulnerable to a deserialization flaw that allows remote code execution via crafted OpenWire messages on port 61616, affecting various activemq-client and activemq-openwire-legacy artifacts, and can be mitigated by upgrading to 5.15.16, 5.16.7, 5.17.6, 5.18.3 or later.

Apache ActiveMQDeserializationMessaging Middleware
0 likes · 3 min read
Remote Code Execution Vulnerability in Apache ActiveMQ < 5.18.3 (Deserialization)
php Courses
php Courses
Oct 24, 2023 · Information Security

Using PHP Encryption Functions for Data Protection

This article explains PHP's built‑in encryption functions—including OpenSSL encryption/decryption, hashing, and password handling—shows how to generate keys, encrypt and decrypt data, and provides best‑practice tips for securely protecting sensitive information in PHP applications.

OpenSSLdata protectionencryption
0 likes · 5 min read
Using PHP Encryption Functions for Data Protection
AntTech
AntTech
Oct 20, 2023 · Information Security

Digital Accessible Online Movie Service for the Visually Impaired: Privacy Computing, Blockchain, and Secure Identity Verification

The article describes how Ant Group and partners created an accessible online movie platform for visually impaired users in China, employing innovative privacy‑computing, blockchain, and terminal‑security technologies to enable secure, minimal‑disclosure identity verification and protect intellectual‑property rights.

Identity verificationaccessible mediadigital accessibility
0 likes · 6 min read
Digital Accessible Online Movie Service for the Visually Impaired: Privacy Computing, Blockchain, and Secure Identity Verification
Java Architect Essentials
Java Architect Essentials
Oct 13, 2023 · Information Security

Understanding JWT Claims and Token Renewal Strategies

This article explains the structure of JWT payloads, enumerates standard and custom claims, demonstrates how to generate tokens with expiration using Java code, and compares single‑token and double‑token renewal schemes—including Redis storage and WeChat OAuth2.0 examples—to help developers manage authentication securely.

Token Refreshbackend developmentinformation security
0 likes · 7 min read
Understanding JWT Claims and Token Renewal Strategies
MaGe Linux Operations
MaGe Linux Operations
Oct 12, 2023 · Information Security

How to Detect and Bypass CDN to Reveal a Website’s Real IP

This guide explains why CDNs hide a site's true IP, how to determine if a website uses a CDN, and outlines practical techniques—including DNS queries, online tools, sub‑domain analysis, email reverse lookup, and scanning scripts—to bypass the CDN and discover the real server address.

CDNIP discoveryNetwork reconnaissance
0 likes · 8 min read
How to Detect and Bypass CDN to Reveal a Website’s Real IP
Open Source Linux
Open Source Linux
Sep 27, 2023 · Information Security

How Companies Spy on Your WeChat Chats and How to Defend Your Privacy

Despite modern privacy expectations, many companies in 2023 still monitor employees' chat records using root‑level management software and network interception, exposing personal WeChat conversations; this article explains the surveillance methods, real‑world examples, and practical steps employees can take to protect their privacy.

WeChatcompany policiesdesktop surveillance
0 likes · 5 min read
How Companies Spy on Your WeChat Chats and How to Defend Your Privacy
Data Thinking Notes
Data Thinking Notes
Sep 24, 2023 · Information Security

How to Build a Robust Data Security Governance Framework: Steps & Best Practices

Data security governance, essential for modern enterprises, involves classifying and authorizing data, implementing scenario-based protections, and establishing comprehensive frameworks that address compliance, asset management, process control, and continuous improvement, guiding organizations through strategic planning, organizational structuring, policy creation, and ongoing operational monitoring.

compliancedata securityframework
0 likes · 15 min read
How to Build a Robust Data Security Governance Framework: Steps & Best Practices
MaGe Linux Operations
MaGe Linux Operations
Sep 12, 2023 · Information Security

Mastering Container Vulnerability Management: Secure DevOps Strategies

This article explains how containers work, outlines the challenges of detecting and fixing vulnerabilities throughout the software lifecycle, and presents practical strategies—including CI/CD pipeline, registry, runtime, and host scanning—plus key principles for building a robust container security program.

CI/CDDevOpsVulnerability Management
0 likes · 7 min read
Mastering Container Vulnerability Management: Secure DevOps Strategies
AntTech
AntTech
Sep 12, 2023 · Artificial Intelligence

Ensuring Trustworthy and Secure AI: Insights from the 2023 Pujiang Innovation Forum

The 2023 Pujiang Innovation Forum highlighted the rapid rise of generative AI, its associated security and privacy risks, and presented Ant Group's multi‑stage, multi‑layered approach—including data, training, and inference controls and three core defense technologies—to achieve safe, reliable, and open knowledge sharing in the era of large language models.

Large Language Modelsinformation securityknowledge sharing
0 likes · 10 min read
Ensuring Trustworthy and Secure AI: Insights from the 2023 Pujiang Innovation Forum
IT Services Circle
IT Services Circle
Sep 8, 2023 · Information Security

High‑Severity Vulnerabilities Discovered in Notepad++ (CVE‑2023‑40031, CVE‑2023‑40036, CVE‑2023‑40164, CVE‑2023‑40166)

Security researchers have identified four high‑severity buffer‑overflow vulnerabilities (CVE‑2023‑40031, CVE‑2023‑40036, CVE‑2023‑40164, CVE‑2023‑40166) in the popular open‑source editor Notepad++, disclosed after the developers failed to patch them before the release of version 8.5.6, urging users to apply mitigations.

CVENotepadOpen Source
0 likes · 3 min read
High‑Severity Vulnerabilities Discovered in Notepad++ (CVE‑2023‑40031, CVE‑2023‑40036, CVE‑2023‑40164, CVE‑2023‑40166)
Architect
Architect
Sep 4, 2023 · Information Security

Design and Implementation of a Unified Permission Management Service (MPS)

This article details the design and development of a unified permission management service (MPS) that consolidates RBAC, ACL, and DAC models to solve fragmented enterprise permission issues, covering requirement analysis, technical selection, functional modules, deployment, and performance outcomes.

ACLDACGo
0 likes · 16 min read
Design and Implementation of a Unified Permission Management Service (MPS)
MaGe Linux Operations
MaGe Linux Operations
Aug 17, 2023 · Information Security

Explore siusiu: A Docker‑Powered Penetration Testing Toolbox

siusiu is a Docker‑based penetration testing toolbox that bundles dozens of security utilities as Docker images, offering an easy‑to‑use console, multiple installation methods, and a rich command set for both interactive and scripted security assessments.

DevOpsDockerPenetration Testing
0 likes · 6 min read
Explore siusiu: A Docker‑Powered Penetration Testing Toolbox
21CTO
21CTO
Aug 15, 2023 · Information Security

Can Your Keyboard’s Sound Leak Your Password? AI‑Powered Acoustic Eavesdropping

A recent UK study demonstrates that a deep‑learning model can analyze audio recordings of keystrokes—captured via microphones or video‑call platforms like Zoom—to infer typed characters with up to 95 % accuracy, highlighting a serious acoustic side‑channel threat to passwords and other sensitive information.

acoustic side-channelaudio eavesdroppinginformation security
0 likes · 4 min read
Can Your Keyboard’s Sound Leak Your Password? AI‑Powered Acoustic Eavesdropping
AntTech
AntTech
Aug 15, 2023 · Information Security

VILLAIN: Backdoor Attacks Against Vertical Split Learning Presented at USENIX Security 2023

The paper "VILLAIN: Backdoor Attacks Against Vertical Split Learning" introduced at USENIX Security 2023 proposes a novel framework that enables label‑free attackers to infer data labels and inject backdoors into vertically partitioned federated learning models, highlighting new security challenges and defense considerations for collaborative AI systems.

USENIX Securitybackdoor attackfederated learning
0 likes · 4 min read
VILLAIN: Backdoor Attacks Against Vertical Split Learning Presented at USENIX Security 2023
Huolala Tech
Huolala Tech
Aug 15, 2023 · Information Security

How Modern Security Risk Assessment Evolved: Key Features and Practical Insights

This article examines the expanded scope, updated standards, and practical workflow of security risk assessment in today's regulatory environment, offering detailed guidance on assessment criteria, target objects, methodologies, organizational steps, and decision‑making for effective risk management.

compliancedata protectioninformation security
0 likes · 9 min read
How Modern Security Risk Assessment Evolved: Key Features and Practical Insights
MaGe Linux Operations
MaGe Linux Operations
Jul 28, 2023 · Information Security

What Made Wireshark Thrive for 25 Years? Key Lessons from Its History

Celebrating Wireshark's 25‑year journey, this article recounts its origin as Ethereal, the community‑driven growth, pivotal milestones, and the essential support structures that turned a simple open‑source packet analyzer into a cornerstone tool for network reliability, education, and security worldwide.

Wiresharkinformation securitynetwork analysis
0 likes · 5 min read
What Made Wireshark Thrive for 25 Years? Key Lessons from Its History
AntTech
AntTech
Jul 26, 2023 · Information Security

Ant Group and Nanyang Technological University Launch Collaboration on Private Set Intersection Privacy Computing

On July 25, Ant Group and Singapore's Nanyang Technological University announced a research partnership to advance Private Set Intersection (PSI) privacy‑computing technology using Ant's YinYu framework, aiming to improve secure machine‑learning and data‑analysis applications while aligning with regional data‑privacy initiatives.

information securityntuprivacy computing
0 likes · 4 min read
Ant Group and Nanyang Technological University Launch Collaboration on Private Set Intersection Privacy Computing
Alibaba Cloud Developer
Alibaba Cloud Developer
Jul 21, 2023 · Information Security

Mastering Systematic Problem Solving for Complex Security Challenges

This article explores how to systematically tackle complex security problems by defining system thinking, distinguishing simple from complex issues, and applying a comprehensive, deep, and dynamic approach illustrated with a data‑leakage case study and practical recommendations for future security strategy.

Case studycomplex problemsinformation security
0 likes · 16 min read
Mastering Systematic Problem Solving for Complex Security Challenges
21CTO
21CTO
Jul 20, 2023 · Information Security

Kevin Mitnick: From World’s Most Wanted Hacker to Security Guru

Kevin Mitnick, once dubbed the world’s most famous hacker and the first to be pursued by the FBI, transformed from a teenage social‑engineering prodigy into a celebrated information‑security consultant, author, and founder of Mitnick Security, leaving a lasting impact on computer security after his 2023 death.

Computer securityKevin MitnickPenetration Testing
0 likes · 5 min read
Kevin Mitnick: From World’s Most Wanted Hacker to Security Guru
Efficient Ops
Efficient Ops
Jul 19, 2023 · Information Security

How Shenwan Hongyuan Achieved National‑Level DevSecOps Excellence

Shenwan Hongyuan Securities showcased its advanced DevSecOps capabilities by passing the CAICT's DevSecOps security and risk management assessment and DevOps continuous delivery level‑3 evaluation, sharing detailed cultural, process, and technical practices that boost software security across the full lifecycle.

Continuous DeliveryDevOpsDevSecOps
0 likes · 12 min read
How Shenwan Hongyuan Achieved National‑Level DevSecOps Excellence
IT Services Circle
IT Services Circle
Jul 13, 2023 · Information Security

Manual Mitigation Steps for BlackLotus UEFI Bootkit (CVE‑2023‑24932) and Microsoft’s Three‑Phase Update Strategy

This article explains the BlackLotus UEFI bootkit (CVE‑2023‑24932), outlines Microsoft's three‑phase remediation strategy, details the KB5025885 and KB5028166/KB5028185 updates, provides a simplified registry command for manual activation, and warns of compatibility issues for legacy boot managers.

CVE-2023-24932Secure BootUEFI
0 likes · 6 min read
Manual Mitigation Steps for BlackLotus UEFI Bootkit (CVE‑2023‑24932) and Microsoft’s Three‑Phase Update Strategy
MaGe Linux Operations
MaGe Linux Operations
Jul 9, 2023 · Information Security

Master Internal Network Tunneling: NPS, FRP, EW, and NGROK Explained

This guide introduces several popular internal network tunneling tools—including NPS/NPC, FRP, EW, and NGROK—explaining their core principles, key features, installation steps, configuration files, and practical usage scenarios such as RDP, SSH, web services, file sharing, and advanced options like encryption, compression, TLS, and bandwidth limiting.

FRPInternal toolsNPS
0 likes · 16 min read
Master Internal Network Tunneling: NPS, FRP, EW, and NGROK Explained
Liangxu Linux
Liangxu Linux
Jul 9, 2023 · Information Security

Mastering tcpdump: Essential Commands and Real‑World Examples for Network Analysis

This guide explains how to use tcpdump (and its predecessor ethereal) for capturing and analyzing network traffic, describes key command‑line options, and provides dozens of practical examples ranging from basic packet dumps to complex filtered captures and related networking utilities.

Linuxinformation securitynetwork monitoring
0 likes · 17 min read
Mastering tcpdump: Essential Commands and Real‑World Examples for Network Analysis
php Courses
php Courses
Jul 6, 2023 · Information Security

Anonymous Sudan Claims to Have Stolen Microsoft Customer Database; Microsoft Denies the Allegations

Anonymous Sudan alleges it has breached Microsoft’s servers and obtained a database containing over 30 million customer credentials, while Microsoft firmly denies any such breach, prompting widespread debate over the hacker group’s capabilities, motives, and the broader implications for information security.

Anonymous SudanMicrosoftcyberattack
0 likes · 4 min read
Anonymous Sudan Claims to Have Stolen Microsoft Customer Database; Microsoft Denies the Allegations
php Courses
php Courses
Jul 3, 2023 · Information Security

June API Security Vulnerability Report: MinIO, Joomla Rest API, and Argo CD Issues with Remediation Guidance

The June API security report highlights three critical vulnerabilities—MinIO unauthorized data exposure, Joomla Rest API unauthenticated access, and multiple Argo CD API flaws—detailing their impacts and providing concrete remediation steps to protect sensitive data and maintain system integrity.

API securityArgo CDJoomla
0 likes · 4 min read
June API Security Vulnerability Report: MinIO, Joomla Rest API, and Argo CD Issues with Remediation Guidance
Efficient Ops
Efficient Ops
Jun 24, 2023 · Information Security

How ICBC Built a DevSecOps Security Framework to Accelerate Safe Software Delivery

This article explains how ICBC's software development center integrated DevSecOps practices—embedding security awareness, automating toolchains, and using metric‑driven assessments—to reduce vulnerabilities, lower compliance risk, and support a cloud‑native, secure smart‑banking ecosystem.

DevSecOpsinformation securitysecurity automation
0 likes · 8 min read
How ICBC Built a DevSecOps Security Framework to Accelerate Safe Software Delivery
Alibaba Cloud Infrastructure
Alibaba Cloud Infrastructure
Jun 22, 2023 · Information Security

Cloud DNS: Challenges, Security Risks, and Future Directions Discussed at the Alibaba Cloud & Tsinghua University Forum

The forum highlighted the growing importance of DNS in cloud-era digital transformation, presented security challenges of cloud‑based DNS load balancing, and outlined research findings and future "DNS+" strategies to ensure stable, scalable, and secure internet naming services.

DNSdigital transformationinformation security
0 likes · 7 min read
Cloud DNS: Challenges, Security Risks, and Future Directions Discussed at the Alibaba Cloud & Tsinghua University Forum
HomeTech
HomeTech
Jun 21, 2023 · Information Security

Transparent Data Masking with AutoProxy Middleware at AutoHome

This article describes AutoHome's data security challenges in the big‑data era and explains how the self‑developed AutoProxy encryption middleware provides transparent, compliant data masking across legacy and new sensitive data, reducing cost, improving performance, and enabling automated masking workflows.

MiddlewareTransparent Encryptionauto-proxy
0 likes · 8 min read
Transparent Data Masking with AutoProxy Middleware at AutoHome
Liangxu Linux
Liangxu Linux
Jun 20, 2023 · Information Security

How AI Hallucinations Fuel Fake NPM Package Attacks and What You Can Do

The article explains how ChatGPT's hallucinations can generate non‑existent package links that attackers register and weaponize, demonstrates the attack with a fake Node.js npm package, and offers practical steps to detect and prevent such supply‑chain threats.

AI securityChatGPT hallucinationfake npm packages
0 likes · 5 min read
How AI Hallucinations Fuel Fake NPM Package Attacks and What You Can Do
IT Services Circle
IT Services Circle
Jun 15, 2023 · Information Security

Microsoft Edge Image Super-Resolution Feature Raises Privacy Concerns and How to Disable It

Microsoft Edge's newly enabled image super‑resolution feature automatically enhances picture clarity but sends image URLs to Microsoft servers, prompting privacy concerns; the article explains the feature, its local processing claim, and provides step‑by‑step instructions to disable it in both stable and Canary builds.

Browser SettingsMicrosoft Edgeimage super-resolution
0 likes · 3 min read
Microsoft Edge Image Super-Resolution Feature Raises Privacy Concerns and How to Disable It
ITPUB
ITPUB
Jun 12, 2023 · Information Security

Inside Microsoft’s May 2023 Patch: Win32k Exploit Details and Visual Studio Vulnerability

Microsoft’s May 2023 security update addressed 52 CVEs, including a critical Win32k privilege‑escalation flaw (CVE‑2023‑29336) exploited in the wild and a Visual Studio installer UI vulnerability (CVE‑2023‑28299), with researchers detailing the attack vectors, proof‑of‑concept exploits, and mitigation strategies.

CVE-2023-29336MicrosoftVisual Studio
0 likes · 6 min read
Inside Microsoft’s May 2023 Patch: Win32k Exploit Details and Visual Studio Vulnerability
Architects Research Society
Architects Research Society
Jun 10, 2023 · Information Security

Roles and Responsibilities of a Security Architecture Team

The article outlines the composition of a security architecture team, detailing the roles of security architect, information security architect, chief information security officer, and security analyst, along with their business and technical skills, organizational relationships, and key responsibilities in managing enterprise security.

CISOSecurity Analystinformation security
0 likes · 13 min read
Roles and Responsibilities of a Security Architecture Team
ITPUB
ITPUB
Jun 9, 2023 · Information Security

The 70 Largest Data Breaches in History: Impact, Details, and Lessons Learned

This comprehensive list chronicles the 70 biggest data breach incidents ever recorded, detailing dates, affected records, compromised data types, and the security failures that exposed personal information for companies ranging from social networks to financial institutions.

cybersecuritydata breachinformation security
0 likes · 43 min read
The 70 Largest Data Breaches in History: Impact, Details, and Lessons Learned
OPPO Amber Lab
OPPO Amber Lab
Jun 5, 2023 · Information Security

How ChatGPT Impacts Security: Key Insights from the CSA Seminar

An online CSA seminar on May 30 examined ChatGPT’s security impact, presenting a whitepaper and four AI‑security interaction dimensions, while experts discussed telecom‑operator security‑GPT models, safe vertical‑domain large‑model training, and future industry implications.

AI governanceAI securityChatGPT
0 likes · 7 min read
How ChatGPT Impacts Security: Key Insights from the CSA Seminar
Ziru Technology
Ziru Technology
Jun 2, 2023 · Information Security

Mastering Data Classification & Grading: Ziroom’s Compliance Blueprint

This article explains how Ziroom implements a comprehensive data classification and grading system to meet the 2021 Data Security Law, improve risk management, optimize security resources, and boost user trust through automated tools, multi‑level categorization, and continuous manual verification.

Data Governancecompliancedata classification
0 likes · 12 min read
Mastering Data Classification & Grading: Ziroom’s Compliance Blueprint
Java Architect Essentials
Java Architect Essentials
May 26, 2023 · Information Security

Step‑by‑Step WordPress Site Penetration Testing Tutorial

This tutorial walks beginners through the entire process of compromising a WordPress website, from initial information gathering and DNS enumeration to vulnerability scanning, exploitation with tools like sqlmap and nmap, privilege escalation, and establishing persistent backdoors.

NmapPenetration TestingSQLMap
0 likes · 10 min read
Step‑by‑Step WordPress Site Penetration Testing Tutorial
Python Programming Learning Circle
Python Programming Learning Circle
May 25, 2023 · Artificial Intelligence

AI Deepfake Scams: How Synthetic Faces and Voices Enable Fraud and What to Watch For

AI-powered deepfake technology is increasingly being exploited for sophisticated scams, as illustrated by a case where a company executive transferred 4.3 million yuan to a fraudster using a fabricated video call, prompting urgent warnings about the need for verification, emerging regulations, and the broader misuse of face‑swap tools.

AI deepfakeRegulationdeepfake tools
0 likes · 5 min read
AI Deepfake Scams: How Synthetic Faces and Voices Enable Fraud and What to Watch For
Data Thinking Notes
Data Thinking Notes
May 21, 2023 · Information Security

Why Government Data Sharing Stalls and How a “Three‑Rights” Model Can Unlock It

The article analyzes why government data sharing often fails—citing legal, technical, security, and organizational hurdles—then outlines one‑to‑one and centralized sharing models, highlights four critical success factors, and proposes a “three‑rights” framework supported by blockchain to create trustworthy, sustainable inter‑departmental data exchange.

Big DataBlockchainData Governance
0 likes · 11 min read
Why Government Data Sharing Stalls and How a “Three‑Rights” Model Can Unlock It
MaGe Linux Operations
MaGe Linux Operations
May 21, 2023 · Information Security

Step‑by‑Step Webshell Upload and Kernel Privilege Escalation on Ubuntu 16.04

This tutorial walks through setting up an Ubuntu 16.04 vulnerable environment, gathering information, uploading a webshell via MySQL into outfile or log injection, establishing a reverse shell with Metasploit, and finally exploiting CVE‑2021‑4034 for kernel privilege escalation, while also covering post‑exploitation persistence techniques.

KaliLinuxMetasploit
0 likes · 10 min read
Step‑by‑Step Webshell Upload and Kernel Privilege Escalation on Ubuntu 16.04
AntTech
AntTech
May 12, 2023 · Information Security

Exploring a Composite Data Security Governance System: Practices from Ant Group at the 6th Digital China Summit

At the 6th Digital China Construction Summit in Fuzhou, Ant Group’s Song Zheng presented a comprehensive data security governance framework that integrates strategy, management, and technology, outlining four key characteristics—strategic positioning, combat‑driven implementation, full‑staff participation, and technological breakthrough—to guide industry practice.

data securitydigital Chinainformation security
0 likes · 3 min read
Exploring a Composite Data Security Governance System: Practices from Ant Group at the 6th Digital China Summit
vivo Internet Technology
vivo Internet Technology
May 10, 2023 · Information Security

Detecting Apache Commons Text RCE (CVE-2022-42889) with the Doop Static Analysis Framework

The Vivo Internet Security Team demonstrates how to extend the Doop static analysis framework with custom Datalog rules to detect the Apache Commons Text CVE‑2022‑42889 remote code execution vulnerability by tracing taint from StringSubstitutor.replace to ScriptEngine.eval, producing source‑sink CSV reports and showcasing Doop’s extensibility for security research.

Apache Commons TextCVE-2022-42889Datalog
0 likes · 14 min read
Detecting Apache Commons Text RCE (CVE-2022-42889) with the Doop Static Analysis Framework
AntTech
AntTech
May 9, 2023 · Information Security

Ant Group’s Biometric Security Testing Lab: Automated Detection and Evaluation of Fingerprint and Face Recognition Systems

The article details Ant Group’s Ant Security Tianji Lab’s end‑to‑end biometric security testing framework, covering standards, automated 1.0‑2.0‑3.0 detection stages, fingerprint and face‑recognition attack materials, intelligent AI‑driven countermeasures, and a 24/7 robotic testing infrastructure.

AI testingbiometric securityface recognition
0 likes · 25 min read
Ant Group’s Biometric Security Testing Lab: Automated Detection and Evaluation of Fingerprint and Face Recognition Systems
Liangxu Linux
Liangxu Linux
May 2, 2023 · Information Security

Kali Linux vs Parrot OS: Which Penetration Testing Distro Is Right for You?

An in‑depth comparison of Kali Linux and Parrot OS examines their origins, pre‑installed security tools, customization options, hardware requirements, user interfaces, and performance, helping security professionals and enthusiasts choose the most suitable Linux distribution for penetration testing and privacy‑focused work.

Kali LinuxLinux DistributionParrot OS
0 likes · 10 min read
Kali Linux vs Parrot OS: Which Penetration Testing Distro Is Right for You?
iQIYI Technical Product Team
iQIYI Technical Product Team
Apr 28, 2023 · Information Security

Definition, Role, and Implementation of DRM (Digital Rights Management) – iQIYI Case Study

DRM safeguards digital content by authenticating users and encrypting streams, a necessity highlighted by iQIYI’s shift from free distribution to paid membership, prompting a dual‑layer architecture that combines hardware‑based Trusted Execution Environment protection with flexible software SDKs, continuously assessed and evolving to balance security, cost, and user experience.

Content ProtectionDRMDigital Rights Management
0 likes · 9 min read
Definition, Role, and Implementation of DRM (Digital Rights Management) – iQIYI Case Study
JD Tech
JD Tech
Apr 26, 2023 · Information Security

Overview of JD.com's Five‑Element Zero Trust Security Framework

This whitepaper outlines JD.com's practical zero‑trust security approach, detailing a five‑element framework that includes asset digitization, asset identity, diversified security checkpoints, a strategy center, and a zero‑trust cockpit, to help digital enterprises strengthen security, reduce costs, and meet regulatory requirements.

JD.comdigital transformationinformation security
0 likes · 6 min read
Overview of JD.com's Five‑Element Zero Trust Security Framework
Bilibili Tech
Bilibili Tech
Apr 18, 2023 · Cloud Native

Kubernetes Audit Log Analysis for Container Security

The article explains how to enable Kubernetes audit logging and use its detailed fields—such as userAgent, responseStatus, requestURI, and object references—to detect CDK‑generated attacks and other threats like CVE‑2022‑3172, privilege escalation, and backdoor deployment, offering practical detection examples and security recommendations.

API ServerCDKKubernetes
0 likes · 15 min read
Kubernetes Audit Log Analysis for Container Security
Open Source Linux
Open Source Linux
Apr 15, 2023 · Information Security

Understanding Phishing: Types, Tactics, and Prevention Strategies

This article explains how phishing exploits human psychology, outlines common phishing variants such as email, spear, whaling, business email compromise, smishing, vishing, social‑media, pharming and evil‑twin attacks, and provides practical measures to recognize and defend against them.

Email securityPhishingcyberattack prevention
0 likes · 10 min read
Understanding Phishing: Types, Tactics, and Prevention Strategies
Efficient Ops
Efficient Ops
Apr 8, 2023 · Information Security

How China Postal Savings Bank Reached Advanced DevSecOps Maturity – Lessons and Practices

The article details China Postal Savings Bank's successful DevSecOps assessment at the 2023 GOPS Global Operations Conference, sharing the bank's project background, interview insights on culture, processes, and tooling, and outlining the benefits and future plans of adopting standardized DevSecOps practices.

BankingDevSecOpsMaturity Model
0 likes · 17 min read
How China Postal Savings Bank Reached Advanced DevSecOps Maturity – Lessons and Practices
AntTech
AntTech
Apr 7, 2023 · Information Security

Ant Group Launches Cybersecurity Student Innovation Funding Program to Foster Industry‑Academia Collaboration

In 2022, Ant Group and leading cybersecurity firms launched a five‑year funding program to support 1,200 students in open‑source security projects, linking academic research with real‑world industry needs and achieving high academic performance across the first reporting phase.

cybersecurityindustry‑academiainformation security
0 likes · 4 min read
Ant Group Launches Cybersecurity Student Innovation Funding Program to Foster Industry‑Academia Collaboration
Python Programming Learning Circle
Python Programming Learning Circle
Mar 31, 2023 · Information Security

Backdoors in Software: Real-World Cases, Legal Perspectives, and Security Implications

The article recounts real-world examples of hidden backdoors in software—from an Android ROM project and Ken Thompson’s compiler-level exploit—to discuss their legal ambiguity in China, highlight the challenges of detection, and conclude with a call for developers to share their own experiences, alongside a promotional Python course.

AndroidCompilerLegal
0 likes · 6 min read
Backdoors in Software: Real-World Cases, Legal Perspectives, and Security Implications
dbaplus Community
dbaplus Community
Mar 28, 2023 · Information Security

How a Redis Client Bug Exposed ChatGPT User Data and What OpenAI Fixed

A recent bug in the open‑source redis‑py library caused ChatGPT to leak personal data of about 1.2 % of Plus users, allowing some users to see others' names, emails, and partial credit‑card details; OpenAI issued an apology, published a post‑mortem, and deployed a patch to fix the Redis Cluster async client issue.

ChatGPTOpenAIRedis
0 likes · 6 min read
How a Redis Client Bug Exposed ChatGPT User Data and What OpenAI Fixed
21CTO
21CTO
Mar 28, 2023 · Information Security

Why Did Twitter Issue a DMCA Takedown on Its Own Leaked Source Code?

Twitter filed a DMCA request to force GitHub to remove a repository exposing proprietary code, while also seeking a court order to identify the leaker, highlighting the security risks and legal complexities of source‑code leaks in the era of high‑profile tech acquisitions.

DMCAGitHubTwitter
0 likes · 5 min read
Why Did Twitter Issue a DMCA Takedown on Its Own Leaked Source Code?
Top Architect
Top Architect
Mar 13, 2023 · Information Security

Understanding Single Sign‑On (SSO) and CAS Authentication Flows

This article explains the concept, background, and definition of Single Sign‑On (SSO), outlines three SSO deployment types, introduces the Central Authentication Service (CAS) with detailed ticket mechanisms, and provides step‑by‑step SSO and Single Logout (SLO) processes for multiple applications.

CASSSOSingle Sign-On
0 likes · 11 min read
Understanding Single Sign‑On (SSO) and CAS Authentication Flows
Programmer DD
Programmer DD
Mar 12, 2023 · Information Security

GitHub’s 2FA Mandate: Boosting Software Supply Chain Security

Starting March 13, 2023, GitHub will enforce two‑factor authentication for all contributors, rolling out the requirement gradually based on activity and project impact, to strengthen the global software supply chain against account takeover attacks and align with broader cybersecurity policies.

Developer SecurityGitHubinformation security
0 likes · 6 min read
GitHub’s 2FA Mandate: Boosting Software Supply Chain Security
DataFunTalk
DataFunTalk
Mar 10, 2023 · Information Security

Data Security Management Practices and Future Outlook in a Large Commercial Bank

The article outlines a large commercial bank’s understanding of data security, shares its comprehensive management practices—including governance, lifecycle protection, technical support, and industry collaboration—and presents a forward‑looking perspective on future challenges and enhancements in data security.

Financial Industrydata securitygovernance
0 likes · 16 min read
Data Security Management Practices and Future Outlook in a Large Commercial Bank
MaGe Linux Operations
MaGe Linux Operations
Mar 5, 2023 · Information Security

Top 10 Vulnerability Scanners Every Security Team Needs

This guide reviews the ten leading vulnerability scanning solutions, detailing each tool's key features, deployment options, and how they help organizations detect and remediate security weaknesses across networks, servers, cloud and container environments.

Open SourcePenetration TestingSecurity tools
0 likes · 7 min read
Top 10 Vulnerability Scanners Every Security Team Needs
Java Architect Essentials
Java Architect Essentials
Feb 25, 2023 · Information Security

Analysis of Phone and Electricity Recharge Money‑Laundering Schemes in Illicit Apps

The article investigates how certain illicit mobile applications use phone‑bill and electricity‑bill recharge interfaces to launder money, describing the hidden industry chain, the roles of unsuspecting users, the various payment methods involved, and the challenges of tracing the illicit funds.

illicit appsinformation securitymoney laundering
0 likes · 11 min read
Analysis of Phone and Electricity Recharge Money‑Laundering Schemes in Illicit Apps
MaGe Linux Operations
MaGe Linux Operations
Feb 25, 2023 · Information Security

Top 10 Website Security Threats & How to Defend Your Site

This article examines the ten most common website security attacks—from XSS and SQL injection to DDoS and phishing—explaining their motivations, mechanisms, and practical mitigation strategies such as WAF deployment, input sanitization, SSL encryption, and regular updates to help protect any online presence.

DDoSSSLWAF
0 likes · 14 min read
Top 10 Website Security Threats & How to Defend Your Site
AntTech
AntTech
Feb 16, 2023 · Information Security

Evolution of Ant Group's Risk Control Platforms and Data Security Strategies

The article outlines the five‑generation evolution of Ant Group's risk control platforms, the technical and operational challenges faced, the shift toward data‑driven and AI‑enabled security, and the organization’s comprehensive data and network protection measures alongside emerging technologies such as graph risk, blockchain, and privacy computing.

Ant GroupArtificial Intelligenceinformation security
0 likes · 14 min read
Evolution of Ant Group's Risk Control Platforms and Data Security Strategies
DataFunSummit
DataFunSummit
Feb 14, 2023 · Information Security

Digital Watermarking Techniques for Data Leakage Traceability and Protection

This article presents a comprehensive overview of digital watermarking, covering its history, evaluation metrics, various media implementations, challenges posed by AI, and practical applications—especially in e‑commerce—to protect data throughout its lifecycle and enable effective leakage tracing.

data leakagedatabase watermarkdigital watermarking
0 likes · 16 min read
Digital Watermarking Techniques for Data Leakage Traceability and Protection
Bilibili Tech
Bilibili Tech
Feb 10, 2023 · Information Security

Digital Watermarking Technology: Concepts, Features, Algorithms, and Applications

The paper surveys digital watermarking, detailing its definition, security features, embedding models, key algorithms across spatial, transform, and compression domains, and applications such as copyright protection, anti‑counterfeiting, tamper detection, and covert communication, while outlining future robustness challenges and prospects.

ApplicationsLSB algorithmRobustness
0 likes · 18 min read
Digital Watermarking Technology: Concepts, Features, Algorithms, and Applications
21CTO
21CTO
Jan 29, 2023 · Information Security

What the Yandex Source Code Leak Reveals About Security Risks

In July 2022 a former Yandex employee stole 44.7 GB of the company's source code, exposing internal architecture across dozens of services, prompting security experts to warn that while no user data was leaked, the breach could enable future targeted attacks.

MonorepoYandexinformation security
0 likes · 6 min read
What the Yandex Source Code Leak Reveals About Security Risks
Efficient Ops
Efficient Ops
Jan 11, 2023 · Information Security

How Anxin Securities Achieved Advanced DevSecOps Maturity in Financial Services

Anxin Securities' Financial Store system passed the level‑2 DevSecOps assessment by China CAICT, showcasing how cultural, process, and technical practices were integrated to enhance security, efficiency, and digital transformation in a large‑scale financial trading platform.

DevOpsDevSecOpsFinancial Services
0 likes · 14 min read
How Anxin Securities Achieved Advanced DevSecOps Maturity in Financial Services
Efficient Ops
Efficient Ops
Jan 11, 2023 · Information Security

How Zhongtai Securities Achieved Advanced DevSecOps Maturity

Zhongtai Securities shares how adopting DevSecOps standards, integrating security into every stage of its DevOps pipeline, and leveraging automated testing tools dramatically improved delivery speed, reduced vulnerabilities, and positioned the firm at an advanced domestic security level, as confirmed by the latest CAICT assessment.

Continuous DeliveryDevOpsDevSecOps
0 likes · 12 min read
How Zhongtai Securities Achieved Advanced DevSecOps Maturity
Laravel Tech Community
Laravel Tech Community
Jan 10, 2023 · Information Security

Dongle: A Lightweight, Semantic, Developer‑Friendly Go Library for Encoding, Decoding, and Cryptographic Operations

Dongle is a lightweight, Go-based library offering extensive encoding/decoding and cryptographic functions—including various hash, HMAC, and symmetric/asymmetric algorithms—along with recent updates such as tea‑mode support, empty‑string padding, and code restructuring, and is featured in the awesome‑go collection.

encodinginformation security
0 likes · 4 min read
Dongle: A Lightweight, Semantic, Developer‑Friendly Go Library for Encoding, Decoding, and Cryptographic Operations
Efficient Ops
Efficient Ops
Jan 10, 2023 · Information Security

How China’s Leading Bank Achieved Advanced DevSecOps Maturity: An Inside Interview

This article reports on the China Academy of Information and Communications Technology's DevOps standard assessments, highlights Industrial and Commercial Bank of China's successful Level‑2 DevSecOps evaluation, and presents an in‑depth interview revealing the bank’s cultural, process, and technical practices that boosted its security risk management and digital transformation.

BankingDevOps StandardsDevSecOps
0 likes · 11 min read
How China’s Leading Bank Achieved Advanced DevSecOps Maturity: An Inside Interview
Continuous Delivery 2.0
Continuous Delivery 2.0
Jan 10, 2023 · Information Security

Understanding Software Supply Chain Security and the SLSA Framework

The article explains why software supply chain security is increasingly critical, introduces the SLSA (Supply‑Chain Levels for Software Artifacts) framework and its three trust boundaries, outlines common risk points from code commit to package distribution, and discusses mitigation strategies such as mandatory code review, robot‑account controls, and automation.

CI/CDSLSAinformation security
0 likes · 11 min read
Understanding Software Supply Chain Security and the SLSA Framework
Liangxu Linux
Liangxu Linux
Jan 3, 2023 · Information Security

Why Can Public Key Encrypt but Not Decrypt? Unpacking HTTPS Encryption

An in‑depth guide explains the difference between symmetric and asymmetric encryption, why a public key can encrypt but not decrypt, and walks through the TLS 1.2 handshake that underpins HTTPS, covering certificates, random numbers, session key derivation, and the role of public‑private key pairs.

HTTPSHandshakeTLS
0 likes · 16 min read
Why Can Public Key Encrypt but Not Decrypt? Unpacking HTTPS Encryption
Efficient Ops
Efficient Ops
Dec 29, 2022 · Information Security

Mastering AD Domain Security: Attack Techniques and Defense Strategies

This article explains how Active Directory domains work, outlines over 220 attack techniques such as SPN scanning, password spraying, Kerberoasting, DCSync, and privilege‑escalation exploits, and then presents comprehensive defense measures including attack‑surface reduction, strict admin hygiene, network isolation, honeypots, and continuous monitoring.

Active DirectoryDefense StrategiesDomain Security
0 likes · 15 min read
Mastering AD Domain Security: Attack Techniques and Defense Strategies
21CTO
21CTO
Dec 28, 2022 · Information Security

Okta’s Private GitHub Repo Breached: Source Code Stolen but Services Remain Safe

Okta disclosed that attackers copied source code from its private GitHub repositories, yet the breach did not affect its services, customer data, or HIPAA, FedRAMP, and DoD customers, and the company took immediate remedial actions to secure its accounts.

GitHub breachIdentity ManagementOkta
0 likes · 4 min read
Okta’s Private GitHub Repo Breached: Source Code Stolen but Services Remain Safe
Open Source Linux
Open Source Linux
Dec 9, 2022 · Information Security

Top 10 Linux Antivirus Tools to Secure Your Servers

Although Linux is widely regarded as secure, its dominance in web servers makes it a prime target for malware, so this guide reviews the ten most effective antivirus solutions for Linux, explaining their features, usage, and why they matter for protecting your systems.

information securitymalware detection
0 likes · 6 min read
Top 10 Linux Antivirus Tools to Secure Your Servers
Open Source Linux
Open Source Linux
Dec 5, 2022 · Fundamentals

What Jiang Zemin’s 2008 Vision Reveals About China’s Future IT Industry

This article summarizes Jiang Zemin’s 2008 paper on China’s information technology industry, highlighting his 24‑character strategic guideline, the emphasis on autonomous innovation in microelectronics, software, cloud computing, and the enduring relevance of his insights for today’s tech development.

ChinaIT industryTechnology strategy
0 likes · 9 min read
What Jiang Zemin’s 2008 Vision Reveals About China’s Future IT Industry
Liangxu Linux
Liangxu Linux
Nov 28, 2022 · Information Security

Master Wireshark: Interface, Capture, and Advanced Filtering Techniques

This guide walks you through Wireshark’s main interface, demonstrates simple packet captures, explains how to use capture and display filters with concrete examples, and details TCP three‑handshake analysis, providing practical tips for network engineers and security analysts.

TCP handshakeWiresharkcapture filters
0 likes · 13 min read
Master Wireshark: Interface, Capture, and Advanced Filtering Techniques
AntTech
AntTech
Nov 28, 2022 · Information Security

Ant Group Anti‑Intrusion Platform: Architecture, Trillion‑Scale Detection, Risk Assessment, and Automated Response

This article details the evolution, architecture, and key technologies of Ant Group's anti‑intrusion platform, explaining how it handles trillion‑level data streams for intrusion detection, performs multi‑dimensional risk assessment and attribution, and enables rapid, automated security incident response across massive enterprise environments.

Large-Scale Dataanti-intrusioninformation security
0 likes · 15 min read
Ant Group Anti‑Intrusion Platform: Architecture, Trillion‑Scale Detection, Risk Assessment, and Automated Response