vulnerability-mining

标签

Cards List
#vulnerability-mining

@seclink: JSEF安全教学框架与漏洞挖掘基准已新增C类(补丁回归副作用…

X AI KOLs Timeline · 8小时前 缓存

JSEF安全教学框架已新增补丁回归副作用和长程数据流类别,增强了用于评估静态分析工具的基准。

0 人收藏 0 人点赞
#vulnerability-mining

@seclink: 我们刚刚发布了 JSEF v1.4.0-benchmark,一个 Spring Boot 3.x Java 漏洞挖掘基准,现在新增了 85 个样本(503→588 个检查点……

X AI KOLs Timeline · 昨天 缓存

JSEF v1.4.0-benchmark 已发布,在 Spring Boot 3.x Java 漏洞挖掘基准中新增了 85 个样本,以增强安全测试覆盖范围和验证。

0 人收藏 0 人点赞
#vulnerability-mining

@seclink: 这次 fastjson 的 0day, 可以用于验证大模型的漏洞挖掘能力,不用给明确的信息只给出goal目标(搞出 gadget free 的 RCE漏洞) , 看大模型多少步能够挖掘出来,并且自我验证通过。 实践证明: claude 果…

X AI KOLs Following · 2026-07-21 缓存

利用fastjson的0day漏洞测试大模型的漏洞挖掘能力,发现Claude和豆包表现突出。

0 人收藏 0 人点赞
#vulnerability-mining

@heyshrutimishra: We've been watching the wrong AI story. While the timeline keeps debating whether Mythos is real, hyped, or just well-m…

X AI KOLs Following · 2026-05-20 缓存

A thread contrasts the hype around AI security startup Mythos with 360's practical achievement of autonomously discovering 23 vulnerabilities (including two criticals) in the OpenClaw ecosystem, highlighting the real direction of AI security.

0 人收藏 0 人点赞
← 返回首页

提交意见反馈