1. 颠覆代码完整性检查:在 Signal、1Password 等应用中植入本地后门 博客 | 2025-09-04 04:00 | CVE-2025-55305 | blog.trailofbits.com | 原文 ↗ | #backdoor | #vulnerability-disclosure | #v8
2. 内联样式数据窃取:使用链式 CSS 条件语句泄露数据 研究 | 2025-08-27 07:35 | portswigger.net | 原文 ↗ | #chromium | #exfiltration | #css
3. 寻找变异XSS的新工具、$20k Chromium沙箱逃逸、Ekoparty现场漏洞赏金结果 研究 | 2024-11-18 14:02 | yeswehack.com | 原文 ↗ | #bug-bounty | #php | #sandbox-escape
4. Burp Scanner 中的录制登录功能 博客 | 2021-04-22 13:32 | portswigger.net | 原文 ↗ | #product-update | #web-security | #authentication
5. Burp Suite 中的浏览器驱动扫描 博客 | 2021-03-22 14:29 | portswigger.net | 原文 ↗ | #burp-suite | #javascript | #burp-scanner
6. 干净利落地逃逸 Chrome 沙箱 研究 | 2020-04-19 15:00 | theori.io | 原文 ↗ | #use-after-free | #sandbox-escape | #exploit