针对Windows的Java反序列化攻击
https://isc.sans.edu/forums/diary/Java+Deserialization+Attack+Against+Windows/23513/
越过 XSS: Edge Side Include Injection
http://gosecure.net/2018/04/03/beyond-xss-edge-side-include-injection/
新的Android恶意软件——KevDroid调查与分析
http://blog.talosintelligence.com/2018/04/fake-av-investigation-unearths-kevdroid.html
CSRF攻击与防御
https://www.cnblogs.com/phpstudy2015-6/p/6771239.html
小心!恶意的游戏扩展
A root cause analysis of CVE-2018-0797 – Rich Text Format Stylesheet Use-After-Free vulnerability
CloudFront劫持
Oracle EBS Penetration testing tool
https://erpscan.com/press-center/blog/oracle-ebs-penetration-testing-tool/
badtouch——一个可编写脚本的网络身份验证破解程序