###### tags: `資安事件新聞週報` # 資安事件新聞週報 2025/2/24 ~ 2025/2/28 1.重大弱點漏洞/後門/Exploit/Zero Day F5 Networks BIG-IP https://www.tenable.com/plugins/nessus/216689 Red Hat Enterprise Linux 7 https://nvd.nist.gov/vuln/detail/CVE-2025-0624 Trend Micro HouseCall for Home Networks https://nvd.nist.gov/vuln/detail/CVE-2022-28339 Two Actively Exploited Security Flaws in Adobe and Oracle Products Flagged by CISA https://thehackernews.com/2025/02/two-actively-exploited-security-flaws.html CISA Adds Microsoft and Zimbra Flaws to KEV Catalog Amid Active Exploitation https://thehackernews.com/2025/02/cisa-adds-microsoft-and-zimbra-flaws-to.html IBM QRadar SIEM contains multiple vulnerabilities https://www.ibm.com/support/pages/node/7184085 IBM QRadar Data Synchronization App for IBM QRadar SIEM is vulnerable to using components with known vulnerabilities https://www.ibm.com/support/pages/node/7184092 Google Chrome https://www.tenable.com/plugins/nessus/216754 https://www.tenable.com/plugins/nessus/216753 WordPress表單外掛Everest Forms存在重大漏洞,10萬網站曝險 https://www.ithome.com.tw/news/167602 微軟修補低程式碼網站建置平臺Power Pages零時差漏洞 https://www.ithome.com.tw/news/167545 郵件傳輸代理平臺Exim出現嚴重漏洞,攻擊者恐用於注入惡意SQL查詢來影響運作 https://www.ithome.com.tw/news/167569 macOS虛擬化軟體Parallels Desktop存在漏洞,攻擊者有機會取得root權限 https://www.ithome.com.tw/news/167582 Atlassian修補旗下Confluence、Crowd重大層級漏洞 https://www.securityweek.com/atlassian-patches-critical-vulnerabilities-in-confluence-crowd/ 2.銀行/金融/保險/證券/金融監理 新聞及資安 玉山金揭露阻詐計畫的下一步,2月底用金融無塵室技術完成警示帳戶聯防PoC驗證 https://www.ithome.com.tw/news/167588 金融科技產業聯盟成立三大重點:加大合作意願、建立持續合作創新機制、第一階段重點發展金融防詐 https://www.ithome.com.tw/news/167510 花旗銀行出包!280美元險「匯成81兆美元」 1員工機警擋下 https://www.ettoday.net/news/20250228/2917198.htm 實體銀行比網上銀行更安全嗎 https://www.epochtimes.com/b5/25/2/26/n14446356.htm 金管會金檢報告出爐 揪金控個資保護、風險管理等4大缺失 https://udn.com/news/story/7239/8574160 合庫祭高薪徵才!金控、銀行需402名最高起薪6.24萬 2/26開放報名 https://news.cnyes.com/news/id/5870773 銀行新規生效 未助客戶解壓者會被點名批評 https://www.epochtimes.com/b5/25/2/28/n14447192.htm 270萬用戶注意!1銀行「大砍帳戶常用功能」,新規定3/29起生效,轉帳時要留意了 https://www.storm.mg/lifestyle/5321412 「快速通關」轉走1500萬!銀行員勾結詐團 金管會說話了 https://www.chinatimes.com/realtimenews/20250225004797-260410?chdtv 金門女急開通「網路轉帳」領獎金 銀行立即call警方阻詐 https://tw.nextapple.com/local/20250228/0039B1CAA480F4E2F58CB31E0DDDE0F6 3.信用卡/電子支付/行動支付/pay/支付系統/資安 台灣訂定 10 兆元無現金支付目標,AFTEE 先享後付雙「戶」併進推動 BNPL 消費新時代 https://www.techbang.com/posts/121575-taiwan-set-a-cashless-payment-target-of-10-trillion-yuan-and TWQR一碼Pay 國內外支付利器 https://www.chinatimes.com/newspapers/20250224000282-260210?chdtv 德牧獨自買香腸「順手亮出手錶」要求行動支付!收銀員看呆:要刷載具嗎 https://udn.com/news/story/7470/8496383 台男涉信用卡詐騙在星被捕 若罪名成立最長可判10年 https://udn.com/news/story/7321/8578094 一隻阿圓信用卡遭盜刷21萬!親揭事發經過 嘆:真的很恐怖 https://today.line.me/tw/v2/article/DR9YRko 簽帳金融卡風險高?專家:使用跟信用卡相同、遭盜刷程序較麻煩 https://reurl.cc/V0rEpn 最新詐騙手法!輸入1資料「信用卡密碼被盜、存款瞬間蒸發」,警方教1招徹底防詐 https://www.storm.mg/lifestyle/5323349 iPhone這個預設功能隨時令信用卡資料外洩 專家建議離家後應關閉 https://www.hk01.com/article/60211621?utm_source=01articlecopy&utm_medium=referral 日本刷卡新制將上路,實體店無法再簽名認證!專家揭真相:台人不必太擔心 https://reurl.cc/86K34R 4.加密貨幣/數位貨幣/挖礦/區塊鍊/智能合約/WEB3 資安 Bybit遭駭,15億美元加密貨幣損失創歷史紀錄 https://www.informationsecurity.com.tw/article/article_detail.aspx?aid=11666 Bybit 遭駭客攻擊!價值14.6 億美金 ETH 被盜,成加密貨幣史上被駭金額最高紀錄 https://today.line.me/tw/v2/article/PGJgRKV Bybit推出The Great USDC Race,獎金池達10萬枚USDC https://money.udn.com/money/story/123828/8578183 Dragonfly 合夥人談近期熱點:Bybit 被黑、總統加密門、Meme 週期結束,監管成轉機.. https://www.blocktempo.com/dragonfly-partners-talk-about-recent-hot-topics/ Bybit Confirms Record-Breaking $1.5 Billion Crypto Heist in Sophisticated Cold Wallet Attack https://thehackernews.com/2025/02/bybit-confirms-record-breaking-146.html Bybit Hack Traced to Safe{Wallet} Supply Chain Attack Exploited by North Korean Hackers https://thehackernews.com/2025/02/bybit-hack-traced-to-safewallet-supply.html 男子謊稱匯款買精品包 中市警攔阻加密貨幣詐騙 https://www.cna.com.tw/news/asoc/202502280166.aspx FBI指控朝鮮支持的黑客盜竊15億美元加密貨幣 https://www.epochtimes.com/b5/25/2/27/n14446993.htm 限制措施不斷收緊 陸準備針對加密貨幣展開新一輪戰爭 https://www.chinatimes.com/realtimenews/20250228001429-260409 SEC撤銷對Coinbase的訴訟 https://cn.wsj.com/articles/sec%E6%92%A4%E9%8A%B7%E5%B0%8Dcoinbase%E7%9A%84%E8%A8%B4%E8%A8%9F-aa4e7f12 新加坡詐騙損失金額創新高! 星媒:加密貨幣詐騙成隱憂 https://www.ettoday.net/news/20250225/2915187.htm 幣安首次測試「漲停板機制」,RED開盤前三天最多漲400%,適合加密市場嗎 https://www.blocktempo.com/binance-tests-pre-market-trading-limit-mechanism-for-the-first-time-redstone/ 搶銀行落伍了,駭客搶交易所金額上看100倍!情報人員拆解「不用高竿技術,最難環節在這裡」 https://money.udn.com/money/story/5599/8578044 5.資安事件新聞 A.病毒木馬 / 殭屍網路 / 勒索軟體 / Adware /APT /後門程式/IOC Ghost勒索軟體攻擊橫掃70國,美國FBI與CISA發布警報 https://www.informationsecurity.com.tw/article/article_detail.aspx?aid=11652 北美及亞洲政府機關、大學遭Linux後門程式Auto-Color鎖定 https://www.ithome.com.tw/news/167594 存在弱點的病毒掃描工具元件遭濫用,駭客發起大規模自帶驅動程式攻擊,散布惡意程式HiddenGh0st https://thehackernews.com/2025/02/2500-truesightsys-driver-variants.html 駭客利用中國CDN服務攻擊亞太工業,散布RAT木馬程式 https://thehackernews.com/2025/02/fatalrat-phishing-attacks-target-apac.html 13萬設備遭殭屍網路綁架,被用於對M365帳號進行密碼潑灑攻擊 https://securityaffairs.com/174595/cyber-crime/large-botnet-targets-m365-password-spraying-attacks.html 中國駭客用惡意程式ShadowPad發動勒索軟體攻擊,至少20家企業組織受害 https://www.ithome.com.tw/news/167554 中國駭客Mustang Panda針對東南亞國家而來,利用惡意軟體Bookworm從事活動 https://unit42.paloaltonetworks.com/stately-taurus-uses-bookworm-malware/ 中國駭客Earth Preta假借打擊犯罪為由散布惡意程式ToneShell,意圖利用作業系統預載公用程式迴避偵測 https://www.ithome.com.tw/news/167511 駭客濫用GitHub儲存庫發動大規模惡意軟體攻擊行動GitVenom,意圖竊取帳密資料及數位資產 https://www.bleepingcomputer.com/news/security/gitvenom-attacks-abuse-hundreds-of-github-repos-to-steal-crypto/ 竊資軟體ACRStealer冒充破解工具散布,駭客濫用Google Docs掩蓋攻擊行動 https://securityonline.info/acrstealer-malware-exploits-google-docs-as-command-and-control-infrastructure/ 竊資軟體Rhadamanthys利用微軟管理主控臺漏洞進行感染 https://securityonline.info/rhadamanthys-infostealer-exploits-microsoft-management-console/ 駭客組織RedCurl利用Adobe元件側載惡意程式,意圖假借求職對法律產業發動攻擊 https://www.ithome.com.tw/news/167512 JAR檔案簽章工具遭到濫用,攻擊者藉此於受害電腦啟動惡意軟體XLoader https://thehackernews.com/2025/02/cybercriminals-use-eclipse-jarsigner-to.html 假借提供驅動程式部署、瀏覽器更新工具,北韓駭客意圖藉由Dropbox散布惡意程式 https://gbhackers.com/fake-chrome-update-delivers-drivereasy-malware/ 駭客假借提供檔案管理工具Total Commander盜版名義,意圖散布竊資軟體LummaC2 https://securityonline.info/lummac2-malware-masquerading-as-total-commander-crack-to-infect-windows-users/ APT Targets NetEase 163.com Users with Fake Download Pages & Spoofed Domains https://hunt.io/blog/greenspot-apt-targets-163com-fake-downloads-spoofing Suspicious IP_Host https://otx.alienvault.com/pulse/67bab647b790e0131cd4300a Becoming Ransomware Ready: Why Continuous Validation Is Your Best Defense https://thehackernews.com/2025/02/becoming-ransomware-ready-why.html 5 Active Malware Campaigns in Q1 2025 https://thehackernews.com/2025/02/5-active-malware-campaigns-in-q1-2025.html 2,500+ Truesight.sys Driver Variants Exploited to Bypass EDR and Deploy HiddenGh0st RAT https://thehackernews.com/2025/02/2500-truesightsys-driver-variants.html GitVenom Malware Steals $456K in Bitcoin Using Fake GitHub Projects to Hijack Wallets https://thehackernews.com/2025/02/gitvenom-malware-steals-456k-in-bitcoin.html FatalRAT Phishing Attacks Target APAC Industries Using Chinese Cloud Services https://thehackernews.com/2025/02/fatalrat-phishing-attacks-target-apac.html New Malware Campaign Uses Cracked Software to Spread Lumma and ACR Stealer https://thehackernews.com/2025/02/new-malware-campaign-uses-cracked.html New Linux Malware 'Auto-Color' Grants Hackers Full Remote Access to Compromised Systems https://thehackernews.com/2025/02/new-linux-malware-auto-color-grants.html CERT-UA Warns of UAC-0173 Attacks Deploying DCRat to Compromise Ukrainian Notaries https://thehackernews.com/2025/02/cert-ua-warns-of-uac-0173-attacks.html Malicious PyPI Package "automslc" Enables 104K+ Unauthorized Deezer Music Downloads https://thehackernews.com/2025/02/malicious-pypi-package-automslc-enables.html PolarEdge Botnet Exploits Cisco and Other Flaws to Hijack ASUS, QNAP, and Synology Devices https://thehackernews.com/2025/02/polaredge-botnet-exploits-cisco-and.html Leaked Black Basta Ransomware Chat Logs Reveal Inner Workings and Internal Conflicts https://thehackernews.com/2025/02/leaked-black-basta-chat-logs-reveal.html B.行動安全 / iPhone / Android /穿戴裝置 /App / 5G / 即時通訊 針對外傳英國政府施壓開存取用戶資料的後門,蘋果證實即將移除英國iCloud進階資料防護功能 https://www.ithome.com.tw/news/167517 Apple Drops iCloud's Advanced Data Protection in the U.K. Amid Encryption Backdoor Demands https://thehackernews.com/2025/02/apple-drops-iclouds-advanced-data.html Data Leak Exposes TopSec's Role in China's Censorship-as-a-Service Operations https://thehackernews.com/2025/02/data-leak-exposes-topsecs-role-in.html SpyLend貸款詐騙App鎖定安卓用戶而來,已被下載逾10萬次 https://www.bleepingcomputer.com/news/security/spylend-android-malware-downloaded-100-000-times-from-google-play/ C.事件 / 駭客 / DDOS / APT / 雲端/ 暗網/ 徵才 / 國際資安事件 / 資安人力 點序科技部分資訊系統遭到網路攻擊 https://mopsov.twse.com.tw/mops/web/ajax_t05sr01_1?firstin=true&stp=1&step=1&SEQ_NO=3&SPOKE_TIME=160208&SPOKE_DATE=20250224&COMPANY_ID=6485 臺灣資安專家揭開WorstFit,成功探索Windows ANSI字元轉換雷區,找出全新攻擊面與3種攻擊手法 https://www.ithome.com.tw/news/167515 波羅的海海底電纜切斷事件連連,歐盟啟動海底電纜安全倡議 https://www.ithome.com.tw/news/167541 繼臺馬二號、三號海纜後,臺澎三號海纜也發生中斷故障 https://www.ithome.com.tw/news/167546 針對中國駭客Salt Typhoon利用思科網路設備弱點入侵美國電信業者,思科發表調查報告證實此事 https://www.ithome.com.tw/news/167535 Hackers Exploited Krpano Framework Flaw to Inject Spam Ads on 350+ Websites https://thehackernews.com/2025/02/hackers-exploited-krpano-framework-flaw.html Cybercriminals Can Now Clone Any Brand's Site in Minutes Using Darcula PhaaS v3 https://thehackernews.com/2025/02/cybercriminals-can-now-clone-any-brands.html 澳洲政府禁用卡巴斯基軟體 https://www.ithome.com.tw/news/167559 Australia Bans Kaspersky Software Over National Security and Espionage Concerns https://thehackernews.com/2025/02/australia-bans-kaspersky-software-over.html D.資料外洩/個資法/GDPR/網路詐騙/網路釣魚/盜刷/假新聞/網路霸凌/帳號安全 OpenAI Bans Accounts Misusing ChatGPT for Surveillance and Influence Campaigns https://thehackernews.com/2025/02/openai-bans-accounts-misusing-chatgpt.html 高達2.84億筆帳密資料收入Have I Been Pwned,都源自駭客盜取的Log資料 https://www.ithome.com.tw/news/167600 Have I Been Pwned列入2.84億筆遭竊資軟體外流的帳密資料 https://www.bleepingcomputer.com/news/security/have-i-been-pwned-adds-284m-accounts-stolen-by-infostealer-malware/ 中國資安業者天融信資料外洩,透露該公司提供中國政府言論審查監控服務 https://thehackernews.com/2025/02/data-leak-exposes-topsecs-role-in.html Google揭露為期超過2年的網釣攻擊行動,駭客鎖定大專院校而來,每月攻擊數千名師生 https://cloud.google.com/blog/topics/threat-intelligence/phishing-targeting-higher-education 網釣工具Darcula租用服務升級,駭客提供買家自訂工具,號稱能對任何品牌的使用者下手 https://www.bleepingcomputer.com/news/security/darcula-phaas-can-now-auto-generate-phishing-kits-for-any-brand/ 網釣工具包Astaroth同時針對Gmail及M365帳號而來,能繞過多因素驗證並挾持帳號 https://www.ithome.com.tw/news/167516 E.研究報告/工具 全球資安研究社群最認可的2024資安漏洞研究出爐,臺灣資安專家揭開Apache HTTP Server模組架構隱藏問題 https://www.ithome.com.tw/news/167514 2024十大網站攻擊技術公布,臺灣資安專家再度稱霸第一 https://www.ithome.com.tw/news/167513 AI-Powered Deception is a Menace to Our Societies https://thehackernews.com/2025/02/ai-powered-deception-is-menace-to-our.html SOC 3.0 - The Evolution of the SOC and How AI is Empowering Human Talent https://thehackernews.com/2025/02/soc-30-evolution-of-soc-and-how-ai-is.html Three Password Cracking Techniques and How to Defend Against Them https://thehackernews.com/2025/02/three-password-cracking-techniques-and.html F.商業 Google Cloud KMS Adds Quantum-Safe Digital Signatures to Defend Against Future Threats https://thehackernews.com/2025/02/google-cloud-kms-adds-quantum-safe.html Google Cloud KMS 導入抗量子數位簽章功能,強化雲端加密防護 https://www.informationsecurity.com.tw/article/article_detail.aspx?aid=11659 平台商必備的證書! SOC報告助企業掌握供應鏈風險,建構資安治理藍圖 https://www.informationsecurity.com.tw/article/article_detail.aspx?aid=11657 AI浪潮下的資安重整:專訪Check Point新任執行長Nadav Zafrir https://www.informationsecurity.com.tw/article/article_detail.aspx?aid=11667 微軟發表突破性量子晶片 Majorana 1,加速後量子密碼轉換迫切性 https://www.informationsecurity.com.tw/article/article_detail.aspx?aid=11660 Palo Alto Networks 推出 Prisma Cloud 的全新版本 Cortex Cloud https://www.informationsecurity.com.tw/article/article_detail.aspx?aid=11662 微軟針對WSUS服務棄用再度警告,2個月後將停止驅動程式同步服務 https://www.ithome.com.tw/news/167537 近2億用戶數的電子病歷服務商Epic揭醫療AI進展,瞄準AI代理和多模態AI https://www.ithome.com.tw/news/167584 微軟悄悄測試具有廣告的Windows版Office https://www.ithome.com.tw/news/167581 G.政府 臺灣學術機構遭到鎖定,駭客佯稱資安院進行社交工程攻擊,假借執行勒索軟體偵測工具為由散布惡意軟體 https://moda.gov.tw/ACS/press/report/15166 資安署25年1月資安月報:駭客假冒資安院發動社交工程攻擊 https://www.informationsecurity.com.tw/article/article_detail.aspx?aid=11674 數發部要從算力、資料等5策略著手加速國內AI產業生態發展 https://www.ithome.com.tw/news/167608 預算刪減危機衝擊,數發部面臨政策落地與產業創新的雙重考驗 https://www.ithome.com.tw/news/167596 台數發部5大政策工具推AI發展 https://www.epochtimes.com/b5/25/2/27/n14446945.htm 支持無人載具產業發展 數發部擴增實驗範圍至158處 https://ec.ltn.com.tw/article/breakingnews/4965053 數發部數位皮夾拚12月試行 爭取超商取貨也能適用 https://finance.ettoday.net/news/2914448 全球數位人權大會在臺灣!黃彥男:致力成為數位發展標竿國家 https://www.technice.com.tw/issues/ai/165773/ 林佳龍:持續與國際夥伴深化合作 深化資安外交 https://money.udn.com/money/story/5613/8574973 H.工控系統/ICS/SCADA/IOT/物聯網/車聯網/電動車/人工智慧/AI/ML/人臉辨識/醫療 相關資安 D-Link針對已終止支援的無線路由器DIR-823公布新漏洞,呼籲用戶停止使用 https://securityonline.info/publicly-disclosed-exploits-put-d-link-dir-823-users-in-danger-no-security-fixes/ HP修補LaserJet印表機重大漏洞,攻擊者可透過偽造的列印工作觸發 https://securityonline.info/hp-warns-of-critical-security-flaw-in-laserjet-printers-cve-2025-26506-cvssv4-9-2/ Ubiquiti警告IP攝影機存在重大層級漏洞,恐被用於繞過身分驗證、RCE攻擊 https://securityonline.info/cve-2025-23115-cve-2025-23116-hackers-can-hijack-ubiquiti-unifi-protect-cameras/ I.教育訓練 資安事件發生必要知道的復原程序,降低傷害 https://www.ithome.com.tw/pr/163614 iPAS資訊安全工程師中級筆記 https://hackmd.io/@Not/iPASInformationSecuritySpecialist iPas資安工程師證照考前研習 https://reurl.cc/GEbA3p iPAS◆資訊安全規劃實務◆中級測驗題庫彙編(123題) https://reurl.cc/orlD1g GCP Associate Cloud Engineer (ACE) 學習心得、教材資源與筆記分享 — 學習天然高可用與零信任設計 https://medium.com/blacksecurity/gcp-associate-cloud-engineer-78f736aee7ad Coursera 盤點 7 項雲端資安認證,高薪跳板都在這了! https://buzzorange.com/techorange/2022/07/12/cloud-security-certificates/ 一般人也能拿到國際資安認證!CSCU安全電腦使用者認證課程 https://www.ithome.com.tw/pr/160954 全球網絡安全勞動力失衡 (ISC)2免費課程及考試填補人才缺口 https://reurl.cc/m39MDj CISSP資安認證的8大領域 https://2formosa.blogspot.com/2022/12/CISSP-topic-domains.html CISSP考試心得 https://reurl.cc/KbY83j CISSP考試心得 – Benson https://reurl.cc/GbWvxd 目標導向-20天光速考過CISSP https://reurl.cc/2Zq6zn CISSP證照考試實戰心得 第一章:初期準備工作 https://netmag.tw/2022/06/17/the-cissp-has-learned-the-first-chapter-in-actual-combat CISSP證照考試實戰心得 第二章:規律且有紀律的讀書策略 https://netmag.tw/2022/07/01/the-cissp-is-in-the-field-of-combat-chapter-two-regular-and-disciplined-reading-strategies CISSP證照考試實戰心得 第三章:終極一戰 https://netmag.tw/2022/07/12/the-cissp-has-learned-a-third-chapter-in-actual-combat-experience-the-ultimate-battle Quick CISSP Infographic for IPSec https://www.studynotesandtheory.com/single-post/quick-cissp-infographic-for-ipsec CSSLP Certification - Security models in F# https://github.com/vbocan/csslp Certified Secure Software Lifecycle Professional in bullet points https://github.com/joeyhage/csslp-notes CPSA(CREST Practitioner Security Analyst) 資安分析師考試心得 https://tech-blog.cymetrics.io/posts/huli/crest-cpsa-prepare/ EC-Council CEH v11 考試心得、改版資訊以及準備方向 2021、2022 https://reurl.cc/1oyEM8 CEH v11 考試心得與準備方式 https://blog.sean.taipei/2022/01/ceh CEH https://github.com/a3cipher/CEH CodeRed by EC-Council https://github.com/codered-by-ec-council EC-Council CEH Practical / Master 準備心得 — 讓理論與實作相輔相成的學習 https://medium.com/blacksecurity/ceh-practical-master-3e80cac180a2 EC-Council CEHP考試準備心得 https://hackmd.io/@9dCJrgb6QHGd8dRfgHO0zg/r14xNn1po My ceh practical notes https://github.com/dhabaleshwar/CEHPractical/blob/main/Everything%20You%20Need.md CEHP課程筆記 https://hackmd.io/@nfu-johnny/B1Ju_BMPR ECSA v10 考試心得與讀書資料分享/ ECSA v10 Review and Study Materials https://medium.com/blacksecurity/ecsa-v10-1ec76c0eb7d4 EC-Council ECSA資安分析專家 v10 考試心得分享 https://javaxtalk.blogspot.com/2019/05/ec-council-ecsa-v10.html 20180817 EC-Council ECSA v10 PASS https://www.ptt.cc/bbs/License/M.1534571704.A.5BA.html 關於EC-Council CPENT和LPT Master滲透測試證照準備方式及心得分享 https://medium.com/@ChadSecurity/%E9%97%9C%E6%96%BCec-council-cpent%E5%92%8Clpt-master%E6%BB%B2%E9%80%8F%E6%B8%AC%E8%A9%A6%E8%AD%89%E7%85%A7%E6%BA%96%E5%82%99%E6%96%B9%E5%BC%8F%E5%8F%8A%E5%BF%83%E5%BE%97%E5%88%86%E4%BA%AB-efb63de00a8d 深度解析 CPENT 考試心得、以及與 OSCP 的比較 https://reurl.cc/41eL8v EC-Council CPENT v1 滲透測試認證 – 內容及心得分享 https://hackercat.org/pentesting/ec-council-cpent-v1-experience-review CPENT 從暴力到破解 https://hackmd.io/@3WAsoRFgSlyy7pm10p60kg/ByO0zs295 Ec-Council CPENT心得 - 資安菜鳥從CEH到LPT Master https://4hsienyang.medium.com/cpent-lpt-master-ccaebf2dbc7f CPENT考試心得分享:一次拿到 LPT 滲透測試大師認證 https://ucom.uuu.com.tw/web/Testimony/Article/4404 kaizensecurity/CPENT https://github.com/kaizensecurity/CPENT/tree/master CPENT : Pentesting like NO OTHERS ! https://www.linkedin.com/pulse/cpent-pentesting-like-others-belly-rachdianto/ Journey of My CPENT Exam https://medium.com/techiepedia/journey-of-my-cpent-exam-3a5d7ee6d917 [備考心得]CompTIA Security+ (SY0–601) 上篇 https://reurl.cc/M053DK [備考心得]CompTIA Security+ (SY0–601) 下篇 https://reurl.cc/M053Gv comptia-security-plus https://github.com/ajfuto/comptia-security-plus security-plus https://github.com/fjavierm/security-plus CompTIA Security+ Certification Practice Test Questions https://www.examcompass.com/comptia/security-plus-certification/free-security-plus-practice-tests#google_vignette 不只是工程師才要懂的 App 資訊安全:取得資安檢測合格證書血淚史(iT邦幫忙鐵人賽系列書) https://news.pchome.com.tw/living/books/20220202/index-64375841669874292009.html App防駭學,資安防護實戰課程全面提升安全觀念 https://www.ithome.com.tw/pr/161505 OSEP (Evasion Techniques and Breaching Defenses (PEN-300) 心得分享 https://hackmd.io/@henry-ko/HyQ56e8eF OSEP (Evasion Techniques and Breaching Defenses (PEN-300) http://github.com/In3x0rabl3/OSEP OSCP(Offensive Security Certified Professional) https://github.com/0x584A/oscp-notes/tree/master ISACA Certified Information Systems Auditor® (CISA) 國際電腦稽核師認證準備歷程心得、申請流程分享- 2023年 https://reurl.cc/aVLoX9 Learn NIST Inside Out With 21 Hours of Training @ 86% OFF https://thehackernews.com/2022/06/learn-nist-inside-out-with-21-hours-of.html 駭客與國家: 網路攻擊與地緣政治新常態 The hacker and the state: cyber attacks and the new normal of geopolitic https://reurl.cc/D3nKKj Practical Network Penetration Tester (PNPT) Certification Review https://tmc222.medium.com/practical-network-penetration-tester-pnpt-certification-review-4280e4e164df WUSON常用的基本詞彙 https://choson.lifenet.com.tw/?p=1958 證照仍是學習資安基本功的主要管道,有專家打造「資安證照地圖」 https://www.ithome.com.tw/news/156754 用證照證明自己實力之餘,更應將證照視為督促學習的最大動力 https://www.ithome.com.tw/news/156756 打破證照誤解與迷思,資安專家帶你釐清資安證照的意義 https://www.ithome.com.tw/news/156755 Accelerate Your Career with the Global Leader in Cyber Security Training https://www.sans.org/mlp/promo-partnership-hacker-news/ 【成大資安社社課】資安禁術 - 逆向工程地獄試煉 https://www.youtube.com/watch?v=4Yc3-9CjG6U 透過實務演練,教你建立實作標準的安全SOP流程 https://www.ithome.com.tw/pr/163514 6.近期資安活動及研討會 Advanced Scrum Case Study 2025/3/1 https://www.meetup.com/silicon-valley-professional-scrum-bangkok/events/ghffptyhcfbcb/ Saturday AI Hangout with Zack Lim 2025/3/1 https://www.meetup.com/internet-entrepreneurs-network-vietnam/events/305566598/ Secure Code Warrior 線上學資安 - March 2025 2025/3/1 https://www.accupass.com/event/2502250202101789190945 Foundations Info Session 2025/3/3 https://www.meetup.com/codechrysalis/events/306320190/ 數位詐騙攻防:資安實務專題講座(桃園場)2025/3/5 https://isipevent.kktix.cc/events/t0305165isip Taiwan Digital Night #202503 2025/3/6 https://www.meetup.com/taiwan-digital-nomads-hub-%E5%8F%B0%E7%81%A3%E6%95%B8%E4%BD%8D%E9%81%8A%E7%89%A7%E8%80%85%E7%A4%BE%E7%BE%A4/events/306415909/ Masterclass: Investing in AM Mega Trends & Companies with Dr. James Pu 2025/3/6 https://www.meetup.com/workoptional-ai-future-of-work/events/306253404/ Taiwan Robotics Meetup 2025/3/6 https://www.meetup.com/taipei-robotics-meetup-group/events/306097143/ AI 啟動低空經濟,引領未來移動革命 2025/3/6 https://www.accupass.com/event/2502110400191131615043 數位升級!教育訓練智慧解方 2025/3/6 https://www.accupass.com/event/2502190756452509777970 金融反詐 X AI深偽:資安實務專題講座(南部場) 2025/3/6 https://isipevent.kktix.cc/events/s165isip 數位詐騙攻防:資安實務專題講座(桃園場)2025/3/7 https://isipevent.kktix.cc/events/t0307165isip Web Development & Data bootcamps - 2025 Winter Batches 2025/3/7 https://www.meetup.com/le-wagon-tokyo-coding-station/events/306044283/ Atlassian x Canva社群分享會 Women Talk 數位創新管理經驗談 2025/3/8 https://www.meetup.com/taipei-atlassian-community-events/events/306188088/ Communication skills 2025/3/8 https://www.meetup.com/i-t-social-cafe/events/306393224/ Dart Programming Workshop for Mobile Developers 2025/3/8 https://www.meetup.com/ffdg-seoul/events/306342698/ Build an Enterprise RAG App Locally with DeepSeek-R1 & Ollama-No Cloud, No Cost! 2025/3/8 https://www.meetup.com/cloud-experts-group/events/306401417/ Coffee & Code 2025/3/8 https://www.meetup.com/innovate-taiwan/events/306339574/ 2025年資安教育免費線上課程 2025/3/11 https://acsiacad.kktix.cc/events/9fbd241c 迎戰AI時代 零信任重塑資安格局 2025/3/12 https://www.accupass.com/event/2502070639411668728700 How to Land a Software Engineering Job in 2025 2025/3/13 https://www.meetup.com/shanghai-startup-idea-to-ipo/events/306112008/ 從設計、開發到部署:AI 時代下的安全開發策略 2025/3/13 https://www.accupass.com/event/2501230205491979359914 數位時代的法律新思維:從市場競爭到科技監管 2025/3/13 https://www.accupass.com/event/2502190651501680073059 AWS Innovate Online Conference 2025/3/13 https://www.meetup.com/meetups-hk-science-park/events/306132116/ 2025 資安長零信任的第一堂課(三月場)2025/3/13 https://jamf.kktix.cc/events/applexjamf-2025march Rust Programming Meetup 2025/3/13 https://www.meetup.com/taipei-rust-users-group/events/306393950/ Microsoft Season of AI - Best of AI @ Ignite 2024 (Season 3) 2025/3/13 https://www.meetup.com/phinug/events/305836109/ Risk-based testing (RBT) of software: test safer, work smarter. 2025/3/13 https://www.meetup.com/qa-guild-by-mgm-vietnam/events/306413131/ Identities are the new passwords 2025/3/13 https://www.meetup.com/manageengine-hong-kong-events/events/306433229/ 打穩安全的根基:深入威脅建模與自動化測試實務 2025/3/13-2025/3/14 https://www.accupass.com/event/2412190125131865336269 Global AI Bootcamp 2025, Philippines 2025/3/15 https://www.meetup.com/cloud-experts-group/events/303711073/ Global AI Bootcamp - Taipei 2025 2025/3/15 https://www.meetup.com/rladies-taipei/events/305281979/ DEVCORE CONFERENCE 2025 2025/3/15 https://devcore.kktix.cc/events/devcoreconf2025 2025智慧城市展-中保科技論壇 2025/3/18 - 2025/3/20 https://www.accupass.com/event/2502260646281183236650 DevSecOps 革新:開創全面威脅檢測與快速響應的新時代 2025/3/19 https://www.accupass.com/event/2502030327553680337280 Taipei dbt Meetup #34 for all folks working with data! (Hybrid 👫 + 🧑💻)2025/3/19 https://www.meetup.com/taipei-dbt-meetup/events/306252998/ How to Build a Consulting Side Hustle with AI In One Weekend 2025/3/19 https://www.meetup.com/shanghai-startup-idea-to-ipo/events/306152486/ How to Build AI Skills For Your Career 2025/3/20 https://www.meetup.com/shanghai-startup-idea-to-ipo/events/306113277/ [Online] Philippine Bitcoin meetup 2025/3/20 https://www.meetup.com/philippine-bitcoiners/events/304057810/ Workshop: Building a Quiz App with Angular & TypeScript 2025/3/21 https://www.meetup.com/treelevel-io/events/306204363/ 『投資型詐騙-科技防禦最前線』論壇 2025/3/21 https://www.accupass.com/event/2502140610163598385850 OWASP Meetup 高雄線上 2025/3/21 https://csa.kktix.cc/events/owasp20250321-live OWASP Meetup 高雄實體 2025/3/21 https://csa.kktix.cc/events/owasp20250321 Lunch & Learn: Test Automation for Complete Beginners 2025/3/24 https://www.meetup.com/magicpod-community/events/306394705/ Chinese Linguistics, History, and Etymology 2025/3/25 https://www.meetup.com/formosa-technology-and-philosophy-symposium/events/305061650/ AI EXPO Taiwan 2025 2025/3/26 https://aiexpo2025.kktix.cc/events/aiexpo2025 企業 IT 必修課:虛擬化備援 + 弱點掃描,打造無縫資安防護 2025/4/11 https://mstech.kktix.cc/events/d41efa20
×
Sign in
Email
Password
Forgot password
or
By clicking below, you agree to our
terms of service
.
Sign in via Facebook
Sign in via Twitter
Sign in via GitHub
Sign in via Dropbox
Sign in with Wallet
Wallet (
)
Connect another wallet
New to HackMD?
Sign up