| 2018-09-19 | When EL Injection meets Java Deserialization | re4lity | 2662 | |
| 2018-09-19 | Intercepting and Modifying responses with Chrome via the Devtools Protocol | re4lity | 2574 | |
| 2018-09-19 | A Tale of Two Bugs · Our Machinery | re4lity | 1934 | |
| 2018-09-19 | XSS Vulnerabilities in Multiple iFrame Busters Affecting Top Tier Sites | re4lity | 2338 | |
| 2018-09-19 | Peekaboo Critical Vulnerability in NUUO Network Video Recorder | re4lity | 1690 | |
| 2018-09-19 | Cheatsheet - Flask & Jinja2 SSTI | re4lity | 2864 | |
| 2018-09-19 | 碎碎念之Afl-fuzz Docker实践 | re4lity | 1979 | |
| 2018-09-14 | Android平台间谍软件BusyGasper分析 | birk | 10278 | |
| 2018-09-09 | 突破限制—一份安全编写和审计Chrome扩展程序的指南(下) | ginove | 2785 | |
| 2018-09-07 | 突破限制—一份安全编写和审计Chrome扩展程序的指南(上) | ginove | 1741 | |
| 2018-09-06 | 子域名劫持指南 | YSN | 4736 | |
| 2018-09-02 | 利用GIXY发现错误的Nginx配置 | ginove | 6373 | |
| 2018-09-02 | 技术报告:绕过工作流保护机制 - SharePoint远程代码执行 | ginove | 2363 | |