<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Sample Analysis on 思安录 | Thinking&#39;s Security Notes</title>
    <link>https://blog.1sec.day/en-gb/tags/sample-analysis/</link>
    <description>Recent content in Sample Analysis on 思安录 | Thinking&#39;s Security Notes</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-gb</language>
    <managingEditor>Thinking</managingEditor>
    <webMaster>Thinking</webMaster>
    <lastBuildDate>Wed, 15 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.1sec.day/en-gb/tags/sample-analysis/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Grok CLI Whole-Repo Upload Reverse Analysis: How a Single Prompt Ships Your .env to the Cloud</title>
      <link>https://blog.1sec.day/en-gb/posts/2026-07-15-grok-cli-codebase-exfiltration/</link>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2026-07-15-grok-cli-codebase-exfiltration/</guid>
      
      <description></description>
      
    </item>
    
    <item>
      <title>Telegram Desktop Local Session Reuse: a Reproduction That Should Not Have Happened</title>
      <link>https://blog.1sec.day/en-gb/posts/2026-07-15-telegram-desktop-local-session-reuse/</link>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2026-07-15-telegram-desktop-local-session-reuse/</guid>
      
      <description>&lt;blockquote&gt;
&lt;p&gt;The reproduction result exceeded what I understood to be possible. Telegram&amp;rsquo;s device authentication — phone verification, SMS code, 2FA password — seemed, to me, well-designed and complete. But when the tdata directory was copied to another Mac and the client launched, the login screen never appeared. This was not 2FA being cracked. The entire reuse path never entered a stage where credentials were requested.&lt;/p&gt;
&lt;/blockquote&gt;</description>
      
    </item>
    
    <item>
      <title>A Popular Solana Bot on GitHub Was a Wallet Thief: Supply Chain Attack Analysis</title>
      <link>https://blog.1sec.day/en-gb/posts/2025-07-03-solana-bot-supply-chain-attack/</link>
      <pubDate>Thu, 03 Jul 2025 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2025-07-03-solana-bot-supply-chain-attack/</guid>
      
      <description></description>
      
    </item>
    
    <item>
      <title>Osiris Malicious Browser Extension Analysis: Download Link Hijacking Disguised as a Security Tool</title>
      <link>https://blog.1sec.day/en-gb/posts/2025-05-28-osiris-malicious-extension/</link>
      <pubDate>Wed, 28 May 2025 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2025-05-28-osiris-malicious-extension/</guid>
      
      <description></description>
      
    </item>
    
    <item>
      <title>LinkedIn Recruitment Phishing Analysis: A Targeted Attack Against Blockchain Engineers</title>
      <link>https://blog.1sec.day/en-gb/posts/2025-03-15-linkedin-recruitment-phishing/</link>
      <pubDate>Sat, 15 Mar 2025 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2025-03-15-linkedin-recruitment-phishing/</guid>
      
      <description></description>
      
    </item>
    
    <item>
      <title>Solana Blockchain Mass Theft Analysis: Slope Wallet Sentry Leaks Mnemonic Phrases</title>
      <link>https://blog.1sec.day/en-gb/posts/2022-08-04-solana-massive-theft/</link>
      <pubDate>Thu, 04 Aug 2022 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2022-08-04-solana-massive-theft/</guid>
      
      <description></description>
      
    </item>
    
  </channel>
</rss>
