Aggregator
[webapps] LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Operator Surname
[webapps] LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Facebook Integration Page Name Field
[webapps] LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Personal Canned Messages
[webapps] LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via the Chat Transfer Function
[webapps] LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Department Assignment Alias Nick Field
[webapps] Pie Register WordPress Plugin 3.7.1.4 - Authentication Bypass to RCE
[webapps] Simple File List WordPress Plugin 4.2.2 - File Upload to RCE
Proactive Security and Insights for SharePoint Attacks (CVE-2025-53770 and CVE-2025-53771)
威努特助力银行网点实现高可靠性无线组网
Critical Flaw (CVE-2025-37103) in Aruba Instant On APs: Hardcoded Credentials Allow Full Admin Takeover – Patch Now!
Hewlett-Packard Enterprise has issued a critical security advisory concerning a severe vulnerability in Aruba Instant On access points. Embedded credentials have been discovered within the devices, enabling malicious actors to bypass standard authentication and...
The post Critical Flaw (CVE-2025-37103) in Aruba Instant On APs: Hardcoded Credentials Allow Full Admin Takeover – Patch Now! appeared first on Penetration Testing Tools.
npm Supply Chain Attack Exploited in the Wild – Phishing Steals Maintainer Tokens, Injects Malware into Popular Packages
Hackers have successfully injected malicious code into popular npm packages by leveraging a phishing campaign against project maintainers. The attackers orchestrated a targeted campaign aimed at developers stewarding key projects and managed to steal...
The post npm Supply Chain Attack Exploited in the Wild – Phishing Steals Maintainer Tokens, Injects Malware into Popular Packages appeared first on Penetration Testing Tools.
More From Our Main Blog: SharePoint ToolShell | Zero-Day Exploited in-the-Wild Targets Enterprise Servers
SentinelOne shares distinct attack clusters and a detailed timeline of events on an active exploit of the ToolShell 0-day in MS SharePoint.
The post SharePoint ToolShell | Zero-Day Exploited in-the-Wild Targets Enterprise Servers appeared first on SentinelOne.