Aggregator
The Six-Week Window: New Report Finds 80% of Cyberattacks Begin Before CVE Disclosure
The GreyNoise team has uncovered a disquieting pattern: in 80% of cases, anomalous spikes in suspicious internet activity occur prior to the official disclosure of new vulnerabilities (CVEs). These are not coincidences or random...
The post The Six-Week Window: New Report Finds 80% of Cyberattacks Begin Before CVE Disclosure appeared first on Penetration Testing Tools.
CVE-2024-57914 | Linux Kernel up to 6.12.9/6.13-rc6 tcpci_irq null pointer dereference (WID-SEC-2025-0119)
CVE-2024-57916 | Linux Kernel up to 6.1.124/6.6.71/6.12.9/6.13-rc6 GPIO IRQ generic_handle_irq denial of service (Nessus ID 215144 / WID-SEC-2025-0119)
CVE-2024-57915 | Linux Kernel up to 6.1.124/6.6.71/6.12.9/6.13-rc6 u_serial null pointer dereference (Nessus ID 215144 / WID-SEC-2025-0119)
CVE-2024-57913 | Linux Kernel up to 6.1.124/6.6.71/6.12.9/6.13-rc6 usb_ffs_open_thread denial of service (Nessus ID 215144 / WID-SEC-2025-0119)
CVE-2024-57911 | Linux Kernel up to 6.1.124/6.6.71/6.12.9/6.13-rc6 iio_simply_dummy_buffer information disclosure (Nessus ID 215144 / WID-SEC-2025-0119)
CVE-2024-57912 | Linux Kernel up to 6.1.124/6.6.71/6.12.9/6.13-rc6 information disclosure (Nessus ID 215144 / WID-SEC-2025-0119)
国内最专业、最全面的 [ .NET 代码审计 ] 体系化视频学习课程
Sharp4WebCmd5:一键支持内存加载远程文件和无需依赖 cmd 执行命令
红队快速打包,通过 Sharp4CompressArchive 一键定制化压缩文件
Sharp4WebCmd5:一键支持内存加载远程文件和无需依赖 cmd 执行命令
国内最专业、最全面的 [ .NET 代码审计 ] 体系化视频学习课程
红队快速打包,通过 Sharp4CompressArchive 一键定制化压缩文件
CVE-2024-57910 | Linux Kernel up to 6.1.124/6.6.71/6.12.9/6.13-rc6 regmap_read information disclosure (Nessus ID 215144 / WID-SEC-2025-0119)
CVE-2024-57909 | Linux Kernel up to 6.12.9/6.13-rc6 iio_for_each_active_channel information disclosure (WID-SEC-2025-0119)
CVE-2024-57908 | Linux Kernel up to 6.1.124/6.6.71/6.12.9/6.13-rc6 iio_for_each_active_channel information disclosure (Nessus ID 215144 / WID-SEC-2025-0119)
TripleCross: Linux eBPF rootkit
TripleCross TripleCross is a Linux eBPF rootkit that demonstrates the offensive capabilities of the eBPF technology. TripleCross is inspired by previous implant designs in this area, notably the works of Jeff Dileo at DEFCON...
The post TripleCross: Linux eBPF rootkit appeared first on Penetration Testing Tools.
The ShinyHunters Salesforce Attack: Vishing & OAuth Abuse Blamed for Qantas, Allianz, LVMH Breaches
Threat actors operating under the name ShinyHunters have orchestrated a series of cyberattacks targeting major corporations, including Qantas, Allianz Life, LVMH, and Adidas. Each incident centers around attempts to infiltrate client Salesforce environments through...
The post The ShinyHunters Salesforce Attack: Vishing & OAuth Abuse Blamed for Qantas, Allianz, LVMH Breaches appeared first on Penetration Testing Tools.