Aggregator
CVE-2025-9154 | itsourcecode Online Tour and Travel Management System 1.0 /user/page-login.php email sql injection
CVE-2025-9153 | itsourcecode Online Tour and Travel Management System 1.0 travellers.php photo unrestricted upload
雷神众测漏洞周报2025.8.11-2025.8.17
Submit #630274: itsourcecode Sports Management System V1.0 SQL injection [Accepted]
Submit #630214: 1000 Projects daily college class work report book php v1.0 SQL Injection [Duplicate]
CVE-2025-41689 | Wiesemann & Theis Motherbox 3 up to 1.48 missing authentication (VDE-2025-067)
CVE-2025-41685 | SMA ennexos.sunnyportal.com prior 15.08.2025 Email Address exposure of private personal information to an unauthorized actor (VDE-2025-050)
Submit #630202: itsourcecode Online Tour and Travel Management System V1.0 SQL injection [Accepted]
Submit #630201: itsourcecode Online Tour and Travel Management System V1.0 SQL injection [Accepted]
Submit #630200: itsourcecode Online Tour and Travel Management System V1.0 Unrestricted Upload [Accepted]
CVE-2025-38366 | Linux Kernel up to 6.15.4/6.16-rc3 LoongArch num_cpu privilege escalation (Nessus ID 251310 / WID-SEC-2025-1653)
Обычная камера у подъезда — у вас лотерея на ошибочный арест. Угадайте, где вас задержат
The need for speed: Why organizations are turning to rapid, trustworthy MDR
Python 供应链风险:termncolor 和 colorinal 解析
Australian ISP iiNet Suffers Breach of 280,000+ Records
银狐木马变种难防?天擎“六合”引擎默认内存查杀
New ClickFix Attack Uses Fake BBC News Page and Fraudulent Cloudflare Verification to Trick Users
A sophisticated new cyberthreat campaign has emerged that combines impersonation of trusted news sources with deceptive security verification prompts to trick users into executing malicious commands on their systems. According to a Reddit post, the ClickFix attack masquerades as legitimate BBC news content while employing fake Cloudflare verification screens to deliver malware. How the Attack Works The […]
The post New ClickFix Attack Uses Fake BBC News Page and Fraudulent Cloudflare Verification to Trick Users appeared first on Cyber Security News.
DOJ Seizes $2.8 Million in Crypto from Suspected Zeppelin Ransomware Operator
The U.S. Department of Justice has announced the seizure of more than $2.8 million in cryptocurrency from Yanis Alexandrovich Antroppenko, who stands accused of computer fraud and money laundering. Antroppenko is linked to the...
The post DOJ Seizes $2.8 Million in Crypto from Suspected Zeppelin Ransomware Operator appeared first on Penetration Testing Tools.
Leaked Source Code Exposes ERMAC 3.0: A Dangerous Trojan with Flawed Security
Researchers at Hunt.io have published an in-depth analysis of the Android banking trojan ERMAC 3.0, uncovering not only its enhanced capabilities but also severe flaws within its infrastructure. This iteration expands upon the functionality...
The post Leaked Source Code Exposes ERMAC 3.0: A Dangerous Trojan with Flawed Security appeared first on Penetration Testing Tools.