Aggregator
CVE-2025-38520 | Linux Kernel up to 6.1.147/6.6.100/6.12.38/6.15.6 amdkfd exit_mmap deadlock (EUVD-2025-25078)
CVE-2025-38517 | Linux Kernel up to 6.12.38/6.15.6 alloc_tag_top_users initialization (EUVD-2025-25081)
The Patch Isn’t a Fix: New Flaw Lets Attackers Steal NTLM Hashes from Windows
Researchers at Cymulate Research Labs have disclosed a new vulnerability in Windows that allows attackers to bypass Microsoft’s recent patch and once again exfiltrate NTLM hashes without any user interaction. The flaw, tracked as...
The post The Patch Isn’t a Fix: New Flaw Lets Attackers Steal NTLM Hashes from Windows appeared first on Penetration Testing Tools.
Nested App Authentication: Microsoft’s New Feature Is a Double-Edged Sword for Azure Security
Microsoft has introduced a new mechanism known as Nested App Authentication (NAA), which is steadily becoming a key component of the company’s cloud ecosystem. The concept is straightforward: if a user has already signed...
The post Nested App Authentication: Microsoft’s New Feature Is a Double-Edged Sword for Azure Security appeared first on Penetration Testing Tools.
证据显示地球之水起源于彗星
医生救回几乎“身首离断”患者
Analyzing evolution of the PipeMagic malware
Не AirTag, а кое-что похуже. Почему скрытые GPS-трекеры гораздо опаснее, чем кажется.
《全球数据泄露态势月度报告》(2025年7月)| 附下载地址
CVE-2025-9151 | LiuYuYang01 ThriveX-Blog up to 3.1.7 web updateJsonValueByName improper authorization
Phrack是座丰碑
CVE-2025-9150 | Surbowl dormitory-management-php up to 9f1d9d1f528cabffc66fda3652c56ff327fda317 violation_add.php?id=2 ID sql injection
Submit #629873: LiuYuYang01 https://github.com/LiuYuYang01/ThriveX-Blog <=3.1.7 Incorrect Authorization [Accepted]
CVE-2025-9149 | Wavlink WL-NU516U1 M16U1_V240425 /cgi-bin/wireless.cgi sub_4032E4 Guest_ssid command injection
Submit #629618: github.com dormitory-management-php V1.0 SQL Injection [Accepted]
Submit #629181: Wavlink WL-NU516U1-A M16U1_V240425 Buffer Overflow [Accepted]
CVE-2025-9148 | CodePhiliaX Chat2DB up to 0.3.7 JDBC Connection DataSourceController.java sql injection
PipeMagic Malware Mimic as ChatGPT App Exploits Windows Vulnerability to Deploy Ransomware
A sophisticated malware campaign has been identified, utilizing PipeMagic, a highly modular backdoor deployed by the financially motivated threat actor Storm-2460. This advanced malware masquerades as a legitimate open-source ChatGPT Desktop Application while exploiting the zero-day vulnerability CVE-2025-29824 in Windows Common Log File System (CLFS) to deploy ransomware across multiple sectors globally. Key Takeaways1. PipeMagic […]
The post PipeMagic Malware Mimic as ChatGPT App Exploits Windows Vulnerability to Deploy Ransomware appeared first on Cyber Security News.