Aggregator
CVE-2025-8739 | zhenfeng13 My-Blog up to 1.0.0 /admin/tags/save tagName cross-site request forgery (Issue 145 / EUVD-2025-24019)
CVE-2024-32106 | WP Compress Plugin up to 6.10.35 on WordPress cross-site request forgery
Sinobi
You must login to view this content
appshark: scan vulnerabilities in an Android app
AppShark Appshark is a static analysis tool for Android apps. Its goal is to analyze very large apps (Douyin currently has 1.5 million methods). Appshark supports the following features: JSON-based customized scanning rules to...
The post appshark: scan vulnerabilities in an Android app appeared first on Penetration Testing Tools.
Everest
You must login to view this content
李想:知道哪个品牌在黑理想;比亚迪:微信宣布加强治理财经领域「自媒体」违规行为;世界机器人大会开幕 | 极客早知道
李想:知道哪个品牌在黑理想;比亚迪:微信宣布加强治理财经领域「自媒体」违规行为;世界机器人大会开幕 | 极客早知道
永安在线金融行业案例
银行反洗钱方案案例 银行黄牛攻防系统搭建方案案例 银行反营销欺诈解决方案 保险业务安全建设方案案例 保险营销反欺诈方案案例 保险营销发欺诈方案案例 证券反欺诈解决方案案例 证券数据资产泄露解决方案
永安在线金融行业案例
Safepay
You must login to view this content
Supply Chain Alert: Malicious Go Packages Found Targeting Windows and Linux
Cybersecurity researchers have uncovered 11 malicious Go packages designed to download additional components from remote servers and execute them on both Windows and Linux systems. According to Socket researcher Olivia Brown, during execution the...
The post Supply Chain Alert: Malicious Go Packages Found Targeting Windows and Linux appeared first on Penetration Testing Tools.
Lynx
You must login to view this content
法航荷航遭袭泄露客户资料,谷歌成为网络攻击受害者|一周特辑
容器安全 小佑科技 云原生安全防护平台产品介绍
CastleBot Malware-as-a-Service Deploys Range of Payloads Linked to Ransomware Attacks
A sophisticated new malware framework named CastleBot has emerged as a significant threat to cybersecurity, operating as a Malware-as-a-Service (MaaS) platform that enables cybercriminals to deploy diverse malicious payloads ranging from infostealers to backdoors linked to ransomware attacks. First appearing in early 2025, the malware has demonstrated remarkable adaptability and technical sophistication, with activity levels […]
The post CastleBot Malware-as-a-Service Deploys Range of Payloads Linked to Ransomware Attacks appeared first on Cyber Security News.
DARPA announces $4 million winner of AI code review competition at DEF CON
Your Code Is Not Safe: Malicious NPM Packages Are Deleting Files
Two malicious packages have been discovered in the NPM ecosystem, disguised as libraries for building bots and automated services using the WhatsApp Business API. Identified by researchers at Socket, these modules mimicked popular WhatsApp...
The post Your Code Is Not Safe: Malicious NPM Packages Are Deleting Files appeared first on Penetration Testing Tools.
DARPA’s AI Cyber Challenge reveals winning models for automated vulnerability discovery and patching
The initiative seeks to patch vulnerabilities in open-source code before they are exploited by would-be attackers. Now comes the hard part — putting the systems to the test in the real world.
The post DARPA’s AI Cyber Challenge reveals winning models for automated vulnerability discovery and patching appeared first on CyberScoop.