Aggregator
.NET 安全攻防知识交流社区
动态编译的攻防战:通过 .NET 临时文件实现跨站点路径遍历与敏感信息收集
SharePoint Under Siege: China-Linked Storm-2603 Unleashes Warlock Ransomware After Zero-Day Exploitation
The wave of attacks targeting vulnerabilities in Microsoft SharePoint continues to escalate, reaching levels of sophistication and scale not witnessed since the mass infections orchestrated by LockBit. According to Microsoft, the breaches are attributed...
The post SharePoint Under Siege: China-Linked Storm-2603 Unleashes Warlock Ransomware After Zero-Day Exploitation appeared first on Penetration Testing Tools.
围剿百万恶意文件:科技大厂“文件安全中心”建设实践
围剿百万恶意文件:科技大厂“文件安全中心”建设实践
特斯拉廉价 Model Y 减配内饰曝光;Firefox 终止中国账户运营;宇树王兴兴:经常偷懒,用 AI 写代码|极客早知道
特斯拉廉价 Model Y 减配内饰曝光;Firefox 终止中国账户运营;宇树王兴兴:经常偷懒,用 AI 写代码|极客早知道
New Android Banking Malware Targets Indian Banks: Steals Credentials, Intercepts OTPs via Fake Apps
Researchers at CYFIRMA have issued a warning about a new wave of cyberattacks leveraging malicious Android applications disguised as legitimate banking clients. These apps are designed to steal user credentials, intercept messages, and execute...
The post New Android Banking Malware Targets Indian Banks: Steals Credentials, Intercepts OTPs via Fake Apps appeared first on Penetration Testing Tools.
Unlocking the Power of Amazon Security Lake for Proactive Security
[webapps] Invision Community 4.7.20 - (calendar/view.php) SQL Injection
[webapps] XWiki 14 - SQL Injection via getdeleteddocuments.vm
[webapps] Mezzanine CMS 6.1.0 - Stored Cross Site Scripting (XSS)
[local] Linux PAM Environment - Variable Injection Local Privilege Escalation
[webapps] Adobe ColdFusion 2023.6 - Remote File Read
[dos] Xlight FTP 1.1 - Denial Of Service (DOS)
Revisiting UNC3886 Tactics to Defend Against Present Risk
行业安全实践:构建“数字烟草” 物流工控信息安全体系
ropr: blazing fast multithreaded ROP Gadget finder
ropr ropr is a blazing fast multithreaded ROP Gadget finder What is an ROP Gadget? ROP (Return Oriented Programming) Gadgets are small snippets of a few assembly instructions typically ending in a ret instruction which...
The post ropr: blazing fast multithreaded ROP Gadget finder appeared first on Penetration Testing Tools.
CastleLoader Unleashed: New Stealthy Malware Loader Leverages ClickFix & Fake GitHub for Widespread Infections
In the first half of 2025, researchers observed the active exploitation of a new malware loader known as CastleLoader. Since its emergence, this tool has become a central element in the distribution infrastructure for...
The post CastleLoader Unleashed: New Stealthy Malware Loader Leverages ClickFix & Fake GitHub for Widespread Infections appeared first on Penetration Testing Tools.