Aggregator
CVE-2024-54534 | Apple visionOS Web memory corruption (Nessus ID 213685 / WID-SEC-2025-0815)
CVE-2024-47606 | GStreamer up to 1.24.9 qtdemux.c qtdemux_parse_theora_extension integer overflow (GHSL-2024-166 / Nessus ID 213029)
CVE-2024-8069 | Citrix Session Recording/Virtual Apps and Desktops deserialization (CTX691941 / WID-SEC-2024-3443)
CVE-2025-3478 | OpenText Enterprise Security Manager up to 7.8.1 cross site scripting (EUVD-2025-25704 / WID-SEC-2025-1904)
CVE-2024-8068 | Citrix Session Recording/Virtual Apps and Desktops privileges management (CTX691941 / EUVD-2024-49530)
CVE-2025-38079 | Linux Kernel up to 6.14.8 crypto algif_hash use after free (EUVD-2025-18574 / Nessus ID 241773)
Beyond Google Play: The End of Anonymous Sideloading Is Coming to Android
Openness has long been the defining distinction between Android and the iPhone, yet in recent years Google has steadily shifted the balance toward security. Now the company is preparing its most radical step yet...
The post Beyond Google Play: The End of Anonymous Sideloading Is Coming to Android appeared first on Penetration Testing Tools.
ESET warns of PromptLock, the first AI-driven ransomware
The Operating System That Changed Everything: Windows 95 Turns 30
On August 24, 2025, the world marked the 30th anniversary of Windows 95—Microsoft’s first truly mass-market 32-bit consumer operating system, a release that profoundly reshaped personal computing. In an era of limited home internet,...
The post The Operating System That Changed Everything: Windows 95 Turns 30 appeared first on Penetration Testing Tools.
Spyware Exposed: A Critical Unpatched Flaw in TheTruthSpy Puts Thousands at Risk
The creator of the spyware TheTruthSpy—the Vietnamese company 1Byte Software, led by Vanh (Vardi) Tiu—has once again found itself at the center of a major scandal. Independent security researcher Swarang Veid has uncovered a...
The post Spyware Exposed: A Critical Unpatched Flaw in TheTruthSpy Puts Thousands at Risk appeared first on Penetration Testing Tools.
New Data Theft Campaign Targets Salesforce via Salesloft App
New Cache Deception Attack Exploits Miscommunication Between Cache and Web Server
A newly documented cache deception attack leverages mismatches in path normalization and delimiter handling between caching layers and origin servers to expose sensitive endpoints and steal authentication tokens. Researchers have demonstrated how subtle discrepancies in URL processing can trick a content delivery network (CDN) into caching protected resources—only for an attacker to retrieve them later, […]
The post New Cache Deception Attack Exploits Miscommunication Between Cache and Web Server appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Auchan Suffers Another Data Breach, Exposing Customer Loyalty Data
The Auchan retail chain has fallen victim to a cyber incident targeting its customer loyalty program. This time, attackers gained access to the personal data of clients registered in the Waaoh loyalty scheme. Information...
The post Auchan Suffers Another Data Breach, Exposing Customer Loyalty Data appeared first on Penetration Testing Tools.
⼩旺AI截图 – 加⼊ DeepSeek 的 AI 截图、录屏⼯具,到底什么样?
GreyNoise Detects Massive Surge in RDP Web Access Probing: Prelude to Password Attacks?
GreyNoise has observed a sharp and highly atypical surge in reconnaissance activity targeting Microsoft Remote Desktop Web Access and the RDP Web Client: 1,971 unique IP addresses were active simultaneously, whereas the company typically...
The post GreyNoise Detects Massive Surge in RDP Web Access Probing: Prelude to Password Attacks? appeared first on Penetration Testing Tools.
父母指控 OpenAI 的 ChatGPT 杀死了他们的孩子
1200 операторов связи исключены из национальной сети за один день. Масштабная зачистка рынка телекоммуникаций против робозвонков
Invisible Prompts: A New Attack Uses Malicious Images to Hijack Gemini AI
A new study by specialists at The Trail of Bits has revealed a previously unknown vulnerability in the Google Gemini ecosystem and its associated services, enabling the covert exfiltration of user data through images...
The post Invisible Prompts: A New Attack Uses Malicious Images to Hijack Gemini AI appeared first on Penetration Testing Tools.
DOGE Allegedly Uploaded SSA’s Live Numident Database to Unsecured Cloud Server
The Government Accountability Project submitted a protected disclosure from Charles Borges—SSA’s Chief Data Officer—to the Office of Special Counsel and congressional oversight committees. Borges reports that since DOGE’s inception in January 2025, its officials have systematically circumvented SSA’s normal review procedures and a March 20, 2025 temporary restraining order forbidding external access to live Social […]
The post DOGE Allegedly Uploaded SSA’s Live Numident Database to Unsecured Cloud Server appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.