Aggregator
CISA Warns: Critical AMI MegaRAC Firmware Flaw (CVE-2024-54085, CVSS 10.0) Actively Exploited for Server Takeover
Hackers have begun actively exploiting a critical vulnerability that grants them full control over thousands of servers, including those performing vital functions in data centers. This alarming development has prompted a warning from the...
The post CISA Warns: Critical AMI MegaRAC Firmware Flaw (CVE-2024-54085, CVSS 10.0) Actively Exploited for Server Takeover appeared first on Penetration Testing Tools.
CVE-2025-5526 | BuddyPress Docs Plugin up to 2.2.4 on WordPress Download File authorization
CVE-2025-5194 | WP Map Block Plugin up to 2.0.2 on WordPress Block Option cross site scripting
CVE-2025-5093 | Responsive Lightbox & Gallery Plugin up to 2.5.1 on WordPress Swipebox Library cross site scripting
CVE-2025-5035 | Firelight Lightbox Plugin up to 2.3.15 on WordPress cross site scripting
Mitsubishi Electric AC Flaw Lets Hackers Remotely Control Systems
A critical security vulnerability has been discovered in multiple Mitsubishi Electric air conditioning systems, potentially allowing hackers to bypass authentication and remotely control affected units. The flaw, identified as CVE-2025-3699, was disclosed by Mitsubishi Electric on June 26, 2025, and has been assigned a maximum CVSS base score of 9.8, indicating its severity. Authentication Bypass […]
The post Mitsubishi Electric AC Flaw Lets Hackers Remotely Control Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Windows 11 Retires Blue Screen of Death: New Black Crash Screen Focuses on Faster Diagnostics
Microsoft is preparing a significant overhaul of the infamous Blue Screen of Death (BSOD) in Windows. As part of the Windows Resiliency Initiative, the iconic blue error screen will be replaced by a new...
The post Windows 11 Retires Blue Screen of Death: New Black Crash Screen Focuses on Faster Diagnostics appeared first on Penetration Testing Tools.
Google DeepMind 发布 AlphaGenome
网友称相机电池没有3C标志被告知无法登机 事后发现是安检员理解问题
MOVEit Transfer Faces Increased Threats as Scanning Surges and CVE Flaws Are Targeted
MOVEit Transfer Faces Increased Threats as Scanning Surges and CVE Flaws Are Targeted
North Korean APT Launches Massive npm Supply Chain Attack: Typosquatting & Fake Jobs Steal Crypto from Devs
A new wave of malicious npm packages has been uncovered, linked to the ongoing Contagious Interview operation, which has been attributed to North Korean threat actors. The discovery was made by the cybersecurity firm...
The post North Korean APT Launches Massive npm Supply Chain Attack: Typosquatting & Fake Jobs Steal Crypto from Devs appeared first on Penetration Testing Tools.
ChainIQ遭网络攻击,影响UBS和KPMG等知名企业;IBM WebSphere高危RCE漏洞允许攻击者完全控制系统 |牛览
揭秘BAS安全数字罗盘:四大维度量化指标让你的防护看得见,说得清!
EvilConwi Unmasked: Hackers Weaponize Signed ConnectWise ScreenConnect Installers for Malware Deployment
A cybercriminal group has begun exploiting the popular ConnectWise ScreenConnect software to craft malware bearing a legitimate digital signature, thereby enabling the covert installation of remote access tools on victims’ devices. This alarming tactic...
The post EvilConwi Unmasked: Hackers Weaponize Signed ConnectWise ScreenConnect Installers for Malware Deployment appeared first on Penetration Testing Tools.
“OneClik” APT Unmasked: China-Linked Campaign Abuses Microsoft ClickOnce & AWS Cloud to Target Energy Sector
Cybercriminals have launched a large-scale campaign dubbed OneClik, targeting companies in the energy, oil, and gas sectors. The attack leverages Microsoft’s legitimate ClickOnce technology and a custom-designed backdoor known as RunnerBeacon, allowing threat actors...
The post “OneClik” APT Unmasked: China-Linked Campaign Abuses Microsoft ClickOnce & AWS Cloud to Target Energy Sector appeared first on Penetration Testing Tools.
French Police Bust BreachForums Organizers: “ShinyHunters,” “IntelBroker” & Others Arrested in Major Cybercrime Crackdown
The French police have carried out a sweeping operation targeting the organizers of the infamous cybercriminal forum BreachForums, which in recent years had become a major hub for the trafficking of stolen data. According...
The post French Police Bust BreachForums Organizers: “ShinyHunters,” “IntelBroker” & Others Arrested in Major Cybercrime Crackdown appeared first on Penetration Testing Tools.