Aggregator
当浏览器成为新的攻击面:从Scattered Spider攻击路径看防护的新思路
当浏览器成为新的攻击面:从Scattered Spider攻击路径看防护的新思路
From Deepfakes to Dark LLMs: 5 use-cases of how AI is Powering Cybercrime
Pennsylvania Attorney General’s Office Hit by Ransomware Attack
The Office of the Attorney General of Pennsylvania (OAG) has confirmed that it fell victim to a large-scale
The post Pennsylvania Attorney General’s Office Hit by Ransomware Attack appeared first on Penetration Testing Tools.
8,4 миллиона украли за час, 50,6 миллиона заморозили навсегда. Взлом парализовал DeFi-экосистему на пяти блокчейнах
Nucleus Insights turns CVE noise into an explainable threat signal
Nucleus Security introduced Nucleus Insights, AI-powered threat intelligence built to solve one of the most painful problems in vulnerability management: knowing which CVEs matter and why. Unlike traditional threat intelligence feeds made for SOCs and CTI teams, Nucleus Insights is built to automate and scale the day-to-day decisions vulnerability teams make. “Security leaders don’t need more tools; they need the right signal inside the workflows their teams already use,” said Steve Carter, CEO of Nucleus … More →
The post Nucleus Insights turns CVE noise into an explainable threat signal appeared first on Help Net Security.
CISA Warns of WhatsApp 0-Day Vulnerability Exploited in Attacks
CISA has issued an urgent advisory concerning a newly disclosed zero-day vulnerability in Meta Platforms’ WhatsApp messaging service (CVE-2025-55177). This flaw, categorized under CWE-863: Incorrect Authorization, allows an unauthorized actor to manipulate linked device synchronization messages and force a target device to fetch and process content from an attacker-controlled URL. Key Takeaways1. CVE-2025-55177 exploits a […]
The post CISA Warns of WhatsApp 0-Day Vulnerability Exploited in Attacks appeared first on Cyber Security News.
Silver Fox APT Exploits a Microsoft-Signed Driver to Bypass Security
The APT group Silver Fox has integrated a previously unknown vulnerable driver, WatchDog Antimalware, signed by Microsoft, into
The post Silver Fox APT Exploits a Microsoft-Signed Driver to Bypass Security appeared first on Penetration Testing Tools.
CVE-2025-21026 | Samsung Devices insufficient permissions or privileges
CVE-2025-21025 | Samsung Devices MARsExemptionManager access control
CVE-2025-21032 | Samsung Devices Kiosk Mode access control
Laravel’s Creator Warns Against Unnecessary Complexity
Taylor Otwell, the creator and long-standing steward of Laravel, has issued a cautionary note: the growing fascination with
The post Laravel’s Creator Warns Against Unnecessary Complexity appeared first on Penetration Testing Tools.