Aggregator
朝鲜黑客将 BeaverTail 和 OtterCookie 合并成高级 JS 恶意软件
朝鲜黑客将 BeaverTail 和 OtterCookie 合并成高级 JS 恶意软件
Windows на Linux, как родная. Wine 10.17 вышел с обновлённым движком Mono и лучшей поддержкой старых программ
英伟达展示首块美制 Blackwell 芯片
英伟达展示首块美制 Blackwell 芯片
研究人员公布开源压缩工具7-Zip路径遍历漏洞的PoC 相关攻击可能很快就会增多
burpgpt: leverages the power of AI to detect security vulnerabilities
burpgpt burpgpt leverages the power of AI to detect security vulnerabilities that traditional scanners might miss. It sends
The post burpgpt: leverages the power of AI to detect security vulnerabilities appeared first on Penetration Testing Tools.
Trojan on npm: Fake Utility Package Used to Deliver a Cobalt Strike Clone
In October 2025, researchers at Kaspersky Lab uncovered a malicious package on the popular npm registry named https-proxy-utils,
The post Trojan on npm: Fake Utility Package Used to Deliver a Cobalt Strike Clone appeared first on Penetration Testing Tools.
Windows 11 Copilot Actions: The Power and Peril of AI Accessing Local Files
Microsoft has begun testing a new Copilot Actions feature in Windows 11. This experimental mode, available to Windows
The post Windows 11 Copilot Actions: The Power and Peril of AI Accessing Local Files appeared first on Penetration Testing Tools.
JVN: ETERNUS SF製品における不適切なファイルアクセス権設定の脆弱性
Training Solo: New Spectre-v2 Attack Bypasses Kernel and Hypervisor Defenses
Researchers at VUSec have unveiled Training Solo, a study that calls into question the very foundations of defenses
The post Training Solo: New Spectre-v2 Attack Bypasses Kernel and Hypervisor Defenses appeared first on Penetration Testing Tools.
Zero-Day Alert: Attackers Exploit New Flaw to Bypass CentreStack RCE Patch
Gladinet has released a security update for its enterprise CentreStack solution that remedies a local file inclusion (LFI)
The post Zero-Day Alert: Attackers Exploit New Flaw to Bypass CentreStack RCE Patch appeared first on Penetration Testing Tools.
Microsoft Revokes 200+ Certificates Used to Disguise Rhysida Ransomware
Microsoft has revoked more than two hundred digital certificates that had been exploited in attacks involving the Rhysida
The post Microsoft Revokes 200+ Certificates Used to Disguise Rhysida Ransomware appeared first on Penetration Testing Tools.
Dark Web Alert: Massive Data Leak from Russian SMS Aggregators Threatens Global Accounts
An advertisement has surfaced on the dark web offering three terabytes of data allegedly stolen from two major
The post Dark Web Alert: Massive Data Leak from Russian SMS Aggregators Threatens Global Accounts appeared first on Penetration Testing Tools.
新型后门程序针对俄罗斯企业发起攻击
新型后门程序针对俄罗斯企业发起攻击
Phishing Campaign Targets Master Passwords of Top Managers
In recent weeks, a surge of phishing campaigns has emerged in which attackers impersonate popular password managers —
The post Phishing Campaign Targets Master Passwords of Top Managers appeared first on Penetration Testing Tools.