Aggregator
CVE-2025-47696 | Blog Designer Pro Plugin up to 3.4.7 on WordPress file inclusion (EUVD-2025-26283)
Critical Flaw in VS Code Marketplace Puts Developers at Risk
Experts at ReversingLabs have uncovered a critical loophole in the VS Code Marketplace. The platform allows new extensions
The post Critical Flaw in VS Code Marketplace Puts Developers at Risk appeared first on Penetration Testing Tools.
FBI and Dutch Police Take Down Major Fake ID Marketplace
The FBI and Dutch police have conducted a joint operation that shut down VerifTools, a major online marketplace
The post FBI and Dutch Police Take Down Major Fake ID Marketplace appeared first on Penetration Testing Tools.
CVE-2022-1437 | radare2 up to 5.6.x heap-based overflow (Nessus ID 259380)
CVE-2017-13756 | The Sleuth Kit 4.4.2 tsk/vs/dos.c dos_load_ext_table memory corruption (Issue 914 / Nessus ID 259382)
CVE-2022-4729 | Graphite Web Template Name cross site scripting (Issue 2745 / Nessus ID 259381)
CVE-2019-16217 | WordPress up to 5.2.2 Media Upload wp_ajax_upload_attachment cross site scripting (Bug 45936 / Nessus ID 259385)
CVE-2022-38153 | wolfSSL 5.3.0 TLS denial of service (Nessus ID 259384)
CVE-2018-16870 | wolfSSL up to 3.15.6 TLS Bleichenbacher cryptographic issues (Nessus ID 259386)
CVE-2025-46416 | NixOS Nix up to 2.24.15/2.26.4/2.28.4/2.29.1 improper ownership management (EUVD-2025-19410 / Nessus ID 259387)
CVE-2020-29529 | Hashicorp go-slug up to 0.4.x pathname traversal (Nessus ID 259389)
CVE-2023-0756 | GitLab Name privilege escalation (Issue 390910 / EUVD-2023-12774)
CVE-2019-15726 | GitLab Community Edition/Enterprise Edition up to 12.2.1 Markdown IP address information disclosure (ID 55115 / Nessus ID 259390)
BetterBank DeFi Protocol Hacked for Millions on PulseChain
The BetterBank project, which positions itself as a decentralized banking protocol on PulseChain, suffered an exploit in which an attacker siphoned assets valued between $1 and $5 million. The root cause was a vulnerability...
The post BetterBank DeFi Protocol Hacked for Millions on PulseChain appeared first on Penetration Testing Tools.
The Silent Threat: Why Your AI Browser Agent Can’t Be Trusted
Anthropic has issued a warning about a new threat emerging alongside “smart” browser extensions — websites may discreetly inject hidden commands, which an AI agent could execute without hesitation. The company unveiled a research...
The post The Silent Threat: Why Your AI Browser Agent Can’t Be Trusted appeared first on Penetration Testing Tools.
Ransomware: To Pay or Not to Pay? A New Study Explores the True Cost
A researcher from the University of Texas at Dallas has proposed viewing the fight against ransomware not solely through the lens of technology, but also through political intervention. Atanu Lahiri, Professor of Information Systems,...
The post Ransomware: To Pay or Not to Pay? A New Study Explores the True Cost appeared first on Penetration Testing Tools.