Aggregator
CVE-2026-28132 | villatheme WooCommerce Photo Reviews Plugin up to 1.4.4 on WordPress cross site scripting (EUVD-2026-8845)
CVE-2026-1695 | arcinfo PcVue up to 12.0.0/15.2.13/16.3.3 WebVue/WebScheduler/TouchVue/SnapVue client_id cross site scripting
CVE-2026-28136 | VeronaLabs WP SMS Plugin up to 6.9.12 on WordPress sql injection (EUVD-2026-8846)
CVE-2026-28131 | WPVibes Elementor Addon Elements Plugin up to 1.14.4 on WordPress insertion of sensitive information into sent data (EUVD-2026-8844)
CVE-2026-1694 | arcinfo PcVue up to 12.0.0/15.2.13/16.3.3 WebScheduler/TouchVue/SnapVue insertion of sensitive information into sent data
CVE-2026-1698 | arcinfo PcVue up to 15.2.13/16.3.3 HTTP Header /Authentication/Logout Host http headers for scripting syntax (EUVD-2026-8842)
CVE-2026-1692 | arcinfo PcVue up to 12.0.0/15.2.13/16.3.3 WebVue/WebScheduler/TouchVue/SnapVue connect missing origin validation in websockets
CVE-2026-1693 | arcinfo PcVue up to 12.0.0/15.2.13/16.3.3 WebVue/WebScheduler/TouchVue/Snapvue weak authentication
CISA mixup of IOC domains
Интернет защищён от перехвата маршрутов. Кроме случаев, когда DNS не защищён. А DNS не защищён почти везде
Global Cyber Agencies Urge Immediate Patching of Cisco SD-WAN Zero Day
Stealth & Control: Mastering Linux Post-Exploitation with the Eden-RAT GUI
Introduction Eden-RAT is a lightweight remote access tool (RAT) designed for the initial stage of penetration testing. It
The post Stealth & Control: Mastering Linux Post-Exploitation with the Eden-RAT GUI appeared first on Penetration Testing Tools.
The Rogue Peer Threat: CISA Issues Emergency Directive to Thwart Global Cisco SD-WAN Hijacking
The offensives targeting Cisco networking infrastructure have reached such a critical magnitude that United States authorities have invoked
The post The Rogue Peer Threat: CISA Issues Emergency Directive to Thwart Global Cisco SD-WAN Hijacking appeared first on Penetration Testing Tools.
The Chatbot Saboteur: How Claude Was Coerced into a 150GB Heist of Mexican State Intelligence
An unidentified adversary manipulated the Claude chatbot, developed by Anthropic, to orchestrate a series of surgical strikes against
The post The Chatbot Saboteur: How Claude Was Coerced into a 150GB Heist of Mexican State Intelligence appeared first on Penetration Testing Tools.
MicYou – 将 Android 手机变成电脑无线麦克风[跨平台]
CVE-2026-1565 | User Frontend Plugin up to 4.2.8 on WordPress Setting check_filetype_and_ext unrestricted upload
The Spreadsheet Spy: How a Decadelong Chinese Espionage Campaign Hijacked Google Sheets to Bypass Global Defenses
An international cyber-espionage campaign that languished in the shadows for a decade has abruptly surfaced across dozens of
The post The Spreadsheet Spy: How a Decadelong Chinese Espionage Campaign Hijacked Google Sheets to Bypass Global Defenses appeared first on Penetration Testing Tools.
Ghost in the Hull: How Ransomware is Paralyzing Global Fleets via Satellite and Shipboard Systems
Cyber offensives targeting maritime vessels have transcended the realm of rarity, increasingly precipitating tangible disruptions within global fleet
The post Ghost in the Hull: How Ransomware is Paralyzing Global Fleets via Satellite and Shipboard Systems appeared first on Penetration Testing Tools.
Mozilla Crushes 50+ Vulnerabilities in Massive Firefox 148 Security Overhaul
In the latest iteration of the Firefox browser, developers have mitigated dozens of critical vulnerabilities, many of which
The post Mozilla Crushes 50+ Vulnerabilities in Massive Firefox 148 Security Overhaul appeared first on Penetration Testing Tools.