Aggregator
CVE-2025-2339 | otale Tale Blog 2.0.5 /%61dmin/api/logs improper authentication
CVE-2025-2340 | otale Tale Blog 2.0.5 Site Settings /options/save saveOptions Site Title cross site scripting
CVE-2025-2337 | tbeu matio 1.5.28 src/mat.c Mat_VarPrint heap-based overflow (Issue 267 / EUVD-2025-6661)
微软公布量子安全计划路线图:2033 年全面量子安全,比政府要求提前两年
Hook v3: The Banking Trojan That’s Evolving into a Hybrid Ransomware-Spyware Threat
The Android mobile ecosystem has been struck by a new wave of threats driven by the evolution of the HOOK banking trojan. The latest iteration of this malicious program has gained an expanded arsenal...
The post Hook v3: The Banking Trojan That’s Evolving into a Hybrid Ransomware-Spyware Threat appeared first on Penetration Testing Tools.
CISA Adds Three Vulnerabilities to Catalog, Urges Immediate Patching
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. The list includes two flaws in Citrix Session Recording and one in Git, all...
The post CISA Adds Three Vulnerabilities to Catalog, Urges Immediate Patching appeared first on Penetration Testing Tools.
The Spy on the Network: How a Chinese APT Group Is Hijacking Wi-Fi to Target Diplomats
The Chinese group UNC6384 has launched a series of attacks against diplomats in Southeast Asia and several other countries, acting in the interests of Beijing. The campaign, observed by Google Threat Intelligence Group in...
The post The Spy on the Network: How a Chinese APT Group Is Hijacking Wi-Fi to Target Diplomats appeared first on Penetration Testing Tools.
CVE-2025-9533 | TOTOLINK T10 4.1.8cu.5241_B20210927 /formLoginAuth.htm authCode improper authentication
Submit #635941: TOTOLINK T10 T10_V4.1.8cu.5241_B20210927 Missing Authentication [Accepted]
CVE-2025-9532 | Portabilis i-Educar up to 2.10 /RegraAvaliacao/view ID sql injection
CVE-2025-9531 | Portabilis i-Educar up to 2.10 Agenda /intranet/agenda.php cod_agenda sql injection
Home Assistant + Ubiquiti + AI = Home Automation Magic
It seems like every manufacturer of anything electrical that goes in the house wants to be part of the IoT story these days. Further, they all want their own app, which means you have to go to gazillions of bespoke software products to control your things. And they're