Aggregator
CVE-2005-2917 | Squid Proxy up to 2.5.STABLE10 NTLM Authentication denial of service (Nessus ID 20010 / ID 117736)
CVE-2005-2929 | ISC Lynx 2.8.5/2.8.6/2.8.6 Dev13 Lynx URI access control (Nessus ID 21872 / ID 117801)
CVE-2005-2938 | Apple itunes 4.7.1.30/5.0 ituneshelper.exe access control (Nessus ID 20219 / ID 38495)
CVE-2005-2931 | Ipswitch Ipswitch Collaboration Suite up to 8.19 SMTP Service memory corruption (Nessus ID 20319 / ID 74202)
CVE-2005-2993 | HP Tru64 4.0f/5.1b3 denial of service (Nessus ID 20803 / ID 27278)
CVE-2005-2978 | netpbm up to 10.24 memory corruption (Bug 168278 / Nessus ID 22744)
CVE-2005-2977 | PAM 0.80 on SELinux unix_chkpwd information disclosure (Bug 168180 / Nessus ID 21966)
CVE-2005-2996 | Veritas StorageCentral 5.2 Rev. 2190r DCOM Server stack-based overflow (VU#927793 / ID 38473)
CVE-2005-3001 | Sun Solaris 10.0 on SPARC/x86 tl Driver serializer_enter denial of service (Nessus ID 19746 / ID 115278)
CVE-2005-2996 | Veritas Storage Exec up to 5.3 rev 2190R DCOM Server stack-based overflow (VU#927793 / ID 38473)
CVE-2005-3015 | IBM Lotus Domino Enterprise Server 6.5.2 cross site scripting (Nessus ID 19764 / ID 12222)
CVE-2005-3054 | PHP 4.4.0 curl/gd information disclosure (Nessus ID 20624 / ID 12201)
RemoteMonologue: New Windows Technique Weaponizes DCOM for NTLM Credential Harvesting
RemoteMonologue is a Windows credential harvesting technique that enables remote user compromise by leveraging the Interactive User RunAs key and coercing NTLM authentications via DCOM. Features 🔹 Authentication Coercion via DCOM (-dcom) Targets three DCOM...
The post RemoteMonologue: New Windows Technique Weaponizes DCOM for NTLM Credential Harvesting appeared first on Penetration Testing Tools.
Week in review: Backdoor found in SOHO devices running Linux, high-risk WinRAR RCE flaw patched
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Stealthy backdoor found hiding in SOHO devices running Linux SecurityScorecard’s STRIKE team has uncovered a network of compromised small office and home office (SOHO) devices they’re calling LapDogs. High-risk WinRAR RCE vulnerability patched, update quickly! (CVE-2025-6218) A recently patched directory traversal vulnerability (CVE-2025-6218) in WinRAR could be leveraged by remote attackers to execute arbitrary code on affected installations. Breaking the … More →
The post Week in review: Backdoor found in SOHO devices running Linux, high-risk WinRAR RCE flaw patched appeared first on Help Net Security.
“LapDogs” Unmasked: China-Linked Actors Build Covert ORB Network on 1,000+ SOHO Devices for Espionage
In a sweeping espionage campaign dubbed LapDogs, over a thousand small office and home office devices were compromised. Researchers from the STRIKE team at SecurityScorecard reported that the attack was linked to Chinese threat...
The post “LapDogs” Unmasked: China-Linked Actors Build Covert ORB Network on 1,000+ SOHO Devices for Espionage appeared first on Penetration Testing Tools.
CISA, FBI, NSA Urge Software Industry: Adopt Memory-Safe Languages to Drastically Cut Vulnerabilities
The leading cybersecurity agencies in the United States—CISA and the NSA—have issued a joint report urging software developers to adopt so-called memory-safe programming languages. These are technologies inherently designed to protect against critical memory-related...
The post CISA, FBI, NSA Urge Software Industry: Adopt Memory-Safe Languages to Drastically Cut Vulnerabilities appeared first on Penetration Testing Tools.
Linux Gains “Tyr”: New Rust-Written Graphics Driver for Arm Mali GPUs Unveiled
On Friday evening, a surprising announcement introduced Tyr—a new graphics driver for the Linux kernel, written in Rust. Designed to support modern Arm Mali GPUs, the driver interfaces with the Direct Rendering Manager. Despite...
The post Linux Gains “Tyr”: New Rust-Written Graphics Driver for Arm Mali GPUs Unveiled appeared first on Penetration Testing Tools.
Windows 11 24H2 Preview (KB5060829) Unveils Seamless PC Migration & Taskbar Improvements
Microsoft has released the preview update KB5060829 for Windows 11 version 24H2, encompassing 38 technical enhancements, including refinements to the taskbar and a new tool for seamless data migration between devices. Classified as an...
The post Windows 11 24H2 Preview (KB5060829) Unveils Seamless PC Migration & Taskbar Improvements appeared first on Penetration Testing Tools.
African Financial Institutions Targeted: “CL-CRI-1014” IAB Uses Open-Source Tools & Forged Signatures for Covert Access
For nearly a year, a hacker collective has been orchestrating a large-scale campaign targeting the financial sector across Africa. Experts from Unit 42 at Palo Alto Networks have sounded the alarm, tracking this operation...
The post African Financial Institutions Targeted: “CL-CRI-1014” IAB Uses Open-Source Tools & Forged Signatures for Covert Access appeared first on Penetration Testing Tools.