Aggregator
基于栈溢出的内核ROP利用分析与实践
CVE-2022-24302 | Paramiko up to 2.10.0 write_private_key_file information disclosure (EUVD-2022-0192)
house of botcake详细源码解析
Apache Tika XXE漏洞分析(CVE-2025-66516)
React 服务器组件原型链漏洞(CVE-2025-55182)最新POC分析(详细版)
小智ESP32管理平台代码审计分析
BugTrace-AI: The Comprehensive AI-Powered Suite for SAST, DAST, and Vulnerability Research
BugTrace-AI is a comprehensive web vulnerability analysis suite that leverages the power of Generative AI to assist developers,
The post BugTrace-AI: The Comprehensive AI-Powered Suite for SAST, DAST, and Vulnerability Research appeared first on Penetration Testing Tools.
记一次java项目的代码审计
Fastjson2 RCE 深度剖析:从黑名单绕过到双代理链利用
Ashen Lepus (WIRTE) Targets Middle East Governments with Stealthy AshTag Malware Toolkit
The Unit 42 team at Palo Alto Networks has documented a prolonged and low-visibility campaign targeting government bodies
The post Ashen Lepus (WIRTE) Targets Middle East Governments with Stealthy AshTag Malware Toolkit appeared first on Penetration Testing Tools.
Deep Leak: APT35 Hackers’ Payroll, Kashef Surveillance System, and 2004 Nuclear Spy Document Exposed
In the autumn of 2025, files began circulating in the public domain that are attributed to the Iranian
The post Deep Leak: APT35 Hackers’ Payroll, Kashef Surveillance System, and 2004 Nuclear Spy Document Exposed appeared first on Penetration Testing Tools.
Invisible Surveillance: Tool Exploits WhatsApp/Signal Network Latency to Track User Activity
A tool has been released into the public domain that enables covert monitoring of user activity on WhatsApp
The post Invisible Surveillance: Tool Exploits WhatsApp/Signal Network Latency to Track User Activity appeared first on Penetration Testing Tools.
记一次曲折的任意用户登陆导致信息泄露
量产「中国版 FSD」后,地平线为何公开高阶智驾的「灵魂代码」?
Apple Emergency Patch: Two WebKit Zero-Days Actively Exploited in Targeted iOS Attacks
Apple has released out-of-band patches addressing two zero-day vulnerabilities that were already being exploited in real-world attacks. The
The post Apple Emergency Patch: Two WebKit Zero-Days Actively Exploited in Targeted iOS Attacks appeared first on Penetration Testing Tools.
Geely Launches World’s Largest Safety Center in Ningbo, Targeting Zero Fatalities & Zero Data Leaks
Ningbo is a major port city on China’s eastern seaboard, a key industrial hub of Zhejiang Province and
The post Geely Launches World’s Largest Safety Center in Ningbo, Targeting Zero Fatalities & Zero Data Leaks appeared first on Penetration Testing Tools.
New Security Default: CERT-FR Urges Users to Fully Disable Wi-Fi When Not Active
If it already felt as though smartphone security advice had devolved into an endless catalogue of prohibitions, here
The post New Security Default: CERT-FR Urges Users to Fully Disable Wi-Fi When Not Active appeared first on Penetration Testing Tools.
利用数据流“清洗”大模型漏洞检测:LLMSAN 技术解析
Supply Chain Alert: MangaGamer Higurashi USB Installers Compromised with Possible Floxif Malware
MangaGamer has issued a warning about a potential supply-chain attack: in the latest print run of the physical
The post Supply Chain Alert: MangaGamer Higurashi USB Installers Compromised with Possible Floxif Malware appeared first on Penetration Testing Tools.