Aggregator
域渗透-Delegation
China-Nexus Hackers Actively Exploiting React2Shell Vulnerability (CVE-2025-55182) in the Wild
China-nexus threat groups are racing to weaponize the new React2Shell bug, tracked as CVE-2025-55182, only hours after its public disclosure. The flaw sits in React Server Components and lets an attacker run code on the server without logging in. Early scans show broad probing of internet-facing React and Next[.]js apps, with a focus on high-value […]
The post China-Nexus Hackers Actively Exploiting React2Shell Vulnerability (CVE-2025-55182) in the Wild appeared first on Cyber Security News.
Space Bears
You must login to view this content
BlackHat MEA CTF Final 2025
Date: Dec. 2, 2025, 8 a.m. — 04 Dec. 2025, 15:00 UTC [add to calendar]
Format: Jeopardy
On-site
Location: Riyadh
Offical URL: https://blackhatmea.com/capture-the-flag
Rating weight: 22.50
Event organizers: SAFCSP
安卓电视 YouTube 客户端 SmartTube 遭入侵 恶意更新强制推送
安卓电视平台的开源YouTube客户端SmartTube已确认遭入侵——攻击者获取开发者的数字签名密钥后,向用户推送了包含恶意代码的更新包。
此次安全事件由多名用户反馈发现:安卓内置杀毒模块Google Play Protect在部分设备上拦截了SmartTube,并向用户发出安全风险警示。
SmartTube开发者证实,其数字签名密钥于上周末被盗,导致恶意软件被注入应用程序。目前已吊销旧签名,并表示将尽快发布采用独立应用ID的新版本,同时敦促用户升级至该安全版本。
作为安卓电视、Fire TV、安卓电视盒等设备上下载量最高的第三方YouTube客户端之一,SmartTube的流行源于其免费属性、广告拦截功能,以及在低性能设备上的流畅运行表现。
一名逆向工程师对遭入侵的30.51版本进行分析后发现,该版本包含一个名为libalphasdk.so的隐藏原生库([病毒总数平台检测链接])。由于该库未出现在公开源代码中,推测是在发布构建过程中被恶意注入。
开发者表示:“这很可能是一款恶意软件。该文件并非所使用SDK的组成部分,其出现在APK安装包中完全出乎意料且存在高度可疑性。在核实其来源前,建议用户保持警惕。”
经分析,该恶意库会在后台静默运行,无需用户交互即可完成设备指纹采集、向远程服务器注册设备,并通过加密通信通道定期发送设备指标数据及获取配置指令。尽管目前尚未发现账号盗窃、参与DDoS僵尸网络等恶意行为,但攻击者可随时利用该模块发起此类攻击,潜在风险极高。
尽管开发者已在Telegram宣布发布安全测试版及稳定测试版,但这些版本尚未同步至项目官方GitHub仓库。此外,开发者未披露事件完整细节,引发用户信任危机。SmartTube表示,待新版应用正式上架F-Droid应用商店后,将全面回应所有关问题。
在开发者通过详细事后分析报告公开披露全部事件细节前,安全专家建议用户:保持使用经验证安全的旧版本、避免登录高级账户、关闭自动更新功能;受影响用户应重置Google账户密码,检查账户控制台是否存在未授权访问记录,并移除陌生关联服务。
为确保完全安全,SmartTube已从30.55版本起已切换至新签名密钥。30.47 Stable v7a版本出现不同哈希值,可能是在清理受感染系统后尝试恢复该版本所致。
Богатые тоже глохнут. Новый признак статуса в Нью-Йорке — слуховой аппарат по цене «Жигулей»
ChromeAlone: Stealthy Browser Implant Steals Sessions and Phishes for YubiKeys
ChromeAlone is a browser implant that can be used in place of conventional implants like Cobalt Strike or
The post ChromeAlone: Stealthy Browser Implant Steals Sessions and Phishes for YubiKeys appeared first on Penetration Testing Tools.
GoldFactory Malware Injects FriHook/SkyHook into Banking Apps to Exploit 11K SE Asia Users
The GoldFactory group has launched a new wave of attacks targeting mobile-banking users across Southeast Asia. Disguising themselves
The post GoldFactory Malware Injects FriHook/SkyHook into Banking Apps to Exploit 11K SE Asia Users appeared first on Penetration Testing Tools.
Record DDoS Attack: Cloudflare Mitigates Massive 29.7 Tbps Assault from AISURU Botnet
The scale of DDoS attacks continues to surge at a breathtaking pace, and effective protection is increasingly defined
The post Record DDoS Attack: Cloudflare Mitigates Massive 29.7 Tbps Assault from AISURU Botnet appeared first on Penetration Testing Tools.
Australia Enforces Nationwide Social Media Ban for Under-16s; YouTube & Lemon8 React
Australia is preparing to enforce a nationwide ban on social media use by teenagers under 16, and major
The post Australia Enforces Nationwide Social Media Ban for Under-16s; YouTube & Lemon8 React appeared first on Penetration Testing Tools.
黑客篡改版银行应用袭击东南亚,超 1.1 万设备遭感染
Microsoft Finally Patches LNK Flaw (CVE-2025-9491) Exploited by Spies Since 2017
Microsoft has quietly patched a long-standing flaw in Windows that had been exploited in real-world attacks for several
The post Microsoft Finally Patches LNK Flaw (CVE-2025-9491) Exploited by Spies Since 2017 appeared first on Penetration Testing Tools.
美国两男子入侵联邦数据库并删除敏感档案
Securus Trains AI on Years of Inmate Calls to Detect ‘Intent’ for Criminal Activity
The American telecommunications firm Securus Technologies has trained a new AI model on years’ worth of recorded prison
The post Securus Trains AI on Years of Inmate Calls to Detect ‘Intent’ for Criminal Activity appeared first on Penetration Testing Tools.
Policy U-Turn: India Drops Mandatory Sanchar Saathi App After Privacy Backlash
Indian authorities have abandoned plans to compel smartphone manufacturers to pre-install the state-run “cybersecurity” application Sanchar Saathi on
The post Policy U-Turn: India Drops Mandatory Sanchar Saathi App After Privacy Backlash appeared first on Penetration Testing Tools.
PoC Exploit Released for Critical React, Next.js RCE Vulnerability (CVE-2025-55182)
A proof-of-concept (PoC) exploit for CVE-2025-55182, a maximum-severity remote code execution (RCE) flaw in React Server Components, surfaced publicly this week, heightening alarms for developers worldwide. Dubbed “React2Shell” by some researchers, the vulnerability carries a CVSS score of 10.0 and affects React versions 19.0.0 through 19.2.0, as well as Next.js 15.x and 16.x using App […]
The post PoC Exploit Released for Critical React, Next.js RCE Vulnerability (CVE-2025-55182) appeared first on Cyber Security News.
雇佣军间谍软件利用 iOS 零日漏洞攻击链实施设备监听
OpenAI ‘Garlic’ LLM: Secret Model Reportedly Beats Gemini 3 in Coding/Reasoning
Microsoft (MSFT) and its partner OpenAI are developing a new large-scale language model, Garlic, designed to strengthen the
The post OpenAI ‘Garlic’ LLM: Secret Model Reportedly Beats Gemini 3 in Coding/Reasoning appeared first on Penetration Testing Tools.
Linux 6.18 LTS: Rust-Based Android Binder Lands as bcachefs is Removed from Mainline
Linux 6.18 is the final major release of 2025, and it is highly likely to become the next
The post Linux 6.18 LTS: Rust-Based Android Binder Lands as bcachefs is Removed from Mainline appeared first on Penetration Testing Tools.