Aggregator
CVE-2009-4272 | Red Hat Enterprise Linux up to 4 locking (Nessus ID 44096 / ID 155737)
CVE-2003-1576 | Sun Change Manager 1.0 memory corruption (Nessus ID 23480 / XFDB-12132)
某211高校从一个文档到全校三要素泄露和RCE
CVE-2026-7009 | cURL up to 8.19.0 OCSP Stapling certificate validation (51905671e07f087e28e57)
CVE-2026-42377 | Brainstorm Force SureForms Pro Plugin up to 2.8.0 on WordPress authorization (EUVD-2026-26194)
Smartbi历史漏洞分析(一)——RMIServlet接口引发的惨案
CVE-2022-22807 | Schneider Electric EcoStruxure EV Charging Expert prior 4.0.0.13 Web Interface ui layer (SEVD-2022-039-02 / EUVD-2022-27950)
CVE-2022-22764 | Mozilla Firefox up to 96 memory corruption (EUVD-2022-27907 / Nessus ID 247449)
CVE-2022-22763 | Mozilla Thunderbird up to 91.5 Worker access control (Bug 1740534 / EUVD-2022-27906)
CVE-2022-22764 | Mozilla Thunderbird up to 91.5 memory corruption (EUVD-2022-27907 / Nessus ID 247449)
Peering into the Cloud: Decode Windows Defender’s MAPS Protocol with the MAPS Cloud Scanner
MAPS Cloud Scanner A research tool for interacting with Windows Defender’s MAPS (Microsoft Active Protection Service) cloud-based file reputation and
The post Peering into the Cloud: Decode Windows Defender’s MAPS Protocol with the MAPS Cloud Scanner appeared first on Penetration Testing Tools.
600 подписей против Пентагона, секретный контракт и запрет на автономное оружие. Google снова продала душу военным — или нет?
U.S. CISA adds Microsoft Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog
Supply Chain Fallout: LAPSUS$ Leaks 96GB of Stolen Checkmarx Data Following TeamPCP Breach
Checkmarx is grappling with a distressing sequel to its March security breach, as data exfiltrated from a private
The post Supply Chain Fallout: LAPSUS$ Leaks 96GB of Stolen Checkmarx Data Following TeamPCP Breach appeared first on Penetration Testing Tools.
苹果公司印度扩大生产受阻 难以独立运作
食肉细菌在三天内就破坏了男子的手臂和腿
The “Snow” Storm: How UNC6692 Uses Microsoft Teams and Email Bombing to Breach Corporate Fortresses
Corporate correspondence has once again emerged as a convenient portal for adversaries. In this nascent campaign, the assailants
The post The “Snow” Storm: How UNC6692 Uses Microsoft Teams and Email Bombing to Breach Corporate Fortresses appeared first on Penetration Testing Tools.
The Trojan Update: How “GlassWorm” Developers are Using Sleeper Extensions to Hijack Workspaces
The GlassWorm campaign has resurfaced within the developer community, though the adversaries have adopted a more surreptitious operational
The post The Trojan Update: How “GlassWorm” Developers are Using Sleeper Extensions to Hijack Workspaces appeared first on Penetration Testing Tools.
The Poisoned Pipeline: How a GitHub Actions Flaw Infiltrated the Popular “Elementary-Data” Library
The ubiquitous Python library elementary-data has emerged as a conduit for the exfiltration of sensitive developer telemetry. The
The post The Poisoned Pipeline: How a GitHub Actions Flaw Infiltrated the Popular “Elementary-Data” Library appeared first on Penetration Testing Tools.