Aggregator
麦当劳 AI 招聘平台曝 IDOR 漏洞,致全美 6400 万求职数据泄露
麦当劳 AI 招聘平台曝 IDOR 漏洞,致全美 6400 万求职数据泄露
CVE-2009-3152 | NT BBS E-Market cross site scripting (EDB-33130 / XFDB-52157)
Google Gemini for Workspace Vulnerability Lets Attackers Hide Malicious Scripts in Emails
Security researchers have uncovered a significant vulnerability in Google Gemini for Workspace that enables threat actors to embed hidden malicious instructions within emails. The attack exploits the AI assistant’s “Summarize this email” feature to display fabricated security warnings that appear to originate from Google itself, potentially leading to credential theft and social engineering attacks. Key […]
The post Google Gemini for Workspace Vulnerability Lets Attackers Hide Malicious Scripts in Emails appeared first on Cyber Security News.
俄籍数据贩子公然在 Telegram 贩卖个人信息,遭印尼引渡回国
俄籍数据贩子公然在 Telegram 贩卖个人信息,遭印尼引渡回国
ISC Stormcast For Monday, July 14th, 2025 https://isc.sans.edu/podcastdetail/9524, (Mon, Jul 14th)
CVE-2009-0882 | Roman Bogorodskiy nForum 1.5 showtheme.php sql injection (EDB-8170 / BID-34030)
Adobe PDF 阅读器和华硕系统控制器中发现重大安全漏洞
Adobe PDF 阅读器和华硕系统控制器中发现重大安全漏洞
JS漏洞挖掘|分享使用FindSomething联动的挖掘思路
JS漏洞挖掘|分享使用FindSomething联动的挖掘思路
INC 勒索组织再袭美政府!阿拉巴马州 50GB 市政数据遭劫持
INC 勒索组织再袭美政府!阿拉巴马州 50GB 市政数据遭劫持
GrapheneOS Under Scrutiny: Why Privacy-Focused Pixels Are Raising Police Suspicions
Spanish police have begun casting a wary eye on users of Google Pixel smartphones, suspecting potential ties to criminal activity. In Catalonia, law enforcement officials report a growing trend of drug traffickers relying specifically...
The post GrapheneOS Under Scrutiny: Why Privacy-Focused Pixels Are Raising Police Suspicions appeared first on Penetration Testing Tools.
Nippon Steel Hit by Zero-Day Cyberattack, Exposing Data of 100K+ Employees & Partners
One of the world’s largest steel manufacturing conglomerates, the Japanese company Nippon Steel, has reported a large-scale cyberattack during which hackers gained unauthorized access to data belonging to clients, employees, and business partners. The...
The post Nippon Steel Hit by Zero-Day Cyberattack, Exposing Data of 100K+ Employees & Partners appeared first on Penetration Testing Tools.
What's the next step? Reverse Engineering a TP-Link router for vulnerabilities.
Critical Wing FTP Server Flaw (CVSS 10.0) Under Active Exploitation: Patch Now!
Researchers at Huntress have observed active exploitation of a critical vulnerability in Wing FTP Server—a mere day after its public disclosure. The flaw, tracked as CVE-2025-47812, received the highest possible severity rating (CVSS 10.0),...
The post Critical Wing FTP Server Flaw (CVSS 10.0) Under Active Exploitation: Patch Now! appeared first on Penetration Testing Tools.