Aggregator
CVE-2025-44962 | Ruckus Virtual SmartZone/Network Director path traversal
CVE-2025-44954 | Ruckus Virtual SmartZone/Network Director SSH default key
CVE-2025-44960 | Ruckus Virtual SmartZone/Network Director API Route os command injection
CVE-2025-44963 | Ruckus Virtual SmartZone/Network Director JWT Token hard-coded key
CVE-2025-44958 | Ruckus Virtual SmartZone/Network Director storing passwords in a recoverable format
CVE-2025-8517 | givanz Vvveb 1.0.6.1 session fixiation (Issue 312)
Critical Squid Flaw Allows Remote Code Execution & Data Leakage
A critical vulnerability has been discovered in the Squid proxy server, enabling remote execution of arbitrary code. The flaw affects nearly all actively used versions, and given the widespread deployment of Squid, millions of...
The post Critical Squid Flaw Allows Remote Code Execution & Data Leakage appeared first on Penetration Testing Tools.
Lazarus Group’s Covert Supply Chain Attack: North Korean APT Poisons Open Source to Steal Developer Secrets
In the first half of 2025, Sonatype uncovered a large-scale, ongoing assault on the open-source software ecosystem, orchestrated by the North Korean threat actor known as Lazarus. Sonatype’s automated malware detection systems were the...
The post Lazarus Group’s Covert Supply Chain Attack: North Korean APT Poisons Open Source to Steal Developer Secrets appeared first on Penetration Testing Tools.
2025年中漏洞态势研究报告
PlayPraetor: New Android RAT Infects 11,000+ Devices with Real-Time On-Device Fraud
A new large-scale threat has emerged on the Android horizon, dubbed PlayPraetor—a sophisticated piece of malware capable of seizing full control over compromised devices. To date, over 11,000 devices have fallen under its sway,...
The post PlayPraetor: New Android RAT Infects 11,000+ Devices with Real-Time On-Device Fraud appeared first on Penetration Testing Tools.
Luxembourg Hit by “Sophisticated” Cyberattack: Huawei Equipment Targeted, Mobile Networks Down for Hours
The government of Luxembourg has launched an official investigation into an unprecedented disruption of the national telecommunications system that occurred on July 23. The cause of the outage, which left 4G and 5G mobile...
The post Luxembourg Hit by “Sophisticated” Cyberattack: Huawei Equipment Targeted, Mobile Networks Down for Hours appeared first on Penetration Testing Tools.
【已复现】1Panel 远程命令执行漏洞安全通告(CVE-2025-54424)
JVN: 三菱電機製エコガイドTABにおける複数の脆弱性
立即更新:Proton Authenticator验证器发布新版本修复明文记录密钥漏洞
印度无人机军事战略对我威胁与我应对策略建议
越南2020–2025年军事无人机战略发展分析
菲律宾无人机监视南海,背后推手竟是美国?
The Telecom Threat: Liminal Panda’s Covert Campaign Targets Southeast Asian Critical Infrastructure
Experts at Palo Alto Networks’ Unit 42 have uncovered a new cyber-espionage campaign targeting the telecommunications sector in Southeast Asia. At the heart of these operations lies a threat actor identified as CL-STA-0969, closely...
The post The Telecom Threat: Liminal Panda’s Covert Campaign Targets Southeast Asian Critical Infrastructure appeared first on Penetration Testing Tools.
The Dark Side of Recall: Microsoft’s AI Feature is Still Capturing Sensitive Data and Poses Grave Security Risks
In the autumn of 2024, Microsoft reintroduced a controversial feature in Windows called Recall—an artificial intelligence system that periodically captures screenshots, allowing users to later search through their entire on-screen activity. Marketed as a...
The post The Dark Side of Recall: Microsoft’s AI Feature is Still Capturing Sensitive Data and Poses Grave Security Risks appeared first on Penetration Testing Tools.