Last Week in Security (LWiS) - 2025-07-21
文章总结了2025年7月14日至21日的网络安全新闻与技术动态,包括微软项目暴露国防部风险、Cloudflare DNS故障、Clear Linux停运、SharePoint零日漏洞修复等事件,并探讨了钓鱼攻击、Windows漏洞利用及Citrix本地权限提升等技术细节,同时介绍了多种安全工具与exploit。
The CrushFTP service has encountered a newly discovered critical vulnerability, already being exploited in active attacks. Designated CVE-2025-54309 and assigned a CVSS severity score of 9.0, the flaw stems from improper handling of AS2...
The post CrushFTP Zero-Day (CVE-2025-54309) Actively Exploited via AS2 Flaw – Patch Now! appeared first on Penetration Testing Tools.