Pentesting remains one of the most effective ways to identify real-world security weaknesses before adversaries do. But as the threat landscape has evolved, the way we deliver pentest results hasn't kept pace.
Most organizations still rely on traditional reporting methods—static PDFs, emailed documents, and spreadsheet-based tracking. The problem? These outdated workflows introduce delays,
A vulnerability, which was classified as problematic, has been found in Biagiotti Core Plugin up to 2.1.3 on WordPress. Affected by this vulnerability is an unknown functionality of the component Shortcode Handler. This manipulation causes cross site scripting.
The identification of this vulnerability is CVE-2025-9057. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability classified as critical was found in Eaton NMC G2 up to 2.1.x. Affected is an unknown function. The manipulation results in path traversal.
This vulnerability was named CVE-2025-48395. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability classified as problematic has been found in OceanWP Plugin up to 4.1.1 on WordPress. This impacts an unknown function of the component Setting Handler. The manipulation leads to incorrect authorization.
This vulnerability is uniquely identified as CVE-2025-8944. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
Anthropic 宣布,立即停止 Claude 提供给多数股权由中国资本持有的集团或其子公司使用。 这一举措意味着,凡是直接或间接由中国实体控制(占股比例超过 50%)的企业,不再被允许使用 Anthropic 的服务。该政策不仅适用于中国大陆公司,也包括那些在境外设立的子公司、云服务中转实体或具有中国背景投资主体的组织。Anthropic 在其官网公告中表示,此举为应对法律、监管与国家安全风险。Anthropic 一位高管对《金融时报》的简要说明,此举还意在遏制中国公司通过在海外(如新加坡)注册子公司或使用第三方云服务,规避出口管制以获取先进 AI 技术的可能性。这是首个美国 AI 公司公开宣布此类限制的案例,标志着在美国科技公司 AI 出口与服务限制方面,可能更加主动采取防范措施。