Aggregator
CVE-2025-55031 | Mozilla Firefox/Focus up to 141 on iOS information disclosure (EUVD-2025-25225 / WID-SEC-2025-1866)
CVE-2025-55030 | Mozilla Firefox up to 141 on iOS Header Content-Disposition cross site scripting (EUVD-2025-25227 / WID-SEC-2025-1866)
CVE-2025-55154 | ImageMagick up to 6.9.13-26/7.1.2-0 coders/png.c ReadOneMNGIMage integer overflow (Nessus ID 258077 / WID-SEC-2025-1813)
CVE-2025-55160 | ImageMagick up to 6.9.13-26/7.1.2-0 reliance on undefined, unspecified, or implementation-defined behavior (Nessus ID 258077 / WID-SEC-2025-1813)
CVE-2025-55005 | ImageMagick up to 7.1.2-0 heap-based overflow (Nessus ID 260009 / WID-SEC-2025-1813)
The Grok Exploit: How Hackers Are Using AI to Bypass X’s Filters
Cybercriminals have discovered a method to bypass X’s restrictions on posting links by exploiting its built-in assistant, Grok.
The post The Grok Exploit: How Hackers Are Using AI to Bypass X’s Filters appeared first on Penetration Testing Tools.
Iran-Linked Cyber-Espionage Campaign Targets Diplomatic Organizations
In August 2025, specialists from Dream Threat Intelligence documented a large-scale phishing campaign attributed to actors linked to
The post Iran-Linked Cyber-Espionage Campaign Targets Diplomatic Organizations appeared first on Penetration Testing Tools.
Cloudflare’s 1.1.1.1 DNS Service Was Targeted by a Rogue Certificate Authority
On September 3, 2025, researcher Youfu Zhang reported to the Mozilla dev-security-policy mailing list that the certification authority
The post Cloudflare’s 1.1.1.1 DNS Service Was Targeted by a Rogue Certificate Authority appeared first on Penetration Testing Tools.
微软称红海多条海底电缆被切断后其云服务受影响 亚洲与欧洲连接性下降
CVE-2017-15965 | NS Download Shop 2.2.6 on Joomla invoice.create ID sql injection (File 144435/Joo / EDB-43094)
CVE-2017-15966 | Zh YandexMap 6.1.1.0 on Joomla index.php placemarklistid sql injection (File 144436/Joo / EDB-43093)
Mandiant Reveals Attack Exploiting a Publicly Known Sitecore Key
Mandiant researchers have uncovered an attack targeting legacy installations of the Sitecore platform. The attackers exploited a demonstration
The post Mandiant Reveals Attack Exploiting a Publicly Known Sitecore Key appeared first on Penetration Testing Tools.