Aggregator
Researchers Created a Linux Rootkit that Evades Elastic Security EDR Detection
A sophisticated Linux kernel rootkit designed to slip past the defenses of Elastic Security, a leading endpoint detection and response (EDR) platform. Released on GitHub by researcher 0xMatheuZ, the rootkit employs advanced obfuscation techniques to evade YARA-based detection and behavioral monitoring. While presented strictly for educational purposes, Singularity underscores the evolving challenges in kernel-level threat […]
The post Researchers Created a Linux Rootkit that Evades Elastic Security EDR Detection appeared first on Cyber Security News.
国家级黑客潜伏近一年,入侵美国国防部供应商系统
Red Team Arsenal: AzDevRecon Tool Automates Azure DevOps Recon and Secret Hunting
AzDevRecon is a web-based enumeration tool designed for offensive security professionals, red teamers, and penetration testers targeting Azure DevOps. It helps identify misconfigurations,
The post Red Team Arsenal: AzDevRecon Tool Automates Azure DevOps Recon and Secret Hunting appeared first on Penetration Testing Tools.
The Botnet Blitz: Mirai, Gafgyt Fuel RCE Attacks on PHP Servers, IoT, & Cloud Gateways
A sharp surge in attacks targeting PHP servers, Internet of Things (IoT) devices, and cloud gateways has been
The post The Botnet Blitz: Mirai, Gafgyt Fuel RCE Attacks on PHP Servers, IoT, & Cloud Gateways appeared first on Penetration Testing Tools.
Octoverse 2025: India to Surpass U.S. Developers; AI Becomes Baseline
By 2030, India is projected to surpass the United States in the number of software developers—a forecast presented
The post Octoverse 2025: India to Surpass U.S. Developers; AI Becomes Baseline appeared first on Penetration Testing Tools.
Tor Browser 15.0 STABLE: Vertical Tabs, Android Screen Lock, and Major Firefox Updates
The Tor Project team has announced the stable release of Tor Browser 15.0. The new version is built
The post Tor Browser 15.0 STABLE: Vertical Tabs, Android Screen Lock, and Major Firefox Updates appeared first on Penetration Testing Tools.
CVE-2025-6204
CVE-2025-55752
CVE-2025-2783
90% of Windows Games Now Run on Linux: A Historic High for SteamOS Gaming
According to Boiling Steam, the number of Windows games running reliably on Linux has reached its highest level
The post 90% of Windows Games Now Run on Linux: A Historic High for SteamOS Gaming appeared first on Penetration Testing Tools.
The Brash Attack: Single Webpage Freezes Chrome/Chromium Browsers in Seconds
Researcher Jose Pino unveiled a proof-of-concept for a vulnerability in the Blink rendering engine used by Chromium-based browsers,
The post The Brash Attack: Single Webpage Freezes Chrome/Chromium Browsers in Seconds appeared first on Penetration Testing Tools.
TEE.fail: New $1,000 Hardware Attack Bypasses Nvidia, AMD, & Intel Data Isolation
New research has revealed that even the most advanced hardware-based data isolation technologies from leading chip manufacturers—Nvidia Confidential
The post TEE.fail: New $1,000 Hardware Attack Bypasses Nvidia, AMD, & Intel Data Isolation appeared first on Penetration Testing Tools.
SILENT HIJACK: Wear OS Flaw Lets Any App Send User’s Messages Without Permission
A vulnerability in the Google Messages app for Wear OS has jeopardized the privacy of millions of smartwatch
The post SILENT HIJACK: Wear OS Flaw Lets Any App Send User’s Messages Without Permission appeared first on Penetration Testing Tools.
National Security Betrayal: Defense Contractor Sold 8 Zero-Days to Russian Broker for Crypto
Former L3Harris defense contractor employee Peter Williams has pleaded guilty in a U.S. federal court to two counts
The post National Security Betrayal: Defense Contractor Sold 8 Zero-Days to Russian Broker for Crypto appeared first on Penetration Testing Tools.
PhantomRaven Attack: New Malware Steals CI/CD Secrets via AI Slopsquatting on npm
The ongoing PhantomRaven campaign has targeted developers via the npm registry, disseminating dozens of malicious packages across the
The post PhantomRaven Attack: New Malware Steals CI/CD Secrets via AI Slopsquatting on npm appeared first on Penetration Testing Tools.
HTTPS by Default: Chrome to Force Encrypted Connections on Public Sites in 2026
As early as 2026, Google Chrome will adopt a new security policy, requiring HTTPS connections by default when
The post HTTPS by Default: Chrome to Force Encrypted Connections on Public Sites in 2026 appeared first on Penetration Testing Tools.
Filter Evasion: Phishing Campaign Hides Invisible Characters in Email Subject Lines
A newly uncovered phishing campaign, identified by researchers at the Internet Storm Center, showcases a remarkably unconventional method
The post Filter Evasion: Phishing Campaign Hides Invisible Characters in Email Subject Lines appeared first on Penetration Testing Tools.
Cyber War Escalation: Generative AI & VPN Flaws Fuel 90% of All Attacks
The 2025 At-Bay InsurSec Rankings report recorded a sharp surge in cyberattacks linked to email and remote access—two
The post Cyber War Escalation: Generative AI & VPN Flaws Fuel 90% of All Attacks appeared first on Penetration Testing Tools.
BlackShrantac
You must login to view this content