Aggregator
乌克兰和 SpaceX 合作阻止俄罗斯无人机使用 Starlink 发动攻击
乌克兰和 SpaceX 合作阻止俄罗斯无人机使用 Starlink 发动攻击
CVE-2023-43144 | projectworlds Assets Management System 1.0 delete.php ID sql injection (EUVD-2023-47563)
CVE-2023-43139 | franfinance Module up to 2.0.26 on PrestaShop validation.php code injection (EUVD-2023-47558)
CVE-2023-43141 | TOTOLINK A3700R/N600R access control (EUVD-2023-47560)
APT28 Hackers Exploiting Microsoft Office 0-Day in the Wild to Deploy Malware
APT28, the Russia-linked advanced persistent threat group, has launched a sophisticated campaign targeting Central and Eastern Europe using a zero-day vulnerability in Microsoft Office. The threat actors leveraged specially crafted Microsoft Rich Text Format (RTF) files to exploit the vulnerability and deliver malicious backdoors through a multi-stage infection chain. The campaign, tracked as Operation Neusploit, […]
The post APT28 Hackers Exploiting Microsoft Office 0-Day in the Wild to Deploy Malware appeared first on Cyber Security News.
Exploiting CVE-2025-49825 (authentication bypass vulnerability in Teleport)
MIPSEval: Automated Multi-Turn Injection Planning for LLM Security
Multi-turn Injection Planning System for LLM Evaluation MIPSEval is a modular framework for simulating and evaluating the behavior
The post MIPSEval: Automated Multi-Turn Injection Planning for LLM Security appeared first on Penetration Testing Tools.
«Включите, пожалуйста, экран». В метро начали проверять смартфоны — законно ли это?
CVE-2026-1592 | Foxit PDF Editor Cloud up to 2026‑01‑31 New Layer Feature cross site scripting
CVE-2026-1591 | Foxit PDF Editor Cloud up to 2026‑01‑31 File Upload cross site scripting
The Notepad++ supply chain attack — unnoticed execution chains and new IoCs
Zero-Days and “Trunks of Cash”: The Unsealed FBI Files Alleging Jeffrey Epstein’s Personal Hacker
The United States Department of Justice has disseminated a nascent cache of materials pertaining to the Jeffrey Epstein
The post Zero-Days and “Trunks of Cash”: The Unsealed FBI Files Alleging Jeffrey Epstein’s Personal Hacker appeared first on Penetration Testing Tools.
Rootless Containers with Podman
木鱼分析沙箱新版本重磅内测来袭
中国公安部就网络犯罪防治法公开征求意见
The “Skills” Trap: How Over 300 Malicious ClawdBot Plug-ins Are Siphoning Crypto and Keys
The burgeoning AI assistant ClawdBot has precipitously descended into the vortex of a sophisticated malware offensive. Cybersecurity analysts
The post The “Skills” Trap: How Over 300 Malicious ClawdBot Plug-ins Are Siphoning Crypto and Keys appeared first on Penetration Testing Tools.
The “Update” Trap: How State-Sponsored Hackers Hijacked Notepad++ Infrastructure for 6 Months
The lead developer of the ubiquitous text editor Notepad++ has disclosed a formidable security breach that compromised the
The post The “Update” Trap: How State-Sponsored Hackers Hijacked Notepad++ Infrastructure for 6 Months appeared first on Penetration Testing Tools.