Aggregator
CVE-2025-52337 | LogicData eCommerce Framework 5.0.9.7000 Content Explorer Feature unrestricted upload
CVE-2025-51543 | Cicool 3.4.4 reset_password password recovery
CVE-2025-54143 | Mozilla Firefox up to 140 on iOS iFrame access control (EUVD-2025-25230)
CVE-2025-5262 | Mozilla Firefox up to 138 WebRTC vpx_codec_enc_init_multi memory corruption (EUVD-2025-25234 / Nessus ID 237301)
Взлом Lykke: «Мы просто хотели, чтобы у наших ракет было что-то новое и блестящее» — заявила КНДР
Agentic AI是否能化解网络安全危机?
CVE-2025-37785 | Linux Kernel up to 6.14.1 ext4_empty_dir new out-of-bounds (Nessus ID 234884 / WID-SEC-2025-0861)
CVE-2021-47670 | Linux Kernel up to 4.19.170/5.4.92/5.10.10 peak_usb_netif_rx_ni use after free (Nessus ID 240793 / WID-SEC-2025-0861)
CVE-2021-47671 | Linux Kernel up to 5.14.18/5.15.2 es58x_rx_err_msg memory leak (WID-SEC-2025-0861)
CVE-2021-47669 | Linux Kernel up to 4.14.217/4.19.170/5.4.92/5.10.10 vxcan netif_rx_ni use after free (WID-SEC-2025-0861)
CVE-2021-47668 | Linux Kernel up to 5.10.10 netif_rx_ni use after free (WID-SEC-2025-0861)
CVE-2020-36789 | Linux Kernel up to 5.9.8 net/core/skbuff.c can_get_echo_skb reference count (WID-SEC-2025-0861)
Microsoft fixes Windows upgrades failing with 0x8007007F error
BARK: BloodHound Attack Research Kit
BloodHound Attack Research Kit BARK stands for BloodHound Attack Research Kit. It is a PowerShell script built to assist the BloodHound Enterprise team with researching and continuously validating abuse primitives. BARK currently focuses on...
The post BARK: BloodHound Attack Research Kit appeared first on Penetration Testing Tools.
Pharmaceutical firm Inotiv discloses ransomware attack. Qilin group claims responsibility for the hack
Privacy Sandbox: когда 'защита приватности' превращается в инструмент тотальной слежки
Legitimate Chrome VPN With 100,000+ Installs Silently Captures Screenshots and Exfiltrate Sensitive Data
A Chrome VPN extension with over 100,000 installations and verified badge status has been discovered operating as sophisticated spyware, continuously capturing user screenshots and exfiltrating sensitive data without consent. The extension, known as FreeVPN.One, masqueraded as a legitimate privacy tool while secretly implementing comprehensive surveillance capabilities that directly contradict its stated privacy promises. The malicious […]
The post Legitimate Chrome VPN With 100,000+ Installs Silently Captures Screenshots and Exfiltrate Sensitive Data appeared first on Cyber Security News.
AWSGoat: Damn Vulnerable AWS Infrastructure
Compromising an organization’s cloud infrastructure is like sitting on a gold mine for attackers. And sometimes, a simple misconfiguration or a vulnerability in web applications, is all an attacker needs to compromise the entire...
The post AWSGoat: Damn Vulnerable AWS Infrastructure appeared first on Penetration Testing Tools.