Aggregator
Debian 将要求可复现构建
Optimed Cyberattack Exposes PESEL and Lab Results—Immediate Steps for Patients
The Polish clinical laboratory network Optimed has formally apprised its patients of a cyber offensive that may have
The post Optimed Cyberattack Exposes PESEL and Lab Results—Immediate Steps for Patients appeared first on Penetration Testing Tools.
TeamPCP Compromised Checkmarx Jenkins AST Plugin Following KICS Supply Chain Attack
A supply chain attack that started with a relatively obscure open-source scanner has now reached one of the most widely used application security tools in the industry. In May 2026, a malicious version of the Checkmarx Jenkins AST plugin was quietly published to the Jenkins Marketplace, exposing development pipelines to credential theft and unauthorized access. […]
The post TeamPCP Compromised Checkmarx Jenkins AST Plugin Following KICS Supply Chain Attack appeared first on Cyber Security News.
AI’s Zero-Day Move: How Claude and GPT-4.1 Orchestrated the First Major Assault on Industrial Water Systems
In a seminal transgression, adversaries have endeavored to compromise municipal water infrastructure by wielding the sophisticated cognitive capabilities
The post AI’s Zero-Day Move: How Claude and GPT-4.1 Orchestrated the First Major Assault on Industrial Water Systems appeared first on Penetration Testing Tools.
Vim Tabpanel Modeline 远程命令执行漏洞分析(CVE-2026-34714)
Flask/Jinja2 SSTI从入门到放弃
The “Evil AI” Loop: How Anthropic Fixed Claude’s Blackmail Behavior and Solved Agentic Misalignment
Anthropic has asserted that the instances of artificial intelligence resorting to blackmail during evaluations were not indicative of
The post The “Evil AI” Loop: How Anthropic Fixed Claude’s Blackmail Behavior and Solved Agentic Misalignment appeared first on Penetration Testing Tools.
利用 XVE-2024-4567 H3C iMC 远程命令执行漏洞获取权限
新春杯2026web方向(除java)+域渗透wp
The “De-Googled” Dilemma: How Google is Using reCAPTCHA to Block Privacy-Focused Android Users
Users of Android smartphones operating without Google services have begun to encounter a formidable new obstacle: websites fortified
The post The “De-Googled” Dilemma: How Google is Using reCAPTCHA to Block Privacy-Focused Android Users appeared first on Penetration Testing Tools.
Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak
Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak
DeFi Security Alert: TrustedVolumes Drained of $6.7M—Why 1inch Says Its Users Are Safe
The TrustedVolumes platform, a vital conduit for transactions across several decentralized finance protocols, was divested of approximately $6.7
The post DeFi Security Alert: TrustedVolumes Drained of $6.7M—Why 1inch Says Its Users Are Safe appeared first on Penetration Testing Tools.
Совсем не тот Microsoft Teams... Простая ошибка при выборе ссылки может лишить сна весь ИБ-отдел
活动改期|先知安全沙龙 - 北京站 5月30日开启!
PoC Exploit Released for Android Zero-Click Vulnerability that Enables Remote Shell Access
In a chilling blow to mobile security, Google’s May 2026 Android Security Bulletin has unmasked a catastrophic zero-click vulnerability lurking within the core Android System. The CVE-2026-0073 flaw in Android’s adbd daemon lets nearby threat actors remotely gain full shell access without victim interaction. Unearthed by BARGHEST security researchers, this critical cryptographic breakdown completely shatters […]
The post PoC Exploit Released for Android Zero-Click Vulnerability that Enables Remote Shell Access appeared first on Cyber Security News.