Aggregator
Submit #780189: osrg GoBGP 4.3.0 Improper Input Validation [Accepted]
Submit #780179: osrg GoBGP 4.3.0 Off-by-one Error [Accepted]
New macOS Infinity Stealer uses Nuitka Python payload and ClickFix
New macOS Infinity Stealer uses Nuitka Python payload and ClickFix
CVE-2026-2328 | WAGO Device Sphere/Solution Builder up to 1.2.1 improper filtering of special elements (VDE-2026-010 / EUVD-2026-17064)
Smart Homes Are Getting Smarter—But Post-Breach Guidance Is Falling Behind
Critical Fortinet Forticlient EMS flaw now exploited in attacks
Submit #780124: GoBGP 4.3.0 Improper Handling of Length Parameter Inconsistency [Accepted]
New “Prompt Poaching” Attack Steals Users’ AI Conversations via Malicious Browser Extensions
For many users, engaging with an AI assistant requires opening a dedicated browser tab, which inherently isolates the AI from other browsing activities. While this separation improves privacy, it reduces usefulness and context. To bridge this gap, AI-powered browser extensions have surged in popularity, allowing AI agents to seamlessly interact with emails, corporate portals, and […]
The post New “Prompt Poaching” Attack Steals Users’ AI Conversations via Malicious Browser Extensions appeared first on Cyber Security News.
CVE-2026-5119 | GNOME libsoup HTTP Proxy cleartext transmission (EUVD-2026-17062)
CVE-2025-15379 | MLflow up to 3.8.1 Model _install_model_dependencies_to_env command injection (EUVD-2025-209121)
CVE-2026-3945 | tinyproxy up to 1.11.3 Chunk strtol integer overflow (EUVD-2026-17066 / WID-SEC-2026-0909)
EvilMist: The Ultimate Swiss Army Knife for Azure and Entra ID Red Teaming
EvilMist is a collection of scripts and utilities designed to support cloud security configuration audit, cloud penetration testing
The post EvilMist: The Ultimate Swiss Army Knife for Azure and Entra ID Red Teaming appeared first on Penetration Testing Tools.
123456, admin и «пароль». Что изменилось в списке самых популярных паролей мира — и при чём тут взломанные обогреватели
Russia-linked APT TA446 uses DarkSword exploit to target iPhone users in phishing wave
Russia-linked APT TA446 uses DarkSword exploit to target iPhone users in phishing wave
Sailing Blind: Ransomware Paralysis Forces Spain’s Port of Vigo Back to Paper and Pen
A prominent fishing port in northwestern Spain has been thrust into a predicament wherein a cyberattack compelled the
The post Sailing Blind: Ransomware Paralysis Forces Spain’s Port of Vigo Back to Paper and Pen appeared first on Penetration Testing Tools.
Hacker Civil War: ShinyHunters Leaks 340,000 Accounts from “Fake” BreachForums
A scandal is once again erupting around one of the most notorious hacker forums. In March 2026, the
The post Hacker Civil War: ShinyHunters Leaks 340,000 Accounts from “Fake” BreachForums appeared first on Penetration Testing Tools.