Aggregator
【已复现】契约锁电子签章系统 pdfverifier 远程代码执行漏洞
$500,000 Crypto Stolen: Fake AI Extension Targets Blockchain Devs via Open VSX
A Russian blockchain developer has fallen victim to a targeted attack executed through a counterfeit extension within the Cursor AI environment, resulting in the theft of approximately $500,000 worth of cryptocurrency. The incident was...
The post $500,000 Crypto Stolen: Fake AI Extension Targets Blockchain Devs via Open VSX appeared first on Penetration Testing Tools.
AMD Discloses Vulnerabilities: New Processor Flaws Leak Sensitive Data via Speculative Side Channels
AMD has disclosed the discovery of a new class of processor vulnerabilities, dubbed Transient Scheduler Attacks (TSA). These attacks exploit speculative side channels arising from specific microarchitectural conditions, potentially leading to the leakage of...
The post AMD Discloses Vulnerabilities: New Processor Flaws Leak Sensitive Data via Speculative Side Channels appeared first on Penetration Testing Tools.
谷歌为Gemini应用添加图像生成视频能力 由Veo 3 AI视频生成器驱动
银狐情报共享第1期:Att&CK视角下的最新活跃技战术分享
Opossum Attack: New TLS Flaw Injects Malicious Data Into Encrypted Sessions
The discovery of a new vulnerability, aptly named Opossum, has cast a shadow over the reliability of secure communications relying on the Transport Layer Security (TLS) protocol. This exploit enables malicious actors to inject...
The post Opossum Attack: New TLS Flaw Injects Malicious Data Into Encrypted Sessions appeared first on Penetration Testing Tools.
Suricata 8.0 Unleashed: Faster, Safer Network Defense with Rust & New Protocols
The stable release of Suricata 8.0 has officially been unveiled—a powerful open-source intrusion detection and network traffic analysis system developed by the OISF foundation. This marks the first major update in two years since...
The post Suricata 8.0 Unleashed: Faster, Safer Network Defense with Rust & New Protocols appeared first on Penetration Testing Tools.
ChatGPT Leaks Windows Keys, Including Wells Fargo License, Via Clever “Game” Prompt
ChatGPT has once again proven susceptible to unconventional manipulation—this time, the model divulged valid Windows product keys, including one registered to the major financial institution Wells Fargo. The vulnerability was exposed through a peculiar...
The post ChatGPT Leaks Windows Keys, Including Wells Fargo License, Via Clever “Game” Prompt appeared first on Penetration Testing Tools.
安装在近100万台设备上的浏览器扩展程序利用用户IP帮助AI公司抓取内容
Gold Melody Unleashed: New Stealthy Attacks Exploit Leaked ASP.NET Keys
Experts at Palo Alto Networks Unit 42 have uncovered a new malicious campaign orchestrated by the threat actor group known as Gold Melody. This group specializes in gaining unauthorized access to corporate systems and...
The post Gold Melody Unleashed: New Stealthy Attacks Exploit Leaked ASP.NET Keys appeared first on Penetration Testing Tools.
GMX Hacked: $40M Stolen in Major DeFi Cyber Heist
On the morning of July 9, the decentralized exchange GMX fell victim to a major cyber heist. An unidentified attacker siphoned off over $40 million worth of cryptocurrency from the platform. According to GMX...
The post GMX Hacked: $40M Stolen in Major DeFi Cyber Heist appeared first on Penetration Testing Tools.
译文 | 从来无我:在审视 AI 中重识自我
Не зарегистрировался — не обижайся: Госдума готовит удар на миллион для «невидимых» хостеров
Android & Chrome Level Up Security with New Advanced Protection for High-Risk Users
Google has introduced a new security configuration on Android, tailored for users vulnerable to targeted cyberattacks. Known as Advanced Protection, this suite of features—once exclusive to individual Google Accounts—is now available at the device...
The post Android & Chrome Level Up Security with New Advanced Protection for High-Risk Users appeared first on Penetration Testing Tools.
Microsoft Authenticator for iOS: Cloud Backups Arrive, Ditching Personal Accounts
Microsoft is preparing a significant update for users of its Authenticator app on iOS devices. Beginning in September, a new backup system will roll out, eliminating the need to sign in with a personal...
The post Microsoft Authenticator for iOS: Cloud Backups Arrive, Ditching Personal Accounts appeared first on Penetration Testing Tools.
Windows 11 Gets Native App Removal: Bye-Bye Bloatware via Group Policy
Microsoft has introduced a long-anticipated feature in Windows 11 that allows administrators to remove preinstalled Microsoft Store applications via official Group Policy. The new functionality, titled Remove Default Microsoft Store Packages, is already available...
The post Windows 11 Gets Native App Removal: Bye-Bye Bloatware via Group Policy appeared first on Penetration Testing Tools.
【0day】紧急提醒!你的Telegram私密群组/频道可能被未授权访问!
Critical NTFS Vulnerability (CVE-2025-49689) Uncovered: Local Attacker Can Gain SYSTEM Privileges in Windows 11
A researcher at Positive Technologies has uncovered a critical vulnerability in the implementation of the NTFS file system, which enables a local attacker to escalate privileges to SYSTEM by leveraging a specially crafted virtual...
The post Critical NTFS Vulnerability (CVE-2025-49689) Uncovered: Local Attacker Can Gain SYSTEM Privileges in Windows 11 appeared first on Penetration Testing Tools.