Aggregator
NVIDIA Dev Proposes Formal AI Guidelines for Linux Kernel Contributions: “Co-Developed-By” Tag & Configs for Claude, Copilot & More
Veteran Linux kernel developer Sasha Levin, currently at NVIDIA and formerly with Google and Microsoft, has proposed the formal inclusion of guidelines for the use of AI assistants in kernel development within the official...
The post NVIDIA Dev Proposes Formal AI Guidelines for Linux Kernel Contributions: “Co-Developed-By” Tag & Configs for Claude, Copilot & More appeared first on Penetration Testing Tools.
packj: detect malicious/risky open-source software packages
Packj flags malicious/risky open-source packages Packj (pronounced package) is a command-line (CLI) tool to vet open-source software packages for “risky” attributes that make them vulnerable to supply chain attacks. This is the tool behind...
The post packj: detect malicious/risky open-source software packages appeared first on Penetration Testing Tools.
CVE-2017-16570 | KeystoneJS up to 4.0.0-beta.6 CSRF Prevention cross-site request forgery (ID 4437 / EDB-43922)
CVE-2017-15878 | KeystoneJS up to 4.0.0-beta.6 MarkdownType.js cross site scripting (ID 144756 / EDB-43054)
CVE-2017-15879 | KeystoneJS up to 4.0.0-beta.6 CSV Export download.js input validation (ID 144755 / EDB-43053)
CVE-2017-1000375 | NetBSD up to 7.1 Run-time Link-Editor ld.so memory corruption (EDB-42272 / ID 370432)
CVE-2017-7037 | Apple iCloud up to 6.2.1 on Windows WebKit memory corruption (HT207927 / EDB-42378)
CVE-2017-7037 | Apple iTunes up to 12.6.1 on Windows WebKit memory corruption (HT207928 / EDB-42378)
CVE-2020-1040 | Microsoft Windows 2012/2012 R2/2016/Server 2008 R2 SP1 Hyper-V RemoteFX vGPU input validation (EUVD-2020-11934)
CVE-2019-0797 | Microsoft Windows up to Server 2019 Win32k access control (EUVD-2019-1553 / ID 91510)
CVE-2021-27085 | Microsoft Internet Explorer 11 Remote Code Execution (EUVD-2021-13856)
CVE-2021-34448 | Microsoft Windows up to Server 2019 Scripting Engine out-of-bounds write (EUVD-2021-21103)
CVE-2020-6819 | Mozilla Firefox 74.0.0/ESR 68.6.0 nsDocShell Destructor use after free (MFSA 2020-11 / EUVD-2020-27963)
CVE-2020-6820 | Mozilla Firefox 74.0.0/ESR 68.6.0 ReadableStream double free (MFSA 2020-11 / EUVD-2020-27964)
CVE-2021-1906 | Qualcomm Snapdragon Auto GPU Address allocation of resources (EUVD-2021-7370)
CVE-2021-1905 | Qualcomm Snapdragon Auto Memory Mapping use after free (EUVD-2021-7369)
Patchwork APT Targets Turkey’s Defense Sector: Indian Cyber-Espionage Group Seeks Hypersonic & UAV Secrets
The threat group known as Patchwork—also operating under aliases such as APT-C-09, APT-Q-36, Chinastrats, Dropping Elephant, Operation Hangover, Quilted Tiger, and Zinc Emerson—has launched a new targeted phishing campaign aimed at Turkey’s defense sector....
The post Patchwork APT Targets Turkey’s Defense Sector: Indian Cyber-Espionage Group Seeks Hypersonic & UAV Secrets appeared first on Penetration Testing Tools.
CVE-2025-5222 | ICU 76.0.1 SRBRoot::addTag stack-based overflow (EUVD-2025-16306 / Nessus ID 238369)
Tails 6.18 Unveiled: New WebTunnel Bridges Bypass Internet Censorship
The Tails project has released a new version of its security- and privacy-focused operating system. Update 6.18 introduces a significant enhancement that enables users to circumvent internet censorship—even in the most heavily monitored regions....
The post Tails 6.18 Unveiled: New WebTunnel Bridges Bypass Internet Censorship appeared first on Penetration Testing Tools.