Aggregator
JVN: 三菱電機製MELSOFT Update Managerに7-Zipに起因する複数の脆弱性
JVN: 三菱電機製MELSEC iQ-Fシリーズにおけるサービス運用妨害(DoS)の脆弱性
Kingpin of Notorious XSS.is Cybercrime Forum Arrested in Ukraine After Europol-Led Sting
The Paris Prosecutor’s Office has announced the arrest in Ukraine of an alleged administrator of the Russian-language forum XSS.is, a site long recognized as one of the largest hubs of the cybercriminal underworld. The...
The post Kingpin of Notorious XSS.is Cybercrime Forum Arrested in Ukraine After Europol-Led Sting appeared first on Penetration Testing Tools.
清洁用品巨头高乐氏起诉承包商,指控后者向黑客泄露了密码
清洁用品巨头高乐氏起诉承包商,指控后者向黑客泄露了密码
Google Launches OSS Rebuild: A New Weapon Against Open-Source Supply Chain Attacks
Open-source software forms the bedrock of today’s digital infrastructure, powering 77% of all applications and valued at over $12 trillion. Yet its widespread adoption renders it an increasingly attractive target for supply chain attacks,...
The post Google Launches OSS Rebuild: A New Weapon Against Open-Source Supply Chain Attacks appeared first on Penetration Testing Tools.
Microsoft Confirms China-Backed APTs Actively Exploiting SharePoint Zero-Days (CVE-2025-53770, -53771)
Microsoft has confirmed that three China-linked threat groups were behind the recent wave of attacks targeting on-premises SharePoint Server installations. According to the company’s report, since early July, the vulnerabilities identified as CVE-2025-53770 and...
The post Microsoft Confirms China-Backed APTs Actively Exploiting SharePoint Zero-Days (CVE-2025-53770, -53771) appeared first on Penetration Testing Tools.
CVE-2024-35138 | IBM Security Verify Access Appliance up to 10.0.8 cross-site request forgery (EUVD-2024-35550)
DeerStealer: New Malware Uses Stealthy LNK & LOLBins for Undetectable Data Theft
A newly uncovered malicious campaign involving the infostealer DeerStealer has been identified by researchers at ANY.RUN. Threat actors are employing a sophisticated tactic—combining Windows shortcut files (LNK) with trusted system utilities known as Living-off-the-Land...
The post DeerStealer: New Malware Uses Stealthy LNK & LOLBins for Undetectable Data Theft appeared first on Penetration Testing Tools.
Weak Password Destroys 158-Year-Old UK Transport Company: Akira Ransomware Claims 700 Jobs
In 2023, one of the United Kingdom’s oldest transport companies—established 158 years ago—declared bankruptcy following a devastating ransomware attack. The cyber assault brought the operations of Knights of Old (also known as KNP) to...
The post Weak Password Destroys 158-Year-Old UK Transport Company: Akira Ransomware Claims 700 Jobs appeared first on Penetration Testing Tools.