Aggregator
谷歌透露正在将ChromeOS与安卓合并 未来ChromeOS将会彻底消失
MCP特性及攻击面
从零掌握java内存马大全(基于LearnJavaMemshellFromZero复现重组)
Gogs最新RCE分析与利用详情
FBI 查封任天堂 Switch、PS4 游戏盗版网站
FBI 查封任天堂 Switch、PS4 游戏盗版网站
JsRpc+Yakit热加载解决请求响应体加解密问题
JsRpc+Yakit热加载实现明文编辑加密发包
Critical Laravel Vulnerability: 260,000+ APP_KEYs Leaked, Enabling Remote Code Execution
Security researchers from GitGuardian and Synacktiv have uncovered a critical vulnerability in Laravel, the widely used PHP framework that powers hundreds of thousands of web applications. The issue stems from the leakage of the...
The post Critical Laravel Vulnerability: 260,000+ APP_KEYs Leaked, Enabling Remote Code Execution appeared first on Penetration Testing Tools.
反弹Shell执行pty泄露黑客命令记录?
CVE-2025-32023 Redis 漏洞分析
Critical FortiWeb SQL Injection (CVE-2025-25257) Allows Remote Code Execution, PoC Published
Fortinet has released critical security updates for FortiWeb, addressing a severe vulnerability that allowed unauthenticated attackers to execute arbitrary SQL queries remotely. The flaw, tracked as CVE-2025-25257, received a CVSS score of 9.6, placing...
The post Critical FortiWeb SQL Injection (CVE-2025-25257) Allows Remote Code Execution, PoC Published appeared first on Penetration Testing Tools.
GPUHammer: New NVIDIA Vulnerability Threatens AI Models with Data Corruption
NVIDIA has issued a warning about a newly discovered vulnerability in its graphics processing units, dubbed GPUHammer. This attack, rooted in the well-known RowHammer technique, enables malicious actors to corrupt data belonging to other...
The post GPUHammer: New NVIDIA Vulnerability Threatens AI Models with Data Corruption appeared first on Penetration Testing Tools.
$40 Million Crypto Heist: GMX Hacker Returns Funds for $5M Bounty, Dodges Legal Battle
A hacker who siphoned $40 million in cryptocurrency from the decentralized exchange GMX has returned nearly the entire haul in exchange for a $5 million payout. The breach ranked among the largest in DeFi...
The post $40 Million Crypto Heist: GMX Hacker Returns Funds for $5M Bounty, Dodges Legal Battle appeared first on Penetration Testing Tools.
研究人员警告:简单无线电入侵可紧急逼停北美所有列车
研究人员警告:简单无线电入侵可紧急逼停北美所有列车
亚马逊AWS调整新用户政策 不再提供免费试用12个月 换成半年赠金模式
ISC Stormcast For Tuesday, July 15th, 2025 https://isc.sans.edu/podcastdetail/9526, (Tue, Jul 15th)
Windows 11 Gets “Quick Machine Recovery”: Microsoft’s New AI-Powered Auto-Fix for Boot Failures
Microsoft has unveiled a new feature for Windows 11 that could prove to be a true lifeline for users when their computer suddenly fails to boot. This innovation, known as Quick Machine Recovery—or simply...
The post Windows 11 Gets “Quick Machine Recovery”: Microsoft’s New AI-Powered Auto-Fix for Boot Failures appeared first on Penetration Testing Tools.