Aggregator
【已复现】Jenkins Git Parameter 远程命令执行漏洞(CVE-2025-53652)安全风险通告
【已复现】Jenkins Git Parameter 远程命令执行漏洞(CVE-2025-53652)安全风险通告
AI and the Prospect of a Post-Big Tech Internet
Your ‘Smart’ Home Is Not Safe: Gemini Attack Turns a Calendar Invite into a Physical Threat
In a new apartment in Tel Aviv, the lights suddenly switch off, smart blinds rise on their own, and the water heater powers up—without the tenants’ knowledge. This is not part of a “smart...
The post Your ‘Smart’ Home Is Not Safe: Gemini Attack Turns a Calendar Invite into a Physical Threat appeared first on Penetration Testing Tools.
CVE-2025-8742 | macrozheng mall 1.0.3 Admin Login excessive authentication (EUVD-2025-24020)
CVE-2025-8741 | macrozheng mall up to 1.0.3 /admin/login cleartext transmission (EUVD-2025-24021)
Threat Actors Weaponize Malicious Gopackages to Deliver Obfuscated Remote Payloads
Cybersecurity researchers have uncovered a sophisticated malware campaign targeting the Go ecosystem through eleven malicious packages that employ advanced obfuscation techniques to deliver second-stage payloads. The campaign demonstrates a concerning evolution in supply chain attacks, leveraging the decentralized nature of Go’s module system to distribute malicious code that can compromise both Linux build servers and […]
The post Threat Actors Weaponize Malicious Gopackages to Deliver Obfuscated Remote Payloads appeared first on Cyber Security News.
Streamlining Go Concurrency Using a Worker Pool
Submit #623428: Scada-LTS 2.7.8.1 Cross Site Scripting (XSS) Stored [Accepted]
Cloud Chaos: New ‘ECScape’ Attack Threatens Amazon’s Container Service
At the Black Hat USA conference in Las Vegas, Naor Haziz, a researcher at Sweet Security, unveiled an attack dubbed ECScape, capable of completely undermining the trust-based security model of Amazon ECS. The vulnerability...
The post Cloud Chaos: New ‘ECScape’ Attack Threatens Amazon’s Container Service appeared first on Penetration Testing Tools.
The Highs and Lows of My First Real Startup, CoLaunchly
MariaDB Kubernetes Operator 25.08.0 Adds AI Vector Support and Disaster Recovery Enhancements
ИИ-фрод наступает: как новые алгоритмы бьют по онлайн-ритейлу
Submit #623319: macrozheng mall 1.0.3 Improper Restriction of Excessive Authentication Attempts [Accepted]
Submit #623318: macrozheng mall 1.0.3 Cleartext Transmission of Sensitive Information [Accepted]
HTTP/1.1 Must Die: Why This 6-Year-Old Vulnerability Is Still a Major Threat
Six years ago, researchers at PortSwigger first identified a fundamental flaw in the HTTP/1.1 protocol—one that enables HTTP Request Smuggling attacks. Despite being publicly known since 2019, the vulnerability remains unresolved and continues to...
The post HTTP/1.1 Must Die: Why This 6-Year-Old Vulnerability Is Still a Major Threat appeared first on Penetration Testing Tools.
Hackers Breach U.S. Federal Courts, Exposing Confidential Witness Identities
Hackers have breached the electronic case management system of the U.S. federal courts, gaining access to confidential information, including the identities of protected witnesses. The incident, which affected multiple district courts across several states,...
The post Hackers Breach U.S. Federal Courts, Exposing Confidential Witness Identities appeared first on Penetration Testing Tools.