Aggregator
[webapps] Mezzanine CMS 6.1.0 - Stored Cross Site Scripting (XSS)
[local] Linux PAM Environment - Variable Injection Local Privilege Escalation
[webapps] Adobe ColdFusion 2023.6 - Remote File Read
[dos] Xlight FTP 1.1 - Denial Of Service (DOS)
Revisiting UNC3886 Tactics to Defend Against Present Risk
行业安全实践:构建“数字烟草” 物流工控信息安全体系
ropr: blazing fast multithreaded ROP Gadget finder
ropr ropr is a blazing fast multithreaded ROP Gadget finder What is an ROP Gadget? ROP (Return Oriented Programming) Gadgets are small snippets of a few assembly instructions typically ending in a ret instruction which...
The post ropr: blazing fast multithreaded ROP Gadget finder appeared first on Penetration Testing Tools.
CastleLoader Unleashed: New Stealthy Malware Loader Leverages ClickFix & Fake GitHub for Widespread Infections
In the first half of 2025, researchers observed the active exploitation of a new malware loader known as CastleLoader. Since its emergence, this tool has become a central element in the distribution infrastructure for...
The post CastleLoader Unleashed: New Stealthy Malware Loader Leverages ClickFix & Fake GitHub for Widespread Infections appeared first on Penetration Testing Tools.
TerraformGoat: “Vulnerable by Design” multi cloud deployment tool
TerraformGoat TerraformGoat is HuoCorp research lab’s “Vulnerable by Design” multi-cloud deployment tool. Currently, supported cloud vendors include Alibaba Cloud, Tencent Cloud, Huawei Cloud, Amazon Web Services, Google Cloud Platform, and Microsoft Azure. Scenarios ID...
The post TerraformGoat: “Vulnerable by Design” multi cloud deployment tool appeared first on Penetration Testing Tools.
Arcus Media
You must login to view this content
Arcus Media
You must login to view this content
Leak Zone Forum’s Own Elasticsearch Database Exposed, Revealing 22M+ User Records
The Leak Zone forum — widely known as a hub for publishing and distributing hacked databases, stolen credentials, and pirated software — has ironically become the source of a major data breach. According to...
The post Leak Zone Forum’s Own Elasticsearch Database Exposed, Revealing 22M+ User Records appeared first on Penetration Testing Tools.
US Woman Jailed 8.5 Years for Running “Laptop Farm” That Enabled North Korean IT Spies to Infiltrate 300+ US Firms
An Arizona woman has been sentenced to eight and a half years in prison for operating a covert “laptop farm” from her home, which enabled North Korean IT operatives to impersonate American tech professionals...
The post US Woman Jailed 8.5 Years for Running “Laptop Farm” That Enabled North Korean IT Spies to Infiltrate 300+ US Firms appeared first on Penetration Testing Tools.
StackSmash CTF
Date: July 25, 2025, 1 p.m. — 27 July 2025, 21:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: http://ctf.hackthebox.com/
Rating weight: 24.00
Event organizers: Hack The Box
DeadSec CTF 2025
Date: July 25, 2025, 10 p.m. — 27 July 2025, 22:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://www.deadsec.xyz/
Rating weight: 31.29
Event organizers: DeadSec