Aggregator
CVE-2025-7444 | LoginPress Pro Plugin up to 5.0.1 on WordPress OAuth Provider improper authentication (EUVD-2025-21859)
CVE-2025-50056 | rsjoomla RSMail Component up to 1.22.28 on Joomla crafted cross site scripting (EUVD-2025-21871)
CVE-2025-50057 | rsjoomla RSFiles Component up to 1.17.7 on Joomla Search resource consumption (EUVD-2025-21870)
CVE-2025-49485 | Balbooa Forms Component up to 2.3.1.1 on Joomla ID sql injection (EUVD-2025-21872)
CVE-2025-49486 | Balbooa Gallery Component up to 2.4.0 on Joomla Gallery Item cross site scripting (EUVD-2025-21873)
CVE-2025-6197 | Grafana up to 11.3.8/11.4.6/11.5.6/11.6.3/12.0.2 OSS Organization Switching redirect (EUVD-2025-21862 / WID-SEC-2025-1593)
APT41’s New Frontier: Chinese Cyberespionage Group Targets African Governments
The China-linked cyber-espionage group APT41 has launched a new surveillance campaign targeting government IT services in Africa—an unexpected turn for a region previously considered an unlikely target. Researchers at Kaspersky Lab uncovered the operation...
The post APT41’s New Frontier: Chinese Cyberespionage Group Targets African Governments appeared first on Penetration Testing Tools.
CVE-2024-47682 | Linux Kernel up to 6.1.112/6.6.53/6.10.12/6.11.1 scsi sd_read_block_characteristics off-by-one (Nessus ID 213470 / WID-SEC-2024-3251)
CVE-2022-49020 | Linux Kernel up to 6.0.11 p9_fd_create_tcp resource consumption (Nessus ID 210933 / WID-SEC-2024-3251)
CVE-2022-49031 | Linux Kernel up to 6.0.11 afe4403_read_raw out-of-bounds (WID-SEC-2024-3251)
CVE-2022-49012 | Linux Kernel up to 6.0.11 afs_put_server memory leak (c5078548c29c/ef4d3ea40565 / WID-SEC-2024-3251)
CVE-2022-49013 | Linux Kernel up to 5.4.225/5.10.157/5.15.81/6.0.11 sctp_stream_outq_migrate memory leak (WID-SEC-2024-3251)
CVE-2022-49015 | Linux Kernel up to 6.0.11 hsr netif_rx use after free (Nessus ID 210933 / WID-SEC-2024-3251)
CVE-2022-49017 | Linux Kernel up to 5.10.157/5.15.81/6.0.11 tipc_msg_validate use after free (Nessus ID 210933 / WID-SEC-2024-3251)
CVE-2022-49010 | Linux Kernel up to 6.0.11 coretemp_add_core null pointer dereference (Nessus ID 212567 / WID-SEC-2024-3251)
CVE-2022-49011 | Linux Kernel up to 6.0.11 hwmon nv1a_ram_new reference count (Nessus ID 212567 / WID-SEC-2024-3251)
Silent Scourge: Over 3,500 Websites Infected by New Covert Browser Cryptominer
Cybersecurity specialists at cside have uncovered a vast and covert cryptocurrency mining campaign that has compromised over 3,500 websites—marking the largest incident of its kind in recent years and signaling the resurgence of tactics...
The post Silent Scourge: Over 3,500 Websites Infected by New Covert Browser Cryptominer appeared first on Penetration Testing Tools.
Snake Keylogger Strikes Turkish Aerospace & Defense, Evades Detection with Stealthy Tactics
Turkish cybersecurity experts at Malwation have uncovered a large-scale phishing campaign targeting enterprises in the defense and aerospace sectors. Threat actors are disguising malicious attachments as official documents purportedly issued by TUSAŞ, Turkey’s state-owned...
The post Snake Keylogger Strikes Turkish Aerospace & Defense, Evades Detection with Stealthy Tactics appeared first on Penetration Testing Tools.