Aggregator
新漏洞又扎堆?AI:已锁定资产!
新漏洞又扎堆?AI:已锁定资产!
某红队最新高级免杀样本分析
某红队最新高级免杀样本分析
ZMap 十年回首
3500余个网站遭劫持:攻击者利用隐蔽JavaScript与WebSocket技术秘密挖矿
NativeDump: Stealthy LSASS Dumping Tool Bypasses EDRs Using Only NTAPIs
NativeDump allows to dump the lsass process using only NTAPIs generating a Minidump file with only the streams needed to be parsed by tools like Mimikatz or Pypykatz (SystemInfo, ModuleList and Memory64List Streams). NTOpenProcessToken...
The post NativeDump: Stealthy LSASS Dumping Tool Bypasses EDRs Using Only NTAPIs appeared first on Penetration Testing Tools.
CVE-2025-7911 | D-Link DI-8100 1.0 jhttpd /upnp_ctrl.asp sprintf remove_ext_proto/remove_ext_port stack-based overflow (EUVD-2025-22044)
CVE-2025-7912 | TOTOLINK T6 4.1.5cu.748_B20211015 MQTT Service recvSlaveUpgstatus buffer overflow (EUVD-2025-22043)
Intel Axes High-Performance Clear Linux: End of an Era for a Decade of Innovation
Intel has officially announced the discontinuation of Clear Linux—one of the most high-performing and innovative Linux distributions in recent years. This decision comes as part of the company’s broader cost-cutting initiative. Designed from the...
The post Intel Axes High-Performance Clear Linux: End of an Era for a Decade of Innovation appeared first on Penetration Testing Tools.
Akira Ransomware Unleashes Double Extortion Barrage on 12 Global Companies in 72 Hours
The Akira ransomware group has intensified its operations, adding data from 12 new companies to its dark web leak portal within just three days—from July 15 to 17, 2025. This surge in attacks targeted...
The post Akira Ransomware Unleashes Double Extortion Barrage on 12 Global Companies in 72 Hours appeared first on Penetration Testing Tools.
CVE-2017-17417 | Quest NetVault Backup up to 11.3.0.11 sql injection (EDB-46446 / Nessus ID 119681)
New Linuxsys Cryptominer Campaign Exploits Apache HTTP Server & Other Critical Flaws
Researchers at VulnCheck have uncovered a new malicious campaign exploiting the CVE-2021-41773 vulnerability in Apache HTTP Server version 2.4.49. This flaw enables remote code execution by bypassing path traversal protections, allowing attackers to access...
The post New Linuxsys Cryptominer Campaign Exploits Apache HTTP Server & Other Critical Flaws appeared first on Penetration Testing Tools.