Aggregator
CVE-2025-27209 | Node.js up to 24.4.0 V8 denial of service (EUVD-2025-21940 / Nessus ID 242134)
CVE-2025-7394 | wolfSSL up to 5.8.0 RAND_poll random values (EUVD-2025-21938)
CVE-2025-7395 | wolfSSL up to 5.8.0 Server Certificate Domain certificate validation (EUVD-2025-21936)
CVE-2025-7855 | Tenda FH451 1.0.0.9 /goform/qossetting fromqossetting page stack-based overflow (EUVD-2025-21976)
CVE-2025-7854 | Tenda FH451 1.0.0.9 /goform/VirtualSer fromVirtualSer page stack-based overflow (EUVD-2025-21977)
CVE-2025-7853 | Tenda FH451 1.0.0.9 /goform/SetIpBind fromSetIpBind page stack-based overflow (EUVD-2025-21974)
Submit #616367: Tenda FH451 v1.0.0.9 Buffer Overflow [Accepted]
Submit #616366: Tenda FH451 v1.0.0.9 Buffer Overflow [Accepted]
Submit #616359: Tenda FH451 v1.0.0.9 Buffer Overflow [Accepted]
CISA Warns of Fortinet FortiWeb SQL Injection Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Fortinet FortiWeb vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation of the SQL injection flaw in cyberattacks worldwide. The vulnerability, tracked as CVE-2025-25257, affects Fortinet’s FortiWeb web application firewall and carries a severe CVSS score of 9.6 out of 10. […]
The post CISA Warns of Fortinet FortiWeb SQL Injection Vulnerability Exploited in Attacks appeared first on Cyber Security News.
How We Got In: Red team story targeting a Fortune 500 payment system
New CrushFTP zero-day exploited in attacks to hijack servers
上下文工程:打造下一代 AI Agent 的 7 条血泪经验 | Manus 创始人亲述
Unlocking Generative Power: Multi-Token Prediction for Next-Gen LLMs
Defining the Frontier: Multi-Token Prediction's Place in LLM Evolution
Wii U SDBoot1 Exploit “paid the beak”
New SquidLoader Variant Unleashed: Stealthy Malware Hits Hong Kong Financial Sector Undetected
A newly discovered version of the SquidLoader malware has surfaced during a targeted attack on institutions in Hong Kong, sparking significant concern within the financial sector. Of particular alarm is its near-complete evasion of...
The post New SquidLoader Variant Unleashed: Stealthy Malware Hits Hong Kong Financial Sector Undetected appeared first on Penetration Testing Tools.
Microsoft Copilot Gets “Eyes”: New Desktop Share Feature Analyzes Your Screen in Real-Time
Microsoft has begun rolling out an update to the Copilot app for Windows, significantly enhancing its artificial intelligence capabilities through the introduction of the Desktop Share feature. With this update, Copilot can now “see”...
The post Microsoft Copilot Gets “Eyes”: New Desktop Share Feature Analyzes Your Screen in Real-Time appeared first on Penetration Testing Tools.
SonicWall SMA 100 Devices Under Persistent Attack: UNC6148 Deploys Stealthy OVERSTEP Rootkit
Attacks targeting outdated SonicWall SMA 100 devices have once again exposed the fragility of network perimeters often overlooked by conventional security systems. According to the Google Threat Intelligence Group (GTIG), a targeted campaign employing...
The post SonicWall SMA 100 Devices Under Persistent Attack: UNC6148 Deploys Stealthy OVERSTEP Rootkit appeared first on Penetration Testing Tools.