Aggregator
Golden dMSA: Critical Windows Server 2025 Flaw Allows Full Active Directory Takeover
A newly discovered vulnerability in Windows Server 2025—dubbed Golden dMSA—poses a grave risk of widespread compromise across entire Active Directory infrastructures, according to a technical report published by enterprise cybersecurity firm Semperis. The issue...
The post Golden dMSA: Critical Windows Server 2025 Flaw Allows Full Active Directory Takeover appeared first on Penetration Testing Tools.
Masquerade: You Downloaded ScreenConnect not Grok AI!
Paradox.ai Data Breach: “123456” Password & Nexus Stealer Expose Fortune 500 Clients
A recent data breach has exposed a critical vulnerability in the systems of Paradox.ai, the developer behind AI-powered chatbots used in recruitment processes at McDonald’s and other Fortune 500 corporations. The cause of this...
The post Paradox.ai Data Breach: “123456” Password & Nexus Stealer Expose Fortune 500 Clients appeared first on Penetration Testing Tools.
CVE-2025-7747 | Tenda FH451 1.0.0.9 POST Request /goform/WizardHandle fromWizardHandle PPW buffer overflow (EUVD-2025-21787)
CVE-2025-7749 | code-projects Online Appointment Booking System 1.0 getmanagerregion.php city sql injection (EUVD-2025-21794)
CVE-2025-7750 | code-projects Online Appointment Booking System 1.0 adddoctorclinic.php clinic sql injection (EUVD-2025-21812)
CVE-2025-7751 | code-projects Online Appointment Booking System 1.0 /admin/addclinic.php cid sql injection (EUVD-2025-21809)
CVE-2025-7752 | code-projects Online Appointment Booking System 1.0 /admin/deletedoctor.php did sql injection (EUVD-2025-21817)
CVE-2025-7753 | code-projects Online Appointment Booking System 1.0 /admin/adddoctor.php Username sql injection (EUVD-2025-21819)
CVE-2025-25257 | Fortinet FortiWeb up to 7.0.10/7.2.10/7.4.7/7.6.3 HTTP Request sql injection (FG-IR-25-151 / EUVD-2025-21785)
CVE-2025-52046 | TOTOLINK A3300R 17.0.0cu.596_B20250515 sub_4197C0 desc command injection
CVE-2025-50240 | nbcio-boot 1.0.3 deleteRecycleBin userIds sql injection (EUVD-2025-21793)
CVE-2025-7756 | code-projects E-Commerce Site 1.0 cross-site request forgery (EUVD-2025-21822)
CVE-2025-7754 | code-projects Patient Record Management System 1.0 /xray_form.php itr_no sql injection (EUVD-2025-21825)
CVE-2025-23090 | Node.js up to 20.18.1/22.13.0/23.6.0 diagnostics_channel Utility permission (EUVD-2025-3118)
新型PDF二维码攻击规避检测系统并窃取凭证
Year in Review: Looking Back at Godot's 2024
[技巧] 使用TSforge可以直接获得3年Windows 10 ESU扩展安全支持 操作方法如下
HITCON Cyber Range 2025 Quals
Date: July 18, 2025, 2 a.m. — 18 July 2025, 15:59 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://hitcon.kktix.cc/events/hitcon-cyberrange-2025
Rating weight: 0.00
Event organizers: HITCON