Aggregator
CVE-2025-30996 | Themify edmin Theme on WordPress unrestricted upload (EUVD-2026-0951)
CVE-2025-69223 | aio-libs aiohttp up to 3.13.2 data amplification (GHSA-6mq8-rvhq-8wgg / EUVD-2025-206229)
CVE-2025-30996 | Themify bloggie Theme on WordPress unrestricted upload (EUVD-2026-0951)
お知らせ:CyberNewsFlash「React Server Componentsの脆弱性(CVE-2025-55182)について」(更新)
CVE-2023-34167 | Huawei EMUI/Magic UI Icon access control (EUVD-2023-38267)
CVE-2023-34166 | Huawei EMUI/Magic UI API denial of service (EUVD-2023-38266)
CVE-2023-34188 | Cesenta Mongoose up to 7.9 Header Content-Length privilege escalation (EUVD-2023-38288)
CVE-2023-34163 | Huawei EMUI/Magic UI Window Management permission (EUVD-2023-38263)
Identity security planning for 2026 is shifting under pressure
Identity security planning is becoming more focused on scale, governance, and operational strain, according to the Identity Security Outlook 2026 report. The ManageEngine research draws on responses from 515 identity and security leaders in the United States and Canada and reflects budget holders and practitioners who manage day-to-day identity systems. The findings point to three forces shaping near-term strategy: growth in non-human identities, uneven use of AI in identity operations, and sustained momentum toward vendor … More →
The post Identity security planning for 2026 is shifting under pressure appeared first on Help Net Security.
CVE-2025-58147 | Xen Viridian Hypercall vpmask_set out-of-bounds write (EUVD-2025-37345 / Nessus ID 271656)
CVE-2025-62504 | Envoy up to 1.33.11/1.34.9/1.35.5/1.36.1 per_connection_buffer_limit_bytes use after free (GHSA-gcxr-6vrp-wff3 / Nessus ID 281808)
CVE-2025-58149 | Xen PCI Device Unplug permission (EUVD-2025-37346 / Nessus ID 271788)
CVE-2025-62409 | Envoy up to 1.33.9/1.34.8/1.35.4/1.36.0 null pointer dereference (GHSA-pq33-4jxh-hgm3 / Nessus ID 281808)
Unmasking the Code: JS Analyzer Automates JavaScript Recon & Secret Discovery
JS Analyzer A powerful Burp Suite extension for JavaScript static analysis. Extracts API endpoints, URLs, secrets, and email
The post Unmasking the Code: JS Analyzer Automates JavaScript Recon & Secret Discovery appeared first on Penetration Testing Tools.
CVE-2025-31051 | Gardening & Houseplants Theme Plugin up to 1.0.0 on WordPress information disclosure (EUVD-2025-206256)
CVE-2025-31642 | WPCHURCH Plugin up to 2.7.0 on WordPress cross site scripting (EUVD-2025-206257)
CVE-2025-14318 | M-Files Server up to 25.11 Download Prevention authorization (EUVD-2025-204039 / WID-SEC-2025-2878)
Love and Larceny: How Hinge Was Repurposed Into a Malware Control Hub
A security researcher has demonstrated an unconventional scenario in which the popular dating app Hinge can be repurposed
The post Love and Larceny: How Hinge Was Repurposed Into a Malware Control Hub appeared first on Penetration Testing Tools.
The Discord Hijacker: VVS Stealer Uses PyArmor to Evade EDR
A detailed technical analysis of the malware known as VVS Stealer, also referred to as VVS $tealer, has
The post The Discord Hijacker: VVS Stealer Uses PyArmor to Evade EDR appeared first on Penetration Testing Tools.