Aggregator
【火绒安全周报】黑客校友持续攻击母校被捕/恶意软件伪装WordPress插件窃密
【火绒安全周报】黑客校友持续攻击母校被捕/恶意软件伪装WordPress插件窃密
微软正将杀毒软件移出 Windows 内核
诚邀渠道合作伙伴共启新征程
诚邀渠道合作伙伴共启新征程
MOVEit Transfer Systems Face Fresh Attack Risk Following Scanning Activity Surge
Loki: Node.js Command & Control for Script-Jacking Vulnerable Electron Applications
Loki is a stage-1 command and control (C2) framework written in Node.js, built to script-jack vulnerable Electron apps MITRE ATT&CK T1218.015. Developed for red team operations, Loki enables evasion of security software and bypasses application...
The post Loki: Node.js Command & Control for Script-Jacking Vulnerable Electron Applications appeared first on Penetration Testing Tools.
李继刚老师之前在即刻发了一条“知识星球是时间的朋友”
Windows Says Goodbye to Blue Screen of Death, Introduces Black Screen
After nearly four decades as a symbol of frustration and failure for PC users worldwide, Microsoft is officially retiring the iconic Blue Screen of Death (BSOD) in favor of a new, sleeker Black Screen of Death. The change, set to roll out later this summer with Windows 11 version 24H2, marks the most significant visual […]
The post Windows Says Goodbye to Blue Screen of Death, Introduces Black Screen appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Abstract Security Adds Data Lake to Reduce Storage Costs
Abstract Security Adds Data Lake to Reduce Storage Costs
Abstract Security this week added a data lake, dubbed LakeVilla, to a portfolio of tools for migrating data between cybersecurity tools to provide a less expensive alternative to a security information event management (SIEM) platform for storing data.
The post Abstract Security Adds Data Lake to Reduce Storage Costs appeared first on Security Boulevard.
Открыли VS Code с утра? Кто-то уже переписал ваш код — и это не коллега
CISA Warns: Critical AMI MegaRAC Firmware Flaw (CVE-2024-54085, CVSS 10.0) Actively Exploited for Server Takeover
Hackers have begun actively exploiting a critical vulnerability that grants them full control over thousands of servers, including those performing vital functions in data centers. This alarming development has prompted a warning from the...
The post CISA Warns: Critical AMI MegaRAC Firmware Flaw (CVE-2024-54085, CVSS 10.0) Actively Exploited for Server Takeover appeared first on Penetration Testing Tools.
CVE-2025-5526 | BuddyPress Docs Plugin up to 2.2.4 on WordPress Download File authorization
CVE-2025-5194 | WP Map Block Plugin up to 2.0.2 on WordPress Block Option cross site scripting
CVE-2025-5093 | Responsive Lightbox & Gallery Plugin up to 2.5.1 on WordPress Swipebox Library cross site scripting
CVE-2025-5035 | Firelight Lightbox Plugin up to 2.3.15 on WordPress cross site scripting
Mitsubishi Electric AC Flaw Lets Hackers Remotely Control Systems
A critical security vulnerability has been discovered in multiple Mitsubishi Electric air conditioning systems, potentially allowing hackers to bypass authentication and remotely control affected units. The flaw, identified as CVE-2025-3699, was disclosed by Mitsubishi Electric on June 26, 2025, and has been assigned a maximum CVSS base score of 9.8, indicating its severity. Authentication Bypass […]
The post Mitsubishi Electric AC Flaw Lets Hackers Remotely Control Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Windows 11 Retires Blue Screen of Death: New Black Crash Screen Focuses on Faster Diagnostics
Microsoft is preparing a significant overhaul of the infamous Blue Screen of Death (BSOD) in Windows. As part of the Windows Resiliency Initiative, the iconic blue error screen will be replaced by a new...
The post Windows 11 Retires Blue Screen of Death: New Black Crash Screen Focuses on Faster Diagnostics appeared first on Penetration Testing Tools.