Aggregator
【安全圈】LockBit勒索软件重回市场
实战 | 记一次X站逻辑漏洞到到管理员后台
Танк с глазами дрона и мозгом ИИ. Type 100 превращает поле боя в симуляцию, где человек больше не нужен
CVE-2007-0828 | MySQLNewsEngine MySQL affichearticles.php3 newsenginedir file inclusion (EDB-29569 / XFDB-32266)
CVE-2007-2710 | NagiosQL 2.00-p00 prepend_adm.php SETS[path][IT] file inclusion (EDB-3919 / XFDB-34268)
CVE-2007-0491 | Sky GUNNING MySpeach 3.0.6 up.php my_ms[root] file inclusion (EDB-3165 / SA23850)
CVE-2007-6136 | M2Scripts My Space Scripts Poll Creator 0 index.php cross site scripting (EDB-30799 / XFDB-38633)
CVE-2007-2325 | MyNewsGroup MyNews include.php file inclusion (EDB-29899 / XFDB-33867)
Windows Server WSUS Flaw Under Active Attack (CVE-2025-59287, CVSS 9.8) with Public PoC
Hackers have begun actively exploiting a newly disclosed vulnerability in the Windows Server Update Services (WSUS) component. The
The post Windows Server WSUS Flaw Under Active Attack (CVE-2025-59287, CVSS 9.8) with Public PoC appeared first on Penetration Testing Tools.
Jingle Thief: Cloud-Native Fraud Ring Steals Millions via Microsoft 365 Gift Cards
The Unit 42 team at Palo Alto Networks has released an in-depth investigation into a new international cybercrime
The post Jingle Thief: Cloud-Native Fraud Ring Steals Millions via Microsoft 365 Gift Cards appeared first on Penetration Testing Tools.
《你尽力了吗——25年后的再追问》
《你尽力了吗——25年后的再追问》
High-Value Targets: MuddyWater APT Used Compromised VPN Mailbox in Stealth Campaign
Group-IB’s Threat Intelligence team has published a detailed analysis of a new cyber-espionage campaign very likely attributable to
The post High-Value Targets: MuddyWater APT Used Compromised VPN Mailbox in Stealth Campaign appeared first on Penetration Testing Tools.
Mozilla Demands New Firefox Extensions Disclose Data Collection Practices
Beginning November 3, 2025, all developers submitting new Firefox extensions will be required to specify in their manifest.json
The post Mozilla Demands New Firefox Extensions Disclose Data Collection Practices appeared first on Penetration Testing Tools.
Windows Blocks File Previews to Stop NTLM Credential Leaks
Beginning with the October 2025 Windows security updates, File Explorer now automatically blocks the preview of files downloaded
The post Windows Blocks File Previews to Stop NTLM Credential Leaks appeared first on Penetration Testing Tools.
The Global Cascade: AWS Outage Caused by Automated DNS Race Condition
Amazon has published a comprehensive technical report detailing the outage that paralyzed major online platforms and triggered a
The post The Global Cascade: AWS Outage Caused by Automated DNS Race Condition appeared first on Penetration Testing Tools.
Fedora Adopts Groundbreaking AI Policy: Full Accountability for Code Contributions
The Fedora community has officially adopted a comprehensive policy governing the use of artificial intelligence in the creation
The post Fedora Adopts Groundbreaking AI Policy: Full Accountability for Code Contributions appeared first on Penetration Testing Tools.
Cyber Awareness Month: Protecting Your Child in the Digital Age
How can you be a cyber-smart parent? In this interview with Chad Rychlewski, the co-author of a new book, we unpack what family online protection looks like in 2025.
The post Cyber Awareness Month: Protecting Your Child in the Digital Age appeared first on Security Boulevard.