Aggregator
[remote] Tigo Energy Cloud Connect Advanced (CCA) 4.0.1 - Command Injection
[remote] Microsoft SharePoint Server 2019 (16.0.10383.20020) - Remote Code Execution (RCE)
[webapps] VMware vSphere Client 8.0.3.0 - Reflected Cross-Site Scripting (XSS)
[remote] Belkin F9K1009 F9K1010 2.00.04/2.00.09 - Hard Coded Credentials
[webapps] Ghost CMS 5.42.1 - Path Traversal
[webapps] Ghost CMS 5.59.1 - Arbitrary File Read
[webapps] ServiceNow Multiple Versions - Input Validation & Template Injection
[webapps] JetBrains TeamCity 2023.11.4 - Authentication Bypass
冻结I/O:基于VSS实现零数据丢失备份
Your Private Chats Aren’t Private: Over 130,000 Chatbot Conversations Exposed on the Internet Archive
A researcher operating under the pseudonym dead1nfluence has discovered that the Internet Archive contains over 130,000 recorded conversations with popular chatbots — including Claude, Grok, ChatGPT, and others. This finding suggests that with improper...
The post Your Private Chats Aren’t Private: Over 130,000 Chatbot Conversations Exposed on the Internet Archive appeared first on Penetration Testing Tools.
Google Reveals a Far More Dangerous ‘Retbleed’ Exploit for AMD CPUs
Researchers at Google have unveiled an enhanced method for exploiting the Retbleed vulnerability — a flaw that enables the extraction of arbitrary data from the memory of any process on affected systems. This weakness...
The post Google Reveals a Far More Dangerous ‘Retbleed’ Exploit for AMD CPUs appeared first on Penetration Testing Tools.
Alascom Falls Victim to Rhysida Ransomware
Weyhro
You must login to view this content
Weyhro
You must login to view this content
New EDR Killer Tool Allows Ransomware to Cripple Security Solutions
A new tool for disabling EDR systems has emerged in the cybercriminal underground, which Sophos researchers regard as an evolution of the EDRKillShifter utility. Its use has already been documented in attacks by eight...
The post New EDR Killer Tool Allows Ransomware to Cripple Security Solutions appeared first on Penetration Testing Tools.
Hacking Satellites Is Easier Than Ever: Critical Flaws Found in Open-Source Space Software
At the Black Hat conference in Las Vegas, representatives from VisionSpace Technologies demonstrated that disabling a satellite or altering its trajectory can be achieved far more easily — and at a fraction of the...
The post Hacking Satellites Is Easier Than Ever: Critical Flaws Found in Open-Source Space Software appeared first on Penetration Testing Tools.