Aggregator
欧洲批准了 Moderna 的流感和 COVID-19 联合疫苗
CVE-2026-7217 | Deepractice PromptX up to 2.4.0 Document File index.ts path absolute path traversal (Issue 571)
Submit #808194: TOTOLINK N300RT Router V3.4.0-B20250430 Buffer Overflow [Accepted]
Submit #802127: Totolink N300RT Router V3.4.0-B20250430 Buffer Overflow [Accepted]
Inside the Protocol: Master Kerberos Defense and Detection with Kerlab’s Rust Toolkit
Kerlab A Rust implementation of Kerberos for FUn and Detection Kerlab was developed just to drill down kerberos protocol and
The post Inside the Protocol: Master Kerberos Defense and Detection with Kerlab’s Rust Toolkit appeared first on Penetration Testing Tools.
Disinformation campaign targeted Tibetan parliament-in-exile elections
CVE-2026-7216 | donchelo processing-claude-mcp-bridge up to e017b20a4b592a45531a6392f494007f04e661bd create_sketch Tool processing_server.py sketch_name path traversal
Submit #802120: Deepractice PromptX 2.4.0 Improper Authorization [Accepted]
CVE-2026-7215 | egtai gmx-vmd-mcp up to 0.1.0 VMD Launch mcp_server.py launch_vmd_gui_tool structure_file/trajectory_file command injection
Submit #802090: donchelo processing-claude-mcp-bridge e017b20a4b592a45531a6392f494007f04e661bd Path Traversal [Accepted]
Submit #802087: egtai gmx-vmd-mcp 0.1.0 Command Injection [Accepted]
Under Active Fire: CISA Warns of New Exploits in Samsung, SimpleHelp, and D-Link Hardware
The United States Cybersecurity and Infrastructure Security Agency (CISA) has once again augmented its repository of vulnerabilities identified
The post Under Active Fire: CISA Warns of New Exploits in Samsung, SimpleHelp, and D-Link Hardware appeared first on Penetration Testing Tools.
PyPI package with 1.1M monthly downloads hacked to push infostealer
影响Firefox与Tor浏览器的跨会话指纹跟踪漏洞
The Zero-Click Ghost: How an Incomplete Patch Left Windows Open to Fancy Bear’s Credential Theft
An oversight within a security remediation has inadvertently carved a novel path for exploitation. While the developers successfully
The post The Zero-Click Ghost: How an Incomplete Patch Left Windows Open to Fancy Bear’s Credential Theft appeared first on Penetration Testing Tools.
CVE-2026-7214 | eghuzefa engineer-your-data up to 0.1.3 src/server.py read_file/write_file/list_files/file_inf WORKSPACE_PATH path traversal
Легальный сайт не открылся? А виновата «защита». Как сервисы операторов фильтруют трафик и где грань между безопасностью и цензурой
Italy extradites alleged Chinese state hacker to US
The “Unpatchable” Ghost: How PhantomRPC Turns Windows Architecture Against Itself for SYSTEM Control
Security researchers at Kaspersky Lab have identified a surreptitious methodology within Windows to obtain absolute systemic hegemony—a vulnerability
The post The “Unpatchable” Ghost: How PhantomRPC Turns Windows Architecture Against Itself for SYSTEM Control appeared first on Penetration Testing Tools.