Aggregator
Google Launches OSS Rebuild: A New Weapon Against Open-Source Supply Chain Attacks
Open-source software forms the bedrock of today’s digital infrastructure, powering 77% of all applications and valued at over $12 trillion. Yet its widespread adoption renders it an increasingly attractive target for supply chain attacks,...
The post Google Launches OSS Rebuild: A New Weapon Against Open-Source Supply Chain Attacks appeared first on Penetration Testing Tools.
Microsoft Confirms China-Backed APTs Actively Exploiting SharePoint Zero-Days (CVE-2025-53770, -53771)
Microsoft has confirmed that three China-linked threat groups were behind the recent wave of attacks targeting on-premises SharePoint Server installations. According to the company’s report, since early July, the vulnerabilities identified as CVE-2025-53770 and...
The post Microsoft Confirms China-Backed APTs Actively Exploiting SharePoint Zero-Days (CVE-2025-53770, -53771) appeared first on Penetration Testing Tools.
CVE-2024-35138 | IBM Security Verify Access Appliance up to 10.0.8 cross-site request forgery (EUVD-2024-35550)
DeerStealer: New Malware Uses Stealthy LNK & LOLBins for Undetectable Data Theft
A newly uncovered malicious campaign involving the infostealer DeerStealer has been identified by researchers at ANY.RUN. Threat actors are employing a sophisticated tactic—combining Windows shortcut files (LNK) with trusted system utilities known as Living-off-the-Land...
The post DeerStealer: New Malware Uses Stealthy LNK & LOLBins for Undetectable Data Theft appeared first on Penetration Testing Tools.
Weak Password Destroys 158-Year-Old UK Transport Company: Akira Ransomware Claims 700 Jobs
In 2023, one of the United Kingdom’s oldest transport companies—established 158 years ago—declared bankruptcy following a devastating ransomware attack. The cyber assault brought the operations of Knights of Old (also known as KNP) to...
The post Weak Password Destroys 158-Year-Old UK Transport Company: Akira Ransomware Claims 700 Jobs appeared first on Penetration Testing Tools.
使用Ai8051模拟fx2lafw设备制作简易逻辑分析仪
使用Ai8051模拟fx2lafw设备制作简易逻辑分析仪
无线充电联盟WPC宣布Qi2 25W充电选项 即将发布的安卓旗舰机预计都提供支持
CVE-2003-0763 | Squished Mosquito Escapade Scripting Engine PAGE cross site scripting (EDB-23127 / ID 11401)
CVE-2003-0764 | Squished Mosquito Escapade Scripting Engine Error Message PAGE information disclosure (ID 11414)
CVE-2003-0772 | Ipswitch WS_FTP Server 3.x/4.x APPE/STAT Command memory corruption (VU#219140 / EDB-1158)
CVE-2003-0770 | Ikonboard 3.1.1/3.1.2a Cookie FUNC.pm lang memory corruption (EDB-22499 / Nessus ID 11605)
CVE-2003-0780 | Sun MySQL up to 3.0.57/4.0.14 Password Field memory corruption (VU#516492 / EDB-98)
CVE-2004-0124 | Microsoft Windows NT 4.0/2000/XP/Server 2003 RPC/DCOM Object Identity Remote Code Execution (MS04-012 / VU#212892)
CVE-2003-0812 | Microsoft Windows 2000/XP Workstation Service stack-based overflow (MS03-049 / VU#567620)
Cisco ISE Critical RCE Zero-Days (CVSS 10.0) Actively Exploited In The Wild – Patch Immediately!
Recently uncovered critical vulnerabilities in Cisco’s infrastructure are already being actively exploited by malicious actors to compromise corporate networks. The company has officially confirmed that its Product Security Incident Response Team (PSIRT) has observed...
The post Cisco ISE Critical RCE Zero-Days (CVSS 10.0) Actively Exploited In The Wild – Patch Immediately! appeared first on Penetration Testing Tools.