Aggregator
INC 勒索组织再袭美政府!阿拉巴马州 50GB 市政数据遭劫持
GrapheneOS Under Scrutiny: Why Privacy-Focused Pixels Are Raising Police Suspicions
Spanish police have begun casting a wary eye on users of Google Pixel smartphones, suspecting potential ties to criminal activity. In Catalonia, law enforcement officials report a growing trend of drug traffickers relying specifically...
The post GrapheneOS Under Scrutiny: Why Privacy-Focused Pixels Are Raising Police Suspicions appeared first on Penetration Testing Tools.
Nippon Steel Hit by Zero-Day Cyberattack, Exposing Data of 100K+ Employees & Partners
One of the world’s largest steel manufacturing conglomerates, the Japanese company Nippon Steel, has reported a large-scale cyberattack during which hackers gained unauthorized access to data belonging to clients, employees, and business partners. The...
The post Nippon Steel Hit by Zero-Day Cyberattack, Exposing Data of 100K+ Employees & Partners appeared first on Penetration Testing Tools.
What's the next step? Reverse Engineering a TP-Link router for vulnerabilities.
Critical Wing FTP Server Flaw (CVSS 10.0) Under Active Exploitation: Patch Now!
Researchers at Huntress have observed active exploitation of a critical vulnerability in Wing FTP Server—a mere day after its public disclosure. The flaw, tracked as CVE-2025-47812, received the highest possible severity rating (CVSS 10.0),...
The post Critical Wing FTP Server Flaw (CVSS 10.0) Under Active Exploitation: Patch Now! appeared first on Penetration Testing Tools.
GMX交易所被盗4,000万美元算是和解 黑客退回被盗资金并拿到500万美元奖金
CVE-2005-3908 | Amazon Shop prior 5.0.0 search.php Query cross site scripting (EDB-26653 / BID-15634)
Jack Dorsey’s Bitchat: Decentralized Promise, Centralized Security Concerns
Jack Dorsey, co-founder of Twitter and head of Block, recently unveiled his latest endeavor—Bitchat, a messaging application envisioned as a fully decentralized communication tool, independent of traditional internet infrastructure. Instead of relying on conventional...
The post Jack Dorsey’s Bitchat: Decentralized Promise, Centralized Security Concerns appeared first on Penetration Testing Tools.
KongTuke FileFix Leads to New Interlock RAT Variant
Critical Flaws Expose eSIMs to Cloning and Mass Surveillance, Threatening Global Mobile Security
The research laboratory Security Explorations has unveiled the results of a months-long investigation exposing critical vulnerabilities at the core of eSIM technology. The focus of their analysis was a GSMA-certified eUICC card developed by...
The post Critical Flaws Expose eSIMs to Cloning and Mass Surveillance, Threatening Global Mobile Security appeared first on Penetration Testing Tools.
KongTuke FileFix Leads to New Interlock RAT Variant
McDonald’s “123456” Password Exposes 64 Million Job Applicants’ Data
McDonald’s hiring system was found to be secured by a password so trivial that even a child might guess it—”123456.” Two elementary vulnerabilities granted access to the personal data of over 64 million job...
The post McDonald’s “123456” Password Exposes 64 Million Job Applicants’ Data appeared first on Penetration Testing Tools.
黑客利用 GitHub 传播伪装成免费 VPN 的恶意软件
黑客利用 GitHub 传播伪装成免费 VPN 的恶意软件
PerfektBlue: Critical Bluetooth Flaws Expose Millions of Cars to Remote Hacks
Four vulnerabilities within the Bluetooth stack BlueSDK, developed by OpenSynergy and collectively named PerfektBlue, pose a serious security threat to millions of vehicles. These flaws allow remote code execution on targeted devices and potentially...
The post PerfektBlue: Critical Bluetooth Flaws Expose Millions of Cars to Remote Hacks appeared first on Penetration Testing Tools.
Ducex Packer: The New Shield for Triada Android Trojan Evading Detection
Researchers have uncovered a new packer, Ducex, which conceals one of the most formidable mobile malware threats— the Triada Trojan—through advanced encryption and obfuscation techniques. Its analysis in the interactive sandbox environment ANY.RUN reveals...
The post Ducex Packer: The New Shield for Triada Android Trojan Evading Detection appeared first on Penetration Testing Tools.
Crypto Thief Gets 12 Years: Court Cracks Down on $20M SIM Swap Fraud
A federal court in New York has issued a harsh ruling in a high-profile cryptocurrency theft case. Nicholas Truglia, previously convicted for his role in the cyberattack targeting entrepreneur Michael Terpin’s digital assets, has...
The post Crypto Thief Gets 12 Years: Court Cracks Down on $20M SIM Swap Fraud appeared first on Penetration Testing Tools.