Aggregator
Google Gemini for Workspace Vulnerability Lets Attackers Hide Malicious Scripts in Emails
Security researchers have uncovered a significant vulnerability in Google Gemini for Workspace that enables threat actors to embed hidden malicious instructions within emails. The attack exploits the AI assistant’s “Summarize this email” feature to display fabricated security warnings that appear to originate from Google itself, potentially leading to credential theft and social engineering attacks. Key […]
The post Google Gemini for Workspace Vulnerability Lets Attackers Hide Malicious Scripts in Emails appeared first on Cyber Security News.
俄籍数据贩子公然在 Telegram 贩卖个人信息,遭印尼引渡回国
俄籍数据贩子公然在 Telegram 贩卖个人信息,遭印尼引渡回国
ISC Stormcast For Monday, July 14th, 2025 https://isc.sans.edu/podcastdetail/9524, (Mon, Jul 14th)
CVE-2009-0882 | Roman Bogorodskiy nForum 1.5 showtheme.php sql injection (EDB-8170 / BID-34030)
Adobe PDF 阅读器和华硕系统控制器中发现重大安全漏洞
Adobe PDF 阅读器和华硕系统控制器中发现重大安全漏洞
JS漏洞挖掘|分享使用FindSomething联动的挖掘思路
JS漏洞挖掘|分享使用FindSomething联动的挖掘思路
INC 勒索组织再袭美政府!阿拉巴马州 50GB 市政数据遭劫持
INC 勒索组织再袭美政府!阿拉巴马州 50GB 市政数据遭劫持
GrapheneOS Under Scrutiny: Why Privacy-Focused Pixels Are Raising Police Suspicions
Spanish police have begun casting a wary eye on users of Google Pixel smartphones, suspecting potential ties to criminal activity. In Catalonia, law enforcement officials report a growing trend of drug traffickers relying specifically...
The post GrapheneOS Under Scrutiny: Why Privacy-Focused Pixels Are Raising Police Suspicions appeared first on Penetration Testing Tools.
Nippon Steel Hit by Zero-Day Cyberattack, Exposing Data of 100K+ Employees & Partners
One of the world’s largest steel manufacturing conglomerates, the Japanese company Nippon Steel, has reported a large-scale cyberattack during which hackers gained unauthorized access to data belonging to clients, employees, and business partners. The...
The post Nippon Steel Hit by Zero-Day Cyberattack, Exposing Data of 100K+ Employees & Partners appeared first on Penetration Testing Tools.
What's the next step? Reverse Engineering a TP-Link router for vulnerabilities.
Critical Wing FTP Server Flaw (CVSS 10.0) Under Active Exploitation: Patch Now!
Researchers at Huntress have observed active exploitation of a critical vulnerability in Wing FTP Server—a mere day after its public disclosure. The flaw, tracked as CVE-2025-47812, received the highest possible severity rating (CVSS 10.0),...
The post Critical Wing FTP Server Flaw (CVSS 10.0) Under Active Exploitation: Patch Now! appeared first on Penetration Testing Tools.
GMX交易所被盗4,000万美元算是和解 黑客退回被盗资金并拿到500万美元奖金
CVE-2005-3908 | Amazon Shop prior 5.0.0 search.php Query cross site scripting (EDB-26653 / BID-15634)
Jack Dorsey’s Bitchat: Decentralized Promise, Centralized Security Concerns
Jack Dorsey, co-founder of Twitter and head of Block, recently unveiled his latest endeavor—Bitchat, a messaging application envisioned as a fully decentralized communication tool, independent of traditional internet infrastructure. Instead of relying on conventional...
The post Jack Dorsey’s Bitchat: Decentralized Promise, Centralized Security Concerns appeared first on Penetration Testing Tools.