Aggregator
CVE-2025-25171 | ThemesGrove WP SmartPay Plugin up to 2.7.13 on WordPress authentication bypass (EUVD-2025-19262)
CVE-2014-4741 | Artifectx xClassified 1.2 catid sql injection (ID 127370 / EDB-39239)
Resupply Crypto Exploit: $10M Debt Hole Created Via Smart Contract Logic Flaw
The cryptocurrency project Resupply has found itself at the epicenter of a cyber incident following a sophisticated exploit that enabled an attacker to engineer a debt hole totaling 10 million reUSD. The breach affected...
The post Resupply Crypto Exploit: $10M Debt Hole Created Via Smart Contract Logic Flaw appeared first on Penetration Testing Tools.
Cybersecurity jobs available right now: July 1, 2025
Application Security Engineer Fireblocks | Israel | Hybrid – View job details As an Application Security Engineer, you will improve and secure the company’s continuous integration and deployment pipelines through CI/CD security hardening. You will operate, fine-tune, and customize security tooling such as Snyk, Apiiro, and other application security platforms to reduce false positives and enhance threat detection. Application Security Engineer Cambridge University Press & Assessment | Philippines | On-site – View job details As … More →
The post Cybersecurity jobs available right now: July 1, 2025 appeared first on Help Net Security.
Abusing Chrome Remote Desktop on Red Team Operations: A Practical Guide
FBI Warns: Scattered Spider Unleashes Social Engineering & Ransomware on Aviation Sector
The United States Federal Bureau of Investigation has issued an official warning regarding the escalating operations of the hacker collective known as Scattered Spider, which has now begun actively targeting the aviation sector. According...
The post FBI Warns: Scattered Spider Unleashes Social Engineering & Ransomware on Aviation Sector appeared first on Penetration Testing Tools.
Arctic Wolf Exposes “GIFTEDCROOK”: China-Linked APT Launches Evolving Cyber-Espionage on Ukraine Military
The hacker group UAC-0226 continues to aggressively evolve its malicious tool GIFTEDCROOK, which initially functioned as a browser data-stealing utility but has now acquired advanced capabilities, enabling the targeted exfiltration of confidential documents and...
The post Arctic Wolf Exposes “GIFTEDCROOK”: China-Linked APT Launches Evolving Cyber-Espionage on Ukraine Military appeared first on Penetration Testing Tools.
2025网络安全人才生态调查
CVE-2025-40731 | Daily Expense Manager 1.0 /update.php pname/pprice/id sql injection (EUVD-2025-19562)
CVE-2024-23963 | Alpine Halo9 stack-based overflow (EUVD-2024-21389)
CVE-2024-23968 | ChargePoint Home Flex SrvrToSmSetAutoChnlListMsg stack-based overflow (ZDI-24-1050 / EUVD-2024-21394)
CVE-2024-23970 | ChargePoint Home Flex certificate validation (ZDI-24-1052 / EUVD-2024-21396)
CVE-2024-23921 | ChargePoint Home Flex wlanapp command injection (ZDI-24-1049 / EUVD-2024-21351)
CVE-2025-5304 | PT Project Notebooks Plugin up to 1.1.3 on WordPress wpnb_pto_new_users_add authorization (EUVD-2025-19577)
CVE-2025-5937 | MicroPayments Plugin up to 3.2.0 on WordPress Setting adminOptions cross-site request forgery (EUVD-2025-19575)
CVE-2025-45931 | D-Link DIR-816 1.10CNB05_R1B011D88210 bin/goahead system privilege escalation (EUVD-2025-19574)
CVE-2025-6938 | code-projects Simple Pizza Ordering System 1.0 /editcus.php ID sql injection (EUVD-2025-19599)
Silver Fox Unleashes Sainbox RAT & Hidden Rootkit Via Fake Software Installers
The Chinese hacker collective known as Silver Fox, also operating under the alias Void Arachne, has once again drawn the attention of cybersecurity experts. According to Netskope, a new malicious campaign has been uncovered...
The post Silver Fox Unleashes Sainbox RAT & Hidden Rootkit Via Fake Software Installers appeared first on Penetration Testing Tools.