Aggregator
CVE-2025-0818 | File Manager Pro Plugin on WordPress path traversal
CVE-2025-8491 | Easy Restaurant Menu Manager Plugin up to 2.0.2 on WordPress nsc_eprm_save_menu cross-site request forgery
CVE-2025-8760 | INSTAR 2K+/4K 3.11.1 Build 1124 fcgi_server base64_decode Authorization buffer overflow (MZ-25-03 / EUVD-2025-24545)
CVE-2025-8761 | INSTAR 2K+/4K 3.11.1 Build 1124 Backend IPC Server denial of service (MZ-25-03 / EUVD-2025-24543)
CVE-2025-8762 | INSTAR 2K+/4K 3.11.1 Build 1124 UART Interface improper physical access control (MZ-25-03 / EUVD-2025-24544)
Phishing to PowerShell RAT: New Fileless Attack Targets Israeli Critical Infrastructure
Analysts from FortiMail Workspace Security have uncovered a targeted campaign against Israeli companies and organizations within critical infrastructure sectors. The attackers exploited a compromised internal email system to send highly convincing messages to regional...
The post Phishing to PowerShell RAT: New Fileless Attack Targets Israeli Critical Infrastructure appeared first on Penetration Testing Tools.
Telegram Fights Back: Platform Purges Channels Used for Extortion and Doxxing
Pavel Durov announced that over the past 20 days, Telegram has received hundreds of reports from users about cases of extortion and doxxing. Based on these complaints, the platform initiated a large-scale purge of...
The post Telegram Fights Back: Platform Purges Channels Used for Extortion and Doxxing appeared first on Penetration Testing Tools.
Saveitforparts: Receiving NOAA-15 One Last Time
AIOps Under Threat: Researchers Demonstrate How to Poison AI to Hack IT Infrastructure
Automation of IT infrastructure management through artificial intelligence, as revealed in a recent study by RSAC Labs and George Mason University, may carry substantial risks. The researchers found that AIOps solutions—systems leveraging models akin...
The post AIOps Under Threat: Researchers Demonstrate How to Poison AI to Hack IT Infrastructure appeared first on Penetration Testing Tools.
GPT-5 Under Fire: OpenAI’s Latest Model Faces Backlash and “Jailbreak” Flaws
No AI product in history has stirred such a tidal wave of anticipation as OpenAI’s long-awaited GPT-5. Yet, following its high-profile launch last week, the model swiftly found itself under fire—a troubling omen for...
The post GPT-5 Under Fire: OpenAI’s Latest Model Faces Backlash and “Jailbreak” Flaws appeared first on Penetration Testing Tools.
微软推出Microsoft 365轻量级任务栏应用程序 可快速启动文件搜索/联系人/日历
JVN: 複数のAshlar-Vellum製品における複数の脆弱性
JVN: AVEVA製PI Integratorにおける複数の脆弱性
JVN: Santesoft製Sante PACS Serverにおける複数の脆弱性
图感知大型语言模型的对抗攻击与防御
图感知大型语言模型的对抗攻击与防御
Malicious npm Package Lures Job Seekers and Exfiltrates Sensitive Data
A self-proclaimed Ukrainian Web3 team targeted a community member during an interview’s first round by instructing them to clone and run a GitHub repository named EvaCodes-Community/UltraX. Suspecting foul play, the individual contacted the SlowMist security team, who conducted a thorough analysis and uncovered malicious components embedded within the project’s dependencies. With consent, SlowMist issued a […]
The post Malicious npm Package Lures Job Seekers and Exfiltrates Sensitive Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.