Aggregator
CVE-2024-10242 | WSO2 API Manager prior 3.2.0.401/4.0.0.318 Authentication Endpoint cross site scripting (EUVD-2024-55545)
CVE-2024-8010 | WSO2 API Manager prior 4.3.0.39 Publisher xml external entity reference (EUVD-2024-55549)
CVE-2026-23772 | Dell Storage Manager up to 8.0 privileges management (dsa-2026-058 / EUVD-2026-23217)
Business Logic Flaws: The Silent Threat in Modern Web Applications
Navigation Traps: Google’s New June 2026 Penalty Targets Back Button Hijacking
Google is intensifying its campaign against predatory web practices by instituting stringent prohibitions on one of the internet’s
The post Navigation Traps: Google’s New June 2026 Penalty Targets Back Button Hijacking appeared first on Penetration Testing Tools.
Digital Emergency: Massive April Patch Tuesday Fixes Active Exploits and “Wormable” Flaws
The April iteration of “Patch Tuesday” has arrived with such consequence that to overlook it would be an
The post Digital Emergency: Massive April Patch Tuesday Fixes Active Exploits and “Wormable” Flaws appeared first on Penetration Testing Tools.
CVE-2026-1620 | Livemesh Livemesh Addons by Elementor Plugin up to 9.0 on WordPress Template Name lae_get_template_part filename control (EUVD-2026-23205)
CVE-2026-0718 | wpxpo PostX Plugin up to 5.0.5 on WordPress ultp_shareCount_callback authorization (EUVD-2026-23201)
CVE-2026-3355 | ivole Customer Reviews for WooCommerce Plugin up to 5.101.0 on WordPress cross site scripting (EUVD-2026-23207)
CVE-2026-3876 | specialk Prismatic Plugin up to 3.7.3 on WordPress Shortcode prismatic_decode cross site scripting (EUVD-2026-23212)
CVE-2026-3875 | wpdevteam BetterDocs Plugin up to 4.3.8 on WordPress Shortcode betterdocs_feedback_form cross site scripting (EUVD-2026-23209)
CVE-2026-41035 | Samba rsync up to 3.4.1 Qsort Call receive_xattr length length parameter (EUVD-2026-23215)
CVE-2024-2374 | WSO2 API Manager XML Parser xml external entity reference (EUVD-2024-27327)
CVE-2026-3995 | faridsaniee OPEN-BRAIN Plugin up to 0.5.0 on WordPress Setting sanitize_text_field API key cross site scripting (EUVD-2026-23213)
Obsidian Plugin Abuse Delivers PHANTOMPULSE RAT in Targeted Finance, Crypto Attacks
Beyond the Legacy: OpenSSL 4.0.0 Arrives with Encrypted Client Hello and Post-Quantum Prep
The OpenSSL Project has inaugurated a seminal update that profoundly reshapes both its internal architecture and its repertoire
The post Beyond the Legacy: OpenSSL 4.0.0 Arrives with Encrypted Client Hello and Post-Quantum Prep appeared first on Penetration Testing Tools.
Cargo theft malware actor spent a month inside a decoy network before researchers pulled the plug
Proofpoint researchers executed a malicious payload from a threat actor known to target trucking and logistics companies in late February 2026, doing so inside a decoy environment. The environment stayed compromised for more than 30 days, long enough for researchers to watch the actor work through their tools, scripts, and decisions beyond the initial break-in. The attacker had previously been documented targeting transportation carriers through compromised load board platforms, which are online marketplaces connecting shippers … More →
The post Cargo theft malware actor spent a month inside a decoy network before researchers pulled the plug appeared first on Help Net Security.
Sunk by a Script: How a Fuel System Breach Exposed the Global NYK Line Network
A Japanese maritime transport conglomerate has encountered a significant data breach following the compromise of its internal fuel
The post Sunk by a Script: How a Fuel System Breach Exposed the Global NYK Line Network appeared first on Penetration Testing Tools.
The Kernel Ghost: How Predator Spyware Hijacks iPhone NEON Registers to Vanish into iOS
The commercial spyware Predator has proven far more ingenious than previously surmised. Rather than merely infiltrating the iPhone’s
The post The Kernel Ghost: How Predator Spyware Hijacks iPhone NEON Registers to Vanish into iOS appeared first on Penetration Testing Tools.