Recent Advisories

Severity ID Title Vendor Product Date Type
NONE E07F5024-E3D1-

owasp-web-pentest-tools_E07F5024-E3D1-5632-9244-27E181873CF1

OWASP Web Pentest Tools CLI toolkit para suporte em testes de penetração em aplicações web, cobrindo as principais vulnerabilidades do OWASP Top 10...

N/A N/A GITHUBEXPLOIT
NONE THN:4A1D4C8F1F4...

GitHub Actions Supply Chain Attack Redirects Tags to Steal CI/CD Credentials_THN:4A1D4C8F1F41BDB4260E5E273EC4557E

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgc7jpVO6HhBuEBTjkwmNjYhKlFmhhmytOqNZHYuGP-dNWrf3AoyE68yoKj77elddOX4Ps2x9jSuwhi5sE-Qj...

N/A N/A THN
NONE THN:52FFF2D015B...

Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account_THN:52FFF2D015B90EFF3BB99C75AD03B66B

![Mini Shai-Hulud](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjpyJDg_FqUDfeOeVX8IyhBHj9HqwkGZ-hV7b998CMLiBK2uPpmuQEN1cv1xYXJzRiznN6...

N/A N/A THN
NONE EA07DF38-4382-

MC-271325-DoS-PoC_EA07DF38-4382-540C-BCF4-9229CE91EBBA

Log amplification based denial for service for vanilla Minecraft MC-271325 Unauthenticated clients can make vanilla and Fabric Minecraft servers wr...

N/A N/A GITHUBEXPLOIT
NONE AECD405E-97C0-

midnight-ownpublickey-attack_AECD405E-97C0-50FA-BD41-7673DAB158A7

Bounty 295: Why ownPublicKey Can't Be Trusted for Access Control A Comprehensive Tutorial on ZK Circuit Access Control Vulnerabilities in Midnight ...

N/A N/A GITHUBEXPLOIT
NONE BA6E6A92-D62E-

zparty_BA6E6A92-D62E-5A18-A900-CDEE3CAF577A

Zparty Automated web penetration testing framework with local AI, built in Python. Zparty runs a full black-box security audit in one command — rec...

N/A N/A GITHUBEXPLOIT
NONE 42412AD0-717C-

eip-mcp_42412AD0-717C-5E63-A93E-F4E8E747E68E

Exploit Intel Platform MCP Server Package/command: eip-mcp An MCP Model Context Protocol server that gives AI assistants access to the Exploit Inte...

N/A N/A GITHUBEXPLOIT
NONE D854C7EE-EA24-

MC-271325-PoC_D854C7EE-EA24-5BFF-963C-2FF13911CC85

Status trailing-byte log amplification MC-271325 Unauthenticated clients can make vanilla and Fabric Minecraft servers write large stack traces to ...

N/A N/A GITHUBEXPLOIT
NONE MSSECURE:5AD7A8...

How Storm-2949 turned a compromised identity into a cloud-wide breach_MSSECURE:5AD7A84325AFB86E0C1059E1736E3D0E

In this article 1. Attack chain overview 1. Cloud compromise: Microsoft Entra ID and Microsoft 365 2. Initial access and persistence t...

N/A N/A MSSECURE
NONE KREBS:C7BC6C4D1...

CISA Admin Leaked AWS GovCloud Keys on Github_KREBS:C7BC6C4D1F5D2D297FA1745B49D61684

Until this past weekend, a contractor for the **Cybersecurity & Infrastructure Security Agency** (CISA) maintained a public **GitHub** repository t...

N/A N/A KREBS