Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

pentesttools@infosec.exchangeP

pentesttools@infosec.exchange

@pentesttools@infosec.exchange
About
Posts
3
Topics
3
Shares
0
Groups
0
Followers
0
Following
0

View Original

Posts

Recent Best Controversial

  • Office Hours this Wednesday, May 27: AI coding vs. security validation, live with our Head of Engineering and Product Manager.
    pentesttools@infosec.exchangeP pentesttools@infosec.exchange

    Office Hours this Wednesday, May 27: AI coding vs. security validation, live with our Head of Engineering and Product Manager.

    30 minutes of discussion on where the validation gap opens when AI accelerates the codebase. 15 minutes of open Q&A.

    11:00 AM New York / 4:00 PM London / 6:00 PM Bucharest.

    Register: https://zoom.us/webinar/register/5817794651256/WN_1WYk4PoXTci8uZ2J9lo-ng

    #offensivesecurity #pentesting #infosec

    Uncategorized offensivesecuri pentesting infosec

  • CVE-2026-41940 was exploited for 64 days before a patch existed.
    pentesttools@infosec.exchangeP pentesttools@infosec.exchange

    CVE-2026-41940 was exploited for 64 days before a patch existed. First attack: Feb 23. Advisory: Apr 28.

    After disclosure, 15,448 cPanel hosts in malicious activity on May 1 alone. Ransomware and a Mirai botnet running in parallel. CVSS 9.8. CISA KEV.

    We built a free scanner. No account needed.

    Link Preview Image
    Free cPanel vulnerability scanner to detect CVE-2026-41940

    Free cPanel vulnerability scanner for CVE-2026-41940. Detect the authentication bypass via CRLF injection in cPanel & WHM. Get a PDF scan report.

    favicon

    Pentest-Tools.com (pentest-tools.com)

    #infosec #pentesting #vulnerabilitymanagement

    Uncategorized infosec pentesting vulnerabilityma

  • CVE-2026-40321: stored XSS in DNN (DotNetNuke) prior to v10.2.2 chains to full RCE.
    pentesttools@infosec.exchangeP pentesttools@infosec.exchange

    CVE-2026-40321: stored XSS in DNN (DotNetNuke) prior to v10.2.2 chains to full RCE.

    Any authenticated user can upload a crafted SVG with embedded JavaScript. If a power user opens it, the payload calls DNN's own config endpoint to drop an ASPX backdoor in the server root.

    One file. One click. Full RCE. CVSS 8.1, patched, fully documented.

    Write-up + PoC payloads: https://pentest-tools.com/blog/dotnetnuke-xss-to-rce

    More research from our team: https://pentest-tools.com/research

    #offensivesecurity #penetrationtesting #infosec

    Uncategorized offensivesecuri penetrationtest infosec
  • Login

  • Login or register to search.
  • First post
    Last post
0
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups