07/20

HPE warns of hardcoded passwords in Aruba access points

https://www.bleepingcomputer.com/news/security/hpe-warns-of-hardcoded-passwords-in-aruba-access-points/
HPE warns of hardcoded passwords in Aruba access points

Microsoft SharePoint zero-day exploited in RCE attacks, no patch available

https://www.bleepingcomputer.com/news/microsoft/microsoft-sharepoint-zero-day-exploited-in-rce-attacks-no-patch-available/
Microsoft SharePoint zero-day exploited in RCE attacks, no patch available

Modular PIC C2 Agents

https://rastamouse.me/modular-pic-c2-agents/
Modular PIC C2 Agents

Pentest-Tools-Collection/tools/Azure/Get-SPVersionInfo.ps1 at main · LuemmelSec/Pentest-Tools-Collection · GitHub

https://github.com/LuemmelSec/Pentest-Tools-Collection/blob/main/tools/Azure/Get-SPVersionInfo.ps1
Pentest-Tools-Collection/tools/Azure/Get-SPVersionInfo.ps1 at main · LuemmelSec/Pentest-Tools-Collection · GitHub

Critical Unpatched SharePoint Zero-Day Actively Exploited, Breaches 75+ Company Servers

https://thehackernews.com/2025/07/critical-microsoft-sharepoint-flaw.html
Critical Unpatched SharePoint Zero-Day Actively Exploited, Breaches 75+ Company Servers

Customer guidance for SharePoint vulnerability CVE-2025-53770 | MSRC Blog | Microsoft Security Response Center

https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/
Customer guidance for SharePoint vulnerability CVE-2025-53770 | MSRC Blog | Microsoft Security Response Center

SharePoint Under Siege: ToolShell Mass Exploitation (CVE-2025-53770)

https://research.eye.security/sharepoint-under-siege/
SharePoint Under Siege: ToolShell Mass Exploitation (CVE-2025-53770)

Malware Injected into 5 npm Packages After Maintainer Tokens Stolen in Phishing Attack

https://thehackernews.com/2025/07/malware-injected-into-6-npm-packages.html
Malware Injected into 5 npm Packages After Maintainer Tokens Stolen in Phishing Attack

Legless: IPv6 Penetration Testing

https://blog.exploit.org/caster-legless
Legless: IPv6 Penetration Testing

Red Team Tactics: Evading EDR on Linux with io_uring | 0xMatheuZ

https://matheuzsecurity.github.io/hacking/evading-linux-edrs-with-io-uring/
Red Team Tactics: Evading EDR on Linux with io_uring | 0xMatheuZ

Hackers Exploit Critical CrushFTP Flaw to Gain Admin Access on Unpatched Servers

https://thehackernews.com/2025/07/hackers-exploit-critical-crushftp-flaw.html
Hackers Exploit Critical CrushFTP Flaw to Gain Admin Access on Unpatched Servers

EncryptHub Targets Web3 Developers Using Fake AI Platforms to Deploy Fickle Stealer Malware

https://thehackernews.com/2025/07/encrypthub-targets-web3-developers.html
EncryptHub Targets Web3 Developers Using Fake AI Platforms to Deploy Fickle Stealer Malware