<?xml version="1.0" encoding="ISO-8859-1" ?>
<?xml-stylesheet type="text/xsl" href="https://dev.threatperspective.org/xsl/index.xsl"?>

<BODY>
<TITLE>
Welcome to the ThreatPerspective Security Information Center
</TITLE>
<MENU>
    <MENUOBJECT>

	<MENUTITLE>
		Vulnerability Info	
	</MENUTITLE>

<!--	<MENUITEM>
		<menuurl>https://www.securityfocus.com</menuurl>
		<MENUBODY>
			Security Focus	
		</MENUBODY>
	</MENUITEM> 

	<MENUITEM>
		<menuurl>https://www.osvdb.org</menuurl>
		<MENUBODY>
			OSVDB
		</MENUBODY>
	</MENUITEM> -->


	<MENUITEM>
		<menuurl>https://nvd.nist.gov</menuurl>
		<MENUBODY>
			Nist NVD
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>https://cvedetails.com</menuurl>
		<MENUBODY>
			CVE Details
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>https://cve.mitre.org</menuurl>
		<MENUBODY>
			Mitre
		</MENUBODY>
	</MENUITEM>

<!--	<MENUITEM>
		<menuurl>https://ciac.llnl.gov</menuurl>
		<MENUBODY>
			CIAC
		</MENUBODY>
	</MENUITEM> -->

	<MENUITEM>
		<menuurl>https://www.cisa.gov/uscert/</menuurl>
		<MENUBODY>
			US CERT
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>https://www.cert.org</menuurl>
		<MENUBODY>
			OG CERT
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://public.cyber.mil</menuurl>
		<MENUBODY>
			DISA
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>https://www.nsa.gov/Press-Room/Cybersecurity-Advisories-Guidance/</menuurl>
		<MENUBODY>
			NSA
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>
    <MENUOBJECT>
	<MENUTITLE>
		Exploit Info	
	</MENUTITLE>
	<MENUITEM>
		<menuurl>https://www.exploit-db.com</menuurl>
		<MENUBODY>
			Exploit DB
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://www.packetstormsecurity.org</menuurl>
		<MENUBODY>
			Packet Storm
		</MENUBODY>
	</MENUITEM>


    </MENUOBJECT>
    <MENUOBJECT>
	<MENUTITLE>
		Active Groups
	</MENUTITLE>


	<MENUITEM>
		<menuurl>https://www.thc.org</menuurl>
		<MENUBODY>
			THC
		</MENUBODY>
	</MENUITEM>

    </MENUOBJECT>
    <MENUOBJECT>

	<MENUTITLE>
		Commercial Groups
	</MENUTITLE>

	<MENUITEM>
		<menuurl>https://www.rapid7.com</menuurl>
		<MENUBODY>
			Rapid7
		</MENUBODY>

	</MENUITEM>
	<MENUITEM>
		<menuurl>https://www.secunia.com</menuurl>
		<MENUBODY>
			Secunia
		</MENUBODY>

	</MENUITEM>
	<MENUITEM>
		<menuurl>https://www.securiteam.com</menuurl>
		<MENUBODY>
			Securiteam
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>https://www.trustwave.com/Company/SpiderLabs/</menuurl>
		<MENUBODY>
			SpiderLabs	
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>https://www.idefense.com</menuurl>
		<MENUBODY>
			Idefense
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>https://www.coresecurity.com</menuurl>
		<MENUBODY>
			Core	
		</MENUBODY>
	</MENUITEM>




    </MENUOBJECT>

   <MENUOBJECT>
	<MENUTITLE>
		Defunct Groups ?
	</MENUTITLE>
	<MENUITEM>
		<menuurl>https://www.shmoo.com</menuurl>
		<MENUBODY>
			The Shmoo Group
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://www.cultdeadcow.com</menuurl>
		<MENUBODY>
			CDC
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>https://www.attrition.org</menuurl>
		<MENUBODY>
			Attrition
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://www.w00w00.org</menuurl>
		<MENUBODY>
			w00w00
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>https://packetstormsecurity.com/groups/ADM</menuurl>
		<MENUBODY>
			ADM
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://packetstormsecurity.com/groups/teso</menuurl>
		<MENUBODY>
			TESO	
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>
    <MENUOBJECT>
	<MENUTITLE>
		Security Organizations
	</MENUTITLE>
	<MENUITEM>
		<menuurl>https://www.owasp.org</menuurl>
		<MENUBODY>
			OWASP
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>https://www.isc2.org</menuurl>
		<MENUBODY>
			ISC2
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>https://www.isecom.org</menuurl>
		<MENUBODY>
			ISECOM
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>https://www.sans.org</menuurl>
		<MENUBODY>
			SANS
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://www.infragard.org</menuurl>
		<MENUBODY>
			Infragard
		</MENUBODY>
	</MENUITEM>

    </MENUOBJECT>

    <MENUOBJECT>
	<MENUTITLE>
		Methodologies	
	</MENUTITLE>

	<MENUITEM>
		<menuurl>https://www.isecom.org/</menuurl>
		<MENUBODY>
			ISECOM
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://www.osstmm.org</menuurl>
		<MENUBODY>
			OSSTMM
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>
    <MENUOBJECT>

	<MENUTITLE>
		Free Tools
	</MENUTITLE>

	<MENUITEM>
		<menuurl>https://www.openvas.org/</menuurl>
		<MENUBODY>
			OpenVAS
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://www.portswigger.net/proxy/</menuurl>
		<MENUBODY>
			Burp Proxy
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://www.insecure.org</menuurl>
		<MENUBODY>
			Nmap
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>https://www.metasploit.org</menuurl>
		<MENUBODY>
			Metasploit
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://www.nessus.org</menuurl>
		<MENUBODY>
			Nessus
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>https://github.com/SecureAuthCorp/impacket</menuurl>
		<MENUBODY>
			Impacket
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://github.com/OWASP/Amass</menuurl>
		<MENUBODY>
			Amass
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>https://github.com/EmpireProject/Empire</menuurl>
		<MENUBODY>
			Empire
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://w3af.org</menuurl>
		<MENUBODY>
			w3af 
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project</menuurl>
		<MENUBODY>
			ZAP
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>https://sqlmap.org</menuurl>
		<MENUBODY>
			SQLMap 
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://www.cirt.net</menuurl>
		<MENUBODY>
			Nikto
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://docs.microsoft.com/en-us/sysinternals/</menuurl>
		<MENUBODY>
			Sysinternals
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>https://www.coresecurity.com/grid/index-open-source-tools</menuurl>
		<MENUBODY>
			Core Tools
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://github.com/SpiderLabs</menuurl>
		<MENUBODY>
			SpiderLabs Tools
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://thc.org/</menuurl>
		<MENUBODY>
			THC Tools
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>https://beefproject.com/</menuurl>
		<MENUBODY>
		 BeEF
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>https://wpscan.org</menuurl>
		<MENUBODY>
		WP Scan 
		</MENUBODY>
	</MENUITEM>






	<MENUITEM>
		<menuurl>https://https://www.ettercap-project.org/</menuurl>
		<MENUBODY>
			Ettercap
		</MENUBODY>
	</MENUITEM>




	<MENUITEM>
		<menuurl>https://sqlninja.sourceforge.net</menuurl>
		<MENUBODY>
			SQL Ninja
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://www.wireshark.org/</menuurl>
		<MENUBODY>
			Wireshark
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://sectools.org/</menuurl>
		<MENUBODY>
			Sectools.org
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>
    <MENUOBJECT>
	<MENUTITLE>
		Virtualization Tools	
	</MENUTITLE>

	<MENUITEM>
		<menuurl>https://www.vmware.com/</menuurl>
		<MENUBODY>
			VMWare Server
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://www.virtualbox.org/wiki/Downloads</menuurl>
		<MENUBODY>
			Virtual Box
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://www.proxmox.com/</menuurl>
		<MENUBODY>
			Proxmox	
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://bochs.sourceforge.net/</menuurl>
		<MENUBODY>
			Bochs
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://pearpc.sourceforge.net/</menuurl>
		<MENUBODY>
			PearPC	
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://www.microsoft.com/en-us/download/details.aspx?id=3702</menuurl>
		<MENUBODY>
			MS Virtual PC
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>https://docs.microsoft.com/en-us/windows/wsl/install-win10</menuurl>
		<MENUBODY>
			Microsoft WSL
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>

    <MENUOBJECT>
	<MENUTITLE>
		Reverse Engineering	
	</MENUTITLE>
	<MENUITEM>
		<menuurl>https://www.gnu.org/software/binutils/</menuurl>
		<MENUBODY>
			binutils
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>https://www.gnu.org/software/gdb/</menuurl>
		<MENUBODY>
			GDB
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://www.gnu.org/software/ddd/</menuurl>
		<MENUBODY>
			DDD
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://www.ollydbg.de/</menuurl>
		<MENUBODY>
			Ollydbg 
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>https://tools.kali.org/reverse-engineering/edb-debugger</menuurl>
		<MENUBODY>
			EDB-Debugger
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>https://www.coresecurity.com/grid/index-open-source-tools</menuurl>
		<MENUBODY>
			CORE
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://tools.kali.org/reverse-engineering/jad</menuurl>
		<MENUBODY>
			Jad	
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://tools.kali.org/reverse-engineering/javasnoop</menuurl>
		<MENUBODY>
			Javasnoop
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>https://tools.kali.org/forensics/binwalk</menuurl>
		<MENUBODY>
			Binwalk
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>
    <MENUOBJECT>
	<MENUTITLE>
		Defaced Websites
	</MENUTITLE>


	<MENUITEM>
		<menuurl>https://www.zone-h.org/component/option,com_attacks/Itemid,43/</menuurl>
		<MENUBODY>
			Zone H
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>

    <MENUOBJECT>
	<MENUTITLE>
		Technical Conferences
	</MENUTITLE>
	<MENUITEM>
		<menuurl>https://www.defcon.org</menuurl>
		<MENUBODY>
			DefCon
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>https://www.owasp.org/index.php/Category:OWASP_AppSec_Conference</menuurl>
		<MENUBODY>
		 	AppSec	
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://www.blackhat.com</menuurl>
		<MENUBODY>
			Blackhat
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>https://www.cansecwest.com</menuurl>
		<MENUBODY>
			CanSecWest
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>https://toorcon.com</menuurl>
		<MENUBODY>
			Toorcon
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://www.shmoocon.org/</menuurl>
		<MENUBODY>
			ShmooCon
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>https://hope.net/</menuurl>
		<MENUBODY>
			H.O.P.E.
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://www.ccc.de/</menuurl>
		<MENUBODY>
			CCC
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://conference.hackinthebox.org/</menuurl>
		<MENUBODY>
			HiTB
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://www.derbycon.com</menuurl>
		<MENUBODY>
			DerbyCon
		</MENUBODY>
	</MENUITEM>



	<MENUITEM>
		<menuurl>https://www.securitybsides.com</menuurl>
		<MENUBODY>
			Security BSides
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>https://www.rsaconference.com</menuurl>
		<MENUBODY>
			RSA
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>https://infosecsouthwest.com</menuurl>
		<MENUBODY>
			ISSW
		</MENUBODY>
	</MENUITEM>


    </MENUOBJECT>
    <MENUOBJECT>
	<MENUTITLE>
		Groups and Meetups	
	</MENUTITLE>

	<MENUITEM>
		<menuurl>https://www.owasp.org/index.php/OWASP_Chapter</menuurl>
		<MENUBODY>
			OWASP
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>https://www.2600.com/meetings/mtg.html</menuurl>
		<MENUBODY>
			2600
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>
    <MENUOBJECT>
	<MENUTITLE>
		Distros
	</MENUTITLE>


	<MENUITEM>
		<menuurl>https://www.kali.org</menuurl>
		<MENUBODY>
			Kali
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>https://www.knopper.net/knoppix/index-en.html</menuurl>
		<MENUBODY>
			Knoppix
		</MENUBODY>
	</MENUITEM>

    </MENUOBJECT>

    <MENUOBJECT>
	<MENUTITLE>
		Wireless Tools
	</MENUTITLE>
	<MENUITEM>
		<menuurl>https://www.kismetwireless.net</menuurl>
		<MENUBODY>
			Kismet
		</MENUBODY>
	</MENUITEM>



	<MENUITEM>
		<menuurl>https://www.aircrack-ng.org/</menuurl>
		<MENUBODY>
			Aircrack-ng
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>https://csrc.nist.gov/publications/nistpubs/800-48/NIST_SP-48.pdf</menuurl>
		<MENUBODY>
			Wireless SP
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://theta44.org/karma/index.html</menuurl>
		<MENUBODY>
			Karma
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>https://tools.kali.org/wireless-attacks/reaver</menuurl>
		<MENUBODY>
			Reaver
		</MENUBODY>
	</MENUITEM>

    </MENUOBJECT>

    <MENUOBJECT>
	<MENUTITLE>
		Checklists
	</MENUTITLE>

	<MENUITEM>
		<menuurl>https://csrc.nist.gov</menuurl>
		<MENUBODY>
			NIST CSRC
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://nvd.nist.gov/cvss.cfm?version=2</menuurl>
		<MENUBODY>
		 	CVSS	
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://checklists.nist.gov</menuurl>
		<MENUBODY>
			NIST Checklists
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>https://www.cisecurity.org</menuurl>
		<MENUBODY>
			CIS
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>https://www.iad.gov/iad/library/ia-guidance/index.cfm</menuurl>
		<MENUBODY>
			IAD
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>

		<menuurl>https://docs.oracle.com/database/121/DBSEG/title.htm</menuurl>
		<MENUBODY>
			Oracle 
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>

		<menuurl>https://www.petefinnigan.com/orasec.htm</menuurl>
		<MENUBODY>
			PF's Checklists
		</MENUBODY>

	</MENUITEM>

	<MENUITEM>
		<menuurl>https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-security-baselines</menuurl>
		<MENUBODY>
			Microsoft
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>

   <MENUOBJECT>
        <MENUTITLE>
		OS Hardening
        </MENUTITLE>



        <MENUITEM>
                <menuurl>https://bastille-linux.sourceforge.net</menuurl>
                <MENUBODY>
			Bastille Linux
                </MENUBODY>
        </MENUITEM>
        <MENUITEM>
                <menuurl>https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-security-configuration-framework/windows-security-baselines</menuurl>
                <MENUBODY>
			Microsoft
                </MENUBODY>
        </MENUITEM>
   </MENUOBJECT>


    <MENUOBJECT>
	<MENUTITLE>
		Professional Security Programs
	</MENUTITLE>

	<MENUITEM>
		<menuurl>https://www.pcisecuritystandards.org/</menuurl>
		<MENUBODY>
		  PCI	
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://www.isc2.org</menuurl>
		<MENUBODY>
			ISC2
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://www.eccouncil.org/</menuurl>
		<MENUBODY>
		 	EC Council	
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>https://www.sans.org/</menuurl>
		<MENUBODY>
		 	SANS	
		</MENUBODY>
	</MENUITEM>

    </MENUOBJECT>

   <MENUOBJECT>
        <MENUTITLE>
                Password Crackers
        </MENUTITLE>

	<MENUITEM>
		<menuurl>https://www.openwall.com/john/</menuurl>
		<MENUBODY>
			John the Ripper
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://hashcat.net/hashcat/</menuurl>
		<MENUBODY>
			Hashcat 
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>https://en.wikipedia.org/wiki/RainbowCrack</menuurl>
		<MENUBODY>
			RainbowCrack 
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>https://rainbowtables.shmoo.com/</menuurl>
		<MENUBODY>
			Rainbow Tables
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>https://www.l0phtcrack.com</menuurl>
		<MENUBODY>
			L0phtcrack 
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>https://en.wikipedia.org/wiki/Cain_and_Abel_(software)</menuurl>
		<MENUBODY>
			Cain and Abel
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>


    <MENUOBJECT>
	<MENUTITLE>
		Default Passwords
	</MENUTITLE>
	<MENUITEM>
		<menuurl>https://cirt.net/passwords</menuurl>
		<MENUBODY>
			Cirt
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>https://www.petefinnigan.com/default/default_password_list.htm</menuurl>
		<MENUBODY>Oracle</MENUBODY>
	</MENUITEM>



	<MENUITEM>
		<menuurl>https://defaultpassword.com/</menuurl>
		<MENUBODY>
			def pass
		</MENUBODY>
	</MENUITEM>




	<MENUITEM>
		<menuurl>https://www.uktsupport.co.uk/reference/biosp.htm</menuurl>
		<MENUBODY>
			Bios Passwords
		</MENUBODY>
	</MENUITEM>

    </MENUOBJECT>

   <MENUOBJECT>
        <MENUTITLE>
                OSI
        </MENUTITLE>

        <MENUITEM>
                <menuurl>https://www.shodanhq.com</menuurl>
                <MENUBODY>
			SHODAN
                </MENUBODY>
        </MENUITEM>



        <MENUITEM>
                <menuurl>https://www.archive.org/</menuurl>
                <MENUBODY>
                        Way Back Machine
                </MENUBODY>
        </MENUITEM>


        <MENUITEM>
                <menuurl>https://www.domaintools.com</menuurl>
                <MENUBODY>
                        DomainTools
                </MENUBODY>
        </MENUITEM>

    </MENUOBJECT>

   <MENUOBJECT>
        <MENUTITLE>
		Compliance Resources
        </MENUTITLE>

        <MENUITEM>
                <menuurl>https://www.hhs.gov/hipaa/</menuurl>
                <MENUBODY>
                        HIPAA
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl>https://www.congress.gov/bill/107th-congress/house-bill/3763</menuurl>
                <MENUBODY>
			SOX
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl>https://www.congress.gov/bill/106th-congress/senate-bill/900</menuurl>
                <MENUBODY>
			FMA (GLBA)
                </MENUBODY>
        </MENUITEM>


        <MENUITEM>
                <menuurl>https://csrc.nist.gov/</menuurl>
                <MENUBODY>
			FISMA
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl>https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf</menuurl>
                <MENUBODY>
		 	NIST 800-53	
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl>https://www.iso.org/standard/75652.html</menuurl>
                <MENUBODY>
			ISO 27002:2022
                </MENUBODY>
        </MENUITEM>


        <MENUITEM>
                <menuurl>https://www.fedramp.gov</menuurl>
                <MENUBODY>
		 	FedRAMP
                </MENUBODY>
        </MENUITEM>


        <MENUITEM>
                <menuurl>https://www.sans.org/resources/policies/</menuurl>
                <MENUBODY>
			SANS Policies
                </MENUBODY>
        </MENUITEM>

    </MENUOBJECT>

   <MENUOBJECT>
        <MENUTITLE>
		Email Lists
        </MENUTITLE>

<!--        <MENUITEM>
                <menuurl>https://www.securityfocus.com/archive</menuurl>
                <MENUBODY>
			Security Focus
                </MENUBODY>
        </MENUITEM> -->

        <MENUITEM>
                <menuurl>https://seclists.org/fulldisclosure/</menuurl>
                <MENUBODY>
			Full Disclosure
                </MENUBODY>
        </MENUITEM>


        <MENUITEM>
                <menuurl>https://seclists.org/dailydave/</menuurl>
                <MENUBODY>
			Daily Dave
                </MENUBODY>
        </MENUITEM>
        <MENUITEM>
                <menuurl>https://seclists.org</menuurl>
                <MENUBODY>
			Security Lists
                </MENUBODY>
        </MENUITEM>


   </MENUOBJECT>


   <MENUOBJECT>
        <MENUTITLE>
		Defense / IDS
        </MENUTITLE>

        <MENUITEM>
                <menuurl>https://www.snort.org</menuurl>
                <MENUBODY>
			Snort
                </MENUBODY>
        </MENUITEM>


   </MENUOBJECT>

   <MENUOBJECT>

        <MENUTITLE>
		Helpful Sites	
        </MENUTITLE>



        <MENUITEM>


                <menuurl>https://pentestmonkey.net</menuurl>
                <MENUBODY>
			Pentest Monkey
                </MENUBODY>
        </MENUITEM>
        <MENUITEM>
                <menuurl>https://www.offensive-security.com</menuurl>
                <MENUBODY>
			Offensive Security
                </MENUBODY>

        </MENUITEM>

   </MENUOBJECT>

   <MENUOBJECT>
        <MENUTITLE>
		Institutional Stuff	
        </MENUTITLE>

        <MENUITEM>
                <menuurl>https://www.phrack.org</menuurl>
                <MENUBODY>
			Phrack
                </MENUBODY>
        </MENUITEM>
	<MENUITEM>
		<menuurl>https://www.2600.com</menuurl>
		<MENUBODY>
			2600
		</MENUBODY>
	</MENUITEM>

   </MENUOBJECT>

</MENU>

<MSG>
    <MSGARTICLE>
	<MSGTITLE>Welcome to the Security Information Center</MSGTITLE>
	<MSGBODY>This is a portal site created by ThreatPerspective to enable our clients and other interested parties to learn more about Information Security.  The boxes on the left correlate to free information and tools that realate to Information Security.  The boxes on the right are various Information Security related news feeds.</MSGBODY>
    </MSGARTICLE>
</MSG>
<rss version="2.0">
<channel>
    <title>CISA Cybersecurity Advisories</title>
    <link>https://www.cisa.gov/</link>
    <description/>
    <item>
  <title>Defending Against China-Nexus Covert Networks of Compromised Devices</title>
  <link>https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-113a</link>
  <description>&lt;div class="SCXW131754345 BCX8"&gt;
</description>
    </item>
<item>
  <title>Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure</title>
  <link>https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a</link>
  <description>&lt;h2&gt;&lt;strong&gt;Advisory at a Glance&lt;/strong&gt;&lt;/h2&gt;
</description>
    </item>
<item>
  <title>Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure</title>
  <link>https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-343a</link>
  <description>&lt;h2&gt;&lt;strong&gt;Summary&lt;/strong&gt;&lt;/h2&gt;
</description>
    </item>
<item>
  <title>CISA Shares Lessons Learned from an Incident Response Engagement</title>
  <link>https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-266a</link>
  <description>&lt;h2&gt;&lt;strong&gt;Advisory at a Glance&lt;/strong&gt;&lt;/h2&gt;
</description>
    </item>
<item>
  <title>Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System</title>
  <link>https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a</link>
  <description>&lt;h2&gt;&lt;strong&gt;Executive summary&lt;/strong&gt;&lt;/h2&gt;
</description>
    </item>
<item>
  <title>CISA and USCG Identify Areas for Cyber Hygiene Improvement After Conducting Proactive Threat Hunt at US Critical Infrastructure Organization</title>
  <link>https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-212a</link>
  <description>&lt;div class="WordSection1"&gt;
</description>
    </item>
<item>
  <title>#StopRansomware: Interlock</title>
  <link>https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-203a</link>
  <description>&lt;h2&gt;&lt;strong&gt;Summary&lt;/strong&gt;&lt;/h2&gt;
</description>
    </item>
<item>
  <title>Ransomware Actors Exploit Unpatched SimpleHelp Remote Monitoring and Management to Compromise Utility Billing Software Provider</title>
  <link>https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-163a</link>
  <description>&lt;h2&gt;&lt;strong&gt;Summary&lt;/strong&gt;&lt;/h2&gt;
</description>
    </item>
<item>
  <title>Russian GRU Targeting Western Logistics Entities and Technology Companies</title>
  <link>https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-141a</link>
  <description>&lt;h2&gt;&lt;strong&gt;Executive Summary&lt;/strong&gt;&lt;/h2&gt;
</description>
    </item>
<item>
  <title>Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations</title>
  <link>https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-141b</link>
  <description>&lt;h2&gt;&lt;strong&gt;Summary&lt;/strong&gt;&lt;/h2&gt;
</description>
    </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>CISA Analysis Reports</title>
    <link>https://www.cisa.gov/</link>
    <description/>
    <item>
  <title>FIRESTARTER Backdoor</title>
  <link>https://www.cisa.gov/news-events/analysis-reports/ar26-113a</link>
  <description>&lt;h2&gt;&lt;strong&gt;Malware Analysis Report at a Glance&lt;/strong&gt;&lt;/h2&gt;
</description>
    </item>
<item>
  <title>BRICKSTORM Backdoor</title>
  <link>https://www.cisa.gov/news-events/analysis-reports/ar25-338a</link>
  <description>&lt;h2&gt;&lt;strong&gt;Malware Analysis at a Glance&lt;/strong&gt;&lt;/h2&gt;
</description>
    </item>
<item>
  <title>Malicious Listener for Ivanti Endpoint Mobile Management Systems</title>
  <link>https://www.cisa.gov/news-events/analysis-reports/ar25-261a</link>
  <description>&lt;table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap&gt;
</description>
    </item>
<item>
  <title>MAR-251132.c1.v1 Exploitation of SharePoint Vulnerabilities</title>
  <link>https://www.cisa.gov/news-events/analysis-reports/ar25-218a</link>
  <description>&lt;h3&gt;Notification&lt;/h3&gt;
</description>
    </item>
<item>
  <title>MAR-25993211-r1.v2 Ivanti Connect Secure (RESURGE)</title>
  <link>https://www.cisa.gov/news-events/analysis-reports/ar25-087a</link>
  <description>&lt;h3&gt;Notification&lt;/h3&gt;
</description>
    </item>
<item>
  <title>MAR-10448362-1.v1 Volt Typhoon</title>
  <link>https://www.cisa.gov/news-events/analysis-reports/ar24-038a</link>
  <description>&lt;h3&gt;Notification&lt;/h3&gt;
</description>
    </item>
<item>
  <title>MAR-10478915-1.v1 Citrix Bleed</title>
  <link>https://www.cisa.gov/news-events/analysis-reports/ar23-325a</link>
  <description>&lt;p&gt;&amp;nbsp;&amp;nbsp;&lt;/p&gt;
</description>
    </item>
<item>
  <title>MAR-10454006.r5.v1 SUBMARINE, SKIPJACK, SEASPRAY, WHIRLPOOL, and SALTWATER Backdoors </title>
  <link>https://www.cisa.gov/news-events/analysis-reports/ar23-250a-0</link>
  <description>&lt;p&gt;&amp;nbsp;&amp;nbsp;&lt;/p&gt;
</description>
    </item>
<item>
  <title>MAR-10430311-1.v1 Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475</title>
  <link>https://www.cisa.gov/news-events/analysis-reports/ar23-250a</link>
  <description>&lt;p&gt;&amp;nbsp;&amp;nbsp;&lt;/p&gt;
</description>
    </item>
<item>
  <title>Infamous Chisel Malware Analysis Report</title>
  <link>https://www.cisa.gov/news-events/analysis-reports/ar23-243a</link>
  <description>&lt;h4&gt;Infamous Chisel–A collection of components associated with Sandworm designed to enable remote access and exfiltrate information from Android phones.&lt;/h4&gt;
</description>
    </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Bulletins</title>
    <link>https://www.cisa.gov/</link>
    <description></description>
    <item>
  <title>Vulnerability Summary for the Week of June 1, 2026</title>
  <link>https://www.cisa.gov/news-events/bulletins/sb26-159</link>
  <description>&lt;div id=&quot;high_v&quot;&gt;
</description>
    </item>
<item>
  <title>Vulnerability Summary for the Week of May 25, 2026</title>
  <link>https://www.cisa.gov/news-events/bulletins/sb26-152</link>
  <description>&lt;div id=&quot;high_v&quot;&gt;
</description>
    </item>
<item>
  <title>Vulnerability Summary for the Week of May 18, 2026</title>
  <link>https://www.cisa.gov/news-events/bulletins/sb26-145</link>
  <description>&lt;div id=&quot;high_v&quot;&gt;
</description>
    </item>
<item>
  <title>Vulnerability Summary for the Week of May 11, 2026</title>
  <link>https://www.cisa.gov/news-events/bulletins/sb26-138</link>
  <description>&lt;div id=&quot;high_v&quot;&gt;
</description>
    </item>
<item>
  <title>Vulnerability Summary for the Week of May 4, 2026</title>
  <link>https://www.cisa.gov/news-events/bulletins/sb26-131</link>
  <description>&lt;div id=&quot;high_v&quot;&gt;
</description>
    </item>
<item>
  <title>Vulnerability Summary for the Week of April 27, 2026</title>
  <link>https://www.cisa.gov/news-events/bulletins/sb26-125</link>
  <description>&lt;div id=&quot;high_v&quot;&gt;
</description>
    </item>
<item>
  <title>Vulnerability Summary for the Week of April 20, 2026</title>
  <link>https://www.cisa.gov/news-events/bulletins/sb26-117</link>
  <description>&lt;div id=&quot;high_v&quot;&gt;
</description>
    </item>
<item>
  <title>Vulnerability Summary for the Week of April 13, 2026</title>
  <link>https://www.cisa.gov/news-events/bulletins/sb26-110</link>
  <description>&lt;div id=&quot;high_v&quot;&gt;
</description>
    </item>
<item>
  <title>Vulnerability Summary for the Week of April 6, 2026</title>
  <link>https://www.cisa.gov/news-events/bulletins/sb26-103</link>
  <description>&lt;div id=&quot;high_v&quot;&gt;
</description>
    </item>
<item>
  <title>Vulnerability Summary for the Week of February 2, 2026</title>
  <link>https://www.cisa.gov/news-events/bulletins/sb26-040</link>
  <description>&lt;div id=&quot;high_v&quot;&gt;
</description>
    </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>CERT Advisories</title>
    <link>https://seclists.org/#cert</link>
    <description>The &lt;a href=&quot;http://www.cert.org/&quot;&gt;Computer Emergency Response Team&lt;/a&gt; has been responding to security incidents and sharing vulnerability information since the Morris Worm hit in 1986. This archive combines their technical security alerts, tips, and current activity lists.</description>
  <item>
    <title>Apple Releases Security Updates for Multiple Products</title>
    <link>https://seclists.org/cert/2023/3</link>
    <description>&lt;p&gt;Posted by CISA on Mar 28&lt;/p&gt;Cybersecurity and Infrastructure Security Agency (CISA) - Defend Today, Secure Tomorrow&lt;br&gt;
Apple...&lt;br&gt;</description>
  </item>
  <item>
    <title>CISA Releases Six Industrial Control Systems Advisories</title>
    <link>https://seclists.org/cert/2023/2</link>
    <description>&lt;p&gt;Posted by CISA on Mar 23&lt;/p&gt;Cybersecurity and Infrastructure Security Agency (CISA) - Defend Today, Secure Tomorrow&lt;br&gt;
08:00 AM EDT...&lt;br&gt;</description>
  </item>
  <item>
    <title>CISA Releases Eight Industrial Control Systems Advisories</title>
    <link>https://seclists.org/cert/2023/1</link>
    <description>&lt;p&gt;Posted by CISA on Mar 21&lt;/p&gt;Cybersecurity and Infrastructure Security Agency (CISA) - Defend Today, Secure Tomorrow&lt;br&gt;
03/21/2023 08:00 AM...&lt;br&gt;</description>
  </item>
  <item>
    <title>CISA and NSA Release Enduring Security Framework Guidance on Identity and Access Management</title>
    <link>https://seclists.org/cert/2023/0</link>
    <description>&lt;p&gt;Posted by CISA on Mar 21&lt;/p&gt;Cybersecurity and Infrastructure Security Agency (CISA) - Defend Today, Secure Tomorrow&lt;br&gt;
CISA and NSA Release Enduring Security Framework Guidance on Identity and Access Management [...&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Alerts</title>
    <link>https://www.cisa.gov/</link>
    <description></description>
    <item>
  <title>CISA Adds Two Known Exploited Vulnerabilities to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/06/08/cisa-adds-two-known-exploited-vulnerabilities-catalog</link>
  <description>&lt;p&gt;CISA has added two new vulnerabilities to its &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
</description>
    </item>
<item>
  <title>CISA Adds One Known Exploited Vulnerability to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/06/05/cisa-adds-one-known-exploited-vulnerability-catalog</link>
  <description>&lt;p&gt;CISA has added one new vulnerability to its &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
</description>
    </item>
<item>
  <title>CISA Adds One Known Exploited Vulnerability to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/06/03/cisa-adds-one-known-exploited-vulnerability-catalog</link>
  <description>&lt;p&gt;CISA has added one new vulnerability to its&amp;nbsp;&lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
</description>
    </item>
<item>
  <title>CISA Adds Two Known Exploited Vulnerabilities to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/06/02/cisa-adds-two-known-exploited-vulnerabilities-catalog</link>
  <description>&lt;p&gt;CISA has added two new vulnerabilities to its&amp;nbsp;&lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
</description>
    </item>
<item>
  <title>CISA Adds One Known Exploited Vulnerability to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/06/01/cisa-adds-one-known-exploited-vulnerability-catalog</link>
  <description>&lt;p&gt;CISA has added one new vulnerability to its&amp;nbsp;&lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
</description>
    </item>
<item>
  <title>CISA Adds One Known Exploited Vulnerability to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/05/29/cisa-adds-one-known-exploited-vulnerability-catalog</link>
  <description>&lt;p&gt;CISA has added one new vulnerability to its &lt;a href=&quot;/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
</description>
    </item>
<item>
  <title>Supply Chain Compromises Impact Nx Console and GitHub Repositories</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/05/28/supply-chain-compromises-impact-nx-console-and-github-repositories</link>
  <description>&lt;p&gt;CISA is prioritizing the response to multiple emerging software supply chain intrusion campaigns targeting developer ecosystems Continuous Integration/Continuous Development (CI/CD) pipelines. These recent incidents, including the GitHub compromise via a malicious Nx Console Visual Studio Code (VS Code) extension and the “Megalodon” supply chain intrusion campaign, demonstrate how cyber threat actors are abusing tools and processes that support enterprise, cloud, and DevOps environments—specifically CI/CD pipelines, code extensions and workflows.&amp;nbsp;&lt;/p&gt;
</description>
    </item>
<item>
  <title>CISA Adds Three Known Exploited Vulnerabilities to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/05/27/cisa-adds-three-known-exploited-vulnerabilities-catalog</link>
  <description>&lt;p&gt;CISA has added&amp;nbsp;three&amp;nbsp;new vulnerabilities&amp;nbsp;to its&amp;nbsp;&lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
</description>
    </item>
<item>
  <title>CISA Adds One Known Exploited Vulnerability to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/05/26/cisa-adds-one-known-exploited-vulnerability-catalog</link>
  <description>&lt;p&gt;CISA has added&amp;nbsp;one&amp;nbsp;new vulnerability&amp;nbsp;to its&amp;nbsp;&lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&amp;nbsp;&lt;/p&gt;
</description>
    </item>
<item>
  <title>CISA Adds One Known Exploited Vulnerability to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/05/22/cisa-adds-one-known-exploited-vulnerability-catalog</link>
  <description>&lt;p&gt;CISA has added one new vulnerability to its &lt;a href=&quot;/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
</description>
    </item>
<item>
  <title>CISA Adds Two Known Exploited Vulnerabilities to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/05/21/cisa-adds-two-known-exploited-vulnerabilities-catalog</link>
  <description>&lt;p&gt;CISA has added two new vulnerabilities to its &lt;a href=&quot;/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
</description>
    </item>
<item>
  <title>CISA Adds Seven Known Exploited Vulnerabilities to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/05/20/cisa-adds-seven-known-exploited-vulnerabilities-catalog</link>
  <description>&lt;p&gt;CISA has added seven new vulnerabilities to its &lt;a href=&quot;/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
</description>
    </item>
<item>
  <title>CISA Adds One Known Exploited Vulnerability to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/05/15/cisa-adds-one-known-exploited-vulnerability-catalog</link>
  <description>&lt;p&gt;CISA has added one new vulnerability to its &lt;a href=&quot;/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
</description>
    </item>
<item>
  <title>CISA Adds One Known Exploited Vulnerability to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/05/14/cisa-adds-one-known-exploited-vulnerability-catalog</link>
  <description>&lt;p&gt;CISA has added&amp;nbsp;one&amp;nbsp;new vulnerability&amp;nbsp;to its&amp;nbsp;&lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&amp;nbsp;&lt;/p&gt;
</description>
    </item>
<item>
  <title>CISA Adds One Known Exploited Vulnerability to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/05/08/cisa-adds-one-known-exploited-vulnerability-catalog</link>
  <description>&lt;p&gt;CISA has added&amp;nbsp;one&amp;nbsp;new vulnerability&amp;nbsp;to its&amp;nbsp;&lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
</description>
    </item>
<item>
  <title>CISA Adds One Known Exploited Vulnerability to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/05/07/cisa-adds-one-known-exploited-vulnerability-catalog</link>
  <description>&lt;p&gt;CISA has added one new vulnerability to its&amp;nbsp;&lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
</description>
    </item>
<item>
  <title>CISA Adds One Known Exploited Vulnerability to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/05/06/cisa-adds-one-known-exploited-vulnerability-catalog</link>
  <description>&lt;p&gt;CISA has added one new vulnerability to its&amp;nbsp;&lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&amp;nbsp;&lt;/p&gt;
</description>
    </item>
<item>
  <title>CISA Adds One Known Exploited Vulnerability to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/05/01/cisa-adds-one-known-exploited-vulnerability-catalog</link>
  <description>&lt;p&gt;CISA has added one new vulnerability to its &lt;a href=&quot;/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
</description>
    </item>
<item>
  <title>CISA Adds One Known Exploited Vulnerability to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/04/30/cisa-adds-one-known-exploited-vulnerability-catalog</link>
  <description>&lt;p&gt;CISA has added&amp;nbsp;one&amp;nbsp;new&amp;nbsp;vulnerability&amp;nbsp;to its&amp;nbsp;&lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&amp;nbsp;&lt;/p&gt;
</description>
    </item>
<item>
  <title>CISA Adds Two Known Exploited Vulnerabilities to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/04/28/cisa-adds-two-known-exploited-vulnerabilities-catalog</link>
  <description>&lt;p&gt;CISA has added&amp;nbsp;two&amp;nbsp;new&amp;nbsp;vulnerabilities&amp;nbsp;to its&amp;nbsp;&lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
</description>
    </item>
<item>
  <title>CISA Adds Four Known Exploited Vulnerabilities to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/04/24/cisa-adds-four-known-exploited-vulnerabilities-catalog</link>
  <description>&lt;p&gt;CISA has added four new vulnerabilities to its &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
</description>
    </item>
<item>
  <title>CISA Adds One Known Exploited Vulnerability to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/04/23/cisa-adds-one-known-exploited-vulnerability-catalog</link>
  <description>&lt;p&gt;CISA has added one new vulnerability to its &lt;a href=&quot;/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
</description>
    </item>
<item>
  <title>CISA Adds One Known Exploited Vulnerability to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/04/22/cisa-adds-one-known-exploited-vulnerability-catalog</link>
  <description>&lt;p&gt;CISA has added one new vulnerability to its &lt;a href=&quot;/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
</description>
    </item>
<item>
  <title>CISA Adds Eight Known Exploited Vulnerabilities to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/04/20/cisa-adds-eight-known-exploited-vulnerabilities-catalog</link>
  <description>&lt;div class=&quot;OutlineElement Ltr SCXW178812853 BCX8&quot;&gt;
</description>
    </item>
<item>
  <title>​​Supply Chain Compromise Impacts Axios Node Package Manager​ </title>
  <link>https://www.cisa.gov/news-events/alerts/2026/04/20/supply-chain-compromise-impacts-axios-node-package-manager</link>
  <description>&lt;div class=&quot;OutlineElement Ltr SCXW232133708 BCX8&quot;&gt;
</description>
    </item>
<item>
  <title>CISA Adds One Known Exploited Vulnerability to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/04/16/cisa-adds-one-known-exploited-vulnerability-catalog</link>
  <description>&lt;p&gt;CISA has added one new vulnerability to its &lt;a href=&quot;/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
</description>
    </item>
<item>
  <title>CISA Adds Two Known Exploited Vulnerabilities to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/04/14/cisa-adds-two-known-exploited-vulnerabilities-catalog</link>
  <description>&lt;p&gt;CISA has added two new vulnerabilities to its &lt;a href=&quot;/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
</description>
    </item>
<item>
  <title>CISA Adds Seven Known Exploited Vulnerabilities to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/04/13/cisa-adds-seven-known-exploited-vulnerabilities-catalog</link>
  <description>&lt;p&gt;CISA has added seven new vulnerabilities to its &lt;a href=&quot;/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
</description>
    </item>
<item>
  <title>CISA Adds One Known Exploited Vulnerability to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/04/08/cisa-adds-one-known-exploited-vulnerability-catalog</link>
  <description>&lt;p&gt;CISA has added one new vulnerability to its &lt;a href=&quot;/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
</description>
    </item>
<item>
  <title>CISA Adds One Known Exploited Vulnerability to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/04/06/cisa-adds-one-known-exploited-vulnerability-catalog</link>
  <description>&lt;p&gt;CISA has added one new vulnerability to its &lt;a href=&quot;/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
</description>
    </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Daily Dave</title>
    <link>https://seclists.org/#dailydave</link>
    <description>This technical discussion list covers vulnerability research, exploit development, and security events/gossip.  It was started by &lt;a href=&quot;http://www.immunitysec.com/&quot;&gt;ImmunitySec&lt;/a&gt; founder Dave Aitel and many security luminaries participate.  Many posts simply advertise Immunity products, but you can&#39;t really fault Dave for being self-promotional on a list named DailyDave.</description>
  <item>
    <title>OpenAI Codex Security</title>
    <link>https://seclists.org/dailydave/2026/q1/2</link>
    <description>&lt;p&gt;Posted by Dave Aitel via Dailydave on Mar 07&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;https://openai.com/index/codex-security-now-in-research-preview/&quot;&gt;https://openai.com/index/codex-security-now-in-research-preview/&lt;/a&gt;&lt;br&gt;
1. Say what...&lt;br&gt;</description>
  </item>
  <item>
    <title>RE//verse, DistrictCon, an Anole Friend</title>
    <link>https://seclists.org/dailydave/2026/q1/1</link>
    <description>&lt;p&gt;Posted by Dave Aitel via Dailydave on Feb 02&lt;/p&gt;Last month was DistrictCon, a great conference that I did not attend&lt;br&gt;
Today it is...&lt;br&gt;</description>
  </item>
  <item>
    <title>feeling the air</title>
    <link>https://seclists.org/dailydave/2026/q1/0</link>
    <description>&lt;p&gt;Posted by Dave Aitel via Dailydave on Jan 05&lt;/p&gt;For reasons I still don’t fully understand, Miami Beach has enormous&lt;br&gt;
them somewhere overhead, wings spread wide, fingers splayed, feeling the...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Defense ?</title>
    <link>https://seclists.org/dailydave/2025/q4/6</link>
    <description>&lt;p&gt;Posted by Dean Pierce via Dailydave on Nov 16&lt;/p&gt;I like the idea of having a software supply chain that people can pay into&lt;br&gt;
with is a software ecosystem where anyone can build what they need...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Defense ?</title>
    <link>https://seclists.org/dailydave/2025/q4/5</link>
    <description>&lt;p&gt;Posted by Chris Anley via Dailydave on Nov 16&lt;/p&gt;(gingerly raises head above parapet)&lt;br&gt;
of 1 per 15 minutes (calendar year 2024), means that patching an enterprise before an...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Defense ?</title>
    <link>https://seclists.org/dailydave/2025/q4/4</link>
    <description>&lt;p&gt;Posted by Alfonso De Gregorio via Dailydave on Nov 16&lt;/p&gt;Imbalances in the skills and workforce are real. The gap remains hard&lt;br&gt;
regardless: those imbalances are a byproduct of the...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Defense ?</title>
    <link>https://seclists.org/dailydave/2025/q4/3</link>
    <description>&lt;p&gt;Posted by Conan Dooley via Dailydave on Nov 16&lt;/p&gt;Reduce complexity, duplication, and scope in your infrastructure. Your&lt;br&gt;
say, just...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Defense ?</title>
    <link>https://seclists.org/dailydave/2025/q4/2</link>
    <description>&lt;p&gt;Posted by etojake--- via Dailydave on Nov 16&lt;/p&gt;The content of this message was lost. It was probably cross-posted to&lt;br&gt;
multiple lists and previously handled on another list.&lt;br&gt;</description>
  </item>
  <item>
    <title>Defense ?</title>
    <link>https://seclists.org/dailydave/2025/q4/1</link>
    <description>&lt;p&gt;Posted by Dave Aitel via Dailydave on Nov 15&lt;/p&gt;How would one actually move the actual bar in defense? A big part of me&lt;br&gt;
Like...&lt;br&gt;</description>
  </item>
  <item>
    <title>Offensive AI Con</title>
    <link>https://seclists.org/dailydave/2025/q4/0</link>
    <description>&lt;p&gt;Posted by Dave Aitel via Dailydave on Oct 08&lt;/p&gt;So I just got back from &amp;quot;Offensive AI Conference&amp;quot; in San Diego and it was a&lt;br&gt;
FOMO, but also, when a conference is &amp;quot;invite only&amp;quot; then you...&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>BreachExchange</title>
    <link>https://seclists.org/#dataloss</link>
    <description>BreachExchange focuses on all things data breach. Topics include actual data breaches, cyber insurance, risk management, metrics and more. This archive includes its predecessor, the Data Loss news and discussion lists.</description>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Educause Security Discussion</title>
    <link>https://seclists.org/#educause</link>
    <description>Securing networks and computers in an academic environment.</description>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Full Disclosure</title>
    <link>https://seclists.org/#fulldisclosure</link>
    <description>A public, vendor-neutral forum for detailed discussion of vulnerabilities and exploitation techniques, as well as tools, papers, news, and events of interest to the community.  The relaxed atmosphere of this quirky list provides some comic relief and certain industry gossip.  More importantly, fresh vulnerabilities sometimes hit this list many hours or days before they pass through the Bugtraq moderation queue.</description>
  <item>
    <title>[REVIVE-SA-2026-002] Revive Adserver Vulnerabilities</title>
    <link>https://seclists.org/fulldisclosure/2026/Jun/0</link>
    <description>&lt;p&gt;Posted by Matteo Beccati on Jun 04&lt;/p&gt;========================================================================&lt;br&gt;
Versions...&lt;br&gt;</description>
  </item>
  <item>
    <title>CyberDanube Security Research 20260528-0 | Multiple Vulnerabilities in Multiple Vulnerabilities in Mennekes Amtron Series</title>
    <link>https://seclists.org/fulldisclosure/2026/May/25</link>
    <description>&lt;p&gt;Posted by Thomas Weber | CyberDanube via Fulldisclosure on May 31&lt;/p&gt;CyberDanube Security Research 20260528-0&lt;br&gt;
                found|...&lt;br&gt;</description>
  </item>
  <item>
    <title> bmcweb (OpenBMC web server): four vulnerabilities — two unfixed, GHSA without a CVE</title>
    <link>https://seclists.org/fulldisclosure/2026/May/24</link>
    <description>&lt;p&gt;Posted by binreaper via Fulldisclosure on May 31&lt;/p&gt;Hi all,&lt;br&gt;
A Baseboard Management Controller boots before the host CPU, has full control over the server...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Dovecot Security Advisory OXDC-2026-0002</title>
    <link>https://seclists.org/fulldisclosure/2026/May/23</link>
    <description>&lt;p&gt;Posted by Noel Butler via Fulldisclosure on May 25&lt;/p&gt;So when is the fix for dovecot 2.3 source code due to be released?&lt;br&gt;
serious fixes have been made in recent times.&lt;br&gt;</description>
  </item>
  <item>
    <title> SSRF in Anthropic mcp-server-fetch and Microsoft playwright-mcp — publicly disclosed via GitHub issues</title>
    <link>https://seclists.org/fulldisclosure/2026/May/22</link>
    <description>&lt;p&gt;Posted by outreach on May 25&lt;/p&gt;-----BEGIN SECURITY ADVISORY-----&lt;br&gt;
   All versions as of May...&lt;br&gt;</description>
  </item>
  <item>
    <title>[SECURITY ADVISORY] CVE-2021-21735 - ZTE ZXHN H168N V3.5 Unauthenticated Admin Credential Leak</title>
    <link>https://seclists.org/fulldisclosure/2026/May/21</link>
    <description>&lt;p&gt;Posted by m.nageh on May 25&lt;/p&gt;-----BEGIN SECURITY ADVISORY-----&lt;br&gt;
Public URL:...&lt;br&gt;</description>
  </item>
  <item>
    <title>[SECURITY ADVISORY] CVE-2026-34474 - ZTE H298A/H108N Unauthenticated Admin Credential Exposure</title>
    <link>https://seclists.org/fulldisclosure/2026/May/20</link>
    <description>&lt;p&gt;Posted by m.nageh on May 25&lt;/p&gt;-----BEGIN SECURITY ADVISORY-----&lt;br&gt;
Public URL:...&lt;br&gt;</description>
  </item>
  <item>
    <title>[SECURITY ADVISORY] CVE-2026-34472 - ZTE ZXHN H188A V6 Authentication Bypass via Pre-Login Wizard</title>
    <link>https://seclists.org/fulldisclosure/2026/May/19</link>
    <description>&lt;p&gt;Posted by m.nageh on May 25&lt;/p&gt;-----BEGIN SECURITY ADVISORY-----&lt;br&gt;
Public URL:...&lt;br&gt;</description>
  </item>
  <item>
    <title>[SECURITY ADVISORY] CVE-2026-34473 - Unauthenticated DoS in 17+ ZTE Router Models (140K+ Devices)</title>
    <link>https://seclists.org/fulldisclosure/2026/May/18</link>
    <description>&lt;p&gt;Posted by m.nageh on May 25&lt;/p&gt;-----BEGIN SECURITY ADVISORY-----&lt;br&gt;
Contact:        minanageh379 () gmail...&lt;br&gt;</description>
  </item>
  <item>
    <title>Multiple vulnerabilities in Sparx Pro Cloud Server and Enterprise Architect</title>
    <link>https://seclists.org/fulldisclosure/2026/May/17</link>
    <description>&lt;p&gt;Posted by Adamczyk Blazej on May 25&lt;/p&gt;━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━&lt;br&gt;
General...&lt;br&gt;</description>
  </item>
  <item>
    <title>APPLE-SA-05-13-2026-1 Safari 26.5</title>
    <link>https://seclists.org/fulldisclosure/2026/May/16</link>
    <description>&lt;p&gt;Posted by Apple Product Security via Fulldisclosure on May 17&lt;/p&gt;APPLE-SA-05-13-2026-1 Safari 26.5&lt;br&gt;
Impact: Processing maliciously crafted web content may prevent Content...&lt;br&gt;</description>
  </item>
  <item>
    <title>APPLE-SA-05-11-2026-11 visionOS 26.5</title>
    <link>https://seclists.org/fulldisclosure/2026/May/15</link>
    <description>&lt;p&gt;Posted by Apple Product Security via Fulldisclosure on May 17&lt;/p&gt;APPLE-SA-05-11-2026-11 visionOS 26.5&lt;br&gt;
Description:...&lt;br&gt;</description>
  </item>
  <item>
    <title>APPLE-SA-05-11-2026-10 watchOS 26.5</title>
    <link>https://seclists.org/fulldisclosure/2026/May/14</link>
    <description>&lt;p&gt;Posted by Apple Product Security via Fulldisclosure on May 17&lt;/p&gt;APPLE-SA-05-11-2026-10 watchOS 26.5&lt;br&gt;
Description:...&lt;br&gt;</description>
  </item>
  <item>
    <title>APPLE-SA-05-11-2026-9 tvOS 26.5</title>
    <link>https://seclists.org/fulldisclosure/2026/May/13</link>
    <description>&lt;p&gt;Posted by Apple Product Security via Fulldisclosure on May 17&lt;/p&gt;APPLE-SA-05-11-2026-9 tvOS 26.5&lt;br&gt;
Impact: An app may be able to cause a denial-of-service...&lt;br&gt;</description>
  </item>
  <item>
    <title>APPLE-SA-05-11-2026-8 macOS Sonoma 14.8.7</title>
    <link>https://seclists.org/fulldisclosure/2026/May/7</link>
    <description>&lt;p&gt;Posted by Apple Product Security via Fulldisclosure on May 17&lt;/p&gt;APPLE-SA-05-11-2026-8 macOS Sonoma 14.8.7&lt;br&gt;
Description: A...&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Funsec</title>
    <link>https://seclists.org/#funsec</link>
    <description>While most security lists ban off-topic discussion, Funsec is a haven for free community discussion and enjoyment of the lighter, more humorous side of the security community</description>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Info Security News</title>
    <link>https://seclists.org/#isn</link>
    <description>Carries news items (generally from mainstream sources) that relate to security.</description>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Metasploit</title>
    <link>https://seclists.org/#metasploit</link>
    <description>Development discussion for &lt;a href=&quot;http://metasploit.com/&quot;&gt;Metasploit&lt;/a&gt;, the premier open source remote exploitation tool</description>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Microsoft Sec Notification</title>
    <link>https://seclists.org/#microsoft</link>
    <description>Beware that MS often uses these security bulletins as marketing propaganda to downplay serious vulnerabilities in their products&amp;mdash;note how most have a prominent and often-misleading &quot;mitigating factors&quot; section.</description>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Nmap Development</title>
    <link>https://seclists.org/#nmap-dev</link>
    <description>Unmoderated technical development forum for debating ideas, patches, and suggestions regarding proposed changes to &lt;a href=&quot;https://nmap.org&quot;&gt;Nmap&lt;/A&gt; and related projects. &lt;a href=&quot;https://nmap.org/mailman/listinfo/dev&quot;&gt;Subscribe to nmap-dev here&lt;/a&gt;.</description>
  <item>
    <title>[PATCH] nselib/bitcoin: add address classification helpers (refs #2857, PR #3371)</title>
    <link>https://seclists.org/nmap-dev/2026/q2/6</link>
    <description>&lt;p&gt;Posted by Melo via dev on May 25&lt;/p&gt;PR #3371 adds three functions to nselib/bitcoin.lua:&lt;br&gt;
Issue:...&lt;br&gt;</description>
  </item>
  <item>
    <title>[NSE] matter-identify: identify Matter smart-home devices via mDNS</title>
    <link>https://seclists.org/nmap-dev/2026/q2/5</link>
    <description>&lt;p&gt;Posted by Balázs Zoltán on May 11&lt;/p&gt; Hi,&lt;br&gt;
  TXT records are decoded into VID,...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re:</title>
    <link>https://seclists.org/nmap-dev/2026/q2/4</link>
    <description>&lt;p&gt;Posted by Rahmat Ramadhan on May 01&lt;/p&gt;gaa&lt;br&gt;
juanjoserodriguezmontoya35 () gmail com&amp;gt; menulis:&lt;br&gt;</description>
  </item>
  <item>
    <title>[PATCH 0/5] ALPN-based HTTP/2 service detection improvements</title>
    <link>https://seclists.org/nmap-dev/2026/q2/3</link>
    <description>&lt;p&gt;Posted by Urval Kheni on Apr 14&lt;/p&gt;Hi,&lt;br&gt;
 1. Fix OpenSSL provider...&lt;br&gt;</description>
  </item>
  <item>
    <title>Bug Report: ssl-enum-ciphers fails (EOF) on CloudFront/ECDSA targets supporting TLS 1.2</title>
    <link>https://seclists.org/nmap-dev/2026/q2/2</link>
    <description>&lt;p&gt;Posted by Jack Seredyniecki via dev on Apr 14&lt;/p&gt;Hello nmap dev team,&lt;br&gt;
NSE: [ssl-enum-ciphers...&lt;br&gt;</description>
  </item>
  <item>
    <title>[PATCH] Support Linux capabilities for non-root raw packet scanning</title>
    <link>https://seclists.org/nmap-dev/2026/q2/1</link>
    <description>&lt;p&gt;Posted by Ali Norouzi via dev on Apr 14&lt;/p&gt;Hi everyone,&lt;br&gt;
Ali&lt;br&gt;</description>
  </item>
  <item>
    <title>Fix for issue #3326</title>
    <link>https://seclists.org/nmap-dev/2026/q2/0</link>
    <description>&lt;p&gt;Posted by advait deshmukh on Apr 14&lt;/p&gt;Issue link &amp;lt;&lt;a  rel=&quot;nofollow&quot; href=&quot;https://github.com/nmap/nmap/issues/3326&quot;&gt;https://github.com/nmap/nmap/issues/3326&lt;/a&gt;&amp;gt;&lt;br&gt;
Since the user has explicitly specified -6 in the command, it...&lt;br&gt;</description>
  </item>
  <item>
    <title>Interview Invitation for Educational Research</title>
    <link>https://seclists.org/nmap-dev/2026/q1/5</link>
    <description>&lt;p&gt;Posted by Muhammad Hassan Tanveer via dev on Mar 31&lt;/p&gt;Hello Everyone!&lt;br&gt;
invite you to participate in a ~45-minute online...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: GSoC 2026: Password Security Wizard - Optimizing the NSE Brute Library</title>
    <link>https://seclists.org/nmap-dev/2026/q1/4</link>
    <description>&lt;p&gt;Posted by Adithya Shetty on Mar 13&lt;/p&gt;Ah, my mistake.&lt;br&gt;
Thanks for letting me know Gordon&lt;br&gt;</description>
  </item>
  <item>
    <title>[no subject]</title>
    <link>https://seclists.org/nmap-dev/2026/q1/3</link>
    <description>&lt;p&gt;Posted by Juan jose Rodriguez on Mar 08&lt;/p&gt;Contraseña&lt;br&gt;</description>
  </item>
  <item>
    <title>GSoC 2026: Password Security Wizard - Optimizing the NSE Brute Library</title>
    <link>https://seclists.org/nmap-dev/2026/q1/2</link>
    <description>&lt;p&gt;Posted by Adithya Shetty on Mar 02&lt;/p&gt;Hi Nmap Development Team and Fotis,&lt;br&gt;
several of the -brute.nse scripts (specifically focusing on...&lt;br&gt;</description>
  </item>
  <item>
    <title>Question about Nmap and GSoC 2026</title>
    <link>https://seclists.org/nmap-dev/2026/q1/1</link>
    <description>&lt;p&gt;Posted by Sweekar on Jan 29&lt;/p&gt;Hi Nmap developers,&lt;br&gt;
Sweekar&lt;br&gt;</description>
  </item>
  <item>
    <title>PR #3277: Clean up and harden POP3 helper login functions</title>
    <link>https://seclists.org/nmap-dev/2026/q1/0</link>
    <description>&lt;p&gt;Posted by Sweekar on Jan 23&lt;/p&gt;Hello Nmap Developers,&lt;br&gt;
   Normalized...&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Nmap Announce</title>
    <link>https://seclists.org/#nmap-announce</link>
    <description>Moderated list for the most important new releases and announcements regarding the &lt;a href=&quot;https://nmap.org&quot;&gt;Nmap Security Scanner&lt;/a&gt; and related projects. We recommend that all Nmap users &lt;a href=&quot;https://nmap.org/mailman/listinfo/announce&quot;&gt;subscribe to stay informed&lt;/a&gt;.</description>
  <item>
    <title>Npcap Version 1.82 Released with VLAN Tagging and More</title>
    <link>https://seclists.org/nmap-announce/2025/0</link>
    <description>&lt;p&gt;Posted by Gordon Fyodor Lyon on Apr 28&lt;/p&gt;Dear Nmap Community,&lt;br&gt;
useful for Wireshark users.  You can also now send...&lt;br&gt;</description>
  </item>
  <item>
    <title>Nmap 7.95 released: OS and service detection signatures galore!</title>
    <link>https://seclists.org/nmap-announce/2024/0</link>
    <description>&lt;p&gt;Posted by Gordon Fyodor Lyon on May 05&lt;/p&gt;Dear Nmap Community,&lt;br&gt;
Additions include iOS 15...&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>OpenVAS</title>
    <link>http://seclists.org/#openvas</link>
    <description>Development and announcements regarding &lt;a href=&quot;http://www.openvas.com/&quot;&gt;OpenVAS&lt;/a&gt;, a free network security scanner which forked from Nessus. This is a combination of the English openvas-announce, openvas-devel, openvas-discuss, and openvas-plugins lists.</description>
  <item>
    <title>Re: Help with openvas setup</title>
    <link>http://seclists.org/openvas/2013/q3/107</link>
    <description>&lt;p&gt;Posted by Florent THOMAS on Aug 23&lt;/p&gt;+1 I agree, it&amp;apos;s precious.&lt;br&gt;
Regards&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Help with openvas setup</title>
    <link>http://seclists.org/openvas/2013/q3/106</link>
    <description>&lt;p&gt;Posted by Hariharan Madhavan on Aug 23&lt;/p&gt;The best way to get openvas running is by adding the atomic corp repository and installing using yum... There is no &lt;br&gt;
Am running Backtrack R3 which...&lt;br&gt;</description>
  </item>
  <item>
    <title>SCAP plugins and OpenVAS</title>
    <link>http://seclists.org/openvas/2013/q3/105</link>
    <description>&lt;p&gt;Posted by Rajesh Bhavsar on Aug 23&lt;/p&gt;Hi all,&lt;br&gt;
 &lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Help with openvas setup</title>
    <link>http://seclists.org/openvas/2013/q3/104</link>
    <description>&lt;p&gt;Posted by Florent THOMAS on Aug 22&lt;/p&gt;Hy,&lt;br&gt;
Regards&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Help with openvas setup</title>
    <link>http://seclists.org/openvas/2013/q3/103</link>
    <description>&lt;p&gt;Posted by Samuel Mwai on Aug 22&lt;/p&gt;Am running Backtrack R3 which installed fine. Stumbled on this blog, check&lt;br&gt;
K () sper&lt;br&gt;</description>
  </item>
  <item>
    <title>Help with openvas setup</title>
    <link>http://seclists.org/openvas/2013/q3/102</link>
    <description>&lt;p&gt;Posted by Russell, Sean on Aug 22&lt;/p&gt;Hello all.&lt;br&gt;
I run openvasmd --rebuild, then run openvas-check-setup again, but I...&lt;br&gt;</description>
  </item>
  <item>
    <title>Easy startup script for self-compiled OpenVAS</title>
    <link>http://seclists.org/openvas/2013/q3/101</link>
    <description>&lt;p&gt;Posted by Winfried Neessen on Aug 21&lt;/p&gt;Hi,&lt;br&gt;
each service. Also you can kill one service of OpenVAS, run the startup...&lt;br&gt;</description>
  </item>
  <item>
    <title>OpenVAS Feed Server: Load and Cron</title>
    <link>http://seclists.org/openvas/2013/q3/100</link>
    <description>&lt;p&gt;Posted by Jan-Oliver Wagner on Aug 21&lt;/p&gt;Hello OpenVAS users,&lt;br&gt;
If your...&lt;br&gt;</description>
  </item>
  <item>
    <title>&quot;Issue&quot; for create schedule</title>
    <link>http://seclists.org/openvas/2013/q3/99</link>
    <description>&lt;p&gt;Posted by Florent THOMAS on Aug 20&lt;/p&gt;Hy,&lt;br&gt;
regards&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Create credential failed</title>
    <link>http://seclists.org/openvas/2013/q3/98</link>
    <description>&lt;p&gt;Posted by Florent THOMAS on Aug 20&lt;/p&gt;I think I found the problem.&lt;br&gt;
regards&lt;br&gt;</description>
  </item>
  <item>
    <title>Get_schedules not show task information</title>
    <link>http://seclists.org/openvas/2013/q3/97</link>
    <description>&lt;p&gt;Posted by Rodrigo Seguel on Aug 19&lt;/p&gt;after execute get_schedules command with option details=&amp;quot;1&amp;quot;, the output xml&lt;br&gt;
&amp;lt;get_schedules_response status=&amp;quot;200&amp;quot; status_text=&amp;quot;OK&amp;quot;&amp;gt;&amp;lt;schedule...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: cannot connect to the manager</title>
    <link>http://seclists.org/openvas/2013/q3/96</link>
    <description>&lt;p&gt;Posted by brad on Aug 19&lt;/p&gt;I even brought the ports up one at a time like so,&lt;br&gt;
There is only one error I can find, but little on...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: cannot connect to the manager</title>
    <link>http://seclists.org/openvas/2013/q3/95</link>
    <description>&lt;p&gt;Posted by brad on Aug 19&lt;/p&gt;Here is the output of my openvasmd --rebuild -v  &lt;br&gt;
From: Openvas-discuss...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Create credential failed</title>
    <link>http://seclists.org/openvas/2013/q3/94</link>
    <description>&lt;p&gt;Posted by Florent THOMAS on Aug 18&lt;/p&gt;Thanks for your answer. I&amp;apos;m not sure of the use of this. My french level &lt;br&gt;
Thanks for your help&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Create credential failed</title>
    <link>http://seclists.org/openvas/2013/q3/93</link>
    <description>&lt;p&gt;Posted by Michael Meyer on Aug 18&lt;/p&gt;*** Florent THOMAS wrote:&lt;br&gt;
Micha&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Open Source Security</title>
    <link>https://seclists.org/#oss-sec</link>
    <description>Discussion of security flaws, concepts, and practices in the Open Source community</description>
  <item>
    <title>[oss-security][CVE-2026-9669] CPython: bz2.BZ2Decompressor reuse after error can cause a stack buffer overflow</title>
    <link>https://seclists.org/oss-sec/2026/q2/846</link>
    <description>&lt;p&gt;Posted by Alan Coopersmith on Jun 08&lt;/p&gt;The CVE record currently lists versions &amp;quot;affected from 0 before 3.16.0&amp;quot;&lt;br&gt;
There is a HIGH severity...&lt;br&gt;</description>
  </item>
  <item>
    <title>CVE-2026-49975: Apache HTTP Server: mod_http2 denial of service</title>
    <link>https://seclists.org/oss-sec/2026/q2/845</link>
    <description>&lt;p&gt;Posted by Eric Covener on Jun 08&lt;/p&gt;Severity: moderate &lt;br&gt;
References:...&lt;br&gt;</description>
  </item>
  <item>
    <title>CVE-2026-48913: Apache HTTP Server: mod_http2 memory corruption when file handles exhausted</title>
    <link>https://seclists.org/oss-sec/2026/q2/844</link>
    <description>&lt;p&gt;Posted by Eric Covener on Jun 08&lt;/p&gt;Severity: low &lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;https://httpd.apache.org/&quot;&gt;https://httpd.apache.org/&lt;/a&gt;...&lt;br&gt;</description>
  </item>
  <item>
    <title>CVE-2026-44631: Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow</title>
    <link>https://seclists.org/oss-sec/2026/q2/843</link>
    <description>&lt;p&gt;Posted by Eric Covener on Jun 08&lt;/p&gt;Severity: low &lt;br&gt;
References:...&lt;br&gt;</description>
  </item>
  <item>
    <title>CVE-2026-44186: Apache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftp</title>
    <link>https://seclists.org/oss-sec/2026/q2/842</link>
    <description>&lt;p&gt;Posted by Eric Covener on Jun 08&lt;/p&gt;Severity: moderate &lt;br&gt;
Zhenpeng (Leo) Lin at...&lt;br&gt;</description>
  </item>
  <item>
    <title>CVE-2026-44185: Apache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request`</title>
    <link>https://seclists.org/oss-sec/2026/q2/841</link>
    <description>&lt;p&gt;Posted by Eric Covener on Jun 08&lt;/p&gt;Severity: low &lt;br&gt;
References:...&lt;br&gt;</description>
  </item>
  <item>
    <title>CVE-2026-44119: Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modules</title>
    <link>https://seclists.org/oss-sec/2026/q2/840</link>
    <description>&lt;p&gt;Posted by Eric Covener on Jun 08&lt;/p&gt;Severity: moderate &lt;br&gt;
as3617...&lt;br&gt;</description>
  </item>
  <item>
    <title>CVE-2026-43951: Apache HTTP Server: OOB Read in `merge_response_headers` can cause crash</title>
    <link>https://seclists.org/oss-sec/2026/q2/839</link>
    <description>&lt;p&gt;Posted by Eric Covener on Jun 08&lt;/p&gt;Severity: moderate &lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;https://httpd.apache.org/&quot;&gt;https://httpd.apache.org/&lt;/a&gt;...&lt;br&gt;</description>
  </item>
  <item>
    <title>CVE-2026-42536: Apache HTTP Server: mod_xml2enc heap overflow</title>
    <link>https://seclists.org/oss-sec/2026/q2/838</link>
    <description>&lt;p&gt;Posted by Eric Covener on Jun 08&lt;/p&gt;Severity: low &lt;br&gt;
References:...&lt;br&gt;</description>
  </item>
  <item>
    <title>CVE-2026-42535: Apache HTTP Server: mod_dav_fs protected directory access</title>
    <link>https://seclists.org/oss-sec/2026/q2/837</link>
    <description>&lt;p&gt;Posted by Eric Covener on Jun 08&lt;/p&gt;Severity: moderate &lt;br&gt;
References:...&lt;br&gt;</description>
  </item>
  <item>
    <title>CVE-2026-34356: Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow</title>
    <link>https://seclists.org/oss-sec/2026/q2/836</link>
    <description>&lt;p&gt;Posted by Eric Covener on Jun 08&lt;/p&gt;Severity: low &lt;br&gt;
References:...&lt;br&gt;</description>
  </item>
  <item>
    <title>CVE-2026-34355: Apache HTTP Server: mod_proxy_html buffer overflow</title>
    <link>https://seclists.org/oss-sec/2026/q2/835</link>
    <description>&lt;p&gt;Posted by Eric Covener on Jun 08&lt;/p&gt;Severity: moderate &lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;https://httpd.apache.org/&quot;&gt;https://httpd.apache.org/&lt;/a&gt;...&lt;br&gt;</description>
  </item>
  <item>
    <title>CVE-2026-29170: Apache HTTP Server: mod_proxy_ftp XSS</title>
    <link>https://seclists.org/oss-sec/2026/q2/834</link>
    <description>&lt;p&gt;Posted by Eric Covener on Jun 08&lt;/p&gt;Severity: low &lt;br&gt;
Pavel Kohout, Aisle Research, Aisle.com (finder)...&lt;br&gt;</description>
  </item>
  <item>
    <title>CVE-2026-29167: Apache HTTP Server: mod_ldap per-dir use-after-free</title>
    <link>https://seclists.org/oss-sec/2026/q2/833</link>
    <description>&lt;p&gt;Posted by Eric Covener on Jun 08&lt;/p&gt;Severity: low &lt;br&gt;
References:...&lt;br&gt;</description>
  </item>
  <item>
    <title>offlineimap 8.0.3 fixes CVE-2020-37248 (STARTTLS stripping)</title>
    <link>https://seclists.org/oss-sec/2026/q2/832</link>
    <description>&lt;p&gt;Posted by Sebastian Pipping on Jun 08&lt;/p&gt;Hello oss-security,&lt;br&gt;
The key fix commit is…...&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>PaulDotCom</title>
    <link>https://seclists.org/#pauldotcom</link>
    <description>General discussion of security news, research, vulnerabilities, and the PaulDotCom Security Weekly podcast.</description>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Penetration Testing</title>
    <link>https://seclists.org/#pen-test</link>
    <description>While this list is intended for &quot;professionals&quot;, participants frequenly disclose techniques and strategies that would be useful to anyone with a practical interest in security and network auditing.</description>
</channel>
</rss>
<rss version="2.0">
<channel>
        <title>Exploit-DB.com RSS Feed</title>
        <link>https://www.exploit-db.com</link>
        <description>The Exploit Database - Exploits, Shellcode, 0days, Remote Exploits, Local Exploits, Web Apps, Vulnerability Reports, Security Articles, Tutorials and more.</description>
         <item>
            <title>[webapps] OpenEMR 7.0.2 - Arbitrary File Read</title>
            <link>https://www.exploit-db.com/exploits/52610</link>
            <description>OpenEMR 7.0.2 - Arbitrary File Read</description>
        </item>
         <item>
            <title>[webapps] WordPress Contest Gallery 28.1.4 - Unauthenticated Blind SQL Injection</title>
            <link>https://www.exploit-db.com/exploits/52609</link>
            <description>WordPress Contest Gallery 28.1.4 - Unauthenticated Blind SQL Injection</description>
        </item>
         <item>
            <title>[webapps] Drupal Core 10.5.5 - Error-Based SQL Injection</title>
            <link>https://www.exploit-db.com/exploits/52608</link>
            <description>Drupal Core 10.5.5 - Error-Based SQL Injection</description>
        </item>
         <item>
            <title>[webapps] WordPress OrderConvo 14 - Path Traversal</title>
            <link>https://www.exploit-db.com/exploits/52607</link>
            <description>WordPress OrderConvo 14 - Path Traversal</description>
        </item>
         <item>
            <title>[remote] Notepad++ 8.9.6 - Arbitrary Code Execution</title>
            <link>https://www.exploit-db.com/exploits/52606</link>
            <description>Notepad++ 8.9.6 - Arbitrary Code Execution</description>
        </item>
         <item>
            <title>[webapps] YAMCS yamcs-core  5.12.7 - No Rate Limiting</title>
            <link>https://www.exploit-db.com/exploits/52605</link>
            <description>YAMCS yamcs-core  5.12.7 - No Rate Limiting</description>
        </item>
         <item>
            <title>[webapps] YAMCS yamcs-core  5.12.7 - User Enumeration</title>
            <link>https://www.exploit-db.com/exploits/52604</link>
            <description>YAMCS yamcs-core  5.12.7 - User Enumeration</description>
        </item>
         <item>
            <title>[webapps] YAMCS yamcs-core  5.12.7 - LDAP Injection</title>
            <link>https://www.exploit-db.com/exploits/52603</link>
            <description>YAMCS yamcs-core  5.12.7 - LDAP Injection</description>
        </item>
         <item>
            <title>[remote] Microsoft - NTLMv2 Hash Capture</title>
            <link>https://www.exploit-db.com/exploits/52601</link>
            <description>Microsoft - NTLMv2 Hash Capture</description>
        </item>
         <item>
            <title>[webapps] MikroORM   7.0.13 - SQL Injection</title>
            <link>https://www.exploit-db.com/exploits/52600</link>
            <description>MikroORM   7.0.13 - SQL Injection</description>
        </item>
         <item>
            <title>[webapps] Prodigy Commerce 3.3.0 - Local File Inclusion</title>
            <link>https://www.exploit-db.com/exploits/52598</link>
            <description>Prodigy Commerce 3.3.0 - Local File Inclusion</description>
        </item>
         <item>
            <title>[webapps] Langflow 1.3.0 - Remote Code Execution</title>
            <link>https://www.exploit-db.com/exploits/52597</link>
            <description>Langflow 1.3.0 - Remote Code Execution</description>
        </item>
         <item>
            <title>[webapps] Quick Playground for WordPress 1.3.1 - Unauthenticated Remote Code Execution</title>
            <link>https://www.exploit-db.com/exploits/52596</link>
            <description>Quick Playground for WordPress 1.3.1 - Unauthenticated Remote Code Execution</description>
        </item>
         <item>
            <title>[local] ImageMagick - Infinite Loop in the MIFF decoder can lead to CPU exhaustion</title>
            <link>https://www.exploit-db.com/exploits/52595</link>
            <description>ImageMagick - Infinite Loop in the MIFF decoder can lead to CPU exhaustion</description>
        </item>
         <item>
            <title>[local] ZTE Routers  - Unauthenticated Denial of Service</title>
            <link>https://www.exploit-db.com/exploits/52594</link>
            <description>ZTE Routers  - Unauthenticated Denial of Service</description>
        </item>
         <item>
            <title>[local] ZTE ZXHN H188A V6 - Authentication Bypass</title>
            <link>https://www.exploit-db.com/exploits/52593</link>
            <description>ZTE ZXHN H188A V6 - Authentication Bypass</description>
        </item>
         <item>
            <title>[local] ZTE H298A / H108N - Unauthenticated Credential Exposure</title>
            <link>https://www.exploit-db.com/exploits/52592</link>
            <description>ZTE H298A / H108N - Unauthenticated Credential Exposure</description>
        </item>
         <item>
            <title>[local] Linux Kernel -  Local Privilege Escalation</title>
            <link>https://www.exploit-db.com/exploits/52591</link>
            <description>Linux Kernel -  Local Privilege Escalation</description>
        </item>
         <item>
            <title>[webapps] MixPHP Framework 2.2.17 - Unsafe Deserialization Remote Code Execution</title>
            <link>https://www.exploit-db.com/exploits/52590</link>
            <description>MixPHP Framework 2.2.17 - Unsafe Deserialization Remote Code Execution</description>
        </item>
         <item>
            <title>[remote] Wing FTP Server 8.1.3 - Authenticated Remote Code Execution</title>
            <link>https://www.exploit-db.com/exploits/52589</link>
            <description>Wing FTP Server 8.1.3 - Authenticated Remote Code Execution</description>
        </item>
         <item>
            <title>[webapps] CubeCart &lt; 6.7.0 - Reflected Cross-Site Scripting (XSS) (Unauthenticated)</title>
            <link>https://www.exploit-db.com/exploits/52588</link>
            <description>CubeCart &lt; 6.7.0 - Reflected Cross-Site Scripting (XSS) (Unauthenticated)</description>
        </item>
         <item>
            <title>[remote] strongSwan 5.9.13 - libsimaka EAP-SIM/AKA heap buffer overflow</title>
            <link>https://www.exploit-db.com/exploits/52587</link>
            <description>strongSwan 5.9.13 - libsimaka EAP-SIM/AKA heap buffer overflow</description>
        </item>
         <item>
            <title>[dos] strongSwan 5.9.13 - DoS</title>
            <link>https://www.exploit-db.com/exploits/52586</link>
            <description>strongSwan 5.9.13 - DoS</description>
        </item>
         <item>
            <title>[local] Linux Kernel - Local Privilege Escalation</title>
            <link>https://www.exploit-db.com/exploits/52585</link>
            <description>Linux Kernel - Local Privilege Escalation</description>
        </item>
         <item>
            <title>[webapps] Casdoor 3.54.1 - Arbitrary File Write via Path Traversal</title>
            <link>https://www.exploit-db.com/exploits/52584</link>
            <description>Casdoor 3.54.1 - Arbitrary File Write via Path Traversal</description>
        </item>
         <item>
            <title>[webapps] EspoCRM 9.3.3 -  SSRF</title>
            <link>https://www.exploit-db.com/exploits/52583</link>
            <description>EspoCRM 9.3.3 -  SSRF</description>
        </item>
         <item>
            <title>[webapps] scramble - Remote Code Execution</title>
            <link>https://www.exploit-db.com/exploits/52582</link>
            <description>scramble - Remote Code Execution</description>
        </item>
         <item>
            <title>[hardware] MeiG Smart FORGE_SLT711 - OS Command Injection</title>
            <link>https://www.exploit-db.com/exploits/52581</link>
            <description>MeiG Smart FORGE_SLT711 - OS Command Injection</description>
        </item>
         <item>
            <title>[local] Realtek rtl819x  - Local Privilege</title>
            <link>https://www.exploit-db.com/exploits/52580</link>
            <description>Realtek rtl819x  - Local Privilege</description>
        </item>
         <item>
            <title>[webapps] OpenCATS 0.9.7.4 - SQL Injection</title>
            <link>https://www.exploit-db.com/exploits/52579</link>
            <description>OpenCATS 0.9.7.4 - SQL Injection</description>
        </item>
         <item>
            <title>[webapps] Grav CMS 2.0.0-beta.2 -  Remote Code Execution</title>
            <link>https://www.exploit-db.com/exploits/52578</link>
            <description>Grav CMS 2.0.0-beta.2 -  Remote Code Execution</description>
        </item>
         <item>
            <title>[webapps] Apache HTTP Server 2.4.66 - 'mod_http2' Double-Free Denial of Service</title>
            <link>https://www.exploit-db.com/exploits/52577</link>
            <description>Apache HTTP Server 2.4.66 - 'mod_http2' Double-Free Denial of Service</description>
        </item>
         <item>
            <title>[hardware] D-Link DSL2600U - 'rom-0' Admin Password Disclosure</title>
            <link>https://www.exploit-db.com/exploits/52576</link>
            <description>D-Link DSL2600U - 'rom-0' Admin Password Disclosure</description>
        </item>
         <item>
            <title>[webapps] Wordpress Temporary Login Plugin  1.0.0 - 'temp-login-token' Authentication Bypass to Account Takeover</title>
            <link>https://www.exploit-db.com/exploits/52575</link>
            <description>Wordpress Temporary Login Plugin  1.0.0 - 'temp-login-token' Authentication Bypass to Account Takeover</description>
        </item>
         <item>
            <title>[webapps] cPanel - CRLF Injection</title>
            <link>https://www.exploit-db.com/exploits/52574</link>
            <description>cPanel - CRLF Injection</description>
        </item>
         <item>
            <title>[local] Linux Kernel 6.8 - Local Privilege Escalation</title>
            <link>https://www.exploit-db.com/exploits/52573</link>
            <description>Linux Kernel 6.8 - Local Privilege Escalation</description>
        </item>
         <item>
            <title>[webapps] Cockpit 359 - RCE</title>
            <link>https://www.exploit-db.com/exploits/52572</link>
            <description>Cockpit 359 - RCE</description>
        </item>
         <item>
            <title>[webapps] BookStack 25.12.1 - Denial of Service</title>
            <link>https://www.exploit-db.com/exploits/52571</link>
            <description>BookStack 25.12.1 - Denial of Service</description>
        </item>
         <item>
            <title>[local] Lenovo LegionSpace 1.7.11.2 - 'DAService' Unquoted Service Path</title>
            <link>https://www.exploit-db.com/exploits/52570</link>
            <description>Lenovo LegionSpace 1.7.11.2 - 'DAService' Unquoted Service Path</description>
        </item>
         <item>
            <title>[webapps] solaredge - (CSRF-OOB-Injection)</title>
            <link>https://www.exploit-db.com/exploits/52569</link>
            <description>solaredge - (CSRF-OOB-Injection)</description>
        </item>
         <item>
            <title>[webapps] FUXA  1.2.9 -  RCE</title>
            <link>https://www.exploit-db.com/exploits/52568</link>
            <description>FUXA  1.2.9 -  RCE</description>
        </item>
         <item>
            <title>[local] Windows Snipping Tool - NTLMv2 Hash Hijack</title>
            <link>https://www.exploit-db.com/exploits/52567</link>
            <description>Windows Snipping Tool - NTLMv2 Hash Hijack</description>
        </item>
         <item>
            <title>[local] Remote Sunrise Helper for Windows 2026.14 - Unauthenticated File/Directory Listing</title>
            <link>https://www.exploit-db.com/exploits/52566</link>
            <description>Remote Sunrise Helper for Windows 2026.14 - Unauthenticated File/Directory Listing</description>
        </item>
         <item>
            <title>[local] Remote Sunrise Helper for Windows 2026.14 - Remote Code Execution</title>
            <link>https://www.exploit-db.com/exploits/52565</link>
            <description>Remote Sunrise Helper for Windows 2026.14 - Remote Code Execution</description>
        </item>
         <item>
            <title>[webapps] WordPress Plugin Supsystic Contact Form 1.7.36 - SSTI</title>
            <link>https://www.exploit-db.com/exploits/52564</link>
            <description>WordPress Plugin Supsystic Contact Form 1.7.36 - SSTI</description>
        </item>
         <item>
            <title>[webapps] Apache HertzBeat 1.8.0 - Remote Code Execution</title>
            <link>https://www.exploit-db.com/exploits/52563</link>
            <description>Apache HertzBeat 1.8.0 - Remote Code Execution</description>
        </item>
         <item>
            <title>[webapps] ePati Antikor NGFW 2.0.1301 -  Authentication Bypass</title>
            <link>https://www.exploit-db.com/exploits/52562</link>
            <description>ePati Antikor NGFW 2.0.1301 -  Authentication Bypass</description>
        </item>
         <item>
            <title>[webapps] PJPROJECT 2.16 - Heap Bufferoverflow</title>
            <link>https://www.exploit-db.com/exploits/52561</link>
            <description>PJPROJECT 2.16 - Heap Bufferoverflow</description>
        </item>
         <item>
            <title>[webapps] Ninja Forms Uploads - Unauthenticated PHP File Upload</title>
            <link>https://www.exploit-db.com/exploits/52560</link>
            <description>Ninja Forms Uploads - Unauthenticated PHP File Upload</description>
        </item>
         <item>
            <title>[webapps] glances 4.5.2 - command injection</title>
            <link>https://www.exploit-db.com/exploits/52559</link>
            <description>glances 4.5.2 - command injection</description>
        </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Secure Coding</title>
    <link>https://seclists.org/#securecoding</link>
    <description>The Secure Coding list (SC-L) is an open forum for the discussion on developing secure applications. It is moderated by the authors of &lt;a href=&quot;http://www.amazon.com/dp/0596002424?tag=secbks-20&quot;&gt;Secure Coding: Principles and Practices&lt;/a&gt;.</description>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Snort</title>
    <link>https://seclists.org/#snort</link>
    <description>Everyone&#39;s favorite open source IDS, &lt;a href=&quot;http://www.snort.org/&quot;&gt;Snort&lt;/a&gt;. This archive combines the snort-announce, snort-devel, snort-users, and snort-sigs lists.</description>
  <item>
    <title>Re: Snort Subscriber Rules Update 2026-06-04</title>
    <link>https://seclists.org/snort/2026/q2/20</link>
    <description>&lt;p&gt;Posted by Jonathan Lee via Snort-sigs on Jun 08&lt;/p&gt;Hello Snort Team ET issued a bug last night and it was cause the engine to not start. &lt;br&gt;
Rule SID 2054074 (ET EXPLOIT Kingdee Cloud Star...&lt;br&gt;</description>
  </item>
  <item>
    <title>Snort Subscriber Rules Update 2026-06-04</title>
    <link>https://seclists.org/snort/2026/q2/19</link>
    <description>&lt;p&gt;Posted by Research via Snort-sigs on Jun 04&lt;/p&gt;Talos Snort Subscriber Rules Update&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;https://www.snort.org/advisories&quot;&gt;https://www.snort.org/advisories&lt;/a&gt;&lt;br&gt;</description>
  </item>
  <item>
    <title>Snort Subscriber Rules Update 2026-06-02</title>
    <link>https://seclists.org/snort/2026/q2/18</link>
    <description>&lt;p&gt;Posted by Research via Snort-sigs on Jun 02&lt;/p&gt;Talos Snort Subscriber Rules Update&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;https://www.snort.org/advisories&quot;&gt;https://www.snort.org/advisories&lt;/a&gt;&lt;br&gt;</description>
  </item>
  <item>
    <title>Snort Subscriber Rules Update 2026-05-28</title>
    <link>https://seclists.org/snort/2026/q2/17</link>
    <description>&lt;p&gt;Posted by Research via Snort-sigs on May 28&lt;/p&gt;Talos Snort Subscriber Rules Update&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;https://www.snort.org/advisories&quot;&gt;https://www.snort.org/advisories&lt;/a&gt;&lt;br&gt;</description>
  </item>
  <item>
    <title>Snort Subscriber Rules Update 2026-05-26</title>
    <link>https://seclists.org/snort/2026/q2/16</link>
    <description>&lt;p&gt;Posted by Research via Snort-sigs on May 26&lt;/p&gt;Talos Snort Subscriber Rules Update&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;https://www.snort.org/advisories&quot;&gt;https://www.snort.org/advisories&lt;/a&gt;&lt;br&gt;</description>
  </item>
  <item>
    <title>Snort Subscriber Rules Update 2026-05-21</title>
    <link>https://seclists.org/snort/2026/q2/15</link>
    <description>&lt;p&gt;Posted by Research via Snort-sigs on May 21&lt;/p&gt;Talos Snort Subscriber Rules Update&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;https://www.snort.org/advisories&quot;&gt;https://www.snort.org/advisories&lt;/a&gt;&lt;br&gt;</description>
  </item>
  <item>
    <title>Snort Subscriber Rules Update 2026-05-19</title>
    <link>https://seclists.org/snort/2026/q2/14</link>
    <description>&lt;p&gt;Posted by Research via Snort-sigs on May 19&lt;/p&gt;Talos Snort Subscriber Rules Update&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;https://www.snort.org/advisories&quot;&gt;https://www.snort.org/advisories&lt;/a&gt;&lt;br&gt;</description>
  </item>
  <item>
    <title>Snort Subscriber Rules Update 2026-05-14</title>
    <link>https://seclists.org/snort/2026/q2/13</link>
    <description>&lt;p&gt;Posted by Research via Snort-sigs on May 14&lt;/p&gt;Talos Snort Subscriber Rules Update&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;https://www.snort.org/advisories&quot;&gt;https://www.snort.org/advisories&lt;/a&gt;&lt;br&gt;</description>
  </item>
  <item>
    <title>Snort Subscriber Rules Update 2026-05-12</title>
    <link>https://seclists.org/snort/2026/q2/12</link>
    <description>&lt;p&gt;Posted by Research via Snort-sigs on May 12&lt;/p&gt;Talos Snort Subscriber Rules Update&lt;br&gt;
Snort 2: GID 1, SIDs 66438 through...&lt;br&gt;</description>
  </item>
  <item>
    <title>Sharing my Stack Overflow Blog article on SnortML and agentic AI</title>
    <link>https://seclists.org/snort/2026/q2/11</link>
    <description>&lt;p&gt;Posted by Samaresh Kumar Singh via Snort-sigs on May 12&lt;/p&gt;Hello Snort community,&lt;br&gt;
architecture. I tried to explore how AI can...&lt;br&gt;</description>
  </item>
  <item>
    <title>Snort Subscriber Rules Update 2026-05-07</title>
    <link>https://seclists.org/snort/2026/q2/10</link>
    <description>&lt;p&gt;Posted by Research via Snort-sigs on May 07&lt;/p&gt;Talos Snort Subscriber Rules Update&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;https://www.snort.org/advisories&quot;&gt;https://www.snort.org/advisories&lt;/a&gt;&lt;br&gt;</description>
  </item>
  <item>
    <title>Snort Subscriber Rules Update 2026-05-05</title>
    <link>https://seclists.org/snort/2026/q2/9</link>
    <description>&lt;p&gt;Posted by Research via Snort-sigs on May 05&lt;/p&gt;Talos Snort Subscriber Rules Update&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;https://www.snort.org/advisories&quot;&gt;https://www.snort.org/advisories&lt;/a&gt;&lt;br&gt;</description>
  </item>
  <item>
    <title>Snort Subscriber Rules Update 2026-04-30</title>
    <link>https://seclists.org/snort/2026/q2/8</link>
    <description>&lt;p&gt;Posted by Research via Snort-sigs on Apr 30&lt;/p&gt;Talos Snort Subscriber Rules Update&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;https://www.snort.org/advisories&quot;&gt;https://www.snort.org/advisories&lt;/a&gt;&lt;br&gt;</description>
  </item>
  <item>
    <title>Snort Subscriber Rules Update 2026-04-28</title>
    <link>https://seclists.org/snort/2026/q2/7</link>
    <description>&lt;p&gt;Posted by Research via Snort-sigs on Apr 28&lt;/p&gt;Talos Snort Subscriber Rules Update&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;https://www.snort.org/advisories&quot;&gt;https://www.snort.org/advisories&lt;/a&gt;&lt;br&gt;</description>
  </item>
  <item>
    <title>Snort Subscriber Rules Update 2026-04-23</title>
    <link>https://seclists.org/snort/2026/q2/6</link>
    <description>&lt;p&gt;Posted by Research via Snort-sigs on Apr 23&lt;/p&gt;Talos Snort Subscriber Rules Update&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;https://www.snort.org/advisories&quot;&gt;https://www.snort.org/advisories&lt;/a&gt;&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>VulnWatch</title>
    <link>https://seclists.org/#vulnwatch</link>
    <description>A non-discussion, non-patch, all-vulnerability annoucement list supported and run by a community of volunteer moderators distributed around the world.</description>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Web App Security</title>
    <link>https://seclists.org/#webappsec</link>
    <description>Provides insights on the unique challenges which make web applications notoriously hard to secure, as well as attack methods including SQL injection, cross-site scripting (XSS), cross-site request forgery, and more.</description>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Wireshark</title>
    <link>https://seclists.org/#wireshark</link>
    <description>Discussion of the free and open source &lt;a href=&quot;http://www.wireshark.org/&quot;&gt;Wireshark&lt;/a&gt; network sniffer.  No other sniffer (commercial or otherwise) comes close. This archive combines the Wireshark announcement, users, and developers mailing lists.</description>
</channel>
</rss>
</BODY>
