#pentesttools

2026-01-12

Most auditors hate raw scanner noise as much as you hate jumping through hoops trying to explain it. Why? Because a scan ≠ a pass. ⬇️

If you spend more time reformatting 200-page PDFs than reducing risk, you’re stuck in a loop that burns into your team’s energy.

Here are 3 ways we reduce compliance noise:

✅ Capture irrefutable proof 👉 get screenshots, request/response traces, and more to prove a vulnerability exists and matters.

✅ Show continuous progress 👉 replace static snapshots with scheduled scans and vulnerability diffing to demonstrate effective remediation over time.

✅ Sync findings directly 👉 push validated data straight into Jira, Vanta, or Nucleus (or others) to eliminate manual reformatting and status drift.

Read the full white paper here: pentest-tools.com/usage/Compli

For more context and examples: pentest-tools.com/usage/compli

#compliance #offensivesecurity #infosec #pentesttools

Compliance White Paper - Pentest-Tools.com
2026-01-09

Our researchers at Pentest-Tools.com just found a new RCE in cPanel (CVE-2025-63261). 🔧

We discovered that a classic Unsafe Perl Open in AWStats allows command execution. The application fails to sanitize input before the open() call, so a well-placed pipe | character tricks the system into spawning a shell instead of reading a file.

This exploit requires zero actual plumbing. 🪠

Read Part 1 of the technical breakdown by Matei Badanoiu: pentest-tools.com/blog/cpanel-

#infosec #cybersecurity #cPanel #RCE #vulnerability #PentestTools

New CVE-2025-63261 discovered by Pentest-Tools.com
2026-01-05

The holidays are over. The vulnerabilities aren't.

It’s January 5th. Back at the desk. Is your perimeter the same as you left it?

Instead of digging through a backlog of unverified alerts, use Vulnerability Monitoring to establish a clean baseline for 2026.

Configure the Network Scanner for recurring scans. It compares results against the previous state and notifies you only on differences:

New open ports

Changed service versions

Regressions in patched vulnerabilities

Get a clean difference report, not a list of repetitive findings. Start the year with clarity.

pentest-tools.com/network-vuln

#InfoSec #SysAdmin #VulnerabilityManagement #BlueTeam #PentestTools

Network Vulnerability Scanner - Pentest-Tools.com

And it begins, again. AI driven "pentesting platform". I'm just ... I'm just not sure.

securityweek.com/tenzai-raises

#pentesttools #genai

All in one application security test tool? Methinks this has been tried in the past once or twice.

darknet.org.uk/2025/10/reaper-

#appsec #pentesttools

Might be useful for the ever present (these days) scope creep from "yeah and take a look at our AI chat bot"!

darknet.org.uk/2025/09/llamato

#ai #pentesttools

2025-02-20

Is it just me or is every demo/overview of the #FlipperZero extremely unimpressive (especially those for a mainstream audience).

I regretfully watched one such video earlier and one of the features highlighted was the ability to copy TV remote signals :blobcatgoogly2: ...I get it was aimed at a non-technical audience but I literally had a watch that could do that when I was a kid and to this day grandparents around the world have universal remotes with this capability...

So I want to put it out there to the #infosec community - where are the cool flipper zero #projects? And I don't mean installing #DOOM or some other quirky play thing. I want to see legit #RF #hacking, or at least using the #GPIO!
#askfedi #askinfosec #rfhacking #pentesttools #hackingtools

acrypthash👨🏻‍💻acrypthash@infosec.exchange
2024-01-02
The Hacker‘s Choicethc@infosec.exchange
2023-06-12

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst