Exploiting HuggingFace’s Assistants to Extract Users’ Data
https://ift.tt/7fgGU8K
Submitted August 17, 2024 at 07:47PM by oweillnet
via reddit https://ift.tt/6ZqF8JW
https://ift.tt/7fgGU8K
Submitted August 17, 2024 at 07:47PM by oweillnet
via reddit https://ift.tt/6ZqF8JW
www.lasso.security
Exploiting HuggingFace’s Assistants to Extract Users’ Data
Explore the resilience of the new Hugging Chat Assistance to Sleepy Agent and Image Markdown Rendering vulnerabilities.
CVE-2024-7646: Ingress-NGINX Annotation Validation Bypass
https://ift.tt/XqoIifz
Submitted August 18, 2024 at 09:09PM by oshratn
via reddit https://ift.tt/fDTov1p
https://ift.tt/XqoIifz
Submitted August 18, 2024 at 09:09PM by oshratn
via reddit https://ift.tt/fDTov1p
ARMO
CVE-2024-7646: Ingress-NGINX Annotation Validation Bypass
Learn how CVE-2024-7646 allows attackers to bypass ingress-nginx validation and compromise Kubernetes clusters, and how to secure your systems
Phrack 71 released
https://ift.tt/7MKpqGu
Submitted August 20, 2024 at 02:24AM by guitmz
via reddit https://ift.tt/r29A1jT
https://ift.tt/7MKpqGu
Submitted August 20, 2024 at 02:24AM by guitmz
via reddit https://ift.tt/r29A1jT
phrack.org
.:: Phrack Magazine ::.
Phrack staff website.
Columbus ransomware attack: What’s still unknown one month after the data breach
https://ift.tt/dS5OpWz
Submitted August 20, 2024 at 02:43PM by zolakrystie
via reddit https://ift.tt/jZpsMc9
https://ift.tt/dS5OpWz
Submitted August 20, 2024 at 02:43PM by zolakrystie
via reddit https://ift.tt/jZpsMc9
The Columbus Dispatch
Columbus ransomware attack: What’s still unknown one month after the data breach
Mayor Andrew J. Ginther and other city officials have carried out a \
Web Browser Stored Credentials
https://ift.tt/Zv5hreV
Submitted August 20, 2024 at 07:09PM by netbiosX
via reddit https://ift.tt/B6denkj
https://ift.tt/Zv5hreV
Submitted August 20, 2024 at 07:09PM by netbiosX
via reddit https://ift.tt/B6denkj
Penetration Testing Lab
Web Browser Stored Credentials
Microsoft introduced Data Protection Application Programming Interface (DPAPI) in Windows environments as a method to encrypt and decrypt sensitive data such as credentials using the CryptProtectDa…
SSRFing the Web with the help of Copilot Studio (Critical Vuln in Microsoft Copilot Studio)
https://ift.tt/45VBU9N
Submitted August 20, 2024 at 06:43PM by dinobyt3s
via reddit https://ift.tt/oTWmrbG
https://ift.tt/45VBU9N
Submitted August 20, 2024 at 06:43PM by dinobyt3s
via reddit https://ift.tt/oTWmrbG
Tenable®
SSRFing the Web with the Help of Copilot Studio
Tenable Research discovered a critical information-disclosure vulnerability in Microsoft’s Copilot Studio via a server-side request forgery (SSRF), which allowed researchers access to potentially sensitive information regarding service internals with potential…
Protecting Your User’s Data from AI Training Crawlers | Permit
https://ift.tt/0GymEpV
Submitted August 20, 2024 at 10:18PM by Permit_io
via reddit https://ift.tt/C35ZDBb
https://ift.tt/0GymEpV
Submitted August 20, 2024 at 10:18PM by Permit_io
via reddit https://ift.tt/C35ZDBb
www.permit.io
Protecting Your Users' Data from AI Training Crawlers
Learn how to protect user data from AI crawlers with Fine-Grained Authorization (FGA) by Identifying bots, classifying data, and empowering users with control.
Hacking as a pathway to building better Products
https://ift.tt/GbphVPx
Submitted August 20, 2024 at 10:29PM by thinkst
via reddit https://ift.tt/JjYk5fS
https://ift.tt/GbphVPx
Submitted August 20, 2024 at 10:29PM by thinkst
via reddit https://ift.tt/JjYk5fS
Thinkst Thoughts
Hacking as a pathway to building better Products
Most security products are terrible. For years our industry has managed to get by because our products were mandated by someone or some regulation, and users were trained to accept that security an…
Passive decryption of 2G communications, GSM and GPRS impacted
https://ift.tt/aEVvdg9
Submitted August 20, 2024 at 05:40PM by Pure-Benefit-3593
via reddit https://ift.tt/imdJQy8
https://ift.tt/aEVvdg9
Submitted August 20, 2024 at 05:40PM by Pure-Benefit-3593
via reddit https://ift.tt/imdJQy8
SpringerLink
Time-Memory Trade-Offs Sound the Death Knell for GPRS and
This paper introduces a practical TMTO-based attack against GSM (A5/3) and GPRS (GEA-3), which are both technologies used in 2G mobile networks. Although designed in the 80 s, these networks are still quite active today, especially for embedded systems. While...
Sploitify - GTFOBins-like tool for exploits
https://ift.tt/yKwM7AB
Submitted August 19, 2024 at 04:39PM by haxxm0nkey
via reddit https://ift.tt/wE7YJ9V
https://ift.tt/yKwM7AB
Submitted August 19, 2024 at 04:39PM by haxxm0nkey
via reddit https://ift.tt/wE7YJ9V
Realizing Continuous Threat Exposure Management (CTEM) automatically. Security is not about remediating every issue and risk but rather focusing on those that are more likely to be exploited against the organization and bear more impact. The article explores how can this be implemented.
https://ift.tt/xXLmgp6
Submitted August 21, 2024 at 03:58PM by PutApart5987
via reddit https://ift.tt/QFnGNEx
https://ift.tt/xXLmgp6
Submitted August 21, 2024 at 03:58PM by PutApart5987
via reddit https://ift.tt/QFnGNEx
Securityscouter
Realizing Automated Continuous Threat Exposure Management
Following the new coined CTEM term, vendors have started appropriating the use-case to their offering. Exploring solutions and naming a new emerging market.
Call For Papers - Hackfest 2024 - Quebec City, Canada
https://ift.tt/L6ygEOT
Submitted August 21, 2024 at 07:56PM by pathetiq
via reddit https://ift.tt/Ld5kP8K
https://ift.tt/L6ygEOT
Submitted August 21, 2024 at 07:56PM by pathetiq
via reddit https://ift.tt/Ld5kP8K
cfp.hackfest.ca
Hackfest 2024 - 16-bit Edition
Schedule, talks and talk submissions for Hackfest 2024 - 16-bit Edition
BLUUID: Firewallas, Diabetics, And… Bluetooth
https://ift.tt/bjV01Km
Submitted August 22, 2024 at 04:15AM by netsecfriends
via reddit https://ift.tt/5p2uglU
https://ift.tt/bjV01Km
Submitted August 22, 2024 at 04:15AM by netsecfriends
via reddit https://ift.tt/5p2uglU
GreyNoise Labs
GreyNoise Labs - BLUUID: Firewallas, Diabetics, And… Bluetooth
Where I introduce the subject of remotely identifying bluetooth devices, propose that healthcare device oversight is lacking, and exploit a firewall for no reason other than to prove a point.
Best MFA Tools for 2024: Top Picks for Stronger Security
https://ift.tt/ZCSue2f
Submitted August 22, 2024 at 01:27PM by Kapildev_Arulmozhi
via reddit https://ift.tt/zwYlkFJ
https://ift.tt/ZCSue2f
Submitted August 22, 2024 at 01:27PM by Kapildev_Arulmozhi
via reddit https://ift.tt/zwYlkFJ
www.infisign.ai
9 Best Multi-Factor Authentication (MFA) Software in 2024
In today's increasingly digital world, where cyber threats lurk around every corner, securing your online accounts is more important than ever. While passwords remain a cornerstone of security, they're no longer enough. This is where Multi-Factor Authentication…
Gotta cache 'em all: bending the rules of web cache exploitation
https://ift.tt/SNnop8A
Submitted August 22, 2024 at 05:16PM by albinowax
via reddit https://ift.tt/0Rw25Xf
https://ift.tt/SNnop8A
Submitted August 22, 2024 at 05:16PM by albinowax
via reddit https://ift.tt/0Rw25Xf
PortSwigger Research
Gotta cache 'em all: bending the rules of web cache exploitation
Through the years, we have seen many attacks exploiting web caches to hijack sensitive information or store malicious payloads. However, as CDNs became more popular, new discrepancies between propriet
Details about CVE-2024-22263: Spring Cloud Dataflow Arbitrary File Writing
https://ift.tt/qN86fQ9
Submitted August 22, 2024 at 07:56PM by SL7reach
via reddit https://ift.tt/D1fuaQJ
https://ift.tt/qN86fQ9
Submitted August 22, 2024 at 07:56PM by SL7reach
via reddit https://ift.tt/D1fuaQJ
SecureLayer7 - Offensive Security, API Scanner & Attack Surface Management
CVE-2024-22263: Spring Cloud Dataflow Arbitrary File Writing
Introduction Spring Cloud Data Flow, a microservices-based platform for streaming and batch data processing in Cloud Foundry and Kubernetes, is vulnerable to an arbitrary file write issue. The...
Apps falsos ameaçam dados bancários
https://ift.tt/MQaDknr
Submitted August 23, 2024 at 12:03AM by Securityboy09
via reddit https://ift.tt/nI1ACSF
https://ift.tt/MQaDknr
Submitted August 23, 2024 at 12:03AM by Securityboy09
via reddit https://ift.tt/nI1ACSF
Caveiratech
Apps falsos ameaçam dados bancários | CaveiraTech
Apps falsos ameaçam dados bancários: Cibercriminosos estão utilizando Progressive Web Applications (PWAs) para imitar aplicativos de bancos e roubar credenciais de usuários Android e iOS. Empregando táticas como chamadas automatizadas e malvertising, essas…
Splitting the email atom: exploiting parsers to bypass access controls
https://ift.tt/NGJQckp
Submitted August 23, 2024 at 12:20PM by garethheyes
via reddit https://ift.tt/AW5QJkX
https://ift.tt/NGJQckp
Submitted August 23, 2024 at 12:20PM by garethheyes
via reddit https://ift.tt/AW5QJkX
PortSwigger Research
Splitting the email atom: exploiting parsers to bypass access controls
Some websites parse email addresses to extract the domain and infer which organisation the owner belongs to. This pattern makes email-address parser discrepancies critical. Predicting which domain an
GIAC Unoffical | Facebook
https://ift.tt/ldSWumN
Submitted August 23, 2024 at 01:15PM by LibrarianNext5732
via reddit https://ift.tt/D0xvRCw
https://ift.tt/ldSWumN
Submitted August 23, 2024 at 01:15PM by LibrarianNext5732
via reddit https://ift.tt/D0xvRCw
Facebook
Log in or sign up to view
See posts, photos and more on Facebook.
NTLM Credential Theft in Python Windows Applications – Horizon3.ai
https://ift.tt/9JlxTt0
Submitted August 23, 2024 at 07:23PM by scopedsecurity
via reddit https://ift.tt/5e8q6ZC
https://ift.tt/9JlxTt0
Submitted August 23, 2024 at 07:23PM by scopedsecurity
via reddit https://ift.tt/5e8q6ZC
Horizon3.ai
NTLM Credential Theft in Python Windows Applications
NTLM credential theft vulnerabilities in Python Windows applications: Jupyter Notebook CVE-2024-35178, Streamlit from Snowflake CVE-2024-42474 and Hugging Face Gradio CVE-2024-34510
How 1 Exposed Honeywell API Gave us Control Over an Internal Engineering System
https://ift.tt/ebHsku3
Submitted August 23, 2024 at 09:09PM by EatonZ
via reddit https://ift.tt/NX8oi4H
https://ift.tt/ebHsku3
Submitted August 23, 2024 at 09:09PM by EatonZ
via reddit https://ift.tt/NX8oi4H
www.traceable.ai
Traceable - Blog: How 1 Exposed Honeywell API Gave us Control Over an Internal Engineering System
APIs are essential for modern web applications, but they also introduce significant security challenges. Even large enterprises can fall prey to simple API vulnerabilities, as demonstrated by Traceable's discovery of a critical security flaw in Honeywell’s…