Attackers Exploit Microsoft Teams and AnyDesk to Deploy DarkGate Malware
https://ift.tt/MZ8R0f1
Submitted December 18, 2024 at 04:13AM by Glad_Ad534
via reddit https://ift.tt/jDsKR9b
https://ift.tt/MZ8R0f1
Submitted December 18, 2024 at 04:13AM by Glad_Ad534
via reddit https://ift.tt/jDsKR9b
Authentication Bypass Vulnerability in Philips IntelliSpace Cardiovascular
https://ift.tt/OUtD0QH
Submitted December 18, 2024 at 08:37AM by panicnot42
via reddit https://ift.tt/rCPZtlD
https://ift.tt/OUtD0QH
Submitted December 18, 2024 at 08:37AM by panicnot42
via reddit https://ift.tt/rCPZtlD
Understanding Logits And Their Possible Impacts On Large Language Model Output Safety
https://ift.tt/qs59VTv
Submitted December 19, 2024 at 01:24AM by 0xRaindrop
via reddit https://ift.tt/t9GvjlI
https://ift.tt/qs59VTv
Submitted December 19, 2024 at 01:24AM by 0xRaindrop
via reddit https://ift.tt/t9GvjlI
HubPhish Exploits HubSpot Tools to Target 20,000 European Users for Credential Theft
https://ift.tt/1U5XDyF
Submitted December 19, 2024 at 02:36AM by Glad_Ad534
via reddit https://ift.tt/DIbXK61
https://ift.tt/1U5XDyF
Submitted December 19, 2024 at 02:36AM by Glad_Ad534
via reddit https://ift.tt/DIbXK61
APT29 Hackers Target High-Value Victims Using Rogue RDP Servers and PyRDP
https://ift.tt/q1pL3se
Submitted December 19, 2024 at 03:30AM by Glad_Ad534
via reddit https://ift.tt/7Ifsodn
https://ift.tt/q1pL3se
Submitted December 19, 2024 at 03:30AM by Glad_Ad534
via reddit https://ift.tt/7Ifsodn
How an obscure PHP footgun led to RCE in Craft CMS
https://ift.tt/H1R64CV
Submitted December 19, 2024 at 07:53AM by Mempodipper
via reddit https://ift.tt/PwATV6t
https://ift.tt/H1R64CV
Submitted December 19, 2024 at 07:53AM by Mempodipper
via reddit https://ift.tt/PwATV6t
www.assetnote.io
How an obscure PHP footgun led to RCE in Craft CMS
Craft CMS is one of the most popular PHP-based CMSes globally, boasting over 150,000 sites worldwide. This blog post details a pre-authentication RCE vulnerability affecting Craft CMS versions below 4.13.1 and 5.5.1.
Exploiting reflected input via the Range header
https://ift.tt/fTMAu97
Submitted December 19, 2024 at 03:12PM by 6W99ocQnb8Zy17
via reddit https://ift.tt/zW3hJxN
https://ift.tt/fTMAu97
Submitted December 19, 2024 at 03:12PM by 6W99ocQnb8Zy17
via reddit https://ift.tt/zW3hJxN
attackshipsonfi.re
Exploiting Reflected Input Via the Range Header
TL;DR Reflected input is often unexploitable because the attack ends up in a place which stops it working, such as inside a quoted attribute.
I'm Lovin' It: Exploiting McDonald's APIs to hijack deliveries and order food for a penny
https://ift.tt/ncFhMLJ
Submitted December 19, 2024 at 06:42PM by EatonZ
via reddit https://ift.tt/BdJjEUC
https://ift.tt/ncFhMLJ
Submitted December 19, 2024 at 06:42PM by EatonZ
via reddit https://ift.tt/BdJjEUC
Eaton-Works
I’m Lovin’ It: Exploiting McDonald’s APIs to hijack deliveries and order food for a penny
A series of API flaws in McDelivery India made it possible to order food for a penny, hijack other people’s delivery orders, view user information, and more.
New Windows Privilege Escalation Vulnerability!
https://ift.tt/Mv8Xho7
Submitted December 19, 2024 at 10:02PM by SSDisclosure
via reddit https://ift.tt/K0PA2W3
https://ift.tt/Mv8Xho7
Submitted December 19, 2024 at 10:02PM by SSDisclosure
via reddit https://ift.tt/K0PA2W3
SSD Secure Disclosure
SSD Advisory - cldflt Heap-based Overflow (PE) - SSD Secure Disclosure
Summary A vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. To exploit this vulnerability, an attacker must first obtain the ability to execute low-privileged code on the target system. The specific…
CISA Mandates Cloud Security for Federal Agencies by 2025 Under Binding Directive 25-01
https://ift.tt/z0HhKk1
Submitted December 20, 2024 at 03:19AM by Glad_Ad534
via reddit https://ift.tt/Vc0Y87n
https://ift.tt/z0HhKk1
Submitted December 20, 2024 at 03:19AM by Glad_Ad534
via reddit https://ift.tt/Vc0Y87n
techacademy.online
CISA Mandates Cloud Security for Federal Agencies by 2025 Under Binding Directive 25-01
CISA's new directive mandates federal agencies secure cloud environments by 2025, introducing SCuBA tools for monitoring and reducing cyberattack surf
Fortinet Warns of Critical FortiWLM Flaw That Could Lead to Admin Access Exploits
https://ift.tt/kgKLXiC
Submitted December 20, 2024 at 02:58AM by Glad_Ad534
via reddit https://ift.tt/5YOurn7
https://ift.tt/kgKLXiC
Submitted December 20, 2024 at 02:58AM by Glad_Ad534
via reddit https://ift.tt/5YOurn7
techacademy.online
Fortinet Warns of Critical FortiWLM Flaw That Could Lead to Admin Access Exploits
Fortinet patches critical flaws in FortiWLM and FortiManager. CVE-2023-34990 risks sensitive data, while CVE-2024-48889 enables command injection.
CVE-2024-44825 - Invesalius Arbitrary File Write and Directory Traversal
https://ift.tt/71fMsRc
Submitted December 20, 2024 at 03:17PM by AlbatrossMaximum4489
via reddit https://ift.tt/Qu7Hfxa
https://ift.tt/71fMsRc
Submitted December 20, 2024 at 03:17PM by AlbatrossMaximum4489
via reddit https://ift.tt/Qu7Hfxa
🌟 TOP 5 AI and Security Predictions for 2025
https://ift.tt/P2lb4Vt
Submitted December 20, 2024 at 10:33PM by mymalema
via reddit https://ift.tt/rsOwnQh
https://ift.tt/P2lb4Vt
Submitted December 20, 2024 at 10:33PM by mymalema
via reddit https://ift.tt/rsOwnQh
Medium
🚀 TOP 5 AI and Cybersecurity Predictions for 2025
Join the AI Security group at https://www.linkedin.com/groups/14545517 for more similar content.
Another JWT Algorithm Confusion Vulnerability: CVE-2024-54150
https://ift.tt/5IxoX7T
Submitted December 21, 2024 at 01:21PM by ffyns
via reddit https://ift.tt/qcd0Xv1
https://ift.tt/5IxoX7T
Submitted December 21, 2024 at 01:21PM by ffyns
via reddit https://ift.tt/qcd0Xv1
Pentesterlab
Another JWT Algorithm Confusion Vulnerability: CVE-2024-54150
Discover how a code review uncovered a JWT algorithm confusion vulnerability (CVE-2024-54150). Learn key insights to enhance your security skills and spot vulnerabilities effectively.
Security Implications of Catastrophic AI Risks
https://ift.tt/vpcouxw
Submitted December 22, 2024 at 03:34AM by mymalema
via reddit https://ift.tt/VTpwfxu
https://ift.tt/vpcouxw
Submitted December 22, 2024 at 03:34AM by mymalema
via reddit https://ift.tt/VTpwfxu
Medium
🔍 Cybersecurity Implications of Catastrophic AI Risks
The paper “An Overview of Catastrophic AI Risks” by the Center for AI Safety delves into how advanced AI systems introduce critical cybersecurity challenges. (Join the AI Security group at…
Incident Response for Generative AI Workloads: A Structured Approach by AWS
https://ift.tt/Ie6QVCk
Submitted December 22, 2024 at 08:35AM by mymalema
via reddit https://ift.tt/ST4Z6px
https://ift.tt/Ie6QVCk
Submitted December 22, 2024 at 08:35AM by mymalema
via reddit https://ift.tt/ST4Z6px
Medium
🔐 Incident Response for Generative AI Workloads: A Structured Approach by AWS
Amazon Web Services (AWS) outlines a structured approach for incident response in Generative AI workloads, emphasizing both response…
Modular Linux Backdoor IOCONTROL Hits OT, SCADA, IoT
https://ift.tt/DBxFq8y
Submitted December 23, 2024 at 07:52PM by derp6996
via reddit https://ift.tt/0VqvI8h
https://ift.tt/DBxFq8y
Submitted December 23, 2024 at 07:52PM by derp6996
via reddit https://ift.tt/0VqvI8h
Claroty
Inside a New OT/IoT Cyberweapon: IOCONTROL
Team82 has researched a malware sample called IOCONTROL linked to an Iran-based attack group used to target IoT and OT civilian infrastructure in the U.S. and Israel.
Agentic AI security podcast episode
https://ift.tt/EQ3H5jI
Submitted December 24, 2024 at 01:07PM by fcanogab
via reddit https://ift.tt/xSlV5Ek
https://ift.tt/EQ3H5jI
Submitted December 24, 2024 at 01:07PM by fcanogab
via reddit https://ift.tt/xSlV5Ek
Spotify for Creators
Agentic AI Security by Mind the Machine
In this episode of Mind the Machine, host Florencio Cano talks about the concept of agentic AI, exploring what makes AI systems capable of autonomously performing tasks and the unique security challenges they present.
While agentic AI can revolutionize industries…
While agentic AI can revolutionize industries…
Scraping By: My YouTube Data Adventure
https://ift.tt/eBYXhzv
Submitted December 25, 2024 at 12:53AM by nv1t
via reddit https://ift.tt/zBOfU89
https://ift.tt/eBYXhzv
Submitted December 25, 2024 at 12:53AM by nv1t
via reddit https://ift.tt/zBOfU89
Blog
Scraping By: My YouTube Data Adventure
A while ago, I reached out to Mats, the creator behind the YouTube channel Topfvollgold, offering my help with data scraping. I thought it might be useful for his projects and mentioned that I’d be happy to assist if the need ever arose.
Recently, Mats reached…
Recently, Mats reached…
Non-Intrusive Web Recon: Techniques from Chrome DevTools Recorder
https://ift.tt/RNvYwbD
Submitted December 25, 2024 at 09:42PM by toyojuni
via reddit https://ift.tt/YGuMf89
https://ift.tt/RNvYwbD
Submitted December 25, 2024 at 09:42PM by toyojuni
via reddit https://ift.tt/YGuMf89
GMO Flatt Security Research
Non-Intrusive Web Recon: Techniques from Chrome DevTools Recorder
Introduction: The Art of Non-Intrusive Web Recon
Hello, I’m pizzacat83 (@pizzacat83
), a software engineer at Flatt Security Inc.
When hunting for bugs, understanding the behavior of a target application is invaluable. The more knowledge you gain about the…
Hello, I’m pizzacat83 (@pizzacat83
), a software engineer at Flatt Security Inc.
When hunting for bugs, understanding the behavior of a target application is invaluable. The more knowledge you gain about the…
Looking For reputable Gateway which accepts Portuguese prepaid 5G SIM cards and can run open source
https://ift.tt/f41BSgd
Submitted December 27, 2024 at 03:34PM by JMLenterprise
via reddit https://ift.tt/8WvTgne
https://ift.tt/f41BSgd
Submitted December 27, 2024 at 03:34PM by JMLenterprise
via reddit https://ift.tt/8WvTgne
Teltonika-Networks
TRB500 5G Gateway
TRB500 is a compact, energy-efficient Teltonika Networks 5G gateway with speeds of up to 1 Gbps and backward compatibility. Click here to learn more.