Aggregator
从Naptime到Big Sleep:通过大语言模型捕获真实代码中的漏洞
1 year 8 months ago
模糊测试并未发现这一漏洞
City of Columbus Drops Case on Cyberattack Whistleblower
1 year 8 months ago
The security researcher who notified the media of the breach will be free from the city's lawsuit, but not without a caveat.
Kristina Beek, Associate Editor, Dark Reading
分享一个“细思极恐”的提示词
1 year 8 months ago
A Threat Actor Has Allegedly Leaked Employee Data of Balcia Insurance SE
1 year 8 months ago
A Threat Actor Has Allegedly Leaked Employee Data of Balcia Insurance SE
Dark Web Informer
CVE-2024-48463 | Bruno up to 1.29.0 electron shell.openExternal Privilege Escalation
1 year 8 months ago
A vulnerability classified as problematic was found in Bruno up to 1.29.0. Affected by this vulnerability is the function shell.openExternal of the component electron. The manipulation leads to Privilege Escalation.
This vulnerability is known as CVE-2024-48463. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45086 | IBM WebSphere Application Server 8.5/9.0 xml external entity reference
1 year 8 months ago
A vulnerability classified as problematic has been found in IBM WebSphere Application Server 8.5/9.0. Affected is an unknown function. The manipulation leads to xml external entity reference.
This vulnerability is traded as CVE-2024-45086. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45185 | Samsung Mobile Processor/Wearable Processor/Modem Exynos GPRS Protocol out-of-bounds write
1 year 8 months ago
A vulnerability was found in Samsung Mobile Processor, Wearable Processor and Modem Exynos. It has been rated as critical. This issue affects some unknown processing of the component GPRS Protocol Handler. The manipulation leads to out-of-bounds write.
The identification of this vulnerability is CVE-2024-45185. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-30617 | Chamilo LMS 1.11.26 /main/social/home.php cross-site request forgery
1 year 8 months ago
A vulnerability was found in Chamilo LMS 1.11.26. It has been declared as problematic. This vulnerability affects unknown code of the file /main/social/home.php. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2024-30617. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-30619 | Chamilo LMS 1.11.26 message.ajax.php?a=get_count_message information disclosure
1 year 8 months ago
A vulnerability was found in Chamilo LMS 1.11.26. It has been classified as problematic. This affects an unknown part of the file /main/inc/ajax/message.ajax.php?a=get_count_message. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-30619. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
Okta Fixes Auth Bypass Bug After 3-Month Lull
1 year 8 months ago
The bug affected accounts with 52-character user names, and had several pre-conditions that needed to be met in order to be exploited.
Dark Reading Staff
Moroccan Conquest Team Targeted the Website of U.S. Department of Energy and Legacy Management
1 year 8 months ago
Moroccan Conquest Team Targeted the Website of U.S. Department of Energy and Legacy Management
Dark Web Informer
HIMARS DDOS Targeted the Website of Umnye Seti
1 year 8 months ago
HIMARS DDOS Targeted the Website of Umnye Seti
Dark Web Informer
DocuSign's Envelopes API abused to send realistic fake invoices
1 year 8 months ago
Threat actors are abusing DocuSign's Envelopes API to create and mass-distribute fake invoices that appear genuine, impersonating well-known brands like Norton and PayPal. [...]
Bill Toulas
ShadowDefenders Targeted the Website of The Jewish voice
1 year 8 months ago
ShadowDefenders Targeted the Website of The Jewish voice
Dark Web Informer
SYLHET GANG-SG Defaced the Website of Saudi Journalists Association
1 year 8 months ago
SYLHET GANG-SG Defaced the Website of Saudi Journalists Association
Dark Web Informer
Antivirus, Anti-Malware Lead Demand for AI/ML Tools
1 year 8 months ago
Companies are attaching the artificial intelligence term to everything these days, but in cybersecurity, machine learning is more than hype.
Dark Reading Staff
MDR vs. MSSP: Making the Right Choice for Your Business
1 year 8 months ago
Understand the key differences between MDR and MSSP and choose the right cybersecurity service to protect your business.
The post MDR vs. MSSP: Making the Right Choice for Your Business appeared first on D3 Security.
The post MDR vs. MSSP: Making the Right Choice for Your Business appeared first on Security Boulevard.
Shriram Sharma
Police Doxing of Criminals Raising Ransomware-Attack Stakes
1 year 8 months ago
Incident Responders Say Disruptions Help, See No Spike in Median Ransom Payments
For anyone dreaming of law enforcement agencies arresting ransomware bigwigs, or intelligence agencies taking them out with drone strikes, keep on hoping. But here's good news: ransom payments haven't skyrocketed, as disruptions by law enforcement appear to be having an impact.
For anyone dreaming of law enforcement agencies arresting ransomware bigwigs, or intelligence agencies taking them out with drone strikes, keep on hoping. But here's good news: ransom payments haven't skyrocketed, as disruptions by law enforcement appear to be having an impact.
Bypassing ChatGPT Safety Guardrails, One Emoji at a Time
1 year 8 months ago
Mozilla Researcher Uses Non-Natural Language to Jailbreak GPT-4o
Anyone can jailbreak GPT-4o's security guardrails with hexadecimal encoding and emojis. A Mozilla researcher demonstrated the jailbreaking technique, tricking OpenAI's latest model into generating python exploits and malicious SQL injection tools.
Anyone can jailbreak GPT-4o's security guardrails with hexadecimal encoding and emojis. A Mozilla researcher demonstrated the jailbreaking technique, tricking OpenAI's latest model into generating python exploits and malicious SQL injection tools.