Aggregator
COFF文件解析 | CoffLdr
Data Exfiltration via Image Rendering Fixed in Amp Code
In this post we discuss a vulnerability that was present in Amp Code from Sourcegraph by which an attacker could exploit markdown driven image rendering to exfiltrate sensitive information.
This vulnerability is common in AI applications and agents, and it’s actually similar to one we discussed last year in GitHub Copilot which Microsoft fixed.
Exploit DemonstrationFor the proof-of-concept I use a pre-existing demo that created a longer time ago. It happened to just work with Amp as well. The prompt injection is hosted on a website which asks the AI to “backup” information to a third-party site by rendering an image and including previous chat data as a query parameter.
有关公众号的那些事
【安全圈】Cisco Secure Firewall 管理中心软件 RADIUS 远程代码执行漏洞
【安全圈】披露两次大规模数据泄露后,美电信巨头赔1.77亿美元和解
【安全圈】武汉网警侦破两起黑客案件
FFmpeg 迁移到 Forgejo
Hashcat 7.0.0 переписан почти с нуля: что изменилось в главном инструменте для взлома паролей
Nederland zet Chinooks in bij natuurbranden Spanje
ЦРУ 34 года хранило секрет Криптоса. Теперь художник Джим Санборн сказал: «Хватит». И решил продать разгадку.
CVE-2021-2146 | Oracle MySQL Server up to 5.7.33/8.0.23 Options denial of service (Nessus ID 250095)
CVE-2021-45100 | ksmbd up to 3.4.2 ksmbd Server cleartext transmission (Issue 550 / Nessus ID 250097)
CVE-2019-9821 | Mozilla Firefox up to 66.x Shared Worker use after free (Nessus ID 250099 / ID 371797)
CVE-2022-3577 | Linux Kernel Kid-friendly Wired Controller Driver hid-bigbenff.c bigben_probe memory leak (Nessus ID 250107)
CVE-2023-20051 | Cisco Packet Data Network Gateway Vector Packet Processor resource consumption (cisco-sa-cisco-pdng-dos-KmzwEy2Q / EUVD-2023-24230)
NSF and NVIDIA Partner to Enable Fully Open AI Models
The National Science Foundation announced a new partnership with NVIDIA this past week that will enable advances in scientific discovery through artificial intelligence.
The post NSF and NVIDIA Partner to Enable Fully Open AI Models appeared first on Security Boulevard.
aced: parse and resolve a single targeted Active Directory principal’s DACL
Aced Aced is a tool to parse and resolve a single targeted Active Directory principal’s DACL. Aced will identify interesting inbound access allowed privileges against the targeted account, resolve the SIDS of the inbound...
The post aced: parse and resolve a single targeted Active Directory principal’s DACL appeared first on Penetration Testing Tools.