Aggregator
Unbounded AI use can break your systems
In this Help Net Security video, James Wickett, CEO of DryRun Security, explains cyber risks many teams underestimate as they add AI to products. He focuses on how fast LLM features are pushed into live applications without limits or guardrails. The video also looks at AI-generated code and why it should not be trusted by default, especially for business logic and access control. Wickett closes by warning about blurred trust boundaries when AI systems can … More →
The post Unbounded AI use can break your systems appeared first on Help Net Security.
ZDI-CAN-28675: Ashlar-Vellum
ZDI-CAN-28327: QNAP
ZDI-CAN-28834: Netdata
ZDI-CAN-28759: Siemens
ZDI-CAN-27843: Delta Electronics
JVN: 複数のPioneer製品のインストーラーにおけるDLL読み込みに関する脆弱性
Automated FortiGate Attacks Exploit FortiCloud SSO to Alter Firewall Configurations
CVE-2026-23499 | Saleor up to 3.20.107/3.21.42/3.22.26 SVG File cross site scripting (GHSA-666h-2p49-pg95 / EUVD-2026-3775)
Пароль на скотче и Face ID силой. В Иордании научились доставать из смартфонов вообще все (даже то, что вы удалили)
Даже робот-пылесос сможет дать против вас показания. Ирландия хочет легализовать доступ к устройствам интернета вещей
[AI Coding+安全] 二.CodeBuddy赋能恶意代码分析与家族分类实践(肝货)
CVE-2023-39001 | OPNsense up to 23.6 Backup Configuration File diag_backup.php command injection (EUVD-2023-42758)
CVE-2023-39003 | OPNsense up to 23.6 /tmp permission (EUVD-2023-42760)
CVE-2023-39000 | OPNsense up to 23.6 URL core cross site scripting (EUVD-2023-42757)
CVE-2023-38999 | OPNsense up to 23.6 System Halt API /system/halt cross-site request forgery (EUVD-2023-42756)
CVE-2023-38998 | OPNsense up to 23.6 Login Page redirect (EUVD-2023-42755)
Sitting Ducks: разбираемся в уязвимости, которая позволяет хакерам (и не только им) захватывать чужие домены
The internet’s oldest trust mechanism is still one of its weakest links
Attackers continue to rely on domain names as an entry point into enterprise systems. A CSC domain security study finds that large organizations leave this part of their attack surface underprotected, even as attacks become more frequent. The research examined the Forbes Global 2000 and compared them with the world’s top 100 privately held unicorn companies. Domain security adoption: 100 unicorns vs Global 2000 (Source: CSC) Domains sit outside standard security controls Domains operate outside … More →
The post The internet’s oldest trust mechanism is still one of its weakest links appeared first on Help Net Security.