Summary
According to a Microsoft blog and other reputable sources, an unpatched zero-day vulnerability exists in multiple Windows and Office products that has been exploited in a phishing campaign targeting NATO.
Threat Type
Vulnerability
Overview
-Update #01 - 07/13/2023
IOC's added.
-Original Post-
Microsoft has published a blog detailing their investigation into the exploitation of a zero-day vulnerability in their products. According to the investigation, an attacker exploiting this flaw with a “high-c
Google Docs is a popular word processing tool that is used by millions of people around the world. Recently Google added new AI features to Docs (and a couple of other products), such as the ability to generate summaries, and write different kinds of creative content.
Check out Google Labs for more info.
These features can be very helpful, but they also introduce new security risks.
At the moment there are not too many degress of freedom an adversary has, but operating your AI on untrusted data can have unwanted consequences:
Summary
***UPDATED OVERVIEW with PoC and CVSS Score***
Progress, the vendor that provides MOVEit, has released a fix for additional vulnerabilities in their product, once of which being a critical SQL injection flaw.
Threat Type
Vulnerability
Overview
***UPDATE #1, July 11, 2023***
A proof-of-concept (PoC) has been reported for MOVEit's CVE-2023-36934. At this time, there is no further information on the PoC. In addition to the above, the vulnerability has been assessed and now carries a CVSSv3 score 9.1, c