Aggregator
CVE-2024-47575 | Fortinet FortiManager up to 7.6.0 Request FortiJump missing authentication (FG-IR-24-423)
ZombAIs: From Prompt Injection to C2 with Claude Computer Use
A few days ago, Anthropic released Claude Computer Use, which is a model + code that allows Claude to control a computer. It takes screenshots to make decisions, can run bash commands and so forth.
It’s cool, but obviously very dangerous because of prompt injection. Claude Computer Use enables AI to run commands on machines autonomously, posing severe risks if exploited via prompt injection.
DisclaimerSo, first a disclaimer: Claude Computer Use is a Beta Feature and what you are going to see is a fundamental design problem in state-of-the-art LLM-powered Applications and Agents. This is an educational demo to highlight risks of autonomous AI systems processing untrusted data. And remember, do not execute unauthorized code systems without authorization from proper stakeholders.
深入分析自己曾经挖掘到的有趣的XSS漏洞
CVE-2004-0312 | Linksys WAP55AG 1.0.7 information disclosure (EDB-23721 / XFDB-15257)
CVE-2016-10034 | Zend Framework up to 2.4.10/2.5.x/2.6.x/2.7.1 zend-mail setFrom command injection (EDB-40979 / Nessus ID 108931)
CVE-2013-1648 | Open-Xchange Server 6.20.7/6.22.0/6.22.1 Gopher input validation (EDB-24791 / ID 803182)
白泽ers Happy 1024 Day!程序员专属节日,代码改变世界!
CVE-2002-0686 | Iplanet Web Server 4.1 NS-rel-doc-name memory corruption (VU#612843 / XFDB-9506)
Unforeseen Risks to Medical Devices in Ransomware Attacks
Breach Roundup: CISA Proposes Security for Bulk Data Sales
This week, bulk data transfers to China, credit card theft, the Internet Archive still recovering and the Change Healthcare tally is now 100M. Ukraine fought phishers, civil society against the UN cybercrime treaty, TA866 and virtual hard drives spread malware. Google verified Sir Isaac Newton.
Hackers Probing Newly Disclosed Fortinet Zero-Day
Researchers at Mandiant say a new threat cluster, first observed June 27, has been exploiting a Fortinet zero-day that the network edge device manufacturer publicly disclosed Wednesday. Researchers said they can't assess the threat actor's motivation or location.
Socure to Fortify Identity Services With $136M Effectiv Buy
Socure has acquired Effectiv, integrating its engineering team of 30 to strengthen identity verification capabilities. The $136 million deal aims to speed up customer onboarding, enhance transaction monitoring, and deliver cross-platform solutions, with the product integration expected in 45 days.
LinkedIn Fined 310 Million Euros for Privacy Violations
The Irish Data Protection Commission imposed a 310 million euro fine on LinkedIn for violating a European privacy law stemming from the company's use of customer data. It ordered the social media platform to bring its data processing under compliance.