Aggregator
基于CSharpCodeProvider的WebService Memshell利用与检测分析
某APP组件存在权限漏洞可导致远程one click用户劫持
Accelerate Crypto Success: Why a Canadian Crypto License Is Your Launchpad to Growth
Abusing Notion’s AI Agent for Data Theft
Notion just released version 3.0, complete with AI agents. Because the system contains Simon Willson’s lethal trifecta, it’s vulnerable to data theft though prompt injection.
First, the trifecta:
The lethal trifecta of capabilities is:
- Access to your private data—one of the most common purposes of tools in the first place!
- Exposure to untrusted content—any mechanism by which text (or images) controlled by a malicious attacker could become available to your LLM
- The ability to externally communicate in a way that could be used to steal your data (I often call this “exfiltration” but I’m not confident that term is widely understood.)...
The post Abusing Notion’s AI Agent for Data Theft appeared first on Security Boulevard.
Abusing Notion’s AI Agent for Data Theft
Seko AI 想要重新定义短片创作这件事
筑牢安全基底,护航数智未来 | CCS2025成都网络安全技术交流活动圆满结束
BlackShrantac
You must login to view this content
【安全圈】Windows 堆管理曝严重漏洞:记录大小字段缺陷可致任意读写
【安全圈】英国奢侈品百货Harrods确认数据泄露
【安全圈】Medusa勒索软件团伙声称攻击Comcast,索要120万美元赎金
【安全圈】黑客攻陷美国政府的数百台思科防火墙
«Коробочки» больше не игрушки: Мошенники заработали 300 миллионов рублей на виртуальных «рулетках» и «пошлинах».
WhatsApp 0-Click Vulnerability Exploited Using Malicious DNG File
WhatsApp 0-click remote code execution (RCE) vulnerability affecting Apple’s iOS, macOS, and iPadOS platforms, detailed with a proof of concept demonstration. The attack chain exploits two distinct vulnerabilities, identified as CVE-2025-55177 and CVE-2025-43300, to compromise a target device without requiring user interaction. The exploit, demonstrated in a proof-of-concept (PoC) shared by the DarkNavyOrg researchers, is […]
The post WhatsApp 0-Click Vulnerability Exploited Using Malicious DNG File appeared first on Cyber Security News.
Akira Ransomware bypasses MFA on SonicWall VPNs
Mydata
You must login to view this content