Aggregator
GitHub Copilot Jailbreak Vulnerability Let Attackers Train Malicious Models
Researchers have uncovered two critical vulnerabilities in GitHub Copilot, Microsoft’s AI-powered coding assistant, that expose systemic weaknesses in enterprise AI tools. The flaws—dubbed “Affirmation Jailbreak” and “Proxy Hijack”—allow attackers to bypass ethical safeguards, manipulate model behavior, and even hijack access to premium AI resources like OpenAI’s GPT-o1. These findings highlight the ease with which AI […]
The post GitHub Copilot Jailbreak Vulnerability Let Attackers Train Malicious Models appeared first on Cyber Security News.
CVE-2025-21665 | Linux Kernel up to 5.15.176/6.1.126/6.6.73/6.12.10 folio_seek_hole_data bit infinite loop
CVE-2025-21667 | Linux Kernel up to 6.1.126/6.6.73/6.12.10 iomap_write_delalloc_scan infinite loop
CVE-2025-21668 | Linux Kernel up to 6.1.126/6.6.73/6.12.10 imx8mp_blk_ctrl_remove out-of-bounds
JumpCloud Acquires Stack Identity to Extend Access Management Reach
JumpCloud this week revealed it has acquired Stack Identity to fuel an effort to add identity security and access visibility capabilities to its directory.
The post JumpCloud Acquires Stack Identity to Extend Access Management Reach appeared first on Security Boulevard.
CVE-2025-21670 | Linux Kernel up to 6.6.73/6.12.10 vsock_bpf_recvmsg null pointer dereference
CVE-2025-21671 | Linux Kernel up to 6.1.126/6.6.73/6.12.10 zram_meta_alloc uninitialized pointer
CVE-2025-21673 | Linux Kernel up to 6.6.73/6.12.10 cifs_put_tcp_session double free
CVE-2024-57948 | Linux Kernel up to 5.15.176/6.1.126/6.6.73/6.12.10 Network Interface lib/list_debug.c ieee802154_if_remove use after free
CVE-2025-21672 | Linux Kernel up to 6.12.10 fs/afs/addr_prefs.c afs_split_string locking
CVE-2024-12415 | quantumcloud AI Infographic Maker Plugin up to 4.9.0 on WordPress code injection
CVE-2024-12037 | svenl77 Post Form Plugin up to 2.8.13 on WordPress bf_new_submission_link cross site scripting
CVE-2024-13662 | vernonsystems eHive Objects Image Grid Plugin up to 2.4.1 on WordPress cross site scripting
Qilin
Patient monitors with backdoor are sending info to China, CISA warns
Contec CMS8000, a patient monitor manufactured by a Chinese company, and Epsimed MN-120, which is the same monitor but relabeled, exfiltrate patients’ data to a hard-coded IP address and have a backdoor that can be used to download and execute unverified files, the US Cybersecurity and Infrastructure Security Agency confirmed. “CISA assesses the inclusion of this backdoor in the firmware of the monitor can create conditions which may allow remote code execution and device modification … More →
The post Patient monitors with backdoor are sending info to China, CISA warns appeared first on Help Net Security.
DeepSeek’s Growing Influence Sparks a Surge in Frauds and Phishing Attacks
The rapid rise of DeepSeek, a Chinese artificial intelligence (AI) company, has not only disrupted the AI industry but also attracted the attention of cybercriminals. As its AI Assistant app became the most downloaded free app on the iOS App Store in January 2025, surpassing OpenAI’s ChatGPT, malicious actors have exploited its popularity to launch […]
The post DeepSeek’s Growing Influence Sparks a Surge in Frauds and Phishing Attacks appeared first on Cyber Security News.