Aggregator
CVE-2024-21157 | Oracle MySQL Server up to 8.0.36/8.4.0 InnoDB denial of service (Nessus ID 209591)
Cicada3301
CVE-2016-10027 | Smack up to 4.1.8 XMPP Library race condition (FEDORA-2016-897a1e6698 / Nessus ID 96210)
Everest
Everest
NotLockBit: ransomware discovery serves as wake-up call for Mac users
【情报挖掘练习】美军运输机是否降落老挝机场?
LinkedIn hit with $335 million fine for using member data for ad targeting without consent
CVE-2024-50045 | Linux Kernel up to 5.10.226/5.15.167/6.1.112/6.6.56/6.11.3 br_netfilter null pointer dereference
CVE-2024-48657 | Hospital Management System 1.0.0 sql injection
CVE-2024-50050 | Meta Llama Stack Pickle deserialization
CVE-2024-40431 | Realtek SD Card Reader Driver prior 10.0.26100.21374 Kernel Memory memory corruption
CVE-2024-40432 | Realtek SD Card Reader Driver prior 10.0.26100.21374 denial of service
CVE-2024-47575 | Fortinet FortiManager up to 7.6.0 Request FortiJump missing authentication (FG-IR-24-423)
ZombAIs: From Prompt Injection to C2 with Claude Computer Use
A few days ago, Anthropic released Claude Computer Use, which is a model + code that allows Claude to control a computer. It takes screenshots to make decisions, can run bash commands and so forth.
It’s cool, but obviously very dangerous because of prompt injection. Claude Computer Use enables AI to run commands on machines autonomously, posing severe risks if exploited via prompt injection.
DisclaimerSo, first a disclaimer: Claude Computer Use is a Beta Feature and what you are going to see is a fundamental design problem in state-of-the-art LLM-powered Applications and Agents. This is an educational demo to highlight risks of autonomous AI systems processing untrusted data. And remember, do not execute unauthorized code systems without authorization from proper stakeholders.