Aggregator
20+ Hijacked Government Websites Became an Attack Channel
20+ Hijacked Government Websites Became an Attack Channel
Next.js Announces July Security Release to Fix 4 High-Severity and 5 Medium Flaws
Next.js maintainers have announced a scheduled security release for July to address nine vulnerabilities, four rated high severity and five rated medium severity. The patches are expected to be released on July 20, 2022, and will include updated versions for Next.js 16.2 and 15.5. Next.js July Security Release This announcement initiates a formal security release […]
The post Next.js Announces July Security Release to Fix 4 High-Severity and 5 Medium Flaws appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
"Selfish Bravado" Behind TfL Cyber-Attack, Judge Says as Pair Jailed
ValorC3 extends SaaS protection with immutable cloud backups
ValorC3 Data Centers today announced the general availability of Backup as a Service, a fully managed offering that protects the SaaS data businesses rely on most, including Microsoft 365, Entra ID and Salesforce. Every backup is immutable, so data stays recoverable after deletion, corruption or a ransomware attack. Most companies falsely assume SaaS vendors provide backup service. In reality, recent cloud governance tracking shows that 80% of organizations have experienced at least one cloud security … More →
The post ValorC3 extends SaaS protection with immutable cloud backups appeared first on Help Net Security.
CVE-2022-3521 | Linux Kernel kcm net/kcm/kcmsock.c kcm_tx_work race condition (EUVD-2022-42888 / Nessus ID 236648)
CVE-2022-3523 | Linux Kernel Driver mm/memory.c use after free (EUVD-2022-42890 / Nessus ID 236642)
CVE-2022-3518 | SourceCodester Sanitization Management System 1.0 User Creation First Name/Middle Name/Last Name cross site scripting (EUVD-2022-42885)
CVE-2022-3519 | SourceCodester Sanitization Management System 1.0 Quote Requests Tab Manage Remarks cross site scripting (EUVD-2022-42886)
CVE-2022-3520 | vim up to 9.0.764 heap-based overflow (EUVD-2022-42887 / WID-SEC-2022-2222)
WhatsApp GhostPairing Lets Scammers Hijack Accounts Without Stealing Passwords
WhatsApp users are being targeted by a social-engineering technique called GhostPairing that can give scammers access to an account without requiring a password or one-time verification code. Instead of breaking into the service directly, the scam abuses WhatsApp’s legitimate device-linking feature and relies on a victim being persuaded to approve a new connected device. The […]
The post WhatsApp GhostPairing Lets Scammers Hijack Accounts Without Stealing Passwords appeared first on Cyber Security News.
日企AI联盟拟采购近3万枚英伟达Rubin芯片 发力机器人生态
JetBrains Patched 6 Vulnerabilities Across TeamCity, YouTrack and IntelliJ IDEA
JetBrains has addressed six security vulnerabilities in its software development and project management products. The affected applications include IntelliJ IDEA, TeamCity, and YouTrack. The most critical vulnerability, tracked as CVE-2026-59792, is an improper path handling (CWE-23) flaw that could allow attackers to exploit project workspace ID processing to perform path traversal and potentially execute code […]
The post JetBrains Patched 6 Vulnerabilities Across TeamCity, YouTrack and IntelliJ IDEA appeared first on Cyber Security News.
OpenAI Unveils GPT-Red AI Model That Automatically Finds Prompt Injection Vulnerabilities
OpenAI has introduced GPT-Red, an automated safety red-teaming model trained to identify and exploit prompt injection weaknesses in AI agents. Prompt injection occurs when malicious instructions hidden in webpages, emails, local files, code repositories, or tool outputs manipulate an AI system into ignoring its intended task, potentially causing data theft, unauthorized actions, or policy bypasses. […]
The post OpenAI Unveils GPT-Red AI Model That Automatically Finds Prompt Injection Vulnerabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
2 миллиона треков с YouTube Music и сотни тысяч подкастов. Хакер раскрыл исходный код сервиса Suno
OkoBot Malware Uses ClickFix, Hidden Browser Extensions to Steal Crypto Data
New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands
New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands
Intruder brings AI-powered, on-demand penetration testing to web applications
Intruder has announced the launch of AI Pentesting for web applications, providing on-demand penetration testing. Following its initial release of issue-level investigations last quarter, the platform now allows organizations to securely connect their codebases via GitHub or GitLab to automatically scope and launch penetration tests in minutes, with results and audit-ready reporting in hours. Mythos and Daybreak have proven that AI is extremely adept at finding security vulnerabilities. At the same time, AI is accelerating … More →
The post Intruder brings AI-powered, on-demand penetration testing to web applications appeared first on Help Net Security.