Aggregator
OpenAI ChatGPT Atlas Browser Jailbroken to Disguise Malicious Prompt as URLs
OpenAI’s newly launched ChatGPT Atlas browser, designed to blend AI assistance with web navigation, faces a serious security flaw that allows attackers to jailbreak the system by disguising malicious prompts as harmless URLs. This vulnerability exploits the browser’s omnibox, a combined address and search bar that interprets inputs as either navigation commands or natural-language prompts […]
The post OpenAI ChatGPT Atlas Browser Jailbroken to Disguise Malicious Prompt as URLs appeared first on Cyber Security News.
CISA Beware! Hackers Are Actively Exploiting Windows Server Update Services RCE Flaw in the Wild
Cybersecurity researchers are sounding the alarm after discovering that hackers are actively exploiting a critical remote code execution (RCE) vulnerability in Microsoft’s Windows Server Update Services (WSUS). The flaw, tracked as CVE-2025-59287, allows unauthenticated attackers to run arbitrary code on vulnerable servers, and evidence suggests that these attacks are being carried out manually, a technique […]
The post CISA Beware! Hackers Are Actively Exploiting Windows Server Update Services RCE Flaw in the Wild appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-12224 | Iqbolshoh php-business-website up to 10677743a8dfc281f85291a27cf63a0bce043c24 admin/contact.php twitter cross site scripting
CVE-2025-12223 | Bdtask Flight Booking Software up to 3.1 Package Information /b2c/package-information unrestricted upload
CVE-2025-12222 | Bdtask Flight Booking Software up to 3.1 Deposit deposit unrestricted upload
Submit #673540: php-business-website web 1 xss vulnerability [Accepted]
Everest
You must login to view this content
Submit #673454: sourcecodester Online Student Clearance System 1.0 SQL Injection [Duplicate]
Submit #673436: Bdtask Flight Booking Software B2C Portal v3,1 Unrestricted File Upload [Accepted]
Submit #673424: Bdtask Flight Booking Software B2B Portal v3.1 Unrestricted File Upload [Accepted]
CVE-2025-12221 | Azure Access BLU-IC2/BLU-IC4 up to 1.19.5 Busybox config (EUVD-2025-35937)
CVE-2025-12216 | Azure Access BLU-IC2/BLU-IC4 up to 1.19.5 App insufficient or incomplete data removal within hardware component (EUVD-2025-35936)
CVE-2025-12217 | Azure Access BLU-IC2/BLU-IC4 up to 1.19.5 SNMP default credentials (EUVD-2025-35935)
CVE-2025-12220 | Azure Access BLU-IC2/BLU-IC4 up to 1.19.5 Busybox vulnerable third-party component (EUVD-2025-35932)
CVE-2025-12219 | Azure Access BLU-IC2/BLU-IC4 up to 1.19.5 vulnerable third-party component (EUVD-2025-35933)
CVE-2025-12218 | Azure Access BLU-IC2/BLU-IC4 up to 1.19.5 default credentials (EUVD-2025-35934)
Submit #673412: Projectworlds Online Matrimonial System 1.0 SQL Injection [Duplicate]
New CoPhish attack steals OAuth tokens via Copilot Studio agents
Qilin
You must login to view this content