Aggregator
CVE-2022-42936 | Autodesk AutoCAD DWF File DesignReview.exe memory corruption
CVE-2022-42937 | Autodesk AutoCAD DWF File DesignReview.exe memory corruption
CVE-2022-42938 | Autodesk AutoCAD TGA File DesignReview.exe memory corruption
CVE-2022-42939 | Autodesk AutoCAD TGA File DesignReview.exe memory corruption
CVE-2022-41986 | Iij SmartKey up to 2.1.3 on Android One-Time Password information disclosure
CVE-2022-3344 | Linux Kernel KVM expected behavior violation
CVE-2022-3644 | pulp_ansible credentials storage
CVE-2022-36783 | AlgoSec FireFlow search/result.html IntersectudRule cross site scripting
CVE-2022-38580 | Zalando Skipper 0.13.236 server-side request forgery (EDB-51111)
Breaking the Password Barrier: FIDO’s Path to Seamless Security
As the digital world rapidly expands, the need for secure, seamless authentication becomes more urgent. At the forefront of this evolution is FIDO (Fast Identity Online), promoting password-less authentication that combines convenience with strong security. But FIDO’s long-term success depends not only on its security capabilities but also on achieving true interoperability across platforms and..
The post Breaking the Password Barrier: FIDO’s Path to Seamless Security appeared first on Security Boulevard.
CVE-2019-0227 | Oracle WebCenter Portal 12.2.1.3.0 WebCenter Spaces Application server-side request forgery (EDB-46682)
KoviD: Red-Team Linux kernel rootkit
KoviD is a Loadable Kernel Module (LKM) designed for Linux Kernel version 5 and later. Key features include: Self-hiding from SysFS. Provides reverse shell backdoors. Conceals processes from the proc file system. Handles child...
The post KoviD: Red-Team Linux kernel rootkit appeared first on Penetration Testing Tools.
Play Ransomware Group Used Windows Zero-Day
GMA News and Public Affairs Hit by Ransomware Attack
Jailbreakers Use Invisible Characters to Beat AI Guardrails
Subtle obfuscation techniques can systematically evade the guardrails that today's large language models rely on. Researchers from Mindgard team found that adversaries can "smuggle" malicious payloads past tokenizers using emojis, zero-width spaces and homoglyphs.
CrowdStrike Lays Off 500 Workers as AI Flattens Hiring Curve
CrowdStrike plans to axe 500 employees as the endpoint security behemoth looks to operate more efficiently. Saying its use of AI technology "flattens our hiring curve," the company revealed plans to reduce its nearly 10,000-person staff by 5% to scale its business with more focus and discipline.
UK Warns of AI-Based Attacks Against Critical Infrastructure
Proliferation of AI-enabled technology will widen access to offensive tools by nation-state groups and other hackers. The volume of attacks is expected to rise significantly by 2027, and British critical infrastructure will be a prime target, the National Cybersecurity Center said.
Hacker Exploits AI Art Tool to Steal 1.1TB of Disney Data
A California man agreed to plead guilty to hacking a Disney employee's personal computer and stealing over one terabyte of confidential company data. Authorities say the man posted a malicious artificial intelligence art application online and used it to steal an employee's credentials.