Aggregator
CVE-2024-9661 | Soflyy WP All Import Pro Plugin up to 4.9.7 on WordPress delete_and_edit cross-site request forgery
CVE-2024-52884 | AudioCodes Mediant Session Border Controller prior 7.40A.501.841 Configuration Export inadequate encryption
Autonomous LLMs Reshaping Pen Testing: Real-World AD Breaches and the Future of Cybersecurity
Large Language Models (LLMs) are transforming penetration testing (pen testing), leveraging their advanced reasoning and automation capabilities to simulate sophisticated cyberattacks. Recent research demonstrates how autonomous LLM-driven systems can effectively perform assumed breach simulations in enterprise environments, particularly targeting Microsoft Active Directory (AD) networks. These advancements mark a significant departure from traditional pen testing methods, […]
The post Autonomous LLMs Reshaping Pen Testing: Real-World AD Breaches and the Future of Cybersecurity appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2024-9664 | Soflyy WP All Import Pro Plugin up to 4.9.7 on WordPress deserialization
CVE-2024-57249 | Gleamtech FileVista 9.2.0.0 improper authorization
CVE-2024-48091 | Tally Prime Edit Log 2.1 TextShaping.dll uncontrolled search path
CVE-2024-52881 | AudioCodes One Voice Operations Center up to 8.4.581 hard-coded key
Yahoo Finance: U.S. Lawmakers Push to Ban China’s DeepSeek AI Over Security Risks – Feroot Security Analysis
Washington, D.C. – U.S. lawmakers announced a bill to ban DeepSeek, the Chinese AI chatbot app, from government devices following a security analysis by Feroot Security that revealed alarming privacy and national security risks. The research suggests that DeepSeek collects user data, including digital fingerprints, login credentials, and behavioral information, potentially sending it to servers […]
The post Yahoo Finance: U.S. Lawmakers Push to Ban China’s DeepSeek AI Over Security Risks – Feroot Security Analysis appeared first on Feroot Security.
The post Yahoo Finance: U.S. Lawmakers Push to Ban China’s DeepSeek AI Over Security Risks – Feroot Security Analysis appeared first on Security Boulevard.
CVE-2024-35106 | Nextu Fleta AX1500 WIFI6 1.0.3 HTTP POST Request /boafrm/formIpQoS denial of service
CVE-2024-57248 | Gleamtech FileVista 9.2.0.0 HTTP Request path traversal
Securing GAI-Driven Semantic Communications: A Novel Defense Against Backdoor Attacks
Semantic communication systems, powered by Generative AI (GAI), are transforming the way information is transmitted by focusing on the meaning of data rather than raw content. Unlike traditional communication methods, these systems encode semantic features such as text, images, or speech into low-dimensional vectors, significantly reducing bandwidth usage while maintaining the integrity of transmitted information. […]
The post Securing GAI-Driven Semantic Communications: A Novel Defense Against Backdoor Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2024-7419 | WP All Import WP All Export Pro Plugin up to 1.9.1 on WordPress export code injection
Cybercriminals Target IIS Servers to Spread BadIIS Malware
A recent wave of cyberattacks has revealed the exploitation of Microsoft Internet Information Services (IIS) servers by threat actors deploying the BadIIS malware. This campaign, attributed to Chinese-speaking groups, leverages IIS vulnerabilities to manipulate search engine optimization (SEO) rankings and distribute malicious content. The attackers have targeted organizations across Asia, including India, Thailand, and Vietnam, […]
The post Cybercriminals Target IIS Servers to Spread BadIIS Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.