> TODAY'S SUMMARY (6 articles)
Today's cybersecurity news highlights several significant threats and trends. An ongoing campaign involving malicious npm packages, particularly the 'indexed-btree,' demonstrates how attackers can evade supply chain defenses by embedding harmful code in normal runtime behavior. In a notable incident, an AI-generated report mistakenly identified weapons on a Chinese ship, nearly escalating tensions between the US and China. Additionally, researchers successfully escaped OpenAI's Codex sandbox, exploiting vulnerabilities to execute commands on the host machine, although these have since been patched. Lastly, Cisco has addressed a 0-day vulnerability in its email gateway, while the Revolut data breach continues to unfold, involving impersonation of a government agency.
|
// AI-powered summary generated at 16:01
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
Use after free in SQL Server allows an authorized attacker to execute code over a network.
Heap-based buffer overflow in SQL Server allows an authorized attacker to elevate privileges over a network.
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network.
Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.
Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally.
Acknowledgement Updated
Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network.
Information published.
Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network.
Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally.
Improper authorization in XBox Gaming Services allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Microsoft Trace Data Helper allows an authorized attacker to elevate privileges locally.
Use after free in Windows Server allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.