> TODAY'S SUMMARY (2 articles)
Today's cyber news highlights significant legal actions against individuals involved in cybercrime. Raheim Hamilton, co-creator of the Empire Market dark web platform, received a 40-year prison sentence for drug conspiracy, alongside a forfeiture of over $100 million in Bitcoin. Additionally, the FBI has arrested the co-founder of a Canadian cybersecurity firm linked to the ShinyHunters hacking group, which has been notorious for data breaches and ransomware activities. These events underscore ongoing efforts by law enforcement to combat dark web marketplaces and ransomware operations.
|
// AI-powered summary generated at 04:00
The incident, reported to be ransomware-related, has resulted in attackers stealing sensitive personal and clinical data, including lab test results
GenAI company OpenAI has launched its first-ever open-weight models alongside a red teaming challenge
Today we cover Devin AI from Cognition, the first AI Software Engineer.
We will cover Devin proof-of-concept exploits in multiple posts over the next few days. In this first post, we show how a prompt injection payload hosted on a website leads to a full compromise of Devin’s DevBox.
GitHub Issue To...
A Nigerian man accused of hacking, fraud and identity theft has been extradited from France to the US to face charges
During the pre-Black Hat AI Summit, Sean Morgan, Protect AI’s Chief Architect, highlighted the three most prominent security risks of using AI agents
Acknowledgement added. This is an informational change only.
Adversaries are prioritizing stealth over scale, according to OPSWAT’s latest Threat Landscape Report
Trend Micro has released a temporary fix for the flaws, which enable remote code execution on on-prem Apex One machines
This vulnerability allows remote attackers to relay NTLM credentials on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3.
Ransomware actors deploy a range of activities to make it harder for victims to recover and increase the consequences of not paying demands
The UK’s National Cyber Security Centre has released the Cyber Assessment Framework 4.0
This vulnerability allows remote attackers to relay NTLM credentials on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3.
Chanel and Pandora have revealed data breaches reportedly linked to attacks on their Salesforce instances
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Microsoft SharePoint. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5.
Prompt injection pervades discussions about security for LLMs and AI agents. But there is little public information on how to write powerful, discreet, and reliable prompt injection exploits. In this post, we will design and implement a prompt injection exploit targeting GitHub’s Copilot Agent, with...
This vulnerability allows remote attackers to disclose sensitive information or create a denial-of-service condition on affected installations of Microsoft SharePoint. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1.
This vulnerability allows network-adjacent attackers to bypass the SmartScreen security feature on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a C...
Le Centre hospitalier du Gers a été victime d'une cyberattaque, possiblement liée à un ransomware, ce qui a entraîné un fonctionnement en mode dégradé de certains logiciels métiers. Une enquête est en cours et aucune donnée ne semble avoir été compromise à ce stade. Les admissions et la prise en cha...
This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVS...