Prompt Injection Vulnerability in VannaAI Library Allows Remote Code Execution
A high severity security flaw in the VannaAI library, identified as CVE-2024-5565, enables threat actors to execute unauthorized commands remotely through prompt injection techniques.
View full story…
Study Reveals 99.7% of Organizations Using AI-driven SaaS Applications Pose Data Security Risks
Recent research by Wing shows that the widespread use of AI-driven SaaS applications poses a significant risk to organizations’ sensitive data and intellectual property, with 70% of the top 10 AI applications potentially using user data for training their models.
View full story…
Latest Cybernews
Critical Authentication Bypass Vulnerabilities Discovered in Progress Software’s MOVEit Products
Progress Software’s MOVEit Transfer and Gateway products are vulnerable to critical authentication bypass exploits, putting organizations at risk of unauthorized access to sensitive data.
View full story…
Identity Theft Resource Center Reports Decrease in Identity Crimes in 2023
Job scams and compromised credentials are the main forms of identity theft reported in the US, with increasing sophistication of online thieves posing a significant threat to individuals and businesses.
View full story…
New “Skeleton Key” Attack Threatens Security of Multiple genAI Models
Multiple genAI models, including those from Microsoft, OpenAI, Google, Meta, and others, are vulnerable to a new attack called “Skeleton Key” that can bypass ethical and safety guardrails, potentially allowing access to offensive or illegal content.
View full story…
Chinese and North Korean Hackers Target Global Infrastructure with Ransomware
Threat actors with suspected ties to China and North Korea, including ChamelGang, have been identified in ransomware and data encryption attacks targeting government and critical infrastructure sectors globally between 2021 and 2023.
View full story…
New Android Banking Trojan TangleBot Targets Users in Multiple Countries
The latest variant of the Android banking trojan Medusa, now known as TangleBot, poses a significant threat to users’ financial security and privacy by initiating transactions directly on compromised devices and featuring keylogging, screen controls, SMS message reading capabilities, call recording, and unauthorized fund transfers using overlay attacks.
View full story…
FBI Warns of Fake Lawyers Scamming Cryptocurrency Victims
Fraudsters posing as fake lawyers from fictitious law firms target cryptocurrency scam victims with promises to recover stolen funds, resulting in nearly $10 million in losses.
View full story…
Apple Releases Firmware Updates for AirPods and Beats to Address Security Concern CVE-2024-27867
Apple has released firmware updates for its AirPods and Beats products to fix a security vulnerability that could allow unauthorized access to headphones within Bluetooth range.
View full story…
Over 110,000 Websites Impacted by Polyfill JavaScript Library Supply Chain Attack
A supply chain attack involving the Polyfill JavaScript library, owned by Funnull, has injected malware into websites, redirecting users to fraudulent sites, bookmakers, and online casinos.
View full story…
New Snowblind Banking Malware Targets Android Users in Southeast Asia
Snowblind, a novel banking malware strain, utilizes advanced techniques to evade detection and compromise sensitive information on banking apps in Southeast Asia.
View full story…
Latest Cybernews
Four Vietnamese Nationals Indicted in US for Cyber Attacks Causing $71M in Losses
Four Vietnamese nationals, part of the FIN9 cybercrime group, have been indicted in the US for hacking into US companies’ networks and causing over $71 million in losses.
View full story…
Google Introduces Project Naptime for AI-Powered Vulnerability Discovery
Google’s Project Zero introduces Project Naptime, leveraging large language models to automate variant analysis and enhance vulnerability discovery approaches.
View full story…