Aggregator
New Security Advisory Tab Added to the Microsoft Security Update Guide
CVE-2023-50387 and CVE-2023-50868 — DNS Exploit KeyTrap Posed Major Internet Threat
Wednesday February 14 2024 Security Releases
What’s Next for Akamai’s Cloud Computing Strategy
NIST Celebrates National Entrepreneurship Week
ChatGPT: Lack of Isolation between Code Interpreter sessions of GPTs
Your Code Interpreter sandbox, also known as Advanced Data Analysis sessions, are shared between private and public GPTs. Yes, your actual compute container and its storage is shared. Each user gets their own isolated container, but if a user uses multiple GPTs and stores files in Code Interpreter all GPTs can access (and also overwrite) each others files.
This is true also for files uploaded/created with private GPTs and ChatGPT itself.
Scanning Activity for CVE-2024-22024 (XXE) Vulnerability in Ivanti
安全会议PDF读后随笔
【补丁日速递】2024年2月微软补丁日安全风险通告
Tool of First Resort: Israel-Hamas War in Cyber
Tool of First Resort: Israel-Hamas War in Cyber
We’ve hired Ash Devata as CEO at GreyNoise, and I get my dream job.
Trend Micro Discovers Actively Exploited Vulnerability Affecting Millions of Users: Customers Already Protected
Scaling security with AI: from detection to solution
CVE-2024-23724: Ghost CMS Stored XSS Leading to Owner Takeover
The post CVE-2024-23724:
Ghost CMS Stored XSS Leading to Owner Takeover appeared first on Rhino Security Labs.
Decrypted: Rhysida Ransomware
The team at Avast has developed a decryptor for the Rhysida ransomware and released it for public download. The Rhysida ransomware has been active since May 2023. As of Feb 2024, their TOR site lists 78 attacked companies, including IT (Information Technology) sector, healthcare, universities, and government organizations.
The post Decrypted: Rhysida Ransomware appeared first on Avast Threat Labs.