Aggregator
ASCII Smuggling Attack in Gemini Tricks AI Agents into Revealing Smuggled Data
Enterprise AI assistants face a hidden menace when invisible control characters are used to smuggle malicious instructions into prompts. In September 2025, FireTail researcher Viktor Markopoulos tested several large language models (LLMs) for susceptibility to the long-standing ASCII Smuggling technique. His findings reveal that some widely adopted services still fail to strip out hidden Unicode tags, […]
The post ASCII Smuggling Attack in Gemini Tricks AI Agents into Revealing Smuggled Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Submit #668006: wonderwhy-er DesktopCommanderMCP 0.2.13 Improper Neutralization [Accepted]
Submit #668005: wonderwhy-er DesktopCommanderMCP 0.2.13 OS Command Injection [Accepted]
CVE-2025-11460 | Google Chrome up to 141.0.7390.54 Storage use after free
CVE-2025-11458 | Google Chrome up to 141.0.7390.54 Sync heap-based overflow
CVE-2025-11489 | wonderwhy-er DesktopCommanderMCP up to 0.2.13 src/tools/filesystem.ts isPathAllowed symlink (Issue 219)
Marriott, Samsung и Edge в одной атаке: всего один ZIP-архив может стоить вам контроля над компьютером
PoC Exploit Released for Critical Lua Engine Vulnerabilities
Three newly disclosed vulnerabilities have been identified in the Lua scripting engine of Redis 7.4.5, each presenting severe risks of remote code execution and privilege escalation. Redrays has released a detailed proof-of-concept (PoC) to exploit these vulnerabilities, which is now publicly available. Organizations are urged to act immediately. Use-After-Free Flaw (CVE-2025-49844) This vulnerability arises when […]
The post PoC Exploit Released for Critical Lua Engine Vulnerabilities appeared first on Cyber Security News.
Submit #668004: wonderwhy-er DesktopCommanderMCP 0.2.13 wonderwhy-er [Accepted]
CVE-2025-11488 | D-Link DIR-852 up to 20251002 /HNAP1/ command injection
CVE-2025-11487 | SourceCodester Farm Management System 1.0 /uploadProduct.php Type sql injection
CVE-2025-11486 | SourceCodester Farm Management System 1.0 /buyNow.php Name sql injection
Shuyal Stealer Malware Exploits 19 Browsers to Steal Logins
Shuyal Stealer is a recently uncovered infostealer that pushes the boundaries of traditional browser-targeted malware. Unlike most variants that zero in on popular platforms like Chrome and Edge, Shuyal dramatically widens its scope by targeting 19 different browsers, making it far more versatile and dangerous in its data-harvesting capabilities. Beyond the usual theft of browser-stored […]
The post Shuyal Stealer Malware Exploits 19 Browsers to Steal Logins appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.