Aggregator
CVE-2025-20209 | Cisco IOS XR up to 24.2.11 IKEv2 allocation of resources (cisco-sa-xrike-9wYGpRGq)
CVE-2025-30164 | Icinga icingaweb2 up to 2.11.4/2.12.2 Command-Line Interface redirect
Exfiltrating Your ChatGPT Chat History and Memories With Prompt Injection
In this post we demonstrate how a bypass in OpenAI’s “safe URL” rendering feature allows ChatGPT to send personal information to a third-party server. This can be exploited by an adversary via a prompt injection via untrusted data.
If you process untrusted content, like summarizing a website, or analyze a pdf document, the author of that document can exfiltrate any information present in the prompt context, including your past chat history.
Было 69 отключений, стало 2099. Связь в России отключается всё чаще и громче
Overcoming the Limitations of Using AI Security in Telecom
Telecom firms face rising cyberthreats, growing regulatory pressure and shrinking budgets. But instead of chasing flashy solutions, the industry should focus on strengthening its security fundamentals, said Silke Holtmanns, telecommunication and critical infrastructure security expert at Blue Hour.
What Makes an AI Startup Fundable - From a VC Who Knows
Q2 2025 saw AI dominate global VC funding, grabbing $47.5 billion of the $94.6 billion raised. AI Investor Umesh Padval breaks down what makes AI infrastructure startups worth betting on - from platform depth and speed to regional ecosystems and exit timing.
BSidesSF 2025: 0.0.0.0 Day: Exploiting Localhost APIs From The Browser
Creator/Author/Presenter: Gal Elbaz
Our deep appreciation to Security BSides - San Francisco and the Creators/Authors/Presenters for publishing their BSidesSF 2025 video content on YouTube. Originating from the conference’s events held at the lauded CityView / AMC Metreon - certainly a venue like no other; and via the organization's YouTube channel.
Additionally, the organization is welcoming volunteers for the BSidesSF Volunteer Force, as well as their Program Team & Operations roles. See their succinct BSidesSF 'Work With Us' page, in which, the appropriate information is to be had!
The post BSidesSF 2025: 0.0.0.0 Day: Exploiting Localhost APIs From The Browser appeared first on Security Boulevard.
CVE-2025-25292 | SAML-Toolkits ruby-saml up to 1.12.3/1.17.x ReXML/Nokogiri signature verification (GHSA-754f-8gm6-c4r2 / Nessus ID 232721)
CVE-2025-25293 | SAML-Toolkits ruby-saml up to 1.12.3/1.17.x Message Size resource consumption (GHSA-92rq-c8cf-prrq / Nessus ID 233790)
LLMs' AI-Generated Code Remains Wildly Insecure
Chinese Threat Actors Hack 11,000 Android Devices to Deploy PlayPraetor Malware
Chinese-speaking threat actors have used the PlayPraetor Remote Access Trojan (RAT) to infiltrate more than 11,000 Android devices globally in a sophisticated Malware-as-a-Service (MaaS) operation. This allows for on-device fraud (ODF) by controlling the device in real time. First investigated by Cleafy Threat Intelligence in June 2025, the campaign impersonates legitimate Google Play Store pages […]
The post Chinese Threat Actors Hack 11,000 Android Devices to Deploy PlayPraetor Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
调查显示 AI 编程工具使用率上升的同时对其信任度在下降
CVE-2025-0150 | Zoom Workplace App/Meeting SDK up to 6.2.x on iOS denial of service
CVE-2025-43239 | Apple macOS up to 13.6/14.6/15.5 File out-of-bounds (Nessus ID 243030)
CVE-2025-43241 | Apple macOS up to 13.6/14.6/15.5 Restrictions sandbox (Nessus ID 243030)
CVE-2025-43235 | Apple macOS up to 15.5 App denial of service (EUVD-2025-23132 / Nessus ID 243030)
Flo settles class action lawsuit alleging improper data sharing
Ladon SharePoint CVE-2025-53770漏洞后门批量检测
CMS、WhatCMS、CmsInfo等,Cobalt Strike下用法一致,输入URL,仅识别URL对应指纹,输入非URL时,会探测常见cve-2025-53770网站、网络