Aggregator
CVE-2024-23724: Ghost CMS Stored XSS Leading to Owner Takeover
1 year 2 months ago
The post CVE-2024-23724:
Ghost CMS Stored XSS Leading to Owner Takeover appeared first on Rhino Security Labs.
Tyler Ramsbey
Decrypted: Rhysida Ransomware
1 year 2 months ago
The team at Avast has developed a decryptor for the Rhysida ransomware and released it for public download. The Rhysida ransomware has been active since May 2023. As of Feb 2024, their TOR site lists 78 attacked companies, including IT (Information Technology) sector, healthcare, universities, and government organizations.
The post Decrypted: Rhysida Ransomware appeared first on Avast Threat Labs.
Threat Research Team
Deepfakes in the global election year of 2024: A weapon of mass deception?
1 year 2 months ago
As fabricated images, videos and audio clips of real people go mainstream, the prospect of a firehose of AI-powered disinformation is a cause for mounting concern
Vulnerability assessments vs. penetration testing
1 year 2 months ago
Penetration tests are a detailed hands-on exploration of an organization’s weaknesses while vulnerability assessments quickly identify risks without going deeper. Here’s why you need both.
Unleashing the power of cloud with containerisation
1 year 2 months ago
New NCSC guidance describes how organisations can make the most of containerisation.
国内开发者的网络超时日常
1 year 2 months ago
Life find its way.
国内开发者的网络超时日常
1 year 2 months ago
Life find its way.
国内开发者的网络超时日常
1 year 2 months ago
Life find its way.
国内开发者的网络超时日常
1 year 2 months ago
Life find its way.
Say Goodbye to Monolithic EdgeWorkers: Introducing Flexible Composition (Part 2)
1 year 2 months ago
Evan Hughes & AJ Johnson
国内开发者的网络超时日常
1 year 2 months ago
Life find its way.
三仙归洞
1 year 2 months ago
仙人把碗扣下,问里面有几颗豆子。然后,仙人就不见了,只剩下那只碗。一开始大家不信他是仙人,以为就是个变戏法的。
三仙归洞
1 year 2 months ago
仙人把碗扣下,问里面有几颗豆子。然后,仙人就不见了,只剩下那只碗。一开始大家不信他是仙人,以为就是个变戏法的。
三仙归洞
1 year 2 months ago
仙人把碗扣下,问里面有几颗豆子。然后,仙人就不见了,只剩下那只碗。一开始大家不信他是仙人,以为就是个变戏法的。
三仙归洞
1 year 2 months ago
仙人把碗扣下,问里面有几颗豆子。然后,仙人就不见了,只剩下那只碗。一开始大家不信他是仙人,以为就是个变戏法的。
三仙归洞
1 year 2 months ago
仙人把碗扣下,问里面有几颗豆子。然后,仙人就不见了,只剩下那只碗。一开始大家不信他是仙人,以为就是个变戏法的。
三仙归洞
1 year 2 months ago
仙人把碗扣下,问里面有几颗豆子。然后,仙人就不见了,只剩下那只碗。一开始大家不信他是仙人,以为就是个变戏法的。
Video: ASCII Smuggling and Hidden Prompt Instructions
1 year 2 months ago
A couple of weeks ago hidden prompt injections were discovered and we covered it at the time.
This video explains it in more detail, and also highlights implications beyond hiding instructions, including what I call ASCII Smuggling. This is the usage of Unicode Tags Block characters to both craft and deciper hidden messages in plain sight.
Using Unicode encoding to bypass security features or execute code (XSS, SSRF,..) has been in use for a while, however this new TTP enables more sophisticated attack scenarios.
SigmaHQ Rules Release Highlights — r2024–02–12
1 year 2 months ago
Nasreddine Bencherchali