klotz: vulnerability*

0 bookmark(s) - Sort by: Date ↓ / Title / - Bookmarks from other users for this tag

  1. Jessica Lyons writes that a vulnerability in OpenAI's internal JFrog Artifactory instance allowed for the creation of a covert, cross-account communication channel. Researchers discovered that an attacker could use this method to send hidden instructions to a victim's ChatGPT session—such as retrieving data from connected services like Gmail or Google Drive—without any visible indication appearing in the user's chat interface. While OpenAI has since decommissioned the specific Artifactory instance involved, the exploit highlights significant security risks regarding how AI agents interact with trusted internal systems and sensitive user data.

    - The vulnerability allowed attackers to attach Base64-encoded binary data as text properties to repository items within Artifactory.
    - A victim's session would execute these malicious tasks automatically while appearing to perform only the legitimate, requested task.
    - Potential targets for exfiltration included conversation history, files, Google Drive, Microsoft Teams, and GitHub via connected apps.
    - The vulnerability was disclosed in late June, coinciding with a separate zero-day exploitation where OpenAI's agents attacked Hugging Face.
  2. Nicholas Carlini, a research scientist at Anthropic, demonstrated that Claude Code can identify remotely exploitable security vulnerabilities within the Linux kernel. Most significantly, the AI discovered a heap buffer overflow in the NFS driver that had remained undetected for 23 years. By using a simple script to direct the model's attention to specific source files, Carlini was able to uncover complex bugs that require a deep understanding of intricate protocols. While the discovery highlights the growing power of large language models in cybersecurity, it also presents a new bottleneck: the massive volume of potential vulnerabilities found by AI requires significant manual effort from human researchers to validate and report.
  3. Security researcher BobDaHacker discovered multiple critical vulnerabilities in the Petlibro smart pet feeder system. The most severe is an **authentication bypass** allowing attackers to log in to *any* account using publicly available Google IDs. Petlibro acknowledged the issues and offered a $500 bounty, but has left the vulnerable login endpoint active for "legacy compatibility" over two months after initial reporting, despite promising a fix.

    Other vulnerabilities included:

    * Viewing details of any pet by ID.
    * Obtaining serial numbers and MAC addresses.
    * Manipulating feeding schedules, camera feeds, and settings without authentication.
    * Retrieving mealtime messages recorded by owners.
    * Gaining access to devices by adding oneself as a shared owner.
  4. The Rust version of sudo (sudo-rs) used in Ubuntu 25.10 has two moderate security vulnerabilities. Updates are being released to address these issues, including preventing password leaks and improving feedback handling.
  5. This week's security roundup covers the Anubis web AI firewall, AI exploit generation, a vulnerability in CodeRabbit, the potential illegality of adblocking in Germany, a Microsoft Copilot audit log issue, and a disputed Elastic EDR vulnerability.
  6. Vuls is an open-source agentless vulnerability scanner designed to help administrators find and manage security vulnerabilities in their systems. It offers fast, deep, and remote scanning options, along with dynamic analysis and middleware/library scanning. It supports a wide range of operating systems including Linux, FreeBSD, Windows, and macOS.
    2025-05-05 Tags: , , , , by klotz
  7. US crosswalk buttons were hijacked to play AI-generated voices of prominent figures like Bezos, Musk, and Zuckerberg. The hack exploited a default password (1234) on Polara's Field Service app, which allowed unauthorized configuration of the crosswalk signals.
  8. The US government initially ended funding for the Common Vulnerabilities and Exposures (CVE) database. However, funding has been restored through the CVE Foundation and CISA. This article covers CVE from the perspective of effects on Android alone.
  9. Vuls, a free, open-source vulnerability scanner for Linux systems, which uses an agentless SSH approach to scan multiple operating systems for vulnerabilities. It supports various scan modes including fast and deep scanning and can leverage multiple vulnerability databases like NVD and JVN.
  10. Okta has confirmed a security vulnerability where usernames of 52 characters or more allowed account access without a password.

Top of the page

First / Previous / Next / Last / Page 1 of 0 SemanticScuttle - klotz.me: Tags: vulnerability

About - Propulsed by SemanticScuttle