ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories

Identity exposure has long been a significant concern for individuals and organizations alike, but its consequences can be far-reaching and devastating. A recent spate of high-profile security breaches highlights the alarming ease with which attackers can exploit exposed identities to gain unfettered access to sensitive systems and data. At the heart of this issue lies … Read more

Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access

Cybersecurity experts have uncovered a sophisticated attack technique that leverages Oracle’s database software to gain unauthorized access to Windows systems. The exploit, which involves compiling a malicious “khunt” inside the Oracle database, has been used in real-world attacks to breach even the most secure networks. The attackers behind this campaign appear to be highly skilled … Read more

AI Recommendation Poisoning: How “Ask AI” Buttons Silently Alter LLM Memory

A Silent Threat Lurks in AI Recommendation Systems: How “Ask AI” Buttons Can Compromise Large Language Models Artificial intelligence (AI) has become ubiquitous in our daily lives, from virtual assistants to content recommendation engines. However, a growing concern among cybersecurity experts is that these AI systems can be manipulated in ways that compromise their integrity … Read more

Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses

Apple’s iCloud Private Relay, touted as a robust tool for protecting user anonymity online, has been found vulnerable to exploitation through WebKit proxy bypasses. This means that even when users are connected to iCloud Private Relay, their real IP addresses can be exposed under certain conditions. The issue affects millions of Apple device owners worldwide … Read more

CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

A Critical Flaw in Five Crypto Wallet Apps Has Resulted in $5.7 Million Stolen, Highlighting the Importance of Secure Random Number Generation in Cryptocurrency Security. The theft of a staggering $5.7 million from five popular cryptocurrency wallet apps has been attributed to a critical flaw in their underlying code. The vulnerability, rooted in the use … Read more

Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities

As many as 4,400 industrial control systems from Rockwell Automation were left exposed online without proper security measures in place, potentially leaving critical infrastructure vulnerable to cyber attacks. This staggering number has been discovered by researchers who have mapped out how these exposures can be exploited to create active attack paths. The affected devices are … Read more

AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model

A trio of vulnerabilities in popular web development tools has left thousands of developers and organizations exposed to potential attacks. AWS, Google Cloud, and Vercel, a leading platform for building fast and scalable websites, have all been affected by critical flaws that allow hackers to trigger sensitive tools without even running the underlying machine learning … Read more

Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access

A newly discovered vulnerability in Oracle’s database software has allowed attackers to bypass traditional security measures and gain unauthorized access to Windows systems. The exploit, which takes advantage of a weakness in the way Oracle handles SQL injection attacks, has been dubbed “khunt” by researchers. What sets this attack apart is its ability to turn … Read more

AI Recommendation Poisoning: How “Ask AI” Buttons Silently Alter LLM Memory

Silent Takeover: AI Recommendation Poisoning Exposes Vulnerabilities in LLMs A growing concern has emerged in the world of artificial intelligence (AI) as researchers have discovered a vulnerability that allows attackers to secretly manipulate the memory of large language models (LLMs). This phenomenon, known as “AI recommendation poisoning,” raises serious questions about the security and trustworthiness … Read more