Security News

A Taxonomy of Prompt Injection Attacks
2024-03-08 12:06

Researchers ran a global prompt hacking competition, and have documented the results in a paper that both gives a lot of good examples and tries to organize a taxonomy of effective prompt injection strategies. These deployments are vulnerable to prompt injection and jailbreaking, in which models are manipulated to ignore their original instructions and follow potentially malicious ones.

Cisco patches Secure Client VPN flaw that could reveal authentication tokens (CVE-2024-20337)
2024-03-08 10:49

Cisco has fixed two high-severity vulnerabilities affecting its Cisco Secure Client enterprise VPN and endpoint security solution, one of which could be exploited by unauthenticated, remote attackers to grab users' valid SAML authentication token."The attacker could then use the token to establish a remote access VPN session with the privileges of the affected user," Cisco says, but notes that "Individual hosts and services behind the VPN headend would still need additional credentials for successful access."

Secrets Sensei: Conquering Secrets Management Challenges
2024-03-08 09:49

In the realm of cybersecurity, the stakes are sky-high, and at its core lies secrets management — the foundational pillar upon which your security infrastructure rests. We're all familiar with the...

Enjoy 2 Years of Unrestricted Access to Your Favorite Content for Only $40
2024-03-08 09:15

Unlocator VPN + Free Smart DNS blasts through firewalls, censorship and geo-restrictions so you will always be able to access your favorite content. TL;DR: Turbocharge your streaming experience as you just blast through firewalls, geographical restrictions and more with a two-year subscription to Unlocator VPN + Free Smart DNS - it's just $40 through March 10 with code ENJOY20.

Cisco Issues Patch for High-Severity VPN Hijacking Bug in Secure Client
2024-03-08 08:09

Cisco has released patches to address a high-severity security flaw impacting its Secure Client software that could be exploited by a threat actor to open a VPN session with that of a targeted...

QEMU Emulator Exploited as Tunneling Tool to Breach Company Network
2024-03-08 07:48

Threat actors have been observed leveraging the QEMU open-source hardware emulator as tunneling software during a cyber attack targeting an unnamed "large company" to connect to their...

March 2024 Patch Tuesday forecast: A popular framework updated
2024-03-08 06:45

The February 2024 Patch Tuesday was pretty typical, with the standard Microsoft Windows, Office, and Exchange Server updates. Before we get to the March 2024 Patch Tuesday forecast, I want to provide information on the updated NIST framework.

Immediate AI risks and tomorrow’s dangers
2024-03-08 06:30

"At the most basic level, AI has given malicious attackers superpowers," Mackenzie Jackson, developer and security advocate at GitGuardian, told the audience last week at Bsides Zagreb. These superpowers are most evident in the growing impact of fishing, smishing and vishing attacks since the introduction of ChatGPT in November 2022.

#AI
CISA Warns of Actively Exploited JetBrains TeamCity Vulnerability
2024-03-08 06:13

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting JetBrains TeamCity On-Premises software to its Known Exploited Vulnerabilities...

How new and old security threats keep persisting
2024-03-08 06:00

Security leaders recognize that the pattern of buying new tech and the frantic state of find-fix vulnerability management is not working, according to Cymulate. Rather than waiting for the next big cyberattack and hoping they have the right defenses in place, security leaders are now more than ever implementing a proactive approach to cybersecurity by taking action to identify and address security gaps before attackers find and exploit them.