48 Vulnerabilities Uncovered In AI systems : Surge By 220%

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Since the initial disclosure of 15 vulnerabilities in November 2023, a 220% increase in vulnerabilities impacting AI systems has been discovered, bringing the total to 48 vulnerabilities. The world’s first AI/ML bug bounty program, Protect AI, analyzes the whole OSS …

GPT-4 Is Capable Of Exploiting 87% Of One-Day Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Large language models (LLMs) have achieved superhuman performance on many benchmarks, leading to a surge of interest in LLM agents capable of taking action, self-reflecting, and reading documents.  While these agents have shown potential in areas like software engineering and …

ToddyCat APT Hackers Deploy Multiple Tools to Hijack Network Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Advanced Persistent Threat (APT) group known as ToddyCat, new insights have emerged regarding their sophisticated methods of hijacking network infrastructure to steal sensitive data from governmental organizations across the Asia-Pacific region. This group, previously reported on for using data collection and exfiltration tools, has now been observed employing advanced traffic tunneling and data extraction techniques to maintain persistent access to …

TransparentTribe Hackers Weaponize Websites & Documents to Attack Indian Orgs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The hacker group known as TransparentTribe, also referred to as APT-36, has intensified its cyber espionage activities. This group, originating from Pakistan, has been actively targeting Indian government organizations, military personnel, and defense contractors with sophisticated cyberattacks aimed at compromising …

Hackers Offering Admin Access to 3000 Fortinet SSL-VPN

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers are now offering administrative access to over 3000 Fortinet SSL-VPN devices. This breach poses a significant threat to the security of numerous organizations relying on these devices for secure remote access. A tweet from the account DailyDarkWeb, which quickly …

Hackers Mimic Road Toll Collection Services to Steal Your Money

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The FBI’s Internet Crime Complaint Center (IC3) has warned about a sophisticated smishing scam targeting drivers across multiple states. Since early March 2024, over 2,000 complaints have been filed with the IC3, detailing fraudulent text messages that masquerade as road …

Citrix UberAgent Vulnerability Allows Attackers To Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Citrix’s uberAgent, a sophisticated monitoring tool used to enhance performance and security across Citrix platforms, has been identified as having a critical vulnerability. The flaw, tracked under CVE-2024-3902, could allow attackers to escalate their privileges within the system, posing a …

Most Important Python Security Tools for Ethical Hackers & Penetration Testers 2024

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

There are a variety of Python security tools are using in the cybersecurity industries and python is one of the widely used programming languages to develop penetration testing tools. For anyone who is involved in vulnerability research, reverse engineering or …

MITRE Hacked – Attackers Compromised R&D Networks Using Ivanti Zero-days

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The MITRE Corporation, a non-profit organization that runs federally funded research and development centers, has disclosed that a sophisticated cyber attack recently compromised one of its internal research and development networks. MITRE detected the attack on one of its internal …

PoC Exploit Released for Cisco IMC Flaw – Urgent Update Advised

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Proof of Concept (PoC) exploit has been released for a critical vulnerability in Cisco’s Integrated Management Controller (IMC). This flaw, identified as CVE-2024-20356, allows for command injection and could enable attackers to gain root access to affected systems. Overview of …