A new prompt injection vulnerability has been discovered in the EmailGPT service. This API service and Google Chrome plugin help users write emails in Gmail using OpenAI’s GPT model. The …
Criminal IP Unveils Innovative Fraud Detection Data Products on Snowflake Marketplace
AI SPERA, a leader in Cyber Threat Intelligence (CTI) solutions, announced that it has started selling its paid threat detection data from its CTI search engine ‘Criminal IP‘ on the …
Apple To Unveil It’s Dedicated Password Manager For Ios Devices
Apple is set to make a significant announcement at the Worldwide Developers Conference (WWDC), which kicks off on June 10. According to Bloomberg’s Mark Gurman, the tech giant will introduce a new homegrown app called “Passwords,” designed to simplify users’ logging into websites …
VS Code Marketplace Flaw Let Attackers Include Malicious Extensions
Researchers identified security vulnerabilities in the VS Code Marketplace that could be exploited by malicious actors, as these flaws allowed extensions with malicious dependencies to gain credibility (through high install …
Safari, Microsoft Edge, & DuckDuckGo Spoofing Flaws Impacting Millions of Users
RedSecLabs security researchers Rafay Baloch and Muhammad Samaak have uncovered address bar spoofing vulnerabilities in widely used mobile browsers such as Safari, Microsoft Edge, and DuckDuckGo. These vulnerabilities have a …
Mozilla’s 0Day Investigative Network, Next Generation Bug Bounty Program
Generative artificial intelligence (GenAI) is reshaping our world, from streamlining work tasks like coding to helping us plan summer vacations. As we increasingly adopt GenAI services and tools, we face …
PoC Exploit Published For SharePoint XML eXternal Entity (XXE) Injection Vulnerability
A new XXE (XML eXternal Entity) Injection has been discovered to affect SharePoint on both on-prem and cloud instances. This vulnerability has been assigned to CVE-2024-30043, and the severity has …
Frontier Communications Ransomware Attack: 750,000 Users’ Data Exposed
Frontier Communications Parent, Inc. (the “Company”) detected unauthorized access to portions of its information technology environment. The breach, attributed to a likely cybercrime group, exposed the personal data of approximately …
Bitdefender GravityZone Flaw Let Hackers Launch SSRF Attacks
Bitdefender has recently fixed a critical Server-Side Request Forgery (SSRF) vulnerability in its GravityZone Console On-Premise, known as CVE-2024-4177. This flaw, discovered in the host whitelist parser, could have allowed …
Microsoft Made Changes to Recall Feature Following Controversial Security Concerns
Microsoft has announced significant updates to its new Recall feature for Copilot+ PCs, following a wave of security and privacy concerns raised by experts and users. The Recall feature, set …

