GPT-4 Is Capable Of Exploiting 87% Of One-Day Vulnerabilities
Large language models (LLMs) have achieved superhuman performance on many benchmarks, leading to a surge of interest in LLM agents capable of taking action,...
29 0-days Uncovered : Hackers Earned $1,132,500 Pwn2Own Vancouver 2024
The Pwn2Own Vancouver 2024 has come to an end, with researchers receiving a total of $1,132,500 for uncovering 29 distinct zero-day vulnerabilities.
Manfred Paul has...
Microsoft Exchange Server Flaw Let Remote Attackers Access Sensitive Information
ProxyToken, a serious security vulnerability has been detected in the Microsoft Exchange Server by the security analysts.
ProxyToken vulnerability could enable unauthenticated threat actors...
Critical SAP Vulnerabilities Let Attackers Inject Code & Execute Commands
SAP provided security fixes for 19 vulnerabilities, five of which were classified as critical, affecting SAP Business Objects Business Intelligence Platform (CMC) and SAP...
DreamBus Botnet Exploiting RCE Flaw in Apache RocketMQ Servers
A vulnerability affecting Apache RocketMQ servers was publicly disclosed in May 2023, allowing remote code execution through a gateway. RocketMQ is a cloud-native platform...
IBM AIX Vulnerability Let Attackers Trigger DoS Condition
IBM has reported vulnerabilities in its AIX operating system that could allow attackers to cause a Denial of Service (DoS) condition.
The identified vulnerabilities...
Google Fixes Actively Exploited Zero-day Vulnerability : Patch Now!
Google Chrome version 117.0.5938.132 for Windows, Mac, and Linux has been set to release with multiple bug fixes and features. As per Google, this...
OPNsense Firewall Flaws Let Attackers Employ XSS to Escalate Privileges
OPNsense is a firewall and routing platform that is based on FreeBSD. It is open-source, making it freely available for use.
Additionally, OPNsense is...
Ivanti Endpoint Manager SQL Injection Flaw Let Attackers Execute Arbitrary Code
Multiple vulnerabilities involving SQL injection have been identified in Ivanti Endpoint Manager.
These vulnerabilities could potentially enable malicious actors to carry out various unauthorized...
Critical Ping Vulnerability Let Hackers Take Over FreeBSD Systems Remotely
A critical vulnerability in the FreeBSD operating system's ping module allows Attackers to execute an arbitrary code and take over the system remotely. Developers...