Category: Uncategorized
-
Okta debuts passkey support to combat account compromises
Post ContentRead More
-

Microsoft Warns of Cyber Attacks Attempting to Breach Cloud via SQL Server Instance [email protected] (The Hacker News)
Microsoft has detailed a new campaign in which attackers unsuccessfully attempted to move laterally to a cloud environment through a SQL Server instance. “The attackers initially exploited a SQL injection vulnerability in an application within the target’s environment,” security researchers Sunders Bruskin, Hagai Ran Kestenberg, and Fady Nasereldeen said in a Tuesday report. “This allowed theRead More
-
Qualcomm Patches 3 Zero-Days Reported by Google Eduard Kovacs
Qualcomm has patched more than two dozen vulnerabilities, including three zero-days that may have been exploited by spyware vendors. The post Qualcomm Patches 3 Zero-Days Reported by Google appeared first on SecurityWeek. Read More
-

Looney Tunables: New Linux Flaw Enables Privilege Escalation on Major Distributions [email protected] (The Hacker News)
A new Linux security vulnerability dubbed Looney Tunables has been discovered in the GNU C library’s ld.so dynamic loader that, if successfully exploited, could lead to a local privilege escalation and allow a threat actor to gain root privileges. Tracked as CVE-2023-4911 (CVSS score: 7.8), the issue is a buffer overflow that resides in the dynamic loader’s…
-
Synqly Joins Race to Fix Security, Infrastructure Product Integrations Ryan Naraine
Silicon Valley startup lands $4 million in seed funding from SYN Ventures, Okta Ventures and Secure Octane. The post Synqly Joins Race to Fix Security, Infrastructure Product Integrations appeared first on SecurityWeek. Read More
-
ZDI Discusses First Automotive Pwn2Own Kevin Townsend
The Zero Day Initiative (ZDI) will host a new Automotive Pwn2Own at the Automotive World Conference in Tokyo, January 24 to 26, 2024. The post ZDI Discusses First Automotive Pwn2Own appeared first on SecurityWeek. Read More
-

Qualcomm Releases Patch for 3 new Zero-Days Under Active Exploitation [email protected] (The Hacker News)
Chipmaker Qualcomm has released security updates to address 17 vulnerabilities in various components, while warning that three other zero-days have come under active exploitation. Of the 17 flaws, three are rated Critical, 13 are rated High, and one is rated Medium in severity. “There are indications from Google Threat Analysis Group and Google Project Zero…
-

Warning: PyTorch Models Vulnerable to Remote Code Execution via ShellTorch [email protected] (The Hacker News)
Cybersecurity researchers have disclosed multiple critical security flaws in the TorchServe tool for serving and scaling PyTorch models that could be chained to achieve remote code execution on affected systems. Israel-based runtime application security company Oligo, which made the discovery, has coined the vulnerabilities ShellTorch. “These vulnerabilities […] can lead to a full chain RemoteRead More
-
Critical TorchServe Flaws Could Expose AI Infrastructure of Major Companies Eduard Kovacs
ShellTorch attack chains critical TorchServe vulnerabilities and could completely compromise the AI infrastructure of major companies. The post Critical TorchServe Flaws Could Expose AI Infrastructure of Major Companies appeared first on SecurityWeek. Read More
-
Spyware vendor exploiting kernel flaw in Arm Mali GPU drivers
Post ContentRead More
