Cybersecurity

Category Added in a WPeMatico Campaign

Cybersecurity

The impact of prompt injection in LLM agents – Help Net Security

Prompt injection is, thus far, an unresolved challenge that poses a significant threat to Language Model (LLM) integrity. This risk is particularly alarming when LLMs are turned into agents that interact directly with the external world, utilizing tools to fetch data or execute actions. Malicious actors can leverage prompt injection techniques to generate unintended and […]

Cybersecurity

Mozilla Patches Firefox Vulnerability Allowing Remote Code Execution, Sandbox Escape

Mozilla on Tuesday announced security updates for both Firefox and Thunderbird, to address 20 vulnerabilities, including several memory safety issues. Firefox 121 was released with patches for 18 vulnerabilities, five of which have a ‘high’ severity rating. At the top of the list is CVE-2023-6856, a heap buffer overflow bug in WebGL, the JavaScript API […]

Cybersecurity

SimSpace raises $45M to simulate tech stacks for cyber training | TechCrunch

SimSpace, a startup that creates digital replicas of organizations’ tech and networking stacks for cybersecurity training, has raised $45 million in a funding round led by L2 Point Management. Bringing the company’s total raised to $70 million, the investment comes at an auspicious time for SimSpace, which had been entirely bootstrapped until about two years […]

Cybersecurity

Hackers Exploiting Old MS Excel Vulnerability to Spread Agent Tesla Malware

Dec 21, 2023NewsroomVulnerability / Phishing Attack Attackers are weaponizing an old Microsoft Office vulnerability as part of phishing campaigns to distribute a strain of malware called Agent Tesla. The infection chains leverage decoy Excel documents attached in invoice-themed messages to trick potential targets into opening them and activate the exploitation of CVE-2017-11882 (CVSS score: 7.8), […]

Cybersecurity

Urgent: New Chrome Zero-Day Vulnerability Exploited in the Wild – Update ASAP

Dec 21, 2023NewsroomVulnerability / Zero-Day Google has rolled out security updates for the Chrome web browser to address a high-severity zero-day flaw that it said has been exploited in the wild. The vulnerability, assigned the CVE identifier CVE-2023-7024, has been described as a heap-based buffer overflow bug in the WebRTC framework that could be exploited […]

Cybersecurity

Malware leveraging public infrastructure like GitHub on the rise

The use of public services as command-and-control (C2) infrastructure isn’t a revolutionary technique for malicious actors. ReversingLabs has observed such behavior in several malware campaigns throughout the last few years. Malware authors occasionally place their samples in services like Dropbox, Google Drive, OneDrive and Discord to host second stage malware and sidestep detection tools. However, […]

Cybersecurity

From Macro to Payload: Decrypting the Sidewinder Cyber Intrusion Tactics – CYFIRMA

Published On : 2023-12-15 EXECUTIVE SUMMARY At CYFIRMA, our mission is to empower you with the latest insights into the dynamic landscape of cybersecurity threats, addressing risks that impact both organizations and individuals. This report details a sophisticated cyber threat involving a malicious Word file with an embedded macro that, upon opening, prompts victims to […]