Last week, ChatGPT creator OpenAI patched multiple severe vulnerabilities that could have allowed attackers to take over user accounts and view chat histories. The first was a critical web cache deception bug that could have allowed attackers to access user information such as names, emails, and access tokens, which OpenAI’s API would fetch from the ..
Tag : Vulnerabilities
OpenSSL 1.1.1 will reach end of life (EoL) in less than six months and users have been instructed to either upgrade to a newer version or pay for extended support to continue receiving security patches. The OpenSSL Project has reminded users of the open source cryptography and secure communication toolkit that OpenSSL 1.1.1 will reach ..
Several zero-day vulnerabilities patched last year had been exploited by commercial spyware vendors to target Android and iOS devices, according to a report published on Wednesday by Google’s Threat Analysis Group (TAG). Google’s security researchers have detailed the zero-day and n-day vulnerabilities exploited in what they described as two different highly targeted campaigns. For many ..
ChatGPT creator OpenAI has confirmed a data breach caused by a bug in an open source library, just as a cybersecurity firm noticed that a recently introduced component is affected by an actively exploited vulnerability. OpenAI said on Friday that it had taken the chatbot offline earlier in the week while it worked with the ..
Microsoft says it has evidence that Russian APT actors were exploiting a nasty Outlook zero-day as far back as April 2022, a disclosure that ups the stakes on organizations to start hunting for signs of compromise. The vulnerability, tracked as CVE-2023-23397, was flagged in the ‘already exploited’ category when Redmond shipped a fix earlier this ..
Security researchers participating in this year’s Pwn2Own software exploitation contest banked more than $1 million in prizes over three days, organizers announced over the weekend. The highest reward on the first day of the contest was earned for a TOCTOU (time-of-check to time-of-use) race condition exploit used to take full control of a Tesla vehicle. ..
More organizations are emerging to confirm impact from the newly disclosed in-the-wild zero-day exploits hitting Fortra’s GoAnywhere managed file transfer (MFT) software. Tracked as CVE-2023-0669, the vulnerability was publicly disclosed in early February alongside zero-day exploitation and a patch was released a week later. Soon after, attacks targeting the security defect were linked to a ..
Researchers at French offensive hacking shop Synacktiv have demonstrated a pair of successful exploit chains against Tesla’s newest electric car to take top billing at the annual Pwn2Own software exploitation contest. Pwn2Own organizers confirmed the successful hacks exploited flaws in the Tesla-Gateway and Tesla-Infotainment sub-systems to “fully compromise” a new Tesla Model 3 vehicle. The ..
A critical vulnerability in the open-source WooCommerce Payments plugin for WordPress could allow attackers to impersonate any user on the site and potentially take over site administrator accounts. Developed by Automattic and installed on more than 500,000 websites, the WooCommerce Payments plugin is a fully integrated payment solution for WooCommerce that provides transaction management directly ..
Security researchers have published proof-of-concept (PoC) code that provides a roadmap to exploit a recently patched high-severity vulnerability in the Veeam Backup & Replication product Earlier this month, Veeam released a patch for CVE-2023-27532 (CVSS score of 7.5), a security defect the company warned could be exploited to obtain encrypted credentials that are stored in ..


