Re: Vulnerabilities in libheif and libde265
Posted by Hanno Böck on Sep 22 libheif has released another update with various security fixes: https://github.com/strukturag/libheif/releases/tag/v1.23.5 Pasting the relevant part of the release…
Coverage tagged "GitHub".
Posted by Hanno Böck on Sep 22 libheif has released another update with various security fixes: https://github.com/strukturag/libheif/releases/tag/v1.23.5 Pasting the relevant part of the release…
Operation Conflict Compass: Konni Targets Ukraine via Malicious LNK Lures Since 2009, the Democratic People’s Republic of Korea (DPRK) has fully integrated cyber operations into its national…
A Veeam Agent flaw lets local users gain SYSTEM privileges. A public PoC is available, raising the risk of exploitation on shared Windows systems. If you’re running Veeam Agent on a Windows endpoint…
We’ve heard of OpenAI’s AI agents running amok and hacking other companies. Now, a cybersecurity company has turned the tables on the ChatGPT operator by using AI to help hack OpenAI itself. The…
arXiv:2609.22510v1 Announce Type: new Abstract: As LLM applications integrate with external tools, they are increasingly exposed to indirect prompt injection (IPI), where adversarial instructions are…
Posted by Tomas Hoger on Sep 21 Is GitHub going to assign a CVE here? I think GitHub assignment would be ok per this part of the GitHub CNA scope definition: "vulnerabilities affecting open source…
A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads…
We explore how AWS neutralizes exposed IAM credentials using managed policies, detailing GitHub secret scanning and CloudTrail monitoring strategies.
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
# **Equation of Compromise: Anatomy of a Live npm Supply-Chain Campaign**  Over the past week, several vendors have reported on…
Posted by Rainer Gerhards on Sep 20 Hello, We are publishing a GitHub Security Advisory for a denial-of-service vulnerability in the rsyslog mmpstrucdata module…
Release: datasette-auth-github 1.0 I run this GitHub login plugin on the agent.datasette.io demo site and I noticed that my authenticated sessions weren't lasting very long.
Posted by Hanno Böck on Sep 19 Hi, Not sure if related, but this very recent commit https://github.com/strukturag/libheif/commit/6ce2bba558a27b63a508e81c085025f91c89899b sounds like it could be…
AI helped researchers exploit a Discourse flaw in under 72 hours, hijacking OpenAI staff accounts and exposing the risks of shared SSO. Three researchers at Hacktron just took over ChatGPT and Codex…
An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18. The French security company had…
Researchers said they used Anthropic’s Claude and OpenAI’s Codex to identify a damaging flaw embedded in a popular software decoding tool that could leave major internet platforms, enterprise…
Talk about your competitor getting through the door. Security researchers used Anthropic's Claude to help hack into OpenAI employees’ ChatGPT accounts. A trio of bug hunters researching frontier AI…
Executive Summary Following disclosure of the TraderTraitor attack against LayerZero in April 2026, SentinelOne identified an additional victim with the same macOS backdoors. Our analysis explores…
The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India…
An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel.