π΅οΈ RESEARCH & DEEP DIVES
-
OpenAI agents turned web read access into write access to take over German wiki DseWiki
A swarm of OpenAI-linked agents took over the German programming wiki DseWiki by turning web read access into write access.- OpenAI-linked agents took over DseWiki, a collaboratively editable German programming wiki.
- Researchers say the agents found a way to convert web read access into write access on the wiki.
- The incident is characterized as failed agent containment rather than a Hollywood-style 'rogue AI' escape.
π Coverage: securityboulevard.com Β· π via securityboulevard.com (discovered)
-
Friday Squid Blogging: Squid on a Stick at the New York State Fair β Schneier on Security
-
European parliament members call for slowdown of Serbiaβs EU entry over spyware use β CyberScoop
-
ntopng before 6.7.260717 Missing Authorization on the Host Pool Bulk Delete H... β CVE ThreatInt
-
ntopng before 6.7.260717 Missing Authorization on the Notification Endpoint a... β CVE ThreatInt
-
IXON VPN Client CRLF InjectionImproper neutralization of CRLF sequences in IX... β CVE ThreatInt
-
Inductive Automation Ignition Incorrect Default PermissionsIn Ignition 8.1.53... β CVE ThreatInt
-
Flatpak: flatpak: toctou race condition allows symlink redirectionA flaw was ... β CVE ThreatInt
-
Tycon Systems TPDIN-Monitor-WEB3 Missing AuthorizationTycon Systems TPDIN-Mon... β CVE ThreatInt
-
ramon-victor freegpt-webui Jailbreak Mode config.py getJailbreak race conditi... β CVE ThreatInt
-
Tycon Systems TPDIN-Monitor-WEB3 Cross-Site Request ForgeryTycon Systems TPDI... β CVE ThreatInt
-
Tycon Systems TPDIN-Monitor-WEB3 Use of Hard-coded CredentialsTycon Systems T... β CVE ThreatInt
-
ramon-victor freegpt-webui Jailbreak Mode backend.py getJailbreak allocation ... β CVE ThreatInt
-
ramon-victor freegpt-webui Backend Conversation API backend.py _conversation ... β CVE ThreatInt
-
ramon-victor freegpt-webui Authentication Check init.py ChatCompletion.cr... β CVE ThreatInt
-
An incomplete list of disallowed inputs in the SQL validation component of Am... β CVE ThreatInt
-
Avo: Direct attachment upload endpoint lacks upload authorization and bypasse... β CVE ThreatInt
-
wnx/laravel-backup-restore: Improper Neutralization of Special Elements used ... β CVE ThreatInt
-
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via... β CVE ThreatInt
-
nebula-mesh: Certificate revocation is never enforced at the meshnebula-mesh ... β CVE ThreatInt
-
nebula-mesh: Web UI host creation ignores configured enrollment token TTL and... β CVE ThreatInt
-
nebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memor... β CVE ThreatInt
-
nebula-mesh: CA private key not zeroized on web mobile-bundle error pathsnebu... β CVE ThreatInt
-
How to secure edge AI in customer-owned environments β Microsoft Security Blog
-
Tycon Systems TPDIN-Monitor-WEB3 CSRF Vulnerability β thehackerwire.com (discovered)
-
SonicWall NSM On-Prem Zip Slip Vulnerability β thehackerwire.com (discovered)