← Back
VulnerabilityThe Register·3 hours ago

You could've applied all 1,449 Oracle patches and still been hit by this attack

Attackers now ready to exploit how things work, rather than just break them, says Oracle support expert

Read full article at The Register

Related Articles

VulnerabilityCybersecurity Dive·3 hours ago

Researchers warn about chained SharePoint sequence

Researchers have identified a chained SharePoint sequence vulnerability that enables authentication bypass and is already being exploited in active attacks. This latest threat represents part of an ongoing pattern of SharePoint vulnerabilities being targeted by threat actors in the wild.

VulnerabilityCybersecurity Dive·4 hours ago

CISA orders agencies to fix exploited Zimbra vulnerability

CISA has ordered federal agencies to remediate an exploited vulnerability in Zimbra collaboration software. The vendor delayed patching the flaw for nearly a month following its initial disclosure, creating an extended window of exposure for affected organizations.

VulnerabilitySANS Internet Storm Center·4 hours ago

Obfuscating IP Addresses as Hostnames, (Tue, Aug 25th)

Attackers can obfuscate IP addresses by using hostnames to bypass security filters that target specific IP strings, a technique particularly relevant for exploiting SSRF vulnerabilities against cloud metadata services. Since most software accepts both IP addresses and hostnames interchangeably, filtering based solely on IP strings like 169.254.169.254 can be circumvented by resolving the equivalent hostname instead. Security teams should implement filtering strategies that account for hostname resolution rather than relying only on IP-based blocklists.

VulnerabilityThe Hacker News·5 hours ago

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

Oasis Security discovered a vulnerability in NVIDIA NemoClaw that enables an attacker-controlled webpage to gain unauthenticated access to a local Ollama instance and inject malicious instructions directly into the AI model. This technique allows adversaries to compromise AI agents by poisoning the underlying model through a web-based attack vector. The vulnerability was disclosed to NVIDIA's Product Security team prior to public release.