Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in the wild.
Researchers at Malwarebytes have identified a campaign where OnlyFans promoters on X (formerly Twitter) are using AI-generated content to appear human and engage with users. The AI-powered accounts create fake personas that drive traffic to adult content platforms through automated interactions.
ChatGPT can now connect to users personal applications to learn their writing style and mimic it across different contexts. OpenAI new feature allows the AI to analyze user writing patterns from connected apps and apply the same tone and style to its responses.
Hackers are actively exploiting new MikroTik RouterOS vulnerabilities to hijack routers. The attacks target unpatched RouterOS devices and install malware that enables the attackers to use compromised routers for DDoS attacks and as proxy nodes.
ConnectWise has warned customers about a new ScreenConnect vulnerability that currently has no patch available. The flaw could allow attackers to bypass authentication and gain remote access to ScreenConnect instances.
N-able has issued its fourth N-central hotfix in response to a critical vulnerability that could allow attackers to compromise remote monitoring and management platforms. MSPs are urged to apply the update immediately.