PoC exploit released for vulnerabilities in Ivanti Endpoint Manager
Researchers found four critical Ivanti EPM vulnerabilities allowing unauthenticated attackers to exploit machine credentials for relay attacks. Patched in January 2025 after discovery in October 2024. All about the Ivanti [...]
New LLM Vulnerability Puts AI Models Like ChatGPT at Risk
A newly discovered vulnerability in LLMs like ChatGPT raises concerns about adversarial attacks, where techniques like prompt injection can manipulate outputs or expose sensitive data. All about LLM Vulnerability Prompt [...]
Researchers Seek to Strengthen MITRE ATT&CK Against New Threats
A recent study from the National University of Singapore and NCS Cyber Special Ops R&D examines how to improve the MITRE ATT&CK framework to address evolving cyber threats, based on [...]
Obfuscated .NET sectopRAT mimics a Chrome extension
SectopRAT (Arechclient2) is a highly obfuscated .NET-based Remote Access Trojan (RAT). Researchers recently found it posing as a fake Google Docs Chrome extension, enhancing its stealth and data-theft capabilities. Obfuscated [...]
Malware on WordPress sites lets hackers run remote code
Researchers found malware targeting WordPress sites, using backdoors for remote code execution. The attacks exploit vulnerabilities, highlighting the need for better security. WordPress Vulnerabilities Attackers placed malicious scripts in the [...]