Vulnerabilities (2)
Researchers at Adversa AI discovered a major flaw in GPT-5's internal routing system that creates serious security risks. When users ask GPT-5 questions, an internal router decides which model actually responds – it might be GPT-5 Pro, but could equally be older versions like GPT-3.5 or GPT-4o.
Hackers can manipulate this router using specific trigger phrases, forcing queries to weaker, less secure models that are easier to jailbreak. This "PROMISQROUTE" vulnerability means GPT-5 is only as secure as its weakest predecessor.
While the routing saves costs and improves speed, it allows old jailbreaks to work again by targeting vulnerable older models instead of GPT-5's stronger safeguards.
Source: Security Week
Researchers at Adversa AI discovered a major flaw in GPT-5's internal routing system that creates serious security risks. When users ask GPT-5 questions, an internal router decides which model actually responds – it might be GPT-5 Pro, but could equally be older versions like GPT-3.5 or GPT-4o.
Hackers can manipulate this router using specific trigger phrases, forcing queries to weaker, less secure models that are easier to jailbreak. This "PROMISQROUTE" vulnerability means GPT-5 is only as secure as its weakest predecessor.
While the routing saves costs and improves speed, it allows old jailbreaks to work again by targeting vulnerable older models instead of GPT-5's stronger safeguards.
Source: Security Week
China is demanding Nvidia prove its H20 AI chips don't contain backdoors or security flaws, escalating tensions in the global chip trade. Chinese state media warned that backdoor risks could become Nvidia's "self-dug grave," potentially driving away customers worldwide who fear remote shutdowns or data theft.
This comes after the Trump administration recently allowed less sophisticated AI chip exports to China with a 15% fee, reversing stricter 2022 restrictions. Nvidia's chief security officer firmly denied any backdoors exist in their chips, calling such claims harmful to global digital infrastructure.
The dispute reflects deeper US-China tensions over AI technology and national security, with China working to build its own chip ecosystem while reportedly obtaining 140,000 AI chips despite previous US bans.
Source: Dark Reading
China is demanding Nvidia prove its H20 AI chips don't contain backdoors or security flaws, escalating tensions in the global chip trade. Chinese state media warned that backdoor risks could become Nvidia's "self-dug grave," potentially driving away customers worldwide who fear remote shutdowns or data theft.
This comes after the Trump administration recently allowed less sophisticated AI chip exports to China with a 15% fee, reversing stricter 2022 restrictions. Nvidia's chief security officer firmly denied any backdoors exist in their chips, calling such claims harmful to global digital infrastructure.
The dispute reflects deeper US-China tensions over AI technology and national security, with China working to build its own chip ecosystem while reportedly obtaining 140,000 AI chips despite previous US bans.
Source: Dark Reading
Microsoft's August 2025 Patch Tuesday addresses 111 vulnerabilities, with 44 elevation-of-privilege (EoP) flaws that let attackers escalate from initial access to full system control. The update marks the second consecutive month with no actively exploited bugs.
Key concerns include a maximum-severity Azure OpenAI vulnerability (already mitigated by Microsoft), the publicly known "BadSuccessor" Windows Kerberos flaw, and four critical SQL Server bugs enabling injection attacks. The patch also fixes 34 remote code execution vulnerabilities and 16 information disclosure issues.
Security researchers highlight two near-maximum severity flaws: CVE-2025-50165 in Windows Graphics and CVE-2025-53766 in GDI+, both exploitable without user interaction. Organizations should prioritize patching SharePoint, SQL Server, and graphics-related vulnerabilities immediately.
Source: Dark Reading
Microsoft's August 2025 Patch Tuesday addresses 111 vulnerabilities, with 44 elevation-of-privilege (EoP) flaws that let attackers escalate from initial access to full system control. The update marks the second consecutive month with no actively exploited bugs.
Key concerns include a maximum-severity Azure OpenAI vulnerability (already mitigated by Microsoft), the publicly known "BadSuccessor" Windows Kerberos flaw, and four critical SQL Server bugs enabling injection attacks. The patch also fixes 34 remote code execution vulnerabilities and 16 information disclosure issues.
Security researchers highlight two near-maximum severity flaws: CVE-2025-50165 in Windows Graphics and CVE-2025-53766 in GDI+, both exploitable without user interaction. Organizations should prioritize patching SharePoint, SQL Server, and graphics-related vulnerabilities immediately.
Source: Dark Reading
Cybercriminals are abusing Microsoft 365's Direct Send feature to bypass email security and send phishing emails that appear to come from internal users. The technique exploits a legitimate feature designed for printers and scanners, allowing attackers to evade authentication protocols like SPF, DKIM, and DMARC.
Security firm StrongestLayer documented successful attacks targeting HR, finance, and executive personnel. Multiple vendors report widespread campaigns affecting over 70 organizations since May, primarily in US financial services, manufacturing, and healthcare sectors.
Microsoft has acknowledged the issue and introduced detection options, but experts recommend disabling Direct Send and implementing strict DMARC policies.
Source: Dark Reading
Cybercriminals are abusing Microsoft 365's Direct Send feature to bypass email security and send phishing emails that appear to come from internal users. The technique exploits a legitimate feature designed for printers and scanners, allowing attackers to evade authentication protocols like SPF, DKIM, and DMARC.
Security firm StrongestLayer documented successful attacks targeting HR, finance, and executive personnel. Multiple vendors report widespread campaigns affecting over 70 organizations since May, primarily in US financial services, manufacturing, and healthcare sectors.
Microsoft has acknowledged the issue and introduced detection options, but experts recommend disabling Direct Send and implementing strict DMARC policies.
Source: Dark Reading
SonicWall is investigating a potential zero-day vulnerability after a surge in ransomware attacks targeting its firewalls since mid-July. Google's threat intelligence team first spotted the campaign, where hackers deployed a new backdoor called Overstep on fully patched devices. The attacks affect Gen 7 SonicWall firewalls with SSLVPN enabled, particularly TZ and NSa-series models running firmware 7.2.0-7015 or earlier.
What's alarming: attackers bypassed multi-factor authentication and reached domain controllers within hours. SonicWall recommends immediately disabling SSLVPN services, limiting connectivity to trusted IPs, and updating all passwords while the investigation continues.
Source: Security Week
SonicWall is investigating a potential zero-day vulnerability after a surge in ransomware attacks targeting its firewalls since mid-July. Google's threat intelligence team first spotted the campaign, where hackers deployed a new backdoor called Overstep on fully patched devices. The attacks affect Gen 7 SonicWall firewalls with SSLVPN enabled, particularly TZ and NSa-series models running firmware 7.2.0-7015 or earlier.
What's alarming: attackers bypassed multi-factor authentication and reached domain controllers within hours. SonicWall recommends immediately disabling SSLVPN services, limiting connectivity to trusted IPs, and updating all passwords while the investigation continues.
Source: Security Week
Apple released security updates Tuesday fixing dozens of vulnerabilities, including CVE-2025-6558, a bug already exploited against Chrome users. Google patched this flaw in Chrome 138 last July after discovering active attacks targeting its graphics components. The vulnerability lets attackers escape browser sandboxes through malicious web pages.
Apple's updates cover iOS 18.6, macOS Sequoia 15.6, and other platforms, patching 87 CVEs in macOS alone. While there's no evidence Safari users were targeted, the flaw could crash the browser when visiting malicious sites. CISA previously flagged this as a critical threat requiring federal agencies to patch by August 12.
Source: Security Week
Apple released security updates Tuesday fixing dozens of vulnerabilities, including CVE-2025-6558, a bug already exploited against Chrome users. Google patched this flaw in Chrome 138 last July after discovering active attacks targeting its graphics components. The vulnerability lets attackers escape browser sandboxes through malicious web pages.
Apple's updates cover iOS 18.6, macOS Sequoia 15.6, and other platforms, patching 87 CVEs in macOS alone. While there's no evidence Safari users were targeted, the flaw could crash the browser when visiting malicious sites. CISA previously flagged this as a critical threat requiring federal agencies to patch by August 12.
Source: Security Week
The Cybersecurity and Infrastructure Security Agency has added a cross-site request forgery vulnerability in PaperCut NG/MF print management software to its Known Exploited Vulnerabilities catalog. The flaw is currently being exploited by attackers in the wild.
CISA is requiring all federal agencies to patch their systems immediately to prevent potential security breaches. PaperCut NG/MF is widely used across government and enterprise environments for managing printing services, making this vulnerability particularly concerning for organizations running unpatched versions of the software.
Source: The Hacker News
The Cybersecurity and Infrastructure Security Agency has added a cross-site request forgery vulnerability in PaperCut NG/MF print management software to its Known Exploited Vulnerabilities catalog. The flaw is currently being exploited by attackers in the wild.
CISA is requiring all federal agencies to patch their systems immediately to prevent potential security breaches. PaperCut NG/MF is widely used across government and enterprise environments for managing printing services, making this vulnerability particularly concerning for organizations running unpatched versions of the software.
Source: The Hacker News
CISA issued urgent security advisories Thursday covering vulnerabilities in devices from Honeywell, Medtronic, Mitsubishi, LG, and Network Thermostat that could allow attackers to execute malicious code or gain administrative access. The flaws affect critical infrastructure including manufacturing equipment, WiFi thermostats in commercial buildings, patient monitors, and security cameras.
Most concerning is a Network Thermostat vulnerability (CVE-2025-6260) with a 9.8 severity score that lets attackers reset credentials remotely. Medtronic's patient monitors contain three vulnerabilities requiring physical access, while Mitsubishi's manufacturing equipment faces DLL hijacking risks. Companies have released patches for most devices, though some older products won't receive fixes.
Source: Industrial Cyber
CISA issued urgent security advisories Thursday covering vulnerabilities in devices from Honeywell, Medtronic, Mitsubishi, LG, and Network Thermostat that could allow attackers to execute malicious code or gain administrative access. The flaws affect critical infrastructure including manufacturing equipment, WiFi thermostats in commercial buildings, patient monitors, and security cameras.
Most concerning is a Network Thermostat vulnerability (CVE-2025-6260) with a 9.8 severity score that lets attackers reset credentials remotely. Medtronic's patient monitors contain three vulnerabilities requiring physical access, while Mitsubishi's manufacturing equipment faces DLL hijacking risks. Companies have released patches for most devices, though some older products won't receive fixes.
Source: Industrial Cyber
A Chinese cyberespionage group called Fire Ant has been targeting VMware and F5 vulnerabilities to breach supposedly secure, isolated networks. The hackers exploited critical flaws like CVE-2023-34048 in vCenter Server and CVE-2023-20867 in ESXi to gain complete control over virtualization infrastructure. They then used compromised systems as stepping stones to access guest virtual machines and tunnel between network segments that should've been separated.
Cybersecurity firm Sygnia found the group shows remarkable persistence, quickly adapting when defenders try to kick them out by deploying backup backdoors and changing tactics. The attack methods strongly resemble those used by another Chinese group, UNC3886.
Source: SecurityWeek
A Chinese cyberespionage group called Fire Ant has been targeting VMware and F5 vulnerabilities to breach supposedly secure, isolated networks. The hackers exploited critical flaws like CVE-2023-34048 in vCenter Server and CVE-2023-20867 in ESXi to gain complete control over virtualization infrastructure. They then used compromised systems as stepping stones to access guest virtual machines and tunnel between network segments that should've been separated.
Cybersecurity firm Sygnia found the group shows remarkable persistence, quickly adapting when defenders try to kick them out by deploying backup backdoors and changing tactics. The attack methods strongly resemble those used by another Chinese group, UNC3886.
Source: SecurityWeek
CISA has mandated that US federal agencies urgently patch two critical Microsoft SharePoint vulnerabilities (CVE-2025-49706 and CVE-2025-49704) by July 23, following attacks by Chinese hackers. These flaws allow unauthorized access and remote code execution on SharePoint servers. Microsoft has released updates, urging all users to patch immediately.
Security experts warn of risks like data theft and persistent access. The directive underscores the persistent threat from APT groups, stressing the importance of swift patch management to protect government and critical infrastructure from cyber threats.
Source: The Hacker News
CISA has mandated that US federal agencies urgently patch two critical Microsoft SharePoint vulnerabilities (CVE-2025-49706 and CVE-2025-49704) by July 23, following attacks by Chinese hackers. These flaws allow unauthorized access and remote code execution on SharePoint servers. Microsoft has released updates, urging all users to patch immediately.
Security experts warn of risks like data theft and persistent access. The directive underscores the persistent threat from APT groups, stressing the importance of swift patch management to protect government and critical infrastructure from cyber threats.
Source: The Hacker News