generalnews.media
All World Business Technology Science Health Sports Entertainment Security
69 stories
Exclusive

OpenAI's Astra Model Shows Cyber Abilities Strong Enough to Prompt Pause

OpenAI's upcoming AI model, Astra, demonstrated cyber capabilities so powerful that they triggered a pause in its development. The move highlights growing concerns about advanced AI posing significant cybersecurity risks. This signals that even leading AI developers are wary of the offensive potential of their own systems.

Exclusive

CSS Attacks Bypass Webmail Security to Steal Passwords and Tokens

Researchers have demonstrated new CSS-based attack techniques that can evade webmail defenses, allowing attackers to exfiltrate passwords and authentication tokens. The attacks exploit how stylesheets interact with page rendering and user interaction. This is critical because webmail is a high-value target, and the technique may affect other web applications as well.

Exclusive

Metabase Zero-Day Under Active Attack Grants Unauthenticated Admin Access

A zero-day vulnerability in Metabase is being actively exploited in the wild, allowing attackers to gain administrator access without any authentication. This flaw bypasses login controls entirely, enabling full takeover of affected instances. Organizations using Metabase should apply patches or mitigations immediately.

Exclusive

WordPress Pre-Auth XSS Flaw Could Enable PHP Code Execution – Patch Now

A newly disclosed cross-site scripting vulnerability in WordPress can be exploited without authentication, potentially allowing attackers to execute arbitrary PHP code. This could lead to full site compromise, so administrators are strongly advised to apply the available patch immediately.

Exclusive

AI Tool Uncovers Novel HTTP Desync Attacks and Apache Zero-Day

Researchers using an AI-assisted tool called HTTP Terminator identified new HTTP request smuggling (desync) techniques and an Apache zero-day vulnerability. The findings expose previously unknown attack vectors in web infrastructure, underscoring AI's growing role in discovering critical security flaws.

Exclusive

NatJack Attacks Hijack TCP Sessions and Spoof DNS via NAT Table Manipulation

Researchers have uncovered a new attack technique dubbed NatJack that exploits network address translation (NAT) tables to hijack active TCP connections and spoof DNS responses. By manipulating stateful NAT devices, attackers can intercept or redirect traffic without credentials, posing a serious threat to network security. This matters because it undermines trust in standard internet connections and may affect many enterprise and home routers.

Exclusive

Malware Exploits Windows Hello for Business Keys to Maintain Entra ID Access

Researchers have identified a technique where malware abuses Windows Hello for Business keys to gain persistent access to Microsoft Entra ID, even after a user's password is reset. This allows attackers to maintain footholds in enterprise environments by leveraging legitimate authentication mechanisms. The finding highlights a critical security risk for organizations relying on passwordless identity systems.

Exclusive

Flaws in Claude Code and Gemini CLI Expose CI Secrets via GitHub Issue

Security researchers discovered vulnerabilities in Claude Code and Gemini CLI that let a specially crafted GitHub issue access secrets stored in CI workflows. The attack exploits how these developer tools handle untrusted input. This matters because compromised CI secrets could lead to supply-chain attacks or unauthorized access to cloud infrastructure.

Exclusive

TeamPCP Tied to Redis Exploits From 2020 and Later Supply Chain Attack

Security researchers have linked the threat actor TeamPCP to malicious campaigns targeting Redis databases dating back to 2020. The group later leveraged this activity to support a broader supply chain intrusion effort. The findings underscore the persistent and evolving threat that TeamPCP poses to cloud infrastructure and downstream software ecosystems.