A Rails CVE got exploited the same day it was patched
A government Rails site was compromised hours after the CVE-2024-28103 patch dropped. The attackers were watching the release notes.
From the notebook
6 notes on this topic.
A government Rails site was compromised hours after the CVE-2024-28103 patch dropped. The attackers were watching the release notes.
Zapscape is a guest-to-host escape for KVM on x86. It lets a compromised VM run code on the host machine, which is the nightmare scenario for cloud providers.
Someone is flooding the National Vulnerability Database with fake SQLite vulnerabilities written by language models, and it is breaking actual security work.
Fifteen years of a compartmentalised desktop OS, zero remote code execution bugs. The paper tracking every public Qubes vulnerability is out.
Ivanti Sentry got a pre-auth RCE with the maximum theoretical severity score. Public exploit code is already live.
Mythos discovered a vulnerability that was already documented in the data it was trained on. The industry is calling this autonomous discovery.