Security Practitioner

SEARCH

CATEGORIES

TAGS

    Exploiting File Read Vulnerabilities in Gradio to Steal Secrets from Hugging Face Spaces

    June 14, 2024
    This post walks through the vulnerabilities we disclosed affecting Gradio, and our work with Hugging Face to harden the Spaces platform after a recently reported potential breach.

    Fireside Chat: Horizon3.ai and LYT.

    DoD supply chain cyber threats are surging. Learn how CAPT helps suppliers find, fix & verify gaps with scalable, autonomous security testing.

    Get Ahead of Emerging Threats with Horizon3.ai’s Rapid Response Service

    April 30, 2024
    In the ever-evolving landscape of cybersecurity, the speed of your response to emerging cyber threats can be the difference between a minor security incident and a catastrophic breach. Horizon3.ai provides you with a strategic advantage by enabling preemptive action in the steadily shrinking window of time between the public disclosure of a vulnerability and its…

    Fix What Matters: Accelerating Cyber Defense Through the Eyes of an Attacker

    April 30, 2024
    The emergence of new attack vectors, the steady growth of attack surfaces, and the increasing speed at which vulnerabilities are exploited underscore the critical need for proactive defense strategies.

    Fortifying the Chain: A Proven Strategy for Supply Chain Defense

    April 24, 2024
    Understanding the Landscape of Cyber Threats and the Innovations in Third-Party Risk Management

    No waiting, no wondering: Streamline your PCI pentesting process with Horizon3.ai

    Demand for #pentesting expertise is at an all-time high, and many orgs are struggling to meet their annual requirements for the PCI DSS v4.0. This webinar explains how our services fulfill your pentesting requirements and help you streamline your remediation efforts.

    CVE-2023-48788: Fortinet FortiClient EMS SQL Injection Deep Dive

    March 21, 2024
    Introduction In a recent PSIRT, Fortinet acknowledged CVE-2023-48788 - a SQL injection in FortiClient EMS that can lead to remote code execution. FortiClient EMS is an endpoint management solution for enterprises that provides a central location for administering enrolled endpoints. This SQL injection vulnerability is caused by user controlled strings that are passed directly into…

    Fortinet FortiWLM Deep-Dive, IOCs, and the Almost Story of the “Forti Forty”

    March 14, 2024
    Early in 2023, soon after reproducing a remote code execution vulnerability for the Fortinet FortiNAC, I was on the hunt for a set of new research targets. Fortinet seemed like a decent place to start given the variety of lesser-known security appliances I had noticed while searching for the FortiNAC firmware. The first target I…

    NextChat: An AI Chatbot That Lets You Talk to Anyone You Want To

    March 11, 2024
    NextChat a.k.a ChatGPT-Next-Web, a popular Gen AI ChatBot, is vulnerable to a critical server-side request forgery (SSRF) vulnerability.

    What’s the true impact on your organization when an employee is phished?

    You can now fully assess the impact of phished credentials on your organization. Tune into this webinar to watch the NodeZero platform evaluating the blast radius of every phished credential as it comes in using the Phishing Impact test.