Wednesday Updates
What’s up today ?
- Discovered Checkpoint Research : They publish cool research findings I came across one research about “The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT” Read full report here
- DUSTMAKER (successor to the SANDCLOCK) is a cross-platform JavaScript payload optimized for CI/CD pipelines. It does not contain container escape functinoality and while some variants have targeted cryptocurrency wallets, its overall focus is credential theft to facilitate extortion operations.
Cyber Security Products
- Recently got a notification in pwnspectrum about N-able, that said N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution.. I am now interested to know what is this N-able. This is what they offer:
- Endpoint Management, Patch Management, Vulnerability Management.
- Penetration Testing: Ingest data from logs, endpoints, cloud, DNS —> Detects blind spots, investigate incidendts —> Uses AI detection engine to identify patterns singaling real attack + Dark Net Monitoring.
- XDR Platform:
- Sophos: A cyber defense system.
Crazy Things I read
- Microsoft has added age-awareness APIs that can tell if users are children, teens or adults.
- Security researchers have unveiled InjectEave, an electromagnetic side-channel attack that can turn ordinary headphones into unintended transmitters.
Ideas
- Explore how Zero Click Attacks / Exploits work and create one may be ?