James Forshaw from Google Project Zero revealed a critical Windows vulnerability in accessing COM objects via the IDispatch interface. This flaw allows attackers to exploit remoting technologies for executing code in higher-privileged server processes. Despite improvements in type library validation, risks remain, emphasizing the need for secure handling of objects across process boundaries in complex systems.
GitHub Copilot Jailbreak Vulnerability Let Attackers Train Malicious Models
Researchers identified two significant vulnerabilities in GitHub Copilot—”Affirmation Jailbreak” and “Proxy Hijack.” The first allows manipulation of ethical safeguards and prompts Copilot to provide harmful