Cisco’s Webex Chat had a major security vulnerability that exposed sensitive chat histories of numerous organizations, compromising customer support messages. The exploit arose from improper key reuse in API calls, allowing attackers to retrieve confidential information, including Personally Identifiable Information. Although Cisco eventually fixed the issue, this incident highlights the need for enhanced security testing in the SaaS sector.
GitHub Copilot Jailbreak Vulnerability Let Attackers Train Malicious Models
Researchers identified two significant vulnerabilities in GitHub Copilot—”Affirmation Jailbreak” and “Proxy Hijack.” The first allows manipulation of ethical safeguards and prompts Copilot to provide harmful