#Radware

PressMind Labspressmind
2026-01-09

ZombieAgent atakuje ChatGPT – kolejna luka w systemie AI ujawniona

Czy można naprawić sztuczną inteligencję, która z natury chce każdemu dogodzić? Nowy atak na ChatGPT pokazuje, że kiedy stawiamy wyższą barierkę, ktoś po prostu znajduje dłuższą drabinę.

Czytaj dalej:
pressmind.org/zombieagent-atak

Ilustracja przedstawiająca postać wykradającą dane z interfejsu ChatGPT w mrocznym otoczeniu.
Tecnoblog • tecnologia que interessatecnoblog.net@web.brid.gy
2025-09-22
<figure class="wp-block-image size-large wp-lightbox-container"><img alt="Arte com o logotipo da OpenAI. À direita, há a imagem da sombra de uma pessoa mexendo em um celular. Na parte inferior direita, está o logotipo do Tecnoblog." class="wp-image-844948" height="596" src="https://files.tecnoblog.net/wp-content/uploads/2025/08/openai-4_capa-edited-1060x596.png" width="1060" /><button class="lightbox-trigger" type="button">
			<svg fill="none" height="12" viewBox="0 0 12 12" width="12" xmlns="http://www.w3.org/2000/svg">
				<path d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z" fill="#fff">
			</svg>
		</button><figcaption class="wp-element-caption">ChatGPT foi usado em teste de ataque para extrair dados de emails (ilustração: Vitor Pádua/Tecnoblog)</figcaption></figure>


<details class="tb-resumo tb-callout padrao">
    Resumo
    <div class="tb-resumo-topicos tb-callout-texto"><ul>
<li>Pesquisadores da Radware realizaram o ataque Shadow Leak, que usou injeção de prompts para extrair dados do Gmail.</li>
<li>A vulnerabilidade explorava a ferramenta Deep Research do ChatGPT, permitindo a execução de instruções ocultas para acessar dados sigilosos.</li>
<li>O problema, comunicado à OpenAI em junho, já foi resolvido, mas também poderia comprometer serviços como o Outlook e Google Drive.</li>
</ul>
</div>
</details
Security Landsecurityland
2025-09-19

A devastating security flaw has been discovered in OpenAI’s ChatGPT that could silently steal your Gmail data without you ever knowing. Security firm Radware has uncovered what they’re calling “ShadowLeak”.

Read More: security.land/zero-click-chatg

Glesecglesec
2025-08-27

GLESEC expands its SKYWATCH™ Cloud Application Protection (CAP) with advanced integrations from Radware & Cymulate, delivering stronger security, smarter automation, and real-time risk management for regulated industries.

🔗 Know more : glesec.com/glesec-expands-cap-

2025-08-20

Apparently the proud owner of that industrial disaster that is validate.perfdrive.com is #Radware.

Maybe that one or another of their "solutions": radware.com/products/bot-manag

✨ 💩 ✨ 🤡 ✨ ✨ 💥 ✨ ☣ ✨ 🤪 ✨

2025-06-25

Your firewall won’t save you from this…

Watch the YouTube Video Here: youtu.be/PznT8uDWKEA

Sponsored by Radware
#Radware

Security Landsecurityland
2025-05-08

🚨 Radware Cloud WAF flaws let attackers bypass filters. Learn about CVE-2024-56523 & 56524 and secure your systems now.

Read More: security.land/critical-securit

Jezus Michał "Le Wzdych" (on)mgorny@pol.social
2024-08-19

Jeżeli wnerwia was #CloudFlare, powinniście spróbować użyć strony "chronionej" przez #RadWare.

Tak więc #PLk wymyśliło sobie, że ichni "Portal Pasażera" będzie chroniony tym gównem. W praktyce oznacza to, że ilekroć chcę sprawdzić połączenie, zaczynam wpisywać dane i nagle zostaję przekierowany na "weryfikację". Po chwili weryfikacja przechodzi pomyślnie i mogę zacząć wpisywać od nowa.

Po 4 czy 5 wyszukiwaniach strona nagle decyduje, że znów trzeba mnie "zweryfikować". Tyle że tym razem weryfikacja się po prostu wiesza. Karta Firefoksa praktycznie przestaje odpowiadać, kręciołek rusza się co parę minut i wszystko wskazuje na to, że ich durne skrypty traktują moją przeglądarkę DoS-em.

Mogę zacząć używać jej znów, jeżeli wyczyszczę wszystkie ciasteczka. Czy ja wspominałem, że rzekomo "odrzuciłem wszystkie ciastka"?

#kolej #PKP #Firefox

Jesus Michał "Le Sigh" 🏔 (he)mgorny@treehouse.systems
2024-08-19

If you're annoyed by #CloudFlare, you should really try using a site "protected" by #RadWare.

So PLK, the company providing an official "passenger's portal" for Polish railways, decided to protect that site with that crap. This means that whenever I need to look up the train, as soon as I start typing data, I'm getting a sudden redirect to "verification". It passes, and I have to start typing everything again.

Then, after doing 4 or 5 searches, the site suddenly decides I need to be "verified" again. Except that this time the verification process just hangs. The #Firefox tab becomes almost unresponsive, the throbber barely updates every few seconds and it looks like they are simply DoS-ing my browser.

Then I can start using it again if I clear all the cookies. Did I mention that I've clicked "reject all cookies"?

#rail

PortalGeekportalgeekco
2024-03-06

Radware informó que las transacciones maliciosas de aplicaciones web y API aumentan un 171%
@radware

portalgeek.co/2024/03/radware-

Edwin Groothuismavetju@aus.social
2023-02-10

#Radware Alteon Load balancers are not sending the Request Context field in their TLSv1.3 Server Handshake Header Certificate PDU. As such the client will terminate the TLS handshake.

#Wireshark (You need the latest 4.1 dev version for this) will complain about it too, stating that the Certificates Length field is too big.

2020-10-15

Кибервымогатели требуют от компаний деньги и угрожают DDoS-атаками #DDoS-атака, #Travelex, #Radware, #Intel471, #вымогательство securitylab.ru/news/513096.php twitter.com/SecurityLabnews/st

2020-05-28

Inside the Hoaxcalls Botnet: Both Success and Failure - The DDoS group sets itself apart by using exploits -- but it doesn't always pan out. more: threatpost.com/inside-hoaxcall #symantecwebgateway #abandonedexploits #vulnerabilities #malwareanalysis #websecurity #grandstream #hoaxcalls #exploits #failures #takedown #malware #draytek #radware #botnet #zyxel #ddos #iot

2020-04-29

ThreatList: Human-Mimicking Bots Spike, Targeting e-Commerce and Travel - Overall bot activity on the web has soared, with a 26 percent growth rate -- attacks on applicatio... more: threatpost.com/threatlist-bots #mostrecentthreatlists #detectionevasion #trafficanalysis #webapplications #sophistication #topverticals #websecurity #e-commerce #threatlist #thereport #analysis #research #attacks #radware #badbot #growth #bots

2020-04-22

Fast-Moving DDoS Botnet Exploits Unpatched ZyXel RCE Bug - The rapidly evolving Hoaxcalls botnet is exploiting an unpatched vulnerability in the ZyXEL Cloud ... more: threatpost.com/fast-moving-ddo #cloudcnmsecumanager #cloudcommunication #denialofservice #malwareanalysis #uncategorized #vulnerability #appliance #hoaxcalls #unpatched #radware #botnet #mirai #zyxel #ddos #xtc

2019-11-11

DDoS Attacks Target Amazon, SoftLayer and Telecom Infrastructure - The specific type of TCP attack used in the recent spate of DDoS efforts were TCP SYN-ACK reflecti... more: threatpost.com/massive-ddos-am #tcpreflectionattacks #telecomnetworks #websecurity #october2019 #radware #amazon #ddos

2019-10-28

Cybercriminals Impersonate Russian APT ‘Fancy Bear’ to Launch DDoS Attacks - Attacks are targeting international companies in the financial sector, demanding that victims pay ... more: threatpost.com/cybercriminals- #electionhacking #financialsector #junipernetworks #impersonation #websecurity #fancybear #election #group-ib #malware #bitcoin #radware #link11 #ransom #russia #ddos #apt

Greenieamigiac
2018-01-07

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst