Tag: unit 42 research
3 articles

AgentCore Harness Exposes Credential Risks
A default-enabled shell in AgentCore Harness can be exploited through prompt injection, allowing attackers to execute commands and extract plaintext credentials from the harness process memory, putting sensitive data at risk. This simple yet consequential chain highlights a critical vulnerability in credential security.

Malware Exploits Google Password Manager Flaws to Hijack Passkey Accounts
Malware on a Windows machine can secretly hijack your passkey-protected accounts, allowing hackers to sign in without needing your fingerprint, PIN, or any other verification. This shocking exploit targets Google Password Manager, revealing a vulnerability that puts your digital security at risk.

Mirai Botnet Targets TP-Link Routers via CVE-2023-33538 Exploits
Your home router could be a ticking time bomb, vulnerable to exploitation by malicious actors - in fact, a known weakness (CVE-2023-33538) in TP-Link routers has already been targeted by the notorious Mirai botnet. Is your small but mighty box at risk of becoming a launchpad for someone else's agenda?