Aggregator
Hackers Compromise 170 npm Packages to Steal GitHub, npm, AWS, and Kubernetes Secrets
A sprawling supply chain attack has put software developers worldwide on high alert after hackers compromised more than 170 npm packages and two PyPI packages in a coordinated credential theft campaign. The infected packages are collectively downloaded over 200 million times per week, making the potential blast radius enormous. The threat group behind the campaign, […]
The post Hackers Compromise 170 npm Packages to Steal GitHub, npm, AWS, and Kubernetes Secrets appeared first on Cyber Security News.
Xacria XNO Allegedly Breached: 446 Service Orders and Subscriber PII Exposed From the Italian Carrier-Grade Telecom Network Orchestration Platform Used by FASTWEB and SKY ITALIA
То, что скрыто от глаз, выдают звуки. Учёные создали робота для поиска жизни внутри рифов
CVE-2016-10161 | PHP up to 5.6.29/7.0.14/7.1.0 var_unserializer.c object_common1 out-of-bounds (RHSA-2018:1296 / Nessus ID 96799)
CVE-2016-10162 | PHP up to 7.0.14/7.1.0 ext/wddx/wddx.c php_wddx_pop_element null pointer dereference (RHSA-2018:1296 / Nessus ID 96800)
CVE-2016-8214 | EMC Avamar Data Store/Avamar Virtual Edition 7.3.0/7.3.1 permission (Nessus ID 96956 / BID-95719)
CVE-2016-8215 | EMC RSA Security Analytics 10.5.3/10.6.2 cross site scripting (BID-95718 / ID 1037666)
CVE-2016-9303 | Autodesk FBX-SDK prior 2017.1 FBX File memory corruption (BID-95805)
CVE-2016-9304 | Autodesk FBX-SDK prior 2017.1 DFX File Converter memory corruption (BID-95799)
CVE-2016-9305 | Autodesk FBX-SDK prior 2017.1 FBX File Converter uninitialized Pointer data processing (BID-95803)
CVE-2016-9306 | Autodesk FBX-SDK prior 2017.1 DAE File Converter memory corruption (BID-95807)
CVE-2016-9307 | Autodesk FBX-SDK prior 2017.1 3DS File Converter memory corruption (BID-95802)
CVE-2017-5594 | Pagekit CMS up to 1.0.10 Debug Toolbar Password password recovery (EDB-41143 / BID-95806)
CVE-2016-10160 | Apple macOS up to 10.12.3 apache_mod_php memory corruption (HT207615 / Nessus ID 97052)
CVE-2016-10161 | Apple macOS up to 10.12.3 apache_mod_php out-of-bounds (HT207615 / Nessus ID 97052)
Critical Canon MailSuite Vulnerability Enables Remote Code Execution Attacks
Enterprise email infrastructure remains one of the most critical and vulnerable targets for cybercriminals. A highly severe security flaw has just been discovered in Canon’s GUARDIANWALL MailSuite, exposing corporate networks to devastating Remote Code Execution (RCE) attacks. Threat actors can easily exploit this newly disclosed vulnerability to seize complete control over affected web services, making […]
The post Critical Canon MailSuite Vulnerability Enables Remote Code Execution Attacks appeared first on Cyber Security News.
TeamPCP and BreachForums Hackers Running $1,000 Contest for Supply Chain Attacks
The cybercrime underworld is turning open-source supply chain attacks into a twisted competition. After months of infiltrating security tools and CI/CD pipelines, the notorious hacking group TeamPCP has partnered with BreachForums to launch a disturbing new contest. The objective is to compile as many open-source packages as possible. The prize, however, is a surprisingly small […]
The post TeamPCP and BreachForums Hackers Running $1,000 Contest for Supply Chain Attacks appeared first on Cyber Security News.