PROJET AUTOBLOG


The Hacker News

Site original : The Hacker News

⇐ retour index

GitHub Launches AI-Powered Autofix Tool to Assist Devs in Patching Security Flaws

jeudi 21 mars 2024 à 11:30
GitHub on Wednesday announced that it's making available a feature called code scanning autofix in public beta for all Advanced Security customers to provide targeted recommendations in an effort to avoid introducing new security issues. "Powered by GitHub Copilot and CodeQL, code scanning autofix covers more than 90% of alert types in JavaScript, Typescript, Java, and

Making Sense of Operational Technology Attacks: The Past, Present, and Future

jeudi 21 mars 2024 à 10:23
When you read reports about cyber-attacks affecting operational technology (OT), it’s easy to get caught up in the hype and assume every single one is sophisticated. But are OT environments all over the world really besieged by a constant barrage of complex cyber-attacks? Answering that would require breaking down the different types of OT cyber-attacks and then looking back on all the

U.S. Sanctions Russians Behind 'Doppelganger' Cyber Influence Campaign

jeudi 21 mars 2024 à 09:07
The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) on Wednesday announced sanctions against two 46-year-old Russian nationals and the respective companies they own for engaging in cyber influence operations. Ilya Andreevich Gambashidze (Gambashidze), the founder of the Moscow-based company Social Design Agency (SDA), and Nikolai Aleksandrovich Tupikin (Tupikin), the CEO and

Ivanti Releases Urgent Fix for Critical Sentry RCE Vulnerability

jeudi 21 mars 2024 à 04:55
Ivanti has disclosed details of a critical remote code execution flaw impacting Standalone Sentry, urging customers to apply the fixes immediately to stay protected against potential cyber threats. Tracked as CVE-2023-41724, the vulnerability carries a CVSS score of 9.6. "An unauthenticated threat actor can execute arbitrary commands on the underlying operating system of the appliance

Atlassian Releases Fixes for Over 2 Dozen Flaws, Including Critical Bamboo Bug

jeudi 21 mars 2024 à 04:34
Atlassian has released patches for more than two dozen security flaws, including a critical bug impacting Bamboo Data Center and Server that could be exploited without requiring user interaction. Tracked as CVE-2024-1597, the vulnerability carries a CVSS score of 10.0, indicating maximum severity. Described as an SQL injection flaw, it's rooted in a dependency called org.postgresql: