PROJET AUTOBLOG


The Hacker News

Site original : The Hacker News

⇐ retour index

CISA Warns of Flaws in Siemens, GE Digital, and Contec Industrial Control Systems

mercredi 18 janvier 2023 à 06:56
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published four Industrial Control Systems (ICS) advisories, calling out several security flaws affecting products from Siemens, GE Digital, and Contec. The most critical of the issues have been identified in Siemens SINEC INS that could lead to remote code execution via a path traversal flaw (CVE-2022-45092, CVSS score: 9.9)

CISA Warns of Flaws in Siemens, GE Digital, and Contec Industrial Control Systems

mercredi 18 janvier 2023 à 06:56

Microsoft Azure Services Flaws Could've Exposed Cloud Resources to Unauthorized Access

mardi 17 janvier 2023 à 15:12
Four different Microsoft Azure services have been found vulnerable to server-side request forgery (SSRF) attacks that could be exploited to gain unauthorized access to cloud resources. The security issues, which were discovered by Orca between October 8, 2022 and December 2, 2022 in Azure API Management, Azure Functions, Azure Machine Learning, and Azure Digital Twins, have since been addressed

Microsoft Azure Services Flaws Could've Exposed Cloud Resources to Unauthorized Access

mardi 17 janvier 2023 à 15:12

Hackers Can Abuse Legitimate GitHub Codespaces Feature to Deliver Malware

mardi 17 janvier 2023 à 13:45
New research has found that it is possible for threat actors to abuse a legitimate feature in GitHub Codespaces to deliver malware to victim systems. GitHub Codespaces is a cloud-based configurable development environment that allows users to debug, maintain, and commit changes to a given codebase from a web browser or via an integration in Visual Studio Code. It also comes with a port