PROJET AUTOBLOG


The Hacker News

Site original : The Hacker News

⇐ retour index

Malware Strains Targeting Python and JavaScript Developers Through Official Repositories

mardi 13 décembre 2022 à 08:00
An active malware campaign is targeting the Python Package Index (PyPI) and npm repositories for Python and JavaScript with typosquatted and fake modules that deploy a ransomware strain, marking the latest security issue to affect software supply chains. The typosquatted Python packages all impersonate the popular requests library: dequests, fequests, gequests, rdquests, reauests, reduests,

Malware Strains Targeting Python and JavaScript Developers Through Official Repositories

mardi 13 décembre 2022 à 08:00

Fortinet Warns of Active Exploitation of New SSL-VPN Pre-auth RCE Vulnerability

mardi 13 décembre 2022 à 04:34
Fortinet on Monday issued emergency patches for a severe security flaw affecting its FortiOS SSL-VPN product that it said is being actively exploited in the wild. Tracked as CVE-2022-42475 (CVSS score: 9.3), the critical bug relates to a heap-based buffer overflow vulnerability that could allow an unauthenticated attacker to execute arbitrary code via specially crafted requests. The company said

Fortinet Warns of Active Exploitation of New SSL-VPN Pre-auth RCE Vulnerability

mardi 13 décembre 2022 à 04:34

Researchers Demonstrate How EDR and Antivirus Can Be Weaponized Against Users

lundi 12 décembre 2022 à 18:28
High-severity security vulnerabilities have been disclosed in different endpoint detection and response (EDR) and antivirus (AV) products that could be exploited to turn them into data wipers. "This wiper runs with the permissions of an unprivileged user yet has the ability to wipe almost any file on a system, including system files, and make a computer completely unbootable," SafeBreach Labs