PROJET AUTOBLOG


The Hacker News

Site original : The Hacker News

⇐ retour index

Microsoft Issues Patches for 2 Windows Zero-Days and 126 Other Vulnerabilities

mercredi 13 avril 2022 à 05:22
Microsoft's Patch Tuesday updates for the month of April have addressed a total of 128 security vulnerabilities spanning across its software product portfolio, including Windows, Defender, Office, Exchange Server, Visual Studio, and Print Spooler, among others. 10 of the 128 bugs fixed are rated Critical, 115 are rated Important, and three are rated Moderate in severity, with one of the flaws

Cross-Regional Disaster Recovery with Elasticsearch

mercredi 13 avril 2022 à 04:50
Unsurprisingly, here at Rewind, we've got a lot of data to protect (over 2 petabytes worth). One of the databases we use is called Elasticsearch (ES or Opensearch, as it is currently known in AWS). To put it simply, ES is a document database that facilitates lightning-fast search results. Speed is essential when customers are looking for a particular file or item that they need to restore using 

Critical LFI Vulnerability Reported in Hashnode Blogging Platform

mardi 12 avril 2022 à 15:08
Researchers have disclosed a previously undocumented local file inclusion (LFI) vulnerability in Hashnode, a developer-oriented blogging platform, that could be abused to access sensitive data such as SSH keys, server's IP address, and other network information. "The LFI originates in a Bulk Markdown Import feature that can be manipulated to provide attackers with unimpeded ability to download

E.U. Officials Reportedly Targeted with Israeli Pegasus Spyware

mardi 12 avril 2022 à 12:26
Senior officials in the European Union were allegedly targeted with NSO Group's infamous Pegasus surveillance tool, according to a new report from Reuters. At least five individuals, including European Justice Commissioner Didier Reynders, are said to have been singled out in total, the news agency said, citing documents and two unnamed E.U. officials. However, it's not clear who used the

NGINX Shares Mitigations for Zero-Day Bug Affecting LDAP Implementation

mardi 12 avril 2022 à 11:19
The maintainers of the NGINX web server project have issued mitigations to address security weaknesses in its Lightweight Directory Access Protocol (LDAP) Reference Implementation. "NGINX Open Source and NGINX Plus are not themselves affected, and no corrective action is necessary if you do not use the reference implementation," Liam Crilly and Timo Stark of F5 Networks said in an advisory