PROJET AUTOBLOG


The Hacker News

Site original : The Hacker News

⇐ retour index

Digital Signature Spoofing Flaws Uncovered in OpenOffice and LibreOffice

mardi 12 octobre 2021 à 11:02
The maintainers of LibreOffice and OpenOffice have shipped security updates to their productivity software to remediate multiple vulnerabilities that could be weaponized by malicious actors to alter documents to make them appear as if they are digitally signed by a trusted source. The list of the three flaws is as follows — CVE-2021-41830 / CVE-2021-25633 - Content and Macro Manipulation with

GitHub Revoked Insecure SSH Keys Generated by a Popular git Client

mardi 12 octobre 2021 à 09:57
Code hosting platform GitHub has revoked weak SSH authentication keys that were generated via the GitKraken git GUI client due to a vulnerability in a third-party library that increased the likelihood of duplicated SSH keys. As an added precautionary measure, the Microsoft-owned company also said it's building safeguards to prevent vulnerable versions of GitKraken from adding newly generated

Microsoft Fended Off a Record 2.4 Tbps DDoS Attack Targeting Azure Customers

mardi 12 octobre 2021 à 09:16
Microsoft on Monday revealed that its Azure cloud platform mitigated a 2.4 Tbps distributed denial-of-service (DDoS) attack in the last week of August targeting an unnamed customer in Europe, surpassing a 2.3 Tbps attack stopped by Amazon Web Services in February 2020. "This is 140 percent higher than 2020's 1 Tbps attack and higher than any network volumetric event previously detected on Azure,

Microsoft Warns of Iran-Linked Hackers Targeting US and Israeli Defense Firms

mardi 12 octobre 2021 à 08:09
An emerging threat actor likely supporting Iranian national interests has been behind a password spraying campaign targeting US, EU, and Israeli defense technology companies, with additional activity observed against regional ports of entry in the Persian Gulf as well as maritime and cargo transportation companies focused in the Middle East. Microsoft is tracking the hacking crew under the

Ukraine Arrests Operator of DDoS Botnet with 100,000 Compromised Devices

mardi 12 octobre 2021 à 05:02
Ukrainian law enforcement authorities on Monday disclosed the arrest of a hacker responsible for the creation and management of a "powerful botnet" consisting of over 100,000 enslaved devices that was used to carry out distributed denial-of-service (DDoS) and spam attacks on behalf of paid customers. The unnamed individual, from the Ivano-Frankivsk region of the country, is also said to have