PROJET AUTOBLOG


The Hacker News

Site original : The Hacker News

⇐ retour index

New Patch Released for Actively Exploited 0-Day Apache Path Traversal to RCE Attacks

vendredi 8 octobre 2021 à 06:47
The Apache Software Foundation on Thursday released additional security updates for its HTTP Server product to remediate what it says is an "incomplete fix" for an actively exploited path traversal and remote code execution flaw that it patched earlier this week. CVE-2021-42013, as the new vulnerability is identified as, builds upon CVE-2021-41773, a flaw that impacted Apache web servers running

Code Execution Bug Affects Yamale Python Package — Used by Over 200 Projects

jeudi 7 octobre 2021 à 13:50
A high-severity code injection vulnerability has been disclosed in 23andMe's Yamale, a schema and validator for YAML, that could be trivially exploited by adversaries to execute arbitrary Python code. The flaw, tracked as CVE-2021-38305 (CVSS score: 7.8), involves manipulating the schema file provided as input to the tool to circumvent protections and achieve code execution. Particularly, the 

Penetration Testing Your AWS Environment - A CTO's Guide

jeudi 7 octobre 2021 à 12:41
So, you've been thinking about getting a Penetration Test done on your Amazon Web Services (AWS) environment. Great! What should that involve exactly?  There are many options available, and knowing what you need will help you make your often limited security budget go as far as possible. Broadly, the key focus areas for most penetration tests involving AWS: Your externally accessible cloud

New U.S. Government Initiative Holds Contractors Accountable for Cybersecurity

jeudi 7 octobre 2021 à 11:40
The U.S. government on Wednesday announced the formation of a new Civil Cyber-Fraud Initiative that aims to hold contractors accountable for failing to meet required cybersecurity requirements in order to safeguard public sector information and infrastructure. "For too long, companies have chosen silence under the mistaken belief that it is less risky to hide a breach than to bring it forward

Apple now requires all apps to make it easy for users to delete their accounts

jeudi 7 octobre 2021 à 10:24
All third-party iOS, iPadOS, and macOS apps that allow users to create an account should also provide a method for terminating their accounts from within the apps beginning next year, Apple said on Wednesday. "This requirement applies to all app submissions starting January 31, 2022," the iPhone maker said, urging developers to "review any laws that may require you to maintain certain types of