PROJET AUTOBLOG


The Hacker News

Site original : The Hacker News

⇐ retour index

New Google Scorecards Tool Scans Open-Source Software for More Security Risks

vendredi 2 juillet 2021 à 11:44
Google has launched an updated version of Scorecards, its automated security tool that produces a "risk score" for open source initiatives, with improved checks and capabilities to make the data generated by the utility accessible for analysis. "With so much software today relying on open-source projects, consumers need an easy way to judge whether their dependencies are safe," Google's Open

NSA, FBI Reveal Hacking Methods Used by Russian Military Hackers

vendredi 2 juillet 2021 à 08:23
An ongoing brute-force attack campaign targeting enterprise cloud environments has been spearheaded by the Russian military intelligence since mid-2019, according to a joint advisory published by intelligence agencies in the U.K. and U.S. The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and the U.K.'s National

Microsoft Warns of Critical "PrintNightmare" Flaw Being Exploited in the Wild

vendredi 2 juillet 2021 à 07:36
Microsoft on Thursday officially confirmed that the "PrintNightmare" remote code execution (RCE) vulnerability affecting Windows Print Spooler is different from the issue the company addressed as part of its Patch Tuesday update released earlier this month, while warning that it has detected exploitation attempts targeting the flaw. The company is tracking the security weakness under the

IndigoZebra APT Hacking Campaign Targets the Afghan Government

jeudi 1 juillet 2021 à 12:00
Cybersecurity researchers are warning of ongoing attacks coordinated by a suspected Chinese-speaking threat actor targeting the Afghanistan government as part of an espionage campaign that may have had its provenance as far back as 2014. Israeli cybersecurity firm Check Point Research attributed the intrusions to a hacking group tracked under the moniker "IndigoZebra," with past activity aimed

Rethinking Application Security in the API-First Era

jeudi 1 juillet 2021 à 11:58
Securing applications it the API-first era can be an uphill battle. As development accelerates, accountability becomes unclear, and getting controls to operate becomes a challenge in itself. It's time that we rethink our application security strategies to reflect new priorities, principles and processes in the API-first era. Securing tomorrow's applications begins with assessing the business