Search Results for: OSI

GitHub Rolls Out Default Secret Scanning Push Protection for Public Repositories

March 2, 2024 GitHub on Thursday announced that it’s enabling secret scanning push protection by default for all pushes to public repositories. “This means that when a supported secret is detected in any push to a public repository, you will have the option to remove the secret from your commits or, if you deem the …

GitHub Rolls Out Default Secret Scanning Push Protection for Public Repositories Read More »

Cybersecurity for Healthcare—Diagnosing the Threat Landscape and Prescribing Solutions for Recovery

February 22, 2024 On Thanksgiving Day 2023, while many Americans were celebrating, hospitals across the U.S. were doing quite the opposite. Systems were failing. Ambulances were diverted. Care was impaired. Hospitals in three states were hit by a ransomware attack, and in that moment, the real-world repercussions came to light—it wasn’t just computer networks that were …

Cybersecurity for Healthcare—Diagnosing the Threat Landscape and Prescribing Solutions for Recovery Read More »

CISA and OpenSSF Release Framework for Package Repository Security

February 13, 2024 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced that it’s partnering with the Open Source Security Foundation (OpenSSF) Securing Software Repositories Working Group to publish a new framework to secure package repositories. Called the Principles for Package Repository Security, the framework aims to establish a set of foundational rules for package Article posted by: …

CISA and OpenSSF Release Framework for Package Repository Security Read More »

MongoDB Suffers Security Breach, Exposing Customer Data

December 18, 2023 MongoDB on Saturday disclosed it’s actively investigating a security incident that has led to unauthorized access to “certain” corporate systems, resulting in the exposure of customer account metadata and contact information. The American database software company said it first detected anomalous activity on December 13, 2023, and that it immediately activated its incident response …

MongoDB Suffers Security Breach, Exposing Customer Data Read More »

116 Malware Packages Found on PyPI Repository Infecting Windows and Linux Systems

December 15, 2023 Cybersecurity researchers have identified a set of 116 malicious packages on the Python Package Index (PyPI) repository that are designed to infect Windows and Linux systems with a custom backdoor. “In some cases, the final payload is a variant of the infamous W4SP Stealer, or a simple clipboard monitor to steal cryptocurrency, or …

116 Malware Packages Found on PyPI Repository Infecting Windows and Linux Systems Read More »

15,000 Go Module Repositories on GitHub Vulnerable to Repojacking Attack

December 6, 2023 New research has found that over 15,000 Go module repositories on GitHub are vulnerable to an attack called repojacking. “More than 9,000 repositories are vulnerable to repojacking due to GitHub username changes,” Jacob Baines, chief technology officer at VulnCheck, said in a report shared with The Hacker News. “More than 6,000 repositories were vulnerable …

15,000 Go Module Repositories on GitHub Vulnerable to Repojacking Attack Read More »

Kubernetes Secrets of Fortune 500 Companies Exposed in Public Repositories

November 25, 2023 Cybersecurity researchers are warning of publicly exposed Kubernetes configuration secrets that could put organizations at risk of supply chain attacks. “These encoded Kubernetes configuration secrets were uploaded to public repositories,” Aqua security researchers Yakir Kadkoda and Assaf Morag said in a new research published earlier this week. Some of those impacted include two top …

Kubernetes Secrets of Fortune 500 Companies Exposed in Public Repositories Read More »

DarkGate Malware Spreading via Messaging Services Posing as PDF Files

October 14, 2023 A piece of malware known as DarkGate has been observed being spread via instant messaging platforms such as Skype and Microsoft Teams. In these attacks, the messaging apps are used to deliver a Visual Basic for Applications (VBA) loader script that masquerades as a PDF document, which, when opened, triggers the download and execution …

DarkGate Malware Spreading via Messaging Services Posing as PDF Files Read More »

Researchers Uncover Malware Posing as WordPress Caching Plugin

October 13, 2023 Cybersecurity researchers have shed light on a new sophisticated strain of malware that masquerades a WordPress plugin to stealthily create administrator accounts and remotely control a compromised site. “Complete with a professional looking opening comment implying it is a caching plugin, this rogue code contains numerous functions, adds filters to prevent itself …

Researchers Uncover Malware Posing as WordPress Caching Plugin Read More »

GitHub Repositories Hit by Password-Stealing Commits Disguised as Dependabot Contributions

September 29, 2023 A new malicious campaign has been observed hijacking GitHub accounts and committing malicious code disguised as Dependabot contributions with an aim to steal passwords from developers. “The malicious code exfiltrates the GitHub project’s defined secrets to a malicious C2 server and modify any existing javascript files in the attacked project with a …

GitHub Repositories Hit by Password-Stealing Commits Disguised as Dependabot Contributions Read More »

Open Whatsapp chat
Whatsapp Us
Chat with us for faster replies.