Security
Headlines
HeadlinesLatestCVEs

Tag

#git

CVE-2022-38795: Double check CloneURL is acceptable (#20869) by zeripath · Pull Request #20892 · go-gitea/gitea

In Gitea through 1.17.1, repo cloning can occur in the migration function.

CVE
#git
Elite North Korean Hackers Breach Russian Missile Developer

By Waqas North Korean hackers from OpenCarrot and Lazarus breached NPO Mashinostroyeniya, a major Russian missile developer, for at least five months last year. This is a post from HackRead.com Read the original post: Elite North Korean Hackers Breach Russian Missile Developer

Code leaks are causing an influx of new ransomware actors

Cisco Talos is seeing an increasing number of ransomware variants emerge, since 2021, leading to more frequent attacks and new challenges for cybersecurity professionals, particularly regarding actor attribution.

New threat actor targets Bulgaria, China, Vietnam and other countries with customized Yashma ransomware

Cisco Talos discovered an unknown threat actor, seemingly of Vietnamese origin, conducting a ransomware operation that began at least as early as June 4, 2023 with customized Yashma ransomware.

Criminals Have Created Their Own ChatGPT Clones

Cybercriminals are touting large language models that could help them with phishing or creating malware. But the AI chatbots could just be their own kind of scam.

New Security Advisor amps up security in minutes

Categories: Business The new feature provides comprehensive health score that assesses the quality of your Nebula implementation. (Read more...) The post New Security Advisor amps up security in minutes appeared first on Malwarebytes Labs.

FBI Alert: Crypto Scammers are Masquerading as NFT Developers

The U.S. Federal Bureau of Investigation (FBI) is warning about cyber crooks masquerading as legitimate non-fungible token (NFT) developers to steal cryptocurrency and other digital assets from unsuspecting users. In these fraudulent schemes, criminals either obtain direct access to NFT developer social media accounts or create look-alike accounts to promote "exclusive" new NFT releases, often

GHSA-xcq3-7pf3-5jvc: Cockpit PHP Remote File Inclusion vulnerability

PHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3. Users may upload php files through the system file upload utility to obtain remote code execution.

GHSA-w3qm-93vf-5hrw: Cockpit Cross-site Scripting vulnerability

Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3. For any role that has permission to execute function assets, an attacker can upload a html file and that leads to XSS.

CVE-2023-4195: Prevent uploading .phps files · Cockpit-HQ/Cockpit@800c05f

PHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3.