Tag: open-source
-
Malicious NPM Packages Target Roblox Users with Data-Stealing Malware
A new campaign has targeted the npm package repository with malicious JavaScript libraries that are designed to infect Roblox users with open-source stealer malware such as Skuld and Blank-Grabber.”This incident highlights the alarming ease with which threat actors can launch supply chain attacks by exploiting trust and human error within the open source ecosystem, and…
-
Am I Isolated: Open-source container security benchmark
Am I Isolated is an open-source container security benchmark that probes users’ runtime environments and tests for container isolation. The Rust-based container runtime … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/11/08/am-i-isolated-open-source-container-security-benchmark/
-
Osmedeus: Open-source workflow engine for offensive security
Tags: open-sourceOsmedeus is an open-source workflow engine designed for offensive security. It serves as a versatile foundation, enabling users to easily create custo… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/11/06/osmedeus-open-source-workflow-engine-offensive-security/
-
China-Backed MirrorFace Trains Sights on EU Diplomatic Corps
Chinese APT groups increasingly lean on open source platform SoftEther VPN for network access. Now they’re lending their know-how to Iranian counterparts. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/china-backed-mirrorface-trains-sights-on-eu-diplomatic-corps
-
Breach Roundup: Chinese Cyberespionage Using Open Source VPN
Tags: breach, china, cybercrime, cyberespionage, germany, google, hacker, hacking, mfa, okta, open-source, ransomware, vpn, zero-dayAlso: Ransomware Hackers Demand Baguettes. This week, Chinese spying, Italian hacking scandal, an FBI warning and Okta fixed a bug. Google mandated MFA, zero days in PTZOptics and a Mexican airport didn’t pay ransom. Cybercriminals demanded baguettes, breach lettersin Ohio and Germany will shield white hats. The Italian DPA rebuked a bank. First seen on…
-
Bellini Capital Company NineMinds Debuts Free Open Source PSA for MSPs
First seen on scworld.com Jump to article: www.scworld.com/news/bellini-capital-company-nineminds-debuts-free-open-source-psa-for-msps
-
Permiso Adds Three More Open Source Cybersecurity Tools
Permiso today made available three additional tools under an open-source license that make it simpler to secure cloud computing environments. First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/11/permiso-adds-three-more-open-source-cybersecurity-tools/
-
China’s elite hackers expand target list to European Union
Beijing’s hackers are also using an open-source VPN tool for persistence. First seen on cyberscoop.com Jump to article: cyberscoop.com/china-apt-eset-target-typhoon-mirrorface/
-
Prototype Fund: Fördermittel für Open-Source-Software verdoppelt
Der Prototype Fund lädt einzelne Entwickler und Teams ein, sich zu bewerben. Bisher wurden schon Weiterentwicklungen des sozialen Netzwerks Mastodon gefördert. First seen on golem.de Jump to article: www.golem.de/news/prototype-fund-foerdermittel-fuer-open-source-software-verdoppelt-2411-190507.html
-
Open-source software: A first attempt at organization after CRA
The open-source software (OSS) industry is developing the core software for the global infrastructure, to the point that even some proprietary softwar… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/11/05/open-source-cra/
-
EDRsandblast Exploited: How Attackers are Weaponizing Open-Source Code
Unit 42 researchers recently uncovered the toolkit of an extortionist during an investigation where a threat actor attempted to evade endpoint detecti… First seen on securityonline.info Jump to article: securityonline.info/edrsandblast-exploited-how-attackers-are-weaponizing-open-source-code/
-
Whispr: Open-source multi-vault secret injection tool
Whispr is an open-source CLI tool designed to securely inject secrets from secret vaults, such as AWS Secrets Manager and Azure Key Vault, directly in… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/11/04/whispr-open-source-multi-vault-secret-injection-tool/
-
AI Bug Bounty Program Yields 34 Flaws In Open Source Tools
First seen on packetstormsecurity.com Jump to article: packetstormsecurity.com/news/view/36535/AI-Bug-Bounty-Program-Yields-34-Flaws-In-Open-Source-Tools.html
-
OpenPaX: Open-source kernel patch that mitigates memory safety errors
OpenPaX is an open-source kernel patch that mitigates common memory safety errors, re-hardening systems against application-level memory safety attack… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/11/01/openpax-open-source-kernel-patch/
-
Open Source LLM Tool Sniffs Out Python Zero-Days
First seen on darkreading.com Jump to article: www.darkreading.com/application-security/open-source-llm-tool-finds-python-zero-days
-
Gophish Framework Used in Phishing Campaigns to Deploy Remote Access Trojans
Russian-speaking users have become the target of a new phishing campaign that leverages an open-source phishing toolkit called Gophish to deliver Dark… First seen on thehackernews.com Jump to article: thehackernews.com/2024/10/gophish-framework-used-in-phishing.html
-
Tool-Tipp 34 Keycloak – Zentrale Verwaltung von Identitäten und Rollen mit Open Source
First seen on security-insider.de Jump to article: www.security-insider.de/keycloak-open-source-iam-verwaltung-a-8d59caf4f95508e43263040e71a36c91/
-
Open-Source AI, ML Tools Plagued With Vulnerabilities
First seen on scworld.com Jump to article: www.scworld.com/brief/open-source-ai-ml-tools-plagued-with-vulnerabilities
-
AI bug bounty program yields 34 flaws in open-source tools
First seen on scworld.com Jump to article: www.scworld.com/news/ai-bug-bounty-program-yields-34-flaws-in-open-source-tools
-
Hackers Exploit Roundcube Webmail XSS Vulnerability to Steal Login Credentials
Unknown threat actors have been observed attempting to exploit a now-patched security flaw in the open-source Roundcube webmail software as part of a … First seen on thehackernews.com Jump to article: thehackernews.com/2024/10/hackers-exploit-roundcube-webmail-xss.html
-
North Korean Cyber Espionage Group Tenacious Pungsan Compromises Open-Source Repositories with Backdoored npm Packages
In a recent report, the Datadog Security Research Team exposed the latest nefarious activities of the Tenacious Pungsan group, a North Korean cyber-es… First seen on securityonline.info Jump to article: securityonline.info/north-korean-cyber-espionage-group-tenacious-pungsan-compromises-open-source-repositories-with-backdoored-npm-packages/
-
AWS CDK Vulnerabilities Let Takeover S3 Bucket
A significant security vulnerability was uncovered in the AWS Cloud Development Kit (CDK), an open-source framework widely used by developers to defin… First seen on gbhackers.com Jump to article: gbhackers.com/aws-cdk-vulnerabilities/
-
Hackers Abuse EDRSilencer Tool to Bypass Security and Hide Malicious Activity
Threat actors are attempting to abuse the open-source EDRSilencer tool as part of efforts to tamper endpoint detection and response (EDR) solutions an… First seen on thehackernews.com Jump to article: thehackernews.com/2024/10/hackers-abuse-edrsilencer-tool-to.html
-
ONCD releases request for information: Open-source software security
Open-source software is a collective partnership across the development community that requires both private and public buy-in. However, securing open… First seen on securityintelligence.com Jump to article: securityintelligence.com/news/oncd-releases-request-for-information-open-source-software/
-
Unterstützung bei globalen Open-Source-Regularien – Eclipse Foundation gründet Open Regulatory Compliance Working Group
First seen on security-insider.de Jump to article: www.security-insider.de/open-regulatory-compliance-working-group-eclipse-foundation-a-83ef950496a450b16449ae38c65b0255/
-
San Francisco billboards call out tech firms for not paying for open source
Tags: open-sourceFirst seen on theregister.com Jump to article: www.theregister.com/2024/10/25/open_source_funding_ads/
-
LLMjacking and Open-Source Tool Abuse Surge in 2024 Cloud Attacks
First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/llmjacking-opensource-surge-2024/
-
Argus: Open-source information gathering toolkit
Tags: open-sourceArgus is an open-source toolkit that simplifies information gathering and reconnaissance. It features a user-friendly interface and a collection of po… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/10/23/argus-open-source-information-gathering-toolkit/
-
New Scoring System Helps Secure the Open Source AI Model Supply Chain
AI models from Hugging Face can contain similar hidden problems to OSS downloads from repositories such as GitHub. The post New Scoring System Helps S… First seen on securityweek.com Jump to article: www.securityweek.com/new-scoring-system-helps-secure-the-open-source-ai-model-supply-chain/

