Tag: open-source
-
Polizeibesuch im Linux-Livestream: Open-Source-Entwickler Opfer von Swatting
First seen on heise.de Jump to article: www.heise.de/news/Polizeibesuch-im-Linux-Livestream-Open-Source-Entwickler-Opfer-von-Swatting-9873744.html
-
QEMU 9.1 Released: New Features and Hardware Support
QEMU, a popular open-source emulator, has launched its latest version, 9.1 with numerous improvements to enhance performance, security, and scalabilit… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/09/qemu-9-1-released-new-features-and-hardware-support/
-
Machine Learning- und KI-Dienste sind angreifbar – Schwachstellen in Open-Source-MLOps-Plattformen
First seen on security-insider.de Jump to article: www.security-insider.de/cyberangriffsrisiken-mlops-jfrog-sicherheitsforschung-a-0deef1cce8b54fd0b912bb23b01a34c0/
-
Open Source Updates Have 75% Chance of Breaking Apps
First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/open-source-updates-75-breaking/
-
Apache OFBiz Update Fixes High-Severity Flaw Leading to Remote Code Execution
A new security flaw has been addressed in the Apache OFBiz open-source enterprise resource planning (ERP) system that, if successfully exploited, coul… First seen on thehackernews.com Jump to article: thehackernews.com/2024/09/apache-ofbiz-update-fixes-high-severity.html
-
Chinese APT Groups Continue to Leverage Open-Source and Custom Reconnaissance Tools in Cyber Espionage Campaigns
The Natto Thoughts team recently uncovered key insights into the reconnaissance techniques used by Chinese state-sponsored threat actors. A deep dive … First seen on securityonline.info Jump to article: securityonline.info/chinese-apt-groups-continue-to-leverage-open-source-and-custom-reconnaissance-tools-in-cyber-espionage-campaigns/
-
New Loki Backdoor Attacking macOS Systems
Cody Thomas developed Apfell, an open-source macOS post-exploitation framework, in 2018 and evolved into Mythic, a cross-platform framework that addre… First seen on gbhackers.com Jump to article: gbhackers.com/loki-macos-attack/
-
Open Source Tool Allows Voters to Verify Election Results
The ElectionGuard project allows anyone, voters, campaign staffers, and election officials, to cryptographically verify ballots, a promise which may b… First seen on darkreading.com Jump to article: www.darkreading.com/data-privacy/open-source-tool-allows-voters-to-verify-election-results
-
Chinese Hackers Using Open Source Tools To Launch Cyber Attacks
Three Chinese state-backed threat groups, APT10, GALLIUM, and Stately Taurus, have repeatedly employed a modified version of the open-source network s… First seen on gbhackers.com Jump to article: gbhackers.com/chinese-hackers-open-source-attacks/
-
33 open-source cybersecurity solutions you didn’t know you needed
Open-source cybersecurity tools provide transparency and flexibility, allowing users to examine and customize the source code to fit specific security… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/09/10/open-source-cybersec-tools/
-
OpenZiti: Secure, open-source networking for your applications
OpenZiti is a free, open-source project that embeds zero-trust networking principles directly into applications. Example of an OpenZiti overlay networ… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/09/09/openziti-secure-open-source-networking/
-
Respotter: Open-source Responder honeypot
Tags: open-sourceRespotter is an open-source honeypot designed to detect attackers when they launch Responder within your environment. This application identifies acti… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/09/06/respotter-open-source-responder-honeypot/
-
Feds Warn Health Sector to Patch Apache Tomcat Flaws
Healthcare Sector Heavily Relies on Open-Source Web Server; Older Flaws Pose Risk. Federal authorities are alerting healthcare entities of vulnerabili… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/feds-warn-health-sector-to-patch-apache-tomcat-flaws-a-26227
-
Apache fixes critical OFBiz remote code execution vulnerability
Apache has fixed a critical security vulnerability in its open-source OFBiz (Open For Business) software, which could allow attackers to execute arbit… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/apache-fixes-critical-ofbiz-remote-code-execution-vulnerability/
-
Ubuntu Fixes a High-Severity PostgreSQL Vulnerability
PostgreSQL is an open-source, widely used object relational SQL database. However, like any other software, it is not immune to vulnerabilities. A new… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/09/ubuntu-fixes-a-high-severity-postgresql-vulnerability/
-
Apache fixed a new remote code execution flaw in Apache OFBiz
Apache addressed a remote code execution vulnerability affecting the Apache OFBiz open-source enterprise resource planning (ERP) system. Apache fixed … First seen on securityaffairs.com Jump to article: securityaffairs.com/168106/security/apache-ofbiz-rce-cve-2024-45195.html
-
CISA Flags Critical Apache OFBiz Flaw Amid Active Exploitation Reports
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a critical security flaw affecting the Apache OFBiz open-source ente… First seen on thehackernews.com Jump to article: thehackernews.com/2024/08/cisa-flags-critical-apache-ofbiz-flaw.html
-
OpenBAS: Open-source breach and attack simulation platform
OpenBAS is an open-source platform that enables organizations to plan, schedule, and execute crisis exercises, adversary simulations, and breach simul… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/09/04/openbas-open-source-breach-and-attack-simulation-platform/
-
A refresher on Talos’ open-source tools and the importance of the open-source community
Open-source software that is free to download, deploy and modify is a vital component in the fight for cyber security. Freely available software not o… First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/a-refresher-on-talos-open-source-tools/
-
Open-Source Tool Allows Voters to Verify Election Results
The ElectionGuard project allows anyone, voters, campaign staffers, and election officials, to cryptographically verify ballots, a promise which may b… First seen on darkreading.com Jump to article: www.darkreading.com/data-privacy/open-source-tool-allows-voters-to-verify-election-results
-
Critical Flaws in Traccar GPS System Expose Users to Remote Attacks
Two security vulnerabilities have been disclosed in the open-source Traccar GPS tracking system that could be potentially exploited by unauthenticated… First seen on thehackernews.com Jump to article: thehackernews.com/2024/08/critical-flaws-in-traccar-gps-system.html
-
White House says no need to restrict ‘open-source’ artificial intelligence, at least for now
First seen on thesecurityblogger.com Jump to article: www.thesecurityblogger.com/white-house-says-no-need-to-restrict-open-source-artificial-intelligence-at-least-for-now/
-
BSI entdeckt schwere Sicherheitslücken in Mastodon, einige kleinere in Matrix
Im Rahmen einer Open-Source-Codeanalyse hat das BSI den Messenger Matrix und die Social-Media-Anwendung Mastodon auf kritische Schwachstellen untersuc… First seen on heise.de Jump to article: www.heise.de/news/BSI-findet-Sicherheitsluecken-in-Matrix-und-Mastodon-9853779.html
-
Why NTIA Support of Open-Source AI is Good for Security
A fully open model, one where the training data is available for inspection and modification, provides a means for addressing another threat: maliciou… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/09/why-ntia-support-of-open-source-ai-is-good-for-security/
-
Damn Vulnerable UEFI: Simulate real-world firmware attacks
Damn Vulnerable UEFI (DVUEFI) is an open-source exploitation toolkit and learning platform for unveiling and fixing UEFI firmware vulnerabilities. Sim… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/09/02/dvuefi-simulate-real-world-firmware-attacks/
-
Researcher: CrowdStrike blunder could benefit open source
Enterprises with the IT talent might turn to open-source software as a backup for commercial products to mitigate damage from a CrowdStrike-like IT ou… First seen on techtarget.com Jump to article: www.techtarget.com/searchenterprisedesktop/news/366599516/Researcher-CrowdStrike-blunder-could-benefit-open-source
-
Wireshark 4.4.0 Released What’s New!
The Wireshark Foundation has announced the release of Wireshark 4.4.0, marking a significant update to the popular open-source network protocol analyz… First seen on gbhackers.com Jump to article: gbhackers.com/wireshark-4-4-0-released/
-
Sinon: Open-source automatic generative burn-in for Windows deception hosts
Sinon is an open-source, modular tool for the automatic burn-in of Windows-based deception hosts. It aims to reduce the difficulty of orchestrating de… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/08/30/sinon-open-source-automatic-generative-burn-in-for-windows-deception-hosts/
-
BSI deckt schwerwiegende Sicherheitslücken in Matrix und Mastodon auf
Im Rahmen einer Open-Source-Codeanalyse hat das BSI den Messenger Matrix und die Social-Media-Anwendung Mastodon auf kritische Schwachstellen untersuc… First seen on heise.de Jump to article: www.heise.de/news/BSI-findet-Sicherheitsluecken-in-Matrix-und-Mastodon-9853779.html
-
BSI findet Sicherheitslücken in Matrix und Mastodon
Im Rahmen einer Open-Source-Codeanalyse hat das BSI den Messenger Matrix und die Social-Media-Anwendung Mastodon auf kritische Schwachstellen untersuc… First seen on heise.de Jump to article: www.heise.de/news/BSI-findet-Sicherheitsluecken-in-Matrix-und-Mastodon-9853779.html

