Tag: open-source
-
SSH-Snake Tool Used in Data Exfiltration Attacks
A new threat actor is finding success in relying on open-source software (OSS) security tools and a networking mapping tool called SSH-Snake in its ca… First seen on duo.com Jump to article: duo.com/decipher/ssh-snake-tool-used-in-data-exfiltration-attacks
-
Critical Exim Vulnerability Threatens Millions of Email Servers
Exim is a widely used, open-source mail transfer agent (MTA) for Unix and Unix-like operating systems. A critical vulnerability has been discovered in… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/critical-exim-vulnerability-threatens-millions-of-email-servers/
-
CRYSTALRAY Hackers Infect Over 1,500 Victims Using Network Mapping Tool
A threat actor that was previously observed using an open-source network mapping tool has greatly expanded their operations to infect over 1,500 victi… First seen on thehackernews.com Jump to article: thehackernews.com/2024/07/crystalray-hackers-infect-over-1500.html
-
Shuffle Automation: Open-source security automation platform
Shuffle is an open-source automation platform designed by and for security professionals. While security operations are inherently complex, Shuffle si… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/07/22/shuffle-automation-open-source-security-automation-platform/
-
TAG-100’s Global Espionage Campaign: Exploiting Open-Source Tools
A newly identified cyberespionage group, dubbed TAG-100 by cybersecurity firm Recorded Future, has been linked to a series of sophisticated attacks ta… First seen on securityonline.info Jump to article: securityonline.info/tag-100s-global-espionage-campaign-exploiting-open-source-tools/
-
TAG-100 Actors Using Open-Source Tools To Attack Gov Private Orgs
Hackers exploit open-source tools to execute attacks because they are readily available, well-documented, and often have extensive community support, … First seen on gbhackers.com Jump to article: gbhackers.com/tag-100-open-source-cyber-attacks/
-
Two of Wallarm’s Open-source Tools Have Been Accepted into Black Hat Arsenal 2024
We’re gearing up with some seriously cool stuff for Black Hat! But first, a little sneak peek – not just one, but TWO of Wallarm’s open-source tools w… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/two-of-wallarms-open-source-tools-have-been-accepted-into-black-hat-arsenal-2024/
-
Grype: Open-source vulnerability scanner for container images, filesystems
Grype is an open-source vulnerability scanner designed for container images and filesystems that seamlessly integrates with Syft, a powerful Software … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/07/18/grype-open-source-vulnerability-scanner-container-images-filesystems/
-
Ollama drama as ‘easyexploit’ critical flaw found in open source AI server
First seen on theregister.com Jump to article: www.theregister.com/2024/06/24/rce_ollama_wiz/
-
SubSnipe: Open-source tool for finding subdomains vulnerable to takeover
SubSnipe is an open-source, multi-threaded tool to help find subdomains vulnerable to takeover. It’s simpler, produces better output, and has more fin… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/07/17/subsnipe-open-source-tool-find-subdomains-vulnerable-takeover/
-
Critical Unpatched Flaws Disclosed in Popular Gogs Open-Source Git Service
Four unpatched security flaws, including three critical ones, have been disclosed in the Gogs open-source, self-hosted Git service that could enable a… First seen on thehackernews.com Jump to article: thehackernews.com/2024/07/critical-vulnerabilities-disclosed-in.html
-
Realm: Open-source adversary emulation framework
Realm is an open-source adversary emulation framework emphasizing scalability, reliability, and automation. It’s designed to handle engagements of any… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/07/15/realm-open-source-adversary-emulation-framework/
-
The Emerging Role of AI in Open-Source Intelligence
Recently the Office of the Director of National Intelligence (ODNI) unveiled a new strategy for open-source intelligence (OSINT) and referred to OSINT… First seen on thehackernews.com Jump to article: thehackernews.com/2024/07/the-emerging-role-of-ai-in-open-source.html
-
Detecting Living Off The Land attacks with Wazuh
Threat actors commonly use Living Off The Land (LOTL) techniques to evade detection. Learn more from Wazuh about how its open source XDR/SIEM #cyberse… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/detecting-living-off-the-land-attacks-with-wazuh/
-
CRYSTALRAY Group Targets 1,500 Organizations in 6 Months
Relatively New Threat Actor Uses Open-Source Tools, Focuses on US and China. A relatively new threat actor has compromised over 1,500 organizations wo… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/crystalray-group-targets-1500-organizations-in-6-months-a-25759
-
‘CrystalRay’ Expands Arsenal, Hits 1,500 Targets with SSH-Snake and Open Source Tools
A threat actor tracked as CrystalRay has hit 1,500 victims since February, stealing credentials and deploying backdoors. The post ‘CrystalRay’ Expands… First seen on securityweek.com Jump to article: www.securityweek.com/crystalray-expands-arsenal-hits-1500-targets-with-ssh-snake-and-open-source-tools/
-
CrystalRay operations have scaled 10x to over 1,500 victims
A threat actor known as CrystalRay targeted 1,500 victims since February using tools like SSH-Snake and various open-source utilities. The Sysdig Thre… First seen on securityaffairs.com Jump to article: securityaffairs.com/165607/cyber-crime/crystalray-operations-scaled-10x.html
-
CISA offers tools to promote secure use of open-source software
First seen on scmagazine.com Jump to article: www.scmagazine.com/news/cisa-offers-tools-to-promote-secure-use-of-open-source-software
-
9 unverzichtbare Open Source Security Tools
First seen on csoonline.com Jump to article: www.csoonline.com/de/a/9-unverzichtbare-open-source-security-tools
-
BunkerWeb: Open-source Web Application Firewall (WAF)
BunkerWeb is an open-source Web Application Firewall (WAF) distributed under the AGPLv3 free license. The solution’s core code is entirely auditable b… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/07/10/bunkerweb-open-source-web-application-firewall-waf/
-
Malware in Open Source-Software: Wie groß ist die Bedrohung der IT-Sicherheit wirklich?
Im März 2024 machte die Entdeckung einer Backdoor in den zur Komprimierung genutzten xz-Tools und Bibliotheken Schlagzeilen. Aber wie groß ist die Bed… First seen on borncity.com Jump to article: www.borncity.com/blog/2024/07/08/malware-in-open-source-software-wie-gro-ist-die-bedrohung-der-it-sicherheit-wirklich/
-
Datenschutzverletzung im großen Stil Lernen aus dem ATT-Hack
Software-Lieferketten haben sich zu komplizierten Netzen entwickelt, die in hohem Maße auf Open-Source-Bibliotheken angewiesen sind. Immer mehr Untern… First seen on netzpalaver.de Jump to article: netzpalaver.de/2024/07/01/datenschutzverletzung-im-grossen-stil-lernen-aus-dem-att-hack/
-
Google Opens $250K Bug Bounty Contest for VM Hypervisor
If security researchers can execute a guest-to-host attack using a zero-day vulnerability in the KVM open source hypervisor, Google will make it worth… First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/google-opens-250k-bug-bounty-contest-for-vm-hypervisor
-
CISA Advances Open-Source Software Security with Strategic Initiatives and Community Collaboration
The Cybersecurity and Infrastructure Security Agency (CISA) has announced its next phase to enhance the security of open-source software (OSS) through… First seen on thecyberexpress.com Jump to article: thecyberexpress.com/cisa-announces-open-source-software-security/
-
Monocle: Open-source LLM for binary analysis search
Monocle is open-source tooling backed by a large language model (LLM) for performing natural language searches against compiled target binaries. Monoc… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/07/08/monocle-open-source-llm-binary-analysis-search/
-
How CISA Plans to Measure Trust in Open-Source Software
Agency Is in 2nd Phase of Its Open-Source Software Security Road Map. The U.S. Cybersecurity and Infrastructure Security Agency provided details on Mo… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/how-cisa-plans-to-measure-trust-in-open-source-software-a-25723
-
Collaborate on Shifting Left: Why ‘AppSec Is a Team Sport’
Developers are using more and more open-source code because they want to move fast, said Cycode’s Lotem Guy. But the speed of development and the cont… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/interviews/collaborate-on-shifting-left-appsec-team-sport-i-5398
-
CISA Report Finds Most Open-Source Projects Contain Memory-Unsafe Code
First seen on techrepublic.com Jump to article: www.techrepublic.com/article/open-source-projects-memory-unsafe-code-cisa/
-
CISA Flags Memory-Unsafe Code in Major Open Source Projects
Despite more than 50% of all open source code being written in memory-unsafe languages like C++, we are unlikely to see a massive overhaul to codebase… First seen on darkreading.com Jump to article: www.darkreading.com/application-security/cisa-memory-unsafe-code-open-source-projects
-
Eine neue Bedrohung für die Open-Source-Community – Lumma-Malware hat jetzt auch Python-Entwickler als Ziel
First seen on security-insider.de Jump to article: www.security-insider.de/lumma-malware-hat-jetzt-auch-python-entwickler-als-ziel-a-b4b6c6f1d0bc92cbfb83a6f8b7568481/

