Tag: open-source
-
Secator: Open-source pentesting Swiss army knife
Secator is an open-source task and workflow runner tailored for security assessments. It facilitates the use of numerous security tools and aims to en… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/07/03/secator-open-source-pentesting-swiss-army-knife/
-
GeoServer and GeoTools Address XPath Expression Injection Vulnerabilities
Widely used open-source Java tools, GeoServer and GeoTools, that help in geospatial data processing have fixed security vulnerabilities related to XPa… First seen on thecyberexpress.com Jump to article: thecyberexpress.com/xpath-expression-injection-vulnerabilities/
-
Gogs Vulnerabilities Let Attackers Hack Instances Steal Source Code
Gogs is a standard open-source code hosting system used by many developers. Several Gogs vulnerabilities have been discovered recently by the cybersec… First seen on gbhackers.com Jump to article: gbhackers.com/gogs-vulnerabilities-hack-steal-source-code/
-
CocoaPods: Anfällig für Supply-Chain-Angriffe in zahllosen Mac- und iOS-Apps
Der Dependency-Manager auf Open-Source-Basis steckt in Millionen von Swift- und Objective-C-Programmen. Offenbar standen für fast ein Jahrzehnt die To… First seen on heise.de Jump to article: www.heise.de/news/CocoaPods-Anfaellig-fuer-Supply-Chain-Angriffe-in-zahllosen-Mac-und-iOS-Apps-9786099.html
-
Critical RCE Vulnerability Discovered in Ollama AI Infrastructure Tool
Tags: ai, cybersecurity, flaw, infrastructure, intelligence, open-source, rce, remote-code-execution, tool, update, vulnerabilityCybersecurity researchers have detailed a now-patch security flaw affecting the Ollama open-source artificial intelligence (AI) infrastructure platfor… First seen on thehackernews.com Jump to article: thehackernews.com/2024/06/critical-rce-vulnerability-discovered.html
-
Multiple Threat Actors Deploying Open-Source Rafel RAT to Target Android Devices
Multiple threat actors, including cyber espionage groups, are employing an open-source Android remote administration tool called Rafel RAT to meet the… First seen on thehackernews.com Jump to article: thehackernews.com/2024/06/iranian-hackers-deploy-rafel-rat-in.html
-
Portainer: Open-source Docker and Kubernetes management
Portainer Community Edition is an open-source, lightweight service delivery platform for containerized applications. It enables the management of Dock… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/07/01/portainer-open-source-docker-kubernetes-management/
-
Gogs Vulnerabilities Let Attackers Hack Instances And Steal Source Code
Gogs is a standard open-source code hosting system used by many developers. Several Gogs vulnerabilities have been discovered recently by the cybersec… First seen on gbhackers.com Jump to article: gbhackers.com/gogs-vulnerabilities-hack-steal-source-code/
-
Majority of Critical Open Source Projects Contain Memory Unsafe Code
A CISA analysis in collaboration with international partners concluded most critical open source projects potentially contain memory safety vulnerabil… First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/open-source-projects-memory-unsafe/
-
Week in review: MOVEit auth bypass flaws quitely fixed, open-source Rafel RAT targets Androids
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Progress quietly fixes MOVEit auth bypass flaws (CVE… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/06/30/week-in-review-moveit-auth-bypass-flaws-quitely-fixed-open-source-rafel-rat-targets-androids/
-
CISA’s Flags Memory-Unsafe Code in Major Open Source Projects
Despite more than 50% of all open source code being written in memory-unsafe languages like C++, we are unlikely to see a massive overhaul to code bas… First seen on darkreading.com Jump to article: www.darkreading.com/application-security/cisa-memory-unsafe-code-open-source-projects
-
Mailcow Mail Server Flaws Expose Servers to Remote Code Execution
Two security vulnerabilities have been disclosed in the Mailcow open-source mail server suite that could be exploited by malicious actors to achieve a… First seen on thehackernews.com Jump to article: thehackernews.com/2024/06/mailcow-mail-server-flaws-expose.html
-
Most critical open source projects not using memory safe code
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published research looking into 172 key open-source projects and whether they are… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-most-critical-open-source-projects-not-using-memory-safe-code/
-
Zeek: Open-source network traffic analysis, security monitoring
Zeek is an open-source network analysis framework. Unlike an active security device such as a firewall, Zeek operates on a versatile ‘sensor’ that can… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/06/25/zeek-open-source-network-analysis-framework-security-monitoring/
-
Critical bug discovered in open source utility Fluent Bit
Tenable researchers discovered a critical vulnerability, dubbed ‘Linguistic Lumberjack,’ in Fluent Bit, an open source logging utility widely used by … First seen on techtarget.com Jump to article: www.techtarget.com/searchsecurity/news/366585766/Critical-bug-discovered-in-open-source-utility-Fluent-Bit
-
New IBM Watsonx GenAI focuses on enterprises, governance
The veteran tech giant, with deep roots in AI, bases its new AI strategy on open source, multimodel support and helping businesses modernize their cod… First seen on techtarget.com Jump to article: www.techtarget.com/searchenterpriseai/news/366585946/New-IBM-Watsonx-GenAI-tech-focuses-on-enterprises-governance
-
Patched Weeks Ago, RCE Bug in AI Tool Still a ‘Probllama’
Companies Eager for Tools Are Putting AI’s Transformative Power Ahead of Security. Hackers targeting a popular open-source project for running artific… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/patched-weeks-ago-rce-bug-in-ai-tool-still-probllama-a-25611
-
Experts observed approximately 120 malicious campaigns using the Rafel RAT
Multiple threat actors are using an open-source Android remote administration tool called Rafel RAT to target Android Devices. Check Point Research id… First seen on securityaffairs.com Jump to article: securityaffairs.com/164844/cyber-crime/multiple-threat-actors-used-rafel-rat.html
-
Open-source Rafel RAT steals info, locks Android devices, asks for ransom
The open-source Rafel RAT is being leveraged by multiple threat actors to compromise Android devices and, in some cases, to lock them, encrypt their c… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/06/24/android-rafel-rat/
-
Addressing Node.js Vulnerabilities in Ubuntu
Node.js is an open-source, cross-platform JavaScript runtime environment built on the powerful V8 engine from Chrome. It allows you to run JavaScript … First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/06/addressing-node-js-vulnerabilities-in-ubuntu/
-
Rafel RAT targets outdated Android phones in ransomware attacks
An open-source Android malware named ‘Rafel RAT’ is widely deployed by multiple cybercriminals to attack outdated devices, some aiming to lock them do… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/rafel-rat-targets-outdated-android-phones-in-ransomware-attacks/
-
Chinese Hackers Caught Spying on Taiwanese Firms
Espionage Group Used SoftEther VPN Client to Exploit Targeted Networks. A Chinese state-sponsored group, tracked as RedJuliett, is using open-source V… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/chinese-hackers-caught-spying-on-taiwanese-firms-a-25603
-
Cilium: Open-source eBPF-based networking, security, observability
Cilium is an open-source, cloud-native solution that leverages eBPF technology in the Linux kernel to provide, secure, and monitor network connectivit… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/06/21/cilium-open-source-ebpf-based-networking-security-observability/
-
Ratel RAT targets outdated Android phones in ransomware attacks
An open-source Android malware named ‘Ratel RAT’ is widely deployed by multiple cybercriminals to attack outdated devices, some aiming to lock them do… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/ratel-rat-targets-outdated-android-phones-in-ransomware-attacks/
-
Das Ringen um Sicherheit Source- oder proprietäre Software?
First seen on security-insider.de Jump to article: www.security-insider.de/sicherheit-von-open-source-vs-proprietaerer-software-a-8e1df85545b683e197b03d2ef9d997c8/
-
UNC3886 hackers use Linux rootkits to hide on VMware ESXi VMs
A suspected Chinese threat actor tracked as UNC3886 uses publicly available open-source rootkits named ‘Reptile’ and ‘Medusa’ to remain hidden on VMwa… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/unc3886-hackers-use-linux-rootkits-to-hide-on-vmware-esxi-vms/
-
SELKS: Open-source Suricata IDS/IPS, network security monitoring, threat hunting
SELKS is a free, open-source, turnkey solution for Suricata-based network intrusion detection and protection (IDS/IPS), network security monitoring (N… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/06/19/selks-open-source-suricata-ids-ips-network-security-monitoring-threat-hunting/
-
Chinese Hackers Used Open-Source Rootkits for Espionage
UNC3886 Targeted Edge Devices for Persistence, Mandiant Says. A suspected Chinese hacking group used open-source rootkits to ensure persistence on com… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/chinese-hackers-used-open-source-rootkits-for-espionage-a-25571
-
Multiple OpenJDK Vulnerabilities Addressed in Ubuntu
OpenJDK, a widely used open-source implementation of Java, recently had several security vulnerabilities patched in Ubuntu. These issues could allow a… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/06/multiple-openjdk-vulnerabilities-addressed-in-ubuntu/

