Information Security News Blog
In recent security news, two researchers, Thomas Chauchefoin and Paul Gerste from SonarSource, have disclosed technical details for a critical Visual Studio Code remote code execution vulnerability and shared a public proof-of-concept (PoC) exploit....
On November 19, the team at market maker Kronos Research encountered a significant issue: a leakage of their API keys resulted in the loss of approximately $26 million in cryptocurrencies. Kronos Research initiated an...
On Sunday, the hacker group SiegedSec, known for their politically motivated attacks, claimed on Telegram to have breached the personnel management application of the Idaho National Laboratory. The group alleges that it accessed detailed...
In the realm of machine learning, Apache Submarine has emerged as a prominent End-to-End Machine Learning Platform, empowering data scientists to seamlessly create and manage machine learning workflows. This versatile platform caters to the...
Atlassian has recently disclosed a critical vulnerability affecting the Bamboo Data Center and Server. This vulnerability, classified as CVE-2023-22516, allows an authenticated attacker to execute arbitrary code on the affected system, posing a severe...
Atomic Stealer, also known as AMOS, is a popular stealer for Mac OS. In September, security researchers from Malwarebytes described how malicious ads were tricking victims into downloading this piece of malware under the...
A critical vulnerability dubbed Looney Tunables in the GNU C library (glibc), a core component of Linux-based systems, has been added to the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV)...
Synology, a leading provider of network-attached storage (NAS) and surveillance solutions, has issued a security advisory to address a high-severity vulnerability affecting Synology Router Manager (SRM). This vulnerability, discovered during the PWN2OWN 2023 security...
GIMP, the GNU Image Manipulation Program, is a widely used open-source image editing software that has gained immense popularity among graphic designers and enthusiasts. However, recent discoveries have revealed four critical security vulnerabilities that...
GibbonEdu is an open-source educational software used by schools and institutions worldwide. A critical vulnerability tracked as CVE-2023-45878 carries a CVSS score of 9.8 and affects GibbonEdu versions 25.0.1 and earlier. This vulnerability allows...
In the Python Package Index (PyPI) repository, counterfeit packages disseminating malicious software were detected. These packages, masquerading as popular Python libraries, garnered thousands of downloads globally, including in the United States and China. A...
Japanese motorcycle manufacturer Yamaha Motor and the American healthcare organization WellLife Network have confirmed cyberattacks on their networks following the publication of their data on a leak site operated by a hacker group utilizing...