Vue normale

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.
Hier — 2 juillet 2024Sécurité

Dev rejects CVE severity, makes his GitHub repo read-only

Par : Ax Sharma
30 juin 2024 à 14:31
The popular open source project, 'ip' had its GitHub repository archived, or made "read-only" by its developer as a result of a dubious CVE report filed for his project. Unfortunately, open-source developers have recently been met with an uptick in debatable or outright bogus CVEs filed for their projects. [...]
À partir d’avant-hierSécurité

Polyfill claims it has been 'defamed', returns after domain shut down

Par : Ax Sharma
27 juin 2024 à 10:57
The owners of Polyfill.io have relaunched the JavaScript CDN service on a new domain after polyfill.io was shut down as researchers exposed it was delivering malicious code on upwards of 100,000 websites.. The Polyfill service claims that it has been "maliciously defamed" and been subject to "media messages slandering Polyfill." [...]

Cloudflare: We never authorized polyfill.io to use our name

Par : Ax Sharma
27 juin 2024 à 09:18
Cloudflare, a lead provider of content delivery network (CDN) services, cloud security, and DDoS protection has warned that it has not authorized the use of its name or logo on the Polyfill.io website, which has recently been caught injecting malware on more than 100,000 websites in a significant supply chain attack. [...]

GitLab affected by GitHub-style CDN flaw allowing malware hosting

Par : Ax Sharma
22 avril 2024 à 15:05
BleepingComputer recently reported how a GitHub flaw, or possibly a design decision, is being abused by threat actors to distribute malware using URLs associated with Microsoft repositories, making the files appear trustworthy. It turns out, GitLab is also affected by this issue and could be abused in a similar fashion. [...]
❌
❌