FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ The Hacker News

New Security Vulnerabilities Uncovered in pfSense Firewall Software - Patch Now

By: Newsroom β€” December 15th 2023 at 11:02
Multiple security vulnerabilities have been discovered in the open-source Netgate pfSense firewall solution called pfSense that could be chained by an attacker to execute arbitrary commands on susceptible appliances. The issues relate to two reflected cross-site scripting (XSS) bugs and one command injection flaw, according to new findings from Sonar. "Security inside a local network is often
☐ β˜† βœ‡ The Hacker News

Researchers Uncover Publisher Spoofing Bug in Microsoft Visual Studio Installer

By: Ravie Lakshmanan β€” June 12th 2023 at 12:47
Security researchers have warned about an "easily exploitable" flaw in the Microsoft Visual Studio installer that could be abused by a malicious actor to impersonate a legitimate publisher and distribute malicious extensions. "A threat actor could impersonate a popular publisher and issue a malicious extension to compromise a targeted system," Varonis researcher Dolev TalerΒ said. "Malicious
☐ β˜† βœ‡ The Hacker News

Hackers Can Abuse Legitimate GitHub Codespaces Feature to Deliver Malware

By: Ravie Lakshmanan β€” January 17th 2023 at 12:45
New research has found that it is possible for threat actors to abuse a legitimate feature in GitHub Codespaces to deliver malware to victim systems. GitHub CodespacesΒ is a cloud-based configurable development environment that allows users to debug, maintain, and commit changes to a given codebase from a web browser or via an integration in Visual Studio Code. It also comes with a port
☐ β˜† βœ‡ The Hacker News

Hackers Can Abuse Visual Studio Marketplace to Target Developers with Malicious Extensions

By: Ravie Lakshmanan β€” January 9th 2023 at 07:21
A new attack vector targeting the Visual Studio Code extensions marketplace could be leveraged to upload rogue extensions masquerading as their legitimate counterparts with the goal of mounting supply chain attacks. The technique "could act as an entry point for an attack on many organizations," Aqua security researcher Ilay GoldmanΒ saidΒ in a report published last week. VS Code extensions,
❌