We immediately disclosed these vulnerabilities to the Jenkins team in January 2023, and they responded quickly by issuing a patch for the Jenkins server and the Jenkins Update https://t.co/8RUN3QCiDw our blog for more information (https://t.co/ZdQGkKjklN)
#jenkins#cve (5/5)๐งต
๐ Ubuntu users, beware! Hackers can exploit a #vulnerability in the command-not-found utility to recommend and trick you into installing rogue packages via snap repositories.
Learn more: https://t.co/pOLdRv5buc
Double-check sources before installation.
#Linux#Cybersecurity
We also found that 26% of the apt packages' commands could be impersonated by attackers!
Understand our findings, implications, and defenses for developers and users alike on our blog.
(3/3) ๐งต
In our research, we delve into how attackers can manipulate the 'command-not-found' package into suggesting their malicious snap packages. We explain how the suggestion mechanism works and the dangers of installing malicious snap packages.
(2/3) ๐งต
๐จ Snap Trap: The Hidden Dangers Within Ubuntuโs Package Suggestion System ๐จ
Attackers could manipulate the package suggestion mechanism in Ubuntu to fool users into installing malicious packages.
https://t.co/YJhVxa4Ejr
@AquaSecTeam
(1/3) ๐งต
#Ubuntu#SSC#CyberSecurity
In this blog, we detail our criteria for npm package deprecation and introduce Dependency-Deprecated-Checker, our new open-source tool. This tool scans your package.json file and alerts you about deprecated packages.
(4/4) ๐งต
๐จDeceptive Deprecation: The Truth About npm Deprecated Packages - new research๐จ
8.2% of popular npm packages are officially deprecated.
However, our study suggests the real number is closer to 21.2%!
@AquaSecTeam@YakirKad
https://t.co/HMveSfDS4J
(1/4) ๐งต
#npm#cve
Moreover, these developers sometimes archived the corresponding repository instead of officially deprecating the package at npm. This behavior led to a discrepancy between the official deprecation status of the package at npm, to the actual deprecation of the package.
(3/4) ๐งต
In this #RSAC 2023 presentation, speakers @YakirKad and @GoldmanIlay elaborate on the many attack vectors in the supply chain ecosystem, including integrated development environment (IDE), source code management (SCM), package managers and CI/CD. https://t.co/BcOdfThE66
๐ Unlock the secrets of supply chain vulnerabilities! Check out this informative session from BlackHat Asia 2023, "Breaking the Chain", where the attacker's perspective is examined across 5 phases of the cloud development flow.
๐ Watch now: https://t.co/MEwLdhyrKe
Presented by: @YakirKad & @GoldmanIlay
#supplychainsecurity #cloudsecurity #blackhatasia2023
In our blog, we delve into Microsoft's lack of protection regarding impersonation of popular packages. Additionally, we explore how attacker's unearth hidden packages, potentially exposing secrets.
These flaws were confirmed by Microsoft, but they still persist!
(2/2) ๐งต
๐จPowerShell Gallery: Security Alert- New Research๐จ
The PowerShell Gallery stands as a vital registry for modules and scripts (over 9 Billion downloads). However, it is not as protected as we thought it to be.
https://t.co/xonpK70728
(1/2) ๐งต
โ๏ธ GitHub Repositories Vulnerable to RepoJacking
Obtaining remote code execution on 37K GitHub repos via RepoJacking:
* Exploitation Scenarios
* RepoJacking Restrictions and Bypasses
* Summary and Mitigations
+ more!
By @goldmanilay and @YakirKad
https://t.co/scnjPmVkyT