Aggregator
23,000 GitHub Repositories Targeted In Supply Chain Attack
In a massive security breach discovered this week, approximately 23,000 GitHub repositories have been compromised in what security experts are calling one of the largest supply chain attacks to date. The attackers exploited vulnerabilities in the software development pipeline to potentially distribute malicious code to thousands of downstream applications and services. GitHub, a platform hosting […]
The post 23,000 GitHub Repositories Targeted In Supply Chain Attack appeared first on Cyber Security News.
Google Quantum AI объединил волны вероятностей с теорией кодов
OKX suspends DEX aggregator after Lazarus hackers try to launder funds
CIAM Basics: A Comprehensive Guide to Customer Identity and Access Management in 2025
CIAM has evolved from a security tool into a business advantage. This comprehensive guide explores how CIAM solutions balance robust security with seamless user experiences, helping organizations build trust, enhance customer engagement, and navigate complex privacy regulations.
The post CIAM Basics: A Comprehensive Guide to Customer Identity and Access Management in 2025 appeared first on Security Boulevard.
CVE-2022-4223 | pgAdmin up to 6.16 HTTP API code injection (Issue 5593)
CVE-2024-0808 | Google Chrome up to 120.0.6099.224 WebUI integer underflow (FEDORA-2024-3f7345570a)
CVE-2024-26651 | Linux Kernel up to 6.8.1 sr9800 usbnet_get_endpoints Privilege Escalation (FEDORA-2024-2fcce4ffb7 / Nessus ID 207818)
CVE-2023-52628 | Linux Kernel up to 5.10.197/5.15.131/6.1.53/6.5.3 nftables nft_payload.c out-of-bounds write
CVE-2024-26659 | Linux Kernel up to 5.10.212/5.15.151/6.1.81/6.6.16/6.7.4 xhci buffer overflow
CVE-2023-52636 | Linux Kernel up to 6.6.16/6.7.4 libceph read_partial_sparse_msg_data state issue (da9c33a70f09/bd9442e553ab/8e46a2d068c9)
CVE-2023-52633 | Linux Kernel up to 5.15.148/6.1.76/6.6.15/6.7.3 timer_read denial of service
CVE-2024-26656 | Linux Kernel up to 6.8.x amdgpu amdgpu_gem_userptr_ioctl use after free (22207fd5c801 / Nessus ID 210888)
CVE-2024-26664 | Linux Kernel up to 6.7.4 hwmon out-of-bounds (Nessus ID 210815)
CVE-2023-52634 | Linux Kernel up to 6.7.3 DRM disable_otg_wa denial of service (ce29728ef648/2ce156482a6f / Nessus ID 210815)
CVE-2023-52635 | Linux Kernel up to 5.10.209/5.15.148/6.1.76/6.6.15/6.7.3 Virtual Address cancel_delayed_work_sync buffer overflow (Nessus ID 210815)
CVE-2023-52632 | Linux Kernel up to 6.1.76/6.6.15/6.7.3 amdkfd __synchronize_srcu denial of service (Nessus ID 210815)
Hackers Rapidly Adopt ClickFix Technique for Sophisticated Attacks
In recent months, a sophisticated social engineering technique known as ClickFix has gained significant traction among cybercriminals and nation-state-sponsored groups. This method exploits human psychology by presenting users with fake prompts that appear to resolve a non-existent issue, effectively bypassing traditional security measures. The ClickFix technique involves deceiving users into executing malicious PowerShell commands by […]
The post Hackers Rapidly Adopt ClickFix Technique for Sophisticated Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Supply Chain Attack Targets 23,000 GitHub Repositories
A critical security incident has been uncovered involving the popular GitHub Action tj-actions/changed-files, which is used in over 23,000 repositories. The attack involves a malicious modification of the Action’s code, leading to the exposure of CI/CD secrets in GitHub Actions build logs. This vulnerability was detected by StepSecurity’s Harden-Runner, a tool designed to secure CI/CD […]
The post Supply Chain Attack Targets 23,000 GitHub Repositories appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.