PROJET AUTOBLOG


The Hacker News

Site original : The Hacker News

⇐ retour index

Kinsing Cryptojacking Hits Kubernetes Clusters via Misconfigured PostgreSQL

lundi 9 janvier 2023 à 15:03
The threat actors behind the Kinsing cryptojacking operation have been spotted exploiting misconfigured and exposed PostgreSQL servers to obtain initial access to Kubernetes environments. A second initial access vector technique entails the use of vulnerable images, Sunders Bruskin, security researcher at Microsoft Defender for Cloud, said in a report last week. Kinsing has a storied history of

Kinsing Cryptojacking Hits Kubernetes Clusters via Misconfigured PostgreSQL

lundi 9 janvier 2023 à 15:03

New Study Uncovers Text-to-SQL Model Vulnerabilities Allowing Data Theft and DoS Attacks

lundi 9 janvier 2023 à 14:37
A group of academics has demonstrated novel attacks that leverage Text-to-SQL models to produce malicious code that could enable adversaries to glean sensitive information and stage denial-of-service (DoS) attacks. "To better interact with users, a wide range of database applications employ AI techniques that can translate human questions into SQL queries (namely Text-to-SQL)," Xutan Peng, a

New Study Uncovers Text-to-SQL Model Vulnerabilities Allowing Data Theft and DoS Attacks

lundi 9 janvier 2023 à 14:37

Why Do User Permissions Matter for SaaS Security?

lundi 9 janvier 2023 à 13:57
Earlier this year, threat actors infiltrated Mailchimp, the popular SaaS email marketing platform. They viewed over 300 Mailchimp customer accounts and exported audience data from 102 of them. The breach was preceded by a successful phishing attempt and led to malicious attacks against Mailchimp’s customers’ end users. Three months later, Mailchimp was hit with another attack. Once again, an