PROJET AUTOBLOG


The Hacker News

Site original : The Hacker News

⇐ retour index

NIST Releases Updated Cybersecurity Guidance for Managing Supply Chain Risks

jeudi 5 mai 2022 à 16:14
The National Institute of Standards and Technology (NIST) on Thursday released an updated cybersecurity guidance for managing risks in the supply chain, as it increasingly emerges as a lucrative attack vector. "It encourages organizations to consider the vulnerabilities not only of a finished product they are considering using, but also of its components — which may have been developed elsewhere

Google to Add Passwordless Authentication Support to Android and Chrome

jeudi 5 mai 2022 à 15:43
Google today announced plans to implement support for passwordless logins in Android and the Chrome web browser to allow users to sign in across different devices and websites irrespective of the platform. "This will simplify sign-ins across devices, websites, and applications no matter the platform - without the need for a single password," Google said. <!--adsense--> Apple and Microsoft are

The Importance of Defining Secure Code

jeudi 5 mai 2022 à 13:14
The developers who create the software, applications and programs that drive digital business have become the lifeblood of many organizations. Most modern businesses would not be able to (profitably) function, without competitive applications and programs, or without 24-hour access to their websites and other infrastructure. And yet, these very same touchpoints are also often the gateway that

Researchers Disclose 10-Year-Old Vulnerabilities in Avast and AVG Antivirus

jeudi 5 mai 2022 à 13:02
Two high-severity security vulnerabilities, which went undetected for several years, have been discovered in a legitimate driver that's part of Avast and AVG antivirus solutions. "These vulnerabilities allow attackers to escalate privileges enabling them to disable security products, overwrite system components, corrupt the operating system, or perform malicious operations unimpeded,"

Heroku Forces User Password Resets Following GitHub OAuth Token Theft

jeudi 5 mai 2022 à 12:58
Salesforce-owned subsidiary Heroku on Thursday acknowledged that the theft of GitHub integration OAuth tokens further involved unauthorized access to an internal customer database. The company, in an updated notification, revealed that a compromised token was abused to breach the database and "exfiltrate the hashed and salted passwords for customers' user accounts." As a consequence, Salesforce