

Google pays hacker duo $22k in bug bounties for flaws in multiple cloud projects
Six payouts have been awarded for vulnerabilities discovered in Theia, Vertex AI, Compute Engine, and Cloud Workstations. Security vulnerabilities found in four Google Cloud Platform (GCP) projects have resulted in over $22,000 in bug bounties for a team of researchers. The most profitable venture for the hacker duo Sreeram KL and Sivanesh Ashok was Vertex…

Popular password managers auto-filled credentials on untrusted websites
Recent research from Google has highlighted potential security vulnerabilities affecting several popular password management tools, including Dashlane, Bitwarden, and Safari’s built-in password manager. UPDATED: Security researchers at Google have issued warnings regarding vulnerabilities that could allow various password managers to automatically fill in credentials on untrusted websites. This disclosure came after Google notified the affected…

Popular password managers auto-filled credentials on untrusted websites
Recent research by Google has raised concerns regarding the security features of popular password management tools including Dashlane, Bitwarden, and Apple’s Safari. UPDATED According to the researchers, vulnerabilities exist that could potentially allow various password managers to inadvertently fill in user credentials on untrusted websites. The Google team revealed their findings on January 17, following…

Git security audit reveals critical overflow bugs
Recent security evaluations have unveiled multiple vulnerabilities across high, medium, and low-security spectrums. A detailed security review of Git’s source code has brought to light several vulnerabilities, including two major overflow bugs. The security audit, facilitated by the Open Source Technology Improvement Fund (OSTIF), was conducted by X41 D-Sec in collaboration with GitLab. This review…

Git security audit reveals critical overflow bugs
Recent security assessments have identified multiple vulnerabilities, including various high, medium, and low-risk issues. A comprehensive security audit of Git’s source code has unveiled numerous vulnerabilities, notably two critical overflow bugs. Conducted by X41 D-Sec and GitLab and backed by the Open Source Technology Improvement Fund (OSTIF), the audit also highlighted various high, medium, and…

Git security audit reveals critical overflow bugs
Recently identified vulnerabilities encompass a range of high, medium, and low-security issues. A security review of the Git source code has uncovered multiple vulnerabilities, including two critical overflow bugs. This audit, conducted by X41 D-Sec under the sponsorship of the Open Source Technology Improvement Fund (OSTIF), reveals several high, medium, and low-severity issues. Considering Git’s…

Git security audit reveals critical overflow bugs
Revealed vulnerabilities encompass several high, medium, and low-severity issues. A recent audit of Git’s source code has uncovered a number of vulnerabilities, including two critical overflow bugs. The audit, which was sponsored by the Open Source Technology Improvement Fund (OSTIF) and conducted by X41 D-Sec alongside GitLab, highlighted several high, medium, and low-severity security issues….

AWS patches bypass bug in CloudTrail API monitoring tool
Threat actors exploring AWS environments and API calls could potentially go undetected. Amazon Web Services (AWS) has addressed a bypass vulnerability that could allow attackers to evade CloudTrail API monitoring. In a blog entry on January 17, Nick Frichette, senior researcher at Datadog Security Labs, addressed this important vulnerability affecting the CloudTrail event logging service,…

AWS patches bypass bug in CloudTrail API monitoring tool
Malicious actors exploring AWS environments and API interactions may operate without detection. Amazon Web Services (AWS) has addressed a vulnerability that could potentially allow attackers to evade CloudTrail API monitoring. In a January 17 blog entry, Datadog Security Labs senior researcher Nick Frichette noted that this vulnerability affects the CloudTrail event logging service, which serves…

AWS patches bypass bug in CloudTrail API monitoring tool
Threat actors exploring AWS environments and API calls may operate undetected Amazon Web Services (AWS) has addressed a critical bypass vulnerability that could have been exploited by attackers to evade monitoring through the CloudTrail API. In a blog post published on January 17 by Datadog Security Labs, senior researcher Nick Frichette discussed how the vulnerability…