admin

AWS patches bypass bug in CloudTrail API monitoring tool

Threat actors exploring AWS environments and API calls could potentially go undetected. Amazon Web Services (AWS) has addressed a bypass vulnerability that could allow attackers to evade CloudTrail API monitoring. In a blog entry on January 17, Nick Frichette, senior researcher at Datadog Security Labs, addressed this important vulnerability affecting the CloudTrail event logging service,…

Read More

AWS patches bypass bug in CloudTrail API monitoring tool

Malicious actors exploring AWS environments and API interactions may operate without detection. Amazon Web Services (AWS) has addressed a vulnerability that could potentially allow attackers to evade CloudTrail API monitoring. In a January 17 blog entry, Datadog Security Labs senior researcher Nick Frichette noted that this vulnerability affects the CloudTrail event logging service, which serves…

Read More

Bitwarden responds to encryption design flaw criticism

Accusations Against Password Vault Provider Over Encryption Issues UPDATED Bitwarden, a password vault provider, has addressed renewed concerns regarding its encryption methods for safeguarding users’ secret keys by improving the security configuration of its mechanisms. This concern revolves around the number of PBKDF2 hash iterations utilized to generate the decryption key for a user’s password…

Read More

Bitwarden responds to encryption design flaw criticism

Concerns Raised Over Password Vault Vendor’s Encryption Practices UPDATED: Password vault provider Bitwarden has addressed renewed concerns surrounding its encryption strategy for safeguarding users’ secret keys by strengthening its default security configurations. The primary concern focuses on the number of PBKDF2 hash iterations used for generating a decryption key for a user’s password vault. According…

Read More

Yellowfin tackles auth bypass bug trio that opened door to RCE

Pre- and post-authentication vulnerabilities pose significant risks A trio of authentication bypass vulnerabilities have been identified and resolved in the widely-used enterprise analytics platform, Yellowfin BI. These vulnerabilities originate from the use of hardcoded keys, exposing the platform to potential exploitation. Initial research conducted by security experts from Assetnote revealed pre-authentication vulnerabilities, which later led…

Read More

Trellix automates tackling open source vulnerabilities at scale

Charlie Osborne 26 January 2023 at 13:52 UTC Updated: 26 January 2023 at 13:55 UTC Over 61,000 vulnerabilities resolved and still counting Trellix has successfully patched more than 61,000 projects impacted by a critical vulnerability in Python, utilizing an innovative automated system to streamline the remediation process significantly. Recently, researchers at the Trellix Advanced Research…

Read More

Trellix automates tackling open source vulnerabilities at scale

Charlie Osborne26 January 2023 at 13:52 UTC Updated: 26 January 2023 at 13:55 UTC Trellix has successfully patched over 61,000 vulnerabilities in open source projects, utilizing an automated tool to expedite the process against a significant Python bug. A year ago, the Trellix Advanced Research Center identified a long-standing vulnerability within Python’s tarfile module, which…

Read More
Back To Top