Code Execution Bug Affects Yamale Python Package — Used by Over 200 Projects

Blog WriterThe Hacker News - Original news source is thehackernews.com

A high-severity code injection vulnerability has been disclosed in 23andMe’s Yamale, a schema and validator for YAML, that could be trivially exploited by adversaries to execute arbitrary Python code. The …

New U.S. Government Initiative Holds Contractors Accountable for Cybersecurity

Blog WriterThe Hacker News - Original news source is thehackernews.com

The U.S. government on Wednesday announced the formation of a new Civil Cyber-Fraud Initiative that aims to hold contractors accountable for failing to meet required cybersecurity requirements in order to …

Twitch Suffers Massive 125GB Data and Source Code Leak Due to Server Misconfiguration

Blog WriterThe Hacker News - Original news source is thehackernews.com

Interactive livestreaming platform Twitch acknowledged a “breach” after an anonymous poster on the 4chan messaging board leaked its source code, an unreleased Steam competitor from Amazon Game Studios, details of creator payouts, …

Iranian Hackers Abuse Dropbox in Cyberattacks Against Aerospace and Telecom Firms

Blog WriterThe Hacker News - Original news source is thehackernews.com

Details have emerged about a new cyber espionage campaign directed against the aerospace and telecommunications industries, primarily in the Middle East, with the goal of stealing sensitive information about critical …

Multiple Critical Flaws Discovered in Honeywell Experion PKS and ACE Controllers

Blog WriterThe Hacker News - Original news source is thehackernews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday released an advisory regarding multiple security vulnerabilities affecting all versions of Honeywell Experion Process Knowledge System C200, C200E, C300, and ACE controllers …

Researchers Discover UEFI Bootkit Targeting Windows Computers Since 2012

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cybersecurity researchers on Tuesday revealed details of a previously undocumented UEFI (Unified Extensible Firmware Interface) bootkit that has been put to use by threat actors to backdoor Windows systems as early as …