Experts Warn of Unprotected Prometheus Endpoints Exposing Sensitive Information

Blog WriterThe Hacker News - Original news source is thehackernews.com

A large-scale unauthenticated scraping of publicly available and non-secured endpoints from older versions of Prometheus event monitoring and alerting solution could be leveraged to inadvertently leak sensitive information, according to …

Critical Flaw in OpenSea Could Have Let Hackers Steal Cryptocurrency From Wallets

Blog WriterThe Hacker News - Original news source is thehackernews.com

A now-patched critical vulnerability in OpenSea, the world’s largest non-fungible token (NFT) marketplace, could’ve been abused by malicious actors to drain cryptocurrency funds from a victim by sending a specially-crafted …

[eBook] The Guide for Reducing SaaS Applications Risk for Lean IT Security Teams

Blog WriterThe Hacker News - Original news source is thehackernews.com

The Software-as-a-service (SaaS) industry has gone from novelty to an integral part of today’s business world in just a few years. While the benefits to most organizations are clear – …

Update Your Windows PCs Immediately to Patch 4 New 0-Days Under Active Attack

Blog WriterThe Hacker News - Original news source is thehackernews.com

Microsoft on Tuesday rolled out security patches to contain a total of 71 vulnerabilities in Microsoft Windows and other software, including a fix for an actively exploited privilege escalation vulnerability that could …

GitHub Revoked Insecure SSH Keys Generated by a Popular git Client

Blog WriterThe Hacker News - Original news source is thehackernews.com

Code hosting platform GitHub has revoked weak SSH authentication keys that were generated via the GitKraken git GUI client due to a vulnerability in a third-party library that increased the likelihood of …

Digital Signature Spoofing Flaws Uncovered in OpenOffice and LibreOffice

Blog WriterThe Hacker News - Original news source is thehackernews.com

The maintainers of LibreOffice and OpenOffice have shipped security updates to their productivity software to remediate multiple vulnerabilities that could be weaponized by malicious actors to alter documents to make …

Microsoft Fended Off a Record 2.4 Tbps DDoS Attack Targeting Azure Customers

Blog WriterThe Hacker News - Original news source is thehackernews.com

Microsoft on Monday revealed that its Azure cloud platform mitigated a 2.4 Tbps distributed denial-of-service (DDoS) attack in the last week of August targeting an unnamed customer in Europe, surpassing …

Microsoft Warns of Iran-Linked Hackers Targeting US and Israeli Defense Firms

Blog WriterThe Hacker News - Original news source is thehackernews.com

An emerging threat actor likely supporting Iranian national interests has been behind a password spraying campaign targeting U.S., E.U., and Israeli defense technology companies, with additional activity observed against regional …