GitHub Repositories Are Vulnerable To RepoJacking

0
[ad_1]
Attack on GitHub Repositories

An attack called RepoJacking may potentially affect millions of GitHub repositories.

If abused, this vulnerability might result in code execution on the internal networks of organizations or on the networks of their customers. 

This includes the repositories of companies like Google, Lyft, and many others. It has many high-quality targets that are vulnerable to attack.

About 2.95% of the 1.25 million GitHub repositories examined by AquaSec’s security team, “Nautilus,” were vulnerable to RepoJacking.

How RepoJacking Attack Works?

RepoJacking is an attack in which a hostile actor registers a login and establishes a repository previously used by a company but whose name has subsequently changed.

On GitHub, username and repository name changes are frequent because companies often acquire or merge with another company to get new management, or they may decide to adopt a new brand name.

When this occurs, a redirection is made to prevent projects employing code from renamed repositories from breaking dependencies; however, if the previous name is registered, the redirection is rendered invalid.

repo

By doing this, any code or project that depends on the attacked project’s dependencies will retrieve those dependencies and other code from the attacker-controlled repository, which may include malware.

As an alternative, the same thing may occur if control of a repository is handed to another user and the original account is removed, enabling an attacker to start an account with the old username.

A threat actor may gather a list of distinct repositories using services like GHTorrent to harvest GitHub metadata linked to public commits and pull requests.

According to the information shared with Cyber Security News, the findings imply that millions of repositories may be susceptible to a similar assault, given that GitHub has over 330 million repositories.

One such repository is Google/mathsteps, formerly owned by Socratic (socraticorg/mathsteps), a business that Google purchased in 2018.

“When you access https://github.com/socraticorg/mathsteps, you are being redirected to https://github.com/google/mathsteps so eventually the user will fetch Google’s repository,” the researchers said.

“However, because the socraticorg organization was available, an attacker could open the socraticorg/mathsteps repository, and users following Google’s instructions will clone the attacker’s repository instead.

And because of the npm install, this will lead to arbitrary code execution on the users.”

Millions of vulnerable repositories

GitHub has safeguards against RepoJacking attacks since it is aware of this risk. Reports indicate that the remedies provided thus far are insufficient and simple to get around.

Because GitHub, for instance, only shields the most well-known projects, the supply chain breach also affects the lesser-known, more susceptible projects that depend on them.

Also, a repository’s name is changed, and GitHub safeguards it with over 100 clones, a sign of malicious planning.

This protection does not cover projects that gained popularity after being given a new name or changing ownership.

Mitigation

  • Check your repositories regularly for any links that might pull resources from outside GitHub repositories, as references to projects like Go modules could, at any point, alter their names.
  • If you change your company’s name, be sure you still own the former name—even if it’s only a placeholder—to stop intruders from using it.

Manage and secure Your Endpoints Efficiently – Free Download


[ad_2]
Source link

6 tips for a cybersecure honeymoon

0
[ad_1]

Your big day is over, but while you’re relaxing on honeymoon you don’t want to get distracted by security problems. So, we rounded up some quick tips to keep your devices safe.

You’ve done it, you’ve got married. The big day is over, and while you’re relaxing on honeymoon you definitely don’t want to get distracted by security problems. So, we rounded up some quick tips to keep you safe.

  • Refrain from posting on social media about your honeymoon. This is good practice before you leave as well. You don’t want people knowing that your home will be empty, so it’s better to wait to show off your honeymoon happiness until you get back home.
  • Feel free to use a VPN. Hotel and airport Wi-Fi is safer now than years ago, thanks to HTTPS everywhere. But if you still can’t shake the feeling of being “exposed,” use a VPN you trust
  • Turn on Find My device. Both iOS and Android offer ways for you to track your device. So turn this on before you go, and if you lose your device you can remotely wipe it, or even leave a message on the screen for whoever finds it.
  • Use strong passwords and encryption. If you don’t use a strong password on all devices, now is the time to change that. Better still, invest in a Password Manager. And make sure that all data stored on your devices is encrypted and backed up before you go.
  • Turn off Bluetooth connectivity. As a rule of thumb, turn it off it if you don’t use it. If you can’t do that, disable it when it’s not in use. Keeping it enabled could allow someone to discover what other devices you have connected to before, pretend to be one of those devices, and gain access to your device.
  • Leave your device in the hotel’s safe. When you’re not using a device, keep it in the safe. What you don’t bring along, you can’t lose or drop in the ocean.

Happy honeymoon!


[ad_2]
Source link

Sony will continue making smartphones for years to come

0
[ad_1]

Qualcomm has announced that Sony will continue making smartphones, for years to come. Qualcomm basically shared a press release in which it’s confirmed that Qualcomm’s partnership with Sony has been extended.

Sony will continue making smartphones… for years to come

The company was quite specific, and mentioned that Sony will keep using its Snapdragon chip for years to come. Qualcomm mentioned a “multi-year” deal, though we’re still not sure how many years were agreed on exactly.

One thing worth noting is that Qualcomm didn’t mention “low-end”, so Sony will likely stick to high-end and mid-range tiers. The press statement says that Sony and Qualcomm’s “joint efforts will focus on the integration of Qualcomm Technologies’ advanced Snapdragon mobile platforms into Sony’s future smartphone lines, providing users with enhanced functionality, higher performance, and more immersive user experiences”.

So, if you were at all worried that Sony will bow out of the smartphone business, that won’t happen, at least not anytime soon. There were no indications of that, but Sony hasn’t really been selling a lot of its phones.

If you were worried about Sony’s smartphone business, don’t be

We all know how that ended for HTC and LG, but Sony is a different store entirely. Much like LG, it has the cash to push its mobile unit as long as it takes, but it also uses its phones in other ways. Sony uses them for showpieces in its movies, for example. On the flip side, there’s the PlayStation that they need to think about.

It’s not exactly a secret that you can play your PlayStation remotely via newer Sony flagships. That alone is a selling point for some people, of course. Sony’s smartphones are here to stay.

I said earlier that Sony is not selling many of its phones, which is a shame, because they’re usually really good.


[ad_2]
Source link

Vimeo launches new AI tools to simplify the editing process

0
[ad_1]

In this day and age of artificial intelligence, every company has been making efforts to integrate generative AIs into their services to make things easier for the end user. Now, in a recent development, Vimeo has introduced a suite of new AI tools powered by OpenAI’s ChatGPT, which will revolutionize the video creation and editing process for its users.

These AI tools are a result of a survey conducted by Vimeo, which revealed that 50% of their customers require multiple takes during video creation, and among those who reshoot, 25% go through over five takes. Ashraf Alkarmi, Vimeo’s Chief Product Officer, explained that these new AI capabilities primarily target entry-level video creators, including employees and social media managers, who often face challenges due to limited skills, time constraints, and resource limitations when it comes to achieving desired effects in video production.

Text-based video editing

Similar to Adobe’s implementation, the text-based video editing tool will provide an effective way for everyday users to edit videos. For example, if your videos contain an excessive amount of filler words like “um” and “ah,” you can ask the AI to automatically remove them. Additionally, the AI also generates a transcript of the video content, allowing users to search for specific words within the transcript and seamlessly delete unwanted sections. Moreover, if you want to create shorter clips tailored for social media platforms, the transcript feature will help you highlight the most important sections.

Furthermore, the company has introduced a new script generator that leverages generative AI, specifically the OpenAI API, to generate video scripts based on brief descriptions and key inputs such as tone (e.g., confident, inspiring, or casual) and desired length.

On-screen teleprompter

In an effort to ensure the smooth delivery of dialogues in videos, Vimeo is also debuting an on-screen teleprompter, which allows users to display scripts with customizable font sizes and pacing, enabling them to stay on the script while engaging with the camera and maintaining eye contact.

“We’re clearly only scratching the surface of what AI can accomplish for organizations and the people within them, and I envision a future in which AI knowledge is a prerequisite, not a luxury, to video production,” said Ashraf Alkarmi.

However, it is important to note that these features will officially launch in July through the company’s Standard and Pro subscription plans, costing $20 (billed annually).


[ad_2]
Source link

Microsoft Teams Vulnerability Let Attackers Deliver Malware

0
[ad_1]
Microsoft Teams Vulnerability

The latest version of Microsoft Teams had a security flaw uncovered recently by Max Corbridge (@CorbridgeMax) and Tom Ellson (@tde_sec), JUMPSEC’s Red Team members.

Due to this flaw, there is a possibility for malware to be injected into organizations that rely on the default configuration of Microsoft Teams.

Microsoft Teams is used by over 280 million active users every month and is a popular way for organizations to talk and work together usin Microsoft 365.

Teams Vulnerability

Successful exploitation of this vulnerability enables the threat actors to evade the client-side security controls. This security feature prohibits users outside the organization from sending any file to the organization’s internal users.

Corbridge asserted in a report that the communication bridge they discovered is more vital because it can send harmful stuff straight to someone’s email, which is more potent than just tricking them.

Apart from this, two Jumpsec’s Red Team members uncovered a solution to circumvent the existing limitation.

They did this by altering the recipient ID in the POST request of a message for internal and external recipients, thereby tricking the system into recognizing an external user as an internal user.

In pragmatic trials, the researchers applied the technique. They successfully infiltrated a command and control payload into the inbox of a target organization, all while operating covertly as part of their red team exercise.

Attackers easily infect organizations using Microsoft Teams by bypassing security measures and anti-phishing training, exploiting the default configuration of it.

By registering a domain similar to the target’s Microsoft 365, the attacker can create messages that appear internal rather than external, increasing the chance of the target downloading the file without suspicion.

Response From Microsoft

Researchers notified Microsoft of their findings, expecting an immediate response due to the considerable impact observed.

Despite Microsoft acknowledging the flaw’s existence, its response indicated that it does not meet the threshold for immediate action, implying a lack of urgency to address the issue.

To minimize risk, organizations utilizing Microsoft Teams without requiring regular communication with external users should disable this feature. And to do this, you have to follow the simple steps that we have mentioned below:-

  • First of all, go to Microsoft Teams Admin Center.
  • Then access the External Access option.
  • After that, you must disable the chat with external unmanaged Teams users.

Organizations can establish an allow-list for specific domains to mitigate exploitation risks when maintaining external communication channels.

Manage and Secure Your Endpoints Efficiently – Free Download


[ad_2]
Source link

Reducing your attack surface is more effective than playing patch-a-mole

0
[ad_1]

There is a lot to be said for the strategy of shielding management interfaces from public internet access

On June 13, 2023 the Cybersecurity and Infrastructure Security Agency (CISA) issued Binding Operational Directive (BOD) 23-02. BOD 23-02 is titled Mitigating the Risk from Internet-Exposed Management Interfaces, and requires federal civilian agencies to remove specific networked management interfaces from the public-facing internet, or implement Zero Trust Architecture capabilities that enforce access control to the interface within 14 days of discovery.

Harsh as that may sound, there is a lot to be said for the strategy of shielding management interfaces from public internet access, or if that’s not an option, to apply every possible access control to make sure that only authorized people have access to the management part of the application.

As we have experienced a few times, applying timely patches is absolutely no guarantee you’ll be safe. Take for example the recent MOVEit vulnerability that was used against hundreds of victims before anyone even became aware of the fact that the vulnerability existed.

And new vulnerabilities are disclosed at a worrying rate. To demonstrate that point, here’s a quick roundup of the ones I looked at just yesterday.

  • Researchers discovered two dangerous vulnerabilities with Azure Bastion and Azure Container Registry that could allow attackers to achieve cross-site scripting (XSS), injecting malicious scripts into trusted websites. Exploitation of the vulnerabilities could have potentially allowed hackers to gain access to a target’s session within the compromised Azure service.
  • Zyxel warned its NAS (Network Attached Storage) devices users to update their firmware to fix a critical severity command injection vulnerability. The newly discovered vulnerability, CVE-2023-27992, is a pre-authentication command injection problem that could allow an unauthenticated attacker to execute operating system commands by sending specially crafted HTTP requests.
  • VMWare published a security advisory about multiple vulnerabilities in Aria Operations for Networks. Of these vulnerabilities, CVE-2023-20887 was confirmed to be exploited in the wild. Successful exploitation would allow a malicious actor with network access to VMware Aria Operations for Networks to perform a command injection attack resulting in remote code execution.
  • We reported about ASUS fixing nine security flaws in several router models. Among them were two critical vulnerabilities that could lead to memory corruption, and one vulnerability that could allow a remote unauthenticated attacker to achieve arbitrary code execution.

These are applications and services that we find in many organizations’ networks. Finding the vulnerable instances and applying the patches could be more than a day’s work in some cases.

But, a workaround that would have worked for many of the above is disablingor minimizing the internet facing access.

This supports the warning from CISA director Jen Easterly, who said:

“Too often, threat actors are able to use network devices to gain unrestricted access to organizational networks, in turn leading to full-scale compromise. Requiring appropriate controls and mitigations outlined in this Directive is an important step in reducing risk to the federal civilian enterprise. While this Directive only applies to federal civilian agencies, as the threat extends to every sector, we urge all organizations to adopt this guidance. When it comes to reducing cyber risk and ensuring resilience, we all have a role to play.”

Recommendations

In a nutshell, the recommendations from CISA to minimize your attack surface are:

  • Remove management interfaces from the internet by making them only accessible from an internal enterprise network. CISA recommends network segmentation to create an isolated management network.
  • Deploy capabilities that enforce access control to the interface through a policy enforcement point separate from the interface itself. In other words, don’t rely on the access control of the instance itself, once it’s vulnerable it could be easy to circumvent.

For more information, we encourage you to read the directive. While the primary audience for this document is FCEB agencies, other organizations may find the content useful.


Malwarebytes EDR and MDR removes all remnants of ransomware and prevents you from getting reinfected. Want to learn more about how we can help protect your business? Get a free trial below.

TRY NOW


[ad_2]
Source link

Echo Pop + 4 Months of Amazon Music Unlimited for Just $39.99

0
[ad_1]

Amazon has brought back one of its more popular deals, but this time for the Echo Pop. You can bundle the Echo Pop with 4 months of Amazon Music Unlimited for just $39.99. That’s basically getting the Echo Pop for the regular price, and getting four months of Amazon Music Unlimited for free.

This deal is only available for some customers. It appears that you do need to be an Amazon Prime Member. As well as not currently subscribing to Amazon Music Unlimited, to get this deal. So you need Prime, and can’t have Music Unlimited.

Echo Pop & Amazon Music Unlimited – Amazon

Why you should buy the Echo Pop & Amazon Music Unlimited bundle

The Echo Pop is a small, affordable, and easy-to-use smart speaker that is perfect for anyone who wants to get started with the world of Alexa. It features a sleek, compact design that fits in any space, and it can be used to control your smart home devices, get information, play music, and more.

Amazon Music Unlimited is a premium music streaming service that offers access to over 90 million songs, ad-free. You can listen to your favorite songs on-demand, and you can also create custom playlists and stations.

With the Echo Pop and 4 months of Amazon Music Unlimited bundle, you get the best of both worlds. You get a great smart speaker that is perfect for everyday use. And you also get access to a premium music streaming service that will keep you entertained for hours on end.

Here are some of the reasons why you should buy this bundle:

  • It’s a great value: The Echo Pop is priced at $49.99, and Amazon Music Unlimited is priced at $9.99 per month. So, you’re saving $30 when you buy the bundle.
  • It’s the perfect way to get started with Alexa: If you’ve never used Alexa before, the Echo Pop is a great way to get started. It’s easy to use and set up, and it’s a great way to learn about all the things that Alexa can do.
  • It’s the perfect way to listen to music: Amazon Music Unlimited is a great music streaming service. It has a huge library of songs, and you can listen to them ad-free.
  • It’s a great gift: If you’re looking for a great gift for someone who loves music, the Echo Pop and 4 months of Amazon Music Unlimited bundle is a perfect choice.

If you’re looking for Alexa and enjoy ad-free music, then this bundle is a great choice for you.

If you’re looking for a versatile and easy-to-use smart speaker, then this bundle is a great option.

Echo Pop & Amazon Music Unlimited – Amazon


[ad_2]
Source link

AI music won’t be able to win a Grammy

0
[ad_1]

AI-generated music is making its presence known in the music industry, but the Recording Academy looks in the opposite direction. In a recent interview, the Academy made up its mind known regarding this kind of music. Will they make an appearance in various categories during the award shows, or will they take the back seat?

This question might weigh down on the minds of lots of people looking forward to this year’s award ceremony. The past few months have brought a ton of AI-generated music to the internet, but Grammy will ignore these entries. From the interview, the Recording Academy makes it clear that they will only consider human creators for their award categories.

From this decision, it is clear that the Academy is already setting a standard and guidelines to govern the use of AI in music production. Certainly, AI-based technology will shape lots of industries, including the music industry, and the Recording Academy recognizes this. But, by updating their requirements for music and performances to win awards, the academy is leveling the playing field.

More information regarding the Grammy’s decision on AI-generated music

From the Recording Academy’s decision regarding AI-generated music, it is clear that the focus is on human creativity. The entire creative process leading to the release of the song needs to be from a human. Songs written or produced by AI would not be considered in Grammy categories.

However, songs that have AI influence in certain elements of the creative process might be considered. Performance categories of the Grammy Awards will also ignore AI-generated music performances and focus more on human creativity. If a song or performance was created or done by an AI model, hence lacking human creativity, the Recording Academy will not consider such entries.

For some reason, the Recording Academy will still accept AI-generated music and content submission. Possibly they will then evaluate these submissions to determine the level of human creativity before vetting them as being fit or not fit for consideration. Giving room for AI assistance in music creation shows that even the Recording Academy acknowledges the role AI will play in the music industry.

In the coming future, the music industry might get to see some AI tools that might help them spice up their music and performances. However, these tools would not replace human creativity, but only improve the result of such creativity. Other music organizations and platforms are also fighting against AI-generated songs as they aim to push original content.


[ad_2]
Source link

What is XSS (Cross Site Scripting)?

0
[ad_1]
Cross Site Scripting

XSS is a very commonly exploited vulnerability type that is very widely spread and easily detectable, and also it is one of the important vulnerabilities in OWASP TOP 10.

What is XSS(Cross-Site Scripting )? An attacker can inject untrusted snippets of JavaScript into your application without validation.

This JavaScript is then executed by the victim who is visiting the target site. It is classified into three types.

  • Reflected XSS
  • Stored XSS
  • DOM-Based XSS

In Reflected XSS, an attacker sends the victim a link to the target application through email, social media, etc.

This link has a script that executes when visiting the target site.

In Stored XSS, the attacker can plant a persistent script in the target website which will execute when anyone visits it.

With DOM Based XSS, no HTTP request is required; the script is injected as a result of modifying the DOM of the target site in the client-side code in the victim’s browser and is then executed.

Understanding XSS – Cross-Site Scripting

                               http://test.gbhackers.com/search?q=gbhackers

                                   Searched for <strong>gbhackers</strong>

                                          <script>alert(document.cookie)</script>

Imagine that we have an URL like this, and we are searching for gbhackers, and it will reflect the following query in the browser.

We trust the domain, and we trust the resource being entered in the search page, so now the untrusted part gbhackers was the query string entered by the browser; the attacker can manipulate the value anything they like, for example, they change like this <script>alert(document.cookie)</script>.

This is just a simple query to pop up an alert on the webpage if someone requested the page of the attacker’s website and passed the document.

Cookies as a parameter in the website, then the attacker can gather all cookies.If they get Auth cookies, they can simply hijack user sessions.

xss
XSS Attack

Potential Risks of Cross-Site Scripting

The attacker can compromise or take over the victim’s user account in the application.

They could retrieve data from the target web application, modify content on the target page, redirect the victim to another malicious or spoof site, or use it to install other malware on the victim’s system.

The consequences of any of the above can seriously impact your ability to conduct business, your customers, and your organization’s reputation.

XSS
XSS Attack Flow

Defenses against Cross-Site Scripting

  • What input do we trust?
  • Does it adhere to expected patterns?
  • Never reflect untrusted data.
  • Applies to data within our database too.
  • Encoding of context(Java/attribute/HTML/CSS).

[ad_2]
Source link

Update now! Apple fixes three actively exploited vulnerabilities

0
[ad_1]

Apple has released security updates for several products to address a set of flaws it said were being actively exploited.

Apple has released security updates for several products to address a set of flaws that it says are being actively exploited.

Updates are available for these products:

Safari 16.5.1

macOS Big Sur and macOS Monterey

iOS 16.5.1 and iPadOS 16.5.1

iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later

iOS 15.7.7 and iPadOS 15.7.7

iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation)

macOS Ventura 13.4.1

 

macOS Monterey 12.6.7

 

macOS Big Sur 11.7.8

 

watchOS 9.5.2

Apple Watch Series 4 and later

watchOS 8.8.1

Apple Watch Series 3, Series 4, Series 5, Series 6, Series 7, and SE

 

The updates may already have reached you in your regular update routines, but it doesn’t hurt to check if your device is at the latest update level. If a Safari update is available for your device, you can get it by updating or upgrading macOS, iOS, or iPadOS.

How to update your iPhone or iPad.

How to update macOS on Mac.

The Common Vulnerabilities and Exposures (CVE) database lists publicly disclosed computer security flaws. The three actively exploited CVEs are:

CVE-2023-32434: a vulnerability in the Kernel due to an integer overflow. Successful exploitation would enable the attacker to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7. This vulnerability was part of the so-called Operation Triangulation.

CVE-2023-32435: a memory corruption issue in the WebKit component  for iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation). Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.This vulnerability was also part of the so-called Operation Triangulation.

CVE-2023-32439: a type confusion issue in the WebKit component. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

WebKit is the browser engine that powers Safari on Macs as well as all browsers on iOS and iPadOS (browsers on iOS and iPadOS are obliged to use it). It is also the web browser engine used by Mail, App Store, and many other apps on macOS, iOS, and Linux.

An integer overflow is a programming error that allows an attacker to manipulate a number the program uses in a way that might be harmful. If the number is used to set the length of a data buffer (an area of memory used to hold data), an integer overflow can lead to a buffer overflow, a vulnerability that allows an attacker to overloaded a buffer with more data than it’s expecting, which creates a route for the attacker to manipulate the program.

Type confusion vulnerabilities are programming flaws that happen when a piece of code doesn’t verify the type of object that is passed to it before using it. So let’s say you have a program that expects a number as input, but instead it receives a string (i.e. a sequence of characters), if the program doesn’t properly check that the input is actually a number and tries to perform arithmetic operations on it as if it were a number, it may produce unexpected results which could be abused by an attacker.

Type confusion can allow an attacker to feed function pointers or data into the wrong piece of code. In some cases, this could allow attackers to execute arbitrary code on a vulnerable device. So, an attacker would have to trick a victim into visiting a malicious website or open such a page in one of the apps that use WebKit to render their pages. In the case of Operation Triangulation these were reportedly delivered via iMessage as zero-click exploits.


We don’t just report on iOS security—we provide it

Cybersecurity risks should never spread beyond a headline. Keep threats off your iOS devices by downloading Malwarebytes for iOS today.


[ad_2]
Source link