GitHub launches Security Lab to boost open source security

Credit to Author: John E Dunn| Date: Mon, 18 Nov 2019 11:24:32 +0000

The idea is simple – create a global platform for reporting and fixing vulnerabilities in open source projects before they do damage.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/pPayEpWTksQ” height=”1″ width=”1″ alt=””/>

Read more

Retailer Orvis.com Leaked Hundreds of Internal Passwords on Pastebin

Credit to Author: BrianKrebs| Date: Mon, 11 Nov 2019 17:33:27 +0000

Orvis, a Vermont-based retailer that specializes in high-end fly fishing equipment and other sporting goods, leaked hundreds of internal passwords on Pastebin.com for several weeks last month, exposing credentials the company used to manage everything from firewalls and routers to administrator accounts and database servers, KrebsOnSecurity has learned. Orvis says the exposure was inadvertent, and that many of the credentials were already expired.

Read more

A week in security (October 7 – 13)

Credit to Author: Malwarebytes Labs| Date: Mon, 14 Oct 2019 15:30:38 +0000

A look at the cybersecurity news from October 7 – 13, including updates on war shipping, managed service providers, and stalkerware.

Categories:

Tags:

(Read more…)

The post A week in security (October 7 – 13) appeared first on Malwarebytes Labs.

Read more

Copy-and-paste sharing on Stack Overflow spreads insecure code

Credit to Author: John E Dunn| Date: Wed, 09 Oct 2019 10:45:30 +0000

It’s the time-saving technique employed by many coders – copy and paste code from crowd-sourcing ‘Q&#38;A’ websites. But is it always secure?<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/owsdar3-5Ug” height=”1″ width=”1″ alt=””/>

Read more

Hackers are infecting WordPress sites via a defunct plug-in

Credit to Author: Danny Bradbury| Date: Thu, 26 Sep 2019 10:37:03 +0000

If you’re a Wordpress admin using a plug-in called Rich Reviews, you’ll want to uninstall it. Now.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/qE8j8GEJrAI” height=”1″ width=”1″ alt=””/>

Read more

GitHub ‘encourages’ hacking, says lawsuit following Capital One breach

Credit to Author: Lisa Vaas| Date: Tue, 06 Aug 2019 12:17:54 +0000

The class action charges Capital One and GitHub, charging it with being “friendly” (at least) toward hacking and for the hackers’ posts.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/SJBRTxPFXi8″ height=”1″ width=”1″ alt=””/>

Read more