Security
Headlines
HeadlinesLatestCVEs

Tag

#amazon

Lean, green coding machine: How sustainable computing drive can reduce attack surfaces

Less is often more when it comes to both infosec and eco-friendly computing practices

PortSwigger
#vulnerability#web#mac#google#microsoft#amazon#linux#red_hat#java#c++#pdf#aws#auth#ruby#chrome
Google WordPress Plug-in Bug Allows AWS Metadata Theft

A successful attacker could use the SSRF vulnerability to collect metadata from WordPress sites hosted on an AWS server, and potentially log in to a cloud instance to run commands.

Lego's Bricklink steps on cross site scripting blocks

Categories: News Tags: lego Tags: bricklink Tags: cross site scripting Tags: bug Tags: flaw We take a look at how Lego's Bricklink service was potentially vulnerable to certain types of XSS attack. (Read more...) The post Lego's Bricklink steps on cross site scripting blocks appeared first on Malwarebytes Labs.

Name That Toon: Kiss and Tell

Feeling creative? Submit your caption and our panel of experts will reward the winner with a $25 Amazon gift card.

How to Run Kubernetes More Securely

The open source container tool is quite popular among developers — and threat actors. Here are a few ways DevOps teams can take control.

AWS Elastic IP Transfer Feature Gives Cyberattackers Free Range

Threat actors can take over victims' cloud accounts to steal data, or use them for command-and-control for phishing attacks, denial of service, or other cyberattacks.

Elon Musk and the Dangers of Censoring Real-Time Flight Trackers

Elon Musk claims plane-tracking data is a risky privacy violation. But the world loses a lot if this information disappears—and that's already happening.

Akamai wrestles with AWS S3 web cache poisoning bug

Definitive solution is ‘non-trivial’ since behavior arises from customers processing non-RFC compliant requests

Are 100% Security Guarantees Possible?

Large vendors are commoditizing capabilities that claim to provide absolute security guarantees backed up by formal verification. How significant are these promises?

CVE-2022-40434: Build website, web app & portals on Airtable without code | Softr

Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page.