Aggregator
Crypto enthusiasts flood npm with more than 281,000 bogus packages overnight
Crypto enthusiasts have lately been flooding software registries like npm and PyPI with thousands of bogus packages that add no functional value and instead put a strain on the entire open source ecosystem.
A single instance, recorded by Sonatype in July 2024, saw 281,512 distinct packages appearing on the npmjs.com registry overnight — each package named a gibberish Latin phrase akin to Lorem Ipsum.
The post Crypto enthusiasts flood npm with more than 281,000 bogus packages overnight appeared first on Security Boulevard.
test
CVE-2024-5576 | Tutor LMS Elementor Addons Plugin up to 2.1.4 on WordPress Course Carousel Widget cross site scripting
CVE-2024-43317 | Metagauss User Registration Team RegistrationMagic Plugin up to 6.0.1.0 on WordPress cross site scripting
CVE-2024-43311 | Geek Code Lab Login As Users Plugin up to 1.4.2 on WordPress privileges management
CVE-2024-43354 | myCred Plugin up to 2.7.2 on WordPress deserialization
CVE-2024-43326 | Jamie Bergen Plugin Notes Plus Plugin up to 1.2.7 on WordPress authorization
CVE-2024-23729 | ColorOS Internet Browser 45.10.3.4.1 on Android com.android.browser.RealBrowserActivity cross site scripting
CVE-2024-42812 | D-Link DIR-860L 2.03 gena.cgi SID buffer overflow
CVE-2024-43345 | PluginOps Landing Page Builder Plugin up to 1.5.2.0 on WordPress path traversal
CVE-2024-42815 | TP-LINK RE365 V1_180213 /usr/bin/httpd USER_AGENT buffer overflow
CVE-2024-43328 | WPDeveloper EmbedPress Plugin up to 4.0.9 on WordPress path traversal
CVE-2024-7592 | Python Software CPython up to 3.13.0 http.cookies cookie resource consumption (ID 123067)
CISA adds Jenkins Command Line Interface (CLI) bug to its Known Exploited Vulnerabilities catalog
CISA adds Jenkins Command Line Interface (CLI) bug to its Known Exploited Vulnerabilities catalog
Announcing new EDR capabilities for Webroot Endpoint Protection
What You Missed About the CrowdStrike Outage:: The Next Strike Might Be Linux Due to eBPF
What You Missed About the CrowdStrike Outage:: The Next Strike Might Be Linux Due to eBPF
What You Missed About the CrowdStrike Outage:: The Next Strike Might Be Linux Due to eBPF
The Other Crowdstrike Outage On July 19, 2024, a flawed update in CrowdStrike Falcon's channel file 291 led to a logic error that caused Windows systems to crash, resulting in widespread BSOD (Blue Screen of Death) incidents. The impact was severe, disrupting critical infrastructure globally, from grounded flights to halted public transit systems. In fact, [...]
The post What You Missed About the CrowdStrike Outage:: The Next Strike Might Be Linux Due to eBPF appeared first on Wallarm.
The post What You Missed About the CrowdStrike Outage:: The Next Strike Might Be Linux Due to eBPF appeared first on Security Boulevard.