infosec Archives - Developer Tech News https://www.developer-tech.com/news/tag/infosec/ Gaming, Apps, HTML5, Java, PHP, C#, .net, IOT Thu, 28 Mar 2024 12:52:55 +0000 en-GB hourly 1 https://www.developer-tech.com/wp-content/uploads/sites/3/2020/09/dev-icon-60x60.png infosec Archives - Developer Tech News https://www.developer-tech.com/news/tag/infosec/ 32 32 PyPI suspends registrations amid malware attack https://www.developer-tech.com/news/2024/mar/28/pypi-suspends-registrations-amid-malware-attack/ https://www.developer-tech.com/news/2024/mar/28/pypi-suspends-registrations-amid-malware-attack/#respond Thu, 28 Mar 2024 12:52:52 +0000 https://www.developer-tech.com/?p=45836 The Python Package Index (PyPI) has suspended new project creation and user registration to mitigate an ongoing malware upload campaign. This move comes as security researchers at Checkmarx uncovered a campaign involving multiple malicious packages related to the same threat actors. The attackers are targeting victims through typosquatting attacks, tricking users into installing malicious Python... Read more »

The post PyPI suspends registrations amid malware attack appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/2024/mar/28/pypi-suspends-registrations-amid-malware-attack/feed/ 0
NVIDIA employs GenAI for rapid software vulnerability detection https://www.developer-tech.com/news/2024/mar/19/nvidia-genai-rapid-software-vulnerability-detection/ https://www.developer-tech.com/news/2024/mar/19/nvidia-genai-rapid-software-vulnerability-detection/#respond Tue, 19 Mar 2024 12:02:57 +0000 https://www.developer-tech.com/?p=45780 NVIDIA has demonstrated how its generative AI technologies can help to quickly identify and mitigate common vulnerabilities and exposures (CVEs) and other software security risks. The NVIDIA NIM and NeMo Retriever microservices – along with the Morpheus accelerated AI framework – enable security analysts to detect and mitigate risks in a matter of seconds, a... Read more »

The post NVIDIA employs GenAI for rapid software vulnerability detection appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/2024/mar/19/nvidia-genai-rapid-software-vulnerability-detection/feed/ 0
Google paid $10M to bug hunters in 2023 https://www.developer-tech.com/news/2024/mar/13/google-paid-10m-bug-hunters-in-2023/ https://www.developer-tech.com/news/2024/mar/13/google-paid-10m-bug-hunters-in-2023/#respond Wed, 13 Mar 2024 15:21:29 +0000 https://www.developer-tech.com/?p=45742 Google has revealed that it paid out $10 million to over 600 bug hunters from 68 countries in 2023. Throughout the year, Google’s bug hunter community played a pivotal role in identifying and addressing thousands of vulnerabilities across various Google platforms. The company’s dedication to incentivising researchers saw the introduction of several new programs and... Read more »

The post Google paid $10M to bug hunters in 2023 appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/2024/mar/13/google-paid-10m-bug-hunters-in-2023/feed/ 0
GitHub enables secret scanning push protection by default https://www.developer-tech.com/news/2024/mar/01/github-enables-secret-scanning-push-protection-default/ https://www.developer-tech.com/news/2024/mar/01/github-enables-secret-scanning-push-protection-default/#respond Fri, 01 Mar 2024 16:50:27 +0000 https://www.developer-tech.com/?p=45701 In response to the alarming trend of API keys, tokens, and other confidential data being inadvertently exposed, GitHub has taken further steps to fortify its platform against potential breaches. Within the first two months of 2024, GitHub has uncovered one million leaked secrets across public repositories, averaging over a dozen incidents per minute. Such alarming... Read more »

The post GitHub enables secret scanning push protection by default appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/2024/mar/01/github-enables-secret-scanning-push-protection-default/feed/ 0
GitHub suffers from over 100K infected repos https://www.developer-tech.com/news/2024/feb/29/github-suffers-over-100k-infected-repos/ https://www.developer-tech.com/news/2024/feb/29/github-suffers-over-100k-infected-repos/#respond Thu, 29 Feb 2024 12:01:58 +0000 https://www.developer-tech.com/?p=45693 Developers face a major security threat as over 100,000 repositories on GitHub are infected with malicious code. This resurgence of a malicious repo confusion campaign – detected by Apiiro’s security researchers – has impacted countless developers who unwittingly use repositories they believe to be trusted but are, in fact, compromised. Similar to dependency confusion attacks... Read more »

The post GitHub suffers from over 100K infected repos appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/2024/feb/29/github-suffers-over-100k-infected-repos/feed/ 0
White House urges adoption of memory-safe programming languages https://www.developer-tech.com/news/2024/feb/27/white-house-urges-adoption-memory-safe-programming-languages/ https://www.developer-tech.com/news/2024/feb/27/white-house-urges-adoption-memory-safe-programming-languages/#respond Tue, 27 Feb 2024 12:14:22 +0000 https://www.developer-tech.com/?p=45684 The White House Office of the National Cyber Director (ONCD) has released a new report today urging the technology industry to take steps to reduce vulnerabilities in software that leave digital systems open to cyberattacks. The report, titled “Back to the Building Blocks: A Path Toward Secure and Measurable Software,” emphasises the importance of technology... Read more »

The post White House urges adoption of memory-safe programming languages appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/2024/feb/27/white-house-urges-adoption-memory-safe-programming-languages/feed/ 0
Python packages caught using DLL sideloading to bypass security https://www.developer-tech.com/news/2024/feb/21/python-packages-dll-sideloading-bypass-security/ https://www.developer-tech.com/news/2024/feb/21/python-packages-dll-sideloading-bypass-security/#respond Wed, 21 Feb 2024 11:55:04 +0000 https://www.developer-tech.com/?p=45680 ReversingLabs researchers have uncovered Python packages using DLL sideloading to bypass security tools. On 10 January 2024, Karlo Zanki, a reverse engineer at ReversingLabs, stumbled upon two suspicious packages on the Python Package Index (PyPI). These packages – named NP6HelperHttptest and NP6HelperHttper – were found to be utilising DLL sideloading, a known technique used by... Read more »

The post Python packages caught using DLL sideloading to bypass security appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/2024/feb/21/python-packages-dll-sideloading-bypass-security/feed/ 0
GitHub rotates credentials following vulnerability discovery https://www.developer-tech.com/news/2024/jan/17/github-rotates-credentials-following-vulnerability-discovery/ https://www.developer-tech.com/news/2024/jan/17/github-rotates-credentials-following-vulnerability-discovery/#respond Wed, 17 Jan 2024 16:58:10 +0000 https://www.developer-tech.com/?p=45542 GitHub has rotated encryption keys following the discovery of a vulnerability that could have enabled threat actors to steal credentials, the company revealed Tuesday.   The Microsoft-owned firm said it first became aware of the high-severity security flaw tracked as CVE-2024-0200 on 26 December 2023. After investigating the issue and verifying there was no evidence it... Read more »

The post GitHub rotates credentials following vulnerability discovery appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/2024/jan/17/github-rotates-credentials-following-vulnerability-discovery/feed/ 0
PHP 8.0 reaches EOL leaving some websites vulnerable https://www.developer-tech.com/news/2023/nov/27/php-8-0-reaches-eol-leaving-some-websites-vulnerable/ https://www.developer-tech.com/news/2023/nov/27/php-8-0-reaches-eol-leaving-some-websites-vulnerable/#respond Mon, 27 Nov 2023 12:43:31 +0000 https://www.developer-tech.com/?p=45393 PHP 8.0 reached its end of life (EOL) on 26 November 2023 and will no longer receive any updates or patches. PHP 8.0 was released on 26 November 2020 and brought many new features and improvements such as named arguments, attributes, constructor property promotion, match expression, nullsafe operator, JIT, and more. The EOL of PHP... Read more »

The post PHP 8.0 reaches EOL leaving some websites vulnerable appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/2023/nov/27/php-8-0-reaches-eol-leaving-some-websites-vulnerable/feed/ 0
Checkmarx uncovers persistent Python package threat https://www.developer-tech.com/news/2023/nov/16/checkmarx-uncovers-persistent-python-package-threat/ https://www.developer-tech.com/news/2023/nov/16/checkmarx-uncovers-persistent-python-package-threat/#respond Thu, 16 Nov 2023 13:00:03 +0000 https://www.developer-tech.com/?p=45359 Checkmarx has uncovered a threat actor that has been quietly infiltrating the open-source ecosystem for nearly six months, planting malicious Python packages with a focus on deception and financial gain. The malicious actor employed a systematic approach, disguising their packages with names closely resembling popular legitimate Python packages. These decoy packages, camouflaged to blend in,... Read more »

The post Checkmarx uncovers persistent Python package threat appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/2023/nov/16/checkmarx-uncovers-persistent-python-package-threat/feed/ 0