Security News > 2024 > June

Polyfill claims it has been 'defamed', returns after domain shut down
2024-06-27 10:57

The owners of Polyfill.io have relaunched the JavaScript CDN service on a new domain after polyfill.io was shut down as researchers exposed it was delivering malicious code on upwards of 100,000 websites. The Polyfill service claims that it has been "Maliciously defamed" and been subject to "Media messages slandering Polyfill."

Prompt Injection Flaw in Vanna AI Exposes Databases to RCE Attacks
2024-06-27 10:04

Cybersecurity researchers have disclosed a high-severity security flaw in the Vanna.AI library that could be exploited to achieve remote code execution vulnerability via prompt injection...

How to Use Python to Build Secure Blockchain Applications
2024-06-27 09:30

Did you know it’s now possible to build blockchain applications, known also as decentralized applications (or “dApps” for short) in native Python? Blockchain development has traditionally required...

PoC exploit for critical Fortra FileCatalyst flaw published (CVE-2024-5276)
2024-06-27 09:19

A critical SQL injection vulnerability in Fortra FileCatalyst Workflow has been patched; a PoC exploit is already available online. Fortra FileCatalyst is an enterprise software solution for accellerated, UDP-based file transfer of large files.

Cloudflare: We never authorized polyfill.io to use our name
2024-06-27 09:18

Further, to keep the internet safe, Cloudflare is automatically replacing polyfill.io links with a safe mirror on websites that use Cloudflare protection. Cloudflare has criticized Polyfill.io's unauthorized usage of its name and logo as it could mislead users into believing that the illicit website is endorsed by Cloudflare.

Russian National Indicted for Cyber Attacks on Ukraine Before 2022 Invasion
2024-06-27 07:41

A 22-year-old Russian national has been indicted in the U.S. for his alleged role in staging destructive cyber attacks against Ukraine and its allies in the days leading to Russia's full-blown...

US offers $10 million for information on indicted WhisperGate malware suspect
2024-06-27 07:27

A federal grand jury in Maryland returned an indictment charging a Russian citizen with conspiracy to hack into and destroy computer systems and data. According to court documents, in Jan. 2022, members of the Main Intelligence Directorate of the General Staff of the Russian Federation conspired to use a U.S.-based company's services to distribute malware known in the cybersecurity community as WhisperGate to dozens of Ukrainian government entities' computer systems and destroy those systems and related data in advance of the Russian invasion of Ukraine.

Critical SQLi Vulnerability Found in Fortra FileCatalyst Workflow Application
2024-06-27 06:45

A critical security flaw has been disclosed in Fortra FileCatalyst Workflow that, if left unpatched, could allow an attacker to tamper with the application database. Tracked as CVE-2024-5276, the...

Gitleaks: Open-source solution for detecting secrets in your code
2024-06-27 04:30

Gitleaks is an open-source SAST tool designed to detect and prevent hardcoded secrets such as passwords, API keys, and tokens in Git repositories. With more than 15 million Docker downloads, 16,200 GitHub stars, 7 million GitHub downloads, thousands of weekly clones, and over 700,000 Homebrew installs, Gitleaks is one of the most trusted secret scanners among security professionals, enterprises, and developers.

Chinese Cyberspies Employ Ransomware in Attacks for Diversion
2024-06-27 04:20

Cyberespionage groups have been using ransomware as a tactic to make attack attribution more challenging, distract defenders, or for a financial reward as a secondary goal to data theft. A joint report from SentinelLabs and Recorded Future analysts presents the case of ChamelGang, a suspected Chinese advanced persistent threat that has been using the CatB ransomware strain in attacks that impact high-profile organizations worldwide.