Security News

Critical SQL Injection Flaws Expose Gentoo Soko to Remote Code Execution
2023-06-28 07:24

Multiple SQL injection vulnerabilities have been disclosed in Gentoo Soko that could lead to remote code execution on vulnerable systems. "These SQL injections happened despite the use of an Object-Relational Mapping library and prepared statements," SonarSource researcher Thomas Chauchefoin said, adding they could result in RCE on Soko because of a "Misconfiguration of the database."

Password-Guessing Was Used to Hack Gentoo Linux Github Account
2018-07-05 10:33

Maintainers of the Gentoo Linux distribution have now revealed the impact and "root cause" of the attack that saw unknown hackers taking control of its GitHub account last week and modifying the...

Gentoo GitHub repo hack made possible by these 3 rookie mistakes
2018-07-05 07:02

Weak password, no 2FA, loose policies ... and only luck limited the damage The developers of Gentoo Linux have revealed how it was possible for its GitHub organization account to be hacked:...

Gentoo hack caused by three rookie mistakes
2018-07-05 07:02

Weak password, no 2FA, loose policies ... and only luck limited the damage The developers of Gentoo Linux have revealed how it was possible for its GitHub repository to be hacked: someone deduced...

Gentoo stops GitHub repo hack in an hour, setting standard for security response
2018-07-02 13:54

Gentoo’s quick and comprehensive response to a hack should be considered the standard against which organizations are judged for handling security breaches.

Github Account of Gentoo Linux Hacked, Code Replaced With Malware
2018-06-29 09:03

Downloaded anything from Gentoo's GitHub account yesterday? Consider those files compromised and dump them now—as an unknown group of hackers or an individual managed to gain access to the GitHub...

Et tu, Gentoo? Horrible gits meddle with Linux distro's GitHub code
2018-06-28 23:58

If you downloaded anything from project's hub repos, consider it compromised If you have fetched anything from Gentoo's GitHub-hosted repositories today, dump those files – because hackers have...