Security News

OpenRefine's Zip Slip Vulnerability Could Let Attackers Execute Malicious Code
2023-10-02 08:02

A high-severity security flaw has been disclosed in the open-source OpenRefine data cleanup and transformation tool that could result in arbitrary code execution on affected systems. Tracked as...

Week in review: Zip Slip, GDPR and the US, why creativity is key to security
2018-06-10 23:36

Here’s an overview of some of last week’s most interesting news and articles: VPNFilter malware targets new devices, can deliver exploits to endpoints Cisco Talos researchers have news about the...

Zip Slip Flaw Affects Thousands of Open-Source Projects
2018-06-06 20:58

An exploit allows attackers to remotely overwrite archive files with their own content, and from there pivot to achieving remote command execution on the machine.

Attackers can hide malware in archive files with Zip Slip flaw; here's how to fight it
2018-06-06 15:32

A newly revealed vulnerability affecting open source software libraries should have you worried about the security of your coding projects.

The Zip Slip vulnerability – what you need to know
2018-06-06 14:55

Thousands of projects affected by painful programming lapse

Zip Slip vulnerability affects thousands of projects
2018-06-05 20:15

An arbitrary file overwrite vulnerability that can be exploited by attackers to achieve code execution on a target system affects a myriad of projects and multiple ecosystems, Snyk researchers...

'Zip Slip' security hole lets evil archive files hack your computer
2018-06-05 17:30

Path traversal flaw could lead to data mangling, code execution – so patch now Booby-trapped compressed archive files can exploit a vulnerability in a large range of software to overwrite...

'Zip Slip' Vulnerability Affects Thousands of Projects Across Many Ecosystems
2018-06-05 16:33

Security researchers at British software firm Snyk have revealed details of a critical vulnerability that affects thousands of projects across many ecosystems and can be exploited by attackers to...