Showing only posts by Jessica Lyons. Show all posts.

Amazon security boss blames Russia's GRU for years-long energy-sector hacks

Source

'Sustained focus on Western critical infrastructure' Russia's Main Intelligence Directorate (GRU) is behind a years-long campaign targeting energy, telecommunications, and tech providers, stealing credentials and compromising misconfigured devices hosted on AWS to give the Kremlin's snoops persistent access to sensitive networks, according to Amazon's security boss.... [...]

'Exploitation is imminent' as 39 percent of cloud environs have max-severity React hole

Source

Finish reading this, then patch A maximum-severity flaw in the widely used JavaScript library React, and several React-based frameworks including Next.js allows unauthenticated, remote attackers to execute malicious code on vulnerable instances. The flaw is easy to abuse, and mass exploitation is "imminent," according to security researchers.... [...]

Stealthy browser extensions waited years before infecting 4.3M Chrome, Edge users with backdoors and spyware

Source

And some are still active in the Microsoft Edge store A seven-year malicious browser extension campaign infected 4.3 million Google Chrome and Microsoft Edge users with malware, including backdoors and spyware sending people's data to servers in China. And, according to Koi researchers, five of the extensions with …

« newer articles | page 3 | older articles »