A week in security (January 16—22)

Last week on Malwarebytes Labs: * [Google to support the use of Rust in Chromium]() * [Law enforcement app SweepWizard leaks data on crime suspects]() * [Accountant ordered to pay ex-employer af ...

Continue Reading
CircleCI: Malware stole GitHub OAuth keys, bypassing 2FA

Software development service company CircleCI has published its [incident report]() on a breach that happened in December. CircleCI revealed an engineer's laptop was successfully infected with a yet-t ...

Continue Reading
Security Bulletin: A security vulnerability has been identified in WebSphere Application Server shipped with IBM Tivoli System Automation Application Manager (CVE-2018-1794)

## Summary WebSphere Application Server is shipped with IBM Tivoli System Automation Application Manager. Information about a security vulnerability affecting WebSphere Application Server has been pub ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

CVE-2022-4037

An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A race condition can le ...

Continue Reading
CVE-2022-4037

An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A race condition can le ...

Continue Reading
A User Can Unblock Themself

# Description `PUT /api/v1/users/{id}` API doesn't properly check the authorizaion. # Proof of Concept 1. [admin] Enable user registration functionality. 2. [user] Register new user and login as them. ...

Continue Reading
Malware Attack on CircleCI Engineer’s Laptop Leads to Recent Security Incident

[![CircleCI Hack](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() DevOps platform CircleCI on Friday disclosed that unidentified ...

Continue Reading
CVE-2022-4037

This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will b ...

Continue Reading

Back to Main

Subscribe for the latest news: