Tag: security

Another top vibe coding platform has some worrying security flaws – here’s what we know

Researchers find Base44’s “vibe coding” platform contained security flaw This allowed threat actors to access data that should be private The bug was squashed within 24 hours with no signs of abuse Vibe coding platform Base44 contained a major security vulnerability which could have allowed unauthorized users to access other…

Read More

Hackers hit SAP security bug to send out nasty Linux malware

A critical flaw in SAP NetWeaver is still being abused, months after patching Researchers saw it used to deploy Auto-Color This backdoor remains dormant when not in use A vulnerability in SAP NetWeaver is being exploited to deploy Linux malware capable of running arbitrary system commands and deploying additional payloads,…

Read More

FBI, CISA warn of more Scattered Spider attacks to come

Scattered Spider is evolving, CISA, FBI and others have warned Hackers are employing additional malware, including DragonForce Companies should use phishing-resistant MFA to defend Scattered Spider is only getting warmed up with its cyberattacks, and businesses should be on their guard for possible attacks, law enforcement forces have said. A…

Read More

Lovense adult toy app leaks private user email addresses – what we know, and how to stay safe if you’re affected

Researchers found a way to extract email addresses from Lovense user accounts A mitigation was released, but allegedly it’s not working as intended The company claims it still needs months before plugging the leak Lovense, a sex tech company specializing in smart, remotely controlled adult toys, had a vulnerability in…

Read More

Hacker adds potentially catastrophic prompt to Amazon’s AI coding service to prove a point

A rogue prompt told Amazon’s AI to wipe disks and nuke AWS cloud profiles Hacker added malicious code through a pull request, exposing cracks in open source trust models AWS says customer data was safe, but the scare was real, and too close A recent breach involving Amazon’s AI coding…

Read More

Endgame Gear warns mouse config tool has been infected with malware

Endgame Gear software hijacked to serve malware Attack spotted by the company’s community Endgame is making significant changes to prevent repeat occurrences Gaming kit maker Endgame Gear has confirmed it was the victim of a supply chain attack which saw unidentified threat actors break into its website and replace a…

Read More