Ivanti Discloses Two New Zero-Day Flaws, One Under Active Exploitation

Context Ivanti has disclosed the discovery of two new high-severity flaws in its Connect Secure and Policy Secure products, one of which is said to have come under targeted exploitation in the wild. This comes after the recent publication of CISA Alert: Ivanti Releases Security Update for Connect Secure and Policy Secure Gateways. Community Threat Assessment Due to the confirmed…

Read More

GitHub Rotates Keys After High-Severity Credential-Exposing Vulnerability Discovered

Context Representatives from GitHub Security has announced the rotation of private keys potentially exposed by a newly discovered vulnerability, which was previously patched in December of 2023, that could let attackers access credentials within private production containers via environment variables. The rotated keys include the GitHub commit signing key as well as GitHub Actions, GitHub Codespaces, and…

Read More

Two Critical Vulnerabilities Patched in GitLab, All Organizations Advised to Update Instances

Context On January 11, 2023, GitLab released security updates to remedy two critical vulnerabilities in GitLab software. All RH-ISAC organizations are urged to immediately update to versions 16.5.6, 16.6.4, and 16.7.2, or to a version where the fix was backported (16.1.6, 16.2.9, 16.3.7, and 16.4.5). According to the security update, the flaws affected the following…

Read More

Firms Potentially Exposed to Supply Chain Compromise Attack via New Class of GitHub CI/CD Attack, PoC Available

Thousands of public GitHub repositories are vulnerable to a newly discovered malicious code injection via self-hosted GitHub Actions runners, which could lead to high-impact attacks, leading to potential disruption to large-scale organizations, according to a recently released news report. Furthermore, threat actors have specifically targeted GitHub repositories recently, demonstrating clear intent and capability, while the…

Read More

Security Researcher Discloses Misconfiguration in Chattr.ai Hiring Service That May Expose Sensitive Data

Context On January 10, 2024, the security researcher known as Mr Bruh published a report outlining a misconfiguration in the popular AI-based hiring vendor Chatter.ai that exposes sensitive user data. According to the report, attackers can use Chatter.ai’s registration feature to create new user profiles with full read/write privileges by abusing a vulnerability or a…

Read More