Rhode Island’s workers’ compensation notifies those affected by January data breach

Rhode Island residents may understandably wonder about the state’s vendor security monitoring. First, it was the Deloitte and the RIBridges data breach that affected more than 730,000 residents. Now the vendor that administers the state’s w… Continue reading Rhode Island’s workers’ compensation notifies those affected by January data breach

npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks

GitHub has rolled out new controls for npm to improve the security of the software supply chain, giving maintainers the ability to explicitly approve a release prior to the packages becoming publicly available for installation.

Called staged publishin… Continue reading npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks

Posted in Uncategorized

Researchers Say the Worst Climate Future is Less Likely. But the Best One is Also Slipping Away

Citing new research, the Associated Press reports that “modest gains in the fight to curb climate change have dialed back the most catastrophic of future heating.”
That’s the good news. But the same research “also confirmed that there’s no chance to l… Continue reading Researchers Say the Worst Climate Future is Less Likely. But the Best One is Also Slipping Away

Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware

A new “coordinated” supply chain attack campaign has impacted eight packages on Packagist including malicious code designed to run a Linux binary retrieved from a GitHub Releases URL.

“Although the affected packages were all Composer packages, the mal… Continue reading Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware

Posted in Uncategorized

Linux Kernel Flaw Lets Unprivileged Users Access Root-Only Files, Execute Arbitrary Commands as Root

Qualys’s Threat Research Unit (TRU) has discovered and published a logic flaw in Linux kernel “that permits an unprivileged local user to disclose sensitive files and execute arbitrary commands as root on default installations of several major distribu… Continue reading Linux Kernel Flaw Lets Unprivileged Users Access Root-Only Files, Execute Arbitrary Commands as Root