Sonatype finds malicious npm packages which broadcast your IP, username, and device fingerprint info on the web

Sonatype researchers discovered and confirmed the presence of two new vulnerable npm packages. Sonatype’s discovery was initially made by its malicious code detection bots. By applying machine learning and artificial intelligence to identify suspi… Continue reading Sonatype finds malicious npm packages which broadcast your IP, username, and device fingerprint info on the web

Inside the “fallguys” malware that steals your browsing data and gaming IMs; Continued attack on open source software

This weekend a report emerged of mysterious npm malware stealing sensitive information from Discord apps and web browsers installed on a user’s machine.
The post Inside the “fallguys” malware that steals your browsing data and gaming IMs; Continue… Continue reading Inside the “fallguys” malware that steals your browsing data and gaming IMs; Continued attack on open source software

From Prototype Pollution to full-on remote code execution, how can adversaries exploit npm modules?

The NodeJS component express-fileupload – touting 7 million downloads from the npm registry –  now has a critical Prototype Pollution vulnerability.
The post From Prototype Pollution to full-on remote code execution, how can adversaries exploit np… Continue reading From Prototype Pollution to full-on remote code execution, how can adversaries exploit npm modules?

Nexus Intelligence Insights:CVE-2020-13935 – Apache Tomcat Websocket – Denial of Service (DoS)

For July’s Nexus Intelligence Insight we take a deep dive into a Denial of Service (DoS) vulnerability impacting the popular Apache Tomcat Websocket component.
The post Nexus Intelligence Insights:CVE-2020-13935 – Apache Tomcat Websock… Continue reading Nexus Intelligence Insights:CVE-2020-13935 – Apache Tomcat Websocket – Denial of Service (DoS)

Nexus Intelligence Insights: xlsx aka SheetJS – Regular Expression Denial of Service (ReDoS) and sonatype-2018-0622

For this month’s Nexus Intelligence Insights, we explore an interesting case of ReDoS vulnerability impacting the popular npm component, SheetJS, also known as “xlsx”. It may pique your interest to learn that this vulnerability w… Continue reading Nexus Intelligence Insights: xlsx aka SheetJS – Regular Expression Denial of Service (ReDoS) and sonatype-2018-0622

Nexus Intelligence Insights: Protect Your Bitcoins from 700+ Malicious RubyGems with sonatype-2020-0196

Last week news broke about how 700 typosquatting libraries had made their way into the famous RubyGems repository. The complete list, first published by Reversing Labs, reveals how crafty attackers can take advantage of the open source software su… Continue reading Nexus Intelligence Insights: Protect Your Bitcoins from 700+ Malicious RubyGems with sonatype-2020-0196

Nexus Intelligence Insights: What’s in a Ghostcat? CVE-2020-1938 Apache Tomcat – Local File Inclusion Potentially Leads to RCE

For this month’s Nexus Intelligence Insights, let’s dive deep into the popular Ghostcat vulnerability making headlines recently.
This vulnerability deserves attention as it impacts the widely used Apache Tomcat web server, has at least… Continue reading Nexus Intelligence Insights: What’s in a Ghostcat? CVE-2020-1938 Apache Tomcat – Local File Inclusion Potentially Leads to RCE

What Does the New CVSS 3.1 Scoring Model Mean for Enterprise Security?

With thousands of security vulnerabilities reported each month in products ranging from hardware devices to firmware to popular software apps, how does one prioritise what needs the most attention? From a business and project management perspectiv… Continue reading What Does the New CVSS 3.1 Scoring Model Mean for Enterprise Security?

Nexus Intelligence Insights CVE-2020-2100: Jenkins – UDP Amplification Reflection Attack Leading to Distributed Denial of Service (DDoS)

In the wake of the serious Jenkins vulnerability impacting at least 12,000 Jenkins servers, we dedicate February’s Nexus Intelligence Insights to helping you solve it.
This vulnerability is clever; it opens up two potential lines of attack. … Continue reading Nexus Intelligence Insights CVE-2020-2100: Jenkins – UDP Amplification Reflection Attack Leading to Distributed Denial of Service (DDoS)