Hackers seize on software flaw to breach two victims, despite patch availability
Days after researchers warned of critical vulnerabilities in popular data-management software, hackers have exploited the flaws to breach two organizations which rely on the technology. LineageOS, a free Android-based operating system, and Ghost, a nonprofit behind widely used blogging software, reported Sunday that unidentified hackers had breached their infrastructure in separate incidents. The disruptions are an example of how bugs found in widely used code often end up being exploited maliciously — even when software updates are available. Both LineageOS and Ghost rely on a tool for managing data centers and cloud-computing networks known as the Salt management framework. Cybersecurity company F-Secure reported two vulnerabilities in Salt last week which could enable attackers to execute code remotely and manipulate data. “Both of these vulnerabilities are exploitable by a remote, unauthenticated attacker,” said Rody Quinlan, a researcher at another security vendor, Tenable. Ghost said it was rebuilding its network. Customer data […]
The post Hackers seize on software flaw to breach two victims, despite patch availability appeared first on CyberScoop.
Continue reading Hackers seize on software flaw to breach two victims, despite patch availability