Quotidien Hebdomadaire Mensuel

Quotidien Shaarli

Tous les liens d'un jour sur une page.

September 20, 2024

GitLab Critical Patch Release: 17.3.3, 17.2.7, 17.1.8, 17.0.8, 16.11.10

Learn more about GitLab Critical Patch Release: 17.3.3, 17.2.7, 17.1.8, 17.0.8, 16.11.10 for GitLab Community Edition (CE) and Enterprise Edition (EE).

Enterprise ServiceNow Knowledge Bases at Risk

Read the blog to learn about ServiceNow’s Knowledge Base data exposure risks and how to mitigate these issues.

Thousands of orgs at risk of ServiceNow KB data leaks

Security researchers say that thousands of companies are potentially leaking secrets from their internal knowledge base (KB) articles via ServiceNow misconfigurations.

Aaron Costello and Dan Meged, of the AppOmni and Adaptive Shield security shops respectively, separately published their findings this week, concluding that pages set to "private" could still be read by tinkering with a ServiceNow customer's KB widgets.

These widgets are essentially containers of information used to construct the pages in KB articles. These can include page elements that allow users to leave feedback on articles, either through star ratings or comments, for example.

New Criminal Complaint Over Pegasus Spyware Hacking of journalists and activists in the UK  

Four victims of Pegasus spyware in the UK have this week filed a criminal complaint with the Metropolitan Police.

Is Tor still safe to use?

This blog post is a response to an investigative news report about a large-scale law-enforcement attack that managed to de-anonymize a user of an old version of the long-retired app Ricochet. This blog post aims to provide insight into what we know so far. Nothing that the Tor Project has learned about this incident suggests that Tor Browser was attacked or exploited. Tor users can continue to use Tor Browser to access the web securely and anonymously.

New macOS malware HZ RAT lets attackers control Macs remotely

It lets attackers control Macs remotely.