Remove contributor security-weekly
article thumbnail

GitHub begins 2FA rollout for code contributors

CSO Magazine

GitHub has begun its official rollout of two-factor authentication (2FA) for developers who contribute code to the platform to enhance the security of accounts and the software supply chain. GitHub is allowing users to choose their preferred 2FA method – SMS, TOTP, security keys, or GitHub mobile.

Mobile 104
article thumbnail

Google to Underwrite Contributors to Linux Security

Security Boulevard

Google and the Linux Foundation announced this week they will underwrite two full-time maintainers for Linux kernel security development. The post Google to Underwrite Contributors to Linux Security appeared first on Security Boulevard.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Assessing the Y, and How, of the XZ Utils incident

SecureList

oss-fuzz cpp-docs wasmtime xz These innocuous patches helped to build the identity of JiaT75 as a legitimate open source contributor and potential maintainer for the XZ Utils project. the JiaT75 individual contributor was rushed to commit the malicious backdoor code. I asked a question here a week ago and have not heard back.

article thumbnail

KrebsOnSecurity Hit By Huge New IoT Botnet “Meris”

Krebs on Security

It’s not immediately clear which security vulnerabilities led to these estimated 250,000 MikroTik routers getting hacked by Meris. Cloudflare recently wrote about its attack , which clocked in at 17.2 million bogus requests-per-second. To put that in perspective, Cloudflare serves over 25 million HTTP requests per second on average.

IoT 284
article thumbnail

Millions of sites could be hacked due to flaws in popular WordPress plugins

Security Affairs

Security researchers disclosed vulnerabilities in Elementor and WP Super Cache WordPress plugins that could be exploited to run arbitrary code and take over a website under certain circumstances. If you want to receive the weekly Security Affairs Newsletter for free subscribe here. The flaw affects plugin versions prior 1.7.2.

Hacking 131
article thumbnail

Reducing Security Risks in Open Source Software at Scale: Scorecards Launches V4

Google Security

Posted by Laurent Simon and Azeem Shaikh, Google Open Source Security Team (GOSST) Since our July announcement of Scorecards V2, the Scorecards project—an automated security tool to flag risky supply chain practices in open source projects—has grown steadily to over 40 unique contributors and 18 implemented security checks.

article thumbnail

Critical flaws in Orbit Fox WordPress plugin allows site takeover

Security Affairs

Security experts from Wordfence have discovered two security vulnerabilities in the Orbit Fox WordPress plugin. “One of these flaws made it possible for attackers with contributor level access or above to escalate their privileges to those of an administrator and potentially take over a WordPress site. Pierluigi Paganini.