CYBERSECURITY / DEFENSE / INTELLIGENCE

  • A significant vulnerability in the Perforce Akana Community Manager Developer Portal has been found, allowing attackers to conduct server-side request forgery (SSRF) attacks.

    Community Manager is an advanced solution designed to assist businesses in creating an API portal that will draw in, manage, and assist developers who create applications using their APIs.

    Organizations frequently use this software to create and maintain developer portals for their APIs. 

    Typically, an SSRF attack involves the attacker forcing the server to connect to internal services only found in the infrastructure of the company. 

    Free Webinar | Mastering WAAP/WAF ROI Analysis | Book Your Spot

    In different circumstances, they might be able to force the server to establish a connection with any random external systems.

    Sensitive information, such as authorization credentials, can leak as a result.

    SSRF in Akana Community Manager Developer Portal

    This critical severity vulnerability tracked as CVE-2024-2796, has a CVSS base score of 9.3. The vulnerability was disclosed by Jakob Antonsson.

    The Akana Community Manager Developer Portal, versions 2022.1.3 and earlier, has a server-side request forgery (SSRF) vulnerability. 

    When an SSRF attack is successful, the hacker can control the target web server to carry out harmful operations or disclose private data. 

    This approach can cause significant damage to an organization, including sensitive data exposure, cross-site port attacks (XSPA), denial of service (DoS), and remote code execution.

    Affected Software Versions

    It has been confirmed that the following Perforce Akana Community Manager Developer Portal versions are impacted:

    • 2022.1.1 
    • 2022.1.2 
    • 2022.1.3

    Patches Released

    • 2022.1.1 (CVE-2024-2796 Patch) 
    • 2022.1.2 (CVE-2024-2796 Patch) 
    • 2022.1.3 (CVE-2024-2796 Patch)

    It is highly recommended that organizations utilizing the Akana Community Manager Developer Portal update to one of the patched versions right away.

    Looking to Safeguard Your Company from Advanced Cyber Threats? Deploy TrustNet to Your Radar ASAP

    The post Critical Flaw with Popular API Portal Let Attackers Launch SSRF Attacks appeared first on GBHackers on Security | #1 Globally Trusted Cyber Security News Platform.

    Go to source

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

  • The ongoing tension between privacy rights and public safety, Europol, along with European Police Chiefs, has issued a call for tech giants to provide lawful access to encrypted communications.

    This development comes as major social media platforms, including those owned by Meta, begin to implement end-to-end encryption. This technology prevents anyone except the communicating users from accessing the messages.

    The Challenge of End-to-End Encryption

    End-to-end encryption ensures that digital conversations are private and secure from any third-party interception, including by the platforms themselves.

    Is Your Network Under Attack? - Read CISO’s Guide to Avoiding the Next Breach - Download Free Guide

    However, this level of privacy raises significant concerns for law enforcement agencies:

    • Prevention of Crime: Encrypted platforms can become safe havens for illegal activities, including child exploitation, human trafficking, and terrorism.
    • Investigation and Prosecution: The inability to access message content can hinder the investigation and prosecution of crimes.
    • Evidence Gathering: Critical evidence necessary for legal processes may become inaccessible, potentially allowing criminals to evade justice.

    Europol’s Call to Action

    During an informal meeting of the Europol hosted by the UK’s National Crime Agency on April 18, a joint declaration was made, emphasizing the urgent need for a balanced approach to encryption that considers both privacy rights and public safety.

    The meeting, which saw participation from police chiefs of all EU Member States and Schengen Associated Countries, highlighted several key points:

    • Public Safety: The primary concern is the potential increase in platforms used for harmful activities without the possibility of oversight or intervention.
    • Legal Access: This is the call for creating means through which law enforcement can legally access data, under strict conditions and oversight, to prevent or investigate serious crimes.
    • Cooperation with Tech Giants: There is a strong emphasis on collaboration between governments, law enforcement agencies, and technology companies to find solutions that balance privacy with security.

    The Role of Europol and International Cooperation

    Given its role in facilitating cross-border law enforcement cooperation within the EU and beyond, Europol’s involvement in this initiative is crucial.

    The agency’s Executive Director, Catherine De Bolle, recently met with Graeme Biggar, Director of the UK National Crime Agency, to discuss ongoing cooperation post-Brexit.

    These strategic exchanges are vital for maintaining and enhancing security across Europe.

    This call for lawful access to encrypted communications will likely spark a heated debate about balancing individual privacy rights and collective security needs.

    Tech companies, privacy advocates, and governments must engage in a nuanced dialogue to address these complex issues effectively.

    As this situation develops, the global community will be watching closely to see how privacy and security can coexist in the digital age and what compromises, if any, are necessary to protect citizens while respecting their rights to private communication.

    Free Webinar: Mastering Web Application and API Protection/WAF ROI Analysis -  Book Your Spot

    The post Europol calls for Tech Giants to Get Lawful Access To end-to-end Encryption appeared first on GBHackers on Security | #1 Globally Trusted Cyber Security News Platform.

    Go to source

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

  • The U.S. Department of State on Monday said it’s taking steps to impose visa restrictions on 13 individuals who are allegedly involved in the development and sale of commercial spyware or who are immediately family members of those involved in such businesses. “These individuals have facilitated or derived financial benefit from the misuse of this technology, which

    Go to source

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

  • The Russia-linked nation-state threat actor tracked as APT28 weaponized a security flaw in the Microsoft Windows Print Spooler component to deliver a previously unknown custom malware called GooseEgg. The post-compromise tool, which is said to have been used since at least June 2020 and possibly as early as April 2019, leveraged a now-patched flaw that allowed for

    Go to source

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

  • Russian-occupied Ukraine was home to some of the worst abuses, according to new report.

    Go to source

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

  • Biden signed a law that extends Section 702 authorities into 2026β€”and lacks proposed limits on intelligence agencies’ right to gather and search Americans’ communications.

    Go to source

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

  • User satisfaction “increased minimally” last year for MHS Genesis, the electronic-records system installed under a 2015 contract, a GAO survey found.

    Go to source

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

  • U.S. could win a war with China today, but would suffer heavy losses, the official told reporters.

    Go to source

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

  • An agreement between the departments of Defense and State aims to ease unemployment among the spouses of servicemembersβ€”and increase military families’ quality of life.

    Go to source

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

  • Anduril says its Ghost Shark proves that UUVs can be designed and built quickly.

    Go to source

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ

    ΒΆΒΆΒΆΒΆΒΆ