Posts

Showing posts with the label Github

Thousands of GitHub, AWS, Docker tokens exposed in Travis CI logs

By Ionut Ilascu,  Bleeping Computer For a second time in less than a year, the Travis CI platform for software development and testing has exposed user data containing authentication tokens that could give access to developers’ accounts on GitHub , Amazon Web Services , and Docker Hub. Researchers at Aqua Security discovered that “tens of thousands of user tokens” are exposed through the Travis CI API that offer access to more than 770 million logs with various types of credentials belonging to free tier users.

Open source 'Package Analysis' tool finds malicious npm, PyPI packages

Image
By Ax Sharma, Bleeping Computer The Open Source Security Foundation (OpenSSF), a Linux Foundation-backed initiative has released its first prototype version of the 'Package Analysis' tool that aims to catch and counter malicious attacks on open source registries. In a pilot run that lasted less than a month, the open source project released on GitHub, was able to identify over 200 malicious npm and PyPI packages. Project aims to combat malware in open source registries This week, OpenSSF released its initial prototype version of the 'Package Analysis' project on GitHub. The project repository contains tools that analyze open source packages, particularly, to hunt for malicious npm and PyPI packages. "The Package Analysis project seeks to understand the behavior and capabilities of packages available on open source repositories: what files do they access, what addresses do they connect to, and what commands do they run?" explain Caleb Brown and David A. Wheeler...

Fighting Fake EDRs With ‘Credit Ratings’ for Police

Image
By  KrebsOnSecurity When KrebsOnSecurity recently explored how cybercriminals were using hacked email accounts at police departments worldwide to obtain warrantless Emergency Data Requests (EDRs) from social media firms and technology providers, many security experts called it a fundamentally unfixable problem. But don’t tell that to Matt Donahue, a former FBI agent who recently quit the agency to launch a startup that aims to help tech companies do a better job screening out phony law enforcement data requests — in part by assigning trustworthiness or “credit ratings” to law enforcement authorities worldwide. A sample Kodex dashboard Image: Kodex.us Donahue is co-founder of Kodex , a company formed in February 2021 that builds security portals designed to help tech companies “manage information requests from government agencies who contact them, and to securely transfer data & collaborate against abuses on their platform.” The 30-year-old Donahue said he left the FBI in April ...