Source |
Bleeping Computer |
Identifiant |
2422126 |
Date de publication |
2021-03-02 00:14:00 (vue: 2021-03-02 12:05:46) |
Titre |
Malicious NPM packages target Amazon, Slack with new dependency attacks |
Texte |
Threat actors are targeting Amazon, Zillow, Lyft, and Slack NodeJS apps using the new 'Dependency Confusion' vulnerability to steal Linux/Unix password files and open reverse shells back to the attackers. [...] |
Notes |
|
Envoyé |
Oui |
Condensat |
actors amazon apps are attackers attacks back confusion dependency files linux/unix lyft malicious new nodejs npm open packages password reverse shells slack steal target targeting threat using vulnerability zillow |
Tags |
Vulnerability
Threat
|
Stories |
|
Move |
|