【資安日報】2022年7月13日,雲端挖礦攻擊鎖定GitHub軟體開發自動化系統下手、VMware修補去年11月揭露的vCenter漏洞 | iThome
在今天的資安新聞裡,駭客針對軟體開發自動化系統服務GitHub Actions,並利用其搭配的Azure的虛擬機器下手發動挖礦攻擊,相當值得留意;而對於VMware去年11月獲報虛擬化平臺vCenter漏洞CVE-2021-22048,該公司近期針對管理主控臺vCenter Server 7.0著手修補
] )[ 1 ].toLowerCase(); // It is not valid HTML for <option> or <optgroup> to have <select> as // either a descendant or sibling, and attempts to inject one can cause // XSS on jQuery versions before 3.5. Since this is invalid HTML and a // possible XSS attack, reject the entire string. // @see https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11023 if ((tag === 'option' tag === 'optgroup') && html.match(/</?select/i)) { html = ''; } // Retain jQuery's prior to 3.5 conversion of pseudo-XHTML, but for only // the tags in the `selfClosingTagsToReplace` list defined above. // @see https://g
related reading
- 【資安週報】2022年7月11日到7月15日ithome.com.tw
- Assessing Claude Mythos Preview’s cybersecurity capabilities \ Anthropicred.anthropic.com
- Security incident disclosure — July 2026huggingface.co
- Project Glasswing: Securing critical software for the AI era \ Anthropicanthropic.com
- GitHub RCE Vulnerability: CVE-2026-3854 Breakdown | Wiz Blogwiz.io
- GitHub · Change is constant. GitHub keeps you ahead.github.com
- "VMs won't contain cyber-capable agents"blog.trailofbits.com
- Lakera – Test your AI hacking skillsgandalf.lakera.ai
- All learning materials - detailed | Web Security Academyportswigger.net
- Hacker wipes Romania's entire land registry databasenews.risky.biz
- Ultralytics AI Library Hacked via GitHub for Cryptomining | Wiz Blogwiz.io
- OpenAI agents carried out an undisclosed cyber-attack on RubyGemsrubyhack.ai