Get a Pentest and security assessment of your IT network.

Cyber Security

A New PHP Composer Bug Could Enable Widespread Supply-Chain Attacks

Vulnerability stems from the way package source download URLs are handled, potentially leading to remote command injection. Researchers exploited the argument injection flaw to craft a malicious Mercurial repository URL that takes advantage of its “alias” option to execute a shell command of the attacker’s choice. Composer is billed as a tool for dependency management in PHP, enabling easy installation of packages relevant to a project. It also allows users to install PHP applications that are available on Packagist, a repository that aggregates all public PHP packages.

Source: https://thehackernews.com/2021/04/a-new-php-composer-bug-could-enable.html

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security