Get a Pentest and security assessment of your IT network.

Cyber Security

Severe Flaw Disclosed In StackStorm DevOps Automation Software

A security researcher has discovered a severe vulnerability in StackStorm, aka “IFTTT for Ops,” a powerful event-driven automation tool. The vulnerability resides in the way the StackStorm REST API improperly handled CORS (cross-origin resource sharing) headers. To exploit this vulnerability, an attacker simply needs to send a maliciously-crafted link to a victim, allowing it to “read/update/create actions and workflows, get internal IPs and execute a command on each machine”

Source: https://thehackernews.com/2019/03/stackstorm-security-vulnerability.html

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security