Okta Impersonation Technique Could be Utilized by Attackers

Okta has a standard process that can be abused for nefarious purposes. The legitimate method for changing credential details within Okta (for example, if a person gets married and changes her last name and adopts a new email address) can be misused by an attacker to impersonate another existing user.

read more

Atlassian Ships Urgent Patch for Critical Bitbucket Vulnerability

Atlassian’s security response team has issued an urgent advisory to warn of a critical command injection flaw in its Bitbucket Server and Data Center product.

The vulnerability carries a CVSS severity score of 9.9 out of 10 and can be exploited remotely to launch code execution attacks, Atlassian said.

read more

BalkanID Adds $2.3M to Seed Funding Round

BalkanID, a Texas startup building technology in the Identity Governance and Administration (IGA) space, has added $2.3 million to its seed financing round, bringing the total raised to $8.1 million.

read more

Privilege Escalation Flaw Haunts VMware Tools

Virtualization technology software giant VMware on Tuesday released patches to fix an important-severity security flaw in the VMware Tools suite of utilities.

The vulnerability, tracked as CVE-2022-31676, could be exploited by attackers to escalate privileges on a compromised system.

read more

GitLab Patches Critical Remote Code Execution Vulnerability

DevOps platform GitLab has issued patches for a critical remote code execution vulnerability impacting its GitLab Community Edition (CE) and Enterprise Edition (EE) releases.

Tracked as CVE-2022-2884 (CVSS 9.9/10 severity), the security flaw can be exploited via the GitHub import API, but requires authentication to be triggered.

read more