OpenSea has confirmed being impacted by a third-party security breach, marking the third attack against the major non-fungible token marketplace following a third-party hack and phishing incident in June 2022 and February 2022, respectively, SiliconAngle reports.
Nansen impacted by third-party breach BleepingComputer reports that Ethereum blockchain analytics firm Nansen has disclosed that its third-party authentication provider was impacted by a data breach, which resulted in the compromise of data from 6.8% of its user base over a 48-hour period.
Given WinRAR’s popularity, researchers think the threat actor behind the fake PoC may have been targeting “other miscreants” looking to add a remote code exploit to their toolkit.
Secrets exposed by thousands of leading websites SecurityWeek reports that exposed Git directories containing code commits, file paths, source codes, and other secrets were observed across 4,500 websites in the Alexa Top 1 Million Websites list.
BleepingComputer reports that attacks leveraging two vulnerabilities in the open-source object storage service MinIO, which could facilitate object storage service compromise, arbitrary code execution, and server takeovers, are underway.