Popular open source vulnerability scanner Nuclei forced to patch worrying security flaw




  • Popular open source vulnerability scanner Nuclei was found to be vulnerable itself
  • A bug allowed crooks to smuggle malicious code past the scanner
  • The vulnerability was fixed in September 2024, but many users still haven’t updated

A vulnerability scanning tool was found to have been vulnerable itself, allowing crooks to smuggle malicious code past the gatekeeper.

Cybersecurity researchers from Wiz found a bug in ProjectDiscovery’s Nuclei in August 2024, after investigating the open source vulnerability scanner, which is designed to automate the detection of security issues across various protocols, systems, and applications using customizable YAML-based templates.

https://cdn.mos.cms.futurecdn.net/UVoJtVCqMw4zd4UHG7SaYa-1200-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img