Security researchers discovered an information disclosure vulnerability known as NotLegit in Microsoft Azure App Service, a cloud computing-based platform for developing and hosting websites. The vulnerability reportedly exposed customers' PHP, Node, Python, Ruby, or Java source codes, which could have been exploited in the wild. This issue only affects Azure App Service Linux clients, not customers who ?utilize IIS-based Azure App Service apps. Researchers developed a vulnerable Azure App Service application and then discovered requests from unknown threat actors to access the.git folder to assess the likelihood of exposure to an issue. As per the experts, hackers are already aware of the flaw and are seeking to uncover vulnerable Azure App Service apps' source code. Customers that installed All PHP, Node, Ruby, and Python apps using "Local Git" on a clean default application in Azure App Service from September 2017, including customers who generated or edited a created file in the application container, are affected by this issue. Researchers notified the Microsoft Security Response Center of the vulnerability, in which users can unintentionally set the.git folder to be created at the root, indicating a high risk of information leakage. In response, Microsoft patched the vulnerability by modifying PHP images to prevent displaying the.git folder as static content, as well as notifying impacted customers and providing extensive advice on how to mitigate the issue.
Researchers at Mysterium VPN have identified 12,088,677 IP addresses serving publicly accessible .env-style files, exposing credentials and tokens at massive scale. The United Stat...
The job search process has become a new attack surface for software engineers, as Microsoft Defender Experts uncovered a coordinated campaign leveraging malicious repositories disg...
Online home improvement marketplace ManoMano has reportedly suffered a significant data breach impacting approximately 38 million users. Threat actors claim to have accessed and ex...