Monday, May 11, 2026
English News
  • Hyderabad
  • Telangana
  • AP News
  • India
  • World
  • Entertainment
  • Sport
  • Science and Tech
  • Business
  • Rewind
  • ...
    • NRI
    • View Point
    • cartoon
    • My Space
    • Education Today
    • Reviews
    • Property
    • Lifestyle
E-Paper
  • NRI
  • View Point
  • cartoon
  • My Space
  • Reviews
  • Education Today
  • Property
  • Lifestyle
Home | Science & Tech | Researcher Enters Servers Of 35 Tech Companies Runs Code

Researcher enters servers of 35 tech companies, runs code

According to Bleeping Computer, security researcher Alex Birsan found a security vulnerability that allowed him to run code on those servers in what is touted as a novel software supply chain attack.

By IANS
Published Date - 11 February 2021, 01:59 PM
Researcher enters servers of 35 tech companies, runs code
whatsapp facebook twitter telegram

New Delhi: A cyber security researcher has utilised a security vulnerability to run code on servers owned by over 35 major tech companies, including Apple, Microsoft, Netflix, Tesla, Uber, Shopify, Yelp and PayPal, the media reported.

According to Bleeping Computer, security researcher Alex Birsan found a security vulnerability that allowed him to run code on those servers in what is touted as a novel software supply chain attack.


Birsan has earned over $130,000 in rewards through bug bounty programmes and pre-approved penetration testing arrangements with these companies.

“I feel that it is important to make it clear that every single organisation targeted during this research has provided permission to have its security tested, either through public bug bounty programs or through private agreements. Please do not attempt this kind of test without authorisation,” Birsan was quoted as saying in the report.

Microsoft awarded him their highest bug bounty amount of $40,000 and released a white paper on this security issue.

The tech giant identified the issue as CVE-2021-24105 for their Azure Artifactory product.

The novel software supply chain attack comprised uploading malware to open source repositories, “which then got distributed downstream automatically into the company’s internal applications”.

The supply chain attack was more sophisticated as it needed no action by the victim, who automatically received the malicious packages.

Apple told Bleeping Computer that Birsan will get a reward via its Security Bounty programme for responsibly disclosing this issue.

PayPal has publicly disclosed Birsan’s HackerOne report mentioning the $30,000 bounty amount.

The possibility remains for such attacks to resurface and grow, especially on open-source platforms with no easy solution for dependency confusion, according to the researcher.

“I believe that finding new and clever ways to leak internal package names will expose even more vulnerable systems, and looking into alternate programming languages and repositories to target will reveal some additional attack surface for dependency confusion bugs,” the researcher said in his blog post.

  • Follow Us :
  • Tags
  • Apple
  • cyber security researcher
  • Microsoft
  • Netflix

Related News

  • Saif praises SRK’s sensibility as producer of ‘Kartavya’

    Saif praises SRK’s sensibility as producer of ‘Kartavya’

  • Kunal Kemmu on song ‘Nindiya’: Came from real moments I’ve experienced as a parent

    Kunal Kemmu on song ‘Nindiya’: Came from real moments I’ve experienced as a parent

  • Sebi classifies ‘significant index’ based on Rs 20,000cr AUM threshold

    Sebi classifies ‘significant index’ based on Rs 20,000cr AUM threshold

  • CG Power and Industrial Solutions posts 32 percent rise in profit

    CG Power and Industrial Solutions posts 32 percent rise in profit

Latest News

  • Lexus launches all-new ES 500e electric sedan in Hyderabad

    11 mins ago
  • Kubbra Sait reveals how Salman Khan shaped her role in Ready

    30 mins ago
  • AIADMK plunged into crisis after poor Tamil Nadu election performance

    37 mins ago
  • Hyderabad police arrest drug peddler, three customers in MDMA case

    38 mins ago
  • Malakpet man arrested for tampering scooter number plate to avoid challans

    43 mins ago
  • Andhra Pradesh resumes Krishna water supply to Tamil Nadu

    45 mins ago
  • Tension prevails as BRS, Congress councilors clash in Asifabad’s Kagaznagar

    46 mins ago
  • Cong MLA gives representation in prajavani on paddy procurement

    53 mins ago

company

  • Home
  • About Us
  • Contact Us
  • Privacy Policy

business

  • Subscribe

telangana today

  • Telangana
  • Hyderabad
  • Latest News
  • Entertainment
  • World
  • Andhra Pradesh
  • Science & Tech
  • Sport

follow us

  • Telangana Today Telangana Today
Telangana Today Telangana Today

© Copyrights 2024 TELANGANA PUBLICATIONS PVT. LTD. All rights reserved. Powered by Veegam