April 30, 2024, 1:45 p.m. | SC Staff

SC Magazine feed for Risk Management www.scmagazine.com

Threat actors could leverage a high-severity vulnerability impacting the R programming language, tracked as CVE-2024-27322, to enable arbitrary code execution during the deserialization of packages using the RDS format and potentially facilitate supply chain attacks, The Hacker News reports.

arbitrary code arbitrary code execution attacks bug code code execution cve cve-2024 cve-2024-27322 deserialization enable exploitation hacker high high-severity vulnerability language network security novel packages programing programming programming language rds reports severity supply supply chain supply chain attacks the hacker news third-party-code threat threat actors vulnerability

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

COMM Penetration Tester (PenTest-2), Chantilly, VA OS&CI Job #368

@ Allen Integrated Solutions | Chantilly, Virginia, United States

Consultant Sécurité SI H/F Gouvernance - Risques - Conformité

@ Hifield | Sèvres, France

Infrastructure Consultant

@ Telefonica Tech | Belfast, United Kingdom