Researcher drops Lexmark RCE zero-day rather than sell vuln ‘for peanuts’
Printer exploit chain could be weaponized to fully compromise more than 100 models [...]
Printer exploit chain could be weaponized to fully compromise more than 100 models [...]
New web targets for the discerning hacker [...]
Have your say to be in with the chance to win Burp Suite swag... [...]
Your fortnightly rundown of AppSec vulnerabilities, new hacking techniques, and other cybersecurity news [...]
Security vulnerability was one of Meta’s top bugs of 2022 [...]
Several applications were vulnerable to brute-force attacks; hundreds more could be at risk [...]
More than 61,000 vulnerabilities patched and counting [...]
Pre- and post-auth path to pwnage [...]
Password vault vendor accused of making a hash of encryption [...]
Manufacturer complacency ‘translates into an unacceptable risk for consumers’, warns security expert [...]
Threat actors poking around AWS environments and API calls could stay under the radar [...]
Have your say to be in with the chance to win Burp Suite swag... [...]
Uncovered vulnerabilities include several high, medium, and low-security issues [...]
Dashlane, Bitwarden, and Safari all cited by Google researchers [...]
Six payouts issued for bugs uncovered in Theia, Vertex AI, Compute Engine, and Cloud Workstations [...]
Severity somewhat blunted by reboot-related caveat [...]
Ethical hackers and bug bounty hunters invited to test Department of Defense assets [...]
How the build pipeline was compromised [...]
Your fortnightly rundown of AppSec vulnerabilities, new hacking techniques, and other cybersecurity news [...]
Your fortnightly rundown of AppSec vulnerabilities, new hacking techniques, and other cybersecurity news [...]
Library has somewhat of an image problem given history of serious bugs [...]
‘Condescending’ response to vulnerability disclosure angers infosec community [...]
‘Class pollution’ flaw similar to dangerous vulnerability type found in JavaScript and similar languages [...]
Protection against XSS, SQLi, and more web attacks for Go-based web applications [...]
Vendor patched the vulnerability in October after a red team alert [...]