Dependency confusion tops the PortSwigger annual web hacking list for 2021
Request smuggling attacks a key theme [...]
Request smuggling attacks a key theme [...]
US investigators recover $3.6bn in digital assets [...]
No customer data was accessed, company claims [...]
Recent moves from the US government agency have laid the groundwork for significant changes to businesses’ compliance obligations, writes US attorney David Oberly [...]
Unresolved vulnerabilities also create code execution risk, warns Bitdefender [...]
Privacy campaigners sign open letter urging government to reconsider E2EE stance [...]
Settlement includes up to $425 million to help people affected by 2017 mega breach [...]
Attackers have targeted mailboxes ‘in multiple waves across two attack phases’ [...]
Agency pulls POLARIS platform offline as investigation continues [...]
Bug hunter earned $17k bounty for HelloSign bug [...]
Critical security bugs inherited by multiple products [...]
Alpha-Omega Project aims to improve software supply chain security for 10,000 OSS projects [...]
Inadvertent defense downgrade quickly reverted [...]
Silicon Valley firm has paid out more than $200,000 since private program’s 2018 launch [...]
Though still in its early stages, SnapFuzz is already showing some promising results [...]
WordPress plugin problem patched [...]
‘Cloudbleed’-like bug affected cloud computing service from Fastly, a H2O contributor [...]
Researchers say 144,000 files were exposed [...]
Urgent patching of file-sharing technology urged [...]
Series of flaws in MDM platform addressed in web console and Linux agent [...]
Tool enables decryption key to work after forced firmware update rendered it useless [...]
New web targets for the discerning hacker [...]
Invalid CVE saga highlights potential problems in the automated vulnerability alert process [...]
The online portal is used to track fare dodging on Swiss public transport [...]
Federal agencies have a little over two years to fundamentally remodel cyber defenses [...]