Dex patches authentication bug that enabled unauthorized access to client applications
With 35.6 million downloads the OAuth 2.0 protocol provider has serious downstream attack surface [...]
With 35.6 million downloads the OAuth 2.0 protocol provider has serious downstream attack surface [...]
‘SBOM turns on flashing lights on the dashboard; VEX helps you figure out which to turn off’ [...]
Argument injection bug posed RCE risk [...]
Confidentiality and authentication flaws uncovered by researchers [...]
Affected firms alerted to bug whose potential impact is heightened by vm2’s use in production environments [...]
A lesson in how to achieve maximum value for your discoveries [...]
‘ProxyNotShell’ abuse less severe than 2021 attack wave due to authentication requirement [...]
Maintainer of Chinese project closes public issue apparently without issuing a fix [...]
New web targets for the discerning hacker [...]
Automating bulk pull request generation FTW [...]
Clients vulnerable due to improper certificate validation [...]
Maintainers patch vulnerability and offer mitigation advice over bug that affects all Kubernetes objects [...]
Maintainers patch vulnerability and offer mitigation advice over bug that affects Rancher-owned objects [...]
Vendor patches code injection vulnerability harnessed in attacks on south Asia [...]
Code injection vulnerability harnessed in attacks on south Asia [...]
Issue still yet to be patched, but workarounds are available [...]
Issue has since been fixed [...]
Webhook, line, and sinker [...]
Vulnerability could have been used to bypass cloud isolation protection [...]
Warning added to Python documentation was deemed preferable to a patch [...]
Issue highlights the challenges of preventing client-side attacks [...]
Open source project provides push notification functionality for iOS, macOS, Android, and tvOS [...]
Infosec advocate speaks to The Daily Swig about the benefits of, and barriers to, ‘shifting left’ [...]
Silicon Valley vendor tackles command injection and MitM-to-RCE issues [...]
Social engineering attack compromises internal networks and Uber’s bug bounty reports [...]