Category: Mix

Hackerone logo
10
Aug
2023

What to Know About the New SEC Cybersecurity Rule [3 Requirements]

SEC’s Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure Rule The SEC’s final rule is aimed at helping investors make…

[tl;dr sec] #194 - CNAPPGoat, KubeFuzz, tl;dr sec swag
10
Aug
2023

[tl;dr sec] #194 – CNAPPGoat, KubeFuzz, tl;dr sec swag

I hope you’ve been doing well! Hacker Summer Camp This is the first time I’m attending the Vegas conferences since…

Assign severity ratings on Attack Surface Custom Policies
10
Aug
2023

Spot risks with our new IP view

Our new IP view offers another point of view on the expanding attack surface Customers often tell us of instances…

New techniques and tools for web race conditions | Blog
10
Aug
2023

New techniques and tools for web race conditions | Blog

Emma Stocks | 10 August 2023 at 06:56 UTC For too long, web race-condition attacks have focused on a tiny…

ShareFile Pre-Auth RCE (CVE-2023-24489) – Assetnote
10
Aug
2023

Metabase Pre-Auth RCE (CVE-2023-38646) – Assetnote

Summary An unauthenticated attacker can obtain the setup token for an instance and use it to achieve remote code execution…

ShareFile Pre-Auth RCE (CVE-2023-24489) – Assetnote
10
Aug
2023

Chaining our way to Pre-Auth RCE in Metabase (CVE-2023-38646) – Assetnote

Metabase is an open source business intelligence tool that lets you create charts and dashboards using data from a variety…

Enhancing API Security with FAST
09
Aug
2023

Enhancing API Security with FAST

Welcome to another inside story straight from the Wallarm labs. Today we’re taking you behind the scenes of our self-testing…

How Intigriti Optimizes Prato's Software Security 
08
Aug
2023

How Intigriti Optimizes Prato’s Software Security 

In the age of digital transformation, cybersecurity has become an essential part of businesses. A rise in cybercrime highlights the…

Hackerone logo
08
Aug
2023

10 LLM Vulnerabilities and How to Establish LLM Security [OWASP]

LLM01: Prompt Injection What Is Prompt Injection? One of the most commonly discussed LLM vulnerabilities, Prompt Injection is a vulnerability…

High-Entropy Writing
07
Aug
2023

High-Entropy Writing

I read a post by Derek Sivers recently that reminded me of Claude Shannon’s concept of Entropy. The post was…

API2:2023 Broken Authentication
05
Aug
2023

API2:2023 Broken Authentication

Welcome to the 3rd post in our weekly series on the new 2023 OWASP API Security Top-10 list, with a…

Hackerone logo
03
Aug
2023

Company Update | HackerOne

HackerOne CEO, Marten Mickos, emailed the following note to employees on August 2, 2023. H1 Team, I have made the painful…