Cox
04
Jun
2024

Cox fixed an API auth bypass exposing millions of modems to attacks

​Cox Communications has fixed an authorization bypass vulnerability that enabled remote attackers to abuse exposed backend APIs to reset millions…

Cyberespionage, China Increasingly Targeting Canadians
03
Jun
2024

China Increasingly Targeting Canadians With Cyber Operations

China is increasingly targeting Canadian citizens and organizations through the scale and scope of its cyber operations, warned the Canadian…

Hackerone logo
03
Jun
2024

3 Bug Bounty Lessons From Retail & eCommerce Customers

How do security vulnerabilities uniquely impact the retail and eCommerce space, and how can retail and eCommerce organizations use ethical…

Hand stealing data
03
Jun
2024

361 million stolen accounts leaked on Telegram added to HIBP

A massive trove of 361 million email addresses from credentials stolen by password-stealing malware, in credential stuffing attacks, and from data…

CISA adds Oracle WebLogic Server flaw to its Known Exploited Vulnerabilities catalog
03
Jun
2024

CISA adds Oracle WebLogic Server flaw to its Known Exploited Vulnerabilities catalog

CISA adds Oracle WebLogic Server flaw to its Known Exploited Vulnerabilities catalog Pierluigi Paganini June 03, 2024 CISA adds Oracle…

Microsoft Azure
03
Jun
2024

Azure Service Tags tagged as security risk, Microsoft disagrees

​Security researchers at Tenable discovered what they describe as a high-severity vulnerability in Azure Service Tag that could allow attackers…

Hackerone logo
03
Jun
2024

Top 10 AI Embarrassments to Avoid

Unlike traditional security flaws, which typically result in data breaches or service disruptions, AI systems can also cause embarrassment through…

Progress
03
Jun
2024

Exploit for critical Progress Telerik auth bypass released, patch now

Researchers have published a proof-of-concept (PoC) exploit script demonstrating a chained remote code execution (RCE) vulnerability on Progress Telerik Report…

Hugging Face Discloses Unauthorized Access To Spaces Platform
03
Jun
2024

Hugging Face Discloses Unauthorized Access To Spaces Platform

Hackers penetrated artificial intelligence (AI) company Hugging Face’s platform to access its user secrets, the company revealed in a blog…

Keeping Pace with an Evolving Security and Trust Landscape
03
Jun
2024

Keeping Pace with an Evolving Security and Trust Landscape

By Dean Coclin, Senior Director, Digital Trust Specialist, DigiCert It’s clear that 2023 will be remembered as the point that…

Popular WordPress Plugins Leave Millions Open to Backdoor Attacks
03
Jun
2024

Popular WordPress Plugins Leave Millions Open to Backdoor Attacks

Fastly researchers discover unauthenticated stored XSS attacks plaguing WordPress Plugins including WP Meta SEO, and the popular WP Statistics and…

97 FTSE 100 firms exposed to supply chain breaches
03
Jun
2024

97 FTSE 100 firms exposed to supply chain breaches

Of the 100 organisations listed on the Financial Times Stock Exchange (FTSE) 100 list of Britain’s most highly capitalised firms,…