OAuth Misconfigurations Endanger Users
Hundreds of millions of users of Grammarly, Vidio, and Bukalapak are at risk due to critical API misconfigurations in the implementation of the OAuth standard
Hundreds of millions of users of Grammarly, Vidio, and Bukalapak are at risk due to critical API misconfigurations in the implementation of the OAuth standard
A recent investigation has unveiled cyber threats, as malicious actors are utilizing the popular gaming platform Discord to distribute the Lumma Stealer malware
Attackers could exploit this flaw to gain unauthorized access, potentially leading to user impersonation, data breaches, and service disruptions.
Misconfigured instances of TeslaMate, a third-party data logging application for Tesla cars, have raised significant security concerns.
Researchers have issued a warning to all Kubernetes users, urging them to promptly update their clusters due to three critical command injection vulnerabilities
A recent report by API security firm Traceable, in collaboration with the Ponemon Institute, sheds light on the state of API security in 2023.
A zero-day vulnerability in the Linux client of Atlas VPN, version 1.0.3, has been discovered, posing a significant privacy risk to users.
Code search and navigation platform Sourcegraph has disclosed a data breach resulting from an accidental leak of an admin access token
San Francisco-based startup Socket has secured $20 million in new funding to strengthen software supply chain security, as investors show increasing interest in open-source software security ventures
JumpCloud, an enterprise software firm, revealed that a sophisticated nation-state threat actor was responsible for a security incident that targeted its customers
© 2024 | CyberMaterial | All rights reserved