Detectify founder Frans Rosén has topped PortSwigger’s top 10 web hacking techniques of 2022 with ‘Account hijacking using dirty dancing in sign-in OAuth-flows’. Published in July, the...
Researchers have disclosed a raft of serious document management system (DMS) vulnerabilities impacting four enterprise vendors who have not yet resolved the issues. In a blog post published...
The maintainers of a new version of popular hacking tool XSS Hunter have been criticized for inspecting potentially sensitive data generated by users after they shared...
Denis Mihaqlovic Dubnikov used cryptocurrencies to attempt to hide his involvement in ransomware attacks on foreign and domestic companies. The Department of Justice successfully brought charges...
A review of the UK’s creaking cybercrime laws has been criticized for lacking “urgency” after the UK government launched a second public consultation on the issue....
Gartner has patched a DOM XSS vulnerability found in the Peer Insights widget, a security bug researchers reckon dates back to the original development of the software. In...
A security researcher said he hacked into Toyota’s supplier management network and was able to access sensitive data associated with around 3,000 suppliers and 14,000 users...
The Clop ransomware gang is now also using a malware variant that explicitly targets Linux servers, but a flaw in the encryption scheme has allowed victims...
The intelligence agency has been quietly moving over the past few months to recruit talented workers affected by the wave of layoffs at tech companies and...
The document is updated once every four years. Members of the public have the opportunity to provide their insight on the newest version of the federal...
Recent Comments