Security
Headlines
HeadlinesLatestCVEs

Headline

Exchange/Outlook Autodiscover Bug Spills $100K+ Email Passwords

Hundreds of thousands of email credentials, many of which double as Active Directory domain credentials, came through to credential-trapping domains in clear text.

Threatpost
#Vulnerabilities#Web Security

Related news

CVE-2021-41829: Vulnerability Disclosure -Statically Derived Encryption Key @ Zoho R.A.P.

Zoho ManageEngine Remote Access Plus before 10.1.2121.1 relies on the application's build number to calculate a certain encryption key.

CVE-2021-41828: Vulnerability Disclosure -Hardcoded Keys/Password @ Zoho R.A.P.

Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials associated with resetPWD.xml.

CVE-2021-41827: Vulnerability Disclosure -Hardcoded Keys/Password @ Zoho R.A.P.

Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials for read-only access. The credentials are in the source code that corresponds to the DCBackupRestore JAR archive.

Meet TruffleHog – a browser extension for finding secret keys in JavaScript code

API keys are accidentally being leaked by websites. Here’s how to find them

CVE-2021-39189:

Pimcore is an open source data & experience management platform. In versions prior to 10.1.3, it is possible to enumerate usernames via the forgot password functionality. This issue is fixed in version 10.1.3. As a workaround, one may apply the available patch manually.

Threatpost: Latest News

Student Loan Breach Exposes 2.5M Records