Security
Headlines
HeadlinesLatestCVEs

Source

DARKReading

Booking.com's OAuth Implementation Allows Full Account Takeover

Researchers exploited issues in the authentication protocol to force an open redirection from the popular hotel reservations site when users used Facebook to log in to accounts.

DARKReading
#vulnerability#web#google#git#perl#oauth#auth
Hackers Target Young Gamers: How Your Child Can Cause Business Compromise

It's 10 p.m. Do you know what your children are playing? In the age of remote work, hackers are actively targeting kids, with implications for enterprises.

On Shaky Ground: Why Dependencies Will Be Your Downfall

There's never enough time or staff to scan code repositories. To avoid dependency confusion attacks, use automated CI/CD tools to make fixes in hard-to-manage software dependencies.

Ermetic Adds Kubernetes Security to CNAPP

The automated capabilities can discover misconfigurations, compliance violations, and risk or excessive privileges in Kubernetes clusters.

Forescout Addresses Modern SecOps Challenges With Launch of Forescout XDR

New eXtended Detection and Response Solution is 450X more efficient than typical SOCs at converting telemetry and logs into actionable alerts.

Visibility Is as Vital as Zero Trust for Low-Code/No-Code Security

By authenticating and authorizing every application, and by maintaining data lineage for auditing, enterprises can reduce the chances of data exfiltration.

Dish Blames Ransomware Attack for Disruptions of Internal Systems, Call Center Services

The cyberattackers might have potentially accessed customer information, the service provider warns.