Security
Headlines
HeadlinesLatestCVEs

Source

PortSwigger

‘We don’t teach developers how to write secure software’ – Linux Foundation’s David A Wheeler on reversing the CVE surge

Teach devs security fundamentals to bolster supply chain resilience, argues Wheeler Addressing a decades-old deficiency in coding curriculums could have a profound effect on the security of the softwa

PortSwigger
#vulnerability#web#google#microsoft#linux#oracle#perl#aws
Hidden DNS resolver insecurity creates widespread website hijack risk

WordPress installations exposed to spoofed password reset vis cache poisoning threat

Critical flaw in open source WebPageTest remains unpatched

Public disclosure, a talk, and a blog post later, the RCE exploit remains unresolved

Dex patches authentication bug that enabled unauthorized access to client applications

With 35.6 million downloads the OAuth 2.0 protocol provider has serious downstream attack surface