Source
PortSwigger
Confidentiality and authentication flaws uncovered by researchers
Affected firms alerted to bug whose potential impact is heightened by vm2’s use in production environments
A lesson in how to achieve maximum value for your discoveries
‘ProxyNotShell’ abuse less severe than 2021 attack wave due to authentication requirement
Maintainer of Chinese project closes public issue apparently without issuing a fix
New web targets for the discerning hacker
Automating bulk pull request generation FTW
Clients vulnerable due to improper certificate validation
Maintainers patch vulnerability and offer mitigation advice over bug that affects Rancher-owned objects
Maintainers patch vulnerability and offer mitigation advice over bug that affects all Kubernetes objects