Source
PortSwigger
NETGEAR resolves router vulnerabilities in bundled gaming component
Silicon Valley vendor tackles command injection and MitM-to-RCE issues
Uber hack linked to hardcoded secrets spotted in powershell script
Social engineering attack compromises internal networks and Uber’s bug bounty reports
Open source CMS TYPO3 tackles XSS vulnerability
Bug spawned by parsing problem in upstream package
WAPPLES web application firewall faulted for multiple flaws
Researcher uncovers RCE and undocumented backdoor risks
Let’s Encrypt builds infrastructure to support browser-based certificate revocation revival
CRLs are back, baby!
Vulnerability in Xalan-J could allow arbitrary code execution
Open source project is used by various SAML implementations
WordPress project WPHash harvests 75 million hashes for detecting vulnerable plugins
Project mission is to crowdsource the indexing and curating of plugin bug data
Six-year-old blind SSRF vulnerability in WordPress Core feature could enable DDoS attacks
Issue present in pingback requests feature
ManageEngine vulnerability posed code injection risk for password management software
Authentication-free flaw opened the door to a raft of exploits