Source
PortSwigger
‘Endemic’ Log4j bug set to persist in the wild for at least a decade, US government warns
Inaugural report from cyber safety panel outlines strengths and weaknesses exposed by momentous security flaw
Prototype pollution in Blitz.js leads to remote code execution
Chain of exploits could be triggered without any authentication
More than 4,000 individuals’ medical data left exposed for 16 years
Private healthcare information was accessible since 2006
Fantasy Premier League football app introduces 2FA to tackle account takeover hacks
Authentication controls added to defend against account hijack threat
Crunch time for EU web authentication plan as Mozilla launches campaign to protect status quo
Mozilla’s message to MEPs appears to be gaining traction, says senior public policy manager at the non-profit
Microsoft Teams security vulnerability left users open to XSS via flawed stickers feature
The friendly image sent by your colleague on a teleconference may be hiding a malicious secret
Vulnerability in AWS IAM Authenticator for Kubernetes could allow user impersonation, privilege escalation attacks
Flaw in Amazon’s Kubernetes service has since been fixed
Vivaldi browser founder Jon von Tetzchner puts privacy at the center of development
A man for all four seasons
Take threats against machine learning systems seriously, security firm warns
A new white paper from NCC Group details the myriad security threats associated with machine learning models