Source
PortSwigger
Serious Snipe-IT bug exploitable to send password reset email traps
Attackers could use the flaw to steal credentials with no authentication required
Zero-day bug in uClibc library could leave IoT devices vulnerable to DNS poisoning attacks
Unpatched flaw caused by the predictability of transaction IDs
State Bar of Georgia reels from cyber-attack
Bar suspends website after mystery assault
<span>TLStorm 2.0: Millions of Aruba and Avaya network switches affected by RCE flaws</span>
Patches issued for vulnerabilities arising from misuse of NanoSSL TLS library
Path traversal flaw found in OWASP enterprise security testing library
Difficult-to-exploit ESAPI vulnerability offers best practice lessons
Path traversal flaw found in OWASP enterprise library of security controls
Difficult-to-exploit ESAPI vulnerability offers best practice lessons
Data breach at US energy supplier Riviera Utilities exposes customer information
Unknown actor accessed employee emails
Poisoned packages: NPM developer reputations could be leveraged to legitimize malicious software
Faulty invitation mechanism enabled ‘package planting’ attacks
Security bug in VMWare Workspace ONE could allow access to internal, cloud networks
Users should patch immediately
Bug Bounty Radar // The latest bug bounty programs for May 2022
New web targets for the discerning hacker