Security
Headlines
HeadlinesLatestCVEs

Source

PortSwigger

How to become a penetration tester: Part 2 – ‘Mr hacking’ John Jackson on the virtue of ‘endless curiosity’

Marine Corps engineer-turned offensive security expert offers careers advice and his best and worst experiences

PortSwigger
#vulnerability#web#ios#microsoft#git#rce
Akamai wrestles with AWS S3 web cache poisoning bug

Definitive solution is ‘non-trivial’ since behavior arises from customers processing non-RFC compliant requests

Safeurl HTTP library brings SSRF protection to Go applications

Prizes offered to anyone who can bypass the library and capture the flag

Critical IP spoofing bug patched in Cacti

‘Not that hard to execute if attacker has access to a monitoring platform running Cacti’

Akamai WAF bypassed via Spring Boot to trigger RCE

Akamai issued an update to resolve the flaw several months ago

ChatGPT bid for bogus bug bounty is thwarted

Improving large language models offer ‘just one more way to attack code, and one more way to defend code’