Source
PortSwigger
ChatGPT bid for bogus crypto bug bounty is thwarted
Improving large language models offer ‘just one more way to attack code, and one more way to defend code’
JSON syntax hack allowed SQL injection payloads to be smuggled past WAFs
Five vendors act to thwart generic hack
NodeBB prototype pollution flaw could lead to account takeover
‘Not a prototype pollution vulnerability as you might normally understand it’
Black Hat Europe 2022: A defendable internet is possible, but only with industry makeover
Empower buyers and stop fixating about zero-days, conference attendees told
Deserialized web security roundup: Algolia API key leak, GitHub CVE reporting, scoring CVSS scores
Your fortnightly rundown of AppSec vulnerabilities, new hacking techniques, and other cybersecurity news
Go SAML library vulnerable to authentication bypass
An attacker could masquerade as an authenticated user without presenting credentials
Critical vulnerability allowed attackers to remotely unlock, control Hyundai, Genesis vehicles
Vehicles made after 2012 were vulnerable to web app exploit
Bug Bounty Radar // The latest bug bounty programs for December 2022
New web targets for the discerning hacker
Tailscale VPN nodes vulnerable to DNS rebinding, RCE
Users should manually update to the latest version now
Intel disputes seriousness of Data Centre Manager authentication flaw
Security researcher scores $10K bug bounty