API securityDLL sideloading leveraged by malicious PyPI packagesSC StaffFebruary 21, 2024Malicious Python Package Index packages NP6HelperHttptest and NP6HelperHttper, which had more than 700 cumulative downloads before being removed.
Application securityWordPress plugin under attack; Bricks Builder bug enables RCELaura FrenchFebruary 20, 2024WordPress site takeover is possible without authentication via the actively exploited vulnerability.
IdentityX alternative Spoutible’s API leaked 2FA seeds, password reset tokensLaura FrenchFebruary 6, 2024“Have I Been Pwned?” creator Troy Hunt detailed the leak of more than 207,000 user records.
Cloud SecurityStop chasing shadow IT: Tackle the root causes of cloud breachesStu SjouwermanFebruary 6, 2024Here are the five root causes of cloud breaches and five ways to mitigate them.
API securityAnyDesk forces password reset for customers as 18k credentials go up for sale onlineSimon HenderyFebruary 5, 2024Given the remote access tool’s popularity with some of the world's largest companies, researchers expect hackers will move fast to exploit freshly stolen credentials.
IdentityMicrosoft fell victim to OAuth attack it issued warning aboutSimon HenderyJanuary 29, 2024Microsoft said it was also compromised via the same OAuth app abuse it warned about and offers tips to detect and protect.
API securitySonicWall API opens 178k firewalls to attackSimon HenderyJanuary 16, 2024More than three-quarters of devices are susceptible to a pair of flaws exposing SonicWall firewalls to DoS and RCE attacks.