Threat actors are poised to launch credential-harvesting phishing and spoofed websites, as well as harness event system software and API flaws ahead of the Milano-Cortina Winter Olympics next month, according to Infosecurity Magazine.
Security researcher Eaton Zveare uncovered five critical flaws in Bluspark's Bluvoyix shipping and supply chain platform, including the use of plaintext passwords and an unauthenticated API.
Centralized cryptocurrency exchange MEXC is being targeted by an illicit Google Chrome extension that aims to steal its API keys, according to The Hacker News.
The release is centered on providing unified visibility and control over APIs, which the company acknowledges now power core enterprise architectures, by extending discovery capabilities to its BIG-IP, NGINX, and third-party gateways like Kong and Apigee.
BleepingComputer reports that Instagram has refuted allegations that information from over 17 million accounts has been compromised, as it addressed a security issue that was exploited to facilitate a mass delivery of password reset emails.