Security researcher Eaton Zveare uncovered five critical flaws in Bluspark's Bluvoyix shipping and supply chain platform, including the use of plaintext passwords and an unauthenticated API.
Centralized cryptocurrency exchange MEXC is being targeted by an illicit Google Chrome extension that aims to steal its API keys, according to The Hacker News.
The release is centered on providing unified visibility and control over APIs, which the company acknowledges now power core enterprise architectures, by extending discovery capabilities to its BIG-IP, NGINX, and third-party gateways like Kong and Apigee.
BleepingComputer reports that Instagram has refuted allegations that information from over 17 million accounts has been compromised, as it addressed a security issue that was exploited to facilitate a mass delivery of password reset emails.
IBM has warned that exploitation of a critical authentication bypass bug in its API Connect end-to-end application programming interface solution, tracked as CVE-2025-13915, could enable remote app access, The Hacker News reports.
Almost 29% of web traffic during the third quarter has been attributed to bots, indicating the rise of automated activity, even if humans still accounted for the most activity, reports SiliconANGLE.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.