Apple's Safari web browser was discovered to have a Fullscreen API security issue, which could be abused to enable fullscreen browser-in-the-middle intrusions concealing the address bar of the parent window, reports BleepingComputer.
Hackread reports that Facebook was claimed by threat actor "ByteBreaker" to have had 1.2 billion account details scraped following the exploitation of its API, with the actor sharing a sample data exposing 100,000 users' full names, usernames, birthdates, gender, phone numbers, email addresses, location, and unique identifier.
GBHackers News reports that malicious Python Package Index repository packages abusing TikTok and Instagram APIs have been leveraged by threat actors to check the validity of pilfered account credentials.
The collaboration allows security teams to gain deeper insight into API vulnerabilities and posture issues by embedding Salt’s threat intelligence into the Wiz security graph.
CEO Amiram Shachar noted that these tools help identify anomalies in API traffic and build baselines that allow organizations to customize security policies.
Nearly 50 online merchants have already been compromised in intrusions exploiting Stripe's legacy application programming interface "api.stripe[.]com/v1/sources" for payment data validation part of an advanced web skimmer campaign that has been underway since August, according to The Hacker News.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.