Many developers unknowingly expose sensitive data, including business-critical information, when they publish code containing their Slack access tokens on GitHub.
Hi, what are you looking for?
Many developers unknowingly expose sensitive data, including business-critical information, when they publish code containing their Slack access tokens on GitHub.
Researchers discovered a severe cross-domain authentication bypass vulnerability that could have been exploited by malicious actors to gain access to Office 365 accounts, including...
The OpenSSL Project announced on Thursday that it’s preparing patches for several vulnerabilities affecting the crypto library.OpenSSL versions 1.0.2h and 1.0.1t will be released...
A new version of the Network Time Protocol daemon (ntpd) released this week by the NTP Project patches several low and medium severity vulnerabilities.
UPDATED. Cisco’s Talos security intelligence and research group has come across a piece of software that installed backdoors on 12 million computers around the...
Mozilla has patched a total of 14 vulnerabilities, including ones rated critical and high severity, with the release of Firefox 46.
Instead of developing their own hacking tools or buying them from third parties, threat groups have increasingly turned their attention to open source security...
Microsoft has been observing the activities of a cyber espionage group that has leveraged a Windows patching system in attacks aimed at organizations in...
The Qatar National Bank (QNB) has launched an investigation after someone leaked a large number of files allegedly stolen from the financial institution’s systems...
A researcher received a $5,000 reward from Facebook after finding a vulnerability that could have been exploited to impersonate users on other websites.
Researchers at Netcraft have come across a Facebook phishing attack in which malicious actors leveraged some clever methods to increase their chances of tricking...
Several people have pleaded guilty to their roles in tax fraud schemes involving the Internal Revenue Service’s “Get Transcript” database.The “Get Transcript” online service...
Researchers at Trend Micro have spotted a new variant of the Fareit malware being delivered to victims using Windows PowerShell.
The United States government has dropped a case in which it attempted to get Apple to extract information from an iPhone after receiving the...
The cybercriminals behind the recently discovered GozNym banking Trojan have started targeting users in European countries.
Custom Malware Prevented Bangladesh Bank From Detecting Fraudulent TransfersResearchers at British multinational defense, security and aerospace company BAE Systems believe they have found the...
The Massachusetts Institute of Technology (MIT) has launched a bug bounty program to encourage responsible disclosure of vulnerabilities found on its websites.
Authorities in Mexico have launched an investigation after a researcher discovered a publicly accessible database containing the personal details of tens of millions of...
Malicious actors have abused PowerShell and Google Docs to deliver a Trojan known as Laziok, FireEye reported on Thursday.
Adobe released an update on Thursday for the Analytics AppMeasurement for Flash library to address a DOM-based cross-site scripting (XSS) vulnerability rated “important.”The AppMeasurement...