Deserialization of Untrusted Data

A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record Read More ...

Continue Reading

CVSS3 - CRITICAL

Unsound API in `secp256k1` allows use-after-free and invalid deallocation from safe code

Because of incorrect bounds on method `Secp256k1::preallocated_gen_new` it was possible to cause use-after-free from safe consumer code. It was also possible to "free" memory not allocated by the appr ...

Continue Reading
CVE-2022-46792

Hasura GraphQL Engine before 2.15.2 mishandles row-level authorization in the Update Many API for Postgres backends. The fixed versions are 2.10.2, 2.11.3, 2.12.1, 2.13.2, 2.14.1, and 2.15.2. (Version ...

Continue Reading
Do more with Azure Spring Apps – scale to zero and enhance productivity

In 2020, Spotify coined the term ["Golden Path”]() to refer to a supported approach and set of components to build and deploy software. Having these paths simplifies the development process, lets ...

Continue Reading
Mitigate threats with the new threat matrix for Kubernetes

Today, we are glad to release the third version of the [threat matrix for Kubernetes](), an evolving knowledge base for security threats that target Kubernetes clusters. The matrix, first released by ...

Continue Reading
Mitigate threats with the new threat matrix for Kubernetes

Today, we are glad to release the third version of the [threat matrix for Kubernetes](), an evolving knowledge base for security threats that target Kubernetes clusters. The matrix, first released by ...

Continue Reading
Exploit for Incorrect Authorization in Hashicorp Consul

# **CVE-2021-41805** ### **Hashicorp Consul RCE via API** **Has...Read More ...

Continue Reading
2023 Predictions: API Security the new Battle Ground in Cybersecurity

The adoption of application programming interfaces, more commonly known as APIs, has increased dramatically in recent years. In many ways, APIs are now the backbone of the Internet. The reason? APIs a ...

Continue Reading

Back to Main

Subscribe for the latest news: