Security Bulletin: IBM Cloud Pak for Security includes components with multiple known vulnerabilities

## Summary IBM Cloud Pak for Security includes components with known vulnerabilities. These have been updated in the latest release and vulnerabilities have been addressed. Please follow the instructi ...

Continue Reading
New Vulnerability Found in the JsonWebToken Open-Source Project

Threat Level Vulnerability Report For a detailed threat advisory, download the pdf file here Summary A new high-severity vulnerability named CVE-2022-23529 has been discovered in the popular JsonWebTo ...

Continue Reading
This Week in Spring – January 9th, 2023

Hi, Spring fans! As I write this I'm on a plane winging my way to Helsinki, Finland. A new year and new journeys begin. It's going to be cold there. Wish me luck! Do you know what always warms me up? ...

Continue Reading
Critical Security Flaw Found in “jsonwebtoken” Library Used by 22,000+ Projects

[![high-severity security flaw]()]() A high-severity security flaw has been disclosed ...

Continue Reading
Timing Attack is vulnerable to Timing Attacks. A remote attacker is able to determine the expected hash-based message authentication code(HMAC) with a large enough number of requests over ...

Continue Reading
Use of Hard-coded Credentials

KubePi is a k8s panel. The jwt authentication function of KubePi through version 1.6.2 uses hard-coded Jwtsigkeys, resulting in the same Jwtsigkeys for all online projects. This means that an attacker ...

Continue Reading
KubePi allows malicious actor to login with a forged JWT token via Hardcoded Jwtsigkeys

### Summary The jwt authentication function of kubepi Read More ...

Continue Reading
JwtSigKey hardcoded causes the k8s cluster to take over

# Description The jwt authentication function of kubepi Read More ...

Continue Reading

Back to Main

Subscribe for the latest news: