SSRF Flaw in Fintech Platform Allowed for Compromise of Bank Accounts

A [server-side request forgery (SSRF) flaw]() in an API of a large financial technology (fintech) platform potentially could have compromised millions of bank customers, allowing attackers to defraud ...

Continue Reading
CVE-2022-22332

IBM Sterling Partner Engagement Manager 6.2.0 could allow an attacker to impersonate another user due to missing revocation mechanism for the JWT token. IBM X-Force ID: 219131.Read More ...

Continue Reading
RST Threat feed. IOC: http://shorta.email/libs/php-jwt-main/src/jwt.php

Found **http://shorta[.]email/libs/php-jwt-main/src/jwt...Read More ...

Continue Reading
RST Threat feed. IOC: http://shorta.email/libs/php-jwt-main/src/key.php

Found **http://shorta[.]email/libs/php-jwt-main/src/key...Read More ...

Continue Reading
CVE-2022-22311

IBM Security Verify Access could allow a user, using man in the middle techniques, to obtain sensitive information or possibly change some information due to improper validiation of JWT tokens.Read Mo ...

Continue Reading
OSS API Firewall Unveils new Feature: Blacklist for Compromised API Tokens and Cookies

Discovering and securing any API is one of the most difficult challenges for developers. The [API security]() landscape is constantly evolving, with new threats and vulnerabilities emerging at a rapid ...

Continue Reading
(RHSA-2022:4671) Important: Red Hat OpenShift GitOps security update

Red Hat Openshift GitOps is a declarative way to implement continuous deployment for cloud native applications. Security Fix(es): * argocd: ArgoCD will blindly trust JWT claims if anonymous access is ...

Continue Reading
Privilege Escalation

openjdk is vulnerable to privilege escalation. The vulnerability exists due to a lack of validation of authorization allowing an attacker to update, insert or delete access to some of Oracle Java SE, ...

Continue Reading

Back to Main

Subscribe for the latest news: