Implementing a robust digital identity

_This post is part seven of GitHub Security Lab’s [series on the OWASP Top 10 Proactive Controls](), where we provide practical guidance for OSS developers on proactively improving your security post ...

Continue Reading
5 ways to connect with Microsoft Security at Identiverse 2022

Identiverse is where the industry gathers to discuss all things identity. The 2022 conference will take place June 21 to 24 in Denver, Colorado, and I’m absolutely thrilled that Microsoft will be the ...

Continue Reading
5 ways to connect with Microsoft Security at Identiverse 2022

Identiverse is where the industry gathers to discuss all things identity. The 2022 conference will take place June 21 to 24 in Denver, Colorado, and I’m absolutely thrilled that Microsoft will be the ...

Continue Reading
CVE-2021-22573

The vulnerability is that IDToken verifier does not verify if token is properly signed. Signature verification makes sure that the token's payload comes from valid provider, not from someone else. An ...

Continue Reading
CVE-2022-0916

An issue was discovered in Logitech Options. The OAuth 2.0 state parameter was not properly validated. This leaves applications vulnerable to CSRF attacks during authentication and authorization opera ...

Continue Reading
RST Threat feed. IOC: https://ws.alleqro.pl.priyadarshi.net/upload-data/form/auth.htm?authorization-allegro-pl/auth/oauth/authorize?client_id=tb5sff3c…

Found **https://ws[.]alleqro.pl.priyadarshi.net/upload-data/form...Read More ...

Continue Reading
RST Threat feed. IOC: https://quintakailua.com/oauth/indexx.php

Found **https://quintakailua[.]com/oauth/indexx.php** ...Read More ...

Continue Reading
RST Threat feed. IOC: https://quintakailua.com/oauth/indexx.php?oauth=eca6c-xech0-el5k21654785017582648ff8fb01b9b9d2cdea1888de946582648ff8fb01b9b9d2cde…

Found **https://quintakailua[.]com/oauth/indexx.php?oauth=eca6c-x...Read More ...

Continue Reading

Back to Main

Subscribe for the latest news: