Improper Verification of Cryptographic Signature in google-oauth-java-client

### Summary The vulnerability impacts only users of the IdTokenVerifier class. The verify method in IdTokenVerifier does not validate the signature before verifying the claims (e.g., iss, aud, etc.). ...

Continue Reading
Improper Verification of Cryptographic Signature in google-oauth-java-client

### Summary The vulnerability impacts only users of the IdTokenVerifier class. The verify method in IdTokenVerifier does not validate the signature before verifying the claims (e.g., iss, aud, etc.). ...

Continue Reading
RST Threat feed. IOC: https://roommejts.com/oppel/oppel/indexx.php?oauth=9z87p-o47pg-tmkwh16547179458b3e276575fc48927c9b98ec924c1d888b3e276575fc48927c…

Found **https://roommejts[.]com/oppel/oppel/indexx.php?oauth=9z8...Read More ...

Continue Reading
This Week in Spring – April 26th, 2022

Hi, Spring fans! Welcome to another installment of _This Week in Spring_! This week I was _hoping_ to be in glorious Chicago, Illinois for the first in-person SpringOne Tour installment since the pand ...

Continue Reading
(RHSA-2022:4932) Important: Red Hat Fuse 7.10.2.P1 security update

This release of Red Hat Fuse 7.10.1 serves as a replacement for Red Hat Fuse 7.10 and includes bug fixes and enhancements, which are documented in the Release Notes document linked in the References. ...

Continue Reading
Exposing POLONIUM activity and infrastructure targeting Israeli organizations

Microsoft successfully detected and disabled attack activity abusing OneDrive by a previously undocumented Lebanon-based activity group Microsoft Threat Intelligence Center (MSTIC) tracks as POLONIUM. ...

Continue Reading
Exposing POLONIUM activity and infrastructure targeting Israeli organizations

Microsoft successfully detected and disabled attack activity abusing OneDrive by a previously undocumented Lebanon-based activity group Microsoft Threat Intelligence Center (MSTIC) tracks as POLONIUM. ...

Continue Reading
CVE-2021-22696

CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization Framework: JWT Secured Authorization Request (JAR)). ...

Continue Reading

Back to Main

Subscribe for the latest news: