OAuth Redirect Flaw in Airline Travel Integration Exposes Millions to Account Hijacking

Cybersecurity researchers have disclosed details of a now-patched account takeover vulnerability affecting a popular online travel service for hotel and car rentals. "By exploiting this flaw, ...

Continue Reading
Do We Really Need The OWASP NHI Top 10?

The Open Web Application Security Project has recently introduced a new Top 10 project - the Non-Human Identity (NHI) Top 10. For years, OWASP has provided security professionals and developers with e ...

Continue Reading
CVE-2025-22610 Coolify Vulnerable to OAuth Secrets Leak

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to fetch th ...

Continue Reading
CVE-2025-22607 Coolify Vulnerable to GitHub / GitLab OAuth Secrets Leak

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to fetch th ...

Continue Reading
Malicious code in bookingcom-oauth (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (a8735f282a15b5745e75f0bccc4b1334d5c464523d1267ed916477c461cd8b8c) The OpenSSF Package Analysis project identified & ...

Continue Reading
Malicious code in coinbase-oauth (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (a5ca839941ed94b22736187227b12ba68ef04a39c55e4155add495e004d8ed43) The OpenSSF Package Analysis project identified & ...

Continue Reading
Malicious code in amazon-oauth (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (e6c3c7c427f25937801f54534b488f10721cf11e43e122f0f00a47350ba80c2c) The OpenSSF Package Analysis project identified & ...

Continue Reading
Malicious code in dropbox-oauth (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (354ecda67f801f9b4cc23fae184e1fd2632d0c6970bb7d4190c00c514816a80f) The OpenSSF Package Analysis project identified & ...

Continue Reading

Back to Main

Subscribe for the latest news: