Hail relies on OIDC email claims to verify the validity of a user’s domain.

Impact All Hail Batch clusters are affected. An attacker is able to: Create one or more accounts with Hail Batch without corresponding real accounts in the organization. For example, a user could cr ...

Continue Reading
Microsoft Incident Response lessons on preventing cloud identity compromise

In response to the increasing frequency and evolution of nation-state cyberthreats, Microsoft is taking additional steps to protect our customers and increase the secure-by-default baseline of our clo ...

Continue Reading
Microsoft Incident Response lessons on preventing cloud identity compromise

In response to the increasing frequency and evolution of nation-state cyberthreats, Microsoft is taking additional steps to protect our customers and increase the secure-by-default baseline of our clo ...

Continue Reading
Microsoft Incident Response lessons on preventing cloud identity compromise

In response to the increasing frequency and evolution of nation-state cyberthreats, Microsoft is taking additional steps to protect our customers and increase the secure-by-default baseline of our clo ...

Continue Reading
CVE-2023-50708

yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. In yii2-authclient prior to version 2.2.15, the Oauth1/2 state and OpenID Connec ...

Continue Reading
CVE-2023-50708

yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. In yii2-authclient prior to version 2.2.15, the Oauth1/2 state and OpenID Connec ...

Continue Reading
CVE-2023-50714

yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. In yii2-authclient prior to version 2.2.15, the Oauth2 PKCE implementation is vu ...

Continue Reading
CVE-2023-50714

yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. In yii2-authclient prior to version 2.2.15, the Oauth2 PKCE implementation is vu ...

Continue Reading

Back to Main

Subscribe for the latest news: