This Week in Spring – April 26th, 2022

Hi, Spring fans! Welcome to another installment of _This Week in Spring_! This week I was _hoping_ to be in glorious Chicago, Illinois for the first in-person SpringOne Tour installment since the pand ...

Continue Reading
(RHSA-2022:4932) Important: Red Hat Fuse 7.10.2.P1 security update

This release of Red Hat Fuse 7.10.1 serves as a replacement for Red Hat Fuse 7.10 and includes bug fixes and enhancements, which are documented in the Release Notes document linked in the References. ...

Continue Reading
Exposing POLONIUM activity and infrastructure targeting Israeli organizations

Microsoft successfully detected and disabled attack activity abusing OneDrive by a previously undocumented Lebanon-based activity group Microsoft Threat Intelligence Center (MSTIC) tracks as POLONIUM. ...

Continue Reading
Exposing POLONIUM activity and infrastructure targeting Israeli organizations

Microsoft successfully detected and disabled attack activity abusing OneDrive by a previously undocumented Lebanon-based activity group Microsoft Threat Intelligence Center (MSTIC) tracks as POLONIUM. ...

Continue Reading
CVE-2021-22696

CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization Framework: JWT Secured Authorization Request (JAR)). ...

Continue Reading
Microweber CMS 1.2.15 Account Takeover

Post ContentRead More ...

Continue Reading
Microweber CMS 1.2.15 – Account Takeover Vulnerability

Post ContentRead More ...

Continue Reading
Denial of service in Spring Security OAuth

Spring Security OAuth versions 2.5.x prior to 2.5.2 and older unsupported versions are susceptible to a Denial-of-Service (DoS) attack via the initiation of the Authorization Request in an OAuth 2.0 C ...

Continue Reading

Back to Main

Subscribe for the latest news: