CISA orders feds to patch Oracle Identity Manager zero-day after signs of abuse

CISA has ordered US federal agencies to patch against an actively exploited Oracle Identity Manager (OIM) flaw within three weeks – a scramble made more urgent by evidence that attackers may have been abusing the bug months before a fix Read More …

You Thought It Was Over? Authentication Coercion Keeps Evolving

Imagine a scenario where malicious actors don’t need to trick you into giving up your password. They have no need to perform sophisticated social engineering attacks or exploit vulnerabilities in your operating system.Instead, they can simply force your computer to Read More …

Louvre used ‘Louvre’ as password for its video surveillance system

At the time of the brazen heist of $102 million in jewels from the Louvre last month, the password to the world-famous museum’s video surveillance system was simply “Louvre,” according to a museum employee with knowledge of the system. The Read More …

Serious Microsoft Entra flaw could have let hackers infiltrate any user – patch now

Security researchers have found a critical vulnerability in Microsoft Entra ID which could have allowed threat actors to gain Global Administrator access to virtually anyone’s tenant – without being detected in any way. The vulnerability consists of two things – Read More …

How AI-Native Development Platforms Enable Fake Captcha Pages

Artificial intelligence has revolutionized web development, empowering even novice users to create professional-looking websites. Tools like Lovable enable anyone to build and host applications with little to no coding knowledge, while Netlify and Vercel position themselves as AI-native development platforms. Read More …

SonicWall customers told to reset credentials following firewall data breach

SonicWall is urging its firewall customers to reset their passwords after confirming it suffering a security incident which may have exposed their data. In a security announcement, SonicWall outlined how unnamed threat actors brute-forced their way into the company’s MySonicWall Read More …

All Plex users should reset passwords in wake of data breach

Popular media server and streaming platform, Plex, warned its users about losing their sensitive data in a cyberattack, and urged them to update their passwords as a result. In a forum post published on September 8, Plex said it recently Read More …

The growing debate over expanding age verification laws

Technologists and policymakers are reckoning with a generation-defining problem on the internet: while it can be a revolutionary force for unprecedented education and connection across the globe, it can also pose dangers to children when they have completely unfettered access. Read More …

Google warns Gmail users to change passwords after data breach

Google is warning about 2.5 billion Gmail users to change their passwords or install a passkey following a data breach that has led to a surge in “phishing” email attacks. The data breach that prompted the warning reportedly happened at Read More …