admin

Ruby on Rails apps vulnerable to data theft through Ransack search

A number of applications have shown vulnerabilities to brute-force attacks, with hundreds more potentially at risk. UPDATED: Poor implementation of the Ransack library in Ruby on Rails (RoR) applications could enable attackers to extract data from backend databases, according to a warning issued by security firm Positive Security. Ransack provides developers with the ability to…

Read More

Facebook two-factor authentication bypass issue patched

Emma Woollacott27 January 2023 at 11:50 UTC Updated: 17 February 2023 at 14:20 UTC A significant security vulnerability was identified as one of Meta’s major issues in 2022. Meta has successfully addressed a flaw in Facebook that could have enabled cybercriminals to bypass SMS-based two-factor authentication (2FA). This vulnerability, which resulted in a bounty of…

Read More

Deserialized web security roundup: ‘Catastrophic cyber events’, another T-Mobile breach, more LastPass problems

Adam Bannister27 January 2023 at 16:48 UTC Updated: 27 February 2023 at 15:33 UTC We bring you a comprehensive update on the latest AppSec vulnerabilities, innovative hacking techniques, and key developments in cybersecurity. According to a recent survey by the World Economic Forum (WEF), 93% of cybersecurity experts and 86% of business leaders anticipate that…

Read More

Deserialized web security roundup: ‘Catastrophic cyber events’, another T-Mobile breach, more LastPass problems

Adam Bannister27 January 2023 at 16:48 UTC Updated: 27 February 2023 at 15:33 UTC This is your bi-weekly summary of application security vulnerabilities, emerging hacking methods, and the latest cybersecurity updates. {“According to 93% of cybersecurity professionals and 86% of business leaders surveyed, a significant catastrophic cyber incident is likely within the next two years,”…

Read More
Back To Top