Full Disclosure·2h ago high[0day-rubbish] Netsis NetOpenX REST 2.0.6.9 Unauthenticated SQL injection to xp_cmdshell SYSTEM command execution (9.8)#netsis#sql-injection#rceVulnerability 5 sources1
oss-security·1d ago highCVE-2026-82378: Apache Roller: OAuth authorization endpoint trusts request-supplied identity#apache-roller#oauth#cve-2026-82378CVE-2026-82378 17 sources
oss-security·2d agoCVE-2026-92289: Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPointAuthenticationCredentials does not verify the client secret#lemonldap#oauth#pkceCVE-2026-92289 3 sources
The Hacker News·2d ago criticalF5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers#apm#big-ip#cisa 14 sources in the wild 4 min
GBHackers·2d agoFake Firefox Extension Hijacks Google Accounts Without Stealing Passwords First#firefox#browser-extension#session-hijacking 2 sources in the wild 5 min
Malwarebytes Labs·3d agoHow device code phishing gives scammers access to your account#device-code-phishing#oauth#mfa-bypass 3 min
Huntress·3d ago highOAuth Token Theft Through Microsoft's Front Door | Huntress#wwahost#appx#oauth 15 min
GBHackers·3d ago highMicrosoft Warns of EvilTokens AI Phishing Service Hijacking Thousands of Accounts#b2-ec#device-code#e-a-p 14 sources in the wild 5 min
GBHackers·3d agoAembit Launches Support for Okta Cross App Access, Extending Enterprise Identity Controls to AI Agents#aembit#okta#iam 3 sources 3 min
Dark Reading·4d ago highShai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub Data#shai-hulud#crowdsec#github 3 sources in the wild
CSO Online·4d agoBeware these fake websites selling subscriptions to AI assistants#scam#fake-websites#ai-subscriptions 3 sources 3 min
BleepingComputer·4d agoWebinar tomorrow: Inside real-world Google Workspace breaches#google-workspace#oauth#social-engineering 3 min
CSO Online·5d agoRevoking the token didn’t kill the backdoor#c2#china-nexus#graphworm in the wild 5 min
Cyber Security News·7d ago highTanStack Supply Chain Attack Lets Hackers Steal 170 Private CrowdSec GitHub Repositories#credential-harvesting#crowdsec#github in the wild 4 min
CSO Online·8d ago highGhostCode attackers abuse device codes to take over Microsoft 365 accounts#device-code-phishing#entra-id#esentire in the wild 3 min2
BleepingComputer·8d agoWebinar: Which Google Workspace security controls actually matter?#google-workspace#incident-response#oauth 3 min
GBHackers·8d ago12 Best SSPM Tools Compared (2026): Features & Pricing#adaptive-shield#appomni#crowdstrike 2 sources 10 min
arXiv cs.CR·10d agoCharacterizing Network Centralization and Observability in the Remote MCP Ecosystem#agents#ecosystem-measurement#llm-securityAI safety & security1
Cyber Security News·10d ago highGhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds#bec#device-code-phishing#esentire in the wild 6 min5
GBHackers·10d ago highGhostCode Abuses Microsoft Entra Device Enrollment to Maintain Access After Token Revocation#bec#device-code-phishing#esentire in the wild 5 min3
BleepingComputer·10d agoWebinar: What happens in the first hours of a Google Workspace breach#google-workspace#incident-response#oauth 3 min
GBHackers·10d agoNIST Issues New Guidance to Protect SSO and API Tokens From Theft and Forgery#cloud-security#identity-security#nist 2 sources 3 min
Help Net Security·11d agoThe modern attack chain: Rethinking Google Workspace security in the age of AI#account-takeover#ai-agents#attack-chain in the wild 8 min