Please turn on your JavaScript for this page to function normally.
OAuth2.0 implementation flaw allows attackers to pop Android users’ accounts
Incorrect OAuth2.0 implementation by third party mobile app developers has opened users of those apps to account compromise, three researchers from the Chinese University of …
OneLogin breached, customers’ Secure Notes compromised
San Francisco-based OneLogin, which offers single sign-on and identity management for cloud-based applications and claims 1400+ enterprise customers in 44 countries, has …
QRLJacking: A new attack vector for hijacking online accounts
We all know that scanning random QR codes is a risky proposition, but a newly detailed social engineering attack vector dubbed QRLJacking adds another risk layer to their use. …
Featured news
Resources
Don't miss
- Mapping the malware blast radius a single alert won’t show you
- SkillSpector: NVIDIA’s open-source security scanner for AI agent skills
- AI cut phishing from hours to seconds, which is where DMARC and BIMI come in
- Aviation cyber risk sits on the ground, the blindness sits in the air
- Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)