GitHub says bug exposed some plaintext passwords
A small but unspecified number of GitHub staff could have seen plaintext passwords. GitHub has said a bug exposed some user passwords — in plaintext. The code repository site, withRead More →
A small but unspecified number of GitHub staff could have seen plaintext passwords. GitHub has said a bug exposed some user passwords — in plaintext. The code repository site, withRead More →
Recently a Dutch information security company has discovered that vehicle infotainment systems (IVI) implemented in some Volkswagen Group car models are vulnerable to remote hacking. Information security researchers from Computest,Read More →
Almost a year ago, on May 4, 2017, information security researcher privately discovered and reported a spoofing vulnerability of the recipient in Google Inbox. The expert noticed that the compositionRead More →
For the most part, SAP implementations continue to be affected by vulnerability in the security configuration initially documented in 2005, information security experts warn. Analysts comment that careless security configurationsRead More →
The Drupal security team has fixed another Drupal remote code execution vulnerability, which suggests users to implement the updates offered immediately as the flaw is being exploited actively in theRead More →
Symantec professionals have found a vulnerability that could allow hackers to compromise iOS devices without the owner’s knowledge. This iOS attack named as “Trustjacking” by information security researchers exploits a vulnerability inRead More →
An information security expert explains that Grouper is an unstable PowerShell module designed for use by pentesters and redteamers that filters the XML output of the Get-GPOReport cmdlet and identifies all theRead More →
So far, researchers have uncovered how web trackers exfiltrate identifying information from web pages, browser password managers, and form inputs. Now, the information security experts report yet another type ofRead More →
Private profile data, like phone numbers and email addresses, could have been easily collected. According to information security experts, the flaw was found in LinkedIn’s widely used AutoFill plugin, which allows approvedRead More →
Cisco has issued a critical patch to fix a serious vulnerability (CVE-2018-0112) in its WebEx software that could be exploited by remote attackers to execute arbitrary code on target machinesRead More →