Conservative MPs attempted Thursday to invite Canada’s Privacy Commissioner to return to a Commons committee as it considered ...
Two things landed within days of each other this week. A security startup reported 21 previously unknown vulnerabilities in FFmpeg, the media library inside almost everything that touches video, all ...
Dashlane said that attackers mounted a coordinated hacking campaign against a large base of its users in an attempt to ...
Six Proto6 flaws in protobuf.js enable RCE and DoS attacks; patched in versions 7.5.6 and 8.0.2 to protect Node.js services.
A github.dev flaw could let attackers steal GitHub OAuth tokens through a one-click attack, exposing private repositories and ...
The change, expected in July, will likely block one of the more common attack vectors; developers are wondering what took ...
A new supply-chain attack has infected 36 packages on the Node Package Manager (npm) index with infostealer malware called IronWorm. The malware targets 86 environment variables (key-value pairs) and ...
A coding error in several Microsoft 365 Android apps could have allowed a malicious app on the same device to silently obtain account tokens and act as the signed-in user, according to new research ...
Explore the latest news and expert commentary on Application Security, brought to you by the editors of Dark Reading ...