• Security
  • By Catalin Cimpanu
  • September 4th, 2015
Security Issues Fixed in OrientDB "Studio" Web Interface

Security Issues Fixed in OrientDB "Studio" Web Interface

OrientDB devs fix CSRF and click-jacking vulnerabilities

Blue Coat Patches SSL Visibility Appliance Against 4 Security Bugs

Blue Coat Patches SSL Visibility Appliance Against 4 Security Bugs

Risk of stealing user sessions and clickjacking

URL Spoofing in Safari Opens Door for Phishing Attacks

URL Spoofing in Safari Opens Door for Phishing Attacks

Flaw can be exploited on the latest versions of iOS and OS X

WSO2 Identity Server Vulnerable to XSS and CSRF Attacks

WSO2 Identity Server Vulnerable to XSS and CSRF Attacks

Proof-of-concept exploit code published for each issue

Multiple Flaws Found in Motorola’s Surfboard SBG6580 Cable Modem

Multiple Flaws Found in Motorola’s Surfboard SBG6580 Cable Modem

Attack exploits backdoor support account, CSRF and XSS flaws

Account Hijacking Flaw Patched by Hilton Hotels in HHonors Website

Account Hijacking Flaw Patched by Hilton Hotels in HHonors Website

Password changing is still not completely secure

D-Link Patches Against Critical Remote Command and Code Execution Flaws

D-Link Patches Against Critical Remote Command and Code Execution Flaws

Both glitches can be exploited without authentication

D-Link Fixes Router Flaws Following Public Disclosure

D-Link Fixes Router Flaws Following Public Disclosure

Company finds several other vulnerable products

Email-Based Pharming Attack Exploits Router Flaws

Email-Based Pharming Attack Exploits Router Flaws

Only the primary DNS address points to rogue server

GoDaddy Domains Exposed to Hijacking Due to CSRF Vulnerability

GoDaddy Domains Exposed to Hijacking Due to CSRF Vulnerability

Domain registrar solves the problem without any delay

Critical PayPal Bug Left All Accounts Vulnerable to Hijacking

Critical PayPal Bug Left All Accounts Vulnerable to Hijacking

Several flaws exploited to take over PayPal accounts

CSRF Vulnerability in Instagram Allowed Hackers to Make Private Profiles Public

CSRF Vulnerability in Instagram Allowed Hackers to Make Private Profiles Public

Facebook has addressed the issue, but it took the company around 6 months to do it

Vulnerabilities in RunKeeper Allowed Cybercriminals to Run XSS Worm

Vulnerabilities in RunKeeper Allowed Cybercriminals to Run XSS Worm

Portuguese security researcher David Sopas is the one who found the flaws

CSRF Vulnerability in Twitter Allowed Hackers to Read DMs, Post Tweets

CSRF Vulnerability in Twitter Allowed Hackers to Read DMs, Post Tweets

Twitter fixed the security hole within hours of being discovered

Cybercriminals Exploit TP-Link Router CSRF Vulnerabilities to Hijack DNS Settings

Cybercriminals Exploit TP-Link Router CSRF Vulnerabilities to Hijack DNS Settings

Hackers can lure users to phishing sites, block updates and replace downloaded files

  • Security
  • By Eduard Kovacs
  • September 16th, 2013
CSRF Vulnerability in eBay Allows Hackers to Hijack User Accounts – Video

CSRF Vulnerability in eBay Allows Hackers to Hijack User Accounts – Video

The issue has been reported to eBay, but it's still unfixed

Google Fixes CSRF Vulnerability in Translator and Clickjacking Flaw in Gmail – Video

Google Fixes CSRF Vulnerability in Translator and Clickjacking Flaw in Gmail – Video

Security researcher Prakhar Prasad is the one who identified the issues

 
Want more? Browse: