• Security
  • By Catalin Cimpanu
  • November 30th, 2015
Road Billboards App Mishandled Security Protocols, Exposed Users to Abuses

Road Billboards App Mishandled Security Protocols, Exposed Users to Abuses

Passwords were exposed in plaintext, API's source code was accessible via the Web, no HTTPS for communications

  • Security
  • By Lucian Constantin
  • February 22nd, 2011
New Session-Stealing Banking Trojan Identified

New Session-Stealing Banking Trojan Identified

XSS Attack on Twitter Subdomain Allowed for Complete Session Hijacking

XSS Attack on Twitter Subdomain Allowed for Complete Session Hijacking

Broad authentication cookie domain scope at fault

Trojan Advertised as Open Source Antivirus Solution

Trojan Advertised as Open Source Antivirus Solution

Hijacks online banking sessions on infected computers

Universal Google Cross-Site Scripting Flaw Discovered

Universal Google Cross-Site Scripting Flaw Discovered

Putting most of a user's Google-hosted assets at risk