RabbitMQ Flaws Expose OAuth Secrets and Cross-Tenant Queue Metadata
Cybersecurity researchers at Miggo have disclosed two access control vulnerabilities in the RabbitMQ message broker that could allow attackers to leak OAuth…
Datadog Security Labs has uncovered several overlapping campaigns that leverage dormant GitHub accounts—some created two to five years ago—to systematically enumerate corporate…
A new malware strain named Umbrij, attributed to the advanced persistent threat (APT) group ToddyCat, is abusing OAuth 2.0 tokens to gain…
A critical pre-authentication remote code execution vulnerability in Progress Kemp LoadMaster, tracked as CVE-2026-8037 (CVSS 9.6), is now facing active exploitation attempts.…
Researchers at Wake Forest University tested 444 AI chatbot apps for iPhone and found that 282 of them (nearly two-thirds) exposed paid…
Researchers at Wake Forest University conducted the first in-depth study of API key leaks in iOS AI apps, using their tool LLMKeyLens.
A critical vulnerability in Progress Kemp LoadMaster, tracked as CVE-2026-8037 with a CVSS score of 9.8, allows unauthenticated attackers to execute arbitrary…
AI agents are increasingly deployed in enterprise environments, inheriting permissions and executing tasks autonomously, often bypassing traditional identity governance controls. This article…
According to a new analysis by Intruder, 60% of organizations have at least one HTTP panel exposed, 49% have a risky port…
The cybersecurity landscape is shifting as Shadow AI evolves from a data leakage concern to a critical access control problem. According to…