[HIGH] – Twitch Extension With 30,000 Installs Exposes OAuth Tokens
A Twitch browser extension with over 30,000 installs exposed OAuth tokens through proxy requests.
Cybersecurity, AI, etc.
A Twitch browser extension with over 30,000 installs exposed OAuth tokens through proxy requests.
Oracle's September Critical Security Patch Update delivers 673 security fixes across product families.
JFrog disclosed a local Parallels Desktop flaw allowing unprivileged macOS users to execute code as root.
Attackers are exploiting an unauthenticated file-upload flaw in WooCommerce Wholesale Lead Capture.
Google patched an actively exploited Pixel modem privilege-escalation flaw in its September update.
DDRop researchers demonstrate a DDR5 interposer attack against Intel and AMD confidential-computing technologies.
cPanel urges LiteSpeed Enterprise administrators to update to 6.3.7 for a shared-hosting privilege-escalation flaw.
Acronis details Red Heron's Gitea exploitation, source-code theft, persistence, and lateral movement.
CISA added an actively exploited Cisco Secure Email Gateway SQL-injection flaw to KEV.
ENISA's new CRA portal centralizes manufacturer reporting of actively exploited vulnerabilities and severe incidents.