
NorthDuty Shields URL Fetching Services from SSRF Attacks
A new two-layer defense strategy protects services that fetch user-provided URLs from critical server-side request forgery vulnerabilities.
Five shifts. Five minutes. No noise.
No spam. Unsubscribe anytime. Powered by Beehiiv.

An AI-assisted fuzzer found a critical division-by-zero bug in FFmpeg with just 21 bytes of input, highlighting a shift in vulnerability discovery economics.

Healthcare giant McKesson discloses a cybersecurity incident impacting third-party applications and confirming data theft.

Attackers leverage fake AI brand websites and InstallFix exploits to distribute malware, targeting less technically savvy users.

A new two-layer defense strategy protects services that fetch user-provided URLs from critical server-side request forgery vulnerabilities.

Microsoft's latest Patch Tuesday addresses an unprecedented 570 flaws, including 6 critical and 10 zero-days, across its product suite.

A vulnerability in Tailscale SSH's argument handling could let attackers run any command on your nodes. Here's how it works and how to fix it.

A flaw in Tailscale SSH's argument handling could let unprivileged users gain root privileges on affected nodes.

Researchers reveal a novel attack vector that weaponizes AI safety mechanisms, forcing models to generate harmful content by overloading their context windows.

Amazon CloudFront now offers a way to generate an HTTP-request-based JA4H fingerprint using CloudFront Functions.

Forgotten Microsoft bootloader components allowed attackers to bypass UEFI Secure Boot for years.

National Police dismantle sophisticated ring involved in investment scams and BEC attacks, seizing millions in assets.

SonicWall urges immediate patching of SMA1000 devices following active exploitation of two zero-day vulnerabilities.

Developer builds lightweight, open-source tool to stop browser profile theft using process lineage and socket monitoring.