Salt Labs exposes a new vulnerability in popular OAuth framework, used in hundreds of online services

This post is the second in a series describing OAuth implementation issues that put companies at risk. We create these posts to share rich technical details, drawn from real-world use cases, to educate the broader industry on the nature of these errors, their potential impact, and how to avoid them to better protect API ecosystems.

Data loss prevention for developers

A security violation in the form of a data breach can create costly damage to a company's reputation. But what exactly is a data breach? The European Commission has divided data breaches into three distinct categories — confidentiality breaches, integrity breaches, and availability breaches: In this article, you'll learn more about what a data breach is and how you can prevent data breaches when designing and developing your software.

DigiCert Code Signing Changes: New Private Key Storage & API Modifications

Beginning on June 1, 2023, at 00:00 UTC, industry standards will mandate that private keys for code signing certificates must be stored on hardware that meets specific security certifications such as FIPS 140 Level 2, Common Criteria EAL 4+, or an equivalent standard. This requirement applies to all new code signing certificate requests and requests for renewal and reissue of existing certificates.

Save, sign in, and unlock with passkeys

Passkeys are the future of authentication: they're both safer, and easier to use than passwords. You can now store, manage, and use passkeys to access online accounts through 1Password in the browser. Later this summer, you'll also get the option to secure your 1Password account, unlock vaults, and sign in securely across multiple devices using a passkey.

ChatGPT Reveals Top 5 Cybersecurity Concerns for Businesses

Welcome to a special edition of Razorwire, where I had the pleasure of interviewing AI language model, ChatGPT. Our discussion revolved around various topics related to information security and cybersecurity. ChatGPT shared valuable insights on how AI can assist in securing organisations against cyber attacks but also emphasised that it should be considered just one tool in a broader cybersecurity strategy. We delved into the future of cybersecurity, key technologies for a defence in depth approach, and the advantages of continuous penetration testing.

June Update: The Escalation of the PaperCut Vulnerability Campaign

Over the past two months, the Cyberint research team has witnessed an extensive campaign in which threat actors are actively exploiting the recently discovered vulnerability in the PaperCut print management platform. The Cyberint research team has identified a significant trend in relation to these recent attacks and associated incidents linked to this vulnerability.

Mergers don't have to be a nightmare for IT teams

When it comes to merger and acquisition activity – 2023 is poised to be an active year despite uncertain macroeconomic conditions. As always, financial due diligence will be the cornerstone of successful M&A endeavors. Unfortunately for IT teams, there’s no similar process for scrutinizing the network.