Researchers found a security flaw in OneDrive File Picker that grants apps access to any and all files in the account when the user grants permission for just one file upload, with the language governing this process cited as too "vague" and "unclear" to communicate what is actually happening.
A security flaw in Titan, Microsoft’s analytics platform, could have enabled a 16-year-old researcher to access over 17 trillion records after gaining access to 17 databases.
Reported security risks in U.S. online voting system OmniBallot have added to the mounting concern over vote manipulation during 2020 US presidential election.
When athletes arrive at the 2022 Winter Olympics they will be required to download an app called MY2022. Meant for contact tracing purposes, it will be packed with some unexpected extras: security flaws and possible censorship features.
Second largest data leak in history exposed First American’s 900 million customer information just by raising or lowering a single digit in the document URL.
Study on security priorities found that 90% of IT and security decision-makers believed their organizations failed to address cybersecurity risks.
A new report finds that security professionals are receptive to the idea of more regulation by the federal government in the interest of improving cyber defenses. 99% feel that federal agencies are not doing enough to protect their own data and systems.
Seventy percent of security pros want governments to impose social media regulation for the collection of personal data by social media companies. Yet, expectations are hazy and 72% also indicated that they have little to no faith that government officials have an understanding of the threats to digital privacy.
The Oasis researchers document a vulnerability chain that can be initiated from any website the AI agent (or its user) visits, without users needing to interact in any way or being at all aware that they are being compromised. The attack targets the OpenClaw "gateway" that essentially acts as the AI agent's nerve center.
Alarms raised about embedded TikTok browser capable of tracking keystrokes. Company says that the ability exists within the code, but that it is not active and only used internally for debugging and testing purposes.









