Topic
Web & API Security.
3 stories of advisories, analysis, and defensive guidance in this topic.
Casdoor Authentication Bypass Flaws Undermine SAML, MFA, and Token Controls
CERT/CC disclosed nine Casdoor flaws that can let attackers bypass SAML, MFA, and token controls.
Firefox 151.0.3 Patches High-Severity JIT and Graphics Flaws
Mozilla released Firefox 151.0.3 to fix two high-severity browser flaws in the JIT engine and graphics text handling path.
Firefox for iOS 151.2 Fixes Reader View JavaScript Execution Bugs
Firefox for iOS 151.2 patches two high-severity Reader View bugs that could lead to arbitrary JavaScript execution.