Security News

Uber Patches Authentication Bypass Vulnerability on Custom SSO Solution (Threatpost)
2017-07-12 16:36

Uber patched an authentication bypass vulnerability in its homegrown SSO solution that allowed attackers to take over subdomains and steal session cookies.

Authentication Bypass Flaw Patched in BIND, Knot DNS (Security Week)
2017-06-30 09:39

The developers of the BIND and Knot DNS software have released updates to patch a potentially serious vulnerability that can be exploited to bypass authentication mechanisms. read more

Authentication Bypass, Potential Backdoors Plague Old WiMAX Routers (Threatpost)
2017-06-08 13:00

WiMAX routers manufactured by several companies, including Huawei and ZyXEL, are vulnerable to an authentication bypass and potential backdoors.

FreeRADIUS Update Resolves Authentication Bypass (Threatpost)
2017-05-30 18:39

Developers behind FreeRADIUS, an open source implementation of the networking protocol RADIUS, are encouraging users to update to address an authentication bypass found in the server.

Authentication Bypass Flaw Patched in FreeRADIUS (Security Week)
2017-05-30 16:14

A FreeRADIUS update released on Friday patches a potentially serious vulnerability that can be exploited to bypass authentication to the server. Developers have known about the flaw for months,...

Criminals are Now Exploiting SS7 Flaws to Hack Smartphone Two-Factor Authentication Systems (Schneier on Security)
2017-05-10 11:50

I've previously written about the serious vulnerabilities in the SS7 phone routing system. Basically, the system doesn't authenticate messages. Now, criminals are using it to hack smartphone-based...