Security News

Facebook offers bounties for user token bugs in third-party apps, websites
2018-09-18 12:34

Facebook is expanding its bug bounty program to include vulnerabilities in third-party apps and websites that involve improper exposure of Facebook user access tokens. What’s in scope? “Access...

Facebook Offers Rewards for Access Token Exposure Flaws
2018-09-18 09:43

Facebook announced on Monday that it has expanded its bug bounty program to introduce rewards for reports describing vulnerabilities that involve the exposure of user access tokens. read more

Facebook Now Offers Bounties For Access Token Exposure
2018-09-17 17:43

The newly expanded Facebook bug bounty program sniffs out access token exposure flaws.

Leaked GitHub API Token Exposed Homebrew Software Repositories
2018-08-09 13:50

A GitHub API token leaked from Homebrew’s Jenkins provided a security researcher with access to core Homebrew software repositories (repos). read more

Google Employees Use a Physical Token as Their Second Authentication Factor
2018-07-26 17:18

Krebs on Security is reporting that all 85,000 Google employees use two-factor authentication with a physical token. A Google spokesperson said Security Keys now form the basis of all account...

Malicious ESLint Packages Steal Software Registry Login Tokens
2018-07-16 16:27

Following the compromise of an ESLint maintainer’s account last week, malicious packages that attempted to steal login tokens from the npm software registry were published without authorization. read more

Phishing Defense: Block OAuth Token Attacks
2018-06-21 10:03

But OAuth Attack Defense Remains Tricky, Warns FireEye's Douglas BienstockJust one click: That's all it takes for a victim to inadvertently grant attackers access to their email account via a...

Yubico snatched my login token vulnerability to claim a $5k Google bug bounty, says bloke
2018-06-18 23:21

USB gizmo biz apologies amid infosec drama Yubico has apologized to a security vulnerability researcher who had complained the dongle peddler lifted his work to nab a $5,000 Google bug bounty.…

The Google Pixelbook power button is now a 2FA token
2018-06-12 14:36

The Pixelbook's power button is a 2FA token, which is great, and almost nobody noticed, which isn't.

Scammers steal nearly $1 million from Bee Token ICO would-be investors
2018-02-02 18:28

Another day, another ICO-related scam. In an attack similar to that which fooled investors into the Enigma cryptocurrency investment platform, users who were aiming to buy Bee Tokens during a...