Browsing Category
Application Security
35 posts
Security Point Break covers application security threats, vulnerabilities and defenses across modern software development. Our reporting follows secure coding, API security, open-source risk, software supply chain attacks, vulnerability research, AppSec testing and the security challenges created by AI-generated code and development tools — with practical context for security and development teams.
SocGholish Attackers Hijack 1,509 WordPress Sites for Drive-by Attacks
Compromised WordPress sites are funneling traffic into a fake browser-update scam long after a malware infrastructure takedown, exposing ongoing security risks.
OpenAI’s Models Didn’t Go Rogue: They Just Found Every Unlocked Door
OpenAI's models exploited vulnerabilities, breaching Hugging Face's systems, highlighting flaws in AI safety protocols and response systems.
OpenSSL Patches 11-byte DoS Flaw it Decided Didn’t Need a CVE
Researchers have uncovered a denial-of-service flaw that might be the most dangerous Eleven since Millie Bobby Brown. The…
AI Security Tools for MCP Servers Get it Wrong 50% of the Time, Study Claims
A Fudan University study reveals that current security scanners for Model Context Protocol servers inaccurately flag potential risks, impeding effective cybersecurity.
Critical Blocksy WordPress Plugin Bug Lets Attackers Skip Login Entirely
A double-extension trick — naming a file shell.woff2.php — is enough to bypass validation and run code as the web server.
GitHub AI Agent Bug Let Attackers Leak Private Code
One word - "Additionally" - was enough to defeat GitHub's guardrails and expose private repository contents to the open web.
AI’s AppSec Catch-22: Faster Code, More Risk and a Shrinking Audit Trail
VIDEO: AI is speeding up software development, challenging security teams to balance rapid release with vulnerability management, leading to risks of deploying known vulnerabilities without adequate oversight.
AI Code Is Moving Faster Than AppSec’s Audit Trail
Checkmarx research points to a deeper software security problem: AI is accelerating development while companies struggle to prove what shipped, what touched the code and who accepted the risk.
Your Doorbell Is Somebody Else’s Cybercrime Tool: Here’s How
A new report reveals that American home internet connections are exploited for cybercrime and espionage, highlighting the lack of regulatory authority among federal agencies to address this growing issue.
Klue Supply Chain Attack: How a 2022 Credential Exposed LastPass and Ten Other Firms
The Klue supply chain attack exposed a structural blind spot that most security teams still haven't fixed: the forgotten OAuth connection sitting quietly in the corner of their Salesforce instance.