Browsing Category
Application Security
36 posts
Security Point Break covers application security threats, vulnerabilities and defenses across modern software development. Our reporting follows secure coding, API security, open-source risk, software supply chain attacks, vulnerability research, AppSec testing and the security challenges created by AI-generated code and development tools — with practical context for security and development teams.
Klue Supply Chain Attack: How a 2022 Credential Exposed LastPass and Ten Other Firms
The Klue supply chain attack exposed a structural blind spot that most security teams still haven't fixed: the forgotten OAuth connection sitting quietly in the corner of their Salesforce instance.
Google Workspace Has a Zombie OAuth Token Problem
A report reveals OAuth-connected Google Workspace apps retained access despite inactivity, posing security risks amid rapid AI tool adoption.
Smart TV Apps on LG and Samsung Are Running Residential Proxy Software
A scan of more than 6,000 LG and Samsung apps found roughly one-third contain SDK code that routes outside internet traffic through the viewer's home connection—without meaningful consumer awareness.
GlassWorm is Back as GlassWASM, Hiding in Open VSX Extensions
A new WebAssembly variant hides its payload in compiled binary and pulls its commands from the Solana blockchain and neither of which standard extension scanners are built to catch.
BabaDeda Loader Resurfaces in ClickFix Campaign Abusing Software Updaters
The updated loader uses fake user fixes, PowerShell, in-memory shellcode and DLL sideloading to deliver stealers and remote-access malware.
Cisco Confirms Third SD-WAN Manager Zero-Day of 2026
Cisco warns of a high-severity flaw in its SD-WAN Manager, enabling attackers with netadmin access to gain root control.
Creative Soundbar Hack Hits a Bad Note
Turn it up to pwned. No authentication, no pairing, no physical access — just a custom firmware pushed over Bluetooth and a Katana V2X that now spies, types, and won't easily forget how.
Critical Adobe Acrobat Flaw Exploited: What You Need to Know
Exodus Intelligence published a full exploit chain for an Acrobat Reader memory flaw, showing how a malicious PDF could bypass several Windows defenses on 32-bit systems.
Sonatype: Open Source Malware Has Moved Beyond Typosquatting
Sonatype's report reveals that attackers craft misleading open-source packages, exploiting familiarity to access developer data, emphasizing the need for cautious dependency management.
‘Malware-Slop’ npm Package Targets Claude AI User Files
OX Security said a malicious npm package tried to steal files from Claude user workspaces and upload them to GitHub.