Browsing Category
Marketplace News
117 posts
Security Point Break tracks the companies, products and market moves shaping cybersecurity. Marketplace News covers security vendors, product launches, funding, acquisitions, partnerships and competitive shifts, with context on what those developments mean for security teams, technology buyers and the broader cybersecurity industry.
Disabled Accounts Still Leave Tokens Behind
Offboarding often closes the login door while leaving OAuth grants, API keys, cached sessions and delegated access alive.
Mexican Banks Hit by GitHub-themed Phishing That Hijacks Customer Accounts
A modular operation abuses GitHub Pages and a spreadsheet API to harvest banking credentials across multiple Mexican brands.
BabaDeda Loader Resurfaces in ClickFix Campaign Abusing Software Updaters
The updated loader uses fake user fixes, PowerShell, in-memory shellcode and DLL sideloading to deliver stealers and remote-access malware.
Google Patches Five Critical Chrome Web Browser Bugs
The browser's latest Stable update closes 28 security holes. Four of the five Critical flaws need an attacker to already be inside Chrome; one does not.
Phishing Kits Abuse Microsoft Login Codes to Steal Cloud Access
LevelBlue says phishing kits are industrializing OAuth device-code attacks, giving attackers Microsoft 365 tokens without stealing a password first.
Microsoft’s Record Patch Tuesday Upstaged Within Hours by New Defender Zero-Day
Microsoft's June Patch Tuesday addressed about 200 vulnerabilities, but the emergence of a new exploit, RoguePlanet, highlights ongoing security concerns with Microsoft Defender.
Acer 5G Hotspot Has Three Critical Bugs: Patches Pending
Acer says firmware updates are coming and offers workaround fixes for three critical bugs.
Cisco Confirms Third SD-WAN Manager Zero-Day of 2026
Cisco warns of a high-severity flaw in its SD-WAN Manager, enabling attackers with netadmin access to gain root control.
CISA Pushes Oracle WebLogic Bug from Patch Backlog to Active-Exploit Priority
The agency added CVE-2024-21182 to its known exploited vulnerability catalog, giving federal agencies until June 4 to address a WebLogic Server flaw Oracle patched in July 2024.
DJI Audit Finds No Backdoors as FCC Fight Moves From Policy to Proof
DJI's independent security assessment found no significant risks in its drones, strengthening its position against U.S. regulations, despite ongoing security concerns and market uncertainties.