Scroll down for all the latest web application security news and information.
Subscribe to our weekly newsletter for the latest in industry news, expert insights, dedicated information security content and online events.
Critical phpBB authentication bypass lets attackers hijack any account with one request
OpenAI brings Lockdown Mode and Active Sessions to ChatGPT to curb prompt injection data theft
Avada Builder flaws allowed file read and SQL injection on one million WordPress sites
Sophos finds fake Claude site spreading DonutLoader and a new Beagle backdoor via DLL sideloading
Dozens of browser extensions openly sell user data via privacy policy disclosures
Null subject phishing campaigns bypass filters and target VIPs with QR code and RMM abuse