Scroll down for all the latest web application security news and information.
Subscribe to our weekly newsletter for the latest in industry news, expert insights, dedicated information security content and online events.
Avada Builder flaws allowed file read and SQL injection on one million WordPress sites
SentinelOne believes the PCPJack campaign may be the brainchild of a former TeamPCP member
Medtronic confirms IT breach as ShinyHunters claims millions of records accesseda
At VulnCon, Lindsey Cerkovnik, head of vulnerability management at CISA, said AI companies should play a bigger role in vulnerability disclosures in the future
Attackers are abusing Microsoft 365 mailbox rules to hide activity, exfiltrate data and retain access after account compromise, researchers warn
GrafanaGhost chains AI prompt injection and URL flaws to exfiltrate sensitive Grafana data