Aggregator
CISOs urged to fix API risk before regulation forces their hand
Most organizations are exposing sensitive data through APIs without security controls in place, and they may not even realize it, according to Raidiam. Their report draws on a detailed assessment of 68 organizations across industries. It deliberately excludes regulated environments like UK Open Banking, where advanced security is mandated. The goal was to understand how typical businesses, those without regulatory pressure, are protecting their APIs. The results aren’t encouraging. Over 80% of organizations fell into … More →
The post CISOs urged to fix API risk before regulation forces their hand appeared first on Help Net Security.
CVE-2007-1996 | codebreak 1.1.2 codebreak.php process_method code injection (EDB-3711 / BID-23425)
CVE-2022-2048 | Oracle Banking Cash Management 14.7.0.2.0/14.7.1.0.0 Accessibility denial of service (Nessus ID 241484)
CVE-2022-2048 | Oracle Banking Supply Chain Finance 14.7.0.2.0/14.7.1.0.0 Security denial of service (Nessus ID 241484)
CVE-2022-2048 | Oracle Autovue for Agile Product Lifecycle Management 21.0.2 Autovue Client denial of service (Nessus ID 241484)
CVE-2022-2048 | Oracle Communications Cloud Native Core Binding Support Function Signaling denial of service (Nessus ID 241484)
CVE-2022-2048 | Oracle Communications Cloud Native Core Policy 22.3.0 denial of service (Nessus ID 241484)
CVE-2022-2048 | Oracle Financial Services Crime and Compliance Management Studio denial of service (Nessus ID 241484)
CVE-2022-2048 | Oracle Banking Corporate Lending Process Management 14.4/14.5/14.6/14.7 Base denial of service (Nessus ID 241484)
CVE-2022-2048 | Oracle Communications Unified Assurance up to 5.5.7.0.0/6.0.0.0.0 Message Bus denial of service (Nessus ID 241484)
CVE-2022-2048 | Oracle Communications Element Manager 9 GEN denial of service (Nessus ID 241484)
CVE-2022-2048 | Oracle Retail EFTLink 20.0.1/21.0.0 Other denial of service (Nessus ID 241484)
CVE-2022-2048 | Oracle AutoVue 21.0.2 Web General denial of service (Nessus ID 241484)
CVE-2022-2048 | Eclipse Jetty HTTP/2 Server insufficient resource pool (GHSA-wgmr-mf83-7x4j / Nessus ID 241484)
CVE-2023-36478 | Eclipse Jetty up to 9.4.52/10.0.15/11.0.15 MetaDataBuilder.java MetaDataBuilder.checkSize integer underflow (GHSA-wgh7-54f2-x98r / Nessus ID 241484)
CVE-2023-36478 | Oracle Communications Cloud Native Core Network Exposure Function Platform denial of service (Nessus ID 241484)
CVE-2025-53367 | DjvuNet DjVuLibre up to 3.5.28 MMRDecoder::scanruns out-of-bounds write (GHSL-2025-055 / EUVD-2025-19908)
Cybersecurity jobs available right now: July 8, 2025
Analyst III-Threat Intel Verizon Data Services | India | Hybrid – View job details As an Analyst III-Threat Intel, you will deploy security tools, analyze logs and endpoints, and assess threats across Verizon’s enterprise and cloud environments. You’ll also help develop automated security controls and drive threat remediation to ensure compliance with regulatory and industry standards. CISO Cherokee Federal | USA | On-site – View job details As a CISO, you will direct and approve … More →
The post Cybersecurity jobs available right now: July 8, 2025 appeared first on Help Net Security.
Why SEC, SolarWinds Agreed to Settle Cyberfraud Lawsuit
The SEC and SolarWinds told a federal judge they've reached a tentative agreement to resolve a first-of-its-kind fraud case over cybersecurity disclosures. Federal regulators alleged that SolarWinds misled investors about its cybersecurity, and the settlement hinges on SEC commissioner approval.