Ο χρήσης Adrestia R&D το αναδημοσίευσε
Intruder's security team has been digging into broken authentication issues in APIs - and research shows they’re far more common than you’d think… To understand how widespread these bugs are, the team built tooling to detect them at scale - which led to the discovery of CVE-2025-0589 in Octopus Deploy, a vulnerability that exposes sensitive Active Directory data like names, emails, and usernames. Some of the vulnerabilities found had existed for years, even in apps listed on public bug bounty programs. These bugs are easy to exploit but hard to spot in a code review, meaning there’s likely plenty more out there. ✅ Get the full details here ->> https://lnkd.in/eGaP9ib4