Critical Golang XML parser bugs can cause SAML authentication bypass
This week, Mattermost, in coordination with Golang has disclosed 3 critical vulnerabilities within Go language’s XML parser. If exploited, these vulnerabilities, also impacting multiple Go-based SAML implementations, can lead to a complete bypass of SAML authentication which powers prominent web applications today. […]
Microsoft removes update block for Windows 10 NVMe SSD devices
Microsoft has removed a safeguard hold blocking Windows 10 updates on systems affected by a known issue causing blue screen of death (BSOD) crashes when users plugged in a Thunderbolt NVMe (Non-Volatile Memory Express) Solid State Drive (SSD). […]
US govt, FireEye breached after SolarWinds supply-chain attack
Trojanized versions of SolarWinds’ Orion IT monitoring and management software have been used in a supply chain attack leading to the breach of government and high-profile companies after attackers deployed a backdoor dubbed SUNBURST or Solorigate. […]