This month’s #BugBountyRadar: Fresh targets from Grindr and Miro, infosec drama with XSS Hunter’s new host, and Belgium rolls out the red carpet for ethical hackers
https://t.co/9zOiONeuGu
Attackers could have created counterfeit driving licenses by exploiting a vulnerability – now patched – in the website of India’s road transport ministry (credit @_RobinJustin_)
https://t.co/VVTsg9KXxL
Password managers part II: The Daily Swig looks at enterprise-grade tech capable of managing login credentials, encryption keys, API tokens and more
https://t.co/tp0ZpIZoYd
‘Standard web app security tests result in false negatives for web APIs’ – @hAPI_hacker on the need for bespoke defenses against increasingly popular attacks https://t.co/QjA3lu6E9u
The US National Institute of Standards and Technology is planning a major reform of its Cybersecurity Framework, an authoritative guideline on managing cybersecurity risk
https://t.co/BgRfbgCBZf
Weaknesses in the CVSS system have been highlighted through new research, with existing metrics blamed for 'overhyping' vulnerabilities
https://t.co/T2xhsXTAUe
API security expert Corey J Ball (@hAPI_hacker) on how to ‘arm the testers, and help prevent that next API-related data breach’
https://t.co/QjA3lu66jW
Part one of our two-part series looks at the security pros and cons of consumer-focused password managers and what they can offer users
https://t.co/slK2RX5gZp