Posts of last 24 hours
Meta has addressed a critical vulnerability involving broken access control that exposed sensitive customer support data across multiple services. This issue highlighted systemic weaknesses in authorization within their shared backend infrastructure. The flaw, categorized as an Insecure Direct Object Reference (CWE-639) combined with Broken Access Control (CWE-284) and Missing Authorization (CWE-862), allowed unauthorized users to […]
The post Critical Meta IDOR Flaw Let Attackers Access Customer Support Cases appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Apple has addressed a year-old vulnerability in its “Hide My Email” privacy feature, which could expose users’ real email addresses. This incident has already led to a class action lawsuit and increased scrutiny of Apple’s privacy claims. Hide My Email, part of the paid iCloud+ subscription, allows users to generate random alias addresses that forward […]
The post Apple Fixes Hide My Email Vulnerability That Exposed Users’ Real Email Addresses appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
NULLZEREPTOOL is a newly uncovered attack framework that turns a Telegram bot into a remote control panel for powerful distributed denial of service campaigns backed by rotating proxy infrastructure. The framework came to light when a single Pastebin post was flagged during continuous paste‑site monitoring, exposing the full Python source for a Telegram‑managed DDoS and […]
The post New NULLZEREPTOOL Uses Telegram to Launch 20 DDoS Methods With Rotating Proxies appeared first on Cyber Security News.