Tag: json web token
2 articles

Exploits Target Issabel Framework Flaw for Unauthenticated OS Command Execution
A critical flaw in the Issabel Framework, rated 9.8 out of 10 for severity, allows hackers to execute malicious commands on vulnerable systems without needing login credentials. This vulnerability can be exploited using a hard-coded security key, enabling attackers to forge tokens and gain control.

Cloudflare Workers Exposed to Remote Spectre Attack
Researchers have successfully demonstrated a remote Spectre attack on Cloudflare Workers, exfiltrating a secret JSON Web Token (JWT) at an alarming rate of 12 bits per second - roughly 360 times faster than previously shown. This chilling exploit could have devastating consequences in the wrong hands.