Tag

Web Security

All articles tagged with #web security

Cloudflare to Launch Quantum-Safe Web Certificates in 2027
technology10 days ago

Cloudflare to Launch Quantum-Safe Web Certificates in 2027

Cloudflare announced plans to become a public certificate authority (CA) issuing quantum-resistant Merkle Tree Certificates (MTCs) starting in Q1 2027. This move addresses the threat of quantum computers breaking current encryption by using a hybrid system that maintains compatibility with legacy devices. The company is acquiring a trusted root from GlobalSign to ensure broad device support and aims to make the transition transparent and free for all users.

cPanel Patches Critical Root-Access Flaw in CalDAV Service
cybersecurity16 days ago

cPanel Patches Critical Root-Access Flaw in CalDAV Service

cPanel has released urgent patches for three vulnerabilities, the most severe of which allows any hosting account holder to execute code as root and seize full control of the server. The critical flaw, CVE-2026-87899, exists in the CalDAV and CardDAV services and affects cPanel & WHM version 120 and later. A second bug in the WP Toolkit plugin allows users to modify databases belonging to other accounts, while a third issue permits local users to read other accounts' calendar and contact data. The vendor credits researcher Ali Mustafa for identifying all three issues, which were disclosed on September 22. No evidence of active exploitation has been reported yet, but cPanel advises immediate updates to specific fixed versions to mitigate the risks.

Chrome ramps to quantum-proof HTTPS with Merkle-tree certificates
technology7 months ago

Chrome ramps to quantum-proof HTTPS with Merkle-tree certificates

Chrome is testing quantum-resistant HTTPS that uses Merkle-tree proofs, letting browsers verify certificates with tiny proofs instead of large data; a Tree Head signs millions of certs, keeping the data near 64 bytes. The plan for a broader rollout runs through 2027 with a parallel quantum-resistant trust store and mandatory certificate transparency, while traditional certificates remain as a safety net during the transition.

Critical AdonisJS Vulnerability Enables Remote Arbitrary File Write
web-security9 months ago

Critical AdonisJS Vulnerability Enables Remote Arbitrary File Write

A critical security flaw (CVSS 9.2) in the '@adonisjs/bodyparser' npm package allows remote attackers to perform arbitrary file writes on servers through path traversal in multipart file handling, emphasizing the need for immediate updates to affected versions. Additionally, a similar high-severity vulnerability was found in the jsPDF library, which has been patched in version 4.0.0.

Anthropic Launches Claude AI Chrome Extension Amid Browser Security Concerns
technology1 year ago

Anthropic Launches Claude AI Chrome Extension Amid Browser Security Concerns

Anthropic's AI Chrome extension, designed to automate tasks, has significant security vulnerabilities with a 23.6% attack success rate, reduced to 11.2% with safety measures. Experts warn that these risks, including prompt injection and malicious instructions, pose serious security concerns, and current protections are insufficient, placing the burden of security on users.