New breach: Indian marketplace Elanic had 2.3M email addresses breached & posted to a hacking forum. Elanic verified the data but advised they will "not have as such any communication and public disclosure" to customers. 56% were already in @haveibeenpwnedhaveibeenpwned.com/
API vulnerability at @Uber found by @sehacure and Manisha Sangwan from @AppSecure: an API endpoint didn't have response sanitization and was leaking Client Secrets and Server Tokens of all Uber apps: medium.com/@appsecure/leakag…
Another exploit is a good reminder for #API owners: make sure vulnerable data like server tokens and client secrets are not returned in API responses from public endpoints: medium.freecodecamp.org/leak…
via @AppSecure
Meet Anand Prakash, one of India's best known 'white hat hackers'. The 23-year-old is, essentially, a one-man tech security help desk for some of the most powerful software companies in the world. Read more: bit.ly/2GX9RS4 |@sehacure