Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Researchers from Nanyang Technological University discovered 84 vulnerabilities in 4G and 5G core networks, affecting open-source implementations like Open5GS, OpenAirInterface, free5GC, SD-Core, and eUPF. These flaws, rooted in implicit trust between core network functions, enable denial-of-service (DoS) attacks and session hijacking, allowing attackers to take over user sessions. The vulnerabilities stem from weaknesses in GTP-C and PFCP protocols, where components fail to validate message formats or resource availability.
An academic study from Nanyang Technological University has disclosed 84 security vulnerabilities in 4G and 5G core networks. These flaws could be exploited to launch denial-of-service attacks or hijack user network sessions, posing a significant risk to mobile communications.
An academic study revealed a widespread class of vulnerabilities in 4G and 5G core networks, caused by implicit trust between network functions. These flaws could be exploited for denial-of-service attacks and session hijacking.
Device code phishing, abusing OAuth 2.0 device authorization grant, has become the fastest-growing threat in 2026. It bypasses multi-factor authentication by targeting the authorization step after the victim is already logged in.
Device code phishing, which exploits the OAuth 2.0 device authorization grant to steal access tokens, has rapidly escalated from a niche technique to a widespread threat in 2026. Originally designed for input-constrained devices like smart TVs, this method is now abused in applications like CLI logins.
Device code phishing, which exploits the OAuth 2.0 device authorization grant to steal access tokens, has rapidly become a major threat in 2026. Originally used in red-team exercises, it now operates at scale, targeting devices like smart TVs and printers with constrained input capabilities.