Welcome to our

Cyber Security News Aggregator

.

Cyber Tzar

provide a

cyber security risk management

platform; including automated penetration tests and risk assesments culminating in a "cyber risk score" out of 1,000, just like a credit score.

Better-Auth Critical Account Takeover via Unauthenticated API Key Creation (CVE-2025-61928)

published on 2025-10-20 19:44:06 UTC by /u/Prior-Penalty
Content:

A complete account takeover found with AI for any application using better-auth with API keys enabled, and with 300k weekly downloads, it probably affects a large number of projects. Some of the folks using it can be found here: https://github.com/better-auth/better-auth/discussions/2581.

submitted by /u/Prior-Penalty
[link] [comments]
Article: Better-Auth Critical Account Takeover via Unauthenticated API Key Creation (CVE-2025-61928) - published 1 day ago.

https://www.reddit.com/r/netsec/comments/1obrlhi/betterauth_critical_account_takeover_via/   
Published: 2025 10 20 19:44:06
Received: 2025 10 20 20:00:21
Feed: /r/netsec - Information Security News and Discussion
Source: /r/netsec - Information Security News and Discussion
Category: Cyber Security
Topic: Cyber Security
Views: 6

Custom HTML Block

Click to Open Code Editor