<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>InfoQ - Security - News</title>
    <link>https://www.infoq.com</link>
    <description>InfoQ Security News feed</description>
    <item>
      <title>Cloudflare Adds Optional OAuth Scopes, Letting Developers Mark What Users May Decline</title>
      <link>https://www.infoq.com/news/2026/09/cloudflare-optional-oauth-scopes/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Security-news</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/09/cloudflare-optional-oauth-scopes/en/headerimage/generatedHeaderImage-1787915759251.jpg"/&gt;&lt;p&gt;Cloudflare has added optional OAuth scopes, letting client owners mark which permissions users may deselect at consent. The company names MCP servers as the motivating case, since agents request the union of everything they might do. Partial consent exists elsewhere, but developer control over which scopes are droppable does not.&lt;/p&gt; &lt;i&gt;By Steef-Jan Wiggers&lt;/i&gt;</description>
      <category>Cloud</category>
      <category>Cloudflare</category>
      <category>Access Control</category>
      <category>Security</category>
      <category>Architecture</category>
      <category>Agents</category>
      <category>Standardization</category>
      <category>DevOps</category>
      <category>AI, ML &amp; Data Engineering</category>
      <category>Architecture &amp; Design</category>
      <category>Development</category>
      <category>news</category>
      <pubDate>Wed, 02 Sep 2026 09:07:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/09/cloudflare-optional-oauth-scopes/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Security-news</guid>
      <dc:creator>Steef-Jan Wiggers</dc:creator>
      <dc:date>2026-09-02T09:07:00Z</dc:date>
      <dc:identifier>/news/2026/09/cloudflare-optional-oauth-scopes/en</dc:identifier>
    </item>
    <item>
      <title>Audio Fingerprinting Discovered on Alibaba Websites While Debugging BLE Multipoint Disconnects</title>
      <link>https://www.infoq.com/news/2026/08/alibaba-audio-fingerprinting/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Security-news</link>
      <description>&lt;img src="https://www.infoq.com/styles/static/images/logo/logo_bigger.jpg"/&gt;&lt;p&gt;A recent discovery revealed that AliExpress employs silent audio streams for device fingerprinting, leveraging the Web Audio API. This technique involves analyzing hardware-specific audio processing to distinguish user devices. Privacy-focused browsers have developed countermeasures, highlighting a security gap in current web standards regarding audio context initialization and user privacy.&lt;/p&gt; &lt;i&gt;By Olimpiu Pop&lt;/i&gt;</description>
      <category>JavaScript</category>
      <category>Web Browser</category>
      <category>Security</category>
      <category>Privacy</category>
      <category>DevOps</category>
      <category>Development</category>
      <category>news</category>
      <pubDate>Fri, 28 Aug 2026 07:07:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/08/alibaba-audio-fingerprinting/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Security-news</guid>
      <dc:creator>Olimpiu Pop</dc:creator>
      <dc:date>2026-08-28T07:07:00Z</dc:date>
      <dc:identifier>/news/2026/08/alibaba-audio-fingerprinting/en</dc:identifier>
    </item>
    <item>
      <title>DRAM Controller Register Manipulation Breaks CPU Memory Isolation</title>
      <link>https://www.infoq.com/news/2026/08/amd-memory-exploit/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Security-news</link>
      <description>&lt;img src="https://www.infoq.com/styles/static/images/logo/logo_bigger.jpg"/&gt;&lt;p&gt;Security researcher Christopher Domas developed skitter-creek-bath-salts, an open-source hardware security tool that disrupts CPU privilege boundaries by manipulating memory controller translation registers. This allows unprivileged software to access protected memory regions, revealing a vulnerability in modern processor architectures that could affect cloud and confidential computing security.&lt;/p&gt; &lt;i&gt;By Olimpiu Pop&lt;/i&gt;</description>
      <category>Security Vulnerabilities</category>
      <category>Memory</category>
      <category>Security</category>
      <category>DevOps</category>
      <category>Development</category>
      <category>news</category>
      <pubDate>Sun, 23 Aug 2026 04:04:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/08/amd-memory-exploit/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Security-news</guid>
      <dc:creator>Olimpiu Pop</dc:creator>
      <dc:date>2026-08-23T04:04:00Z</dc:date>
      <dc:identifier>/news/2026/08/amd-memory-exploit/en</dc:identifier>
    </item>
  </channel>
</rss>
