Cloudflare OAuth now supports optional scopes, giving users more control over what an app can access and helping developers build secure consent flows around the task at hand.

A significant enhancement to the OAuth consent process, moving from an "all-or-nothing" model to a more granular, task-based approach, has been introduced. This update aims to provide users with finer control over the permissions granted to third-party applications, addressing long-standing security and privacy concerns associated with broad consent requests.
Previously, when a user authorized an application via OAuth, they were often presented with a single, comprehensive request for all necessary permissions. This meant that even if an application only needed to perform a specific task, it would typically request access to a wider range of data or functionalities than strictly necessary. Users had little choice but to accept all permissions or deny the application entirely.
The new task-based consent mechanism allows applications to request specific permissions for individual tasks. For example, instead of an application asking for "full access to your calendar," it might now request "permission to create new events" or "permission to view event details," depending on the exact functionality required. This provides a clearer understanding of what data or actions an application intends to perform.
This shift is designed to mitigate risks associated with over-privileged applications. By limiting an application's access to only what is essential for its intended function, the potential impact of a compromised application or a malicious developer is reduced. Should an application be exploited, the attacker's access would be confined to the specific, task-based permissions granted, rather than a broad sweep of user data.
The change also empowers users with more informed decision-making. They can now review and approve or deny individual permissions, rather than being forced into an all-or-nothing choice. This increased transparency is expected to foster greater trust in third-party integrations and improve overall user privacy.
Developers are encouraged to update their applications to leverage this new consent model, ensuring they request only the minimum necessary permissions for each task. This best practice aligns with the principle of least privilege, a fundamental concept in cybersecurity. The implementation of this feature is a direct response to feedback from the developer community and user advocates who have long sought more refined control over OAuth permissions.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early