An attacker sends a single web request to a Bonita server and lands inside an internal API that assumed nobody could reach it. The request arrives unauthenticated. From there the attacker runs code on the host. Bonita BPM handles loan approvals, insurance claims, and employee onboarding for banks, insurers, and government agencies, and its internal surface answers to strangers. Vulnerability researchers at Novee, found the path. They presented it today at Black Hat USA 2026 … More →
The post Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers appeared first on Help Net Security.

The True Cost of Focusing on Cost Instead of Cost-Effectiveness
When payors consider only the cost of the medication and not the cost and risk to the patient, doctor, and healthcare system, the irony is


