Esbuild XSS Bug That Survived 5B Downloads and Bypassed HTML Sanitization
https://ift.tt/OWvEufj
Submitted November 21, 2025 at 05:33AM by va_start
via reddit https://ift.tt/oHN6lKS
https://ift.tt/OWvEufj
Submitted November 21, 2025 at 05:33AM by va_start
via reddit https://ift.tt/oHN6lKS
Depthfirst
depthfirst | Esbuild's XSS Bug that Survived 5 Billion Downloads and Bypassed HTML Sanitization
In 2022, a subtle XSS bug slipped into esbuild, one of the most widely used JavaScript bundlers on the planet. Despite billions of downloads, it remained unnoticed, hiding inside a function that appeared to safely escape HTML. But a missing quote escape created…
Smooth upgrading of OWASP CRS3 to CRS4
https://ift.tt/QFVecNJ
Submitted November 21, 2025 at 02:42PM by dune73
via reddit https://ift.tt/j4CBYZP
https://ift.tt/QFVecNJ
Submitted November 21, 2025 at 02:42PM by dune73
via reddit https://ift.tt/j4CBYZP
Sliver C2 vulnerability enables attack on C2 operators through insecure Wireguard network
https://ift.tt/P8vc0nu
Submitted November 21, 2025 at 06:49PM by catmandx
via reddit https://ift.tt/A0B28kO
https://ift.tt/P8vc0nu
Submitted November 21, 2025 at 06:49PM by catmandx
via reddit https://ift.tt/A0B28kO
Hoang Nguyen
Sliver C2 Insecure Default Network Policy (CVE-2025-27093)
Summary Sliver is a powerful command and control (C2) framework designed to provide advanced capabilities for covertly managing and controlling remote systems.
Hitchhiker's Guide to Attack Surface Management
https://ift.tt/spULjDE
Submitted November 23, 2025 at 08:42AM by alt69785
via reddit https://ift.tt/WzY3aVP
https://ift.tt/spULjDE
Submitted November 23, 2025 at 08:42AM by alt69785
via reddit https://ift.tt/WzY3aVP
devansh
Hitchhiker's Guide to Attack Surface Management
I first heard about the word "ASM" (i.e., Attack Surface Management) probably in late 2018, and I thought it must be some complex infrastructure for tr...
[Tool] Native JSONL viewer for analyzing massive security logs (Suricata, Zeek, EDR) without infrastructure overhead
https://ift.tt/4HBpJnQ
Submitted November 23, 2025 at 12:17PM by hilti
via reddit https://ift.tt/8gqnZXJ
https://ift.tt/4HBpJnQ
Submitted November 23, 2025 at 12:17PM by hilti
via reddit https://ift.tt/8gqnZXJ
iotdata.systems
JSONL Viewer Pro - Fast Desktop Viewer for Security Logs & Large JSONL Files
The fastest way to explore and analyze JSONL files on your desktop. Perfect for security analysts, SOC teams, and DevOps engineers.
NocturneNotes — Secure Rust + GTK4 note‑taking with AES‑256‑GCM
http://www.jegly.xyz
Submitted November 23, 2025 at 04:34PM by reallylonguserthing
via reddit https://ift.tt/wP7HaWF
http://www.jegly.xyz
Submitted November 23, 2025 at 04:34PM by reallylonguserthing
via reddit https://ift.tt/wP7HaWF
Reddit
[ Removed by moderator ] : r/netsec
541K subscribers in the netsec community. /r/netsec is a community-curated aggregator of technical information security content. Our mission is to extract signal from the noise — to provide value to security practitioners, students, researchers, and hackers…
I Analysed Over 3 Million Exposed Databases Using Netlas
https://ift.tt/xj3bqds
Submitted November 23, 2025 at 03:49PM by AnyThing5129
via reddit https://ift.tt/kURwalQ
https://ift.tt/xj3bqds
Submitted November 23, 2025 at 03:49PM by AnyThing5129
via reddit https://ift.tt/kURwalQ
netlas.io
I Analysed Over 3 Million Exposed Databases Using Netlas - Netlas Blog
Analysing 3.2M exposed databases with Netlas to reveal global risks, failed controls, and exposure trends across major DB systems
The First Autonomous AI Cyberattack: Why SaaS Security Must Change
https://ift.tt/8Tzmni5
Submitted November 23, 2025 at 07:07PM by arshidwahga
via reddit https://ift.tt/rcIGqe4
https://ift.tt/8Tzmni5
Submitted November 23, 2025 at 07:07PM by arshidwahga
via reddit https://ift.tt/rcIGqe4
Good and well-renowned Universities Worldwide for Master’s in Infosec (Preferably Europe - Public Universities; Open to Other countries/continents)
http://test.com
Submitted November 24, 2025 at 06:42AM by bhavsec381
via reddit https://ift.tt/zPT0iCZ
http://test.com
Submitted November 24, 2025 at 06:42AM by bhavsec381
via reddit https://ift.tt/zPT0iCZ
A Reverse Engineer’s Anatomy of the macOS Boot Chain & Security Architecture
https://stack.int.mov/a-reverse-engineers-anatomy-of-the-macos-boot-chain-security-architecture/
Submitted November 24, 2025 at 07:31AM by alt69785
via reddit https://ift.tt/PghwnqV
https://stack.int.mov/a-reverse-engineers-anatomy-of-the-macos-boot-chain-security-architecture/
Submitted November 24, 2025 at 07:31AM by alt69785
via reddit https://ift.tt/PghwnqV
/dev/stack
A Reverse Engineer’s Anatomy of the macOS Boot Chain & Security Architecture
1.0 The Silicon Root of Trust: Pre-Boot & Hardware Primitives
The security of the macOS platform on Apple Silicon is not defined by the kernel; it is defined by the physics of the die. Before the first instruction of kernelcache is fetched, a complex, cryptographic…
The security of the macOS platform on Apple Silicon is not defined by the kernel; it is defined by the physics of the die. Before the first instruction of kernelcache is fetched, a complex, cryptographic…
Shai-Hulud Returns: Over 300 NPM Packages and 21K Github Repos infected via Fake Bun Runtime Within Hours
https://ift.tt/HOiuQSk
Submitted November 24, 2025 at 03:29PM by Fit_Wing3352
via reddit https://ift.tt/P5btZck
https://ift.tt/HOiuQSk
Submitted November 24, 2025 at 03:29PM by Fit_Wing3352
via reddit https://ift.tt/P5btZck
Live Updates: Shai1-Hulud, The Second Coming - Hundreds of NPM Packages Compromised
https://ift.tt/2ebkDUw
Submitted November 24, 2025 at 06:19PM by Most-Anywhere-6651
via reddit https://ift.tt/Xven4a6
https://ift.tt/2ebkDUw
Submitted November 24, 2025 at 06:19PM by Most-Anywhere-6651
via reddit https://ift.tt/Xven4a6
www.koi.ai
Live Updates: Sha1-Hulud, The Second Coming - Hundreds of NPM Packages Compromised || Koi
A new wave of the Shai-Hulud malware is compromising hundreds of npm packages and destroying user home directories. Get live updates and mitigation steps.
A systemic flaw in Binance’s IP Whitelisting model: listenKeys bypass the protection entirely
https://technopathy.club/when-ip-whitelisting-isnt-what-it-seems-a-real-world-case-study-from-the-binance-api-816c4312d6d0
Submitted November 25, 2025 at 01:27AM by oliver-zehentleitner
via reddit https://ift.tt/mMvYC65
https://technopathy.club/when-ip-whitelisting-isnt-what-it-seems-a-real-world-case-study-from-the-binance-api-816c4312d6d0
Submitted November 25, 2025 at 01:27AM by oliver-zehentleitner
via reddit https://ift.tt/mMvYC65
Medium
When IP Whitelisting Isn’t What It Seems: A Real-World Case Study from the Binance API
A case study on how Binance’s listenKey design bypasses IP whitelisting, why Bugcrowd dismissed it, and what this teaches us about API…
The challenge to test my software consists of breaking a meta-cloaker.
https://ift.tt/85jMNpV
Submitted November 25, 2025 at 02:53AM by Any_Gap_3150
via reddit https://ift.tt/Jh0KRk5
https://ift.tt/85jMNpV
Submitted November 25, 2025 at 02:53AM by Any_Gap_3150
via reddit https://ift.tt/Jh0KRk5
Split-Second Side Doors: How Bot-Delegated TOCTOU Breaks The CI/CD Threat Model
https://ift.tt/r0gkaMs
Submitted November 25, 2025 at 04:25AM by alt69785
via reddit https://ift.tt/B7jY2Qh
https://ift.tt/r0gkaMs
Submitted November 25, 2025 at 04:25AM by alt69785
via reddit https://ift.tt/B7jY2Qh
boostsecurity.io
Split-Second Side Doors: How Bot-Delegated TOCTOU Breaks The CI/CD Threat Model
Discover how Bot-Delegated TOCTOU vulnerabilities in GitHub Apps can compromise CI/CD pipelines, with detailed case studies and hardening strategies.
There's a New Way to Scale Digital security Teams: Digital Security Teammates
https://ift.tt/Ld10OuF
Submitted November 25, 2025 at 12:15PM by eren_yeager04
via reddit https://ift.tt/MKPI1jG
https://ift.tt/Ld10OuF
Submitted November 25, 2025 at 12:15PM by eren_yeager04
via reddit https://ift.tt/MKPI1jG
Secure.com
Digital Security Teammates vs. Traditional AI SOC
Unlike black-box AI SOC tools, Digital Security Teammates from Secure.com deliver 70% less manual work with full transparency.
Stop Putting Your Passwords Into Random Websites (Yes, Seriously, You Are The Problem) - watchTowr Labs
https://ift.tt/Na2kwzp
Submitted November 25, 2025 at 04:36PM by dx7r__
via reddit https://ift.tt/dzXA3DV
https://ift.tt/Na2kwzp
Submitted November 25, 2025 at 04:36PM by dx7r__
via reddit https://ift.tt/dzXA3DV
watchTowr Labs
Stop Putting Your Passwords Into Random Websites (Yes, Seriously, You Are The Problem)
Welcome to watchTowr vs the Internet, part 68.
That feeling you’re experiencing? Dread. You should be used to it by now.
As is fast becoming an unofficial and, apparently, frowned upon tradition - we identified incredible amounts of publicly exposed passwords…
That feeling you’re experiencing? Dread. You should be used to it by now.
As is fast becoming an unofficial and, apparently, frowned upon tradition - we identified incredible amounts of publicly exposed passwords…
The security researcher's guide to mathematics
https://ift.tt/hlagM15
Submitted November 25, 2025 at 04:54PM by Rude_Ad3947
via reddit https://ift.tt/7MFs6Da
https://ift.tt/hlagM15
Submitted November 25, 2025 at 04:54PM by Rude_Ad3947
via reddit https://ift.tt/7MFs6Da
Medium
The Security Researcher’s Guide to Mathematics
You can be a successful security researcher without knowing much about math. But if you want to see the matrix, you need to get…
Hide the threat - GPO lateral movement
https://ift.tt/YuevCKp
Submitted November 25, 2025 at 07:02PM by -vzh-
via reddit https://ift.tt/wliPftu
https://ift.tt/YuevCKp
Submitted November 25, 2025 at 07:02PM by -vzh-
via reddit https://ift.tt/wliPftu
INTRINSEC
Hide the threat - GPO lateral movement
Learn how to perform and understand lateral mouvement though GPO mechanism during pentest and red team assessments.
An Evening with Claude (Code) - SpecterOps
https://ift.tt/Wh5XTrq
Submitted November 26, 2025 at 01:52AM by alt69785
via reddit https://ift.tt/t0QCVjw
https://ift.tt/Wh5XTrq
Submitted November 26, 2025 at 01:52AM by alt69785
via reddit https://ift.tt/t0QCVjw
SpecterOps
An Evening with Claude (Code) - SpecterOps
This blog post explores a bug, (CVE-2025-64755), I found while trying to find a command execution primitive within Claude Code to demonstrate the risks of web-hosted MCP to a client.
We made a new tool, QuicDraw(H3), because HTTP/3 race condition testing is currently trash.
https://ift.tt/bHhJzkv
Submitted November 26, 2025 at 01:02PM by ES_CY
via reddit https://ift.tt/2Xl7oBC
https://ift.tt/bHhJzkv
Submitted November 26, 2025 at 01:02PM by ES_CY
via reddit https://ift.tt/2Xl7oBC
Cyberark
Racing and Fuzzing HTTP/3: Open-sourcing QuicDraw(H3)
This blog post provides a dive into HTTP/3’s evolution for security engineers, an overview of our research journey, and what led us to develop the open-source tool QuicDraw, which can be used for...