Seclog - #28
seclinks #
A smorgasbord of a bug chain: postMessage, JSONP, WAF bypass, DOM-based XSS, CORS, CSRF
1749129 - Side-channel attack can deanonymize users (potential risk to journalists and activists)
Report #1923672 - Account takeover due to insufficient URL validation on RelayState parameter
Report #1946534 - Open redirect due to scanning QR code via brave browser
acme.sh runs arbitrary commands from a remote server · Issue #4659 · acmesh-official/acme.sh
Analyzing Broken User Authentication Threats to JSON Web Tokens
secvideo #
BSidesSF 2023 - You don’t have to patch! (Pedro Fortuna, Jasvir Nagra)
secgit #
secmisc #
Enjoyed this post? Subscribe to Seclog for more in-depth security analysis and updates.
For any suggestions or feedback, please contact us at: [email protected]Subscribe to Seclog
Enjoyed this post? Subscribe for more in-depth security analysis and updates direct to your inbox.
No spam. Only high-security insights. Unsubscribe at any time.