Seclog - #31 03 Jul 2023 seclinks # Security Alert: Don't npm install https Hackers can steal cryptographic keys by video-recording power LEDs 60 feet away Securing the AI Pipeline Password spraying and MFA bypasses in the modern security landscape Threat Modeling Handbook Azure Attack Paths: Common Findings and Fixes (Part 1) The massive bug at the heart of the npm ecosystem SSO Gadgets II: Unauthenticated Client-Side Template Injection to Account Takeover using SSO Gadget Chain secgit # awslabs/threat-composer smokeme/PDFator mschwager/route-detect ← All Seclogs