Weekly curated security news, tweets, videos, and GitHub projects.
Cloudflare incident ,Legba, secure HAR sharing, Semgrep's New Rule Syntax, GPT-4 Vision Prompt Injection, Data-bouncing, Drone Warfare, CVSS 4.0 etc.
Spotlight: CVE-2023-20198, Attacking AWS Cognito, RCE in Chrome, SSRF to RCE on Mastodon, Security Vuln in CasaOS, Russian Jabber Hijack etc...
Spotlight: KeepnetLabs's Partnership with Pentesters, HTTP/2 ‘Rapid Reset’ DDoS attack, CURL (CVE-2023-38545), PyPI Malware Campaign, ZAP 2.14.0, etc.
Spotlight: IKEA Effect, Severity HIGH security problem of curl, Security is about data, DevSecOps with AI, GPU.zip ,CVE-2023-22515, etc.
Spotlight: Account Takeover of Internal Tesla Accounts, RCE in Chrome, I hacked macOS, security testing for WebSocket, SecDevOps or DevSecOps?, etc.
Spotlight: The bogus CVE problem, DevTunnels for C2, Finding things in JavaScript, web.Monitor, WS_RaceCondition_PoC, Linux Kernel a Process etc.
Spotlight: New Apple spyware, Zero-day Vulnerability Database, Docker for Pentest, Hacking GTA, URL parsers disagree, etc.
Spotlight: Hacking the Police, Bitlocker bypass on Lenovo, NCC's R1CS Implementation Review, Google Extensions etc.
OWASP Top 10 for Large Language Model Applications, Customer takeover in Shopify, Open Cybersecurity Schema Framework, Blocked by Cloudflare etc.