#appsec

84 posts · Last used 5d

Back to Timeline
0xBughunter @bugxhunter@infosec.exchange · 5d ago
🎣 4 million fake applications and one blind spot: A SOC playbook for OAuth clie... 📝 Key takeaways OAuth client ID sp... https://www.csoonline.com/article/4206750/4-million-fake-applications-and-one-blind-spot-a-soc-playbook-for-oauth-client-id-spoofing.html 📰 CSO Online #AppSec #Malware
0
0
0
thecybersecguru @thecybersecguru@infosec.exchange · 5d ago
What Happened to HackerOne? HackerOne has changed significantly from the bug bounty platform many researchers knew in the late 2010s. Its current direction is increasingly centered around Hai, AI-assisted triage, vulnerability validation, agentic testing, continuous testing and CTEM. But the question isn't simply whether HackerOne uses AI. It's how researcher submissions, security intelligence and AI-driven workflows fit together, and what that means for the role and value of human vulnerability researchers. I dug into HackerOne's history, funding, Live Hacking Events, pricing shift, AI architecture, researcher-data controversy and current product strategy. https://thecybersecguru.com/analysis/what-happened-to-hackerone/ #HackerOne #BugBounty #InfoSec #CyberSecurity #AppSec #VulnerabilityResearch #AISecurity #CybersecurityResearch #EthicalHacking #Pentesting #AgenticAI #CTEM #SecurityResearch #BugBountyHunters #ApplicationSecurity
2
1
0
Rubén Santos García @rsgbengi@infosec.exchange · 6d ago
XS-Leaks steal data the same-origin policy swears it protects. SOP hides response contents, not response behavior. This issue covers error-event oracles, frame counting via window.length, the single global socket pool that turns any browser into a stopwatch, and cache probing (terjanq leaked private Google emails this way). Blind injection, cross-origin, against a site you cannot read. https://www.kayssel.com/newsletter/issue-62/ #InfoSec #CyberSecurity #WebSecurity #BugBounty #AppSec #XSLeaks
0
0
0
dilshad @dilshad@infosec.exchange · Aug 07, 2026
NPM account takeovers via expired maintainer domains You don't need to exploit npm to poison it. Buy the expired email domain behind a maintainer's account, reset the password, and the package is yours. We scanned 2.1 million packages, extracted 6.7 million maintainer emails, and found 675 expired domains leaving 2,843 packages open to takeover. Those packages sit under 257,000+ dependent repos and 93,000 downstream packages. One lapsed domain renewal, a supply chain full of blast radius. https://laburity.com/research-npm-account-takeovers/ #SupplyChainSecurity #npm #AccountTakeover #AppSec #Laburity
0
0
0
0xBughunter @bugxhunter@infosec.exchange · Aug 05, 2026
🤖 AI researchers let models off the leash – then watched as th... 📝 The UK’s AI Sec... https://www.theregister.com/ai-and-ml/2026/08/05/ai-researchers-let-models-off-the-leash-then-watched-as-they-tried-to-add-malware-to-a-foss-project/5283165 📰 www.theregister.com - Articles #AI #AppSec
0
0
0
OWASP Boston @owaspboston@infosec.exchange · Aug 04, 2026
RSVP to our next meetup at https://www.meetup.com/owaspboston/events/315832105/ Thank you to Semgrep for sponsoring this meetup! We have Mardiros Merdinian talking on how AI Ethics is a #security problem #appsec
0
0
0
0xBughunter @bugxhunter@infosec.exchange · Aug 04, 2026
🤖 From Input to Impact: Secure AI Where It Runs 📝 AI agents have made their way into virtually every layer of your environment. They run in the apps your emplo... https://www.sentinelone.com/blog/from-input-to-impact-secure-ai-where-it-runs/ 📰 Cybersecurity Blog | SentinelOne #AI #AppSec
0
0
0
0xBughunter @bugxhunter@infosec.exchange · Aug 04, 2026
🤖 Some Claude Chats Are Searchable on Google 📝 And it’s personal information (alternate link ): The exposed data includes an AI-powered therapy app t... https://www.schneier.com/blog/archives/2026/08/some-claude-chats-are-searchable-on-google.html 📰 Schneier on Security #AI #AppSec
0
0
0
RelayShieldAdmin @relayshieldadmin@infosec.exchange · Aug 03, 2026
We searched public GitHub for AWS keys leaked against a domain. 4,240 hits. The top five results: a docs table, a literal AKIA.... placeholder, a redaction tool's own README, a link list, and a domain allowlist. Five out of five. Not one contained a credential. Any scanner that treats a search hit as a finding calls all five a CRITICAL exposure. Free local scanner, MIT: #infosec #devsecops #appsec #opensource
0
0
0
OffSequence @offseq@infosec.exchange · Aug 03, 2026
Tenable's 30-day Claude Mythos Preview AI integration proves CRITICAL RCE & DoS exploits in internal code. No CVE; this is a novel testing approach, not a public vuln. Requires senior security expertise & orchestration harnesses. https://radar.offseq.com/threat/30-days-with-claude-mythos-preview-how-tenable-adapted-our-security-program-and-why-yours-is-next-8b547c9780f46717 #OffSeq #AIsecurity #AppSec #BlueTeam
0
0
0
0xBughunter @bugxhunter@infosec.exchange · Aug 03, 2026
🛡️ Stop depending on heroics and start operationalizing third-party risk 📝 In cybersecurity, third-party risk management normally looks si... https://www.csoonline.com/article/4204027/stop-depending-on-heroics-and-start-operationalizing-third-party-risk.html 📰 CSO Online #AppSec #InfoSec
0
0
0
OffSequence @offseq@infosec.exchange · Aug 02, 2026
FreeRDP <3.29.0 has a CRITICAL buffer over-disclosure (CVE-2026-67292). Malicious WebSocket peers can leak memory or crash clients via crafted Ping frames. No patch confirmed — avoid unknown gateways. Details: https://radar.offseq.com/threat/freerdp-before-3290-contains-a-buffer-over-disclosure-vulnerability-in-the-gateway-websocket-transport-67044e0124c23808 #OffSeq #FreeRDP #CVE202667292 #AppSec
0
0
0
Open Security Conference @OSCo@infosec.exchange · Jul 31, 2026
The next one in the #peoplebehindosco series is Felix. Hi @Gronner@infosec.exchange 👋 Felix is a software engineer with more than 10 years experience in the automotive and medical industry. Working at XITASO he focuses on building secure and safe systems. Besides that he provides trainings on security, safety, software architecture and Rust. To learn in and with a community he organises the SWEC and is a member of the iSAQB. He loves learning by exploring: building small embedded system or tools, mostly in Rust. In his spare time he enjoys playing pen & paper games, miniature figure painting and playing the drums. His Tags: #AppSec, #Embedded, #Rust, #ThreatModeling Thank you very much for your work as a volunteer and your support in organizing the Open Security conference. Stay tuned and follow the hashtag #peoplebehindosco for more people behind osco.
0
0
0
moltenbit @moltenbit@infosec.exchange · Jul 31, 2026
two advisories i reported against globaleaks went public today. globaleaks is the whistleblowing platform a lot of ngos, newsrooms and public bodies run their leak sites on, so tenant separation is load bearing there. CVE-2026-46648 (moderate): db_toggle_escrow runs three adjacent ORM updates. two of them are missing the User.tid == tid filter, so a non-root tenant admin disabling escrow wipes crypto_escrow_bkp2_key for every user on every tenant, while those tenants keep escrow nominally enabled. fixed in 5.0.94. CVE-2026-46647 (low): /api/admin/network checked for internal user, not for admin, so any internal role on the root tenant could read and write network config. fixed in 5.0.93. https://github.com/globaleaks/globaleaks-whistleblowing-software/security/advisories/GHSA-w88m-4vmc-pq9g and https://github.com/globaleaks/globaleaks-whistleblowing-software/security/advisories/GHSA-m5xx-3qv7-37hj #GlobaLeaks #InfoSec #AppSec #Whistleblowing #Cybersecurity #security
0
0
0
0xBughunter @bugxhunter@infosec.exchange · Jul 31, 2026
🐛 Microsoft confirms an AI worm is propagating through Copilot and other MS apps 📝 A prominent Norwegian AI researcher on Tue... https://www.csoonline.com/article/4203630/microsoft-confirms-an-ai-worm-is-propagating-through-copilot-and-other-ms-apps.html 📰 CSO Online #Malware #AI #AppSec
0
0
0
Hans-Martin Münch @h0ng10@infosec.exchange · Jul 30, 2026
So @irsdl@infosec.exchange released a new version of YSoNet (a forge of ysoserial.net), with some cool new features / gadgets: ▸ DataTable + DataTableTypeSpoof Same-graph DataTable root carrier for RCE. No nested BinaryFormatter or extra binder boundary. TypeSpoof emits a real DataTable subclass, so blocking only the exact DataTable wire name may not prevent reconstruction. ▸ TypeConfuseDelegateFileOperations Five delegate-confusion variants for writing, copying, moving and truncating files. No child process, compiler or WPF required. ▸ AssemblyInstallerLoad Loads a specified DLL from a local or UNC path and instantiates [RunInstaller(true)] installer types. Supported by nine serializers. ▸ DynamicUpdateMapExtension Passes x:XData to NetDataContractSerializer without a binder, allowing a XAML-only sink to carry an NDCS gadget. 🔧 NOTABLE UPDATES ▸ TypeConfuseDelegate now supports SortedDictionary and TreeSet roots, useful for testing blocklists that match only the exact SortedSet wire name. ▸ WindowsIdentity and WindowsClaimsIdentity can carry the inner BinaryFormatter graph through actor, bootstrapContext, claims or WIF’s _actor sink. Variant numbering is now aligned across both gadgets and all serializers. 🔗 https://github.com/irsdl/ysonet http://ysonet.com | http://ysonet.net #AppSec #YSoNet
1
0
1
Doyensec @doyensec@infosec.exchange · Jul 30, 2026
"You don't need pentesters anymore." - Every hype cycle, ever. While the AI debate continues in Vegas, we'll be busy finding the bugs it missed and proving which "findings" were never vulnerabilities in the first place. Happy Black Hat & DEF CON! #BlackHat #DEFCON #AppSec #AI #CyberSecurity #HackerSummerCamp #doyensec #security
0
0
0
0xBughunter @bugxhunter@infosec.exchange · Jul 30, 2026
🏛️ AI agents gain access to financial workflows amid growing governance gaps 📝 AI agents are now being allowed to create business records, ... https://www.csoonline.com/article/4203384/ai-agents-gain-access-to-financial-workflows-amid-growing-governance-gaps.html 📰 CSO Online #AI #AppSec
0
0
0
0xBughunter @bugxhunter@infosec.exchange · Jul 30, 2026
🤖 Headteacher had the most guessable username-password combo you could imagine 📝 PWNED Welcome, once again,... https://www.theregister.com/security/2026/07/30/headteacher-had-the-most-guessable-username-password-combo-you-could-imagine/5280709 📰 www.theregister.com - Articles #AI #AppSec
0
0
0