Elektrine lite

โ† Feed

Cure53๐Ÿ”“

cure53@infosec.exchange

<p>And there is fire where we walk.</p>

Posts

  • Post #3576868

    RE: https://mastodon.social/@gwynnion/116859269846708028 Is this a post about LLMs?

  • Post #3532477

    We built a small project to inject Trusted Types enforcing sanitizer use for all HTML sinks. Without changing any of the insecure code. https://github.com/cure53/DOMFortify Maybe it is useful for someone, especially when having to maintain an older site with too many DOMXSS sinks to fix manually.

  • Post #2065577

    Version 3.4.0 of DOMPurify was released today, addressing a large number of issues reported by LLMs and real people alike. Thanks to all who contributed. https://github.com/cure53/DOMPurify/releases/tag/3.4.0 We hope everything went smoothly and that no one was overlooked in the release notes.

  • Post #2065575

    In anticipation of possibly upcoming waves of OSS bugs as well maybe increasing amounts of real attacks, we have been busy hardening DOMPurify. Look at those shiny badges and improvements, LOOK OMG ๐Ÿ˜ฑ https://github.com/cure53/dompurify?tab=readme-ov-file#dompurify Work in progress of course, but lots got done this week ๐Ÿ’ช๐Ÿป

  • Post #2065573

    To all the OSS projects getting swamped by AI tickets right now... IT IS TOTALLY YOUR OWN FAULT. The easy fix is to write better code. You are welcome, this advice was free. *ducks*

  • Post #2065569

    DOMPurify 3.4.1 is out with lots of small improvements. Among them, a better test suite, a small fuzzer, several fixes and hardenings, and as usually we hope all went well ๐Ÿ˜… https://github.com/cure53/DOMPurify/releases/tag/3.4.1

  • Post #2058673

    We did not expect that back in 2014 ๐Ÿฅน

  • Post #1938484

    We&amp;#39;re already seeing a spike in AI-generated PRs making the ecosystem much more secure. Words cannot describe how grateful we are for all the contributions.

  • Post #980695

    We have slightly updated the publicly available contract templates for NDA, MSA and DPA. File format is ODT as usual. Feel free to, just as before, use them as you see it fit for your own purposes ๐Ÿ˜„ https://github.com/cure53/Contracts

  • Post #980694

    DOMPurify 2.5.9 and DOMPurify 3.3.2 were released today in a rush to fix a security issue caused by jsdom&amp;#39;s faulty tag parsing. A total of four people reported the exacty same bug within a window of three days. One did so via email, thank you. One did so via private security advisory, thank you too. One however simply published a ticket for everyone to see, the other one just dropped a CVE on us without a working fix release. Thanks for nothing. https://github.com/cure53/DOMPurify/r...

  • Post #980693

    https://blog.rice.is/post/doom-over-dns/

  • Post #980692

    ๐Ÿคจ ๐Ÿ˜… https://blog.trailofbits.com/2026/03/31/how-we-made-trail-of-bits-ai-native-so-far/

  • Post #980691

    Here&amp;#39;s everybody&amp;#39;s space heroes having a great time with DJT. https://edition.cnn.com/2026/04/07/science/video/donald-trump-call-artemis-ii-hnk-digvid

  • Post #980690

    We know who Angine de Poitrine really is.

  • Post #888507

    Does anyone have a contact at pwn.ai? We would kinda like to have a conversation with them...

  • Post #761166

    DOMPurify 3.3.0 is out. You can now configure which tags can have which attributes much more easily. https://github.com/cure53/DOMPurify/releases/tag/3.3.0 Thanks again to everyone who contributed to and supported the project. โค๏ธ