Cure53๐
cure53@infosec.exchange
<p>And there is fire where we walk.</p>
Posts
-
Post #3576868
RE: https://mastodon.social/@gwynnion/116859269846708028 Is this a post about LLMs?
-
Post #3532477
We built a small project to inject Trusted Types enforcing sanitizer use for all HTML sinks. Without changing any of the insecure code. https://github.com/cure53/DOMFortify Maybe it is useful for someone, especially when having to maintain an older site with too many DOMXSS sinks to fix manually.
-
Post #2065577
Version 3.4.0 of DOMPurify was released today, addressing a large number of issues reported by LLMs and real people alike. Thanks to all who contributed. https://github.com/cure53/DOMPurify/releases/tag/3.4.0 We hope everything went smoothly and that no one was overlooked in the release notes.
-
Post #2065575
In anticipation of possibly upcoming waves of OSS bugs as well maybe increasing amounts of real attacks, we have been busy hardening DOMPurify. Look at those shiny badges and improvements, LOOK OMG ๐ฑ https://github.com/cure53/dompurify?tab=readme-ov-file#dompurify Work in progress of course, but lots got done this week ๐ช๐ป
-
Post #2065573
To all the OSS projects getting swamped by AI tickets right now... IT IS TOTALLY YOUR OWN FAULT. The easy fix is to write better code. You are welcome, this advice was free. *ducks*
-
Post #2065569
DOMPurify 3.4.1 is out with lots of small improvements. Among them, a better test suite, a small fuzzer, several fixes and hardenings, and as usually we hope all went well ๐ https://github.com/cure53/DOMPurify/releases/tag/3.4.1
-
Post #2058673
We did not expect that back in 2014 ๐ฅน
-
Post #1938484
We&#39;re already seeing a spike in AI-generated PRs making the ecosystem much more secure. Words cannot describe how grateful we are for all the contributions.
-
Post #980695
We have slightly updated the publicly available contract templates for NDA, MSA and DPA. File format is ODT as usual. Feel free to, just as before, use them as you see it fit for your own purposes ๐ https://github.com/cure53/Contracts
-
Post #980694
DOMPurify 2.5.9 and DOMPurify 3.3.2 were released today in a rush to fix a security issue caused by jsdom&#39;s faulty tag parsing. A total of four people reported the exacty same bug within a window of three days. One did so via email, thank you. One did so via private security advisory, thank you too. One however simply published a ticket for everyone to see, the other one just dropped a CVE on us without a working fix release. Thanks for nothing. https://github.com/cure53/DOMPurify/r...
-
Post #980693
https://blog.rice.is/post/doom-over-dns/
-
Post #980692
๐คจ ๐ https://blog.trailofbits.com/2026/03/31/how-we-made-trail-of-bits-ai-native-so-far/
-
Post #980691
Here&#39;s everybody&#39;s space heroes having a great time with DJT. https://edition.cnn.com/2026/04/07/science/video/donald-trump-call-artemis-ii-hnk-digvid
-
Post #980690
We know who Angine de Poitrine really is.
-
Post #888507
Does anyone have a contact at pwn.ai? We would kinda like to have a conversation with them...
-
Post #761166
DOMPurify 3.3.0 is out. You can now configure which tags can have which attributes much more easily. https://github.com/cure53/DOMPurify/releases/tag/3.3.0 Thanks again to everyone who contributed to and supported the project. โค๏ธ