Small change to HTML with massive impact on eliminating mXSS attacks
https://github.com/whatwg/html/commit/e21bd3b4a94bfdbc23d863128e0b207be9821a0f
...and now the video of my talk "Finding and Exploiting 20-year-old bugs in Web Browsers" is live too https://www.youtube.com/watch?v=U1kc7fcF5Ao
π¨ New advisory was just published! π¨
Multiple vulnerabilities were discovered in Foscam X5. These vulnerabilities allow a remote attacker to trigger code execution vulnerabilities in the product: https://ssd-disclosure.com/ssd-advisory-multiple-foscam-x5-vulnerabilities/
We found a vulnerability in AMD CPUs that lets us load arbitrary microcode!
The recording of our OffensiveCon presentation is live at https://youtu.be/sUFDKTaCQEk
Slides at http://entrysign.top
Discovery: The "copilot" bot user that Microsoft will soon be flooding your github repos with garbage content from is implemented in some sort of special way that exempts it from the "block" feature you would normally be able to block other users/bots with
Microsoft takes Windows Subsystem for Linux open source after nearly a decade
WSL has also recently added official support for both Fedora and Arch distros.
https://arstechnica.com/gadgets/2025/05/microsoft-takes-windows-subsystem-for-linux-open-source-after-nearly-a-decade/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social
"Go Cryptography Security Audit" by Roland Shoemaker β https://go.dev/blog/tob-crypto-audit
I have been following the INFOSEC industry and am ready to begin my startup. Any investors here interested? Here's my business plan.
DOMPurify 3.2.6 has been released with several smaller fixes and improvements, thanks to all who contributed π
https://github.com/cure53/DOMPurify/releases/tag/3.2.6
Hopefully this will also help with the CI/CD issues that arose after the fake CVE was posted last week.