Source
PortSwigger
Gatsby patches SSRF, XSS bugs in Cloud Image CDN
Remediation compared to ‘changing the tires on a car while in motion’
Malicious proof-of-concepts are exposing GitHub users to malware and more
New research suggests thousands of PoCs could be dangerous
Urlscan.io API unwittingly leaks sensitive URLs, data
Public listings have made sensitive data searchable due to misconfigured third-party services
OpenSSL vulnerability downgraded to ‘high’ severity
Punycode-related flaw fails the logo test
Bug Bounty Radar // The latest bug bounty programs for November 2022
New web targets for the discerning hacker
SQLite patches 22-year-old code execution, denial of service vulnerability
Dormant 32 bit-era coding flaw causes problems for 64-bit systems
Upcoming ‘critical’ OpenSSL update prompts feverish speculation
Is the new Heartbleed or just a bleeding distraction?
VMWare patches RCE exploit in NSX Manager
Bug fixed despite product reaching end of life
GitHub patches bug that could allow access to another user’s repo
Renaming accounts opened the door to hijacking
Jira Align flaws enabled malicious users to gain super admin privileges – and potentially worse
Lateral or upwards movement beyond the instance was theoretically possible, concludes researcher