Source
PortSwigger
DOM XSS vulnerability in Gartner Peer Insights widget patched
Web attack vector closed after failed fix
Toyota sealed up a backdoor to its global supplier management network
Hacker praises carmaker’s prompt response to the (mercifully) good-faith pwnage
Google engineers plot to mitigate prototype pollution
Plan to create boundary between JavaScript objects and their blueprints gathers momentum
Serious security hole plugged in infosec tool binwalk
Path traversals could ‘void reverse engineering efforts and tamper with evidence collected’
Truffle Security relaunches XSS Hunter tool with new features
Popular hacking aid resurrected following end-of-life announcement
Researcher drops Lexmark RCE zero-day rather than sell vuln ‘for peanuts’
Printer exploit chain could be weaponized to fully compromise more than 100 models
Bug Bounty Radar // The latest bug bounty programs for February 2023
New web targets for the discerning hacker
Deserialized web security roundup: ‘Catastrophic cyber events’, another T-Mobile breach, more LastPass problems
Your fortnightly rundown of AppSec vulnerabilities, new hacking techniques, and other cybersecurity news
Facebook two-factor authentication bypass issue patched
Security vulnerability was one of Meta’s top bugs of 2022
Ruby on Rails apps vulnerable to data theft through Ransack search
Several applications were vulnerable to brute-force attacks; hundreds more could be at risk