lyra.horse/blog/2025/12...
"CSS hack accidentally becomes regular hack"
lyra.horse/blog/2025/12...
"CSS hack accidentally becomes regular hack"
this bug is actually pretty fun, can't wait to be able to share the details
this bug is actually pretty fun, can't wait to be able to share the details
this one talks about a new web vulnerability class i discovered that allows for complex interactive cross-origin attacks and data exfiltration
and i've already used it to get a google docs bounty ^^
have fun <3
lyra.horse/blog/2025/12...
this one talks about a new web vulnerability class i discovered that allows for complex interactive cross-origin attacks and data exfiltration
and i've already used it to get a google docs bounty ^^
have fun <3
lyra.horse/blog/2025/12...
it's my bsides talk, except with more new svg clickjacking stuff!
it's my bsides talk, except with more new svg clickjacking stuff!
"I’ve discovered a new technique that turns classic clickjacking on its head and enables the creation of complex interactive clickjacking attacks, as well as multiple forms of data exfiltration."
👉 lyra.horse/blog/2025...
"I’ve discovered a new technique that turns classic clickjacking on its head and enables the creation of complex interactive clickjacking attacks, as well as multiple forms of data exfiltration."
👉 lyra.horse/blog/2025...
it'll come out but idk when, hopefully this month though, thank you for the patience <3
it'll come out but idk when, hopefully this month though, thank you for the patience <3
Security Now: Clickjacking "Whac-A-Mole"
Inside the Password Manager Clickjacking Frenzy and What It Means
with Steve Gibson, @leolaporte.me
Security Now: Clickjacking "Whac-A-Mole"
Inside the Password Manager Clickjacking Frenzy and What It Means
with Steve Gibson, @leolaporte.me
Attack: invisible iframe + fake UI = users clicking your app without knowing.
Fix: X-Frame-Options: DENY + CSP frame-ancestors 'none'. Check your framework.
#SoftwareEngineering #BuildInPublic
Attack: invisible iframe + fake UI = users clicking your app without knowing.
Fix: X-Frame-Options: DENY + CSP frame-ancestors 'none'. Check your framework.
#SoftwareEngineering #BuildInPublic
www.bleepingcomputer.com/news/securit...
www.bleepingcomputer.com/news/securit...
Here's a flexible PoC:
jorianwoltjer.com/blog/p/hacki...
Here's a flexible PoC:
jorianwoltjer.com/blog/p/hacki...
Portable, offline, multipiattaforma, copi il DB (criptato) dove ti serve e sei a posto.
Alcune piattaforme hanno già rilasciato il fix e altre lo faranno nei prossimi giorni.
L'elenco è nell'articolo.
@signorina37.ransomnews.online
www.punto-informatico.it/password-man...
Portable, offline, multipiattaforma, copi il DB (criptato) dove ti serve e sei a posto.
Alcune piattaforme hanno già rilasciato il fix e altre lo faranno nei prossimi giorni.
L'elenco è nell'articolo.
@signorina37.ransomnews.online
www.punto-informatico.it/password-man...
What is it?
In clickjacking, the attacker tricks a user into clicking on something different than what the user perceives.
5/18
What is it?
In clickjacking, the attacker tricks a user into clicking on something different than what the user perceives.
5/18
A crafted URL could bypass its emergency access page — exposing credentials.
Researchers also warn its browser extension was at risk of clickjacking: one bad click could leak logins, cards, even 2FA codes. #CyberAlerts
A crafted URL could bypass its emergency access page — exposing credentials.
Researchers also warn its browser extension was at risk of clickjacking: one bad click could leak logins, cards, even 2FA codes. #CyberAlerts
🐧 Linux desktop malware appears
🍏 Apple patches a critical vulnerability
🐳 Docker escape flaw fixed
🎧 buff.ly/OZq5E9F
#CyberSecurity #InfoSec
🐧 Linux desktop malware appears
🍏 Apple patches a critical vulnerability
🐳 Docker escape flaw fixed
🎧 buff.ly/OZq5E9F
#CyberSecurity #InfoSec