⤷ Title: Malicious JS Lifecycle Hooks Found Hiding Inside PHP Composer Packages
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 23 May 2026 04:32:47 +0000
════════════════════════
⌗ Tags: #Malware #CI/CD Poisoning #Cross_Ecosystem Malice #Cyber Security #devdojo/wave #GitHub Actions Backdoor #infosec #package.json Exploit #PHP Composer #Postinstall Script #Socket Security #Starter Kits #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 23 May 2026 04:32:47 +0000
════════════════════════
⌗ Tags: #Malware #CI/CD Poisoning #Cross_Ecosystem Malice #Cyber Security #devdojo/wave #GitHub Actions Backdoor #infosec #package.json Exploit #PHP Composer #Postinstall Script #Socket Security #Starter Kits #supply chain attack
Daily CyberSecurity
Malicious JS Lifecycle Hooks Found Hiding Inside PHP Composer Packages
Socket exposes a clever cross-ecosystem supply chain attack targeting PHP packages by hiding a malicious JS postinstall backdoor inside package.json.
⤷ Title: Important Security Flaw Patched in Apache ECharts Library
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 26 May 2026 01:01:33 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache ECharts #Cross_Site Scripting #CVE_2026_45249 #JavaScript Library #vulnerability patch #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 26 May 2026 01:01:33 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache ECharts #Cross_Site Scripting #CVE_2026_45249 #JavaScript Library #vulnerability patch #XSS
Daily CyberSecurity
Important Security Flaw Patched in Apache ECharts Library
Learn about the Apache ECharts XSS vulnerability (CVE-2026-45249) in the Lines series tooltip rendering logic and find out how to secure your code.
⤷ Title: The Underminr Paradigm: Subverting DNS Filters via CDN Networks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 27 May 2026 04:46:33 +0000
════════════════════════
⌗ Tags: #Information Security #ADAMnetworks threat intelligence #cloud command and control traffic #cross tenant CDN routing exploit #Encrypted Client Hello ECH security #legacy domain fronting comparison #outminr network monitoring tool #Protective DNS bypass #Server Name Indication SNI spoofing #shared infrastructure website blacklisting #Underminr DNS evasion technique
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 27 May 2026 04:46:33 +0000
════════════════════════
⌗ Tags: #Information Security #ADAMnetworks threat intelligence #cloud command and control traffic #cross tenant CDN routing exploit #Encrypted Client Hello ECH security #legacy domain fronting comparison #outminr network monitoring tool #Protective DNS bypass #Server Name Indication SNI spoofing #shared infrastructure website blacklisting #Underminr DNS evasion technique
Information Security News
Underminr DNS Evasion Technique Bypasses Protective DNS
ADAMnetworks uncovers Underminr, a critical DNS evasion technique impacting 88 million domains by weaponizing cross-tenant routing on shared CDNs.
⤷ Title: The Stealth Emergence of FROST: Tracking Users via SSD Latency Side-Channels
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 29 May 2026 03:31:26 +0000
════════════════════════
⌗ Tags: #Data Leak #Apple M2 Mac web tracking #browser sandbox data exfiltration #browser side_channel storage vulnerability #browser storage quota mitigations #cross_browser web tracking mechanics #FROST SSD fingerprinting attack #Hannes Weissteiner DIMVA conference research #hardware cache timing exploitation #OPFS read write latency telemetry #Origin Private File System tracking
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 29 May 2026 03:31:26 +0000
════════════════════════
⌗ Tags: #Data Leak #Apple M2 Mac web tracking #browser sandbox data exfiltration #browser side_channel storage vulnerability #browser storage quota mitigations #cross_browser web tracking mechanics #FROST SSD fingerprinting attack #Hannes Weissteiner DIMVA conference research #hardware cache timing exploitation #OPFS read write latency telemetry #Origin Private File System tracking
Information Security News
FROST SSD Fingerprinting Attack Tracks Users via Storage
Researchers unveil the FROST SSD fingerprinting attack. Learn how malicious JavaScript reads OPFS storage latency to track open tabs and background apps.
⤷ Title: VaultJacking: Exploiting Google Sync Infrastructure via Intercepted PINs
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 29 May 2026 09:41:23 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cross_site authentication data theft #Google Workspace proxy environment hijacking #iCloud Keychain vs Google security architecture #multi_platform synchronized repository dump #PhishU Adversary_in_the_Middle framework #session cookie token theft mitigations #synchronization PIN credential exfiltration #unauthorized trusted device registry #VaultJacking Google password phishing #WebAuthn hardware perimeter bypass
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 29 May 2026 09:41:23 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cross_site authentication data theft #Google Workspace proxy environment hijacking #iCloud Keychain vs Google security architecture #multi_platform synchronized repository dump #PhishU Adversary_in_the_Middle framework #session cookie token theft mitigations #synchronization PIN credential exfiltration #unauthorized trusted device registry #VaultJacking Google password phishing #WebAuthn hardware perimeter bypass
Information Security News
VaultJacking: Exploiting Google Sync Infrastructure via Intercepted PINs
The Genesis of the VaultJacking Attack Vector A solitary numeric PIN can transform Google’s password repository into an unsecured gateway. Consequently, the emerging VaultJacking phishing methodol…
⤷ Title: When a Routine Pentest Becomes a CVE: XSS to Admin in Rock RMS
════════════════════════
𐀪 Author: Mark Puckett
════════════════════════
ⴵ Time: Mon, 01 Jun 2026 19:46:00 GMT
════════════════════════
⌗ Tags: #cve_2026_36748 #rock_rms #xss_vulnerability #cross_site_scripting
════════════════════════
𐀪 Author: Mark Puckett
════════════════════════
ⴵ Time: Mon, 01 Jun 2026 19:46:00 GMT
════════════════════════
⌗ Tags: #cve_2026_36748 #rock_rms #xss_vulnerability #cross_site_scripting
Medium
When a Routine Pentest Becomes a CVE: XSS to Admin in Rock RMS
Raxis Pentester Jason Taylor has discovered a new high-risk vulnerability in Rock RMS: CVE-2026–36748. Learn how to duplicate and mitigate.
⤷ Title: Native Integration: Microsoft Launches Coreutils for Windows
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 04 Jun 2026 03:53:57 +0000
════════════════════════
⌗ Tags: #Microsoft #Coreutils for Windows preview #cross platform shell script #Microsoft Build 2026 terminal #Rust Linux command tools #uutils open source project #WinGet toolkit installation
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 04 Jun 2026 03:53:57 +0000
════════════════════════
⌗ Tags: #Microsoft #Coreutils for Windows preview #cross platform shell script #Microsoft Build 2026 terminal #Rust Linux command tools #uutils open source project #WinGet toolkit installation
Information Security News
Coreutils for Windows Preview: Native Linux Commands
Explore the Coreutils for Windows preview toolkit. Learn how Microsoft uses Rust to bring native Linux command line tools directly to Windows 11.
⤷ Title: Multiple Security Flaws Fixed in Major Framework Release
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 12 Jun 2026 02:30:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cross_Site Scripting #CVE_2026_40998 #CVE_2026_40999 #CVE_2026_41003 #patch management #Spring Security #Spring Web Services
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 12 Jun 2026 02:30:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cross_Site Scripting #CVE_2026_40998 #CVE_2026_40999 #CVE_2026_41003 #patch management #Spring Security #Spring Web Services
Daily CyberSecurity
Multiple Security Flaws Fixed in Major Framework Release
New updates patch critical Spring security vulnerabilities, mitigating cross-site scripting and server-side request forgery risks across multiple versions.
⤷ Title: Thm Room —Intro to Cross-Site Scripting
════════════════════════
𐀪 Author: Bsbharathkumarreddy
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 15:42:57 GMT
════════════════════════
⌗ Tags: #xss_vulnerability #thm_room #tryhackme_walkthrough #cross_site_scripting #thm_writeup
════════════════════════
𐀪 Author: Bsbharathkumarreddy
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 15:42:57 GMT
════════════════════════
⌗ Tags: #xss_vulnerability #thm_room #tryhackme_walkthrough #cross_site_scripting #thm_writeup
Medium
Thm Room —Intro to Cross-Site Scripting
Task — 1:
⤷ Title: Cybersecurity Practice Lab 3
════════════════════════
𐀪 Author: Akhil Thakur
════════════════════════
ⴵ Time: Mon, 29 Jun 2026 11:44:13 GMT
════════════════════════
⌗ Tags: #cybersecurity #labs #practice #ethical_hacking #cross_site_scripting
════════════════════════
𐀪 Author: Akhil Thakur
════════════════════════
ⴵ Time: Mon, 29 Jun 2026 11:44:13 GMT
════════════════════════
⌗ Tags: #cybersecurity #labs #practice #ethical_hacking #cross_site_scripting
Medium
Cybersecurity Practice Lab 3
XSS (Cross-site scripting)