⤷ Title: vm2’s Sandbox Just Failed for the Third Time This Week.
════════════════════════
𐀪 Author: Vortex 404
════════════════════════
ⴵ Time: Sat, 19 Sep 2026 15:51:47 GMT
════════════════════════
⌗ Tags: #devsecops #vulnerability_management #nodejs #javascript #application_security
════════════════════════
𐀪 Author: Vortex 404
════════════════════════
ⴵ Time: Sat, 19 Sep 2026 15:51:47 GMT
════════════════════════
⌗ Tags: #devsecops #vulnerability_management #nodejs #javascript #application_security
Medium
vm2’s Sandbox Just Failed for the Third Time This Week. A Million Weekly Downloads Are Still Running It
Three separate CVSS 10.0 sandbox escapes landed days apart — in a library that was declared dead once already
⤷ Title: I Found an Unauthenticated XSS in a WordPress Hotel Plugin — Then Someone Beat Me to It by a Week
════════════════════════
𐀪 Author: Mr Abdullah
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 07:47:00 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup #javascript #penetration_testing #bug_bounty #xss_attack
════════════════════════
𐀪 Author: Mr Abdullah
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 07:47:00 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup #javascript #penetration_testing #bug_bounty #xss_attack
Medium
I Found an Unauthenticated XSS in a WordPress Hotel Plugin — Then Someone Beat Me to It by a Week
A reflected XSS in nd-booking, a display:none trap that fools most PoCs, and an honest look at what “duplicate” really means in bug bounty.
⤷ Title: Mastering Prototype Pollution: A Complete Walkthrough of PortSwigger Labs
════════════════════════
𐀪 Author: Bhanvararam choudhary
════════════════════════
ⴵ Time: Thu, 24 Sep 2026 14:14:59 GMT
════════════════════════
⌗ Tags: #javascript #bug_bounty #cybersecurity #prototype_pollution #web_security
════════════════════════
𐀪 Author: Bhanvararam choudhary
════════════════════════
ⴵ Time: Thu, 24 Sep 2026 14:14:59 GMT
════════════════════════
⌗ Tags: #javascript #bug_bounty #cybersecurity #prototype_pollution #web_security
Medium
Mastering Prototype Pollution: A Complete Walkthrough of PortSwigger Labs
From Client-Side DOM XSS to Server-Side RCE and Data Exfiltration — A deep dive into sources, gadgets, sinks, and bypassing flawed…
⤷ Title: Bookmarklet — picoCTF Write-up | Understanding JavaScript Bookmarklets and Client-Side Decryption
════════════════════════
𐀪 Author: Affanhaxor
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 05:41:56 GMT
════════════════════════
⌗ Tags: #web_security #cybersecurity #javascript #bug_bounty #ctf
════════════════════════
𐀪 Author: Affanhaxor
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 05:41:56 GMT
════════════════════════
⌗ Tags: #web_security #cybersecurity #javascript #bug_bounty #ctf
Medium
Bookmarklet — picoCTF Write-up | Understanding JavaScript Bookmarklets and Client-Side Decryption
Introduction
⤷ Title: Electron Fixes Five High-Severity Sandbox and Isolation Vulnerabilities
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 04:10:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_102673 #CVE_2026_102674 #CVE_2026_102676 #desktop app security #Electron #Electron vulnerabilities #javascript #Sandbox Bypass
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 04:10:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_102673 #CVE_2026_102674 #CVE_2026_102676 #desktop app security #Electron #Electron vulnerabilities #javascript #Sandbox Bypass
Daily CyberSecurity
Electron Fixes Five High-Severity Sandbox and Isolation Vulnerabilities
TL;DR Electron maintainers published five Electron vulnerabilities on September 29, 2026, all rated High, with CVSS scores from 7.4 to 8.3. Each flaw lets untrusted content escape a sandbox, an or…
⤷ Title: Moving YouTube Subscriptions Using Only the Browser Console and Poor Judgment
════════════════════════
𐀪 Author: Lokesh Kumar
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 10:19:22 GMT
════════════════════════
⌗ Tags: #javascript #ethical_hacking #youtube
════════════════════════
𐀪 Author: Lokesh Kumar
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 10:19:22 GMT
════════════════════════
⌗ Tags: #javascript #ethical_hacking #youtube
Medium
Moving YouTube Subscriptions Using Only the Browser Console and Poor Judgment
Reading time: 4 minutes. Regret time: ongoing.
⤷ Title: Exploiting Java RMI on Metasploitable 2: CVE-2011–3556
════════════════════════
𐀪 Author: Harikishan
════════════════════════
ⴵ Time: Thu, 01 Oct 2026 14:43:39 GMT
════════════════════════
⌗ Tags: #remote_access #metasploit #hacking #ethical_hacking #javascript
════════════════════════
𐀪 Author: Harikishan
════════════════════════
ⴵ Time: Thu, 01 Oct 2026 14:43:39 GMT
════════════════════════
⌗ Tags: #remote_access #metasploit #hacking #ethical_hacking #javascript
Medium
Exploiting Java RMI on Metasploitable 2: CVE-2011–3556
Java RMI (Remote Method Invocation) is a way for one Java application to ask another Java application on a different machine to perform a…
⤷ Title: Handlebars.js RCE Flaws Disclosed With Public PoC, Threatening 172 Million Monthly Downloads
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 07 Oct 2026 02:03:14 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_106445 #CVE_2026_106446 #Handlebars #Handlebars.js #javascript #Node.js #proof_of_concept #Remote Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 07 Oct 2026 02:03:14 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_106445 #CVE_2026_106446 #Handlebars #Handlebars.js #javascript #Node.js #proof_of_concept #Remote Code Execution
Daily CyberSecurity
Handlebars.js RCE Flaws Disclosed With Public PoC, Threatening 172 Million Monthly Downloads
TL;DR Maintainers of Handlebars.js have patched two critical flaws that can lead to remote code execution. Each Handlebars.js vulnerability lets an attacker run arbitrary JavaScript on a Node.js s…