FreeIntelHub
Feed
Sources
The Hacker News Dark Reading BleepingComputer SecurityWeek Krebs on Security Help Net Security The CyberWire SC Media HackRead GBHackers CSO Online Cybersecurity Dive Information Security Buzz Security Affairs Graham Cluley SANS ISC WeLiveSecurity Google Security Blog Cisco Advisories Palo Alto Networks CISA Advisories US-CERT Alerts Microsoft Security Blog Mandiant Blog Recorded Future Talos Intelligence Unit 42 SentinelOne Blog CrowdStrike Blog Sophos News Threatpost Infosecurity Magazine Cyberscoop The Record SecurityTrails Blog Naked Security Schneier on Security Qualys Blog Rapid7 Blog Tenable Blog Fortinet Blog Trend Micro Research Kaspersky Securelist ESET Research Check Point Research Zscaler Blog Proofpoint Blog Elastic Security Labs Akamai Blog Cisco Talos Blog Volexity Blog NIST NVD Exploit Database Packet Storm Full Disclosure CERT-EU News Wordfence Blog Trail of Bits PortSwigger Research PortSwigger Daily Swig Hacker One Hacktivity Zero Day Initiative Google Project Zero AWS Security Blog Cloudflare Blog Mozilla Security Blog
View all sources
Vendors
Microsoft Google Apple Amazon Intel Cisco Fortinet Linux GitHub Oracle Check Point Cloudflare Rapid7 WordPress Palo Alto Networks
View all vendors
Threats
Data Breach Zero-Day Ransomware CVE Vulnerability Disclosure Advisory TTPs Campaigns Operational Technology Phishing Malware Supply Chain DDoS Insider Threat
View all types
Sectors
Financial Healthcare Defense Government Manufacturing Energy Telecommunications Retail Education Transportation Food & Beverages Technology Legal Media
View all sectors
Actors
Threat Groups Software & Malware Campaigns
Tools
Trending Threat Heatmap MITRE ATT&CK IOC Feed Bookmarks
RSS Feed API
Alerts

General

20 articles

PortSwigger Research General Oracle Aug 7

Listen to the whispers: web timing attacks that actually work

Websites are riddled with timing oracles eager to divulge their innermost secrets. It's time we started listening to them.

PortSwigger Research →

PortSwigger Research General Apple Jul 9

Fickle PDFs: exploiting browser rendering discrepancies

Imagine the CEO of a random company receives an email containing a PDF invoice file. In Safari and MacOS Preview, the total price displayed is £399.

PortSwigger Research →

PortSwigger Research General Jul 2

A hacking hat-trick: previewing three PortSwigger Research publications coming to DEF CON & Black Hat USA

We're delighted to announce three major research releases from PortSwigger Research will be published at both Black Hat USA and DEF CON 32.

PortSwigger Research →

Mozilla Security Blog General Jun 5

Firefox will upgrade more Mixed Content in Version 127

Most of the web already supports HTTPS: In fact, 93% of requests made by Firefox are already HTTPS. As a reminder, HTTP over TLS (HTTPS) fixes the security s...

Mozilla Security Blog →

PortSwigger Research General May 29

Refining your HTTP perspective, with bambdas

When you open a HTTP request or response, what do you instinctively look for? Suspicious parameter names?

PortSwigger Research →

PortSwigger Research General May 22

Introducing SignSaboteur: forge signed web tokens with ease

Signed web tokens are widely used for stateless authentication and authorization throughout the web.

PortSwigger Research →

Mozilla Security Blog General Apr 4

Rapidly Leveling up Firefox Security

At Mozilla, we believe in an open web that is safe to use. To that end, we improve and maintain the security of people using Firefox around the world.

Mozilla Security Blog →

PortSwigger Research General Mar 5

Using form hijacking to bypass CSP

In this post we'll show you how to bypass CSP by using an often overlooked technique that can enable password theft in a seemingly secure configuration. What...

PortSwigger Research →

PortSwigger Research General Oracle Jan 23

Hiding payloads in Java source code strings

In this post we'll show you how Java handles unicode escapes in source code strings in a way you might find surprising - and how you can abuse them to concea...

PortSwigger Research →

PortSwigger Research General Dec 12

Finding that one weird endpoint, with Bambdas

Security research involves a lot of failure.

PortSwigger Research →

Mozilla Security Blog General Dec 6

Mozilla VPN Security Audit 2023

To provide transparency into our ongoing efforts to protect your privacy and security on the Internet, we are releasing a security audit of Mozilla VPN that ...

Mozilla Security Blog →

PortSwigger Research General Dec 5

Blind CSS Exfiltration: exfiltrate unknown web pages

This is a gif of the exfiltration process (We've increased the speed so you're not waiting around for 1 minute). Read on to discover how this works.

T1041

PortSwigger Research →

PortSwigger Research General Oct 18

The single-packet attack: making remote race-conditions 'local'

The single-packet attack is a new technique for triggering web race conditions.

PortSwigger Research →

PortSwigger Research General Oct 3

How to build custom scanners for web security research automation

In this post, I'll share my approach to developing custom automation to aid research into under-appreciated attack classes and (hopefully) push the boundarie...

PortSwigger Research →

Mozilla Security Blog General Sep 13

Version 2.9 of the Mozilla Root Store Policy

Online security is constantly evolving, and thus we are excited to announce the publication of MRSP version 2.9, demonstrating that we are committed to keep ...

Mozilla Security Blog →

PortSwigger Research General Apple Aug 9

Smashing the state machine: the true potential of web race conditions

For too long, web race condition attacks have focused on a tiny handful of scenarios.

PortSwigger Research →

Mozilla Security Blog General May 11

Updated GPG key for signing Firefox Releases

The GPG key used to sign the Firefox release manifests is expiring soon, and so we’re going to be switching over to new key shortly. The new GPG fingerprint ...

Mozilla Security Blog →

Threatpost General Aug 25

Cybercriminals Are Selling Access to Chinese Surveillance Cameras

Tens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed.

Threatpost →

Threatpost General Aug 24

Twitter Whistleblower Complaint: The TL;DR Version

Twitter is blasted for security and privacy lapses by the company’s former head of security who alleges the social media giant’s actions amount to a national...

Threatpost →

Threatpost General Palo Alto Networks SAP Aug 23

Firewall Bug Under Active Attack Triggers CISA Warning

CISA is warning that Palo Alto Networks’ PAN-OS is under active attack and needs to be patched ASAP.

Threatpost →

« Prev 1 ... 63 64 65 66 Next »
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA