home.social

#websecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #websecurity, aggregated by home.social.

fetched live
  1. 🌐 WEB SECURITY TESTING ROADMAP

    From HTTP & reconnaissance to authentication, access control, APIs and reporting. 🔍🛡️ A practical path for understanding how modern web applications are tested and secured.

    ⚡ Learn the process. Test responsibly. Build secure.

    #WebSecurity #CyberSecurity #Pentesting #InfoSec #AppSec

  2. 🌐 WEB SECURITY TESTING ROADMAP

    From HTTP & reconnaissance to authentication, access control, APIs and reporting. 🔍🛡️ A practical path for understanding how modern web applications are tested and secured.

    ⚡ Learn the process. Test responsibly. Build secure.

    #WebSecurity #CyberSecurity #Pentesting #InfoSec #AppSec

  3. FYI: PatronView blocks Amazon's AI crawler after 117,000 daily page reads: Anthropic's crawler hit a 35,000 to 1 crawl ratio, and CAPTCHA solve rates measured just 0.24%. The findings show why small operators are locking down servers. ppc.land/patronview-blocks-ama #AI #WebSecurity #DataPrivacy #Crawling #CAPTCHA

  4. FYI: PatronView blocks Amazon's AI crawler after 117,000 daily page reads: Anthropic's crawler hit a 35,000 to 1 crawl ratio, and CAPTCHA solve rates measured just 0.24%. The findings show why small operators are locking down servers. ppc.land/patronview-blocks-ama #AI #WebSecurity #DataPrivacy #Crawling #CAPTCHA

  5. ICYMI: PatronView blocks Amazon's AI crawler after 117,000 daily page reads: Anthropic's crawler hit a 35,000 to 1 crawl ratio, and CAPTCHA solve rates measured just 0.24%. The findings show why small operators are locking down servers. ppc.land/patronview-blocks-ama #AI #Crawler #WebSecurity #CAPTCHA #DataPrivacy

  6. ICYMI: PatronView blocks Amazon's AI crawler after 117,000 daily page reads: Anthropic's crawler hit a 35,000 to 1 crawl ratio, and CAPTCHA solve rates measured just 0.24%. The findings show why small operators are locking down servers. ppc.land/patronview-blocks-ama #AI #Crawler #WebSecurity #CAPTCHA #DataPrivacy

  7. 🔍 Testing SQL Injection Security with ANDRAX

    ANDRAX brings powerful security assessment tools directly to Android. In this Reel, I test my own website to demonstrate how an SQL Injection vulnerability can be identified and why proper web security matters.

    💬 Comment "ANDRAX" and I'll share more cybersecurity resources.

    #CyberSecurity #ANDRAX #WebSecurity #SQLInjection #InfoSec

  8. 🔍 Testing SQL Injection Security with ANDRAX

    ANDRAX brings powerful security assessment tools directly to Android. In this Reel, I test my own website to demonstrate how an SQL Injection vulnerability can be identified and why proper web security matters.

    💬 Comment "ANDRAX" and I'll share more cybersecurity resources.

    #CyberSecurity #ANDRAX #WebSecurity #SQLInjection #InfoSec

  9. CVE-2026-70553: CRITICAL RCE in MaxSite CMS 105.2 (CVSS 9.3). Attackers can inject PHP via POST to the install endpoint, gaining persistent code exec as www-data. Restrict endpoint & monitor traffic until patched. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE #websecurity #RCE

  10. Oh look, another riveting tale about the unbearable burden of web security. 🙄 Apparently, clicking a link and claiming a username is now a Herculean task worthy of a blog post. 🙃 Thank goodness we have experts to guide us through these perilous digital waters. 🧐
    textslashplain.com/2026/08/04/ #websecurity #digitalburden #expertadvice #clickbait #cybersecurity #HackerNews #ngated

  11. Oh look, another riveting tale about the unbearable burden of web security. 🙄 Apparently, clicking a link and claiming a username is now a Herculean task worthy of a blog post. 🙃 Thank goodness we have experts to guide us through these perilous digital waters. 🧐
    textslashplain.com/2026/08/04/ #websecurity #digitalburden #expertadvice #clickbait #cybersecurity #HackerNews #ngated

  12. 😱 Oh no, the #NHS just realized they're playing peek-a-boo with patient data and Palantir's got front row seats! 🎟️ Meanwhile, their web page only knows how to say "403 Forbidden"—maybe it should've tried "Oops!" instead. 🤦‍♂️
    publictechnology.net/2026/08/0 #Palantir #DataPrivacy #PatientCare #WebSecurity #HackerNews #ngated

  13. 😱 Oh no, the #NHS just realized they're playing peek-a-boo with patient data and Palantir's got front row seats! 🎟️ Meanwhile, their web page only knows how to say "403 Forbidden"—maybe it should've tried "Oops!" instead. 🤦‍♂️
    publictechnology.net/2026/08/0 #Palantir #DataPrivacy #PatientCare #WebSecurity #HackerNews #ngated

  14. Ruby on Rails warnt vor CVE-2026-66066 in Active Storage. Angreifer können über präparierte Bild-Uploads Dateien des Servers auslesen und so an Schlüssel oder Zugangsdaten gelangen. Betroffen sind Anwendungen mit libvips. Updates und forensische Prüfwerkzeuge stehen bereit.

    discuss.rubyonrails.org/t/cve-

    1/2

    #RubyOnRails #Sicherheitslücke #Websecurity #KuketzAugust

  15. Ruby on Rails warnt vor CVE-2026-66066 in Active Storage. Angreifer können über präparierte Bild-Uploads Dateien des Servers auslesen und so an Schlüssel oder Zugangsdaten gelangen. Betroffen sind Anwendungen mit libvips. Updates und forensische Prüfwerkzeuge stehen bereit.

    discuss.rubyonrails.org/t/cve-

    1/2

    #RubyOnRails #Sicherheitslücke #Websecurity #KuketzAugust

  16. ❗We're tracking a spam campaign that abuses cross-site scripting (XSS) flaws in website search forms to funnel victims to phishing and scam pages.
    Here's what we've confirmed so far:

    ➡️ Spam emails, mainly from compromised accounts, many on Microsoft 365 (*.onmicrosoft.com), linking to legitimate sites whose search forms are vulnerable to XSS.
    ➡️ The links carry a hidden payload using a classic technique: an <img> tag pointing to a non-existent file, with the onerror handler carrying the actual JavaScript.
    ➡️ That script redirects the visitor to a landing site. The landing site itself applies restrictive geo/browser filtering,behavior similar to a traffic distribution system (TDS), but handled by the site itself rather than a separate redirect service.
    ➡️ Visitors who don't match the target profile get sent to a random Wikipedia article.
    ➡️ Most landing pages we've seen promote an "AI-powered" investment product, using the .mom TLD - though we've also seen .beauty, .skin, .makeup, .click, and .com.
    ➡️ We've also observed banking phish delivered through the same mechanism, along with other, less common target types.

    We're listing the abused (legitimate) sites as abused-legit and notifying operators so they can patch the vulnerable form.

    🕵️‍♂️ While digging into this, we found two other threads that use a similar spammer modus operandi, but we haven't yet confirmed if they are connected:

    ➡️ A campaign targeting Dutch recipients from early July, using similar tactics.
    ➡️ A separate lure impersonating a Zoom meeting invite, leading to a fake "client update" page that serves a .vbs file.

    We're not asserting that they are the same actor, but it's worth watching out for this pattern.

    Note, this is early-stage research, and we'll share more as we learn...

    #ThreatIntel #XSS #Phishing #InfoSec #Cybercrime #WebSecurity #Scam

  17. ❗We're tracking a spam campaign that abuses cross-site scripting (XSS) flaws in website search forms to funnel victims to phishing and scam pages.
    Here's what we've confirmed so far:

    ➡️ Spam emails, mainly from compromised accounts, many on Microsoft 365 (*.onmicrosoft.com), linking to legitimate sites whose search forms are vulnerable to XSS.
    ➡️ The links carry a hidden payload using a classic technique: an <img> tag pointing to a non-existent file, with the onerror handler carrying the actual JavaScript.
    ➡️ That script redirects the visitor to a landing site. The landing site itself applies restrictive geo/browser filtering,behavior similar to a traffic distribution system (TDS), but handled by the site itself rather than a separate redirect service.
    ➡️ Visitors who don't match the target profile get sent to a random Wikipedia article.
    ➡️ Most landing pages we've seen promote an "AI-powered" investment product, using the .mom TLD - though we've also seen .beauty, .skin, .makeup, .click, and .com.
    ➡️ We've also observed banking phish delivered through the same mechanism, along with other, less common target types.

    We're listing the abused (legitimate) sites as abused-legit and notifying operators so they can patch the vulnerable form.

    🕵️‍♂️ While digging into this, we found two other threads that use a similar spammer modus operandi, but we haven't yet confirmed if they are connected:

    ➡️ A campaign targeting Dutch recipients from early July, using similar tactics.
    ➡️ A separate lure impersonating a Zoom meeting invite, leading to a fake "client update" page that serves a .vbs file.

    We're not asserting that they are the same actor, but it's worth watching out for this pattern.

    Note, this is early-stage research, and we'll share more as we learn...

    #ThreatIntel #XSS #Phishing #InfoSec #Cybercrime #WebSecurity #Scam

  18. CVE-2026-57428 - Unauthenticated XSS in Sprout Clients <= 3.2.3. CVSS 7.1. No patch available. Limit exposure now. #CVE #infosec #websecurity

    valtersit.com/cve/CVE-2026-574

  19. Hono: 45 CVEs, 75% unpatched. Max CVSS 8.2, trust score C. CWE-22 path traversal top risk. Open source edge framework needs patching. #Hono #websecurity #cybersecurity

    valtersit.com/vendors/hono/

  20. Hono: 45 CVEs, 75% unpatched. Max CVSS 8.2, trust score C. CWE-22 path traversal top risk. Open source edge framework needs patching. #Hono #websecurity #cybersecurity

    valtersit.com/vendors/hono/

  21. TLS is sending letters in locked envelopes 🔐✉️

    HTTP is a postcard.
    HTTPS protects the message with encryption and certificate checks.

    The new Networking for Humans post explains TLS without crypto headaches.

    webdad.eu/2026/07/23/%f0%9f%94

  22. RT @glenngabe: Läuft WordPress? Achtung. Es könnte 90 Millionen Websites betreffen. Cybersecurity-Unternehmen sagen, dass Hacker verwundbare WordPress-Versionen ausnutzen, um Websites zu übernehmen. WordPress hat letzte Woche zwei kritische Sicherheitslücken behoben. "Cybersecurity-Berater Daniel Card, der TechCrunch mitteilte, dass er eine Stichprobe von rund 3.500 WordPress-Websites untersucht hat, schätzt, dass weniger als 15% verwundbar sind. Wendet man Cards Projektion auf die gesamte Bevölkerung der WordPress-Websites im Internet an, liegt die Gesamtzahl immer noch bei rund 90 Millionen." techcrunch.com/2026/07/20/ha… Link Hacker nutzen kürzlich behobene WordPress-Bugs aus und setzen Millionen von Websites in Gefahr |... Zwei kritische Sicherheitslücken in der WordPress-Software haben Hackern die Chance gegeben, zehntausende von Websites fernzusteuern, laut Schätzung eines Cybersecurity-Forschers. techcrunch.com

    mehr auf Arint.info

    #Cybersecurity #Hacker #Sicherheitslücken #TechCrunch #WebSecurity #WordPress #arint_info

    https://x.com/glenngabe/status/2079535269884174787#m

  23. Cloudflare launched Precursor, replacing many CAPTCHA checks with continuous behavioral analysis of mouse, typing, scrolling, and browser activity. 🖱️
    The system aims to detect advanced bots while raising fresh privacy concerns over persistent session monitoring despite limited data collection. 🔒

    🔗 nerds.xyz/2026/07/cloudflare-p

    #TechNews #Cloudflare #Privacy #CAPTCHA #BotDetection #WebSecurity #OpenSource #Cybersecurity #DigitalRights #Technology #Browser #AI #Internet #Security

  24. Cloudflare launched Precursor, replacing many CAPTCHA checks with continuous behavioral analysis of mouse, typing, scrolling, and browser activity. 🖱️
    The system aims to detect advanced bots while raising fresh privacy concerns over persistent session monitoring despite limited data collection. 🔒

    🔗 nerds.xyz/2026/07/cloudflare-p

    #TechNews #Cloudflare #Privacy #CAPTCHA #BotDetection #WebSecurity #OpenSource #Cybersecurity #DigitalRights #Technology #Browser #AI #Internet #Security

  25. So, #passkeys ...

    Websites keep encouraging/forcing me to set up passkeys. Yet, most websites only give me this option ONCE, and then never let me set up additional passkeys on other devices. Then the sites basically try to stop all other logins.

    Is it impossible to have two passkeys for a website on two different devices? What is the best practice for #logins with multiple devices these days?

    Am I missing something obvious here?

    #passkey #itsec #websecurity

  26. So, #passkeys ...

    Websites keep encouraging/forcing me to set up passkeys. Yet, most websites only give me this option ONCE, and then never let me set up additional passkeys on other devices. Then the sites basically try to stop all other logins.

    Is it impossible to have two passkeys for a website on two different devices? What is the best practice for #logins with multiple devices these days?

    Am I missing something obvious here?

    #passkey #itsec #websecurity

  27. 🔍🛑 Ah, the groundbreaking revelation that regular sleep patterns might actually be MORE important than the number of hours you sleep. But first, let us in with your precious cookies and #JavaScript. 🍪⏳ Because who needs #science when you have web security to sleep on? 😴🔒
    academic.oup.com/sleep/article #sleeppatterns #importance #websecurity #HackerNews #ngated

  28. 🔍🛑 Ah, the groundbreaking revelation that regular sleep patterns might actually be MORE important than the number of hours you sleep. But first, let us in with your precious cookies and #JavaScript. 🍪⏳ Because who needs #science when you have web security to sleep on? 😴🔒
    academic.oup.com/sleep/article #sleeppatterns #importance #websecurity #HackerNews #ngated

  29. "Just shell out to certbot from PHP"

    No.

    Here's an honest comparison of every PHP ACME client worth using in 2026. Features, code examples, and when to just use certbot anyway.

    #PHP #LetsEncrypt #ACME #TLS #WebSecurity #OpenSource #Laravel

    blendbyte.com/blog/php-acme-cl

  30. 🚨🥳 BREAKING NEWS: Internet genius discovers that typing certain words online can result in being BLOCKED! 🌐🔐 Who knew websites had the audacity to protect themselves from our groundbreaking SQL adventures? 🤯💡
    x.ai/news/grok-4-5 #InternetGenius #OnlineSafety #SQLAdventures #WebSecurity #DigitalDiscovery #HackerNews #ngated