#websecurity — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #websecurity, aggregated by home.social.
-
🌐 WEB SECURITY TESTING ROADMAP
From HTTP & reconnaissance to authentication, access control, APIs and reporting. 🔍🛡️ A practical path for understanding how modern web applications are tested and secured.
⚡ Learn the process. Test responsibly. Build secure.
-
🌐 WEB SECURITY TESTING ROADMAP
From HTTP & reconnaissance to authentication, access control, APIs and reporting. 🔍🛡️ A practical path for understanding how modern web applications are tested and secured.
⚡ Learn the process. Test responsibly. Build secure.
-
FYI: PatronView blocks Amazon's AI crawler after 117,000 daily page reads: Anthropic's crawler hit a 35,000 to 1 crawl ratio, and CAPTCHA solve rates measured just 0.24%. The findings show why small operators are locking down servers. https://ppc.land/patronview-blocks-amazons-ai-crawler-after-117-000-daily-page-reads/ #AI #WebSecurity #DataPrivacy #Crawling #CAPTCHA
-
FYI: PatronView blocks Amazon's AI crawler after 117,000 daily page reads: Anthropic's crawler hit a 35,000 to 1 crawl ratio, and CAPTCHA solve rates measured just 0.24%. The findings show why small operators are locking down servers. https://ppc.land/patronview-blocks-amazons-ai-crawler-after-117-000-daily-page-reads/ #AI #WebSecurity #DataPrivacy #Crawling #CAPTCHA
-
ICYMI: PatronView blocks Amazon's AI crawler after 117,000 daily page reads: Anthropic's crawler hit a 35,000 to 1 crawl ratio, and CAPTCHA solve rates measured just 0.24%. The findings show why small operators are locking down servers. https://ppc.land/patronview-blocks-amazons-ai-crawler-after-117-000-daily-page-reads/ #AI #Crawler #WebSecurity #CAPTCHA #DataPrivacy
-
ICYMI: PatronView blocks Amazon's AI crawler after 117,000 daily page reads: Anthropic's crawler hit a 35,000 to 1 crawl ratio, and CAPTCHA solve rates measured just 0.24%. The findings show why small operators are locking down servers. https://ppc.land/patronview-blocks-amazons-ai-crawler-after-117-000-daily-page-reads/ #AI #Crawler #WebSecurity #CAPTCHA #DataPrivacy
-
🔍 Testing SQL Injection Security with ANDRAX
ANDRAX brings powerful security assessment tools directly to Android. In this Reel, I test my own website to demonstrate how an SQL Injection vulnerability can be identified and why proper web security matters.
💬 Comment "ANDRAX" and I'll share more cybersecurity resources.
-
🔍 Testing SQL Injection Security with ANDRAX
ANDRAX brings powerful security assessment tools directly to Android. In this Reel, I test my own website to demonstrate how an SQL Injection vulnerability can be identified and why proper web security matters.
💬 Comment "ANDRAX" and I'll share more cybersecurity resources.
-
A high-severity Django vulnerability, CVE-2026-15307, can enable remote code execution through spatial lookups. Update to Django 6.0.8 or 5.2.17 now.
#Django #DjangoSecurity #CVE202615307 #RCE #RemoteCodeExecution #Vulnerability #Python #WebSecurity #InfoSec #CyberSecurity
-
CVE-2026-70553: CRITICAL RCE in MaxSite CMS 105.2 (CVSS 9.3). Attackers can inject PHP via POST to the install endpoint, gaining persistent code exec as www-data. Restrict endpoint & monitor traffic until patched. Details: https://radar.offseq.com/threat/cve-2026-70553-improper-control-of-generation-of-code-code-injection-in-maxsite-maxsite-cms-5161bdfb2e6804e9 #OffSeq #CVE #websecurity #RCE
-
Oh look, another riveting tale about the unbearable burden of web security. 🙄 Apparently, clicking a link and claiming a username is now a Herculean task worthy of a blog post. 🙃 Thank goodness we have experts to guide us through these perilous digital waters. 🧐
https://textslashplain.com/2026/08/04/security-is-hard-yall/ #websecurity #digitalburden #expertadvice #clickbait #cybersecurity #HackerNews #ngated -
Oh look, another riveting tale about the unbearable burden of web security. 🙄 Apparently, clicking a link and claiming a username is now a Herculean task worthy of a blog post. 🙃 Thank goodness we have experts to guide us through these perilous digital waters. 🧐
https://textslashplain.com/2026/08/04/security-is-hard-yall/ #websecurity #digitalburden #expertadvice #clickbait #cybersecurity #HackerNews #ngated -
😱 Oh no, the #NHS just realized they're playing peek-a-boo with patient data and Palantir's got front row seats! 🎟️ Meanwhile, their web page only knows how to say "403 Forbidden"—maybe it should've tried "Oops!" instead. 🤦♂️
https://www.publictechnology.net/2026/08/03/health-and-social-care/nhs-apologises-and-admits-palantir-engineers-have-access-to-identifiable-patient-data/ #Palantir #DataPrivacy #PatientCare #WebSecurity #HackerNews #ngated -
😱 Oh no, the #NHS just realized they're playing peek-a-boo with patient data and Palantir's got front row seats! 🎟️ Meanwhile, their web page only knows how to say "403 Forbidden"—maybe it should've tried "Oops!" instead. 🤦♂️
https://www.publictechnology.net/2026/08/03/health-and-social-care/nhs-apologises-and-admits-palantir-engineers-have-access-to-identifiable-patient-data/ #Palantir #DataPrivacy #PatientCare #WebSecurity #HackerNews #ngated -
Ruby on Rails warnt vor CVE-2026-66066 in Active Storage. Angreifer können über präparierte Bild-Uploads Dateien des Servers auslesen und so an Schlüssel oder Zugangsdaten gelangen. Betroffen sind Anwendungen mit libvips. Updates und forensische Prüfwerkzeuge stehen bereit.
1/2
-
Ruby on Rails warnt vor CVE-2026-66066 in Active Storage. Angreifer können über präparierte Bild-Uploads Dateien des Servers auslesen und so an Schlüssel oder Zugangsdaten gelangen. Betroffen sind Anwendungen mit libvips. Updates und forensische Prüfwerkzeuge stehen bereit.
1/2
-
SQLite Critical CVEs or LLM Slop? | JFrog #sqli #owasp #websecurity https://research.jfrog.com/post/sqlite-critical-cves-or-llm-slops/
-
SQLite Critical CVEs or LLM Slop? | JFrog #sqli #owasp #websecurity https://research.jfrog.com/post/sqlite-critical-cves-or-llm-slops/
-
❗We're tracking a spam campaign that abuses cross-site scripting (XSS) flaws in website search forms to funnel victims to phishing and scam pages.
Here's what we've confirmed so far:➡️ Spam emails, mainly from compromised accounts, many on Microsoft 365 (*.onmicrosoft.com), linking to legitimate sites whose search forms are vulnerable to XSS.
➡️ The links carry a hidden payload using a classic technique: an <img> tag pointing to a non-existent file, with the onerror handler carrying the actual JavaScript.
➡️ That script redirects the visitor to a landing site. The landing site itself applies restrictive geo/browser filtering,behavior similar to a traffic distribution system (TDS), but handled by the site itself rather than a separate redirect service.
➡️ Visitors who don't match the target profile get sent to a random Wikipedia article.
➡️ Most landing pages we've seen promote an "AI-powered" investment product, using the .mom TLD - though we've also seen .beauty, .skin, .makeup, .click, and .com.
➡️ We've also observed banking phish delivered through the same mechanism, along with other, less common target types.We're listing the abused (legitimate) sites as abused-legit and notifying operators so they can patch the vulnerable form.
🕵️♂️ While digging into this, we found two other threads that use a similar spammer modus operandi, but we haven't yet confirmed if they are connected:
➡️ A campaign targeting Dutch recipients from early July, using similar tactics.
➡️ A separate lure impersonating a Zoom meeting invite, leading to a fake "client update" page that serves a .vbs file.We're not asserting that they are the same actor, but it's worth watching out for this pattern.
Note, this is early-stage research, and we'll share more as we learn...
#ThreatIntel #XSS #Phishing #InfoSec #Cybercrime #WebSecurity #Scam
-
❗We're tracking a spam campaign that abuses cross-site scripting (XSS) flaws in website search forms to funnel victims to phishing and scam pages.
Here's what we've confirmed so far:➡️ Spam emails, mainly from compromised accounts, many on Microsoft 365 (*.onmicrosoft.com), linking to legitimate sites whose search forms are vulnerable to XSS.
➡️ The links carry a hidden payload using a classic technique: an <img> tag pointing to a non-existent file, with the onerror handler carrying the actual JavaScript.
➡️ That script redirects the visitor to a landing site. The landing site itself applies restrictive geo/browser filtering,behavior similar to a traffic distribution system (TDS), but handled by the site itself rather than a separate redirect service.
➡️ Visitors who don't match the target profile get sent to a random Wikipedia article.
➡️ Most landing pages we've seen promote an "AI-powered" investment product, using the .mom TLD - though we've also seen .beauty, .skin, .makeup, .click, and .com.
➡️ We've also observed banking phish delivered through the same mechanism, along with other, less common target types.We're listing the abused (legitimate) sites as abused-legit and notifying operators so they can patch the vulnerable form.
🕵️♂️ While digging into this, we found two other threads that use a similar spammer modus operandi, but we haven't yet confirmed if they are connected:
➡️ A campaign targeting Dutch recipients from early July, using similar tactics.
➡️ A separate lure impersonating a Zoom meeting invite, leading to a fake "client update" page that serves a .vbs file.We're not asserting that they are the same actor, but it's worth watching out for this pattern.
Note, this is early-stage research, and we'll share more as we learn...
#ThreatIntel #XSS #Phishing #InfoSec #Cybercrime #WebSecurity #Scam
-
CVE-2026-57428 - Unauthenticated XSS in Sprout Clients <= 3.2.3. CVSS 7.1. No patch available. Limit exposure now. #CVE #infosec #websecurity
-
Hono: 45 CVEs, 75% unpatched. Max CVSS 8.2, trust score C. CWE-22 path traversal top risk. Open source edge framework needs patching. #Hono #websecurity #cybersecurity
-
Hono: 45 CVEs, 75% unpatched. Max CVSS 8.2, trust score C. CWE-22 path traversal top risk. Open source edge framework needs patching. #Hono #websecurity #cybersecurity
-
TLS is sending letters in locked envelopes 🔐✉️
HTTP is a postcard.
HTTPS protects the message with encryption and certificate checks.The new Networking for Humans post explains TLS without crypto headaches.
#Networking #TLS #HTTPS #ELI5 #WebSecurity
https://webdad.eu/2026/07/23/%f0%9f%94%90-tls-is-sending-letters-in-locked-envelopes/
-
RT @glenngabe: Läuft WordPress? Achtung. Es könnte 90 Millionen Websites betreffen. Cybersecurity-Unternehmen sagen, dass Hacker verwundbare WordPress-Versionen ausnutzen, um Websites zu übernehmen. WordPress hat letzte Woche zwei kritische Sicherheitslücken behoben. "Cybersecurity-Berater Daniel Card, der TechCrunch mitteilte, dass er eine Stichprobe von rund 3.500 WordPress-Websites untersucht hat, schätzt, dass weniger als 15% verwundbar sind. Wendet man Cards Projektion auf die gesamte Bevölkerung der WordPress-Websites im Internet an, liegt die Gesamtzahl immer noch bei rund 90 Millionen." techcrunch.com/2026/07/20/ha… Link Hacker nutzen kürzlich behobene WordPress-Bugs aus und setzen Millionen von Websites in Gefahr |... Zwei kritische Sicherheitslücken in der WordPress-Software haben Hackern die Chance gegeben, zehntausende von Websites fernzusteuern, laut Schätzung eines Cybersecurity-Forschers. techcrunch.com
mehr auf Arint.info
#Cybersecurity #Hacker #Sicherheitslücken #TechCrunch #WebSecurity #WordPress #arint_info
-
Cloudflare launched Precursor, replacing many CAPTCHA checks with continuous behavioral analysis of mouse, typing, scrolling, and browser activity. 🖱️
The system aims to detect advanced bots while raising fresh privacy concerns over persistent session monitoring despite limited data collection. 🔒🔗 https://nerds.xyz/2026/07/cloudflare-precursor-bot-detection/
#TechNews #Cloudflare #Privacy #CAPTCHA #BotDetection #WebSecurity #OpenSource #Cybersecurity #DigitalRights #Technology #Browser #AI #Internet #Security
-
Cloudflare launched Precursor, replacing many CAPTCHA checks with continuous behavioral analysis of mouse, typing, scrolling, and browser activity. 🖱️
The system aims to detect advanced bots while raising fresh privacy concerns over persistent session monitoring despite limited data collection. 🔒🔗 https://nerds.xyz/2026/07/cloudflare-precursor-bot-detection/
#TechNews #Cloudflare #Privacy #CAPTCHA #BotDetection #WebSecurity #OpenSource #Cybersecurity #DigitalRights #Technology #Browser #AI #Internet #Security
-
So, #passkeys ...
Websites keep encouraging/forcing me to set up passkeys. Yet, most websites only give me this option ONCE, and then never let me set up additional passkeys on other devices. Then the sites basically try to stop all other logins.
Is it impossible to have two passkeys for a website on two different devices? What is the best practice for #logins with multiple devices these days?
Am I missing something obvious here?
-
So, #passkeys ...
Websites keep encouraging/forcing me to set up passkeys. Yet, most websites only give me this option ONCE, and then never let me set up additional passkeys on other devices. Then the sites basically try to stop all other logins.
Is it impossible to have two passkeys for a website on two different devices? What is the best practice for #logins with multiple devices these days?
Am I missing something obvious here?
-
WordPress pre-auth RCE CVE-2026-63030 chains a REST batch bug with SQL injection. Details and a public PoC are out. Update to WordPress 7.0.2 now.
#WordPress #PreAuthRCE #CVE202663030 #SQLInjection #wp2shell #WebSecurity #InfoSec
-
oproxy (open source mitm server) in v0.1.10 released
-
oproxy (open source mitm server) in v0.1.10 released
-
🔍🛑 Ah, the groundbreaking revelation that regular sleep patterns might actually be MORE important than the number of hours you sleep. But first, let us in with your precious cookies and #JavaScript. 🍪⏳ Because who needs #science when you have web security to sleep on? 😴🔒
https://academic.oup.com/sleep/article/47/1/zsad253/7280269 #sleeppatterns #importance #websecurity #HackerNews #ngated -
🔍🛑 Ah, the groundbreaking revelation that regular sleep patterns might actually be MORE important than the number of hours you sleep. But first, let us in with your precious cookies and #JavaScript. 🍪⏳ Because who needs #science when you have web security to sleep on? 😴🔒
https://academic.oup.com/sleep/article/47/1/zsad253/7280269 #sleeppatterns #importance #websecurity #HackerNews #ngated -
"Just shell out to certbot from PHP"
No.
Here's an honest comparison of every PHP ACME client worth using in 2026. Features, code examples, and when to just use certbot anyway.
#PHP #LetsEncrypt #ACME #TLS #WebSecurity #OpenSource #Laravel
https://www.blendbyte.com/blog/php-acme-clients-2026-honest-comparison
-
🚨🥳 BREAKING NEWS: Internet genius discovers that typing certain words online can result in being BLOCKED! 🌐🔐 Who knew websites had the audacity to protect themselves from our groundbreaking SQL adventures? 🤯💡
https://x.ai/news/grok-4-5 #InternetGenius #OnlineSafety #SQLAdventures #WebSecurity #DigitalDiscovery #HackerNews #ngated