XSS in Gmail’s AMP For Email earns researcher $5,000.
https://portswigger.net/daily-swig/xss-in-gmails-amp-for-email-earns-researcher-5-000
https://portswigger.net/daily-swig/xss-in-gmails-amp-for-email-earns-researcher-5-000
The Daily Swig | Cybersecurity news and views
XSS in Gmail’s AMP For Email earns researcher $5,000
Researcher bypasses email filter with inspired style tag trickery
Zero-Day used to access 5.4M user data from Twitter (confirmed by company).
https://hackerone.com/reports/1439026
https://securityaffairs.co/wordpress/134087/data-breach/twitter-zero-day-data-leak.html
https://restoreprivacy.com/twitter-vulnerability-exposes-5-million-accounts/
https://hackerone.com/reports/1439026
https://securityaffairs.co/wordpress/134087/data-breach/twitter-zero-day-data-leak.html
https://restoreprivacy.com/twitter-vulnerability-exposes-5-million-accounts/
HackerOne
X / xAI disclosed on HackerOne: Discoverability by phone...
**Summary:** By using this vulnerability an attacker can find a twitter account by it's phone number/email even if the user has prohibited this in the privacy options.
**Description:** The...
**Description:** The...
CVE-2021-38297 – Analysis of a Go Web Assembly vulnerability
https://jfrog.com/blog/cve-2021-38297-analysis-of-a-go-web-assembly-vulnerability/
https://jfrog.com/blog/cve-2021-38297-analysis-of-a-go-web-assembly-vulnerability/
JFrog
CVE-2021-38297 - Analysis of a Go Web Assembly vulnerability
CVE-2021-38297 allows attackers to override an entire Wasm module & achieve WebAssembly code execution. Read technical analysis & mitigation from JFrog Security research >
Analysis of iOS SingPass app and its RASP protector - part 1
https://www.romainthomas.fr/post/22-08-singpass-rasp-analysis/
https://www.romainthomas.fr/post/22-08-singpass-rasp-analysis/
Romain Thomas
Part 1 – SingPass RASP Analysis | Romain Thomas
This first blog post introduces the RASP checks used in SingPass