ADWINWSF 🏳️‍🌈

@adwinwsf.bsky.social

[ENG | ESP | GAL] MDNI 🔞 | He/Him, 23yo, Autism + ADHD, weird but friendly, generic IT gay furry fox from Spain, Open-ish DMs. Interests: Linux, Videogames, hardware, music, VFX, etc. May RT pol. I'm a boring person. pfp: @msmaesha.bsky.social

Okay a tiny thread because people are going to freak out: This exploit in particular takes advantage of a special command that renders images (via attribute escape). If you have an overlay that processes images (most don't) then yes, this is your problem. Overlay must explicitly create img DOM.

A picture of the exploit, using a command that explicitly includes an image file extension, but also would escape out of the src attribute of an image such than an onerror attribute can be added to the img tag. This onerror attribute can run explicit javascript immediately.

Default behavior for most chat widgets is if you have an image it will not attempt to modify image links into actual HTML image tags. Your overlay/overlay service must explicitly be doing this for you.

A malicious Twitch chat message can trigger code execution in OBS Studio. The attack targets OBS Studio and custom Twitch chat overlays (Browser Sources) that insert unsanitized chat directly into the page and can execute JS within the overlay. cyberinsider.com/malicious-tw...

Malicious Twitch chat messages can trigger code execution on OBS Studio

A malicious Twitch chat message could be turned into native code execution on a streamer’s Windows PC through a OBS Studio flaw.

cyberinsider.com

Pues he migrado mi librería de ebooks de Calibre a Bookorbit, la verdad es que funciona de maravilla. Además tiene sincronización con KOReader, así que puedo descargar libros directamente desde el kindle

Bild

HOLD IT! We're pleased to announce that Phoenix Wright: Ace Attorney Trilogy has sold over 5 million copies! We want to thank everyone who has gone through all the trials and tribulations to seek the truth and deliver justice for all! We couldn't have done it without you! 🎉

Bild