Postmortem of a little community hobby wiki struggling to survive an extinction-event-tier DDOS purely because they banned one guy for using Claude on the wiki https://blog.xkeeper.net/the-cutting-room-floor/tcrf-2026-ddos-postmortem/
Cure53π
@cure53.infosec.exchange.ap.brid.gy
And there is fire where we walk. π bridged from β https://infosec.exchange/@cure53, follow @ap.brid.gy to interact
Blink: Intent to Ship: HTML install element
Blink: Intent to Ship: HTML install element
Blink: Intent to Ship: HTML install element
groups.google.com
RE: https://infosec.exchange/@lcamtuf/117300984631039147 Our entire team has their lips mutilated and here were are, being made fun of...
infosec.exchange
Phase 1 "project babyfication" has completed successfully. Phase 2 "vampire romance" shall now commence.
Imagine a Bitcoin walletswritten in pure CSS, who wants to invest??? π https://groups.google.com/a/mozilla.org/g/dev-platform/c/7vPYZGNHdvQ
In recognition of bravery, patriotism and an unwavering love of freedom, we have decided to rename Microsoft Teams as Microsoft America. Please update your SBOM and software directories; this change is immediate and permanent. Thank you for your attention to this matter. π¦
Open Call for Nominations: European Open Source Awards 2027 Please consider taking a minute and tell us who we should recognize and honor this time around! We need to know about the heroes to be able to celebrate them. https://awards.europeanopensource.academy/nomination-process
Der bundesweite Warntag war heite um 11 Uhr und Entwarnung um 11:45 Uhr. Habt ihr die Meldung auf dem Handy erhalten? Habt ihr die Sirenen gehΓΆrt? Nur durch eurer Feedback kann es verbessert werden! Online-Umfrage zum Bundesweiten Warntag 2026 vom @bbk https://www.warntag-umfrage.de/
A machine pretending to be a human writes a letter to a human, who really doesn't want to read it and sends it to another machine pretending to be a human, so it can write the human-like reponse to the other machine pretending to be human, on behalf of the actual human. Seems a bit inefficient [β¦]
Original post on infosec.exchange
infosec.exchange
Are there more people in the penetration testing business who are flooded with emails from AI agents wanting to negotiate scope and purchase a penetration test? Over the past few weeks, we have received a lot of them - and I mean A LOT - each wilder than the last. Almost all of the emails are [β¦]
Original post on infosec.exchange
infosec.exchange
A computer booting Windows 1.0 and DOOM emulated using just CSS (Original title: CSS-DOS β A computer made of CSS) https://css-dos.ahmedamer.co.uk/
CSS-DOS β A computer made of CSS
css-dos.ahmedamer.co.uk
We built a small project to inject Trusted Types enforcing sanitizer use for all HTML sinks. Without changing any of the insecure code. https://github.com/cure53/DOMFortify Maybe it is useful for someone, especially when having to maintain an older site with too many DOMXSS sinks to fix manually.
GitHub - cure53/DOMFortify: DOMFortify turns on Trusted Types for a page and quietly takes over the browser's default policy, so that old, vulnerable HTML sinks get auto-sanitized before bad markup ever hits the DOM.
DOMFortify turns on Trusted Types for a page and quietly takes over the browser's default policy, so that old, vulnerable HTML sinks get auto-sanitized before bad markup ever hits the DOM. - cu...
github.com
During July & August, we will continue to accept security bug reports for DOMPurify. If anything serious is found, we will patch it immediately and release an update. As always. We call this approach the 'summer of responsible OSS maintenance' and prefer it to ignoring security bugs and [β¦]
Original post on infosec.exchange
infosec.exchange
RE: https://mastodon.online/@mullvadnet/116822244689326681 What a shitty response, shame on you. Coming here and talking about values? Really? Here are the values of the guy your co-whatever is funding, just for the record: https://en.wikipedia.org/wiki/Markus_Allard
mastodon.online
RE: https://mas.to/@patrickbrosset/116809815574070505 ππ» exciting new scripting abilities ππ» no more boring SOP ππ» CSS from <img> to style entire page ππ» big comeback for embedded Java Applets ππ» SVGZ and ActiveX while we're at it
mas.to
We updated our public report repository and there is now lots of new material. Here you are, meanwhile 253 pentest reports, summary reports and papers: https://github.com/cure53/Publications/tree/master#publications
Crazy to see that some folks still get paid their salary in money instead of LLM tokens. They gonna spend the money on tokens anyway, why waste time on legacy payment methods from yesteryear??
Fedizens! Please send me your favourite meme which shows something important about the #Fediverse I'll go first:
We proudly present β DOMPurify 4.0.0 β the first purely agentic sanitizer π€π§Όβ¨ No more rules β no more regex β no more deterministic boredom β Only adaptive intelligence β autonomous decisions β AI-powered sanitation β and the future of XSS prevention β right here β right now π [β¦]
Original post on infosec.exchange
infosec.exchange
RE: https://cyberplace.social/@GossiTheDog/116759868416707730 We heard that Twitter/X too is critical for national security and folks outside the US should no longer be able to use it. Facebook as well, no? #securityfirst
cyberplace.social
Future releases will no longer be able to ignore STML, <ssafe> and the so far quite unknown </lml>. Guess the cat is out of the bag now. This is technically a toot about cats π±
What the f*ck is this now, where do those pages come from? https://dompurify.org/ And who creates this... art? https://dompurify.org/wp-content/uploads/2026/03/hero.png
DOMPurify β Superβfast XSS sanitizer for secure HTML, MathML, and SVG content
Protect websites with DOMPurify, a fast XSS sanitizer securing HTML, MathML, and SVG content for safer apps and clean input everywhere.
dompurify.org
RE: https://mastodon.social/@bagder/116752578588644079 π€¨
The #curl project will not accept or otherwise handle any vulnerability reports during the month of July 2026. We call it the curl summer of bliss. https://daniel.haxx.se/blog/2026/06/15/curl-summer-of-bliss/
Small field update... in the past weeks we have seen. * 10+ requests for audits against vibe-coded crypto software & messenger * 1 request for an audit against vibe-coded medical software * 1 request to only use LLMs for audits as there is allegedly too much code for any human to review * [β¦]
Original post on infosec.exchange
infosec.exchange
DOMPurify 3.4.10 is out, mostly refactoring, should be a bit faster, and a bit more robust. Lots of new tests, documentation etc. Long time to LLM-reported bypasses, maybe things are slowly calming down and we managed to address all exotic config options leading to foot-guns? π€π π [β¦]
Original post on infosec.exchange
infosec.exchange
RE: https://infosec.exchange/@catsalad/116702374049795715 Ma! Yo! There's a stray cat outside
infosec.exchange
The great thing about LLMs is that they make it possible for anyone to create a crypto messenger. All you need is passion and a few tokens. Mega-corporations like Signal can no longer gatekeep and monopolise using their powers - it's finally power to the people!
RE: https://hachyderm.io/@evilpie/116652387705118871 Here is how it all started, like, sort of π https://www.youtube.com/watch?v=KIRvxYqk_Wc
hachyderm.io
RE: https://infosec.exchange/@timb_machine/116647429206728723 This. It's is mostly where our last three to four weeks have spent with for DOMPurify...
Spend less time worrying about LLMs and more time improving your patching and posture.