SonarResearch

@sonarresearch.bsky.social

Cutting-edge security research by Sonar to educate the world about code security across all software. We're also at @SonarResearch@infosec.exchange 🦣 and @Sonar_Research 🐦

Are your data science tools safe? 🕵️‍♂️ We discovered vulnerabilities in JupyterLab Desktop and the JetBrains Jupyter plugin that can lead to code execution with minimal user interaction. Read the technical details here: www.sonarsource.com/blog/hidden-... #appsec #security #vulnerability

More than just data: The hidden security risks in Jupyter notebooks

re your data science tools safe? Sonar researchers uncover vulnerabilities leading to code execution in JupyterLab Desktop and PyCharm.

sonarsource.com

Shellcode execution as a service! To exploit an argument injection in Jellyfin, we searched and found a gadget in the .NET runtime to turn file writes into code execution. Learn about the bug and this new technique in our blog post: www.sonarsource.com/blog/jellyfi... #appsec #vulnerability

Jellyfin RCE | Inconsistent Validation Leads to Argument Injection

Explore a Jellyfin remote code execution flaw where inconsistent validation enables FFmpeg argument injection and unauthenticated code execution.

sonarsource.com

📱 Ever wondered what vulnerabilities look like in Android apps? We have 2 real-world examples for you! From simple misconfig to cross-app data flow, learn how vulnerabilities manifest in the Kotlin code of Android apps: www.sonarsource.com/blog/securin... #appsec #security #vulnerability

Securing Kotlin Apps With SonarQube: Real-World Examples

Explore how real-world vulnerabilities look in the Kotlin code of Android apps and see how SonarQube helps detect them.

sonarsource.com

Catch our second talk at #TROOPERS25: 🕸️ Caught in the FortiNet: Compromising Organizations Using Endpoint Protection Yaniv Nizry will tell you the story of multiple vulnerabilities in Fortinet products that can compromise an entire organization, starting with a single click

Bild

Scripting Outside the Box! 📦 Last week, we saw JS sandboxing pitfalls in API clients. Today, we continue with more complex sandbox escapes in Bruno and Hoppscotch. Learn how they work and how to sandbox JS securely in part 2: www.sonarsource.com/blog/scripti... #appsec #security #vulnerability

Scripting Outside the Box: API Client Security Risks (2/2)

Continuing on API client security, we cover more sandbox bypasses, this time in Bruno and Hoppscotch, as well as JavaScript sandboxing best practices.

sonarsource.com

Ever wondered what's going on behind the scenes of your API client? 🕵️‍♀️ We dug in and found a variety of JS sandboxing pitfalls! Find out how Postman and Insomnia tried to isolate untrusted code and what challenges they faced: www.sonarsource.com/blog/scripti... #appsec #security #vulnerability

Scripting Outside the Box: API Client Security Risks (1/2)

Discover hidden risks in API testing tools like Postman and Insomnia. We dive into scripting vulnerabilities and explore JavaScript sandbox security pitfalls.

sonarsource.com