Web cache poisoning bug discovered in Symfony PHP framework

Vulnerability in open source project has since been patched | Continue reading


@portswigger.net | 2 years ago

Interpol arrests 1k suspects, seizes $27m in crackdown on cybercrime

Worldwide law enforcement operation targets online crime surge | Continue reading


@portswigger.net | 2 years ago

Ukrainian police expose international phone-hacking gang

‘Phoenix’ group laid low following seizure of computing equipment and stolen devices | Continue reading


@portswigger.net | 2 years ago

Microsoft pushes ahead with controversial ‘buy now, pay later’ feature for Edge

‘It’s like you’re recapitulating the worst IE browser extensions and installing them by default’, grumbles one user | Continue reading


@portswigger.net | 2 years ago

Maritime giant Swire Pacific Offshore suffers data breach following cyber-attack

Organization said it suffered ‘unauthorized access’ to systems | Continue reading


@portswigger.net | 2 years ago

New differential fuzzing tool reveals novel HTTP request smuggling techniques

White paper systematically examines the attack while showcasing a ‘laundry list’ of new flaws | Continue reading


@portswigger.net | 2 years ago

WordPress security plugin Hide My WP addresses SQL injection, deactivation flaws

Bugs deemed ‘very easy to exploit as they require no prerequisites’ | Continue reading


@portswigger.net | 2 years ago

Data breach at New Mexico healthcare business impacts 62,000 state residents

True Health New Mexico was hit by a cyber-attack in October | Continue reading


@portswigger.net | 2 years ago

Decrypting diversity: One in five UK infosec professionals say they’ve

Report states diversity and inclusion within the industry is lagging behind | Continue reading


@portswigger.net | 2 years ago

Cyberstalking study: UK residents most accepting of spyware to track partners’

Report from cybersecurity firm Kaspersky reveals worrying attitudes towards spyware usage | Continue reading


@portswigger.net | 2 years ago

Microsoft Unveils ‘Super Duper Secure Mode’ in Latest Version of Edge

Browser goes further to protect against bugs by disabling JIT | Continue reading


@portswigger.net | 2 years ago

Researcher finds SSRF bug in internal Google Cloud project, nabs $10k bounty

Now-patched API vulnerability allowed attacker to access sensitive resources | Continue reading


@portswigger.net | 2 years ago

Clubhouse launches bug bounty program with $3k on offer for critical

Audio-based social media platform prioritizes access control bypasses and information disclosure flaws | Continue reading


@portswigger.net | 2 years ago

Clubhouse launches bug bounty platform with $3k on offer for critical

Audio-based social media platform prioritizes access control bypasses and information disclosure flaws | Continue reading


@portswigger.net | 2 years ago

Dangerous bug in Chrome’s ‘New Tab’ page bypassed security features

‘Chrome’s NTP only has a really weak CSP that doesn’t mitigate XSS’ | Continue reading


@portswigger.net | 2 years ago

New and improved Linux Random Number Generator ready for testing

Proposed replacement for /dev/random promises to double performance and add flexibility | Continue reading


@portswigger.net | 2 years ago

Belarusian hackers claim to have accessed full database of those crossing the

‘Belarus Cyber-Partisans’ say they gained access to all entries in and out of the country over the past 15 years | Continue reading


@portswigger.net | 2 years ago

Exploit-as-a-service: Cybercriminals exploring potential of leasing out zero-day

New approach echoes the depressingly successful ransomware-as-a-service business model | Continue reading


@portswigger.net | 2 years ago

Microsoft fixes reflected XSS in Exchange Server

Researchers’ bid to reproduce ProxyShell yields something entirely new | Continue reading


@portswigger.net | 2 years ago

HTML smuggling: Fresh attack technique is being used to increasingly target

Evasive malware is being spread via email in campaigns similar to those of nation-state actors | Continue reading


@portswigger.net | 2 years ago

Alan Paller: Infosec world pays homage after SANS founder and infosec luminary

‘His vision has changed the lives of hundreds of thousands of security practitioners’ | Continue reading


@portswigger.net | 2 years ago

GoCD bug chain provides second springboard for supply chain attacks

Follow-up to recent GoCD disclosure provides additional path to infiltrating build environments | Continue reading


@portswigger.net | 2 years ago

Smuggling hidden backdoors into JavaScript with homoglyphs and invisible Unicode

Researchers urge developers to secure code by disallowing non-ASCII characters | Continue reading


@portswigger.net | 2 years ago

Two men charged with deploying REvil ransomware attacks, targeting US Government

Individuals face up to 145 years in prison if convicted | Continue reading


@portswigger.net | 2 years ago

Pwn2Own Austin 2021: Synacktiv Crowned Masters of Pwn After Sonos One, WD

French team takes home nearly $200k in winnings as event uncovers 61 zero days | Continue reading


@portswigger.net | 2 years ago

Lessons Learned: How a Severe Vulnerability in the OWASP ModSecurity Core Rule

Years-old WAF bypass flaw was discovered in June | Continue reading


@portswigger.net | 2 years ago

Cisco patches critical bug trio in Policy Suite and ONT networking devices

Critical severity bugs disclosed by networking titan | Continue reading


@portswigger.net | 2 years ago

Human rights activists condemn mass denial of service as Sudan’s nationwide

‘All mobile internet networks are completely cut off,’ one journalist on the ground tells The Daily Swig | Continue reading


@portswigger.net | 2 years ago

Mozilla debuts Site Isolation technology with Firefox update

Sandboxing technology levels up browser security | Continue reading


@portswigger.net | 2 years ago

NIST unveils draft criteria for ‘seal of approval’ scheme on consumer software

Baseline standards proposed for secure development, handling vulnerabilities, and protecting sensitive data | Continue reading


@portswigger.net | 2 years ago

WordPress plugin vulnerability opened up one million sites to remote takeover

Gaping OptinMonster security hole patched | Continue reading


@portswigger.net | 2 years ago

Infosec skills gap widens in all regions bar Asia-Pacific – report

Overall worldwide shortfall shrinks 400k to 2.7m unfilled positions | Continue reading


@portswigger.net | 2 years ago

Africa sees increase in ransomware, botnet attacks – but online scams still pose

Fraud is still the primary goal of cybercriminals operating across the continent, Interpol warns in latest market report | Continue reading


@portswigger.net | 2 years ago

Popular NPM package UA-Parser-JS poisoned with cryptomining, password-stealing

Developer moves quickly to address vulnerabilities after his account was compromised | Continue reading


@portswigger.net | 2 years ago

Swiss exhibitions organizer MCH Group hit by cyber-attack

Investigations yet to confirm if any data was exfiltrated | Continue reading


@portswigger.net | 2 years ago

Japanese punctuation exacerbates privacy flaw that leaks one-word search terms

Researcher questions efficacy of proposed remedies as debate rumbles on 18 months after disclosure | Continue reading


@portswigger.net | 2 years ago

New bug bounty platform launches for Indian ethical hackers

Security researchers can sign up now | Continue reading


@portswigger.net | 2 years ago

Historic scientific notation bug foils WAF defenses

AWS WAF and ModSecurity get ‘blinded by science’ | Continue reading


@portswigger.net | 2 years ago

Google, Mozilla Close to Finalizing Sanitizer API for Chrome and Firefox Browse

Latest specification is a work in progress | Continue reading


@portswigger.net | 2 years ago

(ISC)² hopes diversity drive will hasten glacial progress on plugging infosec

CEO tells (ISC)² Security Congress how orgs should rethink hiring strategies | Continue reading


@portswigger.net | 2 years ago

Dutch police warn DDoS-for-hire customers to desist or face prosecution

We know what you DDoSed last summer | Continue reading


@portswigger.net | 2 years ago

Google distributing 10k security keys to journalists, elected officials

Global initiative ‘will definitely prevent some cyber-attacks’, says expert | Continue reading


@portswigger.net | 2 years ago

Chinese phone manufacturer ZTE launches public bug bounty program

Researchers invited to test for flaws under new YesWeHack platform | Continue reading


@portswigger.net | 2 years ago

Hong Kong’s anti-doxxing law comes into force despite human rights criticism

Violations could attract hefty fines and up to five years in prison | Continue reading


@portswigger.net | 2 years ago

TruffleHog – a browser extension for finding secret keys in JavaScript code

API keys are accidentally being leaked by websites. Here’s how to find them | Continue reading


@portswigger.net | 2 years ago

OPPA: Ohio could become the third US state to enact a new consumer privacy law

Ohio Personal Privacy Act will grant Ohioans an expansive set of new rights, writes US attorney David Oberly | Continue reading


@portswigger.net | 2 years ago

Apache HTTP Server devs issue fix for critical data leak vulnerability – update

Bug was inadvertently introduced in last month’s security release | Continue reading


@portswigger.net | 2 years ago

Let’s Encrypt root cert update catches out many big-name tech firms

Back on the chain gang | Continue reading


@portswigger.net | 2 years ago