May 7, 2021 at 01:06AM

■■■■■ DOM clobbering: Escaping from HTML-injection to execute XSS even if the web page has proper mitigation to prevent script execution. https://portswigger.net/web-security/dom-based/dom-clobbering https://t.me/cKure/7858

May 7, 2021 at 12:56AM

■■■■■ CVE-2020-11292 | Qualcomm | Android bug. A vulnerability in a 5G modem data service could allow mobile hackers to remotely target Android users by injecting malicious code into a phone’s modem – gaining the ability to execute code, access mobile users’ call histories and text messages, and eavesdrop on phone calls. A malicious app…

May 6, 2021 at 11:49AM

■□□□□ Chrome on Windows turns on Intel, AMD chip-level defenses against malicious websites. https://go.theregister.com/feed/www.theregister.com/2021/05/06/chrome_code_protection/ https://t.me/cKure/7853

May 6, 2021 at 05:57AM

■■■□□ Facebook blocks Signal from using ads to show Instagram data collection. Signal attempted to use the Facebook ad program to show how much data is being collected by Instagram to push targeted ads and got banned. https://www.hackread.com/facebook-blocks-signal-instagram-data-collected/ https://t.me/cKure/7850

May 6, 2021 at 12:06AM

■■■■■ pentest lab: A local pentest lab leverages docker to spin multiple victim services and an attacker service running Kali Linux. https://github.com/oliverwiegers/pentest_lab https://t.me/cKure/7847