Follow feeds: blogs, news, RSS and more. An effortless way to read and digest content of your choice.
Get Feederrss.ricterz.me
Get the latest updates from HackerOne Hacker Activity directly as they happen.
Follow now 109 followers
Last updated about 4 hours ago
about 4 hours ago
Rocket.Chat: Autotranslate DDP Method Exposes Private Messages Without Authentication or Room Access...
2 days ago
Node.js: Memory Corruption via TOCTOU Race in SharedArrayBuffer UTF-8 Decode (`StringBytes::Encode`)
2 days ago
Node.js: NULL pointer dereference in node:sqlite DatabaseSync#applyChangeset() via malformed SQLite changeset
4 days ago
Nextcloud: Group restriction bypass via bearer token in user_oidc (SETTING_RESTRICT_LOGIN_TO_GROUPS not enforced...
5 days ago
curl: Credentials forwarded to HTTP after HTTPS→HTTP same-port redirect — url_set_data_creds uses...
5 days ago
curl: curl --skip-existing has a TOCTOU race that lets a post-check symlink...
5 days ago
CoinMate.io: POST /api/bitcoinWithdrawalFees returns financial data without authentication despite being documented as...
5 days ago
CoinMate.io: HMAC signature verification omits endpoint and payload allowing request forgery on...
6 days ago
curl: HTTP/2 proxy CONNECT tunnel unbounded 1xx chain (missing Curl_bump_headersize cap in...
6 days ago
curl: CURLOPT_PROXY_CAINFO_BLOB silently activates native CA store on Apple builds
6 days ago
curl: TLS peer-verification bypass via mid-transfer ssl_config mutation
6 days ago
curl: TLS verifyhost bypass in rustls, mbedTLS, and wolfSSL when verifypeer=0