Follow feeds: blogs, news, RSS and more. An effortless way to read and digest content of your choice.
Get Feederrss.ricterz.me
Get the latest updates from HackerOne Hacker Activity directly as they happen.
Follow now 109 followers
Last updated about 18 hours ago
about 18 hours ago
Node.js: Incomplete fix for CVE-2026-21637: loadSNI() in _tls_wrap.js lacks try/catch leading to...
1 day ago
Rocket.Chat: RBAC bypass on App log endpoints via `permissionRequired` typo — any...
2 days ago
Rocket.Chat: Complete authentication bypass to admin permissions
4 days ago
Nextcloud: SMIL values and by attributes bypass remote image blocking via unvalidated...
4 days ago
Nextcloud: position: fixed !important bypasses CSS sanitizer's fixed-position mitigation, enabling full-viewport phishing...
4 days ago
Nextcloud: Unquoted body background attribute enables CSS injection that bypasses remote image...
4 days ago
Nextcloud: SVG filter primitives bypass remote image blocking, enabling email tracking without...
5 days ago
curl: libcurl omits IPv6 zoneid from host identity and leaks credentials/cookies across...
5 days ago
curl: Digest Auth State Leak on Cross-Origin Redirect via Netrc - Username...
5 days ago
Nextcloud: Stored XSS in attachment-display exploitable through SameSite
6 days ago
curl: libcurl reuses a learned RTSP Session header across different hosts on...
6 days ago
Ruby on Rails: Rails::HTML::Sanitizer.allowed_uri? returns true for entity-encoded control-character-split javascript: URLs