New short article on a real-world exploitation case rather than pure research, demonstrating how a specific mistake in Next.js can lead to a systematic zero-click SXSS on its latest versions (w/@inzo____):
Re:CACHE - Excessive reflection, type confusion, and 0-click SXSS on Next.js
https://t.co/0JWjH6yzC2
A 100%+ surge in submissions changed how we think about triage. We're rolling out new changes, including TriageOne Smart Routing, so reports reach the right analyst based on skillset, severity, and researcher signal. Here's the full story: https://t.co/1FiOUU0XtU
As promised, here is paper part 2 of 2 attacking Azure Front Door issues for various bugs.
Smuggling Through the Front Door... Achieving 0-Click XSS with Cache Poisoning
https://t.co/INtcplLVQx
Azure post 1 of 2 is live now, covering traffic hijacking via Smuggle Caching. Post 2 will focus on a Azure Front Door 0-click XSS that worked on HTTP/1.x and HTTP/2.
Smuggling Through the Front Door... Achieving Global Redirect Poisoning at the Edge
https://t.co/4fTtI2gAdL
Here we go. my DEF CON CTF writeup, a little different from the others. Also, thanks to Pwn de Queijo for letting me play with you guys.
https://t.co/6oQBZSKqoy
Adam (@hash_kitten) posted the solution for the XSS challenge he made earlier in the week on our Searchlight Cyber blog here: https://t.co/LwaSDSu64u - pretty interesting behaviour in Chrome's sanitizer API!
I managed to RCE Fortune 500 companies and made over $50,000 with this technique.
A new npm supply chain technique we just disclosed. The trick is dumb-simple.
We call it npx Confusion.
🧵