Topic
Everything filed under Cybersecurity, newest first.
RSS · JSON · All topics
How one Twitch chat message became code execution on a streamer's PC
A vulnerable chat overlay, an unsandboxed Chromium renderer, and a V8 bug already exploited in the wild were enough to turn viewer-controlled text into native code execution, with OBS itself left at its default settings. I found a Twitch chat overlay that rendered viewer messages as raw HTML inside an OBS Browser Source. That gives a viewer JavaScript execution inside OBS’s embedded Chromium browser. The latest release of OBS at the time shipped a Chromium build that ran without its normal sandbox, and its V8 version was still vulnerable to `CVE-2024-7971`, a bug already…
6 min · 1,461 words
One does not simply defend agentically
The UK NCSC on why defenders cannot mirror attacker use of AI agents—and practical ways to unlock agentic cyber defence without pretending the playing field is symmetric.
8 min · 1,832 words
Autonomous AI Agents are breaking into Online Retailers for $25 a target
Gambit Security reconstructs an ongoing campaign where open-source AI harnesses attack retailers at ~$25/target, steal 600k+ cards, inject skimmers, and sometimes wipe databases during cleanup.
7 min · 1,518 words
A security write-up of a HEIF image-parsing bug chain that could enable repository dumps, Slack RCE, Meta product RCE via image upload, and other authenticated remote code execution paths.
3 min · 696 words
What I learned From Managing a Bug Bounty Program
Aji walks through the real work of running a bug bounty: triage, severity calls that drive payouts, stakeholder management, and the judgment calls that paper workflows omit.
1 min · 324 words
A heap overflow and SSO misconfiguration to compromise OpenAI internal repositories
9 min · 2,047 words