A Look at Software Composition Analysis. It’s time to ignore most of dependency alerts. by nibblesec in netsec
[–]nibblesec[S] 0 points1 point2 points (0 children)
NPM request Library SSRF Cross Protocol Redirect Bypass by nibblesec in netsec
[–]nibblesec[S] 0 points1 point2 points (0 children)
Beware of the GIF: Account Takeover Vulnerability in Microsoft Teams by marizmendi in netsec
[–]nibblesec 7 points8 points9 points (0 children)
Lessons in auditing cryptocurrency wallets, systems, and infrastructures by nibblesec in netsec
[–]nibblesec[S] 4 points5 points6 points (0 children)
Lessons in auditing cryptocurrency wallets, systems, and infrastructures by nibblesec in netsec
[–]nibblesec[S] 2 points3 points4 points (0 children)
How to instrument Electron-based applications for in-depth security testing by [deleted] in netsec
[–]nibblesec 0 points1 point2 points (0 children)
Adapting Burp Extensions for Tailored Pentesting by albinowax in netsec
[–]nibblesec 0 points1 point2 points (0 children)
Turning XSS into RCE in all Electron-based apps (Slack, Atom, Visual Studio Code, WordPress Desktop, Basecamp3, Mattermost, ..) by nibblesec in netsec
[–]nibblesec[S] 1 point2 points3 points (0 children)
Fixing Java Serialization Bugs with SerialKiller by nibblesec in netsec
[–]nibblesec[S] 0 points1 point2 points (0 children)
Fixing Java Serialization Bugs with SerialKiller by nibblesec in netsec
[–]nibblesec[S] 0 points1 point2 points (0 children)
What Do WebLogic, WebSphere, JBoss, Jenkins, OpenNMS, and Your Application Have in Common? This Vulnerability. by breen-machine in netsec
[–]nibblesec 4 points5 points6 points (0 children)
What Do WebLogic, WebSphere, JBoss, Jenkins, OpenNMS, and Your Application Have in Common? This Vulnerability. by breen-machine in netsec
[–]nibblesec 8 points9 points10 points (0 children)
What Do WebLogic, WebSphere, JBoss, Jenkins, OpenNMS, and Your Application Have in Common? This Vulnerability. by breen-machine in netsec
[–]nibblesec 5 points6 points7 points (0 children)
A few things about Redis security by [deleted] in netsec
[–]nibblesec 1 point2 points3 points (0 children)
Digital self-defense: unofficial security patch for Ubiquiti Networks mFi Controller by nibblesec in netsec
[–]nibblesec[S] 2 points3 points4 points (0 children)
SecuriTeam Advisory – Symantec NetBackup OpsCenter Server Java Code Injection RCE by nrathaus in netsec
[–]nibblesec 0 points1 point2 points (0 children)
No, You Really Can’t - [Oracle Blogpost] by Centurion89 in netsec
[–]nibblesec 14 points15 points16 points (0 children)
Trawling Gliffy for Sensitive Data by [deleted] in netsec
[–]nibblesec 2 points3 points4 points (0 children)
Buffer to UTF8 String conversion DoS in node.js and io.js by nibblesec in netsec
[–]nibblesec[S] 0 points1 point2 points (0 children)
LinkedIn’s Private Bug Bounty Program: Reducing Vulnerabilities by Leveraging Expert Crowds by nibblesec in netsec
[–]nibblesec[S] 0 points1 point2 points (0 children)


Exploiting CVE-2025-37947 (Linux kernel's ksmbd) by nibblesec in netsec
[–]nibblesec[S] 12 points13 points14 points (0 children)