Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
chillax
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
31.
▲
Azure's Weakest Link – Full Cross-Tenant Compromise
(binarysecurity.no)
1 points
by
chillax
1y ago
|
0 comments
32.
▲
by
chillax
1y ago
Possible the UK version of this? https://vat-one-stop-shop.ec.europa.eu/index_en
33.
▲
The Great SSL Certificate Panic
(redmonk.com)
22 points
by
chillax
1y ago
|
11 comments
34.
▲
Amazon Q Developer: Secrets Leaked via DNS and Prompt Injection
(embracethered.com)
3 points
by
chillax
1y ago
|
0 comments
35.
▲
Welcome to the IPv4 Games
(ipv4.games)
55 points
by
chillax
1y ago
|
29 comments
36.
▲
Meetingco.st – How much does that meeting cost?
(meetingco.st)
2 points
by
chillax
1y ago
|
0 comments
37.
▲
WAF Detector – For Detecting and Testing Web Application Firewalls (WAFs), CDNs
(github.com)
3 points
by
chillax
1y ago
|
0 comments
38.
▲
BaxBench: Can LLMs Generate Secure and Correct Back Ends?
(baxbench.com)
2 points
by
chillax
1y ago
|
1 comments
39.
▲
Remote Prompt Injection in Gitlab Duo Leads to Source Code Theft
(legitsecurity.com)
214 points
by
chillax
1y ago
|
54 comments
40.
▲
by
chillax
1y ago
Probably refering to CRA - Cyber Resilience Act https://schjodt.com/news/the-cyber-resilience-act-enters-int... https://digital-strategy.ec.europa.eu/en/policies/cyber-resi... https:/&#
41.
▲
GitHub Copilot and Cursor: How Hackers Can Weaponize Code Agents
(pillar.security)
1 points
by
chillax
2y ago
|
0 comments
42.
▲
Azure's Weakest Link? How API Connections Spill Secrets
(binarysecurity.no)
3 points
by
chillax
2y ago
|
0 comments
43.
▲
8M Requests Later,We Made the SolarWinds Supply Chain Attack Look Amateur
(labs.watchtowr.com)
1 points
by
chillax
2y ago
|
0 comments
44.
▲
Top web hacking techniques of 2024
(portswigger.net)
3 points
by
chillax
2y ago
|
0 comments
45.
▲
by
chillax
2y ago
A better link would be the dedicated site for it, also contains introduction which describes what NHI are: https://owasp.org/www-project-non-human-identities-top-10/20...
46.
▲
by
chillax
2y ago
Here is how OWASP define it: > Non-human identities (NHIs) are used to provide authorization to software entities such as applications, APIs, bots, and automated systems to access secured resources. Unlike human identities, NHIs are not
47.
▲
Stealing HttpOnly cookies with the cookie sandwich technique
(portswigger.net)
6 points
by
chillax
2y ago
|
0 comments
48.
▲
Backdooring Your Backdoors – Another $20 Domain, More Governments
(labs.watchtowr.com)
5 points
by
chillax
2y ago
|
0 comments
49.
▲
September 2024 Progress Update on Microsoft's Secure Future Initiative (SFI)
(microsoft.com)
1 points
by
chillax
2y ago
|
0 comments
50.
▲
Hello eBPF: Building a Fast Firewall with Java and eBPF (14)
(mostlynerdless.de)
2 points
by
chillax
2y ago
|
0 comments
51.
▲
Listen to the whispers: web timing attacks that work
(portswigger.net)
3 points
by
chillax
2y ago
|
0 comments
52.
▲
Single-packet race condition breaking the 65535 byte lim
(flatt.tech)
93 points
by
chillax
2y ago
|
31 comments
53.
▲
Ducks Now Sitting (DNS): Internet Infrastructure Insecurity
(eclypsium.com)
2 points
by
chillax
2y ago
|
0 comments
54.
▲
Exploiting Client-Side Path Traversal to Perform CSRF – Introducing CSPT2CSRF
(blog.doyensec.com)
1 points
by
chillax
2y ago
|
0 comments
55.
▲
Phantom Secrets: Undetected Secrets Expose Major Corporations
(aquasec.com)
2 points
by
chillax
2y ago
|
0 comments
56.
▲
Encryption at Rest: Whose Threat Model Is It Anyway?
(scottarc.blog)
199 points
by
chillax
2y ago
|
168 comments
57.
▲
GitHub Self-Service Automation: Introduction to Repoman and Release
(o3c.no)
1 points
by
chillax
2y ago
|
0 comments
58.
▲
Java Scoped Values: Better ThreadLocals
(realjenius.com)
2 points
by
chillax
2y ago
|
0 comments
59.
▲
HTTP/2 Continuation Flood
(nowotarski.info)
2 points
by
chillax
3y ago
|
0 comments
60.
▲
Kobold letters: HTML emails are a risk
(lutrasecurity.com)
337 points
by
chillax
3y ago
|
136 comments
More ›