Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Nonce CSP bypass using disk cache, ‘quiet side channel’ for request smuggling, Amazon Q and the malicious pull request – ethical hacker news roundup

Summary

Roundup: Jorian Woltjer's nonce CSP bypass via bfcache and disk cache, d3d's trust-based HTTP smuggling C2 channel, Tracebit's Gemini CLI hijack, and the malicious Amazon Q pull request.
Published
Collected

original ↗

Related coverage

back