Ultimate double-clickjacking exploit, novel HTTP/2 request tunnelling techniques, when encryption makes matters worse – ethical hacker news roundup
Summary Roundup: an 'ultimate' double-clickjacking PoC with a fake Cloudflare Captcha and Flappy Bird, underrated HTTP request tunnelling attacks, and a critical OpenPGP.js signature spoofing flaw.
Published 2025-06-20 11:43 Collected 2026-07-21 11:20
original ↗
Related coverage Caido v0.58.0 (caido.io) Rickrolling the World Cup, unleashing AI across Google, 0-click stored XSS on Next.js – ethical hacker roundup (yeswehack.com) ‘AI a force multiplier not a replacement’, small vs large models, the state of vibe-coded security – ethical hacker news roundup (yeswehack.com) The Mythos moment, accelerating exploits, CVE Program under pressure – offsec roundup for CISOs (yeswehack.com) Notepad++ hijack, pwning Claude Code, top web hacking techniques of 2025 – ethical hacker news roundup (yeswehack.com) LLM bug hunters lack intuition, ‘security teams will consolidate visibility’ in 2026, EU Cyber Act vuln disclosure revisions – offsec roundup for CISOs (yeswehack.com)
back