Teenager Awarded $25K Bounty For Finding Stored XSS In Instagram Spark AR

Latest Hacking News-- A teenage researcher was awarded $25,000 as bounty for discovering a flaw affecting Instagram. Specifically, he found a stored XSS Teenager Awarded $25K Bounty For Finding Stored XSS In Instagram Spark AR on Latest Hacking News. View original article on Latest Hacking News

Taking down the SSO, Account Takeover in 3 websites of Kolesa due to Insecure JSONP Call

InfoSec Write-ups - Medium-- Taking down the SSO, Account Takeover in the Websites of Kolesa due to Insecure JSONP CallHello, this post is about how I could take-over any account of Kolesa’s websites using Single Sign-On. There was an insecure JSONP call which could break the security of the entire SSO mechanism.What is JSONP?JSONP is a method … Continue reading Taking down the SSO, Account Takeover in 3 websites of Kolesa due to Insecure JSONP Call

Lock and Code S1Ep15: Investigating digital vulnerabilities in our physical world with Samy Kamkar

Malwarebytes Labs-- This week on Lock and Code, we discuss the top security headlines generated right here on Labs and around the Internet. In addition, we talk to Samy Kamkar, chief security officer and co-founder of Open Path, about the digital vulnerabilities in our physical world. If you look through a recent history of hacking, … Continue reading Lock and Code S1Ep15: Investigating digital vulnerabilities in our physical world with Samy Kamkar