Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 03/10/2026"SQLDoom ports the original 1993 Doom's game logic and renderer to SQL and runs it inside CedarDB." GitHub: github.com/cedardb/sqldoom 001
Reposted by Cure53🔓abadidea @0xabad1dea.infosec.exchange.ap.brid.gy · 24/09/2026Postmortem of a little community hobby wiki struggling to survive an extinction-event-tier DDOS purely because they banned one guy for using Claude on the wiki blog.xkeeper.net/the-cutting-room-f… 260106
Reposted by Cure53🔓IntentToShip @intenttoship.dev · 21/09/2026Blink: Intent to Ship: HTML install elementgroups.google.comBlink: Intent to Ship: HTML install elementBlink: Intent to Ship: HTML install element 066
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 20/09/2026RE: infosec.exchange/@lcamtuf/117300984… Our entire team has their lips mutilated and here were are, being made fun of...infosec.exchange 000
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 19/09/2026Phase 1 "project babyfication" has completed successfully. Phase 2 "vampire romance" shall now commence. 100
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 14/09/2026Imagine a Bitcoin walletswritten in pure CSS, who wants to invest??? 🚀 groups.google.com/a/mozilla.org/g/d… 000
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 11/09/2026In recognition of bravery, patriotism and an unwavering love of freedom, we have decided to rename Microsoft Teams as Microsoft America. Please update your SBOM and software directories; this change is immediate and permanent. Thank you for your attention to this matter. 🦅 001
Reposted by Cure53🔓daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 10/09/2026Open Call for Nominations: European Open Source Awards 2027 Please consider taking a minute and tell us who we should recognize and honor this time around! We need to know about the heroes to be able to celebrate them. awards.europeanopensource.academy/n… 159
Reposted by Cure53🔓Manuel 'HonkHase' Atug @honkhase.chaos.social.ap.brid.gy · 10/09/2026Der bundesweite Warntag war heite um 11 Uhr und Entwarnung um 11:45 Uhr. Habt ihr die Meldung auf dem Handy erhalten? Habt ihr die Sirenen gehört? Nur durch eurer Feedback kann es verbessert werden! Online-Umfrage zum Bundesweiten Warntag 2026 vom @bbk www.warntag-umfrage.de 2121
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 09/09/2026A machine pretending to be a human writes a letter to a human, who really doesn't want to read it and sends it to another machine pretending to be a human, so it can write the human-like reponse to the other machine pretending to be human, on behalf of the actual human. Seems a bit inefficient […]infosec.exchangeOriginal post on infosec.exchange 010
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 09/09/2026Are there more people in the penetration testing business who are flooded with emails from AI agents wanting to negotiate scope and purchase a penetration test? Over the past few weeks, we have received a lot of them - and I mean A LOT - each wilder than the last. Almost all of the emails are […]infosec.exchangeOriginal post on infosec.exchange 103
Reposted by Cure53🔓tante @tante.tldr.nettime.org.ap.brid.gy · 14/07/2026A computer booting Windows 1.0 and DOOM emulated using just CSS (Original title: CSS-DOS — A computer made of CSS) css-dos.ahmedamer.co.ukcss-dos.ahmedamer.co.ukCSS-DOS — A computer made of CSS 111
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 04/07/2026RE: mastodon.social/@gwynnion/116859269… Is this a post about LLMs?mastodon.social 000
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 02/07/2026We built a small project to inject Trusted Types enforcing sanitizer use for all HTML sinks. Without changing any of the insecure code. github.com/cure53/DOMFortify Maybe it is useful for someone, especially when having to maintain an older site with too many DOMXSS sinks to fix manually.github.comGitHub - cure53/DOMFortify: DOMFortify turns on Trusted Types for a page and quietly takes over the browser's default policy, so that old, vulnerable HTML sinks get auto-sanitized before bad markup ever hits the DOM.DOMFortify turns on Trusted Types for a page and quietly takes over the browser's default policy, so that old, vulnerable HTML sinks get auto-sanitized before bad markup ever hits the DOM. - cu... 200
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 01/07/2026During July & August, we will continue to accept security bug reports for DOMPurify. If anything serious is found, we will patch it immediately and release an update. As always. We call this approach the 'summer of responsible OSS maintenance' and prefer it to ignoring security bugs and […]infosec.exchangeOriginal post on infosec.exchange 000
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 28/06/2026RE: mastodon.online/@mullvadnet/1168222… What a shitty response, shame on you. Coming here and talking about values? Really? Here are the values of the guy your co-whatever is funding, just for the record: en.wikipedia.org/wiki/Markus_Allardmastodon.online 000
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 25/06/2026RE: mas.to/@patrickbrosset/116809815574… 🙏🏻 exciting new scripting abilities 🙏🏻 no more boring SOP 🙏🏻 CSS from <img> to style entire page 🙏🏻 big comeback for embedded Java Applets 🙏🏻 SVGZ and ActiveX while we're at itmas.to 111
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 23/06/2026We updated our public report repository and there is now lots of new material. Here you are, meanwhile 253 pentest reports, summary reports and papers: github.com/cure53/Publications/tree… 000
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 18/06/2026Crazy to see that some folks still get paid their salary in money instead of LLM tokens. They gonna spend the money on tokens anyway, why waste time on legacy payment methods from yesteryear?? 010
Reposted by Cure53🔓Tom Stafford @tomstafford.mastodon.online.ap.brid.gy · 02/06/2026Fedizens! Please send me your favourite meme which shows something important about the #Fediverse I'll go first: 3039211
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 16/06/2026We proudly present — DOMPurify 4.0.0 — the first purely agentic sanitizer 🤖🧼✨ No more rules — no more regex — no more deterministic boredom — Only adaptive intelligence — autonomous decisions — AI-powered sanitation — and the future of XSS prevention — right here — right now 🚀 […]infosec.exchangeOriginal post on infosec.exchange 001
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 16/06/2026RE: cyberplace.social/@GossiTheDog/1167… We heard that Twitter/X too is critical for national security and folks outside the US should no longer be able to use it. Facebook as well, no? #securityfirstcyberplace.social 000
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 15/06/2026Future releases will no longer be able to ignore STML, <ssafe> and the so far quite unknown </lml>. Guess the cat is out of the bag now. This is technically a toot about cats 🐱 010
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 15/06/2026What the f*ck is this now, where do those pages come from? dompurify.org And who creates this... art? dompurify.org/wp-content/uploads/20…dompurify.orgDOMPurify – Super‑fast XSS sanitizer for secure HTML, MathML, and SVG contentProtect websites with DOMPurify, a fast XSS sanitizer securing HTML, MathML, and SVG content for safer apps and clean input everywhere. 100
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 15/06/2026RE: mastodon.social/@bagder/11675257858… 🤨 000
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 12/06/2026Small field update... in the past weeks we have seen. * 10+ requests for audits against vibe-coded crypto software & messenger * 1 request for an audit against vibe-coded medical software * 1 request to only use LLMs for audits as there is allegedly too much code for any human to review * […]infosec.exchangeOriginal post on infosec.exchange 000
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 12/06/2026DOMPurify 3.4.10 is out, mostly refactoring, should be a bit faster, and a bit more robust. Lots of new tests, documentation etc. Long time to LLM-reported bypasses, maybe things are slowly calming down and we managed to address all exotic config options leading to foot-guns? 🤞🍀 😅 […]infosec.exchangeOriginal post on infosec.exchange 010
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 06/06/2026RE: infosec.exchange/@catsalad/11670237… Ma! Yo! There's a stray cat outsideinfosec.exchange 002
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 05/06/2026The great thing about LLMs is that they make it possible for anyone to create a crypto messenger. All you need is passion and a few tokens. Mega-corporations like Signal can no longer gatekeep and monopolise using their powers - it's finally power to the people! 000
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 28/05/2026RE: hachyderm.io/@evilpie/1166523877051… Here is how it all started, like, sort of 😅 www.youtube.com/watch?v=KIRvxYqk_Wchachyderm.io 000
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 27/05/2026RE: infosec.exchange/@timb_machine/1166… This. It's is mostly where our last three to four weeks have spent with for DOMPurify... 000
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 27/05/2026DOMPurify 3.4.7 is out with again several in-depth improvements. If you are using the IN_PLACE config option in production, you might want to go for this one soonish. This is where folks seem to use their Claude tokens for at the moment 😅 github.com/cure53/DOMPurify/release…github.comRelease DOMPurify 3.4.7 · cure53/DOMPurifyHardened the handling of Shadow Roots when using IN_PLACE, thanks @GameZoneHacker Removed a problem leading to permanent hook pollution, thanks @offset Refactored the test suite and expanded test c... 000
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 19/05/2026You probably not gonna like this, yet somewhat might have anticipated... We are seeing a stark influx in requests to audit vibe-coded cryptography. So, vibe-crypto is a thing and will be one for a while. Do what now? 211
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 19/05/2026DOMPurify XSS via `selectedcontent` re-clone github.com/cure53/DOMPurify/securit… This is one of the most interesting bypasses we have seen in a long time, and it feels that this new HTML element will cause lots of trouble in the future.github.comDOMPurify XSS via `selectedcontent` re-clone### Summary DOMPurify 3.4.4 allows `selectedcontent` by default, allowing a chain in which browsers "re-clone" an XSS payload after sanitization, effectively bypassing DOMPurify. ### Details ... 001
Reposted by Cure53🔓nosfe @nosfe.kamu.social.ap.brid.gy · 18/05/2026@mespique the magic is explained here hellmood.111mb.de//wake_up_16b_writ…hellmood.111mb.deWriteUp: 16 Bytes of x86 that turn Matrix rain into soundComments 001
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 18/05/2026Here's a brief overview of the timeline: Yesterday afternoon (CEST), DOMPurify 3.4.4 was released, which allowed the tag <selectedcontent> by default. At 4am CEST today, an email informing us about the bypass was sent by the finder. The <selectedcontent> tag is dangerous and cannot be […]infosec.exchangeOriginal post on infosec.exchange 000
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 18/05/2026🚨 DOMPurify 3.4.5 is out, fixing a bypass caused by the <selectedcontent> element, affecting Blink. 🚨 The bypass was reported this morning and a fix release was pushed immediately. github.com/cure53/DOMPurify/release… The DOMPurify 3.4.4 release has been deprecated, an […]infosec.exchangeOriginal post on infosec.exchange 000
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 18/05/2026Turns out, the <selectedcontent> element is dangerous. 001
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 17/05/2026DOMPurify 3.4.4 is out with again several small in-depth improvements. These include added stability for IN_PLACE sanitization, improved handling of cross-realm nodes and several newly permitted elements and attributes. github.com/cure53/DOMPurify/release…github.comRelease DOMPurify 3.4.4 · cure53/DOMPurifyAdded the selectedcontent element to default allow-list, thanks @lukewarlow Added the command and commandfor attributes to default allowed-list, thanks @lukewarlow Added better template scrubbing f... 000
Reposted by Cure53🔓Emma Zühlcke @emz.chaos.social.ap.brid.gy · 14/05/2026I’ve written a bunch of browser interventions / quirks myself. It’s fun, but it doesn’t scale. You can only do this for really big sites. denodell.com/blog/browsers-treat-bi…denodell.comBrowsers Treat Big Sites DifferentlySafari and Firefox change how big sites render based on the domain. TikTok, Netflix, Instagram… even SeatGuru. Chrome doesn’t. Why is that? 027
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 13/05/2026DOMPurify 3.4.3 is out with several smaller improvements. Among them, more robust regex for template scrubbing, better handling of nested Shadow DOM structures, test matrix support for Node 26. github.com/cure53/DOMPurify/release…github.comRelease DOMPurify 3.4.3 · cure53/DOMPurifyFixed an issue with handling of nested Shadow DOM trees, thanks @fishjojo1 Fixed the template regexes to be more robust against ReDoS attacks, thanks @aleung27 Updated the node iteration code to ca... 010
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 12/05/2026RE: mstdn.social/@mcnado/11655886919119… Of course, Ivermectin will NOT work against Hantavirus. Unless, that is, you mix it with industry-grade household bleach. Doctors hate this simple trick.mstdn.social 010
Reposted by Cure53🔓tante @tante.tldr.nettime.org.ap.brid.gy · 07/05/2026"There are no more juniors. There was a funeral for their passing in 2024. Nobody came. The machine does what they do now, but cheaper. Of course, juniors weren't valuable for what they produced, they were valuable for who they would become: the senior engineer who knows where the bodies are […]tldr.nettime.orgOriginal post on tldr.nettime.org 2774
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 21/04/2026DOMPurify 3.4.1 is out with lots of small improvements. Among them, a better test suite, a small fuzzer, several fixes and hardenings, and as usually we hope all went well 😅 github.com/cure53/DOMPurify/release…github.comRelease DOMPurify 3.4.1 · cure53/DOMPurifyFixed an issue with on-handler stripping for HTML-spec-reserved custom element names (font-face, color-profile, missing-glyph, font-face-src, font-face-uri, font-face-format, font-face-name) under ... 020
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 21/04/2026We're already seeing a spike in AI-generated PRs making the ecosystem much more secure. Words cannot describe how grateful we are for all the contributions. 010
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 20/04/2026To all the OSS projects getting swamped by AI tickets right now... IT IS TOTALLY YOUR OWN FAULT. The easy fix is to write better code. You are welcome, this advice was free. *ducks* 010
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 17/04/2026In anticipation of possibly upcoming waves of OSS bugs as well maybe increasing amounts of real attacks, we have been busy hardening DOMPurify. Look at those shiny badges and improvements, LOOK OMG 😱 github.com/cure53/dompurify?tab=rea… Work in progress of course […]infosec.exchangeOriginal post on infosec.exchange 010
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 14/04/2026Version 3.4.0 of DOMPurify was released today, addressing a large number of issues reported by LLMs and real people alike. Thanks to all who contributed. github.com/cure53/DOMPurify/release… We hope everything went smoothly and that no one was overlooked in the release notes.github.comRelease DOMPurify 3.4.0 · cure53/DOMPurifyMost relevant changes: Fixed a problem with FORBID_TAGS not winning over ADD_TAGS, thanks @kodareef5 Fixed several minor problems and typos regarding MathML attributes, thanks @DavidOliver Fixed A... 000
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 12/04/2026Wondering if anyone has reliable info on the following and would like to share it. Grok, the LLM used by X, now seems to claim that E. Musk never sent any inflammatory messages on June 5 2025 about Trump's involvement on Epstein's Island. Which he probably did. We cannot fact-check this as we […]infosec.exchangeOriginal post on infosec.exchange 100