Sign in

Cure53🔓

@cure53.infosec.exchange.ap.brid.gy
37 followers 2 following 78 posts

And there is fire where we walk. 🌉 bridged from ⁂ infosec.exchange/@cure53, follow @ap.brid.gy to interact

PostsRepliesMedia
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 03/10/2026
"SQLDoom ports the original 1993 Doom's game logic and renderer to SQL and runs it inside CedarDB." GitHub: github.com/cedardb/sqldoom
001
Reposted by Cure53🔓
abadidea @0xabad1dea.infosec.exchange.ap.brid.gy · 24/09/2026
Postmortem of a little community hobby wiki struggling to survive an extinction-event-tier DDOS purely because they banned one guy for using Claude on the wiki blog.xkeeper.net/the-cutting-room-f…
260106
Reposted by Cure53🔓
IntentToShip @intenttoship.dev · 21/09/2026
Blink: Intent to Ship: HTML install element
groups.google.com
Blink: Intent to Ship: HTML install element
Blink: Intent to Ship: HTML install element
066
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 20/09/2026
RE: infosec.exchange/@lcamtuf/117300984… Our entire team has their lips mutilated and here were are, being made fun of...
infosec.exchange
000
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 19/09/2026
Phase 1 "project babyfication" has completed successfully. Phase 2 "vampire romance" shall now commence.
100
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 14/09/2026
Imagine a Bitcoin walletswritten in pure CSS, who wants to invest??? 🚀 groups.google.com/a/mozilla.org/g/d…
000
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 11/09/2026
In recognition of bravery, patriotism and an unwavering love of freedom, we have decided to rename Microsoft Teams as Microsoft America. Please update your SBOM and software directories; this change is immediate and permanent. Thank you for your attention to this matter. 🦅
001
Reposted by Cure53🔓
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 10/09/2026
Open Call for Nominations: European Open Source Awards 2027 Please consider taking a minute and tell us who we should recognize and honor this time around! We need to know about the heroes to be able to celebrate them. awards.europeanopensource.academy/n…
159
Reposted by Cure53🔓
Manuel 'HonkHase' Atug @honkhase.chaos.social.ap.brid.gy · 10/09/2026
Der bundesweite Warntag war heite um 11 Uhr und Entwarnung um 11:45 Uhr. Habt ihr die Meldung auf dem Handy erhalten? Habt ihr die Sirenen gehört? Nur durch eurer Feedback kann es verbessert werden! Online-Umfrage zum Bundesweiten Warntag 2026 vom @bbk www.warntag-umfrage.de
NINA WarnApp Mock up
2121
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 09/09/2026
A machine pretending to be a human writes a letter to a human, who really doesn't want to read it and sends it to another machine pretending to be a human, so it can write the human-like reponse to the other machine pretending to be human, on behalf of the actual human. Seems a bit inefficient […]
infosec.exchange
Original post on infosec.exchange
010
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 09/09/2026
Are there more people in the penetration testing business who are flooded with emails from AI agents wanting to negotiate scope and purchase a penetration test? Over the past few weeks, we have received a lot of them - and I mean A LOT - each wilder than the last. Almost all of the emails are […]
infosec.exchange
Original post on infosec.exchange
103
Reposted by Cure53🔓
tante @tante.tldr.nettime.org.ap.brid.gy · 14/07/2026
A computer booting Windows 1.0 and DOOM emulated using just CSS (Original title: CSS-DOS — A computer made of CSS) css-dos.ahmedamer.co.uk
css-dos.ahmedamer.co.uk
CSS-DOS — A computer made of CSS
111
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 04/07/2026
RE: mastodon.social/@gwynnion/116859269… Is this a post about LLMs?
mastodon.social
000
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 02/07/2026
We built a small project to inject Trusted Types enforcing sanitizer use for all HTML sinks. Without changing any of the insecure code. github.com/cure53/DOMFortify Maybe it is useful for someone, especially when having to maintain an older site with too many DOMXSS sinks to fix manually.
github.com
GitHub - cure53/DOMFortify: DOMFortify turns on Trusted Types for a page and quietly takes over the browser's default policy, so that old, vulnerable HTML sinks get auto-sanitized before bad markup ever hits the DOM.
DOMFortify turns on Trusted Types for a page and quietly takes over the browser's default policy, so that old, vulnerable HTML sinks get auto-sanitized before bad markup ever hits the DOM. - cu...
200
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 01/07/2026
During July & August, we will continue to accept security bug reports for DOMPurify. If anything serious is found, we will patch it immediately and release an update. As always. We call this approach the 'summer of responsible OSS maintenance' and prefer it to ignoring security bugs and […]
infosec.exchange
Original post on infosec.exchange
000
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 28/06/2026
RE: mastodon.online/@mullvadnet/1168222… What a shitty response, shame on you. Coming here and talking about values? Really? Here are the values of the guy your co-whatever is funding, just for the record: en.wikipedia.org/wiki/Markus_Allard
mastodon.online
000
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 25/06/2026
RE: mas.to/@patrickbrosset/116809815574… 🙏🏻 exciting new scripting abilities 🙏🏻 no more boring SOP 🙏🏻 CSS from <img> to style entire page 🙏🏻 big comeback for embedded Java Applets 🙏🏻 SVGZ and ActiveX while we're at it
mas.to
111
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 23/06/2026
We updated our public report repository and there is now lots of new material. Here you are, meanwhile 253 pentest reports, summary reports and papers: github.com/cure53/Publications/tree…
000
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 18/06/2026
Crazy to see that some folks still get paid their salary in money instead of LLM tokens. They gonna spend the money on tokens anyway, why waste time on legacy payment methods from yesteryear??
010
Reposted by Cure53🔓
Tom Stafford @tomstafford.mastodon.online.ap.brid.gy · 02/06/2026
Fedizens! Please send me your favourite meme which shows something important about the #Fediverse I'll go first:
Star wars meme. Empire soldier land to interrogate the retired general. "Mastodon? Really? Man of your talents?". He replies: "It's a peaceful life"

From: https://knowyourmeme.com/memes/its-a-peaceful-life

"It's a Peaceful Life, also known as Really? Man Of Your Talents?, is a reaction image and image macro meme format using a scene from the 2016 film Rogue One: A Star Wars Story in which the character Galen Erso (played by actor Mads Mikkelsen) tells Orson Krennic (Ben Mendelsohn), "It's a peaceful life," after Krennic expresses pitiful shock that Erso is a farmer"
3039211
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 16/06/2026
We proudly present — DOMPurify 4.0.0 — the first purely agentic sanitizer 🤖🧼✨ No more rules — no more regex — no more deterministic boredom — Only adaptive intelligence — autonomous decisions — AI-powered sanitation — and the future of XSS prevention — right here — right now 🚀 […]
infosec.exchange
Original post on infosec.exchange
001
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 16/06/2026
RE: cyberplace.social/@GossiTheDog/1167… We heard that Twitter/X too is critical for national security and folks outside the US should no longer be able to use it. Facebook as well, no? #securityfirst
cyberplace.social
000
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 15/06/2026
Future releases will no longer be able to ignore STML, <ssafe> and the so far quite unknown </lml>. Guess the cat is out of the bag now. This is technically a toot about cats 🐱
More slop, in DOMPurify context. The toot has the highlights.
010
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 15/06/2026
What the f*ck is this now, where do those pages come from? dompurify.org And who creates this... art? dompurify.org/wp-content/uploads/20…
dompurify.org
DOMPurify – Super‑fast XSS sanitizer for secure HTML, MathML, and SVG content
Protect websites with DOMPurify, a fast XSS sanitizer securing HTML, MathML, and SVG content for safer apps and clean input everywhere.
100
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 15/06/2026
RE: mastodon.social/@bagder/11675257858… 🤨
000
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 12/06/2026
Small field update... in the past weeks we have seen. * 10+ requests for audits against vibe-coded crypto software & messenger * 1 request for an audit against vibe-coded medical software * 1 request to only use LLMs for audits as there is allegedly too much code for any human to review * […]
infosec.exchange
Original post on infosec.exchange
000
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 12/06/2026
DOMPurify 3.4.10 is out, mostly refactoring, should be a bit faster, and a bit more robust. Lots of new tests, documentation etc. Long time to LLM-reported bypasses, maybe things are slowly calming down and we managed to address all exotic config options leading to foot-guns? 🤞🍀 😅 […]
infosec.exchange
Original post on infosec.exchange
010
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 06/06/2026
RE: infosec.exchange/@catsalad/11670237… Ma! Yo! There's a stray cat outside
infosec.exchange
002
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 05/06/2026
The great thing about LLMs is that they make it possible for anyone to create a crypto messenger. All you need is passion and a few tokens. Mega-corporations like Signal can no longer gatekeep and monopolise using their powers - it's finally power to the people!
000
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 28/05/2026
RE: hachyderm.io/@evilpie/1166523877051… Here is how it all started, like, sort of 😅 www.youtube.com/watch?v=KIRvxYqk_Wc
hachyderm.io
000
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 27/05/2026
RE: infosec.exchange/@timb_machine/1166… This. It's is mostly where our last three to four weeks have spent with for DOMPurify...
000
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 27/05/2026
DOMPurify 3.4.7 is out with again several in-depth improvements. If you are using the IN_PLACE config option in production, you might want to go for this one soonish. This is where folks seem to use their Claude tokens for at the moment 😅 github.com/cure53/DOMPurify/release…
github.com
Release DOMPurify 3.4.7 · cure53/DOMPurify
Hardened the handling of Shadow Roots when using IN_PLACE, thanks @GameZoneHacker Removed a problem leading to permanent hook pollution, thanks @offset Refactored the test suite and expanded test c...
000
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 19/05/2026
You probably not gonna like this, yet somewhat might have anticipated... We are seeing a stark influx in requests to audit vibe-coded cryptography. So, vibe-crypto is a thing and will be one for a while. Do what now?
211
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 19/05/2026
DOMPurify XSS via `selectedcontent` re-clone github.com/cure53/DOMPurify/securit… This is one of the most interesting bypasses we have seen in a long time, and it feels that this new HTML element will cause lots of trouble in the future.
github.com
DOMPurify XSS via `selectedcontent` re-clone
### Summary DOMPurify 3.4.4 allows `selectedcontent` by default, allowing a chain in which browsers "re-clone" an XSS payload after sanitization, effectively bypassing DOMPurify. ### Details ...
001
Reposted by Cure53🔓
nosfe @nosfe.kamu.social.ap.brid.gy · 18/05/2026
@mespique the magic is explained here hellmood.111mb.de//wake_up_16b_writ…
hellmood.111mb.de
WriteUp: 16 Bytes of x86 that turn Matrix rain into sound
Comments
001
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 18/05/2026
Here's a brief overview of the timeline: Yesterday afternoon (CEST), DOMPurify 3.4.4 was released, which allowed the tag <selectedcontent> by default. At 4am CEST today, an email informing us about the bypass was sent by the finder. The <selectedcontent> tag is dangerous and cannot be […]
infosec.exchange
Original post on infosec.exchange
000
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 18/05/2026
🚨 DOMPurify 3.4.5 is out, fixing a bypass caused by the <selectedcontent> element, affecting Blink. 🚨 The bypass was reported this morning and a fix release was pushed immediately. github.com/cure53/DOMPurify/release… The DOMPurify 3.4.4 release has been deprecated, an […]
infosec.exchange
Original post on infosec.exchange
000
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 18/05/2026
Turns out, the <selectedcontent> element is dangerous.
001
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 17/05/2026
DOMPurify 3.4.4 is out with again several small in-depth improvements. These include added stability for IN_PLACE sanitization, improved handling of cross-realm nodes and several newly permitted elements and attributes. github.com/cure53/DOMPurify/release…
github.com
Release DOMPurify 3.4.4 · cure53/DOMPurify
Added the selectedcontent element to default allow-list, thanks @lukewarlow Added the command and commandfor attributes to default allowed-list, thanks @lukewarlow Added better template scrubbing f...
000
Reposted by Cure53🔓
Emma Zühlcke @emz.chaos.social.ap.brid.gy · 14/05/2026
I’ve written a bunch of browser interventions / quirks myself. It’s fun, but it doesn’t scale. You can only do this for really big sites. denodell.com/blog/browsers-treat-bi…
denodell.com
Browsers Treat Big Sites Differently
Safari and Firefox change how big sites render based on the domain. TikTok, Netflix, Instagram… even SeatGuru. Chrome doesn’t. Why is that?
027
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 13/05/2026
DOMPurify 3.4.3 is out with several smaller improvements. Among them, more robust regex for template scrubbing, better handling of nested Shadow DOM structures, test matrix support for Node 26. github.com/cure53/DOMPurify/release…
github.com
Release DOMPurify 3.4.3 · cure53/DOMPurify
Fixed an issue with handling of nested Shadow DOM trees, thanks @fishjojo1 Fixed the template regexes to be more robust against ReDoS attacks, thanks @aleung27 Updated the node iteration code to ca...
010
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 12/05/2026
RE: mstdn.social/@mcnado/11655886919119… Of course, Ivermectin will NOT work against Hantavirus. Unless, that is, you mix it with industry-grade household bleach. Doctors hate this simple trick.
mstdn.social
010
Reposted by Cure53🔓
tante @tante.tldr.nettime.org.ap.brid.gy · 07/05/2026
"There are no more juniors. There was a funeral for their passing in 2024. Nobody came. The machine does what they do now, but cheaper. Of course, juniors weren't valuable for what they produced, they were valuable for who they would become: the senior engineer who knows where the bodies are […]
tldr.nettime.org
Original post on tldr.nettime.org
2774
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 23/04/2026
We did not expect that back in 2014 🥹
An NPM badge showing 150M downloads per month.
010
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 21/04/2026
DOMPurify 3.4.1 is out with lots of small improvements. Among them, a better test suite, a small fuzzer, several fixes and hardenings, and as usually we hope all went well 😅 github.com/cure53/DOMPurify/release…
github.com
Release DOMPurify 3.4.1 · cure53/DOMPurify
Fixed an issue with on-handler stripping for HTML-spec-reserved custom element names (font-face, color-profile, missing-glyph, font-face-src, font-face-uri, font-face-format, font-face-name) under ...
020
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 21/04/2026
We're already seeing a spike in AI-generated PRs making the ecosystem much more secure. Words cannot describe how grateful we are for all the contributions.
010
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 20/04/2026
To all the OSS projects getting swamped by AI tickets right now... IT IS TOTALLY YOUR OWN FAULT. The easy fix is to write better code. You are welcome, this advice was free. *ducks*
A picture of ye olde Lisp developer John McCarthy looking at developers and telling them how it is.
010
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 17/04/2026
In anticipation of possibly upcoming waves of OSS bugs as well maybe increasing amounts of real attacks, we have been busy hardening DOMPurify. Look at those shiny badges and improvements, LOOK OMG 😱 github.com/cure53/dompurify?tab=rea… Work in progress of course […]
infosec.exchange
Original post on infosec.exchange
010
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 14/04/2026
Version 3.4.0 of DOMPurify was released today, addressing a large number of issues reported by LLMs and real people alike. Thanks to all who contributed. github.com/cure53/DOMPurify/release… We hope everything went smoothly and that no one was overlooked in the release notes.
github.com
Release DOMPurify 3.4.0 · cure53/DOMPurify
Most relevant changes: Fixed a problem with FORBID_TAGS not winning over ADD_TAGS, thanks @kodareef5 Fixed several minor problems and typos regarding MathML attributes, thanks @DavidOliver Fixed A...
000
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 12/04/2026
Wondering if anyone has reliable info on the following and would like to share it. Grok, the LLM used by X, now seems to claim that E. Musk never sent any inflammatory messages on June 5 2025 about Trump's involvement on Epstein's Island. Which he probably did. We cannot fact-check this as we […]
infosec.exchange
Original post on infosec.exchange
100