Fastmail Fixes CSS Mutation Bugs but Remains Exposed to Hotwiring
Fastmail fixed two CSS mutation bugs and an image-proxy bypass, but CSS hotwiring and other techniques remain a concern for webmail security.
Cybersecurity products, tools, platforms and software categories.
Fastmail fixed two CSS mutation bugs and an image-proxy bypass, but CSS hotwiring and other techniques remain a concern for webmail security.
A Proton Mail vector demonstrated that a proxy bypass could expose the recipient's IP address, contradicting Proton's tracker-protection claims.
A paste race in Yahoo Mail and AOL Mail on Firefox can leak Medium email-login tokens, allowing account takeover.
CSS pseudo-elements and opacity can hide instructions from humans while AI models like OpenAI's Atlas read them, leading to data exfiltration. Atlas…
AOL Mail was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs,…
Rovo is Atlassian's AI assistant that integrates with Jira, Confluence, and third-party apps. It has been found vulnerable to prompt injection attacks…
Jira is Atlassian's project management and issue tracking tool. Data from Jira was targeted in prompt injection attacks against Rovo, potentially exposing…
Confluence is Atlassian's team collaboration and documentation platform. The RovoBlast attack demonstrated exfiltration of private API keys from Confluence, highlighting risks to…
Metabase is a business intelligence and data visualization platform. A critical zero-day vulnerability (CVSS 10.0) allows unauthenticated attackers to inject SQL and…
Okta is a primary target for UNC6671's phishing kits and AitM attacks, with the group using fake Okta login pages to capture…