ZERO DAILY

Hacking, AppSec, and Bug Bounty newsletter

2018-01-02 | AdThink and OnAudience, New year - new rules, and DOM XSS in Facebook mobile

Tuesday, January 2

Greetings, 2018.

TOP STORY

  • AdThink and OnAudience: Web trackers exploit browser login managers. Princeton researchers Gunes Acar, Steven Englehardt, and Arvind Narayanan reveal how a long-known vulnerability in browsers’ built-in password managers is abused by third-party scripts for tracking on more than a thousand sites.

WHILE WE WERE AWAY...

@uraniumhacker shared a blog on an RCE that was recently found on Yahoo, @magoo went through all CA data breach notifications this year and categorized them, @shubs and @alexstamos talk about how NOT to win bug bounties, @nahamsec shared DOM XSS in Facebook Mobile Site, @insitusec published a vulnerability disclosure cheat sheet, @briankrebs says there’s a positive side-effect of BTC fluctuations, and @jobertabma shared a recon trick.  

Notable reports: 255510, 284155, & 272997.  

You can see all the latest and greatest disclosures and bounties on www.hackerone.com/hacktivity

TWEET OF THE DAY

OTHER ARTICLES WE’RE READING

ABOUT ZERO DAILY

Zero Daily is a daily newsletter that highlights application security, bug bounty, and hacker focused topics. The content is curated with love by @luketucker and brought to you by HackerOne.

Friends don’t keep good things to themselves - forward this to your homies and co-workers. BTW, want to see who runs bug bounties?

Have a news tip / story to highlight? We’d love to hear about it. Email: zerodaily@hackerone.com

Get this email forwarded to you? Click here to subscribe to the Zero Daily

 

We should never accept this systemic insecurity as the new normal.

UpGuard co-founder Mike Baukes