Dass sich (KI-)Bots im Open-Data-Portal tummeln, ist nichts Neues. Doch heute ist mir ein besonders merkwürdiger Fall begegnet, über den ich berichten möchte.

Dass sich (KI-)Bots im Open-Data-Portal tummeln, ist nichts Neues. Doch heute ist mir ein besonders merkwürdiger Fall begegnet, über den ich berichten möchte.
CRITICAL stored XSS (CVE-2025-54298) in firecoders.com CommentBox for Joomla v1.0.0-1.1.0. Unauthenticated attackers can inject scripts—risking session hijack & data theft. Disable the plugin & deploy WAF/CSP asap! https://radar.offseq.com/threat/cve-2025-54298-cwe-79-improper-neutralization-of-i-f4298df0 #OffSeq #Joomla #XSS #WebSecurity
OpenAI’s ChatGPT Agent casually clicks through “I am not a robot” verification test - Maybe they should change the button to say, "I am a robot"?
... - https://arstechnica.com/information-technology/2025/07/openais-chatgpt-agent-casually-clicks-through-i-am-not-a-robot-verification-test/ #computer-usingagent #aidevelopmenttools #computerusemodel #machinelearning #authentication #websecurity #aibehavior #aisecurity #cloudflare #agenticai #aiagents #captcha #chatgpt #biz #openai #ai
New Open-Source Tool Spotlight
PrivateBin is a minimalist, open-source pastebin alternative where data is encrypted in the browser before uploading. The server never sees plaintext, ensuring full confidentiality. Ideal for sharing sensitive info securely. #WebSecurity #Encryption
Project link on #GitHub
https://github.com/PrivateBin/PrivateBin
#Infosec #Cybersecurity #Software #Technology #News #CTF #Cybersecuritycareer #hacking #redteam #blueteam #purpleteam #tips #opensource #cloudsecurity
— P.S. Found this helpful? Tap Follow for more cybersecurity tips and insights! I share weekly content for professionals and people who want to get into cyber. Happy hacking
I'll be at DEF CON and Google 0x0g in a couple of weeks. Hit me up if you want to chat about browser/web/extension security and privacy.
It's my first DEF CON, so quite excited! I expect to be most of Friday at the Bug Bounty Village.
I no longer rely on Jetpack Protect. Instead, I’ve built a lean, hardened WordPress security stack using mod_security, Fail2Ban, WPScan, and a few carefully configured rules. No black boxes. No bloat. Just tools I trust.
#WordPress #Infosec #SelfHosting #WebSecurity #JetpackProtect #Fail2Ban #modSecurity #WPScan
https://islandinthenet.com/building-my-own-wordpress-security-stack/
Unpopular opinion: to illustrate the presence of a #websecurity vulnerability, security researchers should rely, not on Rick Hastley's "Never Gonna Give You Up", but on Herb Alpert & the Tijuana Brass's "Spanish Flea". Way funnier!
"We take security and privacy very seriously."
have long become code words for
"We won't bother fixing vulnerabilities that are reported to us."
Cloudflare Slams the Gate on AI’s Data Feast
Important work happening around HTTP Signatures in the Fediverse. Stronger key validation, better digest handling, clearer test vectors—all steps toward more secure and trustworthy ActivityPub communication.
HTTP Signature Upgrades Coming Soon
https://activitypub.blog/2025/07/03/http-signature-upgrades-coming-soon/
Web Hacking 101 at Codegarden showed how developers can test and secure their own applications, using just a few tools and the right mindset.
Guest Blog: https://umbra.co/4kE35SU
Workshop materials: https://umbra.co/3ImmWZ7
Arrrr!
#Umbraco #WebSecurity #Codegarden #H5YR
10 Best Secure Web Gateway Vendors In 2025 https://cybersecuritynews.com/best-secure-web-gateway/ #WebApplication #WebSecurity #websecurity #Top10
My personal websites detect spam by secret means and then present each attempted spammer with a cryptic fake CAPTCHA I coded that SEEMS interactive but never, ever ends.
Today, overcome with spite, I updated the system with a further feature: it overrides the site CSS to render the page’s header in hideous blue lettering. How does a faceful of Brush Script feel, spammer?! Re-evaluate your miserable life!
Tyler Sanderson, Kathryn Grayson Nanz, and Brent Stewart present on Frontend Development at Nebraska.Code().
The Open-Source Software Saving the Internet: Meet Anubis, making AI scrapers do cryptographic pushups while humans browse freely!
Xe Iaso's "uncaptcha" uses JavaScript math to verify you're human, not a bot. 200k downloads later, GNOME, FFmpeg & UNESCO are protected. Small internet fights back!
You Should Run a Certificate Transparency Log
WebPerformance Report Week #27 is out!
Ready for next Week? Don’t miss out!
Join our growing community of #WebPerformance enthusiasts and subscribe today: Web Performance Report:
https://webperformancereport.com/
HTTP Security Report:
https://webperformancereport.com/httpo/
#webperf #corewebvitals #ux #seo #cybersecurity #websecurity
Anubis – Open-Source Web AI Firewall Utility