Filter
Exclude
Time range
-
Near
A critical TOCTOU flaw in Node.js lets hackers bypass HTTP filters in libraries used 160M times weekly. Is your proxy server leaking forged requests? #NodeJS #CyberSecurity2026 #HttpRequestSplitting #TOCTOU #WebDev #InfoSec #JavascriptSecurity meterpreter.org/the-invisibl…

1
2
282
New Shai Hulud Malware Variant Turns Developers Into Supply Chain Attack Vectors, Expel Warns cysecurity.news/2026/01/new-… #cloudsecrettheft #developercredentialtheft #JavaScriptsecurity
2
2
570
8 Dec 2025
LLMs Cannot Reliably Detect Vulnerabilities in JavaScript - arxiv.org/pdf/2512.01255 Researchers have proposed numerous methods to detect vulnerabilities in JavaScript, especially those assisted by Large Language Models (LLMs). However, the actual capability of LLMs in JavaScript vulnerability detection remains questionable, necessitating systematic evaluation and comprehensive benchmarks. Unfortunately, existing benchmarks suffer from three critical limitations: (1) incomplete coverage, such as covering a limited subset of CWE types (2) underestimation of LLM capabilities caused by unreasonable ground truth labeling (3) overestimation due to unrealistic cases such as using isolated vulnerable files rather than complete projects. Qingyuan Fei, Xin Liu, Song Li, Shujiang Wu, Jianwei Hou, Ping Chen, Zifeng Kang - @lzu1949, @ZJU_China, @BeihangUniv, @CAC_China, @FudanUni, @BUPT_news #AISecurity #LLMSecurity #JavaScriptSecurity #VulnerabilityDetection #Benchmarking #SecureCoding #AdversarialML #SoftwareSecurity #SAST #ObfuscationResistance #PromptInjection #CyberResearch
6
406
4 Dec 2025
React2Shell (CVE-2025-55182) has been widely discussed in the security and engineering communities this week. It is a CVSS 10 vulnerability in React Server Components affecting React 19 and frameworks that depend on those packages, including recent versions of Next.js. Key points for teams assessing exposure: • Vulnerable RSC packages: react-server-dom-webpack, -turbopack, -parcel • Recent Next.js versions include these packages by default • Patched versions for React and Next.js are available • AWS, Cloudflare, and GCP have published WAF rules • Static sites do not execute RSC and are not affected This issue matters because the affected RSC packages are included by default in many React 19 and Next.js deployments, even when teams are not intentionally using RSC features. Exploitability varies by configuration, so verification is important. This situation is evolving rapidly as researchers continue to analyze real world behavior. We will update our blog as new information becomes available. Full analysis: averlon.ai/blog/react2shell-… #React2Shell #CVE202555182 #SoftwareSecurity #JavaScriptSecurity #RSC
5
341
[LAB] Client-Side Prototype Pollution via Browser APIs This lab is vulnerable to DOM XSS via client-side prototype pollution. The website's developers have noticed a potential gadget and attempted to patch it. However, you can bypass the measures they've taken. Here’s what you’ll do: ✅ Inject arbitrary properties into Object.prototype 🔍 Identify exploitable gadget properties 💥 Trigger alert() using your payload You can go hands-on manually or use DOM Invader to guide your attack. This lab is based on real vulnerabilities uncovered by our own research team. Start hacking now: portswigger.net/web-security… #WebSecurityAcademy #XSS #PrototypePollution #JavaScriptSecurity #BugBounty
12
67
4,161
It’s harder to spell than to spot 😵‍💫 @Cyber__Studies breaks down how attackers use JavaScript obfuscation to hide malicious code and how you can decode it fast in the latest #LearnWithHTB episode. Watch now: okt.to/eEDNJ6 Find the hidden flag in the video, share it in the comments, and you could win a FREE Silver Annual Subscription to #HTBAcademy! #JavaScriptSecurity #HTB #Deobfuscation #DFIR #BlueTeam #MalwareAnalysis
4
2
60
5,606
6 Jun 2024
🎊 Exciting news! Tanya Janca is set to rock the stage at AppSec PNW in Vancouver with her insightful talk on "30 Tips for Secure JavaScript" on June 15th at 11:15 am PT. Join us for a deep dive into JavaScript security! eventbrite.com/e/4th-annual-… #AppSecPNW #JavaScriptSecurity
3
147
8 Apr 2024
Congratulations to @liran_tal on the publication of your new book, "Node.js Secure Coding"! In today's JS-dependent tech world, secure coding and reviewing code for security issues are important. #JavaScriptSecurity #NodeJS
3 Apr 2024
👋😍 ANNOUNCING my new Node.js book! eval, new Function, the Node.js vm module? Nah, Start by adopting secure coding practices 🔮 Learn how to avoid Code Injection in JavaScript 📌 May 15th, 2024 release 🎁 PreOrder now at 70% discount! nodejs-security.com/book/cod…
1
2
14
2,332
29 Dec 2023
✨📆 Our Year in Review 🍿✨ As we bid farewell to another incredible year, we're thrilled to share with you some moments of all the events our team attended in 2023 🎥✨ #JavaScript #JavaScriptSecurity #Compliance #PCIDSSV4 #Events #Jscrambler
2
51
🎙 Excited to introduce our first speaker, ⁦@freak_crypt⁩ , who will unravel the world of Malicious JavaScript at DevFest Ranchi 2023! Get ready to dive into the code that conceals secrets and threats. 🔍💻 #DevFestRanchi #wtm #DevFest2023 #JavaScriptSecurity #TechTalks
1
3
11
1,124
Say hello to Jazzer.js! Today, we're open sourcing our coverage-guided in-process fuzzing engine for @nodejs. Jazzer.js is based on libfuzzer and brings many of its instrumentation-powered mutations to the #JavaScript ecosystem. Give it a try on @npmjs! github.com/CodeIntelligenceT…
4
7
#JavaScriptSecurity isn't just about attacks. 👉 #Facebook tracking tool capturing sensitive patient data on over 30% of the top 100 hospitals in America. This is why you need #ClientSideSecurity. #WAF #CSP won't find this. hubs.la/Q01dShmp0

2
Can you name the 5 things that are critical to developing secure JavaScript web applications? #JavaScriptSecurity #Feroot Find out in our new blog hubs.la/Q01d8wyh0
2