Grilled Cheese

ExploreLog inSign up
Terms of UsePrivacy PolicyCommunity StandardsHelpGet the app

Grilled Cheese is a product of Village Compute

Version devBuilt at: 2026-10-10 01:38:52 EDT

Explore

PostsPeople
LatestRanked
@hackersbrain.bsky.socialOct 9, 2026, 3:05 PM

Can XSS read HttpOnly cookies? No.

But it can still exploit your authenticated session without stealing the cookie.

Here's how 👇

hackersbrain.com/can-xss-read...

#XSS #CyberSecurity

@hackersbrain.bsky.socialOct 9, 2026, 3:02 PM

Can XSS steal cookies?

JavaScript can read cookies using `document.cookie`. But does that mean an XSS payload can steal them?

And if it does, what can an attacker actually do with a stolen session cookie?

Let's explore how it works.

hackersbrain.com/can-xss-stea...

#XSS #CyberSecurity

@securityonline.bsky.socialOct 8, 2026, 12:44 AM

An active WordPress XSS campaign exploits Ninja Forms flaw CVE-2026-94504 and CVE-2026-93836 to plant hidden admin accounts. Patch now.

#WordPress #NinjaForms #WooCommerce #CVE202694504 #CVE202693836 #XSS #ExploitedInTheWild #Malware

@thedailytechfeed.comOct 7, 2026, 9:04 AM

WordPress 7.1.3 fixes critical XSS, SQLi & data-exposure flaws—update now. #WordPress #Security #XSS #SQLInjection #DataDisclosure #UpdateNow https://thedailytechfeed.com/wordpress-7-1-3-fixes-multiple-critical-vulnerabilities/

@thedailytechfeed.comOct 7, 2026, 8:37 AM

Massive Veeam patch fixes RCE, XSS & file-read holes—update to build 12.3.2.4934 now. #Cybersecurity #Veeam #RCE #XSS #PatchNow #DataProtection https://thedailytechfeed.com/critical-veeam-rce-xss-flaws-discovered-patch-immediately/

@securityonline.bsky.socialOct 6, 2026, 5:38 PM

The WordPress 7.1.3 security update is a WordPress security release that fixes stored XSS, SQL injection and more. Update your site now.

#WordPress #WordPress713 #XSS #SQLInjection #WebSecurity #CMS #PatchNow #Vulnerability

@thedailytechfeed.comOct 5, 2026, 9:01 AM

PageBreak AI found 500+ real XSS holes in Google products—cache poisoning, exploit chains, and far fewer false positives. #AI #WebSecurity #XSS #Google #Cybersecurity #ExploitChains https://thedailytechfeed.com/googles-ai-pagebreak-finds-500-xss-flaws-builds-exploit-chains/

@simsus.social.tchncs.de.ap.brid.gyOct 4, 2026, 6:12 AM

Groupware #Zimbra: Update schließt zahlreiche Sicherheitslücken | Security https://www.heise.de/news/Groupware-Zimbra-Update-schliesst-zahlreiche-Sicherheitsluecken-11468996.html #Patchday #XSS #CrossSiteScripting

@donwebmedia.bsky.socialOct 3, 2026, 1:19 AM

CVE-2026-93875: XSS almacenado en JetAppointment WordPress

Descubrí todo sobre CVE-2026-93875 WordPress: qué riesgos implica, cómo afecta tu sitio y qué medidas tomar. Entrá y enterate antes de que sea tarde.

#cve202693875 #wordpress #jetappointment #xss #wordfence

@anwangxia.bsky.socialOct 1, 2026, 4:58 PM

肃杀的国际环境下,2026年仍然活跃的全球5大暗网论坛
#暗网论坛 #Altenen #DarkForums #Dread #Exploit.in #XSS.is
www.anwangxia.com/5111.html

@kristijankop.bsky.socialSep 30, 2026, 9:31 PM

Can a single email silently install malware on your computer? #email #xss #howitworks #techexplained

@hendryadrian.bsky.socialSep 30, 2026, 7:45 PM

Microsoft will add stronger Content Security Policy protections for Entra ID sign-ins in mid-October 2026, blocking unauthorized scripts and reducing XSS risk during browser-based authentication. #EntraID #Microsoft #XSS

@potato.softwareSep 30, 2026, 7:19 AM

[New Post] 📌MS Entra ID Introduce CSP Protections to Block Unauthorized external Script Injection and Help Prevent XSS Attacks -
www.anoopcnair.com/entra-id-csp...
#MSEntra #MicrosoftEntraID #EntraID #CSP #XSS #PotatoSecurity #HTMDCommunity

@htmdc.bsky.socialSep 30, 2026, 7:19 AM

[New Post] 📌MS Entra ID Introduce CSP Protections to Block Unauthorized external Script Injection and Help Prevent XSS Attacks -
www.anoopcnair.com/entra-id-csp...
#MSEntra #MicrosoftEntraID #EntraID #CSP #XSS #CyberSecurity #HTMDCommunity

@securityonline.bsky.socialSep 30, 2026, 1:47 AM

A JupyterLab Desktop vulnerability, CVE-2026-102530 (CVSS 9.4), turns a malicious server URL into remote code execution. Update to 4.6.2-1 now.

#JupyterLab #JupyterLabDesktop #CVE2026102530 #XSS #RCE #Electron #DataScience #PatchNow

@simsus.social.tchncs.de.ap.brid.gySep 28, 2026, 6:14 PM

Sicherheitslücken: #GitLab-Server sind für Schadcode-Attacken anfällig | Security https://www.heise.de/news/Sicherheitsluecken-GitLab-Server-mit-Schadcode-attackierbar-11465889.html #Patchday #XSS #CrossSiteScripting #RegularExpressions #CICD #git :git:

@hackersbrain.bsky.socialSep 26, 2026, 3:07 PM

An XSS payload gets access to sensitive data.

But how does that data actually reach the attacker?

We break down the full exfiltration flow — JavaScript, HTTP requests, attacker-controlled server — with code, diagrams, and an interactive lab.

🔗 hackersbrain.com/how-does-xss...

#XSS

@securityonline.bsky.socialSep 24, 2026, 2:50 AM

A critical Rancher XSS vulnerability tracked as CVE-2026-88804 exposes admin sessions. Update your clusters immediately to prevent system compromise.

#Rancher #Kubernetes #CVE202688804 #XSS #Cybersecurity #Infosec

@securestep9.bsky.socialSep 22, 2026, 2:52 PM

#WordPress “Comment2Shell” turns anonymous stored #XSS vulnerability into server code execution when an admin views the comment.

It abuses the admin session to upload a malicious plugin. Patch now!
👇

@hugovalters.bsky.socialSep 18, 2026, 7:14 PM

GL.iNet Slate 7 Pro Review: Wi-Fi 7 Travel Router That Fixed My Homelab Bottleneck youtu.be/syFWgIPLxf8 @GLiNetWiFi #Linux #infosec #XSS #valtersit #OpenWrt #SysAdmin #cybersecurity #cybersecurityawareness #cybersecuritynews #cybersecuritytips #python #kali #ubuntu #debian #docker #networking #IoT

Load more