Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Cure53🔓

@cure53@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

And there is fire where we walk.

733 Followers
122 Following
25 Posts
Joined November 07, 2022
Website:
https://cure53.de/
Github:
https://github.com/cure53/
Keybase:
https://keybase.io/cure53/
Pronouns:
they/them
Open post
Cure53🔓 @cure53@infosec.exchange
· 6mo ago

Does anyone have a contact at pwn.ai?

We would kinda like to have a conversation with them...

31
4
18
0
Open post
Cure53🔓 @cure53@infosec.exchange
· 5mo ago

We're already seeing a spike in AI-generated PRs making the ecosystem much more secure.

Words cannot describe how grateful we are for all the contributions.

11
1
7
1
Open post
Cure53🔓 @cure53@infosec.exchange
· 2mo ago
Replying to
@rauschma@fosstodon.org @evilpie@hachyderm.io Here, for example: https://github.com/WICG/declarative-partial-updates/blob/main/fragment-include-explainer.md Leading to possible attack vectors like this: <?marker name="x">
GitHub

declarative-partial-updates/fragment-include-explainer.md at main · WICG/declarative-partial-updates

Contribute to WICG/declarative-partial-updates development by creating an account on GitHub.

2
0
3
0
Open post
Cure53🔓 @cure53@infosec.exchange
· 5mo ago
Replying to
@agowa338 Cyber security is an insanely complex beast with some parts being technical, some being human, some being regulatory, etc., and well, finding bugs is one small component. Emphasis on small. We have not really been great at cyber security in the past, and improvements are needed all across the board. We won't be great at it tomorrow because magic. Having one component potentially improve is, especially given how speculative the current situation is, is nothing to really worry about. Rather the contrary. Time will tell, some processes might change, and that is likely all that will happen for a long time. Most humans in cyber security will very likely notice very little impact for now. Can this all go sideways? Yes, of course. Is it time to say that cyber security is over? I don't think so. At all.
9
1
4
0
Open post
Cure53🔓 @cure53@infosec.exchange
· 5mo ago

We did not expect that back in 2014 🥹

8
0
1
0
Open post
Cure53🔓 @cure53@infosec.exchange
· 7mo ago

DOMPurify 2.5.9 and DOMPurify 3.3.2 were released today in a rush to fix a security issue caused by jsdom's faulty tag parsing.

A total of four people reported the exacty same bug within a window of three days.

One did so via email, thank you. One did so via private security advisory, thank you too.

One however simply published a ticket for everyone to see, the other one just dropped a CVE on us without a working fix release. Thanks for nothing.

https://github.com/cure53/DOMPurify/releases/tag/3.3.2

https://github.com/cure53/DOMPurify/releases/tag/2.5.9

GitHub

Release DOMPurify 3.3.2 · cure53/DOMPurify

Fixed a possible bypass caused by jsdom's faulty raw-text tag parsing, thanks multiple reporters Fixed a prototype pollution issue when working with custom elements, thanks @christos-eth Fixed a le...

11
1
5
1
Open post
Cure53🔓 @cure53@infosec.exchange
· 5mo ago

In anticipation of possibly upcoming waves of OSS bugs as well maybe increasing amounts of real attacks, we have been busy hardening DOMPurify.

Look at those shiny badges and improvements, LOOK OMG 😱

https://github.com/cure53/dompurify?tab=readme-ov-file#dompurify

Work in progress of course, but lots got done this week 💪🏻

GitHub

GitHub - cure53/DOMPurify: DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo: - cure53/DOMPurify

7
0
3
0
Open post
Cure53🔓 @cure53@infosec.exchange
· 5mo ago
Replying to
@bontchev @GossiTheDog Agreed. Current recommendation from our end: Keep calm, find and fix bugs, make the world a bit safer one bug at a time... And ignore the hype train, but keep an open eye on how real and measurable things develop. Just what we did before.
6
0
2
0
Open post
Cure53🔓 @cure53@infosec.exchange
· 9mo ago

We have slightly updated the publicly available contract templates for NDA, MSA and DPA. File format is ODT as usual.

Feel free to, just as before, use them as you see it fit for your own purposes 😄

https://github.com/cure53/Contracts

GitHub

GitHub - cure53/Contracts: A small collection of potentially useful contract templates

A small collection of potentially useful contract templates - cure53/Contracts

13
0
4
0
Open post
Cure53🔓 @cure53@infosec.exchange
· 3mo ago
Replying to
CTFs hopefully being the primary usecase 🫠
2
2
0
0
Open post
Cure53🔓 @cure53@infosec.exchange
· 6mo ago
blog.rice.is

Can it Resolve DOOM? Game Engine in 2,000 DNS Records – blog.rice.is

To a guy like me, Crazy Frog is just a frog.

5
1
1
0
Open post
Cure53🔓 @cure53@infosec.exchange
· 5mo ago

To all the OSS projects getting swamped by AI tickets right now...

IT IS TOTALLY YOUR OWN FAULT.

The easy fix is to write better code.
You are welcome, this advice was free.

*ducks*

3
0
0
0
Open post
Cure53🔓 @cure53@infosec.exchange
· 6mo ago

We know who Angine de Poitrine really is.

3
3
1
0
Open post
Cure53🔓 @cure53@infosec.exchange
· 6mo ago

🤨 😅

https://blog.trailofbits.com/2026/03/31/how-we-made-trail-of-bits-ai-native-so-far/

How we made Trail of Bits AI-native (so far)
The Trail of Bits Blog

How we made Trail of Bits AI-native (so far)

We had 5% buy-in and 95% resistance. A year later, AI-augmented auditors are finding 200 bugs a week on the right engagements. Here’s the six-part operating system we built, open sourced, and are giving away.

3
0
0
0
Open post
Cure53🔓 @cure53@infosec.exchange
· 5mo ago

Version 3.4.0 of DOMPurify was released today, addressing a large number of issues reported by LLMs and real people alike.

Thanks to all who contributed.

https://github.com/cure53/DOMPurify/releases/tag/3.4.0

We hope everything went smoothly and that no one was overlooked in the release notes.

GitHub

Release DOMPurify 3.4.0 · cure53/DOMPurify

Most relevant changes: Fixed a problem with FORBID_TAGS not winning over ADD_TAGS, thanks @kodareef5 Fixed several minor problems and typos regarding MathML attributes, thanks @DavidOliver Fixed A...

2
0
1
0
Open post
Cure53🔓 @cure53@infosec.exchange
· 5mo ago

DOMPurify 3.4.1 is out with lots of small improvements.

Among them, a better test suite, a small fuzzer, several fixes and hardenings, and as usually we hope all went well 😅

https://github.com/cure53/DOMPurify/releases/tag/3.4.1

GitHub

Release DOMPurify 3.4.1 · cure53/DOMPurify

Fixed an issue with on-handler stripping for HTML-spec-reserved custom element names (font-face, color-profile, missing-glyph, font-face-src, font-face-uri, font-face-format, font-face-name) under ...

1
0
0
0
Open post
Cure53🔓 @cure53@infosec.exchange
· 6mo ago

Here's everybody's space heroes having a great time with DJT.

https://edition.cnn.com/2026/04/07/science/video/donald-trump-call-artemis-ii-hnk-digvid

edition.cnn.com
1
6
0
0
Open post
Cure53🔓 @cure53@infosec.exchange
· 11mo ago

DOMPurify 3.3.0 is out. You can now configure which tags can have which attributes much more easily.

https://github.com/cure53/DOMPurify/releases/tag/3.3.0

Thanks again to everyone who contributed to and supported the project. ❤️

GitHub

Release DOMPurify 3.3.0 · cure53/DOMPurify

Added the SVG mask-type attribute to default allow-list, thanks @prasadrajandran Added support for ADD_ATTR and ADD_TAGS to accept functions, thanks @nelstrom Fixed an issue with the slot element b...

2
0
2
0
Open post
Cure53🔓 @cure53@infosec.exchange
· 5mo ago
Replying to
@datenkeller And if you don't, then Roko's Basilisk will get you and teach you some manners soon...
0
1
0
0
Open post
Cure53🔓 @cure53@infosec.exchange
· 6mo ago
Replying to
@buherator Might also just be physics, having a spine and flipping the bird in zero gravity could be really hard.
0
2
0
0
Open post
Cure53🔓 @cure53@infosec.exchange
· 6mo ago
Replying to
@Oytis It's quite likely that he won't be.
0
1
0
0
Open post
Cure53🔓 @cure53@infosec.exchange
· 6mo ago
Replying to
@ctxkyo Thanks 🙏
0
0
0
0
Open post
Cure53🔓 @cure53@infosec.exchange
· 3mo ago
RE: https://mastodon.social/@gwynnion/116859269846708028 Is this a post about LLMs?
Open quoted post
Quoting
Nowhere Girl
@gwynnion@mastodon.social
I would kill or die for Larry the cat.
Open quoted post
mastodon.social

Nowhere Girl: "I would kill or die for Larry the cat." - Mastodon

0
0
0
0
Open post
Cure53🔓 @cure53@infosec.exchange
· 3mo ago
Replying to
@joern@threatactor.club then DOMFartify must bring em back 🚀
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 17:52:09 UTC