Redacted by Counsel: A supply chain postmortem
heartbreak.ing·13h
🛡️Security Type Systems
Preview
Report Post

This was supposed to be a completely different write-up.

I originally intended to publish a sort of "Name and Shame" on some of the biggest tech companies in Silicon Valley. Screenshots of the sites you use daily, all vulnerable to the three of us hijacking your session and doing whatever the fuck we wanted with it.

Unfortunately, as it turns out, the only thing faster than an XSS payload is a veiled legal threat.

At the start of this week, as our disclosure planning was coming to a close, several companies decided to engage in some very aggressive PR management. Because, of course, the last thing a C-Suite wants to sign off on before Q4 earnings — and more importantly, just before Christmas break (happy holidays in advance!) — is Item 1.05 of a Form 8-K.

For those unfa…

Similar Posts

Loading similar posts...