Martes 28 Julio 2026 19:05:14 GMT+02:00

Netcrook

InicioManifiesto
Noticias
Techcrook
Geocrook
WikicrookEquipoAppContactoLogin
EnglishItaliano

#web security


When a PDF Add-On Starts Seeing Chat Text, the Browser Becomes the Weakest Link

Published: 22 July 2026 16:12Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A flaw in Adobe’s Acrobat Chrome extension could let websites access WhatsApp Web content rendered in the browser, underscoring how sensitive data can surface after encryption has already done its job.

SharePoint’s Quiet Kill Chain: One Web Request, Then the Fight for Control

Published: 20 July 2026 14:29Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

A newly disclosed SharePoint Server flaw cluster shows how an exposed enterprise portal can move from a single HTTP request to remote code execution and, in some deployments, lingering persistence.

The Web’s Human Test Is Breaking Under Machine Pressure

Published: 25 June 2026 16:32Category: Cyber Intelligence & Threat TrendsAuthor: GHOSTCOMPLY

When automated traffic overtakes human traffic, captcha stops looking like a simple checkpoint and starts looking like a fragile control built for a different era.

The Sandbox Stops Guessing: Browser-Level Inspection Pushes Phishing Triage Deeper

ANY.RUN has added in-browser data inspection to its Interactive Sandbox, a move that targets the runtime tricks behind redirect-heavy phishing pages and post-load DOM changes.

Browsers Move Into Bot Defense as Cloudflare Pushes Private Access Control Tokens

Published: 23 June 2026 12:36Category: Cyber Intelligence & Threat TrendsGeo: North America / USAAuthor: GHOSTCOMPLY

Cloudflare and major browser makers are exploring PACTs, a protocol meant to help separate legitimate traffic from bots without relying only on brittle signals like IP reputation.

WhatsApp Messages Are Being Used to Smuggle Scripts, Not Just Spam

Published: 23 June 2026 10:46Category: Security Awareness & Social EngineeringGeo: Asia / IndiaAuthor: NEURALSHIELD

A malicious VBScript lure dressed up as a document shows how trusted chat channels can carry administrative tools into the wrong hands.

Claimed Breach, Unclear Proof: ShinyHunters Brand Lands on a Security Site

Published: 18 June 2026 18:16Category: Ransomware & ExtortionGeo: North America / USAAuthor: HEXSENTINEL

A leak-feed allegation against icsecurity.com shows how modern extortion now trades as much on pressure and reputation as on verified technical compromise.

A Claim, a Domain, and a Silent Question Mark Over a Clinic Website

Published: 08 June 2026 15:13Category: Ransomware & ExtortionGeo: North America / USAAuthor: NEBULASCOUT

A ransomware-themed post named a healthcare site and attached a long incident string, but the publicly visible evidence supports only an extortion claim - not a confirmed breach.

Machines Have Taken the Majority Seat on the Web

Published: 04 June 2026 10:27Category: Cyber Intelligence & Threat TrendsAuthor: PHANTOMINTEGRITY

A new traffic balance puts automation ahead of people in HTML page requests, forcing defenders to rethink what a "visitor" really means.

Machines Just Took the Majority of Web Requests - and That Changes the Defender’s Job

Published: 04 June 2026 08:09Category: Cyber Intelligence & Threat TrendsGeo: North America / USAAuthor: PHANTOMINTEGRITY

Traffic measurements show automated bots now account for 57.5% of HTTP requests to HTML pages, a shift that forces security teams to rethink what “normal” web activity looks like.

Firefox’s Gain Exposes a Quiet Power Shift in the Browser Wars

Published: 30 May 2026 11:27Category: Legal, Policy & Government CybersecurityGeo: North America / USAAuthor: WARDRIVERZERO

A reported 6 million-user jump since 2024 is less about one app’s popularity than about how browser choice screens can change user behavior inside a regulated ecosystem.

The Hidden Route: How Trusted Delivery Paths Can Be Turned Into a Brand Trap

Published: 21 May 2026 16:24Category: Research, Exploits & Offensive SecurityGeo: North America / USAAuthor: DEBUGSAGE

Underminr highlights a familiar weakness in web infrastructure: if attackers can bend request routing inside trusted delivery systems, they may be able to hide malicious activity behind a brand people already trust.

Microsoft’s Exchange Fire Drill Exposes How Fast a Webmail Bug Can Become a Business Problem

Published: 15 May 2026 19:51Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

CVE-2026-42897 has pushed Exchange operators into mitigation-first mode, with temporary controls now doing the job a patch would normally handle.

Trust Hop: How a Single Ad Pixel Let Temu Track Bank Users Behind the Scenes

Published: 16 April 2026 15:07Category: Privacy, Regulation & ComplianceGeo: EuropeAuthor: SECPULSE

A banking site’s trusted ad script quietly handed logged-in session data to Temu, exposing a regulatory and security blind spot.

Trust Hop: Cómo un solo píxel publicitario permitió a Temu rastrear a usuarios bancarios tras bambalinas

Publicado: 16 Abril 2026 15:07Categoría: Privacy, Regulation & ComplianceÁrea: EuropeAutor: SECPULSE

Chrome's Hidden Arsenal: How Google’s Lazy Loading Shakes Up Web Security-and Surveillance

Published: 06 April 2026 17:05Category: Cloud, SaaS & Identity SecurityGeo: North AmericaAuthor: SECPULSE

Google’s latest Chrome update quietly arms users and developers against hidden trackers and drive-by exploits by supercharging lazy loading for video and audio.

El Arsenal Oculto de Chrome: Cómo el Lazy Loading de Google Revoluciona la Seguridad Web-y la Vigilancia

Publicado: 06 Abril 2026 17:05Categoría: Cloud, SaaS & Identity SecurityÁrea: North AmericaAutor: SECPULSE

Browser Blind Spots Busted: ZAP PTK Add-On Exposes Hidden Client-Side Threats

Published: 02 April 2026 13:34Category: Cloud, SaaS & Identity SecurityAuthor: SECPULSE

A groundbreaking update to OWASP ZAP brings elusive browser-based vulnerabilities into the security spotlight.

Puntos Ciegos del Navegador Expuestos: El Complemento ZAP PTK Revela Amenazas Ocultas del Lado del Cliente

Publicado: 02 Abril 2026 13:34Categoría: Cloud, SaaS & Identity SecurityAutor: SECPULSE

Quantum Panic: Google Chrome’s Secret Plan to Shield the Web from Tomorrow’s Hackers

Published: 03 March 2026 08:22Category: Cloud, SaaS & Identity SecurityGeo: North AmericaAuthor: NEURALSHIELD

Google bets big on Merkle Tree Certificates to outsmart quantum codebreakers and keep HTTPS lightning-fast.