JavaScript Vulnerabilities with Tim Kadlec - The State of the Web

JavaScript Vulnerabilities with Tim Kadlec - ...

Up next

HTTP Archive's 10th Anniversary

(November 19, 2020) Rick meets with Steve Souders, who created the HTTP Archive project 10 years ago this month, to talk about its origins and reflect on it's growth. They're also joined by Patrick Meenan, creator of WebPageTest and maintainer of HTTP Archive, along with Paul Cal ...  Show more

Design Systems with Brad Frost - The State of the Web

(February 5, 2020) In this episode of the State of the Web, Rick Viscomi talks with Brad Frost (Web Designer and author of Atomic Design) about design systems highlighting web design, material design, and more. Let's get started! For more info about everything discussed in this v ...  Show more

Recommended Episodes

High severity flaw can crash your WebServer when using OpenSSL - Let us discuss
The Backend Engineering Show with Hussein Nasser

On Thursday, OpenSSL maintainers released a fix for two high severity vulnerabilities, let us discuss the impact.

<ul> <li>OpenSSL two major vulnerabilities 0:00</li> <li>why OpenSSL 1:00</li> <li>Bug 1 - Renegotiating TLS 1.2 (CVE-2021-3449) 3:50</li> <li>Bug 2 - Ce ...  Show more

These New WhatsApp Vulnerabilities Can Leak Images, Voice Notes, and Chat by Opening an HTML message
The Backend Engineering Show with Hussein Nasser

Few vulnerabilities in WhatsApp for Andriod discovered that allow an attacker to send an HTML file attachment full access to the user's media, voice notes, pictures, and eventually chat messages (through TLS session resumption keys). In this video, we will discuss the scope of th ...  Show more

NodeJS July 2021 Security Releases
The Backend Engineering Show with Hussein Nasser

In today's show I go through the NodeJS Security Releases for the month of July 2021, lots of interesting vulnerabilities to discuss.

0:00 Intro

1:00 CVE-2021-22918 - libuv DNS Out of bounds Crash

3:40 CVE-2021-22921 - Node Windows installer Local Privileg ...

  Show more

A glimpse into Mr. Putin’s cyber war room. 3CXDesktopAppsupply chain risk. XSS flaw in Azure SFX can lead to remote code execution. AlienFox targets misconfigured servers.
CyberWire Daily

The Vulkan papers offer a glimpse into Mr. Putin’s cyber war room. The 3CXDesktopApp vulnerability and supply chain risk. A cross site scripting flaw in Azure Service Fabric Explorer can lead to remote code execution. Rob Boyce from Accenture Security on threats toEV charging sta ...  Show more