TGViewer
Daily Security Daily Security @ethers_security · 4.02K subscribers
Post #374 838

Forwarded from Security Harvester

Analysis of 8 Foundational Cache Poisoning Attacks (HackerOne, GitHub, Shopify) - Part 1
https://herish.me/blog/cache-poisoning-case-studies-part-1-foundational-attacks/:

1. The first part of a three-section deep dive analyzing early real-world cache poisoning bugs across HackerOne, GitHub, Shopify, and private programs.
2. Although it once appeared niche, cache poisoning has evolved into a high-impact attack vector affecting CDNs, cloud platforms, server frameworks, and multi-tenant SaaS providers.
3. These early reports demonstrate not only how straightforward misconfigurations can lead to devastating effects, but also how attackers learned to weaponize headers, request behaviors, and cache key inconsistencies to breach platforms with millions of users.

@secharvester
More from @ethers_security
  1. Sep 24, 2026photo post
  2. Sep 24, 2026🚨🚨Bitget wallets may have been hacked after $174 million moves across chains 🚨🚨 [sourc…
  3. Aug 8, 2026Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages Recommendation: • If you id…
  4. Aug 1, 2026Great resource to study AI and different types of AI vulnerabilities https://riskatlas.pri…
  5. Jun 9, 2026Claude Fable is out. As you can see, the new model claims to have been significantly impro…
  6. Apr 23, 2026PASSWORD MANAGER 'BITWARDEN' CLI WAS COMPROMISED IN A SUPPLY CHAIN ATTACK ⚠️ BITWARDEN CLI…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →