"While connections made after connecting to a VPN on your iOS device are not affected by this bug, all previously established connections will remain outside the VPN's secure tunnel..."


"CVE-2020-10558 | Tesla Model 3 Vulnerability – Disable Autopilot Notifications, Speedometer, Web Browser, Climate Controls, Turn Signals, Nav, etc."


> Unless customized, Jinja2 is configured by Flask as follows: autoescaping is enabled for all templates ending in .html, .htm, .xml as well as .xhtml when using render_template().


If using flask pay special attention to this configuration.
In Django as far as I'm aware (after testing a bit), render/render_to_string always escapes the content.

"Mass account takeovers using HTTP Request Smuggling on slackb.com/ to steal session cookies"


Very interesting bug report.

AMD – new side-channel attacks affecting CPUs from 2011 to 2019:

mlq.me/download/takeaway.pdf (PDF file)

– The L1D cache way predictor is exploited to access secret information.
– The attacks are named Collide+Probe and Load+Reload.

#AMD #CPU #vulnerability #security #infosec #cybersecurity

