Marius Avram's Avatar

Marius Avram

@mariusavram

Cyber Security Enthusiast. Two sons' proud dad!

114
Followers
129
Following
94
Posts
12.11.2023
Joined
Posts Following

Latest posts by Marius Avram @mariusavram

Goodbye innerHTML, Hello setHTML: Stronger XSS Protection in Firefox 148 hacks.mozilla.org/2026/02/good...

25.02.2026 06:15 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Total.js RCE gadgets all around lab.ctbb.show/research/tot...

23.02.2026 14:46 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

the watchers: How openai, the US government, and persona built an identity surveillance machine that files reports on you to the feds vmfunc.re/blog/persona

18.02.2026 19:48 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
MCP Server Security: The Hidden AI Attack Surface MCP server security is a critical blind spot in AI integration. Our researchers demonstrated code execution, data theft, and response manipulation β€” all invisible to users.

MCP Server Security: The Hidden AI Attack Surface:
www.praetorian.com/blog/mcp-ser...

18.02.2026 06:27 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Hi Robin, I’ve just tested it using a Romanian IP, and everything works fine on my end.

09.02.2026 14:07 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Notepad++ Hijacked by State-Sponsored Hackers notepad-plus-plus.org/news/hijacke...

02.02.2026 05:28 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Poland CERT Report: Coordinated Cyber Sabotage Hits 30+ Wind/Solar Farms & CHP Plant (Dec 29, 2025) cert.pl/en/posts/202...

30.01.2026 14:52 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

We’re expanding localized pricing to Romania! πŸ‡·πŸ‡΄

Individual plan prices drop by 55%:
πŸ’Έ Monthly: 20 USD β†’ 9 USD
πŸ’Έ Yearly: 200 USD β†’ 90 USD

Know a hacker in Romania who’s been waiting? Tag themπŸ‘‡
caido.io/pricing?utm_...

27.01.2026 10:28 πŸ‘ 4 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
Top 10 web hacking techniques of 2025 Welcome to the community vote for the Top 10 Web Hacking Techniques of 2025.

Voting is now live for the top ten web hacking techniques of 2025! Grab a brew, browse the 61 quality nominations and cast your vote on the most creative and ground-breaking techniques:
portswigger.net/polls/top-10...

15.01.2026 15:29 πŸ‘ 7 πŸ” 5 πŸ’¬ 0 πŸ“Œ 0
Overview of the page.

Overview of the page.

πŸ“‘ OWASP Secure Headers Project: We have added information and examples regarding the Trusted Types feature of the Content-Security-Policy header.

πŸ“– owasp.org/www-project-...

#appsec #appsecurity #owasp_shp

12.01.2026 05:59 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

Venezuela and Ukraine expose the clearest form of double standards in international politics,when similar actions are taken by different actors,they are judged by entirely different criteria.Those who condemn Russia for intervening in Ukraine often welcome or justify US intervention in Venezuela

05.01.2026 17:05 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Despite fixed borders, the United States claims ownership of the West. Trump says it openly, echoed by Marco Rubio, this is our hemisphere. Such words expose hegemony. Faced with Trump’s illegal acts, the EU behaves as a complicit impostor, submissive, silent, ready to drag the West into barbarism

05.01.2026 11:53 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

When the US kidnaps a foreign president with Western applause, no law protects anyone. Iraq, Libya, Syria, Ukraine show wars are thefts of resources. Narco-terror claims mask oil and gold looting. Power rules, rights vanish, democracy is a lie!

05.01.2026 11:31 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I don't understand how these clubs are allowed to operate, why fireworks are permitted indoors, why the ceilings are so highly flammable, and, more importantly, why there are no proper emergency exits. It is as if they are designed to be death traps. πŸ€¦β€β™‚οΈ

02.01.2026 13:09 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

It happened in Romania under almost identical circumstances: the ceiling caught fire due to fireworks, killing over 60 people.

02.01.2026 13:09 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

Shlomo Kramer, co-founder of Check Point, Imperva, and Cato Networks, has stated that β€œit’s time to limit the First Amendment. We need to control all social platforms… and take control of what they are saying.”

02.01.2026 10:54 πŸ‘ 8 πŸ” 4 πŸ’¬ 0 πŸ“Œ 9

Turning List-Unsubscribe into an SSRF/XSS Gadget security.lauritz-holtmann.de/post/xss-ssr...

23.12.2025 14:55 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

How we pwned X (Twitter), Vercel, Cursor, Discord, and hundreds of companies through a supply-chain attack gist.github.com/hackermondev...

19.12.2025 08:28 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

Bypass CSP in a single click using my new Custom Action, powered by @renniepak.nl's excellent CSP bypass project.

16.12.2025 15:31 πŸ‘ 12 πŸ” 6 πŸ’¬ 1 πŸ“Œ 0
Preview
AutoVader - The Spanner Four years ago we released DOM Invader, I added a feature called callbacks that enabled you to execute JavaScript and log when sinks, messages or sources are found. This was so powerful but over the y...

Meet AutoVader. It automates DOM Invader with Playwright Java and feeds results back into Burp. Faster client side bug hunting for everyone. πŸš€

thespanner.co.uk/autovader

09.12.2025 12:22 πŸ‘ 12 πŸ” 7 πŸ’¬ 0 πŸ“Œ 0
Preview
Privacy concerns raised as Grok AI found to be a stalker's best friend Grok, the AI chatbot developed by Elon Musk's xAI, has been found to exhibit more alarming behaviour - this time revealing the home addresses of ordinary people upon request.

Grok - Elon Musk's AI chatbot - has been caught handing out home addresses of ordinary individuals... on demand. οΏΌ

When asked, Grok was willing to provide step-by-step instructions on how to stalk these people...

Read more in my article on the Bitdefender blog: www.bitdefender.com/en-us/blog/h...

08.12.2025 16:35 πŸ‘ 13 πŸ” 13 πŸ’¬ 1 πŸ“Œ 0
Post image

We now have a (draft) @metasploit-r7.bsky.social exploit module for the recent Fortinet FortiWeb vulns, chaining CVE-2025-64446 (auth bypass) + CVE-2025-58034 (command injection) to achieve unauthenticated RCE with root privileges: github.com/rapid7/metas...

21.11.2025 13:29 πŸ‘ 21 πŸ” 10 πŸ’¬ 1 πŸ“Œ 0
Introduction - OWASP Top 10:2025 RC1 OWASP Top 10:2025 RC1

Introducing the OWASP Top 10:2025
owasp.org/Top10/2025/0...

07.11.2025 13:44 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Tenable Research has discovered seven vulnerabilities and attack techniques in ChatGPT, including unique indirect prompt injections, exfiltration of personal user information, persistence, evasion, and bypass of safety mechanisms. www.tenable.com/blog/hackedg...

05.11.2025 16:39 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Phrack 72 Has Been Published phrack.org/issues/72/1

19.08.2025 07:13 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
CRITICAL: Compromised Website Report | The Shadowserver Foundation This report is a list of all the websites we (or our collaborative partners) have been able to identify and verify to be compromised.

IP data on compromised instances shared in our Compromised Website report tagged 'fortiweb-compromised': www.shadowserver.org/what-we-do/n...

IP data on exposed instances is in our Device ID report: www.shadowserver.org/what-we-do/n... (device model is set to FortiWeb Management Interface)

16.07.2025 09:02 πŸ‘ 0 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0

true legend!

11.07.2025 15:59 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Opossum Attack

opossum-attack.comΒ <-Β Opossum is a cross-protocol application layer desynchronization attack that affects TLS-based application protocols that rely on both opportunistic and implicit TLS. Among the affected protocols are HTTP, FTP, POP3, SMTP, LMTP and NNTP.

08.07.2025 16:08 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0