Latest updates for Http Request Smuggling

Fresh curated links around http request smuggling are collected here so marketers can spot useful updates and turn timely ideas into posts faster.

Recent items include:

  • Анатомия HTTP Request Smuggling
  • CRLF-Powered Desync Lets Attackers Poison CDN Cache and Serve XSS to Live Users
  • Critical Apache HttpComponents Client Flaw Lets Attackers Impersonate Servers

Post angles to try

Share the most useful takeaway for your audience.
Turn one article into a quick practical checklist.
Ask your audience how this shift affects their work.
Turn angles into scheduled posts

Fresh articles and ideas

Recent curated links from global sources. Generate one free draft from any story, then use SocialBu to schedule and refine your content calendar.

habr.com /4 weeks ago

Анатомия HTTP Request Smuggling

Чтобы разобраться в HTTP Request Smuggling, надо сначала честно ответить на вопрос, который в обычной жизни может прозвучать абсурдно: а как сервер понимает, где заканчивается один...

Read source
cybersecuritynews.com /2 weeks ago

CRLF-Powered Desync Lets Attackers Poison CDN Cache and Serve XSS to Live Users

A limited CRLF injection flaw can be escalated into a severe HTTP desynchronization attack, poisoning CDN caches and delivering XSS payloads to users on legitimate websites. The at...

Read source
gbhackers.com /3 weeks ago

Critical Apache HttpComponents Client Flaw Lets Attackers Impersonate Servers

A critical vulnerability in the Apache HttpComponents Client can allow man-in-the-middle attackers to impersonate trusted servers when applications use the asynchronous version of...

Read source
rubysec.com /1 month ago

GHSA-m5f6-4589-m89f (blazer): Stored XSS vulnerability

Originally appeared on RubySec.An authenticated user can create a malicious query that executes arbitrary JavaScript when another user tries to edit the query. This can be used to...

Read source
rubysec.com /1 month ago

CVE-2026-45573 (decidim-core): Decidim - Push subscriptions can be abused for server-side requests

Originally appeared on RubySec.## Description The push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request...

Read source
rubysec.com /1 month ago

CVE-2026-50276 (datadog): dd-trace-rb - Improper parsing of W3C baggage headers may lead to DoS

Originally appeared on RubySec.### Impact Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing item-count or byte...

Read source
theregister.com /5 days ago

ASCII smuggling isn't just an AI security risk

Phishers find a new use for invisible Unicode tag characters

Read source
thehackernews.com /17 hours ago

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on Sept...

Read source
gbhackers.com /3 weeks ago

GeoServer Pre-Auth SQL Injection Flaw Lets Attackers Gain Remote Code Execution

A newly disclosed SQL injection vulnerability in GeoServer allows remote attackers to execute operating system commands on backend PostgreSQL hosts under high-risk configurations....

Read source
thehackernews.com /2 weeks ago

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

Adversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a user's name, approximate location, subscription tier, and the prompts from the ongo...

Read source
arstechnica.com /2 weeks ago

Grok exfiltrates user data when malicious instructions are encrypted

Cryptographic Context Injection is only the latest way to break an LLM safety guardrail.

Read source
medium.com /13 hours ago

ASCII Smuggling Explained: How Hackers Hide Malicious Prompts in Plain Sight

Imagine receiving an email that looks like an ordinary customer support inquiry. You read every line, find nothing suspicious, and approve…Continue reading on Medium »

Read source
gbhackers.com /1 month ago

SonicWall SMA Zero-Days Let Attackers Turn One WebSocket Request Into Root Control

SonicWall SMA Secure Mobile Access appliances are again at the center of a zero-day storm, with chained flaws that let attackers turn a single crafted WebSocket request into root-l...

Read source
arstechnica.com /5 days ago

Once popular for attacking AI, ASCII smuggling is embraced by spammers

A once-overlooked block of unicode that's invisible to humans is gaining ever wider use.

Read source
smashingmagazine.com /1 month ago

Weaponizing And Defending The React Flight Protocol: Deserialization Sinks In RSCs

While React Server Components rely on the custom Flight protocol to stream interactive UIs, this same mechanism introduces powerful deserialization sinks that attackers can exploit...

Read source
rubysec.com /1 month ago

GHSA-5qhf-9phg-95m2 (loofah): Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character refere...

Originally appeared on RubySec.## Summary Loofah::HTML5::Scrub.allowed_uri? does not correctly reject javascript: or vbscript: URIs when the scheme is split by a numeric character...

Read source
theregister.com /1 month ago

HTTP gets a QUERY method so complex searches can stop pretending to be POST

New verb carries request content while remaining safe, idempotent, and cacheable

Read source
rubysec.com /1 month ago

GHSA-r766-3v88-pfcf (where_is_waldo): where_is_waldo authenticates ActionCable connections from a client-supplied subjec...

Originally appeared on RubySec.WhereIsWaldo::ApplicationCable::Connection (the gem's built-in ActionCable connection) authenticated the connection from `request.params[:subject_id]...

Read source
infosecurity-magazine.com /2 weeks ago

JFrog Artifactory Flaws Enable Software Supply Chain Attacks

Two Artifactory flaws allowed attackers to poison package metadata across software repositories

Read source
bleepingcomputer.com /1 month ago

Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack

Slopsquatting, phantom squatting, and HalluSquatting all exploit the same late-binding attack pattern, where AI coding agents trust hallucinated package, repo, or domain names. Act...

Read source
theregister.com /2 weeks ago

Grok chat duped into swallowing injected instructions

A spoonful of encryption helps the malware go down

Read source
thehackernews.com /1 month ago

Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-202...

Read source
thehackernews.com /2 days ago

JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities...

Read source
thehackernews.com /2 weeks ago

CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification

Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing HTTP/3 traffic into HTTP/...

Read source

Turn fresh research into a full content calendar

Use SocialBu to discover ideas, generate post drafts, and schedule them across your social channels.

Sources covering Http Request Smuggling

feeds.arstechnica.com

Recent coverage from public sources
Public source

rubyland.news

Recent coverage from public sources
Public source

cybersecuritynews.com

Recent coverage from public sources
Public source

feeds.feedburner.com

Recent coverage from public sources
Public source

gbhackers.com

Recent coverage from public sources
Public source

habr.com

Recent coverage from public sources
Public source