ByteBrief
We're a portrait publication through and through. Turn your phone back and your briefing picks up right where you left it.
(We tried widescreen once. It wasn't us.)
A researcher found an XSS flaw in ansi2html, the library SourceHut uses to render CI build logs. An attacker can inject a malicious OSC 8 hyperlink into a public mailing list patch, executing JavaScript in any viewer's browser. SourceHut patched builds.sr.ht to sanitize output; ansi2html released several fixes to PyPI.
Tap to vote and see what everyone thinks.
Summary by ByteBrief