Quotidien Shaarli

Tous les liens d'un jour sur une page.

Aujourd'hui - June 4, 2026

Codex Discovered a Hidden HTTP/2 Bomb - Calif

14 years ago, I helped break HTTP header compression, then was asked to review the fix, which became part of HTTP/2. Life has come full circle: today we're releasing an attack I missed.

Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag

Debug flag disabled Microsoft 365 Android token checks, letting untrusted apps access accounts; patches issued May 12 to reduce risk