DIFF.BLOG
New Following Discover Jobs
More
Top Writers Suggest a blog Upvotes plugin
Report bug Contact About
Sign up
Topics
Follow your own topics →
Menu
New Following Discover Jobs Top Writers
More
Suggest a blog Upvotes plugin Report bug Contact About
Sign up
The home for great developer writing.
We surface the best developer writing from thousands of independent blogs, updated daily.
Join Diff.blog
TOPICS

Hacking fun with zip-slips, tar-slips, symlinks, hardlinks, collisions, and more

224 · Joshua Rogers · June 20, 2026, 6:14 p.m.
Security vulnerabilities unpkg.com cdn zip-slips
Summary
This blog post discusses Joshua Rogers' exploration of security vulnerabilities in unpkg.com CDN by leveraging techniques like zip-slips, tar-slips, symlinks, and hardlinks. He draws on insights from Max Justicz’s previous work, highlighting methods to exploit these vulnerabilities.
Read full post on joshua.hu →
MORE POSTS LIKE THIS
Why your AI agent needs two sandboxes: Benchmark data
Red Hat · Jul 23, 2026
AI Security Sandboxing
‘GitLost’ vulnerability let GitHub’s AI workflows leak private repositories
Siliconangle · Jul 7, 2026
News Security
Factoring RSA Keys with Many Zeros
Bruce Schneier · Jun 29, 2026
Backdoors Cryptography
How memory safety CVEs differ between Rust and C/C++
Kobzol · Jun 15, 2026
Rust Memory Safety
Chrome Extension Vulnerabilities: Millions at Risk
Securityonline · Jun 19, 2026
Vulnerability Report chrome-extensions
Langflow instances are getting exploited – again
Thestack · Jun 15, 2026
Langflow Vulnerabilities
Discover more posts →
AUTHOR
RECENT POSTS FROM THE AUTHOR
Choose how you want to continue.
Continue with GitHub Continue with Google