XSLeak flaw in Slack could allow a malicious workspace member to launch de-anonymisation attacks

clock • 3 min read
XSLeak flaw in Slack could allow a malicious workspace member to launch de-anonymisation attacks
Image:

XSLeak flaw in Slack could allow a malicious workspace member to launch de-anonymisation attacks

Slack says users can prevent such attacks by ensuring that everyone in their workspace is 'trusted'

A security researcher claims to have uncovered a cross-site leak (XSLeak) flaw in the file-sharing feature of Slack's web application which could enable threat actors to identify users outside of t...

To continue reading this article...

Join Computing

  • Unlimited access to real-time news, analysis and opinion from the technology industry
  • Receive important and breaking news in our daily newsletter
  • Be the first to hear about our events and awards programmes
  • Join live member only interviews with IT leaders at the ‘IT Lounge’; your chance to ask your burning tech questions and have them answered
  • Access to the Computing Delta hub providing market intelligence and research
  • Receive our members-only newsletter with exclusive opinion pieces from senior IT Leaders

Join now

 

Already a Computing member?

Login

You may also like
Facebook and Instagram down across the world

Social Networking

Facebook and Instagram are both down for many users around the world.

clock 05 March 2024 • 1 min read
IT Essentials: Time to take the deepfake fight to Big Tech

Government

Speak softly and carry a big stick

clock 04 March 2024 • 3 min read
SEC's X account hacked in embarrassing security lapse

Hacking

Propagated fake news about bitcoin

clock 10 January 2024 • 2 min read

More on Threats and Risks

Palo Alto Networks patches 'critical' vulnerability under active exploitation

Palo Alto Networks patches 'critical' vulnerability under active exploitation

Volexity says a ‘spike in exploitation’ is likely

Kyle Alspach
clock 16 April 2024 • 2 min read
CISA issues emergency order on Microsoft breach by Russian hackers

CISA issues emergency order on Microsoft breach by Russian hackers

Affected bodies must take immediate action, agency says

Kyle Alspach
clock 12 April 2024 • 2 min read
Fortinet addresses critical vulnerability in FortiClientLinux

Fortinet addresses critical vulnerability in FortiClientLinux

FortiOS, FortiProxy, FortiClientMac and FortiSandbox also patched

clock 12 April 2024 • 3 min read