# AppSec Newsletter 0003

Olá champs! Chegou mais uma edição da nossa AppSec Newsletter!

### Links

* [Hashcorp muda licença de seus produtos](https://www.youtube.com/watch?v=cQM1RGfh6Qk)
    
* [New Python URL Parsing Flaw Could Enable Command Execution Attacks](https://thehackernews.com/2023/08/new-python-url-parsing-flaw-enables.html?m=1)
    
* [.NET developers alert: Moq NuGET package exfiltrates user emails from git](https://snyk.io/blog/moq-package-exfiltrates-user-emails/)
    
* (video) [How to Hack ArgoCD to Cluster Administrator](https://www.youtube.com/watch?v=IyLWAZlzPNM) (by John Hammond)
    
* (tool) [navginx: navgix is a multi-threaded golang tool that will check for nginx alias traversal vulnerabilities](https://github.com/hakaioffsec/navgix)
    
* [NIST Drafts Major Update to Its Widely Used Cybersecurity Framework](https://www.nist.gov/news-events/news/2023/08/nist-drafts-major-update-its-widely-used-cybersecurity-framework)
    

### Vagas

* [Mercado Livre: Cyber Security Engineer](https://www.linkedin.com/jobs/view/3689601230/)
    
* [Nova8: Analista de Segurança da Informação Sênior - AppSec](https://www.linkedin.com/jobs/view/3689158902/)
