— Posts
05 / 05
-
2026 · 02 · 10
When Two Parsers Disagree: Exploiting Query String Differentials for XSS
-
2026 · 02 · 03
Shaking the MCP Tree: a security deep dive
-
2025 · 10 · 19
Cloudflare Image Proxy as a CSPT Gadget: A Cross-Origin CSPT Exploit
-
2025 · 06 · 01
Puny-Code, 0-Click Account Takeover
-
2025 · 02 · 15
CSS Data Exfiltration to Steal OAuth Token