Thousands of secrets leaking through vibe-coded sites — has one-prompt web dev come at a hidden security cost? Project Resonance, Wave 15.
A closer look at the Tranco Top 1 Million sites — the technologies powering them and the vulnerabilities underneath. Project Resonance, Wave 12.
My first published writeup — and my first critical. A zero-interaction account takeover on a private HackerOne program.
How BurpSuite intercepts HTTPS, and a simple Frida workflow to strip SSL pinning from Android apps — written so beginners can follow along.
GraphQL lets clients ask for exactly the data they need — and sometimes far more than they should get. A practical tour of the attack surface.
The XML-based open standard behind most Single Sign-On — how identity data moves between an identity provider and a service provider.
Exploring the efficiency of Golang's goroutines and waitgroups — and how they help you write dramatically faster tooling.
Teach your CS professor that his PhD isn't in security. A TryHackMe room — code execution to a reverse shell and privilege escalation.
HackerOne's annual CTF — my first-ever competition. With little prior experience I still cracked a handful of challenges; here's how.
No entries match that search.