The model isn't cooperating #CyberSecurity #Vulnerability #Research
Smashing the token limit with overlapping fragments #CyberSecurity #Vulnerabilities #WebSecurity
HTTP/3 in Burp Suite - it's time to find a bigger wordlist #CyberSecurity #WebSecurity #Networking
What's in a tag name? JavaScript, apparently #WebSecurity #JavaScript #Vulnerability
CSS:the bomb inside your inbox #WebSecurity #CyberSecurity #Vulnerability
CRLF-Powered Desync Attacks: Beheading HTTP Streams #WebSecurity #CyberSecurity #Vulnerability
Can AI do novel security research? Meet the HTTP Terminator #CyberSecurity #AI #Research
Top 10 web hacking techniques of 2025 #CyberSecurity #Hacking #WebSecurity
Top 10 web hacking techniques of 2025: call for nominations #WebSecurity #Hacking #CyberSecurity
The Fragile Lock: Novel Bypasses For SAML Authentication #CyberSecurity #WebSecurity #SAML
Introducing HTTP Anomaly Rank #WebSecurity #CyberSecurity #Vulnerability
WebSocket Turbo Intruder: Unearthing the WebSocket Goldmine #WebSecurity #CyberSecurity #VulnerabilityAnalysis
Cookie Chaos: How to bypass __Host and __Secure cookie prefixes #Cybersecurity #WebSecurity #Vulnerabilities
Inline Style Exfiltration: leaking data with chained CSS conditionals #CyberSecurity #WebSecurity #Vulnerability
Beware the false false-positive: how to distinguish HTTP pipelining from request smuggling #WebSecurity #CyberSecurity #Networking
HTTP/1.1 must die: the desync endgame #WebSecurity #CyberSecurity #Networking
Repeater Strike: manual testing, amplified #CyberSecurity #WebSecurity #Vulnerability
Drag and Pwnd: Leverage ASCII characters to exploit VS Code #CyberSecurity #Vulnerability #VSCode
Document My Pentest: you hack, the AI writes it up! #CyberSecurity #AI #PenetrationTesting
SAML roulette: the hacker always wins #CyberSecurity #Hacking #Vulnerability
Shadow Repeater:AI-enhanced manual testing #Cybersecurity #WebSecurity #AI
Top 10 web hacking techniques of 2024 #CyberSecurity #Hacking #WebSecurity
Bypassing character blocklists with unicode overflows #WebSecurity #CyberSecurity #Vulnerabilities
Stealing HttpOnly cookies with the cookie sandwich technique #CyberSecurity #WebSecurity #Hacking
Top 10 web hacking techniques of 2024: nominations open #CyberSecurity #Hacking #Vulnerability
Bypassing WAFs with the phantom $Version cookie #WebSecurity #CyberSecurity #WAF
New crazy payloads in the URL Validation Bypass Cheat Sheet #CyberSecurity #WebSecurity #Vulnerabilities
Concealing payloads in URL credentials #Cybersecurity #WebSecurity #Vulnerability
Introducing the URL validation bypass cheat sheet #WebSecurity #CyberSecurity #Vulnerability
Gotta cache 'em all: bending the rules of web cache exploitation #WebSecurity #CyberSecurity #Exploitation
Splitting the email atom: exploiting parsers to bypass access controls #Cybersecurity #WebSecurity #Vulnerability
Listen to the whispers: web timing attacks that actually work #CyberSecurity #WebSecurity #Vulnerability
Fickle PDFs: exploiting browser rendering discrepancies #CyberSecurity #WebSecurity #Vulnerability
A hacking hat-trick: previewing three PortSwigger Research publications coming to DEF CON & Black Hat USA #CyberSecurity #Hacking #Research
onwebkitplaybacktargetavailabilitychanged?! New exotic events in the XSS cheat sheet #WebSecurity #CyberSecurity #XSS
Refining your HTTP perspective, with bambdas #WebSecurity #CyberSecurity #Research
Introducing SignSaboteur: forge signed web tokens with ease #WebSecurity #CyberSecurity #Vulnerability
Making desync attacks easy with TRACE #CyberSecurity #WebSecurity #Vulnerability
Using form hijacking to bypass CSP #WebSecurity #CyberSecurity #Vulnerability
Top 10 web hacking techniques of 2023 #CyberSecurity #Hacking #WebSecurity